Sygnia Penetration Test Reveals Critical “vibe coded” Vulnerabilities Within Claude-Based Application
Leading incident response team launches AI Cybersecurity Services in wake of rising AI-assisted code development.
Press Release Disclaimer: This is a press release distributed through the XPR Media network. It has not been independently verified by our newsroom.

![]()
Sygnia, the world’s foremost incident response and cyber readiness team, revealed critical vulnerabilities following a penetration test of a customer onboarding application, developed in Claude, that processed highly sensitive personal and financial information, including government-issued identification, identity verification data, and payment details. Identified by an LLM, the vulnerability enabled low-access privilege users to see critical client personal identification information by not requiring appropriate user verification before issuing or restoring applicant access tokens.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260728834521/en/
LLM analysis highlighting a high-severity vulnerability within a “vibe-coded” application.
Investigation findings highlighted a flaw with access token issuance and restoration, where possession of an applicant GUID was treated as sufficient proof to issue an access token. The reason for this flaw was tied to the AI-assisted implementation strategy which featured access tokens, expiration, rate limiting, and logging, but missed the critical pre-issuance question to validate whether the requester is entitled to receive or restore an applicant token.
“Working code is not the same as secure code,” said Zach Mead, Principal Penetration Tester at Sygnia. “AI-generated code may compile, follow familiar conventions, and pass basic checks, while still making flawed assumptions about trust boundaries, authorization, state, ownership, or third-party integrations. Security teams need to treat AI-generated output as untrusted until validated.”
Key findings of the penetration test include:
- Authentication and authorization failures – Penetration test of an application developed heavily in Claude by a financial institution managing billions in assets revealing AI-assisted code challenges to add structure and security around a difficult workflow.
- Vibe coded flaw vs. vibe coded review – The penetration test conducted with assistance from a LLM highlights that AI can easily be leveraged by threat actors to identify key application vulnerabilities to carry out successful attacks.
- AI-assisted code generation vulnerabilities – Vulnerabilities introduced by LLMs are architectural and logical, weaving in authentication bypasses, broken access controls and state management errors that are difficult to catch by Static Application Security Testing (SAST) tools.
In response to the rise of shadow AI, unvetted employee use of AI tools, and AI-enabled applications, Sygnia launches its AI Cybersecurity Services. A modular set of offerings, the services are designed to help organizations securely adopt, govern, assess, and test AI solutions across the complete AI lifecycle. The services include:
- AI Cyber Posture Assessment – Assesses and secures AI systems across infrastructure, applications, data flows, and prompt behavior.
- AI Governance Framework – Establishes a comprehensive framework for AI onboarding and managing AI usage across the organization.
- AI Governance Assessment – Evaluates existing AI governance controls and provides a prioritized roadmap for improvement.
- AI Application Penetration Testing – Tests internally developed and customer-facing AI applications for exploitable weaknesses across the application, AI interaction layer, supporting infrastructure, and connected data flows.
“AI adoption is moving faster than many organizations’ ability to govern and secure it,” said Ilia Rabinovich, Vice President of Cybersecurity Consulting at Sygnia. “The challenge is not whether enterprises should use AI. They already are. The challenge is whether they understand where AI is being used, what data it can access, how it changes their attack surface, and whether their existing controls are prepared for the risks it introduces.”
Sygnia’s AI Cybersecurity Services address this emerging reality of new pathways for sensitive data exposure, broken authorization logic, unsafe dependencies, and flawed business workflows. Rooted in more than a decade of frontline incident response and cyber readiness experience, the services combine attacker-informed expertise, technical assessment, governance development, application testing, and actionable remediation guidance to help organizations secure AI adoption without slowing innovation.
Learn more about Sygnia’s AI Cybersecurity Services and read the latest threat research, “Code at AI Speed, Risk at AI Scale.”
About Sygnia
Sygnia is the world’s foremost incident response and cyber readiness team. It applies creative approaches and bold solutions to each phase of an organization’s security journey, meeting them where they are to ensure cyber resilience. Sygnia is the trusted advisor and service provider of leading organizations worldwide, including Fortune 100 companies. Sygnia is a Temasek company, part of the ISTARI Collective.
View source version on businesswire.com: https://www.businesswire.com/news/home/20260728834521/en/
Media gallery

