Cyber Security News

PortSwigger Launches Burp AT Agentic AI for Human-Led Web Penetration Testing

PortSwigger has officially launched Burp AT in public beta, bringing agentic AI capabilities directly into Burp Suite Professional for the first time.

The new feature allows penetration testers to delegate specific investigative tasks to AI agents while retaining full control over scope, judgment, and final conclusions, marking a significant shift in how professional web application security testing is conducted.

The launch addresses a growing question in the security community: not whether AI can find and exploit vulnerabilities, since frontier models already demonstrate that capability, but whether such AI can be trusted for professional testing work where accountability and reliability matter.

PortSwigger’s answer is a system that combines Burp Suite’s two-decade-old toolset with project-specific context and specialist pentesting skills developed alongside PortSwigger Research.

PortSwigger Launches Burp AT

Burp AT operates on four core pillars designed to make agentic testing viable in real engagements. First, agents work through Burp’s established tooling rather than starting from scratch, drawing on existing project data like captured traffic, target structure, and prior findings.

Second, a growing library of purpose-built pentesting skills gives agents structured methodologies instead of relying on general model knowledge, with new techniques added as PortSwigger’s researchers develop them.

Third, testers control autonomy levels, deciding what agents can execute independently, what requires approval, and what stays off-limits entirely.

Fourth, and critically, all boundaries are enforced by Burp’s tooling layer rather than the AI model itself, meaning every action is logged, and agents cannot bypass restrictions even if they propose them.

This architecture reflects PortSwigger’s core philosophy for the release: agents propose actions, Burp enforces limits, and the human tester decides.

Burp AT is built for a human to drive. MindFort, from a team that red-teamed frontier models for OpenAI and Anthropic, operates as an autonomous security engineer that runs continuously and patches what it finds.

During closed beta testing, the practical impact became clear. One pentester used Burp AT to analyze 66,000 lines of minified JavaScript within a four-day engagement, a task impossible to complete manually in that timeframe.

The agent reconstructed endpoints and workflows from the obfuscated code and flagged suspicious, unauthenticated areas for deeper investigation. This process surfaced a critical vulnerability that would likely have remained undetected for at least another year. The tester described the experience as transformative for both testing efficiency and skill development.

Because all agent activity runs through Burp Suite itself, testers retain reproducible evidence, including requests and responses, rather than having to trust an AI’s self-reported summary of its actions.

This initial release represents what PortSwigger calls the first phase of a longer roadmap. Currently, Burp AT functions within a human-led workflow, augmenting individual testers’ capacity rather than replacing their oversight.

PortSwigger has indicated that future iterations will introduce additional operating modes suited to teams and enterprises, potentially including more autonomous testing under standing policies with shared visibility and audit trails, while human-led testing remains a permanent option.

Speaking on the launch, PortSwigger Founder and CEO Dafydd Stuttard emphasized that trust must be earned rather than assumed. He noted that while Burp Suite has built credibility over more than 20 years of real-world use, Burp AT is new and must prove itself through the same process, which is why the company chose a public beta rather than a full release, inviting testers to stress-test the tool and shape its development.

Burp AT is available now for all Burp Suite Professional users, offering a practical entry point for security professionals looking to integrate agentic AI into their existing testing workflows without ceding control over sensitive engagements.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

2 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

2 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

3 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

4 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

4 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

5 hours ago