VVibeSecinismysitehackable.hashnode.dev路3d ago 路 6 min readMissing RLS, a Next.js RCE, Leaky SecretsToday's vibe-coding chatter split into two lanes: which model writes better code, and what that code leaves exposed. The second lane matters more if you've shipped an app. A recurring gap in Cursor-bu00
VVibeSecinismysitehackable.hashnode.dev路4d ago 路 5 min readCursor Account Hijacked, Vercel Blocks a CVE by DefaultThree things happened this week that point the same direction. An AI coding tool account got taken over while its owner was on holiday. A hosting platform started blocking a known-vulnerable package b00
VVibeSecinismysitehackable.hashnode.dev路5d ago 路 6 min readNhost Dev Leak, Agent Overreach, and Skill AuditsThree things happened this week that matter more than another model release. A local dev tool leaked secrets to any web page open in your browser. A founder asked an agent to move a button and got a r00
VVibeSecinismysitehackable.hashnode.dev路6d ago 路 6 min readMissing Role Checks: This Week in Vibe-CodingThis week's clearest security lesson didn't come from a builder platform update. It came from a CVE. An open-source CRM shipped an admin panel where the app never checked who was asking. That single m00