Neutron, our AI engine, scored 96.75% on UC Berkeley's CyberGym benchmark. Learn more

Blog

Ostorlab Blog

Vulnerability research, CVE deep dives and engineering write-ups from the Ostorlab team on AI pentesting and mobile, web and API security testing.

Featured Stories See all articles →

Ostorlab now supports uploading an SBOM or Lockfile for extended dependency detection.

Product

CircleCI and AppCenter CI/CD integrations

Addition of CircleCI and AppCenter CI/CD integrations.

Jul 11, 2023

Security

Ostorlab's Insecure Flutter Apps: A Playground for Learning and Testing Mobile Security

Ostorlab has open-sourced two Flutter applications, designed to be intentionally insecure for tes...

Jul 10, 2023

Security

zCamera, 100M+ installation app, from remote compromise to data leaks

This article is a technical deep dive, showing how a 100M+ installation image application can exp...

Jul 04, 2023

Read by Topic

Latest from Engineering, Product & Security

False positives are an engineering-capacity problem, not only a scanner-quality problem. Learn how to measu...

Sep 28, 2026

Learn what separates AI-powered scanning from AI pentesting and how Ostorlab Deep Agentic Scan follows evid...

Jul 22, 2026

Learn how source code security testing works, why traditional SAST creates false positives, and how agentic...

Jul 16, 2026

Ostorlab fits teams testing connected mobile, web, API, and code assets on every release. Where it fits, wh...

Sep 28, 2026

How Ostorlab's Deep Agentic Scan uncovers and empirically proves complex vulnerabilities across web, mobile...

Sep 23, 2026

Compare Ostorlab, Invicti, Burp Suite DAST, HCL AppScan and Fortify for on-premises AppSec testing: deploym...

Sep 15, 2026

Ostorlab vs. pentesting firms: cost, testing frequency, depth and remediation, and when to use AI pentests,...

Sep 25, 2026

API-only scanners miss attack chains that start with secrets or routes in mobile apps, web bundles, or code...

Sep 25, 2026

Compare Ostorlab, XBOW, Aikido, Intruder, Escape and Penti for SOC 2 pentests on exploit evidence, human re...

Sep 25, 2026