Here's my update to the broader community about the ongoing incident investigation. I want to give you the rundown of the situation directly.
A Vercel employee got compromised via the breach of an AI platform customer called https://t.co/7PY6gGtzgI that he was using. The details are being fully investigated.
Through a series of maneuvers that escalated from our colleague’s compromised Vercel Google Workspace account, the attacker got further access to Vercel environments.
Vercel stores all customer environment variables fully encrypted at rest. We have numerous defense-in-depth mechanisms to protect core systems and customer data. We do have a capability however to designate environment variables as “non-sensitive”. Unfortunately, the attacker got further access through their enumeration.
We believe the attacking group to be highly sophisticated and, I strongly suspect, significantly accelerated by AI. They moved with surprising velocity and in-depth understanding of Vercel.
At the moment, we believe the number of customers with security impact to be quite limited. We’ve reached out with utmost priority to the ones we have concerns about. All of our focus right now is on investigation, communication to customers, enhancement of security measures, and sanitization of our environments. We’ve deployed extensive protection measures and monitoring. We’ve analyzed our supply chain, ensuring Next.js, Turbopack, and our many open source projects remain safe for our community.
The recommendation for all Vercel customers is to follow the Security Bulletin closely (https://t.co/BLVnic9fJC). My advice to everyone is to follow the best practices of security response: secret rotation, monitoring access to your Vercel environments and linked services, and ensuring the proper use of the sensitive env variables feature.
In response to this, and to aid in the improvement of all of our customers’ security postures, we’ve already rolled out new capabilities in the dashboard, including an overview page of environment variables, and a better user interface for sensitive env var creation and management. As always, I’m totally open to your feedback.
We’re working with elite cybersecurity firms, industry peers, and law enforcement. We’ve reached out to Context to assist in understanding the full scale of the incident, in an effort to protect other organizations and the broader internet. I also want to thank the Google Mandiant team for their active engagement and assistance.
It’s my mission to turn this attack into the most formidable security response imaginable. It’s always been a top priority for me. Vercel employs some of the most dedicated security researchers and security-minded engineers in the world. I commit to keeping you updated and rolling out extensive improvements and defenses so you, our customers and community, can have the peace of mind that Vercel always has your back.
@ybhrdwj I am very likely going to build this with Claude Code this afternoon and post a link to a free download to this thread, because this is absolutely ridiculous to suggest someone should pay $199 for something that probably took about 18 minutes for Claude Code to make.
I absolutely adore this thread
> be 16 year AI startup bro
> vibe code some nonsense slop app
> try to sell it for $199
> realize that other people can also vibe code
the dude literally open sourced it lmao
we're testing a new version of /init based on your feedback- it should interview you and help setup skills, hooks, etc.
you can enable it with this env_var flag:
CLAUDE_CODE_NEW_INIT=1 claude
would love your feedback!
We believe Cursor discovered a novel solution to Problem Six of the First Proof challenge, a set of math research problems that approximate the work of Stanford, MIT, Berkeley academics. Cursor's solution yields stronger results than the official, human-written solution.
Notably, we used the same harness that built a browser from scratch a few weeks ago. It ran fully autonomously, without nudging or hints, for four days.
This suggests that our technique for scaling agent coordination might generalize beyond coding.
SaaS is dead. It's over.
I just cancelled my free Gmail subscription and vibe coded my own.
There is no spam filtering, no support for attachments, and the storage costs me $150/mo, but worth it. This is the future.
What would be a new level up for cursor would be an audio input let me talk to it and use a transcription process to setup prompts!! Make it happen pls! @cursor_ai
I tested Claude Code with an API key where you pay for tokens. Every code update request for my apps costs about $0.80 in token cost.
I make a couple hundred requests every day with my Max subscription ($100/month). If I paid for tokens, that would cost me around $80/day. So, Claude sells Max about 30 times cheaper than it sells Opus to third parties.
There's no way a third-party IDE company without its own Claude Opus-like model can provide a competing agentic coding service to Anthropic.
Cursor? Are you kidding me?