What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks
This article highlights a growing security risk stemming from the rise of ‘vibe coding’ – AI-driven application development platforms that allow employees to rapidly build and deploy applications. Over 2,000 of these publicly accessible applications contain sensitive corporate data, often deployed without proper security controls or IT oversight, creating a significant attack surface. The existing security infrastructure, focused on endpoint detection and response, data loss prevention, and CASB, struggles to detect and manage this new type of shadow IT, leaving organizations vulnerable to potential breaches.
The core issue is the proliferation of custom applications built using AI-powered ‘vibe coding’ platforms. Employees, motivated by efficiency, are creating applications – such as campaign trackers, vendor intake forms, and financial dashboards – and connecting them directly to production systems like CRMs and ERPs. Critically, these applications are frequently published to the open internet with minimal security configurations. This creates a massive expansion of the attack surface, as vulnerabilities in these custom applications can be exploited without detection by traditional security tools. The article emphasizes that this isn't simply ‘Shadow IT’ – it’s a fundamentally different risk profile, involving custom-built applications with direct connections to critical systems and often deployed on personal devices outside of corporate control.
Existing security solutions are largely ineffective against this new threat. Endpoint Detection and Response (EDR) systems focus on endpoint activity, failing to see the application development process itself. Data Loss Prevention (DLP) systems are limited by their ability to monitor enumerated channels, unable to detect data movement through custom APIs. Cloud Access Security Brokers (CASB) struggle to identify and manage the vast number of custom applications hosted on vibe-coding platforms. Furthermore, Security Service Edge (SSE) deployments often lack the necessary visibility into unmanaged devices and personal browser sessions. The article concludes that visibility needs to shift to an end-to-end, web-session event perspective to effectively manage this emerging risk.
