Neutron, our AI engine, scored 96.75% on UC Berkeley's CyberGym benchmark. Learn more

Author

Bilal Harras

Digital Marketer

Bilal is a digital marketer at Ostorlab, specializing in cybersecurity content, digital strategy, and brand growth. He works on making complex security topics more accessible through clear, credible, and engaging content for both technical and business audiences. By combining strategic communication with valuable content, Bilal contributes to Ostorlab's growth and helps strengthen its brand presence in the cybersecurity space. He believes that valuable content is essential to building a strong and trusted brand.

24 articles LinkedIn

How intent redirection lets attackers reach unexported Android components, leak data via setResult() and abuse PendingIntents, plus six ways to prevent it.

Product

Introducing HarmonyOS App Scans + Huawei AppGallery Scans

Find a vulnerability scanner for HarmonyOS apps and Huawei AppGallery releases: Ostorlab adds aut...

Apr 20, 2026

Security

Mobile AppSec Testing Best Practices at Scale

Mobile AppSec testing for teams shipping iOS and Android fast: MAST vs SAST vs DAST, a testing ch...

Apr 16, 2026

Security

DORA Third-Party Risk: Mobile SDK Governance

Manage DORA third-party risk in mobile apps with per-release SDK inventories and diffs, approval ...

Apr 14, 2026

More by Bilal Harras

Announcing Ostorlab for Bitrise: Mobile security scans in your CI

Ostorlab now integrates with Bitrise to run automated mobile application security scans inside CI workflows. Using a Bitrise Secret plus a simple Script step, teams can install the Ostorlab CLI and run ostorlab ci-scan run against the same build artifacts produced by the pipeline (e.g., Android APK, Android AAB, or iOS IPA). The integration helps shift security left by shortening feedback loops and catching vulnerabilities earlier, with options to tailor scans via profiles (fast, full, agentic deep scan) and optional inputs like test credentials, SBOM, and UI prompts.

Mar 27, 2026

Mobile Operational Resilience Under DORA: The simplest drill library for BFSI journeys

A mobile-first guide to DORA compliance for BFSI teams. Learn how to define your scope, simplify your release process, and avoid the traps that create unnecessary compliance work.

Mar 24, 2026

DORA Compliance for Mobile Releases: The easiest baseline, verdict, and exceptions model

A mobile-first guide to DORA regulation and DORA compliance for BFSI teams. Learn how to define your scope, simplify your release process, and avoid the traps that create unnecessary compliance work.

Mar 10, 2026

DORA Compliance for Mobile Teams: Understanding scope and what you need to do

A mobile-first guide to DORA regulation and DORA compliance for BFSI teams. Learn how to define your scope, simplify your release process, and avoid the traps that create unnecessary compliance work.

Mar 03, 2026

Best Mobile App Security Testing Platforms 2026

Compare Ostorlab, NowSecure, Appknox, Data Theorem, Quokka, Zimperium and MobSF for Android and iOS, with a feature matrix and vendor proof-of-value questions.

Jan 05, 2026

Android FLAG_SECURE: Block Screenshots and Recording

How Android's FLAG_SECURE blocks screenshots, screen recording and recent-apps previews, with code samples, use cases, limitations and casting behavior.

Dec 29, 2025


2 of 2
Next