Close Menu
    What's Hot

    Hugging Face CEO calls for ‘radical transparency’ after ‘unprecedented’ OpenAI hack

    Hedge funds grow at the fastest rate ever

    Zuffa Boxing: Edgar Berlanga climbs off canvas to beat Steven Buttler in Madison Square Garden thriller | Boxing News

    Facebook X (Twitter) Instagram
    Trending
    • Hugging Face CEO calls for ‘radical transparency’ after ‘unprecedented’ OpenAI hack
    • Hedge funds grow at the fastest rate ever
    • Zuffa Boxing: Edgar Berlanga climbs off canvas to beat Steven Buttler in Madison Square Garden thriller | Boxing News
    • This tiny fiber-optic plug could make laser weapons battlefield-ready
    • Putin Needs New Money Pots
    • Bill Clinton Ended Welfare and Paved the Way For Trump’s “Big Beautiful” Act
    • The sting in the tail of Japan’s lost decades
    • China’s CXMT Stock Soars 470% in Start of Trading, Amid A.I. Race
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Artificial Intelligence

    Thousands of Vibe-Coded Apps Expose Corporate and Personal Data on the Open Web

    adminBy adminMay 7, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Thousands of Vibe-Coded Apps Expose Corporate and Personal Data on the Open Web
    Share
    Facebook Twitter LinkedIn Pinterest Email

    As AI increasingly takes over the work of modern programmers, the cybersecurity world has warned that automated coding tools are sure to introduce a new bounty of hackable bugs into software. When those same vibe-coding tools invite anyone to create applications hosted on the web with a click, however, it turns out the security implications go beyond bugs to a total absence of any security—even, sometimes, for highly sensitive corporate and personal data.

    Security researcher Dor Zvi and his team at the cybersecurity firm he cofounded, RedAccess, analyzed thousands of vibe-coded web applications created using the AI software development tools Lovable, Replit, Base44, and Netlify and found more than 5,000 of them that had virtually no security or authentication of any kind. Many of these web apps allowed anyone who merely finds their web URL to access the apps and their data. Others had only trivial barriers to that access, such as requiring that a visitor sign in with any email address. Around 40 percent of the apps exposed sensitive data, Zvi says, including medical information, financial data, corporate presentations, and strategy documents, as well as detailed logs of customer conversations with chatbots.

    “The end result is that organizations are actually leaking private data through vibe-coding applications,” says Zvi. “This is one of the biggest events ever where people are exposing corporate or other sensitive information to anyone in the world.”

    Zvi says RedAccess’ scouring for vulnerable web apps was surprisingly easy. Lovable, Replit, Base44, and Netlify all allow users to host their web apps on those AI companies’ own domains, rather than the users’. So the researchers used straightforward Google and Bing searches for those AI companies’ domains combined with other search terms to identify thousands of apps that had been vibe coded with the companies’ tools.

    Of the 5,000 AI-coded apps that Zvi says were left publicly accessible to anyone who simply typed their URLs into a browser, he found close to 2,000 that, upon closer inspection, seemed to reveal private data: Screenshots of web apps he shared with WIRED—several of which WIRED verified were still online and exposed—showed what appeared to be a hospital’s work assignments with the personally identifiable information of doctors, a company’s detailed ad purchasing information, what appeared to be another firm’s go-to-market strategy presentation, a retailer’s full logs of its chatbot’s conversations with customers, including the customers’ full names and contact information, a shipping firm’s cargo records, and assorted sales and financial records from a variety of other companies. In some cases, Zvi says, he found that the exposed apps would have allowed him to gain administrative privileges over systems and even remove other administrators.

    In the case of Lovable, Zvi says he also found numerous examples of phishing sites that impersonated major corporations, including Bank of America, Costco, FedEx, Trader Joe’s, and McDonald’s, that appeared to have been created with the AI coding tool and hosted on Lovable’s domain.

    When WIRED asked the four AI coding companies about RedAccess’ findings, Netlify didn’t respond, but the three other companies pushed back on the researchers’ claims and protested that they hadn’t shared enough of their findings or provided enough time for them to respond. (RedAccess says it reached out to the companies on Monday.) But they didn’t deny that the web apps RedAccess found were left exposed.

    “From the limited information they shared, [RedAccess’s] core claim appears to be that some users have published apps on the open web that should’ve been private,” Replit’s CEO Amjad Masad wrote in a response post on X. “Replit allows users to choose whether apps are public or private. Public apps being accessible on the internet is expected behavior. Privacy settings can be changed at any time with a single click.”

    apps Corporate data expose Open Personal Thousands vibecoded web
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleInside Dreame’s wild launch event — packed with products no one can buy
    Next Article Best Bug Spray (2026), Tested and Reviewed
    admin
    • Website

    Related Posts

    LIV Golf UK: Lucas Herbert wins with record score of 30 under par as he follows impressive Open display with title | Golf News

    July 27, 2026

    European Researchers Say Big Tech Is Blocking Access to Their Data

    July 26, 2026

    3M Open: Jackson Koivun, 21, holds off Scottie Scheffler to secure victory on just third PGA Tour start as a professional | Golf News

    July 26, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Hugging Face CEO calls for ‘radical transparency’ after ‘unprecedented’ OpenAI hack

    Hedge funds grow at the fastest rate ever

    Zuffa Boxing: Edgar Berlanga climbs off canvas to beat Steven Buttler in Madison Square Garden thriller | Boxing News

    This tiny fiber-optic plug could make laser weapons battlefield-ready

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by