Blog.Portswigger PortSwigger Launches Burp AT: Agentic AI for Penetration Testing
Article Content
- •Burp AT integrates agentic AI into Burp Suite Professional for enhanced pentesting.
- •Penetration testers can delegate tasks to AI while retaining control over the process.
- •A closed beta revealed a critical vulnerability in 66,000 lines of code that would have been missed.
PortSwigger has launched Burp AT in public beta, integrating agentic AI into Burp Suite Professional. This feature allows penetration testers to delegate specific tasks to AI agents while maintaining control over scope and conclusions. The AI can analyze complex code, such as minified JavaScript, and identify vulnerabilities that may go unnoticed otherwise. In a closed beta test, Burp AT helped uncover a critical vulnerability in a substantial codebase that would have remained untested for a year. The tool is designed to enhance human-led pentesting workflows, allowing professionals to focus on high-priority tasks. Burp AT is available now for Burp Suite Professional users, with plans for future enhancements and more autonomous testing capabilities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…