Dev48
Language
  • About
  • Services
  • Industries
  • Technologies
  • Articles
  • Contacts
Book a call
    Home/Articles/How burp at helped expose whistleblower reports via a critical vulnerability tha
Dev48

© 2026 · All rights reserved.

How Burp AT helped expose whistleblower reports via a critical vulnerability that was overlooked for years

Источник: PortSwigger Blog

How Burp AT helped expose whistleblower reports via a critical vulnerability that was overlooked for years

Source: PortSwigger Blog

"It feel like I get 10X the productivity on an engagement. The difference i night and day." Profile Ray Huygen i a Security Analy t at Orange Cyberdefen e, a managed ecurity ervice provider with

September 26, 2026

Andrzej Matykiewicz | Tuesday, 4 August 2026 at 14:45 UTC

"It feels like I get 10X the productivity on an engagement. The difference is night and day."

Profile

Ray Huygen is a Security Analyst at Orange Cyberdefense, a managed security service provider with 2,500+ employees worldwide. He performs regular web, API, and mobile pentesting for clients and has been a Burp Suite user since 2019.

The dilemma of timeboxed engagements

Like most pentesters, one of the biggest challenges Ray faces isn't figuring out what to test; it's what to leave behind. On a so-called "four-plus-one" engagement, where he has four days to test and one day to write up his report, he has to use his knowledge and intuition to make hundreds of judgment calls throughout the week.

On a recent engagement, a client-side JavaScript bundle provided just such a dilemma. "There's no way I could justify spending the time going through 66,000 lines of minified JavaScript." He explains. "It's the sort of thing where you have to write it off and hope you've got some spare time at the end of the engagement, which doesn't really happen. A traditional scanner doesn't really help in this situation either: it can tell you some exposed JavaScript is there, but it can't really analyze it in the same way a human would."

Fortunately, Ray had backup.

Agentic AI meets human-led pentesting

"I was trialing Burp AT at the time, so I said 'This is some sort of source code disclosure. Can we build on this?'" He continues. Meanwhile, he carried on with his usual process. When he checked back in later, he was shocked by what he saw. While he'd been focusing his attention elsewhere, Burp AT had found a way to leak highly sensitive reports submitted via the client's whistleblower initiative.

"Burp AT had gone through all the JavaScript and figured out what it was for and how it worked. It also told me that each whistleblower report was only locked down behind a six-digit alphanumeric code, so it was potentially possible to bruteforce the codes and pull out what are meant to be confidential reports."

From academic finding to confirmed exploit

The attack vector was clear, but Ray didn't want to stop at a hypothetical. He wanted to demonstrate the real-world exploitability and impact of the bug for his client. He knew what he had to do, but as Burp AT is natively integrated with the same Burp Suite tools he works with every day, he was able to hand this off to an agent as well.

"I said 'Hey Burp AT, while you're at it, run an Intruder attack to bruteforce the codes.' When I started to see the exfiltrated reports coming back, I thought 'This is going to be a very awkward conversation with the client!'"

The vulns that get away

It turned out that the vulnerability had been present for a while, and missed during previous security assessments. Not because the other pentesters didn't do their job properly, but because it would previously have been almost impossible, even irresponsible, to dedicate the extensive amount of time required to find it. Ray is convinced that without Burp AT, this pattern would've repeated itself.

"I'm 100% certain that ship would've sailed away for at least another year until the next pentester came along." He confirms. "Even worse, a malicious threat actor could've found it in the meantime and gone on to exploit it."

This serves as a cautionary tale of how many serious vulnerabilities are out there waiting to be discovered, even in apps that undergo routine pentests.

Pairing with AI

Ray is optimistic that Burp AT can help close the gap in what gets tested, massively increasing the depth and breadth pentesters can realistically cover.

"A lot of what has historically been overlooked can now be actioned. There's so much that humans aren't looking at that Burp AT will now make time for."

He likens his relationship with Burp AT to working with a pentesting partner. "I can outsource what I'd describe as grunt work to the AI." He explains. "I feel like I can confidently say 'You test this' while I do something else and then check back in every half hour or so to see what the agents have come back with."

But that's just one side of it. Like working with a colleague, he feels like pairing with Burp AT is genuinely helping sharpen his own skills.

"No matter how experienced you are, there's still stuff that you won't fully understand, and there's always going to be more to learn." He continues. "With Burp AT I can say 'Hey, this is what I've found. My spidey-senses are tingling here. What have I got? Am I chasing the right thing? How should I investigate it?' The learning opportunity is huge."

A new way of working

The impact on Ray's day-to-day workflow is tangible, even though Burp AT is still in its infancy.

"When I can't use it on an engagement, I genuinely feel like I have withdrawal symptoms!" He jokes. "In all seriousness, though, this is life changing. I cannot begin to express how much easier it started making certain portions of the testing, and how much simpler it's made learning."

Try Burp AT

Burp AT is currently available to Burp Suite Professional subscribers as part of a public beta. For more details, see https://portswigger.net/burp/burp-at.

Find out more at our upcoming webinar

Join us on 2 September for a 30-minute look at what Burp AT can do today, and where agentic pentesting in Burp Suite is heading next.

2 September | 4:00 PM BST / 11:00 AM ET / 8:00 AM PT

Register here

Andrzej Matykiewicz

← All articles

More in Cybersecurity

All →
The Infostealer Incursion: How Stolen Credentials Breach Cloud, Code, and AI Environments
Wiz

The Infostealer Incursion: How Stolen Credentials Breach Cloud, Code, and AI Environments

Metasploit Wrap Up: Belgian Waffles, Chocolates, and…Modules-Frites?
Rapid7

Metasploit Wrap Up: Belgian Waffles, Chocolates, and…Modules-Frites?

Wiz Named a Leader in The Forrester Wave™: Proactive Security Platforms, Q3 2026
Wiz

Wiz Named a Leader in The Forrester Wave™: Proactive Security Platforms, Q3 2026

Protéger votre téléviseur connecté et votre boîtier contre le piratage
Kaspersky

Protéger votre téléviseur connecté et votre boîtier contre le piratage

Key source of economic growth in Canada may be overlooked, new research reveals
PwC

Key source of economic growth in Canada may be overlooked, new research reveals

Building trust and governance as agentic AI scales
PwC

Building trust and governance as agentic AI scales

More from PortSwigger

Can AI invent new attack techniques? New research from James Kettle and PortSwigger Research
PortSwigger

Can AI invent new attack techniques? New research from James Kettle and PortSwigger Research

From capable AI models to trusted security testing
PortSwigger

From capable AI models to trusted security testing

Introducing Burp AT: agentic AI, built on two decades of Burp Suite
PortSwigger

Introducing Burp AT: agentic AI, built on two decades of Burp Suite

Burp's new Ambassadors: learn from the people who use Burp Suite everyday
PortSwigger

Burp's new Ambassadors: learn from the people who use Burp Suite everyday