VVibeSecinismysitehackable.hashnode.devยท2d ago ยท 6 min read4 NextAuth Bugs, 1 Budibase Leak: This Week's Real RiskThree new frontier coding models shipped this week and Reddit is busy arguing about Grok 4.6 versus GPT Sol. None of that changes your risk. What does: four disclosed flaws in NextAuth.js, the auth li00
VVibeSecinismysitehackable.hashnode.devยท3d ago ยท 5 min readWho Cleans Up the Mess?Today's signals point the same direction: the vibe-coding world is scaling faster than it's securing itself. A $400M funding round, a mainstream press piece asking who fixes what AI builders leave beh00
VVibeSecinismysitehackable.hashnode.devยท4d ago ยท 6 min readWhat 1,969 Lovable Apps RevealA community researcher scanned nearly 2,000 public Lovable apps this week and found real secrets sitting in the open โ not the anon keys that are supposed to be public, but committed .env files and ha00
VVibeSecinismysitehackable.hashnode.devยท5d ago ยท 5 min readAI Agents Get More Autonomy, Platforms Add GuardrailsAI coding agents got more autonomous by default, and the platforms underneath them started building the containment layer to match. Neither is a breach. Both change what "secure" means for an app you 00
VVibeSecinismysitehackable.hashnode.devยท6d ago ยท 5 min readSupabase MCP Flaw & Vercel's New Security DashboardTwo things happened this week that matter more than they look. A third-party MCP tool that lets AI coding agents talk to Supabase has an unpatched command injection bug. And Vercel just admitted, in i00