Výsledky hledání

výrobce: Vercel× v celém archivu zrušit filtry

5 karet z 6 položek CZ · EN/orig

2

31th August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 31st August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Manchester Airports Group, the UK operator of Manchester, London Stansted, and East Midlands airports, has disclosed a cyberattack that exposed data belonging to about 8.7 million customers. The compromised information includes contact details, vehicle registration numbers, and information collected through car park, lounge, fast-track, and Wi-Fi…

KEV ✓ EPSS 0.04 CVSS 10.0 CVE-2026-18885 CVE-2026-18886 CVE-2026-74820 CVE-2026-75604 CVE-2026-81578 CVE-2026-82078 PaperCut Ubiquiti Vercel ServiceNow IL

tg: incident tg: zneužíváno tg: zranitelnost tg: přehled tp: phishing tp: únik dat tp: AI

· Check Point Research · 31th August – Threat Intelligence Report

SPOJENO PŘES CVE Next.js: disponibili PoC per 2 vulnerabilità

Disponibili Proof of Concept (PoC) per lo sfruttamento di 2 vulnerabilità, già sanate dal vendor, che interessano Next.js, noto framework javascript per la creazione di applicazioni web.

EPSS 0.02 CVSS 9.0 CVE-2026-75604 Next.js Vercel IT FI RO NL

tg: zneužíváno

· CSIRT Itálie (ACN) · Next.js: disponibili PoC per 2 vulnerabilità · NCSC-FI · August 2026 Security Release for Next.js · DNSC Rumunsko · ALERTĂ: Vulnerabilități critice la nivelul NextJS · NCSC-NL · NCSC-2026-0329 [1.00] [H/M] Kwetsbaarheden verholpen in Next.js

1

How legitimate cloud platforms enable phishers to bypass MFA

Threat actors are increasingly exploiting legitimate cloud services to evade detection and streamline the deployment of their scam infrastructure. Cloud hosting services and decentralized networks have become primary platforms for hosting phishing pages and sites. Throughout 2025 and 2026, we have observed phishing operators steadily migrate toward platforms like Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS. This post analyzes the mechanics of a real-life adversary-in-the-middle …

Cloudflare Vercel Netlify GitHub RU

· Securelist (Kaspersky) · How legitimate cloud platforms enable phishers to bypass MFA

2

The Vercel Breach: OAuth Supply Chain Attack Exposes the Hidden Risk in Platform Environment Variables

An OAuth supply chain compromise at Vercel exposed how trusted third party apps and platform environment variables can bypass traditional defenses and amplify blast radius. This article examines the attack chain, underlying design tradeoffs, and what it reveals about modern PaaS and software supply chain risk.

Vercel JP

· Trend Micro · The Vercel Breach: OAuth Supply Chain Attack Exposes the Hidden Risk in Platform Environment Variables