Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows
First reported by The Register ·
A new AI model can find cryptographic flaws, making your existing security tooling potentially obsolete.
Anthropic's AI model, Mythos, played a key role in identifying a critical authentication-bypass vulnerability (CVE-2026-61500) in the Rejetto HTTP File Server (HFS). This flaw allows for full administrative access and remote code execution. Exploitation attempts for this vulnerability were detected shortly after its public disclosure, originating from an IP address in China and targeting systems in the US and Japan. The bug stems from an insecure pseudo-random number generator (PRNG) in the server's implementation, which Mythos identified as reversible and coupled with a leak of its outputs. This allowed attackers to derive the signing key for session cookies, enabling them to forge valid authentication. While Anthropic's Project Glasswing has discovered 286 CVEs, this is one of the few to be actively exploited in the wild, with initial attacks traced to China.
Mythos's success in uncovering CVE-2026-61500 highlights the growing sophistication of AI in security vulnerability research. The model's ability to understand complex mathematical principles, trace cryptographic missteps, and chain together seemingly disparate code paths to achieve exploitation demonstrates a leap in AI's analytical capabilities beyond simple pattern matching. This suggests a future where AI-driven tools will be instrumental in discovering zero-day vulnerabilities, potentially outpacing traditional human-led pen-testing methods.
The exploitation of this Mythos-discovered vulnerability by actors in China, utilizing proxy networks, underscores the persistent threat landscape and the dual-use nature of advanced AI tools. As AI models become more adept at finding critical flaws, their accessibility will become a significant concern. The rapid exploitation of CVE-2026-61500 also signals an arms race where attackers can leverage AI-discovered vulnerabilities as quickly as defenders can patch them, necessitating a proactive and adaptive security posture.
AI-written summary. May contain errors.