"We believe the attacking group to be highly sophisticated and, I strongly suspect, significantly accelerated by AI."
the ai bubble is so funny to me, vercel gets compromised and the ceo praises the hackers for their sophisticated use of AI.
Here's my update to the broader community about the ongoing incident investigation. I want to give you the rundown of the situation directly.
A Vercel employee got compromised via the breach of an AI platform customer called https://t.co/7PY6gGtzgI that he was using. The details are being fully investigated.
Through a series of maneuvers that escalated from our colleagueโs compromised Vercel Google Workspace account, the attacker got further access to Vercel environments.
Vercel stores all customer environment variables fully encrypted at rest. We have numerous defense-in-depth mechanisms to protect core systems and customer data. We do have a capability however to designate environment variables as โnon-sensitiveโ. Unfortunately, the attacker got further access through their enumeration.
We believe the attacking group to be highly sophisticated and, I strongly suspect, significantly accelerated by AI. They moved with surprising velocity and in-depth understanding of Vercel.
At the moment, we believe the number of customers with security impact to be quite limited. Weโve reached out with utmost priority to the ones we have concerns about. All of our focus right now is on investigation, communication to customers, enhancement of security measures, and sanitization of our environments. Weโve deployed extensive protection measures and monitoring. Weโve analyzed our supply chain, ensuring Next.js, Turbopack, and our many open source projects remain safe for our community.
The recommendation for all Vercel customers is to follow the Security Bulletin closely (https://t.co/BLVnic9fJC). My advice to everyone is to follow the best practices of security response: secret rotation, monitoring access to your Vercel environments and linked services, and ensuring the proper use of the sensitive env variables feature.
In response to this, and to aid in the improvement of all of our customersโ security postures, weโve already rolled out new capabilities in the dashboard, including an overview page of environment variables, and a better user interface for sensitive env var creation and management. As always, Iโm totally open to your feedback.
Weโre working with elite cybersecurity firms, industry peers, and law enforcement. Weโve reached out to Context to assist in understanding the full scale of the incident, in an effort to protect other organizations and the broader internet. I also want to thank the Google Mandiant team for their active engagement and assistance.
Itโs my mission to turn this attack into the most formidable security response imaginable. Itโs always been a top priority for me. Vercel employs some of the most dedicated security researchers and security-minded engineers in the world. I commit to keeping you updated and rolling out extensive improvements and defenses so you, our customers and community, can have the peace of mind that Vercel always has your back.
@bepsucks@FlopsyPipsqueak https://t.co/e9saLBOj2c narpy made a video covering everything you just mentioned and owning up to the parts heโs at fault with. He made this video 2 years ago covering events that happened 8-10 years ago (when he was 14/16)โฆ
Hereโs what Iโd do if I was in charge of GitHub, in order:
1. Have more than one 9 of uptime
2. Have more than two 9s of uptime
3. Have more than three 9s of uptime (this oneโs hard)
4. Have more than four 9s of uptime
5. Have more than five 9s of uptime
@forestdonk_@reticentfile@orologio91 Iโm confused, youโre the one making the call out tweet because u saw some random persons story on ig and didnโt even talk to them to find out if itโs real?
I decided to check back on this after some time. coin went to zero. its almost if it was a scam and everyone just hated on me for calling it what it was because the guy was dying.
I have never seen a bigger scam than this. This is fucking crazy. Who the fuck does a raising money for cancer by my memecoin $CANCER what the actual fuck is wrong with these people. PUMP DOT FUN??? Every day we stray further from god