# Security

## Featured articles

- [

    18 AugustSecurity

    ## $1 million hacker challenge for Vercel Sandbox

    Vercel is running a two-week, public HackerOne program with up to $1,000,000 in bounties for escaping a Vercel Sandbox.

    Andy RianchoPrincipal Security Engineer

    ](/blog/one-million-dollar-hacker-challenge-for-vercel-sandbox)

- [

    11 AugustSecurity

    ## Everything hackable will get hacked

    Over the past year, AI models have become much more capable of performing cybersecurity work. These changes are reshaping both the threats facing the web and the tools available to defend it. Right now, defenders have an advantage because they can use stronger models for defensive work than the open-weight models broadly available for offensive research. But this advantage will not always last. The gap will soon close. I have both good news and bad news, neither of which is yet widely understood in the community. Bad news: Near-frontier open-weight models that perform offensive security research are available today. Kimi K3 is an Opus 4.X-class model with no relevant cybersecurity safeguards. Good news: You do not need to wait for “Mythos access” or OpenAI’s cyber program to begin defensive cybersecurity work. Frontier models, with the notable exception of Fable 5, will perform defensive cybersecurity tasks today. The uncertainty around Mythos 5's release seems to have created a kind o

    Malte UblCTO, Vercel

    ](/blog/everything-hackable-will-get-hacked)

- [

    24 FebruarySecurity

    ## Security boundaries in agentic architectures

    Most agents today run generated code with full access to your secrets. As more agents adopt coding agent patterns, where they read filesystems, run shell commands, and generate code, they're becoming multi-component systems that each need a different level of trust. While most teams run all of these components in a single security context, because that's how the default tooling works, we recommend thinking about these security boundaries differently. Below we walk through: The actors in agentic systems Where security boundaries should go between them An architecture for running agent and generated code in separate contexts All agents are starting to look like coding agents More agents are adopting the coding agent architecture. These agents read and write to a filesystem. They run bash, Python, or similar programs to explore their environment. And increasingly, agents generate code to solve particular problems. Even agents that aren't marketed as "coding agents" use code generation as

    Malte Ubl, Harpreet Arora

    ](/blog/security-boundaries-in-agentic-architectures)

## Blog posts

- [

    18 AugustSecurity

    ### $1 million hacker challenge for Vercel Sandbox

- [

    11 AugustSecurity

    ### Everything hackable will get hacked

    Malte UblCTO, Vercel

- [

    27 JulySecurity

    ### DeepsecBench: evaluating model performance in finding cybersecurity vulnerabilities

    Malte Ubl, Eric Dodds

    ](/blog/deepsecbench-evaluating-model-performance-in-finding-cybersecurity-vulnerabilities)

- [

    10 MarchSecurity

    ### How we run Vercel's CDN in front of Discourse

    Jacob ParisDX Engineer

    ](/blog/how-we-run-vercels-cdn-in-front-of-discourse)

- [

    24 FebruarySecurity

    ### Security boundaries in agentic architectures

    Malte Ubl, Harpreet Arora

- [

    3 FebruarySecurity

    ### The Vercel OSS Bug Bounty program is now available

    ](/blog/the-vercel-oss-bug-bounty-program-is-now-available)

- [

    19 DecemberSecurity

    ### Our $1 million hacker challenge for React2Shell

    Malte UblCTO, Vercel

    ](/blog/our-million-dollar-hacker-challenge-for-react2shell)

- [

    24 NovemberSecurity

    ### Security through design: Creating the improved Firewall experience

    Sage Abraham, Liz Hurder, and 3 others

    ](/blog/security-through-design-creating-the-improved-firewall-experience)

- [

    29 OctoberSecurity

    ### Vercel achieves TISAX AL2 compliance to serve automotive partners

    Kacee TaylorHead of Governance, Risk & Compliance (GRC)

    ](/blog/vercel-achieves-tisax-al2-compliance-to-serve-automotive-partners)

- [

    8 SeptemberSecurity

    ### Critical npm supply chain attack response – September 8, 2025

    Aaron BrownHead of Security

    ](/blog/critical-npm-supply-chain-attack-response-september-8-2025)

- [

    13 AugustSecurity

    ### The three types of AI bot traffic and how to handle them

    Kevin CorbettSoftware Engineer

    ](/blog/the-three-types-of-ai-bot-traffic-and-how-to-handle-them)

- [

    23 MaySecurity

    ### Vercel security roundup: improved bot defenses, DoS mitigations, and insights

    Liz Hurder, Kevin Corbett

    ](/blog/vercel-security-roundup-improved-bot-defenses-dos-mitigations-and-insights)

[Show more posts](/blog/category/security/page/2)