It's time to treat browser extensions like supply chain attack vectors
aikido.dev | incident | #ai-security | #supply-chain | #third-party-risk | #infostealer | #oauth | #supply-chain-security | #browser-extensions | #vercel
Summary
The Vercel breach began with a browser extension: an infostealer on a Context.ai employee's machine exposed OAuth tokens. Aikido says treat extensions as supply chain attack vectors.
- Published
- Collected
Skip to content