Matt Palmer's scan found 170 of 1,645 Lovable showcase apps leaking data through inadequate Row Level Security, the same kind of gap Wiz found at Moltbook. Before launch, an AI-built app needs a review that tests the database rules behind its public key.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap0
- Incentives35
- Confidence55
Wiz says its Red Agent found and exploited a GitHub Actions injection that an AI "autofix" commit introduced five days earlier, reaching Snowflake's internal Jira with no human in the loop.
Perspective Coverage
4 publishers
- Builder
- Builder 43%
- Operator
- Operator 42%
- Investor
- Investor 15%
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+35
- Incentives70
- Confidence62
Fabian Hedin, Lovable's CTO, said two-thirds of the Fortune 500 use the tool because staff found it themselves, and put current revenue at $600m. The permissions work starts after the apps are running.
Reality
- Evidence32
- Adoption52
- Hype gap+36
- Incentives82
- Confidence46
A dev.to post lists seven defect patterns in AI-generated code, and the one its author calls most distinctly AI-flavored is a dropped auth middleware that only shows up when you compare a route to its siblings.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+15
- Incentives60
- Confidence45
Kaspersky's Q2 2026 figures credit AI with both writing the bugs and finding them. The disclosures carrying working exploit code never got a CVE identifier at all.
Reality
- Evidence48
- Adoption44
- Hype gap+30
- Incentives66
- Confidence45
Two 2026 studies put AI-generated deployment infrastructure at worse than a coin flip, and the gates most CI pipelines run were built for application source, not config.
Reality
- Evidence58
- Adoption52
- Hype gap+12
- Incentives66
- Confidence57
Eleven real vulnerabilities in roughly 300 pull requests over four months. The noise was bad enough that the fix was a second agent whose only job is refuting the first.
Reality
- Evidence34
- Adoption11
- Hype gap+16
- Incentives44
- Confidence38
Veracode ran more than 150 models over 80 tasks and found 45% of the output carries a known weakness. The level is bad; the flat two-year trend is the part that changes your plan.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+25
- Incentives78
- Confidence48
An account published on dev.to says Copilot Autofix stripped input sanitization from a Snowflake workflow, and an autonomous offensive agent exploited it inside a week.
Reality
- Evidence18
- Adoption
- Insufficient
- Hype gap+58
- Incentives62
- Confidence20
Anthropic says an AI agent did 80% to 90% of the work in a campaign against roughly 30 companies. CrowdStrike puts average breakout time at 29 minutes. Verification cadence is now the control.
Reality
- Evidence34
- Adoption48
- Hype gap+30
- Incentives68
- Confidence38
A Cloudflare engineer argues web apps should let users generate their own missing features. The hard part is not the code generation, it is running that code beside live customer data.
Reality
- Evidence44
- Adoption21
- Hype gap+24
- Incentives68
- Confidence52
A Secure Code Warrior and RMIT study of six frontier models across 11 frameworks found no universal winner and no link between token cost and secure output.
Reality
- Evidence48
- Adoption
- Insufficient
- Hype gap+20
- Incentives68
- Confidence40
An AI editor's remediation for a CWE-78 bug was a shell metacharacter blocklist. The payload git clone ext::sh -c whoami carries none of those characters and runs code anyway.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+18
- Incentives32
- Confidence56