Trail of Bits Skills Marketplace
Trail of Bits released a Claude Code plugin marketplace with 26 security-focused skills for AI-assisted code analysis, including auditors for GitHub Actions, C/C++, Rust, and supply chains, plus tools…
Trail of Bits released a Claude Code plugin marketplace with 26 security-focused skills for AI-assisted code analysis, including auditors for GitHub Actions, C/C++, Rust, and supply chains, plus tools…
PortSwigger has announced the public beta of Burp AT, a new addition to Burp Suite that brings agentic AI to professional penetration testing. The tool enables testers to delegate defined investigativ…
A developer warns that German criminal code § 202c StGB, known as the 'Hacker-Paragraph,' criminalizes the preparation of data espionage and can trap developers who use security tools without explicit…
PortSwigger's Burp Suite faces growing competition from alternatives like Aikido Security, Caido, ZAP, and Invicti as teams demand DAST that runs continuously in CI/CD, AI-powered pentesting, and visi…
Disclose.io launched lookup.disclose.io integrations including a CLI, Caido and Burp Suite plugins, an MCP server for AI agents, and an API, allowing security researchers to map assets to disclosure c…
A developer released Mcpwn, an open-source CLI tool for red-teaming Model Context Protocol (MCP) servers, after finding no existing pentesting tools for the protocol. The tool supports multiple transp…
Burpwn, a transparent intercepting proxy and execution sandbox for AI agents, has been released in early development. The tool allows autonomous agents to perform web pentesting with full TLS-MITM, tr…
A comprehensive survey of man-in-the-middle (MITM) proxy and HTTP interception tools has mapped the ecosystem into four major domains, benchmarking projects against the Python-based mitmproxy (43.8k s…
This article explains how network analysis tools like Burp Suite can be used to inspect the hidden data traffic flowing between apps, websites, and devices. The author describes learning this techniqu…
This article is a curated list of cybersecurity tools and resources, organized by categories such as privilege escalation, credential harvesting, and exploitation frameworks. The repository, created b…