Avi Lumelsky

AI Security Researcher

I'm a Security Researcher at Oligo Security. Currently working on securing AI Application infrastructure and uncovering key vulnerabilities in open-source AI projects.

Research & Talks

November 2025

ShadowRay 2.0 - AI Attacks AI: Self-Propagating Botnet Campaign

  • Discovery: Uncovered active global campaign where threat actors ("IronErn440") exploit CVE-2023-48022 in Ray to hijack AI compute clusters into a self-replicating botnet - the first documented use of AI to systematically attack AI infrastructure
  • Scale: 230,000+ Ray servers exposed globally (10x increase from original ShadowRay discovery) - potentially active since September 2024
  • Sophistication: DevOps-style infrastructure using GitLab/GitHub for region-aware malware delivery, LLM-generated payloads, CPU throttling at ~60% to evade detection, disguised processes masquerading as kernel workers
  • Capabilities: Multi-purpose botnet for cryptojacking, DDoS attacks, data exfiltration, and autonomous propagation across continents via OAST-based discovery
  • Blog: ShadowRay 2.0: Attackers Turn AI Against Itself in Global Campaign
  • Coverage: [Forbes] [Dark Reading]
2024-2025

ShadowMQ - AI/ML Infrastructure Vulnerabilities

2025

Airborne - Wormable Zero-Click RCE in AirPlay

2025

Pwn My Ride - CarPlay Attack Surface & Jailbreaking

  • Discovery: First comprehensive security analysis of Apple CarPlay revealing critical attack vectors enabling car jailbreaking and vehicle system compromise through infotainment interfaces
  • Impact: Demonstrates how CarPlay vulnerabilities can be chained to gain unauthorized access to vehicle systems, potentially affecting millions of CarPlay-enabled vehicles from major manufacturers
  • Significance: Pioneering research into automotive security via smartphone integration protocols - presented at DEF CON 33, one of the world's premier hacking conferences
  • Talk: Pwn My Ride: Jailbreaking Cars with CarPlay - DEF CON 33 / AppSec Village 2025
  • Blog: Pwn My Ride: Exploring the CarPlay Attack Surface [Wired]
2025

Anthropic MCP Inspector

2024

Ollama Vulnerabilities

2024

ShadowRay - First Known Attack on AI Infrastructure

2021-2024

Side Projects & Other