Popular open-source AI framework under siege, critical flaw has no patch
Credit:
The Record
Researchers are warning that hackers are actively exploiting a disputed vulnerability in a popular open-source AI framework known as Ray.
This tool is commonly used to develop and deploy large-scale Python applications, particularly for tasks like machine learning, scientific computing and data processing.
According to Ray’s developer, Anyscale, the framework is used by major tech companies such as Uber, Amazon and OpenAI. Researchers at Israel-based cybersecurity firm Oligo Security found that thousands of publicly exposed Ray servers worldwide were compromised due to the vulnerability tracked as CVE-2023-48022, and dubbed by the company as ShadowRay.