logo

Hackers exploit Ray framework flaw to breach servers, hijack resources

ID: b572fcb0-1ee8-5f90-a2c3-945951ced983

STIX ID: report--b572fcb0-1ee8-5f90-a2c3-945951ced983

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-03-26

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

ShadowRay is an active campaign exploiting a design-related remote code execution issue (CVE-2023-48022) in the Ray open-source AI framework to hijack compute resources, exfiltrate sensitive artifacts (models, environment variables, DB credentials, cloud tokens), and deploy Monero miners and reverse shells; Oligo found hundreds of publicly exposed Ray servers compromised and recommends restricting network exposure, adding authorization, and continuous monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.