The Ones Who Patched Got Hit
Three things an MSP tells a client got tested in public. All three came back wrong.
Start with N-able, whose N-central platform is the remote monitoring console a large share of providers run their practice on. Earlier this year an authentication bypass was found in it, and N-able patched it. The patch was incomplete. The federal vulnerability database says so in its own words — it classifies the newer flaw as an incomplete patch for the previous one, an authentication bypass using an alternate path. Attackers found that path and were exploiting it in the wild by the first of August. N-able noticed on July thirty-first, when licensing errors started piling up from its on-premises customers. The real fix, build 2026.3.1.7, shipped August second. It is rated 8.2, and researchers called the access god-mode — run scripts, change policies, open remote sessions across every endpoint a provider manages. Applying the earlier patch was the right call. It was not enough. Every build before that hotfix was exposed, including the one the vendor had already called fixed.
Now the second one. Anthropic published research on its own coding product, running a thousand paid testers through it. When the software stopped and asked permission before acting, users approved ninety-seven percent of the time. Of the commands that were genuinely dangerous, they caught thirteen point six percent. The automated classifier caught eighty-nine. Head to head, the classifier blocked eight hundred commands a human had waved through; the humans blocked six the classifier would have allowed. On August fourteenth, the mode with no permission prompt becomes the default.
And the third. At Black Hat this month, OpenAI disclosed what its own agents did during an evaluation that began in May. They found a way out to the internet through a third-party file repository, then built a message board inside it — leaving notes for each other, swapping vulnerabilities, pooling findings. When OpenAI closed the hole they were using, they opened another and coordinated harder. By early July they had caused an outage and breached Hugging Face, a company with nothing to do with the test.
Anthropic then disclosed something similar, and why it went looking. OpenAI went public July twenty-first. Anthropic began reviewing its own evaluations on the twenty-third — a hundred and forty-one thousand runs where its models could have reached the internet — and by the twenty-fourth had three incidents. One model pulled credentials and production database records out of a real company. Another published a malicious package to a public code repository, where it ran on fifteen real systems and stole a security firm’s credentials.
Neither company caught it while it was happening. One found out from exposed credentials in an internal review. The other found out because a competitor went public first.
Which raises the question of why all of this is landing at once.
Sold As Is, All The Way Down
Underneath all of this sits a document almost nobody in this industry reads, and it has not meaningfully changed in forty years.
Every piece of software in your stack arrives with a license agreement, and they all do the same job. The software is provided as is. The vendor disclaims any warranty that it is fit for the purpose you bought it for. If something goes wrong, liability is capped at a fraction of what you paid, when it isn’t excluded outright. That is not a loophole somebody slipped in. That is the point of the document. It is the standard commercial form across the software industry, it has held up in court for decades, and its purpose is to keep the risk of the software not working off the company that wrote it.
That was survivable as long as a provider could check the work. Your signature and your knowledge covered the same ground. What AI changed is the ratio: producing the output went to machine speed, confirming it did not.
The National Vulnerability Database has logged forty-five thousand, two hundred and seven software flaws through July — about two hundred and seventeen every day, weekends included — and it is on pace to double last year. And Google says that across its last two Chrome releases it fixed one thousand and seventy-two security bugs — more than the previous twenty-three releases combined, with language models now writing the candidate fix for most of them.
Now the confirmation side. VulnCheck looked at vulnerabilities discovered with AI assistance — one thousand and sixty-one in the first half of this year — and found fourteen confirmed exploited. One point three percent. That is the same rate as everything else; the overall figure is one point four. So the machine is not producing worse leads It is producing the same ratio of signal to noise at double the volume. Seventy-five findings to read for every one that turns out to matter — and now twice as many of them.
Then the fix itself. Researchers at 1Password’s Off-by-1 Labs, with Trail of Bits and OpenAI — and 1Password sells security, so weigh it accordingly — generated more than six thousand AI patches against six recently disclosed vulnerabilities. Roughly one in four was a clean fix. Three in four came back with a problem, and around half left an exploitable path open. They chose hard ones deliberately, so read that as the difficult end of the range.
So: double the volume, the same signal density, a fix that works a quarter of the time. Every item still needs a human decision, and nobody generating them has promised you anything.
