← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

CISA Warns of Exploited Ray Vulnerability; T-Mobile Cut Cable to Stop Chinese Hackers

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • CISA mandated patching for CVE-2025-62593 in Ray-Project Ray due to active exploitation.
  • RondoDox botnet is exploiting the Ray vulnerability using 174 distinct exploits.
  • T-Mobile physically cut a router cable to stop a Salt Typhoon intrusion.
  • GitHub clarified an AI tool-found vulnerability was in human-authored code, not Copilot.

CISA Mandates Patch for Actively Exploited Ray Vulnerability

The Cybersecurity and Infrastructure Security Agency (CISA) has ordered all federal civilian agencies to address a severe code injection vulnerability, identified as CVE-2025-62593, in Ray-Project Ray. This directive follows the flaw's inclusion in the Known Exploited Vulnerabilities catalog, indicating active abuse by threat actors in real-world scenarios.

BitSight observed the RondoDox botnet exploiting this vulnerability. RondoDox, a botnet inspired by Mirai, utilizes 174 different exploits to compromise vulnerable edge devices, highlighting the widespread threat posed by this specific flaw.

T-Mobile Physically Disconnects Network to Counter State-Sponsored Attack

In 2024, T-Mobile's cybersecurity team took the measure of physically cutting a router cable to halt an active network intrusion. The intrusion was attributed to Salt Typhoon, a Chinese state-sponsored hacking group. This action was taken to prevent further compromise of their systems.

GitHub Clarifies Origin of Vulnerability Found by AI Tool

An autonomous AI tool developed by Wiz successfully identified and exploited a critical GitHub Actions workflow vulnerability within a public Snowflake repository, leading to unauthorized access to the company’s internal Jira tickets. Initially, reports suggested GitHub Copilot introduced the flaw.

However, GitHub clarified that the vulnerable code snippet was entirely human-authored, not generated by AI. This distinction addresses concerns about AI's role in introducing security vulnerabilities.

New Linux Botnet Evooo1Bot Emerges

FortiGuard Labs is tracking Evooo1Bot, a new Linux botnet characterized by its modular design. This Mirai variant targets internet-facing devices by exploiting over a dozen known CVEs. Beyond standard DDoS capabilities, Evooo1Bot includes an SSH brute-forcer, a credential sniffer, and a SOCKS5 relay module. These features allow it to convert infected hosts into persistent proxy nodes for attackers, expanding its utility beyond denial-of-service attacks.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~21 min · 18 stories · Aug 21

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

CISA issued a directive for federal agencies to patch a critical code injection vulnerability in Ray-Project Ray, which is actively being exploited by the RondoDox botnet. Separately, T-Mobile physically disconnected a router cable to stop an intrusion by the Chinese state-sponsored hacking group Salt Typhoon.