AI Weekly Malaysia

Summaries

Short AI and tech summaries with source links, signal scores, and why each update matters for builders, founders, and Malaysian tech workers.

Reset

Showing 1-1 of 1 results

DateProviderScoreSummary
05 Oct 2026, 4:09 PMThe Hacker News6.0 Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

CVE-2026-61500 (CVSS 9.3) affects Rejetto HFS 3.0.0 through 3.2.0: the server derived its session-cookie signing key from JavaScript's non-cryptographic Math.random() and leaked outputs of the same V8 PRNG to unauthenticated clients during the SRP login handshake, letting an attacker reconstruct the generator state, recover the signing key, forge an admin cookie, and reach remote code execution through the server_code configuration feature. A patch shipped in July 2026 as version 3.2.1, but a public Python PoC by Alejandro Ramos (aramosf) landed in late September, and VulnCheck's Patrick Garrity says exploitation attempts were detected on October 1, 2026 — one day after Horizon3.ai published more detail. Horizon3.ai researcher Zach Hanley stated that Anthropic's Mythos model was used to discover the flaw.

Why: The direct action item is narrow: if you self-host Rejetto HFS, anything in 3.0.0–3.2.0 is exploitable in the wild as of October 1, 2026 and needs to be on 3.2.1. The broader lesson is worth more — session-signing keys and tokens generated with Math.random() (or any non-CSPRNG) are recoverable from observed outputs, and this is exactly the pattern AI coding assistants emit by default when you ask for a session or token helper, so check any JS/Node auth code you or a vibe-coded tool generated.

Top