A new hacking campaign dubbed "ShadowRay" targets an unpatched vulnerability in Ray, a popular open-source AI framework, to hijack computing power and leak sensitive data from thousands of companies. According to a report by application security firm Oligo, these attacks have been underway since at least September 5, 2023, targeting education, cryptocurrency, biopharma, and other sectors. Ray is an open-source framework developed by Anyscale that is used to scale AI and Python applications across a cluster of machines for distributed computational workloads. The framework boasts over 30,500 stars on GitHub, and it is used by many organizations worldwide, including Amazon, Spotify, LinkedIn, Instacart, Netflix, Uber, and OpenAI, that use it for training ChatGPT. In November 2023, Anyscale disclosed five Ray vulnerabilities, fixing four tracked as CVE-2023-6019, CVE-2023-6020, CVE-2023-6021, and CVE-2023-48023. However, the fifth bug, a critical remote code execution flaw tracked as CVE-2023-48022, was not fixed because, according to them, its lack of authentication was a long-standing design decision. "The remaining CVE (CVE-2023-48022) - that Ray does not have authentication built in - is a long-standing design decision based on how Ray's security boundaries are drawn and consistent with Ray deployment best practices, though we intend to offer authentication in a future version as part of a defense-in-depth strategy," reads the AnyScale security advisory. Specifically, Anysc...
Hackers exploit Ray framework flaw to breach servers, hijack resources
BleepingComputer
·Bill Toulas
·Published Mar 26, 2024
·Updated
Affected Software
1 affected component
Anyscale Ray
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a hacking campaign called 'ShadowRay' that exploits a vulnerability in the Ray framework.
2
What security implications are discussed in the article?
The article highlights the risk of resource hijacking and data leakage from thousands of companies due to the exploited flaw.
3
What products or software are affected by this security issue?
The security issue specifically affects the Ray framework developed by Anyscale.
4
Who are the primary targets of the ShadowRay hacking campaign?
Thousands of companies using the Ray framework are the primary targets of the ShadowRay campaign.
5
Is the flaw in Ray framework currently patched?
No, the vulnerability in the Ray framework remains unpatched at the time of the article.