Researchers disclosed a browser networking flaw dubbed 0.0.0.0 Day that allows malicious websites to send HTTP requests to services bound to localhost by targeting 0.0.0.0, bypassing expected browser protections on macOS and Linux. The issue affects major browsers through inconsistent handling of localhost and private network requests, enabling state-changing actions and, in some cases, remote code execution against local services even when attackers cannot read responses because of CORS. Apple, Google, and other browser vendors have acknowledged the problem and moved to block or restrict 0.0.0.0 as a destination, while Windows is largely unaffected because the operating system already blocks such traffic.
The flaw was tied to active exploitation campaigns against AI and automation infrastructure, including ShadowRay attacks on publicly exposed Ray clusters via the Ray Dashboard and Jobs API, as well as attacks on Selenium Grid and PyTorch/TorchServe instances. Oligo reported hundreds to thousands of compromised Ray servers, with attackers stealing cloud and SaaS credentials, exposing private keys, establishing reverse shells, and deploying cryptominers such as XMRig and NBMiner; Wiz separately documented SeleniumGreed, in which exposed Selenium Grid services were abused for cryptomining. Defenders were urged to stop exposing Ray dashboards and Selenium services to the internet, add authentication and authorization layers, enforce network isolation and firewalling, and harden local services with CSRF protections, host validation, HTTPS, and browser-related private network controls.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
CSIRT.SK published an advisory on the 0.0.0.0 Day issue, stating the underlying weakness had been known since 2006 and summarizing observed exploitation against localhost and local-network services in browsers on macOS and Linux.
Oligo disclosed "0.0.0.0 Day," a browser logic flaw that lets public websites send requests to localhost-bound services via 0.0.0.0, bypassing expected protections. The company said the issue was being actively exploited, including in ShadowRay-style attacks and against services such as Selenium Grid and TorchServe.
Wiz published details of "SeleniumGreed," describing threat actors exploiting exposed Selenium Grid services for cryptomining and providing attack-flow and remediation guidance. The report tied Selenium Grid abuse to the broader pattern of attacks against locally or publicly exposed developer and AI services.
On its publication date, Oligo publicly disclosed the "ShadowRay" campaign targeting AI workloads, describing active in-the-wild exploitation of exposed Ray clusters and warning that hundreds to thousands of servers had been compromised globally.
Oligo reported evidence that attackers had been exploiting publicly exposed Ray clusters for at least seven months before its March 2024 publication, abusing the Ray Jobs API via the dashboard to achieve remote code execution. The campaign led to widespread compromise, credential theft, and cryptomining on affected servers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourceoligo.security
Open sourcewiz.io
Open sourceoligo.security
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.