Ashish Kunwar
22.7K posts

Ashish Kunwar
@D0rkerDevil
ex @Microsoft Security Researcher| Vulnerability Research | Threat Intel | Red Teaming | Penetration Testing | CRTP | CRTO | open to Hiring 🙂


Hey @Hacker0x01 super disappointed. Reported a critical bug on a private program: full access to 73 storage containers, (RCE) entire company's candidate PII downloadable. Triaged valid. Fixed by the team (confirmed). Then 2 months later closed as N/A "third-party SDK issue." If the key is served from your domain, leaking your users' PII, and your team fixes it how is that N/A? Filed mediation but 6–7 months is a long wait. Can someone from the team take a look? Bug is genuinely worth your time.




We’ve identified a security incident that involved unauthorized access to certain internal Vercel systems, impacting a limited subset of customers. Please see our security bulletin: vercel.com/kb/bulletin/ve…


We’ve identified a security incident that involved unauthorized access to certain internal Vercel systems, impacting a limited subset of customers. Please see our security bulletin: vercel.com/kb/bulletin/ve…




🚨 BREAKING: Vercel has been breached. A threat actor has listed their customers' data, source code, databases, and keys up for sale. Vercel has also publicly disclosed they've identified a security incident involving unauthorized access to their internal systems.







