Compromised AI tool Context.ai used as a pivot into Vercel
Attackers compromised AI productivity vendor Context.ai, then used an OAuth token from a Vercel employee who had granted the tool broad Google Workspace access to reach some Vercel environments and read environment variables.
- Disclosed
- Apr 2026
- Organization
- Vercel
- Vendor
- Unknown
- Product
- Context.ai
- Type of AI
- Work assistant
- How it happened
- Supply chain and access: Stolen token or key
- Harm
- Data exposed
- Data involved
- Credentials
- Reach
- One organization
- Severity
- High
- Model at fault
- No
- Status
- Confirmed