Crime App host Vercel says it was hacked and customer data stolen - shinyhunters are selling it for 2million dollars apparently.

link - archive

Cloud app hosting giant Vercel this weekend said hackers had breached its internal systems and accessed customer data. Hackers have claimed they have stolen sensitive customer credentials from Vercel’s systems and are selling the data online.

In a statement on Sunday, Vercel said the breach originated from another software maker, Context AI. One of Vercel’s employees downloaded an app made by Context AI and connected it to their corporate account, which is hosted by Google. The hackers used that connection (known as OAuth) to take over the Vercel employee’s Google account and gain access to some of Vercel’s internal systems, including credentials that were not encrypted.

Vercel says its Next.js and Turbopack projects were not affected by the breach. Both open source projects are widely used by web and app developers.

Vercel said it has contacted customers whose app data and keys were compromised.

In a post on X, Vercel chief executive Guillermo Rauch advised customers to rotate any keys and credentials in their app deployments that are marked as “non-sensitive.”

It’s not clear who is behind the breach at Vercel or Context AI, or if they are the same hacker. The threat actor selling the data claimed to be representing the ShinyHunters hacking group in their listing on a cybercriminal forum. The post, seen by TechCrunch, claimed the hackers were selling access to customer API keys, source code, and database data stolen from Vercel.

The ShinyHunters hacker group, known for breaching cloud-based and database companies, told cybersecurity news site Bleeping Computer that they are not involved in this incident.

A spokesperson for Vercel did not say how many customers could be affected, but said that the company has not received any communication from the threat actor, such as a demand for ransom.

While details of the hack are still emerging, this security breach is the latest in a string of “supply chain” hacks in recent months that have targeted software developers whose code is widely used across the web. By compromising software that’s widely used by companies and supports web infrastructure, hackers can steal credentials from a broad range of targets at once and gain further access to large amounts of data stored by other cloud giants.

Vercel said little else about the attack, except that it was investigating the incident and had sought answers from Context AI. Vercel said the hack may affect “hundreds of users across many organizations,” and not just its own system, warning of potential downstream breaches spanning the tech industry.

Context AI, which builds evaluations and analytics for AI models, confirmed on its website that it had a breach in March involving its Context AI Office Suite consumer app. The app allows users to automate actions and workflows across multiple third-party applications by way of an unnamed third-party service.

Context AI said it notified one customer of the breach, but based on Vercel’s incident, it now believes that the incident is likely broader than first thought. Context AI said the hackers “likely compromised OAuth tokens for some of our consumer users.”

Context AI did not respond to a request for comment or questions about the breach. It’s unclear why Context AI did not disclose the breach at the time, or if the company received any demands from the hacker, such as a ransom.

Corrected to remove a reference to an unrelated Context AI whose staff were acquired by OpenAI. Updated with comment from Vercel.
 
also less notable but lovable also got breached. lol, lmao


pic of shinyhunters post on breachforums: (allegedly)

1776713959551.png
 
Última edición:
"The current market needs applications that are deployed FAST", they said
"You are too slow! We don't have time to setup a proper server in AWS! Use Vercel!", they said
"We need this huge project done NOW NOW NOW NOW NOW"


These massive data breaches are happening every month now, and all my co-workers are fucking jeets
1496386441181.gif
Being a software developer is suffering
AGI when? I want to niggermaxx and live off welfare
 
Última edición:
"The current market needs applications that are deployed FAST", they said
"You are too slow! We don't have time to setup a proper server in AWS! Use Vercel!", they said
"We need this huge project done NOW NOW NOW NOW NOW"


Massive data breaches are happening every month now, and all my co-workers are fucking jeets
Ver archivo adjunto 8888442
Being a software developer is suffering
AGI when? I want to niggermaxx and live off welfare
jugaad yourself free time and work on your own stuff, like switch to openbsd and xlibre

I don't know. I think replacing "your own server" with "private cloud" might be even more impressive.
some genius named a shitty chinese NAS "GNUbee Personal Cloud"

As for OP, SUFFAH JEETSCRIPT WEBSHITTERS
 
I don't know. I think replacing "your own server" with "private cloud" might be even more impressive.
I get it, but this actually kind of had a meaning. Basically 'we replicated all those AWS APIs to spin up your bullshit VMs locally, now you don't have any excuse to give all that money to Bezos'.
 
Good. You use "the cloud" you get what you fuckin' deserve.
The concern is more downstream normies who don't know they are using the cloud. Because some critical app in their lives, such as the one that their doctors and local hospital system uses, is now compromised because some part of that code or functionality ties back to one of these godawful programs.
 
The concern is more downstream normies who don't know they are using the cloud. Because some critical app in their lives, such as the one that their doctors and local hospital system uses, is now compromised because some part of that code or functionality ties back to one of these godawful programs.
Brother, I have bad news for you. That ship sailed a long time ago. Where I am doctors are required to connect to the electronic health system. The only "opt-out" I have is telling them not to share my health info; there's no way for me to have them not collect it. I've received several notices about data breaches that affect me and short of forgoing medical care entirely there is literally nothing I can do to prevent future ones. So in this sense I am a normie.

My point is the normies are already lost, Having "concern" for them is a foolish waste of time or an outright distraction from the real problem unless you seriously believe these cloud services can be made secure in the face of all evidence to the contrary. Frankly anyone at this point that thinks these cloud services could be secure is either malicious or a useful idiot. And the basic truism of "don't put all your eggs in one basket" that everyone knows makes the useful idiot argument pretty hard to swallow.

I would even go so far as to say a "cloud" for the government is a strategic vulnerability that could be induced by a foreign power. However I'm more than willing to believe the government is retarded and self defeating.

[fedposting]
 
Didn't BF go down for good after IntelBroker got arrested? What is this new site?
This is Darkforums.su
Browse with caution as these sites log your IPs.

2 Million dollars for a Vercel leak? He must've failed at blackmailing the company and it's still seeking compensation for it. This shit ain't worth 2 million dollars, what a loser!
 
Atrás
Top Abajo