Attackers exploit a Rejetto HFS bug Horizon3 found with Anthropic's Mythos

TL;DR

  • Attackers began exploiting CVE-2026-61500, a critical login bypass in Rejetto HTTP File Server, a day after Horizon3's Zach Hanley said on 30 September that he found it with Anthropic's Mythos model.
  • The Register reported on 3 October that it is the second Anthropic-linked bug known to be exploited in the wild, and that HFS 3.2.1 or later fixes it.
  • Mythos linked two facts: HFS signed its session cookies with a key from Math.random(), whose output Mythos found it could reverse, and a separate code path leaked that output.

Read the full story

Sign in with your email to read AI News. It’s free.

Share this story

Explain like I’m 15