Security1 distinct publisher2 min readUpdated
A code injection flaw in Ray is now on CISA's mandatory fix list after BitSight saw a Mirai-derived botnet exploiting it. Compute clusters are being swept with the same traffic as routers.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
A KEV listing binds federal civilian agencies and nobody else [10]. That is the narrow half of this. The wide half is that RondoDox carries 174 distinct exploits [2], and a list that long is not aimed at anything in particular. The operator fires, something answers, and what kind of machine answered is discovered afterwards, if at all.
Worth noticing how the Ray flaw arrives in the reporting. BitSight's characterization of RondoDox is a botnet that compromises vulnerable edge devices [3], and CVE-2025-62593 sits inside that description without comment [1]. Ray is not an edge device on any ordinary reading. It is distributed compute framework software, the thing that spreads Python and machine learning jobs across a cluster, which is context the roundup does not supply [9]. The classification here followed the botnet's target file rather than the asset.
The arsenal figure is the part to read numerically. FortiGuard Labs is separately tracking Evooo1Bot, another Mirai variant, working from over a dozen known CVEs [4]. RondoDox's catalogue is somewhere around nine to thirteen times that size [7]. Both are built on the same commodity lineage [8], so the marginal cost of adding a cluster orchestration exploit to one of these kits is the cost of one entry in a config, and the reach it buys is every Ray instance with a routable address.
In the same advisory cycle, CISA, the FBI and HHS warned that Medusa ransomware affiliates are rapidly exploiting newly disclosed Fortra GoAnywhere and BeyondTrust vulnerabilities against critical infrastructure [5], with more than 500 organizations hit to date [6]. That is the adjacent market for fresh CVEs, and nothing in it puts AI infrastructure at the back of the queue. Ray got picked up by the mass scanners first because mass scanners are cheaper to run, not because the flaw is worth less.
What happens to a host after the initial hit is documented, in outline, by the other botnet in the same report. Evooo1Bot's kit includes an SSH brute forcer, a credential sniffer, and a SOCKS5 relay module that converts infected hosts into persistent proxy nodes for the operator [4]. Different code, same economics: a compromised machine's first job is to help reach the next one, and a compute node sitting inside a research or data environment is a better place to start from than a DVR on a home connection.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
CISA has mandated that all federal civilian agencies prioritize fixing a severe code injection vulnerability, CVE-2025-62593, in Ray-Project Ray. The flaw was added to the Known Exploited Vulnerabilities catalog after threat actors were observed actively abusing it in the wild.
BitSight observed CVE-2025-62593 being exploited by RondoDox, a Mirai-inspired botnet utilizing 174 distinct exploits.
RondoDox's exploit set is described as being used to compromise vulnerable edge devices.
FortiGuard Labs is tracking Evooo1Bot, a modular Linux botnet and Mirai variant that targets internet-facing devices by exploiting over a dozen known CVEs, and which carries an SSH brute-forcer, a credential sniffer, and a SOCKS5 relay module designed to convert infected hosts into persistent proxy nodes.
A joint advisory from CISA, the FBI and HHS warns that Medusa ransomware affiliates are rapidly exploiting newly disclosed vulnerabilities in Fortra GoAnywhere and BeyondTrust to compromise critical infrastructure.
The updated Medusa advisory says over 500 critical infrastructure organizations have been hit to date.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Named attributions, single-source and thin on detail
Every fact traces to one weekly roundup paragraph per topic. The core claims are attributed to identifiable authorities (CISA KEV, BitSight, FortiGuard Labs, a joint CISA/FBI/HHS advisory), which raises credibility, but there is no second publisher, no primary advisory text, no affected version range, no exploitation vector, and no description of the affected product. The derived exploit-count comparison rests on an imprecise 'over a dozen' figure, and the characterization of Ray as a distributed compute framework is unsupported by the supplied material.
Exploitation confirmed, compromise scale unknown
Real-world activity is established rather than hypothetical: the flaw is in KEV on the strength of observed abuse, a named vendor saw a specific botnet using it, and a parallel advisory quantifies 500-plus critical infrastructure victims for Medusa. What is missing is any measure of the Ray-specific footprint - no count of exposed or compromised clusters, no geographic or sector spread, and no indication of how much of RondoDox's traffic targets Ray versus its other 173 exploits.
Framing outruns a one-paragraph item
The reported facts are sober and attributed, but the cluster's framing - cluster software 'folded into' a 174-exploit arsenal, compute clusters 'swept with the same traffic as routers' - generalizes from a single roundup paragraph that mentions Ray once and otherwise describes edge-device targeting. No supplied evidence quantifies scanning of compute clusters, and the interpretive premise about what Ray is remains unsupported, so the narrative sits modestly ahead of the record.
Vendor telemetry plus government mandate
Two of the three attributions are commercial security vendors publicizing their own threat visibility - BitSight on RondoDox and FortiGuard Labs on Evooo1Bot - which gives them an interest in emphasizing novelty and breadth of exploit arsenals. Counterweighting that, the KEV listing and the joint CISA/FBI/HHS advisory come from government bodies with regulatory rather than commercial motives, and the publisher is a trade outlet aggregating rather than promoting.
Credible core, unverifiable single source
Confidence in the headline facts is reasonable because they are attributed to authorities whose statements are checkable in principle, and the claims are internally consistent. It is capped by having exactly one publisher, roundup-length treatment, no primary documents, and an unsupported product characterization underpinning the story's angle.
security
Gunra Goes Franchise: Conti's Leaked Code Now Ships With a Builder and an Affiliate Panel2 distinct publishers
security
Akira advisory update: $244m taken, one SonicWall CVE, three controls to audit now1 distinct publisher
product
CISA gives federal agencies three days to patch Ray, the framework under your ML pipelines1 distinct publisher
build
One Mirai variant now proxies, sniffs and spreads: the appliance layer is a pivot, not DDoS fodder1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.