{"id":5025,"date":"2026-08-05T20:24:52","date_gmt":"2026-08-05T20:24:52","guid":{"rendered":"https:\/\/silvybrand.com\/?p=5025"},"modified":"2026-08-05T20:24:52","modified_gmt":"2026-08-05T20:24:52","slug":"the-most-dangerous-ai-hacking-techniques-still-have-human-input","status":"publish","type":"post","link":"https:\/\/silvybrand.com\/?p=5025","title":{"rendered":"The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop"},"content":{"rendered":"<p><br \/>\n<\/p>\n<div>\n<p><span class=\"lead-in-text-callout\">Agentic AI has<\/span> permanently changed cybersecurity by making it <a href=\"https:\/\/www.wired.com\/story\/chrome-needs-twice-a-week-patching-thanks-to-ai-bug-hunting-for-now\/\" class=\"text link\">quicker and easier<\/a> to discover vulnerabilities in software and fix them\u2014or develop so-called exploits to weaponize them. But longtime web security researcher James Kettle wanted to look beyond the <a href=\"https:\/\/www.wired.com\/story\/the-ai-era-is-creating-a-bug-hunting-arms-race\/\" class=\"text link\">bug-hunting apocalypse<\/a> to explore a question that has taken on even more urgency as major AI organizations disclose real-world examples of rogue AI hacking: Can agentic AI develop novel, abstract hacking methods, from concept through to practical attacks?<\/p>\n<p class=\"paywall\">At the <a href=\"https:\/\/www.wired.com\/tag\/black-hat\/\" class=\"text link\">Black Hat<\/a> security conference in Las Vegas on Wednesday, Kettle presented his findings, which illustrate both AI\u2019s rapidly advancing cybersecurity capabilities and its limitations. For now, the answer to Kettle\u2019s question is nuanced. He concluded that AI is perhaps minimally capable but extremely limited in its ability to devise new attack paths in a fully autonomous way. Importantly, though, when paired with human guidance and insight in key moments, Kettle found that AI is an extremely powerful partner in conceptualizing and uncovering new strategies for hacking.<\/p>\n<p class=\"paywall\">After spending years <a href=\"https:\/\/www.wired.com\/story\/web-timing-attacks-black-hat-2024\/\" class=\"text link\">researching web security vulnerabilities<\/a>, Kettle says he has uncovered an entirely new area of potential vulnerability\u2014dubbed Shared-Parser Confusion\u2014as the result of an AI revelation about web servers using shared code to process both requests and responses.<\/p>\n<p class=\"paywall\">\u201cThis is an absolutely massive deal, because if you think about it, requests to a website are completely untrusted, they could be anything, but responses are trusted,\u201d Kettle told WIRED ahead of his conference talk. \u201cSo this is a major attack surface and potentially spills into a lot of different attack types.\u201d<\/p>\n<p class=\"paywall\">The finding came out of months of experiments that began in September 2025 using <a href=\"https:\/\/www.wired.com\/tag\/anthropic\/\" class=\"text link\">Anthropic<\/a>\u2019s and <a href=\"https:\/\/www.wired.com\/tag\/openai\/\" class=\"text link\">OpenAI\u2019s<\/a> latest models at the time. Kettle wanted to explore AI\u2019s ability to do theoretical security research but quickly realized that one obstacle was that the systems were attempting to pass existing research off as original by returning findings about extremely esoteric topics that were difficult to vet. With this in mind, he decided to scope his tests more narrowly so the AI systems were working within his own area of web security expertise. This way he had total command of the material and knew that AI couldn\u2019t trick him. Additionally, Kettle realized that by synthesizing his own research methodology and training models on it, he could probe deeper into what the systems were capable of extrapolating on their own.<\/p>\n<p class=\"paywall\">\u201cI\u2019m interested in pushing AI to the absolute limit to see where it fails and where you need a human,\u201d Kettle says. \u201cThere are still very few people talking about where the limits are, especially in the security space, because there aren\u2019t incentives to talk about that angle. Everyone wants to be seen as AI native, not talk about where their system falls apart completely.\u201d<\/p>\n<p class=\"paywall\">As Kettle honed his experiments\u2014providing models with more methodological data and more refined parameters\u2014and as time passed and more powerful models debuted, he says the systems had more and more findings at a rate far surpassing his own, creating what he describes as a productive research feedback loop.<\/p>\n<p class=\"paywall\">\u201cIt was really interesting going through the process. It would have notable findings maybe every two days without me even logging into the system, to the point that it was making me anxious,\u201d Kettle says, \u201clike I almost don\u2019t want to know. It was so many research leads that you have FOMO about not exploring all of them, so it forces you to automate more analysis.