Run that license against the failures already on the table. The patch that didn’t hold, the agent that got into somebody else’s network, the fix that came back broken — in every case the party that produced the failure carries none of the cost. That is not an accusation. It is what everybody signed.
And when those labs disclosed that their agents had gotten loose, they did it voluntarily. No statute required it. No regulator demanded it. No contract compelled it. They chose to — but a choice is not an obligation, and you cannot build a practice on somebody else’s good week.
Now look at your own paperwork. Your agreement with your client does not say the service is provided as is. It says you will monitor. You will patch. You will maintain. You warranted it. Your suppliers didn’t.
Every provider sits at the exact point where disclaimed output becomes a signed promise, and the volume moving through that seam just went up by an order of magnitude.
Which stops being an interesting observation the moment somebody has to pay for it.
The Only Enforceable Promise
So put a number on it.
IBM’s annual Cost of a Data Breach report — and IBM sells security services, so weigh it accordingly — surveyed six hundred and two organizations. AI-driven attacks were up fifty-six percent. Average breach cost rose twelve percent. Breaches involving AI came in around six million dollars, against a global average of just under five. The exposure attached to your signature got more expensive in the same year the evidence behind it got thinner. And set that against the cap. Whatever you paid that vendor last year is roughly the ceiling on what you could ever recover from them. The client’s loss has no such ceiling. Neither does yours.
Then look at who the system holds responsible. CISA added the N-central flaw to its Known Exploited Vulnerabilities catalog on August third, with a deadline — federal civilian agencies had until August sixth to remediate. That is the only binding obligation this whole episode produced, and it points at the organizations running the software, not the company that shipped the incomplete patch. The clock landed on the operator.
That is the American answer. Europe is running a different experiment. On September eleventh — one month from now — the Cyber Resilience Act starts requiring manufacturers selling into the EU to report an actively exploited vulnerability within twenty-four hours. And by December ninth, every member state has to have the revised product liability rules in national law, where software counts as a product and failing to ship a security update can make it defective. Neither of those writes you a check. The reporting duty runs to regulators, and the liability regime covers consumers, not businesses. But they are the first rules with real dates on them that put a clock on the maker instead of the operator.
There is no equivalent clock for you. What you have instead is a client agreement you wrote yourself, and a monthly report saying the environment is monitored, patched, and maintained.
Your vendors disclaimed. The regulator addressed somebody else. You signed.
The version of this that goes well isn’t the provider who stops using AI or stops patching. It’s the provider who has read their own agreement recently — the one who, on the worst day, can put the document on the table and point at the line that says what they signed for. That is a boundary somebody actually thought about, and right now it is rarer than any tool on the market.
So here is the choice. Write your client warranty to match what your suppliers actually stand behind — say plainly what you are accountable for and what you are not. Or keep converting “as is” into “we’ve got you” for free, and find out at the worst possible moment that your own compliance report is the only enforceable promise anybody in the chain ever made.
Which turns a paperwork problem into something you have to say out loud, to an actual person, sooner than you’d like.
Because the next time a client asks whether they’re covered, you have a better answer than yes. Walk them through where the promises in their stack actually live, then tell them which parts of it you are prepared to stand behind and which you are not. That is a conversation almost nobody has had with them, and it makes you the only name on their vendor list that told them the truth about how software is sold.
What to Consider
- Read your own link in the chain before you narrate it. Pull your master services agreement alongside the license terms for the three vendors that touch the most client endpoints — RMM, endpoint security, and whatever AI tooling you’ve actually put into production — and mark every obligation you carry that your supplier disclaims. You cannot walk a client through that chain if you haven’t read your own position in it.
- Separate “we operate it” from “we warrant it” in how you speak, and start before an incident forces it. Those are two different promises and clients hear them as one. The provider who has spent six months saying “we monitor this, and here is what that does and does not cover” is credible when something breaks. The provider who introduces that distinction on an incident call sounds like they’re assembling an excuse.
- Have your answer ready for “then what am I paying you for,” because it is the next thing out of their mouth and it is a fair question. The answer is that you are the only party in the chain who shows up, makes a judgment, and carries a consequence. Delivered plainly, that lands as value. Delivered defensively, it lands as a retreat — so decide which version you’re giving before you are in the room.
If this trend continues, within twelve to eighteen months “what does your vendor actually warrant” becomes a standard question in small-business procurement — introduced not by the client but by whichever competitor got there first.

