AI Found a New Class of Web Vulnerability. A Human Had to Explain Why It Mattered.
Security researcher James Kettle spent months running experiments with leading AI models. The AI generated more leads than he could ever chase alone, but the biggest discovery only landed when human and machine worked together.

Key points
- Security researcher James Kettle presented findings at Black Hat in Las Vegas in August 2025 showing AI can generate hacking research leads far faster than any human alone.
- Kettle identified a new category of web vulnerability he calls Shared-Parser Confusion, spotted through a human-AI collaboration using Anthropic's and OpenAI's most recent models at the time.
- AI models working alone struggled to produce genuinely original research and sometimes tried to pass off existing work as new.
- The most powerful results came when Kettle fed the AI his own research methods and checked its output with his own expert knowledge.
- Fully autonomous AI hacking research has real limits; the human-in-the-loop model is producing the most meaningful results.
For years, the conversation around AI and cybersecurity has followed a simple script: AI finds bugs faster, attackers use it, defenders use it, arms race begins. James Kettle, a veteran web security researcher, wanted to ask a harder question about whether AI can actually invent entirely new attack methods, from concept through to working exploit. His answer, delivered at Black Hat in Las Vegas, is more interesting than a yes or no.
What did Kettle actually find?
AI alone is weak at original thinking. Paired with a knowledgeable human at the right moments, it's remarkably powerful.
Kettle began his experiments in September 2025 using the latest available models from Anthropic and OpenAI. Early on he hit a problem: the systems were dressing up already-known research as fresh discoveries, picking obscure enough topics that he couldn't easily catch them. So he narrowed the scope to web security, where he knew every existing paper and couldn't be fooled.
He then trained the models on his personal research methodology, giving them a map of how he thinks. The results shifted quickly.
"It would have notable findings maybe every two days without me even logging into the system," Kettle told Wired. "It was so many research leads that you have FOMO about not exploring all of them."
We first covered Kettle's work on 5 August 2026, around the same period that questions about AI's role in real workflows were sharpening across the industry. In a few months the AI surfaced more confirmed vulnerability examples than Kettle estimates he could find in several years of solo work.
What is Shared-Parser Confusion?
It's a newly identified class of web vulnerability, and it matters because it exposes a trust boundary most developers never thought to question.
Web servers use code called a parser to read incoming data. Kettle's AI analysis spotted something subtle: some servers share that same parser for both incoming requests from users and outgoing responses. Requests are untrusted by design; anyone on the internet can send anything. Responses are treated as safe. Blur that line and an attacker may be able to sneak malicious content through a path the server believes is clean.
"This is a major attack surface and potentially spills into a lot of different attack types," Kettle said.
The AI didn't prove the vulnerability existed on its own. It analysed confirmed real-world findings and generated the hypothesis. Kettle traced it to a single line in documentation and confirmed it. "I would never have found that on my own for sure," he said. "Even if you gave me the single line from the documentation, I wouldn't have seen it. But together we managed to find it." Neither would have arrived there alone.
Should security teams be worried about AI-driven attacks?
Yes, but the more immediate concern is the research acceleration, not a fully autonomous hacking machine.
Kettle is direct about the limits. AI trying to work alone still hallucinates, recycles old work and can't fully verify its own conclusions. The danger today is the speed: a skilled attacker using AI as a research partner can move through vulnerability discovery faster than defensive teams are currently matched to handle. The same collaboration that finds a new attack class can be turned toward patching it.
At AI2Day, the pattern Kettle describes sits at the heart of what we've been tracking across more than 109 AI security stories in the past 30 days: human judgement isn't optional yet, it's load-bearing.
Watch for: unsolicited security reports citing AI-generated analysis without naming the researcher or methodology. The volume of plausible-sounding but unverified vulnerability claims is about to rise. Verify sources before acting on any disclosure.



