# Flaw found by Mythos exploited a day after disclosure | QANATONE

> Anthropic's Mythos found a critical flaw in the Rejetto HFS file server that lets attackers forge admin sessions. Attacks began within 24…

Kaynak: https://www.qanatone.com/en/haber/mythos-rejetto-acigi-istismar/

---

[News](https://www.qanatone.com/en/haber/)

# Flaw found by Mythos exploited a day after disclosure

3 Oct 2026 3 min read News · Models

Anthropic's Mythos found a critical flaw in the Rejetto HFS file server that lets attackers forge admin sessions. Attacks began within 24 hours of the write-up.

## What happened

Anthropic's Mythos model found a critical authentication bypass in Rejetto HTTP File Server, tracked as CVE-2026-61500, that lets an attacker forge an admin login and run code on the server. Horizon3.ai published how it works on October 2, and exploitation began on October 3.

## How it works

HFS derived the signing key for its session cookies from Math.random(), which is not designed for security. Mythos chained two benign-looking behaviors, weak random seeding and leaky login output: twelve unauthenticated login requests reveal enough output to rebuild V8's random-number state and forge a valid admin cookie.

**24 hours** from public write-up to the first attack

## The timeline

VulnCheck canary data shows a China-based IP hitting US and Japanese HFS servers within 24 hours, followed by four more hits from US proxies within 48 hours. Version 3.2.1 fixes the bug.

## Why it is new

Chaining two independent code paths used to require sustained human cryptographic analysis; Mythos did it without follow-up prompting. That helps defenders find flaws first, but the window between patch and exploit is now measured in hours.

## What Mythos is

Mythos is Anthropic's most capable vulnerability-hunting model, available only to defensive security researchers and organizations. Its findings go through responsible disclosure, so the HFS fix shipped before details were published; the danger lies in the gap before servers are updated.

## What it means for your business

List every internet-facing tool you run, apply critical updates within days, shut down unused services, and subscribe to security advisories for the software you depend on.

## The patch race

The gap between disclosure and exploitation has been shrinking for years, and AI narrows it further: attackers can feed a technical write-up to a model and get working exploit code within hours. Security teams now aim to patch critical flaws within days, not monthly cycles.

## Who is exposed

HFS is popular with small businesses and individuals as an easy file-sharing tool, often installed once and never updated, exactly the kind of system attackers scan for.

## More articles

[News · Infrastructure ### Apple tightens macOS Full Disk Access over AI agent risks 2 Oct 2026 · 3 min](https://www.qanatone.com/en/haber/apple-tam-disk-erisimi-ajanlar/)[News · Science ### Meta's Muse Spark co-authors six mathematics papers 2 Oct 2026 · 3 min](https://www.qanatone.com/en/haber/meta-muse-spark-matematik-makaleleri/)[News · Search ### Judge throws out two antitrust suits over Google AI Overviews 1 Oct 2026 · 3 min](https://www.qanatone.com/en/haber/ai-overviews-davalari-reddedildi/)[Data · Performance ### We tested award-winning agency sites: most fail on mobile 1 Oct 2026 · 4 min](https://www.qanatone.com/en/haber/ajans-sitelerinde-gozden-kacan-hiz/)[News · Policy ### Fund probe arrests reach 58 as regulator opens refund accounts 1 Oct 2026 · 1 min](https://www.qanatone.com/en/haber/fon-sorusturmasi-iade-hesabi-tutuklama/)[News · Policy ### California subpoenas OpenAI over agents that escaped testing 1 Oct 2026 · 3 min](https://www.qanatone.com/en/haber/kaliforniya-openai-celp/)[News · Models ### Tavus's Griffin passed as human in 48% of video calls 1 Oct 2026 · 3 min](https://www.qanatone.com/en/haber/tavus-griffin-video-turing-testi/)[News · Models ### Anthropic measures open model GLM-5.3's cyber offence skills 30 Sep 2026 · 1 min](https://www.qanatone.com/en/haber/anthropic-glm-5-3-siber-yetenek/)
