Research
Mythos cracks a Math.random() session key in Rejetto HFS; attackers exploited the flaw within a day
Horizon3 disclosed CVE-2026-61500, an authentication bypass in the Rejetto HTTP File Server 3.x line that lets anyone forge an admin session and run code, after Anthropic's Mythos model spotted that session signing keys came from Math.random() and found a second endpoint leaking raw PRNG output that made state recovery tractable with an SMT solver. The research ran inside Project Glasswing between July and September, and both China- and U.S.-based attackers were hitting unpatched servers within 24 hours of publication. Operators should upgrade to HFS 3.2.1. It is a concrete example of frontier models finding cryptographic bugs that scanners miss.