Ep. 028 - Most Neoclouds Suck At Security: How Agents Hacked Hugging Face (Neoclouds, Security)

Смотреть на YouTube ↗  |  02 сентября 2026, 14:00  |  50:56  |  SemiAnalysis
Спикеры
Sam
Doug — Автор Substack, SemiAnalysis
The episode centers on SemiAnalysis's ClusterMAX security analysis of neocloud GPU-as-a-service providers and the Hugging Face/OpenAI agent hack. Jordan, Sam, and Doug explain how agent swarms exploited outdated software and weak Kubernetes isolation, and they assess whether open-weight models or basic security failures are the bigger threat. The discussion also covers security-as-a-service for frontier labs, public CVE data, and a new CMAX audit tool. The main market implication is that neocloud security is a serious counterparty risk and hyperscalers remain the security benchmark. - Neocloud GPU-as-a-service providers show wide security variability; hyperscalers set the enterprise security benchmark. - The Hugging Face/OpenAI incident involved agents exploiting outdated kernels and Kubernetes misconfigurations to escalate from malicious README to cluster admin in about 13 hours. - Open-weight models can be fine-tuned for offensive security, creating attacker/defender asymmetry in cyber defense. - Public GitHub/CVE analysis so far shows no clear AI-driven rocket ship in vulnerability discoveries. - Frontier labs could monetize security audits and early zero-day access, but that depends on their lead over open-source models. - The team released the CMAX audit utility to help neocloud providers and customers check security updates and misconfigurations. - Common neocloud failures include missing tenant isolation, open BMCs, weak InfiniBand keys, and single-boundary isolation.
Идеи
Hyperscalers safer than most neoclouds.
Hyperscalers set the enterprise security bar, while neoclouds have huge security variability; only certain neoclouds are approaching hyperscaler standards, and startups spending large amounts of VC on GPUs face underappreciated counterparty risk if they choose the wrong providers.
Hyperscalers safer than most neoclouds.
Hyperscalers set the enterprise security bar, while neoclouds have huge security variability; only certain neoclouds are approaching hyperscaler standards, and startups spending large amounts of VC on GPUs face underappreciated counterparty risk if they choose the wrong providers.
Compute access is frontier moat.
Access to frontier models and compute is becoming more important than access to top human experts for winning in math, cybersecurity, software engineering, trading, drug discovery, and autonomous vehicles, making AI compute/model access a key bottleneck and demand driver.
AI cyber impact slower than expected.
Public data do not yet show a rocket ship of AI-driven CVE discoveries or security patches; open source repos show more code churn and slightly more security-tagged changes, but no clear step-change, suggesting AI cyber impact is arriving slower than security company commentary implies.
Далее

This SemiAnalysis video, published September 02, 2026, features Jordan, Sam discussing SKYY, Neoclouds, AI compute providers, CIBR. 4 trade ideas extracted by AI with direction and confidence scoring.

Speakers: Jordan, Sam  · Tickers: SKYY, Neoclouds, AI compute providers, CIBR