Autonomous AI Security Agent Finds 700 Systemic Vulnerabilities in Banks and Government Infrastructure
An AI-assisted research system named HTTP Terminator has discovered hundreds of vulnerable targets and invented a novel class of cyberattack, proving the power of human-AI collaboration in security.
By Harper Lane
- Security Researchers
- Argue that human-AI collaboration is the future of vulnerability discovery.
- Enterprise Defenders
- Focus on the immediate need to patch newly discovered vulnerabilities and update web application firewalls.
- Compliance & Governance
- Highlight the need for strict guardrails and human approval gates when deploying AI agents.
Why it matters
Until now, the consensus was that AI could only find known vulnerabilities faster, while genuinely new attack techniques required human experts. This breakthrough proves that when human intuition guides AI scale, the combination can invent entirely new classes of vulnerabilities, fundamentally changing how enterprise networks will be defended and tested.
For the past year, the cybersecurity industry has debated a central anxiety: whether autonomous artificial intelligence agents will eventually replace human security researchers, or whether they are too unpredictable to be trusted on live networks. The assumption has been a binary choice between fully autonomous AI and traditional human-led penetration testing. But a new system unveiled at the Black Hat 2026 conference suggests the most powerful approach is neither. Instead, it is a hybrid model where human intuition directs AI scale, a combination that has just successfully hacked hundreds of enterprise targets to prove its point.[3][5]
The system, named HTTP Terminator, was built by James Kettle, the director of research at the security firm PortSwigger. Kettle designed the agent to hunt for HTTP desync attacks—a complex category of vulnerabilities also known as HTTP request smuggling. In these attacks, front-end and back-end servers disagree on where one web request ends and another begins. By exploiting this confusion, an attacker can slip malicious instructions past security filters, potentially hijacking other users' sessions or extracting sensitive data.[1][3]
To build the system, Kettle fed the AI 138 technical specifications and internet standards, breaking them down into 15,000 fragments of inspiration. The HTTP Terminator then autonomously generated 30,000 unique attack vectors. It deployed these mutations against live websites that had explicitly authorized security testing through bug bounty and vulnerability disclosure programs, ensuring the research remained legal and ethical.[2][3]
The results were unprecedented for an AI-assisted tool. The HTTP Terminator identified roughly 700 vulnerable targets across the internet. The compromised systems included major financial institutions, government infrastructure, widely deployed enterprise security products, and an airport. The system successfully executed response queue poisoning, a technique that forces a server to serve one user's private data to a completely different user.[1][2]
The HTTP Terminator identified roughly 700 vulnerable targets across the internet.
But the most significant outcome was not the sheer volume of vulnerabilities found; it was the nature of the discoveries. The HTTP Terminator invented a genuinely new class of vulnerability dubbed "shared-parser confusion." The system noticed that some web servers reuse the same parsing logic for both incoming requests and outgoing responses. By feeding response-specific headers into a request, the AI tricked the servers into exposing new attack surfaces.[2][4]
The discovery of shared-parser confusion shatters a long-held industry assumption. Until now, the defensible position among security experts was that while AI could find known bugs faster than humans, inventing novel attack categories still required human genius. The HTTP Terminator directly challenges that premise, providing documented evidence that an AI system can propose a previously unknown attack vector.[6]
However, Kettle emphasized that the AI did not achieve this entirely on its own. The HTTP Terminator proposed the shared-parser confusion concept, but it required Kettle's expert validation to generalize and prove it. The system operated within strict deterministic code boundaries, with Kettle posing narrow questions, ruling out weak answers, and guiding the "discovery cascade"—the point where one finding becomes the starting point for the next hypothesis.[1][3][5]
This "human-amplified" model is now forcing enterprise security teams to rethink their defensive postures. Web application firewall providers have already begun updating their security engines to block the new desync patterns and shared-parser confusion techniques identified by the research. Defenders can no longer rely on a static list of known request-smuggling payloads, as AI agents can now generate infinite variations.[4]
As PortSwigger open-sources the HTTP Terminator methodology, derivative tools will likely be in production use by both penetration testers and threat actors within the next year. For corporate compliance and governance teams, the immediate challenge is establishing clear rules of engagement. Organizations will need to define strict human approval gates and autonomy boundaries before allowing AI security tools to execute against their live production environments.[2][5][6]
What to know
- PortSwigger researcher James Kettle debuted 'HTTP Terminator,' an AI-assisted system that discovered roughly 700 vulnerable targets.
- The system generated 30,000 unique HTTP desync attack vectors and tested them against live websites authorized through bug bounty programs.
- HTTP Terminator identified a genuinely new vulnerability class dubbed 'shared-parser confusion,' proving AI can invent novel attack techniques.
- The research concluded that the most effective security model is not fully autonomous AI, but a 'human-amplified' approach where experts guide the AI.
Where opinion splits
Security Researchers
Argue that human-AI collaboration is the future of vulnerability discovery.
Researchers emphasize that fully autonomous AI still struggles with the "discovery cascade"—knowing which anomalies are worth pursuing. By combining an AI's ability to read thousands of technical specifications and generate 30,000 test vectors with a human expert's intuition for what looks suspicious, the industry can uncover vulnerabilities that neither would find alone. This hybrid approach acts as a massive amplifier for human expertise.
Enterprise Defenders
Focus on the immediate need to patch newly discovered vulnerabilities and update web application firewalls.
For network defenders, the theoretical debate over AI autonomy is secondary to the practical reality that 700 live systems were exposed. Security vendors stress that traditional protections relying on known payload signatures are no longer sufficient. Firewalls must now account for ambiguous HTTP features, duplicate headers, and unexpected method-and-body combinations that AI agents can exploit at scale.
Compliance & Governance
Highlight the need for strict guardrails and human approval gates when deploying AI agents.
Governance professionals warn that unleashing AI agents against live infrastructure without defined boundaries creates massive liability. They advocate for a "human-amplified" model where deterministic code enforces hard controls on what the AI can act on independently, ensuring that compliance teams have documented scope limits before any automated scanning begins.
Sources
[1]CSO OnlineEnterprise DefendersAI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques
Read on CSO Online →
[2]The Hacker NewsCompliance & GovernancePortSwigger's HTTP Terminator Uncovers 700 Vulnerable Targets
Read on The Hacker News →
[3]PortSwiggerSecurity ResearchersThe future of AI security research isn't autonomous, it's human-amplified
Read on PortSwigger →
[4]ImpervaEnterprise DefendersMitigating Shared-Parser Confusion and HTTP Terminator Findings
Read on Imperva →
[5]AI GovernanceCompliance & GovernanceHuman-Amplified AI Security Tools Reshape Enterprise Red-Teaming
Read on AI Governance →
[6]Infosec.geSecurity ResearchersHTTP Terminator Invents Novel Attack Categories at Black Hat 2026
Read on Infosec.ge →
Comments
Every angle. Every day.
Get ai stories with full source coverage and perspective breakdowns delivered to your inbox.
