PortSwigger, the security firm behind the Burp Suite testing tools, says its autonomous AI research system HTTP Terminator has discovered novel HTTP desync attack techniques — and exposed a zero-day vulnerability in Apache Traffic Server. The project's lead, researcher James Kettle, frames the result as the first case of an AI producing genuinely novel security research rather than re-applying known bug classes.
HTTP Terminator generated roughly 30,000 candidate desync vectors and tested them against about 30,000 websites where scanning was authorized through bug bounty or vulnerability disclosure programs. It found around 700 vulnerable live targets, including banks, government infrastructure, security products and an airport. The AI surfaced entirely new attack classes — among them a dual-matching Content-Length pattern, a 'dangling-byte' technique enabling more reliable response queue poisoning, and shared-parser confusion.
A human-guided follow-up cascade built on the AI's findings also uncovered an Apache Traffic Server zero-day, underscoring how the machine-generated attack surface can be extended by researchers. Security vendors including Imperva have already said their products mitigate the newly described patterns.
Kettle argues the milestone matters because AI has mostly been used to automate known attacks; HTTP Terminator instead generated attacks no human had previously documented. The findings were disclosed responsibly, with fixes and mitigations coordinated before publication.




