< Back to all clusters
[TECHNOLOGY] · 4 sources

started · updated

AI-Generated Code Spurs Surge in Software Vulnerabilities

Researchers tracking the Vibe Security Radar project reported that 74 software vulnerabilities were directly linked to code produced by artificial‑intelligence tools over a three‑month period in early 2026 – 6 in January, 15 in February and 35 in March. The study warns that the rapid adoption of "vibe coding," where developers describe desired functionality in natural language and let large language models generate the code, is delivering code three to four times faster but with a proportional rise in security flaws such as SQL injection, XSS, hard‑coded secrets and weak cryptography.

The report also highlights new supply‑chain attack vectors: AI‑generated code frequently references non‑existent packages, enabling "slopsquatting" attacks, and AI coding assistants themselves have been compromised, as seen in incidents affecting Amazon Q Developer, Cursor and GitHub Copilot. Adoption rates of AI coding agents in public repositories are estimated between 15.8% and 22.6%, indicating a structural shift in software development that brings governance, quality‑control and security oversight to the forefront.