The Emergence of Mythos in Vulnerability Research
In a significant development for cybersecurity, Anthropic’s proprietary artificial intelligence model, Mythos, has demonstrated its formidable capabilities by uncovering a critical authentication-bypass vulnerability in the Rejetto HTTP File Server (HFS). This discovery, now tracked as CVE-2026-61500, serves as a testament to the model’s advanced aptitude for complex problem-solving. Mythos, which remains restricted from public access due to its high potential for impact, is being utilized by select security partners under Anthropic’s Project Glasswing initiative.
The vulnerability discovered by Mythos allows for full administrative access and remote code execution on affected servers. Shortly after researcher Zach Hanley of Horizon3 used the model to pinpoint the flaw, reports indicated that the vulnerability was already being exploited in the wild. Cybersecurity firm VulnCheck confirmed detection of hostile traffic originating from China-linked IP addresses, targeting hosts across the United States and Japan. This rapid transition from discovery to exploitation highlights the high-stakes environment in which modern AI-powered security research operates.
Understanding the Technical Chain of the HFS Flaw
The brilliance of the Mythos model lies in its ability to synthesize multiple, seemingly unrelated code vulnerabilities into a singular, exploitable attack chain. The issue within Rejetto HFS centers on how the application manages user authentication. Specifically, the software utilizes the Node.js framework Koa, which leverages keygrip to sign session cookies. The integrity of this process relies on the randomness of the initial values generated via Math.random().
Mythos successfully identified a critical cryptographic misstep: the application was leaking raw outputs of the Math.random() function. Because the underlying V8 engine utilizes the xorshift128+ algorithm—which is mathematically reversible—Mythos determined that the leaked outputs could be used to reconstruct the state of the pseudo-random number generator (PRNG). The model further suggested that the Microsoft-developed SMT solver, Z3, could be applied to recover the PRNG seed, allowing an attacker to forge valid session cookies and bypass authentication entirely.
The Strategic Value of AI in Security
The discovery of CVE-2026-61500 is not an isolated success for Mythos. Since the inception of Project Glasswing, the model has been credited with identifying nearly 300 vulnerabilities. This capability marks a shift in offensive security, where AI is moving beyond simple code analysis to performing deep mathematical reasoning and logical correlation.
- Cross-domain logic: Unlike traditional static analysis tools, Mythos identified the link between PRNG usage and external data leakage across separate code paths.
- Constraint Solving: By proposing the use of Z3 SMT solvers to crack cryptographic constraints, the model demonstrated a level of scientific reasoning typically reserved for human experts.
- Industry Impact: The incident has prompted immediate security advisories, with users of Rejetto HFS urged to upgrade to version 3.2.1 or later to mitigate the risk of remote code execution.
The Future of Project Glasswing
As Mythos continues to churn out CVE detections, the cybersecurity industry is forced to reckon with both the potential and the peril of such tools. While Anthropic’s decision to keep Mythos gated under Project Glasswing provides a layer of defense against misuse, the fact that its findings are so rapidly weaponized by external actors underscores a new reality. Defensive research, powered by models like Mythos, is now locked in a high-speed race against threat actors who are equally capable of leveraging AI to identify and capitalize on zero-day vulnerabilities in enterprise infrastructure.










