Ostorlab outperforms Mythos, Microsoft, and Wiz. Our CyberGym benchmark results, at a fraction of the cost. Learn more

Blog

All articles

Browse all published engineering, product, and cybersecurity articles from Ostorlab.

AI Pentesting Providers for SOC 2: An Evidence-First Comparison

Compare Ostorlab, XBOW, Aikido, Intruder, Escape and Penti for SOC 2 AI pentesting, including testing coverage, explo...

Sep 25, 2026

Best Tools for Testing Mobile App Shielding Bypass

Compare Apktool, JADX, Ghidra, Frida, Objection and LLDB for manual tests with Ostorlab’s automated Android and iOS m...

Sep 23, 2026

Post-Mortem: Why Autonomous AI Agents Escape Scope and How to Contain Them

A technical post-mortem on an AI agent that wandered outside its testing scope during an authorized API assessment, w...

Sep 18, 2026

The Fastest Way to Get an Audit-Ready Pentest Report for SOC 2 Compliance

Learn how B2B SaaS startups bypass the 4-week consultancy delay to generate audit-ready SOC 2 pentest reports and Let...

Sep 16, 2026

Ostorlab Neutron Leads UC Berkeley CyberGym: 100% Detection and 96.75% Verified Exploitation

A technical deep-dive into how Ostorlab Neutron achieved 100% vulnerability detection and a 96.75% verified exploit s...

Sep 15, 2026

Best On-Premises Application Security Testing Platforms in 2026

Compare on-premises application security testing platforms in 2026, including Ostorlab, Invicti, Burp Suite DAST, HCL...

Sep 15, 2026

Ostorlab Neutron Reaches 96.7% on CyberGym, Ahead of Microsoft MDASH and Wiz Atlas

Ostorlab has reached 96.7% on CyberGym, moving ahead of the public leaderboard entries for Microsoft MDASH at 91.0% a...

Sep 14, 2026

Best External Attack Surface Management (EASM) Platforms in 2026

Compare leading External Attack Surface Management platforms in 2026, including Ostorlab, Microsoft Defender EASM, Co...

Sep 11, 2026

Best Web Application Security Testing Tools in 2026: DAST vs. Agentic Pentesting

Compare leading web application security testing tools in 2026, including Ostorlab, Burp Suite DAST, Invicti, Rapid7 ...

Sep 11, 2026

Best Enterprise Mobile App Vetting Platforms in 2026

An evidence-led technical comparison of enterprise mobile app vetting platforms in 2026, evaluating Ostorlab, NowSecu...

Sep 10, 2026

Best AI Pentesting Platforms in 2026

Compare leading AI pentesting platforms in 2026 by asset coverage, autonomous exploitation, attack chaining, evidence...

Sep 09, 2026

Autonomous Pentesting vs. Traditional Penetration Testing: Where Agentic AI Delivers—and Where Humans Still Lead

Compare traditional pentesting, PTaaS, and autonomous agentic AI testing: discover where autonomous agents deliver an...

Sep 08, 2026

Introducing Multi-Asset Deep Agentic Scan: Connected Testing Across the Application

Multi-Asset Deep Agentic Scan assesses related mobile, web, API, network, source-code, and documentation assets in on...

Sep 02, 2026

Bypassing Mobile App Shielding: Where Detection Ends and Enforcement Fails

Detection and enforcement are different security properties. Across five production banking apps protected by four co...

Aug 12, 2026

The 2026 Guide to Penetration Testing for Startups (Costs, Process, and Vendor Selection)

A comprehensive guide on what penetration testing is, how much it costs for startups in 2026, the 5-step testing proc...

Aug 09, 2026

Introducing the Ostorlab Platform MCP Server

Ostorlab now supports MCP, giving AI assistants and agents permission-controlled access to security data and workflows.

Aug 08, 2026

Introducing Risk Reruns: Granular Control for Agentic Deep Scans

Introducing Risk Reruns for Agentic Deep Scans—rerun specific risk investigations with customized effort levels, AI m...

Aug 07, 2026

AI Can Run the Attack. Can You Trust the Result?

AI can produce a convincing exploit story in seconds. Runtime proof, negative controls, and human review determine wh...

Aug 06, 2026

Can SOC 2 Accept an AI-Conducted Penetration Test?

SOC 2 doesn't name a required testing method, so auditors judge evidence, not tools. Here's what an AI-conducted pene...

Aug 06, 2026

Introducing Agentic Scan Knowledge: The Scanner That Never Forgets

Agentic Scan Knowledge gives Ostorlab security agents persistent application context, allowing every scan to build on...

Aug 05, 2026

Introducing Ostorlab Mobile Shielding Scan

Ostorlab Mobile Shielding Scan tests Android and iOS protections against real bypasses, including root detection, ant...

Aug 04, 2026

Announcing Ostorlab’s On-Premises Vulnerability Scanner

Announcing the general availability of the Ostorlab On-Premises Vulnerability Scanner, designed to identify and conte...

