Nobody phished anyone in the Vercel or Composio breaches. That's the part worth sitting with for a second, because for the last decade "security awareness training" has been the default answer to "how do we stop account takeover. " Turns out you can skip the user entirely if you just steal the t...
Source: [Dev.to](https://dev.to/coridev/oauth-tokens-were-always-the-weak-link-ai-agents-just-made-it-worse-4dc6)