Exploitation targets Rejetto HFS vulnerability discovered by AI

Summary

Exploitation attempts are actively targeting a newly discovered vulnerability, CVE-2026-61500, in Rejetto HFS, identified by Anthropic's Mythos AI system. This flaw stems from the use of a non-cryptographic PRNG for session signing keys, coupled with exposed random outputs during login. Following its detailed disclosure, these exploitation attempts began within a day, with threat actors observed targeting vulnerable servers across multiple regions. This incident marks the second known actively exploited vulnerability in Rejetto HFS, following a previous issue involving unauthenticated remote code execution.

Analysis

Rejetto HFS: Rejetto HFS is an open-source HTTP file server application that enables users to host and share files over the web. It has previously been targeted by vulnerabilities leading to remote code execution. In the current incident, a critical flaw allowing session forgery and administrative access was discovered through AI-driven analysis and is now under active exploitation. Prior Incidents: This marks the second known actively exploited vulnerability in Rejetto HFS following an earlier unauthenticated remote code execution issue. Active Exploitation: Exploitation attempts on vulnerable Rejetto HFS servers began within a day of detailed disclosure, with observed activity from threat actors targeting hosts in multiple regions. Vulnerability Discovery: Anthropic's Mythos AI system identified the CVE-2026-61500 flaw in Rejetto HFS by analyzing weaknesses in its use of a non-cryptographic PRNG for session signing keys combined with exposed random outputs during login.

Categories

tech

Related sources

View Original Tweet