PortSwigger Unveils AI System for Autonomous Vulnerability Research
PortSwigger Research Director James Kettle unveiled HTTP Terminator in August 2025, applying generative AI to autonomous security research. The system uses AI reasoning to formulate attack hypotheses around complex HTTP behavior, an area where subtle differences between servers and intermediaries can create exploitable weaknesses. Its significance lies in moving AI beyond code assistance toward the discovery of previously unknown attack techniques and software flaws.
HTTP Terminator sends AI-generated hypotheses to automated programs for testing and validation, rather than treating model output as proof of a vulnerability. PortSwigger said the system uncovered several forms of HTTP request desynchronization attacks and identified a zero-day flaw in the Apache Software Foundation’s Apache Traffic Server. The findings offer a practical demonstration of AI-led vulnerability research while retaining deterministic testing as the final check.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.