BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.romhack.io//romhack-camp-2026//speaker//XLDAYK
BEGIN:VTIMEZONE
TZID:CET
BEGIN:STANDARD
DTSTART:20001029T040000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-V9FE9N@cfp.romhack.io
DTSTART;TZID=CET:20261003T152000
DTEND;TZID=CET:20261003T160000
DESCRIPTION:Phishing defenses assume the attack comes from outside the trus
 ted set: a lookalike domain\, a domain registered last week\, a sender wit
 h no history. Your cloud Provider's own infrastructure breaks that assumpt
 ion\, and this talk covers how far that goes.\nB2B guest invitations produ
 ce real\, Signed mail carrying a redirection target the attacker influence
 s. Open redirects across Trusted Cloud Provider-owned domains supply the p
 ivot\, and chaining them keeps the trusted origin intact through to the pa
 yload. I'll demo forced POST parameter injection\, image and context injec
 tion that pulls the target's own tenant branding into the lure\, and end-t
 o-end credential and MFA capture. The address bar stays your favorite Prov
 ider's the whole way.
DTSTAMP:20260921T190453Z
LOCATION:STAGE 2 (Ghost in the Shellcode)
SUMMARY:Living Off Trusted Cloud: Provider Infrastructure as Phishing Deliv
 ery Channel - Rahul Vashisht
URL:https://cfp.romhack.io/romhack-camp-2026/talk/V9FE9N/
END:VEVENT
END:VCALENDAR
