Ostorlab Neutron Leads UC Berkeley CyberGym: 100% Detection and 96.75% Verified Exploitation
A technical deep-dive into how Ostorlab Neutron achieved 100% vulnerability detection and a 96.75% verified exploit solved rate (1,458/1,507 tasks) on UC Berkeley's CyberGym benchmark, combining pure source reverse engineering with deterministic protocol modeling.
Tue 15 September 2026
Best On-Premises Application Security Testing Platforms in 2026
Compare on-premises application security testing platforms in 2026, including Ostorlab, Invicti, ...
Tue 15 September 2026
Best External Attack Surface Management (EASM) Platforms in 2026
Compare leading External Attack Surface Management platforms in 2026, including Ostorlab, Microso...
Fri 11 September 2026
Best Web Application Security Testing Tools in 2026: DAST vs. Agentic Pentesting
Compare leading web application security testing tools in 2026, including Ostorlab, Burp Suite DA...
Fri 11 September 2026
Best Enterprise Mobile App Vetting Platforms in 2026
An evidence-led technical comparison of enterprise mobile app vetting platforms in 2026, evaluating Ostorlab, NowSecure, Quokka Q-scout, Zimperium z3A, Appknox, and Data Theorem across operating models, risk scoring, and continuous monitoring.
Best AI Pentesting Platforms in 2026
Compare leading AI pentesting platforms in 2026 by asset coverage, autonomous exploitation, attack chaining, evidence, compliance, and deployment.
Latest posts
Autonomous Pentesting vs. Traditional Penetration Testing: Where Agentic AI Delivers—and Where Humans Still Lead
Compare traditional pentesting, PTaaS, and autonomous agentic AI testing: discover where autonomous agents deliver and where human testers still lead.
Tue 08 September 2026
New Dashboard UI, On-Premises Scanner, Agentic Scan Knowledge, Multi-Asset Scanning, Linear & MCP Integrations, and New Model Support
This release adds a redesigned Dashboard UI (Cockpit, Focus Mode, and Custom Dashboards), keyboard shortcuts for ticket management, an on-premises vulnerability scanner for internal networks, persistent scan knowledge across runs, an MCP server for AI tools, multi-asset scanning, remediation streams with timeline tracking, Threat Center EUVD intelligence, and expanded AI model support.
Wed 02 September 2026
Introducing Multi-Asset Deep Agentic Scan: Connected Testing Across the Application
Multi-Asset Deep Agentic Scan assesses related mobile, web, API, network, source-code, and documentation assets in one connected agentic investigation.
Wed 02 September 2026
Bypassing Mobile App Shielding: Where Detection Ends and Enforcement Fails
Detection and enforcement are different security properties. Across five production banking apps protected by four commercial shielding products, the detection was sophisticated and the enforcement was fragile.
Wed 12 August 2026
The 2026 Guide to Penetration Testing for Startups (Costs, Process, and Vendor Selection)
A comprehensive guide on what penetration testing is, how much it costs for startups in 2026, the 5-step testing process, and how to choose the right vendor for your tech stack.
Sun 09 August 2026
Introducing the Ostorlab Platform MCP Server
Ostorlab now supports MCP, giving AI assistants and agents permission-controlled access to security data and workflows.
Sat 08 August 2026
Introducing Risk Reruns: Granular Control for Agentic Deep Scans
Introducing Risk Reruns for Agentic Deep Scans—rerun specific risk investigations with customized effort levels, AI models, or parameters without re-uploading assets or starting over.
Fri 07 August 2026
AI Can Run the Attack. Can You Trust the Result?
AI can produce a convincing exploit story in seconds. Runtime proof, negative controls, and human review determine whether that story becomes a finding a security team can trust.
Thu 06 August 2026