Articles Tagged “Application Security”
6 articles found

HTTP Terminator Hunts Request Smuggling Bugs With AI
PortSwigger open-sourced HTTP Terminator, an AI research system that generated 30,000 desync vectors and surfaced a now-patched Apache zero-day.

Burp AT Puts Agentic AI Inside Burp Suite Pentests
PortSwigger's Burp AT public beta gives pentesters AI agents that chase leads through Burp's own tooling, with per-task control over what runs unattended.

AI Agent Sandbox Design: 4 Lessons From New Research
Pillar Security's seven disclosures across Cursor, Codex CLI and Gemini CLI reveal four sandbox failure modes AI agent builders can design against.

Microsoft Dusseldorf Brings Open-Source OAST to Your Servers
Microsoft open-sourced Dusseldorf, a self-hosted OAST platform catching 4 blind bug classes while keeping callback data on your own servers.

VulnHunter Open-Sources Capital One's AI Bug Hunting
Capital One released VulnHunter under Apache 2.0 — an agentic security tool that traces exploit paths and tries to disprove its own findings first.

CodeQL 2.26 Adds Free AI Prompt-Injection Detection
CodeQL 2.26.0 adds a free js/system-prompt-injection query in code scanning, with new sinks for the OpenAI, Anthropic, and Google GenAI SDKs.
