# PortSwigger Blog

Articles and product insights from the PortSwigger team. Keep up to date with Burp Suite and the world of web security by visiting our blog.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Can AI invent new attack techniques? New research from James Kettle and PortSwigger Research

DevFeed: [Can AI invent new attack techniques? New research from James Kettle and PortSwigger Research](<https://devfeed.tech/articles/can-ai-invent-new-attack-techniques-new-research-from-james-kettle-and-portswigger-research-7702.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/can-ai-invent-new-attack-techniques-new-research-from-james-kettle-and-portswigger-research>)

Author: Kieron Hughes

Published: 2026-08-12T09:04:45Z

Content type: article

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [AI research agents](<https://devfeed.tech/topics/ai-research-agents.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [autonomous](<https://devfeed.tech/tags/autonomous.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [http](<https://devfeed.tech/tags/http.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [research](<https://devfeed.tech/tags/research.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

PortSwigger Research describes the HTTP Terminator, an autonomous system used to generate and test new HTTP desync attack techniques against authorized bug-bounty targets. The research emphasizes that human expertise remained important in steering follow-on discoveries.

### Source excerpt

We already know AI can find vulnerabilities. James Kettle, PortSwigger's Director of Research, wanted to answer a harder question: can an autonomous system invent genuinely new attack techniques? To f

## How Burp AT helped expose whistleblower reports via a critical vulnerability that was overlooked for years

DevFeed: [How Burp AT helped expose whistleblower reports via a critical vulnerability that was overlooked for years](<https://devfeed.tech/articles/how-burp-at-helped-expose-whistleblower-reports-via-a-critical-vulnerability-that-was-overlooked-for-years-7717.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/how-burp-at-helped-expose-whistleblower-reports-via-a-critical-vulnerability-that-was-overlooked-for-years>)

Author: Andrzej Matykiewicz

Published: 2026-08-04T14:45:31Z

Content type: article

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [Code](<https://devfeed.tech/topics/code.md>), [API](<https://devfeed.tech/topics/api.md>), [Web](<https://devfeed.tech/topics/web.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [api](<https://devfeed.tech/tags/api.md>), [code](<https://devfeed.tech/tags/code.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [web](<https://devfeed.tech/tags/web.md>)

### AI overview

A security analyst describes how Burp AT analyzed a large client-side JavaScript bundle and uncovered a critical vulnerability in a whistleblower reporting system. Reports were protected only by six-character alphanumeric codes, making brute-force access and disclosure of confidential reports possible; Burp AT then helped demonstrate the exploit using an Intruder attack.

### Source excerpt

"It feels like I get 10X the productivity on an engagement. The difference is night and day." Profile Ray Huygen is a Security Analyst at Orange Cyberdefense, a managed security service provider with

## From capable AI models to trusted security testing

DevFeed: [From capable AI models to trusted security testing](<https://devfeed.tech/articles/from-capable-ai-models-to-trusted-security-testing-7706.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/from-capable-ai-models-to-trusted-security-testing>)

Author: Kieron Hughes

Published: 2026-07-30T14:58:47Z

Content type: article

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [AI Models](<https://devfeed.tech/topics/ai-models.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [audit-trail](<https://devfeed.tech/tags/audit-trail.md>), [black-hat](<https://devfeed.tech/tags/black-hat.md>), [code](<https://devfeed.tech/tags/code.md>), [http](<https://devfeed.tech/tags/http.md>), [models](<https://devfeed.tech/tags/models.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [tools](<https://devfeed.tech/tags/tools.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

PortSwigger describes Burp AT, launched in public beta for Burp Suite Professional users, as a response to research into agentic systems for security testing. The article explains how agents can generate hypotheses, test them, interpret evidence, and pursue longer chains of work, while Burp enforces permissions and scope boundaries, pauses for approval when configured, and records requests and tool activity for inspection.

