GlobalSell

Vercel breach exposes the OAuth gap most security teams cannot detect, scope or contain

Vercel breach exposes the OAuth gap most security teams cannot detect, scope or contain
Key Takeaways

Read this first — then go as deep as you need.

One employee at Vercel adopted an AI tool. One employee at that AI vendor got hit with an infostealer. That combination created a walk-in path to Vercel’s production environments through an OAuth grant that nobody had reviewed. js and its millions of weekly npm downloads, confirmed on Sunday that attackers gained unauthorized access to internal systems.

Mandiant was brought in. Law enforcement was notified. Investigations remain active.

Discussion

Join the discussion

Sign in to leave a comment on this article.

Loading comments...

Enjoying this article?

Get more like it delivered to your inbox — free.

This article was compiled by GlobalSell News from publicly available reporting and has been edited for clarity and length. For full details, read the original source.

Advertisement