vulnit Becomes an OWASP MAS Advocate

OWASP Mobile Application Security recognizes vulnit for sustained contributions to MASVS-RESILIENCE, atomic OWASP MASTG tests, and reproducible demonstrations.

On July 15, 2026, the OWASP Mobile Application Security project recognized vulnit as a new OWASP MAS Advocate for sustained contributions to mobile application security standards.

The recognition matters to us because it reflects the kind of work we want to do: technical contributions that other security teams can inspect, reproduce, and use. It also recognizes the time Jacobo Casado and Sergio García have invested in OWASP MAS working sessions, test migration, runnable demonstrations, and technical review.

The official OWASP MAS announcement describes Advocate status as the project’s highest form of recognition for organizations making sustained and high-impact contributions.

Group at MAScon during the OWASP MAS Advocate recognition, with vulnit on the presentation screen.

MAS Advocate recognition at MAScon. Photo: OWASP MAS.

What vulnit contributed

Our work focused on MASVS-RESILIENCE, the area of the OWASP Mobile Application Security Verification Standard concerned with resistance to debugging, tampering, reverse engineering, emulators, and dynamic instrumentation.

The contribution included:

  • migrating 9 OWASP MASTG version 1 tests into 17 focused OWASP MASTG version 2 tests
  • producing 16 runnable demonstrations with verified device output
  • documenting practical techniques with Frida scripts and radare2 commands
  • reviewing and co-developing technical material with OWASP MAS contributors
  • participating consistently in OWASP MAS Task Force meetings and standards discussions

Breaking broad tests into smaller, atomic tests makes each method easier to understand, execute, review, and maintain. Runnable demonstrations also make the expected behavior concrete: a reader can follow the technique, inspect the device output, and understand what evidence supports the result.

Why reproducible evidence matters

A testing standard becomes more useful when its methods connect clearly to observable behavior.

A test identifier or a PASS/FAIL result is not enough by itself. Security teams also need to understand:

  • which workflow and environment produced the behavior
  • what happened in the application and on the device
  • which static or runtime signals were relevant
  • how another researcher can reproduce the observation
  • why the evidence supports the conclusion

That principle is central to how we think about mobile security at vulnit. Standards provide a shared language and a reviewable testing method. Execution evidence shows what happened in a specific application run. The strongest result connects both.

What the recognition means

OWASP MAS Advocate status recognizes community contribution.

For us, it is evidence that the team can contribute useful engineering work to one of the most important open mobile security standards. It also gives us a responsibility to continue participating, reviewing, testing, and sharing practical material with the community.

We are grateful to the OWASP MAS maintainers and contributors who reviewed the work and collaborated with us throughout the process.

Read the full announcement on the OWASP Mobile Application Security website.

vulnit

Mobile security research and engineering

LinkedIn · View all posts

A necessary cookie remembers your choice for up to 180 days. Privacy policy.