A security incident at Vercel, disclosed on April 19, 2026, highlighted a new type of indicator of compromise related to AI agent OAuth grants. The incident originated from a compromise of Context.ai, a third-party AI tool used by a Vercel employee, which led to the takeover of the employee's Google Workspace account. This allowed attackers to access sensitive environment variables within Vercel's systems. The vulnerability stems from AI tools being granted broad access through OAuth tokens, which are difficult to revoke centrally if managed by individual users. This pattern mirrors a previous incident involving Salesloft and Drift, where attackers exploited OAuth tokens to access customer data. AI
IMPACT Highlights the critical need for robust non-human identity management and centralized OAuth token revocation for AI tools.
RANK_REASON The article discusses a security incident and its implications for how AI tools integrate with existing systems, focusing on the practical security risks rather than a new model release or research.
- AWS
- Drift
- GitHub
- Google Mandiant
- Google Workspace
- Microsoft
- OAuth
- Salesforce
- Salesloft
- Socket
- Vercel
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →