In April 2026, the incident drew significant attention across the software and security industries. Vercel, the company behind Next.js and a leader in modern web development, confirmed that its internal systems had been breached. The attack was not a direct compromise of Vercel’s infrastructure. Rather, the OAuth token theft from a third-party AI tool gave …
|
|



