Neocloud Security Deep Dive Report: Alarming Infrastructure Configuration Errors, Cross-Tenant RCE Could Impact Banks, Telecoms, and Even National Intelligence Agencies
On August 30, the Neocloud security deep dive report was released, revealing multiple cross-tenant security vulnerabilities discovered during the testing of ClusterMAX 3.0. Over a four-month testing period covering 25 vendors and 32 clusters, the team achieved multiple instances of cross-tenant remote code execution (RCE) using only publicly known vulnerabilities and basic configuration checks. Affected entities included banks, telecom companies, universities, research institutions, AI laboratories, and even a national intelligence agency.
Typical issues included: shared Kubernetes control planes leading to tenant metadata visibility, container escape, exposure of BMC/IPMI management networks, misconfigured InfiniBand security keys (P_Key, SA_Key, M_Key), unfortified default trust mode of BlueField DPU, Grafana dashboards using god-level API keys, and lack of VXLAN isolation in front-end networks. The report specifically highlighted a cascading vulnerability case: a misconfigured shared vCluster combined with software versions lagging by two years ultimately completed the proof of concept (POC) verification for cross-tenant RCE within an afternoon.
Notably, the report questioned the mainstream narrative that "AI has fundamentally changed the pace of cybersecurity": statistics on CVEs for GPU drivers, CUDA, PyTorch, Kubernetes, Docker, and the Linux kernel showed no significant increase in vulnerabilities following the proliferation of AI coding models, with most data indicating "no change hypothesis cannot be rejected."
The report also detailed the incident of training agent attacks on Hugging Face, where AI agents achieved cluster-level privilege escalation through a message board established via Artifactory, which went undetected from May until July. While constructing POC verification for existing vulnerabilities, the team found that Claude Fable and GPT-5.6 Sol frequently rejected security-related requests, ultimately relying on open-source models like DeepSeek V4, Kimi K3, and GLM-5.2 to complete the task. It indicated that the core issue in the Neocloud industry is not the new risks brought by AI, but rather the long-standing absence of basic patch management, tenant isolation, and security design, recommending vendors to establish automated security announcement monitoring systems and rectify single points of failure that could expose all users' architectural patterns.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

IMF President Says Stablecoins May Undermine Currency Sovereignty in Emerging Markets

Stablecoin card spending crosses $10.9B

Fomo Announces Trading Support on the First Day of Arc Mainnet Launch

How Can Bitcoin Withstand Quantum Computers? A Comparison of Three Lattice-Based Signature Schemes

Assessment of Payment Networks and Tokenization Experiments in 82 Jurisdictions

CPMI to Improve Cross-Border Payment Standards by 2027

ORO Completes $3 Million Strategic Financing Led by MH Ventures

Interpol's Operation 'Jackal IV' Arrests 58 in Crackdown on Cryptocurrency Fraud

Obita CEO Zhang Dayong: AI Drives Payment Efficiency, Cross-Border Payments Still Require T+1 to T+7

Automakers Become Indispensable in the Second Half of Embodied Intelligence
![[Column] The Dollar Goes Blockchain, the Yuan Turns to Gold... The Currency Hegemony War Has Changed](/public-static/26_2e1840f602.png?format=avif)
[Column] The Dollar Goes Blockchain, the Yuan Turns to Gold... The Currency Hegemony War Has Changed

Cryptocurrency in Brazil: Laws, Taxes, How to Buy, and How to Find the Best Exchange Rates

OPEC: Venezuela Discusses Exit with the USA, 5 Months After the Emirates

Why Aren't Trillion-Dollar Institutions Embracing Blockchain? EthSystems Founder: Privacy is the Fatal Constraint of 'Transparent' Ethereum

Aptos Enhances USDC Receiving Path with CCTP V2

Central Bank Digital Currency on the Blockchain: European Central Bank Takes the Lead

Ripple Prime Launches Total Return Swap Service

HyENA shuts down after processing $4B in trades

Ripple moves to shrink XRP Ledger attack surface as AI audit tests lending push

Spot Trading on Decentralized Exchanges Reaches 13.6%, Sparking Debate on DeFi Governance

Ripple Launches Delta One Service for Derivatives in the U.S.

Trump Administration Plans to Restrict Remote Access to Advanced AI Chip Computing Resources

Circle CCTP V1 to Be Deprecated on October 31, 2026

City Protocol Raises $11 Million: Will It Bring Hedging, Arbitrage, and Private Equity on-chain?

Ant Group launches financial model Ling-3.0-flash-Fin, open source next week

Fun Coffee Funds Network Circulates $72.83 Million, Operators Transfer Over $27.44 Million

ERC-8196 Standard Finalized, Supporting AI Agent Wallet Strategy Execution

BIT Investment Opportunities Forum Held in Hong Kong, Discussing Next Phase of Market and Asset Allocation Opportunities

RWA Weekly: JPMorgan and Three Other Banks Advance Global Stablecoin Alliance; Coinbase Launches Tokenized Stocks on Base Network







