AI Coding Bug Exposes Billions in Corporate Data #
Sagi Tzadik sat before a glowing monitor in a darkened room, unpicking the digital stitches of the world’s most trusted software repository. According to Dark Reading, the Wiz security researcher used an AI-driven reverse-engineering tool to identify CVE-2026-3854, a high-severity vulnerability in GitHub Enterprise Server that allows attackers to achieve remote code execution. This is the reality of 'vibe coding'—a term coined by former Tesla AI head Andrej Karpathy to describe the surge of software built by non-technical users prompting machines. Karpathy told a crowd at Sequoia Capital that this machine-written code is often 'bloaty,' 'brittle,' and 'gross.' It is a black box that hides catastrophic failures until the moment of liquidation. The consequences of this deskilling are no longer theoretical. According to reports from the Wall Street Journal, the White House has moved to restrict access to Anthropic’s 'Mythos' model, fearing the company lacks the compute power to prevent autonomous agents from triggering systemic collapses. This follows the reported liquidation of a corporate database in just nine seconds by an unmonitored AI agent. Read together, the discovery of massive GitHub bugs and the restriction of the Mythos model describe a 'Cognitive Enclosure'; the elite are barricading their proprietary perimeters with elite security models while leaving the working-class developer to rot in a landscape of uninsurable, automated liability. The code is no longer a craft; it is a minefield. According to Bloomberg Law, organizations now face a 'black box' of legal liability as vibe-coded software offers zero copyright protection and infinite security risk. The machines are not building a better world; they are building a faster way for your data to be stolen.