TechNewsReel
Live

PortSwigger's HTTP Terminator Uses AI to Invent Novel Web Attack Techniques

A new autonomous research system demonstrates that AI can move beyond pattern matching to create original protocol-level exploits.

TechNewsReel Newsroom · August 7, 2026

James Kettle of PortSwigger has developed "HTTP Terminator," an AI-assisted research system capable of autonomously inventing and proving new HTTP desynchronization attack techniques. The project marks a significant shift in cybersecurity research, moving from manual vulnerability discovery to an automated system that can identify and exploit flaws in live web infrastructure.

According to PortSwigger, the system was tested on live websites that maintain authorized bug bounty programs or Vulnerability Disclosure Policies (VDPs). The research proved successful, resulting in the compromise of high-value targets, including government infrastructure and banking institutions. The system operates by autonomously generating attack vectors and verifying their effectiveness against real-world targets at scale.

The Mechanics of Desync

HTTP desynchronization, or "desync," occurs when a front-end proxy and a back-end server disagree on the boundaries of an HTTP request. This discrepancy allows an attacker to "smuggle" a second, hidden request inside the first, potentially bypassing security controls or hijacking other users' sessions. While James Kettle has spent a decade researching these vulnerabilities manually, HTTP Terminator represents an evolution toward AI-driven discovery, removing the human bottleneck from the invention of new exploit methodologies.

Implications for Global Infrastructure

This research demonstrates that AI is capable of more than simply finding known bug patterns; it can now invent entirely novel attack methodologies. The ability to automate the discovery of complex protocol-level vulnerabilities significantly increases the risk to global web infrastructure. By enabling the rapid identification of zero-day vulnerabilities across thousands of targets, the barrier to executing sophisticated, large-scale attacks has been lowered.

The Future of Autonomous Research

As AI systems become more adept at protocol analysis, the window between the discovery of a vulnerability and its widespread exploitation is likely to shrink. "Can an autonomous system invent new attack techniques, and use them to hack live websites at scale? Building this sounded like a bad idea, so I did it," Kettle stated regarding the project's inception. The industry must now consider how to defend against an adversary that can iterate and evolve its attack strategies faster than human researchers can patch them.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.