From the Rebellious Cities: How Iranian APTs spy on their own people
DAY 1
15:30-
16:10
AI did not just create a demand for GPUs. It turned GPU data centers into something anyone can rent by the hour.
GPU neo-clouds sell compute, often placing tenants on bare metal. You think you rented GPUs, but in practice, you may have rented a foothold inside the provider’s data center.
We tested GPU providers from both sides of that boundary. From the internet, exposed BMCs led to access to power control, remote console, boot settings, and firmware update flows, while unauthenticated GPU telemetry exposed fleet maps and monitoring endpoints that could be abused for reconnaissance or denial of service. From inside paid leases, we crossed into backend layers tenants should never reach: the InfiniBand fabric, shared storage, cluster DNS, and the server’s own BMC.
This session walks the GPU data center as an attack surface, component by component, and ends with a practical tenant-side checklist for finding the same cracks before attackers do.
-
Location :
-
Track 1(HALL B)
-
-
Category :
-
Technical
-
-
Share :
Speakers
-
Eliad Kimhy
エリアド・キムヒ
Eliad Kimhy is a Senior Security Researcher at Acronis, where he conducts research into emerging threats and cybercrime, and shares insights through conference talks and published reports. Eliad has worked with security teams for close to a decade, helping build and lead the development of threat intelligence production, and the publication of research-based content for technical and general audiences. He has spoken at conferences such as VirusBulletin, CARO, Insomnihack, Thotcon, BsidesSF, BsidesLV, and IT-SA. He is the co-creator and producer of the Webby Honoree podcast Malicious Life, which explores the untold stories and cultural history of hacking.