hacker-news · Crawled Oct 5, 2026

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

1 IoCs 1 Malware 1 CVEs
Read original article ↗

AI Summary

A critical vulnerability, CVE-2026-61500, in Rejetto HTTP File Server (HFS) versions 3.0.0 through 3.2.0 is under active exploitation, enabling attackers to forge administrator session cookies and achieve remote code execution. The flaw stems from the use of a predictable pseudo-random number generator (Math.random()) for session-cookie signing keys, which can be reconstructed by unauthenticated attackers through login responses. A proof-of-concept exploit was publicly released by researcher Alejandro Ramos (aramosf), and exploitation attempts have been observed, including by an unnamed threat actor based in China targeting U.S. systems. The vulnerability follows previous exploitation of another Rejetto HFS flaw, CVE-2024-23692, which was used to deploy cryptocurrency miners and malware such as HATVIBE.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 1 extracted

Type Value Detail
GitHub User aramosf Details →

MITRE ATT&CK TTPs 7 techniques