<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[MSP Minute]]></title><description><![CDATA[A 60 second summary of what's happening in the Managed Service Provider world, emailed every weekday morning. Always free.]]></description><link>https://www.mspminute.com</link><image><url>https://substackcdn.com/image/fetch/$s_!gmWi!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0c3f22b-6d32-46a6-9881-10316cc6169c_354x354.png</url><title>MSP Minute</title><link>https://www.mspminute.com</link></image><generator>Substack</generator><lastBuildDate>Thu, 04 Jun 2026 02:56:18 GMT</lastBuildDate><atom:link href="https://www.mspminute.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[MSP Minute]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[mspminute@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[mspminute@substack.com]]></itunes:email><itunes:name><![CDATA[MSP Minute]]></itunes:name></itunes:owner><itunes:author><![CDATA[MSP Minute]]></itunes:author><googleplay:owner><![CDATA[mspminute@substack.com]]></googleplay:owner><googleplay:email><![CDATA[mspminute@substack.com]]></googleplay:email><googleplay:author><![CDATA[MSP Minute]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[The MSP Minute ⏱ Wednesday 3 June 2026]]></title><description><![CDATA[For Managed Service Providers worldwide. Today... Dashlane's 2FA got brute-forced and encrypted vaults stolen... an MSP hits 48 acquisitions... and UK small businesses are taking their time with AI]]></description><link>https://www.mspminute.com/p/the-msp-minute-wednesday-3-june-2026</link><guid isPermaLink="false">https://www.mspminute.com/p/the-msp-minute-wednesday-3-june-2026</guid><pubDate>Wed, 03 Jun 2026 09:31:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!XG08!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8626670a-f108-4548-be37-613df6dde46f_1402x1122.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>&#128308; Attackers brute-forced Dashlane's 2FA and downloaded encrypted vaults. Here's what MSPs need to know</h2><p>If you deploy Dashlane for clients, check your inboxes this morning.</p><p>Between May 31 and June 2, attackers ran a sustained brute-force campaign against Dashlane&#8217;s two-factor authentication, exploiting a fundamental limitation of TOTP codes. </p><p>A six-digit code gives only one million possible combinations per 30 second window. With enough automated attempts, that window is crackable. Dashlane&#8217;s security systems detected the attack and suspended affected accounts. But not before attackers successfully registered unauthorised devices on a small number of accounts and downloaded their encrypted vaults. <a href="https://www.bleepingcomputer.com/news/security/dashlane-password-manager-users-locked-out-by-brute-force-attacks/">BleepingComputer</a></p><p>Fewer than 20 personal plan users had vaults downloaded. Dashlane&#8217;s zero-knowledge architecture means those vaults remain unreadable without each user&#8217;s master password&#8230; so users with strong, unique master passwords are safe. Users with weak or reused master passwords are at risk of offline cracking attempts. Dashlane confirmed no breach of internal systems and says all affected accounts have been unsuspended. The incident status is currently &#8220;monitoring.&#8221; <a href="https://www.theregister.com/security/2026/06/01/password-manager-dashlane-suspends-customer-accounts-amid-brute-force-attacks/5248991">The Register</a></p><p>Two things worth doing today. </p><ul><li><p>First, if any of your clients use Dashlane and received a vault-risk email from Dashlane directly, treat that account as compromised and rotate the master password immediately</p></li><li><p>Second, and more broadly, this incident is a useful reminder that TOTP 2FA is significantly weaker than most people assume. Where possible, push clients toward phishing-resistant authentication: passkeys, hardware security keys, or number-matching MFA rather than six-digit codes.</p></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading. Subscribe for free to get this MSP summary every weekday morning</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h2>&#128993; The 20 MSP just completed its 48th acquisition</h2><p>The 20 MSP announced yesterday it has acquired four more managed service providers, bringing its total acquisition count to 48 since the company began its aggressive roll-up strategy. <a href="https://www.the20msp.com/2026/06/02/the-20-msp-acquisitions/">The 20 MSP</a></p><p>To put that number in perspective: last year, 466 separate MSP businesses were acquired worldwide: one every 19 hours, on average. The total value of those deals was $4.3 billion. And 2026 is on track to beat that.</p><p>The reason is straightforward. There&#8217;s a lot of money sitting in private equity funds that needs to be deployed, and MSPs with recurring revenue, happy clients, and clean books are exactly what those investors are looking for. Businesses that have been around for ten or fifteen years, built by founders who are starting to think about what comes next, are particularly attractive.</p><p></p><h2>&#128994; UK small businesses are taking their time with AI. That's not a problem&#8230; it's your opportunity.</h2><p>MSP Channel Insights published a fresh piece yesterday on UK SMB AI adoption trends&#8230; and the headline finding is &#8220;cautious optimism&#8221;. <a href="https://msp-channel.com/news/72421/cautious-steps-uk-smbs-and-ai-adoption-trends">MSP Channel Insights</a></p><p>Among small businesses with 50-99 employees, 37% have fully embraced AI and almost half are using it selectively for high-impact tasks. But below that, in the 1-49 employee range that makes up the bulk of most MSPs&#8217; client bases, adoption drops sharply. </p><p>The gap between those two groups is almost entirely explained by one thing: access to someone who can help. Larger businesses have internal IT capacity. The smaller ones are luckier&#8230; they have you &#128515;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XG08!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8626670a-f108-4548-be37-613df6dde46f_1402x1122.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XG08!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8626670a-f108-4548-be37-613df6dde46f_1402x1122.png 424w, https://substackcdn.com/image/fetch/$s_!XG08!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8626670a-f108-4548-be37-613df6dde46f_1402x1122.png 848w, https://substackcdn.com/image/fetch/$s_!XG08!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8626670a-f108-4548-be37-613df6dde46f_1402x1122.png 1272w, https://substackcdn.com/image/fetch/$s_!XG08!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8626670a-f108-4548-be37-613df6dde46f_1402x1122.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XG08!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8626670a-f108-4548-be37-613df6dde46f_1402x1122.png" width="1402" height="1122" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8626670a-f108-4548-be37-613df6dde46f_1402x1122.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1122,&quot;width&quot;:1402,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1062461,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.mspminute.com/i/200409509?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8626670a-f108-4548-be37-613df6dde46f_1402x1122.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XG08!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8626670a-f108-4548-be37-613df6dde46f_1402x1122.png 424w, https://substackcdn.com/image/fetch/$s_!XG08!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8626670a-f108-4548-be37-613df6dde46f_1402x1122.png 848w, https://substackcdn.com/image/fetch/$s_!XG08!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8626670a-f108-4548-be37-613df6dde46f_1402x1122.png 1272w, https://substackcdn.com/image/fetch/$s_!XG08!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8626670a-f108-4548-be37-613df6dde46f_1402x1122.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>That&#8217;s hump day done. We&#8217;ll be back in your inbox tomorrow morning.</p>]]></content:encoded></item><item><title><![CDATA[The MSP Minute ⏱ Tuesday 2 June 2026]]></title><description><![CDATA[For Managed Service Providers worldwide. Today... a critical Windows flaw is being exploited on domain controllers... Dutch police took down a 17 million device botnet... and see you in Barcelona?]]></description><link>https://www.mspminute.com/p/the-msp-minute-tuesday-2-june-2026</link><guid isPermaLink="false">https://www.mspminute.com/p/the-msp-minute-tuesday-2-june-2026</guid><pubDate>Tue, 02 Jun 2026 09:30:35 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!qzkV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97ff74e6-3b0b-45ae-8272-64c8deff21da_1402x1122.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>&#128308; A critical Windows Netlogon flaw is being actively exploited&#8230; and it goes straight for domain controllers</h2><p>If you manage Windows Server domain controllers for clients, this needs attention today.</p><p>CVE-2026-41089 is a CVSS 9.8 stack-based buffer overflow in Windows Netlogon, the service that handles authentication across every Windows domain environment. Belgium&#8217;s national cybersecurity authority confirmed active exploitation on Friday. An attacker sends a specially created network request to a domain controller and can execute arbitrary code remotely without authentication. <a href="https://www.bleepingcomputer.com/news/microsoft/critical-windows-netlogon-remote-code-execution-flaw-now-exploited-in-attacks/">BleepingComputer</a></p><p>Security researchers say this flaw is a fast path to forest-wide takeover. Every domain controller, every account, and every client site that shares the same domain.</p><p>Microsoft disclosed the vulnerability on May 12 and originally rated exploitation as &#8220;less likely.&#8221; Active exploitation has now been confirmed. The official fix arrives with June Patch Tuesday on June 10 (eight days away). </p><p>Given what&#8217;s at stake, waiting is not recommended. Acros Security has released micropatches for legacy Windows Server versions (2008 R2, 2012, 2012 R2) for environments that can&#8217;t wait. Watch for unusual Netlogon service crashes, unexpected authentication failures, and anomalous domain trust errors as potential signs of exploitation. <a href="https://www.helpnetsecurity.com/2026/06/01/windows-netlogon-rce-exploited-cve-2026-41089/">Help Net Security</a></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading. Subscribe for free to get this MSP summary every weekday morning</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h2>&#128993; Dutch police just took a 17 million-device botnet offline&#8230; did some of those devices belong to your clients' employees?</h2><p>The Dutch National Police and NCSC announced last week they had dismantled Asocks, a massive residential proxy botnet running across 17 million compromised consumer devices globally. <a href="https://www.bleepingcomputer.com/news/security/dutch-govt-disrupts-malware-botnet-with-17-million-infected-devices/">BleepingComputer</a></p><p>A residential proxy botnet works by silently enslaving ordinary consumer devices such as home routers, smartphones, IoT equipment. And then routing criminal traffic through them. The result: cyberattacks appear to originate from legitimate residential IP addresses, bypassing IP reputation filters and making detection significantly harder.</p><p></p><h2>&#128994; MSP Global is heading back to Barcelona in October&#8230; and it's taking over a theme park again</h2><p>MSP Global 2026 returns to PortAventura theme park near Barcelona on October 21-22. 3,000+ MSPs and MSSPs will be there, for what the organisers describe as &#8220;the best parties the industry has ever seen.&#8221; </p><p>This year&#8217;s theme is &#8220;Serve Your Ecosystem&#8221;, focused on how MSPs can actively support and strengthen their wider partner and client ecosystems through AI, cybersecurity, compliance, and growth strategies. <a href="https://www.mspglobal.com/">MSP Global</a></p><p>If you subscribe to their newsletter you can get a free registration code, saving &#8364;399 on the standard attendee pass. </p><p>Rollercoasters and business growth. There are worse ways to spend two days.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!qzkV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97ff74e6-3b0b-45ae-8272-64c8deff21da_1402x1122.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qzkV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97ff74e6-3b0b-45ae-8272-64c8deff21da_1402x1122.png 424w, https://substackcdn.com/image/fetch/$s_!qzkV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97ff74e6-3b0b-45ae-8272-64c8deff21da_1402x1122.png 848w, https://substackcdn.com/image/fetch/$s_!qzkV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97ff74e6-3b0b-45ae-8272-64c8deff21da_1402x1122.png 1272w, https://substackcdn.com/image/fetch/$s_!qzkV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97ff74e6-3b0b-45ae-8272-64c8deff21da_1402x1122.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qzkV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97ff74e6-3b0b-45ae-8272-64c8deff21da_1402x1122.png" width="1402" height="1122" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/97ff74e6-3b0b-45ae-8272-64c8deff21da_1402x1122.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1122,&quot;width&quot;:1402,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1842798,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.mspminute.com/i/200261779?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97ff74e6-3b0b-45ae-8272-64c8deff21da_1402x1122.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!qzkV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97ff74e6-3b0b-45ae-8272-64c8deff21da_1402x1122.png 424w, https://substackcdn.com/image/fetch/$s_!qzkV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97ff74e6-3b0b-45ae-8272-64c8deff21da_1402x1122.png 848w, https://substackcdn.com/image/fetch/$s_!qzkV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97ff74e6-3b0b-45ae-8272-64c8deff21da_1402x1122.png 1272w, https://substackcdn.com/image/fetch/$s_!qzkV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97ff74e6-3b0b-45ae-8272-64c8deff21da_1402x1122.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>That&#8217;s your lot for Tuesday. We&#8217;ll be back in your inbox tomorrow morning.</p>]]></content:encoded></item><item><title><![CDATA[The MSP Minute ⏱ Monday 1 June 2026]]></title><description><![CDATA[For Managed Service Providers worldwide. Today... ShinyHunters just added another 42 million records to their collection... a deadline for this month... and two big MSP events open this week]]></description><link>https://www.mspminute.com/p/the-msp-minute-monday-1-june-2026</link><guid isPermaLink="false">https://www.mspminute.com/p/the-msp-minute-monday-1-june-2026</guid><pubDate>Mon, 01 Jun 2026 09:31:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!az8e!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F863dcc08-f5f8-4ce8-b439-21ef6276c42b_1535x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>&#128308; ShinyHunters breached Charter/Spectrum via one phone call&#8230; and 4.9 million customer records are now leaked</h2><p>A hacking group has accessed 4.9 million customer records with a well used playbook.</p><p>ShinyHunters breached Charter Communications (which operates Spectrum, the second largest cable and broadband provider in the US) by vishing a single employee and compromising their Microsoft Entra SSO account. From there, they pivoted straight into Salesforce and exported customer records. Charter refused to pay and some data is now publicly leaked. <a href="https://www.theregister.com/cyber-crime/2026/05/29/shinyhunters-adds-charter-to-trophy-shelf-after-49m-customer-records-leak/5248281">The Register</a></p><p>This is the same SSO-to-Salesforce attack chain used against ADT, Canvas, Carnival, and 7-Eleven this year. The pattern is now so established and so repeatable that ShinyHunters appear to have industrialised it.