Aug 04, 2026

Ostorlab vs Aikido: Securing the Full Application Stack

Ostorlab vs Aikido: AppSec Comparison for Web, Mobile, API, and Source Code

Aug 03, 2026

Setting the Record Straight: Ostorlab vs. Appknox

A technical correction to Appknox's "Top 10 MAST Tools in 2026" comparison, highlighting the difference between stati...

Jul 29, 2026

XBOW vs Ostorlab, AI Pentesting Compared: Mobile, Web, Source Code & API Coverage

An architectural comparison of XBOW and Ostorlab across target scoping, mobile coverage, cross-asset exploit chaining...

Jul 28, 2026

How AI Catches Complex Vulnerabilities: Inside Agentic Pentesting and Exploit Chaining

Discover how agentic AI catches business logic flaws rule-based scanners miss. See a real exploit chain escalating a ...

Jul 28, 2026

Beyond Legacy Mobile AppSec: Why Modern DevSecOps Teams Are Replacing NowSecure with Ostorlab

A detailed comparison of Ostorlab and NowSecure across six key areas, highlighting why modern DevSecOps teams are rep...

Jul 27, 2026

Best Source Code Scanning Tools: 2026 Buyer's Guide

Compare the best source code scanning tools in 2026 across developer-first and enterprise platforms. Review Ostorlab,...

Jul 27, 2026

The Ostorlab Threat Center Now Supports the EU Vulnerability Database

Ostorlab Threat Center now brings EUVD intelligence alongside NVD data, giving security teams broader vulnerability v...

Jul 24, 2026

AI Pentesting Prompts That Produce Evidence, Not Just Findings

A practical guide to designing AI-assisted security testing workflows that turn scoped evidence into reviewable findi...

Jul 23, 2026

When Does an AI Scanner Become an AI Pentest?

Learn what separates AI-powered scanning from AI pentesting and how Ostorlab Deep Agentic Scan follows evidence to va...

Jul 22, 2026

Source Code Security: From Signal to Validated Risk | Ostorlab

Learn how source code security testing works, why traditional SAST creates false positives, and how agentic analysis ...

Jul 16, 2026

Breaking Down the Latest Version of GoPhish: Source-Code Assessment with Ostorlab Agentic Deep Scan

A technical assessment of the latest version of GoPhish that examines how the platform handles trust: identity, untru...

Jul 16, 2026

Ostorlab vs Quokka Q-mast: Mobile DAST Comparison

A technical comparison of Ostorlab and Quokka Q-mast Mobile Application Security Testing (MAST) tools, highlighting t...

Jul 15, 2026

Introducing Ostorlab Source Code Scanning

Source Code Scanning helps you identify security vulnerabilities directly in your source code before they reach produ...

Jul 07, 2026

Deep Scan Improvements: Faster Execution, Better Decisions, and Incremental Testing

The latest Deep Agentic Scan release introduces faster mobile testing, improved reverse engineering, stronger vulnera...

Jun 30, 2026

Introducing Mobile Shielding That Can Resist AI Attacks

Ostorlab has launched Mobile Shielding Scan, an automated, AI-powered testing solution designed specifically for shie...

Jun 25, 2026

The App Was Never Opened

Agentic harnesses change what an LLM can do in mobile app security testing. On its own, a model can name likely risks...

Jun 25, 2026

Introducing Ostorlab Cyber Models

Ostorlab has launched Cyber Models, a managed, prepaid AI infrastructure tier for Deep Agentic Scans. It gives securi...

Jun 23, 2026

There Is No Magic Box: Why AI-Era AppSec Needs a Stack

Walk the floor of any major cybersecurity conference today and you will hear about the promise of autonomous AI-power...

Jun 22, 2026

The Definitive Guide to Mobile App Vetting: Securing the Enterprise App Ecosystem

This comprehensive guide covers the architecture, risk methodologies, and deployment frameworks required to architect...

Jun 19, 2026

Introducing Ostorlab App Vetting for the Agentic Era

Ostorlab has launched App Vetting, a mobile application risk assessment solution that helps teams evaluate Android an...

Jun 16, 2026

Building an AI PR Reviewer Engineers Actually Trust

We built an AI-powered pull request reviewer, shut it down after hallucinations and false positives eroded developer ...

Jun 08, 2026

Introducing Ostorlab’s Single Vulnerability Assessment and Dig Deeper

Ostorlab is launching a powerful, highly targeted AI orchestration engine accessible through two distinct UI workflow...

Jun 02, 2026

Exploit CVE-2026-42208: LiteLLM Unauthenticated SQL Injection via Bearer Token

A technical breakdown of CVE-2026-42208, a CVSS 9.3 critical unauthenticated SQL Injection vulnerability in the LiteL...

May 22, 2026

DirtyFrag: Universal Linux Local Privilege Escalation via Page-Cache Write

A technical breakdown of DirtyFrag, a pair of Linux kernel local privilege escalation vulnerabilities (CVE-2026-43284...

