LIVE · cybersecurity feed
Live wire
CVE-2026-86360 · Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root AccessCVE-2026-21589 · Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 ProductsCVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-DayClingSTUN Malware Turns IoT Devices Into Proxy NodesCVE-2026-61500 · Rejetto HFS servers now actively scanned for critical RCE flawCVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure
aimedium

Mitigate Risks of AI-Generated Apps by Citizen Coders

The increasing use of AI tools by non-technical employees, often referred to as "citizen coders," to develop workplace applications presents significant security and data risks for organizations. While these AI-generated applications can boost productivity and streamline workflows, their rapid creation without proper oversight can lead to "shadow AI" assets with critical vulnerabilities,…

ZeroDay News ·

Source: Tenable Blog

The increasing use of AI tools by non-technical employees, often referred to as "citizen coders," to develop workplace applications presents significant security and data risks for organizations. While these AI-generated applications can boost productivity and streamline workflows, their rapid creation without proper oversight can lead to "shadow AI" assets with critical vulnerabilities, misconfigurations, and weak data protection.

Cybersecurity experts emphasize that a blanket ban on AI-aided development is often counterproductive, as employees may then conceal their development activities. Instead, a structured governance framework is recommended to provide necessary security and compliance guardrails. Tenable, a cybersecurity company, has adopted such a framework to manage the risks associated with its own citizen coders.

The risks from these unsanctioned applications are not entirely new, having gained prominence with the rise of low-code/no-code development platforms. However, generative AI tools have exacerbated the issue by enabling virtually anyone to create functional applications from natural language prompts. Unlike many low-code/no-code platforms that are often hosted as SaaS and monitored by IT, generative AI products are frequently consumer-grade tools accessible to individual employees.

Common security and compliance issues in AI-generated citizen-coder applications developed without IT and security oversight include a lack of testing, scanning, and quality assurance, leading to code with critical vulnerabilities, dangerous misconfigurations, and risky open-source components. These applications may also insecurely access critical company systems and store sensitive data, often without being included in update, patching, monitoring, logging, backup, or disaster recovery plans. Furthermore, they can possess excessive permissions and privileges, bypassing the organization's identity and access management (IAM) systems.

Even when citizen coders attempt to involve IT and security teams, the sheer volume of AI-built applications can overwhelm these departments, making it burdensome to review, approve, and securely onboard them. This can lead to significant costs, particularly if applications consume AI tokens, and can result in dangerous data sprawl as citizen coders create local data lakes.

Tenable's comprehensive five-tier AI governance framework aims to address these challenges. The first tier, "Strategy," involves executive staff setting strategic alignment, investment guidance, and prioritization for AI initiatives. The second tier, "Governance," features an AI Governance Board and AI Technical Council responsible for creating AI policies, guidance documentation, and lists of approved AI tools, while explicitly owning compliance, data privacy, and model risk.

The third tier, "Execution," tasks AI Functional Leads and R&D Champions with driving specific use cases, managing departmental adoption, and measuring productivity. The fourth tier, "Enablement," involves an Enablement Working Group led by IT, Learning & Development (L&D), and Corporate Communications, which handles hands-on training, resource distribution, and enterprise demonstrations. Finally, the fifth tier, "Community," provides dedicated channels for support, crowdsourcing solutions, and discussions on AI usage and engineering.

This multi-tiered model ensures that foundational protections and controls for AI-generated applications are established uniformly company-wide by IT and security experts, rather than being determined independently by individual business units. Mandatory security and compliance awareness training for citizen coders is also a key component of this approach, alongside peer leadership and oversight within departments.

aicitizen developersapplication securitygovernancerisk management
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

U.S. Bank CISO says the security role keeps growing and no one can own all of it

The role of a Chief Information Security Officer (CISO) has expanded significantly to encompass areas such as fraud, resilience, third-party risk, and AI governance, according to Ann Barron-DiCamillo, EVP and CISO at U.S. Bank. She notes that while this consolidation can make security leaders more effective by addressing interconnected risks, no single individual can realistically own every…

security

Microsoft extends the Outlook naughty step with two more file types

Microsoft is implementing new security measures for Outlook, adding two file types, .msix and .msixbundle, to its default block list for attachments. These file types are associated with Windows application packages and bundles. The change is set to affect users of the New Outlook for Windows client and Outlook on the Web within Exchange Online.

patch

ClickFix Attack Hides VBScript Payload in Browser Cache

A new "ClickFix" social engineering campaign has been identified that leverages browser caches to conceal malicious VBScript payloads. The technique, detailed by Microsoft Threat Intelligence on October 3, involves compromised websites pre-fetching a script disguised as an image into a visitor's browser cache. This allows the payload to be present on the victim's device before they are tricked…

CVE-2026-86360critical

Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root Access

Dell has issued an urgent advisory to customers, recommending they patch a critical vulnerability in its System Update (DSU) tool that could allow attackers to gain root access on affected PowerEdge servers. The flaw, identified as CVE-2026-86360, carries a CVSS score of 9.6, indicating its severe potential impact.

CVE-2026-21589critical

Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

A critical vulnerability has been reported in eight Atlassian Data Center products, enabling unauthenticated attackers to read known files within the web application root directory. The flaw, identified as CVE-2026-21589, was disclosed by Atlassian on October 5th and carries a CVSS rating of 9.3 out of 10, indicating its severe impact and ease of exploitation.

breach

FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach

The U.S. Federal Bureau of Investigation (FBI) has reportedly removed an Accenture contractor following an alleged security failure that contributed to a data breach attributed to the ShinyHunters threat group. This incident is said to have resulted in the theft of personal details belonging to thousands of FBI employees. The reported cause of the breach was a patch failure.