Advertisement ยท 728 ร— 90

Posts by Simone

Lovable AI App Builder Reportedly Exposes Thousands of Projects Data via API Flaw A critical Broken Object Level Authorization (BOLA) vulnerability in Lovable, the popular AI-powered app builder platform, is reportedly allowing unauthorized users to access sensitive project data, including source code, database credentials, AI chat histories, and real customer information from thousands of projects created before November 2025. The flaw, classified as a Broken Object Level Authorization issue, allows any free-tier Lovable account holder to make unauthenticated API calls to the platformโ€™s backend and retrieve project data belonging to other users. BOLA vulnerabilities occur when an API grants access to objects without verifying whether the requesting user actually owns or has permission to view them. This class of flaw is ranked #1 in the OWASP API Security Top 10 for its prevalence and ease of exploitation. According to a researcher with the handle @weezerOSINT, the API endpoint https://api.lovable.dev/GetProjectMessagesOutputBody appears to return full project message histories, AI thinking logs, and tool-use records without enforcing proper object-level access controls. The exposed JSON responses contain user IDs, session content, and internal AI reasoning chains that were never intended to be publicly accessible. The vulnerability was reported to Lovable via HackerOne approximately 48 days before public disclosure, yet the flaw reportedly remains unpatched for projects created prior to November 2025. Lovable has a mass data breach affecting every project created before november 2025. I made a lovable account today and was able to access another users source code, database credentials, AI chat histories, and customer data are all readable by any free account. nvidia,โ€ฆ pic.twitter.com/QcVvz9cNZl โ€” impulsive (@weezerOSINT) April 20, 2026 While Lovable appears to have applied a fix for newly created projects, the legacy project base remains exposed, leaving a significant risk window for users who built applications on the platform before the cutoff date. Researchers examining the vulnerability uncovered particularly alarming examples. One affected project belonged to Connected Women in AI, a nonprofit organization, and reportedly contained exposed Supabase database credentials alongside real user data. Among the data found were records linked to individuals from Accenture Denmark and Copenhagen Business School. Beyond nonprofit exposure, employees at major technology firms, including Nvidia, Microsoft, Uber, and Spotify, reportedly have Lovable accounts tied to affected projects, raising the potential that sensitive corporate development data could be at risk. The vulnerability was submitted on the HackerOne bug bounty platform and was marked as a duplicate of report #3583821, labeled โ€œBroken Object Level Authorization on Lovable API leads to unauthorized access to user data and project source codeโ€. The duplicate submission was flagged as Informative, suggesting the issue was already known to the platform prior to the latest disclosure on March 3, 2026, yet public evidence continues to show the flaw remains exploitable on legacy accounts. Security researchers recommend that Lovable users who created projects before November 2025 should immediately rotate any API keys, database credentials, or secrets stored within those projects. Users should assume that chat histories and source code associated with older projects may have already been accessed. The incident underscores a recurring challenge in AI-native development platforms: security controls often lag behind rapid feature deployment, leaving early adopters most exposed. Organizations building production applications on low-code AI builders should enforce secrets management practices independent of the platform, and regularly audit API exposure for any sensitive credentials embedded in project repositories or chat contexts. Follow us on Google News , LinkedIn , and X for daily cybersecurity updates. Contact us to feature your stories. The post Lovable AI App Builder Reportedly Exposes Thousands of Projects Data via API Flaw appeared first on Cyber Security News .

Lovable AI App Builder Reportedly Exposes Thousands of Projects Data via API Flaw

12 hours ago 1 2 0 0
Next.js developer Vercel warns of customer credential compromise Blames outfit called Context.ai, which reckons an agentic OAuth tangle caused the incident Vercel, the company that created the open source Next.js web development framework, has a data leak that led to compromise of some customer credentials, and blamed an outfit called Context.ai for the mess.โ€ฆ

Next.js developer Vercel warns of customer credential compromise

Blames outfit called Context.ai, which reckons an agentic OAuth tangle caused the incident
Vercel, the company that created the open source Next.js web development framework, has a data leak that led to compromise โ€ฆ
#hackernews #news

5 hours ago 1 1 0 0
Post image Post image

๐Ÿšจ The Vercel breach traces back to a Context[.]ai gooner employee infected with Lumma infostealer. The malware harvested his Google Workspace credentials, porn and anime site logins, and the in-game username "lecoonjames" (see profile pic below, he changed the username post-infection, I wonder why).

5 hours ago 2 1 1 0
Post image

#AgentCon #Perth CFP is Open if you want to submit a talk :)

lnkd.in/gcHhiCrm

1 day ago 0 0 0 0

"i can't get enough of this product"

4 days ago 1 0 0 0

ooh this one is cool too @github.com Repository member role labels in the pull request list - Repository member roles, like first-time contributor or collaborator, are now visible directly in the PR list view. This information previously required navigating into each pull request (lnkd.in/eHBfcZ2t)

6 days ago 0 0 0 0
Post image

Github has a bunch of new features today but this one is very cool when you think abut the recent breaches at Trivvy

github.blog/changelog/20...

6 days ago 0 0 1 0

jeez this is dire techcrunch.com/2026/04/13/i...

1 week ago 1 0 0 0
Advertisement

medium.com/the-holistic...

