Blog
All articles
Browse all published engineering, product, and cybersecurity articles from Ostorlab.
AI Pentesting Providers for SOC 2: An Evidence-First Comparison
Compare Ostorlab, XBOW, Aikido, Intruder, Escape and Penti for SOC 2 AI pentesting, including testing coverage, explo...
Sep 25, 2026
Best Tools for Testing Mobile App Shielding Bypass
Compare Apktool, JADX, Ghidra, Frida, Objection and LLDB for manual tests with Ostorlab’s automated Android and iOS m...
Sep 23, 2026
Post-Mortem: Why Autonomous AI Agents Escape Scope and How to Contain Them
A technical post-mortem on an AI agent that wandered outside its testing scope during an authorized API assessment, w...
Sep 18, 2026
The Fastest Way to Get an Audit-Ready Pentest Report for SOC 2 Compliance
Learn how B2B SaaS startups bypass the 4-week consultancy delay to generate audit-ready SOC 2 pentest reports and Let...
Sep 16, 2026
Ostorlab Neutron Leads UC Berkeley CyberGym: 100% Detection and 96.75% Verified Exploitation
A technical deep-dive into how Ostorlab Neutron achieved 100% vulnerability detection and a 96.75% verified exploit s...
Sep 15, 2026
Best On-Premises Application Security Testing Platforms in 2026
Compare on-premises application security testing platforms in 2026, including Ostorlab, Invicti, Burp Suite DAST, HCL...
Sep 15, 2026
Ostorlab Neutron Reaches 96.7% on CyberGym, Ahead of Microsoft MDASH and Wiz Atlas
Ostorlab has reached 96.7% on CyberGym, moving ahead of the public leaderboard entries for Microsoft MDASH at 91.0% a...
Sep 14, 2026
Best External Attack Surface Management (EASM) Platforms in 2026
Compare leading External Attack Surface Management platforms in 2026, including Ostorlab, Microsoft Defender EASM, Co...
Sep 11, 2026
Best Web Application Security Testing Tools in 2026: DAST vs. Agentic Pentesting
Compare leading web application security testing tools in 2026, including Ostorlab, Burp Suite DAST, Invicti, Rapid7 ...
Sep 11, 2026
Best Enterprise Mobile App Vetting Platforms in 2026
An evidence-led technical comparison of enterprise mobile app vetting platforms in 2026, evaluating Ostorlab, NowSecu...
Sep 10, 2026
Best AI Pentesting Platforms in 2026
Compare leading AI pentesting platforms in 2026 by asset coverage, autonomous exploitation, attack chaining, evidence...
Sep 09, 2026
Autonomous Pentesting vs. Traditional Penetration Testing: Where Agentic AI Delivers—and Where Humans Still Lead
Compare traditional pentesting, PTaaS, and autonomous agentic AI testing: discover where autonomous agents deliver an...
Sep 08, 2026
Introducing Multi-Asset Deep Agentic Scan: Connected Testing Across the Application
Multi-Asset Deep Agentic Scan assesses related mobile, web, API, network, source-code, and documentation assets in on...
Sep 02, 2026
Bypassing Mobile App Shielding: Where Detection Ends and Enforcement Fails
Detection and enforcement are different security properties. Across five production banking apps protected by four co...
Aug 12, 2026
The 2026 Guide to Penetration Testing for Startups (Costs, Process, and Vendor Selection)
A comprehensive guide on what penetration testing is, how much it costs for startups in 2026, the 5-step testing proc...
Aug 09, 2026
Introducing the Ostorlab Platform MCP Server
Ostorlab now supports MCP, giving AI assistants and agents permission-controlled access to security data and workflows.
Aug 08, 2026
Introducing Risk Reruns: Granular Control for Agentic Deep Scans
Introducing Risk Reruns for Agentic Deep Scans—rerun specific risk investigations with customized effort levels, AI m...
Aug 07, 2026
AI Can Run the Attack. Can You Trust the Result?
AI can produce a convincing exploit story in seconds. Runtime proof, negative controls, and human review determine wh...
Aug 06, 2026
Can SOC 2 Accept an AI-Conducted Penetration Test?
SOC 2 doesn't name a required testing method, so auditors judge evidence, not tools. Here's what an AI-conducted pene...
Aug 06, 2026
Introducing Agentic Scan Knowledge: The Scanner That Never Forgets
Agentic Scan Knowledge gives Ostorlab security agents persistent application context, allowing every scan to build on...
Aug 05, 2026
Introducing Ostorlab Mobile Shielding Scan
Ostorlab Mobile Shielding Scan tests Android and iOS protections against real bypasses, including root detection, ant...
Aug 04, 2026
Announcing Ostorlab’s On-Premises Vulnerability Scanner
Announcing the general availability of the Ostorlab On-Premises Vulnerability Scanner, designed to identify and conte...
