Cloud app hosting giant Vercel this weekend said hackers had breached its internal systems and accessed customer data.
Hackers have claimed they have stolen sensitive customer credentials from Vercel’s systems and are selling the data online. In a statement on Sunday, Vercel said the breach originated from another software maker, Context AI. One of Vercel’s employees downloaded an app made by Context AI and connected it to their corporate account, which is hosted by Google. The hackers used that connection (known as OAuth) to take over the Vercel employee’s Google account and gain access to some of Vercel’s internal systems, including credentials that were not encrypted.
Read more…
Source: TechCrunch News
Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox
Related:
- Pharma giant Cencora hit by major cyberattack
February 28, 2024
Cencora has confirmed suffering a data breach earlier this month which resulted in the theft of sensitive, personal data. Cencora is a drug wholesale company and a contract research firm that was previously known as Amerisource Bergen. It was formed in 2001, after the merger of Bergen Brunswig and AmeriSource. Read more… Source: MSN News
- A first analysis of the i-Soon data leak
February 21, 2024
Data from a Chinese cybersecurity vendor that works for the Chinese government has exposed a range of hacking tools and services. Although the source is not entirely clear, it seems that a disgruntled staff member of the group leaked the information on purpose. The vendor, i-Soon (aka Anxun) is believed to be a private contractor that ...
- Sharp rise in cyber attacks at UK law firms as hackers eye sensitive data
February 21, 2024
The number of reported cyber attacks on UK law firms has increased 36 per cent over the past year. According to data by speciality reinsurance group Chaucer, there were 166 reported cyber breaches in 2021/22, this number jumped to 226 for 2022/23 (as of 30 September). Chaucer says that the large number of attacks against law ...
- India: EPFO, PMO data breach, Centre says aware of reports, Cert-In looking into details
February 21, 2024
The government is aware of reports of a data breach that claims having datasets from the Prime Minister’s Office (PMO) and the Employees’ Provident Fund Organisation, and has asked the Indian Computer Emergency Response Team (Cert-In) to look into it, senior officials told ET. “We are aware of it but need to verify if the claims ...
- Toronto Public Library uncertain whose data stolen in October cyber attack
February 20, 2024
The Toronto Public Library needs more time to investigate whether cardholder, volunteer and donor data has been compromised during a serious cyberattack four months ago. In a final report to the board on the October 2023 security breach that the library said exposed the personal data of staff and family members, it said it is “currently ...
- UK: Council worker took tens of thousands of email addresses in massive data breach
February 19, 2024
A massive data breach by a worker at Stratford-on-Avon District Council saw tens of thousands of email addresses taken. The breach, which happened in November last year, was over a database of email addresses given by residents, the authority said. The probe found that around 79,000 email addresses from the garden waste collection database were affected. ...

