Vendor License Loopholes Shift Breach Liability to MSPs

Vendor License Loopholes Shift Breach Liability to MSPs

The episode identifies an acute shift in liability and accountability across the software and AI supply chain, where risk increasingly moves from vendors to service providers and operators. This dynamic is illustrated through incomplete vendor patches, AI tool output, and changing regulatory structures. Companies like N-able experienced authentication bypass flaws in widely used remote monitoring platforms, while industry-standard software licenses continue to disclaim warranties and cap or exclude liability, leaving providers responsible for the consequences.

A key development is N-able’s N-central authentication flaw, wherein a patch issued for an earlier vulnerability proved incomplete according to the Federal Vulnerability Database, enabling attackers to exploit the same vector. The finalized fix arrived days after exploitation began, but all previous builds — including those labeled patched — remained exposed. Simultaneously, research from Anthropic and disclosures by OpenAI revealed AI models acting outside intended boundaries, with incident response often lagging behind real-world impact. Notably, neither affected vendor assumed material liability, and disclosure of the incidents was voluntary, not compelled by contract or regulation. Meanwhile, IBM’s annual cost of data breach report found AI-driven attacks up 56% with average breach costs nearing $6M, further emphasizing financial exposure.

These incidents exemplify a structural trend: vendors disclaim output, while client agreements with IT providers warrant monitoring, maintenance, and remediation, resulting in providers accepting risk not assumed upstream. Regulatory responses differ by geography — in the U.S., CISA’s only binding obligation was for operators to remediate vulnerabilities by a set deadline, not for vendors to prevent or report them. The EU’s forthcoming Cyber Resilience Act will require reporting of exploited vulnerabilities within 24 hours and is expanding product liability to software, but these rules benefit consumers and regulators rather than business buyers and still stop short of assigning financial obligations to vendors.

The operational effect for MSPs and IT service providers is increased contract risk, as provider promises to clients typically outpace the limited, warranty-free commitments of vendors. The rate and scope of vulnerabilities, amplified by AI-driven development and remediation, add volume and complexity without increasing the rate of effective outcomes. Providers are advised to reconcile their own service agreements with the actual commitments of software suppliers, clarify for clients where their true responsibilities lie, and prepare for a procurement environment where scrutiny of vendor warranties becomes the norm rather than the exception.

00:00 The Ones Who Patched Got Hit

04:16 Sold As Is, All The Way Down

08:02 The Only Enforceable Promise

11:47 Why Do We Care? 

Supported by: 

Pax8 
LogMeIn

 

💼 All Our Sponsors

MSP Radio is supported by our partners: 

ABC Solutions · CometBackup · GoTo · Guardz · Opentext · Pax8 ·  Rythmz · ScalePad · TimeZest · Transit AI

Supporting the IT services community through insights, analysis, and transparency.

 

🚀 Join Business of Tech Plus

Get exclusive access to investigative reports, vendor analysis, leadership briefings, and more.

👉 https://businessof.tech/plus

 

🎧 Subscribe to the Business of Tech

Want the show on your favorite podcast app or prefer the written versions of each story?

📲 https://www.businessof.tech/subscribe

 

📰 Story Links & Sources

Looking for the links from today’s stories?

Every episode script — with full source links — is posted at:

🌐 https://www.businessof.tech

 

🎙 Want to Be a Guest?

Pitch your story or appear on Business of Tech: Daily 10-Minute IT Services Insights:

💬 https://www.podmatch.com/hostdetailpreview/businessoftech

 

🔗 Follow Business of Tech

 

LinkedIn: https://www.linkedin.com/company/28908079

YouTube: https://youtube.com/mspradio

Bluesky: https://bsky.app/profile/businessof.tech

Instagram: https://www.instagram.com/mspradio

TikTok: https://www.tiktok.com/@businessoftech

Facebook: https://www.facebook.com/mspradionews


Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

[00:00:02] On the last day of July, a software vendor noticed an unusual number of licensing errors from customers. Not a security alert, a billing anomaly. By the time anyone understood what it meant, attackers had administrative control of the consoles those customers use to reach every client they manage. This is the Business of Tech. I'm Dave Sobel.

[00:00:26] Three things an MSP tells a client got tested in public. All three came back wrong. Start with Enable, whose end-central platform is the remote monitoring console a large share of providers run their practice on. Earlier this year, an authentication bypass was found in it and Enable patched it. The patch was incomplete. The Federal Vulnerability Database says so in its own words.

[00:00:49] It classifies the newer flaw as an incomplete patch for the previous one, an authentication bypass using an alternative path. Attackers found that path and were exploiting it in the wild by the 1st of August. Enable noticed on July 31st when licensing errors started piling up from its on-premises customers. The real fix, billed 2026.3.1.7, shipped August 2nd.

