Cisco Talos · Sep 22
Cisco Talos found malware that lets four AI models vote on its next move
Talos published an analysis on September 22 of CLOSEDQUORUM, a 64-bit Windows implant written in Go that sends host details to up to four commercial models, including DeepSeek, Qwen, Mistral and Gemini, and runs whichever action wins a plurality vote: steal, inject, persist or move. It targets LSASS memory, saved passwords in Chrome, Edge and Firefox, and crypto wallets, then reports to its operator through a Discord webhook. The build Talos found shipped with placeholder keys and has no confirmed in-the-wild use, but development builds show real provider credentials being injected at build time.
▸ The MSP Angle
How do we detect malware that uses AI models to make decisions?
Watch behavior, not domains, because blocking every AI provider breaks legitimate work. Talos's list is a good starting rule set: AI API traffic from an unexpected Windows executable, calls to several model providers within seconds, LSASS access alongside process injection, and Discord webhooks from odd processes. If your EDR or SIEM cannot alert on which process is talking to an AI endpoint, that is the gap to close this quarter.
Read at Cisco Talos ↗
Fortune · Sep 24
OpenAI's GPT-6 Cyber is coming, with a product to fence it in
Fortune reported on September 24 that OpenAI will preview GPT-6 Cyber within weeks, its fourth security-tuned model this year after cyber editions of GPT-5.4, 5.5 and 5.6. Access is limited to the application-only Daybreak Red program for alpha testing, and OpenAI plans a companion product to run automated patching workflows while giving it oversight of how the model is used. More launches are expected at DevDay on September 29.
▸ The MSP Angle
Will MSPs get access to AI models built for security work?
Not directly at first, since access runs through vetted programs and the security vendors in them. Expect these capabilities to reach you inside the EDR, vulnerability and patching tools you already resell, so ask those vendors which models they are building on and how usage is monitored. The companion product matters more than the model: automated patching still needs change control that you own.
Read at Fortune ↗
VentureBeat · Sep 22
Anthropic and OpenAI cut flagship model prices within hours of each other
OpenAI released GPT-6 Sol at $2 input and $10 output per million tokens and GPT-6 Luna at $0.10 and $0.50 on September 22, both at least 50% below the GPT-5.6 versions they replace, and a spokesperson called the rates permanent. The same day Anthropic launched Claude Opus 5.5 at $4 and $20, down 20% from Opus 5, with cache reads cut 60% to $0.20 and typical workloads running 40% cheaper. OpenAI is pitching cost per completed task, claiming Sol finishes AutomationBench tasks at $0.27 each.
▸ The MSP Angle
Should we reprice our AI services when model costs drop?
Not by passing every cut straight through, but you should rerun the math on anything priced against last quarter's token costs. Tie client pricing to the outcome delivered, and keep a model routing layer so cheaper tiers like Luna handle extraction and summaries while flagship models take the hard work. The margin from a price cut belongs to whoever can switch models fastest.
Read at VentureBeat ↗
GeekWire · Sep 23
Amazon lets sellers run their stores through Claude without opening Seller Central
At its Accelerate conference on September 23, Amazon launched a U.S. beta plugin that lets independent sellers manage inventory, pricing, listings and analytics through Anthropic's Claude or Amazon's Quick assistant. Sellers pick which data types the agent can read and must approve every action before it runs, and Amazon says setup takes about 60 seconds with no code. Amazon says about 90% of sellers already use outside AI tools, and every primary account holder gets 12 free months of Quick Plus through December 31.
▸ The MSP Angle
Is it safe to let an AI agent make changes in a client's ecommerce account?
It can be, if approval stays on every write action and the agent sees only the data it needs, which is the model Amazon chose here. Help retail clients set that up deliberately: a dedicated account, least-privilege data scopes, and a log of what was approved and by whom. The bigger signal is that major platforms now expect agents at the controls, so every SaaS app your clients use will need an agent access policy.
