→ Back to Home
Application Security

Anthropic's Mythos AI Model Accelerates Zero-Day Exploitation to Under 24 Hours

A critical authentication-bypass vulnerability (CVE-2026-61500) in Rejetto HTTP File Server (HFS), discovered by Horizon3's Zach Hanley using Anthropic's Mythos AI model, was exploited in the wild by a China-based actor within 24 hours of its public disclosure. The flaw stemmed from HFS deriving its Koa session signing key from `Math.random()`, which Mythos was able to determine was fully reversible once raw values were leaked. VulnCheck's canaries detected attacks targeting US and Japanese servers almost immediately after the disclosure. The fix for this vulnerability is Rejetto HFS 3.2.1 or later. This incident is a stark warning for practitioners across all sectors. The speed at which a sophisticated AI model can identify a complex vulnerability and the subsequent near-instantaneous exploitation by threat actors fundamentally changes the calculus of application security. It signifies that the traditional timeline for vulnerability management – discovery, disclosure, patching, and then monitoring for exploitation – is now dangerously compressed. Organizations can no longer rely on a multi-day or even multi-week patching cycle for critical vulnerabilities. The affected parties include any organization utilizing Rejetto HFS, but the broader implication extends to all software users and developers, highlighting the need for a paradigm shift in how vulnerabilities are addressed. This event fits into a broader, well-established trend where AI is increasingly being leveraged in cybersecurity, both offensively and defensively. Microsoft's 2026 Digital Defense Report noted that AI is changing the 'physics of cybersecurity,' enabling attackers to find bugs and build malware faster than defenders can keep up. The median time from vulnerability discovery to weaponization has dropped to well below 24 hours. This acceleration is not limited to vulnerability discovery; AI agents are also being used in phishing campaigns and even autonomous attacks. The increasing sophistication of AI in vulnerability research, as demonstrated by Mythos, means that the security community must adapt to a future where zero-day exploits are not just rare occurrences but potentially rapid-fire events following any public disclosure of a weakness. In practice, this means that organizations must prioritize immediate action upon the disclosure of critical vulnerabilities. This includes implementing robust, automated patching mechanisms that can deploy fixes within hours, not days. Furthermore, security teams need to invest in advanced threat intelligence and proactive hunting capabilities that can detect exploitation attempts of newly disclosed vulnerabilities before official patches are widely deployed. The emphasis should shift from reactive defense to a highly agile, proactive security posture that anticipates AI-driven threats. Organizations should also audit their reliance on predictable random number generation in security-critical functions and consider adopting more robust cryptographic primitives. The trade-off here is between speed and thoroughness; while rapid deployment is crucial, it must not compromise the quality of the fix. Practitioners should closely monitor the activities of AI models in vulnerability research and integrate this intelligence into their security operations to stay ahead of the curve.
#ai#vulnerability#zero-day#exploitation#patching#threat intelligence
Read original source