惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

GbyAI
GbyAI
V
Visual Studio Blog
美团技术团队
L
LINUX DO - 最新话题
Last Week in AI
Last Week in AI
雷峰网
雷峰网
博客园_首页
腾讯CDC
博客园 - Franky
大猫的无限游戏
大猫的无限游戏
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
人人都是产品经理
人人都是产品经理
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
J
Java Code Geeks
W
WeLiveSecurity
Apple Machine Learning Research
Apple Machine Learning Research
Spread Privacy
Spread Privacy
博客园 - 聂微东
量子位
Recent Announcements
Recent Announcements
S
Schneier on Security
O
OpenAI News
PCI Perspectives
PCI Perspectives
H
Heimdal Security Blog
T
Tailwind CSS Blog
S
Security Affairs
Y
Y Combinator Blog
P
Privacy International News Feed
Hacker News: Ask HN
Hacker News: Ask HN
Stack Overflow Blog
Stack Overflow Blog
Application and Cybersecurity Blog
Application and Cybersecurity Blog
U
Unit 42
Webroot Blog
Webroot Blog
Vercel News
Vercel News
Simon Willison's Weblog
Simon Willison's Weblog
B
Blog RSS Feed
S
Secure Thoughts
Microsoft Azure Blog
Microsoft Azure Blog
N
Netflix TechBlog - Medium
V
V2EX
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
D
DataBreaches.Net
月光博客
月光博客
博客园 - 三生石上(FineUI控件)
L
LangChain Blog
S
Security @ Cisco Blogs
The Hacker News
The Hacker News
The GitHub Blog
The GitHub Blog
C
CERT Recently Published Vulnerability Notes

informationweek

2026 tech company layoffs How Sedgwick scaled AI in legacy claims workflows InformationWeek Podcast: CTOs on using AI in regulated spaces How top CIOs are measuring the real ROI of IT automation What AI must learn from Roosevelt, conservation and 1929 Experian's chief innovation officer gleans AI gains with startup collab ETS CIO on competing with AI startups 'running with scissors' Before the next VMware: How CIOs prepare for vendor shocks The strategic alignment powering cyber-resilient organizations The AI infrastructure bottleneck is becoming a CIO problem InformationWeek Podcast: CTOs on reining in rogue AI agents Workplace equity in the age of AI Why and how to implement an AI asset rationalization strategy Why companies are shifting toward private AI models AI agents in automation: When to build, when to buy Navan CTO AI on trial: The Workday case that CIOs can The AI infrastructure boom is coming for enterprise budgets How CIOs can manage LLM costs: A practical guide What CIOs miss when buying vertical SaaS software InformationWeek Podcast: How CTOs balance AI and their teams Whirlpool, Duke Energy, Cleveland Clinic CIOs on scaling AI Where CIOs get stuck rebuilding the enterprise: What 'Rewired' reveals As AI makes projects harder to track, will CIOs need new controls? Why disaster recovery plans fail in geopolitical crises A silent erosion of enterprise AI by data poisoning Priceline CTO prioritizes engineers able to 'hold a room and a roadmap' InformationWeek Podcast: When CTOs need to restart IT projects Wayfair CTO maps agentic path across digital and brick-and-mortar commerce The AI contract gaps the Google-Pentagon deal just made visible Non-human identity sprawl is agentic AI's real risk Anthropic's Mythos forces a rethink of vulnerability management Outsourcing contracts weren't built for AI. CIOs are renegotiating now The AI spend hangover companies didn't plan for The power of CIO networking in the competitive AI world Why CIOs see AI projects stall: Speed without structure kills scale IT leaders should never let a good crisis go to waste SFO's digital twin maps airport operations from the curb to takeoff CIOs caught in the middle as AI startups disrupt vertical Saas Submit an IT Leadership column to InformationWeek Podcast: Rightsizing AI frameworks to avoid failure modes The invisible labor crisis inside IT: AI work the org chart can't see Why AI teams treat training data like capital Ask the Experts: How CIOs can identify and overcome cultural barriers to innovation Nobody told legal about your RAG pipeline -- why that's a problem Meta's new 'AI Zuckerberg' is a mirror for every C-suite Will the music stop for AI's funding dance? Rethink tech talent: Local is the smartest play for IT InformationWeek Podcast: Catching errors in AI-powered code CIOs can combat talent scarcity with AI-augmented leadership -- Gartner How Bellevue, Wash., is applying AI to streamline a broken permitting process Ignore the hype: Smarter tech bets at speed of change Who controls the fix? Colorado's repair fight tests CIO power Ask the Experts: The red flags that signal an AI project isn't worth pursuing The hidden high cost of training AI on AI Red Hat's Marco Bill: Resource control is key for AI sovereignty InformationWeek Podcast: New IT architecture, cloud, edge and AI Enterprises need Tier 1 provider relationships to deliver on AI How CIOs run and rebuild the business at the same time in the AI era It's not your tech stack, it's your structure -- fix it Confidential computing resurfaces as security priority for CIOs FinOps: Helpful tool, or a cloud control placebo for CIOs? Cleveland's open data overhaul: From sticky notes to public dashboards As Microsoft expands Copilot, CIOs face a new AI security gap Why build vs. buy doesn't fit modern IT systems InformationWeek Podcast: Is quantum computing slumbering? Your AI vendor is now a single point of failure A practical guide to controlling AI agent costs before they spiral AI fuels a new wave of technical debt The sunsetting of Sora: A hard lesson in AI portfolio resilience HP pushes broad internal AI use after early productivity gains Why value-based pricing is inevitable InformationWeek Podcast: Safeguarding ecosystems from outsiders Why AI scaling is so hard -- and what CIOs say works Humans are the North Star for AI-native workplaces -- Gartner How IT leaders build a culture for what comes next Compliance costs risk widening the AI gap AI-driven layoffs add new demands on CIOs to prove value AI transformation: Early wins are not enough for CIOs Why CIOs can't let users wait on IT Memory shortage doesn't have to spell disaster for IT budgets Accelerate AI adoption: 3 reasons for adopting MCP How techno-nationalism is complicating IT resilience and supply chains for CIOs InformationWeek Podcast: Compliance crackdown on AI and BYOD Workday’s AI reset: Agents and the race to remake SaaS Why enterprise AI initiatives keep dying before production Metrics of meaning: What do we really measure in AI? Techno-nationalism is reshaping CIO infrastructure strategy Using AI to pick team leaders -- without crossing legal or ethical lines What Oracle's layoffs reveal about running IT with fewer people Chief AI Officer on course-correcting when AI moves too fast Large enterprises need high-performing networks to scale AI InformationWeek Podcast: When do smaller AI models make sense? The future belongs to AI-driven IT Ways AI supercharges risk awareness and data insights for CIOs How automation prepares you for agentic NetOps Should the CIO, CFO or CEO hold the kill switch on AI? The CIO's new mandate: Redesign work itself Ask the Experts: CIOs say they wouldn’t pull workloads back from the cloud How AI is Reshaping the Enterprise
Vibe coding: Speed without security is a liability
2026-03-31 · via informationweek

Software development is undergoing a fundamental shift toward "vibe coding," where developers move away from the granular, manual process of writing code and instead use natural language prompts to describe a desired outcome. 

They provide the "vibe," and AI agents generate the executable code.

For organizations or teams that need to operate quickly, the ability to prompt a feature into existence is incredibly enticing. However, according to a research report from Wakefield Research on behalf of Palo Alto Networks, this surge in AI-driven development is creating a massive security problem. While companies are shipping code faster than ever, we are also accelerating the build-up of technical debt and critical security gaps.

The productivity paradox

The Palo Alto Networks report reveals a major disconnect in how software is built today. While AI assistance has allowed 53% of the 2,800 IT professionals surveyed to ship code weekly or faster, security processes haven't kept up with this new speed. In fact, only 18% of organizations report being able to fix security vulnerabilities at that pace. Essentially, we are moving faster than we can protect ourselves.

Related:Will the music stop for AI's funding dance?

Vibe coding makes it much easier for anyone to build complex software, but that speed often comes at the expense of understanding. When a developer relies on AI to generate code, they can push through logic they haven't personally verified. If you don't fully grasp how the code works, it's impossible to be truly accountable for its security and it makes remediation of issues in the future more complex. This lack of oversight is already hurting code quality, leading to bulkier, less efficient software.

AI: The new primary attack surface

The risks of unverified AI outputs are now a reality. The 2025 Palo Alto Networks report found that 99% of organizations have encountered an attack on an AI system in the past year. As we empower AI agents to write code, we are simultaneously expanding the attack surface in the following three critical ways:

  1. API surges: Because AI agents rely heavily on APIs to communicate and execute tasks, attacks on APIs have surged by 41%. Vibe coding often creates "shadow APIs", with connections the developer may not even realize were established by the AI.

  2. Prompt injection and autonomy: Giving an AI agent the power to edit files or download software libraries on its own is a massive security gamble. If an attacker tricks the AI with a malicious prompt, that independence backfires, and the AI itself effectively becomes a tool for the hacker to move through your systems.

  3. The AI supply chain: AI-generated code frequently leans on open source libraries. If these dependencies aren't rigorously vetted, organizations risk inheriting outdated or malicious packages. More dangerously, AI can hallucinate nonexistent package names. Threat actors now practice "slopsquatting", which is when they register these fabricated names in public repositories to ensure their malicious code is pulled in by unsuspecting AI agents.

  4. Exposed intellectual property: Vibe coding often involves sending proprietary logic to third-party models. Without a secure framework, your company's most valuable intellectual property effectively enters the public domain, where it can be used to train future models

Related:The hidden high cost of training AI on AI

From coder to 'AI team leader'

To survive the era of vibe coding, the role of the senior engineer must evolve. We have seen the rise of the AI team leader. In this model, the engineer's value shifts from the volume of code they personally write to the strategic oversight of an entire ecosystem of AI agents. This isn't about humans manually reviewing every line of AI-generated code, but instead it's about deploying security agents to watch the coding agents.

In this "Agent-to-Agent" security model, the human leader sets the guardrails and high-level intent, while autonomous security agents perform the heavy lifting. This includes real-time vetting, automated remediation and contextual governance.

Related:Red Hat CIO Marco Bill: Resource control is key for AI sovereignty

The path to engineered trust

The consensus among security professionals is clear: the "vibe" isn't enough. According to the Palo Alto Networks report, 97% of organizations are prioritizing the consolidation of their cloud security footprint to eliminate gaps created by fragmented tools.

Speed without security is dangerous. To unlock the true promise of AI-driven productivity, enterprises must move beyond vibe coding and toward engineered trust. This means:

  • Mandating rigorous scanning: AI-generated code must be reviewed with the same (or greater) rigor as human code.

  • Consolidating platforms: Moving away from a slew of different security tools to a unified "code-to-cloud" platform.

  • Defining accountability: Ensuring that every line of code, whether written or "vibed," has a human responsible for its integrity.

The future of the cloud is being written by AI, but it must be governed by humans. If we continue to prioritize the "vibe" of rapid innovation over the reality of secure engineering, we aren't just building applications; we're creating security liabilities.

About the Author

Sarit Tager

Palo Alto Networks

Sarit Tager, vice president of product management at Palo Alto Networks, leads the code and application security product management team for Cortex Cloud. She previously held leadership roles at Check Point Software, JFrog and Vdoo.