Aug 04, 2026
Ostorlab vs Aikido: Securing the Full Application Stack
Ostorlab vs Aikido: AppSec Comparison for Web, Mobile, API, and Source Code
Aug 03, 2026
Setting the Record Straight: Ostorlab vs. Appknox
A technical correction to Appknox's "Top 10 MAST Tools in 2026" comparison, highlighting the difference between stati...
Jul 29, 2026
XBOW vs Ostorlab, AI Pentesting Compared: Mobile, Web, Source Code & API Coverage
An architectural comparison of XBOW and Ostorlab across target scoping, mobile coverage, cross-asset exploit chaining...
Jul 28, 2026
How AI Catches Complex Vulnerabilities: Inside Agentic Pentesting and Exploit Chaining
Discover how agentic AI catches business logic flaws rule-based scanners miss. See a real exploit chain escalating a ...
Jul 28, 2026
Beyond Legacy Mobile AppSec: Why Modern DevSecOps Teams Are Replacing NowSecure with Ostorlab
A detailed comparison of Ostorlab and NowSecure across six key areas, highlighting why modern DevSecOps teams are rep...
Jul 27, 2026
Best Source Code Scanning Tools: 2026 Buyer's Guide
Compare the best source code scanning tools in 2026 across developer-first and enterprise platforms. Review Ostorlab,...
Jul 27, 2026
The Ostorlab Threat Center Now Supports the EU Vulnerability Database
Ostorlab Threat Center now brings EUVD intelligence alongside NVD data, giving security teams broader vulnerability v...
Jul 24, 2026
AI Pentesting Prompts That Produce Evidence, Not Just Findings
A practical guide to designing AI-assisted security testing workflows that turn scoped evidence into reviewable findi...
Jul 23, 2026
When Does an AI Scanner Become an AI Pentest?
Learn what separates AI-powered scanning from AI pentesting and how Ostorlab Deep Agentic Scan follows evidence to va...
Jul 22, 2026
Source Code Security: From Signal to Validated Risk | Ostorlab
Learn how source code security testing works, why traditional SAST creates false positives, and how agentic analysis ...
Jul 16, 2026
Breaking Down the Latest Version of GoPhish: Source-Code Assessment with Ostorlab Agentic Deep Scan
A technical assessment of the latest version of GoPhish that examines how the platform handles trust: identity, untru...
Jul 16, 2026
Ostorlab vs Quokka Q-mast: Mobile DAST Comparison
A technical comparison of Ostorlab and Quokka Q-mast Mobile Application Security Testing (MAST) tools, highlighting t...
Jul 15, 2026
Introducing Ostorlab Source Code Scanning
Source Code Scanning helps you identify security vulnerabilities directly in your source code before they reach produ...
Jul 07, 2026
Deep Scan Improvements: Faster Execution, Better Decisions, and Incremental Testing
The latest Deep Agentic Scan release introduces faster mobile testing, improved reverse engineering, stronger vulnera...
Jun 30, 2026
Introducing Mobile Shielding That Can Resist AI Attacks
Ostorlab has launched Mobile Shielding Scan, an automated, AI-powered testing solution designed specifically for shie...
Jun 25, 2026
The App Was Never Opened
Agentic harnesses change what an LLM can do in mobile app security testing. On its own, a model can name likely risks...
Jun 25, 2026
Introducing Ostorlab Cyber Models
Ostorlab has launched Cyber Models, a managed, prepaid AI infrastructure tier for Deep Agentic Scans. It gives securi...
Jun 23, 2026
There Is No Magic Box: Why AI-Era AppSec Needs a Stack
Walk the floor of any major cybersecurity conference today and you will hear about the promise of autonomous AI-power...
Jun 22, 2026
The Definitive Guide to Mobile App Vetting: Securing the Enterprise App Ecosystem
This comprehensive guide covers the architecture, risk methodologies, and deployment frameworks required to architect...
Jun 19, 2026
Introducing Ostorlab App Vetting for the Agentic Era
Ostorlab has launched App Vetting, a mobile application risk assessment solution that helps teams evaluate Android an...
Jun 16, 2026
Building an AI PR Reviewer Engineers Actually Trust
We built an AI-powered pull request reviewer, shut it down after hallucinations and false positives eroded developer ...
Jun 08, 2026
Introducing Ostorlab’s Single Vulnerability Assessment and Dig Deeper
Ostorlab is launching a powerful, highly targeted AI orchestration engine accessible through two distinct UI workflow...
Jun 02, 2026
Exploit CVE-2026-42208: LiteLLM Unauthenticated SQL Injection via Bearer Token
A technical breakdown of CVE-2026-42208, a CVSS 9.3 critical unauthenticated SQL Injection vulnerability in the LiteL...
May 22, 2026
DirtyFrag: Universal Linux Local Privilege Escalation via Page-Cache Write
A technical breakdown of DirtyFrag, a pair of Linux kernel local privilege escalation vulnerabilities (CVE-2026-43284...
May 13, 2026
Exploit CVE-2026-44109 : OpenClaw Feishu Webhook Authentication Bypass to RCE
A technical breakdown of CVE-2026-44109, a CVSS 9.2 Critical authentication bypass vulnerability in OpenClaw (< 2026....
