OSSLovable Vibe-Coded App Exposes 18K Users First Real BreachThe Register·high signalXBlueskyLinkedInCopy link16 vulnerabilities in Lovable-hosted exam platform. 18,697 user records exposed. First major real-world vibe-coded security breach.SourceSource pageThe Register↳ Follow the threadPolicy dependency / Stack layerPython's Import Statement Is an Execution Boundary: 90% of Initialization-Activated Advisory Vulnerabilities Are High or CriticalarXiv 2609.14791Stack layer / Threat patternArchestra platform 1.4.0-beta.8 switches to native Claude Code sign-in for personal subscriptions and exposes durable runtime health metricsGitHubPolicy dependency / Threat patternA Fine-Tuned RoBERTa-Large Permission Gate Matches Claude Haiku 4.5 at Deciding What an Agent May ToucharXiv 2609.15422Stack layer / Threat patternCline Leaves the IDE: a Standalone Desktop Agent That Imports Claude Code and Codex Sessions and Schedules Recurring PR ReviewsCline GitHub releases (launch reported by RuntimeWire, version cadence verified on the repo)Stack layer / Threat patternArchestra wires OpenAPPA guardrail checks into its LLM proxy checkpoints behind a feature flagGitHubStack layer / Threat patternvLLM's Rust frontend stops returning 404 to RL weight-sync clientsGitHubPolicy dependency / Stack layerRIPPLE: an edit confined to one prompt-policy segment changes downstream behavior, so replay candidate edits after previously accepted ones before persistingarXiv 2609.12127Stack layer / Threat patternA six-year backend dev's case that the vibe-coding market corrects hard, and r/SaaS mostly agreedr/SaaS (153 upvotes, 136 comments)