PortSwigger researcher James Kettle walked off the Black Hat 2026 stage having demonstrated something most security teams assumed was years away: an AI system that does not find known bugs — it invents new attack techniques, then proves them against live targets. HTTP Terminator generated 30,000 attack vectors from 138 protocol RFCs, hit 700+ authorized sites across banking, government, and critical infrastructure, and uncovered a zero-day in Apache Traffic Server. PortSwigger open-sourced it the same week. A New Kind of Desync Attack HTTP desync attacks — also called request smuggling — exploit disagreements between how a front-end proxy and a […]
The post