CISA orders a threeday patch after a flaw in the Ray AI framework comes under active attack
News Source : The Next Web
News Summary
- The Cybersecurity and Infrastructure Security Agency has added a vulnerability in Ray to its Known Exploited Vulnerabilities catalogue.
- The bug, tracked as CVE-2025-62593, is a code-injection weakness that can hand an attacker remote code execution on a vulnerable Ray deployment.
- Ray is maintained by Anyscale and sits at the heart of modern machine-learning pipelines, distributing workloads across clusters of CPUs and GPUs.
- It is the kind of system that tends to be spun up fast by data-science teams and then quietly forgotten by whoever is meant to be securing it.
Never miss a story from us, subscribe to our newsletter