James Kettle’s ‘autonomous research cascade’, CRLF-powered desync attacks, RCE on humanoid robots – ethical hacker news roundup
Can AI perform truly novel security research? And who better to tackle that question than PortSwigger director of security research James Kettle, the human behind so much groundbreaking work in the field? Building an autonomous system to, hopefully, invent new attack techniques and use them to hack websites at scale “sounded like a bad idea, so I did it,” James writes in his latest tour de force. SPOILER: “it worked”. In the research, which James presented at Black Hat and DEF CON last month, he shares “an arsenal of new HTTP desync triggers, gadgets, and exploits that compromised banks, security solutions, and government infrastructure. Then I’ll trace each discovery chain back through the HTTP Terminator, showing how to turn your personal expertise into an autonomous weapon – and the dark arts required to make it lethal.” 🦾
James Kettle wasn’t the only PortSwigger researcher to present research at the iconic hacker cons in Las Vegas. Tom Stacey co-presented ‘CRLF-powered desync attacks: beheading HTTP streams’ with Tobia Righi from TurtleSec, in which the pair demonstrated “how to take a simple header injection primitive and transform it into a full-blown desync worm”. They also showcased “novel methods to detect and exploit IP and connection-locked desyncs which prevent cross-network exploitation by shifting the desync’s execution into the victim's browser to generate an XSS out of thin air and steal HTTPOnly cookies.” Also presented in Las Vegas was ‘CSS: the bomb inside your inbox’ by Gareth Heyes, who turns CSS/webmail sanitisation edge cases into UI hijacking, token/data exfiltration, third-party account takeover and real-time password-stealing keyloggers across major mail providers. 💣
Olivier Laflamme, meanwhile, achieved unauthenticated root RCE on any Unitree G1 Humanoid Robot within Bluetooth range. Dubbed UniBLEed, this multi-layer research spanned BLE, firmware, binaries and cloud infrastructure. He may have hacked an AI-driven robot, but Olivierapparently did not enlist artificial intelligence to help him do so. “I’m happy to announce that these vulnerabilities are 100% human-found,” he wrote. “No AI in the loop!” Way to go, humans. “The Unitree Security Team were awesome to work with,” Olivier added. 🤖
Research roundup
Before we move on to our own new research, we will, humbly, spotlight more stellar work that we’ve spotted elsewhere since our last roundup – kudos to the researchers involved:
🔬 Breaking the M365 Copilot Sandbox with ChatMate– Ori Lahav, Rubrik Zero Labs
🔬 8 out of 10 banks in Belgium HATE this one weird eID RCE – James Arnott, Bay Area Labs
🔬 Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25 – Adam Kues, Searchlight Cyber
🔬 SQLite critical CVEs or LLM slop? – Afek Berger, JFrog
🔬 Ruby 4.0 universal RCE deserialization gadget chain – Luke Jahnke, Elttam
🔬 GitLost: how we tricked GitHub’s AI agent into leaking private repos – Sasi Levi, Noma
🔬SharedRoot; escaping the Claude Cowork sandbox – Oren Yomtov, Accomplish AI
🔬 Hacking your life with AI can get you hacked – Peyton Kennedy, Endor Labs
🔬 A peek into Reddit’s anti-spam internals– Lyra Rebane
🔬Your house has an FFmpeg problem – Jia Hao Poh, Elttam
It’s the quiet ones you have to watch out for
There’s an old French proverb – “c'est dans les vieilles marmites qu'on fait les meilleures soupes” – that translates to: “It’s in the old pots that the best soups are made.” In cybersecurity, these ‘old pots’ are analogous to silent patch gaps: vulnerabilities quietly fixed without an advisory or CVE, leaving defenders unaware while AI makes it dramatically cheaper and faster for attackers to rediscover and exploit them. Using CVE-2023-54391 – a critical Proxmox VE authentication bypass silently fixed in 2023 but only assigned a CVE after exploitation in 2026 – as an example, YesWeHack researchers examined how AI is widening this information asymmetry and what vendors, CNAs and vulnerability intelligence providers can do to reduce the risk.
