MSPs are being pushed from technical support to AI strategy advisor
Channel Insider · Jul 22
Executives from NinjaOne, Insight, and Xage Security argue MSPs must evolve into strategic AI advisors as clients expect guidance on adoption, warning that autonomous agents create operational chaos that needs real controls, not just prompt guardrails, and that security has become a machine-versus-machine arms race.
▸ The MSP Angle
What is the MSP's role as clients adopt AI agents?
The clients who once wanted a working laptop now want to know whether to trust an agent with their data and their systems. That advisory seat is the higher-margin one, and it is yours to claim before a consultancy does. Package the judgment: which AI is safe to turn on, who approves what it does, and how usage is watched. Owning the platform those agents run on is what makes the advice enforceable.
Coca-Cola halted all US Fairlife production after ransomware hit OT systems
Coca-Cola disclosed in an SEC filing that a ransomware attack reached production-related systems at its Fairlife subsidiary, temporarily suspending all US output of the roughly $4 billion dairy brand while Canadian operations continued. No threat group was named and no restoration timeline was given.
▸ The MSP Angle
Can ransomware actually stop a company from making its product?
It just stopped a multibillion-dollar brand's entire US line. For clients with any operational technology, plant floors, logistics, physical processes, the breach is not an IT inconvenience, it is lost revenue by the hour. Segment OT from IT, test restores against a production-down scenario, and price business-continuity work against the number this makes concrete.
Ernst & Young breach traces back to a third-party IT support platform
EY disclosed that an unauthorized party accessed a third-party ITSM support-ticket platform used by its tax practice between March 28 and April 12, downloading attachments with client tax and financial data. EY is offering 24 months of credit monitoring, underscoring how much sensitive data pools in support systems.
▸ The MSP Angle
Am I exposed when a vendor or tool I rely on gets breached?
A support-ticket system took down data security at one of the largest accounting firms on earth, and MSPs run ticketing systems for a living. Your PSA, your documentation tool, your RMM: each holds client secrets and each is a target. Inventory what lives in every third-party platform you touch, and make vendor breach response part of the service you sell, not an afterthought.
SonicWall VPN zero-days rated CVSS 10 were exploited before disclosure
SonicWall patched two actively exploited SMA 1000 flaws, an SSRF rated CVSS 10.0 and a post-auth command injection, on models 6210, 7210, and 8200v. Volexity tracked attackers stealing credentials, session databases, and TOTP MFA seeds, and CISA ordered federal agencies to remediate by July 17.
▸ The MSP Angle
Why do VPN appliances keep getting hit first?
Because they sit at the edge holding the keys, and this crew walked off with MFA seeds, which means stolen second factors too. Edge appliances need their own patch SLA, out-of-band, faster than the rest of the fleet. After a credential-and-seed theft like this, rotating passwords is not enough; MFA re-enrollment is the real cleanup.
CISA orders emergency patching of an exploited Oracle E-Business Suite flaw
CISA gave federal agencies until July 18 to patch CVE-2026-46817, an unauthenticated Oracle EBS Payments flaw rated CVSS 9.8 and exploited since June 29. Shadowserver counts more than 1,000 exposed instances, over half in the US, with the fix shipped in Oracle's May update that many customers never applied.
▸ The MSP Angle
How do critical patches sit unapplied for months?
The fix existed in May; attackers had it since June; and 1,000-plus instances are still open in July. That gap is the whole problem, and it is a service. Clients running big ERP and finance systems rarely patch on their own cadence. A managed patch program with proof of what was applied and when is exactly what turns this headline into a retainer.
A hijacked npm package pushed an infostealer that hunts AI-tool credentials
Attackers used stolen publishing credentials to ship malicious jscrambler releases with an install hook that deployed a Rust infostealer targeting AWS, GCP, and Azure credentials, CI tokens, crypto wallets, and API keys stored by Claude Desktop, Cursor, and VS Code. Socket flagged it within six minutes, but 1,479 malicious downloads landed first.
▸ The MSP Angle
Can a software dependency steal my AI tools' credentials?
This one specifically raided the API keys that AI coding tools leave on developer machines, a new prize in an old attack. If your team or your clients build anything, the developer laptop is now a credential vault worth stealing. Lock down build pipelines, pin dependencies, and keep AI-tool keys out of plaintext config where a preinstall script can grab them.
Mira Murati's Thinking Machines ships its first open model, Inkling
Thinking Machines Lab released Inkling, an open-weight 975-billion-parameter mixture-of-experts model with about 41 billion active parameters, claiming roughly a third of the token usage of a rival model on coding. The startup monetizes through its Tinker customization platform rather than the model itself.
▸ The MSP Angle
Do new open models change what MSPs can offer?
Every capable open model widens the menu you can run for clients without locking them to one vendor's pricing or terms. The catch is that open weights are ingredients, not a service; the value is in hosting, governing, and supporting them safely. Model-agnostic delivery means a launch like this is an option to add, not a platform to rebuild.
Empirical Security raises $25M to predict which CVEs attackers will exploit
Empirical Security, founded by Kenna Security veterans and an EPSS co-creator, raised a $25 million Series A ($37 million total) for AI exploit-prediction products that track more than 18,000 exploited CVEs to help teams prioritize which flaws to fix first as vulnerability volume climbs.
