PANews reported on April 20th that Vercel CEO Guillermo Rauch posted on the X platform that the team is currently conducting a full investigation into the company's security incident. The incident stemmed from a Vercel employee's use of the AI platform client Context.ai, which was compromised. The attackers further gained access to Vercel's environment through the employee's compromised Google Workspace account. All customer environment variables stored by Vercel are fully encrypted, but the attackers exploited environment variables marked as "non-sensitive" by enumerating them. Vercel believes the attackers' techniques are highly sophisticated and may have significantly increased the speed and efficiency of the attack using AI. Currently, the number of affected customers is quite limited, and the affected customers have been contacted first. Vercel advises all customers to follow security bulletins, rotate keys, monitor access permissions, and use sensitive environment variable features correctly.
Vercel CEO: Security incident stemmed from a breach of Context.ai, an AI platform used by employees.
Share to:
Author: PA一线
This content is for market information only and is not investment advice.
Follow PANews official accounts, navigate bull and bear markets together
Recommended Reading
PANews App
24/7 blockchain news tracking and in-depth analysis.

