Vercel breach exposes the OAuth gap most security teams cannot detect, scope, or contain

TL;DR AI
2 min readKey summary
Attackers used a compromised Context.ai account and its OAuth access to enter Vercel internal systems and reach production-related resources.
Vercel said its npm packages were not tampered with, brought in Mandiant, and notified law enforcement.
The company also changed defaults so environment variables are treated as sensitive unless explicitly marked otherwise.
The breach highlights how a single third-party OAuth grant and exposed secrets can bypass traditional security controls.