</p><p>If any of your clients use Microsoft Entra and Salesforce together, the conversation to have today is about whether an SSO account compromise would give an attacker direct access to their CRM.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading. Subscribe for free to get this MSP summary every weekday morning</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h2>&#128993; Windows 11 26H1 drops on Friday&#8230; and your clients absolutely should not install it</h2><p>Microsoft confirmed last week that Windows 11 version 26H1 begins rolling out on June 5 (this Friday). Before that notification lands on any client machine, here&#8217;s what you need to know. <a href="https://blogs.windows.com/windows-insider/2026/05/29/announcing-new-builds-for-29-may-2026/">Windows Insider Blog</a></p><p>26H1 is not a standard feature update. It&#8217;s a hardware-optimised release built specifically for new devices launching in 2026 with next-generation silicon&#8230; think Qualcomm Snapdragon X2 Series and similar. It is explicitly not designed for existing devices and will not be offered through Windows Update to standard machines.</p><p>The problem is that any device that accidentally enrolls in 26H1, through Windows Insider settings or manual selection, cannot update to the next annual feature update later this year. Getting back to 25H2 requires a full reinstall.</p><p>For existing client devices, 25H2 and 24H2 remain the recommended versions and will continue receiving monthly security updates as normal. Worth checking that no client machines are enrolled in the Windows Insider Release Preview channel before Friday.</p><p></p><h2>&#128994; Two of the biggest events in the MSP calendar open this week: one in London, one in Salt Lake City</h2><p>Infosecurity Europe opens tomorrow at ExCeL London (June 2-4) with the Channel Zone returning for its second year. Dedicated sessions for MSPs, MSSPs, and resellers covering regulatory pressure, skills shortages, and the expanding attack surface. If you&#8217;re in London this week, it&#8217;s worth a visit. <a href="https://www.computerweekly.com/microscope/news/366641752/InfoSec-The-Channel-Zone-returns">Microscope</a></p><p>Then on Sunday, Pax8 Beyond 2026 opens in Salt Lake City (June 7-9) at the Salt Palace Convention Center. Three days of cybersecurity, AI, and business growth sessions alongside thousands of MSPs and vendors. Past attendees have described it as &#8220;the Super Bowl of user conferences.&#8221; <a href="https://www.pax8beyond.com/">Pax8 Beyond</a></p><p>If you&#8217;re heading to either, enjoy!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!az8e!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F863dcc08-f5f8-4ce8-b439-21ef6276c42b_1535x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!az8e!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F863dcc08-f5f8-4ce8-b439-21ef6276c42b_1535x1024.png 424w, https://substackcdn.com/image/fetch/$s_!az8e!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F863dcc08-f5f8-4ce8-b439-21ef6276c42b_1535x1024.png 848w, https://substackcdn.com/image/fetch/$s_!az8e!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F863dcc08-f5f8-4ce8-b439-21ef6276c42b_1535x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!az8e!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F863dcc08-f5f8-4ce8-b439-21ef6276c42b_1535x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!az8e!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F863dcc08-f5f8-4ce8-b439-21ef6276c42b_1535x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/863dcc08-f5f8-4ce8-b439-21ef6276c42b_1535x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1268383,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.mspminute.com/i/200089458?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F863dcc08-f5f8-4ce8-b439-21ef6276c42b_1535x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!az8e!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F863dcc08-f5f8-4ce8-b439-21ef6276c42b_1535x1024.png 424w, https://substackcdn.com/image/fetch/$s_!az8e!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F863dcc08-f5f8-4ce8-b439-21ef6276c42b_1535x1024.png 848w, https://substackcdn.com/image/fetch/$s_!az8e!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F863dcc08-f5f8-4ce8-b439-21ef6276c42b_1535x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!az8e!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F863dcc08-f5f8-4ce8-b439-21ef6276c42b_1535x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>That&#8217;s your Monday. We&#8217;ll be back in your inbox tomorrow morning.</p>]]></content:encoded></item><item><title><![CDATA[The MSP Minute ⏱ Friday 29 May 2026]]></title><description><![CDATA[For Managed Service Providers worldwide. Today... $250 phishing kit is defeating Microsoft 365 MFA... a Secure Boot deadline is now less than four weeks away... and the MSP 501 results are almost here]]></description><link>https://www.mspminute.com/p/the-msp-minute-friday-29-may-2026</link><guid isPermaLink="false">https://www.mspminute.com/p/the-msp-minute-friday-29-may-2026</guid><pubDate>Fri, 29 May 2026 09:31:22 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!FLE7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb15d158f-f51b-422b-b485-93985c2e6e7c_1402x1122.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>&#128308; FBI warning about a $250 phishing kit that defeats Microsoft 365 MFA completely</h2><p>Kali365 is a phishing-as-a-service platform sold on Telegram for as little as $250 for 30 days. First seen last month, it&#8217;s already been used in hundreds of confirmed attacks across manufacturing, education, government, financial services, and healthcare. Every single victim was using MFA. <a href="https://www.malwarebytes.com/blog/scams/2026/05/kali365-phishing-kit-bypasses-mfa-and-steals-microsoft-logins">Malwarebytes</a></p><p>The attack doesn&#8217;t steal passwords or intercept MFA codes. Instead it abuses Microsoft&#8217;s legitimate device code login flow&#8230; a real authentication feature designed for devices without keyboards, like smart TVs and printers. </p><p>The victim receives a convincing phishing email, is directed to a genuine Microsoft page, and enters a short device code. That single action hands the attacker a persistent OAuth token tied to the victim&#8217;s account. From that point, the attacker has ongoing access to Outlook, Teams, and OneDrive without ever needing to log in again&#8230; even if the victim changes their password.</p><p>The FBI&#8217;s IC3 published a formal advisory on May 21. The recommended mitigation: restrict or disable device code flow in your Microsoft 365 tenant unless it&#8217;s genuinely needed. For most SMB clients, it isn&#8217;t. Conditional Access policies blocking device code authentication are available in Entra ID. <a href="https://www.ic3.gov/PSA/2026/PSA260521">FBI IC3</a></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading. Subscribe for free to get this MSP summary every weekday morning</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h2>&#128993; The Secure Boot certificate deadline is now less than four weeks away (and you have to manually update Windows Server)</h2><p>We featured this a few weeks ago when Patch Tuesday first included the certificate update. It&#8217;s worth a reminder today because the deadline hasn&#8217;t moved and many estates still haven&#8217;t applied it properly.</p><p>The original Secure Boot certificates, issued in 2011, expire on June 26. Devices that received the May or June Patch Tuesday updates are covered automatically. Devices that aren&#8217;t patched enter a degraded security state after June 26 and cannot receive future boot-level protections. <a href="https://4sysops.com/archives/update-secure-boot-certificates-on-windows-server-and-vms-before-june-2026/">4sysops</a></p><p>Heads up: Windows Server does not apply this update automatically. Unlike desktop Windows, Server estates require manual deployment of the certificate rollout via Group Policy or WSUS.</p><p></p><h2>&#128994; The MSP 501 results are coming in June (which is coming on Monday)</h2><p>The 2026 MSP 501 application window closed three weeks ago. As you read this, the results are being scored and verified, with winners set to be announced in June via a reveal webcast. All 501 winners will then be celebrated at the MSP 501 Awards Gala at MSP Summit in Orlando on September 30. <a href="https://themspsummit.com/msp-501-awards/">MSP Summit</a></p><p>Now in its 19th year, the MSP 501 is the only industry ranking based on actual financial data (managed services revenue, recurring revenue percentage, year-on-year growth) rather than votes or nominations. If you applied this year, the wait is almost over. Hit reply and let us know, would you? </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FLE7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb15d158f-f51b-422b-b485-93985c2e6e7c_1402x1122.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FLE7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb15d158f-f51b-422b-b485-93985c2e6e7c_1402x1122.png 424w, https://substackcdn.com/image/fetch/$s_!FLE7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb15d158f-f51b-422b-b485-93985c2e6e7c_1402x1122.png 848w, https://substackcdn.com/image/fetch/$s_!FLE7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb15d158f-f51b-422b-b485-93985c2e6e7c_1402x1122.png 1272w, https://substackcdn.com/image/fetch/$s_!FLE7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb15d158f-f51b-422b-b485-93985c2e6e7c_1402x1122.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FLE7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb15d158f-f51b-422b-b485-93985c2e6e7c_1402x1122.png" width="1402" height="1122" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b15d158f-f51b-422b-b485-93985c2e6e7c_1402x1122.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1122,&quot;width&quot;:1402,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1884090,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.mspminute.com/i/199713642?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb15d158f-f51b-422b-b485-93985c2e6e7c_1402x1122.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FLE7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb15d158f-f51b-422b-b485-93985c2e6e7c_1402x1122.png 424w, https://substackcdn.com/image/fetch/$s_!FLE7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb15d158f-f51b-422b-b485-93985c2e6e7c_1402x1122.png 848w, https://substackcdn.com/image/fetch/$s_!FLE7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb15d158f-f51b-422b-b485-93985c2e6e7c_1402x1122.png 1272w, https://substackcdn.com/image/fetch/$s_!FLE7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb15d158f-f51b-422b-b485-93985c2e6e7c_1402x1122.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Right, we&#8217;re through another week. We&#8217;ll be back in your inbox on Monday morning when it will be JUNE. The year&#8217;s going so fast &#128577; Have a great weekend.</p>]]></content:encoded></item><item><title><![CDATA[The MSP Minute ⏱ Thursday 28 May 2026]]></title><description><![CDATA[For Managed Service Providers worldwide. Today... ransomware criminals are physically walking into offices... Microsoft's May patch broke something very specific... and the good guys really won.]]></description><link>https://www.mspminute.com/p/the-msp-minute-thursday-28-may-2026</link><guid isPermaLink="false">https://www.mspminute.com/p/the-msp-minute-thursday-28-may-2026</guid><pubDate>Thu, 28 May 2026 09:31:34 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!5Nwa!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44f74ed0-ef5d-46a5-b3ba-b4d412fcc499_1402x1122.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>&#128308; The FBI&#8217;s warning that ransomware criminals are now physically walking into law firm offices pretending to be IT support</h2><p>This is a scary one.</p><p>The Silent Ransom Group has been targeting US law firms since 2023 using phone-based social engineering. So, calling employees, impersonating IT support, and convincing them to open a remote desktop session. What&#8217;s new is when the phone call doesn&#8217;t work, they now send a person to visit. <a href="https://www.bleepingcomputer.com/news/security/fbi-warns-of-silent-ransom-group-in-person-data-theft-attacks/">BleepingComputer</a></p><p>The FBI issued a Flash Alert on Tuesday, its highest severity designation, confirming active in-person intrusions as of Spring 2026. The operative walks into reception posing as an IT technician, talks their way to a workstation, plugs in a USB drive, copies the data, and leaves. </p><p>Over 100 attacks confirmed. 38 firms have already had their data leaked publicly after refusing to pay. The most high-profile victim is a firm with over $1.5 billion in annual revenue. <a href="https://www.theregister.com/security/2026/05/27/fbi-crooks-enter-legal-offices-and-steal-data-via-usb-drive/5247212">The Register</a></p><p>Time to disable your clients&#8217; exposed USB ports on workstations in reception areas or open-plan offices??</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading. Subscribe for free to get this MSP summary every weekday morning</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h2>&#128993; Microsoft's May patch broke domain controller lookups&#8230; but only if your server hostname is exactly 15 characters long</h2><p>This is the most comically specific Windows bug in recent memory.</p><p>Microsoft confirmed on May 26 that KB5087537, part of this month&#8217;s Patch Tuesday, causes domain controller lookup failures on Windows Server 2016 systems&#8230; but only where the server hostname is exactly 15 characters long. <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-domain-controller-lookup-may-fail-on-windows-server-2016/">BleepingComputer</a></p><p>When affected, DCLocator calls return ERROR_INVALID_PARAMETER, meaning applications, scripts, and administrative tools can&#8217;t locate a domain controller at all. It looks like a DNS problem, or a firewall problem, or a replication problem&#8230; until someone checks the hostname length.</p><p>No fix timeline from Microsoft yet. The suggested workaround is to rename the server to a hostname of a different length.</p><p></p><h2>&#128994; CrowdStrike and Google dismantled a botnet that was hiding inside a blockchain. Yes, really</h2><p>Yesterday&#8217;s Glassworm botnet takedown is worth knowing about. Not because it directly affects most MSPs, but because of how the good guys had to approach it.</p><p>Glassworm has been targeting software developers since October 2025, hiding malware inside VS Code extensions, npm packages, PyPI libraries, and GitHub repositories. The clever part: its operators built four separate command-and-control channels specifically designed to survive takedowns. Including one that encoded instructions inside Solana blockchain transactions, which are immutable and can&#8217;t be deleted or seized by anyone. <a href="https://www.bleepingcomputer.com/news/security/glassworm-botnet-disrupted-after-resilient-c2-infrastructure-takedown/">BleepingComputer</a></p><p>CrowdStrike, Google, and the Shadowserver Foundation had to hit all four channels simultaneously on Tuesday at 14:00 UTC&#8230; because taking out three of four would have left the botnet operational. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5Nwa!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44f74ed0-ef5d-46a5-b3ba-b4d412fcc499_1402x1122.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5Nwa!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44f74ed0-ef5d-46a5-b3ba-b4d412fcc499_1402x1122.png 424w, https://substackcdn.com/image/fetch/$s_!5Nwa!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44f74ed0-ef5d-46a5-b3ba-b4d412fcc499_1402x1122.png 848w, https://substackcdn.com/image/fetch/$s_!5Nwa!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44f74ed0-ef5d-46a5-b3ba-b4d412fcc499_1402x1122.png 1272w, https://substackcdn.com/image/fetch/$s_!5Nwa!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44f74ed0-ef5d-46a5-b3ba-b4d412fcc499_1402x1122.