Ray AI Framework — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
November 19, 2025
Last Seen
November 24, 2025

Ray AI Framework is a technology platform referenced in recent ShadowRay threat reports.

Ray AI Framework is a technology platform tracked across 4 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed November 19, 2025; most recent activity November 24, 2025.

Overview

Ray AI Framework is a technology platform referenced in recent ShadowRay threat reports. The ShadowRay threat actor is exploiting a vulnerability in Ray AI Framework to target AI systems, and is also leveraging misconfigurations in open-source Ray servers to enable malicious activity. These developments highlight AI infrastructure risks and the potential for rapid compromise of AI deployments.

Related Threat Clusters

  • ShadowRay 2.0 Exploits Flaw in Open Source Ray Framework to Hijack GPU Clusters

    ShadowRay 2.0 is exploiting a critical unpatched vulnerability in the open source Ray AI framework, allowing it to hijack NVIDIA GPU clusters globally. Organizations using misconfigured Ray servers are particularly…

    2 articles · Updated November 24, 2025
  • ShadowRay 2.0 Campaign Exploits Ray Clusters for Crypto Mining

    A global campaign named ShadowRay 2.0 is targeting exposed Ray clusters, exploiting the unpatched CVE-2023-48022 vulnerability. The attacks, attributed to a threat actor known as IronErn440, have been active since at…

    8 articles · Updated November 18, 2025
  • ShadowRay 2.0 Exploits Flaw in Open Source Ray Framework

    ShadowRay 2.0 is exploiting a critical unpatched vulnerability in the open source Ray AI framework, enabling it to hijack NVIDIA GPU clusters globally. Organizations using misconfigured Ray servers are particularly…

    2 articles · Updated November 24, 2025
  • ShadowRay Exploit Targets Ray AI Framework Vulnerability

    A new exploit known as ShadowRay has emerged, targeting a vulnerability in the Ray AI Framework. This attack is designed to compromise AI systems and has evolved to utilize AI-generated payloads, significantly enhancing…

    3 articles · Updated November 19, 2025

Recent Intelligence Reports

  • ShadowRay 2.0 Turns Misconfigured Open Source Ray Servers Into Self — Opensourceforu · November 24, 2025
  • New ShadowRay Attack Exploits Vulnerability in Ray AI Framework to Target AI Systems — Cyberpress · November 19, 2025
  • New ShadowRay Exploit Targets Vulnerability in Ray AI Framework to Attack AI Systems — Gbhackers · November 19, 2025

Frequently asked questions

What is Ray AI Framework?

Ray AI Framework is a technology platform referenced in recent ShadowRay threat reports.

Is Ray AI Framework still active?

The most recent intelligence report mentioning Ray AI Framework on ThreatCluster is dated November 24, 2025. Activity was first observed November 19, 2025, giving a tracked span from then to November 24, 2025.

What is Ray AI Framework associated with?

Across ThreatCluster reporting, Ray AI Framework most frequently co-occurs with Data Breach, Malware, Zero-day Exploit, ShadowRay Attack.

What are the latest developments involving Ray AI Framework?

The most significant recent cluster is “ShadowRay 2.0 Exploits Flaw in Open Source Ray Framework to Hijack GPU Clusters” (2 articles · Updated November 24, 2025). Ray AI Framework appears across 4 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on Ray AI Framework?

Ray AI Framework appears in 3 intelligence report mentions across 4 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown