惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Cisco Talos Blog
Cisco Talos Blog
量子位
小众软件
小众软件
Microsoft Azure Blog
Microsoft Azure Blog
V
Visual Studio Blog
I
InfoQ
Jina AI
Jina AI
The Cloudflare Blog
Recorded Future
Recorded Future
Recent Announcements
Recent Announcements
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
G
Google Developers Blog
Stack Overflow Blog
Stack Overflow Blog
阮一峰的网络日志
阮一峰的网络日志
Microsoft Security Blog
Microsoft Security Blog
美团技术团队
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Martin Fowler
Martin Fowler
T
Tailwind CSS Blog
博客园 - Franky
酷 壳 – CoolShell
酷 壳 – CoolShell
F
Fortinet All Blogs
WordPress大学
WordPress大学
P
Proofpoint News Feed
D
DataBreaches.Net
爱范儿
爱范儿
雷峰网
雷峰网
D
Docker
B
Blog
Engineering at Meta
Engineering at Meta
腾讯CDC
N
Netflix TechBlog - Medium
C
Check Point Blog
博客园 - 【当耐特】
Apple Machine Learning Research
Apple Machine Learning Research
T
Tenable Blog
GbyAI
GbyAI
Security Archives - TechRepublic
Security Archives - TechRepublic
博客园 - 三生石上(FineUI控件)
T
The Blog of Author Tim Ferriss
博客园 - 聂微东
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
SecWiki News
SecWiki News
S
Security @ Cisco Blogs
S
Security Affairs
V
V2EX
Application and Cybersecurity Blog
Application and Cybersecurity Blog
云风的 BLOG
云风的 BLOG
C
CERT Recently Published Vulnerability Notes
Y
Y Combinator Blog

Vercel News

Vercel Open Source Program: Winter 2026 cohort How Notion Workers run untrusted code at scale with Vercel Sandbox How we run Vercel's CDN in front of Discourse From idea to secure checkout in minutes with Stripe Building Slack agents can be easy Scaling redirects to infinity on Vercel Advancing Python typing Gamma builds design-first agents with Vercel How Avalara turns pipe dreams into patent-pending with v0 Keeping community human while scaling with agents How OpenEvidence built a healthcare AI that physicians actually trust Security boundaries in agentic architectures Skills Night: 69,000+ ways agents are getting smarter Video Generation with AI Gateway We Ralph Wiggumed WebStreams to make them 10x faster How Stably ships AI testing agents in hours, not weeks How we built AEO tracking for coding agents Anyone can build agents, but it takes a platform to run them Introducing Geist Pixel The Vercel AI Accelerator is back with $6m in credits Making agent-friendly pages with content negotiation The Vercel OSS Bug Bounty program is now available Introducing the new v0 Run untrusted code with Vercel Sandbox, now generally available How Stripe built a game-changing app in a single flight with v0 How Sensay went from zero to product in six weeks AGENTS.md outperforms skills in our agent evals Agent skills explained: An FAQ Testing if "bash is all you need" AWS databases are now live on the Vercel Marketplace and v0 Use Perplexity Web Search with Vercel AI Gateway Introducing: React Best Practices Nick Bogaty joins Vercel as Chief Revenue Officer How Mux shipped durable video workflows with their @mux/ai SDK How to build agents with filesystems and bash How we made v0 an effective coding agent Stopping the slow death of internal tools Building AI-Generated Pixel Trading Cards with Vercel AI Gateway We removed 80% of our agent’s tools AI SDK 6 Our $1 million hacker challenge for React2Shell Cline now runs on Vercel AI Gateway How to prompt v0 Build smarter workflows with Notion and v0 Vercel launches partner certification Inside Workflow DevKit: How framework integrations work React2Shell Security Bulletin | Vercel Knowledge Base Billions of requests: Black Friday-Cyber Monday 2025 Investing in the Python ecosystem AWS Databases coming to the Vercel Marketplace How we built the v0 iOS app Workflow Builder: Build your own workflow automation platform Vercel Open Source Program: Fall 2025 cohort Self-driving infrastructure Vercel collaborates with Google for Gemini 3 Pro Preview launch Vercel: The anti-vendor-lock-in cloud How Nous Research used BotID to block automated abuse at scale How AI Gateway runs on Fluid compute What we learned building agents at Vercel Build and deploy data applications on Snowflake with v0 BotID Deep Analysis catches a sophisticated bot network in real-time Vercel achieves TISAX AL2 compliance to serve automotive partners Bun runtime on Vercel Functions David Totten Joins Vercel to Lead Global Field Engineering Vercel Ship AI 2025 recap You can just ship agents AI agents and services on the Vercel Marketplace Built-in durability: Introducing Workflow Development Kit Zero-config backends on Vercel AI Cloud Introducing Vercel Agent: Your new Vercel teammate Update regarding Vercel service disruption on October 20, 2025 Agents at work, a partnership with Salesforce and Slack Running Next.js in ChatGPT: How to Build ChatGPT Apps Talha Tariq joins Vercel as CTO of Security Just another (Black) Friday Server rendering benchmarks: Fluid Compute and Cloudflare Workers Towards the AI Cloud: Our Series F Collaborating with Anthropic on Claude Sonnet 4.5 to power intelligent coding agents Preventing the stampede: Request collapsing in the Vercel CDN BotID uncovers hidden SEO poisoning How we made global routing faster with Bloom filters What you need to know about vibe coding Scale to one: How Fluid solves cold starts Addressing security & quality issues with MCP tools - Vercel AI agents at scale: Rox’s Vercel-powered revenue operating system Agentic Infrastructure Zero Data Retention on AI Gateway Optimizing Vercel Sandbox snapshots How Waldium made a blog platform work for humans and AI alike How FLORA shipped a creative agent on Vercel's AI stack Agent responsibly Making Turborepo 96% faster with agents, sandboxes, and humans Unified reporting for all AI Gateway usage new.website joins forces with v0 SERHANT.'s playbook for rapid AI iteration Two startups at global scale without DevOps Chat SDK brings agents to your users 360 billion tokens, 3 million customers, 6 engineers Meet the 2026 Vercel AI Accelerator Cohort Build knowledge agents without embeddings
Vercel security roundup: improved bot defenses, DoS mitigations, and insights - Vercel – Vercel
2025-05-23 · via Vercel News

