Live data from Hacker News

Vercel April 2026 security incident

bleepingcomputer.com

321–330 of 540 posts

Re: Vercel April 2026 security incident

#321
post #10
post #7

https://x.com/theo/status/2045871215705747965 - "Everything I know about this hack suggests it could happen to any host" He also suggests in another post that Linear and GitHub could also be pwned? Either way, hugops to all the SRE/DevOps out there, seems like it's going to be a busy Sunday for many.

I do remember that OpenAI did use Vercel a year ago. They might have likely moved off of it to something better.

OpenAI owns Contexts.ai, doesn't it?

Re: Vercel April 2026 security incident

#322
post #219

Earlier quoted context omitted.

I don’t understand why they can’t just directly name the responsible app as it will come out eventually.

It’s context.ai https://x.com/rauchg/status/2045995362499076169

Which itself was the subject of a broader compromise as far as i can tell

Re: Vercel April 2026 security incident

#324

Earlier quoted context omitted.

Oracle too

Oracle? Oracle? The Oracle that published an announcement that said "we didn't get hacked" when the hackers had private customer info? The Oracle that does not allow you to do any security testing on their software unless you use one of their approved vendors? The Oracle that one of my customers uses where they have to turn off the HR portal for 2 weeks before annual performance evaluations because there is no way to…

I love a good cathartic rant

Re: Vercel April 2026 security incident

#325
post #304

Earlier quoted context omitted.

> Still no email blast from Vercel alerting users, which is concerning. On the one hand, I get that it's a Sunday, and the CEO can't just write a mass email without approval from legal or other comms teams. But on the other hand... It's Sunday. Unless you're tuned-in to social media over the weekend, your main provider could be undergoing a meltdown while you are completely unaware. Many higher-up folks check company…

Has anyone actually gotten an email from Vercel confirming their secrets were accessed? Right now we're all operating under the hope (?) that since we haven't (yet?) gotten an email, we're not completely hosed.

nope...I feel u, the "Hope-based security" is exactly what Vercel is forcing on its users right now by prioritizing social media over direct notification.

If the attacker is moving with "surprising velocity," every hour of delay on an email blast is another hour the attacker has to use those potentially stolen secrets against downstream infrastructure. Using Twitter/X as a primary disclosure channel for a "sophisticated" breach is amateur hour. If legal is the bottleneck for a mass email during an active compromise, then your incident response plan is fundamentally broken.

Re: Vercel April 2026 security incident

#326

Earlier quoted context omitted.

10 years ago it was Heroku and Three.js.

New one coming in 5 years. Cycle repeats itself.

I don't think so, AIs are going to freeze the tooling to what we have today since that's what's in the training corpus, and it's self reinforcing.

Re: Vercel April 2026 security incident

#327

I've been part of a response team on a security incident and I really feel for them. However, this initial communication is terrible. Something happened, we won't say what, but it was severe enough to notify law enforcement. What floors me is the only actionable advice is to "review environment variables". What should a customer even do with that advice? Make sure the variable are still there? How would you know if a…

Seriously. Why am I reading about this here and not via an email? I've been a paying customer for over a year now. My online news aggregator informs me before the actual company itself does?

Says they emailed affected customers...

Re: Vercel April 2026 security incident

#328
post #235

Earlier quoted context omitted.

Via the incident page: > Environment variables marked as "sensitive" in Vercel are stored in a manner that prevents them from being read, and we currently do not have evidence that those values were accessed. However, if any of your environment variables contain secrets (API keys, tokens, database credentials, signing keys) that were not marked as sensitive, those values should be treated as potentially exposed and r…

How does the app read the variable if it can't be read after you input it? Or do they mean you can't view it after providing the variable value to the UI?

They mean the latter. Very unclear how that translates to meaningful security.

Re: Vercel April 2026 security incident

#330

Earlier quoted context omitted.

Netlify uses AWS (and Cloudflare? Vercel def uses Cloudflare)

Netlify and Vercel both use AWS. AFAIK neither uses Cloudflare. Vercel did use Cloudflare for parts of its infra until about a year ago though.

Ah, ok. I knew they did use Cloudflare but had no idea they migrated off of it.
Post reply on HN