<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Quiet Failures</title>
    <link>https://quietfailures.com/quiet-failures/</link>
    <description>Security for people who never signed up to do security. A free weekly newsletter: one real, fixable exposure at a company like yours, closed in ten minutes.</description>
    <language>en-gb</language>
    <atom:link href="https://quietfailures.com/rss.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>The Remote Desktop you opened &quot;just for now&quot; is still open</title>
      <link>https://quietfailures.com/quiet-failures/exposed-rdp</link>
      <guid isPermaLink="true">https://quietfailures.com/quiet-failures/exposed-rdp</guid>
      <pubDate>Sat, 15 Aug 2026 00:00:00 GMT</pubDate>
      <description>A Remote Desktop port forwarded &apos;just for now&apos; may still expose your Windows PC to the internet, where scanners brute-force it within minutes. How to check yours.</description>
    </item>
    <item>
      <title>Someone else is spending your AI budget on a leaked key</title>
      <link>https://quietfailures.com/quiet-failures/exposed-llm-api-key</link>
      <guid isPermaLink="true">https://quietfailures.com/quiet-failures/exposed-llm-api-key</guid>
      <pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate>
      <description>A leaked OpenAI or cloud API key can quietly run up your bill for years — bots scan for exactly these. How to check your usage and rotate keys in ten minutes.</description>
    </item>
    <item>
      <title>The NAS in the cupboard is answering the whole internet</title>
      <link>https://quietfailures.com/quiet-failures/exposed-nas-internet</link>
      <guid isPermaLink="true">https://quietfailures.com/quiet-failures/exposed-nas-internet</guid>
      <pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate>
      <description>The Synology or QNAP box your team dumps files onto may answer the open internet on its default admin login — exactly what ransomware crews scan for. Check yours.</description>
    </item>
    <item>
      <title>Your second factor is a text message, and that&apos;s the weak link now</title>
      <link>https://quietfailures.com/quiet-failures/sms-mfa-weak</link>
      <guid isPermaLink="true">https://quietfailures.com/quiet-failures/sms-mfa-weak</guid>
      <pubDate>Wed, 12 Aug 2026 00:00:00 GMT</pubDate>
      <description>If your two-factor codes arrive by text, a SIM swap or phishing proxy can relay them in real time. Why SMS is now the weak link in MFA, and what to switch to.</description>
    </item>
    <item>
      <title>Your internal mailing list is readable by the whole internet</title>
      <link>https://quietfailures.com/quiet-failures/google-group-public-visibility</link>
      <guid isPermaLink="true">https://quietfailures.com/quiet-failures/google-group-public-visibility</guid>
      <pubDate>Mon, 10 Aug 2026 00:00:00 GMT</pubDate>
      <description>A Google Group set to public years ago still publishes its message archive to anyone who searches. How to check who can view your groups and close them in ten minutes.</description>
    </item>
    <item>
      <title>Your email is signed with a key attackers can forge</title>
      <link>https://quietfailures.com/quiet-failures/dkim-weak-key</link>
      <guid isPermaLink="true">https://quietfailures.com/quiet-failures/dkim-weak-key</guid>
      <pubDate>Sun, 09 Aug 2026 00:00:00 GMT</pubDate>
      <description>That DKIM key you set up years ago is still 1024-bit — below the 2048-bit floor mailbox providers now expect. How to look up your key length and rotate it in ten minutes.</description>
    </item>
    <item>
      <title>Your cloud storage bucket is answering to strangers</title>
      <link>https://quietfailures.com/quiet-failures/public-cloud-bucket</link>
      <guid isPermaLink="true">https://quietfailures.com/quiet-failures/public-cloud-bucket</guid>
      <pubDate>Sun, 09 Aug 2026 00:00:00 GMT</pubDate>
      <description>A storage bucket set to public years ago to unblock a job is still open — and attackers find them through search indexes. How to check your buckets and lock them down.</description>
    </item>
    <item>
      <title>You have six people with the keys to everything</title>
      <link>https://quietfailures.com/quiet-failures/global-admin-sprawl</link>
      <guid isPermaLink="true">https://quietfailures.com/quiet-failures/global-admin-sprawl</guid>
      <pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate>
      <description>Global Administrator got handed out to whoever needed to change one setting. Now several everyday accounts can rewrite your whole Microsoft 365 tenant. How to count them.</description>
    </item>
    <item>
      <title>You deleted the leaked key&apos;s repo. The key still works.</title>
      <link>https://quietfailures.com/quiet-failures/exposed-git-secrets</link>
