The AI that 'autonomously invented' a new bank-hacking technique needed its human to confirm the technique was real.
James Kettle built a genuinely impressive research machine. Then he wrote, in plain English, that its best discovery was not autonomous. The headline dropped that sentence.
"An autonomous AI invented novel attack techniques no researcher had named and used them to hack live banks and government systems" [SOURCE ↗]

THE CLAIM. an autonomous AI invented novel attack categories no researcher had named and hacked live banks and government systems. THE CHECK: the primary source is James Kettle's own PortSwigger writeup, and it says the opposite of the headline. Of the flagship discovery, Shared-Parser Confusion, Kettle writes 'This discovery was not fully autonomous, the HTTP Terminator proposed it, and I validated it.' Every one of the roughly 700 vulnerable targets sat inside an authorized bug-bounty or vulnerability disclosure scope. Impressive AI-assisted research, mislabeled as an autonomous attack.
James Kettle, director of research at PortSwigger, has spent a decade on HTTP desync attacks, the family of bugs where a front-end and back-end server disagree about where one request ends and the next begins. At Black Hat USA on August 7 he presented the HTTP Terminator: an AI-driven system he fed
🔒 THE FULL AUTOPSY · FREE WITH AN ACCOUNTYou just read the free check. Sign in free, a code by email, no passwords, and the rest unlocks: the evidence trail, the steelman and the rebuttal, all 3 sources with quotes and screenshots, and our on-record call.
Couldn't verify your access — this looks like our error, not yours.