Blog.Portswigger HTTP Terminator Reveals New Attack Techniques in Cybersecurity Research
Article Content
- •HTTP Terminator identified 700 vulnerable sites, showcasing a new class of vulnerability.
- •The research demonstrated the critical role of human oversight in AI-driven cybersecurity.
- •James Kettle's work emphasizes the potential for AI to generate new attack techniques.
PortSwigger's HTTP Terminator, developed by James Kettle, identified hundreds of websites vulnerable to HTTP request smuggling, confirming around 700 vulnerable targets. The system autonomously generated and tested 30,000 unique attack vectors, revealing a new vulnerability class called 'shared-parser confusion.' While capable of running autonomously, the research showed that human input significantly enhanced the discovery process. The findings have implications for critical infrastructure, financial institutions, and enterprise products. The research emphasizes the importance of human expertise in AI-driven security research, making the HTTP Terminator's source code available for other researchers. The system's results were presented at Black Hat USA, highlighting the blend of automated and human-guided research.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Continue Reading
SonicWall SMA1000 Faces Critical Zero-Day Exploitation SonicWall disclosed two critical vulnerabilities in its SMA1000 series appliances, CVE-2026-83548 and CVE-2026-83549, which are being actively exploited. CVE-2026-83548 is a pre-authentication server-side request forgery (SSRF) vulnerability rated 10.0 on the CVSS scale, allowing unauthenticated attackers to access…
Critical Zero-Day Vulnerabilities in Citrix NetScaler Under Active Exploitation On September 26, 2026, security firm watchTowr reported two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances, allowing remote code execution (RCE) and actively exploited in the wild. Citrix has confirmed the existence of these vulnerabilities, tracked as CVE-2026-88771 and…