- Forging Trust
- Posts
- MSPs Under Attack + AI Becomes Real Money for MSPs
MSPs Under Attack + AI Becomes Real Money for MSPs
IT channel and business news with a focus on regulatory compliance.
🤖 AI Is Finally Real Money for MSPs: Turning Hype into Billable Outcomes
The MSP conversation around AI has changed. In 2026, AI is no longer a novelty for demos, webinars, and investor decks; it is becoming a margin story, a service-delivery story, and a client-retention story. Recent MSP market analysis tied to Omdia’s 2026 outlook points to slower overall growth, more intense competition, and rising expectations around both AI and cybersecurity, which means providers need measurable outcomes rather than vague innovation claims…
🎙️ Podcast: Are Macs Really Impossible to Support?
Justin Esgar's got 99 problems, but a Mac ain't one! Justin, the CEO of NYC-based MSP VirtuaComputer and host of the All Things MSP podcast, joins Get NIST-y to talk about the MSP myth that Macs are insecure, unmanageable, or somehow impossible to support without ritual sacrifice.
How can AI power your income?
Ready to transform artificial intelligence from a buzzword into your personal revenue generator
HubSpot’s groundbreaking guide "200+ AI-Powered Income Ideas" is your gateway to financial innovation in the digital age.
Inside you'll discover:
A curated collection of 200+ profitable opportunities spanning content creation, e-commerce, gaming, and emerging digital markets—each vetted for real-world potential
Step-by-step implementation guides designed for beginners, making AI accessible regardless of your technical background
Cutting-edge strategies aligned with current market trends, ensuring your ventures stay ahead of the curve
Download your guide today and unlock a future where artificial intelligence powers your success. Your next income stream is waiting.
🏰 MSPs Are Under Direct Attack
For attackers, compromising a managed service provider is one of the highest-leverage plays in cybersecurity. NSA and CISA warn that malicious actors are known to target MSPs because MSPs often hold privileged access into customer environments, giving an attacker a trusted path to pivot into multiple downstream tenants and making those actions harder to detect than a direct intrusion. The UK’s NCSC makes the same point more bluntly: an MSP is not just a helper, it is another attack surface…
⚠️ Threat Updates
đź”´ phpBB Forums: Critical Auth Bypass Lets Attackers Hijack Any Account (06/08/26)
A newly disclosed authentication bypass in phpBB (PTT‑2026‑004, CVSS 9.4) lets attackers hijack any forum account, including admins, with a single unauthenticated HTTP request that only needs a valid username—no password or prior access required—while a second bug (PTT‑2026‑005) lets adversaries silently take over OAuth‑based logins via a crafted link, making it trivial to steal sessions, impersonate staff, and loot private messages on any unpatched phpBB up to 3.3.16 or 4.0.0‑alpha until sites upgrade to 3.3.17 or disable OAuth and audit linked identities. » More Info
🟠TikTok “Free Software” Videos Drop Vidar & StealC Infostealers (06/08/26)
Attackers are seeding TikTok with likely AI‑generated “activation” videos for Windows, Office, CapCut, Spotify, and other software that walk viewers through running a copy‑paste PowerShell command which silently pulls a remote script to install Vidar and StealC info‑stealing malware, adding Defender exclusions, setting persistence, and exfiltrating browser creds, payment data, and other secrets—some clips racking up ~500K views show how fast social‑media‑driven malware campaigns can spread beyond traditional phishing. » More Info
🗨️ Parting Words
“You can always tell when a man’s well informed. His views are pretty much like your own.” — H. Jackson Brown, Jr.
Are you a vCISO or MSP looking to operationalize security programs? Let’s discuss how Blacksmith Infosec proves that compliance is an opportunity, not a struggle that has to be packaged in FUD!





