BTC $78,455.98 -0.66%
ETH $2,484.48 -0.01%
BNB $752.53 +1.82%
XRP $1.42 +1.64%
SOL $103.35 -0.34%
TRX $0.3385 +1.25%
DOGE $0.0898 -0.53%
ADA $0.2198 +0.27%
BCH $258.05 -0.12%
LINK $12.50 -1.68%
HYPE $84.69 -0.62%
AAVE $128.90 -2.08%
SUI $0.8106 -0.72%
XLM $0.1879 -2.45%
ZEC $1,183.29 +4.24%
BTC $78,455.98 -0.66%
ETH $2,484.48 -0.01%
BNB $752.53 +1.82%
XRP $1.42 +1.64%
SOL $103.35 -0.34%
TRX $0.3385 +1.25%
DOGE $0.0898 -0.53%
ADA $0.2198 +0.27%
BCH $258.05 -0.12%
LINK $12.50 -1.68%
HYPE $84.69 -0.62%
AAVE $128.90 -2.08%
SUI $0.8106 -0.72%
XLM $0.1879 -2.45%
ZEC $1,183.29 +4.24%

telecom

All
Article
Flash

SemiAnalysis releases Neocloud security deep report: Infrastructure configuration errors are shocking, and cross-tenant RCE could affect banks, telecommunications, and even a country's intelligence agency

The semiconductor and AI independent research organization SemiAnalysis released a deep security report on Neocloud (new cloud), revealing various cross-tenant security vulnerabilities discovered during the ClusterMAX 3 testing period. In a four-month test covering 25 vendors and 32 clusters, the team achieved multiple instances of cross-tenant remote code execution (RCE) solely by exploiting publicly known vulnerabilities and basic configuration checks. Affected entities included banks, telecommunications companies, universities, research institutions, AI laboratories, and even a national intelligence agency.Typical issues included: shared Kubernetes control plane leading to tenant metadata visibility, container escape, exposure of BMC/IPMI management networks, incorrect configuration of InfiniBand security keys (P_Key, SA_Key, M_Key), unfortified default trust mode of BlueField DPU, Grafana monitoring dashboards using god-level API keys, and lack of VXLAN isolation in front-end networks. The report specifically pointed out a cascading vulnerability case: a misconfiguration of shared vCluster combined with software versions being two years out of date ultimately completed the POC verification of cross-tenant RCE within an afternoon.Notably, the report questioned the mainstream narrative that "AI has fundamentally changed the pace of cybersecurity": statistics on CVEs for NVIDIA GPU drivers, CUDA, PyTorch, Kubernetes, Docker, and the Linux kernel showed that there was no significant increase in vulnerabilities after the popularization of AI coding models, with most data supporting the "no change hypothesis." The report also detailed the incident where an OpenAI-trained agent attacked Hugging Face, where the AI agent achieved cluster-level privilege escalation through a message board established via Artifactory, which went undetected from May to July. While building POC verification for existing vulnerabilities, the team found that Claude Fable and GPT-5.6 Sol frequently rejected security-related requests, ultimately relying on open-source models such as DeepSeek V4, Kimi K3, and GLM-5.2 to complete the task.SemiAnalysis stated that the core issue in the Neocloud (new cloud) industry is not the new risks brought by AI, but rather the long-term absence of basic patch management, tenant isolation, and security design. They recommended that vendors establish automated security announcement monitoring systems and rectify single points of failure that could expose all users' architectural patterns.

South Korea promotes new regulations for telecom financial fraud prevention, with encrypted assets included in the scope of victim compensation

According to Etoday, the Financial Services Commission of South Korea has announced a draft amendment to the "Special Law on Preventing Telecom Financial Fraud and Returning Victim Funds," planning to include funds from phone scams that are transferred to crypto assets within the scope of victim compensation, and to clarify the standards for the return and valuation of crypto assets. The relevant regulations are expected to officially take effect on October 1.According to the new regulations, if the frozen assets are cryptocurrencies, victims will generally be compensated based on the type and quantity of assets; if the defrauded assets differ in form from the frozen assets, compensation will be made in the form of assets that existed at the time the account was frozen. In cases where cash and crypto assets are mixed, the regulatory authorities will value the crypto assets based on the market price at the time of freezing to determine the final compensation amount.The Financial Services Commission of South Korea stated that clarifying the form of returned assets and the timing of valuation will help achieve faster and fairer compensation in complex cases involving mixed funds from multiple victims. It is reported that the public consultation for the draft amendment will continue until August 24.
app_icon
ChainCatcher Building the Web3 world with innovations.