Scaling real-world hacker research with AI to help AppSec teams find and fix their most exploitable risks before attackers do.

Stockholm and Boston
Back in 2021 I wrote a "how to hack APIs" blog for Detectify. It ended up being one of the most-read things I've written that year, but APIs have changed a lot since then: GraphQL, AI-generated endpoints, all of it. So I rewrote the whole thing for 2026. Check it out👇
2
42
215
9,263
In 2026 the API is the application for most of what you’ll test. Are your API hacking skills up to date? Check out @hakluke´s latest guide on how to hunt for API vulnerabilities in 2026: 👇 labs.detectify.com/how-to/ho…
14
38
18,219
Unauthenticated access in AI agent platforms like Ruflo exposes API keys, logs, & execution tools in one go. Detectify co-founder Johan Edholm spoke with @DarkReading about the expanding attack surface of AI infrastructure. 🔗 darkreading.com/cyber-risk/p…
3
428
When adversaries weaponize LLMs, attack economics change overnight. @DarkReading details how threat actors turned jailbroken AI into a commercial offensive platform. Our CEO Rickard Carlsson breaks down why lowering the barrier to entry changes defense: darkreading.com/cyber-risk/h…
373
.@DarkReading reports on "JadePuffer", the first fully agentic, LLM-driven ransomware attack that autonomously executed a network intrusion and extortion. Our co-founder Johan Edholm discusses how traditional incident response can't keep up with AI threats darkreading.com/cyberattacks…
4
3
809
We are proud to recognize some of the top ethical hackers from our Crowdsource community. Thanks to their research submissions, our customers can access some of the best hackers in the world: labs.detectify.com/crowdsour…
1
4
410
hey SF - Come hack yourself at #RSAC2026. Booth 4514
2
473
450 automated, validated security tests created in 6 months, targeting critical threats (avg. CVSS 8.5). 70% of tests needed no manual fix. Write-up with our prompts, lessons, & build process in @detectify labs! ⤵️ labs.detectify.com/writeups/…
1
1
3
746
With the new API Scanner, customers gain access to dynamic payloads that make every scan different. Instead of relying on static methods, the scanner uses ML to randomize and rotate payloads for each run, ensuring fresh attack simulations every time:
Detectify expands AppSec platform with new API scanning capabilities ift.tt/TPG2Meu
1
749
We know it is hard to ensure all essential web apps are covered with deep DAST. Which of your dozens or hundreds of web apps actually need deep testing? Which are processing user data or even have many components that attackers would target? blog.detectify.com/product-u…
1
878
Break free from the illusion of coverage! detectify.com/asset-classifi…
1
651
See the forest <i>AND</i> the trees! detectify.com/asset-classifi…
536
Attending #RSAC? It's finally your chance to snag some of our famous Go Hack Yourself swag. More info: detectify.com/rsac
678
Find out how Detectify Alfred (AI-Built vuln assessments) is working around the clock to continuously bring you the latest security research: blog.detectify.com/product-u…
1
366