-

Sygnia Penetration Test Reveals Critical “vibe coded” Vulnerabilities Within Claude-Based Application

Leading incident response team launches AI Cybersecurity Services in wake of rising AI-assisted code development.

LAS VEGAS--(BUSINESS WIRE)--Sygnia, the world’s foremost incident response and cyber readiness team, revealed critical vulnerabilities following a penetration test of a customer onboarding application, developed in Claude, that processed highly sensitive personal and financial information, including government-issued identification, identity verification data, and payment details. Identified by an LLM, the vulnerability enabled low-access privilege users to see critical client personal identification information by not requiring appropriate user verification before issuing or restoring applicant access tokens.

Investigation findings highlighted a flaw with access token issuance and restoration, where possession of an applicant GUID was treated as sufficient proof to issue an access token. The reason for this flaw was tied to the AI-assisted implementation strategy which featured access tokens, expiration, rate limiting, and logging, but missed the critical pre-issuance question to validate whether the requester is entitled to receive or restore an applicant token.

“Working code is not the same as secure code,” said Zach Mead, Principal Penetration Tester at Sygnia. “AI-generated code may compile, follow familiar conventions, and pass basic checks, while still making flawed assumptions about trust boundaries, authorization, state, ownership, or third-party integrations. Security teams need to treat AI-generated output as untrusted until validated.”

Key findings of the penetration test include:

  • Authentication and authorization failures – Penetration test of an application developed heavily in Claude by a financial institution managing billions in assets revealing AI-assisted code challenges to add structure and security around a difficult workflow.
  • Vibe coded flaw vs. vibe coded review – The penetration test conducted with assistance from a LLM highlights that AI can easily be leveraged by threat actors to identify key application vulnerabilities to carry out successful attacks.
  • AI-assisted code generation vulnerabilities – Vulnerabilities introduced by LLMs are architectural and logical, weaving in authentication bypasses, broken access controls and state management errors that are difficult to catch by Static Application Security Testing (SAST) tools.

In response to the rise of shadow AI, unvetted employee use of AI tools, and AI-enabled applications, Sygnia launches its AI Cybersecurity Services. A modular set of offerings, the services are designed to help organizations securely adopt, govern, assess, and test AI solutions across the complete AI lifecycle. The services include:

  • AI Cyber Posture Assessment – Assesses and secures AI systems across infrastructure, applications, data flows, and prompt behavior.
  • AI Governance Framework – Establishes a comprehensive framework for AI onboarding and managing AI usage across the organization.
  • AI Governance Assessment – Evaluates existing AI governance controls and provides a prioritized roadmap for improvement.
  • AI Application Penetration Testing – Tests internally developed and customer-facing AI applications for exploitable weaknesses across the application, AI interaction layer, supporting infrastructure, and connected data flows.

“AI adoption is moving faster than many organizations’ ability to govern and secure it,” said Ilia Rabinovich, Vice President of Cybersecurity Consulting at Sygnia. “The challenge is not whether enterprises should use AI. They already are. The challenge is whether they understand where AI is being used, what data it can access, how it changes their attack surface, and whether their existing controls are prepared for the risks it introduces.”

Sygnia’s AI Cybersecurity Services address this emerging reality of new pathways for sensitive data exposure, broken authorization logic, unsafe dependencies, and flawed business workflows. Rooted in more than a decade of frontline incident response and cyber readiness experience, the services combine attacker-informed expertise, technical assessment, governance development, application testing, and actionable remediation guidance to help organizations secure AI adoption without slowing innovation.

Learn more about Sygnia’s AI Cybersecurity Services and read the latest threat research, “Code at AI Speed, Risk at AI Scale.”

About Sygnia

Sygnia is the world’s foremost incident response and cyber readiness team. It applies creative approaches and bold solutions to each phase of an organization’s security journey, meeting them where they are to ensure cyber resilience. Sygnia is the trusted advisor and service provider of leading organizations worldwide, including Fortune 100 companies. Sygnia is a Temasek company, part of the ISTARI Collective.

Contacts

Media Contact
Kathryn Thompson Dossey
Head of Global Communications
Media@sygnia.co
+1 704-776-8127

Sygnia


Release Versions

Contacts

Media Contact
Kathryn Thompson Dossey
Head of Global Communications
Media@sygnia.co
+1 704-776-8127

More News From Sygnia

Sygnia Investigation Finds AI Accelerated Attack Enabled Lone Threat Actor to Rapidly Compromise Enterprise Cloud Environment

TEL-AVIV & NEW YORK--(BUSINESS WIRE)--Cyberattack reveals agentic AI workflows to accelerate victim reconnaissance, attack tool development, command structuring and adaptation....

Sygnia Recognized in 2026 Gartner® Market Guide for Cybersecurity Incident Response Retainer Services

TEL AVIV, Israel & NEW YORK--(BUSINESS WIRE)--Sygnia recognized as a Representative Vendor in the 2026 Gartner® Market Guide for Cybersecurity Incident Response Retainer Services....

73% of CISOs Unprepared for the Next Big Cyber Attack, Incident Response Readiness Report Reveals

TEL-AVIV & NEW YORK--(BUSINESS WIRE)--Sygnia, the foremost global cyber readiness and response team, today released their 2026 CISO Survey: The State of Incident Response Readiness, highlighting a troubling gap between incident response (IR) planning and operational readiness. Based on a global survey of more than 600 senior cyber security decision makers, the findings reveal that though 76% of organizations have experienced at least one cyber attack in the last 12 months, 73% of senior cyber s...
Back to Newsroom