- Forging Trust
- Posts
- The MSP Podcast Edition! AI Slop vs. MSPs + Security on a Shoestring
The MSP Podcast Edition! AI Slop vs. MSPs + Security on a Shoestring
IT channel and business news with a focus on regulatory compliance.
šļø Letās Talk About AI Washing!
AI is everywhere right now ā and if youāre running an MSP, youāre feeling it from every direction. Your PSA has AI. Your RMM has AI. Your documentation platform has AI. Your quoting tool probably has AI. At this point, weāre all just waiting for the coffee maker to start summarizing tickets. But hereās the problem: not all AI is useful. A lot of it is just⦠noise.
Got your own questions for Jared and Mike? Click here to submit them and theyāll be featured on a future episode!
šļø Security on a Shoestring
In March 2026, Jared gave a talk titled "Security on a Shoestring" at . This week on Get NIST-y, we're bringing that talk to you. We'll be back next week with more answers to your questions.
š· Blacksmith at MSPGeekCon!
![]() | ![]() |
![]() | ![]() |
šļø How to Deal with Vendor Risk (Realistically) and Avoid Meaningless Checkmarks
This week on Get NIST-y, we use the Mythos supply chain mess as a reminder that your vendors' vendors can absolutely become your problem. Then we get into a second trap that deserves more skepticism: compliance platforms that promise automation but mostly hand you prettier green check marks.
ā”ļø Attend ChannelCon 2026!
Blacksmith InfoSec is giving subscribers to Forging Trust complimentary access to ChannelCon 2026.
Aug. 3ā5. San Diego. This is where the channel comes together around what's actually working ā across AI, cybersecurity and service delivery. Peer-led insight, independent research, and practical strategies built for MSPs.
Use code SPBlacksmith26 to register at no cost. This is the event where the IT channel moves together. Be part of it.
ā ļø Threat Updates
š“ Red Hat npm Scope: Backdoored Packages Steal Cloud & CI Secrets (06/02/26)
Attackers hijacked Red Hatās official @redhat-cloud-services npm scope and pushed backdoored versions of dozens of JavaScript packages that execute an obfuscated preinstall payload during npm install, turning a trusted supplyāchain channel into a credentialāstealing worm that targets GitHub Actions tokens, cloud provider keys (AWS, Azure, GCP), Kubernetes service accounts, SSH keys, npm tokens, and other CI/CD and developer secrets. Ā» More Info
Attackers are abusing ChatGPTās legitimate shared-content and code-rendering features to host convincingly branded phishing pages on real chatgpt.com URLs, luring users via malicious Google ads and SEOāpoisoned results into āshared chatsā and code snippets that pose as outage notices or install guides and then funnel them to fake download flows or embedded curl commands which silently retrieve and execute malware, effectively turning trusted AI-hosted content into a delivery channel for suspected infostealers and other payloads while bypassing many URL reputation checks ā meaning organizations that treat anything under chatgpt.com as inherently safe should immediately tighten web and email filtering around AI-tool domains, block direct execution of copied installation commands, train developers and end users to distrust āfix it with this curl commandā guidance from shared chats, and instrument endpoint and browser telemetry to detect unusual binary downloads and command-line activity following visits to ChatGPT links, especially those reached via ads or search results. Ā» More Info
šØļø Parting Words
āSomeone asked me, if I were stranded on a desert island what book would I bring: āHow to Build a Boat.āā ā Steven Wright
Are you a vCISO or MSP looking to operationalize security programs? Letās discuss how Blacksmith Infosec proves that compliance is an opportunity, not a struggle that has to be packaged in FUD!







