BTC $78,993.96 +0.89%
ETH $2,510.13 +2.15%
BNB $701.24 +1.07%
XRP $1.42 +1.60%
SOL $106.56 +0.84%
TRX $0.3405 +0.40%
DOGE $0.0861 +0.89%
ADA $0.2047 +1.31%
BCH $254.16 +2.64%
LINK $11.66 +1.68%
HYPE $83.21 +0.12%
AAVE $128.66 +3.49%
SUI $0.7591 +1.63%
XLM $0.1815 +1.03%
ZEC $870.16 +4.01%
BTC $78,993.96 +0.89%
ETH $2,510.13 +2.15%
BNB $701.24 +1.07%
XRP $1.42 +1.60%
SOL $106.56 +0.84%
TRX $0.3405 +0.40%
DOGE $0.0861 +0.89%
ADA $0.2047 +1.31%
BCH $254.16 +2.64%
LINK $11.66 +1.68%
HYPE $83.21 +0.12%
AAVE $128.66 +3.49%
SUI $0.7591 +1.63%
XLM $0.1815 +1.03%
ZEC $870.16 +4.01%

neocloud

All
Article
Flash

SemiAnalysis releases Neocloud security deep report: Infrastructure configuration errors are shocking, and cross-tenant RCE could affect banks, telecommunications, and even a country's intelligence agency

The semiconductor and AI independent research organization SemiAnalysis released a deep security report on Neocloud (new cloud), revealing various cross-tenant security vulnerabilities discovered during the ClusterMAX 3 testing period. In a four-month test covering 25 vendors and 32 clusters, the team achieved multiple instances of cross-tenant remote code execution (RCE) solely by exploiting publicly known vulnerabilities and basic configuration checks. Affected entities included banks, telecommunications companies, universities, research institutions, AI laboratories, and even a national intelligence agency.Typical issues included: shared Kubernetes control plane leading to tenant metadata visibility, container escape, exposure of BMC/IPMI management networks, incorrect configuration of InfiniBand security keys (P_Key, SA_Key, M_Key), unfortified default trust mode of BlueField DPU, Grafana monitoring dashboards using god-level API keys, and lack of VXLAN isolation in front-end networks. The report specifically pointed out a cascading vulnerability case: a misconfiguration of shared vCluster combined with software versions being two years out of date ultimately completed the POC verification of cross-tenant RCE within an afternoon.Notably, the report questioned the mainstream narrative that "AI has fundamentally changed the pace of cybersecurity": statistics on CVEs for NVIDIA GPU drivers, CUDA, PyTorch, Kubernetes, Docker, and the Linux kernel showed that there was no significant increase in vulnerabilities after the popularization of AI coding models, with most data supporting the "no change hypothesis." The report also detailed the incident where an OpenAI-trained agent attacked Hugging Face, where the AI agent achieved cluster-level privilege escalation through a message board established via Artifactory, which went undetected from May to July. While building POC verification for existing vulnerabilities, the team found that Claude Fable and GPT-5.6 Sol frequently rejected security-related requests, ultimately relying on open-source models such as DeepSeek V4, Kimi K3, and GLM-5.2 to complete the task.SemiAnalysis stated that the core issue in the Neocloud (new cloud) industry is not the new risks brought by AI, but rather the long-term absence of basic patch management, tenant isolation, and security design. They recommended that vendors establish automated security announcement monitoring systems and rectify single points of failure that could expose all users' architectural patterns.
app_icon
ChainCatcher Building the Web3 world with innovations.