Neutron, our AI engine, scored 96.75% on UC Berkeley's CyberGym benchmark. Learn more

Blog

Ostorlab Blog

Vulnerability research, CVE deep dives and engineering write-ups from the Ostorlab team on AI pentesting and mobile, web and API security testing.

Featured Stories See all articles →

A technical breakdown of CVE-2026-42208, a CVSS 9.3 critical unauthenticated SQL Injection vulnerability in the LiteLLM Proxy API. Improper parameterization of the Bearer token within raw SQL queries used for complex multi-table joins allows blind boolean-based timing attacks, enabling unauthenticated attackers to exfiltrate sensitive data including virtual API keys, user information, and LLM spend logs directly from the database.

Security

DirtyFrag: Universal Linux Local Privilege Escalation via Page-Cache Write

A technical breakdown of DirtyFrag, a pair of Linux kernel local privilege escalation vulnerabili...

May 13, 2026

Security

CVE-2026-44109: OpenClaw Feishu Auth Bypass to RCE

A technical breakdown of CVE-2026-44109, a CVSS 9.2 Critical authentication bypass vulnerability ...

May 07, 2026

Security

CVE-2026-5205: Critical SSRF in Chatwoot Uploads

A deep dive into a critical Server-Side Request Forgery (SSRF) vulnerability in Chatwoot's upload...

Apr 29, 2026

Read by Topic

Latest from Engineering, Product & Security

False positives are an engineering-capacity problem, not only a scanner-quality problem. Learn how to measu...

Sep 28, 2026

Learn what separates AI-powered scanning from AI pentesting and how Ostorlab Deep Agentic Scan follows evid...

Jul 22, 2026

Learn how source code security testing works, why traditional SAST creates false positives, and how agentic...

Jul 16, 2026

Ostorlab fits teams testing connected mobile, web, API, and code assets on every release. Where it fits, wh...

Sep 28, 2026

How Ostorlab's Deep Agentic Scan uncovers and empirically proves complex vulnerabilities across web, mobile...

Sep 23, 2026

Compare Ostorlab, Invicti, Burp Suite DAST, HCL AppScan and Fortify for on-premises AppSec testing: deploym...

Sep 15, 2026

Ostorlab vs. pentesting firms: cost, testing frequency, depth and remediation, and when to use AI pentests,...

Sep 25, 2026

API-only scanners miss attack chains that start with secrets or routes in mobile apps, web bundles, or code...

Sep 25, 2026

Compare Ostorlab, XBOW, Aikido, Intruder, Escape and Penti for SOC 2 pentests on exploit evidence, human re...

Sep 25, 2026