Vulnerability Management, AI/ML, Application security, Threat Intelligence

AI model Mythos aids discovery of critical Rejetto HFS vulnerability

{“remix_data”:[],”remix_entry_point”:”challenges”,”source_tags”:[“local”],”origin”:”unknown”,”total_draw_time”:0,”total_draw_actions”:0,”layers_used”:0,”brushes_used”:0,”photos_added”:0,”total_editor_...

A critical authentication-bypass vulnerability in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, has been discovered and is now under active exploitation. Based on information from The Register, this flaw allows for full administrative access and remote code execution on vulnerable systems.

The vulnerability, initially exploited from an IP address in China targeting hosts in the US and Japan, was uncovered by researcher Zach Hanley of Horizon3. The flaw stems from an insecure pseudo-random number generator used by HFS, which, combined with a leak of the generator's output, allowed attackers to forge session cookies and gain administrative control. This discovery was facilitated by Anthropic's AI model, Mythos, which is part of its Project Glasswing initiative.

Mythos demonstrated a sophisticated ability to link mathematical concepts, cryptographic missteps, and code leaks to identify the exploit. The Rejetto HFS software has been updated to version 3.2.1 to address this and other security flaws. This incident highlights the growing capability of AI models in uncovering complex security vulnerabilities and the subsequent rapid exploitation by malicious actors, with initial attacks originating from China and later from US-based proxies.

Source: The Register

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds