Introducing Source Code Connect your repository and scan any branch, commit, or tag for actionable source code findings. Try it now

Tag

Security

A technical correction to Appknox's "Top 10 MAST Tools in 2026" comparison, highlighting the difference between static scanners and Ostorlab's autonomous Agentic Deep Scan platform.

Security

XBOW vs Ostorlab, AI Pentesting Compared: Mobile, Web, Source Code & API Coverage

Compare XBOW and Ostorlab's AI pentesting platforms across mobile, web, API, and source code cove...

Tue 28 July 2026

Security

How AI Catches Complex Vulnerabilities: Inside Agentic Pentesting and Exploit Chaining

Discover how agentic AI catches business logic flaws rule-based scanners miss. See a real exploit...

Tue 28 July 2026

Security

Beyond Legacy Mobile AppSec: Why Modern DevSecOps Teams Are Replacing NowSecure with Ostorlab

A detailed comparison of Ostorlab and NowSecure across six key areas, highlighting why modern Dev...

Mon 27 July 2026

Ostorlab Threat Center now brings EUVD intelligence alongside NVD data, giving security teams broader vulnerability visibility as they prepare for the EU Cyber Resilience Act.

Learn how source code security testing works, why traditional SAST creates false positives, and how agentic analysis turns scanner signals into actionable findings.

Latest posts

Breaking Down the Latest Version of GoPhish: Source-Code Assessment with Ostorlab Agentic Deep Scan

A technical assessment of the latest version of GoPhish that examines how the platform handles trust: identity, untrusted content, object ownership, credential lifecycle, and outbound requests. Source-code analysis with Ostorlab Agentic Deep Scan established the eight report-level findings, PoCs, and remediation priorities.

Thu 16 July 2026

The Definitive Guide to Mobile App Vetting: Securing the Enterprise App Ecosystem

This comprehensive guide covers the architecture, risk methodologies, and deployment frameworks required to architect an enterprise mobile app vetting strategy that protects corporate data assets without creating operational friction.

Fri 19 June 2026

Exploit CVE-2026-42208: LiteLLM Unauthenticated SQL Injection via Bearer Token

A technical breakdown of CVE-2026-42208, a CVSS 9.3 critical unauthenticated SQL Injection vulnerability in the LiteLLM Proxy API. Improper parameterization of the Bearer token within raw SQL queries used for complex multi-table joins allows blind boolean-based timing attacks, enabling unauthenticated attackers to exfiltrate sensitive data including virtual API keys, user information, and LLM spend logs directly from the database.

Fri 22 May 2026

DirtyFrag: Universal Linux Local Privilege Escalation via Page-Cache Write

A technical breakdown of DirtyFrag, a pair of Linux kernel local privilege escalation vulnerabilities (CVE-2026-43284 and CVE-2026-43500, CVSS 7.8 HIGH) that allow any unprivileged local user to obtain root on most major Linux distributions. By chaining an xfrm-ESP and an RxRPC in-place decryption path flaw, both rooted in the same page-cache write primitive as Dirty Pipe and Copy Fail, the exploit overwrites read-only page cache pages without a race condition, achieving near-100% reliability.

Wed 13 May 2026

Exploit CVE-2026-44109 : OpenClaw Feishu Webhook Authentication Bypass to RCE

A technical breakdown of CVE-2026-44109, a CVSS 9.2 Critical authentication bypass vulnerability in OpenClaw (< 2026.4.15). Two fail-open logic inversions in the Feishu/Lark plugin — one in the webhook signature validator and one in the card-action replay guard — allow an unauthenticated attacker to inject arbitrary events into OpenClaw's command dispatch engine. When the bot has execution tools enabled, this translates directly to unauthenticated remote code execution on the host machine with the privileges of the OpenClaw process.

Thu 07 May 2026

CVE-2026-5205: Critical SSRF in Chatwoot — How a Single Upload Parameter Exposes Cloud Credentials

A deep dive into a critical Server-Side Request Forgery (SSRF) vulnerability in Chatwoot's upload endpoint (≤ v4.12.1). The /api/v1/accounts/:id/upload endpoint accepts an external_url parameter validated only by a scheme check, allowing any authenticated agent to force the server to fetch arbitrary internal URLs. The full response body is returned in-band through ActiveStorage blobs — turning the upload endpoint into a full-read proxy. Live exploitation on a DigitalOcean droplet confirmed in-band exfiltration of cloud metadata including droplet ID, hostname, SSH public keys, and full metadata bundles. Fixed in v4.13.0.

Wed 29 April 2026

DORA Compliance Checklist for Banking & Fintech: Audit-Ready Operational Resilience Validation

A DORA compliance checklist helps banking and fintech organizations evaluate operational resilience across core areas like ICT risk, incident response, resilience testing, third-party governance, and oversight, while tracking implementation progress and supporting audit readiness.

Wed 29 April 2026

The Complete Guide to Healthcare Application Security Testing: Protecting ePHI, Medical Apps, and Patient Trust

This comprehensive guide explores the critical role of application security testing in modern healthcare. It covers the shift toward application-driven care, the unique value of ePHI, and the regulatory landscape (HIPAA/GDPR). The article outlines a robust strategy for securing the healthcare ecosystem, including patient portals, APIs, and SaMD, while highlighting how autonomous tools like Ostorlab’s Deep Agentic Scan are defining the future of continuous, scalable security validation.

Thu 16 April 2026


Previous
1 of 6