PortSwigger researcher James Kettle said a large language model helped generate novel web attack ideas through an autonomous system called HTTP Terminator, which creates and tests tens of thousands of candidate HTTP desynchronization techniques. The system reportedly surfaced previously unconsidered desync methods, and Kettle described a workflow focused on validating machine-generated findings, filtering false positives, and using unexpected results to drive further research rather than treating AI as fully autonomous offensive tooling.
The work aligns with Kettle’s broader campaign against legacy HTTP parsing behavior, including his argument that HTTP/1.1 remains a root cause of request smuggling and desynchronization risk. By combining large-scale automated hypothesis generation with practical testing against HTTP parsing edge cases, the research highlights how AI can accelerate discovery of exploitable protocol ambiguities while reinforcing the need for defenders to reduce exposure to desync-prone architectures and outdated protocol handling.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
A Risky Business Features podcast episode discussed James Kettle's use of an autonomous system called the HTTP Terminator to generate and test tens of thousands of HTTP desynchronization techniques. The episode summary says the system had already found new desync methods Kettle had not previously considered.
w4ke.info published the article 'Funky chunks - addendum: a few more dirty tricks.' Based on the provided reference, this is a separate technical write-up related to the story and represents an additional public disclosure.
PortSwigger Research published the article 'HTTP/1.1 must die: the desync endgame,' documenting James Kettle's HTTP desynchronization research. The reference provides the publication date but no additional event details beyond the publication itself.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
risky.biz
Open sourcew4ke.info
Open sourceportswigger.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.