aiminute. ← All AI news
Tools AI Minute Newsroom 2026-08-19

The engine underneath a great deal of AI training is being exploited — and Washington gave agencies three days

The engine underneath a great deal of AI training is being exploited — and Washington gave agencies three days

On 17 August the American cyber-security agency CISA added CVE-2025-62593 to its catalogue of vulnerabilities known to be under active attack. The flaw is in Ray, the open-source distributed compute engine that a large share of production machine-learning training and inference runs on. It is rated 9.4 out of 10. The attack path is unusually indirect: Ray tried to block browser-originated requests by checking that the User-Agent header began with 'Mozilla', a check an attacker can satisfy trivially, and pairing that with a DNS-rebinding trick lets a malicious web page — or a malicious advert — run code on the machine of anyone browsing in Firefox or Safari while Ray is running. Federal civilian agencies were given until 20 August to fix it: three days, the shortest window available under Binding Operational Directive 26-04, which is reserved for publicly reachable assets where a successful attack hands over the whole machine. The flaw was disclosed in November 2025, and researchers at BitSight later found the RondoDox botnet had been using it two days before that disclosure. Ray's maintainers dispute the framing: their documentation says Ray is not meant to run outside a strictly controlled network, and token authentication has been available since version 2.52.0.

Why it mattersThis is an argument the AI build-out has been deferring. Ray was designed as an internal cluster tool on the assumption that whoever runs it puts it behind a firewall — and for years that assumption mostly held, because only a handful of labs ran large clusters. Now any company with a GPU budget runs one, often stood up by a data-science team rather than an infrastructure team, and the number of Ray dashboards reachable from the open internet is precisely the thing nobody measures. Whether you call that a vulnerability or a deployment mistake decides who is responsible for fixing it, which is why the maintainers and the government can describe the same fact so differently. A three-day deadline tells you how the US government has settled the question for its own systems. If your employer trains models, the question worth asking today is who owns the cluster dashboard and whether it is exposed.
#Coding

✓ Verified · 4 sources

▶ Related video: Why Ray Became a Distributed Computing Engine for Modern AI
WhatsApp X Telegram
Read in the app — free, in 9 languages

Related stories

TikTok put a shopping chatbot inside the video you are watching.
2026-10-06
Reflection will hand out a 501-billion-parameter model for free.
2026-10-06
Meta's assistant keeps an hourly file on everyone in your life.
2026-10-05
One command restores the Apple Intelligence off switch Apple deleted.
2026-10-05
OpenAI will ship a Codex upgrade daily for 28 days or reset limits.
2026-10-05