May 07, 2026
CVE-2026-5205: Critical SSRF in Chatwoot — How a Single Upload Parameter Exposes Cloud Credentials
A deep dive into a critical Server-Side Request Forgery (SSRF) vulnerability in Chatwoot's upload endpoint (≤ v4.12.1...
Apr 29, 2026
DORA Compliance Checklist for Banking & Fintech: Audit-Ready Operational Resilience Validation
A DORA compliance checklist helps banking and fintech organizations evaluate operational resilience across core areas...
Apr 29, 2026
Inside BeatBanker / BTMOB: Static Analysis of TV_V_23.apk, a Multi-Stage Android Banking Malware Platform
A static analysis of TV_V_23.apk, a multi-stage Android banking malware platform attributed with high confidence to t...
Apr 28, 2026
HarmonyOS Next Security Testing: Tools, Risks, and Differences from Android.
This guide covers the security testing tools, platform-specific risks, and the most common gaps security teams encoun...
Apr 28, 2026
Android Intent Redirection: Attack Vectors and Mitigations
A deep dive into Android intent redirection vulnerabilities, showing how exported “proxy” components can be abused to...
Apr 23, 2026
Introducing HarmonyOS App Scans + Huawei AppGallery Scans
Find a vulnerability scanner for HarmonyOS apps and Huawei AppGallery releases: Ostorlab adds automated, repeatable s...
Apr 20, 2026
Mobile Game Security Testing: Prevent Hacks, Cheating, and Revenue Loss
Mobile game security testing prevents cheating, hacks, and revenue loss by securing client, network, and backend laye...
Apr 20, 2026
Mobile AppSec Testing Best Practices for High-Tech Teams Shipping at Scale
A technical guide to mobile application security testing best practices for high-tech teams shipping iOS and Android ...
Apr 16, 2026
The Complete Guide to Healthcare Application Security Testing: Protecting ePHI, Medical Apps, and Patient Trust
This comprehensive guide explores the critical role of application security testing in modern healthcare. It covers t...
Apr 16, 2026
Mobile Banking Security Testing: Protecting Financial Apps, Data, and Transactions
Protecting mobile banking apps requires more than securing the client alone. This guide explores the risks across dev...
Apr 16, 2026
Twenty CRM Serverless Functions Expose Critical RCE and Permanent Unauthenticated Backdoor Risk (CVE-2026-26720) - PoC & Exploit
A technical breakdown of CVE-2026-26720, a CVSS 9.8 Critical authenticated Remote Code Execution vulnerability in Twe...
Apr 15, 2026
DORA Third‑Party Risk for Mobile AppSec: SDK Governance and Audit‑Ready Evidence Packs
A deep dive into DORA-focused third‑party risk for mobile AppSec, showing why embedded SDKs and runtime providers dem...
Apr 14, 2026
Mobile Application Shielding: What it is and How it works
Mobile application shielding protects apps on untrusted devices by preventing reverse engineering, tampering, debuggi...
Apr 13, 2026
New Roundcube Webmail Vulnerabilities Disclosed : IMAP Command Injection and SSRF via CSS Proxying.
A deep dive into two critical vulnerabilities uncovered in Roundcube Webmail (< 1.6.14, 1.5.14, 1.7 RC4) during a sou...
Apr 08, 2026
Announcing Ostorlab for Harness: Mobile Security Scanning in CI Pipelines
Ostorlab now integrates with Harness CI to run automated mobile application security scans inside CI pipelines. Using...
Apr 06, 2026
CVE-2026-27971 : Qwik server$ Unauthenticated Remote Code Execution
A technical breakdown of CVE-2026-27971, a CVSS 9.2 critical unauthenticated remote code execution vulnerability in Q...
Apr 01, 2026
How to Automate Security Testing Behind Login Walls (2FA & MFA)
Modern applications are more secure than ever, but that security introduces a major challenge. With the widespread ad...
Mar 30, 2026
Announcing Ostorlab for Bitrise: Mobile security scans in your CI
Ostorlab now integrates with Bitrise to run automated mobile application security scans inside CI workflows. Using a ...
Mar 27, 2026
CVE-2026-2599 : Unauthenticated PHP Object Injection → WP_HTML_Token POP Chain
A technical breakdown of CVE-2026-2599, a CVSS 9.8 Critical unauthenticated PHP Object Injection vulnerability in the...
Mar 25, 2026
Mobile Operational Resilience Under DORA: The simplest drill library for BFSI journeys
A mobile-first guide to DORA compliance for BFSI teams. Learn how to define your scope, simplify your release process...
Mar 24, 2026
Ostorlab Launches Agentic Deep Scan: The next-generation vulnerability scanner
Ostorlab has launched Agentic Deep Scan, a next-generation vulnerability scanner that validates real-world risks in i...
Mar 19, 2026
Exploit CVE-2025-68461 : Roundcube Webmail SVG Animate XSS Sanitizer Bypass
A technical breakdown of CVE-2025-68461, a CVSS 7.2 high stored Cross-Site Scripting vulnerability in Roundcube Webma...
Mar 17, 2026
GHSA-cr3w-cw5w-h3fj: 1-Click RCE in Saltcorn
Analysis of GHSA-cr3w-cw5w-h3fj, a CVSS 9.7 critical XSS-to-RCE vulnerability in Saltcorn (≤ 1.5.0-beta.19). Two chai...
Mar 11, 2026
DORA Compliance for Mobile Releases: The easiest baseline, verdict, and exceptions model
A mobile-first guide to DORA regulation and DORA compliance for BFSI teams. Learn how to define your scope, simplify ...
Mar 10, 2026
CVE-2026-26019 : LangChain RecursiveUrlLoader Server-Side Request Forgery Vulnerability
A technical breakdown of CVE-2026-26019, a CVSS 4.1 medium Server-Side Request Forgery vulnerability in the LangChain...
Mar 04, 2026
DORA Compliance for Mobile Teams: Understanding scope and what you need to do
A mobile-first guide to DORA regulation and DORA compliance for BFSI teams. Learn how to define your scope, simplify ...
Mar 03, 2026
Top 10 Mobile Pentesting Tools in 2026
We work with mobile apps every day, and over time we’ve found a list of open-source tools that consistently make our ...
Feb 27, 2026
CVE-2025-64712: Path Traversal RCE in Unstructured Library MSG Processing
A technical breakdown of CVE-2025-64712, a CVSS 9.8 critical path traversal remote code execution vulnerability in th...
Feb 23, 2026
CVE-2026-1357: Unauthenticated RCE in WPvivid Backup Plugin
A technical breakdown of CVE-2026-1357, a CVSS 9.8 critical unauthenticated remote code execution vulnerability in th...
Feb 20, 2026
8 Open-Source AI Pentest Tools for Security Teams in 2026
This article lists eight (8) open-source AI pentest tools. It covers how autonomous agents are potentially changing t...
Jan 30, 2026
Ostorlab 2025 Year in Review
2025 marked the turning point where AI in cybersecurity graduated from experimental prototypes to production-grade en...
Jan 28, 2026
Android Requires Developer Verification Starting from 2026
For years, Android’s openness was one of its biggest strengths. Anyone could build an app, share it, and sideload it ...
Jan 27, 2026
That Time a Zero (could have) Broke the Internet's Plumbing (CVE-2026-0915)
An AI-assisted analysis uncovered a 30-year-old uninitialized buffer vulnerability in glibc's _nss_dns_getnetbyaddr_r...
Jan 21, 2026
Javascript Interface Exposure
Ostorlab's Pentest Engine identified a JavaScript bridge exposure in an Android WebView, allowing unauthenticated nat...
Jan 07, 2026
Best Mobile Application Security Testing (MAST) Platforms in 2026
Compare the best MAST tools for Android and iOS in 2026, including Ostorlab, NowSecure, Appknox, Data Theorem, Quokka...
Jan 05, 2026
Understanding Android's FLAG_SECURE for Screen Security
What Android’s FLAG_SECURE does, how it prevents screenshots and screen recordings of sensitive app content, how to i...
Dec 29, 2025
AI Pentest Engine Discovers Critical WebSocket BFLA in GraphQL Subscriptions
Ostorlab's AI Pentest Engine systematically uncovered a critical Broken Function-Level Authorization (BFLA) vulnerabi...
Dec 26, 2025
AI Engine Triggers Account Takeover via API Version Confusion
Methodical analysis beats blind fuzzing as Ostorlab's AI engine discovers cross-version password reset weakness and a...
Dec 15, 2025
Uncovering a Second-Order Data Exfiltration Chain in Modern SPAs
How a second-order client-side data exfiltration chain was discovered in a modern SPA, transforming a simple open red...
Dec 10, 2025
Going Beyond: Ostorlab AI Engine Discovers Unknown Vulnerability Classes
Ostorlab’s reasoning-driven AI engine breaks past rule-based limits to surface previously unknown and hard-to-detect ...
Oct 13, 2025
Introducing Ostorlab Security Testing Benchmarks: Real Vulnerabilities, Real Impact
The first open-source benchmark suite featuring 93 realistic vulnerable mobile apps that mirror actual CVE and bug bo...
Sep 22, 2025
Banking Report 2025: Security at the Core of Mobile Finance
Large-scale security analysis of 500+ top mobile banking apps reveals widespread vulnerabilities, decade-old codebase...
Sep 15, 2025
Automating Security Research: AI Engine Exploits Complex Blind Code Injection
Precision beats payload spray using Ostorlab's AI engine to systematically land RCE on Titiler and proves exfiltratio...
Sep 04, 2025
AI-Powered Pentesting: A Deep Dive into Android Intent Redirection
This article showcases Ostorlab's AI Pentest Engine's process for analyzing an Android application for Intent Redirec...
