DEF CON 33 - Preventing One of The Largest Supply-Chain Attacks in History - Maksim Shudrak

DEF CON 33 - Preventing One of The Largest Supply-Chain Attacks in History - Maksim Shudrak

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 38:00

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Supply chain attacks via abandoned AWS S3 buckets are a serious, scalable threat enabled by LLMs and big data analysis, with real-world impact on thousands of organizations and government networks.

Key Takeaways:
• Abandoned S3 buckets can be reclaimed and exploited for code execution, affecting thousands of hosts across 158 countries 1:47-2:30.
• Attackers can poison PyTorch models or Maven/PI packages to inject backdoors, leading to code execution on systems from Fortune 500 companies to government agencies 15:00-16:00.
• Malware like RK and Linker, active years ago, can be weaponized via S3 buckets to inject malicious JavaScript into browsers, enabling data exfiltration from sites like Google and Facebook 25:00-27:20.
• The attack surface is vast—4.5K GitHub buckets, 480 Maven/PI buckets, and 188 malware-related buckets were identified, with 28,000 users at risk 10:00-11:00.

This threat is not theoretical; it highlights a critical gap in supply chain security, where dangling bucket references and lack of bucket name predictability enable large-scale attacks. Cloud providers must adopt secure-by-default policies, including non-recyclable bucket names and strict access controls to prevent exploitation.

Sources:

  • 1:47 Discussion of supply chain attacks and S3 bucket exploitation.
  • 15:00 Demonstration of PyTorch model poisoning and code execution.
  • 25:00 Malware weaponization via S3 buckets and JavaScript injection.
  • 10:00 Scale of buckets and user impact a

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

I'm going to get uh Maxim going here fairly quickly because he was asking me about the timer very quickly which means he has a lot to cover and it's a super important topic about supply chain attacks because if the if the robots don't get us this will have a wonderful time. Thank you. Let's give him a big round of applause and a big welcome. Thank you. Imagine one sunny morning you read the news. A crypto worm disrupts operations of hundreds of companies around the world and government networks of 25 countries. The war is spreading and the initial blast radius is estimated to be around 28,000 machines and now likely affecting much more computers around the planet. Uh security industry struggle to understand how did this happen. There's no one source of compromise. Eventually, a security re…