James Kettle wanted to find out if AI tools could go beyond finding new vulnerabilities and actually develop new attack techniques and exploits — so he built a Terminator.
An "HTTP Terminator," to be exact. And as scary as the open source tool may sound, it worked — HTTP Terminator autonomously developed novel desync attacks, also known as HTTP request smuggling, that successfully hacked into real enterprise websites, including those of several financial services companies.
Kettle, director of research at PortSwigger, spoke with Dark Reading senior news director Rob Wright at the News Desk at Black Hat USA 2026 about how HTTP Terminator was developed, what it discovered, and how the tool will occasionally go off script.
"It deviates from instructions in every possible way," Kettle said. "It is told to create vectors for request smuggling, and sometimes it will just decide to create vectors for cache poisoning instead."
For all of our Dark Reading News Desk videos, please check out our YouTube channel, and our curated video articles.
Dark Reading News Desk With James Kettle: Full Transcript
Dark Reading's Rob Wright: Hello and welcome to the Dark Reading News Desk at Black Hat USA 2026 in Las Vegas. I'm Rob Wright with Dark Reading, and I'm here with James Kettle of PortSwigger. James, how are you doing?
James Kettle: Pretty good, thanks.
DR's Rob Wright: You had a session yesterday at Black Hat. Tell me a little bit about it. It sounded very interesting.
James Kettle: Sure. So my session was exploring whether AI can do genuinely novel, original security research, because we already know that AI can hack things. But no one was really exploring how far it can go, and they also, because many of them were kind of using it to market products, they weren't saying where AI fails and where it runs into limitations and where humans actually add value to these systems as well. So I just wanted to take AI models to the absolute limit of their hacking capabilities.
... continue reading