BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Go with the Flow: Riding GCP Dataflow Shadow Depende
 ncy to\n   Cross-Tenant Compromise\n   Tags: Cloud Village | Creator Talk/
 Panel\n   When: Friday\, Aug 7\, 15:10 - 15:30 PDT\n   Where: LVCCW Level 
 3 W313 (Cloud Village Talks) - [1]Map\n\n   Description:\n\n   Cloud resou
 rces rely on a web of trust that most security teams\n   ignore. Even if y
 ou secure access to a resource\, you might miss its\n   "shadow dependenci
 es" - the external\, system-generated resources\n   required for it to fun
 ction.\n\n   GCP Dataflow is just the latest in a long trail of vulnerable
  services\n   suffering from this architectural blind spot. What we found 
 is a\n   fundamental flaw in how Dataflow blindly trusts dependencies loca
 ted\n   far outside its IAM control and security boundaries.\n\n   In this
  talk\, we’ll present two novel attack techniques that\n   weaponize unv
 alidated config files to hijack trusted data pipelines.\n   We’ll also d
 emonstrate a critical cross-tenant vulnerability that\n   extends this iss
 ue by enabling manipulation of Dataflow orchestration\n   across tenant bo
 undaries. The issue remains under responsible\n   disclosure and is expect
 ed to be fixed before the presentation.\n\n   Background: GCP Dataflow and
  Managed Infrastructure\n\n   Organizations running large-scale enterprise
  data workloads\n   increasingly rely on managed data-processing services\
 , especially GCP\n   Dataflow. Built on Apache Beam\, Dataflow executes un
 ified data\n   pipelines while removing much of the operational burden of\
 n   provisioning cluster frameworks\, tuning virtual machines\, and scalin
 g\n   infrastructure in response to demand. Teams define the pipeline\, an
 d\n   Dataflow provisions and scales the underlying compute resources\n   
 automatically.\n\n   During this orchestration\, however\, Dataflow pipeli
 nes often depend on\n   objects stored in standard cloud storage buckets t
 o control execution\,\n   such as code\, templates\, and environment confi
 guration.\n\n   Pipelines routinely ingest and execute files from cloud bu
 ckets\,\n   including JavaScript or Python User Defined Functions (UDFs) f
 or\n   runtime transformation\, structured YAML job templates that define\
 n   pipeline parameters\, and other environment configuration files.\n\n  
  Because these files and their supporting temporary assets are often\n   m
 anaged through automated developer pipelines\, they can become\n   "shadow
 s": overlooked in routine asset inventories and security\n   posture revie
 ws\, yet still critical to the execution of highly trusted\n   cloud workf
 lows.\n\n   Key Takeaways\n\n   Dismantling the shadow resources blind spo
 t: Understand how automated\n   cloud orchestration creates short-lived ac
 cess windows that can evade\n   scheduled security scans and routine asset
  inventories.\n\n   Auditing the infrastructure-as-config attack surface: 
 Learn to treat\n   external execution blueprints as active attack surfaces
  rather than\n   passive configuration files.\n\n   Applying defensive bes
 t practices: Take away architectural\n   recommendations for designing pip
 elines that are more resilient to\n   these attack paths.\n\n   Session De
 tails\n\n   Total duration: 20 minutes\n\n   5 minutes: Background on shad
 ow resources and Dataflow mechanics.\n\n   10 minutes: Walkthrough of the 
 attack paths and the cross-tenant\n   vulnerability.\n\n   5 minutes: Rese
 arch methodology\, defensive takeaways\, and detection\n   strategies.\n\n
    Speakers:Gil Weizman\,Tamir Yehuda\n\n   SpeakerBio:  Gil Weizman\n\n  
  Gil Weizman is an experienced security researcher with over ten years\n  
  of expertise across on‑prem\, cloud\, web\, and SaaS security. Gil\n   
 focuses on threat detection\, product security research\, vulnerability\n 
   research and identifying gaps in security visibility across modern\n   e
 nvironments. Gil specializes in translating real‑world attacker\n   beha
 vior into improved detection and mitigation strategies.\n\n   SpeakerBio: 
  Tamir Yehuda\n\n   Tamir Yehuda is a Senior Security Researcher and cloud
  security team\n   lead at Varonis. He is a full-stack hacker with experie
 nce in malware\n   analysis\, Windows & AD domains\, SaaS applications\, a
 nd cloud\n   infrastructure. Tamir specialize in IaaS & PaaS research focu
 sing\n   mainly on Azure\, GCP\, AWS\, Salesforce\, and ServiceNow. He bri
 ngs over\n   eight years of experience in various types of security resear
 ch and\n   red teaming.\n\n   '\n\n   1. #LVCCW_Level3_South\n\n\n
DTEND:20260807T223000Z
DTSTART:20260807T221000Z
LOCATION:Cloud Village - LVCCW Level 3 W313 (Cloud Village Talks)
SUMMARY:Go with the Flow: Riding GCP Dataflow Shadow Dependency to Cross-Te
 nant Compromise
END:VEVENT
END:VCALENDAR
