Author
Bilal Harras
Bilal is a digital marketer at Ostorlab, specializing in cybersecurity content, digital strategy, and brand growth. He works on making complex security topics more accessible through clear, credible, and engaging content for both technical and business audiences. By combining strategic communication with valuable content, Bilal contributes to Ostorlab's growth and helps strengthen its brand presence in the cybersecurity space. He believes that valuable content is essential to building a strong and trusted brand.
Android Intent Redirection: Attacks and Fixes
How intent redirection lets attackers reach unexported Android components, leak data via setResult() and abuse PendingIntents, plus six ways to prevent it.
Apr 23, 2026
Introducing HarmonyOS App Scans + Huawei AppGallery Scans
Find a vulnerability scanner for HarmonyOS apps and Huawei AppGallery releases: Ostorlab adds aut...
Apr 20, 2026
Mobile AppSec Testing Best Practices at Scale
Mobile AppSec testing for teams shipping iOS and Android fast: MAST vs SAST vs DAST, a testing ch...
Apr 16, 2026
DORA Third-Party Risk: Mobile SDK Governance
Manage DORA third-party risk in mobile apps with per-release SDK inventories and diffs, approval ...
Apr 14, 2026
More by Bilal Harras
Announcing Ostorlab for Bitrise: Mobile security scans in your CI
Ostorlab now integrates with Bitrise to run automated mobile application security scans inside CI workflows. Using a Bitrise Secret plus a simple Script step, teams can install the Ostorlab CLI and run ostorlab ci-scan run against the same build artifacts produced by the pipeline (e.g., Android APK, Android AAB, or iOS IPA). The integration helps shift security left by shortening feedback loops and catching vulnerabilities earlier, with options to tailor scans via profiles (fast, full, agentic deep scan) and optional inputs like test credentials, SBOM, and UI prompts.
Mar 27, 2026
Mobile Operational Resilience Under DORA: The simplest drill library for BFSI journeys
A mobile-first guide to DORA compliance for BFSI teams. Learn how to define your scope, simplify your release process, and avoid the traps that create unnecessary compliance work.
Mar 24, 2026
DORA Compliance for Mobile Releases: The easiest baseline, verdict, and exceptions model
A mobile-first guide to DORA regulation and DORA compliance for BFSI teams. Learn how to define your scope, simplify your release process, and avoid the traps that create unnecessary compliance work.
Mar 10, 2026
DORA Compliance for Mobile Teams: Understanding scope and what you need to do
A mobile-first guide to DORA regulation and DORA compliance for BFSI teams. Learn how to define your scope, simplify your release process, and avoid the traps that create unnecessary compliance work.
Mar 03, 2026
Best Mobile App Security Testing Platforms 2026
Compare Ostorlab, NowSecure, Appknox, Data Theorem, Quokka, Zimperium and MobSF for Android and iOS, with a feature matrix and vendor proof-of-value questions.
Jan 05, 2026
Android FLAG_SECURE: Block Screenshots and Recording
How Android's FLAG_SECURE blocks screenshots, screen recording and recent-apps previews, with code samples, use cases, limitations and casting behavior.
Dec 29, 2025