TMCnet News
Sygnia Penetration Test Reveals Critical "vibe coded" Vulnerabilities Within Claude-Based ApplicationSygnia, the world's foremost incident response and cyber readiness team, revealed critical vulnerabilities following a penetration test of a customer onboarding application, developed in Claude, that processed highly sensitive personal and financial information, including government-issued identification, identity verification data, and payment details. Identified by an LLM, the vulnerability enabled low-access privilege users to see critical client personal identification information by not requiring appropriate user verification before issuing or restoring applicant access tokens. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260728834521/en/
LLM analysis highlighting a high-severity vulnerability within a "vibe-coded" application. Investigation findings highlighted a flaw with access token issuance and restoration, where possession of an applicant GUID was treated as sufficient proof to issue an access token. The reason for this flaw was tied to the AI-assisted implementation strategy which featured access tokens, expiration, rate limiting, and logging, but missed the critical pre-issuance question to validate whether the requester is entitled to receive or restore an applicant token. "Working code is not the same as secure code," said Zach Mead, Principal Penetration Tester at Sygnia. "AI-generated code may compile, follow familiar conventions, and pass basic checks, while still making flawed assumptions about trust boundaries, authorization, state, ownership, or third-party integrations. Security teams need to treat AI-generated output as untrusted until validated." Key findings of the penetration test include:
"AI adoption is moving faster than many organizations' ability to govern and secure it," said Ilia Rabinovich, Vice President of Cybersecurity Consulting at Sygnia. "The challenge is not whether enterprises should use AI. They already are. The challenge is whether they understand where AI is being used, what data it can access, how it changes their attack surface, and whether their existing controls are prepared for the risks it introduces." Sygnia's AI Cybersecurity Services address this emerging reality of new pathways for sensitive data exposure, broken authorization logic, unsafe dependencies, and flawed business workflows. Rooted in more than a decade of frontline incident response and cyber readiness experience, the services combine attacker-informed expertise, technical assessment, governance development, application testing, and actionable remediation guidance to help organizations secure AI adoption without slowing innovation. Learn more about Sygnia's AI Cybersecurity Services and read the latest threat research, "Code at AI Speed, Risk at AI Scale." About Sygnia Sygnia is the world's foremost incident response and cyber readiness team. It applies creative approaches and bold solutions to each phase of an organization's security journey, meeting them where they are to ensure cyber resilience. Sygnia is the trusted advisor and service provider of leading organizations worldwide, including Fortune 100 companies. Sygnia is a Temasek company, part of the ISTARI Collective.
View source version on businesswire.com: https://www.businesswire.com/news/home/20260728834521/en/ |

