Skip to main content
FeaturedDaily
Back to all news

Anthropic

Attackers exploit Mythos-found Rejetto HFS flaw within a day

CVE-2026-61500, a critical bug in Rejetto HTTP File Server, was targeted about 24 hours after a public technical write-up.

By , Editor-in-Chief · FeaturedDailyVerified October 2026

The answer

Attackers exploited critical Rejetto HFS flaw CVE-2026-61500, found with Anthropic's Mythos, about a day after a write-up.

What happened: Attackers began exploiting CVE-2026-61500, a critical flaw in Rejetto HTTP File Server (HFS), within about a day of a public technical write-up. Researchers at Horizon3.ai found the bug using Anthropic's Mythos model, SecurityWeek reported.

The numbers: The flaw scores 9.3 on the CVSS scale. It was discovered in June 2026, and HFS 3.2.1 patched it on 13 July. VulnCheck saw exploitation attempts from a China Telecom IP address against canaries in Japan and the US on 2 October. Four US-based IPs followed.

The details: HFS used JavaScript's Math.random() to make session-cookie values. That generator, xorshift128+, is reversible. An attacker who collects login responses can reconstruct its state and recover the signing key. From there, they can forge administrator session cookies and get remote code execution.

In their words: Horizon3.ai said attackers "able to collect other numbers generated by Math.random() could determine other generated numbers and forge the authentication cookies."

The context: Zach Hanley of Horizon3.ai led the work. Mythos used "advanced mathematical reasoning to recognize that Math.random() PRNG outputs could be reversed to reconstruct the secret session-cookie signing key." Mythos is Anthropic's restricted cyber-capable model. Rejetto's advisory says: "Multiple security vulnerabilities have been found in all previous versions, potentially allowing an attacker to gain administrative access to HFS."

Why it matters: The gap between disclosure and attack was about 24 hours, according to a DEV Community report. The Register called it the second Anthropic-linked vulnerability exploited in the wild, under a headline saying Mythos is "hardcore good at math".

The rivals: Google's Gemini 4 Argon launched to cyber defenders the same week.

What's next: Anyone running HFS should upgrade to version 3.2.1 or later. All earlier versions are affected.

Sources

← All news