- Forging Trust
- Posts
- Teams Vishing + Fastest Growing Attack Surface + NIST-y Roundup
Teams Vishing + Fastest Growing Attack Surface + NIST-y Roundup
IT channel and business news with a focus on regulatory compliance.
š» Why AI Agents Are the Fastest-Growing Attack Surface Your MSP Isn't Governing
BeyondTrustās Phantom Labs clocked a 466.7% year-over-year jump in enterprise AI agents. Sophosās AI Security 2026 Report calls this āthe fastest-growing source of new exposureā businesses face right now. Attackers noticed first ā and if youāre an MSP, this is squarely in your laneā¦
An entire ad agency in the palm of your hand.
Your next campaign needs a dozen fresh ad variations by Friday. Your agency quotes two weeks and a five-figure invoice. Your in-house designers are already buried under this quarter's requests.
Hightouch Ad Studio fixes that. It reads your brand guidelines, your best-performing creative, and your product catalog, then generates on-brand ads your team can ship the same afternoon. You review and approve every asset before it goes live, so quality holds.
Growth teams use it to build variations for every audience, test more of them, and stop rationing creative because production got expensive. The work that once needed a full agency retainer now runs inside your own workflow, at your pace and under your direction.
You direct the work while Ad Studio handles production, and your designers get their week back.
šļø Podcast: Getting Past the CMMC Gatekeeping
This week, Isabel Rivera from Pentakt and Niels Petersen from ECN IT Solutions join Jared and Michael to explain what assessors expect, where technical teams get tripped up, and why waiting may cost more than moving forward. - Why the Phase 2 pause does not eliminate existing NIST 800-171 work- How 110 controls translate into roughly 320 assessment objectives, including HR, approvals, evidence, and separation of duties- Why having no SSP can drive an SPRS score to -203, and why an internal plan of action is not a C3PAO POA&M- What continuous monitoring should include and why your next assessment may require three years of evidenceā¦
ā ļø The Call Is Coming From Inside the Tenant: Why Teams Vishing Just Became the Attack Surface Your Email Gateway Can't See
Your client's next breach probably won't arrive in an inbox. It'll ring on Teamsā¦
šļø NIST-y Podcast Roundup!
Three episodes, one throughline: MSPs catch flak for the compliance decisions their clients refuse to make. This roundup pulls the practical takeaways from our latest run of Get NIST-y ā the podcast where we skip the framework LARP and talk about what actually works in a client environment on a Tuesday afternoonā¦
ā ļø Threat Updates
š“ Warlock Ransomware Abuses Zoho Assist for Stealthy Persistence (7/29/26)
Cisco Talos incident responders have observed Warlock ransomware operators deploying the legitimate Zoho Assist Unattended Agent to establish persistent, privileged remote access on compromised endpoints. By weaponizing a signed, trusted Remote Monitoring and Management (RMM) tool, attackers blend malicious activity with legitimate administrative traffic, sidestepping signature-based antivirus and extending dwell time for lateral movement and data exfiltration before ransomware detonation. This "living off the land" tactic is especially dangerous for MSPs and ITSPs, whose RMM infrastructure is a force multiplier ā a single compromised technician account or management server could hand Warlock operators simultaneous access to the entire downstream client base, turning a core operational tool into a supply-chain attack vector with catastrophic multi-tenant blast radius. MSPs should immediately audit all Zoho Assist and RMM deployments for authorized use and secure configuration, enforce strict application allowlisting to block unsanctioned RMM installations, hunt via EDR for RMM agents executing from unusual user profiles or directories, monitor network logs for Zoho Assist traffic from endpoints that shouldn't be initiating it, and require phishing-resistant MFA on every administrative and RMM account. Ā» More Info
š“ Critical Arista VeloCloud Orchestrator Zero-Day Under Active Exploitation (7/29/26)
A critical unauthenticated OS command injection vulnerability (CVE-2026-16812, CVSS 10.0) in on-premises Arista VeloCloud Orchestrator (VCO) is being actively exploited as a zero-day, prompting CISA to add it to the Known Exploited Vulnerabilities catalog on July 27, 2026 with a July 30, 2026 federal patching deadline. The flaw lets a remote, unauthenticated attacker reach privileged internal functionality and execute arbitrary code on the VCO host. MSPs should immediately inventory all on-prem VCO instances and patch to 5.2.3.14, 6.1.3.4, 6.4.2.4, 7.0.0.1, or later; if patching must be delayed, restrict VCO web interface access to trusted administrative networks only; hunt for Arista-published attacker IPs 8.19.75.217, 206.72.242.124, and 206.72.242.162 in web, firewall, and application logs; and review VCO logs for unexpected outbound connections or unauthorized administrative changes. Hosted and dedicated cloud VCO instances were patched by Arista pre-advisory. Ā» More Info
šØļø Parting Words
āA man is a success if he gets up in the morning and gets to bed at night, and in between he does what he wants to do.ā ā Bob Dylan
Find the Blacksmith Teamā¦
ā¦on demand with |
Are you a vCISO or MSP looking to operationalize security programs? Letās discuss how Blacksmith Infosec proves that compliance is an opportunity, not a struggle that has to be packaged in FUD!





