What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Red Access identified over 380,000 publicly accessible web assets on leading vibe‑coding platforms.
- Corporate‑focused apps—about 5,000 in total—included more than 2,000 that exposed sensitive operational or personal data with default admin access on the open internet.
- Non‑developer users built and deployed these applications via AI‑driven “vibe‑coding” tools, linking them directly to production systems (CRMs, ERPs, ticketing, BI) and often publishing them without any access controls.
- Security tools such as EDR, DLP, and CASB failed to detect the risk because they monitor the underlying platform, not the custom‑built apps that sit on public URLs.
- Axios, WIRED and VentureBeat reported on the Shadow Builders investigation in May, highlighting the scale of the exposure across six continents and every industry.
Why it matters: Enterprises lose control of sensitive data as over 2,000 AI‑built apps expose corporate info, while attackers gain free footholds; traditional security tools miss these exposures.




