PortSwigger Launches Voting for Top 10 Web Hacking Techniques of 2025
PortSwigger Research has announced that nominations are closed and voting is now live for the annual 'Top 10 Web Hacking Techniques of 2025' list. This community-driven initiative aims to highlight novel, practical, and reusable web security research from the past year, distinguishing enduring techniques from fleeting vulnerabilities. The process involves a timeline where community votes create a shortlist of fifteen candidates, followed by a panel vote to determine the final ten winners, with results scheduled for publication on February 3, 2026. James Kettle, Director of Research at PortSwigger, emphasized the importance of identifying underlying methods, such as JNDI Injection or cache poisoning strategies, rather than isolated exploits. Recent notable nominations include advanced techniques involving Next.js race conditions, Go parser inconsistencies, HTTP/1.1 desynchronization, and SAML authentication bypasses. The project serves as a curated resource for security professionals to stay updated on critical advancements in web application security. Participants are encouraged to follow PortSwigger’s social media channels for updates, as email addresses are not collected. This annual event fosters collaboration within the cybersecurity community, ensuring that significant research findings are recognized and accessible for broader application in system defense and testing.
Wire timeline
PortSwigger Launches Voting for Top 10 Web Hacking Techniques of 2025
PortSwigger Research has announced that nominations are closed and voting is now live for the annual 'Top 10 Web Hacking Techniques of 2025' list. This community-driven initiative aims to highlight novel, practical, and reusable web security research from the past year, distinguishing enduring techniques from fleeting vulnerabilities. The process involves a timeline where community votes create a shortlist of fifteen candidates, followed by a panel vote to determine the final ten winners, with results scheduled for publication on February 3, 2026. James Kettle, Director of Research at PortSwigger, emphasized the importance of identifying underlying methods, such as JNDI Injection or cache poisoning strategies, rather than isolated exploits. Recent notable nominations include advanced techniques involving Next.js race conditions, Go parser inconsistencies, HTTP/1.1 desynchronization, and SAML authentication bypasses. The project serves as a curated resource for security professionals to stay updated on critical advancements in web application security. Participants are encouraged to follow PortSwigger’s social media channels for updates, as email addresses are not collected. This annual event fosters collaboration within the cybersecurity community, ensuring that significant research findings are recognized and accessible for broader application in system defense and testing.
PortSwigger Research