AI News selected for Professionals and Decision Makers
AI Security And Privacy Updates

AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day

12:09 · August 7, 2026 · Hacker News AI Section

AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day

PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate desync vectors. PortSwigger said a separate human-guided discovery cascade also exposed a zero-day in Apache Traffic Server. Kettle said HTTP Terminator tested 30,000 websites where

Summary

PortSwigger’s HTTP Terminator, developed by James Kettle, is an AI-assisted system that processed 138 HTTP and SMTP RFCs by breaking them into roughly 15,000 fragments. These fragments served as seeds for generating and testing 30,000 candidate desynchronization vectors. The autonomous phase produced several previously undocumented triggers, including a dual-matching Content-Length pattern and a multipart/byteranges technique that affected more than 200 sites in the authorized test set, among them an unnamed U.S. bank.

A key output was the dangling-byte variant of response queue poisoning. By leaving a smuggled request one byte short, the method ensures the second backend response is withheld until a subsequent victim request supplies the missing byte. This removes the timing race that previously limited RQP reliability on many servers and can expose session cookies or API keys belonging to other users.

The same research run surfaced the broader concept of Shared-Parser Confusion, in which servers reuse response-parsing logic for incoming requests. Kettle validated and generalized the idea after the system proposed it. A separate human-guided discovery cascade identified a desynchronization flaw in Apache Traffic Server, later assigned CVE-2026-63078 and patched; public CVE records still lack an entry for the identifier.

When the system scanned 30,000 sites reachable under bug-bounty or disclosure programs, it flagged approximately 700 targets spanning banks, government systems, security products, and an airport. PortSwigger has open-sourced the implementation, which relies on Claude for document extraction and test generation while requiring human oversight for final validation of certain findings. Recommended defenses remain unchanged: remove HTTP/1.1 upstream connections where feasible, or enforce strict method allow-lists at both proxy and origin layers for requests that may carry bodies.

Why it matters

Directly addresses AI-driven discovery of web-security vulnerabilities with clear privacy impact (session cookies, API keys) and actionable defenses relevant to EU/Dutch organizations subject to GDPR and NIS2. Security professionals can test the open-sourced tool and apply the recommended controls to their HTTP infrastructure.

More in this beat
Apache Traffic Serverbug-bountyclaudeHTTP Terminatoroffensive-securityPortSwiggerzero-day
AI Can Find Bugs, But Human Knowledge Still Proves Them

12:10 · July 16, 2026

AI Can Find Bugs, But Human Knowledge Still Proves Them

This article is highly relevant for security professionals in the Dutch AI market as it addresses the operational challenges of integrating AI into offensive security workflows. It provides actionable guidance on maintaining high validation standards and preventing skill degradation, aligning with the Netherlands' focus on robust and reliable AI deployment.

Relevance 85 · Audience 95

The Claude Code Guide For Startups

02:00 · August 20, 2026

The Claude Code Guide For Startups

This article is highly relevant for product teams and builders as it offers actionable strategies and technical tips for integrating agentic coding into the SDLC. Dutch AI practitioners can apply these insights to scale development efficiently while maintaining governance and compliance through robust evaluation frameworks.

Relevance 85 · Audience 95

How monday.com transformed its platform into an agent-first product where humans and agents collaborate

02:00 · August 20, 2026

How monday.com transformed its platform into an agent-first product where humans and agents collaborate

This case study is highly relevant for product teams and builders as it provides a strategic blueprint for transitioning from superficial AI features to a native, agent-first architecture. It offers actionable insights into integrating LLMs like Claude into core workflows, which is highly applicable for Dutch SaaS companies and AI practitioners looking to drive sustained user engagement.

Relevance 75 · Audience 90

Why Workforce Experience Is Now a Data Protection Issue For Enterprises

17:19 · August 19, 2026

Why Workforce Experience Is Now a Data Protection Issue For Enterprises

This article is highly relevant as it addresses the critical security and privacy risks of "shadow AI" in the enterprise, a major concern for Dutch organizations striving for GDPR compliance. It provides actionable advice for security professionals on balancing employee productivity with robust data protection and vendor governance.

Relevance 85 · Audience 95

Turning conversation into knowledge: how Slack builds human-agent teams

02:00 · August 19, 2026

Turning conversation into knowledge: how Slack builds human-agent teams

This article provides actionable organizational strategies for product teams looking to integrate AI agents into their daily workflows. While it lacks specific Dutch market data or deep technical code, the best practices for AI adoption, context sharing, and productivity measurement are highly applicable to Dutch SMEs and enterprise product builders.

Relevance 65 · Audience 85

How ABC Legal turned every employee into a builder with Claude Managed Agents

02:00 · August 17, 2026

How ABC Legal turned every employee into a builder with Claude Managed Agents

This article provides a highly actionable blueprint for product teams and builders to deploy scalable, observable AI agents using a GitOps approach. It demonstrates how to empower non-technical staff to build automations while maintaining centralized governance, which is highly applicable to Dutch enterprises scaling AI.

Relevance 75 · Audience 90

Don't Want Your LLM to Recommend Nuclear Strike? Try Asking It in Japanese

06:00 · August 15, 2026

Don't Want Your LLM to Recommend Nuclear Strike? Try Asking It in Japanese

This study is highly relevant for Dutch AI researchers and policymakers focused on ethical AI and EU AI Act compliance, as it demonstrates that safety guardrails can behave unpredictably across different languages. It underscores the necessity for multilingual safety evaluations, which is critical for Dutch enterprises deploying LLMs.

Relevance 85 · Audience 95

ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories

20:17 · August 13, 2026

ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories

This article is highly relevant for security professionals as it details emerging attack vectors against AI agents and coding assistants, alongside new defensive strategies like Context Bombs. Understanding these threats is crucial for Dutch enterprises to secure their AI supply chains and maintain compliance with data protection standards.

Relevance 85 · Audience 95

Claude Tag now reads even more of the room

02:00 · August 13, 2026

Claude Tag now reads even more of the room

This update is highly relevant for product teams and builders as it demonstrates advanced context-aware AI integration within daily collaboration tools like Slack. Dutch AI practitioners and SMEs can leverage this to streamline engineering workflows and improve team productivity without incurring extra usage limits.

Relevance 85 · Audience 95

The Claude in Chrome side panel is now Claude Cowork

02:00 · August 12, 2026

The Claude in Chrome side panel is now Claude Cowork

This update is highly relevant for product teams and builders as it introduces powerful browser-based AI agent capabilities for workflow automation. The inclusion of enterprise-grade security controls and prompt injection mitigations aligns well with the strict data and security standards of the Dutch and EU markets.

Relevance 85 · Audience 90

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

18:47 · August 11, 2026

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

This article demonstrates the practical application of AI agents in discovering complex vulnerability chains in widely used enterprise software. It provides crucial insights into how AI is accelerating offensive security capabilities, which Dutch enterprises must understand to defend against increasingly sophisticated cyberattacks.

Relevance 85 · Audience 95