Close Menu
GeekBlog

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    The Minecraft movie is getting a sequel

    October 10, 2025

    Discord says third-party breach exposed 70,000 ID photos

    October 10, 2025

    Andrew Garfield Really Wants You to Stop Asking Him About ‘Avengers: Doomsday’

    October 10, 2025
    Facebook X (Twitter) Instagram Threads
    GeekBlog
    • Home
    • Mobile
    • Reviews
    • Tech News
    • Deals & Offers
    • Gadgets
      • How-To Guides
    • Laptops & PCs
      • AI & Software
    • Blog
    Facebook
    GeekBlog
    Home»Tech News»Vibe Coding Is the New Open Source—in the Worst Way Possible
    Tech News

    Vibe Coding Is the New Open Source—in the Worst Way Possible

    Michael ComaousBy Michael ComaousOctober 6, 20253 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Vibe Coding Is the New Open Source—in the Worst Way Possible
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    Just like you probably don’t grow and grind wheat to make flour for your bread, most software developers don’t write every line of code in a new project from scratch. Doing so would be extremely slow and could create more security issues than it solves. So developers draw on existing libraries—often open source projects—to get various basic software components in place.

    While this approach is efficient, it can create exposure and lack of visibility into software. Increasingly, however, the rise of vibe coding is being used in a similar way, allowing developers to quickly spin up code that they can simply adapt rather than writing from scratch. Security researchers warn, though, that this new genre of plug-and-play code is making software-supply-chain security even more complicated—and dangerous.

    “We’re hitting the point right now where AI is about to lose its grace period on security,” says Alex Zenla, chief technology officer of the cloud security firm Edera. “And AI is its own worst enemy in terms of generating code that’s insecure. If AI is being trained in part on old, vulnerable, or low-quality software that’s available out there, then all the vulnerabilities that have existed can reoccur and be introduced again, not to mention new issues.”

    In addition to sucking up potentially insecure training data, the reality of vibe coding is that it produces a rough draft of code that may not fully take into account all of the specific context and considerations around a given product or service. In other words, even if a company trains a local model on a project’s source code and a natural language description of goals, the production process is still relying on human reviewers’ ability to spot any and every possible flaw or incongruity in code originally generated by AI.

    “Engineering groups need to think about the development lifecycle in the era of vibe coding,” says Eran Kinsbruner, a researcher at the application security firm Checkmarx. “If you ask the exact same LLM model to write for your specific source code, every single time it will have a slightly different output. One developer within the team will generate one output and the other developer is going to get a different output. So that introduces an additional complication beyond open source.”

    In a Checkmarx survey of chief information security officers, application security managers, and heads of development, a third of respondents said that more than 60 percent of their organization’s code was generated by AI in 2024. But only 18 percent of respondents said that their organization has a list of approved tools for vibe coding. Checkmarx polled thousands of professionals and published the findings in August—emphasizing, too, that AI development is making it harder to trace “ownership” of code.

    coding Open Sourcein Vibe worst
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
    Previous ArticleHBO Max subscribers lose access to CNN livestream on November 17
    Next Article Best October Prime Day TV deals 2025: All-time-low prices from Samsung, LG, and more
    Michael Comaous
    • Website

    Michael Comaous is a dedicated professional with a passion for technology, innovation, and creative problem-solving. Over the years, he has built experience across multiple industries, combining strategic thinking with hands-on expertise to deliver meaningful results. Michael is known for his curiosity, attention to detail, and ability to explain complex topics in a clear and approachable way. Whether he’s working on new projects, writing, or collaborating with others, he brings energy and a forward-thinking mindset to everything he does.

    Related Posts

    1 Min Read

    The Minecraft movie is getting a sequel

    3 Mins Read

    Discord says third-party breach exposed 70,000 ID photos

    2 Mins Read

    Andrew Garfield Really Wants You to Stop Asking Him About ‘Avengers: Doomsday’

    1 Min Read

    Prime Day is over, but some of our favorite Samsung deals are still live

    2 Mins Read

    Our Favorite Motorola Smartphone Is $100 Off

    2 Mins Read

    Childhood vaccines safe for a little longer as CDC cancels advisory meeting

    Top Posts

    8BitDo Pro 3 review: better specs, more customization, minor faults

    August 8, 202538 Views

    What founders need to know before choosing their exit at Disrupt 2025

    August 8, 202521 Views

    Grok rolls out AI video creator for X with bonus “spicy” mode

    August 7, 202519 Views
    Stay In Touch
    • Facebook

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    8BitDo Pro 3 review: better specs, more customization, minor faults

    August 8, 202538 Views

    What founders need to know before choosing their exit at Disrupt 2025

    August 8, 202521 Views

    Grok rolls out AI video creator for X with bonus “spicy” mode

    August 7, 202519 Views
    Our Picks

    The Minecraft movie is getting a sequel

    October 10, 2025

    Discord says third-party breach exposed 70,000 ID photos

    October 10, 2025

    Andrew Garfield Really Wants You to Stop Asking Him About ‘Avengers: Doomsday’

    October 10, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook
    • About Us
    • Contact us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    © 2025 geekblog. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.