Neocloud Security Deep Dive Report: Alarming Infrastructure Configuration Errors, Cross-Tenant RCE Could Impact Banks, Telecoms, and Even National Intelligence Agencies
On August 30, the Neocloud security deep dive report was released, revealing multiple cross-tenant security vulnerabilities discovered during the testing of ClusterMAX 3.0. Over a four-month testing period covering 25 vendors and 32 clusters, the team achieved multiple instances of cross-tenant remote code execution (RCE) using only publicly known vulnerabilities and basic configuration checks. Affected entities included banks, telecom companies, universities, research institutions, AI laboratories, and even a national intelligence agency.
Typical issues included: shared Kubernetes control planes leading to tenant metadata visibility, container escape, exposure of BMC/IPMI management networks, misconfigured InfiniBand security keys (P_Key, SA_Key, M_Key), unfortified default trust mode of BlueField DPU, Grafana dashboards using god-level API keys, and lack of VXLAN isolation in front-end networks. The report specifically highlighted a cascading vulnerability case: a misconfigured shared vCluster combined with software versions lagging by two years ultimately completed the proof of concept (POC) verification for cross-tenant RCE within an afternoon.
Notably, the report questioned the mainstream narrative that "AI has fundamentally changed the pace of cybersecurity": statistics on CVEs for GPU drivers, CUDA, PyTorch, Kubernetes, Docker, and the Linux kernel showed no significant increase in vulnerabilities following the proliferation of AI coding models, with most data indicating "no change hypothesis cannot be rejected."
The report also detailed the incident of training agent attacks on Hugging Face, where AI agents achieved cluster-level privilege escalation through a message board established via Artifactory, which went undetected from May until July. While constructing POC verification for existing vulnerabilities, the team found that Claude Fable and GPT-5.6 Sol frequently rejected security-related requests, ultimately relying on open-source models like DeepSeek V4, Kimi K3, and GLM-5.2 to complete the task. It indicated that the core issue in the Neocloud industry is not the new risks brought by AI, but rather the long-standing absence of basic patch management, tenant isolation, and security design, recommending vendors to establish automated security announcement monitoring systems and rectify single points of failure that could expose all users' architectural patterns.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

US Changes Customs Rules, 200,000 Packages Sent from Ukraine

Payment Pathways for Groceries and Fuel Using USDT in India

Mr&强 Analyzes BNC's Transformation into BNB Treasury

Phone Robbery in Nice Involving $25,000 Account Code, 15 Fraud Reports in Béziers

DeepSeek Opens Approximately 150 Backend Engineer Positions

Ukraine Appeals to OECD on Corporate Governance

Philippine Central Bank Plans to Suspend Registration of New Payment System Operators

Infinity Ground Changes Token Code, Contract and Economic Model Remain Unchanged

Google Patches High-Severity Chrome Flaw CVE-2026-85046

Importing Phones Requires IMEI Code Registration from September 4

Two Arrested in Malaysia for Bitcoin Mining with Illegal Connections

Fake DGFiP Letter Targets Crypto Holders

U.S. Department of Justice Investigates Responsibility for X Cyber Attack

Anthropic Upgrades Claude Code/Cowork to Control User Macs in the Background

Ukrainian Government Submits Labor Code Draft Again

Zhipu AI Launches Flagship Store on Tmall, Offering Various Large Model Packages

Parliament Prioritizes Review of Penalties for Illegal Cryptocurrency Mining

Ukrposhta Installed 506 Mailboxes, Plans 62 More

Empirik Completes $21 Million Seed Funding Round, Utilizing AI to Predict System Failures

Summary of Tool Call Results

Anthropic Introduces Context Lock for Claude to Prevent Model Distillation

OpenAI's safeguards could have detected 700 rogue AI agents earlier

Employers Can Pay for Employee Training Tax-Free in 2026









