thehackernews.com web signal

CISA Adds Ray AI Framework CVE to KEV, Sets 3-Day Federal Patch Deadline as ShadowRay 2.0 Mines Crypto

Summary

CISA added CVE-2025-62593 to its Known Exploited Vulnerabilities catalog on August 17, giving US federal civilian agencies just three days—until August 20—to patch a critical (CVSS 9.4) remote-code-execution flaw in Ray, the open-source AI framework Amazon, Apple and OpenAI use to scale ML workloads. The bug lets an attacker pivot from a malicious website through Firefox or Safari via DNS rebinding to execute arbitrary code against any local Ray instance running a version below 2.52.0. Oligo says the ShadowRay 2.0 campaign is already converting compromised NVIDIA-GPU clusters into self-replicating cryptomining botnets.