A Bug Claude Mythos Found Was Exploited Within a Day
Horizon3 used Anthropic’s Claude Mythos to find a critical flaw in the Rejetto HFS file server: its login cookies were signed with a key from Math.random(), which Mythos showed could be rebuilt from twelve logins. Attackers were using the bug the day after the write-up. Users should update to HFS 3.2.1.
A critical vulnerability found with Anthropic’s Claude Mythos was being exploited in the wild the day after it was made public. The bug, CVE-2026-61500, is in Rejetto HFS, a popular free HTTP file server, and lets an unauthenticated attacker forge an administrator login and then run code on the host. Horizon3.ai researcher Zach Hanley published the details on 30 September. By the next evening, VulnCheck’s canary servers had recorded an attacker on a China-hosted IP address going after vulnerable machines in the US and Japan, The Register reports.
The fix is already out. HFS versions 3.0.0 through 3.2.0 are affected, the vulnerability record shows, and version 3.2.1 closes the hole along with other security flaws. The CVE record itself dates from July, so the patch was available well before Horizon3 explained how the attack works; the servers hit last week were ones that had not been updated. Anyone running the 3.x server on an internet-facing machine should update now.
Twelve logins to an admin cookie
The flaw is a textbook mistake with an unusually elegant exploit. HFS signs its session cookies with a key generated by JavaScript’s Math.random(). In V8, the engine behind Node.js, that function runs on an algorithm called xorshift128+, which is fast but not built for secrets: anyone who sees a handful of its outputs can work out its internal state and then calculate every number it has produced or will produce. On its own, that is a theoretical weakness. What made it exploitable is that HFS also handed raw outputs of the same generator to unauthenticated users during login.
Horizon3’s exploit chains the two. It enumerates the admin username through an unauthenticated endpoint, starts a dozen logins to collect leaked random values, and feeds them to Microsoft’s Z3 constraint solver to recover the generator’s state. From there it steps the generator backwards to the value it produced when the server started, which is the cookie-signing key. With the key, the attacker signs a valid administrator cookie and uses HFS’s own server-code setting to execute code. Horizon3 says three to five consecutive outputs are enough for the solver.
What Mythos actually did
Horizon3 runs a vulnerability research system of specialised agents working in parallel, and the finding came from a cryptographic-analysis agent driven by Mythos. The company says the humans supplied the harness and the initial direction, and that Mythos found the chain without follow-up prompting. The part Hanley singles out is the connection. Mythos, he wrote, “didn’t just flag the insecure PRNG in isolation”: it noticed the separate leak, saw that the two facts formed a chain, and worked out that the leak gave exactly the observations needed to rebuild the state. Horizon3’s researchers add that turning an SMT solver on a real-world crypto weakness is not something they would normally have prioritised.
That is a different kind of result from the bulk numbers usually attached to Mythos. Anthropic’s Project Glasswing has put the model to work across open source, and The Register counts 286 CVEs credited to Mythos and Glasswing so far. This one required reasoning across two code paths and a piece of number theory, which is closer to what a skilled human cryptanalyst does.
The day-one problem
The less comfortable lesson is the speed. This is only the second Anthropic-linked vulnerability known to have been exploited in the wild, but the window between a public write-up and real attacks was about a day, and the write-up itself was detailed enough to rebuild the exploit. VulnCheck saw four more attempts on Friday, from US proxy addresses. As AI models find more bugs and describe them more clearly, the time defenders have to patch is shrinking at the same moment the volume of disclosures is rising. Anthropic itself warned on 1 October that open models are close behind Mythos at writing exploits, so a bug like this one may soon not need a restricted model to find. For HFS users, the response is simple: run 3.2.1 or later, and do not leave the admin interface reachable from the internet.
More on Claude
Evergreen coverage we keep current — start here.
Want AI news before everyone else?
The morning's most important AI stories, straight to your inbox. No fluff.