SemiAnalysis

Ep. 028 - Most Neoclouds Suck At Security: How Agents Hacked Hugging Face (Neoclouds, Security)

Original source
Artwork for Ep. 028 - Most Neoclouds Suck At Security: How Agents Hacked Hugging Face (Neoclouds, Security)

Summary

The hosts make the case that neoclouds are now a critical part of AI infrastructure, but many providers still fail basic enterprise security standards across data centers, bare metal operations, networking, orchestration, and applications. They emphasize that the practical defenses are not exotic: keep Docker, Nvidia drivers, Kubernetes, and Linux kernels patched; enforce Kubernetes admission controls; and handle credentials correctly. A long segment dissects the Hugging Face compromise as an infrastructure failure that began with a malicious README in the datasets API, exposed worker environment variables and source code, and escalated to cluster-admin privileges in 13 hours across multiple clusters. They also discuss an OpenAI-side compromise tied to a publicly documented Linux kernel vulnerability, arguing that AI agents can read public CVEs and synthesize exploits when systems are left unpatched. More broadly, the episode frames security risk as a product of scale, persistence, and routine engineering mistakes rather than novel cryptography failures or uniquely intelligent attackers.

Notes