The Register · Oct 3
A flaw an AI model found in a popular file server was under attack within 24 hours
Horizon3 researcher Zach Hanley used Anthropic's Mythos model to find CVE-2026-61500, a critical authentication bypass in Rejetto HTTP File Server that leads to remote code execution. Mythos worked out that the server's random number generator was fully reversible and leaking outputs, which lets an attacker forge session cookies. Exploitation began the evening after disclosure, first from a China-hosted address against servers in the US and Japan; version 3.2.1 fixes it.
▸ The MSP Angle
How fast do I need to patch now that AI is finding vulnerabilities?
Assume the window between disclosure and attack is one day for anything internet facing. Small file servers and utilities like HFS are exactly the shadow infrastructure that never makes the patch list, so scan client perimeters for them and either patch to 3.2.1 or pull them offline. Build an emergency patch lane for exposed services that runs in hours, separate from the monthly cycle.
Read at The Register ↗
U.S. Chamber of Commerce · Oct 2
Small business AI use hit 66%, and the Chamber says it is adding jobs four to one
The U.S. Chamber of Commerce's fifth annual small business technology report found 66% of small businesses now use AI, up from 23% in 2023. Some 25% say AI is creating permanent jobs at their firm against 6% using it to cut headcount, and AI users are 10% more likely to have added staff in the past year. Six in ten worry about litigation and compliance costs from a patchwork of state privacy and AI laws, and 41% now run six or more technology platforms.
▸ The MSP Angle
Are most small businesses actually using AI now?
Yes, two in three by this count, which means your clients are already using it with or without you. The opening is the gap the data exposes: more platforms to manage, more state rules to track, and staff who need training. Lead client reviews with an inventory of what AI is in use and who governs it, then sell the rollout, training and compliance work as a managed service.
Read at U.S. Chamber of Commerce ↗
KQED · Sep 30
California bans firing by algorithm and AI that reads workers' emotions
Governor Newsom signed a slate of AI workplace laws on September 30. SB 947 bars employers from relying solely on automated systems to fire or discipline workers starting July 1, 2027, SB 951 requires 60 days' notice when AI drives layoffs of 25% or more of a workforce, and AB 1883 restricts AI surveillance including emotional inference and neural data. He vetoed a bill that would have protected health care workers who override unsafe AI recommendations.
▸ The MSP Angle
Do California's new AI workplace laws apply to my small business clients?
If they employ people in California, plan as if yes. The practical work is an inventory of every HR, scheduling, monitoring and productivity tool with AI features, then a documented human review step before any discipline or termination decision. Turn off emotion and sentiment analysis in monitoring tools now, since that is restricted and easy to forget is switched on.
Read at KQED ↗
TechCrunch · Oct 2
Apple will make it harder for AI agents to get Full Disk Access on Macs
Apple said it will require very explicit user action before macOS grants Full Disk Access, the permission that exposes files, messages, mail and browsing history. The company said some developers use the permission in ways that expose everything on a system, and that the risk grows as AI agents become more capable and autonomous. Apple has not given a release date or named the macOS versions affected.
▸ The MSP Angle
Should I let AI agent apps have Full Disk Access on company Macs?
Not by default. Audit which apps already hold Full Disk Access across your managed Macs, revoke it for any AI assistant or agent that does not strictly need it, and use your MDM's privacy preference controls to stop users from granting it on their own. Apple tightening the prompt helps, but a managed policy is what actually holds.
Read at TechCrunch ↗
The Hacker News · Oct 2
GitLab patched a 9.9 sandbox escape in its self-hosted AI gateway
GitLab fixed CVE-2026-90970, a CVSS 9.9 prompt template flaw that let a logged-in user with Duo Agent Platform access escape the sandbox and run arbitrary commands on self-hosted AI Gateway instances. Fixed versions are 19.2.4, 19.3.2 and 19.4.1, there is no fix below 18.1.6, and GitLab.com and Dedicated customers are not affected. It is the second critical template engine bug in the gateway this year, after one in February.
