Vibe Coding under Attack

November 2026 | Bucharest

Hands-on vibe coding defense

Vibe Coding under Attack is a hands-on workshop about the security of applications developed with the help of AI.

Participants start by analysing and exploiting an application built almost entirely through vibe coding, following how an attacker thinks and the kinds of mistakes they look for. We cover attack surface, authentication, authorisation, secrets, APIs, business logic, and the problems that AI-assisted development introduces most often. In the first half of the day we break two or three sites built with AI.

In the second half, participants build their own application with the help of a coding agent and apply secure development principles from the design stage onward. The workshop focuses on the difference between an application that works and one that can be considered secure.

By the end of the day, participants leave with a reusable workflow for building and verifying applications created with AI.

Why is this workshop relevant?

AI tools allow developers to write and ship software at unprecedented speeds, yet these rapid builds frequently hide severe security flaws. Coding assistants prioritize functional features, so they regularly generate vulnerabilities in authentication, authorization, and business logic. Traditional security scanners miss these subtle logic errors, leaving live applications exposed to simple attacks. 

This workshop equips developers with the offensive mindset needed to uncover those hidden flaws. Participants exploit vulnerable AI-generated sites first, then build secure applications using a verified, repeatable workflow that keeps production environments safe.

Who is it for?

The workshop is aimed at a beginner to intermediate level.

It is relevant to anyone building software with AI assistance, and to security people who need to assess what comes out of it: developers using coding agents, application security specialists, penetration testers, and technical leads responsible for what ships.

Workshop agenda

About the trainer

CRISTIAN IOSUB

Cristian Iosub is a security specialist at Cybershield. At DefCamp 2025 he delivered the workshop Human Error: The Hidden Threat to Physical Security.

Key learning objectives: 

Exploit real-world vulnerabilities in AI-generated web applications by adopting an offensive attacker mindset

Identify critical security risks in AI-written code, including flawed authentication, broken authorization, and exposed secrets

Architect secure applications from the ground up while using AI coding assistants and prompts

Automate security testing into your development workflow to catch logic flaws before code reaches production

Apply a repeatable framework to verify, harden, and deploy secure AI-assisted software safely

Other information & prerequisites

  • A laptop running Windows, macOS or Linux
  • Access to a coding agent, preferably Claude installed locally
  • Alternatively, a terminal client such as MobaXterm. The trainer provides instances for participants to connect to
  • A stable internet connection

The remaining tools are installed together during the workshop.

Other information

Estimated Workshop Duration: 1 day, exact hours to be confirmed

Language of Instruction: Romanian

Participation fee: EUR 200

FAQs

If we do not meet the minimum number of participants, you can either transfer to another workshop and pay or receive a refund for any difference in price, or opt for a full refund. You will be notified in advance and given options to choose what works best for you.

The workshop price covers food. However, accommodation is not included, but we can recommend nearby options for your convenience.

Yes, full refunds are available up to 15 days before the workshop start date. However, if you cancel after that, we can offer only 50% of the price.

You will receive an email with all the necessary details, including the workshop location, prerequisites, and schedule, at least one week before the event. If you have any immediate questions, feel free to reach out to us directly.