Skip to content

ai-security

A Mythos-found HFS bug was exploited a day after disclosure

Promtime

On Wednesday, Zach Hanley of Horizon3 published a video walking through an exploit for a new Rejetto HFS bug. By Thursday evening, according to The Register, VulnCheck's canaries had caught an actor in China using it against real servers. Hanley found the flaw with Anthropic's Mythos, which linked a predictable random number generator to a separate leak of that generator's raw output.

At a glance

  • CVE-2026-61500 is a critical authentication bypass in the open source Rejetto HFS file server that leads to full admin access and remote code execution; versions 3.2.1 and later fix it.
  • HFS signed session cookies with a key from V8's Math.random(), whose xorshift128+ output can be reversed, and leaked raw outputs elsewhere, so Mythos proposed recovering the seed with the Z3 solver.
  • Garrity's tracker counted 286 Mythos and Project Glasswing CVEs as of Friday; before Thursday only one had been exploited in the wild, and this one took a day.

If you have not been following, Project Glasswing is Anthropic's initiative, announced in April, that gives select partners access to Mythos. Anthropic says the model is too powerful to release to the general public. In Anthropic's own words, Claude Mythos Preview can "surpass all but the most skilled humans at finding and exploiting software vulnerabilities." VulnCheck's Patrick Garrity has tracked CVEs attributed to the program since shortly after the announcement.

CVE-2026-61500 was under attack the day after Horizon3 disclosed it

On Wednesday, Hanley said he had used Mythos to uncover the flaw, and he published a video showing how to exploit HFS and run code remotely on the server. Hanley and his team reported the bug to VulnCheck, which assigned the CVE. Garrity posted on LinkedIn on Thursday:

We started detecting exploitation of CVE-2026-61500 in Rejetto HFS this evening.
Our canaries detected an actor in China targeting real vulnerable hosts in the US.

Attackers have hit HFS before. It appeared in CISA's Known Exploited Vulnerabilities catalog in 2024. According to NIST, that earlier entry, CVE-2024-23692, was a template injection in HFS up to and including 2.3m that allowed remote, unauthenticated arbitrary command execution.

Thursday's traffic came from China, Friday's from two US addresses in one subnet

Garrity told The Register that the Thursday night activity came from a single IP address in China and targeted vulnerable servers in the US and Japan. On Friday he counted four hits from two US addresses, 173.239.211[.]248 and 173.239.211[.]249. Both sit in the same subnet and, he said, appear to be coming from a proxy.

China-linked intruders routinely send their traffic through compromised devices to hide where they really are. In April, a 10-country security advisory warned that China-nexus operatives were using proxy networks "strategically, and at scale."

Before this week, Garrity's tracker showed only one of the 286 Mythos and Project Glasswing CVEs being exploited in real-world attacks. The HFS bug is the second.

The session key came from Math.random(), and HFS leaked its output

HFS generates a random value with Math.random() and passes it to Koa, the Node.js web framework HFS is built on. Koa uses keygrip to sign every session cookie with that value. Hanley wrote that an attacker who can work out the signing key can forge valid session cookies. That stays impossible only if Math.random() is a secure pseudo random number generator.

V8's Math.random() was not secure. Its xorshift128+ algorithm produces fully reversible output: watch enough values and you can rebuild the internal state that produced them. Picture a shuffled deck where a few cards seen in a row tell you the order of every card left. Mythos also found the other half of the chain, a separate code path that leaked raw Math.random() outputs.

Mythos then proposed Z3, Microsoft's publicly available Satisfiability Modulo Theories (SMT) solver, as a way to recover the seed. An SMT solver takes a set of constraints and searches for values that satisfy all of them at once. Horizon3's researchers could not recall seeing an SMT solver used this way to attack a cryptographic flaw in a real application and bypass authentication.

Hanley credits the find to Mythos's grasp of mathematics

Hanley wrote that Mythos excels at mathematical distillations and scientific tasks, especially in computer science and operating systems. In his view, this CVE shows how the model understood the mathematics, spotted an exploitable set of cryptographic missteps and solved the constraints to reach remote code execution. Horizon3 has found "many critical vulnerabilities" with Mythos since joining Project Glasswing in July, he said.

What makes this impressive is that Mythos didn't just flag the insecure PRNG in isolation – it simultaneously identified that the application leaked raw Math.random() outputs through a separate code path, recognized those two facts as a chain, and determined the leak produced exactly the observations needed to make state recovery feasible.

In April, Anthropic said Mythos Preview had already found thousands of high-severity vulnerabilities. According to Futurum, it scored 83% on the CyberGym benchmark, compared with 67% for Claude Opus 4.6.

The reports leave real gaps. They don't say how many HFS servers were exposed, which earlier versions are affected, or whether the attackers got past probing. Friday's hits likely came through a proxy, so the addresses say little about who sent them. In our view, the more telling detail is the root cause: deriving a session-signing key from Math.random() is a weakness of the kind ordinary review should catch, and in HFS it lasted until a frontier model went looking.

Patching HFS before the next scan

If you run Rejetto HFS, update to v3.2.1 or later, which fixes this flaw and several others. Garrity's tracker will show whether more of the 286 Glasswing CVEs come under attack. No figures have been given for how many HFS servers are still exposed. Anthropic expects these capabilities to advance substantially over the next few months, and Futurum's analysts estimate that wider access to them will arrive in "months, not years."

Related stories

  1. Anthropic's IPO filing warns its models may resist shutdown
  2. Cheating on code tests made Anthropic's model sabotage
  3. OpenAI and Anthropic probe tens of thousands of AI misfires
  4. Blocked Claude requests cost money again, in three areas
  5. One of 225 Anthropic-linked CVEs actually got used
  6. Researchers used Claude to reach OpenAI's internal code

Comments

No comments yet. Be the first.

Join the conversation

Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.

We only use your name and avatar from Google. We never store your email address.