Vercel got hacked because an employee clicked 'Allow' on an OAuth prompt. We all do this.
The Vercel breach wasn't some zero-day masterpiece. An employee clicked "Allow" on an OAuth prompt — the same button you and I mash dozens of times a month without reading a single line. Let me walk you through why this one haunts me. What Actually Happened Lumma Stealer malware harvested a Context.ai employee's credentials. The malware harvested credentials including an OAuth token from Context.ai's Google Workspace integration, which was connected to Vercel's systems. Here's the brutal part: t
Comment
Sign in to join the discussion.
Loading comments…