← The Current Ed. 007 Beat

Security

The AI attack surface: exploited vulnerabilities in AI tooling, credential theft, shadow AI, and the rise of agent-assisted security operations. AI concentrates exactly what attackers want, keys, data, and access, in new places. MSPs are paid to protect all three, which makes this the beat with the shortest path from headline to client action.

Security · 5 stories this edition Ed. 007
Security

TechCrunch · Jul 16

Coca-Cola halted all US Fairlife production after ransomware hit OT systems

Coca-Cola disclosed in an SEC filing that a ransomware attack reached production-related systems at its Fairlife subsidiary, temporarily suspending all US output of the roughly $4 billion dairy brand while Canadian operations continued. No threat group was named and no restoration timeline was given.

▸ The MSP Angle

Can ransomware actually stop a company from making its product?

It just stopped a multibillion-dollar brand's entire US line. For clients with any operational technology, plant floors, logistics, physical processes, the breach is not an IT inconvenience, it is lost revenue by the hour. Segment OT from IT, test restores against a production-down scenario, and price business-continuity work against the number this makes concrete.

Read at TechCrunch ↗
Security

BleepingComputer · Jul 17

Ernst & Young breach traces back to a third-party IT support platform

EY disclosed that an unauthorized party accessed a third-party ITSM support-ticket platform used by its tax practice between March 28 and April 12, downloading attachments with client tax and financial data. EY is offering 24 months of credit monitoring, underscoring how much sensitive data pools in support systems.

▸ The MSP Angle

Am I exposed when a vendor or tool I rely on gets breached?

A support-ticket system took down data security at one of the largest accounting firms on earth, and MSPs run ticketing systems for a living. Your PSA, your documentation tool, your RMM: each holds client secrets and each is a target. Inventory what lives in every third-party platform you touch, and make vendor breach response part of the service you sell, not an afterthought.

Read at BleepingComputer ↗
Security

BleepingComputer · Jul 14

SonicWall VPN zero-days rated CVSS 10 were exploited before disclosure

SonicWall patched two actively exploited SMA 1000 flaws, an SSRF rated CVSS 10.0 and a post-auth command injection, on models 6210, 7210, and 8200v. Volexity tracked attackers stealing credentials, session databases, and TOTP MFA seeds, and CISA ordered federal agencies to remediate by July 17.

▸ The MSP Angle

Why do VPN appliances keep getting hit first?

Because they sit at the edge holding the keys, and this crew walked off with MFA seeds, which means stolen second factors too. Edge appliances need their own patch SLA, out-of-band, faster than the rest of the fleet. After a credential-and-seed theft like this, rotating passwords is not enough; MFA re-enrollment is the real cleanup.

Read at BleepingComputer ↗
Security

BleepingComputer · Jul 16

CISA orders emergency patching of an exploited Oracle E-Business Suite flaw

CISA gave federal agencies until July 18 to patch CVE-2026-46817, an unauthenticated Oracle EBS Payments flaw rated CVSS 9.8 and exploited since June 29. Shadowserver counts more than 1,000 exposed instances, over half in the US, with the fix shipped in Oracle's May update that many customers never applied.

▸ The MSP Angle

How do critical patches sit unapplied for months?

The fix existed in May; attackers had it since June; and 1,000-plus instances are still open in July. That gap is the whole problem, and it is a service. Clients running big ERP and finance systems rarely patch on their own cadence. A managed patch program with proof of what was applied and when is exactly what turns this headline into a retainer.

Read at BleepingComputer ↗
Security

Socket · Jul 11

A hijacked npm package pushed an infostealer that hunts AI-tool credentials

Attackers used stolen publishing credentials to ship malicious jscrambler releases with an install hook that deployed a Rust infostealer targeting AWS, GCP, and Azure credentials, CI tokens, crypto wallets, and API keys stored by Claude Desktop, Cursor, and VS Code. Socket flagged it within six minutes, but 1,479 malicious downloads landed first.

▸ The MSP Angle

Can a software dependency steal my AI tools' credentials?

This one specifically raided the API keys that AI coding tools leave on developer machines, a new prize in an old attack. If your team or your clients build anything, the developer laptop is now a credential vault worth stealing. Lock down build pipelines, pin dependencies, and keep AI-tool keys out of plaintext config where a preinstall script can grab them.

Read at Socket ↗

The Current

The full edition has the rest of the picture

Every story with the Synthreo take on what it means for your MSP.

Book a Demo

Your demo starts here

The first step is a brief discovery conversation to understand your business, goals, and AI priorities. From there, we’ll tailor the product demo to what matters most.

Pick a Time

Prefer email? sales@synthreo.ai

Contact

Talk to Synthreo

Tell us who you are and we will get back to you.

Prefer email? sales@synthreo.ai