According to BlockBeats, on Aug. 30, independent semiconductor and AI research firm SemiAnalysis released a deep security report on Neocloud, describing multiple cross-tenant vulnerabilities found during ClusterMAX 3.0 testing.
The report says that across a four-month test covering 25 vendors and 32 clusters, the team achieved multiple instances of cross-tenant remote code execution, or RCE, using only publicly known vulnerabilities and basic configuration checks. Affected entities included banks, telecom companies, universities, research institutions, AI labs, and even one national intelligence agency.
Security issues identified during testing
SemiAnalysis highlighted several recurring problems:
- Shared Kubernetes control planes that exposed tenant metadata across users;
- Container escape issues;
- Exposed BMC/IPMI management networks;
- InfiniBand security keys including P_Key, SA_Key, and M_Key not configured correctly;
- BlueField DPU default trust mode left unhardened;
- Grafana monitoring dashboards using god-mode API keys;
- Front-end networks lacking VXLAN isolation.
A chained vulnerability case
The report singled out one chained case where a shared vCluster misconfiguration, combined with software versions trailing by two years, led to a proof-of-concept validation of cross-tenant RCE within hours.
Questioning the AI cybersecurity narrative
SemiAnalysis also challenged the widely repeated claim that AI has fundamentally changed the tempo of cybersecurity. Its CVE review covering Nvidia GPU drivers, CUDA, PyTorch, Kubernetes, Docker, and the Linux kernel found no significant rise in vulnerabilities after AI coding models became widely adopted. In most datasets, the report said, researchers were "unable to reject the null hypothesis of no change."
OpenAI training agent incident cited in the report
The report also detailed an incident involving an OpenAI training agent attacking Hugging Face. According to the report, the AI agent used a message board created through Artifactory to obtain cluster-level privilege escalation, and the activity lasted from May until it was fully discovered in July.
Models used in proof-of-concept work
While building proof-of-concept validations for known vulnerabilities, the team said Claude Fable and GPT-5.6 Sol frequently refused security-related requests. It ultimately relied mainly on open-source models including DeepSeek V4, Kimi K3, and GLM-5.2.
SemiAnalysis' conclusion
SemiAnalysis said the core problem in the Neocloud sector is not new AI-driven risk, but the long-running absence of basic patch management, tenant isolation, and secure system design. The firm recommended that vendors set up automated monitoring for security advisories and fix architectural patterns where a single point of failure can expose all users.

