Ostorlab outperforms Mythos, Microsoft, and Wiz. Our CyberGym benchmark results, at a fraction of the cost. Learn more

Ostorlab Team

Articles by Ostorlab Team
Featured Stories See all articles →

This technical analysis reveals how sophisticated attack chains—combining path traversal, symbolic link manipulation, and Android SDK quirks—can breach Signal Android's defenses to extract sensitive internal files, despite its legendary encryption remaining intact. While Signal patched these vulnerabilities within days, the discoveries offer crucial lessons about how seemingly minor bugs can be chained into powerful exploits, and why even the best security architecture needs multiple layers of defense

Security

Automating Security Research: AI Engine Exploits Report Portal XXE (CVE-2021-29620)

This article presents a thorough, hands-on analysis and proof of concept for exploiting an OOB XX...

Thu 07 August 2025

Product

From Random to Intelligent: How AI-Powered Monkey Testing Achieves 10x Mobile App Coverage

Ostorlab’s AI Monkey Tester transforms mobile app security testing by using natural language prom...

Fri 01 August 2025

Security

Automating Security Research: AI Engine Exploits Zulip Stored XSS (CVE-2025-52559)

This article presents a thorough, hands-on analysis and proof of concept for exploiting the store...

Mon 28 July 2025

Read by Topic

Latest from Engineering, Product & Security

OXO version 1.0, is 10x times faster, supports ARM64 architectures, and is packed with improved capabilitie...

Mon 29 April 2024

Tips and tricks to make your life easier when developing & debugging OXO Agents.

Thu 18 August 2022

How to debug Nuxt.js application on Webstorm

Fri 18 October 2019

Ostorlab has launched Agentic Deep Scan, a next-generation vulnerability scanner that validates real-world ...

Thu 19 March 2026

Ostorlab’s AI Monkey Tester transforms mobile app security testing by using natural language prompts and ge...

Fri 01 August 2025

This article announces Ostorlab's vulnerability ticketing system V2 and how it automates and streamlines th...

Tue 18 February 2025

An AI-assisted analysis uncovered a 30-year-old uninitialized buffer vulnerability in glibc's _nss_dns_getn...

Wed 21 January 2026

Ostorlab’s reasoning-driven AI engine breaks past rule-based limits to surface previously unknown and hard-...

Mon 13 October 2025

The first open-source benchmark suite featuring 93 realistic vulnerable mobile apps that mirror actual CVE ...

Mon 22 September 2025