One real, fixable thing quietly broken or exposed at a company like yours — taken apart the same way every time. Read any issue; subscribe to get the next one.
A Remote Desktop port forwarded 'just for now' may still expose your Windows PC to the internet, where scanners brute-force it within minutes. How to check yours.
Read the issue →A leaked OpenAI or cloud API key can quietly run up your bill for years — bots scan for exactly these. How to check your usage and rotate keys in ten minutes.
Read the issue →The Synology or QNAP box your team dumps files onto may answer the open internet on its default admin login — exactly what ransomware crews scan for. Check yours.
Read the issue →If your two-factor codes arrive by text, a SIM swap or phishing proxy can relay them in real time. Why SMS is now the weak link in MFA, and what to switch to.
Read the issue →A Google Group set to public years ago still publishes its message archive to anyone who searches. How to check who can view your groups and close them in ten minutes.
Read the issue →A storage bucket set to public years ago to unblock a job is still open — and attackers find them through search indexes. How to check your buckets and lock them down.
Read the issue →That DKIM key you set up years ago is still 1024-bit — below the 2048-bit floor mailbox providers now expect. How to look up your key length and rotate it in ten minutes.
Read the issue →Global Administrator got handed out to whoever needed to change one setting. Now several everyday accounts can rewrite your whole Microsoft 365 tenant. How to count them.
Read the issue →Deleting a file or repo that held a secret doesn't rotate the credential — and most keys leaked years ago still work. How to find and actually revoke yours in ten minutes.
Read the issue →A third-party AI tool still holds an OAuth token to your mail and files. When its vendor is breached, the attacker logs in as you — no password, no MFA. How to check.
Read the issue →Tightening your sharing policy only governs new shares. Folders you opened to a former client or a personal Gmail years ago stay open. How to find them in ten minutes.
Read the issue →The rule forcing an uppercase, a digit and a symbol doesn't make passwords stronger — it just breeds Password1! everywhere. NIST dropped it. What to do instead.
Read the issue →Someone stood up an MCP server so an AI assistant could reach your tools, and it went online with no login. How to check whether your AI endpoint is exposed.
Read the issue →You stopped paying for a cloud service but left the CNAME behind, so a stranger can re-register it and serve their content on your domain. How to find dangling records.
Read the issue →A deployed site often ships its hidden .git folder too, letting anyone rebuild your code and lift live credentials. How to check yoursite.com/.git in a minute.
Read the issue →A phishing kit can pass your user through a real Microsoft login and MFA, then keep a token to their mail and files. How to shut off device-code and app consent.
Read the issue →Manually chasing every CVE feels like security, but the backlog only grows and the real exposures hide inside it. How to check whether your process still works.
Read the issue →A routine dependency bump can silently stop your site sending its clickjacking and content-type protections. How to check your security headers in one minute.
Read the issue →Offboarding took back the laptop but never disabled the login, so a former colleague's account is still live. How to find dormant accounts in ten minutes.
Read the issue →A single npm install can run someone else's script the moment you type it — no import, no run. How to turn off install scripts and check you're covered.
Read the issue →Your TLS certificate renews because someone remembers to do it — and lifetimes are shrinking fast. How to find your expiry date and automate renewal in ten minutes.
Read the issue →You require MFA — but legacy sign-in protocols can't enforce it, so a password-spray walks straight past. How to find and block legacy authentication.
Read the issue →Copilot and Gemini don't leak new data — they surface years of stale 'anyone' links and over-broad access to whoever asks. How to find oversharing.
Read the issue →AI coding tools confidently suggest install commands for packages that don't exist — and attackers register those names. How to check a dependency is real before you install.
Read the issue →Having backups isn't the same as being able to restore. If they share your login and network, ransomware takes them too. How to test a real restore in ten minutes.
Read the issue →A folder shared as 'anyone with the link' to unblock a client can stay public and indexable for years. How to audit your Drive, Dropbox and buckets in ten minutes.
Read the issue →A team member gave an AI browser assistant access to mail and docs — and a hidden instruction on a web page can redirect it. How to audit extension access in ten minutes.
Read the issue →The Grafana or Jenkins box you stood up for the team may be reachable from the open internet on admin/admin. How to check your own exposure in ten minutes.
Read the issue →Shared mailboxes like info@ and sales@ often keep an enabled account with a password and no MFA — a side door into your tenant. How to close it in ten minutes.
Read the issue →One 'git add .' can commit your .env with live API keys, and bots harvest them within minutes. How to check your repos and rotate what leaked in ten minutes.
Read the issue →Forcing a password change every 90 days trains people into weaker passwords, not stronger ones — and NIST retired the advice. What to do instead, and how to switch it off.
Read the issue →After a phishing compromise, a hidden mail rule can keep deleting or forwarding your mail — and a password reset never touches it. How to find and clear it in ten minutes.
Read the issue →A p=none DMARC record enforces nothing — spoofed mail sails through and failing mail still lands. How to read your policy and turn it on in ten minutes.
Read the issue →An old CNAME pointing at a cloud service you stopped paying for lets a stranger serve their content on your domain. How to find dangling DNS records in ten minutes.
Read the issue →SPF is allowed only ten DNS lookups before it quietly breaks — and a growing company crosses that line with no error message. How to check yours in ten minutes and fix it.
Read the issue →The third-party apps your team connected years ago still have live access to your email and files — and it bypasses MFA. How to find and revoke OAuth grants.
Read the issue →One issue a week. No pitch, no roundup — just the next quiet failure, and how to fix it.
Free · one issue a week · no pitch · unsubscribe anytime