Guozhen AIGlobal AI field notes and model intelligence

Realtime AI News

PortSwigger adds AI agent to Burp Suite for autonomous penetration testing

PortSwigger has launched an AI agent, available in beta, for its Burp Suite, aiming to simplify attack simulations for cybersecurity teams. The agent uses large language models to form hypotheses and invoke pentesting tools, accelerating testing while keeping human experts in the loop, according to Security Boulevard.

Published
PortSwigger为Burp Suite新增AI智能体,渗透测试进入人机协作时代
Image source: portswigger.net

PortSwigger has launched an AI agent, available in beta, for its Burp Suite, aiming to simplify attack simulations for cybersecurity teams, according to Security Boulevard. The release marks a significant shift in how penetration testers approach web application security assessments.

Burp AT — Burp Agentic Testing — lets security professionals deploy AI agents that autonomously investigate leads, analyze application behavior, and surface vulnerabilities within Burp Suite's existing workflow. Rather than replacing human testers, it extends their capacity by handling time-intensive investigative work that would otherwise go unaddressed during engagements.

According to PortSwigger, Burp AT is built around four core principles: agents act through Burp's battle-hardened tooling and draw on project context including traffic, target structure, and prior discoveries; a library of purpose-built pentesting skills developed with PortSwigger Research gives agents structured methodologies; testers retain full control over autonomy, deciding what proceeds automatically, what requires approval, and what remains blocked; and scope and permission boundaries are enforced within Burp's tooling layer, architecturally separate from the underlying AI model, with every request and decision logged.

During closed beta testing, one pentester used Burp AT to analyze 66,000 lines of minified JavaScript — a task infeasible to complete manually within a standard four-day engagement. The agent reconstructed hidden endpoints and workflows referenced in the code, ultimately surfacing a critical vulnerability that PortSwigger says would otherwise have gone untested for at least another year.

PortSwigger frames Burp AT as addressing a trust problem rather than a capability problem. Frontier AI models can already form hypotheses, execute exploits, and interpret results. The real challenge is ensuring autonomy operates within verifiable, auditable constraints during professional engagements. Because all agent actions route through Burp Suite's infrastructure, testers retain reproducible evidence — requests, responses, and logs — rather than relying solely on an AI's self-reported account.

Founder and CEO Dafydd Stuttard emphasized that the public beta is meant to let real-world testing validate the tool's reliability, noting that Burp Suite has earned trust through more than two decades of use against real applications. Burp AT is live now in public beta, exclusively for Burp Suite Professional users, as the first phase of a broader rollout.

The move reflects how AI agents are entering every stage of security testing — from triaging leads and analyzing behavior to executing exploits — while keeping humans in the loop and making every action auditable.

What to watch: PortSwigger plans to eventually introduce additional autonomy modes for enterprise teams, including more autonomous testing under standing policy with shared visibility and auditability, while preserving human-led testing as a permanent operating mode — public beta feedback will set the pace.

Why it matters

The penetration-testing leader's AI agent signals that "AI investigates, humans approve" is becoming the standard shape of security testing, with auditability and scope control as the key competitive axes.

PortSwiggerBurp SuiteSecurity
Back to realtime news

Nearby Updates

All

08/04, 03:51

Northeastern student builds AI agent that fixes chemical plants' blueprints

Northeastern University industrial engineering student Sierre Ternoey built an AI agent that reads failure reports from chemical plant simulation software and automatically diagnoses and repairs the underlying process flow diagram. In its best configuration, the agent passed 26 of 30 test cases without disturbing the engineer's original design choices, according to Northeastern Global News.

08/04, 04:00

AWS teams with vibe-coding startup Superblocks to embed AI app building in private clouds

Vibe coding startup Superblocks announced a multi-year joint marketing agreement with AWS that lets its tool be embedded inside AWS customers' private clouds, so business users can build apps without data leaving the enterprise environment. The apps spin up Amazon Aurora databases in the private cloud and integrate with Amazon Bedrock, bringing them under IT management and security instead of becoming rogue applications.

08/04, 03:28

DesignArena creators raise $7.9 million to bring human taste to AI models

The company behind DesignArena — dubbed Intelligence — announced a $7.9 million seed round led by Index Ventures, with participation from Conviction, A*, and Valkyrie. DesignArena, now used by 5.3 million people, ranks AI-generated designs through A/B comparisons and sells the resulting human feedback to frontier labs, with the site currently generating $60 million in ARR.

08/04, 02:43

Apple finally fixed Siri. Why does it feel anticlimactic?

Apple's long-awaited AI overhaul has finally made Siri the assistant it was always supposed to be, ending years of delays. But the launch lands in an AI landscape where chatbots have evolved into agents that can code, reason, create media, and complete complex tasks, making a merely capable assistant feel far less revolutionary.