Live data from Hacker News

Vercel April 2026 security incident

bleepingcomputer.com

31–40 of 540 posts

Re: Vercel April 2026 security incident

#31
post #4

Related: https://news.ycombinator.com/item?id=47824426 https://x.com/theo/status/2045862972342313374 > I have reason to believe this is credible. https://x.com/theo/status/2045870216555499636 > Env vars marked as sensitive are safe. Ones NOT marked as sensitive should be rolled out of precaution https://x.com/theo/status/2045871215705747965 > Everything I know about this hack suggests it could happen to any host http…

Who is this “theo” person and why are multiple people quoting him? He seems to have little to say that’s substantive at this point.

Re: Vercel April 2026 security incident

#32

I'm on a macbook pro, Google Chrome 147.0.7727.56. Clicking the Vercel logo at the top left of the page hard crashes my Chrome app. Like, immediate crash. What an interesting bug.

I'm running 147.0.7727.57 and this doesn't happen. Macbook Air M5. VERY interesting.

Re: Vercel April 2026 security incident

#33
post #7

https://x.com/theo/status/2045871215705747965 - "Everything I know about this hack suggests it could happen to any host" He also suggests in another post that Linear and GitHub could also be pwned? Either way, hugops to all the SRE/DevOps out there, seems like it's going to be a busy Sunday for many.

I don't know if I'd trust some random programmer-streamer-influencer on anything other than the topic of streamer-influencing.

The link at the top of the page it to vercel acknowledging it...

Re: Vercel April 2026 security incident

#34
post #7

https://x.com/theo/status/2045871215705747965 - "Everything I know about this hack suggests it could happen to any host" He also suggests in another post that Linear and GitHub could also be pwned? Either way, hugops to all the SRE/DevOps out there, seems like it's going to be a busy Sunday for many.

Ah, Theo with his vast insights and connections into everything. That man gets around, and his content is worth it's cost.

Theo's content boils down to the same boring formula. 1. Whatever buzzword headline is trending at the time 2. Immediate sponsored ad that is supposed to make you sympathize with Theo cause he "vets" his sponsors. 3. The man makes you listen to a "that totally happened" story that he somehow always involved himself personally. 4. Man serves you up an ad for his t3.chat and how it's the greatest thing in the world and how he should be paid more for his infinite wisdom. 5. A rag on Claude or OpenAI (whichever is leading at the time) 6. 5-10 minutes of paraphrasing an article without critical thought or analysis on the video topic.

I used to enjoy his content when he was still in his Ping era, but it's clear hes drunken the YT marketer kool-aid. I've moved on, his content gets recommend now and again, but I can't entertain his non-sense anymore.

Re: Vercel April 2026 security incident

#35
post #22

Earlier quoted context omitted.

Run ai agents around the clock to do hyper targeted fishing

I feel like humans would be better at hyper targeting. AI agents have the benefit of working at scale, probably "better" used for mass targeting.

this like is saying email marketing is done better if you hand write every email. Thats true, but the hit rate is so low, that you are better off generating 1 million hyper personalized emails and firing them off into the ether

Re: Vercel April 2026 security incident

#36

Much as I want to rip on vercel, its clear that ai is going to lead to mass security breaches. The attack surface is so large, and ai agents are working around the clock. This is a new normal. Open source software is going to change, companies wont be running random repos off github anymore

Your entire recent posting history is "software engineering is over, AI has won."

What's your agenda here?

Re: Vercel April 2026 security incident

#37
post #15

Earlier quoted context omitted.

Based on what, "feels like it"? Claiming that Cloudflare is affected by the same hack has to come from somewhere, but where is that coming from?

from his "sources". > Here’s what I’ve managed to get from my sources: >3. The method of compromise was likely used to hit multiple companies other than Vercel. https://x.com/theo/status/2045870216555499636 To be fair journalists often do this too, eg. "[company] was breached, people within the company claim"

Isn’t he a Vercel evangelist though?

Re: Vercel April 2026 security incident

#38
post #4

Related: https://news.ycombinator.com/item?id=47824426 https://x.com/theo/status/2045862972342313374 > I have reason to believe this is credible. https://x.com/theo/status/2045870216555499636 > Env vars marked as sensitive are safe. Ones NOT marked as sensitive should be rolled out of precaution https://x.com/theo/status/2045871215705747965 > Everything I know about this hack suggests it could happen to any host http…

Who is this “theo” person and why are multiple people quoting him? He seems to have little to say that’s substantive at this point.

Theo Browne is a reasonably well known YouTuber & YC founder.

https://t3.gg/

Re: Vercel April 2026 security incident

#39
post #7

https://x.com/theo/status/2045871215705747965 - "Everything I know about this hack suggests it could happen to any host" He also suggests in another post that Linear and GitHub could also be pwned? Either way, hugops to all the SRE/DevOps out there, seems like it's going to be a busy Sunday for many.

Ah, Theo with his vast insights and connections into everything. That man gets around, and his content is worth it's cost. Theo's content boils down to the same boring formula. 1. Whatever buzzword headline is trending at the time 2. Immediate sponsored ad that is supposed to make you sympathize with Theo cause he "vets" his sponsors. 3. The man makes you listen to a "that totally happened" story that he somehow alwa…

I don't watch his content, but I felt comfortable posting his link as I believe he's generally considered a reputable guy? His tweets sometimes come up in my for you tab and he seems reasonable and knowledgable generally? Maybe I'm wrong and shouldn't have linked to him as a source.

Re: Vercel April 2026 security incident

#40
post #4

Related: https://news.ycombinator.com/item?id=47824426 https://x.com/theo/status/2045862972342313374 > I have reason to believe this is credible. https://x.com/theo/status/2045870216555499636 > Env vars marked as sensitive are safe. Ones NOT marked as sensitive should be rolled out of precaution https://x.com/theo/status/2045871215705747965 > Everything I know about this hack suggests it could happen to any host http…

Who is this “theo” person and why are multiple people quoting him? He seems to have little to say that’s substantive at this point.

He’s a tech influencer, probably getting quoted here because he has the biggest reach of people covering this so far.
Post reply on HN