Hacker Active Well Beyond Context.ai Compromise, Says Vercel CEO

Also read: Vercel Incident Linked to AI Tool Hack, Internal Access Gained
Vercel Finds Customers Breached in Separate Malware, Social Engineering Attacks
In an official update, the company also stated that initially it identified a limited subset of customers whose non-sensitive environment variables stored on Vercel were compromised. However, a deeper assessment of the their network, as well as environment variable read events in the company's logs uncovered two additional findings."First, we have identified a small number of additional accounts that were compromised as part of this incident," the company noted.
But the main concern is the next finding: "Second, we have uncovered a small number of customer accounts with evidence of prior compromise that is independent of and predates this incident, potentially as a result of social engineering, malware, or other methods."
The company did not disclose who were the attackers, what was the motive, or the impact on customers, and is yet to respond to these queries from The Cyber Express. It only stated: "In both cases, we have notified the affected customers."
Meanwhile, Rauch said, Vercel had notified other suspected victims and encouraged them to rotate credentials and adopt best practices.