ALEXKRI.NET
Resume Contact
← Back

Exploitation Hits Rejetto HFS Vulnerability Discovered by AI

This one was found by doing maths, not fuzzing. HFS generated session cookies with Math.random(), and Horizon3.ai used Anthropic’s Mythos to work out that xorshift128+ output is reversible, so a handful of login responses hands you the signing key. That’s CVE-2026-61500, CVSS 9.3: forged admin cookies, then RCE. Patched in 3.2.1 on July 13, exploitation started October 2. The patch gap is still the whole story.

Read the source ↗