Back to Feed
AI SecurityAug 10, 2026

Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds

Stealthium offers security for AI accelerators and neo-clouds, addressing blind spots traditional tools miss.

Summary

A new startup, Stealthium, is addressing security blind spots in AI accelerators and specialized 'neo-clouds' that traditional cybersecurity tools cannot detect. These accelerators, distinct from CPUs and GPUs, power AI workloads, and neo-clouds are AI-first cloud environments often built with them. Stealthium deploys an agent to analyze telemetry signals from these environments, aiming to detect subtle hints of compromise that could otherwise go unnoticed, posing a significant supply chain risk.

Full text

Use of accelerators is growing in line with the growth of AI. These accelerators are specialized chips that are neither CPUs nor GPUs – they specifically offload and speed up the precise workloads required for AI. Primary producers include Tenstorrent, Groq, Cerebras, Graphcore, and Google. Neo-clouds are new but increasingly available specialized clouds distinct from the traditional class of hyperscalers such as Azure, Google Cloud and AWS. They are AI-first, often built with accelerators, and well-suited for customers requiring AI training, inference and model building services. Neo-clouds provide massive parallelism, low-latency edge compute, flexible deployment and cheaper or more predictable economics. Example neo-clouds include CoreWeave and Nebius. Typical AI use of neo-clouds includes training large-scale AI models and running high-throughput AI inference. In the latter, for example, the customer will use the neo-cloud’s accelerator-optimized low latency hardware to ensure rapid response times for in-house developed chatbots. But accelerators, and therefore neo-clouds, suffer from several security blind spots. Traditional cybersecurity tools have been developed over decades around CPU-centric operating systems. They haven’t kept pace with the emergence of accelerators, and they lack visibility into the accelerators’ high-speed video memory. Current cybersecurity cannot readily detect what is happening within neo-cloud hardware. Consequently, if a neo-cloud is stealthily compromised by an attacker, neither it nor its customers are guaranteed to see the compromise. The result could be a severe but invisible supply chain threat to all customers, but especially those using the neo-cloud for AI development purposes. If it had been more successful, the recent Januscape malware could have been used in such a manner. Startup firm Stealthium aims to tackle this threat. It cannot see into the accelerators in the neo cloud, but uses an agent housed within the customers’ infrastructure that is specially trained to detect the subtle hints coming from a compromised neo-cloud.Advertisement. Scroll to continue reading. “Unfortunately, our understanding of the shared model of responsibility for security doesn’t apply here, and certainly security controls and observability aren’t applicable in this space,” comments Chris Hosking, GTM Advisor at Stealthium. “Our go-to thinking has always been that if you cannot see something happening, then nothing is happening.” This is seriously dangerous, especially with accelerators – in cybersecurity, absence of proof is never proof of absence. “Organizations are increasingly uncomfortable because they lack meaningful security and observability controls, in real time, for that silicon accelerator layer,” he continues. “That’s the challenge that Stealthium exists to solve. We believe that AI needs to be trustworthy. Sovereign AI can only be sovereign if it’s secure and trustworthy. That’s the purpose of Stealthium. We’re a security and observability company for AI accelerated runtime.” The technology used is not new; it’s just highly specialized. “We deploy an agent that searches the telemetry coming from the neo cloud, looking for hints of compromise.” It’s the hints rather than the technology that are dramatically different. As an example, Januscape exploited a vulnerability in nested virtualization, enabling the attacker to offer, or sell an environment to a third party. Such an exploit in a neo cloud could lead to cross-tenant leakage, with the third party gaining insights and potential access into legitimate in-house chatbots. Stealthium will detect this by detecting subtle hints in neo cloud telemetry indicating this, or a different, type of attack. Such supply chain attacks already occur, but incidence is likely to increase in the future. The prize is attractive to both financially motivated cybercriminals and information gathering or influence seeking nation states. “As an attacker who has compromised a neo-cloud node, I can get access to a customer’s AI weights,” explains Hosking. “I can poison and corrupt and change the way that the model operates without anyone noticing. So, for example, I could make it more sympathetic to the cause that I’m trying to promote. I could extort the customer or just use the shared environment to run crypto mining or be my new base of operations.” Hypothetically, if a nation state were able to influence or change ChatGPT or Gemini, it would be able to influence entire nations. The stakes are very high in a threat vector that is very new with little established security. Stealthium is an early example of a new type of security company, one that seeks visibility into the operation of accelerators. In this instance, it does not look into the hardware concerned but gathers and analyzes the telemetry coming from the hardware, with a specialized and continuously updated agent trained to detect subtle hints of accelerator compromise. Related: Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack Related: New GitHub, PyPI Policies Boost Supply Chain Security Related: Trump Orders Defense Contractors to Map Software, Suppliers Across Supply Chains Related: North Korean Hackers Target Open Source Developers in Supply Chain Attacks Written By Kevin Townsend Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Kevin Townsend The Fourth Battlefield: The Growing Role of Cyber Operations in Global ConflictCISO Conversations: Russ Kirby – Passion Is the Antidote to BurnoutWeaponized Email AI Assistants Could Help Attackers Hijack AccountsHorizon3 Raises $250 Million to Fund Continuing Growth‘DangleGeddon’: AI Could Weaponize Forgotten DNS Records at Global ScaleAct Security Emerges from Stealth to Fight the Patch ProblemHacker Conversations: Tal Kollander’s Journey From Black Hat to Hack BlockerMedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection Latest News OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack ConcernsCisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents BadNew Jersey, Alabama Join States Targeted in Water CyberattacksMetabase Patches Vulnerability Exploited as Zero-DayNovel Private APN Pivot Let Hackers Sabotage Second Polish Energy FacilityCISA Urges Immediate Patching of Exploited Progress LoadMaster VulnerabilityCorporate Data Stolen in Levi Strauss Cyberattack Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the Move1Kosmos has named Frank Cohen Chief Revenue Officer.ServiceNow has appointed Simon Mouyal as Chief Marketing Officer.James Wilkinson has been named Chief Information Security Officer for the City of Dallas.More People On The MoveExpert Insights Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answe

Indicators of Compromise

  • malware — Januscape

Entities

Stealthium (product)AI accelerators (technology)Neo-clouds (technology)Tenstorrent (vendor)Groq (vendor)Cerebras (vendor)