Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

New East African bat coronavirus can invade human cells

Addressing the flexible plastic waste challenge

China-linked GopherWhisper infects 12 Mongolian government systems with Go backdoor

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Vercel finds more compromised accounts in breach related to Context.ai
Identity

Vercel finds more compromised accounts in breach related to Context.ai

By April 23, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananApril 23, 2026Artificial Intelligence / SaaS Security

Vercel said Wednesday that it has identified a set of additional customer accounts that were compromised as part of a security incident that allowed unauthorized access to its internal systems.

The company said it made the discovery after expanding its investigation to include an additional set of compromise indicators, in addition to examining requests to the Vercel network and environment variable read events in logs.

“Second, we discovered a small number of customer accounts unrelated to this incident and with evidence of prior compromise as a result of social engineering, malware, or other techniques,” the company said in an update.

In both cases, Barthel said it notified the affected parties. The exact number of customers affected was not disclosed.

The development comes after the company that created the Next.js framework admitted that the breach occurred due to a compromise of Context.ai after a Vercel employee used it, which allowed attackers to seize control of a Google Workspace account and use it to access Vercel accounts.

“From there, they were able to migrate to the Vercel environment and then manipulate the system to enumerate and decrypt non-sensitive environment variables,” Vercel said.

Further investigation by Hudson Rock revealed that one of its Context.ai employees was infected with Lumma Stealer in February 2026 after searching for Roblox automated farm scripts and game exploit executors. This indicates that this event may have been “Patient Zero” that triggered the entire chain of malicious actions.

“We understand that threat actors are now operating beyond their startups. [referring to Context.ai] Vercel CEO Guillermo Rauch said in an

It is unclear whether Vercel employees’ use of the Context AI Office Suite is authorized or an example of shadow AI. Shadow AI refers to the unauthorized use of artificial intelligence (AI) tools within SaaS apps without formal IT review or vetting, exposing organizations to unanticipated risks. AI Office Suite has since been deprecated by Context.ai.

“OAuth integration is useful because it reduces friction,” Tanium says. “These are also dangerous because they can inherit trust from users and organizations. If an attacker exploits an authorized integration, they could bypass some of the controls your team relies on to directly compromise your account.”

“What stands out operationally is not the amount of data exposed, but the attacker’s speed and ability to enumerate the internal environment before being detected. This changes the defender’s job. The challenge shifts from defense to rapid scoping and reducing the blast radius.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleApple patches iOS flaw that saved Signal notifications deleted in FBI investigation
Next Article China-linked GopherWhisper infects 12 Mongolian government systems with Go backdoor

Related Posts

China-linked GopherWhisper infects 12 Mongolian government systems with Go backdoor

April 23, 2026

Apple patches iOS flaw that saved Signal notifications deleted in FBI investigation

April 23, 2026

Malicious KICS Docker image and VS Code extension impact Checkmarx supply chain

April 22, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

New East African bat coronavirus can invade human cells

Addressing the flexible plastic waste challenge

China-linked GopherWhisper infects 12 Mongolian government systems with Go backdoor

Vercel finds more compromised accounts in breach related to Context.ai

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.