May 13, 2026

Exploit CVE-2026-44109 : OpenClaw Feishu Webhook Authentication Bypass to RCE

A technical breakdown of CVE-2026-44109, a CVSS 9.2 Critical authentication bypass vulnerability in OpenClaw (< 2026....

May 07, 2026

CVE-2026-5205: Critical SSRF in Chatwoot — How a Single Upload Parameter Exposes Cloud Credentials

A deep dive into a critical Server-Side Request Forgery (SSRF) vulnerability in Chatwoot's upload endpoint (≤ v4.12.1...

Apr 29, 2026

DORA Compliance Checklist for Banking & Fintech: Audit-Ready Operational Resilience Validation

A DORA compliance checklist helps banking and fintech organizations evaluate operational resilience across core areas...

Apr 29, 2026

Inside BeatBanker / BTMOB: Static Analysis of TV_V_23.apk, a Multi-Stage Android Banking Malware Platform

A static analysis of TV_V_23.apk, a multi-stage Android banking malware platform attributed with high confidence to t...

Apr 28, 2026

HarmonyOS Next Security Testing: Tools, Risks, and Differences from Android.

This guide covers the security testing tools, platform-specific risks, and the most common gaps security teams encoun...

Apr 28, 2026

Android Intent Redirection: Attack Vectors and Mitigations

A deep dive into Android intent redirection vulnerabilities, showing how exported “proxy” components can be abused to...

Apr 23, 2026

Introducing HarmonyOS App Scans + Huawei AppGallery Scans

Find a vulnerability scanner for HarmonyOS apps and Huawei AppGallery releases: Ostorlab adds automated, repeatable s...

Apr 20, 2026

Mobile Game Security Testing: Prevent Hacks, Cheating, and Revenue Loss

Mobile game security testing prevents cheating, hacks, and revenue loss by securing client, network, and backend laye...

Apr 20, 2026

Mobile AppSec Testing Best Practices for High-Tech Teams Shipping at Scale

A technical guide to mobile application security testing best practices for high-tech teams shipping iOS and Android ...

Apr 16, 2026

The Complete Guide to Healthcare Application Security Testing: Protecting ePHI, Medical Apps, and Patient Trust

This comprehensive guide explores the critical role of application security testing in modern healthcare. It covers t...

Apr 16, 2026

Mobile Banking Security Testing: Protecting Financial Apps, Data, and Transactions

Protecting mobile banking apps requires more than securing the client alone. This guide explores the risks across dev...

Apr 16, 2026

Twenty CRM Serverless Functions Expose Critical RCE and Permanent Unauthenticated Backdoor Risk (CVE-2026-26720) - PoC & Exploit

A technical breakdown of CVE-2026-26720, a CVSS 9.8 Critical authenticated Remote Code Execution vulnerability in Twe...

Apr 15, 2026

DORA Third‑Party Risk for Mobile AppSec: SDK Governance and Audit‑Ready Evidence Packs

A deep dive into DORA-focused third‑party risk for mobile AppSec, showing why embedded SDKs and runtime providers dem...

Apr 14, 2026

Mobile Application Shielding: What it is and How it works

Mobile application shielding protects apps on untrusted devices by preventing reverse engineering, tampering, debuggi...

Apr 13, 2026

New Roundcube Webmail Vulnerabilities Disclosed : IMAP Command Injection and SSRF via CSS Proxying.

A deep dive into two critical vulnerabilities uncovered in Roundcube Webmail (< 1.6.14, 1.5.14, 1.7 RC4) during a sou...

Apr 08, 2026

Announcing Ostorlab for Harness: Mobile Security Scanning in CI Pipelines

Ostorlab now integrates with Harness CI to run automated mobile application security scans inside CI pipelines. Using...

Apr 06, 2026

CVE-2026-27971 : Qwik server$ Unauthenticated Remote Code Execution

A technical breakdown of CVE-2026-27971, a CVSS 9.2 critical unauthenticated remote code execution vulnerability in Q...

Apr 01, 2026

How to Automate Security Testing Behind Login Walls (2FA & MFA)

Modern applications are more secure than ever, but that security introduces a major challenge. With the widespread ad...

Mar 30, 2026

Announcing Ostorlab for Bitrise: Mobile security scans in your CI

Ostorlab now integrates with Bitrise to run automated mobile application security scans inside CI workflows. Using a ...

Mar 27, 2026

CVE-2026-2599 : Unauthenticated PHP Object Injection → WP_HTML_Token POP Chain

A technical breakdown of CVE-2026-2599, a CVSS 9.8 Critical unauthenticated PHP Object Injection vulnerability in the...

Mar 25, 2026

Mobile Operational Resilience Under DORA: The simplest drill library for BFSI journeys

A mobile-first guide to DORA compliance for BFSI teams. Learn how to define your scope, simplify your release process...

Mar 24, 2026

Ostorlab Launches Agentic Deep Scan: The next-generation vulnerability scanner

Ostorlab has launched Agentic Deep Scan, a next-generation vulnerability scanner that validates real-world risks in i...

