← Back to feed
AI SecurityEmerging1 sourceAug 11, 2026 · 02:18via CSO Online

The future of AI security research isn’t autonomous, it’s human-amplified

Brief

Meet HTTP Terminator, a new AI system that has identified hundreds of websites vulnerable to HTTP request smuggling, hacked them live at scale, and even identified a “genuinely new class” of vulnerability, dubbed “shared-parser confusion.”

But it didn’t do it alone; it was guided by a human the entire time, which may be the most interesting finding of all.

A researcher from security company PortSwigger used his own processes to design and build the AI, HTTP Terminator, posed narrow, high-value questions, ruled out weak answers, applied anomaly-detection logic, used deterministic code to restrict agent behavior, and applied findings to subsequent ‘cascade’ research.

“This inverts the accepted narrative by showing an expert can be a massive amplifier for an AI research system,” James Kettle , PortSwigger’s director of research, explained in a white paper .

Read more on CSO Online