Skip to main content
See every side of every news story
Published loading...Updated

AI-Pwned: Vercel Breach Traced to Stolen Employee Creds

  • On Sunday, San Francisco-based Vercel reported that attackers compromised customer data by hopping through multiple internal systems via a third-party service, prompting the company to advise users to rotate credentials immediately.
  • The compromise originated in February when a Context employee's computer was infected with Lumma Stealer malware, granting attackers access to their Google Workspace account and subsequently Vercel's environment variables.
  • A threat group identifying as ShinyHunters claimed responsibility on Telegram for stolen source code and databases, though Google Threat Intelligence analyst Austin Larsen suspects the attacker is an imposter inflating notoriety.
  • Vercel and Context are conducting coordinated investigations aided by CrowdStrike and Mandiant, while warning that the breach of Context's Google Workspace OAuth app potentially impacts hundreds of users across organizations.
  • Researchers believe the sophisticated attackers likely utilized AI to accelerate their velocity during the breach, underscoring the inherent risks of interconnected cloud applications and overly privileged permissions within SaaS integrations.
Insights by Ground AI

21 Articles

itbrief.initbrief.in
+5 Reposted by 5 other sources

Vercel breach linked to compromised Context.ai integration

Vercel says an attack on a third-party AI tool let hackers hijack a staff Google Workspace account and reach internal systems.

Read Full Article

A Vercel employee had given full access to an AI tool via OAuth to his Google Workspace account, which was used by attackers and thus reached deep into the Next.js provider's infrastructure. Vercel, the cloud company behind the popular Next.js framework, confirmed a security incident. The starting point was not Vercel itself, but a third party: the AI platform Context.ai was compromised, and via it the attackers entered the Google Workspace acco…

Read Full Article
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

CSO Online broke the news on Monday, April 20, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal