Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws

    October 5, 2026

    Google DeepMind Gives AI-Designed Proteins a Watermark

    October 5, 2026

    I tested Noble’s elite triple-driver wireless headphones and they offer some of the most hypnotic, spacious sound I’ve ever heard — if you can afford them

    October 5, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Exploitation Hits Rejetto HFS Vulnerability Discovered by AI 
    Exploitation Hits Rejetto HFS Vulnerability Discovered by AI 
    Cybersecurity

    Exploitation Hits Rejetto HFS Vulnerability Discovered by AI 

    The Tech GuyBy The Tech GuyOctober 5, 2026No Comments2 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    Threat actors are exploiting a critical vulnerability in Rejetto HTTP File Server (HFS) to bypass authentication and gain remote code execution (RCE), VulnCheck warns.

    Advertisement

    Tracked as CVE-2026-61500 (CVSS score of 9.3), the flaw exists because the open source file server discloses outputs of its non-cryptographic session cookie generator to unauthenticated clients during login. It also derives the session-cookie signing key from the same generator.

    The sensitive information leak allows an attacker to reconstruct the generator’s state and recover the signing key using a small set of collected login responses.

    Using the recovered key, the attacker can then forge valid administrator session cookies to gain elevated access to the server and RCE via the server_code configuration feature.

    The issue was that Rejetto HFS’s generator, Math.random(), was using the xorshift128+ algorithm to generate the ‘random’ value that was then passed to the server’s Node.js web framework Koa for signing session cookies.  

    Because the algorithm’s outputs are reversible, an attacker able to collect other numbers generated by Math.random() could determine other generated numbers and forge the authentication cookies, cybersecurity firm Horizon3 explained in a technical report.

    Advertisement. Scroll to continue reading.

    Horizon3.ai researchers uncovered the flaw using Anthropic’s Mythos AI model, which used advanced mathematical reasoning to recognize that Math.random() PRNG outputs could be reversed to reconstruct the secret session-cookie signing key.

    The security firm discovered the weakness in June, and Rejetto HFS version 3.2.1 was released on July 13 with the necessary patches. 

    “Multiple security vulnerabilities have been found in all previous versions, potentially allowing an attacker to gain administrative access to HFS,” Rejetto noted in its advisory.

    On October 2, VulnCheck warned that hackers have begun targeting CVE-2026-61500 as part of small-scale reconnaissance originating from a China Telecom IP. The attempts hit canaries in Japan and the US.

    Related: Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

    Related: Fortra Patches Critical Vulnerabilities in BoKS

    Related: Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks

    Related: Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws

    October 5, 2026

    Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports

    October 5, 2026

    Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

    October 5, 2026

    Trump Names National Intelligence Director Jay Clayton to Lead a New Federal AI Task Force

    October 4, 2026

    Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action

    October 4, 2026

    AI Agents Aimed SQL Injection at US and Canadian Government Sites

    October 4, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026392 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026211 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202517 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws

    October 5, 2026

    Google DeepMind Gives AI-Designed Proteins a Watermark

    October 5, 2026

    I tested Noble’s elite triple-driver wireless headphones and they offer some of the most hypnotic, spacious sound I’ve ever heard — if you can afford them

    October 5, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.