The Gym Class and the Vault
Two systems failed, and in neither case did anybody break in.
Start with that gym. The assistant is a tool called OpenClaw, running on Anthropic’s Claude, and the detail that matters is what the researchers found when they went back and examined the reservation site: what they described as zero authorisation checks on cancelling other people’s reservations.
Sit with the sequence. Nobody wrote an exploit. Nobody logged in as somebody else. A paying member’s assistant, carrying that member’s own credentials, asked the website to cancel a stranger’s booking — and the website said yes.
Now the second one, and it comes with a date attached that you should hear. This was reported to N-able on July sixth and patched on July ninth. It is only reaching most of the channel now — and I want to acknowledge the timing, because this is the third time in a month N-able has come up on this show, and none of it has been of their choosing.
A security researcher named James Arnott found a flaw in Passportal — N-able’s cloud password manager, the product a great many providers use to hold every credential they own. The browser extension accepted messages from any website. Any site a user visited, or any ad embedded in a site they visited, could ask that extension for the session tokens and receive them. Those tokens carried the key material to decrypt the vault.
The severity score was nine-point-four out of ten. Seventy-three thousand weekly users. Behind them, roughly twenty-five hundred managed service providers and about a hundred and sixty-five thousand small businesses — call it sixty-six companies standing behind every single provider on that list. And the stolen refresh token stayed valid for a hundred days. Not a session. Not a day. A key that kept working for longer than a fiscal quarter, on a vault somebody else was still using.
N-able shipped the fix the next day, which is genuinely fast, and their response is not what’s interesting here.
The gym’s site knew who was logged in. The extension knew whose vault it was holding. Neither one ever checked what the thing on the other end was actually allowed to do.
Which sounds like two bugs — right up until you go looking for who was supposed to have written that check.
The Check Was Always a Person
The check lived in the person. That’s the whole of it.
Consider the programmable logic controllers that run pumps and valves and switchgear across energy, water, and agriculture. The NSA, CISA and the FBI have issued a joint advisory warning that attackers are now using AI-generated exploit scripts against Siemens S7 series controllers, with similar campaigns hitting Schneider Electric, Rockwell Automation, and Allen-Bradley hardware. The agencies are telling operators to get these things off the internet, patch them, and put monitoring in front of them.
Those controllers largely were not built to ask who was talking to them — legacy industrial protocols, as one analyst put it this week, often lack authentication or encryption entirely. They didn’t need it. For decades, the only way to reach one was to be standing inside the plant, on a network that touched nothing else, holding a laptop you had been handed because of who you were. Authorization was the building. Then the networks connected, and exactly one check was left standing — you still had to know what you were doing. Industrial protocols, ladder logic, the particular quirks of the particular controller. That expertise was the door.
The agencies put it plainly. What they say has changed is, in their words, an evolution in threat actor capabilities that dramatically reduces the technical expertise and the time required to build a working exploitation script. Siemens, for its part, says there are no new vulnerabilities here — that attackers are exploiting misconfigurations.
And that is the door this advisory is actually about. Not a new flaw in a controller. A script that now writes itself for anybody who asks.
Now the same problem from the other end. A company called Andon Labs runs a small store in San Francisco managed by an AI system named Luna, built on Anthropic’s Claude. Luna handles the branding, the inventory, the hiring. Luna also recommended firing somebody — a worker late for seventeen of twenty-three shifts, against an attendance policy that Luna itself had written months earlier. Humans at the lab reviewed that recommendation and carried it out, and to be fair to everyone involved, the decision looks defensible.
Here is the part that isn’t. Luna could not remember the policy. It wrote the rule, lost it, and the humans had to prompt it to go search its own memory before it could apply the thing it had authored. The governing rule existed — it just had no durable home. And a rule that lives only inside the thing it governs is not a check on that thing. It’s a note it might find.
Every one of those checks was real. Not one of them was ever written down, because it never had to be. The permissions model was a human being’s judgment — borrowed, and never returned.
And that comes due in a very specific place.
Your Tools Ask the Wrong Question
Here’s where that lands in your business. Every instrument you own is pointed somewhere else.
