MobbleOpen in Mobble ⇢
Science · Mathematics & computing · published 2026-10-03 · via The Register

AI-Powered Security Tool Identifies Critical File Server Flaw, Now Under Active Exploitation

Anthropic's Mythos AI model discovered a critical authentication bypass vulnerability in Rejetto HTTP File Server that enables remote code execution and full administrative access. Within a day of public disclosure, the flaw was being actively exploited from Chinese IP addresses targeting vulnerable systems in the US and Japan. The incident marks the second vulnerability found by Mythos through Project Glasswing that has been targeted in real-world attacks.

Expanded Detail

Anthropic's Mythos AI model has demonstrated particular effectiveness in identifying security flaws by leveraging advanced mathematical reasoning capabilities. The model excels at analyzing cryptographic implementations and identifying exploitable logic errors in authentication systems—skills that proved instrumental in discovering the HFS vulnerability. Project Glasswing, which grants select security firms access to Mythos since its April launch, has already identified hundreds of vulnerabilities, though exploitation in the field remains rare until now.

The rapid weaponization of this flaw underscores how quickly discovered vulnerabilities can transition from theoretical to operational threats. The exploitation originated from Chinese infrastructure but involved US-based proxy servers, reflecting common obfuscation tactics used by sophisticated threat actors. Organizations running older versions of HFS faced immediate risk, highlighting the critical importance of timely patching once vulnerabilities enter public disclosure.

Context

This incident could reshape how cybersecurity research balances transparency with risk management. If AI-discovered vulnerabilities are routinely exploited within hours of disclosure, organizations may face narrowing windows for defensive response. The story may influence discussions around controlled vulnerability disclosure practices and whether AI security tools should operate under stricter access restrictions. System administrators managing legacy file servers and other overlooked infrastructure could face increased pressure to maintain update cycles more aggressively.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at The Register →
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows.” Browse more stories.