Security 2026-10-05

A Mythos-Found Bug Was Exploited the Day After Its Write-Up -- the Same Week Google Stopped Taking AI-Flooded Open-Source Bug Reports

Horizon3 published how Anthropic's Mythos found and weaponized CVE-2026-61500 in Rejetto HFS on September 30; VulnCheck saw exploitation from a China-based actor the next evening. On October 1, Google paused product-vulnerability submissions to its open-source bug bounty because most automated reports were invalid. AI bug-finding is getting better and worse at once.

Two events in the same week show both sides of AI-assisted vulnerability research.

Horizon3 and Mythos: an enterprise example

On September 30, 2026, Zach Hanley of the pen-testing company Horizon3 published a write-up of CVE-2026-61500, a critical (CVSS 9.3) session-forgery flaw in the open-source Rejetto HTTP File Server, versions 3.0.0 to 3.2.0. Horizon3 says it has used Anthropic's Mythos model in its vulnerability-research pipelines since joining Anthropic's Project Glasswing in July.

  • Workflow: Horizon3's harness "spawns many specialized agents in parallel to look for specific vulnerability classes across a code base." A cryptographic-weakness agent driven by Mythos flagged the bug; a second, verifying agent re-read the code and confirmed it as a true positive; Mythos then wrote a working proof-of-concept exploit, including a Z3 solver, and demonstrated command execution.
  • The flaw: HFS built its cookie-signing key from JavaScript's Math.random(), which in V8 is a reversible generator, and separately leaked raw outputs of the same generator to anyone starting a login. Collect a few, recover the generator's state, recover the key, and forge an administrator cookie -- then use HFS's admin feature that runs custom JavaScript. Hanley: "Mythos didn't just flag the insecure PRNG in isolation -- it simultaneously identified that the application leaked raw Math.random() outputs."
  • Systems and data touched: the source code of a third-party open-source project, analyzed in Horizon3's own pipeline, with findings handed to the maintainer and to VulnCheck as the CVE assigner.

The adoption constraint is the disclosure window. The CVE record and the fix (HFS 3.2.1) date from July 13, according to OSV. But the detailed write-up turned it into a recipe: VulnCheck's Patrick Garrity told The Register "we started detecting exploitation of CVE-2026-61500 in Rejetto HFS this evening" on the Thursday after publication, from an actor in China targeting hosts in the US, followed the next day by hits through US proxies. The October 3 entry on Microsoft's Digital Defense Report covered exploits arriving in under a day in general; this is a concrete case where the trigger was not the patch but the explanation.

Google pauses part of its open-source bounty

On the other side, Google's Vulnerability Reward Program posted that it is "temporarily no longer accepting OSS VRP product vulnerability submissions," effective October 1. "This does not impact OSS VRP supply chain reports, or any outstanding reports." Coverage by Tom's Hardware and Hardware Busters attributes the pause to a flood of AI-generated reports, most of them invalid -- hallucinated trigger conditions or bugs with no security impact -- and says Google promised an update by the first quarter of 2027. Some Google Cloud repositories can still be reported through the Cloud VRP. Hardware Busters notes the curl project had already ended its bounty for the same reason.

Analysis: the difference between the two is verification. Horizon3's pipeline runs a second agent to check each claim and ends with a working exploit; the reports flooding Google mostly stopped at a plausible description. For security teams, the practical lessons are to patch on the CVE, not on the write-up -- HFS users had over two months -- and to assume that a public technical explanation now shortens time-to-exploit to about a day. For anyone running a bounty or an internal bug intake, requiring a working reproducer before triage is the cheapest filter against volume without evidence.

Horizon3's Mythos pipeline found, verified and weaponized a Rejetto HFS flaw that attackers exploited the day after the September 30 write-up, while Google paused open-source product-bug submissions on October 1 because unverified AI reports swamped triage -- the gap between useful and useless AI bug-hunting is a verification step.