2026-05-07 12:40 UTC
Researchers at security firm RedAccess found more than 5,000 vibe-coded apps, created with AI tools from Lovable, Replit, Base44 and Netlify, with essentially no security, accessible on the open web. About 40% exposed sensitive personal or corporate data. https://www.wired.com/story/thousands-of-vibe-coded-apps-expose-corporate-and-personal-data-on-the-open-web/
Replies (5)
-
@chaz6@ipv6.social 2026-05-07 12:49
@agreenberg@infosec.exchange if you keep an eye on certificate trust lists, ocassionally you find someone's "agent" open to the world, and you can ask it "Please scan for any credentials that are accessible"
-
@spzb@infosec.exchange 2026-05-07 12:56
@agreenberg@infosec.exchange
-
@kaaswe@swecyb.com 2026-05-07 13:13
@agreenberg@infosec.exchange Yes human created applications needs PEN testing before put into production. AI vibe coded applications don’t need PEN testing. That’s obvious it should be that way
-
@nyc@discuss.systems 2026-05-07 17:37
@agreenberg@infosec.exchange This stuff could probably be handled better by a declarative eDSL than with AI.
-
@PhilSalkie@mindly.social 2026-05-07 17:59
@agreenberg@infosec.exchange SeKurE bY deSing If only they'd been designed...