Live data from Hacker News

Vercel April 2026 security incident

bleepingcomputer.com

21–30 of 540 posts

Re: Vercel April 2026 security incident

#21
post #14

This is why you pay a real provider for serious business needs, not an AWS reseller. Next.js is a fundamentally insecure framework, as server components are an anti-pattern full of magic leading to stuff like the below. Given their standards for framework security, it's not hard to believe their business' control plane is just as insecure (and probably built using the same insecure framework). Next.js is the new PHP,…

People say "Next.js is the new PHP" because it's the most popular and prominent tooling out there, and so by sheer number of available targets it's the one that comes up the most when things go wrong like this.

But there are more people trying to secure this framework and the underlying tools than there would be on some obscure framework or something the average company built themselves.

Also "pay a real provider", what does that mean? Are you again implying that the average company should be responsible for _more_ of their own security in their hosting stack, not less?

Most companies have _zero_ security engineers.. Using a vertically-integrated hosting company like Vercel (or other similar companies, perhaps with different tech stacks - this opinion has nothing to do with Next or Node) is very likely their best and most secure option based on what they are able to invest in that area.

Re: Vercel April 2026 security incident

#22
post #19

Earlier quoted context omitted.

ShinyHunters are a phishing group. What does this have to do with AI agents?

Run ai agents around the clock to do hyper targeted fishing

I feel like humans would be better at hyper targeting.

AI agents have the benefit of working at scale, probably "better" used for mass targeting.

Re: Vercel April 2026 security incident

#23
post #7

https://x.com/theo/status/2045871215705747965 - "Everything I know about this hack suggests it could happen to any host" He also suggests in another post that Linear and GitHub could also be pwned? Either way, hugops to all the SRE/DevOps out there, seems like it's going to be a busy Sunday for many.

I don't know if I'd trust some random programmer-streamer-influencer on anything other than the topic of streamer-influencing.

Re: Vercel April 2026 security incident

#24
post #7

https://x.com/theo/status/2045871215705747965 - "Everything I know about this hack suggests it could happen to any host" He also suggests in another post that Linear and GitHub could also be pwned? Either way, hugops to all the SRE/DevOps out there, seems like it's going to be a busy Sunday for many.

”Any host” of what? That’s such a non-descriptive statement and clearly not true at face value.

Re: Vercel April 2026 security incident

#26
post #22

Earlier quoted context omitted.

Run ai agents around the clock to do hyper targeted fishing

I feel like humans would be better at hyper targeting. AI agents have the benefit of working at scale, probably "better" used for mass targeting.

I disagree. Many humans are phishing in a different language than their native tongue, and LLMs are way better at sounding legit/professional than many of them. The best spear-phishing will still be humans, but AI definitely raises the bar.

Re: Vercel April 2026 security incident

#29

Much as I want to rip on vercel, its clear that ai is going to lead to mass security breaches. The attack surface is so large, and ai agents are working around the clock. This is a new normal. Open source software is going to change, companies wont be running random repos off github anymore

>> ai is going to lead to mass security breaches.

Let that be the end of Microsoft. Was forced to use their shitty products for years, by corporate inertia and their free Teams and Azure licenses, first-dose-is-free, curse.

Re: Vercel April 2026 security incident

#30
post #7

https://x.com/theo/status/2045871215705747965 - "Everything I know about this hack suggests it could happen to any host" He also suggests in another post that Linear and GitHub could also be pwned? Either way, hugops to all the SRE/DevOps out there, seems like it's going to be a busy Sunday for many.

I don't know if I'd trust some random programmer-streamer-influencer on anything other than the topic of streamer-influencing.

[deleted]
Post reply on HN