Skip to main content
HIGH Threat Intel #Ransomware

CISA Warns of Active Ray Exploit and Medusa Ransomware Campaign

2 min read Runtime Rebel Intel
Primary source: securityweek.com

This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy

Key points
  • Federal civilian agencies and critical infrastructure operators face active exploitation of Ray and GoAnywhere vulnerabilities by multiple threat groups.
  • Affected systems include Ray-Project Ray deployments, Fortra GoAnywhere, and BeyondTrust instances targeted by ransomware affiliates.
  • Prioritize immediate patching of the Known Exploited Vulnerabilities catalog items and implement strict upstream traffic filtering.

Advertisement

A recent weekly intelligence roundup published by SecurityWeek details critical developments across the threat landscape, including active ransomware campaigns, nation-state espionage operations, and urgent vulnerability disclosures affecting enterprise infrastructure.

Active Vulnerability Exploitation and Botnets

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent directive ordering federal civilian agencies to secure deployments against an actively abused flaw. Specifically, CVE-2025-62593 in Ray-Project Ray has been added to the Known Exploited Vulnerabilities catalog. Telemetry from BitSight reveals that the RondoDox botnet—a Mirai-inspired variant leveraging over 170 distinct exploits—is actively targeting edge devices using this vector.

Concurrently, joint advisories from federal agencies highlight that Medusa ransomware affiliates are aggressively exploiting vulnerabilities in Fortra GoAnywhere and BeyondTrust. These attacks target critical infrastructure entities, employing advanced tactics such as Minidump for credential theft and Interactsh dynamic URLs to verify successful compromise. More than 500 organizations have experienced operational disruptions from this coordinated campaign.

Linux Botnets and Edge Device Risks

FortiGuard Labs released tracking telemetry on Evooo1Bot, a modular Linux botnet designed to compromise internet-facing infrastructure. The malware features an SSH brute-forcer, credential sniffer, and SOCKS5 relay module to transform infected hosts into persistent proxy nodes. Security teams must monitor perimeter devices for anomalous outbound connections and unauthorized administrative access attempts.

Nation-State Espionage and Physical Mitigations

In state-sponsored activity, telecommunications provider T-Mobile physically severed a compromised router cable with scissors during a 2024 intrusion response to halt an espionage campaign orchestrated by the Chinese state-sponsored group Salt Typhoon. The operation targeted multiple major US carriers to gather intelligence.

Corporate networks also face recurring risks from supply chain and cloud misconfigurations. In a separate incident, an autonomous AI agent developed by Wiz identified a critical workflow vulnerability in a public Snowflake repository, prompting GitHub to clarify that the exposed code was human-authored rather than generated by AI assistants.

Actionable Defensive Recommendations

Security professionals should prioritize the following steps to mitigate these emerging threats:

  • Patch Known Exploited Flaws: Immediately apply vendor patches for CVE-2025-62593 and review CISA’s Known Exploited Vulnerabilities catalog.
  • Harden Perimeter Defenses: Audit internet-facing edge devices, disable unnecessary services, and enforce multi-factor authentication for administrative access.
  • Monitor for Botnet Traffic: Implement network monitoring to detect anomalous SOCKS5 proxy traffic and brute-force patterns originating from internal Linux hosts.

Related: The Gentlemen Ransomware: Worm-like Spread, 478 Victims, RaaS Ties, CVE-2025-62593: Ray-Project Ray RCE Exploited In Wild

Advertisement

Advertisement