Mar 19, 2026

Exploit CVE-2025-68461 : Roundcube Webmail SVG Animate XSS Sanitizer Bypass

A technical breakdown of CVE-2025-68461, a CVSS 7.2 high stored Cross-Site Scripting vulnerability in Roundcube Webma...

Mar 17, 2026

GHSA-cr3w-cw5w-h3fj: 1-Click RCE in Saltcorn

Analysis of GHSA-cr3w-cw5w-h3fj, a CVSS 9.7 critical XSS-to-RCE vulnerability in Saltcorn (≤ 1.5.0-beta.19). Two chai...

Mar 11, 2026

DORA Compliance for Mobile Releases: The easiest baseline, verdict, and exceptions model

A mobile-first guide to DORA regulation and DORA compliance for BFSI teams. Learn how to define your scope, simplify ...

Mar 10, 2026

CVE-2026-26019 : LangChain RecursiveUrlLoader Server-Side Request Forgery Vulnerability

A technical breakdown of CVE-2026-26019, a CVSS 4.1 medium Server-Side Request Forgery vulnerability in the LangChain...

Mar 04, 2026

DORA Compliance for Mobile Teams: Understanding scope and what you need to do

A mobile-first guide to DORA regulation and DORA compliance for BFSI teams. Learn how to define your scope, simplify ...

Mar 03, 2026

Top 10 Mobile Pentesting Tools in 2026

We work with mobile apps every day, and over time we’ve found a list of open-source tools that consistently make our ...

Feb 27, 2026

CVE-2025-64712: Path Traversal RCE in Unstructured Library MSG Processing

A technical breakdown of CVE-2025-64712, a CVSS 9.8 critical path traversal remote code execution vulnerability in th...

Feb 23, 2026

CVE-2026-1357: Unauthenticated RCE in WPvivid Backup Plugin

A technical breakdown of CVE-2026-1357, a CVSS 9.8 critical unauthenticated remote code execution vulnerability in th...

Feb 20, 2026

8 Open-Source AI Pentest Tools for Security Teams in 2026

This article lists eight (8) open-source AI pentest tools. It covers how autonomous agents are potentially changing t...

Jan 30, 2026

Ostorlab 2025 Year in Review

2025 marked the turning point where AI in cybersecurity graduated from experimental prototypes to production-grade en...

Jan 28, 2026

Android Requires Developer Verification Starting from 2026

For years, Android’s openness was one of its biggest strengths. Anyone could build an app, share it, and sideload it ...

Jan 27, 2026

That Time a Zero (could have) Broke the Internet's Plumbing (CVE-2026-0915)

An AI-assisted analysis uncovered a 30-year-old uninitialized buffer vulnerability in glibc's _nss_dns_getnetbyaddr_r...

Jan 21, 2026

Javascript Interface Exposure

Ostorlab's Pentest Engine identified a JavaScript bridge exposure in an Android WebView, allowing unauthenticated nat...

Jan 07, 2026

Best Mobile Application Security Testing (MAST) Platforms in 2026

Compare the best MAST tools for Android and iOS in 2026, including Ostorlab, NowSecure, Appknox, Data Theorem, Quokka...

Jan 05, 2026

Understanding Android's FLAG_SECURE for Screen Security

What Android’s FLAG_SECURE does, how it prevents screenshots and screen recordings of sensitive app content, how to i...

Dec 29, 2025

AI Pentest Engine Discovers Critical WebSocket BFLA in GraphQL Subscriptions

Ostorlab's AI Pentest Engine systematically uncovered a critical Broken Function-Level Authorization (BFLA) vulnerabi...

Dec 26, 2025

AI Engine Triggers Account Takeover via API Version Confusion

Methodical analysis beats blind fuzzing as Ostorlab's AI engine discovers cross-version password reset weakness and a...

Dec 15, 2025

Uncovering a Second-Order Data Exfiltration Chain in Modern SPAs

How a second-order client-side data exfiltration chain was discovered in a modern SPA, transforming a simple open red...

Dec 10, 2025

Going Beyond: Ostorlab AI Engine Discovers Unknown Vulnerability Classes

Ostorlab’s reasoning-driven AI engine breaks past rule-based limits to surface previously unknown and hard-to-detect ...

Oct 13, 2025

Introducing Ostorlab Security Testing Benchmarks: Real Vulnerabilities, Real Impact

The first open-source benchmark suite featuring 93 realistic vulnerable mobile apps that mirror actual CVE and bug bo...

Sep 22, 2025

Banking Report 2025: Security at the Core of Mobile Finance

Large-scale security analysis of 500+ top mobile banking apps reveals widespread vulnerabilities, decade-old codebase...

Sep 15, 2025

Automating Security Research: AI Engine Exploits Complex Blind Code Injection

Precision beats payload spray using Ostorlab's AI engine to systematically land RCE on Titiler and proves exfiltratio...

Sep 04, 2025

AI-Powered Pentesting: A Deep Dive into Android Intent Redirection

This article showcases Ostorlab's AI Pentest Engine's process for analyzing an Android application for Intent Redirec...