### Source excerpt

This week, we launched Burp AT in public beta for Burp Suite Professional users. Next week at Black Hat, PortSwigger Research will reveal more of the work that helped shape our direction. Burp AT is o

## Introducing Burp AT: agentic AI, built on two decades of Burp Suite

DevFeed: [Introducing Burp AT: agentic AI, built on two decades of Burp Suite](<https://devfeed.tech/articles/introducing-burp-at-agentic-ai-built-on-two-decades-of-burp-suite-7732.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/introducing-burp-at>)

Author: Fran Hutchings

Published: 2026-07-27T12:51:51Z

Content type: release

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [AI Bots](<https://devfeed.tech/topics/ai-bots.md>)

Tags: [agentic-ai](<https://devfeed.tech/tags/agentic-ai.md>), [agents](<https://devfeed.tech/tags/agents.md>), [frontier-ai-models](<https://devfeed.tech/tags/frontier-ai-models.md>), [release](<https://devfeed.tech/tags/release.md>), [skills](<https://devfeed.tech/tags/skills.md>), [tools](<https://devfeed.tech/tags/tools.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Burp AT launches in public beta for Burp Suite Professional, bringing agentic AI into human-led penetration testing with specialist tools, project context, and enforced boundaries.

### Source excerpt

Burp AT brings agentic AI to human-led pentesting, with Burp Suite's proven tools, your project context, and purpose-built skills. You decide how much work agents take on. Burp enforces the boundaries

## Burp's new Ambassadors: learn from the people who use Burp Suite everyday

DevFeed: [Burp's new Ambassadors: learn from the people who use Burp Suite everyday](<https://devfeed.tech/articles/burp-s-new-ambassadors-learn-from-the-people-who-use-burp-suite-everyday-7700.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/burps-new-ambassadors-learn-from-the-people-who-use-burp-suite-everyday>)

Author: Fran Hutchings

Published: 2026-07-17T13:35:25Z

Content type: article

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Mobile Security](<https://devfeed.tech/topics/mobile-security.md>), [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>)

Tags: [ambassador](<https://devfeed.tech/tags/ambassador.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [bounty](<https://devfeed.tech/tags/bounty.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [community](<https://devfeed.tech/tags/community.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [mobile](<https://devfeed.tech/tags/mobile.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>), [web](<https://devfeed.tech/tags/web.md>)

### AI overview

PortSwigger introduces four new Burp Ambassadors and highlights their contributions to web application security, including research, education, penetration testing, bug bounty work, community events, and practical Burp Suite workflows.

### Source excerpt

Growing our Burp Ambassador community Meet our newest Burp Ambassadors Katie Paxton-Fear Malek Mohammad Yogesh Tantak James Lester Looking ahead Interested in getting involved? Growing our Burp Ambass

## Heading to Vegas? Meet PortSwigger at Black Hat, BSides, and DEF CON 34.

DevFeed: [Heading to Vegas? Meet PortSwigger at Black Hat, BSides, and DEF CON 34.](<https://devfeed.tech/articles/heading-to-vegas-meet-portswigger-at-black-hat-bsides-and-def-con-34-7715.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/heading-to-vegas-meet-portswigger-at-black-hat-bsides-and-def-con-34>)

Author: Fran Hutchings

Published: 2026-07-09T09:20:06Z

Content type: news

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Extension](<https://devfeed.tech/topics/extension.md>), [Web](<https://devfeed.tech/topics/web.md>), [IntelliJ IDEA](<https://devfeed.tech/topics/intellij-idea.md>)

Tags: [black-hat](<https://devfeed.tech/tags/black-hat.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [event](<https://devfeed.tech/tags/event.md>), [events](<https://devfeed.tech/tags/events.md>), [extension](<https://devfeed.tech/tags/extension.md>), [intellij](<https://devfeed.tech/tags/intellij.md>), [java](<https://devfeed.tech/tags/java.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>), [web](<https://devfeed.tech/tags/web.md>)

### AI overview

PortSwigger announces its presence at Black Hat USA, BSides Las Vegas, DEF CON 34, and related events in Las Vegas, including workshops, hands-on sessions, research talks, and opportunities to discuss Burp Suite, web security, security testing, and AppSec workflows.