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5Nwa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44f74ed0-ef5d-46a5-b3ba-b4d412fcc499_1402x1122.png" width="1402" height="1122" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/44f74ed0-ef5d-46a5-b3ba-b4d412fcc499_1402x1122.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1122,&quot;width&quot;:1402,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1898747,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.mspminute.com/i/199573380?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44f74ed0-ef5d-46a5-b3ba-b4d412fcc499_1402x1122.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5Nwa!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44f74ed0-ef5d-46a5-b3ba-b4d412fcc499_1402x1122.png 424w, https://substackcdn.com/image/fetch/$s_!5Nwa!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44f74ed0-ef5d-46a5-b3ba-b4d412fcc499_1402x1122.png 848w, https://substackcdn.com/image/fetch/$s_!5Nwa!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44f74ed0-ef5d-46a5-b3ba-b4d412fcc499_1402x1122.png 1272w, https://substackcdn.com/image/fetch/$s_!5Nwa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44f74ed0-ef5d-46a5-b3ba-b4d412fcc499_1402x1122.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>OK, that&#8217;s Thursday done. We&#8217;ll be back in your inbox tomorrow morning for the final time this week. Have a terrific day.</p>]]></content:encoded></item><item><title><![CDATA[The MSP Minute ⏱ Wednesday 27 May 2026]]></title><description><![CDATA[For Managed Service Providers worldwide. Today... MFA prompt bombing... 800 servers used for cyber attacks are seized... and when The Boss vibe codes an app.]]></description><link>https://www.mspminute.com/p/the-msp-minute-wednesday-27-may-2026</link><guid isPermaLink="false">https://www.mspminute.com/p/the-msp-minute-wednesday-27-may-2026</guid><pubDate>Wed, 27 May 2026 09:31:04 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!-OUT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29c7c59c-fffa-421f-847f-83b7a90f34d0_1122x1402.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>&#128308; Attackers have stopped trying to steal your clients' MFA codes. They just wait for someone to approve a fake request instead</h2><p>MFA was supposed to close the door on account takeovers, right? But it hasn&#8217;t&#8230; because attackers stopped trying to steal the second factor and started exploiting the human approving it instead.</p><p>This technique is called MFA prompt bombing. An attacker gets hold of valid credentials, easily sourced from breached password dumps, then repeatedly triggers push notification requests to the victim&#8217;s phone. </p><p>Dozens of them, sometimes hundreds. The goal is simple: wear the person down until they approve one just to make it stop. And it works. Regularly. <a href="https://thehackernews.com/2026/05/mfa-prompt-bombing-why-your-second.html">The Hacker News</a></p><p>The more sophisticated version pairs the bombing with a vishing call. Someone rings the victim pretending to be from IT support, explains there&#8217;s a system issue, and asks them to approve the next notification to resolve it. </p><p>Three practical things you can do to protect clients from this:</p><ol><li><p>Switch push-only MFA to number matching. The user has to type a code shown on screen into their phone rather than just tapping approve, which breaks the prompt bombing technique entirely</p></li><li><p>Set alert thresholds for repeated failed MFA prompts. Three or more in quick succession should trigger an investigation, not just a log entry</p></li><li><p>Tell clients explicitly: if they receive unexpected MFA requests they didn&#8217;t initiate, the answer is always no&#8230; and they should call your team immediately.</p></li></ol><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading. Subscribe for free to get this MSP summary every weekday morning</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h2>&#128993; Dutch police seized 800 servers and arrested two people for running infrastructure that enabled global cyberattacks</h2><p>A coordinated operation by the Dutch National High Tech Crime Unit last week took down one of Europe&#8217;s largest bulletproof hosting operations&#8230;seizing 800 servers and arresting two people running the infrastructure. <a href="https://krebsonsecurity.com/2026/05/netherlands-seizes-800-servers-arrests-2-for-aiding-cyberattacks/">Krebs on Security</a></p><p>Bulletproof hosting is the engine room of cybercrime. Servers specifically configured to ignore takedown requests and abuse complaints, rented to ransomware groups, phishing operations, and DDoS-for-hire services. </p><p>The seized infrastructure was being used by multiple active threat groups to host command-and-control servers, malware distribution points, and stolen credential databases.</p><p></p><h2>&#128994; The Boss wrote an AI app. Management love it. Now everyone has to use it&#8230;</h2><p>This week&#8217;s BOFH column from The Register is required reading if you ever deployed software you didn&#8217;t choose, to users who didn&#8217;t want it, on behalf of a decision maker who didn&#8217;t understand it. <a href="https://www.theregister.com/bofh/2026/05/22/bofh-vibe-coded-solutions-arrive-for-problems-nobody-has/5243976">The Register</a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-OUT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29c7c59c-fffa-421f-847f-83b7a90f34d0_1122x1402.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-OUT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29c7c59c-fffa-421f-847f-83b7a90f34d0_1122x1402.png 424w, https://substackcdn.com/image/fetch/$s_!-OUT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29c7c59c-fffa-421f-847f-83b7a90f34d0_1122x1402.png 848w, https://substackcdn.com/image/fetch/$s_!-OUT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29c7c59c-fffa-421f-847f-83b7a90f34d0_1122x1402.png 1272w, https://substackcdn.com/image/fetch/$s_!-OUT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29c7c59c-fffa-421f-847f-83b7a90f34d0_1122x1402.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-OUT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29c7c59c-fffa-421f-847f-83b7a90f34d0_1122x1402.png" width="1122" height="1402" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/29c7c59c-fffa-421f-847f-83b7a90f34d0_1122x1402.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1402,&quot;width&quot;:1122,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1597953,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.mspminute.com/i/199430026?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29c7c59c-fffa-421f-847f-83b7a90f34d0_1122x1402.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-OUT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29c7c59c-fffa-421f-847f-83b7a90f34d0_1122x1402.png 424w, https://substackcdn.com/image/fetch/$s_!-OUT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29c7c59c-fffa-421f-847f-83b7a90f34d0_1122x1402.png 848w, https://substackcdn.com/image/fetch/$s_!-OUT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29c7c59c-fffa-421f-847f-83b7a90f34d0_1122x1402.png 1272w, https://substackcdn.com/image/fetch/$s_!-OUT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29c7c59c-fffa-421f-847f-83b7a90f34d0_1122x1402.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>That&#8217;s it for Wednesday. We&#8217;ll be back in your inbox tomorrow morning. Have a great day.</p>]]></content:encoded></item><item><title><![CDATA[The MSP Minute ⏱ Tuesday 26 May 2026]]></title><description><![CDATA[For Managed Service Providers worldwide. Today... three maximum-severity flaws in a network device... the Windows zero-day researcher banned... and when the marketing people have "smart ideas"]]></description><link>https://www.mspminute.com/p/the-msp-minute-tuesday-26-may-2026</link><guid isPermaLink="false">https://www.mspminute.com/p/the-msp-minute-tuesday-26-may-2026</guid><pubDate>Tue, 26 May 2026 09:31:27 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!3zOC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F619d4c94-f3d0-4428-89aa-235edcad3032_1122x1402.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>&#128308; Ubiquiti just patched three maximum-severity flaws in UniFi OS&#8230; and MSPs are specifically named as at risk</h2><p>If you manage UniFi devices for clients, this needs attention today.</p><p>On May 22, Ubiquiti released emergency patches for three CVSS 10.0 vulnerabilities in UniFi OS&#8230; the operating system powering Dream Machines, Cloud Gateways, and network appliances found extensively in MSP-managed environments. All three can be exploited remotely without authentication and without user interaction. <a href="https://www.bleepingcomputer.com/news/security/ubiquiti-patches-three-max-severity-unifi-os-vulnerabilities/">BleepingComputer</a></p><ul><li><p>CVE-2026-34908 allows an unauthenticated attacker to make sweeping unauthorised changes to the entire system</p></li><li><p>CVE-2026-34909 allows file traversal; reading sensitive files and taking over underlying accounts</p></li><li><p>CVE-2026-34910 enables command injection once network access is established. </p></li></ul><p>Two further critical flaws were patched at the same time.</p><p>Censys is tracking nearly 100,000 internet-exposed UniFi OS endpoints globally. No active exploitation has been confirmed yet. But Ubiquiti products have previously been targeted by both state-backed groups and ransomware operators to build botnets and proxy malicious traffic. The window between patch release and active exploitation is getting shorter every month.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading. Subscribe for free to get this MSP summary every weekday morning</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h2>&#128993; GitHub banned Nightmare-Eclipse. They've moved to GitLab&#8230; and set a new deadline of July 14</h2><p>Following on from our recent coverage, GitHub has terminated the Nightmare-Eclipse account that hosted all six unpatched Windows zero-day exploits. <a href="https://cybernews.com/security/github-bans-researcher-releasing-windows-zero-days/">Cybernews</a></p><p>The researcher has immediately moved to GitLab, reposted all six exploits, and issued a new warning. July 14 is now being flagged as a significant date, with hints at remote code execution vulnerabilities still in reserve. The &#8220;big surprise&#8221; previously threatened for June Patch Tuesday remains on the table.</p><p>Microsoft has not commented beyond acknowledging the individual CVEs as they&#8217;ve been disclosed. The exploits remain active, some of which remain confirmed working on fully patched Windows 11 systems, and are being used in real attacks linked to Russian-geolocated infrastructure.</p><p>June 10 is the next Patch Tuesday. What do you think is going to happen in the next couple of months?</p><p></p><h2>&#128994; Marketing had a brilliant idea. IT looked into it&#8230; and realised it had already been implemented</h2><p>The Register&#8217;s On Call column last Friday featured a reader called Hamish, who worked at a British retailer. A senior member of the marketing team had a breakthrough insight: they should add Apple Pay to the company&#8217;s website. Management approved it enthusiastically and it landed on Hamish&#8217;s desk. <a href="https://www.theregister.com/software/2026/05/22/marketing-demanded-it-add-website-feature-that-was-already-working/5242367">The Register</a></p><p>Spoiler alert&#8230; the website already had Apple Pay. And had done for months!!</p><p>Hamish had the satisfaction of closing a ticket for a feature he hadn&#8217;t needed to build.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3zOC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F619d4c94-f3d0-4428-89aa-235edcad3032_1122x1402.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3zOC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F619d4c94-f3d0-4428-89aa-235edcad3032_1122x1402.png 424w, https://substackcdn.com/image/fetch/$s_!3zOC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F619d4c94-f3d0-4428-89aa-235edcad3032_1122x1402.png 848w, https://substackcdn.com/image/fetch/$s_!3zOC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F619d4c94-f3d0-4428-89aa-235edcad3032_1122x1402.png 1272w, https://substackcdn.com/image/fetch/$s_!3zOC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F619d4c94-f3d0-4428-89aa-235edcad3032_1122x1402.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3zOC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F619d4c94-f3d0-4428-89aa-235edcad3032_1122x1402.png" width="1122" height="1402" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/619d4c94-f3d0-4428-89aa-235edcad3032_1122x1402.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1402,&quot;width&quot;:1122,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1602157,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.mspminute.com/i/199299565?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F619d4c94-f3d0-4428-89aa-235edcad3032_1122x1402.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3zOC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F619d4c94-f3d0-4428-89aa-235edcad3032_1122x1402.png 424w, https://substackcdn.com/image/fetch/$s_!3zOC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F619d4c94-f3d0-4428-89aa-235edcad3032_1122x1402.png 848w, https://substackcdn.com/image/fetch/$s_!3zOC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F619d4c94-f3d0-4428-89aa-235edcad3032_1122x1402.png 1272w, https://substackcdn.com/image/fetch/$s_!3zOC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F619d4c94-f3d0-4428-89aa-235edcad3032_1122x1402.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>That&#8217;s it for today. We&#8217;ll be back in your inbox tomorrow morning. Have a great day.</p>]]></content:encoded></item><item><title><![CDATA[The MSP Minute ⏱ Friday 22 May 2026]]></title><description><![CDATA[For Managed Service Providers worldwide. Today... Microsoft just dismantled a criminal operation... AI agents are changing what MSPs need to deliver for clients... and Elon's space AI for your client?]]></description><link>https://www.mspminute.com/p/the-msp-minute-friday-22-may-2026</link><guid isPermaLink="false">https://www.mspminute.com/p/the-msp-minute-friday-22-may-2026</guid><pubDate>Fri, 22 May 2026 09:30:05 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!BdiZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faad68003-1c95-4f6a-9f66-079807da47e7_1122x1402.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>&#128308; Microsoft took down a malware-signing service used by multiple ransomware gangs&#8230; including ones targeting your clients</h2><p>Microsoft&#8217;s Digital Crimes Unit has dismantled Fox Tempest, a criminal operation that ran as a signing-as-a-service platform for ransomware groups. </p><p>Attackers would submit their malware binaries and receive back digitally signed versions that appeared to be legitimate software. The signed malware was then distributed disguised as installers for Microsoft Teams, AnyDesk, PuTTY, and Webex&#8230; yes, the exact tools your clients trust and download regularly. <a href="https://thehackernews.com/2026/05/microsoft-takes-down-malware-signing.html">The Hacker News</a></p><p>Microsoft seized the Fox Tempest domain, took hundreds of virtual machines offline, and revoked over 1,000 fraudulent code-signing certificates.</p><p>The practical takeaway for your clients is how important it is to verify software downloads through official sources. These fake installers reach victims when someone clicked a sponsored result that wasn&#8217;t the official software. </p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading. Subscribe for free to get this MSP summary every weekday morning</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h2>&#128993; AI agents are changing what clients expect from their MSP</h2><p>Zendesk announced at its Relate conference this week a fundamental shift: from chatbot deflection to autonomous AI agents across its entire platform. And it was explicit that channel partners are central to making it work. <a href="https://www.channeldive.com/news/zendesk-agentic-ai-crm-partner-opportunties/820753/">Channel Dive</a></p><p>The SVP of partner sales told Channel Dive: &#8220;This is really a move from helping customers set up simple bots to helping them rethink how service gets done. It&#8217;s less about how do we deflect this ticket, and more about how we design an AI-powered service operation that actually resolves issues end to end.