The Decloak Journal

Security news &
platform updates.

Stories from around the web security world, plus release notes and changes to Decloak itself.

Uncloaked: Even an API Security Testing Company Got Breached by an Unprotected Database
News1 September 2026

Uncloaked: Even an API Security Testing Company Got Breached by an Unprotected Database

Three recent stories, all API-shaped: a ServiceNow access-control gap that let unauthenticated queries pull customer instance data, a compromised third-party app that gave attackers a path into Salesforce customer connections, and an API security testing firm exposed by exactly the kind of unprotected database it tests for.

Introducing Scoreboards: A Real Dashboard for Every Domain You're Watching
News24 August 2026

Introducing Scoreboards: A Real Dashboard for Every Domain You're Watching

Your account now opens to an actual command center instead of a list of scans, aggregate posture across every domain you monitor, plus a dedicated scoreboard for each one. Live for every account, free included.

Uncloaked: A Weaponized Detection Tool, a Government Contact Leak, and Another Vendor Breach
News18 August 2026

Uncloaked: A Weaponized Detection Tool, a Government Contact Leak, and Another Vendor Breach

Three recent stories, all misconfiguration rather than a hack: a data-extortion group hitting Microsoft Power Pages across roughly 15 organisations, a Salesforce campaign that turned a misconfiguration-detection tool into an attack tool, and a hardware wallet company breached through its shipping provider.

Uncloaked: 380,000 Exposed Apps and the Vibe-Coding Security Problem Nobody's Fixing
News5 August 2026

Uncloaked: 380,000 Exposed Apps and the Vibe-Coding Security Problem Nobody's Fixing

Five recent stories, all about the same underlying pattern: apps built by describing them in plain English, shipped fast, and left with security defaults nobody thought to check. A Base44 auth bypass, 380,000 publicly indexed AI-built apps, and a backdoor hiding inside AI coding rules themselves.

Uncloaked: A Misconfigured Cloud Server, a SharePoint Zero-Day, and 29 Million Leaked Secrets
News29 July 2026

Uncloaked: A Misconfigured Cloud Server, a SharePoint Zero-Day, and 29 Million Leaked Secrets

Four stories from the last few weeks: a Nextcloud misconfiguration that exposed 367,000 files, a Salesforce webpage misconfiguration behind a 13.5-million-record breach, an actively exploited SharePoint zero-day, and the year's secrets sprawl numbers.

Uncloaked: The Software Supply Chain Had a Brutal Few Months (And It's Not Over)
News16 July 2026

Uncloaked: The Software Supply Chain Had a Brutal Few Months (And It's Not Over)

Four npm supply chain compromises in four months, including a 100-million-download HTTP client, plus a subdomain takeover disclosed against Anthropic itself. What each incident shares, and what it means for a site you didn't think was affected.

Uncloaked: WordPress Takeovers, Supabase Leaks, and a Skimmer Hiding in Plain Sight
News9 July 2026

Uncloaked: WordPress Takeovers, Supabase Leaks, and a Skimmer Hiding in Plain Sight

Five real security stories from the last few months, all touching attack surfaces Decloak scans for: a plugin flaw hitting 500,000 WordPress sites, a Supabase misconfiguration that exposed 1.5 million API keys, and a card skimmer hiding inside Google Tag Manager.