Introducing Source Code Connect your repository and scan any branch, commit, or tag for actionable source code findings. Try it now

Bilal Harras

Digital Marketer LinkedIn

Bilal is a digital marketer at Ostorlab, specializing in cybersecurity content, digital strategy, and brand growth. He works on making complex security topics more accessible through clear, credible, and engaging content for both technical and business audiences. By combining strategic communication with valuable content, Bilal contributes to Ostorlab's growth and helps strengthen its brand presence in the cybersecurity space. He believes that valuable content is essential to building a strong and trusted brand.

Articles by Bilal Harras

Introducing Risk Reruns for Agentic Deep Scans—rerun specific risk investigations with customized effort levels, AI models, or parameters without re-uploading assets or starting over.

Product

Announcing Ostorlab’s On-Premises Vulnerability Scanner

Announcing the general availability of the Ostorlab On-Premises Vulnerability Scanner, designed t...

Tue 04 August 2026

Security

Ostorlab vs Aikido: Securing the Full Application Stack

Ostorlab vs Aikido: AppSec Comparison for Web, Mobile, API, and Source Code

Mon 03 August 2026

Security

Setting the Record Straight: Ostorlab vs. Appknox

A technical correction to Appknox's "Top 10 MAST Tools in 2026" comparison, highlighting the diff...

Wed 29 July 2026

Compare XBOW and Ostorlab's AI pentesting platforms across mobile, web, API, and source code coverage, including shielding validation, app vetting, and post-scan investigation tools.

A detailed comparison of Ostorlab and NowSecure across six key areas, highlighting why modern DevSecOps teams are replacing legacy mobile AppSec tools.

Latest posts

Ostorlab vs Quokka Q-mast: Mobile DAST Comparison

A technical comparison of Ostorlab and Quokka Q-mast Mobile Application Security Testing (MAST) tools, highlighting their foundational DAST capabilities and advanced AI agentic features for DevSecOps.

Wed 15 July 2026

There Is No Magic Box: Why AI-Era AppSec Needs a Stack

Walk the floor of any major cybersecurity conference today and you will hear about the promise of autonomous AI-powered platforms. But AI-only testing doesn't scale. A resilient AppSec program requires a cost-aware, tiered stack combining rapid traditional scanners, private semantic reviews, and selective orchestration of frontier models.

Mon 22 June 2026

The Definitive Guide to Mobile App Vetting: Securing the Enterprise App Ecosystem

This comprehensive guide covers the architecture, risk methodologies, and deployment frameworks required to architect an enterprise mobile app vetting strategy that protects corporate data assets without creating operational friction.

Fri 19 June 2026

Android Intent Redirection: Attack Vectors and Mitigations

A deep dive into Android intent redirection vulnerabilities, showing how exported “proxy” components can be abused to launch protected components, leak data via setResult(), steal content via URI grants, and hijack flows. Covers common misuse patterns and layered mitigations including validation, allowlists, IntentSanitizer, stripping dangerous flags, immutable PendingIntents, and reducing exported components.

Thu 23 April 2026

Introducing HarmonyOS App Scans + Huawei AppGallery Scans

Find a vulnerability scanner for HarmonyOS apps and Huawei AppGallery releases: Ostorlab adds automated, repeatable security scans so teams can continuously assess Huawei-distributed mobile apps and fix issues faster.

Mon 20 April 2026

Mobile AppSec Testing Best Practices for High-Tech Teams Shipping at Scale

A technical guide to mobile application security testing best practices for high-tech teams shipping iOS and Android apps at scale, covering MAST vs SAST vs DAST, mobile attack-surface testing, evidence-rich findings, CI/CD integration, severity-based release gating, compliance considerations, and how to evaluate a mobile AppSec solution.

Thu 16 April 2026

DORA Third‑Party Risk for Mobile AppSec: SDK Governance and Audit‑Ready Evidence Packs

A deep dive into DORA-focused third‑party risk for mobile AppSec, showing why embedded SDKs and runtime providers demand release‑scoped governance because vulnerabilities persist across multiple app versions in the wild and provider outages directly break critical journeys. It outlines an audit‑ready approach built on per‑release SDK inventories and diffs, approval/ban rules, patch SLAs with time‑boxed exceptions, and evidence packs that stay version‑scoped, indexed, and quickly retrievable.

Tue 14 April 2026

Announcing Ostorlab for Bitrise: Mobile security scans in your CI

Ostorlab now integrates with Bitrise to run automated mobile application security scans inside CI workflows. Using a Bitrise Secret plus a simple Script step, teams can install the Ostorlab CLI and run ostorlab ci-scan run against the same build artifacts produced by the pipeline (e.g., Android APK, Android AAB, or iOS IPA). The integration helps shift security left by shortening feedback loops and catching vulnerabilities earlier, with options to tailor scans via profiles (fast, full, agentic deep scan) and optional inputs like test credentials, SBOM, and UI prompts.

Fri 27 March 2026


Previous
1 of 2