Aug 31, 2025

Automating Security Research: AI Engine Exploits GCP Service Account Secret

This article presents a thorough, hands-on analysis and real-world exploitation of a hardcoded GCP service account wi...

Aug 28, 2025

From Signal to the Android SDK: Chaining Path Traversal, Mimetype Confusion, Security Check Bypass and File Descriptor Bruteforce for Arbitrary File Access

This technical analysis reveals how sophisticated attack chains—combining path traversal, symbolic link manipulation,...

Aug 11, 2025

Automating Security Research: AI Engine Exploits Report Portal XXE (CVE-2021-29620)

This article presents a thorough, hands-on analysis and proof of concept for exploiting an OOB XXE vulnerability CVE-...

Aug 07, 2025

From Random to Intelligent: How AI-Powered Monkey Testing Achieves 10x Mobile App Coverage

Ostorlab’s AI Monkey Tester transforms mobile app security testing by using natural language prompts and generative A...

Aug 01, 2025

Automating Security Research: AI Engine Exploits Zulip Stored XSS (CVE-2025-52559)

This article presents a thorough, hands-on analysis and proof of concept for exploiting the stored XSS vulnerability ...

Jul 28, 2025

Know Your App's Data Habits: A Deep Dive into Our Comprehensive Privacy Analysis

Ostorlab's Privacy Scan automatically detects mismatches between what your app's privacy policy says and what it actu...

Ostorlab Security Scanner GitHub Integration

The Ostorlab Security Scanner GitHub Integration enhances mobile app development workflows by embedding automated sec...

May 21, 2025

Scan, Sync, Remediate: Ostorlab Meets Vanta for Faster Audits

This article announces the new integration between Ostorlab and Vanta, explains how it works, outlines the setup proc...

May 20, 2025

Bypassing Obfuscation in Android Apps: A Dual Approach with DalvikFLIRT and LLM-Powered Rewrites

This research introduces a pioneering dual approach that combines signature-based matching (DalvikFLIRT) with LLM-pow...

Apr 16, 2025

From Moonshot to Production: Building Ostorlab Copilot

This article outlines our journey in implementing ostorlab copilot, the challenges we encountered, and the lessons we...

Feb 24, 2025

Effective Vulnerability Ticketing System with Ostorlab

This article announces Ostorlab's vulnerability ticketing system V2 and how it automates and streamlines the entire p...

Feb 18, 2025

AI-Automated Attack Surface Management: The Future of Cybersecurity Discovery

This article explores AI-automated attack surface management, its impact on cybersecurity, and how it automates asset...

Feb 14, 2025

Pre-Auth Root RCE Vulnerability in CyberPanel: Deep Dive Exploit Analysis

A technical analysis of a vulnerability in CyberPanel, a Pre-Auth Root RCE, including confirmed exploitation paths, i...

Oct 30, 2024

Defending Against GraphQL Attacks: A Deep Dive into Common Vulnerabilities

This article is an in-depth look at the most common GraphQL vulnerabilities, why they occur, and how they can be mitigated.

Oct 21, 2024

Assessing the Large-Scale Exposure of CUPS Vulnerabilities: Chained CVEs Leading to Remote Code Execution

This article assesses the large-scale exposure of systems to multiple CVEs affecting the CUPS printing service, which...

Threat Center v2: Staying Ahead of Vulnerabilities

The Threat Center provides essential updates for organizations to stay informed about security threats, offering acti...

Oct 10, 2024

Deep Dive: Stored XSS Vulnerability in LiteSpeed Cache Plugin for WordPress (CVE-2024-47374)

An in-depth look at the CVE-2024-47374 vulnerability affecting LiteSpeed Cache plugin for WordPress, its impact, and ...

Oct 10, 2024

Actively Exploited CVE-2022-21445, Deep Dive

The article delves into the technical details of this CVE, its potential impact, and the methods used to detect and e...

Sep 25, 2024

Unraveling the VigorConnect Vulnerability: A Journey of Discovery and Correction

The article uncovers an Arbitrary File Read vulnerability in VigorConnect that lets attackers access sensitive files....

OXO Titan UI: Simplifying Security Scanning for Everyone

OXO Titan UI encapsulates OXO's capabilities within an accessible interface, democratizing advanced security scanning...

Advanced Techniques for Bypassing 403 Errors

Discover the comprehensive techniques that are commonly used to bypass 403 errors. Learn about the various methods us...

Revolutionizing Mobile Security Testing with Ostorlab's AI-Powered Monkey Tester

Introducing the AI-powered Monkey Tester in the Ostorlab mobile vulnerability scanner, significantly boosting test co...

Jul 16, 2024

CVE-2024-5315 Dolibarr SQL Injection Investigation

CVE-2024-5315, an actively exploited Dolibarr SQL Injection with in incorrect patched-in version.

