{
  "id": 11711845,
  "title": "Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows",
  "url": "https://urgent.news/2026/10/03/anthropics-super-bug-hunting-model-mythos-is-hardcore-good-at-math-as",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-03T15:27:00.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/10/03/anthropics-super-bug-hunting-model-mythos-is-hardcore-good-at-math-as-latest-vuln-under-attack-shows/5300933"
  },
  "original_language": "en",
  "account": "An Anthropic-linked vulnerability, CVE-2026-61500, has been exploited in the wild, allowing attackers to achieve full admin access and remote code execution via the Rejetto HTTP File Server (HFS). The critical authentication-bypass bug was discovered by Zach Hanley, an AI pen-testing researcher at Horizon3, using Mythos, an advanced model developed by Anthropic to hunt for security flaws. HFS is an open-source web file server that was previously listed on the US Cybersecurity and Infrastructure Security Agency's catalog of Known Exploited Vulnerabilities in 2024. Mythos, which possesses exceptional mathematical and scientific abilities, particularly in computer science and operating systems, was able to uncover the vulnerability by identifying cryptographic missteps and recognizing the leaking of raw Math.random() outputs. This allowed Mythos to determine that an attacker could derive the session signing key, enabling them to forge valid session cookies and bypass authentication. The vulnerability highlights the importance of using a secure pseudo-random number generator (PRNG) and emphasizes the potential risks associated with insecure random number generation.",
  "summary": "Exploitation attempts came from China-hosted IP, VulnCheck researcher says",
  "key_points": [
    "Anthropic's Mythos model discovered CVE-2026-61500 vulnerability",
    "Mythos exploited Rejetto HTTP File Server for admin access",
    "Secure PRNG crucial to prevent session signing key derivation"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows",
        "url": "https://urgent.news/2026/10/03/anthropics-super-bug-hunting-model-mythos-is-hardcore-good-at-math-as-11713863",
        "published": "2026-10-03T15:27:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}