Vibe-coded apps are the new shadow IT
The New Stack Andy Gombar
Vibe-coded internal tools are creating a new form of shadow IT that bypasses OAuth logs by deploying infrastructure directly into cloud accounts. The risk described peaks when a misconfigured app runs for 6 weeks before CSPM flags a public endpoint tied to an over-permissioned IAM role. Webflow argues security must shift from detection-focused playbooks toward an enforced baseline (platform and process controls) plus review and behavioral telemetry before CSPM findings.
Why it matters
Shadow IT used to be a SaaS problem. Someone on the marketing team signed up for a tool, connected it The post Vibe-coded apps are the new shadow IT appeared first on The New Stack.