Top 10 web hacking techniques of 2025
2026-03-13T20:51:57Z•eb4c655a4346e05a09927fe65ea296154ce8db647f5dcb28da644a7a1e8cffb3
ai-security-toolsauthentication-bypassblind-cssburp-suitecache-poisoningcookie-prefix-bypasscookie-sandwichcss-exfiltrationhttp-desynchttp1.1httponly-exfiltrationjwt-forgerynamespace-confusionparser-discrepancypdf-rendering-discrepanciesportswiggerrequest-smugglingsamlsignsaboteurssrf-url-validation-bypasstiming-attacksvscode-exploitwaf-bypassweb-securitywebsocket-security
What happened
PortSwigger Research published a large collection of 2024–2026 web-security findings and tooling, highlighted by the “Top 10 web hacking techniques of 2025.” Key themes: parser and namespace discrepancies (SAML chains/namespace confusion leading to full authentication bypasses in some Ruby/PHP SAML ecosystems), HTTP desynchronisation/request smuggling (including new exploitation primitives and TRACE-assisted desync techniques that can enable widespread takeover), cookie-parser attacks (bypassing __Host/__Secure prefixes and HttpOnly protections via novel "cookie sandwich" and phantom $Version-
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- portswigger_research
- Record identifier
- eb4c655a4346e05a09927fe65ea296154ce8db647f5dcb28da644a7a1e8cffb3
- Enrichment time
- 2026-03-13T20:51:57Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.