Vibe Coding under Attack
November 2026 | Bucharest
Hands-on vibe coding defense
Vibe Coding under Attack is a hands-on workshop about the security of applications developed with the help of AI.
Participants start by analysing and exploiting an application built almost entirely through vibe coding, following how an attacker thinks and the kinds of mistakes they look for. We cover attack surface, authentication, authorisation, secrets, APIs, business logic, and the problems that AI-assisted development introduces most often. In the first half of the day we break two or three sites built with AI.
In the second half, participants build their own application with the help of a coding agent and apply secure development principles from the design stage onward. The workshop focuses on the difference between an application that works and one that can be considered secure.
By the end of the day, participants leave with a reusable workflow for building and verifying applications created with AI.
Why is this workshop relevant?
AI tools allow developers to write and ship software at unprecedented speeds, yet these rapid builds frequently hide severe security flaws. Coding assistants prioritize functional features, so they regularly generate vulnerabilities in authentication, authorization, and business logic. Traditional security scanners miss these subtle logic errors, leaving live applications exposed to simple attacks.
This workshop equips developers with the offensive mindset needed to uncover those hidden flaws. Participants exploit vulnerable AI-generated sites first, then build secure applications using a verified, repeatable workflow that keeps production environments safe.
Who is it for?
The workshop is aimed at a beginner to intermediate level.
It is relevant to anyone building software with AI assistance, and to security people who need to assess what comes out of it: developers using coding agents, application security specialists, penetration testers, and technical leads responsible for what ships.
Workshop agenda
About the trainer
CRISTIAN IOSUB
Cristian Iosub is a security specialist at Cybershield. At DefCamp 2025 he delivered the workshop Human Error: The Hidden Threat to Physical Security.
Key learning objectives:
✔ Exploit real-world vulnerabilities in AI-generated web applications by adopting an offensive attacker mindset
✔ Identify critical security risks in AI-written code, including flawed authentication, broken authorization, and exposed secrets
✔ Architect secure applications from the ground up while using AI coding assistants and prompts
✔ Automate security testing into your development workflow to catch logic flaws before code reaches production
✔ Apply a repeatable framework to verify, harden, and deploy secure AI-assisted software safely
Other information & prerequisites
- A laptop running Windows, macOS or Linux
- Access to a coding agent, preferably Claude installed locally
- Alternatively, a terminal client such as MobaXterm. The trainer provides instances for participants to connect to
- A stable internet connection
The remaining tools are installed together during the workshop.
Other information
Estimated Workshop Duration: 1 day, exact hours to be confirmed
Language of Instruction: Romanian
Participation fee: EUR 200
FAQs
If we do not meet the minimum number of participants, you can either transfer to another workshop and pay or receive a refund for any difference in price, or opt for a full refund. You will be notified in advance and given options to choose what works best for you.
The workshop price covers food. However, accommodation is not included, but we can recommend nearby options for your convenience.
Yes, full refunds are available up to 15 days before the workshop start date. However, if you cancel after that, we can offer only 50% of the price.
You will receive an email with all the necessary details, including the workshop location, prerequisites, and schedule, at least one week before the event. If you have any immediate questions, feel free to reach out to us directly.