Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AI Tool Uncovers New HTTP Desync Methods and Apache Flaw

AI Tool Uncovers New HTTP Desync Methods and Apache Flaw

Posted on August 7, 2026 By CWS

PortSwigger, a key player in web security, has announced groundbreaking findings from its AI-assisted research system, HTTP Terminator. Developed by James Kettle, this advanced tool has identified innovative HTTP desynchronization techniques after evaluating a vast array of 30,000 potential vectors.

Groundbreaking Discoveries in Web Security

The HTTP Terminator’s exploration resulted in the discovery of a zero-day vulnerability within the Apache Traffic Server, alongside novel desync methods. James Kettle highlighted that the tool analyzed 30,000 websites with authorized scanning under bug bounty agreements, revealing around 700 potential vulnerabilities. These targeted assets included financial institutions, governmental systems, security solutions, and even airports, emphasizing the widespread risk posed by these findings.

Technical Insights and Desync Techniques

The research unveiled innovative desync triggers, such as dual-matching Content-Length patterns and the “dangling-byte” technique, which enhances the reliability of response queue poisoning (RQP). This vulnerability can lead to significant security breaches, as it may cause the front end to misassociate backend responses with incorrect users, potentially exposing sensitive data like session cookies.

In addition, Shared-Parser Confusion emerged as a broader concept, initially proposed by the system but later validated by Kettle. The recommended defense remains consistent: avoid HTTP/1.1 upstream usage or employ strict allow-listing to manage request methods effectively.

Research Process and Future Implications

To drive these discoveries, Kettle integrated 138 HTTP and SMTP RFCs into the HTTP Terminator, dividing them into 15,000 small fragments to inspire the generation of unique candidate vectors. One particular technique, Content-Type: multipart/byteranges, was successful across various server implementations, compromising over 200 websites, including a prominent U.S. bank.

Furthermore, the human-guided discovery process led to identifying a desynchronization zero-day in the Apache Traffic Server. Although the issue is patched and tracked under CVE-2026-63078, current public records lack comprehensive verification details, leaving some uncertainty around the specific Traffic Server release addressed.

Finally, PortSwigger’s open-source release of HTTP Terminator allows further community engagement, although the details of the models used for each discovery are not specified in the research paper. Meanwhile, related research teams have released tools for studying CRLF-powered desync attacks, enriching the security field’s resources.

These advancements underscore the critical role of AI tools in enhancing cybersecurity measures, demonstrating a promising future for autonomous research systems in identifying vulnerabilities.

The Hacker News Tags:AI, Apache zero-day, bug bounty, CVE-2026-63078, Cybersecurity, HTTP desync, HTTP Terminator, James Kettle, PortSwigger, RQP, Shared-Parser Confusion, Vulnerability, web security

Post navigation

Previous Post: UNC6671 Exploits Microsoft 365 Through Phishing Attacks
Next Post: Key Cybersecurity Innovations at Black Hat 2026

Related Posts

New Atomic macOS Stealer Campaign Exploits ClickFix to Target Apple Users New Atomic macOS Stealer Campaign Exploits ClickFix to Target Apple Users The Hacker News
Enhancing SOC Workflows with AI and Wazuh Solutions Enhancing SOC Workflows with AI and Wazuh Solutions The Hacker News
NGate Malware Exploits HandyPay App in Brazil for NFC Data Theft NGate Malware Exploits HandyPay App in Brazil for NFC Data Theft The Hacker News
Fraudulent Android Apps Stole Millions via Fake Subscriptions Fraudulent Android Apps Stole Millions via Fake Subscriptions The Hacker News
FBI Alerts: Russian Hackers Phish WhatsApp, Signal Users FBI Alerts: Russian Hackers Phish WhatsApp, Signal Users The Hacker News
DoJ Revises China Hacking Statement, Targets Identified DoJ Revises China Hacking Statement, Targets Identified The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Probes Teams Calling Disruption Affecting Users
  • Cyberattacks Target Colorado Water Utilities’ OT Systems
  • Microsoft Entra ID to End SMS Sign-In by 2027
  • Fake LastPass App Distributes Rapuncel Malware
  • PowerShell Backdoor TASK#STOMP Steals Sensitive Data

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Probes Teams Calling Disruption Affecting Users
  • Cyberattacks Target Colorado Water Utilities’ OT Systems
  • Microsoft Entra ID to End SMS Sign-In by 2027
  • Fake LastPass App Distributes Rapuncel Malware
  • PowerShell Backdoor TASK#STOMP Steals Sensitive Data

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark