Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE
Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both enabling unauthenticated remote code execution (RCE). The…
Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both enabling unauthenticated remote code execution (RCE). The…
Security researchers have uncovered a class of vulnerabilities in agent infrastructure from Amazon Web Services (AWS), Google, and Vercel that allow attackers…
Vercel released security patches for two critical Next.js vulnerabilities enabling unauthenticated RCE. The company moved its monthly security release forward by one…
The Vercel AI SDK harness packages for Codex and OpenCode had authorization bypass vulnerabilities, fixed in versions 1.0.29 and 1.0.28 respectively.
Cybersecurity researchers have uncovered a sophisticated software supply chain attack dubbed 'SleeperGem' targeting the Ruby ecosystem. Three malicious gems were published to…
Vercel is a cloud platform for static sites and serverless functions. The SleeperGem malware checks for Vercel environment variables to avoid running…