### Source excerpt

First hand of the week: Find us at BSides Workshop: Burp But Yours, with Hannah and Tib3rius Center stage: Visit us at Black Hat USA - Booth 5342 Lightning talks at the booth Catch our researchers' br

## Burp Extensibility 2026: Awards, Talks, and Highlights

DevFeed: [Burp Extensibility 2026: Awards, Talks, and Highlights](<https://devfeed.tech/articles/burp-extensibility-2026-awards-talks-and-highlights-7693.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/burp-extensibility-2026-awards-talks-and-highlights>)

Author: Fran Hutchings

Published: 2026-06-19T12:18:14Z

Content type: article

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Extension](<https://devfeed.tech/topics/extension.md>), [Reconnaissance](<https://devfeed.tech/topics/recon.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [JSON Web Tokens](<https://devfeed.tech/topics/jwt.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [auth](<https://devfeed.tech/tags/auth.md>), [awards](<https://devfeed.tech/tags/awards.md>), [community](<https://devfeed.tech/tags/community.md>), [discord](<https://devfeed.tech/tags/discord.md>), [extension](<https://devfeed.tech/tags/extension.md>), [pii](<https://devfeed.tech/tags/pii.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [tokens](<https://devfeed.tech/tags/tokens.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [workshops](<https://devfeed.tech/tags/workshops.md>)

### AI overview

PortSwigger's Extensibility Month highlighted Burp Suite extensions, Bambdas, and BChecks through talks, workshops, community sessions, and the 2026 Burp Extension Awards. The article summarizes the community-voted award process and notable tools for reconnaissance, authentication, access control, workflow manipulation, and vulnerability discovery.

### Source excerpt

The 2026 Burp Suite Extension Awards Best Recon & Discovery Best Auth & Access Control Best Workflow & Manipulation Best API & Specialist Testing Hidden Gem Most Nominated The talks In

## The beast needs a cage: What's next for AppSec post-Mythos

DevFeed: [The beast needs a cage: What's next for AppSec post-Mythos](<https://devfeed.tech/articles/the-beast-needs-a-cage-what-s-next-for-appsec-post-mythos-7738.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/the-beast-needs-a-cage-whats-next-for-appsec-post-mythos>)

Author: Dafydd Stuttard

Published: 2026-05-12T14:18:47Z

Content type: opinion

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [AI Chat](<https://devfeed.tech/topics/ai-chat.md>), [AI Bots](<https://devfeed.tech/topics/ai-bots.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [audit-trail](<https://devfeed.tech/tags/audit-trail.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [llms](<https://devfeed.tech/tags/llms.md>), [safety](<https://devfeed.tech/tags/safety.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

An opinion piece on how increasingly capable LLMs could automate application-security vulnerability workflows, while their nondeterminism and ability to act create safety and assurance challenges.

### Source excerpt

Now that the dust has settled on Mythos dropping, there is space for more considered reflection on the direction of travel. Mythos wasn't a surprise; it's another data point on a trajectory that's bee

## 3 ways custom scan checks turn practitioner knowledge into scalable automation

DevFeed: [3 ways custom scan checks turn practitioner knowledge into scalable automation](<https://devfeed.tech/articles/3-ways-custom-scan-checks-turn-practitioner-knowledge-into-scalable-automation-7686.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/3-ways-custom-scan-checks-turn-practitioner-knowledge-into-scalable-automation>)

Author: Hassan Ud-Deen

Published: 2026-05-01T06:52:00Z

Content type: article

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>)

Tags: [apis](<https://devfeed.tech/tags/apis.md>), [automation](<https://devfeed.tech/tags/automation.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

The article explains how Burp Suite custom scan checks turn pentesters' vulnerability knowledge and manual proofs of concept into repeatable, scalable DAST tests. It describes using tailored detection logic to rapidly assess applications and APIs after a CVE disclosure.

### Source excerpt

Senior pentesters have a deeply refined intuition about what is vulnerable in an environment. The problem? That expertise is often siloed with an individual and trapped in their notes or Python scripts.

## PortSwigger recognized at the Northern Tech Awards 2026.

DevFeed: [PortSwigger recognized at the Northern Tech Awards 2026.](<https://devfeed.tech/articles/portswigger-recognized-at-the-northern-tech-awards-2026-7735.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/portswigger-recognized-at-the-northern-tech-awards-2026>)

Author: Fran Hutchings

Published: 2026-04-28T10:42:54Z

Content type: news

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Web](<https://devfeed.tech/topics/web.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [awards](<https://devfeed.tech/tags/awards.md>), [global](<https://devfeed.tech/tags/global.md>), [growth](<https://devfeed.tech/tags/growth.md>), [innovation](<https://devfeed.tech/tags/innovation.md>), [leadership](<https://devfeed.tech/tags/leadership.md>), [security](<https://devfeed.tech/tags/security.md>), [web](<https://devfeed.tech/tags/web.md>)

### AI overview

PortSwigger won the Overall Judges' Award at the 2026 Northern Tech Awards, recognizing its performance in growth, innovation, global ambition, cultural excellence, and leadership. The company says it will continue investing in research, evolving its products, and supporting its mission to help secure the web.

