UpGuard Launches User Risk to Deliver the Industry's First 360 Degree View of Cyber Risk
New Human Risk Management (HRM) solution provides a unified picture of internal workforce risk MOUNTAIN
Loading...
![]() |
Widespread "YOLO Mode" risks in AI coding tools are creating significant supply chain and data breach exposure
MOUNTAIN VIEW, Calif., Feb. 4, 2026 /PRNewswire/ -- UpGuard, a leader in cybersecurity and risk management, released new research highlighting a critical security vulnerability within developer workflows. UpGuard's analysis of more than 18,000 AI agent configuration files from public GitHub repositories identified a concerning pattern: one in five developers have granted AI code agents unrestricted access to perform high-risk actions without human oversight.
In using AI to improve efficiency, developers are granting extensive permissions to download content from the web, and read, write, and delete files on their machines without requiring developer permission. This comes at the cost of essential security guardrails, exposing organizations to major supply chain and data security risks.
"Security teams lack visibility into what AI agents are touching, exposing, or leaking when developers grant vibe coding tools broad access without oversight," said Greg Pollock, director of Research and Insights at UpGuard. "Despite the best intentions, developers are increasing the potential for security vulnerabilities and exploitation. This is how small workflow shortcuts can escalate into major supply chain and credential exposure problems."
Key Findings:
These risks highlight a critical governance gap, slowing down incident response and increasing the likelihood of credential and data exposure. To read UpGuard's recent research on vibe coding, visit the following:
About UpGuard's Breach Risk
UpGuard's Breach Risk solution is designed to turn hidden shortcuts such as misconfigurations or overly broad permissions to early threat signals like dark web chatter, into clear, actionable visibility. By providing deep insight into the AI-generated changes, access, and data flow, UpGuard's Breach Risk solution helps security teams enforce a strict governance framework.
About UpGuard
Founded in 2012, UpGuard is a leader in cybersecurity and risk management. The company's AI-powered platform for cyber risk posture management (CRPM), provides a centralized, actionable view of cyber risk across an organization's vendors, attack surface, and workforce. Trusted by thousands of companies, UpGuard's platform is designed to help security teams manage cyber risk with confidence and efficiency. To learn more, visit www.upguard.com.