Urgent.News

What's breaking now, across thousands of outlets.

Tech

Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows

Exploitation attempts came from China-hosted IP, VulnCheck researcher says

Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows

An Anthropic-linked vulnerability, CVE-2026-61500, has been exploited in the wild, allowing attackers to achieve full admin access and remote code execution via the Rejetto HTTP File Server (HFS). The critical authentication-bypass bug was discovered by Zach Hanley, an AI pen-testing researcher at Horizon3, using Mythos, an advanced model developed by Anthropic to hunt for security flaws.

HFS is an open-source web file server that was previously listed on the US Cybersecurity and Infrastructure Security Agency's catalog of Known Exploited Vulnerabilities in 2024. Mythos, which possesses exceptional mathematical and scientific abilities, particularly in computer science and operating systems, was able to uncover the vulnerability by identifying cryptographic missteps and recognizing the leaking of raw Math.random() outputs.

This allowed Mythos to determine that an attacker could derive the session signing key, enabling them to forge valid session cookies and bypass authentication. The vulnerability highlights the importance of using a secure pseudo-random number generator (PRNG) and emphasizes the potential risks associated with insecure random number generation.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at theregister.com →

More in Tech

More from Saturday 3 October →