Anthropic's Mythos AI uncovers critical HFS bug that is already being exploited
Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server, and attackers in China began exploiting it within days.
Anthropic's bug-hunting AI, Mythos, flagged a severe authentication-bypass issue in the open-source Rejetto HTTP File Server, assigned CVE-2026-61500. Horizon3 researcher Zach Hanley demonstrated how the flaw lets an attacker reconstruct the session-signing key by exploiting a weak Math.random implementation, using an SMT solver to recover the PRNG seed. After the disclosure, VulnCheck observed exploitation attempts from a China-based IP against servers in the United States and Japan, followed by activity from two US addresses that appear to be proxy nodes.
The incident marks only the second real-world exploit among the 286 CVEs uncovered by Mythos and Project Glasswing since the program’s launch in April. Users are urged to upgrade to Rejetto HFS version 3.2.1 or later. The episode highlights Mythos's strength in mathematical analysis and the growing threat of proxy-based attacks linked to Chinese actors.
Why it matters
A powerful AI tool is revealing critical software flaws that attackers quickly weaponize, exposing global networks to remote code execution.
In this story
Related stories
2 in this thread