Neutron, our AI engine, scored 96.75% on UC Berkeley's CyberGym benchmark. Learn more

Blog

Ostorlab Blog

Vulnerability research, CVE deep dives and engineering write-ups from the Ostorlab team on AI pentesting and mobile, web and API security testing.

Featured Stories See all articles →

A technical deep-dive into how Ostorlab Neutron reached a 96.75% verified exploit solved rate (1,458/1,507 tasks) and localized the flaw in all 1,507 tasks on UC Berkeley's CyberGym benchmark, combining pure source reverse engineering with deterministic protocol modeling.

Product

Who Should Use Ostorlab? Best-Fit Teams, Use Cases, and When to Choose Something Else

Ostorlab fits teams testing connected mobile, web, API, and code assets on every release. Where i...

Sep 28, 2026

Security

Ostorlab vs. Pentesting Firms: 2026 Cost & Depth Comparison

Ostorlab vs. pentesting firms: cost, testing frequency, depth and remediation, and when to use AI...

Sep 25, 2026

Security

Why API Security Testing Misses Cross-Asset Attack Chains

API-only scanners miss attack chains that start with secrets or routes in mobile apps, web bundle...

Sep 25, 2026

Read by Topic

Latest from Engineering, Product & Security

Learn what separates AI-powered scanning from AI pentesting and how Ostorlab Deep Agentic Scan follows evid...

Jul 22, 2026

Learn how source code security testing works, why traditional SAST creates false positives, and how agentic...

Jul 16, 2026

Agentic harnesses change what an LLM can do in mobile app security testing. On its own, a model can name li...

Jun 25, 2026

Ostorlab fits teams testing connected mobile, web, API, and code assets on every release. Where it fits, wh...

Sep 28, 2026

How Ostorlab's Deep Agentic Scan uncovers and empirically proves complex vulnerabilities across web, mobile...

Sep 23, 2026

Compare Ostorlab, Invicti, Burp Suite DAST, HCL AppScan and Fortify for on-premises AppSec testing: deploym...

Sep 15, 2026

Ostorlab vs. pentesting firms: cost, testing frequency, depth and remediation, and when to use AI pentests,...

Sep 25, 2026

API-only scanners miss attack chains that start with secrets or routes in mobile apps, web bundles, or code...

Sep 25, 2026

Compare Ostorlab, XBOW, Aikido, Intruder, Escape and Penti for SOC 2 pentests on exploit evidence, human re...

Sep 25, 2026