Webmail has been around for decades and it's always had to solve a very difficult problem of taking untrusted HTML and displaying it to the user in a safe way. This is made even more challenging by ...
Throughout May 2026 we ran Extensibility Month on the PortSwigger Discord server - a full month of talks, workshops, community sessions, and the Burp Extension Awards, decided by community vote. The ...
This release updates the bundled Java runtime to Java 26. It also includes improvements to Burp Scanner and a range of bug fixes.
This release introduces a combined installer for Burp Suite Professional and Community Edition, greater extension control over HTTP traffic, Markdown support in Notes, and collection-level notes in ...
Today, we are delighted to launch our official Burp Ambassador Program: a community initiative to collaborate more closely with experienced Burp users, and support the great work they’re already doing ...
Welcome to the Top 10 Web Hacking Techniques of 2025, the 19th edition of our annual community-powered effort to identify the most innovative must-read web security research published in the last year ...
This release introduces the Discover tab, faster table navigation with command palette, smarter SQLi detection, SPNEGO support for NTLM, plus other improvements, a Java update, and a browser upgrade.
DNS Exfilnspector automatically decodes DNS exfiltration queries captured through Burp Collaborator, converting blind remote code execution into visible output. The extension continuously monitors ...
This post shows how to achieve a full authentication bypass in the Ruby and PHP SAML ecosystem by exploiting several parser-level inconsistencies: including attribute pollution, namespace confusion, ...
Postman Collection Importer converts Postman collections and environments into Repeater tabs and Sitemap entries. The extension supports variable resolution, authentication methods, and multiple ...
If you've ever used Burp Intruder or Turbo Intruder, you'll be familiar with the ritual of manually digging through thousands of responses by repeatedly sorting the table via length, status code, etc.
WebSocket Turbo Intruder is a Burp Suite extension for fuzzing WebSocket messages with custom Python code. It extends the Burp Suite engine so it can exploit the WebSocket protocol specific ...