Read at GeekWire ↗
PYMNTS · Sep 24
Anthropic, Google and OpenAI plan their own AI safety standards body
Anthropic, Google and OpenAI aim to launch the Standards Authority for Frontier AI by the end of 2026 or early 2027, according to a September 24 report citing The Information. The self-regulatory body would support third-party testing before deployment, set protocols for reporting safety and security incidents, define the labs' voluntary commitments, and set qualifications for independent auditors. The companies first pursued a public-private partnership, which stalled, and critics worry the group could shut out open-source developers and smaller rivals.
▸ The MSP Angle
Will AI industry safety standards affect which vendors our clients can use?
Probably, the same way security frameworks shape vendor questionnaires today. If incident reporting and auditor qualifications get defined here, expect clients and insurers to start asking whether a vendor follows them. Build that question into your AI vendor reviews now, and watch whether the open-weight models you deploy for privacy reasons end up outside the tent.
Read at PYMNTS ↗
UN News · Sep 23
The UN Security Council held its first briefing on losing control of AI
The Security Council held its first high-level briefing on the safety risks of frontier AI on September 23, chaired by France, with OpenAI's Sam Altman, Anthropic's Dario Amodei and Turing Award winner Yoshua Bengio among the briefers. Bengio warned that uncontrolled AI systems are a threat no country can contain alone, and the lab leaders urged the Council to back international standards. The UN pointed to the Global Digital Compact and the UN's new Independent International Scientific Panel on AI.
▸ The MSP Angle
Does international AI regulation matter for a small business?
Not directly, and no treaty will land on an SMB this year. What does trickle down is vocabulary: incident reporting, pre-deployment testing and third-party evaluation are showing up in vendor contracts, cyber insurance forms and state bills. Clients who already log their AI tools and incidents will find each new rule cheaper to meet.
Read at UN News ↗
Yahoo Finance · Sep 23
MSP 501 survey: 57% of MSPs expect AI to be a top revenue gainer
Informa's 2026 MSP 501 report, released September 23, found 57% of respondents expect AI to rank among their biggest revenue gainers over the next year, up from 37%, second only to managed security. Nearly a third project AI revenue growth above 20% this year, 91% offer or use AI solutions (up from 79%), and 36% now build custom AI solutions, up from 21%. Across the list, recurring revenue grew 11.9% while headcount grew 6.9%.
▸ The MSP Angle
How are other MSPs making money from AI services?
The fastest movers have shifted from reselling AI licenses to building custom solutions, which is where the jump from 21% to 36% sits. Start with productivity and repetitive work inside your own shop, the top two uses in the survey, then package what worked for clients with a measurable outcome attached. Revenue growing faster than headcount is the whole argument, so track that ratio for yourself.
Read at Yahoo Finance ↗
Journal of Accountancy · Sep 15
Korn Ferry: AI raised efficiency for 63% of workers and workload for 52%
Korn Ferry's Workforce 2026 survey of more than 16,000 employees found 63% say AI tools made them more efficient, but 52% say more tasks are now expected of them, and 64% say their employers prioritize efficiency over new ways of creating value. Sixty-two percent report their workload rose significantly over two years, 61% feel they are doing multiple roles, and 49% are exhausted by the pace of change. Only 58% feel fairly rewarded for the extra load.
▸ The MSP Angle
Why aren't AI productivity gains making my team less busy?
Because freed-up hours get refilled by default unless someone decides where they go. Before an AI rollout, agree on what the saved time is for, whether that is advisory work, more clients per tech, or simply less overtime, and measure it. Clients hear the same story from their staff, which makes change management a service you can sell alongside the tooling.
Read at Journal of Accountancy ↗
Yahoo Finance · Sep 21
AMD crossed $1 trillion in market value on AI data center demand
AMD shares rose about 10% to more than $615 on September 21, lifting its market value above $1 trillion for the first time as chip stocks rallied. The stock is up nearly 290% this year on demand for AI infrastructure after the company beat estimates in early August. Nvidia still leads the sector at more than $5 trillion.
▸ The MSP Angle
Will more competition in AI chips lower costs for my clients?
Over time, yes, because a credible second supplier puts pressure on what AI compute costs. The near-term effect for SMBs is indirect: cheaper inference flows through to API rates and to the tools you resell. Keep contracts short enough to capture those drops instead of locking clients into today's pricing for three years.
Read at Yahoo Finance ↗