OSSLovable Vibe-Coded App Exposes 18K Users First Real BreachThe Register·high signalXBlueskyLinkedInCopy link16 vulnerabilities in Lovable-hosted exam platform. 18,697 user records exposed. First major real-world vibe-coded security breach.SourceSource pageThe Register↳ Follow the threadStack layer / Threat patternhumans& Released Persimmon, a 550B User Simulator That Fools LLM Judges About 20% of the Time in Group Chatshumans&Stack layer / Threat patternVibe Coding Cut Task Time 27% and Raised Security Vulnerabilities in the Same TrialarXiv 2609.09560Stack layer / Threat patternCline Desktop 0.0.25 lets Claude Code and Codex CLI providers start sessions with no API key, and caps Codex models at real backend budgetsGitHub ReleasesPolicy dependency / Stack layerCROSS-CATEGORY: Three Independent Agent-Action Gates Shipped in 48 Hours, All Judging the Command Against Stated IntentProduct Hunt, github.com/AGGIB/Stroq and rewarelabs.com (three independent sources; the 72% figure is Reware's own)Threat pattern / ContrastShopify Abandons React Native for Swift and Kotlin, Saying Coding Agents Made Building Twice Cheaper Than Sharing One CodebaseShopify Engineering / Hacker News (1110pts, 804 comments)Stack layer / Threat patternLLM-synthesized CodeQL queries beat baseline query suites by 82% F1 and cost far less than scanning repos with the model directlyarXiv 2609.10412Threat pattern / ContrastDeepSeek Harness CVE-2026-82533 (CVSS 9.4): a sandboxed agent could flip its own session to 'danger-full-access' through the unauthenticated local UIThe Hacker NewsStack layer / Threat patternGoogle's Agent Development Kit for Python Carries a CVSS 10.0 Unauthenticated RCE via Test Session ReplayOffSeq Threat Radar