'Thousands' of businesses at mercy of miscreants thanks to unpatched Ray AI flaw
ID: 173850a3-74a3-58b7-a930-f5941a8459b6
STIX ID: report--173850a3-74a3-58b7-a930-f5941a8459b6
Feed Name: The Register (Security)
A critical remote-code-execution vulnerability (CVE-2023-48022, "ShadowRay") in the Ray AI framework (notably in versions 2.6.3 and 2.8.0) is being actively exploited in the wild, enabling unauthenticated attackers to submit jobs, execute code as root on exposed deployments, steal credentials and SSH keys, exfiltrate sensitive data from affected organizations, and repurpose GPU-equipped clusters for cryptocurrency mining; the flaw carries a 9.8 CVSS score and has been exploited against medical, analytics, educational, and other victims over several months.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
