**This Week In Cybersecurity: CISA Warns Of Actively Exploited Ray Vulnerability**
The ever-evolving landscape of cybersecurity demands constant vigilance. SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape. This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers maintain a well-rounded awareness of the evolving cybersecurity environment.
Here are this week’s highlights:
**CISA Warns of Actively Exploited Ray Vulnerability**
CISA has mandated that all federal civilian agencies prioritize fixing a severe code injection vulnerability (CVE-2025-62593) in Ray-Project Ray. The flaw was added to the Known Exploited Vulnerabilities catalog after threat actors were observed actively abusing it in the wild. BitSight observed the vulnerability being exploited by RondoDox, a Mirai-inspired botnet utilizing a staggering 174 distinct exploits to compromise vulnerable edge devices.
**GitHub Says Vulnerability Found by Autonomous Wiz Agent Not Introduced by AI**
An autonomous AI tool developed by Wiz successfully identified and exploited a critical GitHub Actions workflow vulnerability in a public Snowflake repository, gaining unauthorized access to the company’s internal Jira tickets. Although initially reported as a flaw introduced by GitHub Copilot, GitHub has clarified for SecurityWeek that the vulnerable code snippet was entirely human-authored.
**Threema DDoS Attack**
Encrypted messaging provider Threema recently endured significant service disruptions following a series of sophisticated, sustained DDoS attacks targeting its infrastructure and colocation partner. To stabilize operations, the company quickly implemented specialized upstream traffic filtering to block the malicious requests before they could reach and overload its servers.
**Evooo1Bot Linux Botnet**
FortiGuard Labs is tracking Evooo1Bot, a highly modular Linux botnet that targets internet-facing devices by exploiting over a dozen known CVEs. Going beyond standard DDoS capabilities, this Mirai variant is equipped with an SSH brute-forcer, credential sniffer, and a SOCKS5 relay module designed to convert infected hosts into persistent proxy nodes for attackers.
**T-Mobile Physically Cut Router Cable to Stop Chinese Hackers**
To stop an active network intrusion by the Chinese state-sponsored hacking group Salt Typhoon in 2024, T-Mobile’s cybersecurity staff physically cut a compromised router’s network cable with scissors at a Bellevue data center. T-Mobile was targeted in an extensive espionage campaign that impacted several other major US carriers.
**TeamPCP Claims Massive Data Theft from Alation**
Data catalog provider Alation confirmed an unauthorized intrusion into its internal network following a recent cyberattack. The hacking group TeamPCP has publicly claimed responsibility for the breach, alleging they successfully exfiltrated 73 gigabytes of sensitive data from the enterprise software company.
**Data Breach at Japan’s Sakura Internet Affects Over 1 Million Customer Records**
Japanese hosting provider Sakura Internet discovered a severe data breach in its sales management system, potentially compromising contract and membership information for up to 1.36 million users. The massive exposure was identified while security teams were investigating a completely separate malware infection that impacted a small subset of the company’s rental server accounts.
**Medusa Ransomware Targeting GoAnywhere and BeyondTrust Vulnerabilities**
A joint advisory from CISA, the FBI, and HHS cautions that Medusa ransomware affiliates are rapidly exploiting newly disclosed vulnerabilities in Fortra GoAnywhere and BeyondTrust to compromise critical infrastructure. The updated alert highlights the group’s evolving evasion toolkit, which now includes utilizing Minidump for credential theft and Interactsh dynamic URLs to verify successful network exploitation. The advisory says over 500 critical infrastructure organizations have been hit to date.
**Zombie Card Attack**
Academic researchers have demonstrated a new Zombie Card attack that bypasses cryptographic checks to complete contactless payments using physically expired Visa credit cards. By leveraging a smartphone relay setup to alter the expiration date fed to the POS terminal, attackers can exploit a communication gap between the local hardware and the issuing bank. The attack does not appear to work against Mastercard, American Express and Discover cards, and it does not work against all banks. Visa has not responded to SecurityWeek’s request for comment.
**Canadian Security Firm Secures Top-Tier NIST Certification for Post-Quantum Hardware Module**
Crypto4A has become the first company globally to achieve FIPS 140-3 Level 3 validation for an HSM supporting all NIST-approved post-quantum cryptographic algorithms. The newly certified QASM module delivers a tamper-resistant foundation to protect sensitive cryptographic keys from the future threat of advanced quantum computing attacks.
**Related**
* In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities
* In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street
### FAQ
**What is the Ray vulnerability mentioned by CISA, and who is at risk?**
The Ray vulnerability, identified as CVE-2025-62593, is a severe code injection flaw in the Ray-Project Ray framework. It has been added to CISA’s Known Exploited Vulnerabilities catalog because threat actors, specifically the RondoDox botnet, are actively exploiting it in the wild. All federal civilian agencies in the United States are mandated to prioritize fixing this vulnerability, though any organization or individual using Ray is potentially at risk.
**How did the GitHub vulnerability differ from an AI-introduced flaw?**
An autonomous AI security agent developed by Wiz successfully exploited a critical vulnerability in a GitHub repository. Initial reports suggested the flaw might have been introduced by GitHub Copilot. However, GitHub clarified that an AI tool did not create the vulnerability; instead, the AI successfully identified that the vulnerable code was entirely human-authored, demonstrating a new method for discovering existing coding errors.
**What makes the Evooo1Bot Linux botnet particularly dangerous?**
Unlike standard DDoS bots, Evooo1Bot is a highly modular Linux botnet. It exploits over a dozen known vulnerabilities to compromise devices and includes advanced capabilities beyond DDoS, such as an SSH brute-forcer, a credential sniffer, and a SOCKS5 relay module. These features allow it to turn infected hosts into persistent proxy nodes, making it a versatile and significant threat.
**What is a “Zombie Card” attack, and how can it be prevented?**
A Zombie Card attack exploits contactless payment systems by using a smartphone relay to trick a Point-of-Sale (POS) terminal into believing an expired Visa card is valid. This bypasses cryptographic checks by altering the expiration date information. Since the attack targets a communication gap between hardware and the issuing bank, prevention relies on payment providers and banks updating their verification systems to validate card status more rigorously.
**What is post-quantum cryptography, and why is Crypto4A’s certification significant?**
Post-quantum cryptography refers to encryption methods designed to be secure against attacks from future quantum computers, which could break current encryption. Crypto4A’s achievement of FIPS 140-3 Level 3 validation for a Hardware Security Module (HSM) that supports all NIST-approved post-quantum algorithms is significant because it provides a validated, tamper-resistant foundation for protecting sensitive keys against this future threat, marking a major step toward quantum-safe security.
### Conclusion
This week’s cybersecurity headlines paint a picture of a diverse and persistent threat landscape. From actively exploited vulnerabilities in widespread software and the evolution of sophisticated botnets to novel physical attack methods and the emergence of post-quantum security solutions, the challenges are multifaceted. Organizations and individuals must remain proactive, ensuring systems are patched, unusual traffic is monitored, and security frameworks evolve to address both current exploits and future technological risks. Staying informed is the first line of defense.



