AI-Driven HTTP Terminator Exposes Desync Tricks and Apache Zero-Day

PortSwigger's AI-assisted HTTP Terminator independently generated and validated new HTTP desynchronization techniques after testing 30,000 candidate vectors, including a dangling-byte method that stabilizes response queue poisoning; a human-guided cascade uncovered an Apache Traffic Server zero-day (CVE-2026-63078) with patch status unclear. The researchers scanned 30,000 authorized sites and found about 700 vulnerable targets—ranging from banks to government infrastructure—before deeper validation. They also reported a Shared-Parser Confusion concept and recommended mitigations such as avoiding HTTP/1.1 upstream or restricting bodies in allowed methods. The work highlights autonomous AI discovery with human input for the Apache bug and ongoing model evaluations.
- AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day The Hacker News
- The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop WIRED
- Can AI do novel security research? Meet the HTTP Terminator PortSwigger
- Black Hat 2026: Autonomous AI Invents Novel Attacks, Hits Banks and Government Tech Times
Reading Insights
0
6
2 min
vs 3 min read
83%
557 → 97 words
Want the full story? Read the original article
Read on The Hacker News