Jul 14, 2024

CocoaPods Supply Chain Fire: What Should You Know

E.V.A Information Security uncovered critical vulnerabilities in CocoaPods, leading to immediate patches, and develop...

Jul 03, 2024

🚀 OXO v1.0!

OXO version 1.0, is 10x times faster, supports ARM64 architectures, and is packed with improved capabilities like sca...

Apr 29, 2024

Apple Privacy: A Comprehensive Guide to Privacy Manifest Files

This article offers a guide to Privacy Manifest files in Apple's ecosystem, stressing their importance for transparen...

Apr 18, 2024

Enhancing PostMessage XSS Detection with Proxy Object Instrumentation

The article introduces a new method for detecting PostMessage Cross-Site Scripting (XSS) vulnerabilities using JavaSc...

Apr 04, 2024

Ostorlab KEV update for 02 April 2024

New vulnerabilities added to Ostorlab known exploited vulnerabilities catalog

Apr 02, 2024

Discovering & Monitoring Mobile Applications Attack Surface with Ostorlab

The article introduces Ostorlab Attack Surface Discovery as a solution for discovering and continuously monitoring mo...

Mar 26, 2024

Security Landscape of Mobile Banking Applications in North America

This article examines the security of mobile banking applications in North America, uncovering widespread vulnerabili...

Mar 19, 2024

Swift Under the Microscope: Practical Dynamic Instrumentation

Article on Swift Dynamic Instrumentation. The article explains the steps to perform dynamic analysis of Swift-based a...

Mar 11, 2024

Ostorlab KEV update for 11th March 2024

New vulnerabilities added to Ostorlab known exploited vulnerabilities catalog

Mar 11, 2024

Ostorlab KEV update for 26th February 2024

New vulnerabilities added to Ostorlab known exploited vulnerabilities catalog

Feb 26, 2024

Mapping Dependency Confusion: A Novel Detection Approach using Source Map Files

The article delves into dependency confusion vulnerabilities and introduces a novel detection and exploitation techni...

Known Exploitable Vulnerabilities: Catching them all

In this article we will Discover essential tools and empirical insights for identifying critical, high-severity, and ...

Jan 10, 2024

2023 in review

As 2023 has concluded, it's time to reflect and prepare for an optimistic 2024.

Jan 10, 2024

New OWASP Mobile Top 10

Release of new OWASP Mobile Top 10 with improvements, updates and a behind the scenes.

Nov 27, 2023

Ostorlab's Victory at the Swiss Cyber defence Security Challenge 2023

Ostorlab clinches the top spot in the Swiss Cyber defense Security Challenge, showcasing their commitment to advancin...

Nov 10, 2023

One Scheme to Rule Them All: OAuth Account Takeover

This article delves into the exploitation of OAuth account takeover using app impersonation through custom scheme hij...

Oct 17, 2023

ZIP Exploitation: Critical Vulnerabilities Found in Popular Zip Libraries in Swift and Flutter

Recent in-depth investigations reveal serious vulnerabilities discovered in widely-used zip packages in Flutter and S...

Aug 04, 2023

Ostorlab's Insecure Flutter Apps: A Playground for Learning and Testing Mobile Security

Ostorlab has open-sourced two Flutter applications, designed to be intentionally insecure for testing and educational...

Jul 10, 2023

zCamera, 100M+ installation app, from remote compromise to data leaks

This article is a technical deep dive, showing how a 100M+ installation image application can expose its user’s image...

Jul 04, 2023

AI-powered recommendations and fixes, Improved Flutter Detection, and much more

The new release brings a new AI Engine for improved recommendations, powerful new additions to Flutter detection and ...

Jun 26, 2023

Secure Mobile Biometric Authentication: Best Practices and Implementation Guidelines for Kotlin, Swift, and Flutter

In this Article, we define a secure implementation of mobile biometric authentication and provide detailed implementa...

Jun 20, 2023

Flutter Reverse Engineering and Security Analysis

Article on Static and Dynamic analysis techniques for Reverse engineering Flutter Applications. The article goes over...

Jun 15, 2023

Strategies for writing super fast Python

In this article, we look at different ways to improve the performance of Python which is an interpreted language.

Apr 18, 2023

Automation rule policies, Artifacts redesign, improved detection and much more.

An overview of all the new features of the Ostorlab platform and its detection capabilities.

Apr 14, 2023

GodFather Android Malware Analysis

In This article, we analyze the GodFather Android malware, which continues to appear in various formats and primarily...

Apr 14, 2023

Ostorlab Achieves SOC2 Type 2 Certification for Commitment to Security and Data Protection

Ostorlab has successfully completed its SOC2 Type 2 audit, demonstrating its commitment to security and data protection.

Apr 12, 2023

Fix it! at Ostorlab

Ostorlab's Fix it! practice is one of our most successful engineering practices helping us eradicate bugs and kill te...

Feb 19, 2023

Where are all these 3rd party SDKs sending my users' data? 😨

Ostorlab’s new features are laser-focused on helping teams understand, track and search their attack surface, what at...

