Top 10 web hacking techniques of 2025

2026-06-10T08:52:01Z8fa86afb71c7d61054a20fd72a18088ce084d800f57a3a3eafb86a0d71d6aa6a
SAMLTRACE-methodauthentication-bypasscache-poisoningcookie-prefix-bypasscss-exfiltrationhttp-desynchttponly-bypassjwtnamespace-confusionparser-vulnerabilitiesrequest-smugglingsigned-tokensurl-validation-bypasswaf-bypassweb-securitywebsocket-security

What happened

Collection of PortSwigger Research posts (2023–2026) highlighting new and practical web‑security techniques and exploits. Notable findings include parser‑level SAML authentication bypasses (Ruby/PHP namespace and attribute pollution leading to full auth bypass), systemic HTTP/1.1 desynchronisation (request smuggling and desync exploitation including a TRACE‑assisted technique), cookie prefix and HttpOnly bypasses, CSS‑based data exfiltration, JWT forging tools (SignSaboteur), WebSocket testing blindspots, and multiple WAF/cache/URL‑validation bypasses. The feed also documents tooling and AI‑dr

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
portswigger_research
Record identifier
8fa86afb71c7d61054a20fd72a18088ce084d800f57a3a3eafb86a0d71d6aa6a
Enrichment time
2026-06-10T08:52:01Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.