▸ The MSP Angle
Do self-hosted AI tools need the same patching as other servers?
Yes, and often faster, because they run with broad access and any authenticated user can be the attacker. If a client self-hosts GitLab with the AI gateway, upgrade now and check who holds agent platform access. Fold every self-hosted AI component into your vulnerability scanning and patch SLAs instead of leaving it to the dev team.
Read at The Hacker News ↗
Google · Sep 30
Google's Gemini 4 Argon launched for vetted cyber defenders first, at $2 and $10 per million tokens
Google DeepMind's Gemini 4 Argon is rolling out first to trusted cyber defenders through its Fairwind Program, with paid API customers and Google AI Ultra subscribers next and no date given. Introductory pricing is $2 per million input tokens and $10 per million output tokens, rising to $4 and $20 later, with output limits expanded to 1 million tokens. Google reports 77.9% on DeepSWE v1.1 and 51.3% on AutomationBench, figures no third party had reproduced at launch.
▸ The MSP Angle
Should I plan around a new AI model's introductory pricing?
No. Argon's published path doubles the price after the introductory period, so model it at $4 and $20 when you quote any service built on it. Benchmark it on your own workloads once access opens, and keep your automations portable so you can move between models as pricing and availability shift.
Read at Google ↗
ChannelPro · Oct 2
MSP Summit speakers told providers to sell the outcome and treat AI as plumbing
At MSP Summit 2026 in Orlando, Pisces Growth Consulting's Megan Killion argued that strategic value requires a specific buyer, workflow and outcome, with AI as the enabler rather than the pitch. Pax8's Chance Weaver said about 80% of client situations can be solved with automation or business intelligence, while CloudBlue's Tarik Faouzi warned that untracked token consumption erodes margins. ConnectWise's David Raissipour urged MSPs to retrain technicians for higher-value roles rather than add headcount.
▸ The MSP Angle
How should an MSP package AI services so clients actually buy them?
Name the buyer, the workflow and the result, then price that, not the model. Start with one offering bundled into an existing service, track token consumption per client from day one so margins stay visible, and expand only after delivery is repeatable. Discovery comes first: most client asks turn out to be automation problems, which is good news for margin.
Read at ChannelPro ↗
Newsbytes.PH · Oct 3
AMD says splitting agent workloads between local PCs and the cloud cuts costs 40% to 60%
AMD's Asia Pacific general manager Alexey Navolokin said token consumption climbs fast once agents move from occasional prompts to continuous departmental workloads. AMD's analysis puts three-year savings at 40% to 60% for a 500-PC fleet running half its AI work locally, and estimates one AI workstation at about $6,533 over three years against $81,108 for equivalent cloud usage. These are vendor figures built to sell hardware.
▸ The MSP Angle
Is it cheaper to run AI agents locally instead of in the cloud?
Sometimes, for steady, high-volume work, and almost never for bursty use. Treat AMD's numbers as a vendor case and run your own: measure each client's token spend per workflow for a month, then price local hardware only for the workloads that run all day. The deliverable worth selling is the right-sizing analysis itself, refreshed as model prices fall.
Read at Newsbytes.PH ↗
Engadget · Oct 1
A judge threw out Penske and Chegg's lawsuits over Google's AI Overviews
Judge Amit Mehta dismissed antitrust suits from Penske Media and Chegg, which argued that Google's AI Overviews repackage publisher content and divert readers without fair compensation. Mehta, who ruled in 2024 that Google holds a search monopoly, found the plaintiffs had not shown Google illegally used that power against them, writing that an expectation of search traffic is not an agreement. The ruling leaves AI summaries in search results unchallenged for now.
▸ The MSP Angle
Will AI search summaries keep cutting traffic to my clients' websites?
Plan as if they will, since this ruling removes a near-term legal check. Clients that depend on organic search should measure traffic from AI summaries and answer engines separately, structure their pages so they get cited rather than skipped, and build direct channels like email and repeat customers that do not rely on a search click.
Read at Engadget ↗