For production use, deploy one or more dedicated scanning machines. Running scans on the DAST server machine may degrade performance. You need to configure your ...
This release adds the ability to export SMTP Collaborator interactions as email files, expands hotkey and title bar customization, and improves command palette performance. It also includes a range of ...
This release adds customisable title bar actions, multiple evidence items for manually created issues, and evidence highlighting for issues raised by Burp AT. It also includes bug fixes and a Java ...
Webmail has been around for decades and it's always had to solve a very difficult problem of taking untrusted HTML and displaying it to the user in a safe way. This is made even more challenging by ...
Burp AT brings agentic AI to human-led pentesting, with Burp Suite’s proven tools, your project context, and purpose-built skills. You decide how much work agents take on. Burp enforces the boundaries ...
This release updates the bundled Java runtime to Java 26. It also includes improvements to Burp Scanner and a range of bug fixes.
Today, we are delighted to launch our official Burp Ambassador Program: a community initiative to collaborate more closely with experienced Burp users, and support the great work they’re already doing ...
We’re excited to announce a new partnership with Meta Bug Bounty, bringing together two organizations committed to raising the bar for web security at a global scale. This partnership brings together ...
This release adds collections for secure message sharing, quick URL actions in command palette, OAuth2 Client Credentials support for API scanning, and improvements to Comparer and extension hotkeys, ...
If you've ever used Burp Intruder or Turbo Intruder, you'll be familiar with the ritual of manually digging through thousands of responses by repeatedly sorting the table via length, status code, etc.
I discovered how to use CSS to steal attribute data without selectors and stylesheet imports! This means you can now exploit CSS injection via style attributes! Learn how below: Someone asked if you ...
Sometimes people think they've found HTTP request smuggling, when they're actually just observing HTTP keep-alive or pipelining. This is usually a false positive, but sometimes there's actually a real ...