Emma Fang
Krity
Old endpoints rarely die. They get forgotten. They survive refactors, go-lives, and cloud migrations, quietly drifting outside the visibility of gateway security testing. Many are inherited through third-party SDKs, shared libraries, and open-source middleware that teams never provisioned and never fully tracked. Built from a real security review of a production mobile app, this talk shows how a legacy authentication endpoint quietly bypassed every modern control around it. Through a live demonstration using only open-source tooling, we show how forgotten APIs can become full paths to compromise and why cloud-native visibility models fail by design.
Emma Fang
Senior Security Architect, Head of Security COE UK&I at EPAM
Emma is a seasoned Security Architect with extensive experience in cloud security and AppSec, and security strategy. As Regional Practice Lead at EPAM Systems, she oversees security initiatives and lead a team of security practitioners in UK&I, Switzerland, and Germany. Beyond her professional work, she is a recognised technical conference speaker, a passionate mentor and a dedicated advocate for fostering diversity in the cyber workforce.
Krity
Senior Application Security Engineer at ServiceNow
Krity is a dedicated cybersecurity professional with a strong foundation in application security, data analysis, and machine learning. As an Application Security Engineer at ServiceNow, she leverages her diverse experience and research background to enhance security practices. Beyond her technical role, Krity serves as the Community & Development Lead at Breaking Barriers Women in Cybersecurity (BBWIC), a nonprofit dedicated to empowering women in the field. Her work reflects a deep commitment to both advancing cybersecurity and fostering inclusive community growth, making her a passionate advocate for innovation, collaboration, and leadership in the industry.