Tools
2026-08-19
The engine underneath a great deal of AI training is being exploited — and Washington gave agencies three days
On 17 August the American cyber-security agency CISA added CVE-2025-62593 to its catalogue of vulnerabilities known to be under active attack. The flaw is in Ray, the open-source distributed compute engine that a large share of production machine-learning training and inference runs on. It is rated 9.4 out of 10. The attack path is unusually indirect: Ray tried to block browser-originated requests by checking that the User-Agent header began with 'Mozilla', a check an attacker can satisfy trivially, and pairing that with a DNS-rebinding trick lets a malicious web page — or a malicious advert — run code on the machine of anyone browsing in Firefox or Safari while Ray is running. Federal civilian agencies were given until 20 August to fix it: three days, the shortest window available under Binding Operational Directive 26-04, which is reserved for publicly reachable assets where a successful attack hands over the whole machine. The flaw was disclosed in November 2025, and researchers at BitSight later found the RondoDox botnet had been using it two days before that disclosure. Ray's maintainers dispute the framing: their documentation says Ray is not meant to run outside a strictly controlled network, and token authentication has been available since version 2.52.0.
Why it mattersThis is an argument the AI build-out has been deferring. Ray was designed as an internal cluster tool on the assumption that whoever runs it puts it behind a firewall — and for years that assumption mostly held, because only a handful of labs ran large clusters. Now any company with a GPU budget runs one, often stood up by a data-science team rather than an infrastructure team, and the number of Ray dashboards reachable from the open internet is precisely the thing nobody measures. Whether you call that a vulnerability or a deployment mistake decides who is responsible for fixing it, which is why the maintainers and the government can describe the same fact so differently. A three-day deadline tells you how the US government has settled the question for its own systems. If your employer trains models, the question worth asking today is who owns the cluster dashboard and whether it is exposed.
✓ Verified · 4 sources
▶ Related video: Why Ray Became a Distributed Computing Engine for Modern AI
Read in the app — free, in 9 languages
Related stories
Apple Music will tell you when a song was made by a machine — but the uploader decides whether to say so
2026-08-21Rumour: the anonymous model that just topped a coding benchmark, for free, is said to be Zhipu's unreleased flagship
2026-08-21Nvidia is paying $6 billion for the machine that builds a rival's models — and hiring 109 of the people who ran it
2026-08-21Stripe has just paid $7.5 billion for a model router. Days later Ramp built one and is giving it away until January.
2026-08-21Meta's assistant is now a Mac app that reads your screen and types into any window — and what it sees can train the model
2026-08-21