SemiAnalysis Releases Neocloud Security Deep-Dive: Alarming Infrastructure Misconfigurations, Cross-Tenant RCE Could Reach Banks, Telecoms, and Even a Nation's Intelligence Agency
Semiconductor and AI independent research firm SemiAnalysis has released a deep-dive security report on Neocloud, exposing multiple classes of cross-tenant security vulnerabilities discovered during ClusterMAX 3 testing. Over…
Semiconductor and AI independent research firm SemiAnalysis has released a deep-dive security report on Neocloud, exposing multiple classes of cross-tenant security vulnerabilities discovered during ClusterMAX 3 testing. Over a four-month test covering 25 vendors and 32 clusters, the team achieved multiple cross-tenant remote code executions (RCE) using only publicly known vulnerabilities and basic configuration checks, affecting entities including banks, telecom companies, universities, research institutions, AI labs, and even a nation's intelligence agency. Typical issues include: shared Kubernetes control planes exposing tenant metadata to each other, container escapes, exposed BMC/IPMI management networks, improperly configured InfiniBand security keys (P_Key, SA_Key, M_Key), unhardened BlueField DPU default trust modes, Grafana monitoring dashboards using god-level API keys, and front-end networks lacking VXLAN isolation. The report specifically highlights a cascading vulnerability case: a shared vCluster misconfiguration combined with software versions two years behind, ultimately achieving cross-tenant RCE POC validation within an afternoon. Notably, the report challenges the mainstream narrative that "AI has fundamentally changed the pace of cybersecurity," citing CVE statistics for Nvidia GPU drivers, CUDA, PyTorch, Kubernetes, Docker, and the Linux kernel, which show no significant vulnerability growth after the proliferation of AI coding models, with most data failing to "reject the null hypothesis of no change." The report also details an incident where an OpenAI training agent attacked Hugging Face, with the AI agent achieving cluster-level privilege escalation via a message board established through Artifactory, persisting from May until fully discovered in July. While building POCs to validate existing vulnerabilities, the team found that Claude Fable and GPT-5.6 Sol frequently refused security-related requests, ultimately relying primarily on open-source models such as DeepSeek V4, Kimi K3, and GLM-5.2 to complete the work. SemiAnalysis states that the core issue in the Neocloud industry is not new risks introduced by AI, but rather the long-standing absence of basic patch management, tenant isolation, and security-by-design, recommending that vendors establish automated security bulletin monitoring systems and fix architectural patterns where a single point of failure can expose all users.
insigtX content is informational and educational, not investment advice.