← Back to the feed

Anthropic’s super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows

The Register ·

Anthropic’s Mythos model helped identify a critical authentication flaw in Rejetto HTTP File Server (HFS), and attackers began exploiting it within a day of its public disclosure. The activity makes the vulnerability the second Mythos-linked flaw known to have been used in real-world attacks, raising the stakes for organisations running vulnerable servers.

Tracked as CVE-2026-61500, the flaw could let an attacker forge session cookies, gain administrator access and execute code remotely. Researcher Zach Hanley said Mythos helped analyse weaknesses in the server’s use of JavaScript’s Math.random() and reversible random-number outputs; HFS users should update to version 3.2.1 or later. VulnCheck reported initial attempts from one China-hosted IP targeting vulnerable systems in the US and Japan, followed by four hits from two US IP addresses that appeared to be using a proxy. Its tracker listed 286 CVEs uncovered by Mythos and Project Glasswing as of Friday.

  • Attackers began exploiting a critical HFS flaw within a day of disclosure.
  • Mythos helped researchers uncover the authentication-bypass vulnerability.
  • Update Rejetto HFS to version 3.2.1 or later.

New here? Start with this

Anthropic's Mythos is an AI model designed to identify security weaknesses in software before attackers can find them. It works by analysing code to spot flaws that could allow attackers to break in, and has proven particularly effective at finding bugs in areas like cryptography and authentication systems.

Rejetto HTTP File Server is a popular tool used to share files over networks and the internet. A critical vulnerability was recently discovered in the software, partly with Mythos's help, that could allow attackers to forge access credentials and gain full administrative control of vulnerable servers.

When security flaws are publicly disclosed, there is often a race between defenders patching the vulnerability and attackers exploiting it. In this case, attackers began attempting to exploit the flaw within a day of its public release, demonstrating why swift disclosure and rapid patching are crucial for organisations running affected systems.

AI Asia Technology World

Read the full article at the source →