Attempts observed after the HFS disclosure
Attack activity has been reported following disclosure of a Rejetto HTTP File Server vulnerability investigated with Anthropic's Mythos model. The flaw concerns the server's authentication mechanism. The activity involves attempts against vulnerable systems. Successful compromise of every target has not been established. Mythos was used in the investigation of the flaw; it has not been identified as carrying out these attacks.[1], [2]
Horizon3 researcher Zach Hanley disclosed CVE-2026-61500 on Wednesday and published a demonstration video. VulnCheck researcher Patrick Garrity reported attempts on Thursday evening. He told The Register that the initial activity originated from a China-hosted IP address and targeted vulnerable servers in the US and Japan. Four further hits on Friday came from two US IP addresses in the same subnet. Garrity said these appeared to be proxies. The country hosting an address does not establish where an attacker is located or identify a state sponsor. A count of successfully compromised servers has not been established.[1]
