Drooid Logo
Back to today’s briefing

Story perspectives

Exposed Ray Servers Under Attack: AI Exploits Surge

11/20/2025

43 5 Full Breakdown

1 of 1

Story summary
  • Ray, the open-source AI framework, contains CVE-2023-48022 and is exploited by ShadowRay 2.0 to execute arbitrary code via the Jobs API.
  • More than 230,000 Ray servers are exposed online, a substantial increase from a few thousand in 2023.
  • The threat group IronErn440 uses AI-generated payloads for cryptojacking and has deployed malware to steal credentials and conduct DDoS.
  • Anyscale, maintainer of Ray, has not yet implemented security measures despite warnings.