Flaw found by Mythos exploited a day after disclosure
Anthropic's Mythos found a critical flaw in the Rejetto HFS file server that lets attackers forge admin sessions. Attacks began within 24 hours of the write-up.
What happened
Anthropic's Mythos model found a critical authentication bypass in Rejetto HTTP File Server, tracked as CVE-2026-61500, that lets an attacker forge an admin login and run code on the server. Horizon3.ai published how it works on October 2, and exploitation began on October 3.
How it works
HFS derived the signing key for its session cookies from Math.random(), which is not designed for security. Mythos chained two benign-looking behaviors, weak random seeding and leaky login output: twelve unauthenticated login requests reveal enough output to rebuild V8's random-number state and forge a valid admin cookie.
The timeline
VulnCheck canary data shows a China-based IP hitting US and Japanese HFS servers within 24 hours, followed by four more hits from US proxies within 48 hours. Version 3.2.1 fixes the bug.
Why it is new
Chaining two independent code paths used to require sustained human cryptographic analysis; Mythos did it without follow-up prompting. That helps defenders find flaws first, but the window between patch and exploit is now measured in hours.
What Mythos is
Mythos is Anthropic's most capable vulnerability-hunting model, available only to defensive security researchers and organizations. Its findings go through responsible disclosure, so the HFS fix shipped before details were published; the danger lies in the gap before servers are updated.
What it means for your business
List every internet-facing tool you run, apply critical updates within days, shut down unused services, and subscribe to security advisories for the software you depend on.
The patch race
The gap between disclosure and exploitation has been shrinking for years, and AI narrows it further: attackers can feed a technical write-up to a model and get working exploit code within hours. Security teams now aim to patch critical flaws within days, not monthly cycles.
Who is exposed
HFS is popular with small businesses and individuals as an easy file-sharing tool, often installed once and never updated, exactly the kind of system attackers scan for.
