安全
Anthropic的超级漏洞挖掘模型Mythos在数学方面表现极强,最新漏洞遭攻击事件即为明证
VulnCheck研究人员称,攻击尝试来自托管于中国的IP地址
第二起已知被利用的与Anthropic相关的漏洞,其初始活动源自一个位于中国的IP地址,该地址针对美国和日本的易受攻击主机发起攻击。
该漏洞是Rejetto HTTP File Server(HFS)中的一个关键身份验证绕过缺陷,可导致完全的管理员访问权限和远程代码执行。HFS是一个开源Web文件服务器,此前曾于2024年出现在美国网络安全与基础设施安全局(CISA)的已知利用漏洞目录中。
周三,AI渗透测试公司Horizon3的研究员Zach Hanley表示,他使用Mythos发现了该文件服务器中的一个新缺陷,现被追踪为CVE-2026-61500。如果您使用Rejetto HFS,请务必更新至v3.2.1或更高版本,以修复此漏洞及其他安全问题。
Hanley还发布了一段视频,展示了利用HFS并在服务器上远程执行代码的步骤。
到了第二天,该CVE便遭到了利用。
“我们今晚开始检测到针对Rejetto HFS中CVE-2026-61500的利用活动,”VulnCheck安全研究员Patrick Garrity周四在LinkedIn上发帖称,并补充说Hanley及其团队已向VulnCheck报告了该漏洞以分配CVE编号。
“我们的金丝雀检测到一名来自中国的行为者正针对美国真实的易受攻击主机,”Garrity补充道。
自今年4月该项目宣布以来不久,Garrity一直在追踪归因于Mythos和Project Glasswing(Anthropic的一项举措,旨在让特定合作伙伴访问该漏洞挖掘模型)的CVE。Anthropic声称Mythos过于强大,无法向公众发布(插入邪恶的笑声)。
截至周五,根据Garrity的追踪器显示,Mythos和Project Glasswing已发现了286个CVE,而在周四之前,这些漏洞中仅有其中一个在现实世界的攻击中被利用过。
Garrity告诉《The Register》,周四晚上的活动源自中国的一个IP地址,并针对美国和日本的易受攻击服务器发起攻击。
“我们今天看到了四次命中,”他周五对我们说。这些命中源自美国两个不同的IP地址:173.239.211[.]248和173.239.211[.]249。两者位于同一子网,“似乎来自一个代理服务器,”Garrity补充道。
与中国相关的数字入侵者 routinely 使用被攻陷的设备作为代理来路由恶意流量并掩盖攻击者的真实位置,今年4月,一份涉及10个国家的安全公告警告称,与中国有关联的网络行动者正在“战略性地、大规模地”使用代理网络。
在他的分析文章中,Hanley表示,自该公司于7月加入Project Glasswing以来,Horizon3一直在其漏洞研究中使用Mythos,并发现了“许多关键漏洞”。
Mythos的疯狂数学技能
根据Hanley的说法,CVE-2026-61500突显了Mythos在发现漏洞方面的几项能力,使其表现非常出色。具体来说,Mythos擅长数学蒸馏和科学任务,尤其是那些与计算机科学和操作系统相关的任务。Hanley写道,发现此CVE“体现了Mythos在理解数学方面的能力,它如何识别出一组可被利用的密码学失误,以及如何通过解决约束条件以实现远程代码执行”。
该安全问题源于HFS对用户身份验证的方式。它使用Math.random()生成一个随机值,然后将该值传递给Koa,即HFS基于Node.js的Web框架基础。Koa使用keygrip使用该随机值对所有会话Cookie进行签名。
Hanley表示,这意味着“如果攻击者能够推导出会话签名密钥是什么,他们就可以伪造有效的会话Cookie”。在假设Math.random()使用安全伪随机数生成器(PRNG)的情况下,这本来是不可能的。
但 V8 的 Math.random() 并未使用安全的伪随机数生成器(PRNG)。Mythos 发现,其使用的 xorshift128+ 算法的输出是完全可逆的——而该应用程序正在泄露 Math.random() 的输出。
该模型的分析声称,可以使用 Z3(一款由微软开发、公开可用的可满足性模理论(SMT)求解器)来恢复 PRNG 的种子。Hanley 指出,Horizon3 的研究人员回忆不起曾见过有人以这种方式利用 SMT 求解器攻击真实应用程序中的加密缺陷并绕过身份验证。
他写道:“令人印象深刻之处在于,Mythos 不仅仅孤立地标记了不安全的 PRNG——它还同时识别出该应用程序通过另一条代码路径泄露了原始的 Math.random() 输出,将这两个事实识别为一条链条,并确定该泄露产生的观测结果恰好足以使状态恢复成为可能。”®
security
Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows
Exploitation attempts came from China-hosted IP, VulnCheck researcher says
The second Anthropic-linked vulnerability known to have been exploited in the wild saw initial activity from an IP address in China targeting vulnerable hosts in the US and Japan.