### Source excerpt

We're proud to announce that PortSwigger recently won the Overall Judges' Award at the Northern Tech Awards 2026. The Northern Tech Awards are run by GP Bullhound, the tech advisory and investment fir

## Introducing the official Burp Ambassador Program

DevFeed: [Introducing the official Burp Ambassador Program](<https://devfeed.tech/articles/introducing-the-official-burp-ambassador-program-7733.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/introducing-the-official-burp-ambassador-program>)

Author: Fran Hutchings

Published: 2026-04-16T13:24:25Z

Content type: news

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>)

Tags: [ambassador](<https://devfeed.tech/tags/ambassador.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [community](<https://devfeed.tech/tags/community.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [extension](<https://devfeed.tech/tags/extension.md>)

### AI overview

PortSwigger announces the Burp Ambassador Program, a community initiative for experienced Burp users to help shape Burp Suite and share application-security knowledge.

### Source excerpt

Why we're launching the program What it means to be a Burp Ambassador What we're aiming for Our Burp Ambassadors Alan Levy Corey Ball Federico Dotta Rana Khalil Tib3rius Looking ahead Get Involved - B

## PortSwigger partners with Meta Bug Bounty to empower bug hunters with training and Pro licenses

DevFeed: [PortSwigger partners with Meta Bug Bounty to empower bug hunters with training and Pro licenses](<https://devfeed.tech/articles/portswigger-partners-with-meta-bug-bounty-to-empower-bug-hunters-with-training-and-pro-licenses-7734.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/portswigger-partners-with-meta-bug-bounty-to-empower-bug-hunters-with-training-and-pro-licenses>)

Author: Fran Hutchings

Published: 2026-04-07T12:12:07Z

Content type: release

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Web](<https://devfeed.tech/topics/web.md>), [Meta](<https://devfeed.tech/topics/meta.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>)

Tags: [accessibility](<https://devfeed.tech/tags/accessibility.md>), [bounty](<https://devfeed.tech/tags/bounty.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [collaboration](<https://devfeed.tech/tags/collaboration.md>), [education](<https://devfeed.tech/tags/education.md>), [meta](<https://devfeed.tech/tags/meta.md>), [partners](<https://devfeed.tech/tags/partners.md>), [security](<https://devfeed.tech/tags/security.md>), [tooling](<https://devfeed.tech/tags/tooling.md>), [training](<https://devfeed.tech/tags/training.md>), [web](<https://devfeed.tech/tags/web.md>)

### AI overview

PortSwigger announces a partnership with Meta Bug Bounty to provide eligible bug hunters with training, learning pathways, and Burp Suite Professional licenses. The initiative aims to improve testing efficiency, help researchers identify high-impact vulnerabilities, and strengthen the global security research community.

### Source excerpt

More power for bug hunters An education-first approach to bug bounty Rewards on Meta's Bug Bounty Platform Our shared vision Ready to get started? We're excited to announce a new partnership with Meta

## HTTP/1.1 Must Die: Conquering the 0.CL Challenge

DevFeed: [HTTP/1.1 Must Die: Conquering the 0.CL Challenge](<https://devfeed.tech/articles/http-1-1-must-die-conquering-the-0-cl-challenge-7725.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/http-1-1-must-die-conquering-the-0-cl-challenge>)

Author: Fran Hutchings

Published: 2026-03-13T09:21:19Z

Content type: article

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Parser](<https://devfeed.tech/topics/parser.md>), [payload](<https://devfeed.tech/topics/payload.md>), [Extension](<https://devfeed.tech/topics/extension.md>), [Script](<https://devfeed.tech/topics/script.md>)

Tags: [article](<https://devfeed.tech/tags/article.md>), [extension](<https://devfeed.tech/tags/extension.md>), [http](<https://devfeed.tech/tags/http.md>), [payload](<https://devfeed.tech/tags/payload.md>), [security](<https://devfeed.tech/tags/security.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [tools](<https://devfeed.tech/tags/tools.md>)

### AI overview

A technical guide to the 0.CL variant of HTTP request smuggling, explaining the front-end/back-end parsing discrepancy, four proof-of-concept approaches, and detection with PortSwigger's HTTP Request Smuggler extension in a controlled lab.

