Quiet Failures

The archive.

One real, fixable thing quietly broken or exposed at a company like yours — taken apart the same way every time. Read any issue; subscribe to get the next one.

ISSUE 36 quiet-failures · 6 min read

The Remote Desktop you opened "just for now" is still open

A Remote Desktop port forwarded 'just for now' may still expose your Windows PC to the internet, where scanners brute-force it within minutes. How to check yours.

Read the issue →
ISSUE 35 quiet-failures · 6 min read

Someone else is spending your AI budget on a leaked key

A leaked OpenAI or cloud API key can quietly run up your bill for years — bots scan for exactly these. How to check your usage and rotate keys in ten minutes.

Read the issue →
ISSUE 34 quiet-failures · 6 min read

The NAS in the cupboard is answering the whole internet

The Synology or QNAP box your team dumps files onto may answer the open internet on its default admin login — exactly what ransomware crews scan for. Check yours.

Read the issue →
ISSUE 33 quiet-failures · 6 min read

Your second factor is a text message, and that's the weak link now

If your two-factor codes arrive by text, a SIM swap or phishing proxy can relay them in real time. Why SMS is now the weak link in MFA, and what to switch to.

Read the issue →
ISSUE 32 quiet-failures · 6 min read

Your internal mailing list is readable by the whole internet

A Google Group set to public years ago still publishes its message archive to anyone who searches. How to check who can view your groups and close them in ten minutes.

Read the issue →
ISSUE 31 quiet-failures · 6 min read

Your cloud storage bucket is answering to strangers

A storage bucket set to public years ago to unblock a job is still open — and attackers find them through search indexes. How to check your buckets and lock them down.

Read the issue →
ISSUE 30 quiet-failures · 6 min read

Your email is signed with a key attackers can forge

That DKIM key you set up years ago is still 1024-bit — below the 2048-bit floor mailbox providers now expect. How to look up your key length and rotate it in ten minutes.

Read the issue →
ISSUE 29 quiet-failures · 6 min read

You have six people with the keys to everything

Global Administrator got handed out to whoever needed to change one setting. Now several everyday accounts can rewrite your whole Microsoft 365 tenant. How to count them.

Read the issue →
ISSUE 28 quiet-failures · 7 min read

You deleted the leaked key's repo. The key still works.

Deleting a file or repo that held a secret doesn't rotate the credential — and most keys leaked years ago still work. How to find and actually revoke yours in ten minutes.

Read the issue →
ISSUE 27 quiet-failures · 6 min read

The AI tool a colleague connected months ago just became your breach

A third-party AI tool still holds an OAuth token to your mail and files. When its vendor is breached, the attacker logs in as you — no password, no MFA. How to check.

Read the issue →
ISSUE 26 quiet-failures · 6 min read

The Drive files still shared with clients who left years ago

Tightening your sharing policy only governs new shares. Folders you opened to a former client or a personal Gmail years ago stay open. How to find them in ten minutes.

Read the issue →
ISSUE 25 quiet-failures · 6 min read

Your password policy still demands a capital, a number and a symbol

The rule forcing an uppercase, a digit and a symbol doesn't make passwords stronger — it just breeds Password1! everywhere. NIST dropped it. What to do instead.

Read the issue →
ISSUE 24 quiet-failures · 7 min read

The AI tool your team wired up is answering to the whole internet

Someone stood up an MCP server so an AI assistant could reach your tools, and it went online with no login. How to check whether your AI endpoint is exposed.

Read the issue →
ISSUE 23 quiet-failures · 6 min read

The subdomain still pointing at a service you cancelled

You stopped paying for a cloud service but left the CNAME behind, so a stranger can re-register it and serve their content on your domain. How to find dangling records.

Read the issue →
ISSUE 22 quiet-failures · 6 min read

Your website is quietly serving its own source code at /.git

A deployed site often ships its hidden .git folder too, letting anyone rebuild your code and lift live credentials. How to check yoursite.com/.git in a minute.

Read the issue →
ISSUE 21 quiet-failures · 7 min read

MFA passed, and the attacker still walked in through one consent screen

A phishing kit can pass your user through a real Microsoft login and MFA, then keep a token to their mail and files. How to shut off device-code and app consent.

Read the issue →
ISSUE 20 quiet-failures · 7 min read

The vulnerability list you'll never reach the bottom of

Manually chasing every CVE feels like security, but the backlog only grows and the real exposures hide inside it. How to check whether your process still works.

Read the issue →
ISSUE 19 quiet-failures · 6 min read

The security headers a library update quietly switched off

A routine dependency bump can silently stop your site sending its clickjacking and content-type protections. How to check your security headers in one minute.

