Find notable cyber news and cases, enriched with sources, timelines, and signals.

ShadowRay 2.0 Ray cluster hijacking campaign

Campaign
First reported
Last updated
Happening score
H score 42
2 unique sources, 2 articles

Summary

Hide ▲

The ShadowRay 2.0 campaign is hijacking exposed Ray clusters on the public internet, using AI-generated payloads and CVE-2023-48022 to spread a self-propagating cryptomining botnet. The operation matters because it goes beyond mining: it also includes reported credential theft and DDoS activity. Two delivery waves were observed, with a GitLab path ending on November 5 and a GitHub path active since November 17. The target surface is large, with more than 230,000 Ray servers reportedly reachable online.

Related Happenings

Shai-Hulud worm clone activity on NPM

Malware Activity
H score69 First: 18.05.2026 12:45 Last: 18.05.2026 12:45 Sources 1

About this happening: The Shai-Hulud malware activity has continued to evolve across the npm supply chain and related developer ecosystems. It first infected npm packages in September 202...

TeamPCP Mini Shai-Hulud npm supply-chain campaign

Campaign
H score75 First: 12.05.2026 14:07 Last: 12.05.2026 14:07 Sources 1

About this happening: The TeamPCP-linked Mini Shai-Hulud campaign is an active npm supply-chain operation that steals developer credentials and abuses trusted publishing paths to spread tro...

Tropic Trooper trojanized SumatraPDF remote-access campaign

Campaign
H score34 First: 24.04.2026 12:29 Last: 24.04.2026 12:29 Sources 1

About this happening: Tropic Trooper is running an active campaign that uses a trojanized SumatraPDF lure to plant AdaptixC2 Beacon and later abuse VS Code tunnels for remote access...

Mirax social media ad campaign targeting Spanish-speaking users

Campaign
H score44 First: 13.04.2026 17:30 Last: 13.04.2026 17:30 Sources 1

About this happening: The Mirax distribution campaign is using social media advertisements and fake IPTV or streaming apps to reach Spanish-speaking users at scale, raising the risk of...

React2Shell (CVE-2025-55182) mass scanning and exploitation wave

Exploitation Wave
H score89 First: 20.02.2026 23:07 Last: 20.02.2026 23:07 Sources 1

About this happening: CVE-2025-55182 (React2Shell) was publicly disclosed on December 3, 2025 as a CVSS 10 remote code execution flaw in React Server Components. Since then, the vulnera...

Timeline

  1. 18.11.2025 22:56 1 articles · 7mo ago

    GitLab-delivered ShadowRay 2.0 wave ends

    Exploitation Observed

    A GitLab-delivered ShadowRay 2.0 wave against exposed Ray clusters terminated on November 5, using CVE-2023-48022 to push payloads into public-internet reachable Ray infrastructure.

    Show sources
  2. 18.11.2025 22:56 1 articles · 7mo ago

    GitHub-delivered ShadowRay 2.0 wave begins

    Exploitation Observed

    A GitHub-delivered ShadowRay 2.0 wave against exposed Ray clusters has been active since November 17, using CVE-2023-48022 to extend compromise across public-internet reachable Ray infrastructure.

    Show sources
  3. 18.11.2025 22:56 2 articles · 7mo ago

    ShadowRay 2.0 disclosure and analysis

    Initial Disclosure

    ShadowRay 2.0 was disclosed on November 18 as a global campaign against exposed Ray clusters on the public internet, with AI-generated payloads attributed to IronErn440 that exploit CVE-2023-48022 for self-propagating mining, open Python reverse shells, persist via cron jobs and systemd modifications, and launch Sockstress-based DDoS attacks.

    Show sources