      <guid isPermaLink="true">https://quietfailures.com/quiet-failures/exposed-git-secrets</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
      <description>Deleting a file or repo that held a secret doesn&apos;t rotate the credential — and most keys leaked years ago still work. How to find and actually revoke yours in ten minutes.</description>
    </item>
    <item>
      <title>The AI tool a colleague connected months ago just became your breach</title>
      <link>https://quietfailures.com/quiet-failures/oauth-stale-grant</link>
      <guid isPermaLink="true">https://quietfailures.com/quiet-failures/oauth-stale-grant</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
      <description>A third-party AI tool still holds an OAuth token to your mail and files. When its vendor is breached, the attacker logs in as you — no password, no MFA. How to check.</description>
    </item>
    <item>
      <title>The Drive files still shared with clients who left years ago</title>
      <link>https://quietfailures.com/quiet-failures/external-share-accumulation</link>
      <guid isPermaLink="true">https://quietfailures.com/quiet-failures/external-share-accumulation</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate>
      <description>Tightening your sharing policy only governs new shares. Folders you opened to a former client or a personal Gmail years ago stay open. How to find them in ten minutes.</description>
    </item>
    <item>
      <title>Your password policy still demands a capital, a number and a symbol</title>
      <link>https://quietfailures.com/quiet-failures/password-complexity-myth</link>
      <guid isPermaLink="true">https://quietfailures.com/quiet-failures/password-complexity-myth</guid>
      <pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate>
      <description>The rule forcing an uppercase, a digit and a symbol doesn&apos;t make passwords stronger — it just breeds Password1! everywhere. NIST dropped it. What to do instead.</description>
    </item>
    <item>
      <title>The AI tool your team wired up is answering to the whole internet</title>
      <link>https://quietfailures.com/quiet-failures/exposed-mcp-server</link>
      <guid isPermaLink="true">https://quietfailures.com/quiet-failures/exposed-mcp-server</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <description>Someone stood up an MCP server so an AI assistant could reach your tools, and it went online with no login. How to check whether your AI endpoint is exposed.</description>
    </item>
    <item>
      <title>The subdomain still pointing at a service you cancelled</title>
      <link>https://quietfailures.com/quiet-failures/dangling-cname-cancelled-service</link>
      <guid isPermaLink="true">https://quietfailures.com/quiet-failures/dangling-cname-cancelled-service</guid>
      <pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate>
      <description>You stopped paying for a cloud service but left the CNAME behind, so a stranger can re-register it and serve their content on your domain. How to find dangling records.</description>
    </item>
    <item>
      <title>Your website is quietly serving its own source code at /.git</title>
      <link>https://quietfailures.com/quiet-failures/exposed-git-directory</link>
      <guid isPermaLink="true">https://quietfailures.com/quiet-failures/exposed-git-directory</guid>
      <pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate>
      <description>A deployed site often ships its hidden .git folder too, letting anyone rebuild your code and lift live credentials. How to check yoursite.com/.git in a minute.</description>
    </item>
    <item>
      <title>MFA passed, and the attacker still walked in through one consent screen</title>
      <link>https://quietfailures.com/quiet-failures/oauth-consent-phishing</link>
      <guid isPermaLink="true">https://quietfailures.com/quiet-failures/oauth-consent-phishing</guid>
      <pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate>
      <description>A phishing kit can pass your user through a real Microsoft login and MFA, then keep a token to their mail and files. How to shut off device-code and app consent.</description>
    </item>
    <item>
      <title>The vulnerability list you&apos;ll never reach the bottom of</title>
      <link>https://quietfailures.com/quiet-failures/vulnerability-management-obsolete</link>
      <guid isPermaLink="true">https://quietfailures.com/quiet-failures/vulnerability-management-obsolete</guid>
      <pubDate>Sun, 19 Jul 2026 00:00:00 GMT</pubDate>
      <description>Manually chasing every CVE feels like security, but the backlog only grows and the real exposures hide inside it. How to check whether your process still works.</description>
    </item>
    <item>
      <title>The security headers a library update quietly switched off</title>
      <link>https://quietfailures.com/quiet-failures/missing-security-headers</link>
      <guid isPermaLink="true">https://quietfailures.com/quiet-failures/missing-security-headers</guid>
