Skills
Vercel Breached via Context AI OAuth Supply Chain: Employee Granted 'Allow All' Permissions to Third-Party AI Tool, Attacker Pivoted to Customer Environment Variables
A Vercel employee signed up for Context AI's 'AI Office Suite' using their enterprise Google Workspace account with full OAuth permissions. When Context AI was compromised in March, attackers used the token to access the employee's Vercel account, then enumerated and decrypted non-sensitive environment variables. Vercel says 'hundreds of users across many organizations' may be affected, though variables marked 'sensitive' were not accessed. The breach demonstrates how third-party AI tool OAuth grants create lateral movement paths in enterprise environments.
↳ Follow the thread