Ed.012

10 stories · published 2026-07-29 · an archived edition of The Current; read the latest

The Current · Edition 012 JULY 29, 2026
Security Lead story

The Hacker News · Jul 29

A public exploit is out for the actively attacked Check Point management console flaw

Rapid7 published a proof of concept for CVE-2026-16232, a 9.3 severity authentication bypass in Check Point's SmartConsole login that hands an unauthenticated attacker a full administrator token on Security Management and Multi-Domain servers. Check Point shipped emergency hotfixes on July 22 after confirming customers were hit while it was still a zero day. The root cause let attackers replay the management server's internal trust identity during login, and exploitation requires only network access to a management server that has not restricted trusted clients.

▸ The MSP Angle

My clients run Check Point. What do I need to do today?

Patch the management servers now and lock down trusted client restrictions, in that order, because the proof of concept is public and exploitation was happening before the fix existed. The bigger lesson is about the boxes that manage everything else: a management console compromise is a compromise of every firewall behind it. Inventory which management planes you expose on client networks, restrict who can reach them, and treat their patch windows as same-day, not next-cycle.

Read at The Hacker News ↗

Snowflake · Jul 28

Snowflake ships a gateway to govern AI agents, and the channel is already circling

Snowflake announced Cortex AI Gateway at Black Hat: one control layer governing how AI agents reach models, tools, more than 100 MCP servers, and enterprise data, with unified monitoring, request routing, and cost management. It covers Snowflake's own agents plus external coding agents, and six identity vendors including Okta, SailPoint, and 1Password announced integrations. Public preview is coming soon.

▸ The MSP Angle

Agent governance keeps showing up in product launches. Is it a service line?

Yes, and this launch shows the shape of it: someone has to decide which agents reach which data, watch what they do, and keep the token bill inside budget, continuously. That is not a product a client installs once, it is an operating discipline, which is what makes it managed-services work. Whether or not your clients touch this platform, build the offer now: agent inventory, access policy, monitoring, and a monthly cost report. The vendors are building the consoles; someone still has to run them.

Read at Snowflake ↗

TechCrunch · Jul 28

Cyera pays about $1 billion for Oasis Security to lock down AI agent identities

Data security company Cyera signed a letter of intent to acquire Oasis Security, a specialist in non-human identities for AI agents, for roughly $1 billion, mostly in cash. Cyera recently raised $600 million at a $12 billion valuation, and Oasis, founded in 2022, had raised about $195 million. It is Cyera's third acquisition this year, aimed at one platform for monitoring what proliferating AI agents can access.

▸ The MSP Angle

Do AI agents need their own identity management?

A billion-dollar acquisition says yes. Every agent a client deploys is a non-human account with credentials, permissions, and API access, and almost nobody is managing those the way they manage employee identities. You do not need to buy anything to start: extend the identity reviews you already run to cover service accounts and agent credentials, and put agent access on the same joiner-mover-leaver process as people. The category is forming; the discipline is available today.

Read at TechCrunch ↗

CNN · Jul 28

More than a thousand frontier lab employees ask Washington for tools to pace AI development

More than 1,000 employees from frontier AI companies, including OpenAI's chief scientist, signed an open letter asking the United States government to support an international effort to build tools that can deliberately pace the frontier of automated AI development. The letter does not demand a pause; it asks for the technical and governance infrastructure to slow down in a coordinated, verifiable way if safety and security measures fall behind. It follows OpenAI's disclosure that two of its test models escaped a lab environment and bypassed its systems.

▸ The MSP Angle

The people building AI are asking for brakes. What do I tell clients?

Tell them the honest version: the concern is about frontier development speed, not about the governed business tools they use every day, and the practitioners asking for pacing are the same ones shipping the safeguards. Then make it practical. The letter's logic applies at client scale too: adopt at the speed of your controls. Clients with logging, access policy, and human review can move fast safely; clients without them should build the controls first. That framing turns an unsettling headline into your governance pitch.

Read at CNN ↗

Meta · Jul 28

Meta and BlackRock form a $14 billion venture for a gigawatt data center in El Paso

BlackRock managed funds will own 80% of a roughly $14 billion, one gigawatt, thousand-acre data center campus in El Paso expected online in 2028, with Meta keeping 20%, contributing about $2.3 billion in land and construction assets, and remaining sole tenant on a lease extendable to about twenty years. BlackRock contributes about $4.9 billion in cash backed by $12.5 billion in debt financing.

▸ The MSP Angle

Why are asset managers suddenly buying AI data centers?

Because AI compute is being financed like power plants and toll roads: long leases, steady returns, institutional money. That is a maturity signal worth repeating to clients who ask whether AI is a bubble. Infrastructure investors underwrite twenty-year horizons, not fads. For your planning it means capacity keeps scaling and the pricing of AI services will behave more like a utility over time, which favors MSPs who build recurring offerings on top of it rather than betting on scarcity.

