Sev0AI security incidents, tracked

All incidents / Leaky AI product

ShadowRay 2.0: attackers hijacked exposed Ray AI clusters into a botnet

Multiple, disclosed 18 Nov 2025. Leaky AI product Data exposed High

Oligo Security found an active campaign exploiting a disputed, unpatched flaw in the Ray AI compute framework to take over internet-exposed clusters, using AI-generated payloads. Hijacked clusters were used for cryptomining, data and credential theft and DDoS attacks, with more than 230,000 Ray servers exposed online.

Disclosed
18 Nov 2025
Organization
Multiple
Vendor
Any model
Product
Ray (open source)
Type of AI
AI building block
How it happened
Leaky AI product: Unsecured AI infrastructure
Harm
Data exposed
Data involved
Credentials, Unknown
Reach
Many organizations
Severity
High
Model at fault
No
Status
Confirmed
Vulnerability IDs
CVE-2023-48022

Sources

  1. https://www.oligo.security/blog/shadowray-2-0-attackers-turn-ai-against-itself-in-global-campaign-that-hijacks-ai-into-self-propagating-botnet
  2. https://thehackernews.com/2025/11/shadowray-20-exploits-unpatched-ray.html

Related incidents

Data for this record: incidents.json. Cite as: Sev0, "ShadowRay 2.0: attackers hijacked exposed Ray AI clusters into a botnet", https://sev0.fyi/incidents/2025-11-18-shadowray-2-ray-clusters-botnet/