<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Http-Desync on CuraSec</title><link>https://curasec.metacog.co.kr/tags/http-desync/</link><description>Recent content in Http-Desync on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 07 Aug 2026 11:54:55 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/http-desync/index.xml" rel="self" type="application/rss+xml"/><item><title>AI Tool Finds Novel HTTP Desync Techniques; Apache Traffic Server 0-Day</title><link>https://curasec.metacog.co.kr/insights/2026-08-07-ai-assisted-http-terminator-finds-novel-http-desync-techniqu/</link><pubDate>Fri, 07 Aug 2026 11:54:55 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-07-ai-assisted-http-terminator-finds-novel-http-desync-techniqu/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> An Apache Traffic Server zero-day surfaced during this research with no patch yet available; confirm whether ATS is in your proxy stack and monitor PortSwigger and Apache advisories for remediation guidance. The novel desync techniques also warrant a review of request-handling assumptions in any HTTP pipeline you operate.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> PortSwigger&amp;rsquo;s research introduces new HTTP desynchronization primitives that expand the attack surface for reverse proxies and CDNs, but no IOCs, active exploitation, or mappable TTPs are published yet — file for context when building HTTP-layer detections.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item></channel></rss>