News, Trends, and Insights for IT & Managed Services Providers
News, Trends, and Insights for IT & Managed Services Providers
Google logo screengrab

Two sophisticated ransomware groups, Akira and Lynx, are increasingly targeting managed service providers and small businesses with advanced techniques that exploit stolen credentials and vulnerabilities. Together, these operations have compromised over 365 organizations, showcasing their effectiveness in accessing high-value infrastructure providers. The Akira group, which has targeted 220 victims including major firms like Hitachi Vantara, has shifted its tactics from traditional phishing to leveraging stolen administrative credentials. Meanwhile, Lynx has struck about 145 victims, focusing on private businesses and critical infrastructure, including a CBS affiliate in Chattanooga, Tennessee. Both groups employ double extortion tactics, combining file encryption with data theft to pressure their victims into paying ransoms.

While discussing ransomware, the U.S. Cybersecurity and Infrastructure Security Agency has announced the public release of Thorium, an open-source platform designed for malware and forensic analysis. Thorium can automate tasks and handle over 1,700 jobs per second while processing more than 10 million files per hour. This platform improves cybersecurity operations by integrating various tools and supports software analysis, digital forensics, and incident response, allowing analysts to efficiently address complex malware threats. It aims to empower a wider audience, including IT professionals without in-house malware analysis capabilities, to perform effective preliminary analyses and better manage risks. For installation instructions and access, users can visit CISA’s official GitHub repository.

Additionally, SonicWall is urging its customers to disable SSL Virtual Private Network after reports of ransomware attacks targeting its systems surfaced. This warning comes after Google’s announcement that its AI-powered bug hunter, Big Sleep, has identified 20 security vulnerabilities in popular open-source software, including FFmpeg and ImageMagick. Heather Adkins, Google’s vice president of security, mentioned that although these vulnerabilities have not yet been fixed, their discovery demonstrates AI’s potential in automating vulnerability detection. However, concerns remain about the reliability of AI-generated bug reports, with some developers experiencing false positives. 

And… A recently discovered prompt-injection vulnerability in Google’s Gemini AI chatbot presents serious security risks, enabling attackers to craft convincing phishing campaigns. Researchers have shown that by embedding malicious instructions within emails, attackers can manipulate the chatbot to generate fake security alerts, potentially deceiving users into revealing sensitive information. This flaw does not rely on links or attachments and exploits designed HTML and CSS within the email body. Although Google has previously tried to address similar vulnerabilities, researchers from the security firm 0din warn that this technique remains effective. The impact could go beyond Gemini, possibly affecting other Google Workspace products, as malicious actors might exploit this vulnerability to compromise multiple accounts through automated systems. Security experts advise strengthening defenses, including sanitizing HTML inputs and monitoring chatbot outputs for sensitive data.

Why do we care?

SPs, you’re now prime targets—again. Akira and Lynx, two ransomware gangs, have hit over 365 organizations, including MSPs and SMBs, using stolen admin credentials and skipping the phishing. This isn’t theoretical—it’s infrastructure-level compromise.

Add to that: CISA dropped Thorium, an open-source malware analysis engine that chews through 10 million files an hour. That’s a gift—if you use it. Most of you don’t have a malware lab, and now you don’t need one. No excuses.

But here’s the other side: SonicWall VPNs are under attack, and customers are being told to shut them off. You better be on top of that—or ready to answer hard questions.

And let’s not ignore Google. Their AI bot Gemini has a prompt-injection bug—attackers don’t need links or attachments, just clever HTML. That means your Google Workspace installs are now phishing vectors from the inside out.

The stacks we rely on—SonicWall, Google, even AI detection—are full of holes. The bad guys are evolving. Are you?

Choose your upgrade:

Get the full benefits of Business of Tech Plus

Insider Access

$12/month

Perfect for MSPs and ITSPs that want full interviews, early access, and ad-free listening

  • Programmatic Ad-free private podcast feedSame show, little interruptions
  • Channel Chatter previews1–2 topics with light insights
  • Early access to interview episodesHear it days before public release
  • Monthly Insider BriefTighter analysis you can share internally
  • Extra audio segmentsCut interviews, behind-the-scenes commentary, quick competitive notes
  • Become an Insider for $12/month

    Leadership Access

    $149/month

    Perfect for MSPs and Vendors that run a team and need the extended tactics, executive summaries, and weekly alignment brief

  • All Insider Access benefits plus . . .
  • Invite your teamIncludes access for 5 team members with option to add more
  • Vendor Strategy BriefsThe entire library, plus new analysis every month
  • Channel ChatterAll topics, full insights, complete vendor discussion + sentiment list
  • Quarterly State of the Channel Briefing
  • Monthly AMA submission priorityAsk Dave direct questions, and skip the line
  • Get the Leadership Edge for $149/month

    Vendor Partner

    $500/month

    Perfect for channel companies or vendors looking to deepen their engagement with the show.

  • All Leadership Access benefits plus . . .
  • Get highlighted as a show sponsor You'll get placement in the show notes, throughout the website, and on our dedicated sponsors page.
  • Enjoy regular shout outs You'll be featured in a rotating format during the show
  • Become a show sponsor for $500/month

    Search all stories