Steven Tey Urges Admins to Restrict Unconfigured Google OAuth Apps
Steven Tey warns that third-party Google OAuth apps requesting scopes beyond basic profile data are a dangerous attack vector. He recommends Workspace admins restrict unconfigured third-party apps, linking to the Google admin settings page and crediting a tip.
Original post · 1 min read
To safeguard your org from attacks like this, highly recommend asking your Google workspace admin to restrict "unconfigured third-party apps" to only be able to request basic info needed 👇
Here's the direct link to access that settings page: admin.google.com/ac/owl/settings
h/t @matid for the pro-tip!
Guillermo Rauch @rauchgHere's my update to the broader community about the ongoing incident investigation. I want to give you the rundown of the situation directly.
A Vercel employee got compromised via the breach of an AI platform customer called Context.ai that he was using. The details are being fully investigated.
Through a series of maneuvers that escalated from our colleague’s compromised Vercel Google Workspace account, the attacker got further access to Vercel environments.
Vercel stores all customer environment variables fully encrypted at rest. We have numerous defense-in-depth mechanisms to prot…