Author
Bilal Harras
Bilal is a digital marketer at Ostorlab, specializing in cybersecurity content, digital strategy, and brand growth. He works on making complex security topics more accessible through clear, credible, and engaging content for both technical and business audiences. By combining strategic communication with valuable content, Bilal contributes to Ostorlab's growth and helps strengthen its brand presence in the cybersecurity space. He believes that valuable content is essential to building a strong and trusted brand.
We Built an AI Agent for Our Own Backlog. Now It's Yours.
How a small agent that turned bug tickets into pull requests became Ostorlab's ticket agent: an AI teammate you give a job, a model, and rules for when it runs.
Oct 06, 2026
Why API Security Testing Misses Cross-Asset Attack Chains
API-only scanners miss attack chains that start with secrets or routes in mobile apps, web bundle...
Sep 25, 2026
Best API Security Testing Tools in 2026: 4 Compared
The best API security testing tools in 2026: StackHawk, 42Crunch, Escape, and Ostorlab compared o...
Sep 22, 2026
Post-Mortem: Why Autonomous AI Agents Escape Scope and How to Contain Them
A technical post-mortem on an AI agent that wandered outside its testing scope during an authoriz...
Sep 18, 2026
More by Bilal Harras
The 2026 Guide to Penetration Testing for Startups (Costs, Process, and Vendor Selection)
A comprehensive guide on what penetration testing is, how much it costs for startups in 2026, the 5-step testing process, and how to choose the right vendor for your tech stack.
Aug 09, 2026
Introducing Risk Reruns: Granular Control for Agentic Deep Scans
Introducing Risk Reruns for Agentic Deep Scans—rerun specific risk investigations with customized effort levels, AI models, or parameters without re-uploading assets or starting over.
Aug 07, 2026
Announcing Ostorlab’s On-Premises Vulnerability Scanner
Announcing the general availability of the Ostorlab On-Premises Vulnerability Scanner, designed to identify and contextualize security flaws within your local infrastructure.
Aug 04, 2026
Ostorlab vs Aikido: AppSec Platform Comparison
Ostorlab vs Aikido on SAST, web and API pentesting, mobile binary testing, cloud posture, BYOK and remediation, with a side-by-side table and an FAQ.
Aug 03, 2026
Ostorlab vs Appknox: Setting the Record Straight
Ostorlab responds to the Appknox 'Top 10 MAST Tools' list: what it got wrong, KnoxIQ vs Agentic Deep Scan, full-stack coverage, deployment and pricing.
Jul 29, 2026
XBOW vs Ostorlab: AI Pentesting Compared
XBOW and Ostorlab compared on target scoping, mobile and API coverage, cross-asset exploit chaining, CI/CD testing, evidence and remediation workflows.
Jul 28, 2026
Ostorlab vs NowSecure: Mobile AppSec Comparison
Ostorlab vs NowSecure in six areas: cost and scale, CI/CD integration, business-logic coverage, framework support, targeted scans and geo-restricted apps.
Jul 27, 2026
Ostorlab vs Quokka Q-mast: Mobile DAST Comparison
Ostorlab vs Quokka Q-mast for mobile DAST: authenticated flows, TLS pinning bypass, PCAP evidence, geo-restricted apps, API scanning and Agentic Deep Scan.
Jul 15, 2026
There Is No Magic Box: Why AI-Era AppSec Needs a Stack
Walk the floor of any major cybersecurity conference today and you will hear about the promise of autonomous AI-powered platforms. But AI-only testing doesn't scale. A resilient AppSec program requires a cost-aware, tiered stack combining rapid traditional scanners, private semantic reviews, and selective orchestration of frontier models.
Jun 22, 2026
The Definitive Guide to Mobile App Vetting: Securing the Enterprise App Ecosystem
This comprehensive guide covers the architecture, risk methodologies, and deployment frameworks required to architect an enterprise mobile app vetting strategy that protects corporate data assets without creating operational friction.
Jun 19, 2026