### Source excerpt

Note: This is a guest post by pentester Julen Garrido Estévez (@b3xal). 1. Acknowledgements 2. Intro 3. Required tools 4. Strategy to solve/exploit the lab 5. Detecting 0.CL 5.1. Practical confirmatio

## Automation without alignment: The hidden cost of modern DAST

DevFeed: [Automation without alignment: The hidden cost of modern DAST](<https://devfeed.tech/articles/automation-without-alignment-the-hidden-cost-of-modern-dast-7688.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/automation-without-alignment-the-hidden-cost-of-modern-dast>)

Author: Dafydd Stuttard

Published: 2026-03-12T12:02:57Z

Content type: article

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [Security](<https://devfeed.tech/topics/security.md>), [Web app](<https://devfeed.tech/topics/webapp.md>), [Web](<https://devfeed.tech/topics/web.md>)

Tags: [automation](<https://devfeed.tech/tags/automation.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>), [tool](<https://devfeed.tech/tags/tool.md>), [web](<https://devfeed.tech/tags/web.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

### AI overview

The article argues that modern DAST automation delivers diminishing returns when it operates separately from manual web security testing. It presents DAST as an extension of practitioner workflows that still requires human judgment, and highlights the friction created when automated findings must be validated in a separate tool.

### Source excerpt

Watch the webinar recording: Burp Suite DAST x Burp Suite Professional: Better Together I'm a firm believer that if you want to understand how secure an application really is, you have to test how it

## PortSwigger X Intigriti: Burp Suite Professional licenses up for grabs with this new collaboration

DevFeed: [PortSwigger X Intigriti: Burp Suite Professional licenses up for grabs with this new collaboration](<https://devfeed.tech/articles/portswigger-x-intigriti-burp-suite-professional-licenses-up-for-grabs-with-this-new-collaboration-7736.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/portswigger-x-intigriti-burp-suite-professional-licenses-up-for-grabs-with-this-new-collaboration>)

Author: Fran Hutchings

Published: 2026-03-11T10:36:26Z

Content type: news

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [collaboration](<https://devfeed.tech/tags/collaboration.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>), [vulnerability-disclosure](<https://devfeed.tech/tags/vulnerability-disclosure.md>), [web](<https://devfeed.tech/tags/web.md>)

### AI overview

PortSwigger and Intigriti announced a collaboration that awards eligible bug bounty researchers a six-month Burp Suite Professional license after reaching 400 reputation points on Intigriti.

### Source excerpt

At PortSwigger, we're always looking for ways to enable the world to secure the web, and today we're excited to take that mission a step further. We're pleased to announce a new collaboration bringing

## How I sped up exploit validation in Repeater using Burp AI

DevFeed: [How I sped up exploit validation in Repeater using Burp AI](<https://devfeed.tech/articles/how-i-sped-up-exploit-validation-in-repeater-using-burp-ai-7719.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/how-i-sped-up-exploit-validation-in-repeater-using-burp-ai>)

Author: Hassan Ud-Deen

Published: 2026-01-22T15:18:00Z

Content type: article

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [AI Chat](<https://devfeed.tech/topics/ai-chat.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [api](<https://devfeed.tech/tags/api.md>), [auth](<https://devfeed.tech/tags/auth.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [rest-api](<https://devfeed.tech/tags/rest-api.md>), [saas](<https://devfeed.tech/tags/saas.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>), [validation](<https://devfeed.tech/tags/validation.md>), [workflow](<https://devfeed.tech/tags/workflow.md>)

### AI overview

A practitioner describes using Burp AI in Burp Suite Repeater to speed up exploratory application-security testing. In a time-boxed SaaS API assessment, it suggested concrete access-control tests based on a selected request and response.

