Thousands of AI-Generated Apps Expose Corporate and Personal Data
Security researcher Dor Zvi and his team at RedAccess discovered that over 5,000 web applications created using AI development tools like Lovable, Replit, Base44, and Netlify lack basic security measures. These "vibe-coded" apps, hosted on the platforms' own domains, are easily discoverable via search engines and often allow unrestricted public access. Approximately 40 percent of these applications expose sensitive data, including medical records, financial information, corporate strategies, and customer chat logs. In some instances, the vulnerabilities allowed for administrative takeover of systems. The research highlights a significant risk where employees bypass traditional development cycles and security checks to deploy apps directly into production. Additionally, researchers identified numerous phishing sites impersonating major corporations such as Bank of America and McDonald's, created and hosted on these AI platforms. This incident underscores the dangers of rapid, unregulated AI-assisted software deployment, resulting in one of the largest recent exposures of corporate and personal information to the open web.
Wire timeline
Thousands of AI-Generated Apps Expose Corporate and Personal Data
Security researcher Dor Zvi and his team at RedAccess discovered that over 5,000 web applications created using AI development tools like Lovable, Replit, Base44, and Netlify lack basic security measures. These "vibe-coded" apps, hosted on the platforms' own domains, are easily discoverable via search engines and often allow unrestricted public access. Approximately 40 percent of these applications expose sensitive data, including medical records, financial information, corporate strategies, and customer chat logs. In some instances, the vulnerabilities allowed for administrative takeover of systems. The research highlights a significant risk where employees bypass traditional development cycles and security checks to deploy apps directly into production. Additionally, researchers identified numerous phishing sites impersonating major corporations such as Bank of America and McDonald's, created and hosted on these AI platforms. This incident underscores the dangers of rapid, unregulated AI-assisted software deployment, resulting in one of the largest recent exposures of corporate and personal information to the open web.
Slashdot