• Forging Trust
  • Posts
  • The MSP Podcast Edition! AI Slop vs. MSPs + Security on a Shoestring

The MSP Podcast Edition! AI Slop vs. MSPs + Security on a Shoestring

IT channel and business news with a focus on regulatory compliance.

šŸŽ™ļø Let’s Talk About AI Washing!

AI is everywhere right now — and if you’re running an MSP, you’re feeling it from every direction. Your PSA has AI. Your RMM has AI. Your documentation platform has AI. Your quoting tool probably has AI. At this point, we’re all just waiting for the coffee maker to start summarizing tickets. But here’s the problem: not all AI is useful. A lot of it is just… noise.

Got your own questions for Jared and Mike? Click here to submit them and they’ll be featured on a future episode!

šŸŽ™ļø Security on a Shoestring

In March 2026, Jared gave a talk titled "Security on a Shoestring" at . This week on Get NIST-y, we're bringing that talk to you. We'll be back next week with more answers to your questions.

šŸ“· Blacksmith at MSPGeekCon!

šŸŽ™ļø How to Deal with Vendor Risk (Realistically) and Avoid Meaningless Checkmarks

This week on Get NIST-y, we use the Mythos supply chain mess as a reminder that your vendors' vendors can absolutely become your problem. Then we get into a second trap that deserves more skepticism: compliance platforms that promise automation but mostly hand you prettier green check marks.

āž”ļø Attend ChannelCon 2026!

Blacksmith InfoSec is giving subscribers to Forging Trust complimentary access to ChannelCon 2026.

Aug. 3–5. San Diego. This is where the channel comes together around what's actually working – across AI, cybersecurity and service delivery. Peer-led insight, independent research, and practical strategies built for MSPs.

Use code SPBlacksmith26 to register at no cost. This is the event where the IT channel moves together. Be part of it.

āš ļø Threat Updates

šŸ”“ Red Hat npm Scope: Backdoored Packages Steal Cloud & CI Secrets (06/02/26)

Attackers hijacked Red Hat’s official @redhat-cloud-services npm scope and pushed backdoored versions of dozens of JavaScript packages that execute an obfuscated preinstall payload during npm install, turning a trusted supply‑chain channel into a credential‑stealing worm that targets GitHub Actions tokens, cloud provider keys (AWS, Azure, GCP), Kubernetes service accounts, SSH keys, npm tokens, and other CI/CD and developer secrets. Ā» More Info

Attackers are abusing ChatGPT’s legitimate shared-content and code-rendering features to host convincingly branded phishing pages on real chatgpt.com URLs, luring users via malicious Google ads and SEO‑poisoned results into ā€œshared chatsā€ and code snippets that pose as outage notices or install guides and then funnel them to fake download flows or embedded curl commands which silently retrieve and execute malware, effectively turning trusted AI-hosted content into a delivery channel for suspected infostealers and other payloads while bypassing many URL reputation checks — meaning organizations that treat anything under chatgpt.com as inherently safe should immediately tighten web and email filtering around AI-tool domains, block direct execution of copied installation commands, train developers and end users to distrust ā€œfix it with this curl commandā€ guidance from shared chats, and instrument endpoint and browser telemetry to detect unusual binary downloads and command-line activity following visits to ChatGPT links, especially those reached via ads or search results. Ā» More Info

šŸ—Øļø Parting Words

ā€œSomeone asked me, if I were stranded on a desert island what book would I bring: ā€˜How to Build a Boat.ā€™ā€ — Steven Wright

Find the Blacksmith Team…

…on demand with 
Get NIST-y on Spotify!

Are you a vCISO or MSP looking to operationalize security programs? Let’s discuss how Blacksmith Infosec proves that compliance is an opportunity, not a struggle that has to be packaged in FUD!