Top 10 web hacking techniques of 2025
2026-05-12T20:52:00Z•7e0b20a4d410d9d996863ec7a7c530bc61497ba005d17e72996cc44bcffd7f6d
AI-assisted-testingBurp-extensionsCSP-bypassCSS-exfiltrationHTTP-desyncHTTP/1.1HttpOnly-bypassJWT-forgerySAMLSignSaboteurURL-validation-bypassWAF-bypassWebSocketauthentication-bypasscache-poisoningcookie-prefix-bypassphp-samlrace-conditionsrequest-smugglingruby-samltiming-attacksweb-security
What happened
Collection of PortSwigger Research posts (2024–2026) covering high-impact web security techniques and tooling. Key themes include parser-level SAML authentication bypasses (Ruby/PHP SAML), HTTP desynchronisation/request-smuggling and the insecurity of HTTP/1.1, cookie- and HttpOnly-bypass techniques (cookie prefixes, cookie sandwich), cache and URL validation exploitation, CSS-based data exfiltration, timing and rendering-oracle attacks, JWT signing forgery (SignSaboteur), new exploitation techniques for WebSocket and race conditions, and multiple Burp extensions that use AI to automate and强化(
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- portswigger_research
- Record identifier
- 7e0b20a4d410d9d996863ec7a7c530bc61497ba005d17e72996cc44bcffd7f6d
- Enrichment time
- 2026-05-12T20:52:00Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.