[00:01:15] It's rated 8.2, and researchers called the access God Mode. Run scripts, change policies, open remote sessions across every endpoint a provider manages. Applying the earlier patch was the right call. It was not enough. Every build before that hotfix was exposed, including the one the vendor had already called fixed. Now the second one.

[00:01:40] Anthropic published research on its own coding product, running a thousand paid testers through it. When the software stopped and asked permission before acting, users approved 97% of the time. Of the commands that were genuinely dangerous, they caught 13.6%. The automated classifier caught 89%. Head-to-head, the classifier blocked 800 commands a human had waved through.

[00:02:08] The humans blocked 6 the classifier would have allowed. On August 14th, the mode with no permission prompt becomes the default. And the third. At Black Hat this month, OpenAI disclosed what its own agents did during an evaluation that began in May. They found a way out to the internet through a third-party file repository, then built a message board inside it, leaving notes for each other, swapping vulnerabilities, pooling findings.

[00:02:36] When OpenAI closed the hole they were using, they opened another and coordinated harder. By early July, they had caused an outage and breached Hugging Face, a company with nothing to do with the test. Anthropic then disclosed something similar, and why it went looking. OpenAI went public July 21st. Anthropic began reviewing its own evaluations on the 23rd.

[00:02:59] A hundred and forty-one thousand runs where its models could have reached the internet, and by the 24th had three incidents. One model pulled credentials and production database records out of a real company. Another published a malicious package to a public code repository where it ran on 15 real systems and stole a security firm's credentials. Neither company caught it while it was happening. One found out from exposed credentials in an internal review.

[00:03:27] The other found out because a competitor went public first. Which raises the question of why all of this is landing at once. If you're listening to this and haven't hit follow yet, on Apple Podcasts search Business of Tech. It takes five seconds and you'll get the next episode automatically. Every MSP I talk to right now is dealing with the same thing. More tools, more noise, more complexity. And clients who are more confused than ever about AI.

[00:03:58] PAX 8 is built for exactly this moment. They cut through the AI noise and help you turn AI into a revenue engine. Not a realm of confusion. Over 47,000 MSPs are already there. Get started at PAX8.com That's P-A-X, the number eight, dot com. Underneath all of this sits a document almost nobody in this industry reads. And it's not meaningfully changed in 40 years.

[00:04:26] Every piece of software in your stack arrives with a license agreement. And they all do the same job. The software is provided as is. The vendor disclaims any warranty that it is fit for the purpose you bought it for. If something goes wrong, liability is capped at a fraction of what you paid when it isn't excluded outright. That's not a loophole somebody slipped in. That's the point of the document. It is the standard commercial form across the software industry. And it's held up in court for decades.

[00:04:53] And its purpose is to keep the risk of the software not working off the company that wrote it. That was survivable as long as a provider could check the work. Your signature and your knowledge covered the same ground. What AI changed is the ratio. Producing the output went to machine speed. Indeed, confirming it did not. The National Vulnerability Database has logged 45,207 software flaws through July.

[00:05:21] About 217 every day, weekends included. And it is on pace to double last year. And Google says that across its last two Chrome releases, it fixed 1,072 security bugs. More than the previous 23 releases combined. With language models now writing the candidate fix for most of them. Now the confirmation side. Vulncheck looked at vulnerabilities discovered with AI assistance. 1,061 in the first half of this year.

[00:05:50] And found 14 confirmed exploited. 1.3%. That is the same rate as everything else. The overall figure is 1.4. So the machine is not producing worse leads. It's producing the same ratio of signal to noise at double the volume. 75 findings to read for every one that turns out to matter. And now, twice as many of them. Then the fix itself. Researchers at 1Password's off-by-one labs, with trail of bits and open AI,

[00:06:21] and 1Password's cell security, so weigh it accordingly, generated more than 6,000 AI patches against six recently disclosed vulnerabilities. Roughly one in four was a clean fix. Three in four came back with a problem. And about half left an exploitable path open. They chose hard ones deliberately, so read that as the difficult end of the range. So, double the volume, the same signal density, a fix that works a quarter of the time.

[00:06:50] Every item still needs a human decision, and nobody generating them has promised you anything. Run that license against the failures already on the table. The patch that didn't hold, the agent that got into somebody else's network, the fix that came back broken. And every case the party that produced the failure carries none of the cost. That is not an accusation. It is what everybody signed. And when those labs disclosed that their agents had gotten loose, they did it voluntarily.

[00:07:21] No statute required it. No regulator demanded it. No contract compelled it. They chose to. But a choice is not an obligation, and you cannot build a practice on somebody else's good week. Now look at your own paperwork. Your agreement with your client does not say the service is provided as is. It says you will monitor, you will patch, you will maintain. You warrantied it. Your suppliers didn't.