1 week ago 1 0 1 0

็„กๆ–™ใƒˆใƒฉใ‚คใ‚ขใƒซใซ็™ป้Œฒใงใใพใ™ใฎใงใ€ใœใฒ่ฉฆใ—ใฆใฟใฆใใ ใ•ใ„ใ€‚ใƒฉใƒณใƒŠใƒผ/ใ‚จใƒผใ‚ธใ‚งใƒณใƒˆใฏใ‚ปใƒซใƒ•ใƒ›ใ‚นใƒˆใ‚‚ใงใใพใ™ใ—ใ€ใƒ›ใ‚นใƒ†ใƒƒใƒ‰ใ‚จใƒผใ‚ธใ‚งใƒณใƒˆใ‚‚ไฝฟใˆใพใ™ใ€‚

1 week ago 1 0 1 0

urban hippies but they might land in the witches category

and then however you categorise the fitness influencer type mums

1 week ago 1 0 0 0
Post image

this made me double take, pretty sure i already have PMS mastered but i guess claude makes me more angry and fed up sometimes so it could help :D

1 week ago 0 0 0 0

So cute. Im struggling today and this made me smile. Feels like ive been seeing your cute pups for so long, its a nice constant

1 week ago 1 0 1 0

yeah i auto filter it out like i do with advertising. There's a tone and some words that make me immediately disengage. For example anything that says i blah blah "not x, not y, just blah blah" and im out

1 week ago 0 0 0 0

what stream are you watching? I found this one but it has lots of interviews etc on it www.youtube.com/watch?v=m3kR...

2 weeks ago 0 0 1 0

ooh i thought i missed it becuase im on Aus time!

2 weeks ago 1 0 0 0

we wanted ads to be added without your permissions but just not those ones

3 weeks ago 1 0 0 0

i dont know why but adds in enterprise apps makes me so angry. When windows started putting ads on the lock screen... why

3 weeks ago 2 0 0 0
Advertisement
Post image

the saga continues :D

3 weeks ago 0 0 2 0

lol its been reversed www.theregister.com/2026/03/30/g...

3 weeks ago 0 0 1 0
Post image

YUUUUKKKKKKK

3 weeks ago 1 0 1 0

this is very cool! A Claude Code plugin that shows what's happening โ€” context usage, active tools, running agents, and todo progress. Always visible below your input. github.com/jarrodwatts/...

3 weeks ago 2 0 0 0

Buildkite has hosted agents as well and a free plan if that helps :) buildkite.com/docs/agent/b...

3 weeks ago 0 0 0 0
Post image

this is a shame, Trivvy was an awesome free tool.

"rivy version 0.69.4 has been compromised. This includes the Brew version, so if you run `brew info trivy` and it shows 0.69.4 installed, please start incident response ASAP."

1 month ago 1 1 0 0
Preview
OIDC with Azure OpenID Connect (OIDC) allows your Buildkite pipelines to authenticate directly with Microsoft Azure without storing long-lived credentials. Instead of managing client secrets, your pipeline requests a...

i know its "cringe" to be excited about things but ... i published my first ever @buildkite.bsky.social docs today and i'm excited about it ๐Ÿซถ

Yay for OIDC for Azure buildkite.com/docs/pipelin...

1 month ago 6 0 0 0
CI/CD Pipeline MCP Servers Review โ€” ChatForest Review of CI/CD pipeline MCP servers for AI-assisted build and deployment workflows

Every major CI/CD platform now has an MCP server โ€” Jenkins, CircleCI, GitHub Actions, Argo CD, Buildkite, Azure DevOps. We reviewed them all.

1 month ago 1 1 0 0
Preview
Azure/alz-terraform-accelerator | DeepWiki This document provides an overview of the Azure Landing Zones Terraform Accelerator, a comprehensive Infrastructure as Code (IaC) solution for deploying standardized Azure environments. The accelerato

It took me a good week to understand how the Azure #LandingZone #accelerator repo was put together so I could extend it and write up doco for my team.

Turns out deepwiki can do it in five seconds for any repo you point it to! Amazing !

[lnkd.in/g6rtExr2](deepwiki.com/Azure/alz-te...)

1 month ago 0 0 0 0
Advertisement
The Job Market Split Nobody's Talking About (It's Already Started). Here's What to Do About It.
The Job Market Split Nobody's Talking About (It's Already Started). Here's What to Do About It. YouTube video by AI News & Strategy Daily | Nate B Jones

Interesting vid if you're like me and wondering what the future holds: "Code is about to cost nothing, and knowing what to build is about to cost you everything."

www.youtube.com/watch?v=RtML...

1 month ago 0 0 0 0

Managing Azure Policy at scale? @MrTaoYang has open sourced AzPolicyFactory - a mature IaC pattern using Bicep, Azure DevOps/GitHub Actions, and unit tests per policy.

Very cool!
blog.tyang.org/2026/03/08/d...

1 month ago 1 1 0 0

Tech post warning! Lol

I found that CFPLand is defunct, probably for a long time. Anyone have a good resource for events with open CFPs? Is *your* event open for CFPs? Will boost your event for responses! ๐Ÿ˜

(Also, please kindly boost this for reach, itโ€™s much appreciated!)

2 years ago 7 6 7 0