Pipelines of Privilege: Attack Paths from DevOps to MLOps Infrastructure | SO-CON 26

Pipelines of Privilege: Attack Paths from DevOps to MLOps Infrastructure | SO-CON 26

Source: YouTube · SpecterOps · published Jun 4, 2026 · 46:02

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

BLUF: This presentation explores attack paths from DevOps to MLOps, highlighting how traditional infrastructure vulnerabilities can compromise machine learning models, and outlines defensive strategies to secure the ML lifecycle [0:00].

Key Takeaways:
• The speaker, Brett Hawkins from Armory, introduces the topic of attack vectors bridging DevOps and MLOps, noting the session will be demo-heavy to illustrate these risks [0:00].
• A significant portion of the talk is dedicated to demonstrating how attackers can exploit the ML pipeline, with sections three and four focusing on the bulk of these offensive demonstrations [0:19].
• The presentation shifts to defensive measures in sections five and six, aiming to provide a comprehensive wrap-up on securing ML systems against these identified attack paths [0:23].
• The speaker references a recently released blog post detailing this research, encouraging the audience to review additional written material for deeper context [0:27].

Closing Statement: Understanding the intersection of DevOps and MLOps security is critical for protecting machine learning infrastructure from sophisticated attack paths.

Sources:

  • 0:00 Introduction to the topic of DevOps to MLOps attack paths.
  • 0:19 Overview of the demo-heavy structure focusing on offensive techniques.
  • 0:23 Transition to defensive strategies and conclusion.
  • 0:27 Reference to a related blog post for further reading.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

All right, so yeah, today we're going to talk about uh attack paths from DevOps to ML Ops. And as as mentioned, I am Brett Hawkins and I'm at Armory. Uh so this talk is going to be very demo-heavy. Uh probably half the talk is going to be demos. We're just going to go over some kind of background items uh before we get into really sections three and four is the bulk of this presentation. There's going to be a lot of demos. And then sections five and six we'll kind of switch gears to the defensive side and wrap things up. Uh before I do get started, I did release a blog post on this research last week. So if you wanted to snap the QR code, I'll leave this up here for for just a just a second um to kind of leave this up. All right. All right, so again uh I'm Brett. Uh you know, I focus on of…