VFF - The signal in the noise
News

5,000 vibe-coded apps expose shadow AI as enterprise security blind spot

Read original
Share
5,000 vibe-coded apps expose shadow AI as enterprise security blind spot

RedAccess discovered 380,000 publicly accessible applications and infrastructure built with vibe coding tools like Lovable and Replit, with roughly 5,000 containing sensitive corporate data including healthcare records, financial information, and customer conversations. The exposure stems from default privacy settings that make apps public unless manually switched to private, combined with indexing by search engines. This represents a new class of shadow AI risk that traditional enterprise security programs were not designed to detect or prevent.

  • RedAccess found 380,000 publicly accessible assets built with vibe coding platforms, with 5,000 containing sensitive corporate information
  • Exposed data includes healthcare records, financial information, shipping logistics, and customer service conversations from multiple jurisdictions
  • Default settings on vibe coding platforms make applications public by default, and many get indexed by Google, making discovery trivial
  • IBM's 2025 breach report shows shadow AI incidents add $670,000 to average breach costs, with 97% of AI-related breaches lacking proper access controls

Vibe coding tools have democratized application development but created a massive blind spot in enterprise security. Traditional security programs monitor servers, endpoints, and cloud accounts, but not ad-hoc applications built by non-technical staff on weekend projects. This gap is now quantified at scale and correlates with regulatory exposure under HIPAA, GDPR, and LGPD, making it a compliance and risk management issue, not just a technical one.

For operators and founders, this signals that citizen developer tools require new governance frameworks and that security budgets must expand to cover shadow AI. Gartner forecasts that prompt-to-app approaches will increase software defects by 2,500% by 2028, with remediation costs consuming innovation budgets. Organizations without AI governance policies face both breach liability and operational drag from fixing contextual bugs in AI-generated code.

  • Default-public settings on vibe coding platforms create systemic exposure that user education alone cannot solve, requiring platform-level privacy defaults to shift
  • Shadow AI breaches disproportionately expose customer PII at 65% versus 53% across all breaches, creating heightened regulatory and reputational risk
  • Enterprise security teams need new discovery and monitoring tools specifically for shadow AI assets, representing a new market category for security vendors
  • Organizations must establish AI governance policies and access controls before citizen developers deploy production applications, or face breach costs averaging $4.63 million

Monitor whether vibe coding platforms respond by changing default privacy settings and adding built-in governance controls. Watch for regulatory action under HIPAA, GDPR, and LGPD targeting organizations with exposed healthcare and financial data. Track whether security vendors launch shadow AI discovery tools and whether enterprises begin requiring approval workflows for citizen-developed applications.

Share

Subscribe to the newsletter

The latest stories and analysis, delivered to your inbox.

Free. No spam. Unsubscribe any time.

Related stories

AWS Guidance: Securing Agentic AI with Data Mesh Architecture

AWS Guidance: Securing Agentic AI with Data Mesh Architecture

AWS published a technical guide on building agentic AI applications using a modern data mesh architecture that enforces fine-grained access control across multiple data sources. The approach replaces specialized vector databases with Amazon S3 Vectors (reducing costs up to 90%), uses S3 Tables with Apache Iceberg for governed data access, and exposes data through Model Context Protocol tools via AgentCore Gateway with Lambda-backed interceptors. This addresses governance gaps in autonomous AI agents that query databases and synthesize answers across organizational data sources.

by Venkata Sistla· AWS Machine Learning Blog
Anthropic Accuses Alibaba of Unauthorized Claude Model Access
TrendingNews

Anthropic Accuses Alibaba of Unauthorized Claude Model Access

Anthropic has accused Alibaba Group of illicitly accessing its Claude AI models to extract their capabilities in violation of terms of service. In a June 10 letter to U.S. senators, Anthropic stated that Alibaba and its Qwen AI lab generated more than 28.8 million queries against Claude models without authorization. The accusation raises questions about AI model security and competitive practices in the global AI market.

by Henry Siu· The Information
Huntington Bank Redacts 400M Documents in Months Using AWS ML

Huntington Bank Redacts 400M Documents in Months Using AWS ML

Huntington National Bank processed over 400 million documents to redact sensitive customer data using AWS machine learning services, reducing an estimated multi-year effort to months. The bank built a scalable workflow combining Amazon Textract, SageMaker, Step Functions, and Lambda while meeting strict compliance requirements including PCI DSS certification, encryption at rest and in transit, and 95% redaction accuracy. The solution used AWS DataSync and Direct Connect to securely transfer documents from on-premises storage to AWS for processing and back again.

by Rob Carnell· AWS Machine Learning Blog
Telecom Operators Move to Autonomous AI Agents for Network Operations

Telecom Operators Move to Autonomous AI Agents for Network Operations

NVIDIA is demonstrating AI agent infrastructure for telecom operators at DTW Ignite 2026, moving beyond task automation toward autonomous network operations. The platform combines synthetic data generation, telecom-domain models, secure runtimes, and simulations to enable agents that proactively detect problems and coordinate changes across network and business systems. Partners including SoftBank, AdaptKey, Amdocs, and NTT DATA are piloting agents for network self-healing, customer care, and data migration workflows.

by Lilac Ilan· NVIDIA Blog (AI)