Multiple studies and industry reports found that AI-generated or "vibe-coded" software is frequently shipped with serious security flaws, including XSS, SQL injection, hardcoded secrets, unsafe eval usage, weak authentication logic, wildcard CORS, exposed .env data, and insecure dependencies. One analysis of 5,600 publicly accessible AI-built applications reported more than 2,000 high-risk vulnerabilities and over 400 exposed secrets, while a separate review of 549 self-described AI-generated repositories found widespread committed secrets, injection issues, hardcoded passwords, and other common sanitization failures. Veracode and other researchers similarly warned that code produced by large language models often maps to OWASP Top 10 weakness classes and that repeated AI-assisted edits, poor prompts, and excessive agent permissions can further increase risk.
At the same time, researchers and vendors highlighted both the promise and fragility of AI-assisted security tooling. Trail of Bits reported that OpenAI Codex goal-based prompting helped uncover previously unknown bugs in projects including Rust, curl, zlib, and Keycloak, but stressed that human experts were still needed to scope goals, validate findings, and handle disclosure. New academic work also showed that LLM-based vulnerability detectors can be easily misled: the ALIBI framework used adversarial code comments to evade four detectors with success rates above 90%. In response to growing concern over agent reliability, Amazon backed the Lean language project to strengthen formal verification for AI agents, while security experts argued that theorem proving can improve assurance for high-risk components but should be applied selectively as part of broader defense-in-depth.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Amazon announced on 26 July that it would provide substantial long-term financial support to the Lean Focused Research Organization, citing Lean's strategic importance for AI agent safety and formal verification. The company also said it already uses Lean-based verification in Bedrock AgentCore, AWS Clean Rooms' SampCert, AWS Neuron, and Aurora protocol verification.
A researcher published an r/netsec analysis of 549 self-described AI-generated repositories, after initially considering 577 and excluding 28 for size or availability. The study reported frequent issues including committed secrets, high-severity findings, injection-related problems, wildcard CORS, and hardcoded passwords, and released anonymized per-repository JSONL results.
Trail of Bits disclosed that its /goal-based autonomous bug-hunting workflow used during Patch the Planet found previously unknown issues in projects including Rust, curl, zlib, and Keycloak. The post says some Rust bugs were later patched in Rust 1.98 and that one variant-hunting effort reported nine bugs, three already fixed and merged upstream.
An arXiv paper introduced ALIBI, a black-box attack framework that uses adversarial code comments to evade LLM-based vulnerability detectors. The authors reported over 90% attack success across four detectors when tested on 125 real-world null-pointer dereference vulnerabilities.
Research cited in the source reported that scans of 5,600 publicly accessible AI-generated applications found more than 2,000 high-risk vulnerabilities and over 400 exposed secrets, indicating that roughly one in three projects was publicly deployed with exploitable flaws.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
infoworld.com
Open sourceinfoworld.com
Open sourcethenewstack.io
Open sourcereversinglabs.com
Open sourcereddit.com
Open sourcearxiv.org
Open sourceveracode.com
Open sourcecodeby.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.