Live data from Hacker News

Vercel April 2026 security incident

bleepingcomputer.com

41–50 of 540 posts

Re: Vercel April 2026 security incident

#41
post #11

Oy vey: https://x.com/theo/status/2045862972342313374?s=46

He doesn't work at Vercel but he is the type to never pass up any opportunity to chase clout.

Almost like that’s his job.

Hey, I’m with you - I think social media needs to die specifically for this reason. I’m reminded of the term “snake oil” - it’s like the dawn of newspapers again.

Re: Vercel April 2026 security incident

#42

Much as I want to rip on vercel, its clear that ai is going to lead to mass security breaches. The attack surface is so large, and ai agents are working around the clock. This is a new normal. Open source software is going to change, companies wont be running random repos off github anymore

Slop coding and makeshift sites being thrown up with abandon at breakneck speeds is going to buy me a lot of minivans.

Re: Vercel April 2026 security incident

#43
post #36

Much as I want to rip on vercel, its clear that ai is going to lead to mass security breaches. The attack surface is so large, and ai agents are working around the clock. This is a new normal. Open source software is going to change, companies wont be running random repos off github anymore

Your entire recent posting history is "software engineering is over, AI has won." What's your agenda here?

Paid by a Sama minion, I bet.

Re: Vercel April 2026 security incident

#44

I'm on a macbook pro, Google Chrome 147.0.7727.56. Clicking the Vercel logo at the top left of the page hard crashes my Chrome app. Like, immediate crash. What an interesting bug.

Do you have a chrome://crashes/ entry ?

it did add an entry - windows 11, chrome

Re: Vercel April 2026 security incident

#45
post #9

There is no serious reason to use Vercel, other than for those being locked into the NextJs ecosystem and demo projects.

I recently got hit by a car on my bike. While I was starting the claim filing process the web portal for ICBC (British Columbia insurance) was acting a little funky / stalling / and then gave me a weird access error. Down at the bottom of the error page was a little grey underlined link that said “vercel”.

I’m not exactly surprised, but it seems like the unserious, ill-informed and lazy are taking over. There is absolutely zero reason why a large, essential public service should be overspending and running on an unnecessary managed service like vercel… yet, here we are.

Re: Vercel April 2026 security incident

#46
post #36

Much as I want to rip on vercel, its clear that ai is going to lead to mass security breaches. The attack surface is so large, and ai agents are working around the clock. This is a new normal. Open source software is going to change, companies wont be running random repos off github anymore

Your entire recent posting history is "software engineering is over, AI has won." What's your agenda here?

how many recent security breaches have we seen?

Re: Vercel April 2026 security incident

#47
post #39

Earlier quoted context omitted.

Ah, Theo with his vast insights and connections into everything. That man gets around, and his content is worth it's cost. Theo's content boils down to the same boring formula. 1. Whatever buzzword headline is trending at the time 2. Immediate sponsored ad that is supposed to make you sympathize with Theo cause he "vets" his sponsors. 3. The man makes you listen to a "that totally happened" story that he somehow alwa…

I don't watch his content, but I felt comfortable posting his link as I believe he's generally considered a reputable guy? His tweets sometimes come up in my for you tab and he seems reasonable and knowledgable generally? Maybe I'm wrong and shouldn't have linked to him as a source.

He's kind of like an LLM in that his content has the surface texture of something substantial, and sometimes it's backed by substance, yet it's often half-true or totally off the mark too. You'll notice if you're previously acquainted with what he's talking about, otherwise he seems to be as you described.

I don't think he's a bad guy or that he's trying to be misleading. I suspect he wants his content to actually carry value, but he produces too much for that to be possible. Primarily he's a performer, not a technologist.

Re: Vercel April 2026 security incident

#48
post #15

Earlier quoted context omitted.

from his "sources". > Here’s what I’ve managed to get from my sources: >3. The method of compromise was likely used to hit multiple companies other than Vercel. https://x.com/theo/status/2045870216555499636 To be fair journalists often do this too, eg. "[company] was breached, people within the company claim"

Isn’t he a Vercel evangelist though?

He is "whatever gives me short-term boost in popularity". Including doing 180 turns on whatever he's evangelizing or bashing.

Re: Vercel April 2026 security incident

#50
post #39

Earlier quoted context omitted.

Ah, Theo with his vast insights and connections into everything. That man gets around, and his content is worth it's cost. Theo's content boils down to the same boring formula. 1. Whatever buzzword headline is trending at the time 2. Immediate sponsored ad that is supposed to make you sympathize with Theo cause he "vets" his sponsors. 3. The man makes you listen to a "that totally happened" story that he somehow alwa…

I don't watch his content, but I felt comfortable posting his link as I believe he's generally considered a reputable guy? His tweets sometimes come up in my for you tab and he seems reasonable and knowledgable generally? Maybe I'm wrong and shouldn't have linked to him as a source.

Nothing on x.com is reputable at this point.
Post reply on HN