2,000 vibe-coded apps were found exposed on the open internet.
Connected to production CRMs, ERPs, BI tools. 380,000 public assets scanned. 5,000 looked corporate. 2,000 had sensitive data with no access controls.
This isn't Shadow IT. It's Shadow Building.
Employees building full apps with AI in hours. Wiring them to live systems. Publishing to the open web. Without Security or IT knowing.
EDR sees browser activity, not the build. DLP can't see API-to-API data movement. CASB can't distinguish custom apps from the platform.
Every security tool is doing its job. The category sits in the gaps between them.
The fix: session-layer visibility. Every step - build, OAuth grant, data load, publish - is a browser event. That's where governance has to live.
Or: just ask your team what they've built. Most aren't hiding it.