financial modeling

The enterprise security gap now has a price tag in shadow AI apps.

Recent research from Israeli cybersecurity firm RedAccess reveals the alarming scale of vulnerabilities associated with vibe-coded applications, exposing sensitive corporate data.

4 min readVentureBeat
The enterprise security gap now has a price tag in shadow AI apps.

The security industry has spent years building sophisticated frameworks to protect servers, cloud infrastructure, and corporate endpoints. Yet as the RedAccess research reveals, a new category of enterprise assets has emerged outside those protections entirely: applications built by employees over a weekend using vibe coding platforms, deployed on public URLs, and connected to live databases containing sensitive corporate data. The scale is striking—380,000 publicly accessible assets across Lovable, Base44, Replit, and Netlify, with roughly 5,000 containing sensitive information spanning healthcare records, financial data, and customer PII. This is not a theoretical risk. It is an active, quantified exposure that security teams have no visibility into, and the cost implications are already materializing. IBM's 2025 Cost of a Data Breach Report found that shadow AI breaches added an average of $670,000 to incident costs, pushing the shadow AI breach average to $4.63 million. The pattern extends beyond vibe-coded apps themselves. Recent research on Claude Code, Copilot and Codex all got hacked. Every attacker went for the credential, not the model demonstrates that AI development tools are being targeted across multiple vectors, while the Vercel breach exposes the OAuth gap most security teams cannot detect, scope or contain illustrates how quickly a single unauthorized tool adoption can cascade into a supply chain compromise. Together, these findings paint a picture of security architectures that were designed for a different era of enterprise computing.

The core problem is structural, not procedural. Traditional asset discovery tools were built to find servers, containers, and cloud instances—finite, trackable infrastructure with identifiable fingerprints. They have no mechanism for discovering a marketing configurator that a product manager built on Lovable, connected to a Supabase database holding live customer records, and shared with external contractors through a public URL that Google indexed within hours. The platforms themselves compound the issue: privacy defaults make apps publicly accessible unless users manually opt for privacy, and the assumption embedded in that design choice is that the platform handles security. It does not. The CVE-2025-48757 documentation found insufficient or missing Row-Level Security policies in Lovable-generated Supabase projects, meaning the AI generated the database layer but not the access controls that should have restricted who could read the data. This is the critical insight: AI generates syntactically correct code that lacks awareness of broader system architecture and nuanced business rules, a defect category Gartner forecasts will increase software defects by 2,500% by 2028.

What makes this particularly challenging is that the exposure happens at AI-generation speed while security review remains a human process. Escape.tech's October 2025 scan found over 2,000 high-impact vulnerabilities and 175 instances of personal data exposure across 5,600 vibe-coded applications, with every vulnerability residing in a live production system discoverable within hours. The velocity mismatch is stark: employees can deploy functioning applications in minutes, but security teams have no inventory of what was built, what data it connects to, or whether authentication is required. The detection challenge runs deeper than most organizations realize. These apps deploy on platform subdomains that rotate frequently and sit behind CDN layers that mask origin infrastructure. Conventional SIEM and endpoint telemetry generate limited signals for applications that exist in the gap between network visibility and application inventory—a gap most security stacks were never architected to cover.

The question for security leaders is not whether vibe-coded apps exist inside their perimeter. The question is how many, holding what data, visible to whom. The RedAccess findings suggest the answer, for most organizations, is worse than anyone in the C-suite currently knows. Organizations that treat this as a policy problem will write memos that gather dust. Those that treat it as an architecture problem will deploy discovery scanning across the major vibe coding domains, require pre-deployment security review, extend AppSec pipelines to citizen-built applications, and add these platforms to DLP rules. The structural failure is the same across the ecosystem: security review happens after deployment or not at all. Identity systems track human users and service accounts, but they do not track the Lovable app a sales operations analyst deployed last Tuesday connected to a live CRM database. The organizations that start scanning this week will find them. The ones that wait will read about themselves next.

From VentureBeat

Most enterprise security programs were built to protect servers, endpoints, and cloud accounts. None of them was built to find a customer intake form that a product manager vibe coded on Lovable over a weekend, connected to a live Supabase database, and deployed on a public URL indexed by Google. That gap now has a price tag.

Read the original at VentureBeat