RELEASE NOTES & SECURITY REPORTS

Free scanners, vulnerability reports, and platform-specific guidance. No fluff.

After Testing Every Major LLM, None Ship Validation That Survives the First Pass
2026.05.02 · 7 MIN READ · We tested Claude Sonnet 4.5, GPT-5, Gemini 2.5, Cursor, Lovable, Bolt, and Replit. None produce input validation that survives a red-team …
SCANNER
Vibe Coding Security Weekly — Apr 30, 2026: Apple Blocks Vibe-Coding Updates, Claude Code Source-Map Leak, Lovable Goes Mobile
2026.04.30 · 5 MIN READ · Three days in vibe-coding security: Apple blocks Replit and Vibecode App Store updates over post-approval code changes, Anthropic ships full …
SCANNER
Lovable Security Report April 2026: 380K Apps Scanned, 5K Leaking, 5 Brands Phished on Lovable's Domain
2026.04.30 · 8 MIN READ · April 2026 was the month Lovable's exposure landscape went mainstream. RedAccess scanned 380,000 vibe-coded apps across Lovable, Base44, …
SCANNER
Vibe Coding Security Weekly — Apr 28, 2026: Wiz Red Agent, SecureVibeBench, Red Gate's DB Failure Patterns
2026.04.28 · 6 MIN READ · Five days of vibe-coding security stories: Wiz launches Red Agent and AI-BOM at Google Cloud Next, SecureVibeBench numbers the AI …
SCANNER
Vibe Coding Security Weekly — Apr 23, 2026: Lovable 48-Day Leak, Anthropic MCP RCE, Gitar Launch
2026.04.23 · 6 MIN READ · Seven days of vibe-coding security stories in one place: Lovable's 48-day chat exposure, Anthropic's MCP RCE affecting 200,000+ servers, …
SCANNER
Your CLAUDE.md Is Attack Surface: Snyk ToxicSkills + MCP Prompt Injection
2026.04.20 · 4 MIN READ · Snyk scanned 3,984 agent skills and found critical issues in 13.4% of them, with 76 confirmed malicious. A March 2026 arXiv paper tested MCP …
SCANNER
When Beauty Bloggers Explain RLS, Vibe Coding Is Baseline
2026.04.20 · 3 MIN READ · A Japanese beauty blogger shipped a real app with Claude Code in 2026 — and her post includes a whole section teaching Supabase Row-Level …
SCANNER
Vercel Breach via Context.ai: Your AI Stack Is Now Your Supply Chain
2026.04.20 · 3 MIN READ · Vercel confirmed a breach that started with a third-party AI tool an employee used. Attackers pivoted from Context.ai to Google Workspace to …
SCANNER
Prompt Injection Turns AI Coding Agents Into Key Exfiltrators
2026.04.20 · 3 MIN READ · Researchers prompt-injected AI coding agents from Anthropic, Google, and Microsoft running inside GitHub Actions and exfiltrated API keys …
SCANNER
Lovable BOLA: The $6.6B Vibe-Coding Platform Just Got Vibe-Coded
2026.04.20 · 4 MIN READ · Researcher discloses a Broken Object Level Authorization flaw on Lovable: change a project ID in the URL, free account, pull anyone's full …
SCANNER
Kiro IDE: Vibe-Coding Fix or Compliance Gate in AI Cosplay?
2026.04.20 · 3 MIN READ · Kiro IDE's pitch is docs-first AI coding with automated security scans on every save. On paper it kills vibe-coding mistakes. In practice it …
SCANNER
DeepKeep Launches Vibe AI Red Teaming. Red Teaming Is Now Vibe-ified.
2026.04.20 · 3 MIN READ · DeepKeep shipped Vibe AI Red Teaming: human-in-the-loop attacks on AI apps and agents, with natural-language steering. CTO says it's 'the …
SCANNER