News, Trends, and Insights for IT & Managed Services Providers
News, Trends, and Insights for IT & Managed Services Providers
purple and pink light illustration

And as many managed services providers run ConnectWise Automate, ConnectWise has released a critical security update for its Automate platform to address vulnerabilities that could allow attackers to intercept sensitive data or inject malicious software updates. The identified flaws primarily affect on-premises installations, where misconfigurations may expose systems to network-based exploits. The vulnerabilities are classified as severe, with a base score of 9.6 for the first flaw, which involves the cleartext transmission of sensitive information, and a score of 8.8 for the second flaw, which allows code downloads without integrity checks. Thousands of IT service providers using ConnectWise Automate are at risk, particularly those running versions prior to the latest 2025.9 update. Security experts emphasize the urgency for on-premises users to apply this patch manually, as the fix enforces secure communications and helps prevent potential exploits in an increasingly volatile threat landscape.

Why do we care?

If you’re running ConnectWise Automate on-prem, stop what you’re doing and patch. Right now.

Two major vulnerabilities — one letting attackers read sensitive data in cleartext, another letting them inject code during updates. Both critical, both ugly, and both hit anyone not running the latest 2025.9 release.

Here’s the thing — this isn’t a “maybe later” update. Automate runs deep in your clients’ systems. If that’s compromised, you’re the attack vector.  Again.  RMM’s are a big bullseye used by attackers.

And it’s another argument against hosting RMM tools yourself. Cloud versions get patched automatically; on-prem ones depend on you keeping up. If you’re still maintaining an RMM server in your office or a colo, ask yourself — is that risk really worth it anymore?

If you don’t handle it, you’ll be explaining why you became their breach headline.

Choose your upgrade:

Get the full benefits of Business of Tech Plus

Insider Access

$12/month

Perfect for MSPs and ITSPs that want full interviews, early access, and ad-free listening

  • Programmatic Ad-free private podcast feedSame show, little interruptions
  • Channel Chatter previews1–2 topics with light insights
  • Early access to interview episodesHear it days before public release
  • Monthly Insider BriefTighter analysis you can share internally
  • Extra audio segmentsCut interviews, behind-the-scenes commentary, quick competitive notes
  • Become an Insider for $12/month

    Leadership Access

    $149/month

    Perfect for MSPs and Vendors that run a team and need the extended tactics, executive summaries, and weekly alignment brief

  • All Insider Access benefits plus . . .
  • Invite your teamIncludes access for 5 team members with option to add more
  • Vendor Strategy BriefsThe entire library, plus new analysis every month
  • Channel ChatterAll topics, full insights, complete vendor discussion + sentiment list
  • Quarterly State of the Channel Briefing
  • Monthly AMA submission priorityAsk Dave direct questions, and skip the line
  • Get the Leadership Edge for $149/month

    Vendor Partner

    $500/month

    Perfect for channel companies or vendors looking to deepen their engagement with the show.

  • All Leadership Access benefits plus . . .
  • Get highlighted as a show sponsor You'll get placement in the show notes, throughout the website, and on our dedicated sponsors page.
  • Enjoy regular shout outs You'll be featured in a rotating format during the show
  • Become a show sponsor for $500/month

    Search all stories