A central structural shift discussed is the acceleration of security risk and remediation cycles driven by AI-powered tooling available to both attackers and defenders. The episode highlights that the difference between offensive and defensive capabilities now depends less on underlying technology and more on access controls and permission settings, as demonstrated by offerings and incidents involving Anthropic, OpenAI, Cloudflare, and tool vulnerabilities in products from Connectwise and Enable.
Primary evidence of this shift includes the use of advanced AI models and agent frameworks, which have enabled attackers to compress the timeline for successful ransomware intrusions to under 10 hours, according to Unit 42 and The Register. On the defense side, Cloudflare and OpenAI announced an early access service leveraging Daybreak models (including GPT 5.6 Cyber) for vulnerability detection and suggested patching, subject to human review. Meanwhile, Microsoft implemented a policy throttling unpatched Exchange servers until remediation occurs, rather than relying on voluntary patching, marking a move towards enforced maintenance in vendor ecosystems.
Supporting developments underline the blurred line between offense and defense: Anthropic’s simultaneous release of two AI models (Claude Fable 5.1 and Claude Mythos 5.1) with identical capabilities but different access restrictions based on user vetting, and OpenAI’s promotion of its GPT-6 Astra model’s security testing performance, while applying safeguard layers to limit exploit generation. Reports from Hack the Box and Red Sift, citing increased enterprise adoption of AI for both security assessment and attack surface discovery, reinforce that automation now exposes vulnerabilities faster than traditional remediation processes can keep pace.
The operational implication for MSPs and IT service providers is that speed of decision-making—particularly client approval for emergency remediation—has become a critical risk control point. The analysis underscores that technical controls and cyber insurance arrangements are frequently untrusted or unused, leaving actual exposure governed by change management logistics. Providers are advised to formalize rapid approval clauses and escalation contacts in contracts, shifting from hypothetical scenarios to incorporating real vendor disclosures as triggers. This adjustment is positioned as a necessary response to a landscape in which exploits and mitigations move at comparable velocity, and traditional maintenance rhythms no longer align with risk movement.
00:00 The Intruder Left A Report
04:17 Same Model, Different Door
06:44 Configured, Never Turned On
09:47 Why Do We Care?
Supported by:
💼 All Our Sponsors
MSP Radio is supported by our partners:
ABC Solutions · CometBackup · Firetail · Guardz · HaloPSA · LogMeIn · Mailprotector · OpenText · Pax8 · Proofpoint · Rythmz · ScalePad · TimeZest · Transit AI · USecure
Supporting the IT services community through insights, analysis, and transparency.
🚀 Join Business of Tech Plus
Get exclusive access to investigative reports, vendor analysis, leadership briefings, and more.
👉 https://businessof.tech/plus
🎧 Subscribe to the Business of Tech
Want the show on your favorite podcast app or prefer the written versions of each story?
📲 https://www.businessof.tech/subscribe
📰 Story Links & Sources
Looking for the links from today’s stories?
Every episode script — with full source links — is posted at:
🎙 Want to Be a Guest?
Pitch your story or appear on Business of Tech: Daily 10-Minute IT Services Insights:
💬 https://www.podmatch.com/hostdetailpreview/businessoftech
🔗 Follow Business of Tech
LinkedIn: https://www.linkedin.com/company/28908079
YouTube: https://youtube.com/mspradio
Bluesky: https://bsky.app/profile/businessof.tech
Instagram: https://www.instagram.com/mspradio
TikTok: https://www.tiktok.com/@businessoftech
Facebook: https://www.facebook.com/mspradionews
Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
[00:00:02] Nine in ten of the largest companies in America have configured the control that stops email impersonation. Fewer than four in ten have turned it on. That's a deadbolt fitted to every door in the building and never once thrown. Everything expensive that happened in security this week happened in the gap between those two numbers. This is the Business of Tech. I'm Dave Sobel.
[00:00:28] Two sides of the same business went to machine speed using the same tools. Start with the register. A human attacker used Frontier AI models and a set of agents to run a ransomware intrusion from end to end. Reconnaissance, credential theft, cloud abuse, extortion. The whole thing took under 10 hours. Unit 42, the Palo Alto Networks team that ran the incident response, set that against the benchmark.
[00:00:56] A human crew doing the same job takes about two weeks. And when it was finished, the attacker left the victim an 80-page security audit describing what had just been done to them. Then ConnectWise, the company disclosed a new vulnerability in Screen Connect, the remote access tool MSPs use to reach client machines. And what it published was not a patch. It was a list of mitigation steps, with a permanent fix promised later in the week.
