BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Chaining Credentials Through the AI Infrastructure N
 obody\n   Secured\n   Tags: Red Team Village | Misc\n   When: Saturday\, A
 ug 8\, 14:00 - 14:59 PDT\n   Where: LVCCW Level 1 Hall 1 309 (Red Team Vil
 lage) Workshop Stage 2 -\n   [1]Map\n\n   Description:\n\n   AI/ML service
 s are proliferating across enterprise networks without\n   security review
 . Developers deploy Ollama instances locally\, data\n   science teams stan
 d up Jupyter notebooks and MLflow registries without\n   authentication\, 
 platform engineers run Ray clusters and LiteLLM API\n   gateways on defaul
 t configurations\, and MCP tool servers expose file\n   system access and 
 code execution to the network. These services rarely\n   appear in traditi
 onal vulnerability scans and are seldom included in\n   asset inventories.
 \n\n   To measure the scope of this problem\, I built a 5-VM benchmark lab
 \n   simulating four independent teams deploying 19 AI/ML endpoints with\n
    122 planted findings. The lab includes a manifest-driven scoring\n   ha
 rness that enables objective detection measurement across three\n   valida
 tion modes: standard (substring matching)\, strict (host\n   attribution a
 nd source module accuracy)\, and contract (workflow\n   metadata and evide
 nce chain verification).\n\n   The tool is aipostex\, an open-source singl
 e-binary Go framework\n   designed for the full AI infrastructure attack l
 ifecycle. It performs\n   network discovery across 20+ AI service families
 \, executes 123\n   vulnerability templates\, and provides 17 dedicated ex
 ploit modules\n   covering Ollama\, Jupyter\, MCP servers\, LiteLLM gatewa
 ys\, MLflow\, Ray\,\n   vector databases\, and inference endpoints. MCP co
 verage includes\n   schema poisoning\, environment variable extraction\, a
 nd CVE-specific\n   checks for DNS rebinding and remote code execution thr
 ough tool\n   servers. A separate model-scan capability identifies deseria
 lization\n   risk in pickle\, PyTorch\, TensorFlow\, and ONNX model files.
 \n\n   The live demonstration walks through a credential chain attack agai
 nst\n   the benchmark lab. The attack begins with Ray cluster enumeration 
 to\n   harvest API keys from job environment variables\, pivots into MLflo
 w\n   where experiment run parameters and tags contain embedded secrets an
 d\n   cloud credentials\, then chains those tokens to authenticate against
  a\n   HuggingFace TGI inference endpoint. Each hop crosses a different\n 
   team's infrastructure\, discovered and linked by the tool's credential\n
    chain-loading engine.\n\n   The session also covers the safety and oper
 ational controls that make\n   this suitable for production engagements: e
 xplicit --force-exploit\n   gating on mutating actions\, --mode full requi
 rement for exploit\n   templates\, proof-strength classification on every 
 finding (reachable\,\n   read-confirmed\, execution-confirmed)\, and OPSEC
  features including\n   User-Agent rotation\, TLS fingerprint randomizatio
 n\, and timing jitter.\n\n   Open-source release coinciding with presentat
 ion.\n\n   Does your workshop come with a tactic?\n\n   Yes. The tactic is
  "Hands-On: Credential Chain Exploitation Across\n   Shadow AI Infrastruct
 ure."\n\n   Each group of about five attendees gets their own isolated\n  
  cloud-hosted lab instance\, a full 5-VM environment spun up on AWS and\n 
   accessible only through a VPN tunnel. You SSH into your group's attack\n
    box and work through a guided attack chain against the lab's 19 AI/ML\n
    endpoints.\n\n   First\, you scan the /24 and discover what's running a
 cross four target\n   hosts. The tool fingerprints each endpoint and gives
  you structured\n   next steps\, so even if you've never touched MLflow or
  Ray before\, you\n   know what to run next.\n\n   Then you follow the cre
 dential chain. Enumerate a Ray cluster and pull\n   API keys from job envi
 ronment variables. Take those into MLflow and\n   extract secrets from exp
 eriment run parameters and tags. Chain the\n   tokens forward to authentic
 ate against a HuggingFace TGI inference\n   endpoint. Three hops\, three t
 eams' infrastructure\, all connected.\n\n   At the end\, you run the scori
 ng harness against your results and see\n   how you did. Detection rate\, 
 missed findings\, proof-strength\n   breakdown\, all compared against the 
 122-finding answer key.\n\n   Groups that finish the guided chain early ca
 n explore additional\n   attack surfaces across the lab's remaining endpoi
 nts\, including MCP\n   schema poisoning\, Jupyter cell secret mining\, an
 d vector database\n   injection. The scoring harness covers all 122 findin
 gs\, not just the\n   guided path\, so there is plenty of room to improve 
 your score.\n\n   Each wave runs about 50 minutes with a 10-minute reset b
 etween waves.\n   I'll run two waves. All you need is a laptop with an SSH
  client and a\n   WireGuard client. No prior AI/ML experience required. Ev
 erything you\n   use during the tactic\, the tool binary\, lab docs\, and 
 scoring harness\,\n   is yours to take home and run on your own infrastruc
 ture.\n\n   https://professor-moody.github.io/aipostex/\n\n   https://prof
 essor-moody.github.io/aipostex-lab/\n\n   SpeakerBio:  Nathan Keys\n\n   N
 athan is a security researcher focused on ML supply-chain security.\n   Th
 eir research spans information hiding in model artifacts\, data\n   poison
 ing of retrieval pipelines\, and post-exploitation of AI\n   infrastructur
 e. Nathan is currently a principal penetration tester in\n   the financial
  sector. This is their first DEF CON talk. Outside of his\n   passion for 
 research\, Nathan loves to touch grass\, read all manner of\n   scientific
  study or journal\, and listen to old school southern rap\n   (think UGK).
  Nathan has changed careers more than once\, from\n   winemaking to restau
 rants to professional hacking now for the last\n   seven years\, and he lo
 ves a good story and a good conversation.\n\n   '\n\n   1. #LVCCW_Level1_H
 all1\n\n\n
DTEND:20260808T215900Z
DTSTART:20260808T210000Z
LOCATION:Red Team Village - LVCCW Level 1 Hall 1 309 (Red Team Village) Wor
 kshop Stage 2
SUMMARY:Chaining Credentials Through the AI Infrastructure Nobody Secured
END:VEVENT
END:VCALENDAR
