US Cyber Agency Flags Danger in Popular AI Tool Ray After Hackers Attack

CISA warns tech developers as hackers actively exploit a critical vulnerability in open-source AI framework Ray.
CISA

US cybersecurity agency CISA warns that hackers are actively exploiting a major flaw in AI framework Ray.

The United States Cybersecurity and Infrastructure Security Agency, widely known as CISA, has issued an urgent warning after discovering that internet hackers are actively taking advantage of a critical security hole in a popular artificial intelligence software tool called Ray.

Ray is a widely used open source computer platform that helps developers build and run large artificial intelligence systems and machine learning projects across many connected computers.

Because the system lacks proper identity verification tools on key entry points, bad actors can trick web browsers into letting them break into a developer’s machine and execute unauthorized commands.

The official warning was issued on August 17, 2026, when CISA formally added the flaw, tracked as CVE-2025-62593, to its Known Exploited Vulnerabilities catalog.

This special government list highlights dangerous security weaknesses that cybercriminals are currently using in real world attacks.

Federal agencies and private tech organizations in the United States have been directed to update their software and apply necessary security fixes by August 20, 2026, to ensure their networks remain completely safe.

The primary reason this weakness exists is that the creators of Ray designed the software without standard password checks or user logins on critical internal endpoints.

When a computer engineer uses Ray for testing while browsing the web, a hacker can serve a bad advertisement or lure the developer to a malicious website.

Using a clever trick called a DNS rebinding attack, the hacker can turn common browsers like Mozilla Firefox and Apple Safari into tools that secretly send dangerous commands directly into the developer’s computer system.

Once inside, attackers can steal secret data, hijack powerful computer graphics chips for unauthorized cryptocurrency mining, or pivot to attack other connected computers inside a company’s private network.

See Also: Vietnam Enforces Strict New Cybersecurity Law to Control Online Content and Accounts

Explaining how missing passwords caused the security hole, Ray software maintainers shared that due to the longstanding decision by the Ray Development team to not implement any sort of authentication on critical endpoints, like the /api/jobs & /api/job_agent/jobs/ has once again led to a severe vulnerability that allows attackers to execute arbitrary code against Ray”.

Describing how an unsuspecting tech worker can accidentally trigger the hack while working online, the development team added that “combined with a DNS rebinding attack against the browser, and this vulnerability is exploitable against a developer running Ray who inadvertently visits a malicious website, or is served a malicious advertisement”.

Cybersecurity researchers warn that unpatched systems have already been targeted by botnet groups trying to hijack high powered computing hardware.

The software maintainers have fixed the flaw in version 2.52.0 of the Python package. By encouraging tech workers to update their tools immediately, security experts hope to lock out digital intruders and protect the essential infrastructure behind modern artificial intelligence.

About the Author

Jennifer Sakmufuwo Baba

Jennifer Sakmufuwo Baba is a tech analyst, senior staff, and writer covering artificial intelligence, cybersecurity , and emerging technologies at TechRegard. Based in Nigeria, she's passionate about translating complex tech developments into compelling, accessible stories for diverse audiences. Her work focuses on how technology shapes innovation across Africa and globally.