Introducing Source Code Connect your repository and scan any branch, commit, or tag for actionable source code findings. Try it now

Bilal Harras

Digital Marketer LinkedIn

Bilal is a digital marketer at Ostorlab, specializing in cybersecurity content, digital strategy, and brand growth. He works on making complex security topics more accessible through clear, credible, and engaging content for both technical and business audiences. By combining strategic communication with valuable content, Bilal contributes to Ostorlab's growth and helps strengthen its brand presence in the cybersecurity space. He believes that valuable content is essential to building a strong and trusted brand.

Articles by Bilal Harras

Introducing Risk Reruns for Agentic Deep Scans—rerun specific risk investigations with customized effort levels, AI models, or parameters without re-uploading assets or starting over.

Security

The 2026 Guide to Penetration Testing for Startups (Costs, Process, and Vendor Selection)

A comprehensive guide on what penetration testing is, how much it costs for startups in 2026, the...

Thu 06 August 2026

Product

Announcing Ostorlab’s On-Premises Vulnerability Scanner

Announcing the general availability of the Ostorlab On-Premises Vulnerability Scanner, designed t...

Tue 04 August 2026

Security

Ostorlab vs Aikido: Securing the Full Application Stack

Ostorlab vs Aikido: AppSec Comparison for Web, Mobile, API, and Source Code

Mon 03 August 2026

A technical correction to Appknox's "Top 10 MAST Tools in 2026" comparison, highlighting the difference between static scanners and Ostorlab's autonomous Agentic Deep Scan platform.

Compare XBOW and Ostorlab's AI pentesting platforms across mobile, web, API, and source code coverage, including shielding validation, app vetting, and post-scan investigation tools.

Latest posts

Beyond Legacy Mobile AppSec: Why Modern DevSecOps Teams Are Replacing NowSecure with Ostorlab

A detailed comparison of Ostorlab and NowSecure across six key areas, highlighting why modern DevSecOps teams are replacing legacy mobile AppSec tools.

Mon 27 July 2026

Ostorlab vs Quokka Q-mast: Mobile DAST Comparison

A technical comparison of Ostorlab and Quokka Q-mast Mobile Application Security Testing (MAST) tools, highlighting their foundational DAST capabilities and advanced AI agentic features for DevSecOps.

Wed 15 July 2026

There Is No Magic Box: Why AI-Era AppSec Needs a Stack

Walk the floor of any major cybersecurity conference today and you will hear about the promise of autonomous AI-powered platforms. But AI-only testing doesn't scale. A resilient AppSec program requires a cost-aware, tiered stack combining rapid traditional scanners, private semantic reviews, and selective orchestration of frontier models.

Mon 22 June 2026

The Definitive Guide to Mobile App Vetting: Securing the Enterprise App Ecosystem

This comprehensive guide covers the architecture, risk methodologies, and deployment frameworks required to architect an enterprise mobile app vetting strategy that protects corporate data assets without creating operational friction.

Fri 19 June 2026

Android Intent Redirection: Attack Vectors and Mitigations

A deep dive into Android intent redirection vulnerabilities, showing how exported “proxy” components can be abused to launch protected components, leak data via setResult(), steal content via URI grants, and hijack flows. Covers common misuse patterns and layered mitigations including validation, allowlists, IntentSanitizer, stripping dangerous flags, immutable PendingIntents, and reducing exported components.

Thu 23 April 2026

Introducing HarmonyOS App Scans + Huawei AppGallery Scans

Find a vulnerability scanner for HarmonyOS apps and Huawei AppGallery releases: Ostorlab adds automated, repeatable security scans so teams can continuously assess Huawei-distributed mobile apps and fix issues faster.

Mon 20 April 2026

Mobile AppSec Testing Best Practices for High-Tech Teams Shipping at Scale

A technical guide to mobile application security testing best practices for high-tech teams shipping iOS and Android apps at scale, covering MAST vs SAST vs DAST, mobile attack-surface testing, evidence-rich findings, CI/CD integration, severity-based release gating, compliance considerations, and how to evaluate a mobile AppSec solution.

Thu 16 April 2026

DORA Third‑Party Risk for Mobile AppSec: SDK Governance and Audit‑Ready Evidence Packs

A deep dive into DORA-focused third‑party risk for mobile AppSec, showing why embedded SDKs and runtime providers demand release‑scoped governance because vulnerabilities persist across multiple app versions in the wild and provider outages directly break critical journeys. It outlines an audit‑ready approach built on per‑release SDK inventories and diffs, approval/ban rules, patch SLAs with time‑boxed exceptions, and evidence packs that stay version‑scoped, indexed, and quickly retrievable.

Tue 14 April 2026


Previous
1 of 2