### Source excerpt

Note: This is a guest post by IT security consultant Adarsh Kumar. I've been using Burp Suite day to day for years, so when Burp AI was introduced, I was curious how it would actually hold up dur

## Functional PoCs in less than a minute? Julen Garrido Estévez puts Burp AI to the test

DevFeed: [Functional PoCs in less than a minute? Julen Garrido Estévez puts Burp AI to the test](<https://devfeed.tech/articles/functional-pocs-in-less-than-a-minute-julen-garrido-estevez-puts-burp-ai-to-the-test-7708.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/functional-pocs-in-less-than-a-minute>)

Author: Hassan Ud-Deen

Published: 2026-01-16T00:00:00Z

Content type: article

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Prompt Engineering](<https://devfeed.tech/topics/prompt-engineering.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Web](<https://devfeed.tech/topics/web.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [analysis](<https://devfeed.tech/tags/analysis.md>), [cost](<https://devfeed.tech/tags/cost.md>), [generation](<https://devfeed.tech/tags/generation.md>), [hallucinations](<https://devfeed.tech/tags/hallucinations.md>), [insights](<https://devfeed.tech/tags/insights.md>), [security](<https://devfeed.tech/tags/security.md>), [time](<https://devfeed.tech/tags/time.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [web](<https://devfeed.tech/tags/web.md>)

### AI overview

A pentester evaluates Burp AI in Repeater using controlled tests across Web Security Academy labs, a deliberately vulnerable shop, and personal environments. The article compares prompting styles by cost, requests, time to proof of concept, adherence, and hallucinations, finding that clear free-form prompts provided the best overall balance and produced a valid PoC at low cost.

### Source excerpt

Note: This is a guest post by pentester Julen Garrido Estévez (@b3xal). Methodology Key results Examples Key learnings Prompt template A pentester's POV on Burp AI Pentester Julen Garrido Es

## Burp On Tour 2025: bringing the AppSec community together around the world

DevFeed: [Burp On Tour 2025: bringing the AppSec community together around the world](<https://devfeed.tech/articles/burp-on-tour-2025-bringing-the-appsec-community-together-around-the-world-7695.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/burp-on-tour-2025-bringing-the-appsec-community-together-around-the-world>)

Author: Amelia Coen

Published: 2025-12-12T11:34:28Z

Content type: article

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [HTTP](<https://devfeed.tech/topics/http.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>)

Tags: [agentic-ai](<https://devfeed.tech/tags/agentic-ai.md>), [ai](<https://devfeed.tech/tags/ai.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [black-hat](<https://devfeed.tech/tags/black-hat.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [developer](<https://devfeed.tech/tags/developer.md>), [http](<https://devfeed.tech/tags/http.md>), [web-apps](<https://devfeed.tech/tags/web-apps.md>)

### AI overview

Burp On Tour 2025 brought Burp Suite and PortSwigger representatives to universities, security conferences, meetups, and global events to connect with the application security community. The article highlights research on risks in applications relying on downstream HTTP/1.1, new agentic AI capabilities in Burp AI, and Burp Suite DAST runtime testing for modern web applications and APIs with CI/CD integration.

### Source excerpt

In 2025, we set out with a simple mission: take Burp Suite on the road and meet the global AppSec community where you are. Burp On Tour was born from our desire to learn from you; the brilliant people

## DAST without disruption: Burp Suite DAST winter update 2025

DevFeed: [DAST without disruption: Burp Suite DAST winter update 2025](<https://devfeed.tech/articles/dast-without-disruption-burp-suite-dast-winter-update-2025-7698.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/burp-suite-dast-winter-update-2025>)

Author: Rob Samuels

Published: 2025-12-11T13:09:30Z

Content type: release

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [API](<https://devfeed.tech/topics/api.md>), [OpenAPI Specification](<https://devfeed.tech/topics/openapi.md>), [Postman](<https://devfeed.tech/topics/postman.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [CSS](<https://devfeed.tech/topics/css.md>), [selectors](<https://devfeed.tech/topics/selectors.md>), [Single-page application (SPA)](<https://devfeed.tech/topics/spa.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [automation](<https://devfeed.tech/tags/automation.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [environment-variables](<https://devfeed.tech/tags/environment-variables.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [openapi](<https://devfeed.tech/tags/openapi.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [responses](<https://devfeed.tech/tags/responses.md>), [security](<https://devfeed.tech/tags/security.md>), [selectors](<https://devfeed.tech/tags/selectors.md>), [troubleshooting](<https://devfeed.tech/tags/troubleshooting.md>), [ui](<https://devfeed.tech/tags/ui.md>), [update](<https://devfeed.tech/tags/update.md>)

