News, Trends, and Insights for IT & Managed Services Providers
News, Trends, and Insights for IT & Managed Services Providers
two hands reaching for a flying object in the sky

Prompt injections present a significant security challenge as OpenAI’s new ChatGPT Atlas browser integrates advanced AI capabilities. Launched on October 21, 2025, Atlas allows users to leverage its AI for various tasks, but experts warn that it also opens pathways for potential attacks. According to LayerX, a web browser security firm, the Atlas browser was recently found to have vulnerabilities that could allow attackers to inject harmful instructions. OpenAI’s Chief Information Security Officer, Dane Stuckey, acknowledged that prompt injection remains an unresolved security issue, with adversaries likely to invest resources in exploiting these vulnerabilities.

Cybersecurity researchers have identified a significant vulnerability within Microsoft Teams that can allow attackers to bypass Microsoft Defender for Office 365 protections through the guest access feature. When users join an external tenant as guests, their protection is dictated by that environment, not their home organization, raising concerns about the security of external collaborations. Rhys Downing, a security researcher at Ontinue, highlighted that this creates potential “protection-free zones” for attackers who can disable safeguards in their own tenants. The recent update in Teams, which enables users to chat with anyone via email, further complicates this issue by allowing automated invitations that may evade traditional email security measures. Organizations are advised to implement strict B2B collaboration settings and educate employees about the risks of unsolicited Teams invitations to mitigate these threats.

The FBI has reported a staggering $262 million in losses due to account takeover fraud schemes perpetrated by cybercriminals impersonating bank support teams since the beginning of 2025. Over 5,100 complaints have been filed with the FBI’s Internet Crime Complaint Center, affecting individuals and businesses across various sectors. Cybercriminals use social engineering tactics to gain unauthorized access to online banking and payroll accounts, often changing passwords to lock victims out. Once access is secured, these criminals quickly transfer funds to cryptocurrency wallets, making recovery extremely difficult. The FBI advises individuals to monitor their financial accounts closely, utilize complex passwords, enable multi-factor authentication, and directly contact their financial institutions if they suspect fraud.

Why do we care?

The attacks aren’t coming through the neat, technical holes we used to worry about. They’re coming through identity, trust, and the places where users assume they’re protected when they’re not.

Prompt injections in something like the Atlas browser show how fragile these AI integrations really are. This isn’t a patchable flaw — it’s a structural problem in how LLMs work. So if you’re letting AI tools touch customer data or automate tasks, you need guardrails. Assume adversarial content will get through.

Teams guest access? Same issue. The second you step into someone else’s tenant, your protections aren’t your own. And now Microsoft wants users chatting with anyone via email. Great for productivity, terrible for security. If you’re not locking down B2B collaboration, you’re handing attackers an easy path in.

And the FBI’s numbers make it obvious: social engineering beats tech every time. Criminals aren’t breaking in — they’re talking their way in, then draining accounts before anyone notices.

MSPs need to recognize that modern security is about managing trust boundaries, not piling on more tools. AI, Teams, bank portals — it’s all the same lesson. If you don’t control identity, collaboration, and data access, the attackers will.

Choose your upgrade:

Get the full benefits of Business of Tech Plus

Insider Access

$12/month

Perfect for MSPs and ITSPs that want full interviews, early access, and ad-free listening

  • Programmatic Ad-free private podcast feedSame show, little interruptions
  • Channel Chatter previews1–2 topics with light insights
  • Early access to interview episodesHear it days before public release
  • Monthly Insider BriefTighter analysis you can share internally
  • Extra audio segmentsCut interviews, behind-the-scenes commentary, quick competitive notes
  • Become an Insider for $12/month

    Leadership Access

    $149/month

    Perfect for MSPs and Vendors that run a team and need the extended tactics, executive summaries, and weekly alignment brief

  • All Insider Access benefits plus . . .
  • Invite your teamIncludes access for 5 team members with option to add more
  • Vendor Strategy BriefsThe entire library, plus new analysis every month
  • Channel ChatterAll topics, full insights, complete vendor discussion + sentiment list
  • Quarterly State of the Channel Briefing
  • Monthly AMA submission priorityAsk Dave direct questions, and skip the line
  • Get the Leadership Edge for $149/month

    Vendor Partner

    $500/month

    Perfect for channel companies or vendors looking to deepen their engagement with the show.

  • All Leadership Access benefits plus . . .
  • Get highlighted as a show sponsor You'll get placement in the show notes, throughout the website, and on our dedicated sponsors page.
  • Enjoy regular shout outs You'll be featured in a rotating format during the show
  • Become a show sponsor for $500/month

    Search all stories