Neocloud Security Deep Dive Report: Alarming Infrastructure Configuration Errors, Cross-Tenant RCE Could Impact Banks, Telecoms, and Even National Intelligence Agencies
On August 30, the Neocloud security deep dive report was released, revealing multiple cross-tenant security vulnerabilities discovered during the testing of ClusterMAX 3.0. Over a four-month testing period covering 25 vendors and 32 clusters, the team achieved multiple instances of cross-tenant remote code execution (RCE) using only publicly known vulnerabilities and basic configuration checks. Affected entities included banks, telecom companies, universities, research institutions, AI laboratories, and even a national intelligence agency.
Typical issues included: shared Kubernetes control planes leading to tenant metadata visibility, container escape, exposure of BMC/IPMI management networks, misconfigured InfiniBand security keys (P_Key, SA_Key, M_Key), unfortified default trust mode of BlueField DPU, Grafana dashboards using god-level API keys, and lack of VXLAN isolation in front-end networks. The report specifically highlighted a cascading vulnerability case: a misconfigured shared vCluster combined with software versions lagging by two years ultimately completed the proof of concept (POC) verification for cross-tenant RCE within an afternoon.
Notably, the report questioned the mainstream narrative that "AI has fundamentally changed the pace of cybersecurity": statistics on CVEs for GPU drivers, CUDA, PyTorch, Kubernetes, Docker, and the Linux kernel showed no significant increase in vulnerabilities following the proliferation of AI coding models, with most data indicating "no change hypothesis cannot be rejected."
The report also detailed the incident of training agent attacks on Hugging Face, where AI agents achieved cluster-level privilege escalation through a message board established via Artifactory, which went undetected from May until July. While constructing POC verification for existing vulnerabilities, the team found that Claude Fable and GPT-5.6 Sol frequently rejected security-related requests, ultimately relying on open-source models like DeepSeek V4, Kimi K3, and GLM-5.2 to complete the task. It indicated that the core issue in the Neocloud industry is not the new risks brought by AI, but rather the long-standing absence of basic patch management, tenant isolation, and security design, recommending vendors to establish automated security announcement monitoring systems and rectify single points of failure that could expose all users' architectural patterns.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

How Uniswap's Fee Switch Redefined Revenue

Arbitrum Nova Migration Window Ends, Transitioning to Minimal Maintenance Mode

Debt Expansion and Currency Shuffle: The Biggest Beta Opportunity in the Crypto Market According to Hayes

Sui Chain DeFi Protocol Full Sail Announces Liquidation: $91,000 Lost Due to Attack on Oracle Switchboard

G20 Supports Regulatory Path for Digital Assets, Strengthens Anti-Money Laundering Enforcement Requirements

Jupiter Launches Universal Deposit, Supporting Multi-Chain Asset Cross-Chain Exchange for USDC
Leverage, Ferraris, and the Law of Attraction: Carl Moon’s "First Life" | WE TALK by WEEX
From a supermarket clerk in Northern Europe to a trader, racer, and musician who dictates his own destiny, Carl Moon’s story isn’t a simple get-rich-quick fantasy. It’s a long-term, self-driven game of goals, discipline, and risk control.

Coldcard Wave 3 Attackers Transfer Stolen Funds for the First Time, Some Assets Converted to ETH

Three Public Chains Halt Operations in Four Days: Who Has the Power to Press the Pause Button?

Kraken IPO delayed until Q2 2027: report

Goldman Sachs, BofA and 19 Other Banks Plan U.S. Dollar Stablecoin Launch

Saudi Arabia Confirms Death of Two Filipino Sailors in Iranian Attack on Oil Tanker

Tracking Cryptocurrency May Be Included in Exporters' Currency Revenue Control

Backpack Adds Micron, SanDisk Shares as Margin Collateral

What is Hedera Hashgraph and how does HBAR work?

Agentic Payment Research Report: From Payment Pathways to Ecological Landscape

What is Chainlink and how does the LINK oracle network work?

Wyoming Adopts Chainlink for FRNT On-Chain Reserve Verification

Crypto Will Eventually Merge with AI Finance

From Glamsterdam to Hegotá: What Will Ethereum Address in Its Next Phase After Scaling?

The Similarities and Differences of Meme from a Long-Cycle Perspective

August Cryptocurrency Security Incident Report: Total Loss of $215 Million, Price Manipulation and Governance Vulnerabilities as Major Attack Methods

TAC Report Reveals Cosmos EVM Vulnerability Attackers Cashed Out Approximately $1 Million

Cronos' Single-Player Philosophy: Theft Is No Big Deal, Just Roll Back

China's Blockchain BaaS Market Expected to Reach 2.07 Billion Yuan by 2025, Ant Group Leads with 32.4% Market Share

AI Networking (Broadcom/AVGO) and Space Tech (RKLB): The Impact of TradFi Megatrends on the Cryptocurrency Market

SNDK Stock Trading Rewards: Share $100K on WEEX

When AI Agents Gain On-Chain Execution Authority: Who Verifies the Information They See and the Commands They Issue?

How Much of the $1.5 Billion Can Be Recovered? The Realistic Boundaries and Industry Insights of Bybit's Lawsuit Against North Korea










