Ray-Project vulnerability now under active attack


CISA confirmed active exploitation of CVE-2025-62593, a code injection flaw in Ray-Project Ray. The vulnerability allows remote attackers to execute arbitrary code on distributed compute clusters. Federal agencies must patch publicly exposed Ray instances under BOD 26-04. Ray deployments often lack network segmentation, exposing dashboard and worker APIs to broader networks. No affected version range or exploit details are public yet.

This week also brings dbt Core v1.12 with an opt-in Rust parser that delivers 5-10× faster parsing on large projects. The parser is the same engine powering dbt Core v2.0, giving teams a low-risk migration path before the major version upgrade.

In this issue:

  • Ray-Project CVE-2025-62593: CISA confirms active exploitation
  • dbt Core v1.12: Rust parser option, on_error config, vars.yml support
  • St. Louis PBS loses archive access after cloud provider collapse
  • AMD building ROCm backend for headless GPU compute in QEMU VMs

Ray-Project Vulnerability Under Active Attack

The Signal

CISA added CVE-2025-62593, a code injection flaw in Ray-Project Ray, to its KEV catalog.

What Changed

  • Ray vulnerability allows remote attackers to execute arbitrary code on distributed compute clusters.
  • https://www.cisa.gov/news-events/alerts/2026/08/17/cisa-adds-one-known-exploited-vulnerability-catalog
  • CISA confirmed active exploitation in the wild as of August 17, 2026.
  • Federal agencies must remediate publicly exposed vulnerable assets per BOD 26-04 requirements.

Operational Impact

Teams running Ray clusters for ML training or distributed workloads face immediate risk of full cluster compromise. Ray deployments often lack network segmentation, exposing dashboard and worker APIs to broader networks. Operators must audit Ray cluster exposure, apply available patches, and check for compromise indicators before patching.

Watch For

No public exploit details or affected version ranges have been disclosed yet. Monitor Ray-Project security advisories for technical specifics and IOC guidance.


dbt Core v1.12 Ships Rust Parser Option and Quality-of-Life Upgrades

The Signal

dbt Core v1.12 introduces opt-in Rust parser delivering 5-10× faster parsing on large projects.

What Changed

  • New `--use-v2-parser` flag delegates parsing to Rust engine from dbt Core v2.0.
  • `on_error` config lets downstream models continue when upstream fails (default: `skip_children`).
  • Dedicated `vars.yml` file at project root, parsed before `dbt_project.yml`.
  • JavaScript UDFs for Snowflake and BigQuery; Python UDFs now support Databricks Unity Catalog.
  • New `--sql` flag for `dbt run-operation` executes ad hoc SQL without creating macros.
  • UDF `overloads` support multiple argument signatures; `packages` config for third-party PyPI dependencies.
  • Latest Semantic Layer YAML spec nests semantic definitions within model columns.
  • Snowflake adds Iceberg v3; BigQuery enables parallel microbatch; Redshift supports `query_group` session parameter.

Operational Impact

The Rust parser is the same engine powering dbt Core v2.0, giving teams a low-risk migration path before the major version upgrade. Teams can test parser compatibility on production projects by adding the flag, then remove it if issues surface. The `vars.yml` file reduces merge conflicts in large projects and enables variable references inside `dbt_project.yml` itself, fixing a long-standing parsing limitation. The `on_error='continue'` config solves a 2020 feature request: daily rollups can now proceed when an infrequently-changing dimension fails to refresh.

Watch For

Upgrade to v1.12 and run `dbt parse --use-v2-parser` to check v2.0 compatibility. Report parser edge cases before dbt Core v2.0 reaches GA.


PBS Data Trapped in Iron Mountain After Provider Collapse

The Signal

St. Louis NinePBS lost access to one-third of its archive when cloud provider Open Source Storage became defunct.

What Changed

  • NinePBS used OSS since 2019 for mixed onsite and cloud storage of programming archive.
  • OSS went delinquent in 2025, cutting off station access to data despite active contract.
  • Data sits on OSS-owned infrastructure inside Iron Mountain datacenter; Iron Mountain lacks account access.
  • Court ruled August 2026: station owns data, must find third party for extraction by September 14.
  • Multi-tenant infrastructure prevents direct recovery; must avoid compromising other OSS customer data.

Operational Impact

This exposes a custody gap in cloud storage contracts. The station owns the data legally but has no technical access path. Iron Mountain cannot release the data without OSS authorization, which no longer exists. Teams using smaller cloud providers should verify: who controls the datacenter account, what happens to physical infrastructure if the provider fails, and whether you can recover data without provider cooperation. Standard backup strategies failed here because the cloud tier itself became inaccessible.

Watch For

The September 14 status update will show whether third-party extraction from defunct provider infrastructure is viable. Other OSS customers likely face identical access problems with no clear timeline for resolution.


AMD Builds New ROCm Backend for GPU Compute in QEMU Virtual Machines

The Signal

AMD is developing a new ROCm backend for QEMU using dedicated headless VirtIO GPU instances.

What Changed

  • Current ROCm VM implementation shares VirtIO GPU context with display path, causing stuttering
  • New architecture uses dedicated headless VirtIO GPU instance solely for compute workloads
  • AMD building open-source ROCm backend library that loads in-process with QEMU
  • Addresses memory access limits and compute/render model mismatch in current implementation
  • Many accelerators lack display engines, making shared display path architecturally problematic

Operational Impact

Teams running ROCm workloads in VMs currently face display contention and memory constraints. The new backend targets headless compute scenarios: CI/CD pipelines, multi-tenant cloud GPU sharing, and development environments. AMD will distribute the backend library as part of ROCm, but no timeline or migration path has been announced.

Watch For

The mailing list discussion is ongoing. Performance benchmarks and upstream merge timeline remain unspecified.


Quick Reads

  • Ray-Project — CISA confirms active exploitation of code injection flaw in distributed compute clusters.
  • dbt Core v1.12 — New Rust parser offers 5-10× faster parsing and downstream error handling.
  • PBS Data Recovery — Cloud provider collapse leaves station archive trapped in Iron Mountain datacenter.
  • AMD ROCm — New headless VirtIO backend targets GPU compute workloads in QEMU virtual machines.

Subscribe to Signal Field

Data & infrastructure news. Subscribers get new posts by email a day before they go live on the site.

Email signup is coming soon — in the meantime, follow the Signal Field RSS feed.

Need a Custom MCP System?

Configuration & integration for your stack — from tool selection to production deployment. The directory recommends. The consultancy configures.

Get Started →