We’ve released Next.js versions 16.2.6 and 15.5.18 with important security fixes.
These fixes address multiple vulnerabilities across high, moderate, and low severity, including one upstream React issue. We strongly recommend upgrading as soon as possible.
⬇️
Here's my update to the broader community about the ongoing incident investigation. I want to give you the rundown of the situation directly.
A Vercel employee got compromised via the breach of an AI platform customer called https://t.co/7PY6gGtzgI that he was using. The details are being fully investigated.
Through a series of maneuvers that escalated from our colleague’s compromised Vercel Google Workspace account, the attacker got further access to Vercel environments.
Vercel stores all customer environment variables fully encrypted at rest. We have numerous defense-in-depth mechanisms to protect core systems and customer data. We do have a capability however to designate environment variables as “non-sensitive”. Unfortunately, the attacker got further access through their enumeration.
We believe the attacking group to be highly sophisticated and, I strongly suspect, significantly accelerated by AI. They moved with surprising velocity and in-depth understanding of Vercel.
At the moment, we believe the number of customers with security impact to be quite limited. We’ve reached out with utmost priority to the ones we have concerns about. All of our focus right now is on investigation, communication to customers, enhancement of security measures, and sanitization of our environments. We’ve deployed extensive protection measures and monitoring. We’ve analyzed our supply chain, ensuring Next.js, Turbopack, and our many open source projects remain safe for our community.
The recommendation for all Vercel customers is to follow the Security Bulletin closely (https://t.co/BLVnic9fJC). My advice to everyone is to follow the best practices of security response: secret rotation, monitoring access to your Vercel environments and linked services, and ensuring the proper use of the sensitive env variables feature.
In response to this, and to aid in the improvement of all of our customers’ security postures, we’ve already rolled out new capabilities in the dashboard, including an overview page of environment variables, and a better user interface for sensitive env var creation and management. As always, I’m totally open to your feedback.
We’re working with elite cybersecurity firms, industry peers, and law enforcement. We’ve reached out to Context to assist in understanding the full scale of the incident, in an effort to protect other organizations and the broader internet. I also want to thank the Google Mandiant team for their active engagement and assistance.
It’s my mission to turn this attack into the most formidable security response imaginable. It’s always been a top priority for me. Vercel employs some of the most dedicated security researchers and security-minded engineers in the world. I commit to keeping you updated and rolling out extensive improvements and defenses so you, our customers and community, can have the peace of mind that Vercel always has your back.
We’ve identified a security incident that involved unauthorized access to certain internal Vercel systems, impacting a limited subset of customers. Please see our security bulletin:
https://t.co/0S939n3qHC
We’re also launching Immersive Navigation - our biggest navigation upgrade in over a decade!
A new vivid 3D view better reflects your surroundings, with helpful road details like lanes, crosswalks, traffic lights etc. Gemini models analyze real world imagery from Street View and aerial photos to give you an accurate view of landmarks along your route.
Starts rolling out in the US today.
Claude can now build interactive charts and diagrams, directly in the chat.
Available today in beta on all plans, including free.
Try it out: https://t.co/tHPAZRgQkn
Así está la situación en gringolandia
La gestapo cada día más violenta contra las mujeres y sobre todos las jóvenes..
En este vídeo se ve como empujan violentamente a la celda a Cassandra Feuerstein..
El fascismo puro y duro de Trump
Developer Week Day 2. 🛠️
We just gave your Coding Agent a Design Degree🎓🎨
Introducing the Stitch MCP Server. 🔌
You can now pipe Stitch designs directly into your favorite tools like Antigravity.
* Generate new screens without leaving your IDE
* Fetch the code from any design
* Inject context: Give your agent full visual awareness
Docs and more information 👇
Excited to launch Pencil
INFINITE DESIGN CANVAS for Claude Code
> Superfast WebGL canvas, fully editable, running parallel design agents
> Runs locally with Claude Code → turn designs into code
> Design files live in your git repo → Open json-based .pen format
Got 2nd place in the @GoogleDeepMind SG hackathon!
I built a webapp that converts 2d topo maps into 3d colourful renders + lets you fly through and ask gemini live api what you're looking at.
We will make the new 𝕏 algorithm, including all code used to determine what organic and advertising posts are recommended to users, open source in 7 days.
This will be repeated every 4 weeks, with comprehensive developer notes, to help you understand what changed.