Analysis

Autonomous Hacking Incidents & Web App / API Security

Page published

Earliest dated coverage: 7 Oct 2026 · First observed: 9 Oct 2026 · Latest dated coverage: 7 Oct 2026

Coverage timeline

7 Oct 2026firecompass.com

Single-source analysis — one report is available.

Why it matters

The analysis signals that LLMs are lowering the skill and budget barrier to discovering novel web/API exploits at scale, meaning defenders must assume previously 'theoretical' attack chains are now routinely achievable.

FireCompass field notes from Black Hat USA 2026 and DEF CON 34 argue that AI has collapsed the cost of expert-grade attacks, citing PortSwigger's James Kettle feeding his HTTP desync research to a model to build 'HTTP Terminator,' which processed 138 RFCs, generated novel request-smuggling vectors, and found ~700 vulnerable targets across 30,000 authorized sites, plus a referenced one-click Microsoft 365 Copilot data-theft attack. The piece frames these as evidence for continuous automated penetration testing.