Thousands of Vibe-Coded Apps Expose Corporate and Personal Data On the Open Web [Slashdot]
An anonymous reader quotes a report from Wired: Security researcher Dor Zvi and his team at the cybersecurity firm he cofounded, RedAccess, analyzed thousands of vibe-coded web applications created using the AI software development tools Lovable, Replit, Base44, and Netlify and found more than 5,000 of them that had virtually no security or authentication of any kind. Many of these web apps allowed anyone who merely finds their web URL to access the apps and their data. Others had only trivial barriers to that access, such as requiring that a visitor sign in with any email address. Around 40 percent of the apps exposed sensitive data, Zvi says, including medical information, financial data, corporate presentations, and strategy documents, as well as detailed logs of customer conversations with chatbots. "The end result is that organizations are actually leaking private data through vibe-coding applications," says Zvi. "This is one of the biggest events ever where people are exposing corporate or other sensitive information to anyone in the world." Zvi says RedAccess' scouring for vulnerable web apps was surprisingly easy. Lovable, Replit, Base44, and Netlify all allow users to host their web apps on those AI companies' own domains, rather than the users'. So the researchers used straightforward Google and Bing searches for those AI companies' domains combined with other search terms to identify thousands of apps that had been vibe coded with the companies' tools. Of the 5,000 AI-coded apps that Zvi says were left publicly accessible to anyone who simply typed their URLs into a browser, he found close to 2,000 that, upon closer inspection, seemed to reveal private data: Screenshots of web apps he shared with WIRED -- several of which WIRED verified were still online and exposed -- showed what appeared to be a hospital's work assignments with the personally identifiable information of doctors, a company's detailed ad purchasing information, what appeared to be another firm's go-to-market strategy presentation, a retailer's full logs of its chatbot's conversations with customers, including the customers' full names and contact information, a shipping firm's cargo records, and assorted sales and financial records from a variety of other companies. In some cases, Zvi says, he found that the exposed apps would have allowed him to gain administrative privileges over systems and even remove other administrators. In the case of Lovable, Zvi says he also found numerous examples of phishing sites that impersonated major corporations, including Bank of America, Costco, FedEx, Trader Joe's, and McDonald's, that appeared to have been created with the AI coding tool and hosted on Lovable's domain. "Anyone from your company at any moment can generate an app, and this is not going through any development cycle or any security check," Zvi says. "People can just start using it in production without asking anyone. And they do."
Read more of this story at Slashdot.
Elon Musk faces criminal probe in France after ignoring summons in X case [Ars Technica - All content]
French prosecutors yesterday opened a criminal investigation into Elon Musk and X, escalating a probe into sexual images of minors and other alleged illegal content on Musk's social network.
The action came three months after French law enforcement authorities raided X’s Paris office and summoned Musk for questioning. Prosecutors wanted to interview Musk and former X CEO Linda Yaccarino in April, but they did not appear.
The earlier request to interview Musk and Yaccarino was described as voluntary. Authorities are now seeking to compel them to appear for questioning with the threat of criminal charges. In addition to sexual images of minors, the investigation involves Grok's dissemination of Holocaust-denial claims and sexually explicit deepfakes.
Chrome's 4GB AI model isn't new, but you're not wrong for being confused [Ars Technica - All content]
All of Google's products have been getting more AI features, including Chrome, which now offers split-screen Gemini chatbot support, the ability to automate web browsing, and more. Some desktop Chrome users have also noted that the browser appears to suddenly want more storage space for AI. This is true—Chrome does download a 4GB AI model for on-device processing. It's been doing that for years, though.
Google hasn't actually changed anything about Chrome's on-device AI, but the confusion is understandable, as the company has done a poor job of explaining what it's doing and why. This is, unfortunately, par for the course with Google's AI efforts.
Just this week, someone noticed that Chrome had downloaded a 4GB Gemini Nano model and inferred from its sudden appearance that Google was deploying that AI on all Chrome installs right now. That's not exactly true. Google announced in 2024 that it would begin adding local AI capabilities to Chrome, powering features like Help Me Write, tab organization, and scam detection.
UFO files spanning decades are released by Defense Department [NPR Topics: News]

Cold War reports of mysterious rotating saucers; recent sightings of metallic elliptical objects floating in mid-air. Those and other reports of unidentified anomalous phenomena or UAPs — the military's term for UFOs — are described in documents released Friday.
(Image credit: NASA)
Canvas is back online, but questions — and final exam disruptions — linger [NPR Topics: News]

Some schools are warning users not to log back into Canvas yet, after a ransomware group claimed credit for a data breach. Half of North America's higher education institutions use the platform.
