Anthropic's Mythos model uncovers Rejetto HTTP File Server flaw now under active attack
AI

Anthropic's Mythos model uncovers Rejetto HTTP File Server flaw now under active attack

TechNews Editorial
TechNews EditorialOct 3, 2026 · 2 min read
Share

Why it matters

The discovery demonstrates how advanced AI models can autonomously chain complex vulnerabilities together to achieve remote code execution in real world applications.

The facts

  • Anthropic bug hunting model Mythos helped discover a critical authentication bypass vulnerability in Rejetto HTTP File Server.
  • VulnCheck observed initial exploitation attempts originating from China and targeting hosts in the US and Japan.
  • The flaw allows full admin access and remote code execution by leveraging a predictable Math.random function and an SMT solver.

A critical authentication bypass bug in Rejetto HTTP File Server has become the second Anthropic linked vulnerability known to suffer exploitation in the wild. Initial attack activity arrived from a China hosted IP address and targeted vulnerable systems located in the United States and Japan. Rejetto HFS functions as an open source web file server that previously appeared on the US Cybersecurity and Infrastructure Security Agency catalog of Known Exploited Vulnerabilities in 2024. Users operating Rejetto HFS must update to version 3.2.1 or later to fix this security flaw alongside other vulnerabilities.

Researchers detected active exploitation

Patrick Garrity, a security researcher at VulnCheck, reported on LinkedIn that his team started detecting exploitation of the new flaw on Wednesday evening. Garrity tracks vulnerabilities attributed to Mythos and Project Glasswing, an Anthropic initiative that gives select partners access to the bug hunting model. Anthropic has withheld the Mythos model from general public release due to its extreme capability levels. By Friday, Garrity recorded that Mythos and Project Glasswing had uncovered a total of 286 CVEs.

Prior to Thursday, only one of the vulnerabilities found by the model had seen real world attacks. The Thursday evening activity originated from a single IP address in China and targeted vulnerable servers in the US and Japan. On Friday, VulnCheck observed four additional hits originating from two different US IP addresses within the same subnet. Garrity noted that these US addresses appear to route traffic through a proxy server. China linked digital intruders routinely use compromised devices as proxies to mask their true locations.

Mathematical prowess enabled the breakthrough

Zach Hanley, a researcher at AI pen testing company Horizon3, used Mythos to discover the flaw now tracked as CVE-2026-61500. Horizon3 joined Project Glasswing in July and has used Mythos to uncover many critical vulnerabilities. Hanley published a video demonstrating the exploit steps to remotely execute code on the server. According to Hanley, the discovery highlights the model strengths in mathematical distillations, scientific tasks, computer science, and operating systems.

A compromised network device forwards incoming attack traffic to two remote servers, concealing where the traffic originally came from.
Illustration: AI & Tech News

The authentication bypass mechanism

The security issue arises from how Rejetto HFS authenticates users through generated random values. The application generates a random value using Math.random() and passes it to the Koa Node.js web framework. Koa utilizes keygrip to sign all session cookies with that random value. V8 Math.random() relies on an insecure xorshift128+ algorithm that is fully reversible, and the application leaked those Math.random outputs. Mythos discovered the insecure PRNG and determined that the application leaked raw outputs through a separate code path.

The AI model recognized those two factors as an attack chain and deduced that the leak produced exact observations to make state recovery feasible. Mythos also analyzed that a Microsoft developed Satisfiability Modulo Theories solver named Z3 could recover the PRNG seed. Hanley stated that Horizon3 researchers had never seen an SMT solver used this way to attack a cryptographic flaw in a real application and bypass authentication. Horizon3 reported the bug to VulnCheck for CVE assignment.

Newsletter

Get the best AI & tech news daily

A concise daily digest. Unsubscribe anytime.

We use your email only to send this newsletter.

Keep reading