AI framework vulnerability is being used to compromise enterprise servers (CVE-2023-48022)

Attackers are leveraging a vulnerability in Anyscale’s Ray AI software to compromise enterprise servers and saddle them with cryptominers and reverse shells.

“We observed hundreds of compromised clusters in the past three weeks alone. Each cluster uses a public IP address, and most clusters contain hundreds to thousands of servers. There are hundreds of servers that are still vulnerable and exposed.”

The open-source Ray framework is used for scaling AI and Python applications from a laptop to a cluster and to accelerate machine learning workloads.

The attackers did not just use the Ray clusters for covert cryptomining – they also installed reverse shells, to establish a permanent connection with the servers and allow them to control them remotely.

“AI production workloads were compromised, meaning an attacker could affect an AI model’s integrity or accuracy, steal models, and infect models during the training phase,” the researchers added.

“We know that truly, crypto mining is one of the better-case scenarios. If the attackers had chosen instead to create malicious models and alter the output of AI being used in sensitive applications, the impact could be enormous,” he commented.

Share this article on social media:

Subscribe to Our Newsletter!
Stay on top of cybersecurity risks, evolving threats and industry news.
This field is for validation purposes and should be left unchanged.

The Latest Cybersecurity News

From major cyberattacks, newly discovered critical vulnerabilities to recommended best practices, read it here first:
GET STARTED TODAY

Tell us About your Needs
Get an Answer the Same Business Day

Got an urgent request? Call us at 1-877-805-7475 or Book a meeting.

What happens next:

A Vumetric expert will contact you to learn more about your cybersecurity needs and goals.

The project's scope will be defined (Target environment, deadlines, requirements, etc.)

A detailed quote including all-inclusive pricing and statement of work is sent to you.

PCI-DSS
This field is for validation purposes and should be left unchanged.
2024 EDITION

PENETRATION TESTING Buyer's Guide

Everything You Need to Know

Gain confidence in your future cybersecurity assessments by learning to effectively plan, scope and execute projects.

BOOK A MEETING

Enter your Email Address

This field is for validation purposes and should be left unchanged.

* No free email provider (e.g: gmail.com, hotmail.com, etc.)

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.