Rudi kwa Habari
UsalamaAI Understanding muhtasari

Unyonyaji wa hatari ya Rejetto HFS iliyogunduliwa na Mythos AI ya Anthropic inaibua wasiwasi wa usalama.

SecurityWeek inaripoti kwamba watendaji tishio wanatumia CVE‑2026‑61500 kikamilifu katika Seva ya Faili ya Rejetto HTTP, dosari iliyofichuliwa awali na mtindo wa Anthropic wa Mythos AI, kughushi vidakuzi vya msimamizi na kufikia utekelezaji wa msimbo wa mbali.

4 min readRead the linked source
Source-provided image accompanying Exploitation of Rejetto HFS vulnerability discovered by Anthropic’s Mythos AI raises security concerns
Rejeleo la chanzoChanzo kimerekodiwa
Mchapishaji
securityweek.com
Kiungo cha chanzo
securityweek.comhttps://www.securityweek.com/exploitation-hits-rejetto-hfs-vulnerability-discovered-by-ai/
Aina ya chanzo
Chanzo kilichounganishwa - hali ya chanzo-msingi haijaanzishwa.
MuktadhaElewa hili katika sekunde 60

Anzia hapa

Masharti muhimu

Algorithm
Seti maalum ya sheria au hatua ambazo kompyuta hufuata ili kutatua tatizo au kukamilisha kazi.
Kipengele
Tofauti ya ingizo inayotumiwa na modeli kufanya ubashiri.
Haraka
Maagizo ya ingizo na muktadha uliotolewa kwa modeli ya uzalishaji.
Jijaribu mwenyeweMaswali ya Usalama ya AI

Nini kilitokea

Threat actors are exploiting a critical vulnerability (CVE‑2026‑61500, CVSS 9.3) in the open‑source Rejetto HTTP File Server (HFS). The flaw allows unauthenticated users to reconstruct the session‑cookie signing key by observing outputs of the server’s Math.random() generator, which uses the reversible xorshift128+ . With the recovered key, attackers can forge administrator cookies and execute arbitrary code via the server_code configuration. Horizon3.ai disclosed that its researchers discovered the flaw using Anthropic’s Mythos AI model, which identified the reversibility of the PRNG. Rejetto released version 3.2.1 on July 13 with patches. On October 2, VulnCheck warned that exploitation attempts have begun, originating from a China Telecom IP and targeting canaries in Japan and the United States.

The vulnerability stems from Rejetto HFS exposing outputs of its non‑cryptographic session‑cookie generator to unauthenticated clients during login. The generator, based on the xorshift128+ , produces values that can be reversed, allowing an attacker who collects a few login responses to reconstruct the generator’s internal state.

Horizon3.ai’s technical report explains that once the session‑cookie signing key is recovered, an attacker can forge valid administrator cookies. These forged cookies grant elevated privileges, enabling remote code execution through the server_code configuration option.

Anthropic’s Mythos AI model was used by Horizon3.ai to recognize the reversibility of the PRNG and to formulate the attack path. The AI’s mathematical reasoning accelerated the discovery of the flaw, which was reported to Rejetto in June.

Rejetto responded with a patched release (v3.2.1) on July 13. However, VulnCheck’s October 2 advisory indicates that exploitation attempts have already begun, targeting canary systems in Japan and the United States from a China Telecom IP address.

The report does not provide independent verification of successful compromises beyond the observed reconnaissance activity, and no public exploit code has been released.

Maelezo ya chanzo: securityweek.com ↗

Kwa nini ni muhimu

The incident illustrates how AI‑assisted vulnerability discovery can accelerate both defensive and offensive security activities. By leveraging advanced mathematical reasoning, Mythos identified a subtle weakness in a widely deployed file‑server product, prompting a rapid patch. However, the same AI‑derived insight appears to have been weaponized by attackers within weeks, exposing servers that have not yet applied the update. Given the high CVSS score and the ease of forging admin cookies, unpatched HFS installations face a severe risk of remote code execution, potentially leading to data theft, ransomware deployment, or lateral movement within networks. The case also underscores the broader challenge of securing software that relies on weak random number generators, especially when those weaknesses become more visible through AI analysis.

AI‑driven vulnerability discovery can shorten the time between flaw identification and patch release, improving overall software security. Conversely, the same AI insights can be rapidly adopted by malicious actors, compressing the window for defenders.

The use of a reversible PRNG for session‑cookie signing violates best practices for cryptographic randomness, highlighting a class of weaknesses that may exist in other legacy or open‑source projects.

Given the high severity rating (CVSS 9.3) and the ease of forging admin credentials, any unpatched HFS deployment is at immediate risk of remote code execution, which could be leveraged for data exfiltration, ransomware, or as a foothold for deeper network intrusion.

The incident may broader scrutiny of random number generation practices in web servers and other networked applications, potentially leading to new security guidelines or mandatory updates.

Interactive Mechanism

Mbinu shirikishi: Jinsi Inavyofanya Kazi Kweli

Chunguza teknolojia msingi nyuma ya ukuzaji huu kwa maingiliano.

Thinking Budget (Test-Time Tokens):1,024 tokens
Complex Accuracy79%Math & Code Logic
Latency3.2sTime to first full output
Inference Cost$0.0092Per query estimated
Reasoning StyleStep VerificationInternal chain depth
Active Thinking Trace:
1Deconstruct user problem into formal constraints
2Propose candidate hypotheses & step-by-step calculation
3Self-correction: Backtrack and refute subtle edge cases
4Exhaustive consistency check & final output synthesis
Core takeaway: Test-time compute fundamentally changes AI economics. Instead of only scaling during pre-training, giving reasoning models more tokens at inference time allows them to systematically solve PhD-level STEM problems.
Ukaguzi wa Dhana ya Kuingiliana+10 Points
AI Security Quiz

A public chatbot and an internal agent with write access are being assessed. Why need separate threat models?

Nini cha kutazama baadaye

Security teams should monitor for indicators of compromise linked to forged HFS admin cookies, such as unexpected processes spawned by the server_code or anomalous traffic from known malicious IP ranges. Organizations using Rejetto HFS must verify that version 3.2.1 or later is deployed and consider additional network segmentation to limit exposure. Researchers will likely examine whether other software that employs Math.random() or similar PRNGs is vulnerable to similar reconstruction attacks, potentially prompting broader advisories. Finally, the security community will watch how AI tools are employed in both vulnerability research and exploitation, influencing future threat‑modeling and defensive strategies.

Detection of forged HFS admin cookies in network logs or authentication systems.

Unusual execution of scripts or commands via the server_code configuration on HFS instances.

Emergence of similar PRNG‑related vulnerabilities in other software, especially those using Math.random() or xorshift algorithms.

Further disclosures from security firms about AI‑assisted discovery techniques and their impact on threat landscapes.

Responses from Rejetto regarding additional mitigations, such as deprecating the vulnerable PRNG or providing migration tools for existing installations.

Miongozo & maswali yanayohusiana

Usalama wa AIMifano ya AI ImefafanuliwaMaadili ya AIMustakabali wa AIJaribu unachojua - jaribu maswali ya AI bila malipoTafuta istilahi ya AI katika faharasa yetuFuata kifuatiliaji cha udhibiti wa AI
Je, umepata hii kuwa muhimu?