BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: A Billion-User Blast Radius: Owning ChatGPT’s Secu
 re Sandbox\n   Tags: AI Village | Creator Talk/Panel\n   When: Sunday\, Au
 g 9\, 10:00 - 10:30 PDT\n   Where: LVCCW Level 1 Hall 3 1103 (Creator Stag
 e 5) - [1]Map\n\n   Description:\n\n   OpenAI designed ChatGPT’s contain
 er sandbox as a secure runtime\n   environment\, enforcing full network is
 olation\, strict execution\n   timeouts\, and an AI supervisor to filter e
 very command. Under this\n   model\, owning the container and extracting s
 ensitive data seemed\n   impossible. However\, we demonstrate that by chai
 ning file-parsing\n   abuse for persistent execution\, reasoning-channel h
 ijacking for data\n   extraction\, and shared infrastructure manipulation\
 , an attacker can\n   establish a Cross-tenant data exfiltration.\n\n   In
  this talk\, we demonstrate a complete attack chain that shatters\n   Chat
 GPT’s secure sandbox. By abusing spreadsheet file parsing\, we\n   bypas
 s the LLM supervisor to gain persistent\, unmonitored root\n   execution. 
 From there\, we escalate the attack by live-patching the\n   internal Jupy
 ter kernel to hijack the model’s hidden python.exec\n   reasoning channe
 l\, executing a Reasoning Injection Attack to extract\n   sensitive user d
 ata. To exfiltrate this data\, we bypass network\n   isolation by weaponiz
 ing the Task Scheduler to launder malicious URLs\n   past strict web guard
 rails.\n\n   The attack reaches its climax by exploiting a shared JFrog pa
 ckage\n   manager. We engineered a signaling protocol that weaponizes glob
 ally\n   visible authentication rate limits\, translating these lockout ti
 mers\n   into a half-duplex covert channel. This provides reliable data\n 
   exfiltration and Command and Control from isolated enterprise\n   enviro
 nments to external attackers. Our exploit chain combines file\n   parsing 
 abuse\, Chain of Thought hijacking\, privilege confusion\, and\n   rate li
 mit Denial of Service to orchestrate a Command and Control (C2)\n   networ
 k directly inside ChatGPT.\n\n   Breaching AI sandbox agents becomes a cri
 tical vulnerability when\n   trust boundaries are shared across millions o
 f users. This research\n   proves that as AI agents gain more capabilities
 \, the attack surface\n   expands dramatically\, even when strict security
  constraints and\n   mitigations are in place.\n\n   SpeakerBio:  Simcha K
 osman\n\n   Simcha Kosman is a Senior Security Researcher at Palo Alto Net
 works\n   with over seven years of experience in vulnerability research. H
 e\n   discovered his first vulnerability at age 15\, earning his first bug
 \n   bounty\, and has since uncovered security flaws in processors\, embed
 ded\n   systems\, and large-scale open-source projects. His current work\n
    focuses on AI security\, exploring the intersection of LLM and software
 \n   exploitation. Simcha has presented his research in the past at BSides
 \,\n   Nullcon\, and Black Hat.\n\n   '\n\n   1. #LVCCW_Level1_Hall3\n\n\n
DTEND:20260809T173000Z
DTSTART:20260809T170000Z
LOCATION:AI Village - LVCCW Level 1 Hall 3 1103 (Creator Stage 5)
SUMMARY:A Billion-User Blast Radius: Owning ChatGPT’s Secure Sandbox
END:VEVENT
END:VCALENDAR
