Published October 3, 2026 · Added October 5, 2026

Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows

The Register reports that Anthropic's Claude Mythos model was used to find a critical authentication-bypass bug in Rejetto HTTP File Server, an open source web file server, now tracked as CVE-2026-61500 and capable of giving attackers full admin access and remote code execution. Horizon3 researcher Zach Hanley used Mythos to uncover the flaw and published a walkthrough, and VulnCheck's Patrick Garrity says exploitation began the next day, with early activity from a China-hosted IP targeting vulnerable hosts in the US and Japan, making it the second Anthropic-linked vulnerability known to have been exploited in the wild. Users are advised to update to HFS v3.2.1 or later.

The Register reports that Anthropic’s Claude Mythos model was used to find a critical authentication-bypass bug in Rejetto HTTP File Server, an open source web file server, now tracked as CVE-2026-61500 and capable of giving attackers full admin access and remote code execution. Horizon3 researcher Zach Hanley used Mythos to uncover the flaw and published a walkthrough, and VulnCheck’s Patrick Garrity says exploitation began the next day, with early activity from a China-hosted IP targeting vulnerable hosts in the US and Japan, making it the second Anthropic-linked vulnerability known to have been exploited in the wild. Users are advised to update to HFS v3.2.1 or later.

Read the original story.

Source: The Register