\u201d<\/p>\n<p class=\"paywall\">In addition to finding more proven examples of certain vulnerabilities in a few months than he could likely find in a few years, Kettle also hoped that the AI system could find an entire novel class of those types of bugs. And in a way it did succeed, he says, but the finding related to an extremely rare type of bug and was not actually exploitable in the one vulnerable target available. Kettle emphasizes, though, that the Shared-Parser Confusion finding was so significant, even though it was a human\/AI collaboration, because it illustrates the reality of how AI systems can contribute most powerfully to cybersecurity work right now for both defensive and offensive hacking.<\/p>\n<p class=\"paywall\">\u201cIt wasn\u2019t able to prove this itself, but it analyzed some real, proven findings and came up with the hypothesis, and I evaluated it and confirmed it,\u201d Kettle says. \u201cThat\u2019s probably going to be the discovery that has the biggest long-term impact. It couldn\u2019t do that on its own, but I would never have found that on my own for sure. Even if you gave me the single line from the [documentation], I wouldn\u2019t have seen it. But together we managed to find it.\u201d<\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/www.wired.com\/story\/the-most-dangerous-ai-hacking-techniques-still-have-human-input\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Agentic AI has permanently changed cybersecurity by making it quicker and easier to discover vulnerabilities in software and fix them\u2014or develop so-called exploits to weaponize them. But longtime web security researcher James Kettle wanted to look beyond the bug-hunting apocalypse to explore a question that has taken on even more urgency as major AI organizations [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[],"class_list":["post-5025","post","type-post","status-publish","format-standard","category-gadgets"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop - Silvybrand Lifestyle Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/silvybrand.com\/?p=5025\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop - Silvybrand Lifestyle Blog\" \/>\n<meta property=\"og:description\" content=\"Agentic AI has permanently changed cybersecurity by making it quicker and easier to discover vulnerabilities in software and fix them\u2014or develop so-called exploits to weaponize them. But longtime web security researcher James Kettle wanted to look beyond the bug-hunting apocalypse to explore a question that has taken on even more urgency as major AI organizations [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/silvybrand.com\/?p=5025\" \/>\n<meta property=\"og:site_name\" content=\"Silvybrand Lifestyle Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-05T20:24:52+00:00\" \/>\n<meta name=\"author\" content=\"SILVYBRAND\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"SILVYBRAND\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/silvybrand.com\\\/?p=5025#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/silvybrand.com\\\/?p=5025\"},\"author\":{\"name\":\"SILVYBRAND\",\"@id\":\"https:\\\/\\\/silvybrand.com\\\/#\\\/schema\\\/person\\\/8bdc6818a5b6ef5b9745e468818e37f3\"},\"headline\":\"The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop\",\"datePublished\":\"2026-08-05T20:24:52+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/silvybrand.com\\\/?p=5025\"},\"wordCount\":802,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/silvybrand.com\\\/#organization\"},\"articleSection\":[\"Gadgets\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/silvybrand.com\\\/?p=5025#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/silvybrand.com\\\/?p=5025\",\"url\":\"https:\\\/\\\/silvybrand.com\\\/?p=5025\",\"name\":\"The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop - Silvybrand Lifestyle Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/silvybrand.com\\\/#website\"},\"datePublished\":\"2026-08-05T20:24:52+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/silvybrand.com\\\/?p=5025#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/silvybrand.com\\\/?p=5025\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/silvybrand.com\\\/?p=5025#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/silvybrand.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/silvybrand.com\\\/#website\",\"url\":\"https:\\\/\\\/silvybrand.com\\\/\",\"name\":\"Silvybrand Lifestyle Blog\",\"description\":\"Your daily dose of lifestyle, fashion, travel, beauty, and inspiration \u2014 living boldly, stylishly, and confidently.\",\"publisher\":{\"@id\":\"https:\\\/\\\/silvybrand.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/silvybrand.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/silvybrand.com\\\/#organization\",\"name\":\"Silvybrand Lifestyle Blog\",\"url\":\"https:\\\/\\\/silvybrand.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/silvybrand.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/silvybrand.com\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/SILVYBRAND-LOGO.jpg\",\"contentUrl\":\"https:\\\/\\\/silvybrand.com\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/SILVYBRAND-LOGO.jpg\",\"width\":1115,\"height\":522,\"caption\":\"Silvybrand Lifestyle Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/silvybrand.