惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园_首页
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
P
Proofpoint News Feed
G
Google Developers Blog
B
Blog
Engineering at Meta
Engineering at Meta
阮一峰的网络日志
阮一峰的网络日志
The Register - Security
The Register - Security
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - 叶小钗
The Cloudflare Blog
The Hacker News
The Hacker News
D
Darknet – Hacking Tools, Hacker News & Cyber Security
C
CXSECURITY Database RSS Feed - CXSecurity.com
雷峰网
雷峰网
F
Fortinet All Blogs
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
H
Hackread – Cybersecurity News, Data Breaches, AI and More
酷 壳 – CoolShell
酷 壳 – CoolShell
Last Week in AI
Last Week in AI
T
Threat Research - Cisco Blogs
A
About on SuperTechFans
量子位
Recorded Future
Recorded Future
博客园 - 三生石上(FineUI控件)
H
Help Net Security
Help Net Security
Help Net Security
P
Palo Alto Networks Blog
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
T
Troy Hunt's Blog
W
WeLiveSecurity
V
Vulnerabilities – Threatpost
T
The Exploit Database - CXSecurity.com
Know Your Adversary
Know Your Adversary
Apple Machine Learning Research
Apple Machine Learning Research
Scott Helme
Scott Helme
N
News | PayPal Newsroom
AWS News Blog
AWS News Blog
D
DataBreaches.Net
Blog — PlanetScale
Blog — PlanetScale
MongoDB | Blog
MongoDB | Blog
B
Blog RSS Feed
腾讯CDC
J
Java Code Geeks
Microsoft Azure Blog
Microsoft Azure Blog
TaoSecurity Blog
TaoSecurity Blog
GbyAI
GbyAI
Y
Y Combinator Blog
Hacker News - Newest:
Hacker News - Newest: "LLM"
D
Docker

Futurism

Meta’s AI Support Bot Is Giving Hackers Access to Other People’s Instagram Accounts Just by Asking Websites Are Spying on Your Solid State Drive The Trump Phone Appears to Have Already Leaked Its Customers’ Personal Information Through a Glaring Exploit How to Get Rid of Reddit’s Giant App-Shilling Popup That Breaks Its Entire Mobile Site Your Former Employer Is Selling Your Slacks and Emails to Train AI Madison Square Garden Reportedly Used Facial Recognition to Stalk Trans Woman For Two Years Top Security Experts Alarmed by Power of Anthropic’s New Hacker AI Companies Just Learned a Brutal Lesson About Training AI to Do Human Jobs Huge Group of Experts Warns Meta That Its Pervert Glasses Will Enable Terrible Crimes
Vibe Coded Apps Are Spilling Users’ Personal Information Directly Into the Maw of Greedy Hackers
Jon Christia · 2026-05-10 · via Futurism

Two men dressed as burglars wearing black masks and black clothing, each carrying a large sack over their shoulder. The image has a stylized, high-contrast effect with a greenish tint.

Illustration by Tag Hartman-Simkins / Futurism. Source: Getty Images

Sign up to see the future, today

Can’t-miss innovations from the bleeding edge of science and tech

Artificial intelligence has torn through many industries since the debut of ChatGPT in 2022, but there’s probably no single area where it’s had a clearer material impact than software development.

Programmers running the gamut from experienced to novice have embraced the tech, using chatbots and specialty tools to quickly generate code from natural language prompts. “Vibe coding,” as it’s come to be known, lets almost anyone churn out entire apps in little time — even if they have little or no technical chops.

On a certain level, you have to admit that’s pretty cool. But as we’re learning time and again, it also has distinct downsides.

One particularly glaring drawback is that a lot of vibe-coded software is now being deployed with gaping security flaws. In the latest sign that we may be veering into an AI-enabled hack-pocalypse, a fascinating new Wired story covers research by a cybersecurity firm called RedAccess that found sprawling privacy issues in vibe-coded apps.

The firm examined thousands of web apps created with the vibe coding platforms Lovable, Replit, Base44, and Netlify. What it found was, to put it lightly, not good: 5,000 of them had “virtually no security or authentication of any kind,” and a full 40 percent exposed users’ sensitive data, from medical and financial info to corporate documents and logs of ostensibly private chatbot conversations.

“The end result is that organizations are actually leaking private data through vibe-coding applications,” RedAccess cofounder Dor Zvi told Wired. “This is one of the biggest events ever where people are exposing corporate or other sensitive information to anyone in the world.”

The vibe coding platforms’ response to the embarrassing revelations left something to be desired. Netlify ignored it completely, while the other platforms basically deflected blame onto users, saying they should have better secured their work before putting it out into the world.

“We’re treating this as an ongoing matter,” a Lovable spokesperson told Wired. “It’s also worth noting that Lovable gives builders the tools to build securely, but how an app is configured is ultimately the creator’s responsibility.”

On a certain level they’re right, but these are also the companies claiming that creating software is now as simple as describing it to an AI bot. The reality is that AI remains extremely imperfect, so the resulting code is going have issues that only an experienced human developer or security expert would be able to identify — and these apps, fundamentally, are in the market of putting those people out of business.

“Anyone from your company at any moment can generate an app, and this is not going through any development cycle or any security check,” Zvi told Wired. “People can just start using it in production without asking anyone. And they do.”

More on vibe coding: Entirely Vibe-Coded Operating System Is a Bug-Filled Disaster