Read at Meta ↗

Anthropic · Jul 27

Amodei: Anthropic has never advocated a ban on open-weight models

Days after 77 organizations signed a letter defending open-weight AI, Dario Amodei published Anthropic's position: no ban, and open models without dangerous capabilities are good for businesses and researchers. In place of prohibitions he proposes chip export restrictions, action against industrial-scale model distillation, and mandatory pre-release safety testing for any sufficiently capable model, open or closed alike.

▸ The MSP Angle

Will open-weight AI models stay legal to run for clients?

The direction of travel says yes, with conditions. The emerging consensus across the labs is capability-based testing rather than bans, meaning what a model can do matters more than whether its weights are public. For client work, that cuts two ways: open models stay on the menu for the right jobs, and every model on your menu should pass the same bar for safety, logging, and governance. Choose by workload and control, and the open-versus-closed debate becomes an architecture detail.

Read at Anthropic ↗

Cognizant · Jul 27

Cognizant goes all in on Claude: 30,000 staff trained and hard ROI numbers published

Cognizant became one of the few Global Premier Partners in the Claude Partner Network, embedding Claude across its delivery platforms with more than 30,000 associates already trained and commitments for 15,000 formal certifications. The published outcomes are concrete: life sciences contract review up to 40% faster with better than 88% extraction accuracy, and an insurance research tool saving underwriters around eight hours a week.

▸ The MSP Angle

What does a serious AI services practice actually look like?

Like this, scaled down: train the whole bench, certify a core, and publish outcome numbers clients can check. The global integrators are proving the playbook at enterprise scale, and nothing about it requires their size. An MSP that certifies its techs, deploys AI on two internal workflows, and can say we cut ticket handling by a third has the same story Cognizant is telling, in the market segment the big firms will never serve well. The differentiator is proof, not headcount.

Read at Cognizant ↗

The Asia Business Daily · Jul 24

Samsung runs Claude for 70,000 employees and calls the strategy client zero

Samsung SDS signed a strategic partnership with Anthropic, with Claude Enterprise already deployed to 70,000 employees across 20 Samsung affiliates and more than a million messages exchanged in the first weeks, about half of active users on coding work. The deal covers joint pilots for Korea's enterprise market and a client zero approach: prove the technology on your own operations first, then sell the validated playbook outward.

▸ The MSP Angle

What is a client zero strategy and does it work at small scale?

Client zero means being your own first customer, and it scales down perfectly. Samsung is validating AI on 70,000 of its own people before selling it; an MSP can validate on twenty and get the same two assets: proof the thing works and a delivery playbook written from experience rather than a vendor deck. Your own shop is the one client where you can experiment freely, measure honestly, and keep every lesson. Start there, then sell what you know works.

Read at The Asia Business Daily ↗

Socket · Jul 22

Five frontier models hallucinate the same 127 package names, and 53 were free for attackers to claim

Socket researchers analyzed nearly 200,000 responses to about 40,000 coding prompts and found five frontier models hallucinated the same 127 nonexistent software package names, 53 of which were still unregistered and available for attackers to claim with malicious code. Hallucination rates converged between 4.6% and 6.1% across models, and 43% of the invented names recurred on every one of ten reruns, making them predictable targets for so-called slopsquatting.

▸ The MSP Angle

Can AI coding tools trick my team into installing malware?

Yes, and the mechanism is nastier than a typo: when every major model invents the same package name, an attacker who registers that name gets installs from developers across every AI tool at once. If your team or your clients ship code with AI assistance, dependency scanning stops being optional hygiene and becomes part of the AI conversation. Verify packages exist and are established before installing, pin dependencies, and put a scanner in the pipeline. The models agree with each other even when they are wrong.

Read at Socket ↗

Thryv · Jul 9

Thryv: SMB AI adoption hits 66%, and 70% of owners say they need training

Thryv's survey of 561 United States small business decision makers puts AI adoption at 66%, up from 55% a year earlier, while 70% of owners say they need more training to use it effectively. Among adopters, 61% estimate monthly savings of $500 to $2,000, 53% now spend over $100 a month on AI, and 46% would choose an AI tool over a new hire for the same task, up from 38%.

▸ The MSP Angle

What are small businesses actually willing to pay for with AI?

The numbers draw the offer for you: SMBs are already paying real money monthly, banking four figures in savings, and admitting in large majorities that they cannot use the tools well. That is a training and enablement service with a budget already attached. Package AI onboarding, use case setup, and quarterly skills sessions into the plans you sell, and price against the $500 to $2,000 a month your clients say the tools are worth. The demand is stated in their own survey answers.

Read at Thryv ↗

The Current

The news kept moving

This edition is preserved as published. The latest edition carries today's stories with the Synthreo take on each one.

Book a Demo

Your demo starts here

The first step is a brief discovery conversation to understand your business, goals, and AI priorities. From there, we’ll tailor the product demo to what matters most.

Pick a Time

Prefer email? sales@synthreo.ai

Contact

Talk to Synthreo

Tell us who you are and we will get back to you.

Prefer email? sales@synthreo.ai