Two events in the same week show both sides of AI-assisted vulnerability research.
Horizon3 and Mythos: an enterprise example
On September 30, 2026, Zach Hanley of the pen-testing company Horizon3 published a write-up of CVE-2026-61500, a critical (CVSS 9.3) session-forgery flaw in the open-source Rejetto HTTP File Server, versions 3.0.0 to 3.2.0. Horizon3 says it has used Anthropic's Mythos model in its vulnerability-research pipelines since joining Anthropic's Project Glasswing in July.
- Workflow: Horizon3's harness "spawns many specialized agents in parallel to look for specific vulnerability classes across a code base." A cryptographic-weakness agent driven by Mythos flagged the bug; a second, verifying agent re-read the code and confirmed it as a true positive; Mythos then wrote a working proof-of-concept exploit, including a Z3 solver, and demonstrated command execution.
- The flaw: HFS built its cookie-signing key from JavaScript's
Math.random(), which in V8 is a reversible generator, and separately leaked raw outputs of the same generator to anyone starting a login. Collect a few, recover the generator's state, recover the key, and forge an administrator cookie -- then use HFS's admin feature that runs custom JavaScript. Hanley: "Mythos didn't just flag the insecure PRNG in isolation -- it simultaneously identified that the application leaked raw Math.random() outputs." - Systems and data touched: the source code of a third-party open-source project, analyzed in Horizon3's own pipeline, with findings handed to the maintainer and to VulnCheck as the CVE assigner.
The adoption constraint is the disclosure window. The CVE record and the fix (HFS 3.2.1) date from July 13, according to OSV. But the detailed write-up turned it into a recipe: VulnCheck's Patrick Garrity told The Register "we started detecting exploitation of CVE-2026-61500 in Rejetto HFS this evening" on the Thursday after publication, from an actor in China targeting hosts in the US, followed the next day by hits through US proxies. The October 3 entry on Microsoft's Digital Defense Report covered exploits arriving in under a day in general; this is a concrete case where the trigger was not the patch but the explanation.
Google pauses part of its open-source bounty
On the other side, Google's Vulnerability Reward Program posted that it is "temporarily no longer accepting OSS VRP product vulnerability submissions," effective October 1. "This does not impact OSS VRP supply chain reports, or any outstanding reports." Coverage by Tom's Hardware and Hardware Busters attributes the pause to a flood of AI-generated reports, most of them invalid -- hallucinated trigger conditions or bugs with no security impact -- and says Google promised an update by the first quarter of 2027. Some Google Cloud repositories can still be reported through the Cloud VRP. Hardware Busters notes the curl project had already ended its bounty for the same reason.
Analysis: the difference between the two is verification. Horizon3's pipeline runs a second agent to check each claim and ends with a working exploit; the reports flooding Google mostly stopped at a plausible description. For security teams, the practical lessons are to patch on the CVE, not on the write-up -- HFS users had over two months -- and to assume that a public technical explanation now shortens time-to-exploit to about a day. For anyone running a bounty or an internal bug intake, requiring a working reproducer before triage is the cheapest filter against volume without evidence.
Horizon3's Mythos pipeline found, verified and weaponized a Rejetto HFS flaw that attackers exploited the day after the September 30 write-up, while Google paused open-source product-bug submissions on October 1 because unverified AI reports swamped triage -- the gap between useful and useless AI bug-hunting is a verification step.
Sources
- Horizon3's Tales from the Trenches: Anthropic's Mythos and Rejetto HFS (Horizon3)
- Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows (The Register)
- CVE-2026-61500 (OSV)
- Google VRP: PSA for open-source bug hunters (X)
- Google Pauses Its Open-Source Bug Bounty for Product Flaws as AI Slop Buries Maintainers (Hardware Busters)
- Google suspends part of the OSS VRP bug bounty program due to an influx of invalid AI submissions (Tom's Hardware)