Blog
Ostorlab Blog
Vulnerability research, CVE deep dives and engineering write-ups from the Ostorlab team on AI pentesting and mobile, web and API security testing.
Detection of Apple's Privacy Manifest, liblzma backdoor, and Attack Surface fixes.
This update introduces fixes for the Attack Surface, detection for the liblzma backdoor, and a public store for agents.
Apr 01, 2024
Discovering & Monitoring Mobile Applications Attack Surface with Ostorlab
The article introduces Ostorlab Attack Surface Discovery as a solution for discovering and contin...
Mar 26, 2024
Addition of CSS Injection Detection, ARM64 support, and migration of Agent's Docker Images.
This update introduces fixes for the Attack Surface, migration of Agent's Docker Images to Docker...
Mar 25, 2024
Security Landscape of Mobile Banking Applications in North America
This article examines the security of mobile banking applications in North America, uncovering wi...
Mar 19, 2024
Read by Topic
Latest from Engineering, Product & SecurityThe True Cost of False Positives: Calculating the Engineering Tax of Noisy Scanners
False positives are an engineering-capacity problem, not only a scanner-quality problem. Learn how to measu...
Sep 28, 2026
When Does an AI Scanner Become an AI Pentest?
Learn what separates AI-powered scanning from AI pentesting and how Ostorlab Deep Agentic Scan follows evid...
Jul 22, 2026
Source Code Security: From Signal to Validated Risk | Ostorlab
Learn how source code security testing works, why traditional SAST creates false positives, and how agentic...
Jul 16, 2026
Who Should Use Ostorlab? Best-Fit Teams, Use Cases, and When to Choose Something Else
Ostorlab fits teams testing connected mobile, web, API, and code assets on every release. Where it fits, wh...
Sep 28, 2026
How Deep Agentic Scan Catches Tricky Real-World Vulnerabilities
How Ostorlab's Deep Agentic Scan uncovers and empirically proves complex vulnerabilities across web, mobile...
Sep 23, 2026
Best On-Premises AppSec Testing Platforms (2026)
Compare Ostorlab, Invicti, Burp Suite DAST, HCL AppScan and Fortify for on-premises AppSec testing: deploym...
Sep 15, 2026
Ostorlab vs. Pentesting Firms: 2026 Cost & Depth Comparison
Ostorlab vs. pentesting firms: cost, testing frequency, depth and remediation, and when to use AI pentests,...
Sep 25, 2026
Why API Security Testing Misses Cross-Asset Attack Chains
API-only scanners miss attack chains that start with secrets or routes in mobile apps, web bundles, or code...
Sep 25, 2026
AI Pentesting for SOC 2: 6 Providers Compared
Compare Ostorlab, XBOW, Aikido, Intruder, Escape and Penti for SOC 2 pentests on exploit evidence, human re...
Sep 25, 2026
Changelog
View all changesThe Breach Brief Newsletter
Weekly offensive AI and cybersecurity breakdowns curated by Ostorlab.