Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Russian forces kill several in Ukraine, launch ‘brutal’ attack in Odesa | Russia-Ukraine war News

    August 9, 2026

    A Democratic Socialist Spreads the Word, Even in Hostile Territory

    August 9, 2026

    Britain is paying the price for failing to invest in its young people | Richard Partington

    August 9, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Russian forces kill several in Ukraine, launch ‘brutal’ attack in Odesa | Russia-Ukraine war News
    • A Democratic Socialist Spreads the Word, Even in Hostile Territory
    • Britain is paying the price for failing to invest in its young people | Richard Partington
    • What do cybersecurity leaders want in staff? These 3 skills beat certifications and experience
    • Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
    • BIP-110 Chain Falls Behind as Hashpower Support Lags
    • Inside the War on Hezbollah’s Finances
    • Andy Burnham to tour Britain in effort to reconnect government with public | Andy Burnham
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Sunday, August 9
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 9, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalAug 07, 2026Web Security / Vulnerability

    PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate desync vectors.

    PortSwigger said a separate human-guided discovery cascade also exposed a zero-day in Apache Traffic Server. Kettle said HTTP Terminator tested 30,000 websites where scanning was authorized through bug bounty or vulnerability disclosure programs and found roughly 700 vulnerable targets before deeper validation and RQP research.

    Kettle said those findings involved banks, government infrastructure, security products, and an airport.

    The research produced new desync triggers, a dual-matching Content-Length pattern, and a “dangling-byte” technique designed to make response queue poisoning (RQP) more reliable. RQP can potentially make a front end lose track of which back-end response belongs to which user, potentially exposing another user’s response, including session cookies or API keys.

    Cybersecurity

    The researchers also disclosed Shared-Parser Confusion, a broader attack concept that the system proposed but Kettle validated. The defense has not changed: PortSwigger recommends avoiding HTTP/1.1 upstream. Where HTTP/1.1 cannot be removed, it recommends allow-listing methods at both layers and restricting which methods may carry request bodies.

    In the technical write-up, Kettle said he fed HTTP Terminator 138 HTTP and SMTP RFCs. Those RFCs were split into about 15,000 small fragments and used as inspiration to generate 30,000 unique candidate vectors.

    One Content-Type: multipart/byteranges technique worked across multiple server implementations and exposed more than 200 websites in the test set, including an unnamed U.S. bank.

    The autonomous research then tested 16 ideas for improving RQP. Only the dangling-byte technique survived evaluation. It leaves a smuggled request one byte short so the second back-end response is not produced until a victim request supplies the missing byte, eliminating a race condition that otherwise makes RQP unreliable on many sites.

    In the human-guided cascade, a malformed request eventually exposed the desynchronization zero-day in Apache Traffic Server. The researchers said the issue has since been patched and tracked as CVE-2026-63078.

    An August 7 check by The Hacker News did not find a public record for CVE-2026-63078 in CVE.org or NVD, and Apache’s July advisory covering 34 flaws did not list it. That leaves a verification gap around the Apache case: the cited public records do not yet let defenders map CVE-2026-63078 to a specific fixed Traffic Server release.

    Kettle said Shared-Parser Confusion emerged when HTTP Terminator noticed that response-processing rules could be misapplied to requests when servers reuse parsing logic. The system proposed the concept, but Kettle, director of research at PortSwigger, validated and generalized it. “Neither of us would have discovered it alone,” he said.

    That distinction defines the autonomy boundary in this research: the system generated and proved several techniques without direct human discovery input, while the Apache zero-day and Shared-Parser Confusion still required Kettle’s intervention.

    Cybersecurity

    PortSwigger has open-sourced HTTP Terminator. The paper does not identify which exact model or version generated each autonomous discovery. The released implementation uses Claude for document extraction and test-case generation, while its investigator stage requires Claude Code.

    Separately, researchers behind CRLF-powered desync attacks released public tools for studying that attack class, including crlf-desyncs and crlf-powered-desync-scanner.

    Kettle separately tested newer models on a rediscovery benchmark and reported a 30% success rate for GPT-5.6 Sol when given an inspiration technique.

    AIAssisted Apache Desync finds HTTP Techniques Terminator ZeroDay
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

    Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

    New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables

    18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

    Growing Up The Hard Way

    UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Russian forces kill several in Ukraine, launch ‘brutal’ attack in Odesa | Russia-Ukraine war News

    August 9, 2026

    A Democratic Socialist Spreads the Word, Even in Hostile Territory

    August 9, 2026

    Britain is paying the price for failing to invest in its young people | Richard Partington

    August 9, 2026

    What do cybersecurity leaders want in staff? These 3 skills beat certifications and experience

    August 9, 2026
    Latest Posts

    With Hopes High for New H.I.V. Prevention Pill, Merck Takes Steps to Ensure Access

    July 24, 2026

    Trump to speak at rescheduled White House Correspondents’ Dinner following failed April shooting

    July 24, 2026

    When is an apology not an apology? When it comes from an AI boss with an out-of-control chatbot | Marina Hyde

    July 24, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Russian forces kill several in Ukraine, launch ‘brutal’ attack in Odesa | Russia-Ukraine war News

    August 9, 2026

    A Democratic Socialist Spreads the Word, Even in Hostile Territory

    August 9, 2026

    Britain is paying the price for failing to invest in its young people | Richard Partington

    August 9, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.