### AI overview

A winter 2025 update to Burp Suite DAST adds scan freeze windows, improved site and folder management, editable recorded login flows, real-time authentication diagnostics, XPath and CSS session checks, and imports for Postman collections with environment variables. The changes aim to make automated application and API security scanning more reliable and easier to manage at scale.

### Source excerpt

AppSec teams are under constant pressure to secure fast-moving applications without slowing anything down. But scanning windows, fragile authentication, and sprawling API estates often get in the way

## How to detect React2Shell with Burp Suite

DevFeed: [How to detect React2Shell with Burp Suite](<https://devfeed.tech/articles/how-to-detect-react2shell-with-burp-suite-7723.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/how-to-detect-react2shell-with-burp-suite>)

Author: Tom Ryder

Published: 2025-12-05T13:53:30Z

Content type: tutorial

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Security](<https://devfeed.tech/topics/security.md>), [Next.js](<https://devfeed.tech/topics/next-js.md>), [React](<https://devfeed.tech/topics/react.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [configuration](<https://devfeed.tech/topics/configuration.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [automated](<https://devfeed.tech/tags/automated.md>), [community](<https://devfeed.tech/tags/community.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [cve](<https://devfeed.tech/tags/cve.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [incident](<https://devfeed.tech/tags/incident.md>), [log4j](<https://devfeed.tech/tags/log4j.md>), [next-js](<https://devfeed.tech/tags/next-js.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [react](<https://devfeed.tech/tags/react.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This tutorial explains how to detect the React2Shell vulnerabilities (CVE-2025-55182 and CVE-2025-66478) in Next.js-based applications using Burp Suite. It describes built-in default scans, custom scan configuration, and ActiveScan++ for automated detection and investigation.

### Source excerpt

Detecting React2Shell with Burp Suite Two new critical vulnerabilities, collectively known as React2Shell (CVE-2025-55182 and CVE-2025-66478), are rapidly gaining traction in the security community. D

## PortSwigger x TryHackMe: Supporting Advent of Cyber

DevFeed: [PortSwigger x TryHackMe: Supporting Advent of Cyber](<https://devfeed.tech/articles/portswigger-x-tryhackme-supporting-advent-of-cyber-7737.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/portswigger-x-tryhackme-supporting-advent-of-cyber>)

Author: Hassan Ud-Deen

Published: 2025-12-01T09:00:00Z

Content type: news

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Web](<https://devfeed.tech/topics/web.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [automation](<https://devfeed.tech/tags/automation.md>), [beginner](<https://devfeed.tech/tags/beginner.md>), [community](<https://devfeed.tech/tags/community.md>), [learn](<https://devfeed.tech/tags/learn.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>)

### AI overview

PortSwigger describes its support for TryHackMe's Advent of Cyber, a December event built around beginner-friendly, hands-on security challenges. The article highlights web security, Burp Suite workflows, automation, and BurpAI, while presenting AI assistance as a way to improve pentesting efficiency without replacing human expertise.

### Source excerpt

Every December, TryHackMe's Advent of Cyber brings the security community together around a simple idea: learn something new by getting hands-on. Each day during the festive season reveals a beginner-

## Hacking with Burp AI in the Chesspocalypse: API expert Corey Ball showcases how Burp AI can support pentesters.

DevFeed: [Hacking with Burp AI in the Chesspocalypse: API expert Corey Ball showcases how Burp AI can support pentesters.](<https://devfeed.tech/articles/hacking-with-burp-ai-in-the-chesspocalypse-api-expert-corey-ball-showcases-how-burp-ai-can-support-pentesters-7713.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/hacking-with-burp-ai-in-the-chesspocalypse-api-expert-corey-ball-showcases-how-burp-ai-can-support-pentesters>)

Author: Amelia Coen

Published: 2025-11-14T15:09:32Z

Content type: article

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>)