Aug 31, 2025
Automating Security Research: AI Engine Exploits GCP Service Account Secret
This article presents a thorough, hands-on analysis and real-world exploitation of a hardcoded GCP service account wi...
Aug 28, 2025
From Signal to the Android SDK: Chaining Path Traversal, Mimetype Confusion, Security Check Bypass and File Descriptor Bruteforce for Arbitrary File Access
This technical analysis reveals how sophisticated attack chains—combining path traversal, symbolic link manipulation,...
Aug 11, 2025
Automating Security Research: AI Engine Exploits Report Portal XXE (CVE-2021-29620)
This article presents a thorough, hands-on analysis and proof of concept for exploiting an OOB XXE vulnerability CVE-...
Aug 07, 2025
From Random to Intelligent: How AI-Powered Monkey Testing Achieves 10x Mobile App Coverage
Ostorlab’s AI Monkey Tester transforms mobile app security testing by using natural language prompts and generative A...
Aug 01, 2025
Automating Security Research: AI Engine Exploits Zulip Stored XSS (CVE-2025-52559)
This article presents a thorough, hands-on analysis and proof of concept for exploiting the stored XSS vulnerability ...
Jul 28, 2025
Know Your App's Data Habits: A Deep Dive into Our Comprehensive Privacy Analysis
Ostorlab's Privacy Scan automatically detects mismatches between what your app's privacy policy says and what it actu...
May 27, 2025
Ostorlab Security Scanner GitHub Integration
The Ostorlab Security Scanner GitHub Integration enhances mobile app development workflows by embedding automated sec...
May 21, 2025
Scan, Sync, Remediate: Ostorlab Meets Vanta for Faster Audits
This article announces the new integration between Ostorlab and Vanta, explains how it works, outlines the setup proc...
May 20, 2025
Bypassing Obfuscation in Android Apps: A Dual Approach with DalvikFLIRT and LLM-Powered Rewrites
This research introduces a pioneering dual approach that combines signature-based matching (DalvikFLIRT) with LLM-pow...
Apr 16, 2025
From Moonshot to Production: Building Ostorlab Copilot
This article outlines our journey in implementing ostorlab copilot, the challenges we encountered, and the lessons we...
Feb 24, 2025
Effective Vulnerability Ticketing System with Ostorlab
This article announces Ostorlab's vulnerability ticketing system V2 and how it automates and streamlines the entire p...
Feb 18, 2025
AI-Automated Attack Surface Management: The Future of Cybersecurity Discovery
This article explores AI-automated attack surface management, its impact on cybersecurity, and how it automates asset...
Feb 14, 2025
Pre-Auth Root RCE Vulnerability in CyberPanel: Deep Dive Exploit Analysis
A technical analysis of a vulnerability in CyberPanel, a Pre-Auth Root RCE, including confirmed exploitation paths, i...
Oct 30, 2024
Defending Against GraphQL Attacks: A Deep Dive into Common Vulnerabilities
This article is an in-depth look at the most common GraphQL vulnerabilities, why they occur, and how they can be mitigated.
Oct 21, 2024
Assessing the Large-Scale Exposure of CUPS Vulnerabilities: Chained CVEs Leading to Remote Code Execution
This article assesses the large-scale exposure of systems to multiple CVEs affecting the CUPS printing service, which...
Oct 16, 2024
Threat Center v2: Staying Ahead of Vulnerabilities
The Threat Center provides essential updates for organizations to stay informed about security threats, offering acti...
Oct 10, 2024
Deep Dive: Stored XSS Vulnerability in LiteSpeed Cache Plugin for WordPress (CVE-2024-47374)
An in-depth look at the CVE-2024-47374 vulnerability affecting LiteSpeed Cache plugin for WordPress, its impact, and ...
Oct 10, 2024
Actively Exploited CVE-2022-21445, Deep Dive
The article delves into the technical details of this CVE, its potential impact, and the methods used to detect and e...
Sep 25, 2024
Unraveling the VigorConnect Vulnerability: A Journey of Discovery and Correction
The article uncovers an Arbitrary File Read vulnerability in VigorConnect that lets attackers access sensitive files....
Sep 12, 2024
OXO Titan UI: Simplifying Security Scanning for Everyone
OXO Titan UI encapsulates OXO's capabilities within an accessible interface, democratizing advanced security scanning...
Aug 26, 2024
Advanced Techniques for Bypassing 403 Errors
Discover the comprehensive techniques that are commonly used to bypass 403 errors. Learn about the various methods us...
Aug 05, 2024
Revolutionizing Mobile Security Testing with Ostorlab's AI-Powered Monkey Tester
Introducing the AI-powered Monkey Tester in the Ostorlab mobile vulnerability scanner, significantly boosting test co...
Jul 16, 2024
CVE-2024-5315 Dolibarr SQL Injection Investigation
CVE-2024-5315, an actively exploited Dolibarr SQL Injection with in incorrect patched-in version.
