뉴스로 돌아가기
보안AI Understanding 브리핑

Anthropic의 Mythos AI가 발견한 Rejetto HFS 취약점 악용으로 보안 우려 제기

SecurityWeek는 위협 행위자가 원래 Anthropic의 Mythos AI 모델에서 발견한 결함인 Rejetto HTTP 파일 서버의 CVE‑2026‑61500을 적극적으로 악용하여 관리자 쿠키를 위조하고 원격 코드 실행을 달성하고 있다고 보고했습니다.

4 min readRead the linked source
Source-provided image accompanying Exploitation of Rejetto HFS vulnerability discovered by Anthropic’s Mythos AI raises security concerns
소스 참조녹음된 소스
출판사
securityweek.com
소스 링크
securityweek.comhttps://www.securityweek.com/exploitation-hits-rejetto-hfs-vulnerability-discovered-by-ai/
소스 유형
연결된 소스 — 기본 소스 상태가 설정되지 않았습니다.
맥락60초 안에 이해하세요

여기서 시작하세요

주요 용어

알고리즘
문제를 해결하거나 작업을 완료하기 위해 컴퓨터가 따르는 정의된 규칙 또는 단계 세트입니다.
특징
예측을 위해 모델에서 사용되는 입력 변수입니다.
프롬프트
생성 모델에 제공되는 입력 지침 및 컨텍스트입니다.
자신을 테스트해 보세요AI 보안 퀴즈

무슨 일이 일어났나요?

Threat actors are exploiting a critical vulnerability (CVE‑2026‑61500, CVSS 9.3) in the open‑source Rejetto HTTP File Server (HFS). The flaw allows unauthenticated users to reconstruct the session‑cookie signing key by observing outputs of the server’s Math.random() generator, which uses the reversible xorshift128+ . With the recovered key, attackers can forge administrator cookies and execute arbitrary code via the server_code configuration. Horizon3.ai disclosed that its researchers discovered the flaw using Anthropic’s Mythos AI model, which identified the reversibility of the PRNG. Rejetto released version 3.2.1 on July 13 with patches. On October 2, VulnCheck warned that exploitation attempts have begun, originating from a China Telecom IP and targeting canaries in Japan and the United States.

The vulnerability stems from Rejetto HFS exposing outputs of its non‑cryptographic session‑cookie generator to unauthenticated clients during login. The generator, based on the xorshift128+ , produces values that can be reversed, allowing an attacker who collects a few login responses to reconstruct the generator’s internal state.

Horizon3.ai’s technical report explains that once the session‑cookie signing key is recovered, an attacker can forge valid administrator cookies. These forged cookies grant elevated privileges, enabling remote code execution through the server_code configuration option.

Anthropic’s Mythos AI model was used by Horizon3.ai to recognize the reversibility of the PRNG and to formulate the attack path. The AI’s mathematical reasoning accelerated the discovery of the flaw, which was reported to Rejetto in June.

Rejetto responded with a patched release (v3.2.1) on July 13. However, VulnCheck’s October 2 advisory indicates that exploitation attempts have already begun, targeting canary systems in Japan and the United States from a China Telecom IP address.

The report does not provide independent verification of successful compromises beyond the observed reconnaissance activity, and no public exploit code has been released.

소스 세부정보: securityweek.com ↗

왜 중요한가요?

The incident illustrates how AI‑assisted vulnerability discovery can accelerate both defensive and offensive security activities. By leveraging advanced mathematical reasoning, Mythos identified a subtle weakness in a widely deployed file‑server product, prompting a rapid patch. However, the same AI‑derived insight appears to have been weaponized by attackers within weeks, exposing servers that have not yet applied the update. Given the high CVSS score and the ease of forging admin cookies, unpatched HFS installations face a severe risk of remote code execution, potentially leading to data theft, ransomware deployment, or lateral movement within networks. The case also underscores the broader challenge of securing software that relies on weak random number generators, especially when those weaknesses become more visible through AI analysis.

AI‑driven vulnerability discovery can shorten the time between flaw identification and patch release, improving overall software security. Conversely, the same AI insights can be rapidly adopted by malicious actors, compressing the window for defenders.

The use of a reversible PRNG for session‑cookie signing violates best practices for cryptographic randomness, highlighting a class of weaknesses that may exist in other legacy or open‑source projects.

Given the high severity rating (CVSS 9.3) and the ease of forging admin credentials, any unpatched HFS deployment is at immediate risk of remote code execution, which could be leveraged for data exfiltration, ransomware, or as a foothold for deeper network intrusion.

The incident may broader scrutiny of random number generation practices in web servers and other networked applications, potentially leading to new security guidelines or mandatory updates.

Interactive Mechanism

대화형 메커니즘: 실제로 작동하는 방식

이 개발의 이면에 있는 기본 기술을 대화식으로 살펴보세요.

Thinking Budget (Test-Time Tokens):1,024 tokens
Complex Accuracy79%Math & Code Logic
Latency3.2sTime to first full output
Inference Cost$0.0092Per query estimated
Reasoning StyleStep VerificationInternal chain depth
Active Thinking Trace:
1Deconstruct user problem into formal constraints
2Propose candidate hypotheses & step-by-step calculation
3Self-correction: Backtrack and refute subtle edge cases
4Exhaustive consistency check & final output synthesis
Core takeaway: Test-time compute fundamentally changes AI economics. Instead of only scaling during pre-training, giving reasoning models more tokens at inference time allows them to systematically solve PhD-level STEM problems.
대화형 개념 확인+10 Points
AI Security Quiz

A public chatbot and an internal agent with write access are being assessed. Why need separate threat models?

다음에 무엇을 볼 것인가

Security teams should monitor for indicators of compromise linked to forged HFS admin cookies, such as unexpected processes spawned by the server_code or anomalous traffic from known malicious IP ranges. Organizations using Rejetto HFS must verify that version 3.2.1 or later is deployed and consider additional network segmentation to limit exposure. Researchers will likely examine whether other software that employs Math.random() or similar PRNGs is vulnerable to similar reconstruction attacks, potentially prompting broader advisories. Finally, the security community will watch how AI tools are employed in both vulnerability research and exploitation, influencing future threat‑modeling and defensive strategies.

Detection of forged HFS admin cookies in network logs or authentication systems.

Unusual execution of scripts or commands via the server_code configuration on HFS instances.

Emergence of similar PRNG‑related vulnerabilities in other software, especially those using Math.random() or xorshift algorithms.

Further disclosures from security firms about AI‑assisted discovery techniques and their impact on threat landscapes.

Responses from Rejetto regarding additional mitigations, such as deprecating the vulnerable PRNG or providing migration tools for existing installations.

관련 가이드 및 퀴즈

AI 보안AI 모델 설명AI 윤리AI의 미래알고 있는 내용을 테스트해 보세요. 무료 AI 퀴즈를 시도해 보세요.용어집에서 AI 용어를 찾아보세요.AI 규제 추적기를 따르세요
이것이 유용하다고 생각하시나요?