Listen to this Post

A New Chapter in AI-Powered Security Research
Artificial intelligence has already changed how defenders search for vulnerabilities, analyze malware, write security tools, and automate penetration testing. But a more unsettling question is now emerging: Can AI actually discover attack techniques that humans have not taught it?
At Black Hat USA 2026, that question moved from theory to a remarkable real-world experiment.
James Kettle, director of research at PortSwigger and a longtime researcher of HTTP request smuggling, developed an open-source system originally called the “Desync Machine.” The project eventually earned a much more intimidating name: HTTP Terminator.
The name was not chosen because the tool was designed to behave like a science-fiction robot. It came from what Kettle observed while developing it. The system could independently experiment with HTTP request-smuggling techniques, learn from successful results, and use those discoveries to generate new attack ideas against additional targets.
Most importantly, the system reportedly discovered novel HTTP desynchronization techniques and successfully exploited live websites, including multiple financial-sector organizations during authorized research.
That makes this story about much more than another AI cybersecurity tool. It is about what happens when an AI system is given enough autonomy to explore an attack methodology rather than simply execute a list of predefined tests.
The Experiment Behind HTTP Terminator
Kettle’s central research question was straightforward but ambitious: Can an AI system conduct genuinely original security research?
AI models have become surprisingly capable at identifying known vulnerabilities. They can read source code, reason about attack surfaces, generate proof-of-concept code, analyze logs, and suggest exploitation paths.
But discovering something genuinely new is different.
Novel security research requires experimentation, hypothesis generation, failure analysis, adaptation, and the ability to recognize when an unexpected result is actually important.
Kettle wanted to push AI toward that territory.
Rather than simply asking an AI model to scan websites for known vulnerabilities, he built an autonomous workflow focused specifically on HTTP request smuggling and desynchronization attacks.
Why HTTP Request Smuggling Matters
HTTP request smuggling occurs when different components in a web infrastructure disagree about how HTTP requests should be interpreted.
A modern website may involve browsers, CDNs, load balancers, reverse proxies, web application firewalls, API gateways, and backend servers.
If two components parse the same sequence of HTTP data differently, an attacker may be able to manipulate the boundary between requests.
That can create consequences ranging from request routing problems to cache poisoning, authentication attacks, internal access, or compromise of applications behind the vulnerable infrastructure.
The difficulty is that these attacks frequently depend on subtle implementation differences.
That makes HTTP desynchronization an interesting target for AI-assisted research.
From “Desync Machine” to “HTTP Terminator”
Kettle initially intended to call the project the Desync Machine.
Then the system began demonstrating behavior that made the original name feel insufficient.
The AI was not simply following a predictable sequence of instructions. It could generate ideas, test them, examine the results, and use successful discoveries as inspiration for further experimentation.
The feedback loop became one of the most important parts of the research.
When the system discovered a technique that worked against one target, it could analyze the successful result and use the information to formulate additional techniques.
That creates something very different from a traditional vulnerability scanner.
The AI Was Capable of Discovering New Techniques
According to Kettle, the HTTP Terminator autonomously developed multiple novel request-smuggling techniques.
The important word here is novel.
The system was not merely reproducing a database of known CVEs or executing a fixed collection of security checks.
Instead, it was operating within a methodology that Kettle had developed through years of research and using AI experimentation to explore possibilities within that methodology.
The result demonstrated that AI
🕵️📝Let’s dive deep and fact‑check.
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
References:
Reported By: www.darkreading.com
Extra Source Hub (Possible Sources for article):
https://www.reddit.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube




