惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Y
Y Combinator Blog
有赞技术团队
有赞技术团队
J
Java Code Geeks
H
Hackread – Cybersecurity News, Data Breaches, AI and More
美团技术团队
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Hugging Face - Blog
Hugging Face - Blog
人人都是产品经理
人人都是产品经理
酷 壳 – CoolShell
酷 壳 – CoolShell
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
C
Check Point Blog
博客园 - 【当耐特】
The GitHub Blog
The GitHub Blog
Recent Announcements
Recent Announcements
The Cloudflare Blog
Microsoft Azure Blog
Microsoft Azure Blog
腾讯CDC
Vercel News
Vercel News
IT之家
IT之家
MyScale Blog
MyScale Blog
博客园_首页
Martin Fowler
Martin Fowler
WordPress大学
WordPress大学
罗磊的独立博客

Fast Company

IBM just settled a major anti-DEI case for $17 million Sustainability is maturing 2028 candidates will face a new kind of economic anger Trader Joe’s class action settlement: How to find out if you’re an eligible shopper and claim your money Mamdani filmed his pied-á-terre tax video outside Ken Griffin’s $238 million penthouse. Social media loves him for it A U.S. state just banned big AI data centers. Here’s why it might not be the last From legacy processes to AI-native work OpenAI shifts its focus to business users amid Anthropic pressure A massive tariff refund program is launching. Here’s who actually gets the money Why people can’t build wealth on wages alone, and what to do about it Eldercare—the leadership crisis no one is talking about Why workplaces need a gendered health approach Why AI is the ultimate accelerator for creativity AI anxiety is turning volatile Inside NTT Research’s push to commercialize deep tech Warren Buffett once said that success at the end of your life comes down to 1 word For her ‘Confessions’ sequel, Madonna takes Helvetica to the club Nearly two-thirds of parents support their Gen Z kids financially, survey finds Gatorade, the inventor of the sports drink, is making a surprising pivot to reach non-athletes 6 mindset shifts to improve your risk and failure tolerance Record high beef prices won’t be fixed with more cattle, ranchers say. Here’s why For women, gender disparities in ADHD diagnoses can be deadly What’s next for Live Nation? Jury reaches verdict in antitrust case over Ticketmaster fees Social Security COLA prediction for 2027 could mean bad news for seniors Canva is officially ‘an AI platform with design tools’ Allbirds stock is already falling after the AI pivot. History suggests investors should proceed with caution Google DeepMind’s Demis Hassabis on the long game of AI The Trump Store isn’t shy about hawking merch. It’s paying off like never before Get ready for the great American TV trade-in rush AI isn’t built for all languages and cultures. There’s a push to fix that
Lovable left AI prompts and user data exposed, one resear...
Mark Sulliva · 2026-04-21 · via Fast Company
A researcher revealed that the vibe-coding platform Lovable exposed users’ chat histories with AI models to other users accessing the platform through an API (application programming interface). X user @weezerOSINT , reported the exposure in a post on Monday . “I made a Lovable account today and was able to access another user’s source code, database credentials, AI chat histories, and customer data are all readable by any free account,” the researcher wrote. The post included a screenshot of another Lovable user’s project code and chats, along with an unresolved ticket for the bug that allegedly caused the data leak. Lovable has a mass data breach affecting every project created before november 2025. I made a lovable account today and was able to access another users source code, database credentials, AI chat histories, and customer data are all readable by any free account. nvidia,… pic.twitter.com/QcVvz9cNZl — impulsive (@weezerOSINT) April 20, 2026 In a follow-up conversation with Fast Company , @weezerOSINT (who did not share his real name) says it took 30 minutes using xAI’s Grok 4.2 model to conduct the research, adding that before AI, finding similar exposures would take hours or days. @weezerOSINT reported the issue via HackerOne, a cybersecurity company that runs bug bounty and vulnerability disclosure programs, in early March. On Monday, the researcher showed that Lovable projects created before November 2025 still expose the data. Lovable declined to provide an executive to explain the situation, and pointed to its public statement on X. Lovable initially said on X that no “data breach” had occurred, and that exposing project code was “intentional behavior.” When users mark their projects “public,” the company explained, they opt to have their code visible to other users. We were made aware of concerns regarding the visibility of chat messages and code on Lovable projects with public visibility settings. To be clear: We did not suffer a data breach. Our documentation of what “public” implies was unclear, and that’s a failure on us. Specifically… — Lovable (@Lovable) April 20, 2026 But that did not account for the exposure of users’ chats and prompts with the AI model, which Lovable made accessible for public projects until recently. “We also retroactively patched our API so public project chats couldn’t be accessed, no matter what,” Lovable said in a second, clarifying post on X. “Unfortunately, in February, while unifying permissions in our backend, we accidentally re-enabled access to chats on public projects.” We’re sorry our initial statement didn't properly address our mistake. Here's what a public project on Lovable means, and how we got to where we are today: In the early days, people didn't know what Lovable was capable of. So we wanted to make it easy to explore what others were… https://t.co/8X2LMjETaS — Lovable (@Lovable) April 20, 2026 As for @weezerOSINT’s early-March report to HackerOne, Lovable says the ticket had been closed because its “HackerOne partners” believed that viewing public projects’ chats was “the intended behavior.” As a vibe-coding platform, Lovable treats natural-language prompts used to generate code as a core part of the building process. The company initially believed its community would benefit from seeing how other developers used prompts to build features, functions, components, or database schemas, so chats were treated as standard project metadata. But the risk of exposing sensitive information in those chat histories appears to have outweighed that benefit. Lovable says that in December 2025 it made all new projects “private by default” for all users. Lovable’s most recent funding round came in December 2025, when it raised $330 million from CapitalG, Menlo Ventures, Khosla Ventures, and others. After the round, the company was valued at $6.6 billion, reportedly tripling its valuation in about five months.