• Forging Trust
  • Posts
  • Stack ≠ Security + Bad Social Proof is Hurting Cybersecurity

Stack ≠ Security + Bad Social Proof is Hurting Cybersecurity

IT channel and business news with a focus on regulatory compliance.

In partnership with

⛓️‍💥 Don’t Blame the Drill

Imagine you hire a handyman to mount your new TV. A few days later, it crashes off the wall. Your first instinct isn’t to question the brand of drill he used. You blame the man who held it. Something he did wasn’t up to par — the anchor placement, the stud check, the torque on the bolts. The tool was fine. The execution wasn’t.

Cybersecurity works exactly the same way, which is why a client is never going to say “your tools messed this up big time”…

🎙️ Podcast: Keeping MSPs Out of the Unpaid Compliance Department Trap

Shared responsibility gets ugly when the client wants compliance, but not ownership. In this episode, we answer:

  • A medical client's cyber insurer wants annual security policies, but the doctors want the front desk to handle it. What now?

  • How should an MSP separate recurring compliance help from client-owned decisions and project work?

LLM traffic converts 3× better than Google search

58% of buyers now start their research in ChatGPT or Gemini, not Google. Most startups aren't showing up there yet.

The ones that are get cited by the AI tools their buyers, investors, and future hires already use. And they convert at 3×.

Download the free AEO Playbook for Startups from HubSpot and get the exact steps to start showing up. Five minutes to read.

🤔 Are You Using the Wrong Kind of Social Proof to Sell Compliance and Security?

Social proof is one of the most powerful strings you can pull when it comes to marketing and selling — but it’s not all the same. MSPs, vendors, and the IT channel at large may have been using a “proven terrible” type of social proof for years without even knowing it. Here’s how to avoid that mistake…

⚠️ Threat Updates

🔴 Klue Integration Breach Exposes Customer Salesforce Environments via Stolen OAuth Tokens (06/22/26)

On June 12, competitive intelligence platform Klue discovered an attacker had used a compromised legacy credential tied to an integration service to harvest OAuth tokens connecting Klue to third-party platforms — most notably Salesforce — and accessed data inside affected customer environments. The breach was confined to those connected platforms; no data stored within the Klue platform itself was affected. Klue responded by revoking all affected credentials and tokens, removing unauthorized code, pulling down impacted integrations, notifying law enforcement, and engaging CrowdStrike to validate containment. Affected customers should revoke and reissue any Klue-linked OAuth tokens for Salesforce and other connected platforms, audit those environments for unauthorized data access during the June 12 window, and contact Klue's security team for customer-specific remediation guidance. » More Info

🔴 Lookalike npm Package "postcss-minify-selector-parser" Deploys Multi-Stage Windows RAT on Developer Machines (06/24/26)

A malicious npm package named postcss-minify-selector-parser was caught impersonating postcss-selector-parser — a legitimate build tool with over 150 million weekly downloads — by mimicking its keywords and even listing the real package as a dependency to pass casual review. It then silently deploys a multi-stage Windows remote access trojan the moment a developer imports it, giving attackers a persistent remote shell, file transfer capability, host profiling, VM-detection evasion, and direct access to Google Chrome's saved login database including bypass of app-bound encryption. Any developer who installed these packages should immediately remove them, scan temp folders and registry run keys for persistence artifacts, and rotate all stored browser credentials. » More Info

🗨️ Parting Words

“If you write a wise enough quote, your name will be remembered forever.” — Unknown

Find the Blacksmith Team…

on demand with 
Get NIST-y on Spotify!

Are you a vCISO or MSP looking to operationalize security programs? Let’s discuss how Blacksmith Infosec proves that compliance is an opportunity, not a struggle that has to be packaged in FUD!