The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop

Security researcher James Kettle discusses how AI can be used to discover new web vulnerabilities when guided by human expertise. He highlights a new 'Shared-Parser Confusion' vulnerability discovered through AI-assisted research.
Why it matters
It demonstrates that while AI is not yet fully autonomous in hacking, it serves as a powerful force multiplier for human security researchers to find complex, high-impact vulnerabilities.
At the Black Hat security conference in Las Vegas on Wednesday, Kettle presented his findings, which illustrate both AI’s rapidly advancing cybersecurity capabilities and its limitations. For now, the answer to Kettle’s question is nuanced. He concluded that AI is perhaps minimally capable but extremely limited in its ability to devise new attack paths in a fully autonomous way. Importantly, though, when paired with human guidance and insight in key moments, Kettle found that AI is an extremely powerful partner in conceptualizing and uncovering new strategies for hacking.
After spending years researching web security vulnerabilities, Kettle says he has uncovered an entirely new area of potential vulnerability—dubbed Shared-Parser Confusion—as the result of an AI revelation about web servers using shared code to process both requests and responses.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in