Neutron, our AI engine, scored 96.75% on UC Berkeley's CyberGym benchmark. Learn more

Tag

#AI

25 articles

How a small agent that turned bug tickets into pull requests became Ostorlab's ticket agent: an AI teammate you give a job, a model, and rules for when it runs.

Product

Introducing Multi-Asset Deep Agentic Scan: Connected Testing Across the Application

Multi-Asset Deep Agentic Scan assesses related mobile, web, API, network, source-code, and docume...

Sep 02, 2026

Product

Introducing the Ostorlab Platform MCP Server

Ostorlab now supports MCP, giving AI assistants and agents permission-controlled access to securi...

Aug 08, 2026

Security

AI Can Run the Attack. Can You Trust the Result?

AI can produce a convincing exploit story in seconds. Runtime proof, negative controls, and human...

Aug 06, 2026

More tagged #AI

AI Pentesting Prompts That Produce Evidence, Not Just Findings

A practical guide to designing AI-assisted security testing workflows that turn scoped evidence into reviewable findings through structured outputs, validation gates, and controlled execution.

Jul 23, 2026

There Is No Magic Box: Why AI-Era AppSec Needs a Stack

Walk the floor of any major cybersecurity conference today and you will hear about the promise of autonomous AI-powered platforms. But AI-only testing doesn't scale. A resilient AppSec program requires a cost-aware, tiered stack combining rapid traditional scanners, private semantic reviews, and selective orchestration of frontier models.

Jun 22, 2026

Exploit CVE-2026-42208: LiteLLM Unauthenticated SQL Injection via Bearer Token

A technical breakdown of CVE-2026-42208, a CVSS 9.3 critical unauthenticated SQL Injection vulnerability in the LiteLLM Proxy API. Improper parameterization of the Bearer token within raw SQL queries used for complex multi-table joins allows blind boolean-based timing attacks, enabling unauthenticated attackers to exfiltrate sensitive data including virtual API keys, user information, and LLM spend logs directly from the database.

May 22, 2026

9 Open-Source AI Pentesting Tools Compared (2026)

PentestGPT, PentAGI, HexStrike AI, Strix, CAI, Nebula, NeuroSploit, Deadend CLI and RedAmon compared: key features of each AI pentest agent, GitHub stars and licenses.

Jan 30, 2026

AI Pentest Engine Discovers Critical WebSocket BFLA in GraphQL Subscriptions

Ostorlab's AI Pentest Engine systematically uncovered a critical Broken Function-Level Authorization (BFLA) vulnerability in a GraphQL WebSocket endpoint, allowing unauthenticated access to a real-time translation service. This case study details the AI's step-by-step process, from discovery to proof-of-concept.

Dec 26, 2025

AI Pentest Upgrades, ServiceNow Integration, Redesigned Email Notifications, and Enhanced Platform Controls

This release delivers major advancements across the Ostorlab platform, including a significant upgrade to AI Pentest, enhanced web and mobile automation, a full-featured ServiceNow integration, redesigned email notifications, improved threat intelligence capabilities, and comprehensive access control enhancements with role and owner-based permissions.

Dec 17, 2025

AI Engine Triggers Account Takeover via API Version Confusion

Methodical analysis beats blind fuzzing as Ostorlab's AI engine discovers cross-version password reset weakness and achieves account takeover without email access.

Dec 15, 2025

Going Beyond: Ostorlab AI Engine Discovers Unknown Vulnerability Classes

Ostorlab’s reasoning-driven AI engine breaks past rule-based limits to surface previously unknown and hard-to-detect vulnerabilities—including WebView Safe Browsing bypasses, SQLi via projections, WebCrypto key exfiltration, and JWT verification ordering flaws—delivering deeper, smarter, complementary security coverage.

Oct 13, 2025

Automating Security Research: AI Engine Exploits Complex Blind Code Injection

Precision beats payload spray using Ostorlab's AI engine to systematically land RCE on Titiler and proves exfiltration without a single stack trace.

Sep 04, 2025

AI-Powered Pentesting: A Deep Dive into Android Intent Redirection

This article showcases Ostorlab's AI Pentest Engine's process for analyzing an Android application for Intent Redirection vulnerabilities. Follow the engine's journey from static analysis and initial findings to rigorous dynamic validation, demonstrating its ability to not only identify potential threats but also to meticulously discard false positives.

Aug 31, 2025


Previous
1 of 2