The Vercel Breach: OAuth Supply Chain Attack Exposes the Hidden Risk in Platform Environment Variables
An OAuth supply chain compromise at Vercel exposed how trusted third party apps and platform environment variables can bypass traditional defences and amplify blast radius. This article examines the attack chain, underlying design trade-offs, and what it reveals about modern PaaS and software supply chain risk.