{"podcast":{"title":"Cybersecurity Today","slug":"cybersecurity-today-65508","podcast_index_feed_id":65508,"rss_url":"https://cybersecuritytoday.libsyn.com/rss","website_url":"https://www.technewsday.ca","image_url":"https://static.libsyn.com/p/assets/f/e/d/2/fed2f9cae1dc03ee16c3140a3186d450/Cybersecurity_Today_Apple_Podcast_3000x3000-20260618-qlx6twu0nx.jpg","author":"Tech Newsday","episode_count":100,"summary":"Updates on the latest cybersecurity threats to businesses, data breach disclosures, and how you can secure your firm in an increasingly risky time.","last_synced_at":"2026-07-13T06:21:08.396305+00:00","page_url":"https://stenobird.com/podcast/cybersecurity-today-65508"},"episode":{"title":"Inside The Vercel Supply Chain Exploit","slug":"inside-the-vercel-supply-chain-exploit","published_at":"2026-04-24T04:54:00+00:00","page_url":"https://stenobird.com/podcast/cybersecurity-today-65508/inside-the-vercel-supply-chain-exploit","show_page_url":"https://stenobird.com/podcast/cybersecurity-today-65508","url":"https://cybersecuritytoday.libsyn.com/inside-the-vercel-supply-chain-exploit","audio_url":"https://traffic.libsyn.com/secure/cybersecuritytoday/LATE.mp3?dest-id=679928","summary":"Inside the Vercel Breach: Highlighting OAuth Token Risk In a special edition of Cybersecurity Today, host Jim Love and guest Jamie Blasco (CTO, Nudge Security) discuss Vercel, a major developer hosting platform, and a breach tied to OAuth grants and shadow AI. Reporting shared by Contrast Security's David Lindner describes how a Context AI employee downloaded Roblox AutoFarm scripts, got infected with an info stealer, and attackers harvested credentials, compromised Context AI, then used an over-permissioned OAuth token from a Vercel employee who had signed up to Context AI with an enterprise account and clicked \"allow all,\" with Vercel working with Mandiant on a breach allegedly being sold for $2 million. The episode emphasizes that MFA may not mitigate OAuth abuse, urges admin-managed consent, continuous inventory and auditing of OAuth grants, and better visibility into risky third-party app access across Google Workspace and Microsoft 365. Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst 00:00 Special Edition Intro 00:14 Sponsor Message Meter 00:33 Supply Chain Hack Setup 01:16 Breach Seen In Wild 02:36 Meet Jamie Blasko 02:56 Who Is Vercel 04:34 How The Breach Happened 05:58 Context AI And Shadow IT 07:58 OAuth Controls And Audits 09:11 Impact And Open Questions 11:24 Why MFA Falls Short 12:22 Where To Get Help 14:07 Host Takeaways OAuth Risk 14:53 What To Do Next 16:06 Wrap Up And Feedback 16:42 Sponsor Close Meter 17:24 Final Sign Off","meta_description":"Inside the Vercel Breach: Highlighting OAuth Token Risk In a special edition of Cybersecurity Today, host Jim Love and guest Jamie Blasco (CTO, Nudge Secu…","key_points":[],"chapters":[],"topics":[],"duration_seconds":1059,"processing_state":"not_requested","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/cybersecurity-today-65508/episodes/inside-the-vercel-supply-chain-exploit/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/cybersecurity-today-65508/inside-the-vercel-supply-chain-exploit.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}