BTC $78,111.20 -0.02%
ETH $2,438.46 -0.81%
BNB $685.81 -1.05%
XRP $1.37 -1.74%
SOL $102.82 -2.09%
TRX $0.3365 -1.23%
DOGE $0.0825 -2.51%
ADA $0.1957 -2.57%
BCH $247.49 +0.94%
LINK $11.24 -1.37%
HYPE $81.33 -2.59%
AAVE $123.58 -0.48%
SUI $0.7214 -2.58%
XLM $0.1761 -1.92%
ZEC $829.89 -0.75%
BTC $78,111.20 -0.02%
ETH $2,438.46 -0.81%
BNB $685.81 -1.05%
XRP $1.37 -1.74%
SOL $102.82 -2.09%
TRX $0.3365 -1.23%
DOGE $0.0825 -2.51%
ADA $0.1957 -2.57%
BCH $247.49 +0.94%
LINK $11.24 -1.37%
HYPE $81.33 -2.59%
AAVE $123.58 -0.48%
SUI $0.7214 -2.58%
XLM $0.1761 -1.92%
ZEC $829.89 -0.75%

mu

All
Article
Flash

first_img OpenAI terminates the Cursor model contract, Musk criticizes Altman

OpenAI has notified SpaceX that it will terminate the contract to provide models for the AI coding tool Cursor it acquired, with a suggested termination date of November 12, stating that this is the longest notice period stipulated in the contract. OpenAI expressed that the decision was difficult, as it values the widespread use of its models by developers, but due to Musk's past breaches of contract, it does not trust SpaceX to use the technology as agreed, and mentioned issues related to the use of OpenAI models during xAI training and contract problems when acquiring X.Musk stated on X that he does not care at all and referred to Sam Altman and Greg Brockman as frauds, accusing them of stealing from an open nonprofit organization. Musk was a co-founder of OpenAI but later filed a $150 billion lawsuit against OpenAI and lost due to exceeding the deadline. OpenAI had attempted to acquire Cursor's developer Anysphere but was unsuccessful, while SpaceX acquired Cursor for $60 billion, with the merger completed on August 15.Michael Truel, co-founder of Cursor and now an executive at SpaceX, stated that Cursor views the OpenAI platform as neutral infrastructure and is negotiating with OpenAI, noting that OpenAI models account for 5% of Cursor's user traffic. Tom Brown, co-founder of Anthropic, stated that they will continue to expand computing power to provide the Claude model on Cursor.

SemiAnalysis releases Neocloud security deep report: Infrastructure configuration errors are shocking, and cross-tenant RCE could affect banks, telecommunications, and even a country's intelligence agency

The semiconductor and AI independent research organization SemiAnalysis released a deep security report on Neocloud (new cloud), revealing various cross-tenant security vulnerabilities discovered during the ClusterMAX 3 testing period. In a four-month test covering 25 vendors and 32 clusters, the team achieved multiple instances of cross-tenant remote code execution (RCE) solely by exploiting publicly known vulnerabilities and basic configuration checks. Affected entities included banks, telecommunications companies, universities, research institutions, AI laboratories, and even a national intelligence agency.Typical issues included: shared Kubernetes control plane leading to tenant metadata visibility, container escape, exposure of BMC/IPMI management networks, incorrect configuration of InfiniBand security keys (P_Key, SA_Key, M_Key), unfortified default trust mode of BlueField DPU, Grafana monitoring dashboards using god-level API keys, and lack of VXLAN isolation in front-end networks. The report specifically pointed out a cascading vulnerability case: a misconfiguration of shared vCluster combined with software versions being two years out of date ultimately completed the POC verification of cross-tenant RCE within an afternoon.Notably, the report questioned the mainstream narrative that "AI has fundamentally changed the pace of cybersecurity": statistics on CVEs for NVIDIA GPU drivers, CUDA, PyTorch, Kubernetes, Docker, and the Linux kernel showed that there was no significant increase in vulnerabilities after the popularization of AI coding models, with most data supporting the "no change hypothesis." The report also detailed the incident where an OpenAI-trained agent attacked Hugging Face, where the AI agent achieved cluster-level privilege escalation through a message board established via Artifactory, which went undetected from May to July. While building POC verification for existing vulnerabilities, the team found that Claude Fable and GPT-5.6 Sol frequently rejected security-related requests, ultimately relying on open-source models such as DeepSeek V4, Kimi K3, and GLM-5.2 to complete the task.SemiAnalysis stated that the core issue in the Neocloud (new cloud) industry is not the new risks brought by AI, but rather the long-term absence of basic patch management, tenant isolation, and security design. They recommended that vendors establish automated security announcement monitoring systems and rectify single points of failure that could expose all users' architectural patterns.
app_icon
ChainCatcher Building the Web3 world with innovations.