August 1, 2026

Orca's New Security Product Is a Warning Label for Vibe Coding

A cloud security giant just admitted the scale of the problem

On July 29-30, Orca Security released its State of AI Security Report 2026, built on telemetry from more than 1,200 production cloud environments. The headline number: 52% of organizations now build custom applications with AI. That's not a future trend, that's a majority of companies today, and it's why Orca didn't just publish a report -- it shipped a product. Orca AI AppGen Security is built specifically to find and secure AI-built applications that were created outside traditional development pipelines, and Orca named names: it's built to cover apps made directly with Claude, Supabase, and Lovable.

Orca CEO Gil Geron put it plainly: "Everyone is a builder now...Organizations need security that can keep pace with this shift without slowing innovation." That's a security vendor's CEO conceding that the builder population has exploded past what traditional AppSec was ever designed to watch. Orca also cited IBM research showing that breaches involving "shadow AI" cost organizations $670,000 more on average than other incidents -- a real, painful number attached to a very specific failure mode: apps nobody in security knew existed until something went wrong.

Why a scanner product had to exist at all

Think about what Orca is actually reacting to. Someone opens Claude, generates a backend, wires it to Supabase for the database, deploys it through Lovable, and ships an app -- all in an afternoon, all without a single security review. Nobody on that path owns authentication. Nobody owns data isolation between customers or tenants. Nobody owns access control defaults. Each piece -- the model, the database, the host -- was built as a general-purpose tool, and general-purpose tools don't come with opinions about who should see what data. That absence is exactly the gap Orca built a whole product to fill, and the $670,000 shadow-AI premium IBM measured is the price tag on that absence when it goes wrong.

This isn't an isolated story either -- it's part of a pattern we've been tracking closely, including in our take on the rough week AI security just had and in Okta's own bet that agent identity is becoming the new perimeter. The industry is converging on the same conclusion from different directions: AI-built software is shipping faster than anyone is securing it.

The real blind spot is architectural, not procedural

Here's our sharp disagreement with how the industry is framing this. Orca's product is a good, honest response to a real problem -- but it's still a scanner arriving after the fact, looking for leaks that already happened. That's the only option you have when "AI app building" means stapling together a general-purpose coding assistant, a generic database, and a generic hosting platform. Security in that stack was never the default; it's a bolt-on that a third party has to go discover, catalog, and patch, one app at a time, across every customer who used those tools.</br></br>We think that's backwards. If data isolation, authentication, and access control aren't part of the architecture from the first app you build, you're always going to be in catch-up mode, and a $670,000 premium is what catch-up mode costs when it fails. The fix isn't a better scanner. It's an AI app builder where those defaults are built into the platform itself -- not bolted onto whatever a raw model happened to generate. That's the entire premise behind how we've built ViibeStack's platform and why our Security and Trust Center pages exist as first-class parts of the product, not marketing afterthoughts -- including a documented incident response process, which is the kind of thing that doesn't exist at all for an app someone assembled from three unrelated tools over a weekend.

What to actually ask before you build anything real

If you're evaluating vibe coding tools for anything that will touch real customer data, don't start with speed or output quality. Start with ownership. Ask: who is responsible for auth in the app I'm about to build -- me, or the platform? Is tenant data isolated by default, or is that something I have to configure correctly myself, every time? If a security vendor had to build a separate product just to go find apps like mine after they're deployed, what does that tell you about the defaults you're inheriting?</br></br>Those aren't hypothetical questions anymore -- they're the exact questions Orca's own report and product launch are forcing the market to confront. We covered the related shift in SaaS risk in our take on Gartner's $234B SaaS-at-risk estimate, and the pattern holds here too: the tools winning this next phase won't be the ones that build fastest with the fewest guardrails. They'll be the ones where security was never a separate purchase in the first place.

Sources

← Back to News