Attackers exploit a Rejetto HFS bug Horizon3 found with Anthropic's Mythos
TL;DR
- Attackers began exploiting CVE-2026-61500, a critical login bypass in Rejetto HTTP File Server, a day after Horizon3's Zach Hanley said on 30 September that he found it with Anthropic's Mythos model.
- The Register reported on 3 October that it is the second Anthropic-linked bug known to be exploited in the wild, and that HFS 3.2.1 or later fixes it.
- Mythos linked two facts: HFS signed its session cookies with a key from Math.random(), whose output Mythos found it could reverse, and a separate code path leaked that output.
Read the full story
Sign in with your email to read AI News. It’s free.