SemiAnalysis tested 25 AI clouds and got into other customers' data. It won't name the providers.

SemiAnalysis tested 25 AI clouds and got into other customers' data. It won't name the providers.

Key points

  • SemiAnalysis says it broke isolation between customers at AI cloud providers while testing 25 companies and 32 clusters.
  • Exposed data belonged to banks, telcos, universities, AI labs and one national intelligence agency. That provider patched within a week.
  • The report names no vulnerable provider. CoreWeave (CRWV) and Microsoft's (MSFT) Azure appear only in a software-version check.

The most important AI story of the weekend isn't about chips. SemiAnalysis, the research shop everyone in this industry reads, spent four months testing 25 AI cloud providers across 32 clusters for its upcoming ClusterMAX 3.0 ratings, and it published the security findings early because of what it found along the way. In several cases its testers reached data belonging to other customers on the same infrastructure: banks, telecom companies, universities, AI labs, and in one instance "a national intelligence agency from a country with a top-10 global GDP."

That provider patched it within a week of being told, and SemiAnalysis went back and verified the fix. Credit where it's due.

The scary part isn't the hacking

Much of what they did wasn't sophisticated. That's the part I can't get past. "We have found quite a few dead simple vulnerabilities. We have not developed anything novel," the report says. Some of the bugs had public write-ups more than three years old, and in a lot of cases the entire test was checking whether a provider's software was older than the version the vendor said was the safe minimum.

It was.

The whole industry has spent 2026 arguing about AI super-hackers, and that fear isn't fake. OpenAI's own models broke out of a test sandbox and into Hugging Face's production systems this summer, which SemiAnalysis recaps in detail. But when the firm went digging through vulnerability data for proof that AI has fundamentally changed the pace of cyberattacks, it says it mostly couldn't find the effect. What it found instead was GPU clouds running years-old software with publicly documented container escapes. The futuristic threat gets the headlines. The 2023 threat gets your data.

What it says it reachedHow
Other tenants' metadataServer management networks left open, missing network segmentation, misconfigured InfiniBand security keys
Root access on the shared hostContainer escape using an NVIDIA bug disclosed in 2025
Other tenants' dataKubernetes services with no default-deny network policy, and a kubelet reachable on a public address
Cross-tenant remote code executionAll of the above chained together at a single provider

A different provider produced the worst finding. It built shared Kubernetes control planes against the documentation of its own software, ran cluster software that was more than two years out of date, and left the kubelet reachable on a public IP. SemiAnalysis chained those weaknesses into a working cross-tenant attack in an afternoon and demonstrated it between two accounts it controlled itself, then spent months following up until the provider fixed it.

The monitoring failure may be the most revealing example. A provider gave SemiAnalysis a Grafana dashboard that accidentally showed someone else's machine on it. When the firm dug in, the real problem was uglier: every customer's dashboard was querying the database with a key that could read logs and metrics from every tenant on the platform. The separation between customers only existed at the display layer. Behind it sat GPU utilization, project names and inference stats for everyone, including that intelligence agency.

Advertisement

Why I care about this as an investor

By SemiAnalysis's own tally, neoclouds have signed deals worth hundreds of billions of dollars over the last year, and the report names nine of the biggest companies in tech as renters, among them OpenAI, Anthropic and Google. Those are announced contract values, not revenue that has arrived yet. Those labs already behave like they don't trust anybody. They take bare-metal clusters, they demand zero-trust setups, and they often give the operator read-only access to the lab's own systems. This report explains exactly why, and every procurement team renting GPUs now has a reason to examine it.

And here's the stat that tells you how young this sector still is: "The only neocloud we are aware of that runs a paid bug bounty program is Together, via HackerOne." One. Google and Microsoft pay six-figure bounties for bugs. Most GPU clouds offer a contact address.

Now, before anyone panics about their portfolio: the report names no provider where it found the cross-tenant problems, all 25 were notified, and none let the 90-day disclosure clock run out. The only two providers named at all, CoreWeave (CRWV) and Azure, appear in a routine software-version comparison, and the one that failed the driver check there was Azure. Nothing in this report says sell anything. What it says is that security just became a ranking, because the full ClusterMAX 3.0 ratings are coming, they'll sort these providers into tiers, and the customers signing the contracts treat those tiers as a buying guide.

One more thing if you use AI coding tools. SemiAnalysis found that one co-tenant on the vulnerable infrastructure was an inference provider serving tokens to the public through OpenRouter, and it warns that a tenant-isolation failure at a token provider can become a supply chain attack on the customer's own machine. Cheap tokens run on somebody's cluster. This report is a good reminder to care whose.

The full ratings haven't been published yet. When they land, we'll cover them.

Sources

Advertisement

Frequently asked questions

What did SemiAnalysis find in its neocloud security testing?

SemiAnalysis said it broke the isolation between customers at AI cloud providers during testing for its ClusterMAX 3.0 ratings, reading other tenants' metadata, escaping containers to reach root on shared hosts, reading cross-tenant data, and in one case demonstrating cross-tenant remote code execution. It tested 25 providers across 32 clusters between April and July 2026 and published the findings on August 30, 2026.

Which AI cloud providers had the security vulnerabilities?

SemiAnalysis did not name them. The report says all 25 providers that supplied a cluster were notified under responsible disclosure, that no provider let the 90-day clock expire, and that vulnerable providers are identified only by ClusterMAX tier. No publicly traded neocloud has been tied to any of the cross-tenant findings.

Was CoreWeave (CRWV) named in the SemiAnalysis security report?

CoreWeave is named, but not as a source of any breach. It appears in a comparison of minimum software versions alongside Microsoft's Azure, and the report identifies Azure as the Gold-tier provider whose NVIDIA driver fell below the minimum version in the environment tested. The providers behind the cross-tenant findings are not named anywhere in the report.

Whose data was exposed in the neocloud security testing?

SemiAnalysis said the information it reached belonged to banks, telecom companies, universities, research institutions, AI labs and, in one case, a national intelligence agency from a country with a top-10 global GDP. The firm said it disclosed that finding immediately, the provider patched it within a week, and SemiAnalysis verified the patch.

More on CRWV and MSFT

David Han
David Han

David Han is the founder of AIStockWire, where he covers AI, semiconductors, and technology stocks. He focuses on finding stories the market hasn’t fully connected yet, drawing on filings, insider activity, earnings, and industry data. His commentary has been quoted by U.S. News & World Report, Moneywise, and Yahoo Finance. He invests in the companies he writes about and discloses his positions. Nothing he publishes is investment advice.