Learning from the Vercel breach: Shadow AI & OAuth sprawl
2026-04-29T13:23:40Z•86655fa531ff289529bf016a4c35a912c7304a93bbbc4ca8cef91b655669c57c
active-exploitationanodotcheckmarxcisadata-wiperexchange-onlinegithubglasswormlapsus$litellmoauthopenvsxopsec-playbookphishingransomwarercerobinhoodsql-injectionsupply-chainthird-party-risktls-deprecationvect-2.0vercelvimeowindows-zero-day
What happened
Multiple high-impact security events reported: a Vercel breach highlights the risk of third‑party OAuth integrations and downstream account compromise; GitHub patched a critical RCE (CVE-2026-3854) that could have exposed millions of private repos; CISA has ordered federal patching for a Windows vulnerability being exploited as a zero‑day; and attackers are actively exploiting a critical pre‑auth SQL injection in the LiteLLM gateway (CVE-2026-42208) to steal sensitive data. Other notable incidents include the Anodot breach impacting Vimeo users, Checkmarx data leaked by LAPSUS$, a GlassWorm/VS
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 86655fa531ff289529bf016a4c35a912c7304a93bbbc4ca8cef91b655669c57c
- Enrichment time
- 2026-04-29T13:23:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.