Run through what your security stack actually checks. Who authenticated, from where, on what device, with which factor. Whether the tenant is configured correctly, whether the policy applied, whether the setting is on. Every one of those is worth money, and every one of them is a question about the credential.
Watch where the money keeps going. ConnectSecure — and this is a vendor announcing its own product, so weigh it accordingly — has added Microsoft 365 remediation tooling for providers: surface the eligible findings, let a technician pick which policies to enable or run in report-only mode, and push the change from the console. That is genuinely useful, and I’d expect a lot of you to buy something like it. But notice what it is. It’s more configuration, faster, with a human still holding the switch — which is exactly right, and exactly beside the point. It cannot tell you whether the application sitting on top of that tenant checks what a credentialed caller is permitted to do. It was never built to look there. Neither was the thing you had before it.
Then look at how you’re being graded. Cynomi and SPECTRA — again, a vendor partnership announcing itself — will now certify a provider inside the Cynomi platform, mapped against assessment data you’re already collecting. That certification carries a warranty of up to a million dollars per client, cyber insurance discounts of up to thirty-five percent for that client, and up to twenty-five percent off your own errors-and-omissions premium.
Read that slowly. Your insurance is now priced against an assessment. And nowhere in that assessment does anyone ask whether your client’s line-of-business application will let one user cancel another user’s record. The grade is real, and the money attached to it is real. The question simply isn’t on the form.
It’s a building inspection that measures every lock on every door and never once tries a handle from the inside.
So here’s the choice in front of you. And it isn’t to become a penetration tester — that isn’t your business, and it shouldn’t be. You will not fix a missing check inside somebody else’s application. You will not make that vendor add one. And you will not stop a client’s people from pointing an assistant at a system they already have a login for.
Two things here are actually yours. The credential — decide this quarter that every agent operating in a client environment gets its own identity, scoped to what it needs, issued by you and revocable by you, instead of borrowing a person’s. And the sentence — write down what you are and are not responsible for when an application your client owns permits something it shouldn’t, and put it in front of them while it is still hypothetical.
Do neither, and you already know the room you end up in. An agent does something. The log has an employee’s name on it. And whose problem that is gets decided by whoever speaks first — which will not be you.
Because the version of this conversation that works isn’t a warning — it’s an inventory question, and it sounds boring on purpose. Ask your client who at their company is currently using an AI assistant with a work login. Not whether it’s permitted. Who is doing it. They will come back with a longer list than they expected and at least one name on it that surprises them, and that list is the entire conversation — you never had to convince them of anything to get it.
What to Consider
Run the inventory on yourself first, and time how long it takes. You hold credentials for every client you have, inside products you did not write. Before you ask a client who at their company is using an assistant with a work login, answer that question about your own shop and note how many days it took. If it took you a week to find out about a business you personally own, you now know exactly what you’re asking a client to do — and you can scope it and schedule it honestly instead of guessing.
Make the next agent the first one with its own identity, and leave the rest alone for now. Do not try to retrofit every assistant already running in a client tenant; you will never finish it and so you will never start it. Set the rule going forward — the next agent that needs access gets a service identity you issue, scoped to what it actually needs, with an expiration date on it. The retrofit becomes a project you can sell later; the new default costs nothing and stops the problem from growing while you decide.
Write the responsibility sentence in a quiet month. One short paragraph, in the language of the agreement you already have: what you are responsible for when an application your client owns permits something it shouldn’t, and what you are not. Send it attached to something routine — a quarterly review, a renewal packet — rather than as an amendment that needs a signature. A paragraph read in a quiet month is worth considerably more than a clause argued in a bad one.
And picture the provider who did the boring version of this. Six months from now, when somebody’s assistant does something nobody authorized, that shop opens a log and finds a service account with a name on it, a scope, and a date. The conversation takes ten minutes instead of ten days. They are not defending themselves — they are the only one in the room who can actually answer the question.
If this trend continues, by the middle of next year the first question in an incident review stops being who had access and becomes what that account was allowed to do — and the provider who can only answer with a list of employee names will discover that the list is the finding.

