Author
Abir Jelti
Abir is a digital marketer at Ostorlab. She focuses on mobile application security testing, producing educational and data-driven content around vulnerabilities, security practices, and real-world testing insights. Her work is grounded in in-depth research and is reviewed for technical accuracy and reproducibility by the Ostorlab engineering team. She contributes to making security findings clear, structured, and actionable.
Source Code Security: From Signal to Validated Risk | Ostorlab
Learn how source code security testing works, why traditional SAST creates false positives, and how agentic analysis turns scanner signals into actionable findings.
Jul 16, 2026
The App Was Never Opened
Agentic harnesses change what an LLM can do in mobile app security testing. On its own, a model c...
Jun 25, 2026
Introducing Ostorlab App Vetting for the Agentic Era
Ostorlab has launched App Vetting, a mobile application risk assessment solution that helps teams...
Jun 16, 2026
Building an AI PR Reviewer Engineers Actually Trust
We built an AI-powered pull request reviewer, shut it down after hallucinations and false positiv...
Jun 08, 2026
More by Abir Jelti
DORA Compliance Checklist for Banking & Fintech: Audit-Ready Operational Resilience Validation
A DORA compliance checklist helps banking and fintech organizations evaluate operational resilience across core areas like ICT risk, incident response, resilience testing, third-party governance, and oversight, while tracking implementation progress and supporting audit readiness.
Apr 29, 2026
Mobile Banking App Security Testing Guide
Protecting mobile banking apps requires more than securing the client alone. This guide explores the risks across devices, networks, and backend systems, and explains why continuous mobile security testing is essential for protecting financial data and transactions.
Apr 16, 2026
Announcing Ostorlab for Harness: Mobile Security Scanning in CI Pipelines
Ostorlab now integrates with Harness CI to run automated mobile application security scans inside CI pipelines. Using Harness Secrets and a simple Run step, teams can install the Ostorlab CLI and run ostorlab ci-scan run against the same build artifacts produced by the pipeline (e.g., Android APK, Android AAB, or iOS IPA). The integration helps bring security into CI by improving feedback speed and catching vulnerabilities earlier, with options to tailor scans via profiles (fast, full) and optional inputs like test credentials, SBOM, and UI prompts.
Apr 06, 2026
Security Testing Behind Login Walls: 2FA and MFA
Why scanners stop at the login page and how Ostorlab automates testing behind SMS, email and TOTP 2FA, with a manual fallback and secured credentials.
Mar 30, 2026