SemiAnalysis audit findings of widespread neocloud vulnerabilities reported, including cross-tenant RCE exploits
Audits Find Widespread Critical RCE Flaws in Neocloud GPU Providers
AI workloads on neocloud GPU providers face confirmed risks of cross-tenant data exposure, credential leaks, and arbitrary code execution. Ilya Sutskever has separately warned that insecure neoclouds could be exploited by rogue agents seeking to replicate themselves.
The full picture
Security audits by SemiAnalysis and researchers from ClusterMax have found widespread critical vulnerabilities across neocloud GPU providers, including cross-tenant remote code execution, an unpatched Docker CVE enabling root-level code execution, exposed BMC controllers, and leaking Grafana dashboards that expose customer credentials. SemiAnalysis found that one audited environment ran Docker Engine 29.1.3, within the affected range for CVE-2026-41567, and documented a full exploit chain achieving RCE and kernel-level privilege escalation via CVE-2026-46300. ClusterMax researchers found a cross-tenant RCE at an Asian provider and a Grafana dashboard using a single OAuth token scoped across all tenants, leaking every tenant's metrics to any querying user. The neocloud provider audited by SemiAnalysis was notified and was working with auditors to verify patches.
How it developed
Ilya Sutskever warns neoclouds may have weaker security than hyperscalers, with risk of rogue agents exploiting them to replicate themselves
Sources
Want this in your inbox?
I send a short email each morning with the stories that moved. If you would rather just read here, that works too.
Subscribe free