Cryptojacking bot
"The flaw exists in an Application Programming Interface for Ray, an open-source framework for automating, scaling and optimizing compute resources that Oligo researchers called Kubernetes for AI due to its popularity.
"This vulnerability allows for unauthenticated remote code execution.
"The attackers 'have turned Ray’s legitimate orchestration features into tools for a self-propagating, globally cryptojacking operation, spreading autonomously across exposed Ray clusters,' Oligo researchers Ari Lumelsky and Gal Elbaz wrote."
Comments
Post a Comment
Empathy recommended