Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Seatrium picks up 9th FSRU conversion job with Karpowership

    October 5, 2026

    Did Russian oligarch close to Putin fund part of Donald Trump Jr.’s wedding?

    October 5, 2026

    Accept ‘bad things’ in return for benefits of AI, says Sam Altman | OpenAI

    October 5, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Seatrium picks up 9th FSRU conversion job with Karpowership
    • Did Russian oligarch close to Putin fund part of Donald Trump Jr.’s wedding?
    • Accept ‘bad things’ in return for benefits of AI, says Sam Altman | OpenAI
    • The Interview – Olara Otunnu, diplomat: UN cannot be diplomatic ivory tower
    • Best Power Banks (2026): My Picks After Testing Over 100
    • Exploitation Hits Rejetto HFS Vulnerability Discovered by AI 
    • US payroll revision turns July job gain into a loss
    • ‘There could be local extinction’: The fight to protect Indonesia’s orangutans as El Niño fuels fires
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, October 5
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Exploitation Hits Rejetto HFS Vulnerability Discovered by AI 

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 5, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Threat actors are exploiting a critical vulnerability in Rejetto HTTP File Server (HFS) to bypass authentication and gain remote code execution (RCE), VulnCheck warns.

    Tracked as CVE-2026-61500 (CVSS score of 9.3), the flaw exists because the open source file server discloses outputs of its non-cryptographic session cookie generator to unauthenticated clients during login. It also derives the session-cookie signing key from the same generator.

    The sensitive information leak allows an attacker to reconstruct the generator’s state and recover the signing key using a small set of collected login responses.

    Using the recovered key, the attacker can then forge valid administrator session cookies to gain elevated access to the server and RCE via the server_code configuration feature.

    The issue was that Rejetto HFS’s generator, Math.random(), was using the xorshift128+ algorithm to generate the ‘random’ value that was then passed to the server’s Node.js web framework Koa for signing session cookies.  

    Because the algorithm’s outputs are reversible, an attacker able to collect other numbers generated by Math.random() could determine other generated numbers and forge the authentication cookies, cybersecurity firm Horizon3 explained in a technical report.

    Advertisement. Scroll to continue reading.

    Horizon3.ai researchers uncovered the flaw using Anthropic’s Mythos AI model, which used advanced mathematical reasoning to recognize that Math.random() PRNG outputs could be reversed to reconstruct the secret session-cookie signing key.

    The security firm discovered the weakness in June, and Rejetto HFS version 3.2.1 was released on July 13 with the necessary patches. 

    “Multiple security vulnerabilities have been found in all previous versions, potentially allowing an attacker to gain administrative access to HFS,” Rejetto noted in its advisory.

    On October 2, VulnCheck warned that hackers have begun targeting CVE-2026-61500 as part of small-scale reconnaissance originating from a China Telecom IP. The attempts hit canaries in Japan and the US.

    Related: Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

    Related: Fortra Patches Critical Vulnerabilities in BoKS

    Related: Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks

    Related: Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action

    discovered exploitation HFS hits Rejetto Vulnerability
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

    Google halts open-source bug bounty program amid AI spam surge

    Alleged ShinyHunters Leader Arrested in Jordan

    Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

    Citrix patches NetScaler SAML zero-day exploited in attacks

    Nvidia Hits Record High as Market Value Reaches $5.7 Trillion

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Seatrium picks up 9th FSRU conversion job with Karpowership

    October 5, 2026

    Did Russian oligarch close to Putin fund part of Donald Trump Jr.’s wedding?

    October 5, 2026

    Accept ‘bad things’ in return for benefits of AI, says Sam Altman | OpenAI

    October 5, 2026

    The Interview – Olara Otunnu, diplomat: UN cannot be diplomatic ivory tower

    October 5, 2026
    Latest Posts

    Bald Range Wildfire Forces Evacuation of 18,000 in British Columbia

    August 9, 2026

    Amazon deforestation alerts fall to lowest level since 2013, Brazilian data show

    August 9, 2026

    Institutional bear market: Why Bitcoin’s downturn is different

    August 9, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Seatrium picks up 9th FSRU conversion job with Karpowership

    October 5, 2026

    Did Russian oligarch close to Putin fund part of Donald Trump Jr.’s wedding?

    October 5, 2026

    Accept ‘bad things’ in return for benefits of AI, says Sam Altman | OpenAI

    October 5, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.