Saturday Aug 8

AI Invents Attacks Nobody Named

8AUG
AI MADE ITNO NAME

An AI stopped hunting known bugs and started inventing new ones. At Black Hat, PortSwigger's James Kettle showed a system that found attack types no textbook lists. It earned real bug bounties.

For two years the pitch was speed. Machines finding known flaws faster than people. That changed this week.

Kettle's system found three things nobody had catalogued: new request-smuggling triggers, a poisoning route into cloud proxies, and a dual-parser class. Live sites paid bounties. That makes the claim checkable, not marketing.

A Tencent Xuanwu pipeline separately found over 100 logic bugs in Chrome and Android. Nvidia researchers showed a fine-tuned 30B open model hitting 56% success at 70-125x lower cost.

full brief & sources

⚡ Why this matters

  • First controlled demonstration of an AI generating attack categories rather than applying known ones.
  • The bug bounties are verifiable, so this is not a vendor claim.
  • Signature-based defenses assume attackers reuse published techniques. That assumption is now weaker.

🔍 What happened

  • Black Hat USA 2026 ran August 1-6 at Mandalay Bay, with roughly 20,000 attendees.
  • James Kettle of PortSwigger presented HTTP Terminator, an autonomous research system, in the week's most-debated session.
  • It found novel HTTP desync triggers, a poisoning vector against cloud-scale reverse proxies, and a dual-parser attack class.
  • Tencent Security Xuanwu Lab showed an LLM pipeline that found 100+ logic vulnerabilities in Chrome and Android.
  • Nvidia researchers reported a fine-tuned 30B open model reaching 56% exploit success against AI agents at 70-125x lower cost than frontier models.
  • Vicarius found 79% of organisations were breached by a flaw already sitting in their own inventory.

💬 Smart takes

  • James Kettle, PortSwigger: the write-up traces each discovery chain, and the bounties came from production systems.
  • Diana Kelley, CISO at Noma Security: "There's much less patience for generic 'AI-powered' claims and much more focus on provable controls."
  • Chase Cunningham, Demo-Force: "You cannot walk 20 feet without encountering agentic, AI-powered or autonomous attached to a product that, in some cases, was apparently doing just fine without those words last year."
  • Skeptic: HTTP parsing is unusually well-suited to automated search. One narrow domain does not prove general research ability.

🧭 Where this goes

  1. Likelyweb application firewall vendors ship 'unknown-technique' detection modes within two quarters.
  2. Likelymore labs publish autonomous-research results in narrow, checkable domains before claiming anything broad.
  3. Possiblebug bounty programmes add rules covering machine-generated submissions as volume climbs.
  4. Wild Carda novel attack class discovered by a machine shows up in a real breach before its disclosure window closes.

🥄 The Spoon Take

Every security roadmap assumes attackers work from a published playbook. That is why signature lists work. A system that writes new pages breaks the assumption, not the tooling. The cheap-open-model finding matters more than the headline one: this capability does not stay locked behind frontier budgets.

🤔 Pushback

One researcher, one protocol, one conference. HTTP parsing may simply be the rare domain where brute-force search looks like insight.