DALLAS – New research from Trend Micro sheds light on the sophisticated mechanics behind the recent security breach at Vercel, confirming that the industry faces a new and dangerous frontier: supply chain compromise through Artificial Intelligence (AI) integrations.
What initially seemed like a direct hack turned out to be a case study on how the interconnectivity of modern development tools can be used as a double-edged sword.
The OAuth "Domino Effect"The technical report reveals that the attack vector was an AI application (Context.ai) with overly broad OAuth permissions. By compromising this third-party tool, attackers not only obtained the data from the application but also inherited access tokens that allowed them to move laterally into Vercel's internal systems.