Tag
#Android
Bypassing Mobile App Shielding: Where Detection Ends and Enforcement Fails
Detection and enforcement are different security properties. Across five production banking apps protected by four commercial shielding products, the detection was sophisticated and the enforcement was fragile.
Aug 12, 2026
BeatBanker/BTMOB Android Banking Malware Analysis
Static analysis of TV_V_23.apk, BeatBanker/BTMOB Android banking malware disguised as a flashligh...
Apr 28, 2026
Android Intent Redirection: Attacks and Fixes
How intent redirection lets attackers reach unexported Android components, leak data via setResul...
Apr 23, 2026
Android Developer Verification 2026: Who Needs It
From 2026, certified Android devices can block apps from unverified developers. What changes for ...
Jan 27, 2026
More tagged #Android
Android WebView addJavascriptInterface Risks
Case study: Ostorlab's AI pentest engine finds an Android WebView JavaScript bridge reachable via deep links and chains it into native UI manipulation.
Jan 07, 2026
Best Mobile App Security Testing Platforms 2026
Compare Ostorlab, NowSecure, Appknox, Data Theorem, Quokka, Zimperium and MobSF for Android and iOS, with a feature matrix and vendor proof-of-value questions.
Jan 05, 2026
Android FLAG_SECURE: Block Screenshots and Recording
How Android's FLAG_SECURE blocks screenshots, screen recording and recent-apps previews, with code samples, use cases, limitations and casting behavior.
Dec 29, 2025
Going Beyond: Ostorlab AI Engine Discovers Unknown Vulnerability Classes
Ostorlab’s reasoning-driven AI engine breaks past rule-based limits to surface previously unknown and hard-to-detect vulnerabilities—including WebView Safe Browsing bypasses, SQLi via projections, WebCrypto key exfiltration, and JWT verification ordering flaws—delivering deeper, smarter, complementary security coverage.
Oct 13, 2025
Introducing Ostorlab Security Testing Benchmarks: Real Vulnerabilities, Real Impact
The first open-source benchmark suite featuring 93 realistic vulnerable mobile apps that mirror actual CVE and bug bounty findings - not theoretical textbook examples.
Sep 22, 2025
AI-Powered Pentesting: A Deep Dive into Android Intent Redirection
This article showcases Ostorlab's AI Pentest Engine's process for analyzing an Android application for Intent Redirection vulnerabilities. Follow the engine's journey from static analysis and initial findings to rigorous dynamic validation, demonstrating its ability to not only identify potential threats but also to meticulously discard false positives.
Aug 31, 2025
Know Your App's Data Habits: A Deep Dive into Our Comprehensive Privacy Analysis
Ostorlab's Privacy Scan automatically detects mismatches between what your app's privacy policy says and what it actually does. This comprehensive analysis of policy text, permissions, code, and UI elements helps mobile developers avoid compliance violations and build user trust through accurate privacy practices.
May 27, 2025
Secure Biometric Login in Kotlin, Swift and Flutter
In this Article, we define a secure implementation of mobile biometric authentication and provide detailed implementations in the 3 main modern mobile languages, namely Kotlin for Android, Swift for iOS, and Dart for Flutter multiplatform applications.
Jun 20, 2023
GodFather Android Malware Analysis
In This article, we analyze the GodFather Android malware, which continues to appear in various formats and primarily targets banking and cryptocurrency applications to steal money and sensitive information for the users.
Apr 14, 2023
Mobile CI/CD with Jenkins, GitHub Actions, Azure DevOps
This article will cover the main challenges when implementing a CI/CD pipeline for mobile applications. We will also provide examples of how you can implement a CI/CD pipeline for Android and iOS applications in the most used Mobile CI/CD tools.
Oct 27, 2022