<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/anthropic-s-super-bug-hunting-model-mythos-is-hardcore-good-at-math-as-latest-vuln-under-attack-sho-huh55ikq3" -->

---
title: Anthropic&#x27;s super bug-hunting model Mythos is hardcore...
description: A critical authentication-bypass vulnerability in Rejetto HTTP File Server (CVE-2026-61500), discovered by Horizon3 researchers using Anthropic&#x27;s Mythos AI...
canonical: https://daily.dev/posts/anthropic-s-super-bug-hunting-model-mythos-is-hardcore-good-at-math-as-latest-vuln-under-attack-sho-huh55ikq3
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Anthropic&#x27;s super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows | daily.dev
og:description: A critical authentication-bypass vulnerability in Rejetto HTTP File Server (CVE-2026-61500), discovered by Horizon3 researchers using Anthropic&#x27;s Mythos AI...
og:url: https://daily.dev/posts/anthropic-s-super-bug-hunting-model-mythos-is-hardcore-good-at-math-as-latest-vuln-under-attack-sho-huh55ikq3
og:image: https://api.daily.dev/og/posts/HUH55IKQ3.png
og:image:alt: Anthropic&#x27;s super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows

**[The Register](https://daily.dev/sources/theregister)** · 4 min read · 0 upvotes · 0 comments

## Summary

A critical authentication-bypass vulnerability in Rejetto HTTP File Server (CVE-2026-61500), discovered by Horizon3 researchers using Anthropic's Mythos AI model, is now being actively exploited in the wild, with initial attacks traced to a China-hosted IP targeting US and Japan servers. Mythos identified that HFS's session signing relied on an insecure Math.random() output in V8, and chained this with a separate leak of raw Math.random() values to recover the PRNG seed using Microsoft's Z3 SMT solver, enabling forged session cookies and remote code execution. Users are urged to update HFS to v3.2.1 or later. This marks the second known case of a Mythos/Project Glasswing-discovered CVE being exploited in the wild out of 286 uncovered so far.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.theregister.com/security/2026/10/03/anthropics-super-bug-hunting-model-mythos-is-hardcore-good-at-math-as-latest-vuln-under-attack-shows/5300933>

## Questions this post answers

### What is CVE-2026-61500 and how does it affect Rejetto HFS?

CVE-2026-61500 is a critical authentication-bypass vulnerability in Rejetto HTTP File Server that allows full admin access and remote code execution. It exploits HFS's use of Math.random() to generate a session-signing value passed to Koa's keygrip, combined with V8's insecure xorshift128+ PRNG and a separate leak of raw Math.random() outputs, letting attackers recover the PRNG seed with the Z3 SMT solver and forge valid session cookies. Update to HFS v3.2.1 or later to fix it.

_Teams running exposed file servers can track emerging CVEs like this one on daily.dev before attackers strike._

### Has the Rejetto HFS vulnerability found by Anthropic's Mythos model been exploited in the wild?

Yes, exploitation of CVE-2026-61500 began the day after disclosure, with initial activity detected from an IP address in China targeting vulnerable hosts in the US and Japan. A day later, four more hits came from two US-based IP addresses in the same subnet, believed to be a proxy. This is only the second Mythos-linked CVE out of 286 found so far to see real-world exploitation.

_Developers patching internet-facing services can follow fast-moving exploitation timelines like this on daily.dev._

### How did Anthropic's Mythos AI model discover the Rejetto HFS vulnerability?

Mythos identified that HFS's Math.random()-based session signing used V8's xorshift128+ algorithm, which is fully reversible, and simultaneously spotted a separate code path leaking raw Math.random() outputs. It chained these two findings and determined the leaked values gave enough information to recover the PRNG seed using Microsoft's Z3 SMT solver, enabling forged session cookies and authentication bypass.

