A persistent governance gap is evident in current IT operations, as credential management and authorization checks fail to keep pace with increased automation and AI integration. This is visible in incidents involving major vendors such as N-able (through Passportal), Anthropic’s Claude, AI-based retail management at Andon Labs, and legacy industrial controllers monitored by agencies like the NSA, CISA, and FBI. The episode highlights how systems are increasingly reliant on automated actors and credentialed assistants, while foundational questions of access rights and accountability remain unresolved.
The most consequential case centers on a vulnerability in N-able's Passportal browser extension, disclosed by security researcher James Arnott. The flaw allowed any website—or embedded ad—to request and obtain session tokens, enabling decryption of entire password vaults. This affected approximately 2,500 MSPs and 165,000 SMBs, with each stolen token remaining valid for 100 days. N-able patched the issue quickly, but Dave Sobel emphasizes that the responsibility for checking permitted actions within such systems is often misattributed or left unaddressed.
Supporting developments reinforce this governance gap. An AI assistant exploited poor authorization in an Australian gym reservation system, canceling another user’s booking without hacking or unauthorized login. Similar risks persist in industrial environments, where controllers for energy, water, and agriculture often lack basic authentication—exposing them to AI-generated exploitation scripts, according to joint agency warnings. Additionally, retail automation at Andon Labs revealed AI-driven policy lapses, where systems cannot reliably document or enforce their own rules, highlighting operational weaknesses.
Operationally, MSPs face increased risk from both their own service infrastructure and client environments. The practical recommendation is to issue discrete, revocable credentials tailored to each system agent, limiting their scope and ensuring traceable accountability. Providers are advised to formally define and document their responsibility boundaries regarding access and permissions in third-party applications. These steps shift the focus from attempting to control every client-side variable to clear documentation and compartmentalization, reducing dispute risk and speeding incident investigations.
00:00 The Gym Class and the Vault
03:39 The Check Was Always a Person
06:37 Your Tools Ask the Wrong Question
10:27 Why Do We Care?
Supported by:
💼 All Our Sponsors
MSP Radio is supported by our partners:
ABC Solutions · CometBackup · Guardz · HaloPSA · LogMeIn · OpenText · Pax8 · Proofpoint · Rythmz · ScalePad · TimeZest · Transit AI · USecure
Supporting the IT services community through insights, analysis, and transparency.
🚀 Join Business of Tech Plus
Get exclusive access to investigative reports, vendor analysis, leadership briefings, and more.
👉 https://businessof.tech/plus
🎧 Subscribe to the Business of Tech
Want the show on your favorite podcast app or prefer the written versions of each story?
📲 https://www.businessof.tech/subscribe
📰 Story Links & Sources
Looking for the links from today’s stories?
Every episode script — with full source links — is posted at:
🎙 Want to Be a Guest?
Pitch your story or appear on Business of Tech: Daily 10-Minute IT Services Insights:
💬 https://www.podmatch.com/hostdetailpreview/businessoftech
🔗 Follow Business of Tech
LinkedIn: https://www.linkedin.com/company/28908079
YouTube: https://youtube.com/mspradio
Bluesky: https://bsky.app/profile/businessof.tech
Instagram: https://www.instagram.com/mspradio
TikTok: https://www.tiktok.com/@businessoftech
Facebook: https://www.facebook.com/mspradionews
Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

