Urgent.News

One page, thousands of outlets. See who else covered it.

Editions

Tech

CISA gives feds 3 days to fix actively exploited Ray RCE bug

Phishing, malvertising attacks could target devs to gain access to private corporate networks

CISA gives feds 3 days to fix actively exploited Ray RCE bug

The Cybersecurity and Infrastructure Security Agency (CISA) has instructed US federal civilian executive branch agencies to fix a critical vulnerability in Ray, a widely used open-source framework for scaling Python and machine-learning workloads, within three days. Known as CVE-2025-62593, the vulnerability allows attackers to execute arbitrary code on a vulnerable Ray system using Firefox or Safari browsers.

The flaw, tracked since November 2025, is particularly concerning as it can be exploited through phishing attacks or malicious ads to gain unauthorized access to Ray instances in private corporate networks. The issue stems from Ray's default security model, which assumes clusters run inside a trusted, isolated network, leaving authentication and access control to surrounding infrastructure.

Ray 2.52.0, released to address the flaw, introduces optional token-based authentication, though it remains disabled by default. Despite CISA's urgency, the agency did not provide a clear explanation for the three-day window, noting the vulnerability is believed to be used in ransomware campaigns, though the specific field remains unknown.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at theregister.com →

More in Tech

Why Google Won't Index Your Pages: 4 GSC Fixes

Originally published on echoeffect.net . If you have been inside Google Search Console recently and clicked into the Pages report (previously called Index Coverage), you may have seen a section titled…

More from Tuesday 18 August →