Fetching from the wire…
Security2026-07-28 · source-backed
PortSwigger opened Burp AT to Burp Suite Professional users on July 27. Scope, tool access, and approval rules live outside the model in a propose-enforce-decide loop, with every request and decision logged for reproducibility, plus a library of pentesting skills co-developed with PortSwigger Research replacing general model improvisation. One beta tester analyzed 66,000 lines of minified JavaScript in a four-day engagement and surfaced a critical vulnerability that would otherwise have gone untested for another year. Dafydd Stuttard: "Burp AT is new, and it has to earn that trust in the real world." (PortSwigger)
Each link below shares sources, entities, or timing with this story.
James Kettle published the whitepaper August 5, presented at Black Hat and DEF CON (PortSwigger). The architecture detail is what agent builders should copy: Turbo Intruder got an MCP interface plus Python orchestration, and the exploitation agent's script was deliberately spl...
v0.14.0 landed July 28 and model/tool data is no longer logged unless you explicitly opt in. It also brings Programmatic Tool Calling to JS (the model generates hosted JavaScript that coordinates tools and reduces intermediate results, preserved across streaming, sessions, and...
xAI launched Grok 4.5 and Grok Build on July 8, trained partly on Cursor developer-session data. The numbers are loud: 83.3% on Terminal-Bench 2.1, 64.7% on SWE-Bench Pro, priced at $2/$6 per million tokens. On a single coding task that works out to roughly $2.49 versus $11.80...
Released August 1, it adds a tier-aware merge that stops file layers being dropped during incremental rebuilds, preserves the graph's directed flag through graphify update, fixes edge rendering in query results, and resolves C# members, Kotlin anonymous objects and Ruby mixins...
Two thirds. Not two thirds of a contrived jailbreak set. Two thirds of realistic malicious issue requests, against the exact three tools most of the people reading this run daily. Ankur Singh, Jinqiu Yang, and Tse-Hsun Chen built IssueTrojanBench across four attack categories...
jazzzooo announced Buz July 24: a fork of Bun taken from the last commit before the Rust migration, rebuilt against modern Zig and achieving sub-1-second incremental compiles, with 11,000+ lines of dead code removed. The author is upfront that it's "nowhere near ready for prod...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.