Live data from Hacker News

Vercel April 2026 security incident

bleepingcomputer.com

51–60 of 540 posts

Re: Vercel April 2026 security incident

#51

I'm on a macbook pro, Google Chrome 147.0.7727.56. Clicking the Vercel logo at the top left of the page hard crashes my Chrome app. Like, immediate crash. What an interesting bug.

Huh, curiously; I'm on Arch Linux, crash happens in Google Chrome (147.0.7727.101) for me too, but not in Firefox (149.0.2) nor even in Chromium (147.0.7727.101).

I find it fun we're all reading a story how Vercel likely is compromised somehow, and managed to reproduce a crash on their webpage, so now we all give it a try. Surely could never backfire :)

Re: Vercel April 2026 security incident

#53
post #48

Earlier quoted context omitted.

Isn’t he a Vercel evangelist though?

He is "whatever gives me short-term boost in popularity". Including doing 180 turns on whatever he's evangelizing or bashing.

Fair enough. That’s probably a better description from what I’ve seen from him. I remember that arc browser shilling.

Re: Vercel April 2026 security incident

#54
post #4

Related: https://news.ycombinator.com/item?id=47824426 https://x.com/theo/status/2045862972342313374 > I have reason to believe this is credible. https://x.com/theo/status/2045870216555499636 > Env vars marked as sensitive are safe. Ones NOT marked as sensitive should be rolled out of precaution https://x.com/theo/status/2045871215705747965 > Everything I know about this hack suggests it could happen to any host http…

Who is this “theo” person and why are multiple people quoting him? He seems to have little to say that’s substantive at this point.

[deleted]

Re: Vercel April 2026 security incident

#55
post #36

Earlier quoted context omitted.

Your entire recent posting history is "software engineering is over, AI has won." What's your agenda here?

how many recent security breaches have we seen?

How many can unequivocally be attributed to malicious AI?

Re: Vercel April 2026 security incident

#56
post #39

Earlier quoted context omitted.

I don't watch his content, but I felt comfortable posting his link as I believe he's generally considered a reputable guy? His tweets sometimes come up in my for you tab and he seems reasonable and knowledgable generally? Maybe I'm wrong and shouldn't have linked to him as a source.

He's kind of like an LLM in that his content has the surface texture of something substantial, and sometimes it's backed by substance, yet it's often half-true or totally off the mark too. You'll notice if you're previously acquainted with what he's talking about, otherwise he seems to be as you described. I don't think he's a bad guy or that he's trying to be misleading. I suspect he wants his content to actually ca…

I agree with this comment. YouTube's summarize this video feature has been a godsend when it comes to Theo's videos.

Re: Vercel April 2026 security incident

#57
post #7

https://x.com/theo/status/2045871215705747965 - "Everything I know about this hack suggests it could happen to any host" He also suggests in another post that Linear and GitHub could also be pwned? Either way, hugops to all the SRE/DevOps out there, seems like it's going to be a busy Sunday for many.

> @theo: "I have reason to believe this is credible. If you are using Vercel, it’s a good idea to roll your secrets and env vars."

> @ErdalToprak: "And use your own vps or k3s cluster there’s no reason in 2026 to delegate your infra to a middle man except if you’re at AWS level needs"

> @theo: "This is still a stupid take"

lol, okay. Thanks for the insight, Theo, whoever you are.

Re: Vercel April 2026 security incident

#59

I'm on a macbook pro, Google Chrome 147.0.7727.56. Clicking the Vercel logo at the top left of the page hard crashes my Chrome app. Like, immediate crash. What an interesting bug.

Same with Chrome on Windows 11. I opened the vercel home page using the url once after which it stopped crashing when clicking on the logo.

Re: Vercel April 2026 security incident

#60
post #22

Earlier quoted context omitted.

I feel like humans would be better at hyper targeting. AI agents have the benefit of working at scale, probably "better" used for mass targeting.

this like is saying email marketing is done better if you hand write every email. Thats true, but the hit rate is so low, that you are better off generating 1 million hyper personalized emails and firing them off into the ether

As someone who did the former for a couple years, “better off” is subjective and dependent on your business model, particularly for B2B. It’s a trade off like anything else. You may get more leads, but they may convert at a lower rate. Sending at that scale also increases your risk of email deliverability problems. Trashing your domain has more impacts than you’d think. In smaller, targeted markets it even can damage your business reputation and hurt future sales if done poorly; word gets around.
Post reply on HN