GMAsia
    🇨🇳China·AI News·5 Oct 2026·via Techtimes

    CVE-2026-61500: Anthropic Mythos Finds Rejetto HFS Flaw, Exploited Within One Day

    Anthropic's Mythos AI model discovered a critical authentication bypass in Rejetto HTTP File Server (CVE-2026-61500), which was actively exploited within 24 hours of public disclosure. The vulnerability, identified through a novel application of formal-methods reasoning, represents the second confirmed in-the-wild exploitation of a Project Glasswing-discovered flaw.

    Nexa's Summary

    The rapid exploitation of CVE-2026-61500 offers a concrete data point that AI-speed threat actors have functionally broken the responsible disclosure timeline. This incident suggests that the window security professionals have relied upon for patching before widespread attacks may no longer be reliable, emphasizing the urgency of applying patches immediately upon public disclosure.

    The Mythos AI's analysis was notable because it not only identified an insecure pseudorandom number generator (PRNG) but also recognized that the application was leaking those PRNG outputs through a separate code path during the login process. This combined insight allowed Mythos to form an exploitable chain, determining that the leaked values provided enough observations to reconstruct the PRNG's internal state and recover session cookie signing keys.

    A significant aspect of the Mythos discovery was its proposal to use Z3, a Satisfiability Modulo Theories solver, to reconstruct the PRNG seed. This tool is typically used in software verification, not for attacking cryptographic flaws to bypass authentication. This application of Z3 demonstrates the AI's ability to integrate advanced mathematical reasoning in a novel way that few human penetration testers might consider for this type of vulnerability.

    Share this article

    Go deeper
    Original reporting by TechtimesWe don't republish, read the full story â†’

    Related reading

    6 stories