[00:01:25] The flaw affects cloud and on-premises deployments both. There's no confirmation yet that this particular one is being exploited. But Bleeping Computer notes why nobody is waiting to find out. Screen Connect's vulnerabilities have been targeted in the wild repeatedly by ransomware crews and by state-backed groups, including a North Korean operation in 2024. Enable lands again, too, with an emergency hotfix.
[00:01:51] And Central 2026.3 hotfix 4 out September 5th for a critical pre-authentication remote code execution flaw. And per HelpNet Security, the company's public advisory said there were no confirmations of exploitation, while a separate notice sent directly to customers called it a zero-day being exploited in the wild. We covered Enable shipping an incomplete patch back in August on a different issue.
[00:02:17] I'm not going to spend much time on them today, because they're the example, not the story. Now the other side of it. Cloudflare and OpenAI announced a joint service that does vulnerability discovery and remediation at the edge, running on OpenAI's Daybreak models, including one called the GPT 5.6 Cyber. It finds the flaw, ranks it, and writes a suggested patch. It's in early access, and nothing takes effect without a human approving it.
[00:02:44] That is Cloudflare and OpenAI describing their own product, so take the framing for what it is. But note the list of tasks, because it is the same list the attacker in the first story handed to a machine. And Microsoft stopped waiting on any of it. Beginning the second week of this month, an Exchange Server 2026 or 2019 installation not patched to last October's final baseline gets throttled and then blocked when it sends mail into Exchange Online through an on-premises connector.
[00:03:14] Microsoft is not asking anybody to patch. It is degrading the server until somebody does. Four disclosures in one week. Two from people breaking in, two from people selling the fix. All four moved at the same speed. If you're listening to this and haven't hit follow yet, on Apple Podcasts search Business of Tech. It takes five seconds, and you'll get the next episode automatically. Here's a reality every MSP knows.
[00:03:41] Native Microsoft 365 security leaves gaps. Those gaps land on your desk. Proofpoint 365 Total Protection closes them. It's an MSP-first platform that unifies Microsoft 365 security, backup, and compliance into one integrated console. High security efficacy, less operational friction, and multi-tenant management that scales as you grow. Protect clients against modern threats and stop stitching point tools together.
[00:04:10] Built on Hornet security, now part of Proofpoint. See it at Proofpoint-Total-Protection.com The reason they all move at the same speed is that they're all reaching for the same thing. Finding a flaw in writing the fix stopped being a specialty and became a feature of a general-purpose model. Look at how the model companies themselves handle that. Anthropic released two models, Claude Fable 5.1 and Claude Mythos 5.1.
[00:04:39] According to reporting in the Next Web and Silicon Republic, the two are the same model. The difference between them is the safeguard settings. Fable is generally available. Mythos is restricted. You can only get it if you are a vetted user working in cybersecurity or the life sciences. Same weight, same capability, one gate. And look at who the gate is for. Those vetting programs are open only to a set of US organizations.
[00:05:04] So whether your shop can buy into the defensive tier of this has already been decided for most of the planet, and it wasn't decided on capability. Think about what that arrangement says the company believes. If the security work could be separated from the attack work down at the level of the model, they would have built two different models. They didn't because it can't. So they built one and put a bouncer on the door. OpenAI arrives at the same place from the other direction.
[00:05:30] The company says GPT-6 Astra scored 100% on a cybersecurity benchmark called Exploit Bench. That is OpenAI's own number about OpenAI's own product. And then describes the safeguards that stopped the model from building advanced exploits while promoting it for secure code review and patching. One capability, two names for it depending on who is holding it. And the arrival of that capability is measurable.
[00:05:57] Hack the Box, in its own global skills benchmark, that is the company's own competition data, and Hack the Box sells security training, found that 68% of the top 25 cybersecurity teams now use AI agents and that median solve times have been cut in half. Dark Reading, independently, describes the end of the era of hidden vulnerabilities. Bugs that used to sit undiscovered for years are surfacing faster than the vendors who own them can remediate.
[00:06:26] So here's the mechanism in one sentence. The thing separating the Defender's tool from the Attacker's tool is not what it can do. It's a permission setting. And a permission setting only binds the party that applied for an account. That accounts for two of the three parties in this. The third one never applied for anything. The two parties that got faster are the ones selling the tools and the ones using them to break in. The party paying for all of it didn't get faster at anything.
