Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Microsoft starts removing WMIC tool used by cybercriminals

    August 18, 2026

    Bitcoin turned $10,000 into $870,000 in a decade where 87% of active stock funds failed to beat passive rivals

    August 18, 2026

    IVF staff accused of misleading UK parents about donors at northern Cyprus clinics

    August 18, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Microsoft starts removing WMIC tool used by cybercriminals
    • Bitcoin turned $10,000 into $870,000 in a decade where 87% of active stock funds failed to beat passive rivals
    • IVF staff accused of misleading UK parents about donors at northern Cyprus clinics
    • Despite energy crisis, Bangladesh’s factories are slow to adopt solar power: Study
    • Councils won’t be able to block betting shops | Gambling
    • Palestine weekly: Global outcry fails to break West Bank siege | Israel-Palestine conflict News
    • Russia warns UK of ‘consequences’ over reports Ukraine using British drones in attacks | Russia
    • Russia says UK ‘will pay’ for supplying drones to Ukraine
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, August 18
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 18, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananAug 18, 2026Vulnerability / Network Security

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

    Ray is an open-source, Python-native distributed computing framework designed to scale artificial intelligence and machine learning workloads. As of writing, the GitHub project has more than 43,500 stars and has been forked over 7,900 times.

    The vulnerability in question relates to CVE-2025-62593 (CVSS score: 9.4), which can result in remote code execution via web browsers like Mozilla Firefox and Apple Safari by means of a DNS rebinding attack.

    “Due to the longstanding decision by the Ray Development team to not implement any sort of authentication on critical endpoints, like the /api/jobs & /api/job_agent/jobs/ has once again led to a severe vulnerability that allows attackers to execute arbitrary code against Ray,” according to an advisory shared by Ray maintainers in November 2025. “This time in a development context via the browsers Firefox and Safari.”

    Cybersecurity

    The issue, at its core, stems from insufficient controls against browser-based attacks, specifically scenarios where the User-Agent header can be modified.

    “Combined with a DNS rebinding attack against the browser, and this vulnerability is exploitable against a developer running Ray who inadvertently visits a malicious website, or is served a malicious advertisement,” the project maintainers added.

    It’s worth noting that the defect primarily impacts developers running development/testing environments with Ray. Should a targeted victim fall prey to a phishing attack, or be served a malicious ad, it can lead to the execution of arbitrary shell code on their machine.

    The project maintainers also noted that the attack can also be extended to attack network-adjacent instances of Ray by leveraging the browser as a confused deputy intermediary to target Ray instances running inside a private corporate network.

    The issue has been addressed in version 2.52.0 of the Python package. Ray has credited Oligo security researcher Avi Lumelsky with discovering the fetch bypass and Jonathan Leitschuh for coming up with the DNS rebinding attack.

    Cybersecurity

    CISA has not shared any details of how the vulnerability is being exploited in the wild. However, a BitSight report from March 2026 revealed that the threat actors behind the RondoDox DDoS botnet had incorporated the vulnerability into their arsenal two days before it was publicly disclosed on November 26, 2025, because of the availability of a proof-of-concept (PoC) exploit.

    According to Oligo, unpatched Ray instances have also been at the receiving end of cyber attacks that aim to turn infected clusters with NVIDIA GPUs into a self-replicating cryptocurrency mining botnet as part of a campaign dubbed ShadowRay 2.0.

    In light of active exploitation of CVE-2025-62593, Federal Civilian Executive Branch (FCEB) agencies are recommended to apply necessary fixes and mitigations by August 20, 2026.

    actively BrowserBased CISA Exploited flags Flaw Ray RCE trigger
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Microsoft starts removing WMIC tool used by cybercriminals

    Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies

    Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

    How MCP Servers Can Expose Enterprise Secrets

    Turf War Between Claude Agents Leads to Self-Replicating Malware

    Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Microsoft starts removing WMIC tool used by cybercriminals

    August 18, 2026

    Bitcoin turned $10,000 into $870,000 in a decade where 87% of active stock funds failed to beat passive rivals

    August 18, 2026

    IVF staff accused of misleading UK parents about donors at northern Cyprus clinics

    August 18, 2026

    Despite energy crisis, Bangladesh’s factories are slow to adopt solar power: Study

    August 18, 2026
    Latest Posts

    Wisconsin’s Democratic primary for governor: a look at the 5 remaining

    July 27, 2026

    UK CO2 storage project that will reuse existing infrastructure secures lease

    July 27, 2026

    Bangladesh shipbreakers push back against stricter environmental standards

    July 27, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Microsoft starts removing WMIC tool used by cybercriminals

    August 18, 2026

    Bitcoin turned $10,000 into $870,000 in a decade where 87% of active stock funds failed to beat passive rivals

    August 18, 2026

    IVF staff accused of misleading UK parents about donors at northern Cyprus clinics

    August 18, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.