The HFS bug was public for 11 weeks. The write-up got it exploited in a day.

The Rejetto HFS flaw was described in a public CVE in July and nobody reported exploiting it. A detailed walkthrough went up on 30 September. Attacks started the next day.

Share
An open padlock surrounded by scattered black computer keyboard keys under red and green light
Photo by FlyD on Unsplash

On Wednesday, 30 September, Zach Hanley of the security firm Horizon3 published a detailed write-up of a flaw in Rejetto HFS, a small open source file server. Its researchers had found it with Anthropic's Mythos model. Horizon3 says "Mythos identified the insecure PRNG usage to sign the keys as well as a way to leak other numbers from the same PRNG stream." The post came with exploit steps and a video of the full attack.

The next day, VulnCheck's canaries saw attackers using it. The Register quoted VulnCheck researcher Patrick Garrity: "Our canaries detected an actor in China targeting real vulnerable hosts in the US."

My first reaction was the obvious headline: AI finds the bug, attackers move in a day, this is what the AI era looks like. Then I looked at when the bug actually became public, and it doesn't fit.

Timeline: CVE-2026-61500 public on 13 July with no reported exploitation for 11 weeks, walkthrough published 30 September, exploited 1 October
The advisory sat public for eleven weeks. The walkthrough was used within a day. Sources: OSV, Horizon3, VulnCheck via The Register.

When did CVE-2026-61500 become public?

On 13 July. The OSV record for CVE-2026-61500 was published that day, rated critical, with a fix in version 3.2.1. The description isn't vague. It says HFS derives its session signing key from Math.random(), that the same generator's output is exposed to anyone attempting a login, and that an attacker can rebuild the generator's state, recover the key and forge an admin session.

That is the whole bug, in plain words, in a public database, for eleven weeks. As far as I can find, nobody reported exploiting it in that time. WindowsForum's timeline notes that CISA's July enrichment entry recorded "Exploitation: none". The attacks begin the day after the walkthrough.

So the question I'm left with isn't how fast AI makes attackers. It's what the attackers were waiting for.

What changed on 30 September?

Not the knowledge that the bug existed. The knowledge of how to do it. Knowing that a random number generator is predictable is one thing. Knowing which responses leak its output, how many you need, and how to feed them to a solver (Horizon3 used Z3) to get the key back is the work. The July advisory left that work to the reader. The September post did it for them.

There's a real case for publishing the method. Defenders need to understand it, and the patch had been out for months. The point isn't that Horizon3 did something wrong. It's that the useful measure of exposure is the time from walkthrough to patch, and here, for anyone still on 3.2.0, that time was zero. VulnCheck counted roughly 100 internet facing HFS servers.

Biology already had this argument

The cross that helped me is from 2011. Two labs had shown how H5N1 bird flu could become transmissible between mammals, and the papers were headed for Science and Nature. On 20 December 2011 the US National Science Advisory Board for Biosecurity recommended that "the general conclusions highlighting the novel outcome be published, but that the manuscripts not include the methodological and other details that could enable replication of the experiments by those who would seek to do harm."

That is the same split: publish the what, hold the how. Three months later, on 30 March 2012, the board reversed and backed full publication of revised versions. Its reasoning was that the data didn't "appear to provide information that would immediately enable misuse."

The word that does the work there is "immediately". The biologists accepted that conclusions and methods carry different risk, and made the decision on whether the methods were an immediate recipe. In security that test is nearly always failed by a good write-up, because a good write-up is supposed to be a recipe. The HFS timeline is close to a controlled demonstration: the conclusion sat public for eleven weeks, and the recipe was used within a day.

Where AI does come in is the other end. If tools like Mythos make the finding cheap, more bugs will have both an advisory and a walkthrough, and the gap between them is where defenders live. I wrote about AI built malware that votes across four models, and about sandboxes that held while the attack went between them. This one is less dramatic and, I think, more useful: patch on the advisory, because the walkthrough won't wait for you.

What I'm confident of, and what I'm not

The dates are established: OSV for 13 July, Horizon3 for 30 September, VulnCheck as reported for 1 October. That nobody exploited it before the write-up is inferred from the absence of reports, which is not proof. Whether this holds as a pattern across many bugs, and how much AI tools will shorten the gap, is still a guess.

The claim, in one sentence: a vulnerability advisory tells attackers what is broken and a walkthrough tells them how, and the clock that matters for defenders starts with the walkthrough, not the CVE.

Sources

Horizon3.ai, "Anthropic Mythos Finds Rejetto HFS RCE", 30 September 2026. https://horizon3.ai/attack-research/disclosures/anthropic-mythos-rejetto-hfs-rce/

OSV, CVE-2026-61500. https://osv.dev/vulnerability/CVE-2026-61500

The Register, "Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows", 3 October 2026. https://www.theregister.com/security/2026/10/03/anthropics-super-bug-hunting-model-mythos-is-hardcore-good-at-math-as-latest-vuln-under-attack-shows/5300933

WindowsForum, "CVE-2026-61500: Attackers Exploit Rejetto HFS Session Forgery RCE", October 2026 (VulnCheck timeline and host count). https://windowsforum.com/news/cve-2026-61500-attackers-exploit-rejetto-hfs-session-forgery-rce-upgrade-to-3-2-1.447112/

CIDRAP, "US government urges journals to omit details of two H5N1 studies", 20 December 2011. https://www.cidrap.umn.edu/avian-influenza-bird-flu/us-government-urges-journals-omit-details-two-h5n1-studies

CIDRAP, "NSABB reverses recommendation on H5N1 studies", 30 March 2012. https://www.cidrap.umn.edu/avian-influenza-bird-flu/nsabb-reverses-recommendation-h5n1-studies