Talk Intermediate 14:50 - 15:20 August 07, 2026

Michal Kamensky

The tale of CVE-2026-40412, hacking Microsoft Planetary Computer Pro service. This talk will walk you through the journey of discovering a chain of vulnerabilities in the service itself and in its open source dependencies. All those findings combined resulted in cross tenant access. From a file read, to exploiting a buffer overflow (bypassing ASLR) to finding and exploiting a devastating design flaw. This talk will address the unique challenges of exploiting memory corruption bugs in cloud services, the pitfalls of cloud services’ architecture and how we helped the engineering team fix the issues we found at the design level.

Michal Kamensky

Security Researcher

Michal is a security researcher on the Microsoft STORM team, where she focuses on vulnerability research across the hybrid cloud domain. Previously she has worked as a security researcher at Bounce Security, and for the last few years volunteers as a Defcon goon. She enjoys diving into large code bases, understanding complex architectures, and eliminating vulnerabilities at scale.