Skip to content
Anthropic's Mythos model finds critical HFS flaw; exploitation begins within 24 hours

Anthropic's Mythos model finds critical HFS flaw; exploitation begins within 24 hours

News.Lavx.Hu • October 3, 2026

Anthropic's restricted bug-hunting model Mythos discovered a critical authentication bypass in Rejetto HTTP File Server that allows remote code execution. Attackers began exploiting the flaw within a day of disclosure, with initial activity traced to China-hosted infrastructure.

Anthropic's Mythos bug-hunting model has uncovered its second vulnerability known to be exploited in the wild — a critical authentication bypass in Rejetto HTTP File Server (HFS) that grants full administrative access and remote code execution.

Horizon3 researcher Zach Hanley discovered the flaw, now tracked as CVE-2026-61500, on Wednesday using Mythos through Anthropic's Project Glasswing program. By Thursday evening, VulnCheck security researcher Patrick Garrity detected active exploitation attempts originating from an IP address in China targeting vulnerable hosts in the United States and Japan.

"We started detecting exploitation of CVE-2026-61500 in Rejetto HFS this evening," Garrity posted on Thursday. "Our canaries detected an actor in China targeting real vulnerable hosts in the US."

Users of Rejetto HFS should update to version 3.2.1 or later immediately. The software previously appeared on CISA's Known Exploited Vulnerabilities catalog in 2024.

How Mythos found the flaw

Mythos excels at mathematical reasoning and computer science tasks, capabilities that proved decisive in uncovering this vulnerability. The bug stems from how HFS handles session authentication.

The server generates a random value using JavaScript's Math.random() and passes it to Koa, the Node.js web framework underlying HFS. Koa uses the keygrip library to sign all session cookies with that random value. If an attacker can derive the session signing key, they can forge valid session cookies and bypass authentication entirely.

This should be impossible if Math.random() uses a cryptographically secure pseudo-random number generator. But V8's implementation relied on the xorshift128+ algorithm, which is fully reversible. The application was also leaking Math.random() outputs through a separate code path.

Mythos recognized that these two facts formed an exploit chain. The model determined that Z3, a Microsoft-developed Satisfiability Modulo Theories (SMT) solver, could recover the PRNG seed from the leaked outputs — enabling an attacker to calculate the session signing key and forge administrative cookies.

"What makes this impressive is that Mythos didn't just flag the insecure PRNG in isolation," Hanley wrote. "It simultaneously identified that the application leaked raw Math.random() outputs through a separate code path, recognized those two facts as a chain, and determined the leak produced exactly the observations needed to make state recovery feasible."

Horizon3 researchers could not recall seeing an SMT solver used this way to attack a cryptographic flaw in a real application.

Project Glasswing track record

Anthropic launched Project Glasswing in April, granting select security partners access to Mythos under strict controls. The company considers the model too powerful for public release. As of Friday, Mythos has uncovered 286 CVEs across Glasswing partners, according to Garrity's tracker. Only two have been exploited in the wild — this HFS vulnerability and one flaw.

Hanley said Horizon3 has discovered "many critical vulnerabilities" since joining Glasswing in July. The company published a video demonstrating the HFS exploit and remote code execution.

The rapid exploitation timeline — within 24 hours of public disclosure — underscores the growing speed at which threat actors weaponize newly revealed vulnerabilities, particularly when detailed proof-of-concept code is available.

Source : theregister.com