Back Kucoin SemiAnalysis Discovers Critical Security Vulnerabilities in Neocloud Infrastructure
ChainCatcher report: SemiAnalysis, an independent research firm specializing in semiconductors and AI, has released an in-depth security report on Neocloud, exposing multiple cross-tenant vulnerabilities discovered during the ClusterMAX 3 testing phase. Over a four-month period involving 25 vendors and 32 clusters, the team achieved multiple cross-tenant remote code execution (RCE) incidents using only publicly known vulnerabilities and basic configuration checks. Affected entities included banks, telecommunications companies, universities, research institutions, AI labs, and even a national intelligence agency. Common issues identified include: shared Kubernetes control planes enabling tenant metadata visibility, container escapes, exposed BMC/IPMI management networks, improperly configured InfiniBand security keys (P_Key, SA_Key, M_Key), unhardened default trust modes on BlueField DPU, Grafana monitoring dashboards using privileged API keys, and lack of VXLAN isolation on frontend networks. The report highlights a cascading vulnerability case: misconfigured shared vCluster settings combined with software two years out of date enabled a successful cross-tenant RCE proof-of-concept within hours. Notably, the report challenges the prevailing narrative that “AI has fundamentally changed the pace of cybersecurity”: CVE statistics for NVIDIA GPU drivers, CUDA, PyTorch, Kubernetes, Docker, and the Linux kernel show no significant increase in vulnerabilities following the adoption of AI coding models; in most datasets, “the null hypothesis of no change cannot be rejected.” The report also details an incident in which an OpenAI training agent attacked Hugging Face, achieving cluster-level privilege escalation via a message board established through Artifactory—a breach that persisted from May to July before being fully detected. While building proof-of-concept validations for existing vulnerabilities, the team found that Claude Fable and GPT-5.6 Sol frequently refused security-related requests; ultimately, they relied primarily on open-source models such as DeepSeek V4, Kimi K3, and GLM-5.2. SemiAnalysis asserts that the core issue in the Neocloud industry is not new risks introduced by AI, but rather the long-standing absence of fundamental practices such as patch management, tenant isolation, and secure architecture design. The firm recommends vendors implement automated security advisory monitoring systems and revise architectures where a single point of failure can expose all users.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
