news.mlab.sh
Back to the feed
vulnerability

CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE

Critical
Image: The Hacker News
Summary

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability, CVE-2025-62593, to its Known Exploited Vulnerabilities (KEV) catalog in the Ray distributed computing framework. This vulnerability, stemming from a lack of authentication on key endpoints, allows for remote code execution via web browsers and has been actively exploited by threat actors, including those behind the RondoDox DDoS botnet and in a campaign dubbed ShadowRay 2.0, targeting Ray instances within private corporate networks.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.