Live data from Hacker News

Vercel April 2026 security incident

bleepingcomputer.com

531–540 of 540 posts

Re: Vercel April 2026 security incident

#531

Earlier quoted context omitted.

The answer is Yes, this can be exploited from the outside by taking over dev machines and using their access. If you answer No and complain that it’s not taken seriously, it’s at least in part because you didn’t show the risk clearly.

maybe a dumb idea , but maybe using some kind of one time token access would resolve ? some physical keycard would guarantee this to not happen at all right ?

There is always a disgruntled employee:) They will do anything to do maximum harm

Re: Vercel April 2026 security incident

#532

Earlier quoted context omitted.

Usually, companies have procedures for such events. But most do not.

Usually have procedures, but most don't? Say again

Yes, they say we have backup procedures, but have they ever tested that the backups work? They write procedures to please auditors:)

Re: Vercel April 2026 security incident

#533
post #481

Earlier quoted context omitted.

You expect the CEO of a company to have the legal depth of knowledge AND knowledge of all their customers, contracts and SLAs to be able to wing a communication and not somehow trip over all of that? They also should understand every possible legal jurisdiction that could be affected? You realise even the head of their legal department (a HIGHLY competent lawyer) likely wouldn’t say there could do that without speaki…

What use is a CEO if they can't take the lead in times like this? If they are unprepared frankly they suck as CEO and should be thrown out. If only competency was a requirement for these jobs...

Take the lead couldn't be more different than act by themselves.

Take the lead, yes they should be able to as that's the job pretty much.

Act by themselves, sure they can make decisions in small cases. But on big things you hear everybody's input, weigh it, and only if needed, cast the deciding vote.

Re: Vercel April 2026 security incident

#535
post #136

Earlier quoted context omitted.

All of this is available in Cloudflare $5 plan?

Every three months I'm trying to deploy to Cloudflare from Monorepo and I hadn't have success yet. While Vercel works every time from the box. Maybe I could dig deeper and try to understand how it works, but I'm super lazy to do that.

Same here, deploying a Next.js app just works right out of the box with Vercel.

I've had so much trouble with Cloudflare, turns out you've to configure your deploy commands to use opennextjs-cloudflare. Vercel DX is much better for sure, and Cloudflare isn't even close. (I'm not even an engineer btw, so needed some time to figure out.)

Re: Vercel April 2026 security incident

#536
post #296

Earlier quoted context omitted.

10 years ago it was Heroku and Ruby on Rails*

but now Ruby on Rails is not a circus like how Next.js is. see [0]: Rails security Audit Report [0]: https://ostif.org/ruby-on-rails-audit-complete/

Can you elaborate as to why your linked article would suggest nextjs to be a "circus"? If anything, DHH (founder of RoR) and his Looney-Tunes opinions are much closer to a circus sideshow than anything I've seen come out of Vercel.
Post reply on HN