BTC $78,324.94 -0.53%
ETH $2,465.37 -0.46%
BNB $688.48 -1.38%
XRP $1.37 -2.32%
SOL $103.09 -3.17%
TRX $0.3328 -2.17%
DOGE $0.0827 -3.10%
ADA $0.1954 -3.91%
BCH $245.73 -2.43%
LINK $11.31 -2.29%
HYPE $81.70 -2.36%
AAVE $124.16 -1.54%
SUI $0.7185 -3.76%
XLM $0.1758 -2.35%
ZEC $834.33 -2.74%
BTC $78,324.94 -0.53%
ETH $2,465.37 -0.46%
BNB $688.48 -1.38%
XRP $1.37 -2.32%
SOL $103.09 -3.17%
TRX $0.3328 -2.17%
DOGE $0.0827 -3.10%
ADA $0.1954 -3.91%
BCH $245.73 -2.43%
LINK $11.31 -2.29%
HYPE $81.70 -2.36%
AAVE $124.16 -1.54%
SUI $0.7185 -3.76%
XLM $0.1758 -2.35%
ZEC $834.33 -2.74%

comm

All
Article
Flash

SemiAnalysis releases Neocloud security deep report: Infrastructure configuration errors are shocking, and cross-tenant RCE could affect banks, telecommunications, and even a country's intelligence agency

The semiconductor and AI independent research organization SemiAnalysis released a deep security report on Neocloud (new cloud), revealing various cross-tenant security vulnerabilities discovered during the ClusterMAX 3 testing period. In a four-month test covering 25 vendors and 32 clusters, the team achieved multiple instances of cross-tenant remote code execution (RCE) solely by exploiting publicly known vulnerabilities and basic configuration checks. Affected entities included banks, telecommunications companies, universities, research institutions, AI laboratories, and even a national intelligence agency.Typical issues included: shared Kubernetes control plane leading to tenant metadata visibility, container escape, exposure of BMC/IPMI management networks, incorrect configuration of InfiniBand security keys (P_Key, SA_Key, M_Key), unfortified default trust mode of BlueField DPU, Grafana monitoring dashboards using god-level API keys, and lack of VXLAN isolation in front-end networks. The report specifically pointed out a cascading vulnerability case: a misconfiguration of shared vCluster combined with software versions being two years out of date ultimately completed the POC verification of cross-tenant RCE within an afternoon.Notably, the report questioned the mainstream narrative that "AI has fundamentally changed the pace of cybersecurity": statistics on CVEs for NVIDIA GPU drivers, CUDA, PyTorch, Kubernetes, Docker, and the Linux kernel showed that there was no significant increase in vulnerabilities after the popularization of AI coding models, with most data supporting the "no change hypothesis." The report also detailed the incident where an OpenAI-trained agent attacked Hugging Face, where the AI agent achieved cluster-level privilege escalation through a message board established via Artifactory, which went undetected from May to July. While building POC verification for existing vulnerabilities, the team found that Claude Fable and GPT-5.6 Sol frequently rejected security-related requests, ultimately relying on open-source models such as DeepSeek V4, Kimi K3, and GLM-5.2 to complete the task.SemiAnalysis stated that the core issue in the Neocloud (new cloud) industry is not the new risks brought by AI, but rather the long-term absence of basic patch management, tenant isolation, and security design. They recommended that vendors establish automated security announcement monitoring systems and rectify single points of failure that could expose all users' architectural patterns.

first_img The president of the Polish Olympic Committee was arrested on suspicion of cryptocurrency bribery

Polish Olympic Committee President Radosław Piszczek was arrested on Thursday, suspected of receiving kickbacks from the cryptocurrency platform Zondacrypto during the signing of a sponsorship agreement. Polish Sports Minister Jakub Rudnicki confirmed the arrest on the X platform, stating, "Such a person should not hold the position of President of the Polish Olympic Committee; Piszczek has brought shame to Polish sports." Interior Minister Marcin Kwiatkowski referred to him as "a symbol of extreme corruption plaguing the Olympic movement."According to the investigation, Piszczek facilitated the sponsorship agreement between the Polish Olympic Committee and Zondacrypto in October 2025, which promised cryptocurrency rewards to medalists of the 2026 Milan-Cortina Winter Olympics. The Polish government accused Zondacrypto of having ties to nationalist opposition groups, organized crime, and Russian intelligence agencies, estimating that the platform's collapse caused losses of about 350 million zlotys (approximately 80 million euros), affecting around 30,000 people. The Interior Minister described Zondacrypto as "essentially a Ponzi scheme."Media investigations also revealed that Piszczek received a Patek Philippe watch worth approximately 40,000 euros from Zondacrypto CEO Przemysław Kral, who claimed the watch was purchased out of his own pocket. Kral is currently cooperating with prosecutors in hopes of a reduced sentence. Zondacrypto was founded by Sylwester Sucheck in 2014, who went missing in 2022, with Kral taking over his position. The Polish prosecutors launched an investigation in April of this year, and most Polish sports federations subsequently called for Piszczek's resignation.
app_icon
ChainCatcher Building the Web3 world with innovations.