      <pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate>
      <description>A routine dependency bump can silently stop your site sending its clickjacking and content-type protections. How to check your security headers in one minute.</description>
    </item>
    <item>
      <title>The leaver who can still log in</title>
      <link>https://quietfailures.com/quiet-failures/stale-offboarded-accounts</link>
      <guid isPermaLink="true">https://quietfailures.com/quiet-failures/stale-offboarded-accounts</guid>
      <pubDate>Sun, 05 Jul 2026 00:00:00 GMT</pubDate>
      <description>Offboarding took back the laptop but never disabled the login, so a former colleague&apos;s account is still live. How to find dormant accounts in ten minutes.</description>
    </item>
    <item>
      <title>The &apos;npm install&apos; that ran a stranger&apos;s code on your machine</title>
      <link>https://quietfailures.com/quiet-failures/npm-install-scripts</link>
      <guid isPermaLink="true">https://quietfailures.com/quiet-failures/npm-install-scripts</guid>
      <pubDate>Sun, 28 Jun 2026 00:00:00 GMT</pubDate>
      <description>A single npm install can run someone else&apos;s script the moment you type it — no import, no run. How to turn off install scripts and check you&apos;re covered.</description>
    </item>
    <item>
      <title>The certificate nobody&apos;s job it is to renew</title>
      <link>https://quietfailures.com/quiet-failures/cert-expiry-automation</link>
      <guid isPermaLink="true">https://quietfailures.com/quiet-failures/cert-expiry-automation</guid>
      <pubDate>Sun, 21 Jun 2026 00:00:00 GMT</pubDate>
      <description>Your TLS certificate renews because someone remembers to do it — and lifetimes are shrinking fast. How to find your expiry date and automate renewal in ten minutes.</description>
    </item>
    <item>
      <title>MFA is on, but the old protocols that ignore it never got turned off</title>
      <link>https://quietfailures.com/quiet-failures/legacy-auth-enabled</link>
      <guid isPermaLink="true">https://quietfailures.com/quiet-failures/legacy-auth-enabled</guid>
      <pubDate>Sun, 14 Jun 2026 00:00:00 GMT</pubDate>
      <description>You require MFA — but legacy sign-in protocols can&apos;t enforce it, so a password-spray walks straight past. How to find and block legacy authentication.</description>
    </item>
    <item>
      <title>Your AI assistant can read every file your permissions forgot about</title>
      <link>https://quietfailures.com/quiet-failures/ai-copilot-oversharing</link>
      <guid isPermaLink="true">https://quietfailures.com/quiet-failures/ai-copilot-oversharing</guid>
      <pubDate>Sun, 07 Jun 2026 00:00:00 GMT</pubDate>
      <description>Copilot and Gemini don&apos;t leak new data — they surface years of stale &apos;anyone&apos; links and over-broad access to whoever asks. How to find oversharing.</description>
    </item>
    <item>
      <title>The package your AI assistant invented, and someone registered</title>
      <link>https://quietfailures.com/quiet-failures/slopsquatting-ghost-package</link>
      <guid isPermaLink="true">https://quietfailures.com/quiet-failures/slopsquatting-ghost-package</guid>
      <pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate>
      <description>AI coding tools confidently suggest install commands for packages that don&apos;t exist — and attackers register those names. How to check a dependency is real before you install.</description>
    </item>
    <item>
      <title>Your backup works. Your restore is the part you never tested.</title>
      <link>https://quietfailures.com/quiet-failures/untested-restore</link>
      <guid isPermaLink="true">https://quietfailures.com/quiet-failures/untested-restore</guid>
      <pubDate>Sun, 24 May 2026 00:00:00 GMT</pubDate>
      <description>Having backups isn&apos;t the same as being able to restore. If they share your login and network, ransomware takes them too. How to test a real restore in ten minutes.</description>
    </item>
    <item>
      <title>The share link set to &apos;anyone with the link&apos;</title>
      <link>https://quietfailures.com/quiet-failures/public-share-exposure</link>
      <guid isPermaLink="true">https://quietfailures.com/quiet-failures/public-share-exposure</guid>
      <pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate>
      <description>A folder shared as &apos;anyone with the link&apos; to unblock a client can stay public and indexable for years. How to audit your Drive, Dropbox and buckets in ten minutes.</description>
    </item>
    <item>
      <title>The AI browser add-on that can read your inbox</title>
      <link>https://quietfailures.com/quiet-failures/ai-agent-inbox-access</link>
      <guid isPermaLink="true">https://quietfailures.com/quiet-failures/ai-agent-inbox-access</guid>
      <pubDate>Sun, 10 May 2026 00:00:00 GMT</pubDate>
