← Back to BrewedIntel
vulnerabilityhighVulnerability DisclosureWeb Application Security

Aug 27, 2025 • PortSwigger Research

"The entire internet is broken": ethical hacking expert John Hammond meets James Kettle

Security researchers John Hammond and James Kettle have collaborated to highlight a critical security issue affecting tens of millions of websites globally....

Source
PortSwigger Research
Category
vulnerability
Severity
high

Executive Summary

Security researchers John Hammond and James Kettle have collaborated to highlight a critical security issue affecting tens of millions of websites globally. The discussion centers on widespread vulnerabilities within web application security frameworks that potentially allow unauthorized compromise. While specific technical details are not fully elaborated in the provided excerpt, the scale suggests a systemic risk across the internet infrastructure. The severity is considered high due to the potential exposure of vast numbers of organizations and users. Mitigation strategies likely involve rigorous application security testing, patching known vulnerabilities, and adopting secure coding practices. This research underscores the fragility of current web security postures. Organizations are advised to monitor emerging advisories related to this collaboration for specific remediation steps. Immediate attention to web application firewalls and vulnerability scanning is recommended to prevent exploitation by malicious actors seeking to leverage these widespread weaknesses for initial access.

Summary

In a brand-new collaboration between ethical hacking and AppSec expert John Hammond and world-renowned security researcher James Kettle, the pair explore how tens of millions of websites are compromis

Published Analysis

Security researchers John Hammond and James Kettle have collaborated to highlight a critical security issue affecting tens of millions of websites globally. The discussion centers on widespread vulnerabilities within web application security frameworks that potentially allow unauthorized compromise. While specific technical details are not fully elaborated in the provided excerpt, the scale suggests a systemic risk across the internet infrastructure. The severity is considered high due to the potential exposure of vast numbers of organizations and users. Mitigation strategies likely involve rigorous application security testing, patching known vulnerabilities, and adopting secure coding practices. This research underscores the fragility of current web security postures. Organizations are advised to monitor emerging advisories related to this collaboration for specific remediation steps. Immediate attention to web application firewalls and vulnerability scanning is recommended to prevent exploitation by malicious actors seeking to leverage these widespread weaknesses for initial access. In a brand-new collaboration between ethical hacking and AppSec expert John Hammond and world-renowned security researcher James Kettle, the pair explore how tens of millions of websites are compromis In a brand-new collaboration between ethical hacking and AppSec expert John Hammond and world-renowned security researcher James Kettle, the pair explore how tens of millions of websites are compromis