Wu Shuo learned that, according to an official post from Vercel, their security team, after joint investigation with GitHub, Microsoft, npmjs, and SocketSecurity, confirmed that no npm packages released by Vercel have been compromised in recent security incidents. Vercel stated that, at present, there is no evidence of tampering, and their software supply chain remains secure. It is reported that Vercel confirmed on April 19th that their internal systems were accessed without authorization. The cause was that an attacker gained access by infiltrating a third-party AI tool (Context ai) used by an employee of the platform through Google Workspace OAuth credentials, obtaining some non-sensitive environment variables, but sensitive data was not affected.

Ver originales
Esta página puede contener contenido de terceros, que se proporciona únicamente con fines informativos (sin garantías ni declaraciones) y no debe considerarse como un respaldo por parte de Gate a las opiniones expresadas ni como asesoramiento financiero o profesional. Consulte el Descargo de responsabilidad para obtener más detalles.
  • Recompensa
  • Comentar
  • Republicar
  • Compartir
Comentar
Añadir un comentario
Añadir un comentario
Sin comentarios
  • Anclado