Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Rejetto HFS Vulnerability Exploited, AI Identifies Flaw

Rejetto HFS Vulnerability Exploited, AI Identifies Flaw

Posted on October 5, 2026 By CWS

Cybersecurity researchers have uncovered a severe vulnerability in the Rejetto HTTP File Server (HFS) that is being actively exploited by threat actors. The flaw, identified as CVE-2026-61500 with a CVSS score of 9.3, allows attackers to bypass authentication mechanisms and execute remote code on susceptible systems, as reported by VulnCheck.

Details of the Rejetto HFS Vulnerability

The vulnerability arises from the server’s non-cryptographic session cookie generator, which leaks crucial outputs to unauthenticated users during the login process. This flaw enables malicious actors to reverse-engineer the session-cookie signing key by analyzing a small number of login responses.

Once the signing key is compromised, attackers can create legitimate-looking administrator session cookies, gaining unauthorized access and executing arbitrary code through the server’s configuration features. This significant security issue is rooted in Rejetto HFS’s use of the xorshift128+ algorithm for generating ‘random’ values, which are then utilized by the Koa web framework in Node.js to sign session cookies.

AI’s Role in Identifying the Flaw

The weakness was detected by researchers at Horizon3.ai through the use of Anthropic’s Mythos AI model. The AI’s advanced mathematical reasoning capabilities identified that the outputs from the Math.random() pseudo-random number generator (PRNG) could be reversed, enabling the reconstruction of the secret session-cookie signing key.

This discovery was made in June, leading to the release of Rejetto HFS version 3.2.1 on July 13, which addressed the vulnerability. Rejetto’s advisory warned of multiple security weaknesses in all previous versions, potentially allowing administrative access to attackers.

Current Exploitation and Security Measures

On October 2, VulnCheck alerted the cybersecurity community that hackers have begun exploiting CVE-2026-61500. These attacks have been traced back to reconnaissance activities originating from a China Telecom IP, specifically targeting canaries in Japan and the United States.

With the vulnerability being actively exploited, organizations using Rejetto HFS are urged to update to the latest patched version immediately to mitigate potential risks. Continuous monitoring and implementing robust security practices are essential to protect against such vulnerabilities.

The exploitation of Rejetto HFS highlights the ongoing challenges in cybersecurity, emphasizing the critical role of AI in identifying and addressing complex security flaws.

Security Week News Tags:AI discovery, CVE-2026-61500, Cybersecurity, Horizon3, Math.random(), Mythos AI, RCE, Rejetto HFS, session cookies, Vulnerability

Post navigation

Previous Post: Apple Tightens macOS Disk Access to Protect Against AI Risks
Next Post: Phishing Scams Exploit ScreenConnect for Remote Access

Related Posts

Linux Foundation to Oversee AI Attestation Standard TRACE Linux Foundation to Oversee AI Attestation Standard TRACE Security Week News
Google Gemini Tricked Into Showing Phishing Message Hidden in Email  Google Gemini Tricked Into Showing Phishing Message Hidden in Email  Security Week News
UNC6692 Deploys Snow Malware via Email Scams and Social Tactics UNC6692 Deploys Snow Malware via Email Scams and Social Tactics Security Week News
CISA Adds Exploited XWiki, VMware Flaws to KEV Catalog CISA Adds Exploited XWiki, VMware Flaws to KEV Catalog Security Week News
Google and FBI Halt Major Proxy Network Using Millions of Devices Google and FBI Halt Major Proxy Network Using Millions of Devices Security Week News
Open VSX Publisher Account Hijacked in Fresh GlassWorm Attack Open VSX Publisher Account Hijacked in Fresh GlassWorm Attack Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Windows 11 Update Causes App Crashes Due to Audio Bug
  • Healthcare Firms in NJ and TX Suffer Major Data Breaches
  • Phishing Scams Exploit ScreenConnect for Remote Access
  • Rejetto HFS Vulnerability Exploited, AI Identifies Flaw
  • Apple Tightens macOS Disk Access to Protect Against AI Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Windows 11 Update Causes App Crashes Due to Audio Bug
  • Healthcare Firms in NJ and TX Suffer Major Data Breaches
  • Phishing Scams Exploit ScreenConnect for Remote Access
  • Rejetto HFS Vulnerability Exploited, AI Identifies Flaw
  • Apple Tightens macOS Disk Access to Protect Against AI Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark