# Can AI do novel security research? Meet the HTTP Terminator

DevFeed: [Can AI do novel security research? Meet the HTTP Terminator](<https://devfeed.tech/articles/can-ai-do-novel-security-research-meet-the-http-terminator-7670.md>)

Original publisher: [Read original article](<https://portswigger.net/research/can-ai-do-novel-security-research>)

Author: James Kettle

Published: 2026-08-05T19:30:00Z

Content type: article

Language: en

Sources: [PortSwigger Research](<https://devfeed.tech/sources/portswigger-research.md>)

Topics: [AI research agents](<https://devfeed.tech/topics/ai-research-agents.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [automation](<https://devfeed.tech/tags/automation.md>), [autonomous](<https://devfeed.tech/tags/autonomous.md>), [exploits](<https://devfeed.tech/tags/exploits.md>), [generative-ai](<https://devfeed.tech/tags/generative-ai.md>), [http](<https://devfeed.tech/tags/http.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>)

## AI overview

The article examines whether autonomous AI systems can discover novel web-security attack techniques. It presents the HTTP Terminator, describes HTTP desynchronization research and exploits, and explores the limits of fully autonomous versus human/AI research loops.

## Source excerpt

Abstract We all know AI can find bugs. After a decade of research, I asked a harder question: can an autonomous system invent new attack techniques, and use them to hack live websites at scale? Buildi