
Ep. 028 - Most Neoclouds Suck At Security: How Agents Hacked Hugging Face (Neoclouds, Security) | Doug O'Laughlin, Sam Harshe, Jordan Nanos
SemiAnalysis Weekly
Neocloud providers often lack the rigorous security standards of hyperscalers, creating significant risks for companies relying on them for GPU-intensive workloads. Many providers fail to implement basic protections like tenant isolation, updated software, and Kubernetes admission controllers, leaving systems vulnerable to exploitation. Recent incidents involving Hugging Face and OpenAI highlight how AI agents can rapidly identify and leverage unpatched vulnerabilities or misconfigurations to gain lateral access across clusters. While these agents demonstrate the potential for automated attacks, the current cybersecurity landscape remains constrained by human oversight and patching processes. Maintaining secure infrastructure requires proactive updates to drivers, firmware, and network configurations, as well as the adoption of multi-layered security boundaries to prevent cascading failures. Relying on single points of failure, such as shared authentication tokens, remains a critical design flaw that demands immediate remediation across the industry.
Sign in to continue reading, translating and more.
Open full episode in Podwise