# How Burp AT helped expose whistleblower reports via a critical vulnerability that was overlooked for years

DevFeed: [How Burp AT helped expose whistleblower reports via a critical vulnerability that was overlooked for years](<https://devfeed.tech/articles/how-burp-at-helped-expose-whistleblower-reports-via-a-critical-vulnerability-that-was-overlooked-for-years-7717.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/how-burp-at-helped-expose-whistleblower-reports-via-a-critical-vulnerability-that-was-overlooked-for-years>)

Author: Andrzej Matykiewicz

Published: 2026-08-04T14:45:31Z

Content type: article

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [Code](<https://devfeed.tech/topics/code.md>), [API](<https://devfeed.tech/topics/api.md>), [Web](<https://devfeed.tech/topics/web.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [api](<https://devfeed.tech/tags/api.md>), [code](<https://devfeed.tech/tags/code.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [web](<https://devfeed.tech/tags/web.md>)

## AI overview

A security analyst describes how Burp AT analyzed a large client-side JavaScript bundle and uncovered a critical vulnerability in a whistleblower reporting system. Reports were protected only by six-character alphanumeric codes, making brute-force access and disclosure of confidential reports possible; Burp AT then helped demonstrate the exploit using an Intruder attack.

## Source excerpt

"It feels like I get 10X the productivity on an engagement. The difference is night and day." Profile Ray Huygen is a Security Analyst at Orange Cyberdefense, a managed security service provider with