返回新闻
安全AI Understanding 简报

Anthropic Mythos AI 发现的 Rejetto HFS 漏洞利用引发安全担忧

SecurityWeek 报告称,威胁行为者正在积极利用 Rejetto HTTP 文件服务器中的 CVE-2026-61500(该缺陷最初由 Anthropic 的 Mythos AI 模型发现)来伪造管理 cookie 并实现远程代码执行。

4 min readRead the linked source
Source-provided image accompanying Exploitation of Rejetto HFS vulnerability discovered by Anthropic’s Mythos AI raises security concerns
来源参考来源记录
出版商
securityweek.com
来源链接
securityweek.comhttps://www.securityweek.com/exploitation-hits-rejetto-hfs-vulnerability-discovered-by-ai/
来源类型
链接来源——主要来源状态尚未确定。
背景60 秒内了解这一点

从这里开始

关键术语

算法
计算机为解决问题或完成任务而遵循的一组定义的规则或步骤。
特征
模型用来进行预测的输入变量。
迅速的
提供给生成模型的输入指令和上下文。
测试一下自己人工智能安全测验

发生了什么

Threat actors are exploiting a critical vulnerability (CVE‑2026‑61500, CVSS 9.3) in the open‑source Rejetto HTTP File Server (HFS). The flaw allows unauthenticated users to reconstruct the session‑cookie signing key by observing outputs of the server’s Math.random() generator, which uses the reversible xorshift128+ . With the recovered key, attackers can forge administrator cookies and execute arbitrary code via the server_code configuration. Horizon3.ai disclosed that its researchers discovered the flaw using Anthropic’s Mythos AI model, which identified the reversibility of the PRNG. Rejetto released version 3.2.1 on July 13 with patches. On October 2, VulnCheck warned that exploitation attempts have begun, originating from a China Telecom IP and targeting canaries in Japan and the United States.

The vulnerability stems from Rejetto HFS exposing outputs of its non‑cryptographic session‑cookie generator to unauthenticated clients during login. The generator, based on the xorshift128+ , produces values that can be reversed, allowing an attacker who collects a few login responses to reconstruct the generator’s internal state.

Horizon3.ai’s technical report explains that once the session‑cookie signing key is recovered, an attacker can forge valid administrator cookies. These forged cookies grant elevated privileges, enabling remote code execution through the server_code configuration option.

Anthropic’s Mythos AI model was used by Horizon3.ai to recognize the reversibility of the PRNG and to formulate the attack path. The AI’s mathematical reasoning accelerated the discovery of the flaw, which was reported to Rejetto in June.

Rejetto responded with a patched release (v3.2.1) on July 13. However, VulnCheck’s October 2 advisory indicates that exploitation attempts have already begun, targeting canary systems in Japan and the United States from a China Telecom IP address.

The report does not provide independent verification of successful compromises beyond the observed reconnaissance activity, and no public exploit code has been released.

来源详情: securityweek.com ↗

为什么这很重要

The incident illustrates how AI‑assisted vulnerability discovery can accelerate both defensive and offensive security activities. By leveraging advanced mathematical reasoning, Mythos identified a subtle weakness in a widely deployed file‑server product, prompting a rapid patch. However, the same AI‑derived insight appears to have been weaponized by attackers within weeks, exposing servers that have not yet applied the update. Given the high CVSS score and the ease of forging admin cookies, unpatched HFS installations face a severe risk of remote code execution, potentially leading to data theft, ransomware deployment, or lateral movement within networks. The case also underscores the broader challenge of securing software that relies on weak random number generators, especially when those weaknesses become more visible through AI analysis.

AI‑driven vulnerability discovery can shorten the time between flaw identification and patch release, improving overall software security. Conversely, the same AI insights can be rapidly adopted by malicious actors, compressing the window for defenders.

The use of a reversible PRNG for session‑cookie signing violates best practices for cryptographic randomness, highlighting a class of weaknesses that may exist in other legacy or open‑source projects.

Given the high severity rating (CVSS 9.3) and the ease of forging admin credentials, any unpatched HFS deployment is at immediate risk of remote code execution, which could be leveraged for data exfiltration, ransomware, or as a foothold for deeper network intrusion.

The incident may broader scrutiny of random number generation practices in web servers and other networked applications, potentially leading to new security guidelines or mandatory updates.

Interactive Mechanism

互动机制:它实际上是如何运作的

以交互方式探索这一发展背后的基础技术。

Thinking Budget (Test-Time Tokens):1,024 tokens
Complex Accuracy79%Math & Code Logic
Latency3.2sTime to first full output
Inference Cost$0.0092Per query estimated
Reasoning StyleStep VerificationInternal chain depth
Active Thinking Trace:
1Deconstruct user problem into formal constraints
2Propose candidate hypotheses & step-by-step calculation
3Self-correction: Backtrack and refute subtle edge cases
4Exhaustive consistency check & final output synthesis
Core takeaway: Test-time compute fundamentally changes AI economics. Instead of only scaling during pre-training, giving reasoning models more tokens at inference time allows them to systematically solve PhD-level STEM problems.
交互式概念检查+10 Points
AI Security Quiz

A public chatbot and an internal agent with write access are being assessed. Why need separate threat models?

接下来看什么

Security teams should monitor for indicators of compromise linked to forged HFS admin cookies, such as unexpected processes spawned by the server_code or anomalous traffic from known malicious IP ranges. Organizations using Rejetto HFS must verify that version 3.2.1 or later is deployed and consider additional network segmentation to limit exposure. Researchers will likely examine whether other software that employs Math.random() or similar PRNGs is vulnerable to similar reconstruction attacks, potentially prompting broader advisories. Finally, the security community will watch how AI tools are employed in both vulnerability research and exploitation, influencing future threat‑modeling and defensive strategies.

Detection of forged HFS admin cookies in network logs or authentication systems.

Unusual execution of scripts or commands via the server_code configuration on HFS instances.

Emergence of similar PRNG‑related vulnerabilities in other software, especially those using Math.random() or xorshift algorithms.

Further disclosures from security firms about AI‑assisted discovery techniques and their impact on threat landscapes.

Responses from Rejetto regarding additional mitigations, such as deprecating the vulnerable PRNG or providing migration tools for existing installations.

相关指南和测验

人工智能安全人工智能模型解释AI 伦理AI 的未来测试你所知道的——尝试免费的人工智能测验在我们的词汇表中查找人工智能术语关注AI监管追踪器
觉得这有用吗?