• News/
  • https://www.theregister.com/2025/11/18/selfreplicating_botnet_ray_clusters/

Self-replicating botnet attacks Ray clusters

The Register
·
Jessica Lyons
·
Published Nov 18, 2025
·
Updated

updated Malefactors are actively attacking internet-facing Ray clusters and abusing the open source AI framework to spread a self-replicating botnet that mines for cryptocurrency, steals data, and launches distributed denial of service (DDoS) attacks. Oligo Security bug hunters say the ongoing campaign, which they've named ShadowRay 2.0, has been active since at least September 2024. The attacks exploit CVE-2023-48022, a critical – and unpatched – vulnerability in Ray, an open source distributed computing framework for AI workloads that's used by major tech companies, including Amazon, Apple, and OpenAI. This is the same flaw Oligo previously reported as being under exploitation in late 2023. At the time, the application security firm dubbed the vulnerability ShadowRay. The security hole, which received a 9.8 CVSS rating, allows remote attackers to execute arbitrary code via an exposed Ray dashboard API. It remains unpatched because Anyscale, the vendor that developed the framework, maintains that Ray is not intended for use outside a "strictly controlled network environment," and, as such, the bug report is irrelevant. In October, Anyscale handed off Ray to the Linux Foundation's PyTorch Foundation, which is now responsible for maintaining the open source project. Following publication, Anyscale sent a statement suggesting – like last time – that it didn't plan to address the problem because it's not a vulnerability if Ray is being used correctly. "The activity highlighted i...

Read full article

Affected Software

1 affected component
Anyscale Ray
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the emergence of a self-replicating botnet that attacks Ray clusters, abusing the open-source AI framework.

2

What security implications are discussed?

The security implications include cryptocurrency mining, data theft, and the potential for launching distributed denial of service (DDoS) attacks.

3

What products or software are affected?

The affected software highlighted in the article is Anyscale Ray.

4

How are attackers exploiting Ray clusters?

Attackers are exploiting Ray clusters to spread the self-replicating botnet and exploit resources for illicit activities.

5

What can users do to protect their Ray clusters?

Users can enhance security by applying patches, monitoring network traffic, and implementing strict access controls.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203