Tags: [agentic-ai](<https://devfeed.tech/tags/agentic-ai.md>), [ai](<https://devfeed.tech/tags/ai.md>), [article](<https://devfeed.tech/tags/article.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [web-app](<https://devfeed.tech/tags/web-app.md>)

### AI overview

The article presents Burp AI in Burp Suite Professional as an agentic AI assistant for penetration testing. Corey Ball demonstrates how it analyzes requests, identifies vulnerabilities, adapts testing from failed SQL injection attempts to NoSQL injection, uncovers a flaw exposing coupon data, and explains findings to help testers learn and work more effectively.

### Source excerpt

AI isn't just reshaping cybersecurity - it's challenging testers to rethink their entire playbook. In his latest article, "Hacking with Burp AI in the Chesspocalypse", API expert Corey Ball draws less

## Can Burp AI hack a website? CyberMaddy explores the new agentic capabilities in Burp AI

DevFeed: [Can Burp AI hack a website? CyberMaddy explores the new agentic capabilities in Burp AI](<https://devfeed.tech/articles/can-burp-ai-hack-a-website-cybermaddy-explores-the-new-agentic-capabilities-in-burp-ai-7704.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/can-burp-ai-hack-a-website-cybermaddy-explores-the-new-agentic-capabilities-in-burp-ai>)

Author: Amelia Coen

Published: 2025-10-22T13:15:24Z

Content type: news

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [AI Chat](<https://devfeed.tech/topics/ai-chat.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [llm](<https://devfeed.tech/tags/llm.md>), [sql](<https://devfeed.tech/tags/sql.md>), [testing](<https://devfeed.tech/tags/testing.md>), [video](<https://devfeed.tech/tags/video.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [web](<https://devfeed.tech/tags/web.md>), [workflow](<https://devfeed.tech/tags/workflow.md>)

### AI overview

A video examines Burp AI's agentic capabilities for ethical web-security testing, including its use in Repeater to identify SQL injection, XSS, and insecure configurations.

### Source excerpt

In her latest video, CyberMaddy dives into the world of AI-driven ethical hacking, exploring how Burp AI performs in Repeater when tasked with finding web vulnerabilities like SQL injection, cross-sit

## Burp AI takes on a vulnerable web app: watch Tib3rius put Burp's new agentic capabilities to the test

DevFeed: [Burp AI takes on a vulnerable web app: watch Tib3rius put Burp's new agentic capabilities to the test](<https://devfeed.tech/articles/burp-ai-takes-on-a-vulnerable-web-app-watch-tib3rius-put-burp-s-new-agentic-capabilities-to-the-test-7691.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/burp-ai-takes-on-a-vulnerable-web-app-watch-tib3rius-put-burps-new-agentic-capabilities-to-the-test>)

Author: Amelia Coen

Published: 2025-10-22T12:59:05Z

Content type: article

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Web app](<https://devfeed.tech/topics/webapp.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [blog](<https://devfeed.tech/tags/blog.md>), [blog-post](<https://devfeed.tech/tags/blog-post.md>), [exploits](<https://devfeed.tech/tags/exploits.md>), [false-positives](<https://devfeed.tech/tags/false-positives.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [testing](<https://devfeed.tech/tags/testing.md>), [video](<https://devfeed.tech/tags/video.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [web-app](<https://devfeed.tech/tags/web-app.md>), [workflow](<https://devfeed.tech/tags/workflow.md>)

### AI overview

A video demonstrates Burp AI testing a deliberately vulnerable web app. It shows Burp AI autonomously exploiting discovered vulnerabilities, identifying false positives, and using agentic capabilities in Repeater to adapt payloads and approaches through natural-language prompts.

### Source excerpt

What happens when you set Burp AI loose on a deliberately vulnerable web app? In his latest video, Tib3rius takes Burp's new agentic Burp AI capabilities for a spin - and the results are seriously coo

[Next page](<https://devfeed.tech/sources/portswigger-blog.md?cursor=WyIyMDI1LTEwLTIyVDEyOjU5OjA1KzAwOjAwIiwgIjM1YTUwMGNkLWUzNmItNGI0OS1iZTMxLTUzNjUyMDMxNzMxNiJd>)