Vibe coded apps are the new shadow IT
Blog post from Webflow
AI-assisted “vibe coding” is shifting shadow IT from unauthorized SaaS services to internally built applications and cloud infrastructure that legitimate employees can deploy rapidly without formal security review, often with unintended exposure such as public endpoints, excessive IAM permissions, hardcoded secrets, or production-data access. Unlike SaaS sprawl, these tools operate within corporate cloud environments and may evade conventional detection methods based on OAuth, SSO, procurement, or asset inventories. The proposed response combines preventive platform controls, including least-privilege IAM guardrails, enforced secrets management, and VPN-default deployment targets, with risk-tiered process controls such as automated baseline checks and security-informed peer or formal reviews. CSPM tools remain valuable for identifying deployed misconfigurations, while cloud telemetry can help identify anomalous activity such as direct production API calls or untracked public resources. Embedding security baselines into AI-native development tools and onboarding processes is presented as a way to make secure practices accessible without broadly slowing engineering, with responsibility distributed between platform security teams, peer reviewers, and formal security escalation for higher-risk systems.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| AI Agents | 3 | 5,780 | 1,243 | 245 | -15% |
| Secrets Management | 2 | 2,244 | 480 | 132 | -13% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.