Skip to content

(Menu)

News

Flaw found by Mythos exploited a day after disclosure

3 min read News · Models

Anthropic's Mythos found a critical flaw in the Rejetto HFS file server that lets attackers forge admin sessions. Attacks began within 24 hours of the write-up.

What happened

Anthropic's Mythos model found a critical authentication bypass in Rejetto HTTP File Server, tracked as CVE-2026-61500, that lets an attacker forge an admin login and run code on the server. Horizon3.ai published how it works on October 2, and exploitation began on October 3.

How it works

HFS derived the signing key for its session cookies from Math.random(), which is not designed for security. Mythos chained two benign-looking behaviors, weak random seeding and leaky login output: twelve unauthenticated login requests reveal enough output to rebuild V8's random-number state and forge a valid admin cookie.

24 hoursfrom public write-up to the first attack

The timeline

VulnCheck canary data shows a China-based IP hitting US and Japanese HFS servers within 24 hours, followed by four more hits from US proxies within 48 hours. Version 3.2.1 fixes the bug.

Why it is new

Chaining two independent code paths used to require sustained human cryptographic analysis; Mythos did it without follow-up prompting. That helps defenders find flaws first, but the window between patch and exploit is now measured in hours.

What Mythos is

Mythos is Anthropic's most capable vulnerability-hunting model, available only to defensive security researchers and organizations. Its findings go through responsible disclosure, so the HFS fix shipped before details were published; the danger lies in the gap before servers are updated.

What it means for your business

List every internet-facing tool you run, apply critical updates within days, shut down unused services, and subscribe to security advisories for the software you depend on.

The patch race

The gap between disclosure and exploitation has been shrinking for years, and AI narrows it further: attackers can feed a technical write-up to a model and get working exploit code within hours. Security teams now aim to patch critical flaws within days, not monthly cycles.

Who is exposed

HFS is popular with small businesses and individuals as an easy file-sharing tool, often installed once and never updated, exactly the kind of system attackers scan for.