BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: One Chain to Own Them All — Breaking AI Infrastruc
 tures\n   Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲\n   When:
  Friday\, Aug 7\, 17:00 - 17:59 PDT\n   Where: LVCCW Level 1 Hall 3 903 (M
 ain Track 5) and DCTV-5 - [1]Map\n\n   Description:\n\n   2025 marks the d
 awn of AI security. Pwn2Own Berlin launched its first\n   AI track\, featu
 ring Ollama and Triton Inference Server\, while\n   ZeroDay.Cloud introduc
 ed new challenges targeting vLLM and Ollama.\n   These competitions pushed
  us to take a closer look at the security of\n   core AI infrastructures. 
 vLLM exposes limited API functionality by\n   default — until we discove
 red that its completions endpoint accepts\n   prompt_embeds\, which are lo
 aded via torch.load with weights_only\n   enabled. We had previously discl
 osed CVE-2025-32434\, a bypass for the\n   weights_only mechanism\; after 
 it was patched\, we wondered: could we\n   succeed again? This led us to a
  heap overflow vulnerability that\n   bypasses weights_only entirely (CVE-
 2026-24747)\, which we leveraged to\n   compromise vLLM. This finding over
 turned a common assumption: that\n   PyTorch flaws only enable model poiso
 ning\, requiring victims to load\n   malicious models locally. In fact\, m
 any AI applications expose APIs\n   that invoke torch.load for routine ope
 rations such as model loading\n   and LoRA fine-tuning — turning a "loca
 l" vulnerability into a remote\n   one. After mapping this attack surface\
 , we developed exploits against\n   ComfyUI\, NVIDIA Dynamo and others. In
  this talk\, we'll walk through\n   the discovery of this new PyTorch weig
 hts_only bypass and demonstrate\n   its exploitation across AI infrastruct
 ures.\n\n   Speakers:Ji'an "azraelxuemo" Zhou\,Lei "llfamsec" Lu\n\n   Spe
 akerBio:  Ji'an "azraelxuemo" Zhou\n\n   He focuses on Java security and A
 I security\, and his work has helped\n   many high-profile vendors—inclu
 ding Google\, Amazon\, Cloudera\, IBM\,\n   Microsoft\, Oracle\, among oth
 ers. He has presented at Black Hat Europe\n   2024\, Zer0Con 2025\, Off-by
 -One Con 2025\, Black Hat USA 2025\, DEFCON 33\n   and Zer0Con 2026.\n\n  
  SpeakerBio:  Lei "llfamsec" Lu\n\n   He has focuses on application and sy
 stem security. He has reported\n   many vulnerabilities to Linux\, AMD\, A
 pple\, Microsoft\, etc. He has\n   presented at PHDays 2025.\n\n   '\n\n  
  1. #LVCCW_Level1_Hall3\n\n\n
DTEND:20260808T005900Z
DTSTART:20260808Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5
SUMMARY:One Chain to Own Them All — Breaking AI Infrastructures
END:VEVENT
END:VCALENDAR