      <description>A team member gave an AI browser assistant access to mail and docs — and a hidden instruction on a web page can redirect it. How to audit extension access in ten minutes.</description>
    </item>
    <item>
      <title>Your internal dashboard is on the public internet</title>
      <link>https://quietfailures.com/quiet-failures/exposed-admin-panel</link>
      <guid isPermaLink="true">https://quietfailures.com/quiet-failures/exposed-admin-panel</guid>
      <pubDate>Sun, 03 May 2026 00:00:00 GMT</pubDate>
      <description>The Grafana or Jenkins box you stood up for the team may be reachable from the open internet on admin/admin. How to check your own exposure in ten minutes.</description>
    </item>
    <item>
      <title>Your info@ mailbox is a login nobody protected</title>
      <link>https://quietfailures.com/quiet-failures/shared-mailbox-login</link>
      <guid isPermaLink="true">https://quietfailures.com/quiet-failures/shared-mailbox-login</guid>
      <pubDate>Sun, 26 Apr 2026 00:00:00 GMT</pubDate>
      <description>Shared mailboxes like info@ and sales@ often keep an enabled account with a password and no MFA — a side door into your tenant. How to close it in ten minutes.</description>
    </item>
    <item>
      <title>The .env file that quietly rode into a public repo</title>
      <link>https://quietfailures.com/quiet-failures/env-file-in-public-repo</link>
      <guid isPermaLink="true">https://quietfailures.com/quiet-failures/env-file-in-public-repo</guid>
      <pubDate>Sun, 19 Apr 2026 00:00:00 GMT</pubDate>
      <description>One &apos;git add .&apos; can commit your .env with live API keys, and bots harvest them within minutes. How to check your repos and rotate what leaked in ten minutes.</description>
    </item>
    <item>
      <title>You&apos;re still forcing password changes every 90 days</title>
      <link>https://quietfailures.com/quiet-failures/password-rotation-myth</link>
      <guid isPermaLink="true">https://quietfailures.com/quiet-failures/password-rotation-myth</guid>
      <pubDate>Sun, 12 Apr 2026 00:00:00 GMT</pubDate>
      <description>Forcing a password change every 90 days trains people into weaker passwords, not stronger ones — and NIST retired the advice. What to do instead, and how to switch it off.</description>
    </item>
    <item>
      <title>The inbox rule an attacker left behind</title>
      <link>https://quietfailures.com/quiet-failures/malicious-inbox-rules</link>
      <guid isPermaLink="true">https://quietfailures.com/quiet-failures/malicious-inbox-rules</guid>
      <pubDate>Sun, 05 Apr 2026 00:00:00 GMT</pubDate>
      <description>After a phishing compromise, a hidden mail rule can keep deleting or forwarding your mail — and a password reset never touches it. How to find and clear it in ten minutes.</description>
    </item>
    <item>
      <title>Your DMARC record is set — and doing nothing</title>
      <link>https://quietfailures.com/quiet-failures/dmarc-record-doing-nothing</link>
      <guid isPermaLink="true">https://quietfailures.com/quiet-failures/dmarc-record-doing-nothing</guid>
      <pubDate>Sun, 29 Mar 2026 00:00:00 GMT</pubDate>
      <description>A p=none DMARC record enforces nothing — spoofed mail sails through and failing mail still lands. How to read your policy and turn it on in ten minutes.</description>
    </item>
    <item>
      <title>The subdomain you forgot points at a service anyone can claim</title>
      <link>https://quietfailures.com/quiet-failures/dangling-subdomain-takeover</link>
      <guid isPermaLink="true">https://quietfailures.com/quiet-failures/dangling-subdomain-takeover</guid>
      <pubDate>Sun, 22 Mar 2026 00:00:00 GMT</pubDate>
      <description>An old CNAME pointing at a cloud service you stopped paying for lets a stranger serve their content on your domain. How to find dangling DNS records in ten minutes.</description>
    </item>
    <item>
      <title>Your SPF record is silently failing</title>
      <link>https://quietfailures.com/quiet-failures/spf-record-silently-failing</link>
      <guid isPermaLink="true">https://quietfailures.com/quiet-failures/spf-record-silently-failing</guid>
      <pubDate>Sun, 15 Mar 2026 00:00:00 GMT</pubDate>
      <description>SPF is allowed only ten DNS lookups before it quietly breaks — and a growing company crosses that line with no error message. How to check yours in ten minutes and fix it.</description>
    </item>
    <item>
      <title>The OAuth grant nobody revoked</title>
      <link>https://quietfailures.com/quiet-failures/oauth-grant-nobody-revoked</link>
      <guid isPermaLink="true">https://quietfailures.com/quiet-failures/oauth-grant-nobody-revoked</guid>
      <pubDate>Sun, 08 Mar 2026 00:00:00 GMT</pubDate>
      <description>The third-party apps your team connected years ago still have live access to your email and files — and it bypasses MFA. How to find and revoke OAuth grants.</description>
    </item>
  </channel>
</rss>