Feb 02, 2023

Ostorlab, top 10 vulnerability management innovators of 2023 by GRC Viewpoint

Ostorlab has been selected as one of the top 10 vulnerability management innovators of 2023 by GRC Viewpoint.

Jan 16, 2023

2022 at Ostorlab

2022 is a year that brings with it many global challenges, including war, economic uncertainty, and rising inflation ...

Jan 03, 2023

Build you CI/CD pipeline for Mobile Applications with Jenkins, Github Actions and Azure Devops

This article will cover the main challenges when implementing a CI/CD pipeline for mobile applications. We will also ...

Oct 27, 2022

Text4Shell (CVE-2022-42889) in Mobile Applications ... should I worry?

CVE-2022-42889 is a vulnerability in the Apache Commons Text Library caused by string interpolation abusing powerful ...

Oct 24, 2022

New Dashboard, Better Insights

As a reflection of the many new capabilities and changes we have made, we have released a new dashboard providing bet...

Oct 20, 2022

OWASP Mobile Application Verification Standard Support

The Mobile Application Security Verification Standard is an important step toward building secure Mobile Applications...

Oct 04, 2022

Tips and tricks for developing & debugging OXO Agents.

Tips and tricks to make your life easier when developing & debugging OXO Agents.

Aug 18, 2022

Improved Attack Surface Discovery, Mobile and Web Security Scanning

Largest release with improvements to Attack Surface, Open-Source, Mobile and Web scanning and much much more.

Aug 18, 2022

Life of a Scan: how OXO's open-source vulnerability scanner works

This article talks about how OXO works under the hood.

Aug 02, 2022

Attack Surface Insights - part 2

Attack Surface is not just about open ports and services; this article covers key insights beyond the standard techni...

Jun 16, 2022

Mapping your Attack Surface - part 1

Attack surface mapping has become the number one headache of CISO's of most large organization, this article goes ove...

May 17, 2022

What I've learned from my first job as a Software Engineer at Ostorlab

This article talks about the experience of Rabson Phiri who works as a Software Engineer at Ostorlab.

Apr 19, 2022

Ostorlab vs. NowSecure vs. MobSF vs. Immuniweb vs. AppKnox vs. Quixxi vs. Oversecured

This article provides a comprehensive view of the security mobile security scanning solutions, while at the same time...

Mar 21, 2022

Ostorlab is Open-Source 🎊

This is a major release open-sourcing Ostorlab and announcing tons of new features and capabilities.

Feb 21, 2022

How did we react to Log4j vulnerability? Read our analysis for mobile applications.

What is the impact of Log4j vulnerability on mobile applications

Dec 20, 2021

Ostorlab Q&A with Safety Detectives

Wanna learn a bit more about Ostorlab? We answered Aviva Zack’s questions for Safety Detective about the Company, our...

Nov 08, 2021

New Features, improved ticket management, integrations including Jira support

Vulnerability management is a hard journey, the help enable fixing of vulnerabilities urgently, diligently and effici...

Nov 04, 2021

Release of a new remediation capabilities to enable fast, diligent and efficient fixes

Vulnerability management is a hard journey, the help enable fixing of vulnerabilities urgently, diligently and effici...

Oct 06, 2021

UI call coverage release for dynamic security testing

Ostorlab released the UI call coverage in the analysis environment to show the UI flow exercised during the dynamic s...

Sep 01, 2021

Ostorlab Nuggets in June issue 5

Health Tech, Compromises and attacks, Instrumentation, Black Hat conferences, eBPF and more….

May 27, 2021

Universal bypass of SSL Pinning ... from theory to a full working PoC with LLDB

This article is about bypassing SSL pinning without needing to. Sounds confusing? We will go over the theory, build a...

May 18, 2021

5 things every mobile security professional should know about WebViews

This article is about WebViews and the security notions we need to have in mind when using these component in both An...

May 18, 2021

Ostorlab detects Dependency Confusion

Dependency Confusion is a new attack with high severity impact. This article is an overview of the vulnerability as w...

Mar 03, 2021

Finding superhuman XSS polyglot payloads with Genetic Algorithms

The following article is a technical deep dive into how genetic algorithms can be leveraged to create superhuman XSS ...

Mar 01, 2021

News and Updates of Week 8

This weeks is marked by multiple high profile data breaches affecting Cashalo, Npower, Kia, T-Mobile and Clubhouse.

Feb 28, 2021

Ostorlab adds Web Security Scanning to its arsenal

Ostorlab is adding Web Security Scanner to its arsenal with novel approaches to vulnerability discovery.

Feb 15, 2021

Release of a new analysis environment to aid manual assessment

New Analysis Environment with access to disassembly, decompiled source, call trace, function tagging and many other features.

Jan 11, 2021

Finding and Validating Hardcoded Keys and Secrets

Hardcoded secrets are easy to find and might open a gate to sensitive data or privileged access. This makes them a gr...

Oct 30, 2020

Autonomous Security: Pushing Security Automation to the Next Level

The article introduces the term Autonomous Security in the context of security scanning and defines 5 tiers of maturity.

