What is Detectify?

Web security blog

SQLi in INSERT worse than SELECT

Mathias Karlsson SQL Injection

Stored XSS-ing Millions Of Sites Through HTML Comment Box

CSP flaws: cookie fixation

Cookie fixation CSP Mathias Karlsson

postMessage XSS on a million sites

AddThis Mathias Karlsson postmessage

The pitfalls of postMessage

Mathias Karlsson postmessage

Combining host header injection and lax host parsing serving malicious data

bug bounty Fastly Frans Rosén Heroku Mathias Karlsson

The story of EV-SSL, AWS and trailing dot domains

Frans Rosén Hostile Subdomain takeover SSL

Using Chrome’s web-custom-data UTI to inject a stored XSS in Slack

Frans Rosén Slack XSS

How I made LastPass give me all your passwords

Cross Site Scripting Lastpass Mathias Karlsson XSS

What HPKP is but isn’t

HPKP HTTP public key pinning