The Vercel incident was very simple. An employee connected an external AI tool to the company's Google Workspace through OAuth, and an attacker took over the account. From there, he had access to any internal data not marked as sensitive.
Clearly, this is not a real hack or a notorious zero-day exploitation. Eventually, someone, legitimately, connected an AI tool and clicked "Allow". That's it. The game is over.
I mean, let's be honest. Everyone at least once, connected a new AI tool, downloaded an Add-on, or used an unknown app "just to try it", didn't you? And in many cases, we linked it to our Google Workspace or GitHub. Did anyone connect it to production? Raise your hand.
The entire AI revolution relies on countless numbers of tools with connectivity and broad access. The downside is that we help attackers by making their attack path easier. Once they are in, everything is accessible, making the above recommendations the norm and even the default.
If you want to ensure the trustworthiness of your environment, you need to review and control the “mess” that AI tools create.
You probably cannot avoid it, but if you oversee and govern it, you can keep it trustworthy.
Not sure how to start maintaining your environment trustworthy?
