News, Trends, and Insights for IT & Managed Services Providers
News, Trends, and Insights for IT & Managed Services Providers
89a2cfe6 d49d 401e bf6d b2cb5694a54e

The Intruder Left A Report
Two sides of the same business went to machine speed, using the same tools.

Start with The Register. A human attacker used frontier AI models and a set of agents to run a ransomware intrusion from end to end — reconnaissance, credential theft, cloud abuse, extortion. The whole thing took under ten hours. Unit 42, the Palo Alto Networks team that ran the incident response, set that against the benchmark: a human crew doing the same job takes about two weeks. And when it was finished, the attacker left the victim an eighty-page security audit describing what had just been done to them.

Then ConnectWise. The company disclosed a new vulnerability in ScreenConnect — the remote access tool MSPs use to reach client machines — and what it published was not a patch. It was a list of mitigation steps, with a permanent fix promised later in the week. The flaw affects cloud and on-premises deployments both. There’s no confirmation yet that this particular one is being exploited — but BleepingComputer notes why nobody is waiting to find out. ScreenConnect vulnerabilities have been targeted in the wild repeatedly, by ransomware crews and by state-backed groups, including a North Korean operation in 2024.

N-able lands again too with an emergency hotfix — N-central 2026.3 Hotfix 4, out September fifth — for a critical pre-authentication remote code execution flaw. And per Help Net Security, the company’s public advisory said there were no confirmations of exploitation, while a separate notice sent directly to customers called it a zero-day being exploited in the wild. We covered N-able shipping an incomplete patch back in August on a different issue. I’m not going to spend much time on them today, because they’re the example, not the story.

Now the other side of it. Cloudflare and OpenAI announced a joint service that does vulnerability discovery and remediation at the edge, running on OpenAI’s Daybreak models, including one called GPT-5.6 Cyber. It finds the flaw, ranks it, and writes a suggested patch. It’s in early access, and nothing takes effect without a human approving it.  That is Cloudflare and OpenAI describing their own product, so take the framing for what it is — but note the list of tasks, because it is the same list the attacker in the first story handed to a machine.

And Microsoft stopped waiting on any of it. Beginning the second week of this month, an Exchange Server 2016 or 2019 installation not patched to last October’s final baseline gets throttled, and then blocked, when it sends mail into Exchange Online through an on-premises connector. Microsoft is not asking anybody to patch. It is degrading the server until somebody does.

Four disclosures in one week. Two from people breaking in, two from people selling the fix. All four moved at the same speed.

Same Model, Different Door
The reason they all move at the same speed is that they are all reaching for the same thing.

Finding a flaw and writing the fix stopped being a specialty and became a feature of a general-purpose model.

Look at how the model companies themselves handle that. Anthropic released two models, Claude Fable 5.1 and Claude Mythos 5.1. According to reporting in The Next Web and Silicon Republic, the two are the same model. The difference between them is the safeguard settings. Fable is generally available. Mythos is restricted — you can get it only if you are a vetted user working in cybersecurity or the life sciences. Same weights, same capability, one gate. And look at who the gate is for. Those vetting programmes are open only to a set of U.S. organisations. So whether your shop can buy into the defensive tier of this has already been decided for most of the planet, and it wasn’t decided on capability.

Think about what that arrangement says the company believes. If the security work could be separated from the attack work down at the level of the model, they would have built two different models. They didn’t, because it can’t. So they built one and put a bouncer on the door.

OpenAI arrives at the same place from the other direction. The company says GPT-6 Astra scored a hundred percent on a cybersecurity benchmark called ExploitBench — that is OpenAI’s own number about OpenAI’s own product — and then describes the safeguards that stop the model from building advanced exploits, while promoting it for secure code review and patching. One capability. Two names for it, depending on who is holding it.

And the arrival of that capability is measurable. Hack The Box, in its own global skills benchmark — that is the company’s own competition data, and Hack The Box sells security training — found that sixty-eight percent of the top twenty-five cybersecurity teams now use AI agents, and that median solve times have been cut in half. Dark Reading, independently, describes the end of the era of hidden vulnerabilities: bugs that used to sit undiscovered for years are surfacing faster than the vendors who own them can remediate.

So here is the mechanism in one sentence. The thing separating the defender’s tool from the attacker’s tool is not what it can do. It’s a permission setting.

And a permission setting only binds the party that applied for an account.

That accounts for two of the three parties in this. The third one never applied for anything.

Configured, Never Turned On
The two parties that got faster are the ones selling the tools and the ones using them to break in. The party paying for all of it didn’t get faster at anything.

Here’s what that looks like when somebody measures it.

