Top 10 web hacking techniques of 2025

2026-05-12T20:52:00Z7e0b20a4d410d9d996863ec7a7c530bc61497ba005d17e72996cc44bcffd7f6d
AI-assisted-testingBurp-extensionsCSP-bypassCSS-exfiltrationHTTP-desyncHTTP/1.1HttpOnly-bypassJWT-forgerySAMLSignSaboteurURL-validation-bypassWAF-bypassWebSocketauthentication-bypasscache-poisoningcookie-prefix-bypassphp-samlrace-conditionsrequest-smugglingruby-samltiming-attacksweb-security

What happened

Collection of PortSwigger Research posts (2024–2026) covering high-impact web security techniques and tooling. Key themes include parser-level SAML authentication bypasses (Ruby/PHP SAML), HTTP desynchronisation/request-smuggling and the insecurity of HTTP/1.1, cookie- and HttpOnly-bypass techniques (cookie prefixes, cookie sandwich), cache and URL validation exploitation, CSS-based data exfiltration, timing and rendering-oracle attacks, JWT signing forgery (SignSaboteur), new exploitation techniques for WebSocket and race conditions, and multiple Burp extensions that use AI to automate and强化(

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
portswigger_research
Record identifier
7e0b20a4d410d9d996863ec7a7c530bc61497ba005d17e72996cc44bcffd7f6d
Enrichment time
2026-05-12T20:52:00Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.