(Image credit: Michael Warren)
Pentagon Begins Releasing New Files On UFOs [Slashdot]
The Pentagon has begun releasing new UFO/UAP files through a newly launched public website, starting with 162 documents from agencies including the FBI, State Department, NASA, and others. Officials say more files will be released on a rolling basis. The Associated Press reports: The Pentagon has begun releasing new files on UFOs, saying members of the public can draw their own conclusions on "unidentified anomalous phenomena" like an object that a drone pilot says shone a bright light in the sky and then vanished. It said in a post on X on Friday that while past administrations sought to discredit or dissuade the American people, President Donald Trump "is focused on providing maximum transparency to the public, who can ultimately make up their own minds about the information contained in these files." It said additional documents will be released on a rolling basis. Besides the Pentagon, the effort is led by the White House, the director of national intelligence, the Energy Department, NASA and the FBI. A newly unveiled website housing the documents on unidentified anomalous phenomena, or UAPs, has a decidedly retro feel, with black-and-white military imagery of flying objects displayed prominently on the page, with statements displayed in typewriter-like font. The first release includes 162 files, such as old State Department cables, FBI documents and transcripts from NASA of crewed flights into space. One document details an FBI interview with someone identified as a drone pilot who, in September 2023, reported seeing a "linear object" with a light bright enough to "see bands within the light" in the sky. "The object was visible for five to ten seconds and then the light went out and the object vanished," according to the FBI interview. Another file is a NASA photograph from the Apollo 17 mission in 1972, showing three dots in a triangular formation. The Pentagon says in an accompanying caption that "there is no consensus about the nature of the anomaly" but that a new, preliminary analysis indicated that it could be a "physical object."
Read more of this story at Slashdot.
Apple, Intel Have Reached Preliminary Chip-Making Agreement [Slashdot]
Apple and Intel have reportedly reached a preliminary agreement (paywalled; alternative source) for Intel to manufacture some chips used in Apple devices, after more than a year of talks and pressure from the Trump administration. It's still unclear which Apple products would use Intel-made chips, but the deal would mark a major potential win for Intel's foundry ambitions and give Apple another manufacturing option beyond TSMC.
Read more of this story at Slashdot.
| Feed | RSS | Last fetched | Next fetched after |
|---|---|---|---|
| 0xADADA | XML | 04:00, Sunday, 10 May | 12:00, Sunday, 10 May |
| AI Daily News by Bush Bush | XML | 06:00, Sunday, 10 May | 18:00, Sunday, 10 May |
| Ars Technica - All content | XML | 09:00, Sunday, 10 May | 10:00, Sunday, 10 May |
| art blog - miromi | XML | 04:00, Sunday, 10 May | 12:00, Sunday, 10 May |
| Astral Codex Ten | XML | 04:00, Sunday, 10 May | 12:00, Sunday, 10 May |
| Blog - Ethan Zuckerman | XML | 04:00, Sunday, 10 May | 12:00, Sunday, 10 May |
| Cool Tools | XML | 09:00, Sunday, 10 May | 10:00, Sunday, 10 May |
| Explorations of Style | XML | 09:00, Saturday, 09 May | 09:00, Sunday, 10 May |
| Geek&Poke | XML | 06:00, Sunday, 10 May | 18:00, Sunday, 10 May |
| goatee | XML | 05:00, Sunday, 10 May | 11:00, Sunday, 10 May |
| Hacker News | XML | 09:00, Sunday, 10 May | 10:00, Sunday, 10 May |
| IDEAS | Matt Nisbet | XML | 04:00, Sunday, 10 May | 12:00, Sunday, 10 May |
| Joho the Blog | XML | 04:00, Sunday, 10 May | 12:00, Sunday, 10 May |
| LESSIG Blog | XML | 06:00, Sunday, 10 May | 18:00, Sunday, 10 May |
| Notes From the North Country | XML | 09:00, Saturday, 09 May | 09:00, Sunday, 10 May |
| NPR Topics: News | XML | 09:00, Sunday, 10 May | 10:00, Sunday, 10 May |
| Pharyngula | XML | 05:00, Sunday, 10 May | 11:00, Sunday, 10 May |
| Philip Greenspun’s Weblog | XML | 09:00, Sunday, 10 May | 11:00, Sunday, 10 May |
| Philosophical Disquisitions | XML | 09:00, Sunday, 10 May | 11:00, Sunday, 10 May |
| quarlo | XML | 06:00, Sunday, 10 May | 18:00, Sunday, 10 May |
| Rhetorica | XML | 05:00, Saturday, 09 May | 05:00, Monday, 11 May |
| Science-Based Medicine | XML | 04:00, Sunday, 10 May | 12:00, Sunday, 10 May |
| Slashdot | XML | 09:00, Sunday, 10 May | 09:30, Sunday, 10 May |
| Stories by Yonatan Zunger on Medium | XML | 04:00, Sunday, 10 May | 12:00, Sunday, 10 May |
| Study Hacks - Decoding Patterns of Success - Cal Newport | XML | 04:00, Sunday, 10 May | 12:00, Sunday, 10 May |
| tinywords | XML | 06:00, Sunday, 10 May | 10:00, Sunday, 10 May |
| W3C - News | XML | 09:00, Sunday, 10 May | 10:00, Sunday, 10 May |