3 ms·
Am I reading this[1] correctly that they basically had that "compromised OAuth token" for a month now and it was only detected now when the attackers posted abo
by eddythompson80 6mo ago
Am I reading this[1] correctly that they basically had that "compromised OAuth token" for a month now and it was only detected now when the attackers posted about it in a forum?
[1] https://context.ai/security-update https://context.ai/security-update
- Maxious 6mo agoAnd that they engaged Crowdstrike for incident response... who missed OAuth tokens in the clear?
- eddythompson80 6mo agolol, yeah that Crowdstrike part was a funny CYA name drop
- newdee 6mo ago> Vercel’s internal OAuth configurations appear to have allowed this action to grant these broad permissions in Vercel’s enterprise Google Workspace. This was an interesting tidbit too. If true, this means that Vercel’s IT/Infosec maybe didn’t bother enabling the allowlist and request/review features for OAuth apps in their Google Workspace. On top of that, they almost certainly didn’t enable the scope limits for unchecked OAuth apps (e.g limiting it to sign-on/basic profile scopes).
- pier25 6mo agoA month? If true this is insane.