In collaboration with @github, @Microsoft, @npmjs, and @SocketSecurity, our security team has confirmed that no npm packages published by Vercel have been compromised.
There is no evidence of tampering, and we believe the supply chain remains safe.
https://t.co/0S939n3qHC
Here's my update to the broader community about the ongoing incident investigation. I want to give you the rundown of the situation directly.
A Vercel employee got compromised via the breach of an AI platform customer called https://t.co/7PY6gGtzgI that he was using. The details are being fully investigated.
Through a series of maneuvers that escalated from our colleague’s compromised Vercel Google Workspace account, the attacker got further access to Vercel environments.
Vercel stores all customer environment variables fully encrypted at rest. We have numerous defense-in-depth mechanisms to protect core systems and customer data. We do have a capability however to designate environment variables as “non-sensitive”. Unfortunately, the attacker got further access through their enumeration.
We believe the attacking group to be highly sophisticated and, I strongly suspect, significantly accelerated by AI. They moved with surprising velocity and in-depth understanding of Vercel.
At the moment, we believe the number of customers with security impact to be quite limited. We’ve reached out with utmost priority to the ones we have concerns about. All of our focus right now is on investigation, communication to customers, enhancement of security measures, and sanitization of our environments. We’ve deployed extensive protection measures and monitoring. We’ve analyzed our supply chain, ensuring Next.js, Turbopack, and our many open source projects remain safe for our community.
The recommendation for all Vercel customers is to follow the Security Bulletin closely (https://t.co/BLVnic9fJC). My advice to everyone is to follow the best practices of security response: secret rotation, monitoring access to your Vercel environments and linked services, and ensuring the proper use of the sensitive env variables feature.
In response to this, and to aid in the improvement of all of our customers’ security postures, we’ve already rolled out new capabilities in the dashboard, including an overview page of environment variables, and a better user interface for sensitive env var creation and management. As always, I’m totally open to your feedback.
We’re working with elite cybersecurity firms, industry peers, and law enforcement. We’ve reached out to Context to assist in understanding the full scale of the incident, in an effort to protect other organizations and the broader internet. I also want to thank the Google Mandiant team for their active engagement and assistance.
It’s my mission to turn this attack into the most formidable security response imaginable. It’s always been a top priority for me. Vercel employs some of the most dedicated security researchers and security-minded engineers in the world. I commit to keeping you updated and rolling out extensive improvements and defenses so you, our customers and community, can have the peace of mind that Vercel always has your back.
NOTION IS LEAKING YOUR EMPLOYEES EMAILS
every public Notion page silently exposes the full name, email, and profile photo of everyone who ever touched it
here's how it works:
> public page leaks editor UUIDs in block permissions - no auth needed
> feed those UUIDs into /api/v3/syncRecordValuesMain
> get names + emails + photos back instantly
> zero tokens. zero cookies. one POST request.
your company wiki is public? job board? onboarding doc?
that's every editor's corporate email, free for anyone to grab
pair it with getLoginOptions - also zero auth - and you know exactly who uses a password vs SSO
that's a pre-sorted credential stuffing list handed to you on a plate
reported to HackerOne July 2022
triaged as "informative"
never fixed
still works today
a vercel foi hackeada hoje
o grupo ShinyHunters tá vendendo os dados internos da empresa no BreachForums por 2 milhões de dólares
source code, API keys, NPM tokens, GitHub tokens, contas de funcionários, dados do Linear interno e sistema de gerenciamento de usuários
se você tem projeto na vercel, lê o próximo tweet
We’ve identified a security incident that involved unauthorized access to certain internal Vercel systems, impacting a limited subset of customers. Please see our security bulletin:
https://t.co/0S939n3qHC
VERCEL GOT HACKED
ShinyHunters - the group behind the Ticketmaster breach - is selling Vercel's internal database for $2M on BreachForums
here's why every developer should care:
- they have NPM tokens and GitHub tokens
- Vercel owns Next.js - 6 million weekly downloads
- one malicious push = global supply chain attack
- Vercel confirmed the breach today, April 19
- they literally DMed the hackers on Telegram asking them to stop
rotate your env variables RIGHT NOW
I'll probably get attacked for saying this, but every team in crypto should use this as an opportunity to slow down and focus on security.
If possible, dedicate an entire team to it.
I know how hard it is. There's an enormous amount of pressure to grow at all costs. Your runway will pressure you. Your investors will pressure you. Your token holders will pressure you.
But you can't grow if you're hacked.
Take time to stop what you're doing, stop stressing about growth, and audit your whole stack. Custody. Risk. Dependencies. Access control. Everything. The world will still be here when you get back.
Focus on the safety of your users' funds above all else. In the long term, this is the most important requirement to grow.
Always learning new stuff on @publed_official.
If you want to know about Multi-Label Logistic Classifiers, check out this Knowledge Object 👇
https://t.co/ZpZhrq7pQM
Yesterday, our co-founder @vitorhsr99 shared our project with the talk: “When Science and Education Meet Web3."
Huge thanks to @upholdtalent and @subvisual for hosting the return of @BragaBlockchain! 📍
It was a pleasure hearing all your great insights! 🙌
🚀 Publed is thrilled to be back at @SolanaConf, this time in the vibrant city of Singapore! 🌟
Join us as we continue to explore and innovate. Who will be there? Let us know in the comments! 📍
Can't wait to see what unfolds!✨
https://t.co/GRaQcDtarq
🧵1/10 In Defense of #Haskell, #Jazz, and Pure Math: Why They're Not as Useless as You Think. Let's decode their hidden worth and unexpected impact (THREAD). 🎶💻📐
Inspiration behind these thoughts: 👇
https://t.co/Gi3gdCgYFP
A while ago, @rmdmac was invited to talk at Bitalks 🇵🇹 where he shared valuable insights on creating value through a positive work environment, the journey from services to products, and the importance of quick learning and validation in business
https://t.co/M8iXFKsUbv
Exciting announcement! Join our Discord community for exclusive updates, engaging discussions, and more!
Connect with fellow Publeders and become a part of our thriving community.
Click the link to join now: [https://t.co/JBjft7hCiX]
It was a pleasure to be at @PortoCoda today as a speaker, presenting my talk: When Science & Education meet Web3.
I covered topics such as DeSci (Decentralized Science), DeEd (Decentralized Education), projects working in each of these fields, and finally @publed_official working in both 🤝
It's good to see this paradigm shift, with several speakers presenting different real-world use cases for Web3 technologies.
Congratulations @PortoCoda for the excellent organization!