News

A Day After Researchers Showed How Anthropic's Mythos Cracked a File Server, Attackers Started Probing It

Anthropic's Mythos found a file server bug that needed a math trick most humans would skip. Researchers published the recipe, and attackers showed up the next day.

A Day After Researchers Showed How Anthropic's Mythos Cracked a File Server, Attackers Started Probing It

An AI model built to find bugs for defenders found one that required a mathematical trick human researchers often give up on. Researchers published how it worked on Wednesday. By Thursday evening, attackers were already knocking.

The flaw, CVE-2026-61500, is a critical authentication bypass (CVSS 9.3) in Rejetto HTTP File Server (HFS), an open source web file server. It affects versions 3.0.0 through 3.2.0 and lets an attacker forge an administrator session, take full admin control and run code on the machine.

Horizon3.ai researcher Zach Hanley found it in June using Anthropic's Mythos, the bug-hunting model Anthropic says is too powerful to release publicly. Horizon3 joined Project Glasswing, the program that gives select partners access to Mythos, in July.

A bug only worth exploiting with a solver

HFS signs its session cookies with a key generated by JavaScript's Math.random(). In the V8 engine, that function runs on xorshift128+, a generator that is not cryptographically secure and whose outputs can be reversed. Separately, HFS leaked raw Math.random() outputs to unauthenticated users during login through a different code path.

Either fact alone looks like a footnote. Mythos put them together into a working attack chain: collect a handful of login responses (Horizon3's exploit samples the endpoint 12 times), reconstruct the generator's state, run it backwards to the signing key created at startup, then forge an admin cookie and execute code through HFS's documented server_code feature.

The model even proposed the tool for the math: Z3, Microsoft's open source SMT solver. Horizon3 said its researchers could not recall ever seeing an SMT solver used this way to bypass authentication in a real application.

Hanley wrote that the impressive part was not Mythos flagging a weak random number generator on its own. It was the model spotting the separate leak, realizing the two belonged in one chain, and working out that the leak supplied exactly the observations the attack needed. "It did not require follow-on prompting to find the disparate PRNG leak that made this theoretical issue a demonstrable one," Horizon3 said.

Then the canaries lit up

Rejetto shipped a fix in version 3.2.1 on July 13. A Python proof of concept by researcher Alejandro Ramos went public in late September, and Hanley published his write-up, with a video of the exploitation steps, on September 30.

The next day, VulnCheck's honeypots caught exploitation attempts. "We started detecting exploitation of CVE-2026-61500 in Rejetto HFS this evening," VulnCheck's Patrick Garrity posted. "Our canaries detected an actor in China targeting real vulnerable hosts in the US."

The first traffic came from a single China Telecom IP probing canaries in the US and Japan, which VulnCheck VP of research Caitlin Condon called "small-scale reconnaissance only." By Friday, Garrity counted four more hits from two US addresses in the same subnet that "appear to be coming from a proxy."

HFS has been here before. An earlier flaw, CVE-2024-23692, was exploited in 2024 to drop crypto miners, trojans and HATVIBE malware, and it sits in CISA's Known Exploited Vulnerabilities catalog.

The second one, out of 286

By Garrity's count, Mythos and Project Glasswing have uncovered 286 CVEs as of Friday. Until Thursday, only one had been exploited in real attacks. This Rejetto bug is the second.

That ratio is mostly good news for defenders. But Horizon3's warning cuts the other way: bugs that were once too mathematically tedious to weaponize get much cheaper when a model does the reasoning, and the writeup becomes the recipe. It fits the broader pattern in Anthropic's own September threat report and in its warning that China's open GLM-5.3 nearly matches elite US models at building exploits.

The patch has been sitting there since July. Anyone still running HFS 3.0.0 through 3.2.0 is now racing people who have read the same blog post.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free