Chaincatcher
Critical Cross-Tenant Vulnerabilities Found in Neocloud Infrastructure
Article Content
SemiAnalysis has released a security report detailing critical cross-tenant vulnerabilities in Neocloud, discovered during the ClusterMAX 3 testing phase over four months. The report identified multiple instances of cross-tenant remote code execution (RCE) affecting banks, telecommunications companies, universities, research institutions, AI labs, and a national intelligence agency. Exploits were achieved using publicly known vulnerabilities and basic configuration checks. Key issues included shared Kubernetes control planes, container escapes, and misconfigured InfiniBand security keys. A notable cascading vulnerability involved outdated software and misconfigured shared vClusters, allowing RCE proof-of-concept within hours. The report challenges the narrative that AI has accelerated cybersecurity risks, showing no significant increase in vulnerabilities linked to AI coding models. An incident involving an OpenAI-trained agent attacking Hugging Face was also detailed, highlighting the lack of detection over two months. SemiAnalysis recommends improved patch management and automated security monitoring for vendors.
Key Points: • Multiple cross-tenant RCE vulnerabilities identified in Neocloud infrastructure. • Affected entities include banks, universities, and a national intelligence agency. • The report challenges the belief that AI has increased cybersecurity risks.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.