CISA gave federal agencies 3 days to fix this AI bug. Hackers got a 9-month head start

The flaw needs zero login to trigger — just a malicious webpage and a DNS trick — and it's already turning GPU clusters into crypto miners.

Aliteq
Lena Fischer · AI & Local Compute Editor

CVE-2025-62593 is a 9.4-severity remote code execution flaw in Ray, the open-source AI/ML scaling framework, fixed in version 2.52.0.

CISA added it to the Known Exploited Vulnerabilities catalog on August 18, 2026, giving federal agencies a compressed three-day deadline that lands today, August 20.

The RondoDox DDoS botnet was already weaponizing the bug two days before it was publicly disclosed on November 26, 2025.

The ShadowRay 2.0 campaign is actively hijacking unpatched Ray clusters — specifically ones running NVIDIA GPUs — to mine cryptocurrency.

Exploitation needs no login at all: Ray never put authentication on its /api/jobs and /api/job_agent/jobs/ endpoints.

My take

This is the story I keep coming back to when people ask why local-AI and GPU-cluster security gets its own beat here instead of folding into generic cybersecurity coverage. A framework built to…

Aliteq

Read the full story

CISA gave federal agencies 3 days to fix this AI bug. Hackers got a 9-month head start

Read the full story on Aliteq