&#8221;</p><p></p><h2>&#128994; SpaceX just filed for the biggest IPO in history. And buried inside is something relevant to MSPs</h2><p>SpaceX filed its S-1 with the SEC on Wednesday. It&#8217;s the formal start of what could be the largest IPO in corporate history, targeting a Nasdaq listing under the ticker SPCX in June. <a href="https://fortune.com/2026/05/20/spacex-ipo-filing-s1-total-addressable-market-make-life-multiplanetary/">Fortune</a></p><p>The fun bit buried in the filing: Did you know that Starlink accounts for 70% of revenue?</p><p>And SpaceX plans to begin deploying AI compute satellites into Sun-synchronous orbit as early as 2028, effectively positioning space as the next data centre frontier, powered by solar energy. They&#8217;re calling it orbital AI infrastructure. Fancy.</p><p>The MSP angle: Starlink Business is already a growing line in MSP service catalogues (especially for clients in rural or remote locations, or as a backup connectivity solution).</p><p>If SpaceX goes public at the valuations being discussed, Starlink&#8217;s investment in its business product line is only going one way. Worth knowing about before your clients ask.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BdiZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faad68003-1c95-4f6a-9f66-079807da47e7_1122x1402.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BdiZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faad68003-1c95-4f6a-9f66-079807da47e7_1122x1402.png 424w, https://substackcdn.com/image/fetch/$s_!BdiZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faad68003-1c95-4f6a-9f66-079807da47e7_1122x1402.png 848w, https://substackcdn.com/image/fetch/$s_!BdiZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faad68003-1c95-4f6a-9f66-079807da47e7_1122x1402.png 1272w, https://substackcdn.com/image/fetch/$s_!BdiZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faad68003-1c95-4f6a-9f66-079807da47e7_1122x1402.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BdiZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faad68003-1c95-4f6a-9f66-079807da47e7_1122x1402.png" width="1122" height="1402" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/aad68003-1c95-4f6a-9f66-079807da47e7_1122x1402.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1402,&quot;width&quot;:1122,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1276382,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.mspminute.com/i/198817491?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faad68003-1c95-4f6a-9f66-079807da47e7_1122x1402.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BdiZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faad68003-1c95-4f6a-9f66-079807da47e7_1122x1402.png 424w, https://substackcdn.com/image/fetch/$s_!BdiZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faad68003-1c95-4f6a-9f66-079807da47e7_1122x1402.png 848w, https://substackcdn.com/image/fetch/$s_!BdiZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faad68003-1c95-4f6a-9f66-079807da47e7_1122x1402.png 1272w, https://substackcdn.com/image/fetch/$s_!BdiZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faad68003-1c95-4f6a-9f66-079807da47e7_1122x1402.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>That&#8217;s your lot for this week. We&#8217;re having a day off on Monday as i&#8217;s a public holiday here in the UK. So we&#8217;ll be back in your inbox on Tuesday morning. Have a great weekend.</p>]]></content:encoded></item><item><title><![CDATA[The MSP Minute ⏱ Thursday 21 May 2026]]></title><description><![CDATA[For Managed Service Providers worldwide. Today... 7-Eleven confirmed hackers got in... a major ERP vendor decided it only wants to sell through the channel... and an AI embarassed itself]]></description><link>https://www.mspminute.com/p/the-msp-minute-thursday-21-may-2026</link><guid isPermaLink="false">https://www.mspminute.com/p/the-msp-minute-thursday-21-may-2026</guid><pubDate>Thu, 21 May 2026 09:31:22 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!YGBe!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd821fa75-34cd-4340-bcbe-0af3123f7e4a_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>&#128308; 7-Eleven just confirmed ShinyHunters breached its Salesforce environment</h2><p>7-Eleven, which has 86,000 stores and 100 million loyalty programme members globally, officially confirmed this week that ShinyHunters breached its systems via its Salesforce environment.</p><p>It happened on April 8. 600,000 records containing personal information and internal corporate data were stolen. The group listed them on its leak site on April 17 with a ransom deadline. 7-Eleven didn&#8217;t pay. And so ShinyHunters is now selling the data for $250,000. <a href="https://www.bleepingcomputer.com/news/security/7-eleven-confirms-data-breach-claimed-by-the-shinyhunters-gang/">BleepingComputer</a></p><p>The attack method is the one worth noting. ShinyHunters didn't exploit a Salesforce vulnerability. The intrusion came from outside the platform itself. This is exactly the same playbook used against ADT, Instructure, Vimeo, Medtronic, and Zara this year. Every one of those organisations had Salesforce and thought they were protected.</p><p>If any of your clients use Salesforce, or any major cloud CRM, the conversation to have today is about third-party integration hygiene and OAuth app permissions. The door ShinyHunters keeps walking through isn&#8217;t a Salesforce problem. It&#8217;s a configuration problem.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading. Subscribe for free to get this MSP summary every weekday morning</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h2>&#128993; A multi billion ERP vendor just restructured its entire business to run through channel partners</h2><p>Infor, one of the world&#8217;s largest enterprise software companies specialising in industry-specific ERP and cloud solutions, has announced it&#8217;s going all-in on the channel. <a href="https://www.channeldive.com/news/infor-erp-cloud-ai-partner-program-aws/820637/">Channel Dive</a></p><p>The restructuring means Infor&#8217;s resellers, MSPs, and system integrators will now be the primary route to market for its cloud ERP and AI products globally. </p><p>The company has launched a new partner programme on AWS Marketplace, and simplified its commercial model specifically designed to help channel partners win mid-market manufacturing, distribution, and healthcare accounts.</p><p>ERP has historically been a hard sell for MSPs&#8230; complex, long-cycle, and dominated by vendor direct teams. Infor is explicitly changing that model. If you have clients in manufacturing, food and beverage, healthcare, or distribution who are running legacy ERP systems, this is worth a look.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/p/the-msp-minute-thursday-21-may-2026?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">MSP Minute is free every weekday for all MSPs. Please share the love with a friend</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/p/the-msp-minute-thursday-21-may-2026?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.mspminute.com/p/the-msp-minute-thursday-21-may-2026?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><h2>&#128994; An AI was put in charge of reading names at a graduation. It skipped hundreds of them&#8230;</h2><p>Helping to prove that AI isn&#8217;t ready to replace everything just yet&#8230;</p><p>An Arizona college replaced its human announcer with an AI system to read student names at this year&#8217;s graduation ceremony. </p><p>The AI skipped hundreds of names entirely, leaving students to walk across the stage in complete silence while their families waited to hear their moment called out. Students and families are furious. <a href="https://www.nbcnews.com/news/us-news/arizona-college-skips-several-graduates-ai-malfunction-commencement-ce-rcna346182">NBC</a></p><p>The college said it switched to AI to save money. Sometimes the old way is just fine.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YGBe!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd821fa75-34cd-4340-bcbe-0af3123f7e4a_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YGBe!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd821fa75-34cd-4340-bcbe-0af3123f7e4a_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!YGBe!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd821fa75-34cd-4340-bcbe-0af3123f7e4a_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!YGBe!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd821fa75-34cd-4340-bcbe-0af3123f7e4a_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!YGBe!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd821fa75-34cd-4340-bcbe-0af3123f7e4a_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YGBe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd821fa75-34cd-4340-bcbe-0af3123f7e4a_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d821fa75-34cd-4340-bcbe-0af3123f7e4a_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1705308,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.mspminute.com/i/198666606?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd821fa75-34cd-4340-bcbe-0af3123f7e4a_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!YGBe!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd821fa75-34cd-4340-bcbe-0af3123f7e4a_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!YGBe!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd821fa75-34cd-4340-bcbe-0af3123f7e4a_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!YGBe!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd821fa75-34cd-4340-bcbe-0af3123f7e4a_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!YGBe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd821fa75-34cd-4340-bcbe-0af3123f7e4a_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Exciting stuff. We&#8217;re into Thursday, and that&#8217;s the highway to the weekend. Enjoy yourself today. We&#8217;ll be back in your inbox tomorrow morning.</p>]]></content:encoded></item><item><title><![CDATA[The MSP Minute ⏱ Wednesday 20 May 2026]]></title><description><![CDATA[For Managed Service Providers worldwide. Today... a sixth Windows zero-day dropped and it works on fully patched machines... Microsoft's channel conflict... and a hidden partition is breaking updates.]]></description><link>https://www.mspminute.com/p/the-msp-minute-wednesday-20-may-2026</link><guid isPermaLink="false">https://www.mspminute.com/p/the-msp-minute-wednesday-20-may-2026</guid><pubDate>Wed, 20 May 2026 09:30:40 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!qErb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77ec7863-e345-4e3e-bbf8-ca2df514eaa4_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>&#128308; Nightmare-Eclipse just dropped a sixth Windows zero-day&#8230; and this one was supposed to be fixed in 2020</h2><p>Six exploits in six weeks. This is one very determined researcher.</p><p>Nightmare-Eclipse published MiniPlasma on Monday. It&#8217;s a privilege escalation zero-day that gives any standard user full system-level access on fully patched Windows 11 machines running the latest May 2026 updates. </p><p>BleepingComputer, Will Dormann and ThreatLocker all confirmed it works. <a href="https://blog.barracuda.com/2026/05/19/nightmare-eclipse-zero-days-grudge">Barracuda</a></p><p>The flaw targets the Windows Cloud Filter driver, the component that handles OneDrive and cloud-backed file sync. It was originally reported to Microsoft by Google Project Zero researcher James Forshaw back in September 2020. Microsoft said they fixed it in December 2020. The original proof-of-concept code still works without modification.</p><p>No patch until June 10 at the earliest. In the meantime, Barracuda&#8217;s profile of this researcher, published yesterday, is worth reading. </p><ul><li><p>The exploits are linked to Russian-geolocated infrastructure</p></li><li><p>The researcher has promised &#8220;a big surprise&#8221; for June Patch Tuesday</p></li><li><p>And has deployed a dead man&#8217;s switch with more exploits set to release automatically if certain conditions are met</p></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading. Subscribe for free to get this MSP summary every weekday morning</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h2>&#128993; Microsoft just eliminated bulk enterprise discounts. And MSPs are losing midmarket deals because of it</h2><p>Channel Dive published yesterday that Microsoft&#8217;s decision to remove bulk enterprise agreement discounts is creating significant channel conflict&#8230; and the midmarket is feeling it most. <a href="https://www.channeldive.com/news/microsoft-licensing-ignites-a-midmarket-battle-shi-ntiva-sherweb-opkalla-criterion/820533/">Channel Dive</a></p><p>Customers are shopping around. Deals that MSPs considered locked are being lost as clients find lower per-seat pricing through direct or alternative routes. The elimination of volume discounts means the price advantage that used to reward loyalty and consolidation is gone. And clients are noticing.</p><p>The practical question for MSPs with midmarket Microsoft customers: when did you last have a proactive conversation about licensing costs and value? If the answer is &#8220;at renewal,&#8221; that might be too late. </p><p>The MSPs holding those relationships through this shift are the ones having the conversation before the client starts shopping around.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/p/the-msp-minute-wednesday-20-may-2026?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">MSP Minute is free every weekday for all MSPs. Please share the love with a friend</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/p/the-msp-minute-wednesday-20-may-2026?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.mspminute.com/p/the-msp-minute-wednesday-20-may-2026?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><h2>&#128994; A hidden 100MB partition nobody thinks about is breaking Windows updates across client estates</h2><p>File this under &#8220;the most classic IT problem in existence&#8221;.</p><p>Microsoft confirmed this week that the May Windows 11 update (KB5089549) is failing to install on some machines with a cryptic error that rolls back at 35% completion. </p><p>The cause: the EFI System Partition, a tiny hidden boot partition that Windows actively conceals from users, is running out of space. OEM firmware updates and old deployment images have quietly filled it over the years on affected devices. When the partition hits 10MB or less of free space, the security update fails. <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-confirms-kb5089549-windows-11-security-update-install-issues/">BleepingComputer</a></p><p>The fix is already out. Microsoft pushed a Known Issue Rollback automatically to most consumer and unmanaged devices, so a restart resolves it on most affected machines. For managed enterprise fleets, there&#8217;s a Group Policy mitigation available.</p><p>But the underlying issue doesn&#8217;t go away with the rollback. Every time Microsoft does more work in the boot environment: Secure Boot certificates, BitLocker, TPM measurements&#8230; this hidden partition gets a little fuller. