Loading…
Friday November 6, 2026 3:30pm - 4:15pm PST
Standard SSRF mitigations are written around a specific threat model: an attacker reaching RFC 1918 space or link-local addresses through an application. Block 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, 169.254.0.0/16, done. This model works for application-layer SSRF.

IaaS platforms have a second trust layer this model does not address. When a platform builds internal services - request routing, worker scheduling, data pipeline sinks - those services communicate over a network the application-layer blocklist does not see. CGNAT space (100.64.0.0/10) is one example: used for internal carrier routing and often present in IaaS backend networks, but it appears in neither RFC 1918 nor link-local blocklists.

I spent several months building an automated pipeline to probe IaaS attack surfaces, and the same root cause kept appearing across unrelated products from the same provider: different entry points, same internal network reachability, same CGNAT address class. Four products, one underlying issue.

The automation made the pattern visible. A human researcher testing one product at a time would likely miss the connection. The pipeline - scanner output fed to an LLM reasoning layer that classifies, clusters, and flags for human review - surfaces structural patterns that individual test results obscure.

This talk covers: the technical mechanics of CGNAT SSRF (probes, indicators, what a response tells you), how I built the LLM-assisted research pipeline, how to structure a consolidated disclosure when you find a vulnerability class instead of a single bug, and what to look for when testing your own IaaS-hosted services.

Research conducted via responsible disclosure. Will be fully public before November 2026.
Speakers
avatar for Ofri Ouzan

Ofri Ouzan

Security Researcher, JFrog Security
Ofri Ouzan is a security researcher at JFrog Security. With over 6 years of experience in the cybersecurity field, she specializes in conducting security research focusing on vulnerabilities and exploitation. Ofri excels at exploring new technologies and developing solutions to address... Read More →
avatar for Stav David

Stav David

Founder building automated offensive security tooling

Stav David is a security researcher and founder who builds automated offensive security infrastructure. He started by building multi-cloud DDoS attack simulation tooling - real bot fleets testing whether mitigation vendors actually block what they claim to block. The recon pipeline... Read More →
Friday November 6, 2026 3:30pm - 4:15pm PST
Room: Seacliff AB (Bay Level)

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link