
The second Anthropic-linked vulnerability known to have been exploited in the wild saw initial activity from an IP address in China targeting vulnerable hosts in the US and Japan. The vuln is a critical authentication-bypass bug in Rejetto HTTP File Server (HFS) that can lead to full admin access and remote code execution. HFS is an open source web file server that previously appeared on the US Cybersecurity and Infrastructure Security Agency's catalog of Known Exploited Vulnerabilities in 2024. On Wednesday, researcher Zach Hanley at AI pen-testing company Horizon3 said he used Mythos to uncover a new flaw in the file server, now tracked as CVE-2026-61500. If you use Rejetto HFS, be sure to update to v3.2.1 or later, which fixes this and other security flaws. Hanley also published a video showing the steps to exploit HFS and remotely execute code on the server. By the next day, the CVE was under exploitation. We started detecting exploitation of CVE-2026-61500 in Rejetto HFS this evening," VulnCheck security researcher Patrick Garrity posted on LinkedIn on Thursday, adding that Hanley and team reported the bug to VulnCheck for CVE assignment. Our canaries detected an actor in China targeting real vulnerable hosts in the US," Garrity added. Garrity has been tracking CVEs attributed to Mythos and Project Glasswing, Anthropic's initiative to give select partners access to the bug-hunting model, since shortly after the program was announced in April. Anthropic claims that Mythos is too powerful to release to the general public (insert evil laugh). As of Friday, Mythos and Project Glasswing have uncovered 286 CVEs, according to Garrity's tracker, and up until Thursday only one of these bugs had been exploited in real-world attacks. The Thursday night activity originated from one IP address in China and targeted vulnerable servers in the US and Japan, Garrity told The Register. Today we have seen four hits," he told us on Friday. These originated from two different IP addresses in the US: 173.239.211[.]248 and 173.239.211[.]249. Both are in the same subnet, and appear to be coming from a proxy," Garrity added. China-linked digital intruders routinely use compromised devices as proxies to route malicious traffic and disguise the attackers' true location, and in April a 10-country security advisory warned of China-nexus cyber operatives using proxy networks strategically, and at scale." In his write-up, Hanley said Horizon3 has used Mythos in its vulnerability research - and discovered many critical vulnerabilities" - ever since the security company joined Project Glasswing in July. Mythos' mad math skillz CVE-2026-61500 highlights a couple of Mythos capabilities that make it really good at uncovering vulnerabilities, according to Hanley. Namely, Mythos excels at mathematical distillations and scientific tasks, especially those relating to computer science and operating systems. Finding this CVE speaks to Mythos's capabilities in understanding of mathematics, how it identified an exploitable set of cryptographic missteps, and approached solving the constraints to achieve remote code execution," Hanley wrote. The security issue stems from how HFS authenticates users. It generates a random value with Math.random() and then passes this value to Koa, the Node.js web framework foundation for HFS. Koa uses keygrip to sign all session cookies with that random value. This means that if an attacker can derive what the session signing key is, they can forge valid session cookies," Hanley said. This should not be possible, assuming Math.random() uses a secure pseudo random number generator (PRNG). But V8's Math.random() did not use a secure PRNG. Mythos discovered that the output of the xorshift128+ algorithm it used was fully reversible - and the application was leaking Math.random() outputs. The model's analysis claimed that Z3, a Microsoft-developed, publicly available Satisfiability Modulo Theories (SMT) solver, could be used to recover the PRNG seed. Hanley notes that Horizon3's researchers could not recall seeing an SMT solver used this way to attack a cryptographic flaw in a real application and bypass authentication. What makes this impressive is that Mythos didn't just flag the insecure PRNG in isolation - it simultaneously identified that the application leaked raw Math.random() outputs through a separate code path, recognized those two facts as a chain, and determined the leak produced exactly the observations needed to make state recovery feasible," he wrote.(R)