Red Sift published its U.S. DMARC adoption report this year, measuring five thousand domains belonging to the largest organizations across forty-nine states and Washington D.C.  Nearly ninety percent of them have a DMARC record published. Only thirty-eight point four percent actually enforce it at the reject level. Red Sift sells email security, so the gap they found is a gap they would like to sell into — take the number with that attached. But the number is the point. Nine in ten configured the control. Fewer than four in ten turned it on.

And when a control isn’t operating, the fallback assumption is that the insurance covers it. Cohesity surveyed UK business leaders — a data resilience vendor asking about resilience, so weigh it accordingly — and found only twenty-two percent trust their cyber policy to cover the costs of an attack. In the same research, chief executives put the revenue hit from a typical breach at around fifteen percent.  Fifteen percent. Run that against a client doing ten million a year and you’re describing a million and a half dollars, on the assumption the policy pays — which is the assumption more than three quarters of them just told a surveyor they don’t hold.

That’s the whole exposure. A control that’s configured but not live, and a transfer that’s purchased but not trusted. Neither of those is a technology problem, and neither one gets solved by anybody’s model.

What sits between the fix existing and the fix being live isn’t engineering. It’s a scheduled maintenance window, a change-control process, and a client who has to say yes — and all three of those were designed for a world where a flaw took weeks to weaponize.

So here’s the choice.

Go get the standing right to deploy. Put an emergency change window in the agreement in writing, name the person on the client side who can approve inside an hour, and test the rollback before you need it — so the answer is already yes when the next flaw arrives with no patch behind it.

Or keep the authority conversation where it lives now, inside the incident, which is the one moment a client is least likely to grant it.

And there’s a version of that conversation that’s a great deal easier to have than it sounds.

Why Do We Care?
Because there’s a conversation to have at the next review, and it isn’t about threats. It’s one question: when the next flaw lands with no patch behind it, who on your side can tell me to act, and how fast can I reach them? Ask it, write the name into the agreement, and get a phone number that works at eleven at night. The client who can’t answer has just shown you where their real exposure is, and it isn’t in the stack you sold them.

What to Consider

Ask it inside the review you already have on the calendar. Do not build a new meeting around this — the quarterly review already has a security section, and this replaces the dashboard slide nobody looks at. The answer takes about ninety seconds, and it is the single most useful ninety seconds in the meeting, because everything else on that agenda describes what you did and this one tells you what you’ll be permitted to do.

Bring ConnectWise, not a hypothetical. The strongest version of this conversation isn’t “imagine a breach” — it’s a real week, this month, where the vendor disclosed a live flaw in the tool you use to reach their machines and had no patch to hand anybody. Your client can look it up in thirty seconds. The scenario you’re describing isn’t a story about attackers; it’s a story where the fix didn’t exist yet and the only remaining variable was how quickly you were allowed to act.

Write down what happens when nobody answers. Get the named approver into the agreement, get an alternate, and then get the part everyone skips: what you are authorized to do if both are unreachable past a defined number of hours. Without that sentence, somebody on your team makes that call alone at two in the morning and finds out afterward whether it was the right one — and the client finds out at the same time they do.

If this trend continues, a year from now the pre-authorized emergency change window will be a standard clause in managed security agreements — and the providers who didn’t raise it in a client review this year will be signing whatever version of it their client’s insurer wrote first.

Choose your upgrade:

Get the full benefits of Business of Tech Plus

Insider Access

$12/month

Perfect for MSPs and ITSPs that want full interviews, early access, and ad-free listening

  • Programmatic Ad-free private podcast feedSame show, little interruptions
  • Channel Chatter previews1–2 topics with light insights
  • Early access to interview episodesHear it days before public release
  • Monthly Insider BriefTighter analysis you can share internally
  • Extra audio segmentsCut interviews, behind-the-scenes commentary, quick competitive notes
  • Become an Insider for $12/month

    Leadership Access

    $149/month

    Perfect for MSPs and Vendors that run a team and need the extended tactics, executive summaries, and weekly alignment brief

  • All Insider Access benefits plus . . .
  • Invite your teamIncludes access for 5 team members with option to add more
  • Vendor Strategy BriefsThe entire library, plus new analysis every month
  • Channel ChatterAll topics, full insights, complete vendor discussion + sentiment list
  • Quarterly State of the Channel Briefing
  • Monthly AMA submission priorityAsk Dave direct questions, and skip the line
  • Get the Leadership Edge for $149/month

    Vendor Partner

    $500/month

    Perfect for channel companies or vendors looking to deepen their engagement with the show.

  • All Leadership Access benefits plus . . .
  • Get highlighted as a show sponsor You'll get placement in the show notes, throughout the website, and on our dedicated sponsors page.
  • Enjoy regular shout outs You'll be featured in a rotating format during the show
  • Become a show sponsor for $500/month

    Search all stories