Jul 14, 2024
CocoaPods Supply Chain Fire: What Should You Know
E.V.A Information Security uncovered critical vulnerabilities in CocoaPods, leading to immediate patches, and develop...
Jul 03, 2024
🚀 OXO v1.0!
OXO version 1.0, is 10x times faster, supports ARM64 architectures, and is packed with improved capabilities like sca...
Apr 29, 2024
Apple Privacy: A Comprehensive Guide to Privacy Manifest Files
This article offers a guide to Privacy Manifest files in Apple's ecosystem, stressing their importance for transparen...
Apr 18, 2024
Enhancing PostMessage XSS Detection with Proxy Object Instrumentation
The article introduces a new method for detecting PostMessage Cross-Site Scripting (XSS) vulnerabilities using JavaSc...
Apr 04, 2024
Ostorlab KEV update for 02 April 2024
New vulnerabilities added to Ostorlab known exploited vulnerabilities catalog
Apr 02, 2024
Discovering & Monitoring Mobile Applications Attack Surface with Ostorlab
The article introduces Ostorlab Attack Surface Discovery as a solution for discovering and continuously monitoring mo...
Mar 26, 2024
Security Landscape of Mobile Banking Applications in North America
This article examines the security of mobile banking applications in North America, uncovering widespread vulnerabili...
Mar 19, 2024
Swift Under the Microscope: Practical Dynamic Instrumentation
Article on Swift Dynamic Instrumentation. The article explains the steps to perform dynamic analysis of Swift-based a...
Mar 11, 2024
Ostorlab KEV update for 11th March 2024
New vulnerabilities added to Ostorlab known exploited vulnerabilities catalog
Mar 11, 2024
Ostorlab KEV update for 26th February 2024
New vulnerabilities added to Ostorlab known exploited vulnerabilities catalog
Feb 26, 2024
Mapping Dependency Confusion: A Novel Detection Approach using Source Map Files
The article delves into dependency confusion vulnerabilities and introduces a novel detection and exploitation techni...
Feb 13, 2024
Known Exploitable Vulnerabilities: Catching them all
In this article we will Discover essential tools and empirical insights for identifying critical, high-severity, and ...
Jan 10, 2024
2023 in review
As 2023 has concluded, it's time to reflect and prepare for an optimistic 2024.
Jan 10, 2024
New OWASP Mobile Top 10
Release of new OWASP Mobile Top 10 with improvements, updates and a behind the scenes.
Nov 27, 2023
Ostorlab's Victory at the Swiss Cyber defence Security Challenge 2023
Ostorlab clinches the top spot in the Swiss Cyber defense Security Challenge, showcasing their commitment to advancin...
Nov 10, 2023
One Scheme to Rule Them All: OAuth Account Takeover
This article delves into the exploitation of OAuth account takeover using app impersonation through custom scheme hij...
Oct 17, 2023
ZIP Exploitation: Critical Vulnerabilities Found in Popular Zip Libraries in Swift and Flutter
Recent in-depth investigations reveal serious vulnerabilities discovered in widely-used zip packages in Flutter and S...
Aug 04, 2023
Ostorlab's Insecure Flutter Apps: A Playground for Learning and Testing Mobile Security
Ostorlab has open-sourced two Flutter applications, designed to be intentionally insecure for testing and educational...
Jul 10, 2023
zCamera, 100M+ installation app, from remote compromise to data leaks
This article is a technical deep dive, showing how a 100M+ installation image application can expose its user’s image...
Jul 04, 2023
AI-powered recommendations and fixes, Improved Flutter Detection, and much more
The new release brings a new AI Engine for improved recommendations, powerful new additions to Flutter detection and ...
Jun 26, 2023
Secure Mobile Biometric Authentication: Best Practices and Implementation Guidelines for Kotlin, Swift, and Flutter
In this Article, we define a secure implementation of mobile biometric authentication and provide detailed implementa...
Jun 20, 2023
Flutter Reverse Engineering and Security Analysis
Article on Static and Dynamic analysis techniques for Reverse engineering Flutter Applications. The article goes over...
Jun 15, 2023
Strategies for writing super fast Python
In this article, we look at different ways to improve the performance of Python which is an interpreted language.
Apr 18, 2023
Automation rule policies, Artifacts redesign, improved detection and much more.
An overview of all the new features of the Ostorlab platform and its detection capabilities.
Apr 14, 2023
GodFather Android Malware Analysis
In This article, we analyze the GodFather Android malware, which continues to appear in various formats and primarily...
Apr 14, 2023
Ostorlab Achieves SOC2 Type 2 Certification for Commitment to Security and Data Protection
Ostorlab has successfully completed its SOC2 Type 2 audit, demonstrating its commitment to security and data protection.
Apr 12, 2023
Fix it! at Ostorlab
Ostorlab's Fix it! practice is one of our most successful engineering practices helping us eradicate bugs and kill te...
Feb 19, 2023
Where are all these 3rd party SDKs sending my users' data? 😨
Ostorlab’s new features are laser-focused on helping teams understand, track and search their attack surface, what at...
