Skip to content

ai-security

Attackers hit a Mythos-found HFS bug within a day

Claude News

According to The Register, the break-in to Rejetto HTTP File Server came down to math. Anthropic's Mythos worked out that the server's random-number generator could be run backwards with an off-the-shelf solver, and Horizon3's researchers say they could not recall seeing that done to bypass authentication in a real application. Attackers were exploiting the resulting bug, CVE-2026-61500, the day after it went public.

At a glance

  • VulnCheck's canaries caught exploitation attempts from a China-hosted IP address against vulnerable HFS hosts in the US and Japan, a day after Horizon3's Zach Hanley published his findings and an exploit video.
  • HFS signed session cookies with a key from V8's Math.random(), whose xorshift128+ output can be reversed. The app also leaked raw outputs, so an attacker could recover the key and forge cookies.
  • VulnCheck's tracker counts 286 CVEs from Mythos and Project Glasswing as of Friday, and until Thursday only one had been exploited in real attacks, which makes the HFS bug the second.

In case you missed it: Anthropic announced Project Glasswing in April. The program gave select partners access to Mythos, and Anthropic said the model was too powerful for public release. According to Anthropic, about 50 initial partners found more than 10,000 high- or critical-severity flaws. In a September 21 article, The Register reported that VulnCheck researcher Patrick Garrity's tracker of Glasswing CVEs stood at 225. Only one of them had been exploited in the wild: a SQL injection bug in Ghost, CVE-2026-26980.

CVE-2026-61500 went from an exploit video to live attacks in about a day

The bug is a critical authentication bypass in Rejetto HFS, an open source web file server, and it can lead to full admin access and remote code execution. Attackers already know HFS: it appeared in CISA's Known Exploited Vulnerabilities catalog in 2024. On Wednesday, Zach Hanley of AI pen-testing company Horizon3 said he had found the flaw with Mythos. He also published a video that walks through the exploit step by step.

On Thursday evening Garrity posted on LinkedIn that VulnCheck had started detecting exploitation. Hanley's team had reported the bug to VulnCheck for CVE assignment. VulnCheck's canaries, decoy systems set up to attract attackers, saw an actor in China targeting real vulnerable hosts in the US. Garrity told The Register that this activity came from a single China-hosted IP address and also hit servers in Japan. The fix ships in HFS v3.2.1 or later, which also closes other security flaws.

Friday's four hits came from two US addresses in the same subnet

On Friday the traffic came from somewhere else. Garrity said VulnCheck had seen four hits that day from 173.239.211[.]248 and 173.239.211[.]249. Both are US addresses in the same subnet, and they appear to be coming from a proxy. The Register notes that China-linked intruders routinely route traffic through compromised devices to hide their location. In April, an advisory from 10 countries warned that China-nexus operatives were using proxy networks “strategically, and at scale.”

Horizon3 joined Glasswing in July. Hanley wrote that since then, Mythos has helped the company discover “many critical vulnerabilities.” Across the whole program, Garrity's tracker counted 286 Mythos and Glasswing CVEs as of Friday, and until Thursday only one of them had been exploited in real-world attacks.

HFS signed its session cookies with a key from Math.random()

HFS generates a random value with Math.random() and passes it to Koa, the Node.js web framework that HFS is built on. Koa then uses the keygrip library to sign every session cookie with that value. As Hanley put it, an attacker who can derive the signing key can forge valid session cookies. That stays out of reach only if Math.random() is a secure generator, and V8's version, built on xorshift128+, is not.

Picture a deck shuffled by a fixed recipe. Watch enough cards come off the top and you can rebuild the whole order. Mythos found both halves of that problem: the generator's output was fully reversible, and a separate code path in HFS leaked raw Math.random() outputs. Hanley wrote that Mythos saw the two facts as a chain and worked out that the leak gave exactly the observations needed to recover the generator's state.

Mythos proposed the Z3 solver to recover the generator's seed

To get from the leak to the key, the model's analysis proposed Z3, a publicly available Satisfiability Modulo Theories (SMT) solver developed by Microsoft. You give an SMT solver a set of constraints, and it searches for values that satisfy all of them at once. Hanley wrote that the find shows Mythos's understanding of mathematics. Horizon3's researchers could not recall an SMT solver being used this way against a real application.

The math has a history. According to the Little Man In My Head blog, V8's Math.random() outputs only 52 of the 64 bits that xorshift128+ generates. The same blog describes an earlier Node.js ecosystem bug, CVE-2025-7783, which affected axios and the deprecated request library. An attacker with five consecutive outputs could predict future ones using z3. The author called it an edge case “extremely unlikely to be exploited.”

The Little Man In My Head author also argues that z3 is not the most efficient way in. Given at least two complete 64-bit outputs, xorshift128+ can be inverted in about 2^26 operations. Inverting the full Math.random() needs three outputs and currently takes about 2^50 operations.

The reporting leaves two things open. It does not say whether any of the probed HFS servers were actually compromised. And Z3-based Math.random() prediction appears to have a precedent in CVE-2025-7783, so Mythos's contribution reads less like new mathematics and more like noticing that a weak generator and a leak formed a chain. In our view, the one-day gap says more about the published exploit video than about Mythos. As The Register reported earlier, Garrity's data showed Glasswing bugs getting weaponized no more often than other vulnerabilities.

How far the Glasswing tally reaches

If you run HFS, v3.2.1 is the version to reach. Nobody has said how many exposed servers are still unpatched. Anthropic says it is expanding Glasswing to roughly 150 new organizations in more than 15 countries. It also expects many other AI companies to have Mythos-class models within 6 to 12 months, possibly released without misuse safeguards. Garrity's tracker, at 286 CVEs as of Friday, will show whether the second exploited bug stays rare.

Related stories

  1. Anthropic puts Zhipu's GLM-5.3 in the Mythos hacking class
  2. Anthropic's 225 bug finds, one attack in the wild
  3. One email check hides Claude's Android debug menu
  4. Anthropic's IPO filing warns its models may resist shutdown
  5. Cheating model tried to sabotage Anthropic's safety code
  6. OpenAI, Google and Anthropic draft a standards body, SAFA

Comments

No comments yet. Be the first.

Join the conversation

Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.

We only use your name and avatar from Google. We never store your email address.