Detalle de la noticia

Vulnerabilidad

Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows

Fuente: The Register - Security Publicado: 03/10/2026 · 15:27 UTC
Compartir:
Vulnerabilidad Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows
Imagen: The Register - Security

The se­cond Anth­ro­pic-lin­ked vul­ne­ra­bi­lity known to have been ex­ploi­ted in the wild saw initial ac­ti­vity from an IP ad­dress in China tar­ge­ting vul­ne­ra­ble hosts in the US and Japan. The vuln is a cri­ti­cal authen­ti­ca­tion-by­pass bug in Re­jet­to HTTP File Ser­ver (HFS) that can lead to full admin ac­cess and re­mo­te code execu­tion. HFS is an open sour­ce web file ser­ver that pre­viously ap­pea­red on the US Cy­ber­se­cu­rity and In­fras­truc­tu­re Se­cu­rity Agency’s ca­ta­log of Known Ex­ploi­ted Vul­ne­ra­bi­li­ties in 2024. On Wed­nes­day, re­sear­cher Zach Han­ley at AI pen-tes­ting com­pany Ho­ri­zon3 said he used Mythos to un­co­ver a new flaw in the file ser­ver, now trac­ked as CVE-2026-61500. If you use Re­jet­to HFS, be sure to up­da­te to v3.2.1 or later, which fixes this and other se­cu­rity flaws. Han­ley also pu­blished a video sho­wing the steps to ex­ploit HFS and re­mo­tely execu­te code on the ser­ver. By the next day, the CVE was under ex­ploi­ta­tion. “We star­ted de­tec­ting ex­ploi­ta­tion of CVE-2026-61500 in Re­jet­to HFS this eve­ning,” Vuln­Check se­cu­rity re­sear­cher Pa­trick Ga­rrity posted on Lin­ke­dIn on Thurs­day, ad­ding that Han­ley and team re­por­ted the bug to Vuln­Check for CVE as­sign­ment. “Our ca­na­ries de­tec­ted an actor in China tar­ge­ting real vul­ne­ra­ble hosts in the US,” Ga­rrity added. Ga­rrity has been trac­king CVEs at­tri­bu­ted to Mythos and Pro­ject Glass­wing, Anth­ro­pic’s initia­ti­ve to give se­lect part­ners ac­cess to the bug-hun­ting model, since shortly after the pro­gram was an­noun­ced in April. Anth­ro­pic claims that Mythos is too po­wer­ful to re­lea­se to the ge­ne­ral pu­blic (in­sert evil laugh). As of Fri­day, Mythos and Pro­ject Glass­wing have un­co­ve­red 286 CVEs, ac­cor­ding to Ga­rrity’s trac­ker, and up until Thurs­day only one of these bugs had been ex­ploi­ted in real-world at­tacks. The Thurs­day night ac­ti­vity ori­gi­na­ted from one IP ad­dress in China and tar­ge­ted vul­ne­ra­ble ser­vers in the US and Japan, Ga­rrity told The Re­gis­ter. “Today we have seen four hits,” he told us on Fri­day. These ori­gi­na­ted from two dif­fe­rent IP ad­dres­ses in the US: 173.239.211[.]248 and 173.239.211[.]249. Both are in the same sub­net, and “ap­pear to be co­ming from a proxy,” Ga­rrity added. China-lin­ked di­gi­tal in­tru­ders rou­ti­nely use com­pro­mi­sed de­vi­ces as pro­xies to route ma­li­cious traf­fic and dis­gui­se the at­tac­kers’ true lo­ca­tion, and in April a 10-country se­cu­rity ad­vi­sory war­ned of China-nexus cyber ope­ra­ti­ves using proxy net­works “stra­te­gi­cally, and at scale.” In his write-up, Han­ley said Ho­ri­zon3 has used Mythos in its vul­ne­ra­bi­lity re­search – and dis­co­ve­red “many cri­ti­cal vul­ne­ra­bi­li­ties” – ever since the se­cu­rity com­pany joi­ned Pro­ject Glass­wing in July. Mythos' mad math skillz CVE-2026-61500 high­lights a couple of Mythos ca­pa­bi­li­ties that make it really good at un­co­ve­ring vul­ne­ra­bi­li­ties, ac­cor­ding to Han­ley. Na­mely, Mythos ex­cels at mathe­ma­ti­cal dis­ti­lla­tions and scien­ti­fic tasks, es­pe­cially those re­la­ting to com­pu­ter scien­ce and ope­ra­ting sys­tems. Fin­ding this CVE “speaks to Mythos’s ca­pa­bi­li­ties in un­ders­tan­ding of mathe­ma­tics, how it iden­ti­fied an ex­ploi­ta­ble set of cry­pto­graphic miss­teps, and ap­proa­ched sol­ving the cons­traints to achie­ve re­mo­te code execu­tion,” Han­ley wrote. The se­cu­rity issue stems from how HFS authen­ti­ca­tes users. It ge­ne­ra­tes a ran­dom value with Math.ran­dom() and then pas­ses this value to Koa, the Node.js web fra­me­work foun­da­tion for HFS. Koa uses key­grip to sign all ses­sion coo­kies with that ran­dom value. This means that if an “at­tac­ker can de­ri­ve what the ses­sion sig­ning key is, they can forge valid ses­sion coo­kies,” Han­ley said. This should not be pos­si­ble, as­su­ming Math.ran­dom() uses a se­cu­re pseu­do ran­dom num­ber ge­ne­ra­tor (PRNG). But V8’s Math.ran­dom() did not use a se­cu­re PRNG. Mythos dis­co­ve­red that the out­put of the xorshift128+ al­go­rithm it used was fully re­ver­si­ble – and the ap­pli­ca­tion was lea­king Math.ran­dom() out­puts.