logo

Critical Unpatched Ray AI Platform Vulnerability Exploited for Cryptocurrency Mining

ID: 0d1388f1-5d0a-5071-a17a-102ce6db675f

STIX ID: report--0d1388f1-5d0a-5071-a17a-102ce6db675f

Feed Name: The Hacker News

Threat Score
82/100

Date Published: 2024-03-27

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Researchers report an active campaign dubbed ShadowRay exploiting a critical missing-authentication flaw in the Anyscale Ray distributed compute framework (CVE-2023-48022, CVSS 9.8) since September 2023, allowing attackers to run arbitrary jobs, achieve remote code execution, exfiltrate credentials, poison models, and deploy cryptocurrency miners across hundreds of GPU clusters; Anyscale has released detection tooling and plans to add authentication in a future Ray release but has not issued an immediate fix.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.