BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Living Off Someone Else's Inference\n   Tags: Recon 
 Village | Creator Talk/Panel\n   When: Sunday\, Aug 9\, 10:45 - 11:30 PDT\
 n   Where: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - [1]Map\n\n   Descr
 iption:\n\n   LLM-powered tooling is becoming a force multiplier for attac
 kers\, from\n   reconnaissance automation to post-exploitation enumeration
 . Using\n   their own API keys creates attribution and cost\, so they look
  for\n   alternatives.\n\n   Thousands of inference endpoints sit exposed 
 on the internet:\n   misconfigured Ollama instances\, open vLLM deployment
 s\, leaked API keys\n   in directory listings\, and expired OAuth tokens f
 rom AI coding\n   assistants that can be silently refreshed. Attackers can
  discover\n   these resources and use them as free compute for their opera
 tions\,\n   without spending a dollar or registering an account.\n\n   Att
 endees will learn how to:\n\n   •   Discover exposed inference endpo
 ints and leaked API keys\n   using Infreerence •   Validate that dis
 covered resources provide\n   usable inference access •   Operate Ec
 hidna\, powered entirely by\n   discovered inference •   Chain LLM s
 kill agents together to\n   execute a guided campaign against a target net
 work\n\n   Current LLMs are effective force multipliers when directed\, an
 d\n   significantly more so when the compute bill goes to someone else. Th
 is\n   is resource hijacking applied to the AI era: living off someone els
 e's\n   inference. Understanding this threat is essential for any organiza
 tion\n   deploying or exposing AI infrastructure.\n\n   Two tools will be 
 released as open source during the session:\n\n   •   Infreerence: A
  multi-phase scanner and dashboard that\n   discovers exposed inference en
 dpoints and leaked API keys through\n   Shodan and Censys\, validates them
  against live provider APIs\, and\n   catalogs usable inference resources 
 across 10+ providers. • \n    Echidna: A Mythic C2 agent type that c
 onsumes discovered inference\n   endpoints and turns them into operator-di
 rected skill agents for\n   reconnaissance\, exploitation planning\, post-
 exploitation\, and lateral\n   movement.\n\n   Speakers:Redon Gashi\,Armen
 d Gashi\n\n   SpeakerBio:  Redon Gashi\, Managing Security Consultant at S
 entry\n   Cybersecurity\n\n   Redon Gashi is a Managing Security Consultan
 t and offensive team lead\n   at Sentry\, where he has spent close to a de
 cade leading and executing\n   penetration tests and red team operations f
 or Fortune 500 clients\n   across banking\, telecom\, insurance\, and fint
 ech. He holds the OSEP\,\n   CRTL\, and CRTO certifications\, and has pers
 onally performed over 200\n   engagements spanning web applications\, inte
 rnal infrastructure\, and\n   mobile platforms\, while leading many more a
 cross his team. A former\n   lecturer at Cyber Academy\, speaker at multip
 le BSides conferences\, and\n   multiple-time CTF champion\, Redon combine
 s deep hands-on technical\n   expertise with a proven ability to build and
  scale offensive security\n   teams.\n\n   SpeakerBio:  Armend Gashi\, Man
 aging Security Consultant at Sentry\n   Cybersecurity\n\n   Armend Gashi i
 s Managing Security Consultant at Sentry. With over 5\n   years in the ind
 ustry\, he specializes in application security and AWS\n   cloud assessmen
 ts. Armend has conducted AI red teaming engagements\,\n   developed multi-
 agent systems to perform security-focused tasks such\n   as code auditing 
 and exploit development\, and was part of\n   Anthropic’s external AI re
 d team capability through HackerOne.\n\n   Armend has led security researc
 h initiatives resulting in the\n   discovery of multiple vulnerabilities\,
  including:\n\n   CVE-2023-26482 - Critical-risk vulnerability enabling re
 mote code\n   execution CVE-2023-48239 - High-risk vulnerability allowing 
 arbitrary\n   user storage updates CVE-2023-35928 - High-risk vulnerabilit
 y enabling\n   user account hijacking CVE-2023-45660 - Medium-risk applica
 tion-level\n   denial of service vulnerability CVE-2023-48301 - Medium-ris
 k arbitrary\n   browser code injection vulnerability CVE-2023-48307 - Low-
 risk\n   server-side request forgery vulnerability\n\n   '\n\n   1. #LVCCW
 _Level1_Hall3\n\n\n
DTEND:20260809T183000Z
DTSTART:20260809T174500Z
LOCATION:Recon Village - LVCCW Level 1 Hall 3 801 (Creator Stage 2)
SUMMARY:Living Off Someone Else's Inference
END:VEVENT
END:VCALENDAR
