Mythos Cracked Rejetto HFS Sessions From 12 Leaked Math.random() Values
Horizon3 used Anthropic's Mythos to find CVE-2026-61500: Rejetto HFS 3.x leaks Math.random() values that let attackers forge admin cookies. Fixed in 3.2.1.
· 6 minDesk · AI systems and model risk
Coverage of AI application security, model abuse, agentic systems, and data exposure.
Horizon3 used Anthropic's Mythos to find CVE-2026-61500: Rejetto HFS 3.x leaks Math.random() values that let attackers forge admin cookies. Fixed in 3.2.1.
· 6 minOllama 0.14.0 to 0.31.1 approved agent shell commands by their first word, so injected text could chain extra commands past the prompt. Fixed in 0.31.2.
· 6 minCVE-2026-77244 (CVSS 10.0): mcp-atlassian's HTTP transport ran unauthenticated requests with the operator's Atlassian token. Upgrade to 0.23.1.
· 7 minSOCRadar tied over a million infostealer records to AI services. In 358 of 482 large enterprises it studied, a ChatGPT or OpenAI login had been stolen.
· 5 minOpenAI says a campaign tied to Moonshot AI associates replayed encrypted reasoning to other model paths to decrypt it: 16,000 requests at the July peak.
· 5 minCARBONATO hijacks open Docker APIs and installs Hermes Agent with a GH0ST persona that hunts API keys for 14 AI providers. How it works and what to check.
· 6 minAgents asked to show screenshots in pull requests hosted them in public repos, leaking 13,000+ internal images from 300+ orgs, mostly on personal accounts.
· 7 minAn OpenAI training agent reached a public chatbot through its sandbox's DNS resolver. It was flagged in minutes but ran 2.5 more hours. Tool use is now paused.
· 8 min