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!qErb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77ec7863-e345-4e3e-bbf8-ca2df514eaa4_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qErb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77ec7863-e345-4e3e-bbf8-ca2df514eaa4_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!qErb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77ec7863-e345-4e3e-bbf8-ca2df514eaa4_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!qErb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77ec7863-e345-4e3e-bbf8-ca2df514eaa4_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!qErb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77ec7863-e345-4e3e-bbf8-ca2df514eaa4_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qErb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77ec7863-e345-4e3e-bbf8-ca2df514eaa4_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/77ec7863-e345-4e3e-bbf8-ca2df514eaa4_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1801791,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.mspminute.com/i/198514369?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77ec7863-e345-4e3e-bbf8-ca2df514eaa4_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!qErb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77ec7863-e345-4e3e-bbf8-ca2df514eaa4_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!qErb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77ec7863-e345-4e3e-bbf8-ca2df514eaa4_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!qErb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77ec7863-e345-4e3e-bbf8-ca2df514eaa4_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!qErb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77ec7863-e345-4e3e-bbf8-ca2df514eaa4_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Okay, that&#8217;s Wednesday done. Have a great day. We&#8217;ll be back in your inbox tomorrow morning.</p>]]></content:encoded></item><item><title><![CDATA[The MSP Minute ⏱ Tuesday 19 May 2026]]></title><description><![CDATA[For Managed Service Providers worldwide. Today... the biggest breach report numbers are eye-opening... identity attacks are now the dominant threat... and the good guys had a very good week]]></description><link>https://www.mspminute.com/p/the-msp-minute-tuesday-19-may-2026</link><guid isPermaLink="false">https://www.mspminute.com/p/the-msp-minute-tuesday-19-may-2026</guid><pubDate>Tue, 19 May 2026 09:30:52 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!C8rp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e8a87c9-17cc-44bb-a03b-4ff51a6b9237_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>&#128308; The 2026 Verizon DBIR is out today&#8230; and two thirds of all breaches now start with identity</h2><p>The 2026 Verizon Data Breach Investigations Report confirms what&#8217;s been building for years: identity is now the dominant attack surface. </p><p>Two thirds of all breaches investigated began with an identity-related attack: stolen credentials, session hijacking, or MFA bypass. Vulnerability exploitation jumped 34% year on year. And third-party breaches now account for 30% of all incidents, double the previous year&#8217;s figure. <a href="https://www.verizon.com/business/resources/reports/dbir/">Verizon</a></p><p>Let&#8217;s look at the SMB numbers. Ransomware appeared in 88% of SMB breach incidents, compared to just 39% at large organisations. Your clients are not collateral damage in attacks aimed at big companies. They&#8217;re the primary target.</p><p>The report also confirms that 64% of ransomware victims now refuse to pay, up from 50% two years ago. And median ransom payments have fallen from $150,000 to $115,000. But the volume of attacks keeps climbing regardless.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading. Subscribe for free to get this MSP summary every weekday morning</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h2>&#128993; 71% of organisations had at least one identity breach last year. Most didn't spot it quickly</h2><p>Another report&#8230; Sophos published its State of Identity Security 2026 report last week. They surveyed 5,000 IT and cybersecurity leaders across 17 countries, and it reads as a direct companion to the Verizon DBIR. <a href="https://www.helpnetsecurity.com/2026/05/14/sophos-2026-identity-breach-costs-report/">Help Net Security</a></p><ul><li><p>71% of organisations suffered at least one identity-related breach in the past 12 months</p></li><li><p>The average organisation reported three separate incidents</p></li><li><p>And only 24% continuously monitor for unusual login attempts&#8230; meaning the majority of these breaches had a significant undetected window before anyone noticed.</p></li></ul><p>The specific number to act on: only 34% of organisations regularly audit or rotate service accounts. As AI agents multiply across client environments, each one creating new credentials and demanding persistent access, that gap is going to become significantly more dangerous. </p><p>If identity monitoring and service account hygiene aren&#8217;t already in your security stack conversation with clients, both reports published this week give you everything you need to start it.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/p/the-msp-minute-tuesday-19-may-2026?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">MSP Minute is free every weekday for all MSPs. Please share the love with a friend</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/p/the-msp-minute-tuesday-19-may-2026?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.mspminute.com/p/the-msp-minute-tuesday-19-may-2026?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><h2>&#128994; The good guys just found 47 zero-days in three days&#8230; and got paid $1.3 million for it</h2><p>Pwn2Own Berlin 2026 wrapped up on Saturday and it was a good week for the white hats.</p><p>Security researchers collected $1,298,250 in rewards over three days after finding and exploiting 47 unique zero-day vulnerabilities across Windows 11, Microsoft Exchange, Microsoft Edge, VMware ESXi, Red Hat Linux, and AI coding agents. Every single one of those vulnerabilities gets reported privately to the vendor, who then has 90 days to patch before any details become public. <a href="https://www.bleepingcomputer.com/news/security/hackers-earn-1-298-250-for-47-zero-days-at-pwn2own-berlin-2026/">BleepingComputer</a></p><p>DEVCORE took the Master of Pwn title with 50.5 points and $505,000. The standout moment was Orange Tsai&#8217;s $200,000 payday for chaining three bugs to achieve remote code execution with system privileges on Microsoft Exchange.</p><p>The whole point of Pwn2Own is easy to lose in the headline numbers: this is organised, paid, responsible disclosure. Every bug found here is a bug that gets patched rather than sold to the highest bidder on the dark web. It is, in the most literal sense, hackers making the world safer. High five to the white hats!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!C8rp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e8a87c9-17cc-44bb-a03b-4ff51a6b9237_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!C8rp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e8a87c9-17cc-44bb-a03b-4ff51a6b9237_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!C8rp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e8a87c9-17cc-44bb-a03b-4ff51a6b9237_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!C8rp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e8a87c9-17cc-44bb-a03b-4ff51a6b9237_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!C8rp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e8a87c9-17cc-44bb-a03b-4ff51a6b9237_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!C8rp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e8a87c9-17cc-44bb-a03b-4ff51a6b9237_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3e8a87c9-17cc-44bb-a03b-4ff51a6b9237_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1590627,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.mspminute.com/i/198374013?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e8a87c9-17cc-44bb-a03b-4ff51a6b9237_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!C8rp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e8a87c9-17cc-44bb-a03b-4ff51a6b9237_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!C8rp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e8a87c9-17cc-44bb-a03b-4ff51a6b9237_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!C8rp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e8a87c9-17cc-44bb-a03b-4ff51a6b9237_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!C8rp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e8a87c9-17cc-44bb-a03b-4ff51a6b9237_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Right, enjoy your Tuesday. We&#8217;ll be back in your inbox tomorrow morning. See you then.</p>]]></content:encoded></item><item><title><![CDATA[The MSP Minute ⏱ Monday 18 May 2026]]></title><description><![CDATA[For Managed Service Providers worldwide. Today... Microsoft Exchange has an actively exploited zero-day... a big managed services report landed... and a small Mediterranean island just made history]]></description><link>https://www.mspminute.com/p/the-msp-minute-monday-18-may-2026</link><guid isPermaLink="false">https://www.mspminute.com/p/the-msp-minute-monday-18-may-2026</guid><pubDate>Mon, 18 May 2026 09:30:40 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!icqa!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd5fc2af-aa00-4b93-8087-a3e02d817642_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>&#128308; Microsoft Exchange has an actively exploited zero-day&#8230; and there's no permanent patch yet</h2><p>If you manage on-premises Exchange for any clients, heads up on this. </p><p>Microsoft disclosed CVE-2026-42897 on Thursday. It&#8217;s a cross-site scripting vulnerability in Exchange Server 2016, 2019, and Subscription Edition that&#8217;s being actively exploited in the wild. </p><p>An attacker sends an email; if the recipient opens it in Outlook Web Access, arbitrary JavaScript executes in their browser session. From there, an attacker can steal session cookies, spoof content, or perform actions on behalf of the user. Exchange Online is not affected. <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-exchange-zero-day-flaw-exploited-in-attacks/">BleepingComputer</a></p><p>A permanent patch is still in development. In the meantime Microsoft has issued automatic mitigations via its Exchange Emergency Mitigation Service. If you have EEMS enabled, it should have applied already. </p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading. Subscribe for free to get this MSP summary every weekday morning</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h2>&#128993; New data: 98% of companies say AI is now a core managed services requirement</h2><p>KPMG&#8217;s 2026 Managed Services Outlook, published last week and based on surveys of 1,224 senior leaders involved in managed services decisions, gives one of the clearest reads yet on where the market is heading.</p><p>98% of respondents say AI implementation is now a critical managed services capability. And AI management is expected to become the single largest area of managed services investment over the next two years, say 56% of respondents. <a href="https://www.channele2e.com/news/channel-brief-the-messy-middle-is-the-msp-opportunity">ChannelE2E</a></p><p>How does that change your AI plans going forward?</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/p/the-msp-minute-monday-18-may-2026?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">MSP Minute is free every weekday for all MSPs. Please share the love with a friend</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/p/the-msp-minute-monday-18-may-2026?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.mspminute.com/p/the-msp-minute-monday-18-may-2026?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><h2>&#128994; A small Mediterranean island just became the first country in the world to give every citizen free AI</h2><p>Malta, a country smaller than most cities with a population of just 574,000, announced on Saturday that it has struck a world-first deal with OpenAI.</p><p>Every Maltese resident and citizen gets a free year of ChatGPT Plus. The catch: they have to complete a government-backed AI literacy course first, developed by the University of Malta, covering what AI is, what it can&#8217;t do, and how to use it responsibly. <a href="https://openai.com/index/malta-chatgpt-plus-partnership/">OpenAI</a></p><p>No national government has done this before. Could you imagine this happening where you live??</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!icqa!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd5fc2af-aa00-4b93-8087-a3e02d817642_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!icqa!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd5fc2af-aa00-4b93-8087-a3e02d817642_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!icqa!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd5fc2af-aa00-4b93-8087-a3e02d817642_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!icqa!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd5fc2af-aa00-4b93-8087-a3e02d817642_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!icqa!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd5fc2af-aa00-4b93-8087-a3e02d817642_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!icqa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd5fc2af-aa00-4b93-8087-a3e02d817642_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fd5fc2af-aa00-4b93-8087-a3e02d817642_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2060014,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.mspminute.com/i/198222157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd5fc2af-aa00-4b93-8087-a3e02d817642_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!icqa!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd5fc2af-aa00-4b93-8087-a3e02d817642_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!icqa!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd5fc2af-aa00-4b93-8087-a3e02d817642_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!icqa!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd5fc2af-aa00-4b93-8087-a3e02d817642_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!icqa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd5fc2af-aa00-4b93-8087-a3e02d817642_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Hokey doke, that&#8217;s Monday done. We&#8217;ll be back in your inbox tomorrow morning. See you then.</p>]]></content:encoded></item><item><title><![CDATA[The MSP Minute ⏱ Friday 15 May 2026]]></title><description><![CDATA[For Managed Service Providers worldwide. Today... two more unpatched Windows zero-days... the most comprehensive MSP market report just landed... and possibly the best tech story of the year]]></description><link>https://www.mspminute.com/p/the-msp-minute-friday-15-may-2026</link><guid isPermaLink="false">https://www.mspminute.com/p/the-msp-minute-friday-15-may-2026</guid><pubDate>Fri, 15 May 2026 09:30:59 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!YYaW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48397858-1e41-440b-a463-ce1845d11a5e_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>&#128308; A disgruntled researcher just dropped two more unpatched Windows zero-days&#8230; and has threatened more are coming</h2><p>Do you remember BlueHammer, RedSun, and UnDefend? All Windows Defender exploits dropped by an anonymous researcher called Nightmare-Eclipse earlier this year. They were exploited in real attacks within days of publication.</p><p>This week Nightmare-Eclipse dropped two more unpatched zero-days: YellowKey and GreenPlasma. </p><p>YellowKey allows an attacker with physical access to a Windows 11 or Server 2022/2025 machine to bypass BitLocker encryption entirely. Plug in a USB drive, reboot into Windows Recovery Environment, enter a key sequence, and unrestricted access to the supposedly encrypted volume is granted. Independent security researcher Kevin Beaumont confirmed the exploit works. <a href="https://www.bleepingcomputer.com/news/security/windows-bitlocker-zero-day-gives-access-to-protected-drives-poc-released/">BleepingComputer</a></p><p>GreenPlasma is a privilege escalation flaw that hands system-level access to unprivileged users. The PoC is incomplete but security researchers say it&#8217;s enough of a starting point for a determined attacker to finish the job.