The Register reports that Anthropic’s Claude Mythos model was used to find a critical authentication-bypass bug in Rejetto HTTP File Server, an open source web file server, now tracked as CVE-2026-61500 and capable of giving attackers full admin access and remote code execution. Horizon3 researcher Zach Hanley used Mythos to uncover the flaw and published a walkthrough, and VulnCheck’s Patrick Garrity says exploitation began the next day, with early activity from a China-hosted IP targeting vulnerable hosts in the US and Japan, making it the second Anthropic-linked vulnerability known to have been exploited in the wild. Users are advised to update to HFS v3.2.1 or later.
Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows
The Register reports that Anthropic's Claude Mythos model was used to find a critical authentication-bypass bug in Rejetto HTTP File Server, an open source web file server, now tracked as CVE-2026-61500 and capable of giving attackers full admin access and remote code execution. Horizon3 researcher Zach Hanley used Mythos to uncover the flaw and published a walkthrough, and VulnCheck's Patrick Garrity says exploitation began the next day, with early activity from a China-hosted IP targeting vulnerable hosts in the US and Japan, making it the second Anthropic-linked vulnerability known to have been exploited in the wild. Users are advised to update to HFS v3.2.1 or later.
Source: The Register