From the Rebellious Cities: How Iranian APTs spy on their own people
DAY 2
13:20-
14:00
AI did not just create a demand for GPUs. It turned GPU data centers into something anyone can rent by the hour.
GPU neo-clouds sell compute, often placing tenants on bare metal. You think you rented GPUs, but in practice, you may have rented a foothold inside the provider’s data center.
We tested GPU providers from both sides of that boundary. From the internet, exposed BMCs led to access to power control, remote console, boot settings, and firmware update flows, while unauthenticated GPU telemetry exposed fleet maps and monitoring endpoints that could be abused for reconnaissance or denial of service. From inside paid leases, we crossed into backend layers tenants should never reach: the InfiniBand fabric, shared storage, cluster DNS, and the server’s own BMC.
This session walks the GPU data center as an attack surface, component by component, and ends with a practical tenant-side checklist for finding the same cracks before attackers do.
-
Location :
-
Track 1(HALL B)
-
-
Category :
-
Technical
-
-
Share :
Speakers
-
Eliad Kimhy
エリアド・キムヒ
Eliad Kimhy is a Senior Security Researcher at Acronis, where he conducts research into emerging threats and cybercrime, and shares insights through conference talks and published reports. Eliad has worked with security teams for close to a decade, helping build and lead the development of threat intelligence production, and the publication of research-based content for technical and general audiences. He has spoken at conferences such as VirusBulletin, CARO, Insomnihack, Thotcon, BsidesSF, BsidesLV, and IT-SA. He is the co-creator and producer of the Webby Honoree podcast Malicious Life, which explores the untold stories and cultural history of hacking.
-
Subhajeet Singha
スバジート・シンハ
Subhajeet Singha is a senior threat researcher at TRU Labs at Acronis, specializing in threat intelligence, malware research, and reverse engineering. His work focuses on analyzing emerging cyber threats, uncovering sophisticated attack campaigns, and enhancing detection mechanisms to strengthen cybersecurity defenses. With a deep understanding of malware behavior and threat actor tactics, Subhajeet actively investigates advanced persistent threats (APTs), reverse-engineers complex malware strains, and contributes to research initiatives that improve industry-wide threat detection. He has previously spoken in conferences like Virus Bulletin, Positive Hack Talks, AVAR & ROOTCON, VULNCON.