News, Trends, and Insights for IT & Managed Services Providers
News, Trends, and Insights for IT & Managed Services Providers

Updating on the SharePoint security issue I reported on yesterday.   Microsoft has released patches for two vulnerable editions of its SharePoint Server collaboration tool, following the discovery of a critical flaw known as “ToolShell.” Administrators are urged to apply these updates immediately, as threat actors are actively exploiting this vulnerability to carry out remote code execution attacks. The patches address two specific vulnerabilities, CVE-2025-53370 and CVE-2025-53771, which involve deserialization and spoofing.

The Washington Post is reporting that according to Charles Carmakal, chief technology officer of Google’s Mandiant Consulting, early assessments indicate that at least one actor responsible for these attacks is a China-nexus threat actor.

Why do we care?

Not every provider needs to panic. Many SMB clients have already migrated to SharePoint Online or Microsoft 365, which aren’t affected by these specific vulnerabilities. For providers focusing on modern cloud stacks, this serves more as a reinforcement of why leaving legacy on-prem infrastructure behind reduces risk.

But if they haven’t, don’t just fire off a patching alert—start the bigger conversation about lifecycle management. If your clients won’t touch those servers, you need to plan for it—because attackers already are.

Choose your upgrade:

Get the full benefits of Business of Tech Plus

Insider Access

$12/month

Perfect for MSPs and ITSPs that want full interviews, early access, and ad-free listening

  • Programmatic Ad-free private podcast feedSame show, little interruptions
  • Channel Chatter previews1–2 topics with light insights
  • Early access to interview episodesHear it days before public release
  • Monthly Insider BriefTighter analysis you can share internally
  • Extra audio segmentsCut interviews, behind-the-scenes commentary, quick competitive notes
  • Become an Insider for $12/month

    Leadership Access

    $149/month

    Perfect for MSPs and Vendors that run a team and need the extended tactics, executive summaries, and weekly alignment brief

  • All Insider Access benefits plus . . .
  • Invite your teamIncludes access for 5 team members with option to add more
  • Vendor Strategy BriefsThe entire library, plus new analysis every month
  • Channel ChatterAll topics, full insights, complete vendor discussion + sentiment list
  • Quarterly State of the Channel Briefing
  • Monthly AMA submission priorityAsk Dave direct questions, and skip the line
  • Get the Leadership Edge for $149/month

    Vendor Partner

    $500/month

    Perfect for channel companies or vendors looking to deepen their engagement with the show.

  • All Leadership Access benefits plus . . .
  • Get highlighted as a show sponsor You'll get placement in the show notes, throughout the website, and on our dedicated sponsors page.
  • Enjoy regular shout outs You'll be featured in a rotating format during the show
  • Become a show sponsor for $500/month

    Search all stories