I'm sure you'll agree that it's pretty shocking, and it works in every browser. It's also a pretty nice way to bypass a WAF. Let's continue the journey. If localName returns a lowercase version of the ...
This release adds customisable title bar actions, multiple evidence items for manually created issues, and evidence highlighting for issues raised by Burp AT. It also includes bug fixes and a Java ...
Webmail has been around for decades and it's always had to solve a very difficult problem of taking untrusted HTML and displaying it to the user in a safe way. This is made even more challenging by ...
Burp AT brings agentic AI to human-led pentesting, with Burp Suite’s proven tools, your project context, and purpose-built skills. You decide how much work agents take on. Burp enforces the boundaries ...
Throughout May 2026 we ran Extensibility Month on the PortSwigger Discord server - a full month of talks, workshops, community sessions, and the Burp Extension Awards, decided by community vote. The ...
This release updates the bundled Java runtime to Java 26. It also includes improvements to Burp Scanner and a range of bug fixes.
This release introduces a combined installer for Burp Suite Professional and Community Edition, greater extension control over HTTP traffic, Markdown support in Notes, and collection-level notes in ...
Welcome to the Top 10 Web Hacking Techniques of 2025, the 19th edition of our annual community-powered effort to identify the most innovative must-read web security research published in the last year ...
This release introduces the Discover tab, faster table navigation with command palette, smarter SQLi detection, SPNEGO support for NTLM, plus other improvements, a Java update, and a browser upgrade.
Two new critical vulnerabilities, collectively known as React2Shell (CVE-2025-55182 and CVE-2025-66478), are rapidly gaining traction in the security community. Default scans in both versions of Burp ...
WebSocket Turbo Intruder is a Burp Suite extension for fuzzing WebSocket messages with custom Python code. It extends the Burp Suite engine so it can exploit the WebSocket protocol specific ...
At PortSwigger, we believe AI has the power to transform penetration testing - not by replacing human testers, but by augmenting them. With the release of Burp Suite Professional 2025.2, we’re ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results