updated Malefactors are actively attacking internet-facing Ray clusters and abusing the open source AI framework to spread a self-replicating botnet that mines for cryptocurrency, steals data, and launches distributed denial of service (DDoS) attacks. Oligo Security bug hunters say the ongoing campaign, which they've named ShadowRay 2.0, has been active since at least September 2024. The attacks exploit CVE-2023-48022, a critical – and unpatched – vulnerability in Ray, an open source distributed computing framework for AI workloads that's used by major tech companies, including Amazon, Apple, and OpenAI. This is the same flaw Oligo previously reported as being under exploitation in late 2023. At the time, the application security firm dubbed the vulnerability ShadowRay. The security hole, which received a 9.8 CVSS rating, allows remote attackers to execute arbitrary code via an exposed Ray dashboard API. It remains unpatched because Anyscale, the vendor that developed the framework, maintains that Ray is not intended for use outside a "strictly controlled network environment," and, as such, the bug report is irrelevant. In October, Anyscale handed off Ray to the Linux Foundation's PyTorch Foundation, which is now responsible for maintaining the open source project. Following publication, Anyscale sent a statement suggesting – like last time – that it didn't plan to address the problem because it's not a vulnerability if Ray is being used correctly. "The activity highlighted i...
Self-replicating botnet attacks Ray clusters
The Register
·Jessica Lyons
·Published Nov 18, 2025
·Updated
Affected Software
1 affected component
Anyscale Ray
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the emergence of a self-replicating botnet that attacks Ray clusters, abusing the open-source AI framework.
2
What security implications are discussed?
The security implications include cryptocurrency mining, data theft, and the potential for launching distributed denial of service (DDoS) attacks.
3
What products or software are affected?
The affected software highlighted in the article is Anyscale Ray.
4
How are attackers exploiting Ray clusters?
Attackers are exploiting Ray clusters to spread the self-replicating botnet and exploit resources for illicit activities.
5
What can users do to protect their Ray clusters?
Users can enhance security by applying patches, monitoring network traffic, and implementing strict access controls.