Read the issue →
ISSUE 18 quiet-failures · 6 min read

The leaver who can still log in

Offboarding took back the laptop but never disabled the login, so a former colleague's account is still live. How to find dormant accounts in ten minutes.

Read the issue →
ISSUE 17 quiet-failures · 6 min read

The 'npm install' that ran a stranger's code on your machine

A single npm install can run someone else's script the moment you type it — no import, no run. How to turn off install scripts and check you're covered.

Read the issue →
ISSUE 16 quiet-failures · 6 min read

The certificate nobody's job it is to renew

Your TLS certificate renews because someone remembers to do it — and lifetimes are shrinking fast. How to find your expiry date and automate renewal in ten minutes.

Read the issue →
ISSUE 15 quiet-failures · 6 min read

MFA is on, but the old protocols that ignore it never got turned off

You require MFA — but legacy sign-in protocols can't enforce it, so a password-spray walks straight past. How to find and block legacy authentication.

Read the issue →
ISSUE 14 quiet-failures · 7 min read

Your AI assistant can read every file your permissions forgot about

Copilot and Gemini don't leak new data — they surface years of stale 'anyone' links and over-broad access to whoever asks. How to find oversharing.

Read the issue →
ISSUE 13 quiet-failures · 6 min read

The package your AI assistant invented, and someone registered

AI coding tools confidently suggest install commands for packages that don't exist — and attackers register those names. How to check a dependency is real before you install.

Read the issue →
ISSUE 12 quiet-failures · 6 min read

Your backup works. Your restore is the part you never tested.

Having backups isn't the same as being able to restore. If they share your login and network, ransomware takes them too. How to test a real restore in ten minutes.

Read the issue →
ISSUE 11 quiet-failures · 6 min read

The share link set to 'anyone with the link'

A folder shared as 'anyone with the link' to unblock a client can stay public and indexable for years. How to audit your Drive, Dropbox and buckets in ten minutes.

Read the issue →
ISSUE 10 quiet-failures · 7 min read

The AI browser add-on that can read your inbox

A team member gave an AI browser assistant access to mail and docs — and a hidden instruction on a web page can redirect it. How to audit extension access in ten minutes.

Read the issue →
ISSUE 09 quiet-failures · 6 min read

Your internal dashboard is on the public internet

The Grafana or Jenkins box you stood up for the team may be reachable from the open internet on admin/admin. How to check your own exposure in ten minutes.

Read the issue →
ISSUE 08 quiet-failures · 5 min read

Your info@ mailbox is a login nobody protected

Shared mailboxes like info@ and sales@ often keep an enabled account with a password and no MFA — a side door into your tenant. How to close it in ten minutes.

Read the issue →
ISSUE 07 quiet-failures · 6 min read

The .env file that quietly rode into a public repo

One 'git add .' can commit your .env with live API keys, and bots harvest them within minutes. How to check your repos and rotate what leaked in ten minutes.

Read the issue →
ISSUE 06 quiet-failures · 6 min read

You're still forcing password changes every 90 days

Forcing a password change every 90 days trains people into weaker passwords, not stronger ones — and NIST retired the advice. What to do instead, and how to switch it off.

Read the issue →
ISSUE 05 quiet-failures · 6 min read

The inbox rule an attacker left behind

After a phishing compromise, a hidden mail rule can keep deleting or forwarding your mail — and a password reset never touches it. How to find and clear it in ten minutes.

Read the issue →
ISSUE 04 quiet-failures · 6 min read

Your DMARC record is set — and doing nothing

A p=none DMARC record enforces nothing — spoofed mail sails through and failing mail still lands. How to read your policy and turn it on in ten minutes.

Read the issue →
ISSUE 03 quiet-failures · 6 min read

The subdomain you forgot points at a service anyone can claim

An old CNAME pointing at a cloud service you stopped paying for lets a stranger serve their content on your domain. How to find dangling DNS records in ten minutes.

Read the issue →
ISSUE 02 quiet-failures · 5 min read

Your SPF record is silently failing

SPF is allowed only ten DNS lookups before it quietly breaks — and a growing company crosses that line with no error message. How to check yours in ten minutes and fix it.

Read the issue →
ISSUE 01 quiet-failures · 6 min read

The OAuth grant nobody revoked

The third-party apps your team connected years ago still have live access to your email and files — and it bypasses MFA. How to find and revoke OAuth grants.

Read the issue →
Don't miss the next one

Find the risk before it finds you.

One issue a week. No pitch, no roundup — just the next quiet failure, and how to fix it.

Check your inbox — confirm and you're in. Latest issue: The Remote Desktop you opened "just for now" is still open.

Free · one issue a week · no pitch · unsubscribe anytime