_Security engineers evaluating AI-assisted bug hunting can compare real findings like this one on daily.dev._

## Similar posts on daily.dev

- [Anthropic Mythos model can find and exploit 0-days](https://daily.dev/posts/anthropic-mythos-model-can-find-and-exploit-0-days-eohtlhp4z) · The Register · 1 upvotes · 2 comments
- [Claude Mythos Preview \\ red.anthropic.com](https://daily.dev/posts/claude-mythos-preview-red-anthropic-com-wkjczmbgu) · Hacker News · 5 upvotes · 0 comments
- [Anthropic’s Mythos AI Uncovered Serious Security Holes in Every Major OS and Browser](https://daily.dev/posts/anthropic-s-mythos-ai-uncovered-serious-security-holes-in-every-major-os-and-browser-jmuf840uh) · Singularity Hub · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#nodejs](https://daily.dev/tags/nodejs), [#vulnerability](https://daily.dev/tags/vulnerability), [#anthropic](https://daily.dev/tags/anthropic), [#ai-security](https://daily.dev/tags/ai-security)

[View this post on daily.dev](https://daily.dev/posts/anthropic-s-super-bug-hunting-model-mythos-is-hardcore-good-at-math-as-latest-vuln-under-attack-sho-huh55ikq3)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows","url":"https://daily.dev/posts/anthropic-s-super-bug-hunting-model-mythos-is-hardcore-good-at-math-as-latest-vuln-under-attack-sho-huh55ikq3","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/anthropic-s-super-bug-hunting-model-mythos-is-hardcore-good-at-math-as-latest-vuln-under-attack-sho-huh55ikq3"},"datePublished":"2026-10-03T15:27:35.626Z","dateModified":"2026-10-03T15:27:59.558Z","description":"A critical authentication-bypass vulnerability in Rejetto HTTP File Server (CVE-2026-61500), discovered by Horizon3 researchers using Anthropic's Mythos AI...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/ca7dbada549eb45a6c887df7e531a9cf?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/ca7dbada549eb45a6c887df7e531a9cf?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"The Register","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"The Register","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/66aa2113fdad463992ffcbf0e8963fda","url":"https://daily.dev/sources/theregister"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/anthropic-s-super-bug-hunting-model-mythos-is-hardcore-good-at-math-as-latest-vuln-under-attack-sho-huh55ikq3","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,nodejs,vulnerability,anthropic,ai-security","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"The Register","item":"https://daily.dev/sources/theregister"},{"@type":"ListItem","position":3,"name":"Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/anthropic-s-super-bug-hunting-model-mythos-is-hardcore-good-at-math-as-latest-vuln-under-attack-sho-huh55ikq3#faq","mainEntity":[{"@type":"Question","name":"What is CVE-2026-61500 and how does it affect Rejetto HFS?","acceptedAnswer":{"@type":"Answer","text":"CVE-2026-61500 is a critical authentication-bypass vulnerability in Rejetto HTTP File Server that allows full admin access and remote code execution. It exploits HFS's use of Math.random() to generate a session-signing value passed to Koa's keygrip, combined with V8's insecure xorshift128+ PRNG and a separate leak of raw Math.random() outputs, letting attackers recover the PRNG seed with the Z3 SMT solver and forge valid session cookies. Update to HFS v3.2.1 or later to fix it. Teams running exposed file servers can track emerging CVEs like this one on daily.dev before attackers strike."}},{"@type":"Question","name":"Has the Rejetto HFS vulnerability found by Anthropic's Mythos model been exploited in the wild?","acceptedAnswer":{"@type":"Answer","text":"Yes, exploitation of CVE-2026-61500 began the day after disclosure, with initial activity detected from an IP address in China targeting vulnerable hosts in the US and Japan. A day later, four more hits came from two US-based IP addresses in the same subnet, believed to be a proxy. This is only the second Mythos-linked CVE out of 286 found so far to see real-world exploitation. Developers patching internet-facing services can follow fast-moving exploitation timelines like this on daily.dev."}},{"@type":"Question","name":"How did Anthropic's Mythos AI model discover the Rejetto HFS vulnerability?","acceptedAnswer":{"@type":"Answer","text":"Mythos identified that HFS's Math.random()-based session signing used V8's xorshift128+ algorithm, which is fully reversible, and simultaneously spotted a separate code path leaking raw Math.random() outputs. It chained these two findings and determined the leaked values gave enough information to recover the PRNG seed using Microsoft's Z3 SMT solver, enabling forged session cookies and authentication bypass. Security engineers evaluating AI-assisted bug hunting can compare real findings like this one on daily.dev."}}]}
```

