Shadow IT Is Back - And Vibe Coding Made It 10x Worse
Blog post from Qovery
AI coding tools have emerged as a significant component of Shadow IT, posing risks that extend beyond previous waves of unsanctioned technology use due to their broad OAuth access and ability to execute code. These tools, exemplified by platforms like Claude Code and Copilot, can inadvertently grant unauthorized access to critical infrastructure, as demonstrated by incidents like the Vercel breach and the rapid deletion of databases by AI agents. Rather than banning these tools, the solution lies in integrating them into a governed platform that enforces strict policies, audits actions, and ensures environment separation to mitigate risks. This approach, advocated by platforms like Qovery, emphasizes the importance of adapting security strategies to accommodate the evolving nature of Shadow IT, ensuring that productivity enhancements do not compromise security.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| AI Agents | 12 | 4,942 | 1,264 | 250 | +12% |
| AI Coding Assistant | 10 | 1,798 | 527 | 167 | +21% |
| Kubernetes | 4 | 1,965 | 371 | 106 | -15% |
| Harness engineering | 2 | 185 | 101 | 53 | +13% |
| Developer Experience | 1 | 473 | 283 | 114 | -23% |
| Platform Engineering | 1 | 1,288 | 297 | 83 | +19% |
| Secrets Management | 1 | 2,152 | 360 | 101 | +18% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.