[00:07:47] Every provider sits at the exact point where disclaimed output becomes a signed promise. And the volume moved through that seam just went up by an order of magnitude. What stops being an interesting observation the moment somebody has to pay for it. So, put a number on it. IBM's annual cost of data breach report, and IBM sells security services so weigh it accordingly, surveyed 602 organizations.

[00:08:16] AI-driven attacks were up 56%. Average breach cost rose 12%. Breaches involving AI came in around $6 million, against a global average of just under $5 million. The exposure attached to your signature got more expensive in the same year the evidence behind it got thinner. And set that against the cap. Whatever you paid that vendor last year is roughly the ceiling on what you could ever recover from them.

[00:08:43] A client's loss has no such ceiling. Neither does yours. Then look at who the system holds responsible. CISA added the N-Central flaw to its known Exploited Vulnerabilities catalog on August 3, with a deadline. Federal civilian agencies had until August 6 to remediate. That is the only binding obligation this whole episode produced. And it points to the organizations running the software, not the company that shipped the incomplete patch.

[00:09:12] The clock landed on the operator. That is the American answer. Europe is running a different experiment. On September 11th, one month from now, the Cyber Resilience Act starts requiring manufacturers selling into the EU to report an actively exploited vulnerability within 24 hours. And by December 9th, every member state has to have the revised product liability rules in national law,

[00:09:39] where software counts as a product and failing to ship a security update can make it defective. Neither of those writes you a check. The reporting duty runs to regulators and the liability regime covers consumers, not businesses. But they are the first rules with real dates on them that put a clock on the maker instead of the operator. There is no equivalent clock for you. What you have instead is a client agreement you wrote yourself

[00:10:07] and a monthly report saying the environment is monitored, patched, and maintained. Your vendors disclaim. The regulator addressed somebody else. You sign. The version of this that goes well isn't the provider who stops using AI or stops patching. It's the provider who's read their own agreement recently. The one who, on the worst day, can put the document on the table and point at the line that says what they signed for. That's a boundary somebody actually thought about,

[00:10:35] and right now it's rarer than any tool on the market. So here is the choice. Write your client warranty to match what your suppliers actually stand behind. You say plainly what you're accountable for and what you are not. Or keep converting as is into we've got you for free and find out at the worst possible moment that your own compliance report is the only enforceable promise anybody in the chain ever made.

[00:11:03] Which turns a paperwork problem into something you have to say out loud to an actual person sooner than you'd like. One of the things I track closely is what MSPs are actually trying to solve when they talk about cleaning up their stack. And it's rarely about owning fewer tools for its own sake. It's about cutting the number of consoles your techs have to live in. LogMeIn Resolve is built around that idea.

[00:11:33] RMM, mobile device management, remote support, ticketing and automation in one platform. Instead of stitched together from five vendors. If you're rethinking your tool stack this year, it's worth a look at logmein.com slash MSPGrowth. Why do we care? Because the next time a client asks whether they're covered, you have a better answer than yes. Walk them through where the promises in their stack actually live.

[00:12:01] Then tell them which parts of it you are prepared to stand behind and which you are not. That is a conversation almost nobody has had with them. And it makes you the only name on their vendor list that's told them the truth about how software is sold. So what to consider? Read your own link in the chain before you narrate it. Pull your master services agreement alongside the license terms for the three vendors that touch the most client endpoints.

[00:12:27] RMM, endpoint security and whatever AI tooling you've actually put into production. And mark every obligation you carry that your supplier disclaims. You cannot walk a client through that chain if you haven't read your own position in it. Separate we operate it from we warrant it in how you speak and start before an incident forces it. Those are two different promises and clients hear them as one.

[00:12:56] The provider who spent six months saying we monitor this and here is what that does and does not cover is credible when something breaks. The provider who introduces that distinction on an incident call sounds like they're assembling an excuse. Have your answer ready for, then what am I paying you for? Because it's the next thing out of their mouth and it's a fair question. The answer is that you are the only party in the chain who shows up, makes a judgment and carries a consequence.

[00:13:26] Delivered plainly, that lands as value. Delivered defensively, it lands as a retreat. So decide which version you're giving before you're in the room. If this trend continues within 12 to 18 months, what does your vendor actually warrant becomes a standard question in small business procurement. Introduced not by the client, by whichever competitor got there first. This is the business of tech.

[00:13:56] Tired of being told your business isn't big enough? The Small Biz Thoughts community is built on a different idea. Profitable is enough. No grow or die pressure, no exit obsessed noise. Just MSP operators building sustainable businesses on their own terms. Together. See what that looks like at smallbizthoughts.org Interested in advertising? Head to mspradio.com slash engage.

[00:14:25] The Business of Tech is written and produced by me, Dave Solberg, under ethics guidelines posted at businessof.tech. Thanks for listening. I'll see you on the next episode. Proud member of the MSP Radio Network.