Help Net Security · Oct 1
Google: flaws found by AI are twice as likely to allow remote code execution
Google Threat Intelligence Group found that 50% of vulnerabilities discovered by AI enable remote code execution, against 26% of those found other ways, while monthly CVE disclosures doubled from 5,045 in January to 10,740 in August. One AI-found command injection flaw in BeyondTrust's remote access tools was exploited within four days of disclosure and by five threat clusters within seven. Half of this year's 2,076-plus AI software vulnerabilities hit agent orchestration frameworks such as Flowise and Langflow.
▸ The MSP Angle
How should an MSP prioritize patching now that AI is finding more vulnerabilities?
By exploitation risk, not volume, since only about 1 in 431 disclosed flaws was exploited but the AI-found ones skew severe and get weaponized in days. Put internet-facing remote access and privileged access tools at the top of the queue with a patch window measured in days. If you or your clients run agent builders like Flowise or Langflow, inventory them now, because they are where half of this year's AI software flaws landed.
Read at Help Net Security ↗
Yahoo Finance · Oct 1
Heartland Forward: 43% of small businesses use AI, and 70% say it helps the bottom line
A Heartland Forward survey of 691 small business owners, fielded by Echelon Insights September 3 to 11, found 43% use AI and 70% of users report a net-positive effect on their finances. Among users, 93% say it saves time, more than half save five or more hours a week, 81% get more done with existing staff, and 20% have hired because of AI-driven growth. Only 12% completed formal training, with 83% self-taught, and among non-users 52% see no need while just 6% each cite cost or complexity.
▸ The MSP Angle
Why are small businesses not using AI yet?
Mostly because they do not see where it fits, not because of price or difficulty, so a feature pitch will not move them. Lead with a specific workflow and the hours it saves, since time savings is what users actually report. The 83% self-taught figure is your opening for paid training and guided rollout: users are already sold, and nobody has shown them how to do it well.
Read at Yahoo Finance ↗
Anthropic · Oct 1
Barclays says Claude now sorts 120,000 emails a day and helps 16,000 staff
Barclays expanded its work with Anthropic on October 1, reporting that its Claude-based Colleague Knowledge Assistant serves more than 16,000 staff and has handled over 1 million searches since launching in 2025. In Global Markets, Claude processes and routes about 120,000 emails a day, cutting manual triage. The bank expects half its developers to use Claude Code by the end of 2026 and most of them by 2027.
▸ The MSP Angle
What are the most practical first AI projects for a business?
The two Barclays wins are internal knowledge search and inbox triage, and both scale down to a 30-person firm. Start clients there because the data already exists, the result is easy to measure in searches answered or emails routed, and a wrong answer is caught by a person before it reaches a customer. Package those two as a fixed-scope starter project before anyone talks about autonomous agents.
Read at Anthropic ↗
Channel Insider · Oct 2
Vectra AI launched a partner program built around selling AI security services
Vectra AI introduced its global Ascent Partner Program for resellers, MSSPs and integrators, organized around co-selling, co-marketing, co-delivery and co-innovation. Partners get an enablement path from introductory to advanced training, services-focused certifications, and rebates and incentives tied to growing capability. The program encourages partners to lead with security assessments and attach consulting and managed services to licenses rather than push rip-and-replace.
▸ The MSP Angle
Are security vendors paying MSPs more for services than for license resale?
Increasingly, yes, and this program is built that way, with rebates tied to capability rather than seat count. Use that to restructure your own security offers around an assessment first and a managed service second, with the license as a line item. Before you sign, check that the incentives reward delivery you actually do, and that the vendor's co-delivery does not put its own people in front of your clients.
Read at Channel Insider ↗
Channel Insider · Sep 28
Wiz opened an MSP program with one console for every client's cloud and AI security
Wiz announced its Partner Alliance Managed Service Provider Program on September 28, now in public preview, for delivering cloud and AI application security from its AI-APP platform. Wiz Tenant Manager gives providers a single console with aggregated findings, tenant groups, baseline policies that can be overridden per client, and role-based, audited access into each environment. Wiz advertises just-in-time provisioning and consumption billing without upfront annual commitments, but did not publish pricing or minimums.