</p><p>No patches yet. The researcher has claimed a &#8220;dead man&#8217;s switch&#8221; with more exploits ready to publish. Microsoft has not yet commented on the specific exploits. <a href="https://www.theregister.com/security/2026/05/13/disgruntled-researcher-releases-two-more-microsoft-zero-days/5239758">The Register</a></p><p>For clients with laptops, BitLocker alone is no longer sufficient. A PIN requirement on top of BitLocker is the recommended mitigation for YellowKey right now.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading. Subscribe for free to get this MSP summary every weekday morning</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h2>&#128993; The most comprehensive snapshot of the MSP market just dropped. And the AI revenue gap is widening</h2><p>GTIA published its State of the Channel 2026 global report this week, and of course, the headline is about AI. <a href="https://gtia.org/blog/state-of-the-channel-2026-a-global-industry-in-motion">GTIA</a></p><p>AI is already generating meaningful revenue for a significant portion of MSPs. </p><ul><li><p>In the UK and Ireland, over a third of providers report that between 11% and 25% of their revenue now comes from AI-related products and services</p></li><li><p>In North America, a quarter of MSPs self-identify as AI-driven, and are already generating AI revenue.</p></li></ul><p>The gap between those MSPs and the ones still figuring out where AI fits is starting to widen. The report is free to access for GTIA members.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/p/the-msp-minute-friday-15-may-2026?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">MSP Minute is free every weekday for all MSPs. Please share the love with a friend</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/p/the-msp-minute-friday-15-may-2026?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.mspminute.com/p/the-msp-minute-friday-15-may-2026?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><h2>&#128994; Someone just recovered $400,000 in Bitcoin they'd locked themselves out of 11 years ago. The story involves AI, an old college computer, and a very rude password</h2><p>In 2015, a college student bought Bitcoin at $250 a coin, changed their wallet password while drunk, and immediately forgot what they&#8217;d typed. </p><p>The wallet sat untouched for over eleven years while they tried approximately 7 trillion password combinations across multiple recovery tools. Nothing worked. </p><p>In a last-ditch effort recently, they dumped the entire contents of an old college computer into Claude. Which found a forgotten wallet backup file predating the password change, identified a bug in the recovery tool that had been silently blocking every previous attempt, and fixed it. </p><p>The wallet unlocked. And five Bitcoin, now worth approximately $400,000, were recovered. What a story! <a href="https://www.tomshardware.com/tech-industry/cryptocurrency/bitcoin-trader-recovers-usd400-000-using-claude-ai-after-losing-wallet-password-11-years-ago-bot-tried-3-5-trillion-passwords-before-decrypting-an-old-wallet-backup">Tom&#8217;s Hardware</a> <em>(fair warning: this contains some fruity language)</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YYaW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48397858-1e41-440b-a463-ce1845d11a5e_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YYaW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48397858-1e41-440b-a463-ce1845d11a5e_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!YYaW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48397858-1e41-440b-a463-ce1845d11a5e_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!YYaW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48397858-1e41-440b-a463-ce1845d11a5e_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!YYaW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48397858-1e41-440b-a463-ce1845d11a5e_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YYaW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48397858-1e41-440b-a463-ce1845d11a5e_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/48397858-1e41-440b-a463-ce1845d11a5e_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2358412,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.mspminute.com/i/197821011?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48397858-1e41-440b-a463-ce1845d11a5e_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!YYaW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48397858-1e41-440b-a463-ce1845d11a5e_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!YYaW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48397858-1e41-440b-a463-ce1845d11a5e_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!YYaW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48397858-1e41-440b-a463-ce1845d11a5e_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!YYaW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48397858-1e41-440b-a463-ce1845d11a5e_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Hooray! We made it through to the weekend. Have a great one. We&#8217;ll be back in your inbox on Monday morning.</p>]]></content:encoded></item><item><title><![CDATA[The MSP Minute ⏱ Wednesday 13 May 2026]]></title><description><![CDATA[For Managed Service Providers worldwide. Today... AI just built its first zero-day exploit... Android is getting its biggest security upgrade in years... and even cybercriminals need a vacation]]></description><link>https://www.mspminute.com/p/the-msp-minute-wednesday-13-may-2026-b12</link><guid isPermaLink="false">https://www.mspminute.com/p/the-msp-minute-wednesday-13-may-2026-b12</guid><pubDate>Thu, 14 May 2026 09:31:07 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!fsT_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bb7c15d-fc68-461c-9d6b-b45dd202bf76_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>&#128308; For the first time, Google caught an AI-generated zero-day exploit in the wild</h2><p>This is the moment security researchers have been warning about for years.</p><p>Google&#8217;s Threat Intelligence Group published a report on Monday confirming the first documented case of a cybercrime group using AI to discover and weaponise a previously unknown zero-day vulnerability. </p><p>The target was a popular open-source web-based system administration tool. The exploit, a Python script designed to bypass 2FA, was identified by Google before the group could launch its planned mass exploitation campaign. Google worked with the vendor to patch it quietly. <a href="https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access">Google Cloud Blog</a></p><p>The reason Google knew AI was involved: the code gave itself away. It had all the hallmarks of code written by an LLM.</p><p>The GTIG chief analyst put it plainly: &#8220;The reality is that the AI vulnerability race has already begun. For every zero-day we can trace back to AI, there are probably many more out there.&#8221; <a href="https://www.securityweek.com/google-detects-first-ai-generated-zero-day-exploit/">SecurityWeek</a></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading. Subscribe for free to get this MSP summary every weekday morning</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h2>&#128993; Do you manage mobile devices for clients? Android 17 is about to make your life easier</h2><p>Another Google story. It announced yesterday that Android 17, due next month, is getting its biggest security overhaul yet. Several features are directly relevant to MSPs managing devices in the field.</p><p>Verified financial calls: Android will now work with banking apps to automatically detect and terminate spoofed calls from scammers impersonating banks, before the scammer even gets to speak. <a href="https://www.bleepingcomputer.com/news/security/android-17-to-expand-banking-scam-call-and-privacy-protections/">BleepingComputer</a></p><p>Theft protection: The &#8220;Mark as Lost&#8221; feature now requires biometric authentication, so even a thief with the PIN can&#8217;t access or track-disable a reported device. Remote Lock and Theft Detection Lock will be enabled by default on all new Android 17 devices globally.</p><p>And for MDM specifically: Android Enterprise is getting Advanced Protection support later this year, meaning organisations can enforce Google&#8217;s strongest security settings across managed devices by policy. </p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/p/the-msp-minute-wednesday-13-may-2026-b12?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">MSP Minute is free every weekday for all MSPs. Please share the love with a friend</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/p/the-msp-minute-wednesday-13-may-2026-b12?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.mspminute.com/p/the-msp-minute-wednesday-13-may-2026-b12?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><h2>&#128994; Ransomware gangs take summer breaks too</h2><p>Every year, without fail, ransomware attack volumes drop between Q2 and Q3. Researchers have tracked this pattern consistently across multiple years and multiple groups.</p><p>The working theory, delivered with appropriate dry wit by the analysts at Industrial Cyber, is that threat actors take summer holidays. The data supports it. Attack volumes spike in Q1, hold through early Q2, then quietly dip as the weather improves. <a href="https://industrialcyber.co/reports/ransomware-reaches-elevated-new-normal-as-attack-volumes-hold-steady-into-2026-reshape-baseline-risk-expectations/">Industrial Cyber</a></p><p>The practical implication: the next six to eight weeks are historically the best window of the year for MSPs to get clients to sit down, review their security posture, and fix the things that have been on the list since January. </p><p>Book those reviews now. The bad guys will be back from the beach in September.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fsT_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bb7c15d-fc68-461c-9d6b-b45dd202bf76_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fsT_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bb7c15d-fc68-461c-9d6b-b45dd202bf76_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!fsT_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bb7c15d-fc68-461c-9d6b-b45dd202bf76_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!fsT_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bb7c15d-fc68-461c-9d6b-b45dd202bf76_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!fsT_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bb7c15d-fc68-461c-9d6b-b45dd202bf76_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fsT_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bb7c15d-fc68-461c-9d6b-b45dd202bf76_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1bb7c15d-fc68-461c-9d6b-b45dd202bf76_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2754339,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.mspminute.com/i/197641630?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bb7c15d-fc68-461c-9d6b-b45dd202bf76_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fsT_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bb7c15d-fc68-461c-9d6b-b45dd202bf76_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!fsT_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bb7c15d-fc68-461c-9d6b-b45dd202bf76_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!fsT_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bb7c15d-fc68-461c-9d6b-b45dd202bf76_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!fsT_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bb7c15d-fc68-461c-9d6b-b45dd202bf76_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Ooh, we are perilously close to the weekend. Have a great day, we&#8217;ll be back in your inbox tomorrow morning.</p>]]></content:encoded></item><item><title><![CDATA[The MSP Minute ⏱ Wednesday 13 May 2026]]></title><description><![CDATA[For Managed Service Providers worldwide. Today... companies are hiding 90% of ransomware attacks... May Patch Tuesday patched two Defender exploits... and the biggest MSP event in the UK starts]]></description><link>https://www.mspminute.com/p/the-msp-minute-wednesday-13-may-2026</link><guid isPermaLink="false">https://www.mspminute.com/p/the-msp-minute-wednesday-13-may-2026</guid><pubDate>Wed, 13 May 2026 09:31:22 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!9w8w!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7ee1a4a-fc2a-4f76-8846-e483b9a1b1f7_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>&#128308; Nine out of ten ransomware attacks never get reported. Here's what that means for your clients</h2><p>The number your clients never see is the one that should worry them most.</p><p>BlackFog published research this week showing that in Q1 2026, there were 264 publicly disclosed ransomware attacks globally. The actual number of attacks was 2,160, nearly ten times higher. </p><p>Companies are quietly paying ransoms, restoring from backups, and saying nothing. This ratio of hidden to disclosed attacks ticked up slightly from Q1 2025. <a href="https://www.cybersecuritydive.com/news/ransomware-undisclosed-attacks-blackfog/819595/">Cybersecurity Dive</a></p><p>The reason companies stay quiet is understandable. But the effect is that the public picture of ransomware risk is dramatically understated. </p><p>This is one of the most useful numbers in the MSP sales toolkit. When a client says &#8220;we&#8217;ve never had a problem,&#8221; the honest answer is that most organisations that DID have a problem didn&#8217;t tell anyone about it.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading. Subscribe for free to get this MSP summary every weekday morning</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h2>&#128993; May Patch Tuesday is done: 120 flaws fixed, no zero-days this month</h2><p>Yesterday&#8217;s Patch Tuesday addressed 120 vulnerabilities across Windows, Office, Azure, and Microsoft 365&#8230; including 17 critical flaws, 14 of which are remote code execution vulnerabilities.</p><p>The good news: no zero-days exploited in the wild this month, which makes it a relatively calm Patch Tuesday by recent standards. The Secure Boot certificate update we flagged yesterday is included. <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-may-2026-patch-tuesday-fixes-120-flaws-no-zero-days/">BleepingComputer</a></p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/p/the-msp-minute-wednesday-13-may-2026?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">MSP Minute is free every weekday for all MSPs. Please share the love with a friend</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/p/the-msp-minute-wednesday-13-may-2026?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.mspminute.com/p/the-msp-minute-wednesday-13-may-2026?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><h2>&#128994; The UK's biggest MSP event opens this morning. You going?</h2><p>The MSP Show opens its doors today at ExCeL London for its third time. It&#8217;s co-located with the SITS Service Desk and IT Support Show. <a href="https://www.mspshow.co.uk/blog/registration-now-open-msp-show-returns-for-its-third-edition-alongside-sits-on-13-14-may-2026/">MSP Show</a></p><p>If you&#8217;re there today or tomorrow, enjoy it. Hit reply and tell us if you&#8217;re heading over. </p><p>And we&#8217;ll keep an eye on any big announcements from the show floor today.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9w8w!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7ee1a4a-fc2a-4f76-8846-e483b9a1b1f7_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9w8w!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7ee1a4a-fc2a-4f76-8846-e483b9a1b1f7_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!9w8w!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7ee1a4a-fc2a-4f76-8846-e483b9a1b1f7_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!9w8w!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7ee1a4a-fc2a-4f76-8846-e483b9a1b1f7_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!9w8w!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7ee1a4a-fc2a-4f76-8846-e483b9a1b1f7_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9w8w!