Learning from the Vercel breach: Shadow AI & OAuth sprawl

2026-04-29T13:23:40Z86655fa531ff289529bf016a4c35a912c7304a93bbbc4ca8cef91b655669c57c
active-exploitationanodotcheckmarxcisadata-wiperexchange-onlinegithubglasswormlapsus$litellmoauthopenvsxopsec-playbookphishingransomwarercerobinhoodsql-injectionsupply-chainthird-party-risktls-deprecationvect-2.0vercelvimeowindows-zero-day

What happened

Multiple high-impact security events reported: a Vercel breach highlights the risk of third‑party OAuth integrations and downstream account compromise; GitHub patched a critical RCE (CVE-2026-3854) that could have exposed millions of private repos; CISA has ordered federal patching for a Windows vulnerability being exploited as a zero‑day; and attackers are actively exploiting a critical pre‑auth SQL injection in the LiteLLM gateway (CVE-2026-42208) to steal sensitive data. Other notable incidents include the Anodot breach impacting Vimeo users, Checkmarx data leaked by LAPSUS$, a GlassWorm/VS

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
86655fa531ff289529bf016a4c35a912c7304a93bbbc4ca8cef91b655669c57c
Enrichment time
2026-04-29T13:23:40Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Learning from the Vercel breach: Shadow AI & OAuth sprawl · Baitaphish