TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

PortSwigger Blog

HTTP/1.1 must die: Dafydd Stuttard on what this means for enterprise security

2025-10-09 · Read original ↗

ATT&CK techniques detected

2 predictions
T1588.006Vulnerabilities
70%
"http / 1. 1 must die : dafydd stuttard on what this means for enterprise security research academy my account customers about blog careers legal contact resellers attack surface visibility improve security posture, prioritize manual testing, free up time. ci - driven scanning mor…"
T1190Exploit Public-Facing Application
43%
"##s, service meshes, microservices, apis, and these are often from a range of different vendors. that complexity is fertile ground for hard - to - spot, protocol - level issues that often have critical implications for your security. in a large organization, a single successful d…"

Summary

At Black Hat USA 2025 and DEF CON 33, PortSwigger's Director of Research, James Kettle, unveiled new HTTP desync techniques that prove one thing beyond doubt: HTTP/1.1 is broken, and every organizatio