




Denson Ngumo
253 posts

@denson_ngumo
Cloud Infrastructure Engineer, Sysadmin, Gamer and resident tech head at @AnganiLTD Opinions==my own #DevOps














Here's my update to the broader community about the ongoing incident investigation. I want to give you the rundown of the situation directly. A Vercel employee got compromised via the breach of an AI platform customer called Context.ai that he was using. The details are being fully investigated. Through a series of maneuvers that escalated from our colleague’s compromised Vercel Google Workspace account, the attacker got further access to Vercel environments. Vercel stores all customer environment variables fully encrypted at rest. We have numerous defense-in-depth mechanisms to protect core systems and customer data. We do have a capability however to designate environment variables as “non-sensitive”. Unfortunately, the attacker got further access through their enumeration. We believe the attacking group to be highly sophisticated and, I strongly suspect, significantly accelerated by AI. They moved with surprising velocity and in-depth understanding of Vercel. At the moment, we believe the number of customers with security impact to be quite limited. We’ve reached out with utmost priority to the ones we have concerns about. All of our focus right now is on investigation, communication to customers, enhancement of security measures, and sanitization of our environments. We’ve deployed extensive protection measures and monitoring. We’ve analyzed our supply chain, ensuring Next.js, Turbopack, and our many open source projects remain safe for our community. The recommendation for all Vercel customers is to follow the Security Bulletin closely (vercel.com/kb/bulletin/ve…). My advice to everyone is to follow the best practices of security response: secret rotation, monitoring access to your Vercel environments and linked services, and ensuring the proper use of the sensitive env variables feature. In response to this, and to aid in the improvement of all of our customers’ security postures, we’ve already rolled out new capabilities in the dashboard, including an overview page of environment variables, and a better user interface for sensitive env var creation and management. As always, I’m totally open to your feedback. We’re working with elite cybersecurity firms, industry peers, and law enforcement. We’ve reached out to Context to assist in understanding the full scale of the incident, in an effort to protect other organizations and the broader internet. I also want to thank the Google Mandiant team for their active engagement and assistance. It’s my mission to turn this attack into the most formidable security response imaginable. It’s always been a top priority for me. Vercel employs some of the most dedicated security researchers and security-minded engineers in the world. I commit to keeping you updated and rolling out extensive improvements and defenses so you, our customers and community, can have the peace of mind that Vercel always has your back.





Today, Micron shared some news that comes with a heavy heart: we’ve made the difficult decision to wind down the Crucial consumer business. This means that sales of Crucial-branded products through retailers, e-tailers, and distributors worldwide will gradually come to an end. For nearly three decades, Crucial has been more than just a brand - it’s been a trusted companion for millions of people building, upgrading, and creating. Thanks to an incredible community of passionate customers, dedicated partners, and talented Micron team members, Crucial became synonymous with innovation, quality, and reliability in memory and storage. We are deeply grateful for the support and loyalty that made this journey possible. Some things to note as we wind down: Crucial consumer products will continue to ship through the end of February 2026, and we’ll work closely with our partners and customers to ensure a smooth transition. Warranty service and support will remain available for all Crucial products. While this chapter is closing, Micron will continue to serve commercial customers globally with Micron-branded enterprise products. Thank you - for 29 amazing years of trust, collaboration, and shared success. Crucial wouldn’t have been what it was without you. Read more here: investors.micron.com/news-releases/…

🐙 Ceph Tentacle (v20.2.0) is out! The 20th stable #Ceph release brings updates to #CephFS, #RADOS, #RBD, #RGW, and #Dashboard, along with an expanded #SeaStore tech preview. Community feedback is encouraged. Read more here: t.ly/CephTentacle20… #CephTentacle #OpenSource

We’re excited to welcome Prof. Adewale Adedokun as Chairman of the Board and Prof. Aziz Hilali as Vice-Chairman. We invite the community to give them their full support. We invite the community to give them their full support. Read more here>> bit.ly/AFRINICBoard-A…


