Initializing portfolio

000

Aravind.
All articles
Cybersecurity2 min read

An AI Found the Bug. Now Attackers Are Using It.

A critical Rejetto HFS flaw found with Anthropic's Mythos model by Horizon3.ai is now being probed in the wild, CVE-2026-61500, CVSS 9.3.

AravindChief Technology Officer & Advisor · AI, Cloud & Cybersecurity
An AI Found the Bug. Now Attackers Are Using It.

A critical vulnerability in Rejetto HTTP File Server, tracked as CVE-2026-61500 and scored 9.3 on CVSS, is being targeted in the wild. VulnCheck warned on 2 October that it had started seeing reconnaissance against its canaries, traced to a China Telecom IP, with hits in Japan and the US.

What makes this one worth reading is how it was found.

The flaw

HFS signs session cookies with a key derived from JavaScript's Math.random(), which in V8 uses the xorshift128+ generator. That generator is not built for security, and its outputs are reversible. During login, HFS also leaks values from the same random stream to unauthenticated clients. Collect enough of them, reconstruct the generator state, recover the signing key, forge an administrator cookie. From there the server_code configuration feature gives remote code execution.

How it was found

Horizon3.ai researchers found it in June using Anthropic's Mythos model, as part of Project Glasswing. Per the reports, Mythos linked the weak generator to the separate code path that leaked its output, then proposed using the Z3 solver to recover the key. It also produced a working proof of concept. Horizon3 said it would normally have tried brute force first and had not seen an SMT solver used this way against a real application.

The fix is out. Rejetto HFS 3.2.1 shipped on 13 July. The gap between a patch in July and exploitation in October is the part defenders should look at.

What I take from it

AI-assisted bug hunting is no longer a lab demo. The same capability that helps a research firm responsibly disclose a flaw is available to people who will not. If you run HFS 3.x, update to 3.2.1 now. If you run any open-source tooling exposed to the internet, assume models are reading its code, because they are.

Source: SecurityWeek - Exploitation Hits Rejetto HFS Vulnerability Discovered by AI

#Anthropic#Mythos#Rejetto HFS#Horizon3.ai#VulnCheck

Comments

Checking you're human…

Keep reading

Get the next essay first

Checking you're human…

By subscribing you agree to our Privacy Policy. Unsubscribe anytime.