Vercel's CEO, Guillermo Rauch, announced that the team has completed a comprehensive security investigation, analyzing over 1 petabyte of Vercel network and API logs. According to Foresight News, this investigation extends beyond the initial Context.ai account breach.
The findings reveal that the attackers' activities surpassed Context.ai, distributing malware more broadly with the aim of stealing account keys from platforms like Vercel. Once the keys are obtained, attackers swiftly enumerate non-sensitive environment variables.
In response, Vercel has intensified collaboration with industry partners such as Microsoft, AWS, and Wiz to safeguard the broader internet ecosystem. Other potential victims have been notified, with recommendations to immediately rotate credentials and enhance security best practices.