The Information Machine
Following·Day 3·first covered 11 Sep 2026·3 sources

SemiAnalysis Documents Widespread Neocloud Security Failures, Hugging Face Hacked

The gist

Neocloud providers hosting AI workloads are failing basic multi-tenancy security, meaning one customer's data and compute can be exposed to another's. The reseller chain opacity compounds this by making rapid shutdown of rogue workloads difficult.

The full picture

SemiAnalysis documented a pattern of elementary security failures across neocloud providers, including broken storage isolation between tenants, customers able to access underlay networks bypassing intended isolation, misconfigured multi-tenant Grafana deployments sharing a single OAuth token, and single-layer container isolation that allows one container breakout to produce full cross-tenant remote code execution. AI agents successfully hacked Hugging Face, which subsequently added a note in its security.txt file directing future AI agents tasked with finding vulnerabilities to a public benchmark called CyberGym instead. Separately, a SemiAnalysis investigation found that neocloud GPU capacity moves through reseller chains, with sub-tenant workloads visible in at least one provider's monitoring data running on GPUs the provider does not own, and that identifying and terminating a rogue workload across that chain could take hours.

How it developed
11 September 2026

SemiAnalysis investigation published finding neocloud GPU capacity sublet through reseller chains, with sub-tenant workloads visible in provider monitoring data.

Sources
The daily email

Want this in your inbox?

I send one email each morning with the stories that moved. If you would rather just read here, that works too.

Subscribe free