Analysis
Autonomous Hacking Incidents & Web App / API Security
First reported · Discovered firecompass.com
Page published
Earliest dated coverage: 7 Oct 2026 · First observed: 9 Oct 2026 · Latest dated coverage: 7 Oct 2026
Coverage timeline
Single-source analysis — one report is available.
Why it matters
The analysis signals that LLMs are lowering the skill and budget barrier to discovering novel web/API exploits at scale, meaning defenders must assume previously 'theoretical' attack chains are now routinely achievable.
FireCompass field notes from Black Hat USA 2026 and DEF CON 34 argue that AI has collapsed the cost of expert-grade attacks, citing PortSwigger's James Kettle feeding his HTTP desync research to a model to build 'HTTP Terminator,' which processed 138 RFCs, generated novel request-smuggling vectors, and found ~700 vulnerable targets across 30,000 authorized sites, plus a referenced one-click Microsoft 365 Copilot data-theft attack. The piece frames these as evidence for continuous automated penetration testing.