Too Close to the Metal: Attacking GPU Neo-Clouds from the Inside and Out
DAY 2
16:45-
17:25
AI did not just create a demand for GPUs. It turned GPU data centers into something anyone can rent by the hour.
GPU neo-clouds sell compute, often placing tenants on bare metal. You think you rented GPUs, but in practice, you may have rented a foothold inside the provider’s data center.
We tested GPU providers from both sides of that boundary. From the internet, exposed BMCs led to access to power control, remote console, boot settings, and firmware update flows, while unauthenticated GPU telemetry exposed fleet maps and monitoring endpoints that could be abused for reconnaissance or denial of service. From inside paid leases, we crossed into backend layers tenants should never reach: the InfiniBand fabric, shared storage, cluster DNS, and the server’s own BMC.
This session walks the GPU data center as an attack surface, component by component, and ends with a practical tenant-side checklist for finding the same cracks before attackers do.
-
Location :
-
Track 1(HALL B)
-
-
Category :
-
Technical
-
-
Share :
Speakers
-
Michael Katchinskiy
マイケル・カチンスキー
Michael Katchinskiy is the Head of Research at Lava Labs, where he focuses on AI infrastructure security. Prior to Lava Labs, Michael worked at Microsoft and Aqua Security, where his work focused on cloud-native and Kubernetes security research. Michael has presented his research at Black Hat, DEF CON, fwd:cloudsec, and KubeCon.
-
Yakir Kadkoda
ヤキール・カドコダ
Former Director of Research at Aqua Security. Having built and broken critical infrastructure at national scale, his security research has been presented at Black Hat, RSAC, DEF CON, and other top-tier conferences.