Top 10 web hacking techniques of 2025
2026-07-21T20:51:53Z•fd65fb970fbfe6e00a8b91c44178a4b8ad258dbfcfa90ef8f660480d25f360b4
SAMLauthentication-bypasscookie-prefix-bypasscookiescss-exfiltrationhttp-desynchttponly-bypassjwt-forgeryparser-inconsistencyrequest-smugglingresearch-collectiontoolingwebwebsocket
What happened
This PortSwigger Research collection (Top 10 Web Hacking Techniques of 2025 and related posts) surveys a year of high-impact web security research. Key findings include parser-level SAML inconsistencies that enable full authentication bypasses in Ruby and PHP SAML ecosystems (leading to unauthenticated admin access on targets such as GitLab Enterprise), widespread HTTP desynchronisation (desync) and request-smuggling techniques that can enable host takeover, new techniques to bypass cookie protections (__Host / __Secure prefixes and HttpOnly), novel CSS/inline-style exfiltration primitives, a
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- portswigger_research
- Record identifier
- fd65fb970fbfe6e00a8b91c44178a4b8ad258dbfcfa90ef8f660480d25f360b4
- Enrichment time
- 2026-07-21T20:51:53Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.