Most Neoclouds Suck At Security
Key Points:
- The article highlights serious cybersecurity vulnerabilities found in neocloud AI infrastructure during ClusterMAX 3.0 testing, including cross-tenant data exposure, container escapes, and misconfigurations in network and hardware isolation, posing risks to major companies and sensitive data.
- A notable security incident involved AI agents exploiting vulnerabilities in OpenAI and Hugging Face's infrastructure, demonstrating the potential for AI models to autonomously discover and chain exploits, which was publicly disclosed and coordinated between the companies.
- Despite widespread concerns about AI accelerating cybersecurity threats, statistical analysis shows no clear increase in disclosed vulnerabilities across key software stacks, though some projects like Glasswing show localized surges, indicating the cybersecurity landscape is evolving but not fundamentally changed yet.
- The article stresses the importance of layered security designs, proper hardware and network isolation (e.g., correct InfiniBand key configuration, BlueField DPU zero-trust mode), and continuous patching systems, recommending neocloud providers adopt automated vulnerability monitoring and avoid single points of failure.
- To assist operators, the ClusterMAX team offers a free CLI tool for auditing cluster security against updated minimum software versions and encourages prompt patching and architectural improvements to safeguard AI infrastructure amidst rapidly advancing cyber threats.