
DEF CON 33 - Preventing One of The Largest Supply Chain Attacks in History - Maksim Shudrak
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 38:00
Max, a security researcher, presents a study on exploiting abandoned AWS S3 buckets for supply chain attacks, demonstrating how attackers can claim these resources to deliver malicious payloads using automated scanning and LLMs.
Key Takeaways:
• Supply Chain Risk: By claiming deleted S3 buckets, attackers can serve malware to scripts or applications that automatically pull executables or libraries, bypassing perimeter defenses.
• Massive Scale: Scanning GitHub, PyPI, Maven, and malware databases revealed over 5,000 reclaimable buckets, resulting in 26GB of logs and traffic from 243,000 hosts globally.
• AI Efficiency: Custom LLM agents were essential for filtering millions of log requests to identify 500 sensitive buckets, reducing classification time from months to days.
• Critical Exploits: Poisoned PyTorch models, binaries, and package dependencies allowed arbitrary code execution on victim machines, impacting Fortune 500 companies and government entities.
• Malware Hijacking: Research showed that malware families like RK Stealer and Linker rely on abandoned buckets, allowing third parties to hijack their command and control infrastructure.
• Remediation: Solutions involve non-recyclable bucket names and scanning code for dangling references, though cloud providers must ultimately adopt secure-by-default designs.
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
I'm going to get uh Maxim going here fairly quickly because he was asking me about the timer very quickly which means he has a lot to cover and it's a super important topic about supply chain attacks because if the if the robots don't get us this will have a wonderful time. Thank you. Let's give him a big round of applause and a big welcome. Thank you. Imagine one sunny morning you read the news. A crypto worm disrupts operations of hundreds of companies around the world and government networks of 25 countries. The war is spreading and the initial blast radius is estimated to be around 28,000 machines and now likely affecting much more computers around the planet. Uh security industry struggle to understand how did this happen. There's no one source of compromise. Eventually, a security re…