Cloud development platform Vercel was hacked

The Verge
Vercel suffered a security breach linked to a compromised third-party AI tool, leading to the potential exposure of customer data.

Summary

The cloud development platform Vercel recently experienced a security incident where hackers gained unauthorized access to its systems. The breach, which Vercel confirmed impacted a limited subset of customers, involved the theft of data such as employee names, email addresses, and activity timestamps. Vercel identified the source of the attack as a compromised third-party AI tool that leveraged a vulnerable Google Workspace OAuth application. In response, the company has advised administrators to review their activity logs and rotate sensitive environmental variables like API keys and tokens as a security precaution.

(Source:The Verge)