4 min read

Billions of attacks blocked while cutting response time and expanding control

Since February, Vercel blocked 148 billion malicious requests from 108 million unique IP addresses. Every deployment automatically inherits these protections, keeping your workloads secure by default and enabling your team to focus on shipping rather than incidents.
Our real-time DDoS filtering, managed Web Application Firewall (WAF), and enhanced visibility ensure consistent, proactive security.

Here's what's new since February.

Link to headingWAF performance insights

Since our last update, Vercel WAF mitigated over 148 billion malicious requests, a 70% increase quarter-over-quarter. These requests originated from over 108 million unique IP addresses, a staggering 468% increase that signals a sharp rise in distributed activity.

The largest volumes of malicious traffic originated from:

  • United States: 55 billion

  • Ireland: 29 billion

  • Singapore: 7 billion

  • Hong Kong: 5 billion

  • Germany: 3 billion

This quarter's insights highlight shifting global threat trends, with notable increases in malicious activity emerging in new geographies. At the same time, other regions like Australia (previously among the top sources of malicious traffic) dropped out of the top five.

Attack volumes and unique IPs have grown dramatically. This reinforces the importance of automatic global protections with Vercel to ensure your deployments remain secure by default.

Link to headingKey security enhancements

Link to headingAdvanced bot protection

Our new Bot Filter entered public beta, free for all users on all plans. Bot Filter is a managed WAF ruleset that you can activate with one click, immediately challenging non-browser bot traffic without disrupting critical automations such as verified webhook providers (Googlebot, Stripe, PayPal) and internal cron jobs.

You can preview which requests Bot Filter would block using log-only mode, improving performance by ensuring your application resources remain available for legitimate users. If you have feedback on this beta feature, leave a comment in the Vercel Community.

