• Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
  • Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
Login
Join Free
Home
Asia
Africa
Europe
Latin America
Middle East
North America
Asia
Africa
Europe
Latin America
Middle East
North America
Asia
Africa
Europe
Latin America
Middle East
North America
Coming Soon
Job Board
Events
Contact Awards
USMC Deception Manual
Login
Join Free
Home Global Operations

RedAccess Finds 5,000 Vibe-Coded Apps Leaking Corporate and Medical Data With No Authentication

  • SOFX Staff Writer
  • May 14, 2026
(BEST-BACKGROUNDS / Shutterstock)
Share on FacebookShare on TwitterLinkedIn

Cybersecurity firm RedAccess identified more than 5,000 web applications built with AI-assisted development platforms Lovable, Replit, Base44, and Netlify carrying no authentication controls, leaving them open to anyone with the correct URL, according to RedAccess research published May 7, 2026.

Of 380,000 publicly accessible assets the firm examined, close to 2,000 appeared to expose genuine private data. WIRED independently verified multiple exposed applications were still live at the time of reporting.

Exposed apps included a hospital’s work assignments with doctor personally identifiable information (PII), a retailer’s chatbot logs with customer names and contact details, cargo records from a shipping company, and corporate strategy presentations. RedAccess cofounder Dor Zvi said researchers also found patient conversations from a children’s long-term care facility and incident response records from a security company.

RedAccess additionally found phishing sites built on Lovable and hosted on the platform’s own domain, impersonating Bank of America, Costco, FedEx, Trader Joe’s, and McDonald’s.

While Replit, Lovable, and Base44 pushed back on the findings, Netlify did not respond to requests for comment. Replit CEO Amjad Masad said on X that “public apps being accessible on the internet is expected behavior.” 

A Lovable spokesperson said “how an app is configured is ultimately the creator’s responsibility.”

Replit launched Security Center 2.0, a vulnerability audit tool for deployed projects, on May 7, the same day WIRED published the findings. The platform did not indicate whether the tool addresses applications already publicly exposed.

Next up in our commitment to security: Security Center 2.0.

We’ve made it dramatically easier to understand your security posture across every Replit app you manage, and take action across all of them in bulk.

With Security Center 2.0, you can:
– Instantly identify risky apps
-… pic.twitter.com/hCuyn0hi7w

— Replit ⠕ (@Replit) May 7, 2026


Zvi compared the pattern to the wave of misconfigured Amazon S3 storage buckets that previously left data from companies including Verizon accessible on the open web. “Anyone from your company at any moment can generate an app, and this is not going through any development cycle or any security check,” he said. “People can just start using it in production without asking anyone. And they do.”

SOFX Staff Writer

SOFX Staff Writer

The Editor Staff at SOFX comprises a diverse, global team of dedicated staff writers and skilled freelancers. Together, they form the backbone of our reporting and content creation.

Subscribe
Login
Notify of
guest
guest
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
ADVERTISEMENT

Trending News

BBC Investigation Exposes Smart Glasses Filming Scheme With Pay-to-Remove Footage Demand

BBC Investigation Exposes Smart Glasses Filming Scheme With Pay-to-Remove Footage Demand

by SOFX Staff Writer
May 8, 2026
0

A London woman was covertly filmed through smart glasses in a shopping centre, had the footage viewed approximately 40,000 times...

Pentagon Releases 162 Declassified UFO Files Spanning 1942 to 2025

Pentagon Releases 162 Declassified UFO Files Spanning 1942 to 2025

by SOFX Staff Writer
May 9, 2026
1

The Department of War published 162 declassified files on unidentified anomalous phenomena Friday, launching a dedicated government website and kicking...

CNN Alleges That CIA Carried Out Car Bombing Near Mexico City Targeting Sinaloa Cartel Operative

CNN Alleges That CIA Carried Out Car Bombing Near Mexico City Targeting Sinaloa Cartel Operative

by SOFX Staff Writer
May 13, 2026
3

The CIA has significantly expanded covert operations targeting Mexican drug cartels, including actions that allegedly involved direct participation in deadly...

Super Hornets Drops Precision Bombs Down Smokestacks of Iranian Tankers

Super Hornets Drops Precision Bombs Down Smokestacks of Iranian Tankers

by SOFX Staff Writer
May 9, 2026
1

A U.S. Navy F/A-18 Super Hornet fired precision munitions down the smokestacks of two Iranian-flagged oil tankers Friday, disabling both...

ADVERTISEMENT
ADVERTISEMENT
Next Post
Arcadia Mayor Eileen Wang Pleads Guilty to Acting as Illegal Agent for China

Arcadia Mayor Eileen Wang Pleads Guilty to Acting as Illegal Agent for China

Navy Confirms Trump-Class Battleship Is Nuclear-Powered via Carrier’s A1B Reactor

Navy Confirms Trump-Class Battleship Is Nuclear-Powered via Carrier's A1B Reactor

997 Morrison Dr. Suite 200, Charleston, SC 29403

News

  • Global Operations
  • Special Interest
  • Industry
  • Global Operations
  • Special Interest
  • Industry

Resources

  • About Us
  • Contact Us
  • Advertise with Us
  • Editorial Policy
  • Privacy Policy
  • About Us
  • Contact Us
  • Advertise with Us
  • Editorial Policy
  • Privacy Policy
No Result
View All Result
  • Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
Subscribe
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.

Log in to your account

Lost your password?
wpDiscuz