Eigen RadarAI
Analysis

Attack attempts reported after disclosure of Mythos-linked HFS flaw

VulnCheck has reported attack attempts after disclosure of a Rejetto HTTP File Server flaw investigated by Horizon3 researcher Zach Hanley with Mythos. The activity targeted vulnerable servers in the US and Japan. CVE-2026-61500 can enable authentication bypass and remote code execution through recovered session-signing material. HFS 3.2.1 and later fix the issue; the observations do not establish that every target was compromised.

Artificial Intelligence··Evening
A man in a green polo, seen from behind, works at a keyboard beside a small server connected by network cables.

Attempts observed after the HFS disclosure

Attack activity has been reported following disclosure of a Rejetto HTTP File Server vulnerability investigated with Anthropic's Mythos model. The flaw concerns the server's authentication mechanism. The activity involves attempts against vulnerable systems. Successful compromise of every target has not been established. Mythos was used in the investigation of the flaw; it has not been identified as carrying out these attacks.[1], [2]

Horizon3 researcher Zach Hanley disclosed CVE-2026-61500 on Wednesday and published a demonstration video. VulnCheck researcher Patrick Garrity reported attempts on Thursday evening. He told The Register that the initial activity originated from a China-hosted IP address and targeted vulnerable servers in the US and Japan. Four further hits on Friday came from two US IP addresses in the same subnet. Garrity said these appeared to be proxies. The country hosting an address does not establish where an attacker is located or identify a state sponsor. A count of successfully compromised servers has not been established.[1]

Session-signing material can be recovered

HFS is an open-source web file server. The vulnerability can allow authentication bypass, full administrator access and remote code execution. The application generates a value using Math.random(), then passes it through the Koa framework so keygrip can sign session cookies. The research connects an insecure pseudorandom-number generator with a separate code path that exposes outputs from the same generator. Recovering its state can reveal signing material and permit forged cookies that appear valid. Hanley says Mythos identified the possibility of using the Z3 constraint solver to recover that state. His assessment concerns this investigation, rather than a comparison across all AI models.[1]

HFS 3.2.1 and later include the fix

HFS version 3.2.1 and later fix this vulnerability and other security issues. Horizon3 has used Mythos for research since joining Project Glasswing in July. Garrity's tracker contained 286 CVEs associated with Mythos and Glasswing as of Friday. Before the newly reported HFS activity, only one of those vulnerabilities was known to have been exploited in real attacks; the observations add a second. Garrity tracks flaws associated with the model and program. Hanley's praise for Mythos's mathematical abilities remains the researcher's assessment, with no independent performance comparison covering all security tasks.[1]

References

  1. News sourceThe RegisterAttack observations follow disclosure of a Mythos-linked HFS flaw↩1↩2↩3↩4
  2. News sourceDiarioBitcoinMythos detectó una falla en Rejetto HFS que comenzó a ser explotada↩