Get the latest tech news
‘ShadowRay’ vulnerability on Ray framework exposes thousands of AI workloads, compute power and data
For months, this flaw has allowed attackers to exploit AI production workloads, computing power, credentials and other sensitive data on Ray.
For the last seven months, this flaw has allowed attackers to exploit thousands of companies’ AI production workloads, computing power, credentials, passwords, keys, tokens and “a trove” of other sensitive information, according to new research from Oligo Security. This decision “underscores the complexity of balancing security and usability in software development,” the Oligo researchers write, “highlighting the importance of careful consideration in implementing changes to critical systems like Ray and other open-source components with network access.” The Oligo researchers concede that “shadow vulnerabilities will always exist” and that signs of exploit vary — data could be loaded from untrusted sources, firewall rules might be missing or users may not take into account dependency behavior.
Or read this on Venture Beat