Fetching from the wire…
Security2026-07-28 · source-backed
PortSwigger opened Burp AT to Burp Suite Professional users on July 27. Scope, tool access, and approval rules live outside the model in a propose-enforce-decide loop, with every request and decision logged for reproducibility, plus a library of pentesting skills co-developed with PortSwigger Research replacing general model improvisation. One beta tester analyzed 66,000 lines of minified JavaScript in a four-day engagement and surfaced a critical vulnerability that would otherwise have gone untested for another year. Dafydd Stuttard: "Burp AT is new, and it has to earn that trust in the real world." (PortSwigger)
Each link below shares sources, entities, or timing with this story.
Shared entities / Shared topic / What happened next
Both cover JavaScript, July; overlapping topics (approval, model); picks up the JavaScript thread on 2026-07-29.
Shared entity: July / Shared topic / Earlier coverage / Tension
Both cover July; overlapping topics (decision, model, trust); earlier July coverage from 2026-07-14.
Shared entities / Earlier coverage / Tension
Both cover July, Scope; earlier July coverage from 2026-07-26; pushes against this story (against).
Both cover JavaScript, July; earlier JavaScript coverage from 2026-07-25; pushes against this story (against).
CodeQL supports JavaScript / Shared entity: JavaScript / Earlier coverage
Linked by a graph relationship (CodeQL supports JavaScript); both cover JavaScript; earlier JavaScript coverage from 2026-07-12.
Shared entity: July / Shared topic / Earlier coverage / Tension
Both cover July; overlapping topics (access, model); earlier July coverage from 2026-07-24.
Both cover July; overlapping topics (access, model); earlier July coverage from 2026-07-23.
Both cover July; overlapping topics (access, another); earlier July coverage from 2026-07-09.