Codex versus Claude Code
YesWeHack researcher Brumens tested how far Codex can take a Bug Bounty investigation, from recon and hypothesis generation through to validated exploitation. In blind PortSwigger labs, Codex independently solved a DOM XSS in under four minutes and gained administrator access via a JWT flaw in one minute 14 seconds; separate WordPress research by HashKitten also showed a multi-agent Codex workflow chaining a pre-auth SQL injection to RCE. 🧠
Brumens also put rival agentic coding tool Claude Code through its paces via blind Bug Bounty labs: DOM XSS and HTTP request smuggling. Could it find and prove real vulnerabilities? The results were impressive, but the hunter still played a vital role. Our guide to leveraging Claude Code for Bug Bounty hunting covers the full setup, from installation and connecting Claude Code to Burp Suite via MCP to understanding its limitations and using our plugin to help mitigate them. 🦾
Speaking of mitigating its limitations, we recently introduced the YesWeHack Claude Kit: an open-source Claude Code plugin that helps hunters structure findings, spot gaps in evidence and review reports before submission. Serving as an always-on layer of guardrails, the plugin works alongside three on-demand skills for writing, triaging and vulnerability-specific checks. Together, they keep every claim grounded in verified evidence and help hunters produce reports that triagers can validate more efficiently. 🛠️
One of our most successful hunters has shared his own experiences of using Anthropic’s agentic coding tool. In an interview with YesWeHack, Icare explains the transformative impact of his Iron Man-inspired, multi-agent setup ‘Jarvis’. Yet despite all this automation, Icare echoes our previous interviewees: every finding still needs human validation, and he always makes the final call before submission. 🧠
Introducing PimpMyCaido
Following the success of our PimpMyBurp series, we’ve now launched PimpMyCaido, with the first instalment explaining how Caido users can harness DOMLogger++ to uncover DOM XSS, client-side path traversal, prototype pollution and sanitiser bypasses.
In another hunter interview published on our blog recently, sunshinefactory talks hardware and IoT hacking, CTFs, reverse engineering and black-box testing. Berlin-based hunter krevetk0, meanwhile, shares how he chooses Bug Bounty targets, how he got into hacking and the impact of his most memorable vulnerability to date.
Live hacking with PUMA
In case you missed it: our latest leHACK live Bug Bounty featured targets from iconic sportswear brand PUMA. The event showed the value of in-person collaboration, as well as both AI-assisted testing – the impact of which was noted by our triage team – and manual testing, with the overall winners actually eschewing automation on this occasion. Again: way to go humans! Watch the highlights or read the full recap and hear from the winners. 👏
The next live hacking event isn’t far away. Two years after a successful live Bug Bounty at Ekoparty 2024 in Buenos Aires, Galicia Bank, Bug Bounty Argentina and YesWeHack are teaming up once again for the hacker con’s 2026 edition. The event, which is open to all Ekoparty attendees, takes place between 7-9 October. Ready for the rematch? 👊
Talkie Pwnii has started a series focused on solving PortSwigger Web Security Academy labs, kicking off with a walkthrough of how to solve the ‘SSRF with whitelist-based input filter’ lab.
As for our own, Dojo challenges, the current puzzle is Highscore, described thus: ”You are trapped inside an old retro game, trying every trick to break into another user's session and reach the next level. Can you bypass the game's restrictions, break free and advance?” Solutions submitted by 28 September will be in contention to win YesWeHack swag. The best solution and winners have, by the way, been published for the previous two challenges: Hacker Club and Streamcore.
Leaderboards
As for the top performers on real Bug Bounty Programs, perennial number one rabhi is still, unusually, not in the podium places on this quarter’s leaderboard, with Edra, SecurityReapers and YoyoDavelion setting the pace so far in Q3. Edra is also out in front for the month of September, followed by hakupiku and DinDinDin. Rabhi is, however, still at the summit for 2026 as a whole, with Edra and YoyoDavelion occupying second and third place respectively.🏆
🤘 Meet the YesWeHack team 🤘
With Black Hat and DEF CON in the rear-view mirror, there are still LOTS more opportunities to meet the YesWeHack team, learn more about hunting on our Bug Bounty platform – and potentially bag some swag. Catch us at one of these upcoming conferences 👇
📍GISEC Global| Dubai | 16-18 September
📍ROOTCON| Clark, Philippines | 24-25 September
📍ECSO CISO Meetup| Berlin, Germany | 1-2 October
📍 Banco Galicia x YesWeHack: live hacking event at Ekoparty 2026 Buenos Aires | 7-9 October
📍Les Assises de la cybersécurité | Monaco, France | 7-10 October
📍 it-sa Expo&Congress| Nuremberg, Germany | 27-29 October
📍 Cyber Security Nordic 2026| Helsinki, Finland | 28-29 October | booth 1D15
📍 Barcelona Cybersecurity Congress (BCC)| Barcelona, Spain | 3-5 November
And that’s a wrap until our next edition in November – happy hunting in the meantime! 👊
Read this monthly roundup of content aimed at ethical hackers even sooner by subscribing to Bug Bounty Bulletin.
Are you a CISO, other security professional or security-conscious dev? Check out our CISO-focused sister newsletter, CrowdSecWisdom – bringing you news, insights and inspiration around offensive security topics like Bug Bounty, vulnerability disclosure and management, pentest management and attack surface protection.



