Another day, another attack.
This time it’s Vercel – a Web3 infrastructure provider that fell prey to an attack comprising a ‘limited subset’ of customers’ credentials. As per the bulletin presented by the Vercel team, an illicit actor got access to API keys of various Vercel customers, maneuvering the entire app.
Further investigation revealed that the hacker had mainly aimed at the Google Workspace OAuth app, initiated via Context.ai, a third-party AI tool. With this small tool, the attacker was able to impact multiple users of the OAuth app across various organizations, including Vercel.
Once getting access to the platform’s Google Workspace, the hacker was capable of manipulating unmarked “sensitive”…







