Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Rejetto HFS Flaw Detected by Mythos AI

Critical Rejetto HFS Flaw Detected by Mythos AI

Posted on October 7, 2026 By CWS

Anthropic’s Mythos AI has discovered a significant security flaw in Rejetto HTTP File Server (HFS), enhancing the risk of unauthorized administrative access and arbitrary code execution by remote attackers. This vulnerability, cataloged as CVE-2026-61500, arises from the use of predictable session-signing keys, generated via JavaScript’s Math.random() function, which is not cryptographically secure.

Background of the Vulnerability

The detection was made by Horizon3 after joining Anthropic’s Project Glasswing in July 2026. This initiative leverages the Mythos Preview model, alongside industry partners, to identify and rectify critical software vulnerabilities. Mythos AI is renowned for autonomously discovering high-severity flaws and crafting sophisticated exploitation pathways.

Rejetto’s HFS, an open-source tool for file hosting and sharing, has faced security challenges before, such as the CVE-2024-23692 vulnerability that allowed remote code execution. The latest flaw impacts the TypeScript-based HFS 3.x series, which utilizes the Koa Node.js framework for session management.

Technical Details and Exploit

When HFS’s COOKIE_SIGN_KEYS configuration remains unset, a signing key is produced via randomId(30), depending on Math.random(). However, Node.js’s V8 engine implements Math.random() with the xorshift128+ pseudo-random-number generator, which is not designed for cryptographic security. Attackers can reconstruct its internal state if they capture enough consecutive output values.

Mythos AI identified that HFS leaked these outputs during its authentication process. The loginSrp1 endpoint generates a session ID with Math.random(), storing it in a client-side session cookie. Since the cookie is signed yet unencrypted, attackers can decode their cookies and retrieve high-precision random values from the V8 pseudo-random stream.

Implications and Recommendations

By exploiting this weakness, attackers can repeatedly trigger the login process to recover the xorshift128+ internal state using a solver like Z3. They can reverse-engineer the state to retrieve the session-signing key created during server startup. This key enables attackers to produce a valid session cookie impersonating the HFS administrator, bypassing IP restrictions and executing arbitrary code.

Horizon3 noted that Mythos not only detected the weak pseudo-random number generator usage but also linked it to the exposed random values, devised a recovery strategy, generated a Z3-based proof of concept, and demonstrated code execution capabilities. This finding underscores a broader concern: AI-driven vulnerability research could simplify the exploitation of complex flaws, making them more accessible to malicious actors.

To mitigate this risk, HFS administrators should upgrade to a vendor-fixed release upon availability, configure robust COOKIE_SIGN_KEYS, avoid Math.random() for security-critical tasks, restrict public access to administrative functions, and monitor logs for unusual activity.

Cyber Security News Tags:administrative access, AI research, attack prevention, code execution, CVE-2026-61500, Cybersecurity, Exploit, Horizon3, Mythos AI, Node.js, Project Glasswing, Rejetto HFS, Security, session forging, Vulnerability

Post navigation

Previous Post: ASOS Hit by Cyberattack Compromising User Data
Next Post: FBI Alerts on Persistent FortiBleed Threat to Fortinet Devices

Related Posts

KFC Venezuela Alleged Data Breach KFC Venezuela Alleged Data Breach Cyber Security News
Europol‑Backed Operation Leads to 34 Arrests in Black Axe Crime Network Bust Europol‑Backed Operation Leads to 34 Arrests in Black Axe Crime Network Bust Cyber Security News
Hackers Leverages Google Calendar APIs With Serverless MeetC2 Communication Framework Hackers Leverages Google Calendar APIs With Serverless MeetC2 Communication Framework Cyber Security News
Hackers Use Fake Websites for Chrome and Windows Exploits Hackers Use Fake Websites for Chrome and Windows Exploits Cyber Security News
Anthropic Alleges Alibaba’s Unauthorized Access to AI Models Anthropic Alleges Alibaba’s Unauthorized Access to AI Models Cyber Security News
Search Engines are Indexing ChatGPT Conversations! Search Engines are Indexing ChatGPT Conversations! Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Rockstar Faces Data Breaches: Source Code and Records Stolen
  • Hadrian Secures $40M to Boost AI Security Platform
  • FBI Alerts on Persistent FortiBleed Threat to Fortinet Devices
  • Critical Rejetto HFS Flaw Detected by Mythos AI
  • ASOS Hit by Cyberattack Compromising User Data

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Rockstar Faces Data Breaches: Source Code and Records Stolen
  • Hadrian Secures $40M to Boost AI Security Platform
  • FBI Alerts on Persistent FortiBleed Threat to Fortinet Devices
  • Critical Rejetto HFS Flaw Detected by Mythos AI
  • ASOS Hit by Cyberattack Compromising User Data

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark