Amy Egan Great blog post, as always! Looking forward to learning how it goes with your internal apps
Jonoroboto Don't worry Amy, it's guaranteed we'll break at least a core part of it, trying to fix security exploits 😂
Belty6979 5979 That’s a really interesting use case for Deepsec. Finding issues on a few hundred pages is already impressive, so I’d be curious to see what it uncovers when you run it against your internal apps.
system Hi there! I'm just a bot here to share some info that might help you before a human arrives. If your account is eligible, you can use our new self-service recovery flow: 1. Go to vercel.com/login 2. Choose to sign in using the email + one-time password (OTP) option. 3. Select Use another sign-in method 4. Verify your identity using the GitHub, GitLab, or Bitbucket account previously linked to your Vercel account 5. Follow the remaining prompts to complete the recovery process If you've ever set up a passkey, possibly on another device, you can use that to get back into your account and update 2FA settings yourself. You can also use recovery codes if you've stored those in a safe place that you can still access. If you are unable to access your account using the steps above, you can open a support case using the Start 2FA recovery option on the Two-Factor Authentication login screen. **Please do not publicly post account details, like your email address, that could help an attacker gain access to your account in the future.** There's no need to open an additional case if you already have one open. Thanks for your patience while the team works to resolve all cases as quickly as possible while keeping everyone’s accounts safe and secure. A human should be here soon to help.
Amy Egan Hey there! Thanks for sharing the case number and for NOT posting your email. I found your case and confirmed it's assigned to the right team. It looks like the case was opened just a few hours ago, so escalation doesn't seem to be necessary here. Someone from the support team will reply soon
system Thank you for bringing this to our attention. To ensure this is investigated with the necessary priority and privacy, please report all security-related concerns, potential exploits, or abuse directly to the Vercel Security Team. Please submit your report here: vercel.com/abuse Reporting via this official channel is the fastest way to reach our security engineers and ensures that sensitive information is handled in a secure environment rather than a public forum.
Hali New DDOS request has been sended. 1m requests sent successfully with no deny and my project get pause
Amy Egan Were the visits from verified bots? Can we see the graph?
Anshuman Bhardwaj Hi there, I see that there's an ongoing support thread about this and our Support team experts are sharing solutions there. To avoid miscommunication or duplicates I'll defer to them.
Mikelabs They closed my ticket and did not resolve the issue, then issued me a refund. It would be nice if someone from the Vercel team could actually address this.
Mikelabs This is still totally unresolved