The Cybersecurity and Infrastructure Security Agency (CISA) has ordered all federal civilian agencies to address a severe code injection vulnerability, identified as CVE-2025-62593, in Ray-Project Ray. This directive follows the flaw's inclusion in the Known Exploited Vulnerabilities catalog, indicating active abuse by threat actors in real-world scenarios.
BitSight observed the RondoDox botnet exploiting this vulnerability. RondoDox, a botnet inspired by Mirai, utilizes 174 different exploits to compromise vulnerable edge devices, highlighting the widespread threat posed by this specific flaw.
In 2024, T-Mobile's cybersecurity team took the measure of physically cutting a router cable to halt an active network intrusion. The intrusion was attributed to Salt Typhoon, a Chinese state-sponsored hacking group. This action was taken to prevent further compromise of their systems.
An autonomous AI tool developed by Wiz successfully identified and exploited a critical GitHub Actions workflow vulnerability within a public Snowflake repository, leading to unauthorized access to the company’s internal Jira tickets. Initially, reports suggested GitHub Copilot introduced the flaw.
However, GitHub clarified that the vulnerable code snippet was entirely human-authored, not generated by AI. This distinction addresses concerns about AI's role in introducing security vulnerabilities.
FortiGuard Labs is tracking Evooo1Bot, a new Linux botnet characterized by its modular design. This Mirai variant targets internet-facing devices by exploiting over a dozen known CVEs. Beyond standard DDoS capabilities, Evooo1Bot includes an SSH brute-forcer, a credential sniffer, and a SOCKS5 relay module. These features allow it to convert infected hosts into persistent proxy nodes for attackers, expanding its utility beyond denial-of-service attacks.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
CISA issued a directive for federal agencies to patch a critical code injection vulnerability in Ray-Project Ray, which is actively being exploited by the RondoDox botnet. Separately, T-Mobile physically disconnected a router cable to stop an intrusion by the Chinese state-sponsored hacking group Salt Typhoon.