Vercel CEO releases security incident update: Google Workspace account compromised, attacker gained environment access rights

robot
Abstract generation in progress
ME News Report, April 20 (UTC+8), Vercel, the front-end cloud platform, CEO Guillermo Rauch tweeted that the team is currently conducting a comprehensive investigation into the company's security incident. The incident was caused by a Vercel employee's AI platform client, Context.ai, being compromised, leading to the breach of their Vercel Google Workspace account. The attacker further gained environment access through a series of operations. All customer environment variables at Vercel are fully encrypted at rest, but the platform supports marking some variables as "non-sensitive," allowing the attacker to obtain further access through enumeration. Their speed of action and understanding of Vercel's architecture exceeded expectations. Currently, the number of customers affected by the security incident is limited; Vercel has prioritized contacting the relevant customers and deploying protective measures and monitoring. The team is working closely with Mandiant, industry partners, and law enforcement agencies, and has conducted a comprehensive review of the supply chain (including open-source projects like Next.js, Turbopack, etc.) to ensure security. The official has also launched a new dashboard feature to help users overview and manage environment variables. (Source: Foresight News)
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments