Перейти к содержимому
Оригинал
Permission Protocol · AI Agent Incident Tracker·· 19.04.2026Оценка ИИ60

Vercel 称遭黑客入侵致客户数据泄露,源头指向 Context AI 的 OAuth 授权

Оригинальный заголовок: App Host Vercel Says It Was Hacked and Customer Data Stolen

Заголовок и краткое изложение на выбранном языке ожидают перевода.

Краткий обзор ИИ

Vercel 称此次入侵源自一个连接到企业 Google 账号的 Context AI 应用,攻击者借该 OAuth 路径访问内部系统。TechCrunch 报道称受影响客户的 App 数据和密钥被泄露,Vercel 建议客户轮换部分部署凭证。分析认为 OAuth 授权本应是可审查的生产访问决策,却常被当作一次性同意点击,凭证暴露前应记录应用、scope、数据类别、有效期和签署方。

Полный текст

Полный текст на выбранном языке ожидает перевода. Пока показан оригинал.

Back to incident tracker

2026-04-19

CriticalMedia report

App Host Vercel Says It Was Hacked and Customer Data Stolen

The Vercel and Context AI OAuth breach shows why AI app grants and deployment credential access need scoped human approval.

Context AI OAuth app / VercelCredential exposureOAuth credential exposureGoogle Workspace / internal systems / deployment credentials

What happened

Vercel said the breach originated from a Context AI app connected to a corporate Google account; attackers used that OAuth path to access internal systems.

Why it matters

TechCrunch reported that affected customer app data and keys were compromised, with Vercel advising customers to rotate certain deployment credentials.

Missing authorization check

Not applicable: no agent authorization boundary was crossed in this incident.

Would PP block it?

The compromise ran through package, credential, or vendor infrastructure rather than through an agent tool call, so there is no agent action for an authorization gate to hold.

Incident analysis

Timeline and technical read

Timeline

  1. 2026-04-19

    Reports describe Vercel investigating a security incident tied to a Context AI OAuth connection.

  2. 2026-04-20

    Coverage stated that affected customers were advised to rotate certain deployment credentials.

  3. Permission boundary

    The authorization check belongs at the AI app grant and at any sensitive credential read.

Technical breakdown

  • OAuth grants are authorization events, but many product flows treat them as a one-time consent click instead of a reviewable production access decision.
  • An AI app connected to corporate identity can inherit access to internal systems and credential material.
  • A signed receipt should capture the app, scopes, data classes, expiration, and signer before credentials are exposed.

Authorization boundary

Where the authorization boundary should have been

This incident is categorized as Credential exposure. The relevant Permission Protocol gate is Credential Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.

If enforced at
OAuth grant, SaaS app connection, credential read
Still needs
Third-party SaaS OAuth grants outside deploy workflow
Receipt required for
Corporate account connection, credential access, deployment key read

No agent took an action in this incident. Permission Protocol gates what an agent does, so it does not apply where the harm required no agent action.

Start small

Put the relevant gate at this action boundary.

This incident maps to Credential Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.

Replay this incident with a signer in the loop

Источник: Permission Protocol · AI Agent Incident Tracker · permissionprotocol.com