Pax8 · Jul 13
Pax8 survey: 61% of small businesses actively use AI, but a third are stuck in experimentation
Pax8's Q2 2026 SMB AI Pulse survey of 402 US small business leaders found 61% actively using AI and 29% experimenting, with just 1.5% not started, down from 9% in Q1. Nearly one in three AI-using SMBs are stalled in pilot mode, citing lack of expertise (28%), cost and unclear ROI (24%), and security concerns (21%), and only 23% have a documented AI policy.
▸ The MSP Angle
Why do small businesses get stuck between AI pilots and production?
Adoption is no longer the sale; completion is. A third of SMBs are stalled between pilot and production for exactly the reasons a managed practice fixes: expertise, predictable cost, and security. And the 77% with no written AI policy is the easiest first engagement on this list.
Read at Pax8 ↗
BleepingComputer · Jul 15
Threat actor ran 200+ hacking sessions through Google's Gemini CLI
Trend Micro tracked a Russian-speaking actor who drove Google's open-source Gemini CLI through more than 200 sessions as a hands-on attack agent: compromising eight systems at a dental clinic, reaching its OpenDental patient database, and migrating botnet command infrastructure in six minutes with a 5 KB jailbreak playbook. The model troubleshot the attacker's failures at least 59 times.
▸ The MSP Angle
Are attackers really using AI coding tools to hack small businesses?
This was not a lab demo. A real clinic lost real patient data to a rented brain that never gets tired, and free agentic tooling has collapsed the skill floor for intrusion. The defense bar rises to match: monitored endpoints, restricted egress, and someone watching identity anomalies around the clock. Small healthcare clients are exactly the profile that got hit.
Read at BleepingComputer ↗
ChannelBuzz.ca · Jul 14
Rewst rebuilds its MSP automation engine around the Model Context Protocol
Rewst is rebuilding its automation platform around MCP so a technician can describe a business process and have an AI agent assemble the workflow, no deep scripting required. The company points to a shortage of roughly 1,000 automation engineers against some 80,000 MSPs worldwide; the rebuilt platform reaches existing partners in phases through Q3 2026.
▸ The MSP Angle
Can AI agents build MSP automations without scripting skills?
The automation-engineer bottleneck is dissolving across the industry, and MCP is becoming the common rail everything plugs into. The MSPs that win the next two years treat agent-built automation as a billable product line with margins and SLAs, not an internal efficiency trick.
Read at ChannelBuzz.ca ↗
Reuters · Jul 13
TSMC posts a record quarter on AI demand, revenue up 36%
TSMC reported record Q2 2026 revenue of NT$1.27 trillion, about $39.6 billion, up 36% year over year on AI chip demand from customers including Nvidia and Apple; June revenue alone rose 67.9%. The stock is up 57% this year, putting the foundry's market value near $1.96 trillion.
▸ The MSP Angle
What does TSMC's record quarter mean for AI pricing?
Compute supply is still the choke point under every AI product you and your clients touch. Silicon this constrained keeps usage-based pricing volatile, which is why per-client budgets and flat packaging are what make an AI line item safe to sell.
Read at Reuters ↗
BleepingComputer · Jul 4
JadePuffer is the first ransomware campaign run end to end by an AI agent
Sysdig researchers documented JadePuffer as the first known ransomware operation executed end to end by an LLM agent: it exploited CVE-2025-3248 in exposed Langflow servers, stole credentials, planted a cron beacon, pivoted into a production MySQL server, and encrypted 1,342 configuration items. When a login failed, the agent fixed its own payload within 31 seconds.
▸ The MSP Angle
Has ransomware been fully automated by AI yet?
Yes, and the economics matter more than the novelty: an agent that adapts in 31 seconds costs the attacker almost nothing to run at scale. Patch cadence on internet-exposed tooling and tested restores are no longer quarterly hygiene, they are the product your clients are paying you for.
Read at BleepingComputer ↗
PPC Land · Jul 7
FTC policy move could force Colorado to rewrite its AI bias law
The FTC approved a proposed policy statement on July 1 arguing that state laws forcing changes to AI outputs may be preempted because they could push companies into deception under Section 5; comments run through July 31. Colorado's rewritten AI law, SB 26-189, effective January 1, 2027 with penalties up to $20,000 per violation, is the most exposed statute.
▸ The MSP Angle
Will federal preemption kill state AI laws like Colorado's?
Do not let clients read this as a reprieve. Preemption fights take years, Colorado's compliance clock still starts January 1, 2027, and the safest posture, documented AI use with human review on consequential decisions, satisfies every version of the rules that could emerge.
Read at PPC Land ↗
Above the Law · Jul 10
Small law firms are billing more hours per case, the opposite of the AI promise
An analysis of millions of MyCase invoices from April 2024 through March 2026 found small-firm hours per case rose 3 to 7% in most practice areas, with bankruptcy up 32%, while average rates climbed from $262 to $274 an hour. Two years into the AI boom, the promised efficiency has not reached small legal practices.
▸ The MSP Angle
Why is AI not making small law firms more efficient?
Tools do not implement themselves, and that is the whole services opportunity. Professional-services clients buying a subscription and expecting transformation are the ones stalling; the gap between an AI license and a working workflow is exactly what a managed AI practice sells.
Read at Above the Law ↗
BleepingComputer · Jun 30
Prompt injection dressed as a video game tricked six AI browsers into stealing passwords
LayerX researchers wrapped malicious instructions in a BioShock-themed puzzle game and got six agentic browsers, including ChatGPT Atlas, Comet, and Claude's Chrome extension, to exfiltrate passwords from a GitHub repository. OpenAI shipped a working fix, one vendor's patch reportedly remained bypassable, and another closed the report without a fix.
▸ The MSP Angle
Are AI browser agents safe to use with saved passwords?
Treat agentic browsers as unmanaged automation holding your users' credentials. Until the category matures, the sensible client policy is simple: no saved passwords in AI browsers, and agent permissions that ask before they act.
Read at BleepingComputer ↗
Google Workspace Updates · Jul 16
Google Meet AI note-taking defaults are changing for Workspace tenants
Workspace admins can now restrict Gemini's automatic meeting notes to meetings with three or more participants, and the automatic setting defaults to on for Business Standard and Plus editions while staying off for Enterprise. Admin controls roll out through August 3; end-user defaults take effect September 21, 2026.
▸ The MSP Angle
Do I need to change Google Meet AI note-taking settings for my clients?
Yes, review every managed tenant before September 21. Default-on transcription in client meetings is a confidentiality decision someone else just made for your Business-edition tenants. Decide per client whether it matches their obligations, then set it deliberately.
Read at Google Workspace Updates ↗