AI-Powered Security Tool Identifies Critical File Server Flaw, Now Under Active Exploitation
Anthropic's Mythos AI model discovered a critical authentication bypass vulnerability in Rejetto HTTP File Server that enables remote code execution and full administrative access. Within a day of public disclosure, the flaw was being actively exploited from Chinese IP addresses targeting vulnerable systems in the US and Japan. The incident marks the second vulnerability found by Mythos through Project Glasswing that has been targeted in real-world attacks.
Anthropic's Mythos AI model has demonstrated particular effectiveness in identifying security flaws by leveraging advanced mathematical reasoning capabilities. The model excels at analyzing cryptographic implementations and identifying exploitable logic errors in authentication systems—skills that proved instrumental in discovering the HFS vulnerability. Project Glasswing, which grants select security firms access to Mythos since its April launch, has already identified hundreds of vulnerabilities, though exploitation in the field remains rare until now.
The rapid weaponization of this flaw underscores how quickly discovered vulnerabilities can transition from theoretical to operational threats. The exploitation originated from Chinese infrastructure but involved US-based proxy servers, reflecting common obfuscation tactics used by sophisticated threat actors. Organizations running older versions of HFS faced immediate risk, highlighting the critical importance of timely patching once vulnerabilities enter public disclosure.
This incident could reshape how cybersecurity research balances transparency with risk management. If AI-discovered vulnerabilities are routinely exploited within hours of disclosure, organizations may face narrowing windows for defensive response. The story may influence discussions around controlled vulnerability disclosure practices and whether AI security tools should operate under stricter access restrictions. System administrators managing legacy file servers and other overlooked infrastructure could face increased pressure to maintain update cycles more aggressively.