Gate News message, April 23 — Vercel CEO Guillermo Rauch announced that the company has completed an in-depth security investigation analyzing nearly 1 petabyte of complete network and API logs, significantly expanding the scope beyond the initial Context.ai account compromise.
The investigation revealed that the attacker’s activity extends well beyond Context.ai and has distributed malware across a broader range of targets, aiming to steal account credentials for Vercel and other platforms. Once attackers obtain credentials, they quickly and comprehensively enumerate non-sensitive environment variables.
Vercel is deepening collaboration with industry partners including Microsoft, AWS, and Wiz to protect the broader internet ecosystem. The company has also notified other suspected victims, recommending immediate credential rotation and strengthened security best practices.