▸ The MSP Angle
Can an MSP offer cloud and AI security without an annual vendor commitment?
Wiz says so, which removes the usual barrier of buying capacity before you have clients to fill it. The multi-tenant console and group policies are what make a managed offer profitable, so test those first in the preview. Get pricing, minimum consumption and preview eligibility in writing before you quote anything, because none of it was published.
Read at Channel Insider ↗
Connecticut Public · Sep 29
Connecticut's AI law starts taking effect, with hiring rules to follow in a year
Parts of Connecticut's AI law, Public Act 26-15, took effect October 1, including disclosure requirements for AI subscriptions, whistleblower protections for people building large frontier models, and standard definitions of AI technology. Companies using automated decision tools in employment must have a compliance framework by October 1, 2027, with plain-language notice to applicants and employees about when and how AI influences decisions. Sen. James Maroney called the law "the floor" and the Attorney General's Office holds enforcement authority.
▸ The MSP Angle
Do we have to tell job applicants when AI is used in hiring?
In Connecticut you will, by October 2027, and other states are moving the same way, so treat notice as the default. Inventory which client tools touch hiring today: resume screeners, scheduling bots, interview scoring. Help clients write the plain-language notice and keep a record of where AI informs a decision, because using a tool does not shield them from discrimination claims.
Read at Connecticut Public ↗
Challenger, Gray & Christmas · Oct 1
AI fell to fifth among layoff reasons in September, yet still leads for the year
U.S. employers announced 43,281 job cuts in September, the lowest September total since 2022, and AI was cited for 3,961 of them, about 9% and fifth among reasons. AI remains the top reason for the year at 120,136 cuts, or 21% of the total. Technology companies cut 10,799 jobs in September and 165,925 so far this year, 29% of all announced cuts.
▸ The MSP Angle
Are companies still cutting jobs because of AI?
Less than in the spring, but AI is still the largest single reason cited this year, and most of those cuts landed in tech. For your SMB clients the pattern is redeploying staff rather than layoffs, and that is the message to bring: AI that absorbs growth without new hires. Watch your own hiring plans too, since entry-level service desk work is exactly what agents now handle first.
Read at Challenger, Gray & Christmas ↗
HotHardware · Sep 28
Nvidia and about 100 partners launched a platform to box in rogue AI agents
Nvidia's Open Agent Safety Platform pairs OpenShell, an Apache-licensed runtime that sandboxes agents with no direct network access except through a supervisor that checks each request, with a proprietary hardware watchdog on BlueField-4 DPUs that can quarantine an agent in milliseconds. OpenShell runs on x86 and Arm and is on GitHub, while the watchdog currently runs only on Nvidia servers. Partners include Anthropic, Cisco, CrowdStrike, Hugging Face, Palo Alto Networks and Salesforce; Google, OpenAI, Meta, AMD and Intel are absent.
▸ The MSP Angle
How do you stop an AI agent from going outside its permissions?
Put the boundary outside the agent: a sandbox with no direct network path, a gateway that checks every outbound call against policy, and a monitor the agent cannot switch off. OpenShell gives you the first two for free on ordinary hardware, so it is worth piloting for any agent you host for clients. Treat it as one layer, alongside scoped credentials and human approval before data or permissions change.
Read at HotHardware ↗
Cloudflare · Oct 1
Cloudflare open-sourced Clef, models that pick an agent's next step in about 39 milliseconds
Cloudflare released Clef, a 27 billion parameter decision model, and Clef-Flash, a 9 billion parameter version, which return structured choices with probability scores instead of generated text. Clef-Flash posted a 38.8 millisecond median latency and Clef 209.3 milliseconds, and in Cloudflare's tests Clef classified a domain in 2.2 seconds against 4.7 seconds for the fastest general model tried. Both are Apache 2.0 on Hugging Face and hosted on Workers AI, alongside a new reinforcement learning fine-tuning offering.
▸ The MSP Angle
Do AI agents need a large language model for every decision?
No, and routing every ticket-triage or classification step through a frontier model is how agent costs run away. Small decision models like these handle the yes, no and which-queue calls faster and more predictably, with the big model reserved for writing and reasoning. When you design client agents, split the routing from the drafting and price each part on what it actually costs to run.
Read at Cloudflare ↗