We built decloak.dev as the web intelligence service for the modern era. Start for free with features for vibe coders all the way through to Enterprise!

London
Filter
Exclude
Time range
-
Minimum likes
decloak.dev retweeted
Decloak by @decloakdev Exposed API keys. Misconfigured DBs. Vulnerable libraries. Catch them all🔥 AI agent runs full site investigation + penetration testing. Available - decloak.dev/?ref=microlaunch Paste your URL + your scored security report (15 secs)
3
1
6
200
Replying to @intelphere
This is unfortunately something that can only be improved with employee training. The human link might always be the weakest!
1
1
9
3/ Trezor's vendor breach kept getting worse. First, 67K more customers exposed because the vendor kept data it was required to delete. Then attackers used the breach itself to send fake "security alert" phishing emails to 347K addresses, weaponizing the trust a real breach notification depends on.
1
2
5
2/ Aura, ~900K records exposed. Not a technical exploit, an employee convinced to hand over access via a targeted voice phishing call. ShinyHunters claimed it. Every layer of technical scanning doesn't close a gap that opens on the phone.
2
28
23
141
1/ A company that sells identity theft protection got breached by a phone call. A thread on three recent stories.
1
41
28
172
We've just launched Decloak on @peerpush_com! Click the link below and help us reach more people! We're on a mission ot help everyone get better at improving their web security! Whether you're a vibe coder or a professional pentester! 🚀 peerpush.com/p/decloak
38
27
145
2/ Expiry's the one everyone knows. Chain validation is invisible until it breaks for the wrong client. Protocol version, still accepting TLS 1.0/1.1? And cipher strength, the one almost nobody checks manually, because there's no browser warning for it.
1
35
26
134
1/ A green padlock tells a visitor almost nothing about whether the connection behind it is actually well configured. Four separate things can each quietly go wrong while it stays green.
1
47
32
206
Replying to @DamienWayne
Decloak.dev we're already at 65+ security intelligence features. We're now expanding on our AI pentesting which was released a while ago!
2
20
Decloak has just launched on @MicroLaunchHQ! Thanks for your help @SaidAitmbarek We'd appreciate any upvotes to help with our listing😄 We've launched an exclusive promotion for 50% off for two months no ANY paid plan, which you can find on our page! microlaunch.net/p/decloakweb…
2
57
59
257,014
2/ Four categories are honestly marked Not Tested by default, each with the actual reason shown. Insecure Design needs architecture review we don't have access to. Logging failures need internal server config we can't see from outside.
1
46
31
179
1/ Every report now includes a literal OWASP Top 10:2025 checklist. Ten rows, always present. Confirmed, Clean, or Not Tested.
1
58
41
251
2/ WebAuthn is built so there's no credential to store or script. The login ceremony requires a physical gesture on the actual device. Nothing to paste into an automation script, by design.
1
44
29
150
1/ Most scanners stop at the login page. Decloak's authenticated scan mode doesn't, and for passkeys specifically, the usual workaround (script the login) doesn't even apply.
1
56
38
232
Decloak now reports on what findings map to the OWASP Top 10 categories. This brings our security intelligence platform feature count to 66! And we keep going! Onto the next build...
1
52
41
212
2/ That's exactly the blind spot most scanners miss, they check your servers, not the third-party JS your own site is loading. We've been fetching full GTM configs, flagging scripts firing to suspicious domains, and checking Subresource Integrity since before this requirement existed.
1
28
25
109
1/ PCI DSS v4.0 added a requirement that every script on a payment page has to be inventoried and justified. Another requires detecting unauthorized changes to those scripts. Both exist because of Magecart-style card skimming.
1
46
35
153
2/ We rebuilt it as a real, print-safe document system, one shared shell of reusable pieces (cover page, TOC, finding cards, charts) instead of five separate reskins. Built and proven on the free tier first, then ported to the more complex paid reports.
1
23
25
106
1/ Your PDF report used to be a webpage forced into PDF form. Raw markdown leaking through. Text cut off at page edges. No table of contents, no page numbers. For a report customers hand to auditors, that wasn't good enough.
1
46
36
185