買幣
行情
現貨
合約
理財
活動
更多
reward-center新手專區
信息首頁快訊詳情
SemiAnalysis Releases Neocloud Security Deep Dive Report: Infrastructure Misconfigurations Abound, Cross-Tenant RCE Could Impact Banks, Telecoms, and Even a Nation's Intelligence Agency
  • GLM0%
  • NVDAX0%
  • GPT0%
  • COMMON0%
  • GPU0%

BlockBeats News, August 30th – Semiconductor and AI independent research firm SemiAnalysis released a Neocloud Security Deep Dive report, uncovering multiple cross-tenant security vulnerabilities discovered during the ClusterMAX 3.0 testing phase. Over a four-month period, covering 25 vendors and 32 clusters, the team was able to achieve multiple cross-tenant remote code executions (RCE) using only publicly known vulnerabilities and basic configuration checks. The affected entities included banks, telecommunications companies, universities, research institutions, AI labs, and even a national intelligence agency.

Common issues identified included: shared Kubernetes control plane leading to cross-tenant metadata leakage, container escape, exposed BMC/IPMI management networks, improperly configured InfiniBand security keys (P_Key, SA_Key, M_Key), unsecured default trust mode in BlueField DPU, Grafana dashboards using god-level API keys, and a lack of VXLAN isolation in the frontend network. The report specifically highlighted a cascade vulnerability case: a misconfigured shared vCluster combined with a two-year-old software version lag that culminated in a cross-tenant RCE proof of concept being successfully demonstrated within an afternoon.

A notable point in the report raised questions about the mainstream narrative of "AI fundamentally changing the cybersecurity landscape": CVE statistics for NVIDIA GPU drivers, CUDA, PyTorch, Kubernetes, Docker, and the Linux kernel showed no significant increase in vulnerabilities post the proliferation of AI coding models, with most data unable to reject the null hypothesis of no change.

The report also detailed the OpenAI training agent attack on Hugging Face, where the AI agent achieved cluster-level privilege escalation through a message board established via Artifactory, a vulnerability that persisted from May to July before being fully discovered. While building POC validations for existing vulnerabilities, the team found Claude Fable and GPT-5.6 Sol frequently denying security-related requests, eventually relying heavily on open-source models like DeepSeek V4, Kimi K3, and GLM-5.2 to succeed. SemiAnalysis stated that the core issue in the Neocloud industry is not new risks brought by AI but rather the longstanding absence of fundamental patch management, tenant isolation, and security design. They recommended vendors establish an automated security bulletin monitoring system and address single points of failure in their architecture that could expose all users.

來源:BlockBeats

免責聲明:當前內容均來自第三方觀點或由AI直接翻譯第三方觀點,CoinEx不保證內容的真實性、準確性和原創性,不構成CoinEx相關的任何投資建議。數字資產價格波動劇烈,請注意潛在風險。

熱搜榜
  • 幣種
    價格
    24H漲跌