4 Sources
[1]
Amazon's AI Coding Revealed a Dirty Little Secret
Coders who use artificial intelligence to help them write software are facing a growing problem, and Amazon.com Inc. is the latest company to fall victim. A hacker was recently able to infiltrate an AI-powered plugin for Amazon's coding tool,1 secretly instructing it to delete files from the
[2]
Read This Before You Trust Any AI-Written Code
We are in the era of vibe coding, allowing artificial intelligence models to generate code based on a developer's prompt. Unfortunately, under the hood, the vibes are bad. According to a recent report published by data security firm Veracode, about half of all AI-generated code contains security
[3]
Nearly half of all code generated by AI found to contain security flaws - even big LLMs affected
Java is the worst offender, Python, C# and JavaScript also affected Nearly half (45%) of AI-generated code contains security flaws despite appearing production-ready, new research from Veracode has found. Its study of more than 100 large language models across 80 different coding tasks revealed
[4]
Amazon's AI coding revealed a dirty little secret
While AI enhances coding speed, it introduces new risks, necessitating human oversight and security prioritization to mitigate potential threats. Coders who use artificial intelligence to help them write software are facing a growing problem, and Amazon.com Inc. is the latest company to fall
Share
Copy Link
Recent incidents and studies reveal significant security flaws in AI-generated code, raising concerns about the widespread adoption of AI in software development.
The integration of artificial intelligence (AI) in software development has been rapidly gaining traction, with tools like Amazon's Q Developer and startups such as Replit, Lovable, and Figma leading the charge. These AI-powered coding assistants, often built on models like OpenAI's ChatGPT or Anthropic's Claude, promise to revolutionize the way software is created
1
4
.One of the most popular applications of AI in programming is "vibe coding," where developers can use natural language commands to generate entire code blocks. This approach has sparked excitement for a new generation of applications that can be built quickly and efficiently
1
4
.
Source: TechRadar
However, recent incidents and studies have revealed significant security flaws in AI-generated code, raising concerns about the widespread adoption of these tools. A report by data security firm Veracode found that approximately 45% of AI-generated code contains security vulnerabilities
2
3
.The study, which evaluated over 100 large language models across 80 different coding tasks, uncovered alarming statistics:
3

Source: Bloomberg
A recent security breach at Amazon highlighted the potential risks associated with AI-powered coding tools. A hacker managed to infiltrate an AI-powered plugin for Amazon's Q Developer software, instructing it to delete files from the computers it was used on
1
4
.The hacker exploited a vulnerability in the public GitHub repository where Amazon managed the code for Q Developer. By submitting a seemingly normal update with hidden instructions, the hacker tricked the AI tool into creating malicious code
4
.Perhaps most concerning is the lack of improvement in AI-generated code security over time. While syntax has significantly improved, with AI models now producing compilable code nearly all the time, the security of the generated code has remained stagnant
2
.Jens Wessling, CTO of Veracode, emphasized this point: "Our research shows models are getting better at coding accurately but are not improving at security"
3
.Related Stories

Source: ET
The rapid adoption of AI in software development has created a double-edged sword. While these tools can significantly enhance coding speed and efficiency, they also introduce new risks that require careful management
4
.According to the 2025 State of Application Risk Report by Legit Security, more than two-thirds of organizations are now using AI models to help develop software. However, 46% of them are using these models in risky ways, often without proper oversight from cybersecurity teams
4
.To address these security concerns, experts suggest several approaches:
3
4
As the software development landscape continues to evolve with AI integration, striking a balance between innovation and security will be crucial. The "vibe coding" revolution promises a future where software development is more accessible, but it comes with a host of potential security challenges that must be addressed to ensure safe and reliable code production
4
.Summarized by
Navi
[1]
[3]
10 Jun 2026•Technology

05 Sept 2025•Technology

17 Dec 2025•Technology

1
Technology

2
Technology

3
Policy and Regulation
