Introducing Risk Reruns: Granular Control for Agentic Deep Scans
Introducing Risk Reruns for Agentic Deep Scans—rerun specific risk investigations with customized effort levels, AI models, or parameters without re-uploading assets or starting over.
Thu 06 August 2026
Announcing Ostorlab’s On-Premises Vulnerability Scanner
Announcing the general availability of the Ostorlab On-Premises Vulnerability Scanner, designed t...
Tue 04 August 2026
Ostorlab vs Aikido: Securing the Full Application Stack
Ostorlab vs Aikido: AppSec Comparison for Web, Mobile, API, and Source Code
Mon 03 August 2026
Setting the Record Straight: Ostorlab vs. Appknox
A technical correction to Appknox's "Top 10 MAST Tools in 2026" comparison, highlighting the diff...
Wed 29 July 2026
XBOW vs Ostorlab, AI Pentesting Compared: Mobile, Web, Source Code & API Coverage
Compare XBOW and Ostorlab's AI pentesting platforms across mobile, web, API, and source code coverage, including shielding validation, app vetting, and post-scan investigation tools.
Beyond Legacy Mobile AppSec: Why Modern DevSecOps Teams Are Replacing NowSecure with Ostorlab
A detailed comparison of Ostorlab and NowSecure across six key areas, highlighting why modern DevSecOps teams are replacing legacy mobile AppSec tools.
Latest posts
Ostorlab vs Quokka Q-mast: Mobile DAST Comparison
A technical comparison of Ostorlab and Quokka Q-mast Mobile Application Security Testing (MAST) tools, highlighting their foundational DAST capabilities and advanced AI agentic features for DevSecOps.
Wed 15 July 2026
There Is No Magic Box: Why AI-Era AppSec Needs a Stack
Walk the floor of any major cybersecurity conference today and you will hear about the promise of autonomous AI-powered platforms. But AI-only testing doesn't scale. A resilient AppSec program requires a cost-aware, tiered stack combining rapid traditional scanners, private semantic reviews, and selective orchestration of frontier models.
Mon 22 June 2026
The Definitive Guide to Mobile App Vetting: Securing the Enterprise App Ecosystem
This comprehensive guide covers the architecture, risk methodologies, and deployment frameworks required to architect an enterprise mobile app vetting strategy that protects corporate data assets without creating operational friction.
Fri 19 June 2026
Android Intent Redirection: Attack Vectors and Mitigations
A deep dive into Android intent redirection vulnerabilities, showing how exported “proxy” components can be abused to launch protected components, leak data via setResult(), steal content via URI grants, and hijack flows. Covers common misuse patterns and layered mitigations including validation, allowlists, IntentSanitizer, stripping dangerous flags, immutable PendingIntents, and reducing exported components.
Thu 23 April 2026
Introducing HarmonyOS App Scans + Huawei AppGallery Scans
Find a vulnerability scanner for HarmonyOS apps and Huawei AppGallery releases: Ostorlab adds automated, repeatable security scans so teams can continuously assess Huawei-distributed mobile apps and fix issues faster.
Mon 20 April 2026
Mobile AppSec Testing Best Practices for High-Tech Teams Shipping at Scale
A technical guide to mobile application security testing best practices for high-tech teams shipping iOS and Android apps at scale, covering MAST vs SAST vs DAST, mobile attack-surface testing, evidence-rich findings, CI/CD integration, severity-based release gating, compliance considerations, and how to evaluate a mobile AppSec solution.
Thu 16 April 2026
DORA Third‑Party Risk for Mobile AppSec: SDK Governance and Audit‑Ready Evidence Packs
A deep dive into DORA-focused third‑party risk for mobile AppSec, showing why embedded SDKs and runtime providers demand release‑scoped governance because vulnerabilities persist across multiple app versions in the wild and provider outages directly break critical journeys. It outlines an audit‑ready approach built on per‑release SDK inventories and diffs, approval/ban rules, patch SLAs with time‑boxed exceptions, and evidence packs that stay version‑scoped, indexed, and quickly retrievable.
Tue 14 April 2026
Announcing Ostorlab for Bitrise: Mobile security scans in your CI
Ostorlab now integrates with Bitrise to run automated mobile application security scans inside CI workflows. Using a Bitrise Secret plus a simple Script step, teams can install the Ostorlab CLI and run ostorlab ci-scan run against the same build artifacts produced by the pipeline (e.g., Android APK, Android AAB, or iOS IPA). The integration helps shift security left by shortening feedback loops and catching vulnerabilities earlier, with options to tailor scans via profiles (fast, full, agentic deep scan) and optional inputs like test credentials, SBOM, and UI prompts.
Fri 27 March 2026