Oct 26, 2020

Two efficient features to continuously monitor mobile applications

Whether we are developing a mobile application or assessing its security, we need to continuously review it with ever...

Oct 24, 2020

Create scans directly from the Android and iOS Store

Ostorlab now supports creating scans directly from Android Play Store and iOS App Store

Aug 16, 2020

COVID-19 Contact Tracing App Wiqaytna Mobile Application Security Review

Mobile security testing of Covid-19 Contact Tracing Application Wiqaytna

[Online Event] Security of 3rd party dependencies in Mobile Applications

Mobile applications assessments, automation of 3rd party dependency review

Jun 12, 2020

What's New in Ostorlab Mobile Security Scanner 2020.05.08

Xamarin decompilation, deprecated TLS protocols, hardcoded secrets and even more, Owasp top 10

May 08, 2020

Detection Engine @ Ostorlab

Overview of the detection capabilities provided by Ostorlab

May 01, 2020

What's New in Ostorlab 2020.04

Better management of scan lifecycle, export scan results and subscriptions

Apr 08, 2020

Private Scan Management

Announcement on changes in the management of scan accessibility

Dec 29, 2019

Ostorlab Mobile Security Scanner: Release New Portal

Ostorlab Mobile Security Scanner Release of a new portal to track scans progress and access scan history.

Dec 26, 2019

Nuxt.js debugging in Webstorm

How to debug Nuxt.js application on Webstorm

Oct 18, 2019

Taking Cloud Run for a Test drive

We took Cloud Run for a Test Drive, these are we what learnt.

Oct 16, 2019

Ostorlab Insecure Application

This article describes the usage of Ostorlab Insecure Application.

Oct 14, 2019

Application Security Testing on non-Jailbroken iOS from Linux

How to perform security checks of an iOS application file on a non-jailbroken iPhone from a Linux Machine.

Oct 08, 2019

Community scanner goes full capabilities

In a mission to build the best security scanning technologies, Ostorlab team is proud to announce that the community ...

Mar 03, 2019

Security, what opportunities and challenges for 2019?

Use the start of the year to contemplate how the previous year went, and prepare for the upcoming is an important exe...

Jan 07, 2019

DOM XSS Fuzzing strategies - Part 1

XSS are still by far the most common type of vulnerabilities, this article presents strategies to automate the search...

Dec 22, 2018

Hardcoded AWS keys in Mobile Applications

This article is about how to manage AWS access keys when using AWS services in your mobile application.

Dec 20, 2018

New Features and Roadmap

The last few months, Ostorlab team has been hard at work adding exciting new features. Some of these have already hit...

Sep 20, 2018

Reinforcement Learning & Automated Testing - part 1

I will be sharing through a series of blog posts our past experimentations with the use of reinforcement learning for...

Jan 22, 2018

Critical attack surface of mobile applications

the Attack Surface of mobile applications.

Jan 17, 2018

Finding security bugs in Android applications the hard way

Ostorlab is a community effort to build a mobile application vulnerability scanner to help developers build secure mo...

Jun 16, 2017

New Taint Engine ... more vulnerabilities found

We have been for the last few months hard at work developing a new scan engine to identify new classes of vulnerabili...

Apr 23, 2017

Testing Cordova Applications

Hybrid frameworks like Cordova offers the advantage of building one app for multiple platform (support for Android, i...

Nov 24, 2016

Android, SQL and ContentProviders or Why SQL injections aren't dead yet ?

Before we get into SQL injections and what might go wrong, we'll start by covering some technical information on Cont...

Nov 03, 2016

Android external libs!

For an Android developer, it has become standard practice to use external libraries to easily extend the functionalit...

Nov 01, 2016

Vulnerabilities tested by Google Play Store

Google will start identifying security weaknesses in Apps pushed to the Play Store...

Sep 05, 2016

Python Concurrency and Parallelism: building a custom ProcessPoolExecutor

At Ostorlab we scan hundreds of Mobile Applications each day, each scan is very resource intensive but at the same ti...

Jul 18, 2016

New in Android M and N: Runtime Permissions

In Android, the permission system was one of the major security concerns of the platform for many reasons...

May 27, 2016

SSL Pinning on Android: Best Practices, OkHttp & Retrofit Examples (2026)

Learn how SSL pinning works on Android, what threats it helps mitigate, where it can break, and how to implement it s...

May 11, 2016

Reversing JNI, or how Facebook is crashing their own application

Apparently Facebook is crashing their apps intentionally in order to test users reaction and evaluate their adherence...

Jan 07, 2016

What every pentesters should learn in 2016

The last years have come with meaningful changes in the way IT professionals operate and the way we approach security...

Jan 02, 2016

Ostorlab Beta is out

We are pleased to release the Beta version of our online mobile application security scanner.

Dec 20, 2015

Best SSL/TLS resources (Attacks, Tools, Talks)

This article will reference the best current resources on SSL/TLS.

Aug 25, 2015