[00:06:56] Here's what that looks like when somebody measures it. RedSift published its U.S. DMARC adoption report this year, measuring 5,000 domains belonging to the largest organizations from 49 states and Washington, D.C. Nearly 90% of them have a DMARC record published. Only 38.4% actually enforce it at the reject level. RedSift sells email security, so the gap they found is a gap they would like to sell into. Take the number with that attached.
[00:07:25] But the number is the point. 9 in 10 configured the control. Fewer than 4 in 10 turned it on. And when a control isn't operating, the fallback assumption is that the insurance covers it. Cohesity surveyed UK business leaders, a data resilience vendor asking about resilience, so weigh it accordingly, and found only 22% trust their cyber policy to cover the costs of an attack.
[00:07:50] In the same research, chief executives put the revenue hit from a typical breach at around 15%. 15%. Run that against a client doing $10 million a year and you're describing a million and a half dollars, on the assumption the policy pays. Which is the assumption more than three quarters of them just told a surveyor they don't hold. That's the whole exposure. A control that's configured but not live, and a transfer that's purchased but not trusted.
[00:08:17] Neither of those is a technology problem, and neither one gets solved by anybody's model. What sits between the fix existing and the fix being live isn't engineering. It's a scheduled maintenance window, a change control process, and a client who has to say yes. And all three of those were designed for a world where a flaw took weeks to weaponize. So here's the choice. Go get the standing right to deploy. Put an emergency change window in the agreement in writing.
[00:08:46] Name the person on the client side who can approve inside an hour, and test the rollback before you need it. So the answer is already yes when the next flaw arrives with no patch behind it. Or keep the authority conversation where it lives now, inside the incident, which is the one moment a client is least likely to grant it. And there's a version of that conversation that's a great deal easier to have than it sounds.
[00:09:10] The MSPs getting ahead in security aren't adding more tools, they're getting the work off their plate. Guards consolidates the stack, endpoint, email identity, and then puts an autonomous analyst on top of it. Triaging the alerts, correlating the signals, drafting the client reporting, automatically. It's purpose-built for MSPs protecting S&B clients, month to month.
[00:09:38] Real SecOps without hiring a SecOps team. Start at guards.com. That's G-U-A-R-D-Z dot com. Why do we care? Because there's a conversation to have at the next review, and it isn't about threats. It's one question. When the next flaw lands with no patch behind it, who on your side can tell me to act, and how fast can I reach them?
[00:10:05] Ask it, write the name into the agreement, and get a phone number that works at 11 at night. The client who can't answer has just shown you where their real exposure is, and it isn't in the stack you sold them. So what to consider? Ask it inside the review you already have on the calendar. Do not build a new meeting around this. The quarterly review already has a security section, and this replaces the dashboard slide nobody looks at.
[00:10:31] The answer takes about 90 seconds, and it's the single most useful 90 seconds in the meeting, because everything else on that agenda describes what you did, and this one tells you what you'll be permitted to do. Bring ConnectWise, not a hypothetical. The strongest version of this conversation isn't imagine a breach. It's a real week, this month, where the vendor disclosed a live flaw in the tool you used to reach their machines, and had no patch to hand anybody. Your client can look it up in 30 seconds.
[00:11:00] The scenario you're describing isn't a story about attackers. It's a story where the fix didn't exist yet, and the only remaining variable was how quickly you were allowed to act. Write down what happens when nobody answers. Get the name to prove her into the agreement, get an alternate, then get the part everyone skips. What you are authorized to do if both are unreachable, pass a defined number of hours.
[00:11:25] Without that sentence, somebody on your team makes that call alone at 2 in the morning, and finds out afterward whether it was the right one, and the client finds out at the same time they do. If this trend continues, a year from now the pre-authorized emergency change window will be a standard clause in managed security agreements. And the providers who didn't raise it in a client review this year will be signing whatever version of it their client's insurer wrote first.
[00:11:55] This is the business of tech. What would you fix in your business with the right playbook? Small Biz Thoughts members get a library of templates and operational resources, recorded member calls, and classes through IT Service Provider University. Operational education built specifically for independent MSPs. Start at smallbizthoughts.org.
[00:12:21] Interested in advertising? Head to mspradio.com slash engage. The Business of Tech is written and produced by me, Dave Sobel, under ethics guidelines posted at businessof.tech. Thanks for listening. I'll see you on the next episode. Proud member of the MSP Radio Network. Proud member of the MSP Radio Network. There we go.

