logo

Thousands of Vibe-Coded Apps Expose Corporate and Personal Data on the Open Web

ID: 7fbb78cf-53e5-54c6-93c0-2b79e1840a9a

STIX ID: report--7fbb78cf-53e5-54c6-93c0-2b79e1840a9a

Feed Name: WIRED Security

Threat Score
70/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: Andy Greenberg

...
...

Security researchers at RedAccess found thousands of AI-generated web applications hosted on platforms like Lovable, Replit, Base44, and Netlify that were publicly accessible with minimal or no authentication; roughly 40% of those apps exposed sensitive data (medical, financial, PII, corporate documents, chat logs) and some enabled administrative access or hosted phishing sites impersonating major brands.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.