Frontend cloud platform Vercel, the creator of Next.js and Turbo.js, has warned about a data breach after a compromised third-party AI application abused OAuth to access its internal systems.
A Vercel employee used the third-party app, identified as Context.ai, which allowed the attackers to take over their Google Workspace account and access some environment variables that the company said were not marked as “sensitive.”
“Environment variables marked as ‘sensitive’ in Vercel are stored in a manner that prevents them from being read, and we currently do not have evidence that those values were accessed,” Vercel said in a security post.
The incident compromised what the company described as a “limited subset” of customers whose Vercel credentials were exposed. These customers have now been reached out to with requests to rotate their credentials, Vercel said.
According to reports surfacing on the internet, a threat actor claiming to be the Shinyhunters began attempting to sell the stole
The breach highlights vulnerabilities in Apple's supply chain diversification strategy, potentially impacting investor confidence and competitive positioning.
The post Apple investigates exposure to Tata Electronics data breach appeared first on Crypto Briefing.
The rapid integration of GLM-5.2 by Vercel signals a shift towards open-source AI models, challenging the dominance of closed systems.
The post Vercel CEO impressed by Z.AI’s GLM-5.2 coding capabilities appeared first on Crypto Briefing.
Two healthcare firms are preparing to pay $3.3 million to settle a class action lawsuit over a ransomware attack that allegedly exposed the personal and medical data of hundreds of thousands of people. According to the official settlement website, Mt. Baker Imaging and Northwest Radiologists agreed to settle claims tied to a data security incident […]
The post Up to $5,000 Per Person Incoming After Healthcare Firms Accused of Exposing 340,184 Americans in Data Breach appeared first on The Daily Hodl.
Vercel has open-sourced eve, an Apache-2.0 agent framework now in public preview. An agent is a directory of files, with durable execution, sandboxes, approvals, connections, channels, and evals built in. Scaffold with npx eve@latest init and deploy unchanged via vercel deploy.
The post Vercel Releases Eve: An Open-Source AI Agent Framework Where Each Agent is a Directory of Files Mapped to Capabilities appeared first on MarkTechPost.
A New York City-based insurance firm is setting aside millions of dollars to compensate victims of a data breach that occurred more than one and a half years ago. According to the settlement website, insurance company Lemonade Inc has agreed to set up a $10.5 million fund to compensate victims of a data breach that exposed […]
The post New York Firm Handing Out Up To $10,000 Per Person in Settlement Over Data Breach That Exposed Personal Information appeared first on The Daily Hodl.
A California healthcare firm is preparing to pay more than $1.5 million to settle a class action lawsuit over a cyberattack that allegedly exposed patient data. According to the official settlement website, Deanco Healthcare, doing business as Mission Community Hospital, has agreed to establish a $1.5 million settlement fund tied to a May 1, 2023 […]
The post California Healthcare Firm Sending Up To $5,100 Per Person Over Data Breach Affecting 269,547 Americans appeared first on The Daily Hodl.
Grok Build's in-terminal marketplace bundles skills, agents, hooks, and MCP servers, with commit-SHA verification on every remote plugin.
The post xAI Ships Grok Build Plugin Marketplace With MongoDB, Vercel, Sentry, Chrome DevTools, Cloudflare, and Superpowers Plugins at Launch appeared first on MarkTechPost.
The record fine against Coupang underscores the growing regulatory focus on data protection, emphasizing the need for robust internal security measures.
The post Coupang fined a record $409 million over massive data breach affecting 33 million users appeared first on Crypto Briefing.