- Forging Trust
- Posts
- Marked Increase in Shadow AI Risks + The End of Human Pen Testing(?)
Marked Increase in Shadow AI Risks + The End of Human Pen Testing(?)
IT channel and business news with a focus on regulatory compliance.
🤖 Why Doubling Sensitive Data Uploads Should Keep MSPs Up at Night
Managed service providers are quietly inheriting a new kind of data‑loss problem: clients’ employees are shoveling sensitive data into AI tools at a rate that has doubled in the last year, with the average organization now seeing roughly 223 incidents per month where users send sensitive data to AI apps. For MSPs, that shift isn’t just a “client awareness” issue — it’s a direct extension of your security, data protection, and compliance obligations, whether your contracts say so explicitly or not…
🎙️ Podcast: Security/Compliance Symbiosis
Compliance is not security. Security is not compliance. But if you treat either one like a box-checking exercise, your client is going to have a bad time. In this episode of Get NIST-y, Jared and Mike talk with Shawn Duffy from Duffy Compliance Services about where SMBs, MSPs, and service providers keep stepping on the same rakes.
No theory. No slides. Just pipeline.
Most founders know their product. Few know how to get it in front of the right people. In this hands-on session, Clay + HubSpot for Startups walk you through ICP definition, prospect list enrichment, and AI-personalized outreach. You launch your first sequence before the session ends. June 18. 11am ET / 4pm GMT.
🤔 Is Penetration Testing Changing Forever?
The “death of human pen testing” makes a great headline, but what we are really watching is the death of traditional pen testing: slow, point‑in‑time, human‑only engagements that cannot keep up with AI‑accelerated attack surfaces or modern compliance expectations. Automated and AI‑assisted testing will gut the old model — but they are far more likely to elevate and reshape human testers than replace them outright…
⚠️ Threat Updates
🔴 Windows: “SprySOCKS” Backdoor Uses SOCKS5 Tunneling for Stealthy Persistence (06/17/26)
A newly uncovered Windows backdoor dubbed SprySOCKS is being used in targeted attacks to establish covert persistence and proxy-based command-and-control by leveraging SOCKS5 tunneling, allowing threat actors to quietly route malicious traffic through infected systems, evade network detection, and maintain long-term access while blending into legitimate traffic patterns—raising the risk of lateral movement, data exfiltration, and proxy abuse on compromised hosts unless organizations implement strict outbound traffic monitoring, endpoint detection, and network segmentation controls. » More Info
🔴 OptinMonster CDN: Supply‑Chain Attack Plants Hidden Admins on 1.2M+ WordPress Sites (06/12/26)
A CDN‑level supply‑chain compromise at OptinMonster’s parent company Awesome Motive let attackers inject malicious JavaScript into the OptinMonster, TrustPulse, and PushEngage SDKs, silently backdooring over 1.2 million WordPress sites by waiting for logged‑in admins, auto‑creating rogue “developer_api1”/dev_xxxxxx administrator accounts, and deploying a self‑hiding plugin backdoor while exfiltrating credentials to a fake tidio.cc domain, so any site that loaded the affected BunnyNet‑hosted scripts during the June 12–13 window should assume full site compromise, hunt for those rogue admin accounts and “Content Delivery Helper”/“Database Optimizer” plugins on disk, rotate all secrets, and treat third‑party CDN JavaScript as untrusted until vendors confirm remediation. » More Info
🗨️ Parting Words
“The problem with quotes on the internet is that they’re often made up.” — Abraham Lincoln
Are you a vCISO or MSP looking to operationalize security programs? Let’s discuss how Blacksmith Infosec proves that compliance is an opportunity, not a struggle that has to be packaged in FUD!





