Menu

Post image 1
Post image 2
Post image 3
Post image 4
Post image 5
Post image 6
Post image 7
1 / 7
0

AI-assisted intruders pwned Vercel via OAuth abuse and a pilfered employee account

go.theregister.com·Carly Page·about 1 month ago
#50IKUlP5
#vercel#rauch#says#didn#credentials#photo
Reading 0:00
15s threshold

Vercel's CEO reckons the crooks behind its recent breach likely had a helping hand from AI, saying the attackers moved with "surprising velocity" and a deep understanding of the company's infrastructure. In a public update following the incident, Guillermo Rauch reckons the intrusion began with a compromised employee account linked to Context.ai. An attacker used that access to hijack the employee's Vercel Google Workspace account to drill into the company's systems. From there, the hacker poked around environment variables – including ones not marked as sensitive – and used that to get deeper in. Rauch says the attacker may not have been working alone. "We believe the attacking group to be highly sophisticated and, I strongly suspect, significantly accelerated by AI," Rauch said. "They moved with surprising velocity and in-depth understanding of Vercel." Rauch didn't go into detail on the AI claim, saying only that the cyber baddies didn't hang about.…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More