Learning from the Vercel breach: Shadow AI & OAuth sprawl
Summary
When employees connect unapproved AI apps to work platforms like Google Workspace or Salesforce using OAuth (a system that lets apps access your accounts), they create persistent bridges that attackers can exploit if the AI app gets hacked. The Vercel breach showed this risk in action: an employee used a trial version of Context.ai without approval, and when Context.ai was compromised, attackers used the OAuth tokens (digital keys that grant access) to reach sensitive Vercel data like API keys and employee records.
Classification
Affected Vendors
Related Issues
Original source: https://www.bleepingcomputer.com/news/security/learning-from-the-vercel-breach-shadow-ai-and-oauth-sprawl/
First tracked: April 29, 2026 at 02:00 PM
Classified by LLM (prompt v3) · confidence: 92%