Fetching from the wire…
Top 5 · 2026-03-11 · source-backed
The man who coined "vibe coding" a year ago now declares it passe and introduces "agentic engineering" — the discipline of orchestrating AI agents that plan, write, test, and ship code under structured human oversight. The timing isn't accidental. Escape.tech released the largest vibe-coding security study ever: 2,000+ vulnerabilities, 400+ exposed secrets, and 175 PII instances across 5,600+ production vibe-coded apps on Lovable, Base44, Create.xyz, and others. Every vulnerability was in live production. Meanwhile, Meta acquired Moltbook — whose founder proudly "didn't write one line of code" — only for researchers to discover its Supabase credentials were public, exposing 1.5M API keys. The message is clear: vibe coding shipped fast but created an ocean of security debt. The industry now needs engineering discipline, not vibes. The New Stack | Escape.tech
Each link below shares sources, entities, or timing with this story.
Wiz disclosed that Moltbook, a social network for AI agents, exposed 1.5M API authentication tokens, 35,000 email addresses, and private agent messages through a misconfigured Supabase database. The vulnerability: a Supabase API key exposed in client-side JavaScript granting f...
Willison's framing has settled into a real split: vibe coding (intent-first, accept-without-reading, optimized for speed with Lovable/Bolt/v0) versus agentic engineering (correctness-first, Claude Code/Aider/Cline under structured oversight). The tell is process. Spec-driven S...
Security researcher @weezerOSINT demonstrated that any free Lovable account could access other users' source code, database credentials, AI chat histories, and customer data via a Broken Object Level Authorization (BOLA) flaw. Every project created before November 2025 was exp...
A GitHub repo cataloging Claude Code tips doesn't normally warrant a top story. But shanraisshan/claude-code-best-practice at 53.4K stars isn't a tips list anymore. It's the de facto reference for how an entire generation of developers is learning to work with AI coding agents...
Of 53 tracked agentic projects, 28 are coding agents, and the five fastest-growing tools, Claude Code, Gemini CLI, Codex, Cline, and Aider, are all in that category (Help Net Security). Security advisories cluster around n8n (57), Claude Code (22), AutoGPT (15), Dify (13), and...
I've been saying for months that the missing piece in agentic coding isn't smarter models. It's that agents can't provision anything. They can write code all day but the moment they need a database, an auth provider, or a hosting account, a human has to step in, click through...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.