BTC $78,539.85 +1.12%
ETH $2,466.44 +2.02%
BNB $691.02 +0.91%
XRP $1.38 +1.52%
SOL $102.98 +1.22%
TRX $0.3325 -1.03%
DOGE $0.0828 +1.12%
ADA $0.1976 +3.04%
BCH $246.91 +1.54%
LINK $11.31 +1.69%
HYPE $84.04 +5.16%
AAVE $123.94 +1.41%
SUI $0.7264 +2.14%
XLM $0.1772 +1.56%
ZEC $849.00 +1.80%
BTC $78,539.85 +1.12%
ETH $2,466.44 +2.02%
BNB $691.02 +0.91%
XRP $1.38 +1.52%
SOL $102.98 +1.22%
TRX $0.3325 -1.03%
DOGE $0.0828 +1.12%
ADA $0.1976 +3.04%
BCH $246.91 +1.54%
LINK $11.31 +1.69%
HYPE $84.04 +5.16%
AAVE $123.94 +1.41%
SUI $0.7264 +2.14%
XLM $0.1772 +1.56%
ZEC $849.00 +1.80%

cati

All
Article
Flash

The Ministry of Industry and Information Technology has launched a special initiative to cultivate artificial intelligence application service providers

The Ministry of Industry and Information Technology of China has launched a special action to cultivate artificial intelligence application service providers, encouraging various regions to increase the procurement of large models, intelligent agents, and Token services through first purchase and first use, risk compensation, and other methods, while using tools such as "computing power vouchers" to reduce computing power costs.The Ministry of Industry and Information Technology will also establish a national resource pool for AI application service providers, aiming to exceed 2,000 by the end of 2026 and no less than 3,000 by the end of 2027. These service providers mainly help enterprises implement AI projects, with services ranging from early consulting, program design, to system development, integration delivery, and then to subsequent operation and maintenance and security governance.This policy also specifically names FDE. The Ministry encourages service providers to form FDE teams to directly address project implementation issues on-site with users. Various regions are also required to open real business scenarios, organize supply and demand matching, and turn high-frequency, essential business needs into standardized AI products that can be delivered repeatedly.

SemiAnalysis releases Neocloud security deep report: Infrastructure configuration errors are shocking, and cross-tenant RCE could affect banks, telecommunications, and even a country's intelligence agency

The semiconductor and AI independent research organization SemiAnalysis released a deep security report on Neocloud (new cloud), revealing various cross-tenant security vulnerabilities discovered during the ClusterMAX 3 testing period. In a four-month test covering 25 vendors and 32 clusters, the team achieved multiple instances of cross-tenant remote code execution (RCE) solely by exploiting publicly known vulnerabilities and basic configuration checks. Affected entities included banks, telecommunications companies, universities, research institutions, AI laboratories, and even a national intelligence agency.Typical issues included: shared Kubernetes control plane leading to tenant metadata visibility, container escape, exposure of BMC/IPMI management networks, incorrect configuration of InfiniBand security keys (P_Key, SA_Key, M_Key), unfortified default trust mode of BlueField DPU, Grafana monitoring dashboards using god-level API keys, and lack of VXLAN isolation in front-end networks. The report specifically pointed out a cascading vulnerability case: a misconfiguration of shared vCluster combined with software versions being two years out of date ultimately completed the POC verification of cross-tenant RCE within an afternoon.Notably, the report questioned the mainstream narrative that "AI has fundamentally changed the pace of cybersecurity": statistics on CVEs for NVIDIA GPU drivers, CUDA, PyTorch, Kubernetes, Docker, and the Linux kernel showed that there was no significant increase in vulnerabilities after the popularization of AI coding models, with most data supporting the "no change hypothesis." The report also detailed the incident where an OpenAI-trained agent attacked Hugging Face, where the AI agent achieved cluster-level privilege escalation through a message board established via Artifactory, which went undetected from May to July. While building POC verification for existing vulnerabilities, the team found that Claude Fable and GPT-5.6 Sol frequently rejected security-related requests, ultimately relying on open-source models such as DeepSeek V4, Kimi K3, and GLM-5.2 to complete the task.SemiAnalysis stated that the core issue in the Neocloud (new cloud) industry is not the new risks brought by AI, but rather the long-term absence of basic patch management, tenant isolation, and security design. They recommended that vendors establish automated security announcement monitoring systems and rectify single points of failure that could expose all users' architectural patterns.

