Product
Introducing Risk Reruns: Granular Control for Agentic Deep Scans
Introducing Risk Reruns for Agentic Deep Scans—rerun specific risk investigations with customized effort levels, AI models, or parameters without re-uploading assets or starting over.
Thu 06 August 2026
Introducing the Ostorlab Platform MCP Server
Ostorlab now supports MCP, giving AI assistants and agents permission-controlled access to securi...
Thu 06 August 2026
Introducing Agentic Scan Knowledge: The Scanner That Never Forgets
Agentic Scan Knowledge gives Ostorlab security agents persistent application context, allowing ev...
Wed 05 August 2026
Introducing Ostorlab Mobile Shielding Scan
Ostorlab Mobile Shielding Scan tests Android and iOS protections against real bypasses, including...
Tue 04 August 2026
Announcing Ostorlab’s On-Premises Vulnerability Scanner
Announcing the general availability of the Ostorlab On-Premises Vulnerability Scanner, designed to identify and contextualize security flaws within your local infrastructure.
The Ostorlab Threat Center Now Supports the EU Vulnerability Database
Ostorlab Threat Center now brings EUVD intelligence alongside NVD data, giving security teams broader vulnerability visibility as they prepare for the EU Cyber Resilience Act.
Latest posts
Introducing Ostorlab Source Code Scanning
Source Code Scanning helps you identify security vulnerabilities directly in your source code before they reach production. Connect your repositories, run scans on demand, and review actionable findings from within Ostorlab.
Tue 07 July 2026
App Vetting, Scan Coverage Heatmap, Mobile Shielding Scan, Deep Agentic Scan Improvements, Cyber Models & Source Code Scanning
This release introduces App Vetting, Scan Coverage Heatmap, Mobile Shielding Scan, Deep Agentic Scan improvements, Cyber Models, additional model support, and source code scanning.
Tue 07 July 2026
Deep Scan Improvements: Faster Execution, Better Decisions, and Incremental Testing
The latest Deep Agentic Scan release introduces faster mobile testing, improved reverse engineering, stronger vulnerability detection, incremental coverage through historical scan processing, improved vulnerability chaining, and managed Cyber Models for mobile and web assessments.
Tue 30 June 2026
Introducing Mobile Shielding That Can Resist AI Attacks
Ostorlab has launched Mobile Shielding Scan, an automated, AI-powered testing solution designed specifically for shielding detection and validation. It gives security teams streamlined, continuous validation of critical iOS and Android runtime protections, identifying whether security shields are actually present and if they can withstand real-world attacks. This empowers organizations with an automated, scalable, and powerful way to continuously validate RASP tools and mobile self-defense layers across every release.
Thu 25 June 2026
Introducing Ostorlab Cyber Models
Ostorlab has launched Cyber Models, a managed, prepaid AI infrastructure tier for Deep Agentic Scans. It gives security teams streamlined access to specialized models like GPT-5.5 Cyber and Opus 4.8 with Cyber Verification Program through approved provider channels. This bypasses the need to manage external API keys, provider rate limits, or fragmented billing dashboards.
Tue 23 June 2026
Introducing Ostorlab App Vetting for the Agentic Era
Ostorlab has launched App Vetting, a mobile application risk assessment solution that helps teams evaluate Android and iOS apps before approval. It combines static analysis, dynamic testing, and secure sandbox execution with continuous monitoring, weighted risk scoring, and agentic workflows to identify vulnerabilities, privacy risks, malware indicators, telemetry behavior, and trust issues while helping teams prioritize what matters most.
Tue 16 June 2026
Introducing Ostorlab’s Single Vulnerability Assessment and Dig Deeper
Ostorlab is launching a powerful, highly targeted AI orchestration engine accessible through two distinct UI workflows: Single Vulnerability Assessment (SVA) and Dig Deeper. While both features share the exact same underlying AI logic, capabilities, and "Bring-Your-Own-Key" structure, they are tailored for different entry points in your workflow. SVA is launched as a fresh, standalone scan for targeted, cost-efficient assessments, fix validations, or bug bounty verifications. Dig Deeper is triggered directly from an existing finding within a scan report to instantly investigate false positives or trace exploit paths. Together, they give teams surgical control over how they test and validate individual vulnerabilities.
Tue 02 June 2026
Single Vulnerability Assessment (SVA), Dig Deeper, Scan Report PDF Design Improvement & Multilanguage Support
This release introduces Single Vulnerability Assessment (SVA) for targeted validation, Dig Deeper for granular root-cause investigation, Live Attack Scenario Risk & Status Tracking, Scan Report PDF Design Improvement, full multilanguage localization, and new compliance whitelisting support.
Mon 01 June 2026