1 in 5 breached companies were compromised through AI tools last year…
Security shut all of it down and made the tool “prototype only”.
Essentially those 3,000 people can now build whatever they want as long as it touches no company data.
The reason is where data goes the moment you connect it. Point Replit or Lovable at your Snowflake and the query runs on their cloud, because their cloud is where the app is. No setting keeps it on your side.
IBM studied 600 breached organizations last year. 20% were compromised through AI tools their own IT department never approved.. Of the companies that had an AI-related breach, 97% had no access controls on those tools at all.
The attack chain is short.
An AI agent pulls a package off public npm to make one feature work. That package gets compromised upstream. It is now running inside an app that queries your customer database, forwarding results to an endpoint nobody at your company controls, and no one can tell you which app or which employee built it.
This is a new tool which runs the whole thing inside the customer's own AWS account. The database gets spun up there. Inference runs through their Bedrock. Before an app ships, agents read the generated code against rules the customer's security team wrote and send it back for rewriting until it passes.
The AI can only install packages the company already approved. LinkedIn is owned by Microsoft. Microsoft has a partnership with Replit. LinkedIn bought Superblocks anyway.
Glean grew by noticing employees were pasting company data into ChatGPT, then selling enterprises the version that runs inside their own cloud.
Superblocks is running that play on vibe coding.
Brad Menezes (@bradmenezes)
Today we’re partnering with AWS to launch Superblocks 3.0: the secure way for employees to vibe code production enterprise software.
In a single prompt, Superblocks can replace million dollar SaaS, while IT & Security stay in control.
OpenAI and Anthropic are releasing new models with advanced cyber attack capability and vibe coding is every company's achilles heel:
> Personal Replit accounts store untracked customer data.
> Lovable prototypes with your data open to the public internet.
> Claude on the desktop pulls malicious packages.
How Superblocks 3.0 works:
Superblocks Builds: Import vibe coded prototypes. Model routing picks the best frontier or open source model per task. Saves up to 30% on token costs.
Superblocks Secures: A swarm of security agents work like a real human team to find and fix vulnerabilities.
Superblocks Deploys: Unlike consumer vibe coding tools that send your data to their cloud, Superblocks deploys the application, database, and AI inference securely inside your private AWS environment.
Superblocks 3.0 is trusted across enterprises like Instacart, Benchling, and even banks and social networks with the most stringent security requirements.
Book a demo here: superblocks.com/book-a-demo
Everyone says, “AI is replacing SaaS”, yet find me a Fortune 500 company that has vibe coded its own CRM instead of using Salesforce.
That changes today.
To celebrate our launch, we're building 1,000 enterprise apps for free.
Comment a SaaS tool you hate and why, and we'll reply with an enterprise-grade replacement.
Video
— https://nitter.net/bradmenezes/status/2084328970649026710#m