This section is displayed for the Audit selected items scan type. The URLs of the selected items are listed. Note that the same URL appears more than once if there are multiple requests to the same ...
This release adds customisable title bar actions, multiple evidence items for manually created issues, and evidence highlighting for issues raised by Burp AT. It also includes bug fixes and a Java ...
The Qualys WAS extension connects Burp with the Qualys Web Application Scanning (WAS) module on the Qualys Cloud Platform. It lets you import a WAS finding into Repeater to manually validate a scanner ...
Throughout May 2026 we ran Extensibility Month on the PortSwigger Discord server - a full month of talks, workshops, community sessions, and the Burp Extension Awards, decided by community vote. The ...
This release introduces a combined installer for Burp Suite Professional and Community Edition, greater extension control over HTTP traffic, Markdown support in Notes, and collection-level notes in ...
Today, we are delighted to launch our official Burp Ambassador Program: a community initiative to collaborate more closely with experienced Burp users, and support the great work they’re already doing ...
Welcome to the Top 10 Web Hacking Techniques of 2025, the 19th edition of our annual community-powered effort to identify the most innovative must-read web security research published in the last year ...
This post shows how to achieve a full authentication bypass in the Ruby and PHP SAML ecosystem by exploiting several parser-level inconsistencies: including attribute pollution, namespace confusion, ...
Two new critical vulnerabilities, collectively known as React2Shell (CVE-2025-55182 and CVE-2025-66478), are rapidly gaining traction in the security community. Default scans in both versions of Burp ...
Postman Collection Importer converts Postman collections and environments into Repeater tabs and Sitemap entries. The extension supports variable resolution, authentication methods, and multiple ...
If you've ever used Burp Intruder or Turbo Intruder, you'll be familiar with the ritual of manually digging through thousands of responses by repeatedly sorting the table via length, status code, etc.
WebSocket Turbo Intruder is a Burp Suite extension for fuzzing WebSocket messages with custom Python code. It extends the Burp Suite engine so it can exploit the WebSocket protocol specific ...