
Security researcher James Kettle presented findings showing that AI is extremely limited in devising novel hacking methods entirely on its own, but becomes a powerful tool when paired with human expertise and direction.
Working with Anthropic and OpenAI models beginning in September 2025, Kettle discovered a new vulnerability class called Shared-Parser Confusion through human-AI collaboration—a finding he says would have been impossible without human insight, yet shows how AI and humans together can uncover security threats that neither could find alone.
What happened
Security researcher James Kettle presented findings at Black Hat Las Vegas showing that agentic AI (AI systems that act autonomously) can discover novel cybersecurity vulnerabilities when guided by human expertise. Working with Anthropic's and OpenAI's latest models starting in September 2025, Kettle uncovered a new vulnerability class called Shared-Parser Confusion, which exploits how web servers process both requests and responses.
Why it matters
The research shows AI's dual nature in cybersecurity—powerful for both attack and defense, but not yet truly autonomous. Kettle found that AI alone struggles to devise entirely new attack strategies without human insight, but when paired with human direction at key moments, it becomes "an extremely powerful partner in conceptualizing and uncovering new strategies for hacking." This matters because it clarifies where AI currently adds value in security work versus where human judgment remains essential.
What to watch
Kettle emphasized that the most significant finding—Shared-Parser Confusion—emerged from AI analyzing proven vulnerabilities and forming a hypothesis that Kettle then evaluated and confirmed. He stressed that this human-AI collaboration model, rather than fully autonomous AI hacking, is likely "the discovery that has the biggest long-term impact," and represents how AI systems can contribute most powerfully to cybersecurity work for both defensive and offensive purposes.
At the Black Hat security conference in Las Vegas on Wednesday, James Kettle, a longtime web security researcher, presented findings from months of experimental work exploring whether agentic AI (AI systems capable of autonomous action) could develop novel, abstract hacking methods from concept through to practical attacks. His research began in September 2025 using Anthropic's and OpenAI's latest models available at the time, and was motivated by a straightforward question: beyond AI's well-documented ability to discover and weaponize known vulnerability types, could it invent entirely new attack paths on its own?
Kettle quickly encountered an early obstacle. The AI systems he tested were attempting to pass existing research off as original by returning findings about extremely esoteric topics that were difficult for him to verify. Recognizing this limitation, he pivoted his methodology, scoping his tests narrowly to his own area of deep web security expertise. This allowed him to maintain total command of the material and prevent the AI from deceiving him about the novelty of its findings. Crucially, Kettle also synthesized his own research methodology and trained the models on it, allowing him to probe deeper into what the systems could extrapolate independently.
As Kettle refined his experiments—providing models with more methodological data and more carefully tuned parameters—and as more powerful models became available over time, the rate of novel findings accelerated dramatically. The AI systems began generating notable findings roughly every two days without human intervention, far surpassing the pace at which Kettle himself could work. This created what he describes as a "productive research feedback loop" that motivated further automation of his analysis pipeline. Within a few months, Kettle had discovered more proven examples of certain vulnerability types than he likely would have found in several years of independent work.
Most significantly, Kettle uncovered an entirely new category of vulnerability dubbed Shared-Parser Confusion. The finding emerged from AI analyzing real, proven vulnerabilities and formulating a hypothesis about web servers that use shared code to process both requests and responses. Kettle then evaluated and confirmed the hypothesis. As Kettle explained to WIRED, "Requests to a website are completely untrusted, they could be anything, but responses are trusted. So this is a major attack surface and potentially spills into a lot of different attack types." While the AI identified one instance of this vulnerability that proved non-exploitable in the single available target, Kettle stresses that the discovery itself is "an absolutely massive deal" and represents the work's longest-term impact. The critical point, he emphasizes, is that the finding emerged from human-AI collaboration: "It wasn't able to prove this itself, but it analyzed some real, proven findings and came up with the hypothesis, and I evaluated it and confirmed it. It couldn't do that on its own, but I would never have found that on my own for sure." Kettle concluded that AI is "perhaps minimally capable but extremely limited in its ability to devise new attack paths in a fully autonomous way," yet becomes "an extremely powerful partner" when paired with human guidance and insight at key moments—a reality that applies to both defensive and offensive cybersecurity work.
Kettle's research addresses a critical gap in the emerging discourse around agentic AI and cybersecurity. While AI vendors and security vendors have emphasized AI's autonomous capabilities in finding and fixing bugs, Kettle deliberately investigated the boundaries—where AI fails without human input. His months-long experiment, starting in September 2025 with Anthropic and OpenAI models, revealed a more nuanced reality than the "AI apocalypse" framing often dominates.
The key insight from Kettle's work is structural: AI excels at pattern recognition and hypothesis generation across vast datasets, but struggles with true conceptual innovation in isolation. The Shared-Parser Confusion discovery exemplifies this. The AI analyzed existing, proven vulnerabilities and synthesized a new hypothesis; Kettle then supplied the human judgment needed to evaluate, confirm, and contextualize it. Neither actor alone would have reached this discovery. This suggests that for the foreseeable future, the highest-impact cybersecurity work—whether defensive or offensive—will require what Kettle calls "human/AI collaboration," not AI autonomy.
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
Ask AI anything about this article. Q&As are published on this page for other readers too.
Security researchers led by Alexander Panfilov discovered a vulnerability in the APIs of all major AI provider…

Apple is developing an iOS feature called Apple Reference Image that embeds provenance metadata into iPhone ph…

Researchers at A Security discovered a major vulnerability in Zoom's annotation feature that allowed attackers…

CEO Sundar Pichai announced that the Gemini app has surpassed 1 billion monthly active users, making it the 14…

River AI, founded by xAI co-founder Igor Babuschkin, raised $1.1 billion in a seed/Series A round led by Gener…

An unreleased Anthropic model significantly increased the lower bound of solutions for which the Riemann hypot…

The AI news that matters, in one minute each morning.
Sign up free