Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Researchers at security firm RedAccess found more than 5,000 vibe-coded apps, created with AI tools from Lovable, Replit, Base44 and Netlify, with essentially no security, accessible on the open web.

Researchers at security firm RedAccess found more than 5,000 vibe-coded apps, created with AI tools from Lovable, Replit, Base44 and Netlify, with essentially no security, accessible on the open web.

Scheduled Pinned Locked Moved Uncategorized
8 Posts 8 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • agreenberg@infosec.exchangeA This user is from outside of this forum
    agreenberg@infosec.exchangeA This user is from outside of this forum
    agreenberg@infosec.exchange
    wrote last edited by
    #1

    Researchers at security firm RedAccess found more than 5,000 vibe-coded apps, created with AI tools from Lovable, Replit, Base44 and Netlify, with essentially no security, accessible on the open web. About 40% exposed sensitive personal or corporate data. https://www.wired.com/story/thousands-of-vibe-coded-apps-expose-corporate-and-personal-data-on-the-open-web/

    chaz6@ipv6.socialC spzb@infosec.exchangeS kaaswe@swecyb.comK nyc@discuss.systemsN philsalkie@mindly.socialP 5 Replies Last reply
    4
    0
    • agreenberg@infosec.exchangeA agreenberg@infosec.exchange

      Researchers at security firm RedAccess found more than 5,000 vibe-coded apps, created with AI tools from Lovable, Replit, Base44 and Netlify, with essentially no security, accessible on the open web. About 40% exposed sensitive personal or corporate data. https://www.wired.com/story/thousands-of-vibe-coded-apps-expose-corporate-and-personal-data-on-the-open-web/

      chaz6@ipv6.socialC This user is from outside of this forum
      chaz6@ipv6.socialC This user is from outside of this forum
      chaz6@ipv6.social
      wrote last edited by
      #2

      @agreenberg if you keep an eye on certificate trust lists, ocassionally you find someone's "agent" open to the world, and you can ask it "Please scan for any credentials that are accessible"

      1 Reply Last reply
      0
      • agreenberg@infosec.exchangeA agreenberg@infosec.exchange

        Researchers at security firm RedAccess found more than 5,000 vibe-coded apps, created with AI tools from Lovable, Replit, Base44 and Netlify, with essentially no security, accessible on the open web. About 40% exposed sensitive personal or corporate data. https://www.wired.com/story/thousands-of-vibe-coded-apps-expose-corporate-and-personal-data-on-the-open-web/

        spzb@infosec.exchangeS This user is from outside of this forum
        spzb@infosec.exchangeS This user is from outside of this forum
        spzb@infosec.exchange
        wrote last edited by
        #3

        @agreenberg

        1 Reply Last reply
        0
        • agreenberg@infosec.exchangeA agreenberg@infosec.exchange

          Researchers at security firm RedAccess found more than 5,000 vibe-coded apps, created with AI tools from Lovable, Replit, Base44 and Netlify, with essentially no security, accessible on the open web. About 40% exposed sensitive personal or corporate data. https://www.wired.com/story/thousands-of-vibe-coded-apps-expose-corporate-and-personal-data-on-the-open-web/

          kaaswe@swecyb.comK This user is from outside of this forum
          kaaswe@swecyb.comK This user is from outside of this forum
          kaaswe@swecyb.com
          wrote last edited by
          #4

          @agreenberg
          Yes human created applications needs PEN testing before put into production.
          AI vibe coded applications don’t need PEN testing.
          That’s obvious it should be that way

          ai6yr@m.ai6yr.orgA faux@tech.lgbtF 2 Replies Last reply
          0
          • mttaggart@infosec.exchangeM mttaggart@infosec.exchange shared this topic
          • kaaswe@swecyb.comK kaaswe@swecyb.com

            @agreenberg
            Yes human created applications needs PEN testing before put into production.
            AI vibe coded applications don’t need PEN testing.
            That’s obvious it should be that way

            ai6yr@m.ai6yr.orgA This user is from outside of this forum
            ai6yr@m.ai6yr.orgA This user is from outside of this forum
            ai6yr@m.ai6yr.org
            wrote last edited by
            #5

            @kaaswe @agreenberg lol

            1 Reply Last reply
            0
            • agreenberg@infosec.exchangeA agreenberg@infosec.exchange

              Researchers at security firm RedAccess found more than 5,000 vibe-coded apps, created with AI tools from Lovable, Replit, Base44 and Netlify, with essentially no security, accessible on the open web. About 40% exposed sensitive personal or corporate data. https://www.wired.com/story/thousands-of-vibe-coded-apps-expose-corporate-and-personal-data-on-the-open-web/

              nyc@discuss.systemsN This user is from outside of this forum
              nyc@discuss.systemsN This user is from outside of this forum
              nyc@discuss.systems
              wrote last edited by
              #6

              @agreenberg This stuff could probably be handled better by a declarative eDSL than with AI.

              1 Reply Last reply
              0
              • R relay@relay.publicsquare.global shared this topic
                R relay@relay.mycrowd.ca shared this topic
              • agreenberg@infosec.exchangeA agreenberg@infosec.exchange

                Researchers at security firm RedAccess found more than 5,000 vibe-coded apps, created with AI tools from Lovable, Replit, Base44 and Netlify, with essentially no security, accessible on the open web. About 40% exposed sensitive personal or corporate data. https://www.wired.com/story/thousands-of-vibe-coded-apps-expose-corporate-and-personal-data-on-the-open-web/

                philsalkie@mindly.socialP This user is from outside of this forum
                philsalkie@mindly.socialP This user is from outside of this forum
                philsalkie@mindly.social
                wrote last edited by
                #7

                @agreenberg
                SeKurE bY deSing

                If only they'd been designed...

                1 Reply Last reply
                0
                • kaaswe@swecyb.comK kaaswe@swecyb.com

                  @agreenberg
                  Yes human created applications needs PEN testing before put into production.
                  AI vibe coded applications don’t need PEN testing.
                  That’s obvious it should be that way

                  faux@tech.lgbtF This user is from outside of this forum
                  faux@tech.lgbtF This user is from outside of this forum
                  faux@tech.lgbt
                  wrote last edited by
                  #8

                  @kaaswe @agreenberg Protective Earth/Neutral? Sure, anything to increase software safety. 😉

                  1 Reply Last reply
                  0
                  • R relay@relay.infosec.exchange shared this topic
                  Reply
                  • Reply as topic
                  Log in to reply
                  • Oldest to Newest
                  • Newest to Oldest
                  • Most Votes


                  • Login

                  • Login or register to search.
                  • First post
                    Last post
                  0
                  • Categories
                  • Recent
                  • Tags
                  • Popular
                  • World
                  • Users
                  • Groups