Observed Signal · Aug 30, 2026 · Technical Release · Source: SemiAnalysis · Impact: 3/5 · Sentiment: Negative
Infrastructure Market: Most Neoclouds Fail at Security
SemiAnalysis published findings from its ClusterMAX 3.0 security testing (April–July 2026), reporting widespread misconfigurations, out-of-date software, and multiple cross-tenant vulnerabilities across neocloud providers. Tests on 25 providers and 32 clusters uncovered issues including container escapes (e.g., NVIDIA Container Toolkit CVE-2025-23266), Prometheus/Grafana misconfigurations exposing tenant telemetry, incorrect InfiniBand partition and key settings, and BlueField DPU management plane exposure (RShim). The report links these operational failures to real supply-chain risk for major customers (banks, telcos, AI labs, and a national intelligence agency). SemiAnalysis offers a ClusterMAX CLI audit tool, urges enrollment in vendor embargo programs, and recommends systemic patching and stronger isolation practices.
Widespread operational security failures in neocloud infrastructure affect AI supply chains used by major enterprises and labs; the findings increase supply-chain and data-exposure risk for large customers but do not represent an immediate platform policy change.
Key Takeaways & Evidence Grounding
- SemiAnalysis ran ClusterMAX 3.0 security testing across 25 providers and 32 clusters between April and July 2026.
- ClusterMAX provides a CLI (pip install clustermax) and a publicly hosted minimum-versions feed used for automated audits (clustermax.ai).
- Testing discovered cross-tenant metadata exposure and at least one demonstrated cross-tenant RCE that exposed data belonging to banks, telcos, universities, AI labs, and a national intelligence agency.
- The article references specific CVEs and vulnerabilities mentioned in testing and incidents, including CVE-2025-23266, CVE-2026-65617, CVE-2026-46300, CVE-2026-41567, and CVE-2025-23299.
- SemiAnalysis states it followed coordinated disclosure procedures; providers patched issues and the 90-day disclosure clock did not expire in any case.
Connected Companies & Entities
17 Entities mappedCoreWeave
AI-native GPU cloud for training and inference at scale.
“Even a Gold provider may fail to meet a basic requirement, such as the minimum NVIDIA driver version. Here, we compare CoreWeave and Azure....”
Together AI
Open-source AI cloud for training, inference and GPU compute.
“Notably, the only neocloud we are aware of that runs a paid bug bounty program is Together, via HackerOne....”
SemiAnalysis
AI infrastructure and semiconductor research, data models, tools and consulting.
“Source: SemiAnalysis Research, sales@semianalysis.com...”
Dell
Enterprise infrastructure, devices, cloud subscriptions and IT services provider.
“Server OEMs such as Dell and SuperMicro have similar intake forms and publish BMC, firmware, and platform advisories, but alas no bounties....”
Anthropic
Foundation model company selling AI assistants and model APIs.
“Project Glasswing and Daybreak from Anthropic and OpenAI are discovering new vulnerabilities in industry-standard software, building POC exp...”
Amazon
Global commerce, cloud, advertising and subscription platform company.
“AWS and Oracle have decided to cheap out. Server OEMs such as Dell and SuperMicro have similar intake forms and publish BMC, firmware, and p...”
Wiz
Cloud security SaaS for code, cloud and runtime risk.
“To tell this story, the simplest example of the exploit is NVIDIAscape (CVE-2025-23266), named by Wiz....”
NVIDIA
Accelerated computing company spanning AI software, cloud and gaming.
“This is why embargoed security programs exist. One of our key recommendations to neoclouds is to enroll in this embargo program from Nvidia ...”
AMD
US semiconductor company designing processors and computing chips.
“For example, Nvidia, AMD and Intel all have product security bulletins, bug bounty programs, and simple intake forms to submit vulnerability...”
Microsoft Azure
Enterprise cloud infrastructure, data and AI platform.
“OpenAI, Anthropic, Google, Meta, SpaceX, Microsoft, Amazon, AMD, NVIDIA and many more well funded companies currently rent GPUs from neoclou...”
Intel
Computing infrastructure company combining chips, AI tooling and enterprise platforms.
“For example, Nvidia, AMD and Intel all have product security bulletins, bug bounty programs, and simple intake forms to submit vulnerability...”
Microsoft
Diversified software, cloud, advertising and gaming platform company.
“OpenAI, Anthropic, Google, Meta, SpaceX, Microsoft, Amazon, AMD, NVIDIA and many more well funded companies currently rent GPUs from neoclou...”
Oracle
Enterprise cloud infrastructure and customer experience software provider.
“AWS and Oracle have decided to cheap out. Server OEMs such as Dell and SuperMicro have similar intake forms and publish BMC, firmware, and p...”
OpenAI
Foundation model company selling AI software, APIs and subscriptions.
“Project Glasswing and Daybreak from Anthropic and OpenAI are discovering new vulnerabilities in industry-standard software, building POC exp...”
Hugging Face
Open AI model hub with hosted inference and collaboration.
“Here’s the Hugging Face timeline: Beginning on July 9, AI agents exploit Hugging Face’s datasets API, which runs on Kubernetes....”
Amazon Web Services (AWS)
Cloud infrastructure, platform and AI services for enterprises and developers.
“AWS and Oracle have decided to cheap out. Server OEMs such as Dell and SuperMicro have similar intake forms and publish BMC, firmware, and p...”
Search, video, adtech and cloud giant within Alphabet.
“The Google Chrome team may have given a preview of the future of software engineering in an insightful recent blog post that describes, with...”
Ontology Mapping & Concepts
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
