ZeroHour
Malware

RondoDox

0 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser

CISA added actively exploited Ray flaw CVE-2025-62593 (CVSS 9.4) to its KEV catalog; the DNS rebinding RCE has powered crypto-mining and DDoS botnet campaigns.

CISA added CVE-2025-62593 (CVSS 9.4) to its Known Exploited Vulnerabilities catalog, citing active exploitation of a DNS rebinding-driven RCE flaw in the Ray distributed computing framework, fixed in version 2.52.0. The flaw stems from missing authentication on critical Ray endpoints and an insufficient User-Agent header guard, exploitable against developers running Ray in Firefox or Safari via malicious websites or ads. RondoDox botnet operators incorporated the PoC exploit before the November 26, 2025 disclosure, and unpatched GPU-equipped clusters were hijacked into self-replicating crypto-mining botnets in the ShadowRay 2.0 campaign. FCEB agencies must apply fixes by August 20, 2026.

The Hacker News · 28d agoExploit / PoC in the wildCVE-2025-625931

Related CVEs

  • Actively Exploited Browser-Based RCE in Ray AI Compute Engine
    Ray, the open-source AI compute engine, is vulnerable to a critical remote code execution flaw (CVE-2025-62593, CWE-94/CWE-352) in versions prior to 2.52.0, caused by an insufficient guard against browser-based attacks: the software distinguishes browser traffic only by checking that the User-Agent header starts with 'Mozilla', but the fetch specification allows that header to be modified. An attacker can combine DNS rebinding with a crafted User-Agent so that a developer's Firefox or Safari browser silently sends malicious requests to locally running Ray services after the developer visits an attacker-controlled website or is served a malicious advertisement (malvertising). Successful exploitation yields full remote code execution on the machine running Ray, with high confidentiality, integrity and availability impact reflected in the CVSS 4.0 score of 9.4. Affected users are developers running Ray as a development tool on any version before 2.52.0, which is the fixed release. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-17, a public proof of concept is available in the project's GitHub security advisory (GHSA-q279-jhrf-cc6v), and EPSS estimates a 16.9% probability of exploitation in the next 30 days.
    · Ray-Project (Anyscale) Ray All versions prior to 2.52.0 (patched in 2.52.0) KEV PoC large

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.