Aise hui Vercel ki band:
Yeh jo incident hua hai na, Vercel ke core code pe direct attack nahi tha. Scene hua yeh ki unke ek employee ne jo AI tool use kiya tha (Context.ai naam hai uska), woh hack ho gaya. Attackers ne Google Workspace ke OAuth mein ek gadbad ka fayda uthaya aur Vercel ke internal systems mein ghus gaye. Yeh dikhata hai ki aajkal AI tools use karne mein kitna risk hai, especially jab sab ek dusre se jude hue hain. Vercel toh Next.js framework chalaata hai jise lakho log use karte hain, toh sabke liye yeh bada warning hai.
Kya kya data leak hua?
Vercel toh khud $9.3 billion valuation wali company hai, jisne pichle September $300 million ki funding li thi. Aur June 2025 tak $200 million ka revenue kama rahi thi. Unka kehna hai ki jo 'sensitive' nahi mark kiya tha woh environment variables unke system se access ho gaye. Isme API keys, database credentials jaise secrets ho sakte hain jo Web3 applications ko power karte hain. Chainlink jaise bade players bhi ab apni API keys jaldi se change kar rahe hain.
AI ka speed aur naye risks:
Vercel CEO Guillermo Rauch ne kaha ki yeh attack AI ki wajah se bahut fast tha. Jabki Vercel cloud market mein AWS, Cloudflare jaise bade players se compete kar raha hai aur uske paas frontend deployment market ka 22% share hai (2025 tak), yeh incident trust ko damage kar sakta hai. Cybercrime forums par $2 million mein Vercel data bechne ka bhi daawa kiya ja raha hai.
Future mein kya dhyan rakhna hai:
Yeh Vercel wala incident sirf ek data breach nahi hai. Yeh dikhata hai ki kaise cloud services aur third-party AI tools milkar naye tarah ke supply chain attacks ko invite kar rahe hain. Ab sirf code check karna kaafi nahi, har use kiye gaye tool, especially AI wale tools ki security ko bhi check karna padega. Vercel ne 'sensitive' data flag karne ka option diya tha, par shayad default security settings mein kuch kami reh gayi. Agar sach mein sensitive tokens access hue hain toh nuksaan bada ho sakta hai.
