[SemiAnalysis Releases Neocloud Security In-Depth Report: Shocking Infrastructure Misconfigurations, Cross-Tenant RCE Could Impact Banks, Telecoms, and Even National Intelligence Agencies] BlockBeats News, August 30 – The independent semiconductor and AI research organization SemiAnalysis has released an in-depth security report on Neocloud, exposing multiple cross-tenant security vulnerabilities discovered during the testing of ClusterMAX 3.0. Over a four-month testing period covering 25 vendors and 32 clusters, the team was able to execute multiple cross-tenant remote code executions (RCE) using only publicly known vulnerabilities and basic configuration checks. Affected entities include banks, telecom companies, universities, research institutions, AI labs, and even a national intelligence agency. Typical issues include: shared Kubernetes control planes leading to tenant metadata exposure, container escapes, exposed BMC/IPMI management networks, improperly configured InfiniBand security keys (P_Key, SA_Key, M_Key), unfortified default trust modes in BlueField DPUs, Grafana monitoring dashboards using god-level API keys, and lack of VXLAN isolation in front-end networks. The report highlights a specific cascading vulnerability case: a shared vCluster misconfiguration combined with software versions lagging two years behind, which ultimately enabled proof-of-concept (POC) validation of cross-tenant RCE within an afternoon. Notably, the report challenges the mainstream narrative that "AI has fundamentally changed the pace of cybersecurity." CVE statistics for NVIDIA GPU drivers, CUDA, PyTorch, Kubernetes, Docker, and the Linux kernel show no significant increase in vulnerabilities following the proliferation of AI coding models, with most data failing to reject the null hypothesis of no change. The report also details an incident where an OpenAI training agent attacked Hugging Face. The AI agent exploited a message board established via Artifactory to achieve cluster-level privilege escalation, which went undetected from May until July. While constructing POC validations for existing vulnerabilities, the team found that Claude Fable and GPT-5.6 Sol frequently refused security-related requests, ultimately relying on open-source models like DeepSeek V4, Kimi K3, and GLM-5.2 to complete the task. SemiAnalysis stated that the core issue in the Neocloud industry is not new risks introduced by AI but rather the long-standing neglect of basic patch management, tenant isolation, and secure design. They recommend that vendors establish automated security advisory monitoring systems and address architectural models where single points of failure can expose all users. [Original Link]
--
Loading...