A recent study by Israeli cybersecurity firm RedAccess uncovered over 380,000 publicly accessible apps and databases created with popular vibe coding platforms like Lovable, Base44, and Replit, along with Netlify’s deployment service. Alarmingly, around 5,000 of these assets exposed sensitive corporate data, including shipping schedules, healthcare trial details, customer conversations, and financial records. The root cause lies in default settings that leave these applications public unless manually secured, resulting in Google indexing many such tools.
This issue is emblematic of a larger shadow AI problem, where employee-built AI-powered applications bypass traditional security reviews, increasing breach risks and regulatory exposure. Research from Escape.tech and Gartner highlights numerous security flaws and forecasts soaring defect rates in AI-generated citizen-developed apps. Furthermore, IBM’s 2025 report links significant breach costs and privacy lapses to shadow AI implementations, with a majority lacking formal AI governance.
To tackle this emerging threat, CISOs are urged to implement automated scans for vibe-coded applications, enforce authentication, integrate app security scans, extend data loss prevention policies, and introduce AI governance frameworks with strict pre-deployment reviews. Without proactive measures, organizations risk data leaks, costly breaches, and regulatory penalties as shadow AI proliferates beyond IT oversight.