<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/ongoing-attack-campaign-exploits-critical-vulnerability-in-ray-ai-platform-ngldt0e3g" -->

---
title: Ongoing Attack Campaign Exploits Critical Vulnerability...
description: A critical vulnerability in the Anyscale Ray AI platform has been actively exploited by threat actors for the past seven months, allowing them to hijack...
canonical: https://daily.dev/posts/ongoing-attack-campaign-exploits-critical-vulnerability-in-ray-ai-platform-ngldt0e3g
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Ongoing Attack Campaign Exploits Critical Vulnerability in Ray AI Platform | daily.dev
og:description: A critical vulnerability in the Anyscale Ray AI platform has been actively exploited by threat actors for the past seven months, allowing them to hijack...
og:url: https://daily.dev/posts/ongoing-attack-campaign-exploits-critical-vulnerability-in-ray-ai-platform-ngldt0e3g
og:image: https://api.daily.dev/og/posts/nglDT0e3G.png
og:image:alt: Ongoing Attack Campaign Exploits Critical Vulnerability in Ray AI Platform
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Ongoing Attack Campaign Exploits Critical Vulnerability in Ray AI Platform

**[Collections](https://daily.dev/sources/collections)** · 1 min read · 1 upvotes · 0 comments

## Summary

A critical vulnerability in the Anyscale Ray AI platform has been actively exploited by threat actors for the past seven months, allowing them to hijack computing power for illicit cryptocurrency mining. Sectors such as education, cryptocurrency, and biopharma have been targeted, with severe consequences including exposed sensitive data, tampered AI models, compromised network credentials, and installed cryptocurrency miners and reverse shells on compromised servers. Immediate patching and securing of Ray AI installations is crucial to prevent further compromise.

## Content

Cybersecurity researchers have discovered a critical vulnerability in the Anyscale Ray AI platform that has been actively exploited by threat actors for the past seven months. This vulnerability allows attackers to hijack computing power for illicit cryptocurrency mining. Sectors such as education, cryptocurrency, and biopharma have been targeted, with thousands of servers being hacked due to insecurely deployed Ray AI frameworks.

Companies like OpenAI, Uber, and Netflix, which rely on Ray for their AI workloads, have also fallen victim to this ongoing attack campaign. The consequences of these attacks have been severe, with sensitive data exposed, AI models tampered with, network credentials compromised, and cryptocurrency miners and reverse shells installed on compromised servers.

It is crucial for organizations to immediately patch and secure their installations of the Ray AI framework to prevent further compromise and safeguard their valuable computing resources. This security alert serves as a reminder of the importance of maintaining robust cybersecurity measures to protect against evolving threats.

## Similar posts on daily.dev

- [Don’t just attend KubeCon \+ CloudNativeCon, Merge Forward your experience\!](https://daily.dev/posts/don-t-just-attend-kubecon-cloudnativecon-merge-forward-your-experience--l0rpp73x8) · CNCF · 1 upvotes · 0 comments
- [Announcing H2 2026 KCDs](https://daily.dev/posts/announcing-h2-2026-kcds-m96goajm1) · CNCF · 1 upvotes · 0 comments
- [Two months of Open Community Groups](https://daily.dev/posts/two-months-of-open-community-groups-asf52zhbs) · CNCF · 0 upvotes · 0 comments
- [CNCF Unveils Schedule for KubeCon \+ CloudNativeCon Europe 2026](https://daily.dev/posts/cncf-unveils-schedule-for-kubecon-cloudnativecon-europe-2026-ikhcoa5cb) · CNCF · 2 upvotes · 0 comments
- [CNCF Debuts KubeCon \+ CloudNativeCon Japan 2026 Schedule](https://daily.dev/posts/cncf-debuts-kubecon-cloudnativecon-japan-2026-schedule-xp5pyudub) · CNCF · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#cyber](https://daily.dev/tags/cyber), [#vulnerability](https://daily.dev/tags/vulnerability)

[View this post on daily.dev](https://daily.dev/posts/ongoing-attack-campaign-exploits-critical-vulnerability-in-ray-ai-platform-ngldt0e3g)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Ongoing Attack Campaign Exploits Critical Vulnerability in Ray AI Platform","url":"https://daily.dev/posts/ongoing-attack-campaign-exploits-critical-vulnerability-in-ray-ai-platform-ngldt0e3g","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/ongoing-attack-campaign-exploits-critical-vulnerability-in-ray-ai-platform-ngldt0e3g"},"datePublished":"2024-03-27T23:53:47.846Z","dateModified":"2024-03-28T21:47:24.048Z","description":"A critical vulnerability in the Anyscale Ray AI platform has been actively exploited by threat actors for the past seven months, allowing them to hijack...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/d54af2c3b5e66b970667434342588aa4?_a=AQAEufR","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/d54af2c3b5e66b970667434342588aa4?_a=AQAEufR","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/ongoing-attack-campaign-exploits-critical-vulnerability-in-ray-ai-platform-ngldt0e3g","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,cyber,vulnerability","timeRequired":"PT1M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Ongoing Attack Campaign Exploits Critical Vulnerability in Ray AI Platform"}]}
```

