Mark RadarMARK RADAR
EN

Vibe Coding Raises Security Concerns as More Than 5,000 Apps Risk Data Exposure

2 reports · First detected 2026-05-11 · Last active 2026-05-11

“Vibe Coding” allows users to direct AI in natural language to rapidly generate software, lowering barriers to development. It also enables employees with little cybersecurity experience to build corporate tools independently, creating “shadow AI” that is difficult for IT departments to control. Without authentication, such applications can directly expose medical and financial information, as well as internal presentations. The risk stems from poor deployment and access management, rather than platform vulnerabilities.

A recent RedAccess survey found that more than 5,000 Vibe Coding applications were accessible over the public internet without basic authentication, including about 2,000 tools built for corporate use. Their exposure of sensitive data shows that employee-built tools have become a gap in corporate cybersecurity governance. Companies need to immediately inventory public endpoints, add authentication and restrict data-access permissions.

All Coverage

2 original reports

The Backstory

The history behind this event
AI Development Trend Vibe Coding Sparks Security Debate, Underscoring Value of Human Expertise2026-03-27 · 1 reports · similarity 0.85

Vibe coding is a development approach in which AI rapidly generates software from natural-language instructions. Former OpenAI researcher Andrej Karpathy coined the term in February 2025. The approach lowers the barrier to building apps, but it can also lead people without engineering training to overlook critical issues such as access controls, data protection and system architecture. Responsibility for cybersecurity therefore cannot be handed over to AI.

An AI-assisted app called “惜食獵人” recently came under scrutiny after vulnerabilities, including the exposure of GPS coordinates, were disclosed, prompting online debate over the security of vibe coding. The incident shows that while AI can shorten development and product-launch timelines, developers must still conduct code reviews, security testing and risk assessments themselves. Those most at risk of being replaced are people unable to distinguish good code from bad.

Mark Radar|MARK RADAR