Feb 02, 2023
Ostorlab, top 10 vulnerability management innovators of 2023 by GRC Viewpoint
Ostorlab has been selected as one of the top 10 vulnerability management innovators of 2023 by GRC Viewpoint.
Jan 16, 2023
2022 at Ostorlab
2022 is a year that brings with it many global challenges, including war, economic uncertainty, and rising inflation ...
Jan 03, 2023
Build you CI/CD pipeline for Mobile Applications with Jenkins, Github Actions and Azure Devops
This article will cover the main challenges when implementing a CI/CD pipeline for mobile applications. We will also ...
Oct 27, 2022
Text4Shell (CVE-2022-42889) in Mobile Applications ... should I worry?
CVE-2022-42889 is a vulnerability in the Apache Commons Text Library caused by string interpolation abusing powerful ...
Oct 24, 2022
New Dashboard, Better Insights
As a reflection of the many new capabilities and changes we have made, we have released a new dashboard providing bet...
Oct 20, 2022
OWASP Mobile Application Verification Standard Support
The Mobile Application Security Verification Standard is an important step toward building secure Mobile Applications...
Oct 04, 2022
Tips and tricks for developing & debugging OXO Agents.
Tips and tricks to make your life easier when developing & debugging OXO Agents.
Aug 18, 2022
Improved Attack Surface Discovery, Mobile and Web Security Scanning
Largest release with improvements to Attack Surface, Open-Source, Mobile and Web scanning and much much more.
Aug 18, 2022
Life of a Scan: how OXO's open-source vulnerability scanner works
This article talks about how OXO works under the hood.
Aug 02, 2022
Attack Surface Insights - part 2
Attack Surface is not just about open ports and services; this article covers key insights beyond the standard techni...
Jun 16, 2022
Mapping your Attack Surface - part 1
Attack surface mapping has become the number one headache of CISO's of most large organization, this article goes ove...
May 17, 2022
What I've learned from my first job as a Software Engineer at Ostorlab
This article talks about the experience of Rabson Phiri who works as a Software Engineer at Ostorlab.
Apr 19, 2022
Ostorlab vs. NowSecure vs. MobSF vs. Immuniweb vs. AppKnox vs. Quixxi vs. Oversecured
This article provides a comprehensive view of the security mobile security scanning solutions, while at the same time...
Mar 21, 2022
Ostorlab is Open-Source 🎊
This is a major release open-sourcing Ostorlab and announcing tons of new features and capabilities.
Feb 21, 2022
How did we react to Log4j vulnerability? Read our analysis for mobile applications.
What is the impact of Log4j vulnerability on mobile applications
Dec 20, 2021
Ostorlab Q&A with Safety Detectives
Wanna learn a bit more about Ostorlab? We answered Aviva Zack’s questions for Safety Detective about the Company, our...
Nov 08, 2021
New Features, improved ticket management, integrations including Jira support
Vulnerability management is a hard journey, the help enable fixing of vulnerabilities urgently, diligently and effici...
Nov 04, 2021
Release of a new remediation capabilities to enable fast, diligent and efficient fixes
Vulnerability management is a hard journey, the help enable fixing of vulnerabilities urgently, diligently and effici...
Oct 06, 2021
UI call coverage release for dynamic security testing
Ostorlab released the UI call coverage in the analysis environment to show the UI flow exercised during the dynamic s...
Sep 01, 2021
Ostorlab Nuggets in June issue 5
Health Tech, Compromises and attacks, Instrumentation, Black Hat conferences, eBPF and more….
May 27, 2021
Universal bypass of SSL Pinning ... from theory to a full working PoC with LLDB
This article is about bypassing SSL pinning without needing to. Sounds confusing? We will go over the theory, build a...
May 18, 2021
5 things every mobile security professional should know about WebViews
This article is about WebViews and the security notions we need to have in mind when using these component in both An...
May 18, 2021
Ostorlab detects Dependency Confusion
Dependency Confusion is a new attack with high severity impact. This article is an overview of the vulnerability as w...
Mar 03, 2021
Finding superhuman XSS polyglot payloads with Genetic Algorithms
The following article is a technical deep dive into how genetic algorithms can be leveraged to create superhuman XSS ...
Mar 01, 2021
News and Updates of Week 8
This weeks is marked by multiple high profile data breaches affecting Cashalo, Npower, Kia, T-Mobile and Clubhouse.
Feb 28, 2021
Ostorlab adds Web Security Scanning to its arsenal
Ostorlab is adding Web Security Scanner to its arsenal with novel approaches to vulnerability discovery.
Feb 15, 2021
Release of a new analysis environment to aid manual assessment
New Analysis Environment with access to disassembly, decompiled source, call trace, function tagging and many other features.
Jan 11, 2021
Finding and Validating Hardcoded Keys and Secrets
Hardcoded secrets are easy to find and might open a gate to sensitive data or privileged access. This makes them a gr...