▸ The MSP Angle
How do I prioritize patching when everything is critical?
You cannot patch it all, so the win is patching what will actually be attacked. Exploit-prediction is where remediation is heading: rank by real-world exploitation likelihood, not raw CVSS. Whether you buy a tool or build the discipline, a defensible prioritization method is what lets a lean team credibly promise patch coverage across many clients.
AI and cyber take most of the week's biggest venture rounds
Machine-identity vendor Keyfactor took $1 billion from Summit Partners and AI-chip maker SambaNova raised a $1 billion Series F, with AI claiming five of the week's ten largest US venture rounds. Capital keeps concentrating in AI infrastructure and identity security.
▸ The MSP Angle
Where is the smart money going in AI and security?
A billion dollars into machine identity is a tell: as agents proliferate, the hard problem becomes proving who and what is allowed to act. That is a client conversation you can start now, because agent identity and access will land on your desk long before the funded products mature. Watch what gets built here; it becomes your toolset in 18 months.
Gmail's AI writing tool adds free-form custom editing prompts
Google replaced Gmail's preset Help me write refinements with a prompt bar that accepts custom natural-language editing instructions, plus undo and redo, rolling out to rapid-release Workspace domains from July 16 with completion targeted around July 20.
▸ The MSP Angle
Should I worry about new AI writing features in my clients' email?
Not alarm, but oversight. Every new free-form AI prompt in a client tool is another place company data flows into a model, often switched on by default and invisible to the admin who should be deciding. Know which AI features are live in each tenant you manage, decide per client whether they belong on, and put that decision in writing rather than discovering it after the fact.
Do the EU AI Act delays mean MSPs can ignore it for now?
No. The delays apply to high-risk system rules in 2027 and 2028. Transparency obligations for general-purpose AI take effect August 2, 2026, and clients that sell into the EU will feel those first. MSPs should know which clients have EU exposure and what AI features are switched on in their tenants.
How should MSPs price AI services when model costs keep changing?
Price the outcome, not the tokens, and protect the margin underneath with per-client usage budgets and the freedom to switch models when a cheaper equivalent ships. GPT-5.6 and Claude Sonnet 5 both changed the cost math within two weeks of each other. Contracts pinned to a single vendor's pricing age badly.
Are self-hosted AI agent builders safe for clients to run?
Treat them as production attack surface. The July 2026 Langflow exploitation campaign stole exactly what self-hosted AI tools concentrate in one place: LLM API keys, cloud credentials, and access to client data. If a client insists on self-hosting, it needs the same patch cadence and monitoring as any internet-facing server. Most SMB clients are better served by a managed, isolated AI platform.
Can AI agents carry out cyberattacks without human operators?
Yes. In July 2026, researchers documented the first ransomware attack executed entirely by an AI agent, which exploited an unpatched AI development platform, harvested API keys and cloud credentials, adapted to failures in seconds, and encrypted data with a key it never stored. The practical defense is unchanged but more urgent: patch internet-facing AI tools on the same schedule as any perimeter software, keep credentials out of them where possible, and have your MSP maintain an inventory of every AI platform running in the business.
Does using AI at work really lower layoff risk?
The data points that way. Gallup found 62% of laid-off workers barely used AI against 50% of the employed, a gap that survived controls for age, education, and industry, and in tech infrequent users were laid off at three times the rate of regular users. Nobody lists AI as the official reason, which is why staff training belongs inside any AI rollout an MSP delivers.
Should MSPs join vendor AI partner programs like OpenAI's?
Selectively, yes. Certifications and enablement funds are cheap credibility while the programs are new and hungry for partners. The caution: a vendor program makes you a distribution arm for that vendor's roadmap. Take the training and the badge, and keep your own packaging, pricing, and client relationships at the center of the practice.
Does MFA still stop ransomware?
Not by itself anymore. Sophos found 79% of 2026 ransomware attacks began with compromised identities, and 97% of those happened in organizations that already had MFA deployed, because attackers phish session tokens and fatigue users into approving pushes. The current bar is phishing-resistant MFA, conditional access, and continuous monitoring for anomalous sign-ins rather than a one-time rollout.
Do I need to patch the AI features inside mainstream SaaS tools?
Yes. The July 2026 ServiceNow AI Platform flaw (CVE-2026-6875, CVSS 9.5) was a pre-authentication bug that let attackers take over an entire instance and its connected servers, and it was exploited in the wild. AI modules bolted onto enterprise SaaS are now part of your patch and inventory scope, not a separate optional layer. Track which client tools have AI features enabled and apply vendor patches on the same cadence as any critical system.
Am I exposed when a third-party tool or vendor gets breached?
Yes, and it is now one of the most common breach paths. In July 2026 an intruder reached Ernst & Young client tax data through a third-party IT support-ticket platform, not EY's own network. Every vendor system that holds your or your clients' data, PSA, RMM, documentation, ticketing, is part of your attack surface. Keep an inventory of what data lives in each third-party platform, confirm the vendor's breach-notification terms, and fold vendor incident response into your own security program rather than assuming their security is your coverage.