anyscale News Articles

Recent news articles refferecing the vendors vulnerabilities.

ShadowRay 2.0 Exploits Unpatched Ray Flaw to Build Self-Spreading GPU Cryptomining Botnet

ShadowRay 2.0 exploits an unpatched Ray flaw to spread cryptomining and DDoS malware across exposed GPU clusters.

1 week ago

New ShadowRay attacks convert Ray clusters into crypto miners

A global campaign dubbed ShadowRay 2.0 hijacks exposed Ray Clusters by exploiting an old code execution flaw to turn them into a self-propagating cryptomining botnet.

1 week ago

Large-scale attack on Ray framework exposes AI security risks

Attacks on AI infrastructure are now a reality, as Oligo research has shown. It's unclear exactly how widespread the damage is.

Thousands of companies using Ray framework exposed to cyberattacks, researchers say

Researchers are warning that hackers are actively exploiting a disputed vulnerability in a popular open-source AI framework known as Ray.

Ray AI Framework Vulnerability Exploited to Hack Hundreds of Clusters

Disputed Ray AI framework vulnerability exploited to steal information and deploy cryptominers on hundreds of clusters.

AI framework vulnerability is being used to compromise enterprise servers (CVE-2023-48022) - Help Net Security

Attackers are exploiting CVE-2023-48022 to compromise enterprise servers and saddle them with cryptominers and reverse shells.

Critical Unpatched Ray AI Platform Vulnerability Exploited for Cryptocurrency Mining

Researchers uncover active exploitation of a critical flaw in Anyscale Ray, a popular AI platform.

Flaw in Ray AI framework potentially leaks sensitive data of workloads

Threat actor targets AI workloads, believed to be first exploited in the wild.

New ShadowRay Campaign Targets Ray AI Framework in Global Attack

Discover the new ShadowRay campaign exploiting CVE-2023-48022 in the Ray AI framework, risking thousands of companies

New critical Ray AI framework vulnerability emerges

Open-source artificial intelligence compute framework Ray has been found to be impacted by a critical vulnerability, tracked as CVE-2023-48023, which could be exploited to facilitate unauthorized node access, according to SecurityWeek.

No more news articles to load.