Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows

Anthropic's AI model, Mythos, has been used to identify a critical vulnerability in the Rejetto HTTP File Server, which is now being actively exploited by attackers. Security researchers are tracking the use of AI in both discovering and potentially weaponizing software vulnerabilities.
Why it matters
The use of AI models for both offensive and defensive cybersecurity represents a major shift in the threat landscape.
Exploitation attempts came from China-hosted IP, VulnCheck researcher says
The second Anthropic-linked vulnerability known to have been exploited in the wild saw initial activity from an IP address in China targeting vulnerable hosts in the US and Japan.
The vuln is a critical authentication-bypass bug in Rejetto HTTP File Server (HFS) that can lead to full admin access and remote code execution. HFS is an open source web file server that previously appeared on the US Cybersecurity and Infrastructure Security Agency’s catalog of Known Exploited Vulnerabilities in 2024.
On Wednesday, researcher Zach Hanley at AI pen-testing company Horizon3 said he used Mythos to uncover a new flaw in the file server , now tracked as CVE-2026-61500. If you use Rejetto HFS, be sure to update to v3.2.1 or later, which fixes this and other security flaws.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in