first_img OneKey reproduces the transaction replacement attack targeting the old version of the Ledger Ethereum application

The security team of the open-source wallet provider OneKey successfully replicated the exploitation of a vulnerability in the old version of the Ledger Ethereum application in a laboratory environment. OneKey's founder and CEO Wang Yishi stated that they executed a "transaction replacement attack" on Ledger Ethereum application version 1.22.1 by exploiting a previously patched vulnerability, allowing attackers to overwrite pending transactions while users review legitimate transactions.Ledger responded that exploiting this vulnerability requires controlling the communication between the device and the host, such as through malware, compromised wallet software, or malicious web pages. Ledger has added application layer protections in the Ethereum application version 1.22.2 released on August 13 and fixed the underlying issue in Secure SDK 26.6.1 on August 21. Ledger emphasized that no users were hacked as a result; this was merely a replication of the vulnerability in a laboratory environment.This security test occurred after the Coldcard vulnerability incident. Previously, the Coldcard wallet had a firmware vulnerability that posed security risks to some mnemonic phrase generation, but Ledger stated that its devices were not affected by this vulnerability because recovery phrases are generated by a certified random source built into the device's secure chip. The vulnerability replicated by OneKey is unrelated to mnemonic phrase generation but affects the way transactions are processed during the signing process.

first_img Viewpoint: The AI application layer should not be priced based on tokens, but should be anchored to "recognizable work value."

a16z partner Sarah Wang recently published an article pointing out that AI application layer products should not price based on tokens like the model layer, but rather on "recognizable work units." The article argues that token pricing anchors the value of application products to a unit whose cost is continuously declining, making it difficult for customers to predict context length, retrieval volume, or reasoning time, and improperly compares applications to raw computing power.The article suggests a tiered pricing model based on value levels: model layer priced by tokens; application layer priced by recognizable work units for customers (such as account research briefs, code modifications, completed queries), which can be encapsulated through Credits; and scenarios that are attributable and have clear value priced directly by results (such as resolved customer service conversations, qualified leads). The design of Credits should map to different levels of work difficulty to protect gross margins and distinguish "work value" from "delivery cost." The article uses Clay as an example, where its new pricing separates Data Credits (third-party data) from Actions (orchestrated work), only passing on costs for reasoning models with significant cost fluctuations without markup. The author believes that pricing anchored to value rather than computing cost allows customers to understand spending in relation to value, while also benefiting product providers in maintaining profit margins.

The Sandbox: Compensation will be carried out based on the on-chain snapshot before the attack, and the compensation application process is expected to open within two weeks

The Sandbox released an update on the security vulnerability attack incident involving the SAND cross-chain bridge, stating that the attacker modified the verification mechanism to forge cross-chain deposit messages and mint unbacked SAND. This incident resulted in approximately 14.7423 million SAND being withdrawn, valued at about $697,000. Additionally, some uncollateralized SAND was profited through market trading, leading to an overall economic impact of approximately $1.497 million, of which the attacker actually obtained about $987,000.The Sandbox stated that the attack did not affect the supply of SAND on Ethereum and Polygon, with the total amount of SAND on Ethereum remaining unchanged at 3 billion. There were also no super administrator privileges stolen, and the attack stemmed from a vulnerability caused by the combination of the general call function in the token contract and the design of bridge permissions. Currently, the related addresses have been marked, and collaboration has begun with exchanges, security agencies, and the LayerZero team.For affected users, The Sandbox promises to compensate wallets holding legitimate bridged SAND with a 1:1 ratio of SAND on the Ethereum chain based on an on-chain snapshot taken before the attack. The compensation application process is expected to open within two weeks and will last for two weeks.
app_icon
ChainCatcher Building the Web3 world with innovations.