We built decloak.dev as the web intelligence service for the modern era. Start for free with features for vibe coders all the way through to Enterprise!

London
1/ A company that sells identity theft protection got breached by a phone call. A thread on three recent stories.
1
44
28
181
1/ A green padlock tells a visitor almost nothing about whether the connection behind it is actually well configured. Four separate things can each quietly go wrong while it stays green.
1
49
32
211
1/ Every report now includes a literal OWASP Top 10:2025 checklist. Ten rows, always present. Confirmed, Clean, or Not Tested.
1
59
40
253
1/ Most scanners stop at the login page. Decloak's authenticated scan mode doesn't, and for passkeys specifically, the usual workaround (script the login) doesn't even apply.
1
58
38
236
Decloak now reports on what findings map to the OWASP Top 10 categories. This brings our security intelligence platform feature count to 66! And we keep going! Onto the next build...
1
53
41
215
1/ PCI DSS v4.0 added a requirement that every script on a payment page has to be inventoried and justified. Another requires detecting unauthorized changes to those scripts. Both exist because of Magecart-style card skimming.
1
47
35
155
1/ Your PDF report used to be a webpage forced into PDF form. Raw markdown leaking through. Text cut off at page edges. No table of contents, no page numbers. For a report customers hand to auditors, that wasn't good enough.
1
46
37
186
1/ MCP has quietly become the standard way AI agents connect to real tools. 97M+ monthly SDK downloads, adopted by every major AI lab. Decloak now ships an MCP server.
2
47
37
195
We've completely redesigned our PDF cybersecurity reports to be more professional and ready to send to a colleague or auditor. Previous PDF reports were more like PDF versions of the web report. The new ones are in a whole different ballgame! This applies to our free reports, agentic reports, and our active testing (DAST) and AI pentesting.
1
37
33
176
1/ We rebuilt the scan report from the ground up. Not a redesign pass, a rethink of how a report should actually work. And it's not just paid customers who benefit.
1
37
31
195
1/ "One fixed behavior for every scan" works for most people. It's exactly wrong for the professionals who know precisely what they want tuned. Expert Mode is for them.
3
33
29
178
1/ A security professional evaluating us said their 76-page scan came back as "1,706 findings, 103 groups" and asked why the header issue true of the whole site wasn't just one line. That wasn't a feature request. It was a correctness bar.
2
51
42
271
1/ An API security testing company got breached by an unprotected database. Three stories this time, all API-shaped.
1
42
39
286
We've just launched "Expert Mode" on Decloak, so cybersecurity and pentesting professionals have full control over how our agentic security scans work!
5
51
52
97,910
1/ Everything else we do is signal detection. It observes and flags things that look wrong. AI Pentesting is different: it actually attempts exploitation, in a sandbox, and only calls something confirmed once a real tool has proven it.
1
45
40
233
1/ Your dashboard used to be a list. Domains, scans, a grade next to each. Useful, but it made you go hunting for the actual picture.
1
46
40
213
1/ An auditor doesn't want a login to your dashboard. They want something they can file, reference, and hand to their own reviewers without your tool needing to still exist in six months.
1
34
30
142
1/ Four DNS records decide whether someone can send email that looks like it came from you, or get a fraudulent SSL cert issued in your name.
1
24
23
108
1/ A misconfiguration-detection tool got weaponized into the exact attack it was built to prevent. One of three real stories from the last couple of weeks. A thread.
1
17
16
89
1/ Most of what a modern app actually does happens through an API. Most API vulnerabilities never show up in a page-level scan.
1
4
12
90
1/ Scanning a bare IP now checks for exposed databases and open ports too. Redis, MongoDB, an unauthenticated Docker API, these show up unauthenticated in the wild far more often than they should.
1
2
5
61
1/ A wordlist can only ever find the subdomains someone thought to guess. It was never going to find internal-billing-v2.example.….
1
1
2
37
1/ A subdomain pointing at a service you stopped using isn't just clutter. It's claimable.
1
2
3
33
1/ A single-page scan checks one URL. Most real sites aren't one page. The full-site AI agent decides for itself which pages on your domain are actually worth investigating, and runs the full 8-layer check on each one.
1
2
2
38
1/ 380,000 publicly accessible apps built with AI coding tools. Not hacked. Just left with default settings nobody thought to check. A thread on five stories from the last few months.
1
2
3
42
1/ Scared to add a Content-Security-Policy because it might break something? That's the right instinct, actually. The wrong move is skipping it entirely. The right move is report-only mode first, so you see exactly what it would break before it does.
1
2
2
25
1/ The Supabase mistake that's worse than a missing RLS policy: the service_role key sitting in your client-side JavaScript. That key bypasses Row Level Security entirely, by design. If it's in a bundle your browser downloads, your carefully written policies don't matter anymore.
1
1
20
1/ 1,000 findings. 7 things to fix first. A full scan surfacing hundreds of findings is great for coverage. It's a terrible Monday-morning to-do list.
1
15
1/ There's a chat widget on every page now. What it actually does depends entirely on your plan, and that gap is worth explaining properly.
1
12
1/ Four npm supply chain compromises in four months. None of them typosquats. The real, trusted packages, compromised at the source. A thread.
1
20
1/ staging.yourcompany.com from a redesign two years ago is probably still online right now. Still resolving. Still running whatever was live the day everyone stopped thinking about it. And finding it doesn't require guessing, Certificate Transparency logs make every subdomain you've ever had a certificate for permanently searchable.
1
8
1/ Your production site might be shipping its own uncompiled source code right now, comments included. Not through a vulnerability. Through a debugging feature (source maps) that most build tools leave on by default and nobody remembers to turn off before deploying.
1
10
1/ NIS2's compliance deadline lands this October. It now covers roughly 160,000 EU entities, up from about 10,000 under the old NIS directive. If your org wasn't in scope before, there's a real chance it is now.
1
11
1/ Five real security stories from the last few months. All of them attack surfaces we scan for. A thread.
1
16
1/ You could always run a security scan on a client's site. Handing them the PDF with our logo on it was the part that never quite worked. Not anymore.
1
6
1/ One HTTP header stops most XSS attacks from being exploitable even after the vulnerability exists. Almost nobody sets it. Not because it's expensive. Not because it's hard. Because a badly configured one can silently break your site, and there's rarely an obvious error beyond a console warning nobody checks.
1
7
1/ Row Level Security is off by default on every new Supabase project. That single setting is behind the most common security failure we see in apps built with AI tools. Anyone with your public anon key can read every row in every table, no exploit required. Is your app affected? Genuinely worth checking today.
1
13
Just shipped your project? Run one quick security check before sharing it with the world. Free. No signup. 👉 decloak.dev #IndieHackers #Startup #BuildInPublic #Coding #DevTools
14
Developers spend hours fixing bugs—but many never run a security scan until it's too late. Take 15 seconds to check your website before attackers do. 🔗 decloak.dev #WebSecurity #Developers #AI #SaaS #BuildInPublic
1
2
24