The Hidden Security Risk Inside AI-Built Apps

A financial institution’s AI-assisted application contained a critical security flaw that could have exposed sensitive customer information, according to a new penetration test by Israeli cybersecurity company Sygnia.

The application, developed largely using Anthropic’s Claude, processed highly sensitive data, including government-issued identification, identity verification records and payment details. Sygnia found that users with limited access privileges could potentially view customer information because the system failed to properly verify whether they were authorized to receive or restore access tokens.

The vulnerability was linked to the application’s authentication process. The system treated possession of an applicant GUID — a unique identifier assigned to users — as sufficient proof to issue an access token, without an additional verification step confirming that the requester was entitled to access the account.

Sygnia said the flaw highlights a growing challenge around AI-assisted software development: code generated with the help of large language models can appear functional while still containing serious security weaknesses.

The company described the issue as a “vibe coded” vulnerability — a flaw introduced when AI-generated code is accepted without sufficient review of security assumptions, architecture and access controls. The penetration test itself was also conducted with the assistance of an LLM, demonstrating how AI can be used both to build applications and to identify weaknesses within them.

“AI adoption is moving faster than many organizations’ ability to govern and secure it,” said Ilia Rabinovich, Vice President of Cybersecurity Consulting at Sygnia. “The challenge is not whether enterprises should use AI. They already are. The challenge is whether they understand where AI is being used, what data it can access, how it changes their attack surface, and whether their existing controls are prepared for the risks it introduces.”

According to Sygnia, many vulnerabilities introduced by AI-assisted development are not simple coding mistakes, but deeper architectural and logical flaws involving authentication, authorization, state management and business workflows. These issues can be difficult for traditional security testing tools to detect.

The company has launched a new AI cybersecurity services portfolio designed to help organizations assess AI applications, establish governance frameworks and conduct penetration testing across AI systems and supporting infrastructure.

Sygnia said the finding demonstrates how AI-assisted development can introduce security gaps that are difficult to detect with traditional tools. As enterprises increasingly deploy applications built with the help of large language models, security testing will need to become part of the development process — not an afterthought.

Click Here For The Original Source

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW