Dev.to
7/10/2026

The original title is: "AI security roundup: nursery data breach, sudo exploit, and leaked secrets in vibe-coded apps"
Original: AI Security Breaches, Vibe Coding Secrets Leak, and OpenAI's $500B Week
Short summary
A roundup of a chaotic week in AI security: ransomware hit a nursery chain exposing 8,000 children's records, sudo CVE-2025-32463 was actively exploited, and vibe-coded apps shipped with hardcoded API keys. OpenAI simultaneously hit a $500B valuation. The core takeaway is that AI-generated code needs the same review rigor as human-written code—secret scanning and code review are non-negotiable.
- •Ransomware gang Radiant hacked nursery chain Kido, stealing data on 8,000 children
- •Sudo CVE-2025-32463 added to CISA's Known Exploited Vulnerabilities list, actively exploited in the wild
- •Vibe-coded apps shipping with hardcoded API keys—developers treating AI output as trusted without review
Generated with AI, which can make mistakes.
Is this a good recommendation for you?


