Loading…
Secure AI Summit 2024 (Powered by Cloud Native)
Attending this event?
Tuesday June 25, 2024 4:15pm - 4:50pm PDT
The Oligo Security team recently identified ShellTorch, a chain of 4 vulnerabilities that allow a full chain of Remote Code Execution (RCE), with a new CVE-2023-43654 having a CVSS score of 9.8, and found tens of thousands of vulnerable instances publicly exposed in Torchserve, which is part of the PyTorch ecosystem (one of the most widely adopted OSS frameworks for AI in the world), open to unauthorized access and insertion of malicious AI models.   In this talk, we’ll dive into the research team’s identification of the TorchServe vulnerabilities enabling a total takeover of impacted systems.  With the growing popularity of AI and LLMs, securing these applications and their tooling stacks is becoming increasingly important.  Come to this session to unpack this newly discovered high-severity exploit from the researchers themselves, which enables the viewing, modifying, stealing, and deleting of AI models and sensitive data on a targeted TorchServe server, with a live demo of its reproduction, and steps you can take immediately to mitigate the risk.
Speakers
avatar for Avi Lumelsky

Avi Lumelsky

AI Security Researcher @ CTO Office, Oligo Security
Avi has a relentless curiosity about AI, Security, and Business — and the places where all three connect.An experienced Software Engineer and Architect, Avi focuses on AI, with deep security insights. Edit Profile... Read More →
avatar for Gal Elbaz

Gal Elbaz

Co-founder & CTO at Oligo Security, Oligo Security
Co-founder & CTO at Oligo Security with 10+ years of experience in vulnerability research and practical hacking. He previously worked as a Security Researcher at CheckPoint and served in the IDF Intelligence. In his free time, he enjoys playing CTFs.
Tuesday June 25, 2024 4:15pm - 4:50pm PDT
Room 447
Log in to leave feedback.

Attendees (7)


Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link