Talk Intermediate 17:30 - 18:00 August 08, 2026

Samantha Pearlstein

Users building apps with vibe coding platforms like Lovable or Base44 often overlook critical security vulnerabilities. As these platforms gain rapid adoption, thousands of apps are being created without sufficient attention to security, leaving significant flaws in plain sight. Our research, conducted across thousands of apps, revealed widespread issues, including 175 instances of sensitive PII leakage (such as medical records and personal contact information), SSRF, 0-click account takeovers, and IDORs.

In this talk, we’ll share our field experience in developing discovery and security testing techniques that uncover exploitable web app and API behaviors at scale. We’ll walk through concrete examples, showing how critical vulnerabilities hide in plain sight and how even minor misconfigurations can lead to catastrophic breaches. Attendees will learn to identify these security risks and secure their no-code apps, including best practices for handling sensitive data and securing APIs.

Samantha Pearlstein

Founding Sales Engineer @ Escape

Samantha is a sales engineer with a strong background in security research, executive cyber resilience, and nation-state threats. As a former consultant at Accenture, she led cyber resilience initiatives for Fortune 100 executives, developed GenAI-powered security tools, and delivered workshops on emerging cyber challenges. Today, as a Sales Engineer at Escape, Samantha helps AppSec teams secure their APIs and SPAs, combining her passion for cybersecurity with hands-on problem-solving.