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7ee1a4a-fc2a-4f76-8846-e483b9a1b1f7_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a7ee1a4a-fc2a-4f76-8846-e483b9a1b1f7_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1850251,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.mspminute.com/i/197459751?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7ee1a4a-fc2a-4f76-8846-e483b9a1b1f7_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9w8w!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7ee1a4a-fc2a-4f76-8846-e483b9a1b1f7_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!9w8w!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7ee1a4a-fc2a-4f76-8846-e483b9a1b1f7_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!9w8w!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7ee1a4a-fc2a-4f76-8846-e483b9a1b1f7_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!9w8w!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7ee1a4a-fc2a-4f76-8846-e483b9a1b1f7_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>Enjoy your hump day. We&#8217;ll be back in your inbox tomorrow morning.</p>]]></content:encoded></item><item><title><![CDATA[The MSP Minute ⏱ Tuesday 12 May 2026]]></title><description><![CDATA[For Managed Service Providers worldwide. Today... Microsoft's biggest update in years is dropping right now... buried inside is a deadline you can't miss... and how much is your MSP worth?]]></description><link>https://www.mspminute.com/p/the-msp-minute-tuesday-12-may-2026</link><guid isPermaLink="false">https://www.mspminute.com/p/the-msp-minute-tuesday-12-may-2026</guid><pubDate>Tue, 12 May 2026 06:25:28 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!rY3e!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0bf40f2f-7563-4457-9458-d5712cd0fa91_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>&#128308; May Patch Tuesday is live&#8230; and this one is bigger than usual</h2><p>Updates are dropping from Microsoft right now and this month&#8217;s Patch Tuesday is expected to be a record-breaker.</p><p>The reason: Project Glasswing. In an unprecedented move, Microsoft joined forces with 11 other major tech companies, including Apple, Amazon, and Cisco, to use AI to hunt for vulnerabilities across their own software before attackers find them. </p><p>The result is a significantly higher volume of CVEs than normal. Expect fixes across the entire Microsoft portfolio. <a href="https://www.helpnetsecurity.com/2026/05/08/may-2026-patch-tuesday-forecast/">Help Net Security</a></p><p>Also watch for fixes for RedSun and UnDefend &#8212; the two Microsoft Defender exploits we flagged in April that remained unpatched after Patch Tuesday last month. Both have been actively exploited and both are expected to be addressed today.</p><p>BleepingComputer will have the full breakdown on this live page as it lands: <a href="https://www.bleepingcomputer.com/tag/patch-tuesday/">BleepingComputer</a></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading. Subscribe for free to get this MSP summary every weekday morning</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h2>&#128993; There's a Secure Boot deadline buried in today's update (you have 45 days)</h2><p>This one is easy to miss in the noise of Patch Tuesday.</p><p>Today&#8217;s update includes a critical Secure Boot certificate rollout. The original Secure Boot certificates, issued in 2011, expire on June 26. That&#8217;s 45 days away. Devices that receive today&#8217;s update are covered. Devices that miss it have one more chance in June&#8217;s Patch Tuesday, after which there&#8217;s no comfortable window remaining. <a href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/act-now-secure-boot-certificates-expire-in-june-2026/4426856">Microsoft</a></p><p>After June 26, unpatched devices enter what Microsoft describes as a &#8220;degraded security state&#8221;. They continue to function normally but can no longer receive future boot-level protections. Over time this leads to compatibility issues as newer OS versions, firmware, and Secure Boot-dependent software may fail to load.</p><p>Worth checking today that your patch management is picking this up across all client estates&#8230; especially any devices that have been offline or excluded from automatic updates.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/p/the-msp-minute-tuesday-12-may-2026?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">MSP Minute is free every weekday for all MSPs. Please share the love with a friend</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/p/the-msp-minute-tuesday-12-may-2026?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.mspminute.com/p/the-msp-minute-tuesday-12-may-2026?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><h2>&#128994; If you've ever wondered what your MSP is worth&#8230;</h2><p>MSP Channel Insights published a video yesterday featuring a panel discussion on financial visibility, profitability, and exit readiness in the MSP market. <a href="https://msp-channel.com/video/5167/financial-visibility-profitability-and-exit-readiness-in-the-msp-market">MSP Channel Insights</a></p><p>The timing is good. Private equity is still actively buying MSPs. Multiples remain strong for businesses with recurring revenue, clean financials, and documented processes. </p><p>The MSPs getting the best deals are the ones who started thinking about exit readiness two or three years before they were ready to sell, not six months before.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rY3e!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0bf40f2f-7563-4457-9458-d5712cd0fa91_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rY3e!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0bf40f2f-7563-4457-9458-d5712cd0fa91_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!rY3e!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0bf40f2f-7563-4457-9458-d5712cd0fa91_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!rY3e!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0bf40f2f-7563-4457-9458-d5712cd0fa91_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!rY3e!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0bf40f2f-7563-4457-9458-d5712cd0fa91_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rY3e!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0bf40f2f-7563-4457-9458-d5712cd0fa91_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0bf40f2f-7563-4457-9458-d5712cd0fa91_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1968729,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.mspminute.com/i/197313570?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0bf40f2f-7563-4457-9458-d5712cd0fa91_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rY3e!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0bf40f2f-7563-4457-9458-d5712cd0fa91_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!rY3e!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0bf40f2f-7563-4457-9458-d5712cd0fa91_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!rY3e!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0bf40f2f-7563-4457-9458-d5712cd0fa91_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!rY3e!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0bf40f2f-7563-4457-9458-d5712cd0fa91_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Enjoy Patch Tuesday! Hit reply and let us know if it&#8217;s something you look forward to or whether your heart sinks on this day once a month. We&#8217;ll be back in your inbox tomorrow morning.</p>]]></content:encoded></item><item><title><![CDATA[The MSP Minute ⏱ Monday 11 May 2026]]></title><description><![CDATA[For Managed Service Providers worldwide. Today... trouble for Ivanti again... Patch Tuesday is tomorrow... and The Register's readers have opinions about the new website. Many, many opinions]]></description><link>https://www.mspminute.com/p/the-msp-minute-monday-11-may-2026</link><guid isPermaLink="false">https://www.mspminute.com/p/the-msp-minute-monday-11-may-2026</guid><pubDate>Mon, 11 May 2026 06:17:51 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!8ks_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec4b62a-e005-4486-89a7-e6362a75c519_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>&#128308; Ivanti has another actively exploited zero-day. This is the 33rd time CISA has flagged one of their vulnerabilities</h2><p>If you manage any Ivanti Endpoint Manager Mobile deployments, check them this morning.</p><p>Ivanti disclosed CVE-2026-6973 on Thursday. It&#8217;s a high-severity flaw in EPMM that allows an authenticated admin-level attacker to execute arbitrary code remotely. CISA added it to the Known Exploited Vulnerabilities catalog the same day and gave federal agencies until yesterday to patch. <a href="https://www.bleepingcomputer.com/news/security/ivanti-warns-of-new-epmm-flaw-exploited-in-zero-day-attacks/">BleepingComputer</a></p><p>Ivanti patched four additional high-severity EPMM vulnerabilities at the same time, including one that allows unauthenticated remote code execution, and another that lets an attacker impersonate a registered Sentry host to obtain valid certificates. Those four have not yet been confirmed as exploited.</p><p>This is the 33rd Ivanti vulnerability CISA has confirmed as exploited in the wild. Patch to EPMM versions 12.6.1.1, 12.7.0.1, or 12.8.0.1. And if you haven&#8217;t rotated credentials since January&#8217;s Ivanti breach, do that too. It significantly reduces the risk from this specific flaw.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading. Subscribe for free to get this MSP summary every weekday morning</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h2>&#128993; Patch Tuesday is tomorrow (after last month's domain controller disaster, you'll want to be ready)</h2><p>Microsoft&#8217;s May Patch Tuesday lands tomorrow.</p><p>No official preview yet of what&#8217;s coming, but given April&#8217;s record 167 vulnerabilities and the out-of-band emergency fix for domain controller reboot loops that followed, it&#8217;s worth having your patch management process off the bench, warmed up and ready to play. <a href="https://www.bleepingcomputer.com/tag/patch-tuesday/">BleepingComputer</a></p><p>We&#8217;ll cover anything significant in tomorrow&#8217;s MSP Minute.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/p/the-msp-minute-monday-11-may-2026?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">MSP Minute is free every weekday for all MSPs. Please share the love with a friend</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/p/the-msp-minute-monday-11-may-2026?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.mspminute.com/p/the-msp-minute-monday-11-may-2026?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><h2>&#128994; The Register got a new website last week. Its readers have thoughts&#8230; 200 of them</h2><p>On Thursday we told you The Register had launched its first redesign in over 20 years. What we didn&#8217;t know then was how its readers would react.</p><p>The answer is: at considerable length. The forum thread now runs to over 200 comments from IT professionals methodically cataloguing every grievance with surgical precision. </p><p>Highlights include one reader describing the new design as having a &#8220;Homer Simpson&#8217;s Website &#8216;Look what I did, Marge!&#8217; effect.&#8221; Another noted approvingly that at least RSS was kept, because &#8220;you obviously know your audience.&#8221; A third spent three paragraphs on the masthead width. <a href="https://forums.theregister.com/forum/all/2026/05/06/202614/">The Register Forums</a></p><p>Honestly, it&#8217;s the most relatable thing on the internet this morning. Nobody reviews a UI change like an IT professional who didn&#8217;t ask for it &#128515;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8ks_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec4b62a-e005-4486-89a7-e6362a75c519_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8ks_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec4b62a-e005-4486-89a7-e6362a75c519_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!8ks_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec4b62a-e005-4486-89a7-e6362a75c519_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!8ks_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec4b62a-e005-4486-89a7-e6362a75c519_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!8ks_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec4b62a-e005-4486-89a7-e6362a75c519_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8ks_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec4b62a-e005-4486-89a7-e6362a75c519_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/aec4b62a-e005-4486-89a7-e6362a75c519_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1598692,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.mspminute.com/i/197178965?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec4b62a-e005-4486-89a7-e6362a75c519_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8ks_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec4b62a-e005-4486-89a7-e6362a75c519_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!8ks_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec4b62a-e005-4486-89a7-e6362a75c519_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!8ks_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec4b62a-e005-4486-89a7-e6362a75c519_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!8ks_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec4b62a-e005-4486-89a7-e6362a75c519_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Right, that&#8217;s your lot for today. Have a fun day Monday.</p>]]></content:encoded></item><item><title><![CDATA[The MSP Minute ⏱ Friday 8 May 2026]]></title><description><![CDATA[For Managed Service Providers worldwide. Today... the world's most widely used education platform got breached (twice)... Huntress with more distributors... and Google's helping itself to 4GB of space]]></description><link>https://www.mspminute.com/p/the-msp-minute-friday-8-may-2026</link><guid isPermaLink="false">https://www.mspminute.com/p/the-msp-minute-friday-8-may-2026</guid><pubDate>Fri, 08 May 2026 06:37:43 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!c97K!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbbdf8a9-2c43-45dd-8ce4-4dcd440a8d78_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>&#128308; 280 million student records stolen&#8230; and the platform that got breached thought it had contained the attack</h2><p>This is a developing story.</p><p>ShinyHunters breached Instructure, the company behind Canvas, the learning management system used by 41% of higher education institutions in North America and thousands of schools globally. Data on 280 million students and staff across 8,809 institutions has been stolen. Names, email addresses, student IDs, and private messages between students and teachers. <a href="https://www.bleepingcomputer.com/news/security/instructure-hacker-claims-data-theft-from-8-800-schools-universities/">BleepingComputer</a></p><p>On May 2, Instructure said the incident was contained. On May 7, ShinyHunters replaced the Canvas login page with a ransom demand (for the second time) demonstrating publicly that it wasn&#8217;t. </p><p>Harvard, Duke, Penn, and thousands of other institutions woke up yesterday to find their students locked out during final exams. The deadline to pay is May 12. <a href="https://krebsonsecurity.com/2026/05/canvas-breach-disrupts-schools-colleges-nationwide/">Krebs on Security</a></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading. Subscribe for free to get this MSP summary every weekday morning</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h2>&#128993; <strong>Huntress just got a lot easier to buy, through distributors MSPs already use</strong></h2><p>Good news if you&#8217;ve been thinking about buying from Huntress.