BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Living Off Someone Else's Inference\n   Tags: Red Te
 am Village | Misc\n   When: Saturday\, Aug 8\, 14:00 - 15:59 PDT\n   Where
 : LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 2 -\n   [1]Map\
 n\n   Description:\n\n   LLM-powered tooling is becoming a force multiplie
 r for attackers\, from\n   reconnaissance automation to post-exploitation 
 enumeration. Using\n   their own API keys creates attribution and cost\, s
 o they look for\n   alternatives.\n\n   Thousands of inference endpoints s
 it exposed on the internet:\n   misconfigured Ollama instances\, open vLLM
  deployments\, leaked API keys\n   in directory listings\, and expired OAu
 th tokens from AI coding\n   assistants that can be silently refreshed. At
 tackers can discover\n   these resources and use them as free compute for 
 their operations\,\n   without spending a dollar or registering an account
 .\n\n   Attendees will learn how to:\n\n   •   Discover exposed infe
 rence endpoints and leaked API keys\n   using Infreerence •   Valida
 te that discovered resources provide\n   usable inference access •  
  Operate Echidna\, powered entirely by\n   discovered inference •   
 Chain LLM skill agents together to\n   execute a guided campaign against a
  target network\n\n   Current LLMs are effective force multipliers when di
 rected\, and\n   significantly more so when the compute bill goes to someo
 ne else. This\n   is resource hijacking applied to the AI era: living off 
 someone else's\n   inference. Understanding this threat is essential for a
 ny organization\n   deploying or exposing AI infrastructure.\n\n   Two too
 ls will be released as open source during the session:\n\n   •   Inf
 reerence: A multi-phase scanner and dashboard that\n   discovers exposed i
 nference endpoints and leaked API keys through\n   Shodan and Censys\, val
 idates them against live provider APIs\, and\n   catalogs usable inference
  resources across 10+ providers. • \n    Echidna: A Mythic C2 agent 
 type that consumes discovered inference\n   endpoints and turns them into 
 operator-directed skill agents for\n   reconnaissance\, exploitation plann
 ing\, post-exploitation\, and lateral\n   movement.\n\n   Speakers:Armend 
 Gashi\,Redon Gashi\n\n   SpeakerBio:  Armend Gashi\, Managing Security Con
 sultant at Sentry\n   Cybersecurity\n\n   Armend Gashi is Managing Securit
 y Consultant at Sentry. With over 5\n   years in the industry\, he special
 izes in application security and AWS\n   cloud assessments. Armend has con
 ducted AI red teaming engagements\,\n   developed multi-agent systems to p
 erform security-focused tasks such\n   as code auditing and exploit develo
 pment\, and was part of\n   Anthropic’s external AI red team capability 
 through HackerOne.\n\n   Armend has led security research initiatives resu
 lting in the\n   discovery of multiple vulnerabilities\, including:\n\n   
 CVE-2023-26482 - Critical-risk vulnerability enabling remote code\n   exec
 ution CVE-2023-48239 - High-risk vulnerability allowing arbitrary\n   user
  storage updates CVE-2023-35928 - High-risk vulnerability enabling\n   use
 r account hijacking CVE-2023-45660 - Medium-risk application-level\n   den
 ial of service vulnerability CVE-2023-48301 - Medium-risk arbitrary\n   br
 owser code injection vulnerability CVE-2023-48307 - Low-risk\n   server-si
 de request forgery vulnerability\n\n   SpeakerBio:  Redon Gashi\, Managing
  Security Consultant at Sentry\n   Cybersecurity\n\n   Redon Gashi is a Ma
 naging Security Consultant and offensive team lead\n   at Sentry\, where h
 e has spent close to a decade leading and executing\n   penetration tests 
 and red team operations for Fortune 500 clients\n   across banking\, telec
 om\, insurance\, and fintech. He holds the OSEP\,\n   CRTL\, and CRTO cert
 ifications\, and has personally performed over 200\n   engagements spannin
 g web applications\, internal infrastructure\, and\n   mobile platforms\, 
 while leading many more across his team. A former\n   lecturer at Cyber Ac
 ademy\, speaker at multiple BSides conferences\, and\n   multiple-time CTF
  champion\, Redon combines deep hands-on technical\n   expertise with a pr
 oven ability to build and scale offensive security\n   teams.\n\n   '\n\n 
   1. #LVCCW_Level1_Hall1\n\n\n
DTEND:20260808T225900Z
DTSTART:20260808T210000Z
LOCATION:Red Team Village - LVCCW Level 1 Hall 1 309 (Red Team Village) Tac
 tic Table 2
SUMMARY:Living Off Someone Else's Inference
END:VEVENT
END:VCALENDAR
