Related Threat Clusters
-
Vibe-Coded Apps Expose Sensitive Data on Open Web
Recent research revealed that over 5,000 vibe-coded applications, created using platforms like Lovable and Base44, exposed sensitive corporate and personal data. The cybersecurity firm RedAccess found that approximately…
7 articles · Updated May 9, 2026 -
API Flaw in Lovable AI App Builder Exposes Sensitive Data of Thousands
A critical Broken Object Level Authorization (BOLA) vulnerability in Lovable, an AI-powered app builder, has been reported, allowing unauthorized access to sensitive project data. This flaw affects thousands of projects…
2 articles · Updated April 21, 2026 -
Lovable Faces Backlash Over Data Exposure Due to BOLA Vulnerability
Lovable, a vibe-coding platform, is under scrutiny after a researcher revealed a significant data exposure issue affecting all projects created before November 2025. The researcher, known as @weezerOSINT, demonstrated…
6 articles · Updated April 21, 2026 -
Insurance Phishing Campaigns Evolve into Account Hijacking Threats
CTM360's research reveals a significant evolution in phishing tactics targeting insurance sectors, where attackers now employ real-time account hijacking methods. In a simulation involving 13.9 million phishing…
2 articles · Updated July 25, 2026 -
Rise in Infostealer Attacks Targeting Enterprise SSO Credentials
Infostealer malware is increasingly exposing enterprise identity credentials, with 16% of infections involving Single Sign-On or identity provider details, according to Flare's analysis of 18.7 million logs from 2025. A…
97 articles · Updated February 4, 2026 -
Lovable Platform Hosts Vulnerable App Exposing 18,000 Users' Data
Vibe-coding platform Lovable has been implicated in hosting an app with 16 vulnerabilities, including six critical ones, discovered by tech entrepreneur Taimur Khan. The vulnerabilities led to the exposure of personal…
2 articles · Updated February 27, 2026 -
Exploiting Personal Digital Footprints for Scams
Organizations are facing risks as employees maintain personal digital presences outside enterprise security. These personal accounts, including email and social media, are vulnerable to exploitation, leading to…
1 article · Updated February 24, 2026
Recent Intelligence Reports
- Go 430850 — unsafe.sh · July 26, 2026
- 5,000 vibe-coded apps just proved shadow AI is the new S3 bucket crisis — Venturebeat · May 9, 2026
- Thousands of Vibe — Rss.Slashdot · May 8, 2026
- Hot startup Lovable's security stumble shows one big risk in using AI to code — Businessinsider · April 21, 2026
- Lovable left thousands of projects exposed for 48 days, and the vibe coding security crisis is ... — Thenextweb · April 21, 2026
- Lovable goes on ego trip denying vulnerability, then blames others for said vulnerability — Cybernews · April 21, 2026
- Lovable denies data leak, cites 'intentional behavior' — Theregister · April 21, 2026
- Lovable AI App Builder Hit by Reported API Flaw Exposing Thousands of Projects — Gbhackers · April 21, 2026