<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>VibeZero Blog</title><description>Security, release readiness, and shipping AI-built apps with confidence. Field notes from the team building VibeZero.</description><link>https://vibezero.io/blog/</link><item><title>The fix your AI swears it shipped</title><link>https://vibezero.io/blog/the-fix-your-ai-swears-it-shipped/</link><guid isPermaLink="true">https://vibezero.io/blog/the-fix-your-ai-swears-it-shipped/</guid><description>Prompting the AI to fix its own security bugs feels like closure. Why unverified fixes fail, how they quietly regress, and what a real fix loop looks like.</description><pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate></item><item><title>72,000 photos and no lock on the door</title><link>https://vibezero.io/blog/tea-app-firebase-breach/</link><guid isPermaLink="true">https://vibezero.io/blog/tea-app-firebase-breach/</guid><description>The Tea app breach exposed 72,000 user photos, including 13,000 selfies and government IDs, in a cloud storage bucket with no authentication.</description><pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate></item><item><title>1.5 million keys and not one line of code</title><link>https://vibezero.io/blog/moltbook-breach-same-bug-again/</link><guid isPermaLink="true">https://vibezero.io/blog/moltbook-breach-same-bug-again/</guid><description>The Moltbook breach exposed 1.5 million API keys: a vibe-coded app shipped a Supabase backend with row-level security off. Why it keeps happening.</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Introducing the VibeZero blog</title><link>https://vibezero.io/blog/introducing-the-vibezero-blog/</link><guid isPermaLink="true">https://vibezero.io/blog/introducing-the-vibezero-blog/</guid><description>Why we are writing about security, release readiness, and shipping AI-built apps without the guesswork.</description><pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate></item><item><title>The most common vulnerabilities in vibe-coded apps</title><link>https://vibezero.io/blog/most-common-vibe-coded-app-vulnerabilities/</link><guid isPermaLink="true">https://vibezero.io/blog/most-common-vibe-coded-app-vulnerabilities/</guid><description>What actually goes wrong when apps are built by prompting an AI: the five vulnerability classes that show up again and again, with the research behind each one.</description><pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate></item><item><title>The five layers of a release gate</title><link>https://vibezero.io/blog/five-layers-of-a-release-gate/</link><guid isPermaLink="true">https://vibezero.io/blog/five-layers-of-a-release-gate/</guid><description>A single scan should look at code, dependencies, secrets, configuration, and the running app. Here is why each layer matters.</description><pubDate>Sat, 18 Jul 2026 00:00:00 GMT</pubDate></item></channel></rss>