Oct 30, 2020
Autonomous Security: Pushing Security Automation to the Next Level
The article introduces the term Autonomous Security in the context of security scanning and defines 5 tiers of maturity.
Oct 26, 2020
Two efficient features to continuously monitor mobile applications
Whether we are developing a mobile application or assessing its security, we need to continuously review it with ever...
Oct 24, 2020
Create scans directly from the Android and iOS Store
Ostorlab now supports creating scans directly from Android Play Store and iOS App Store
Aug 16, 2020
How to Carry out Nation-scale Mobile Devices Compromise: COVID-19 Contact Tracing App BeAware Bahrain Review
Mobile security testing of Covid-19 Contact Tracing Application BeAware
Jul 05, 2020
COVID-19 Contact Tracing App Wiqaytna Mobile Application Security Review
Mobile security testing of Covid-19 Contact Tracing Application Wiqaytna
Jun 15, 2020
[Online Event] Security of 3rd party dependencies in Mobile Applications
Mobile applications assessments, automation of 3rd party dependency review
Jun 12, 2020
What's New in Ostorlab Mobile Security Scanner 2020.05.08
Xamarin decompilation, deprecated TLS protocols, hardcoded secrets and even more, Owasp top 10
May 08, 2020
May 01, 2020
What's New in Ostorlab 2020.04
Better management of scan lifecycle, export scan results and subscriptions
Apr 08, 2020
Dec 29, 2019
Ostorlab Mobile Security Scanner: Release New Portal
Ostorlab Mobile Security Scanner Release of a new portal to track scans progress and access scan history.
Dec 26, 2019
Oct 18, 2019
Taking Cloud Run for a Test drive
We took Cloud Run for a Test Drive, these are we what learnt.
Oct 16, 2019
Ostorlab Insecure Application
This article describes the usage of Ostorlab Insecure Application.
Oct 14, 2019
Application Security Testing on non-Jailbroken iOS from Linux
How to perform security checks of an iOS application file on a non-jailbroken iPhone from a Linux Machine.
Oct 08, 2019
Community scanner goes full capabilities
In a mission to build the best security scanning technologies, Ostorlab team is proud to announce that the community ...
Mar 03, 2019
Security, what opportunities and challenges for 2019?
Use the start of the year to contemplate how the previous year went, and prepare for the upcoming is an important exe...
Jan 07, 2019
DOM XSS Fuzzing strategies - Part 1
XSS are still by far the most common type of vulnerabilities, this article presents strategies to automate the search...
Dec 22, 2018
Hardcoded AWS keys in Mobile Applications
This article is about how to manage AWS access keys when using AWS services in your mobile application.
Dec 20, 2018
Oct 28, 2018
New Features and Roadmap
The last few months, Ostorlab team has been hard at work adding exciting new features. Some of these have already hit...
Sep 20, 2018
Reinforcement Learning & Automated Testing - part 1
I will be sharing through a series of blog posts our past experimentations with the use of reinforcement learning for...
Jan 22, 2018
Jan 17, 2018
Finding security bugs in Android applications the hard way
Ostorlab is a community effort to build a mobile application vulnerability scanner to help developers build secure mo...
Jun 16, 2017
New Taint Engine ... more vulnerabilities found
We have been for the last few months hard at work developing a new scan engine to identify new classes of vulnerabili...
Apr 23, 2017
Testing Cordova Applications
Hybrid frameworks like Cordova offers the advantage of building one app for multiple platform (support for Android, i...
Nov 24, 2016
Android, SQL and ContentProviders or Why SQL injections aren't dead yet ?
Before we get into SQL injections and what might go wrong, we'll start by covering some technical information on Cont...
Nov 03, 2016
Android external libs!
For an Android developer, it has become standard practice to use external libraries to easily extend the functionalit...
Nov 01, 2016
Vulnerabilities tested by Google Play Store
Google will start identifying security weaknesses in Apps pushed to the Play Store...
Sep 05, 2016
Python Concurrency and Parallelism: building a custom ProcessPoolExecutor
At Ostorlab we scan hundreds of Mobile Applications each day, each scan is very resource intensive but at the same ti...
Jul 18, 2016
New in Android M and N: Runtime Permissions
In Android, the permission system was one of the major security concerns of the platform for many reasons...
May 27, 2016
SSL Pinning on Android: Best Practices, OkHttp & Retrofit Examples (2026)
Learn how SSL pinning works on Android, what threats it helps mitigate, where it can break, and how to implement it s...
May 11, 2016
Reversing JNI, or how Facebook is crashing their own application
Apparently Facebook is crashing their apps intentionally in order to test users reaction and evaluate their adherence...
Jan 07, 2016
What every pentesters should learn in 2016
The last years have come with meaningful changes in the way IT professionals operate and the way we approach security...
Jan 02, 2016
Ostorlab Beta is out
We are pleased to release the Beta version of our online mobile application security scanner.
Dec 20, 2015
Best SSL/TLS resources (Attacks, Tools, Talks)
This article will reference the best current resources on SSL/TLS.
Aug 25, 2015