theregister.com web signal

Anthropic's Mythos finds Rejetto HFS flaw, exploited in a day

TL;DR

  • Horizon3's Zach Hanley used Anthropic's Mythos model to find CVE-2026-61500, a critical authentication-bypass bug in Rejetto HTTP File Server.
  • HFS derived its Koa session signing key from Math.random(); Mythos determined V8's xorshift128+ output was fully reversible once the app leaked raw values.
  • Within a day of Wednesday's disclosure, VulnCheck's canaries saw a China-based IP attacking US and Japanese servers; the fix is HFS 3.2.1.

Anthropic's Mythos model found a critical authentication-bypass bug in Rejetto HTTP File Server. Within a day of Wednesday's disclosure, VulnCheck's canaries picked up an attacker in China hitting vulnerable servers in the US and Japan.

The flaw, tracked as CVE-2026-61500, sits in how HFS derives the signing key for its Koa session cookies: from Math.random(). V8's implementation of Math.random() runs on the xorshift128+ algorithm, which The Register reports Mythos determined was "fully reversible" once the application leaked outputs through a separate code path. Two facts chained: a forged cookie, an admin session, remote code execution.

"What makes this impressive is that Mythos didn't just flag the insecure PRNG in isolation," wrote Horizon3's Zach Hanley. "It simultaneously identified that the application leaked raw Math.random() outputs through a separate code path, recognized those two facts as a chain, and determined the leak produced exactly the observations needed to make state recovery feasible."

VulnCheck's Patrick Garrity said the firm's "canaries detected an actor in China targeting real vulnerable hosts in the US." By the next day he reported "four hits" from two US proxy IPs, 173.239.211[.]248 and 173.239.211[.]249. Horizon3 joined Anthropic's restricted-access Project Glasswing in July 2026.

The piece notes Anthropic claims Mythos is "too powerful to release to the general public." This is the second Anthropic-linked vulnerability now known to be exploited in the wild. The fix is Rejetto HFS 3.2.1 or later.