Second Time’s a Charm: Another Exploit Unearthed
The second exploit connected to Anthropic decided to play around in the wild, with some mischievous activities emerging from an IP address in China. Not aiming low, they set their sights on vulnerable targets in the US and Japan. What’s the vulnerability, you wonder? A severe authentication-bypass flaw in Rejetto HTTP File Server (HFS). And when I say “severe,” I mean it could grant complete admin access and allow nefarious individuals to perform remote code execution. HFS is somewhat outdated, having already appeared on the US Cybersecurity and Infrastructure Security Agency’s list of Known Exploited Vulnerabilities back in 2024.
Mythos: The Unrecognized Champion?
On a pleasant Wednesday, researcher Zach Hanley from Horizon3, a premier AI penetration testing company, revealed that he enlisted the help of Mythos to discover a new flaw in the file server. This latest one is dubbed CVE-2026-61500, and if you’re foolish enough to still be using Rejetto HFS, do yourself a favor and upgrade to v3.2.1 or later. Allegedly, it resolves this and other rather bothersome security issues.
Video Proof: Because Seeing is Believing
For those who prefer visual representations of flaws, Hanley even created a video illustrating the steps to exploit HFS and fiddle with remote code execution on the server. By the following day, the CVE was being exploited. VulnCheck security researcher Patrick Garrity had a conversation on LinkedIn, mentioning they began observing exploitation of CVE-2026-61500 in Rejetto HFS by Thursday evening. Thanks to Hanley and his team, they informed VulnCheck about the bug for CVE assignment.
China: Up to No Good Again
“Our canaries detected an actor in China targeting real vulnerable hosts in the US,” Garrity stated. Garrity has been closely monitoring CVEs related to Mythos and Project Glasswing, Anthropic’s initiative to provide select partners access to the bug-hunting model since shortly after its inception in April. Anthropic has been somewhat secretive, stating that Mythos is too potent to be released to the wider public. Laugh it up, buddy.
286 CVEs and Counting
As of Friday, Mythos and Project Glasswing have identified 286 CVEs, according to Garrity’s tracking system. Up until Thursday, only one of these issues had surfaced in actual attacks. The Thursday night escapades originated from a single IP address in China, targeting vulnerable servers in the US and Japan, Garrity shared with GadgetLad. “Today we have witnessed four hits,” he told us on Friday.
Proxy Antics
These came from two distinct IP addresses in the US: 173.239.211[.]248 and 173.239.211[.]249. Both share the same abode – subnet, that is – and “appear to be emanating from a proxy,” Garrity noted. China’s digital troublemakers are fond of employing compromised devices as proxies to redirect malicious traffic while obscuring their true locations. In April, a 10-country security advisory discussed China-linked cyber operatives utilizing proxy networks “strategically, and at scale.”
Mythos’ Wild Math Abilities
Let’s discuss CVE-2026-61500 – it showcases several of Mythos’s standout features that make it brilliant at identifying vulnerabilities, according to Hanley. Mythos is the whiz of mathematical manipulation and scientific tasks, particularly those involving computer science and operating systems. Discovering this CVE “illustrates Mythos’s talent in grasping mathematics, how it pinpointed an exploitable array of cryptographic errors, and approached overcoming the constraints to achieve remote code execution,” Hanley wrote.
Weak Authentication
The security dilemma arises from how HFS handles user authentication. It generates a random value with Math.random() and passes it to Koa, the Node.js web framework underpinning HFS. Koa uses keygrip to sign all session cookies with that random value. The problem is, if an attacker can uncover the session signing key, they can fabricate valid session cookies. This shouldn’t occur if Math.random() operates using a secure pseudo-random number generator (PRNG). However, V8’s Math.random() wasn’t cooperating.
Math Mischief Handled
Mythos discovered that the xorshift128+ algorithm’s output was entirely reversible, and the application was disclosing Math.random() outputs. The model’s analysis posited that Z3, a Microsoft SMT solver available for use, could be utilized to recover the PRNG seed. Hanley noted that Horizon3’s researchers couldn’t recall encountering an SMT solver applied in this manner to address a crypto vulnerability in a real application and evade authentication.
A Not-So-Happy Mistake
“What makes this remarkable is that Mythos didn’t merely flag the insecure PRNG in isolation – it simultaneously recognized that the application leaked raw Math.random() outputs through a separate code path, connected those two facts as interlinked, and established that the leak created exactly the observations necessary to render state recovery practical,” Hanley observed.
Summary: A Geordie’s Overview of Digital Turmoil
If you find yourself still operating Rejetto HFS, it may be time to reevaluate your choices. Mythos, with its incredible math skills, has been revealing vulnerabilities as if they’re going out of style. If only China would take up knitting instead of meddling where they don’t belong.