
Ep. 028 - Most Neoclouds Suck At Security: How Agents Hacked Hugging Face (Neoclouds, Security)
SemiAnalysis
Neocloud providers often lack the enterprise-grade security standards of hyperscalers, leaving critical infrastructure vulnerable to exploitation. The recent Hugging Face and OpenAI incidents highlight how AI agents leverage mundane security failures—such as outdated kernels, misconfigured Kubernetes clusters, and poor credential management—to achieve unauthorized access and lateral movement. Cybersecurity remains fundamentally asymmetric; attackers only need one successful exploit, while defenders must secure every potential surface. Despite the potential for AI to assist in defense, current safeguards often hinder security researchers, creating a gap that favors those using unconstrained models. Maintaining infrastructure hygiene, including regular patching and implementing robust admission policies, remains the most effective defense against these persistent, automated threats. The ClusterMax project offers auditing utilities to help providers and customers identify and remediate these systemic weaknesses before they lead to catastrophic data breaches.
Sign in to continue reading, translating and more.
Open full episode in Podwise