Link to headingFaster denial-of-service mitigation

We introduced Protectd, a powerful update to our denial-of-service (DoS) mitigation infrastructure. Protectd analyzes roughly 550,000 events per second globally, significantly accelerating our ability to mitigate Layer 7 attacks.

The result is a median mitigation time of just 2.5 seconds and a P99 of around 3.5 seconds, blocking sophisticated attacks that traditional CDNs often miss. Protectd operates transparently and immediately benefits all deployments without any configuration required.

Link to headingComprehensive SDLC security guidance

Our new Secure every step of a modern SDLC whitepaper, is a comprehensive resource that clearly outlines how Vercel's built-in security features apply to every phase of software development, from planning and coding to deployment and monitoring. This whitepaper aims to simplify compliance discussions and helps streamline secure application development.

Read the Secure SDLC whitepaper

Building, deploying, and operating secure applications on Vercel.

Read now

Link to headingProactive vulnerability management and account security

In recent months, Vercel proactively hardened our platform against high-severity vulnerabilities in open-source frameworks, ensuring that customer applications remained secure without requiring manual intervention. We still recommend updating to the latest patched versions of the affected packages and frameworks.

  • React Router and Remix vulnerabilities CVE-2025-43864 and CVE-2025-43865: Vercel proactively deployed mitigation to the Vercel Firewall, and purged any potentially impacted caches, to protect customers against CVEs that can lead to cache poisoning denial of service and stored cross-site scripting attacks

  • React Router vulnerability CVE-2025-31137: Our platform architecture prevented exposure to this CVE that allows URL manipulation

  • SAMLStorm CVE-2025-29774 and CVE-2025-29775: We deployed a security update to the Vercel Firewall that mitigated this SAML authentication bypass risk

  • Next.js middleware vulnerabilities CVE-2025-29927 and CVE-2025-30218: While Vercel was not affected by CVE-2025-29927, during our analysis we identified a low serverity issue, CVE-2025-30218, at the edge, which we patched and disclosed early to our infrastructure provider partners

  • Multi-Factor Authentication (MFA): Strengthen your account security by adding a second factor using TOTP apps like Google Authenticator or Authy alongside existing Passkeys

Link to headingFirewall usability improvements

We’ve rolled out several Firewall updates to give teams more flexibility and control over rule creation, finer control during active threats, and deeper visibility into malicious or unexpected traffic patterns.

Verified bots and cron jobs now bypass Attack Challenge Mode, ensuring core services like payments and analytics aren’t interrupted during security incidents. Custom Firewall rules now support the logical OR operator, reducing configuration complexity, especially in use cases where multiple conditions must be grouped more flexibly.

System bypass rules have also been expanded, allowing you to apply them to preview domains with increased limits, offering greater flexibility for deployment using external proxies. Finally, the Firewall dashboard now includes IP enrichment. Hover over any IP address to see ASN, location, and other metadata. This gives teams faster insight and more control when investigating traffic.

Link to headingOnline session: Protecting your traffic with the Vercel Firewall

We hosted an online session, Protecting your traffic with the Vercel Firewall. Watch the recording to learn practical guidance on DDoS and bot protection strategies, effective traffic control and threat mitigation techniques, and previews into the product roadmap.

Link to headingLooking ahead

At this year’s RSA Conference, we sat down with security teams to talk through what’s shaping web security in 2025. Conversations focused on securing the software supply chain, applying AI-driven automation inside security teams (not just in business processes) and ensuring that emerging practices such as vibe coding are built with security in mind from the start.

These conversations continue to shape our ongoing work across the Vercel platform and in tools like v0 to ensure every deployment is secure by default.

Link to headingUpcoming events

We’re continuing these conversations at Vercel Ship on June 25th. Join us in New York City or steam online for live demos, technical discussions, and insights from customers who rely on Vercel to secure their applications.

Link to headingOpen roles

We're also expanding our team to continue enhancing the security and availability of your applications. If you're passionate about secure web infrastructure, explore our current open roles:

Learn about security that scales with you

The Vercel Firewall delivers multi-layer protection against application-layer attacks, DDoS threats, and bots. Visit our security page to sign up for a demo or add firewall rules today

Learn more