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/silvybrand.com\\\/#\\\/schema\\\/person\\\/8bdc6818a5b6ef5b9745e468818e37f3\",\"name\":\"SILVYBRAND\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/e7db54afd7d090e59e1a481fd3e6812d467eb2a3b81e7a3092023acfc59a496b?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/e7db54afd7d090e59e1a481fd3e6812d467eb2a3b81e7a3092023acfc59a496b?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/e7db54afd7d090e59e1a481fd3e6812d467eb2a3b81e7a3092023acfc59a496b?s=96&d=mm&r=g\",\"caption\":\"SILVYBRAND\"},\"sameAs\":[\"https:\\\/\\\/silvybrand.com\"],\"url\":\"https:\\\/\\\/silvybrand.com\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop - Silvybrand Lifestyle Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/silvybrand.com\/?p=5025","og_locale":"en_US","og_type":"article","og_title":"The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop - Silvybrand Lifestyle Blog","og_description":"Agentic AI has permanently changed cybersecurity by making it quicker and easier to discover vulnerabilities in software and fix them\u2014or develop so-called exploits to weaponize them. But longtime web security researcher James Kettle wanted to look beyond the bug-hunting apocalypse to explore a question that has taken on even more urgency as major AI organizations [&hellip;]","og_url":"https:\/\/silvybrand.com\/?p=5025","og_site_name":"Silvybrand Lifestyle Blog","article_published_time":"2026-08-05T20:24:52+00:00","author":"SILVYBRAND","twitter_card":"summary_large_image","twitter_misc":{"Written by":"SILVYBRAND","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/silvybrand.com\/?p=5025#article","isPartOf":{"@id":"https:\/\/silvybrand.com\/?p=5025"},"author":{"name":"SILVYBRAND","@id":"https:\/\/silvybrand.com\/#\/schema\/person\/8bdc6818a5b6ef5b9745e468818e37f3"},"headline":"The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop","datePublished":"2026-08-05T20:24:52+00:00","mainEntityOfPage":{"@id":"https:\/\/silvybrand.com\/?p=5025"},"wordCount":802,"commentCount":0,"publisher":{"@id":"https:\/\/silvybrand.com\/#organization"},"articleSection":["Gadgets"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/silvybrand.com\/?p=5025#respond"]}]},{"@type":"WebPage","@id":"https:\/\/silvybrand.com\/?p=5025","url":"https:\/\/silvybrand.com\/?p=5025","name":"The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop - Silvybrand Lifestyle Blog","isPartOf":{"@id":"https:\/\/silvybrand.com\/#website"},"datePublished":"2026-08-05T20:24:52+00:00","breadcrumb":{"@id":"https:\/\/silvybrand.com\/?p=5025#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/silvybrand.com\/?p=5025"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/silvybrand.com\/?p=5025#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/silvybrand.com\/"},{"@type":"ListItem","position":2,"name":"The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop"}]},{"@type":"WebSite","@id":"https:\/\/silvybrand.com\/#website","url":"https:\/\/silvybrand.com\/","name":"Silvybrand Lifestyle Blog","description":"Your daily dose of lifestyle, fashion, travel, beauty, and inspiration \u2014 living boldly, stylishly, and confidently.","publisher":{"@id":"https:\/\/silvybrand.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/silvybrand.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/silvybrand.com\/#organization","name":"Silvybrand Lifestyle Blog","url":"https:\/\/silvybrand.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/silvybrand.com\/#\/schema\/logo\/image\/","url":"https:\/\/silvybrand.com\/wp-content\/uploads\/2026\/05\/SILVYBRAND-LOGO.jpg","contentUrl":"https:\/\/silvybrand.com\/wp-content\/uploads\/2026\/05\/SILVYBRAND-LOGO.jpg","width":1115,"height":522,"caption":"Silvybrand Lifestyle Blog"},"image":{"@id":"https:\/\/silvybrand.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/silvybrand.com\/#\/schema\/person\/8bdc6818a5b6ef5b9745e468818e37f3","name":"SILVYBRAND","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/e7db54afd7d090e59e1a481fd3e6812d467eb2a3b81e7a3092023acfc59a496b?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/e7db54afd7d090e59e1a481fd3e6812d467eb2a3b81e7a3092023acfc59a496b?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/e7db54afd7d090e59e1a481fd3e6812d467eb2a3b81e7a3092023acfc59a496b?s=96&d=mm&r=g","caption":"SILVYBRAND"},"sameAs":["https:\/\/silvybrand.com"],"url":"https:\/\/silvybrand.com\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/silvybrand.com\/index.php?rest_route=\/wp\/v2\/posts\/5025","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/silvybrand.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/silvybrand.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/silvybrand.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/silvybrand.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=5025"}],"version-history":[{"count":0,"href":"https:\/\/silvybrand.com\/index.php?rest_route=\/wp\/v2\/posts\/5025\/revisions"}],"wp:attachment":[{"href":"https:\/\/silvybrand.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=5025"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/silvybrand.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=5025"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/silvybrand.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=5025"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}