Ray is an open-source distributed computing framework used to orchestrate AI/ML workloads.
Ray is a tool tracked across 5 threat clusters and 10 intelligence report mentions on ThreatCluster. First observed November 18, 2025; most recent activity August 2, 2026.
Ray is an open-source distributed computing framework used to orchestrate AI/ML workloads. Recent reporting describes a vulnerability in Ray that can be exploited to hijack AI clusters, with ShadowRay 2.0 actively leveraging this flaw to seize control of cluster nodes. This highlights the risk of insecure AI infrastructure and the need for timely patching and tight access controls.
In late March 2026, the Vect ransomware group partnered with TeamPCP, a credential theft specialist, to enhance their cybercriminal operations. This collaboration aims to leverage TeamPCP's extensive credential…
At Black Hat USA 2026, 29% of sessions focused on AI security, highlighting a shift in attack methodologies targeting agent infrastructure. Significant briefings from Check Point Research revealed vulnerabilities in…
A global campaign named ShadowRay 2.0 is targeting exposed Ray clusters, exploiting the unpatched CVE-2023-48022 vulnerability. The attacks, attributed to a threat actor known as IronErn440, have been active since at…
TeamPCP, a cloud-native threat actor that emerged in December 2025, is targeting misconfigured cloud services such as Docker APIs and Kubernetes clusters. The group is building a distributed proxy and scanning…
The ShadowRay 2.0 campaign exploits a critical vulnerability (CVE-2023-48022) in the Ray open-source framework, allowing attackers to hijack exposed Ray clusters for cryptomining, data theft, and DDoS attacks. Oligo…
Ray is an open-source distributed computing framework used to orchestrate AI/ML workloads.
The most recent intelligence report mentioning Ray on ThreatCluster is dated August 2, 2026. Activity was first observed November 18, 2025, giving a tracked span from then to August 2, 2026.
Across ThreatCluster reporting, Ray most frequently co-occurs with DeadCatx3, IronErn440, ShellForce, TeamPCP, Botnet, among 12 tracked related entities.
The most significant recent cluster is “Vect and TeamPCP Form Alliance for Ransomware Operations” (8 articles · Updated July 2, 2026). Ray appears across 5 threat clusters in total, listed above with sources.
Ray appears in 10 intelligence report mentions across 5 deduplicated threat clusters, aggregated from 17,000+ monitored sources.