The vuln is a critical authentication-bypass bug in Rejetto HTTP File Server (HFS) that can lead to full admin access and remote code execution. HFS is an open source web file server that previously appeared on the US Cybersecurity and Infrastructure Security Agency’s catalog of Known Exploited Vulnerabilities in 2024.
On Wednesday, researcher Zach Hanley at AI pen-testing company Horizon3 said he used Mythos to uncover a new flaw in the file server , now tracked as CVE-2026-61500. If you use Rejetto HFS, be sure to update to v3.2.1 or later, which fixes this and other security flaws.
Hanley also published a video showing the steps to exploit HFS and remotely execute code on the server.
By the next day, the CVE was under exploitation.
“We started detecting exploitation of CVE-2026-61500 in Rejetto HFS this evening,” VulnCheck security researcher Patrick Garrity posted on LinkedIn on Thursday, adding that Hanley and team reported the bug to VulnCheck for CVE assignment.
“Our canaries detected an actor in China targeting real vulnerable hosts in the US,” Garrity added.
Garrity has been tracking CVEs attributed to Mythos and Project Glasswing, Anthropic’s initiative to give select partners access to the bug-hunting model, since shortly after the program was announced in April. Anthropic claims that Mythos is too powerful to release to the general public (insert evil laugh).
As of Friday, Mythos and Project Glasswing have uncovered 286 CVEs , according to Garrity’s tracker, and up until Thursday only one of these bugs had been exploited in real-world attacks.
The Thursday night activity originated from one IP address in China and targeted vulnerable servers in the US and Japan, Garrity told The Register .
“Today we have seen four hits,” he told us on Friday. These originated from two different IP addresses in the US: 173.239.211[.]248 and 173.239.211[.]249. Both are in the same subnet, and “appear to be coming from a proxy,” Garrity added.
China-linked digital intruders routinely use compromised devices as proxies to route malicious traffic and disguise the attackers’ true location, and in April a 10-country security advisory warned of China-nexus cyber operatives using proxy networks “strategically, and at scale.”
In his write-up, Hanley said Horizon3 has used Mythos in its vulnerability research – and discovered “many critical vulnerabilities” – ever since the security company joined Project Glasswing in July.
Mythos' mad math skillz
CVE-2026-61500 highlights a couple of Mythos capabilities that make it really good at uncovering vulnerabilities, according to Hanley. Namely, Mythos excels at mathematical distillations and scientific tasks, especially those relating to computer science and operating systems. Finding this CVE “speaks to Mythos’s capabilities in understanding of mathematics, how it identified an exploitable set of cryptographic missteps, and approached solving the constraints to achieve remote code execution,” Hanley wrote.
The security issue stems from how HFS authenticates users. It generates a random value with Math.random() and then passes this value to Koa , the Node.js web framework foundation for HFS. Koa uses keygrip to sign all session cookies with that random value.
This means that if an “attacker can derive what the session signing key is, they can forge valid session cookies,” Hanley said. This should not be possible, assuming Math.random() uses a secure pseudo random number generator (PRNG).
But V8’s Math.random() did not use a secure PRNG. Mythos discovered that the output of the xorshift128+ algorithm it used was fully reversible – and the application was leaking Math.random() outputs.
The model’s analysis claimed that Z3 , a Microsoft-developed, publicly available Satisfiability Modulo Theories (SMT) solver, could be used to recover the PRNG seed. Hanley notes that Horizon3’s researchers could not recall seeing an SMT solver used this way to attack a cryptographic flaw in a real application and bypass authentication.
“What makes this impressive is that Mythos didn’t just flag the insecure PRNG in isolation – it simultaneously identified that the application leaked raw Math.random() outputs through a separate code path, recognized those two facts as a chain, and determined the leak produced exactly the observations needed to make state recovery feasible,” he wrote.®
首次收录 · 2026-10-04 · 8.62 分