ShadowRay 2.0: attackers hijacked exposed Ray AI clusters into a botnet
Oligo Security found an active campaign exploiting a disputed, unpatched flaw in the Ray AI compute framework to take over internet-exposed clusters, using AI-generated payloads. Hijacked clusters were used for cryptomining, data and credential theft and DDoS attacks, with more than 230,000 Ray servers exposed online.
- Disclosed
- 18 Nov 2025
- Organization
- Multiple
- Vendor
- Any model
- Product
- Ray (open source)
- Type of AI
- AI building block
- How it happened
- Leaky AI product: Unsecured AI infrastructure
- Harm
- Data exposed
- Data involved
- Credentials, Unknown
- Reach
- Many organizations
- Severity
- High
- Model at fault
- No
- Status
- Confirmed
- Vulnerability IDs
- CVE-2023-48022