</p><p>It announced four new distribution partnerships this week: Ingram Micro, Vertosoft, Liquid PC, and QBS Software. <a href="https://www.channeldive.com/news/huntress-cybersecurity-partner-expansion-tsd-msp/819353/">Channel Dive</a></p><p>Huntress currently protects more than 250,000 organisations and 5 million endpoints. The VP of Channels was explicit that this isn&#8217;t a move away from MSPs&#8230; it&#8217;s a move toward reaching more of them, faster, with less friction. </p><p>If Huntress is already in your stack, nothing changes. If it isn&#8217;t, it just got easier to add.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/p/the-msp-minute-friday-8-may-2026?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">MSP Minute is free every weekday for all MSPs. Please share the love with a friend</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/p/the-msp-minute-friday-8-may-2026?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.mspminute.com/p/the-msp-minute-friday-8-may-2026?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><h2>&#128994; Google&#8217;s been quietly helping itself to 4GB of your clients' hard drives. Surprise!</h2><p>It turns out Google Chrome has been silently downloading a 4GB AI model (Gemini Nano) onto user devices without asking. No notification or consent prompt. And if you find it and delete it, Chrome just downloads it again. <a href="https://www.theregister.com/ai-and-ml/2026/05/07/chrome-silently-installs-a-4-gb-local-llm-on-your-computer/5230893">The Register</a></p><p>The kicker: the &#8220;AI Mode&#8221; button now visible in Chrome&#8217;s address bar doesn&#8217;t even use the local model. Every query still gets sent to Google&#8217;s servers anyway. So Chrome is filling 4GB of your clients&#8217; hard drives with an AI model that their browser&#8217;s own AI feature doesn&#8217;t actually use.</p><p>Google&#8217;s response: this has been happening since 2024, and there&#8217;s now a setting to turn it off. You&#8217;re welcome.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!c97K!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbbdf8a9-2c43-45dd-8ce4-4dcd440a8d78_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!c97K!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbbdf8a9-2c43-45dd-8ce4-4dcd440a8d78_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!c97K!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbbdf8a9-2c43-45dd-8ce4-4dcd440a8d78_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!c97K!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbbdf8a9-2c43-45dd-8ce4-4dcd440a8d78_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!c97K!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbbdf8a9-2c43-45dd-8ce4-4dcd440a8d78_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!c97K!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbbdf8a9-2c43-45dd-8ce4-4dcd440a8d78_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bbbdf8a9-2c43-45dd-8ce4-4dcd440a8d78_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1184859,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.mspminute.com/i/196869551?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbbdf8a9-2c43-45dd-8ce4-4dcd440a8d78_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!c97K!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbbdf8a9-2c43-45dd-8ce4-4dcd440a8d78_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!c97K!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbbdf8a9-2c43-45dd-8ce4-4dcd440a8d78_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!c97K!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbbdf8a9-2c43-45dd-8ce4-4dcd440a8d78_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!c97K!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbbdf8a9-2c43-45dd-8ce4-4dcd440a8d78_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>Hooray, we made it to Friday! Hope you have an easy one today. We&#8217;ll be back in your inbox on Monday morning. Enjoy.</p>]]></content:encoded></item><item><title><![CDATA[The MSP Minute ⏱ Thursday 7 May 2026]]></title><description><![CDATA[For Managed Service Providers worldwide. Today... a state hacking group is using Teams to get in... Microsoft Defender had a bit of a moment... and a beloved IT publication just did something "oooo"]]></description><link>https://www.mspminute.com/p/the-msp-minute-thursday-7-may-2026</link><guid isPermaLink="false">https://www.mspminute.com/p/the-msp-minute-thursday-7-may-2026</guid><pubDate>Thu, 07 May 2026 07:51:16 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!B593!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbae934f-a758-432a-b2fc-54e7a9dbd216_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>&#128308; Iranian state hackers are pretending to be ransomware gangs&#8230; using Teams to get in</h2><p>This one is worth reading carefully, because the attack method will be familiar.</p><p>A threat group tracked as MuddyWater, linked to Iranian state intelligence, has been caught running a campaign that deliberately looks like a ransomware attack&#8230; but isn&#8217;t. </p><p>The goal isn&#8217;t money. It&#8217;s persistent, undetected access. Rapid7 published the full analysis yesterday after observing the campaign earlier this year. <a href="https://thehackernews.com/2026/05/muddywater-uses-microsoft-teams-to.html">The Hacker News</a></p><p>The attack starts with Teams. Attackers pose as IT helpdesk staff, use interactive screen-sharing to harvest credentials, and manipulate MFA approval. Once inside, they deploy remote access tools including DWAgent and AnyDesk.</p><p>The ransomware elements are essentially theatre: chaos ransomware artifacts are dropped to look opportunistic, but file encryption doesn&#8217;t actually happen. The real objective is a quiet backdoor that stays open long after the &#8220;incident&#8221; appears to be over.</p><p>The uncomfortable thing is that this attack looks exactly like the helpdesk impersonation campaigns we&#8217;ve covered all month (while the difference is who&#8217;s behind it and why). A financially motivated criminal group wants to encrypt and extort. Whereas a nation-state wants to sit silently inside your clients&#8217; networks for months. </p><p>Worth making sure your clients know that your techs will never initiate an unsolicited Teams session asking for screen access.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading. Subscribe for free to get this MSP summary every weekday morning</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h2>&#128993; <strong>Microsoft Defender briefly decided that legitimate security certificates were malware. It's now fixed</strong></h2><p>If your team got flooded with high-severity Defender alerts earlier this week, this is why.</p><p>On April 30, Microsoft pushed a Defender signature update that incorrectly flagged two widely trusted DigiCert root certificates as Trojan:Win32/Cerdigent.A!dha malware. </p><p>On affected systems, Defender didn&#8217;t just alert&#8230; it automatically quarantined and removed the certificates from the Windows trust store. Without those certificates, systems risk failing to validate HTTPS connections and breaking code-signing verification for legitimate software. <a href="https://www.bleepingcomputer.com/news/security/microsoft-defender-wrongly-flags-digicert-certs-as-trojan-win32-cerdigentadha/">BleepingComputer</a></p><p>The fix is out. Microsoft pushed a corrected signature update and the certificates are being automatically restored on affected machines. </p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/p/the-msp-minute-thursday-7-may-2026?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">MSP Minute is free every weekday for all MSPs. Please share the love with a friend</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/p/the-msp-minute-thursday-7-may-2026?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.mspminute.com/p/the-msp-minute-thursday-7-may-2026?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><h2>&#128994; The Register just got a new website (for the first time since Vista)</h2><p>If you visited The Register this morning and thought your browser was broken&#8230; it wasn&#8217;t.</p><p>The beloved IT news institution that has been the spiritual home of grumpy, brilliant, sardonic technology professionals since 1998, launched a brand new website design yesterday. Their first redesign in over 20 years. <a href="https://www.theregister.com/site-news/2026/05/06/weve-only-gone-and-done-it-changed-what-youre-used-to/5230826">The Register</a></p><p>The piece they wrote announcing it is exactly what you&#8217;d expect: self-deprecating, warm, and written in the voice of someone who has been putting off a very large piece of technical debt for approximately two decades. They describe the old system as held together with &#8220;tape and glue.&#8221;</p><p>If you&#8217;re not reading The Register every morning alongside the MSP Minute, you should be. Nobody covers enterprise technology with more wit, more depth, or more justified scepticism. And now it looks kinda nice too.</p><p>PS <a href="https://web.archive.org/web/19980628145626/https://www.theregister.co.uk/">here&#8217;s what their website first looked like in 1998</a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!B593!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbae934f-a758-432a-b2fc-54e7a9dbd216_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!B593!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbae934f-a758-432a-b2fc-54e7a9dbd216_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!B593!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbae934f-a758-432a-b2fc-54e7a9dbd216_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!B593!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbae934f-a758-432a-b2fc-54e7a9dbd216_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!B593!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbae934f-a758-432a-b2fc-54e7a9dbd216_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!B593!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbae934f-a758-432a-b2fc-54e7a9dbd216_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dbae934f-a758-432a-b2fc-54e7a9dbd216_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3360207,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.mspminute.com/i/196746377?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbae934f-a758-432a-b2fc-54e7a9dbd216_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!B593!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbae934f-a758-432a-b2fc-54e7a9dbd216_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!B593!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbae934f-a758-432a-b2fc-54e7a9dbd216_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!B593!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbae934f-a758-432a-b2fc-54e7a9dbd216_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!B593!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbae934f-a758-432a-b2fc-54e7a9dbd216_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>Well, would you believe it, that&#8217;s Thursday done. We&#8217;ll be back in your inbox tomorrow morning for the final time this week. Have a fun day.</p>]]></content:encoded></item><item><title><![CDATA[The MSP Minute ⏱ Wednesday 6 May 2026]]></title><description><![CDATA[For Managed Service Providers worldwide. Today... hackers are using your own RMM tools against you... Microsoft's new AI role had a dangerous identity flaw... and a security vendor's all in on MSPs]]></description><link>https://www.mspminute.com/p/the-msp-minute-wednesday-6-may-2026</link><guid isPermaLink="false">https://www.mspminute.com/p/the-msp-minute-wednesday-6-may-2026</guid><pubDate>Wed, 06 May 2026 06:44:30 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gmWi!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0c3f22b-6d32-46a6-9881-10316cc6169c_354x354.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>&#128308; Attackers are weaponising legitimate RMM tools to break into client networks. And it's working on 80+ organisations</h2><p>A phishing campaign tracked as VENOMOUS#HELPER has compromised over 80 organisations by delivering customised versions of SimpleHelp and ScreenConnect.</p><p>Victims install what looks like a legitimate remote access tool, not realising it&#8217;s been modified. Once installed, the attacker has persistent access that&#8217;s extremely difficult to detect because the software appears completely normal. <a href="https://thehackernews.com/2026/05/phishing-campaign-hits-80-orgs-using.html">The Hacker News</a></p><p>The attacker deploys both SimpleHelp and ScreenConnect simultaneously, deliberately creating a redundant dual-channel backdoor. Block one, the other stays active. Security firm Securonix links the campaign to a financially motivated group operating as a ransomware precursor&#8230; meaning the goal is to establish quiet, persistent access before launching a bigger attack later.</p><p>Two things worth doing today. First, check whether any of your clients have received unsolicited requests to install remote access software recently. Second, review your own RMM deployment practices. Are clients able to verify that a remote session request genuinely came from you?</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading. Subscribe for free to get this MSP summary every weekday morning</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h2>&#128993; <strong>Microsoft's new AI admin role had a flaw that could hand attackers the keys to an entire tenant</strong></h2><p>Worth understanding before you have the E7 and Agent 365 conversation with clients.</p><p>Researchers at identity security firm Silverfort discovered that Microsoft&#8217;s Agent ID Administrator role (a new role introduced to manage AI agent identities in Entra ID) had a dangerous scope gap. It was designed to manage agent-related objects only, but in practice it could take ownership of any service principal across the entire tenant. <a href="https://thehackernews.com/2026/04/microsoft-patches-entra-id-role-flaw.html">The Hacker News</a></p><p>In plain English: a role meant for managing AI agents turned out to have accidental admin-level power over every app identity in the organisation. An attacker assigned that role could silently take over high-privileged service principals, inject their own credentials, and operate as those applications (with all their permissions) while appearing to be doing nothing unusual.</p><p>Microsoft patched it on April 9, so no action needed today. But the timing is worth noting. Agent 365 launched last Friday. AI agent identities are going to multiply fast across client tenants. This won&#8217;t be the last identity flaw in the new AI layer.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/p/the-msp-minute-wednesday-6-may-2026?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">MSP Minute is free every weekday for all MSPs. Please share the love with a friend</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.mspminute.com/p/the-msp-minute-wednesday-6-may-2026?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.mspminute.com/p/the-msp-minute-wednesday-6-may-2026?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><h2>&#128994; A $150M-funded AI security vendor just decided MSPs are the only way it wants to sell</h2><p>Sublime Security, named the #1 security company on Fast Company&#8217;s Most Innovative Companies list this year, has gone 100% channel-led and launched a formal MSP and MSSP partner program. <a href="https://www.channele2e.com/news/sublime-security-builds-channel-program-around-email-security-services">ChannelE2E</a></p><p>The program includes protected margins, deal registration, dedicated partner resources, and hands-on technical enablement. The product itself is AI-powered email security that partners can tune specifically for each client, which turns it into a genuine managed service rather than just a resale.</p><p>Email remains the single biggest attack vector. Phishing accounts for the majority of breaches. And a well-funded, award-winning vendor just decided it can only reach its customers through people like you. </p><p></p><p>Okay, that&#8217;s Wednesday done. We&#8217;ll be back in your inbox tomorrow morning. Have a fun day.</p>]]></content:encoded></item></channel></rss>