Thousands of apps built with Agentic AI platforms like Lovable, Replit, Netlify, and Base44 are exposing private data

Reddit r/AI_Agents News

Summary

A Red Access investigation reveals that thousands of AI-generated web apps on platforms like Lovable and Replit are exposing sensitive private data due to misconfigurations. This highlights significant security risks associated with the rising trend of 'vibe coding' and unvetted AI tool usage.

A new investigation by Israeli cybersecurity firm Red Access found thousands of AI-generated web apps leaking data ranging from medical records to internal business documents. The findings add to mounting concerns about vibe coding, a fast-growing trend in which users rely heavily on AI tools to generate and deploy software with little or no traditional coding experience. A new investigation by Israeli cybersecurity firm Red Access found roughly 380,000 publicly accessible assets created with AI-powered coding tools such as Lovable, Replit, Netlify, and Base44. According to the researchers, about 5,000 of those apps exposed potentially sensitive information. The findings, reported by Axios, suggest many users are publishing internal tools online without realizing they are publicly accessible. Dor Zvi, CEO of Red Access, said the company uncovered the apps while researching “shadow AI,” where employees use AI tools without formal approval from their organizations.
Original Article

Similar Articles

AI News: A Huge Week for AI Apps (Anthropic, OpenAI, Google)

YouTube AI Channels

OpenAI’s new Codex desktop app combines code generation, browser automation and persistent agents into a single IDE, while Anthropic upgraded Claude Code with parallel sessions and Google launched desktop apps, Chrome slash commands and an expressive TTS model.

AI has another security problem

Lobsters Hottest

Article argues that AI-generated code and closed-source software are inherently less secure, and that LLMs like Anthropic’s Mythos will exacerbate vulnerabilities, making open-source projects the only trustworthy option.

AI News: Anthropic Went Crazy This Week!

YouTube AI Channels

Anthropic launched 74 updates in 52 days including Computer Use, Projects, and Claude Code Auto Mode, while Google countered with Gemini 3.1 Flash Live, vibe-coded browser demos, and Lyria 3 Pro music tools, as GenSpark enters with $20/month unlimited AI through 2026.