The Decloak Journal
Stories from around the web security world, plus release notes and changes to Decloak itself.

Three recent stories, all API-shaped: a ServiceNow access-control gap that let unauthenticated queries pull customer instance data, a compromised third-party app that gave attackers a path into Salesforce customer connections, and an API security testing firm exposed by exactly the kind of unprotected database it tests for.

Your account now opens to an actual command center instead of a list of scans, aggregate posture across every domain you monitor, plus a dedicated scoreboard for each one. Live for every account, free included.

Three recent stories, all misconfiguration rather than a hack: a data-extortion group hitting Microsoft Power Pages across roughly 15 organisations, a Salesforce campaign that turned a misconfiguration-detection tool into an attack tool, and a hardware wallet company breached through its shipping provider.

Five recent stories, all about the same underlying pattern: apps built by describing them in plain English, shipped fast, and left with security defaults nobody thought to check. A Base44 auth bypass, 380,000 publicly indexed AI-built apps, and a backdoor hiding inside AI coding rules themselves.

Four stories from the last few weeks: a Nextcloud misconfiguration that exposed 367,000 files, a Salesforce webpage misconfiguration behind a 13.5-million-record breach, an actively exploited SharePoint zero-day, and the year's secrets sprawl numbers.

Four npm supply chain compromises in four months, including a 100-million-download HTTP client, plus a subdomain takeover disclosed against Anthropic itself. What each incident shares, and what it means for a site you didn't think was affected.

Five real security stories from the last few months, all touching attack surfaces Decloak scans for: a plugin flaw hitting 500,000 WordPress sites, a Supabase misconfiguration that exposed 1.5 million API keys, and a card skimmer hiding inside Google Tag Manager.