Search a title or topic

Over 20 million podcasts, powered by 

Player FM logo
Artwork

Content provided by Dave Sobel and MSP Radio. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Dave Sobel and MSP Radio or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.
Player FM - Podcast App
Go offline with the Player FM app!

Microsoft 365 Copilot's Security Flaw, AI in Misinformation, and Emerging Cybersecurity Solutions

14:41
 
Share
 

Manage episode 488399092 series 2555839
Content provided by Dave Sobel and MSP Radio. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Dave Sobel and MSP Radio or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.

Microsoft 365 Copilot has been identified as having a significant security vulnerability known as Echo Leak, which allows hackers to access sensitive information without user interaction. This zero-click exploit was discovered by AIM Security after three months of reverse engineering the software. Although Microsoft claims the issue has been addressed and no customers were affected, experts warn that this flaw reflects deeper security concerns in AI systems, reminiscent of vulnerabilities seen in software two decades ago. The incident raises critical questions about the security of AI agents that have ambient access to data and the need for rethinking endpoint protection and trust boundaries.

OpenAI's latest threat report reveals that state-level actors, including those linked to North Korea and Russia, are exploiting ChatGPT for cyber operations. The report outlines ten operations that were shut down, including the generation of fake job applications and social media content aimed at spreading disinformation. Notably, some campaigns were traced back to China, showcasing the use of AI in creating deceptive online personas. This highlights the strategic use of AI by malicious actors, emphasizing the need for heightened awareness and security measures.

ConnectWise is facing scrutiny over its recent digital certificate updates, urging customers to update their ScreenConnect, Automate, and ConnectWise RMM solutions. The company is attempting to distance itself from a previously disclosed nation-state breach while addressing concerns raised by a third-party researcher regarding configuration data handling. The rushed certificate rotation has led to reduced confidence among customers, especially given the recent history of exploitation of ScreenConnect. This situation underscores the importance of transparency and trust in vendor relationships, as well as the need for managed service providers to audit their update processes.

New tools from Huntress, Netgear, and Varonis signal a shift towards more automated and resilient security solutions. Huntress has launched a Threat Simulator to enhance user engagement in security training, while Netgear's acquisition of Exium aims to simplify networking and security for managed service providers. Varonis has introduced a Model Context Protocol Server to integrate AI tools into its data security platform. These developments reflect a growing trend in cybersecurity towards realism, automation, and simplification, emphasizing the need for IT service providers to adapt and align with these evolving security landscapes.

Three things to know today

00:00 From Copilot to Cybercrime: How AI Agents Are Creating New Frontlines in Espionage and Misinformation

05:54 ConnectWise Urges Immediate Updates Amid Certificate Rotation, Rekindling Security Concerns After Prior Breach

08:45 Automation, Engagement, and Recovery: Security Vendors Roll Out Tools That Align with MSP Priorities

Supported by:

https://www.huntress.com/mspradio/

https://cometbackup.com/?utm_source=mspradio&utm_medium=podcast&utm_campaign=sponsorship

💼 All Our Sponsors

Support the vendors who support the show:

👉 https://businessof.tech/sponsors/

🚀 Join Business of Tech Plus

Get exclusive access to investigative reports, vendor analysis, leadership briefings, and more.

👉 https://businessof.tech/plus

🎧 Subscribe to the Business of Tech

Want the show on your favorite podcast app or prefer the written versions of each story?

📲 https://www.businessof.tech/subscribe

📰 Story Links & Sources

Looking for the links from today’s stories?

Every episode script — with full source links — is posted at:

🌐 https://www.businessof.tech

🎙 Want to Be a Guest?

Pitch your story or appear on Business of Tech: Daily 10-Minute IT Services Insights:

💬 https://www.podmatch.com/hostdetailpreview/businessoftech

🔗 Follow Business of Tech

LinkedIn: https://www.linkedin.com/company/28908079

YouTube: https://youtube.com/mspradio

Bluesky: https://bsky.app/profile/businessof.tech

Instagram: https://www.instagram.com/mspradio

TikTok: https://www.tiktok.com/@businessoftech

Facebook: https://www.facebook.com/mspradionews

Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

  continue reading

1842 episodes

Artwork
iconShare
 
Manage episode 488399092 series 2555839
Content provided by Dave Sobel and MSP Radio. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Dave Sobel and MSP Radio or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.

Microsoft 365 Copilot has been identified as having a significant security vulnerability known as Echo Leak, which allows hackers to access sensitive information without user interaction. This zero-click exploit was discovered by AIM Security after three months of reverse engineering the software. Although Microsoft claims the issue has been addressed and no customers were affected, experts warn that this flaw reflects deeper security concerns in AI systems, reminiscent of vulnerabilities seen in software two decades ago. The incident raises critical questions about the security of AI agents that have ambient access to data and the need for rethinking endpoint protection and trust boundaries.

OpenAI's latest threat report reveals that state-level actors, including those linked to North Korea and Russia, are exploiting ChatGPT for cyber operations. The report outlines ten operations that were shut down, including the generation of fake job applications and social media content aimed at spreading disinformation. Notably, some campaigns were traced back to China, showcasing the use of AI in creating deceptive online personas. This highlights the strategic use of AI by malicious actors, emphasizing the need for heightened awareness and security measures.

ConnectWise is facing scrutiny over its recent digital certificate updates, urging customers to update their ScreenConnect, Automate, and ConnectWise RMM solutions. The company is attempting to distance itself from a previously disclosed nation-state breach while addressing concerns raised by a third-party researcher regarding configuration data handling. The rushed certificate rotation has led to reduced confidence among customers, especially given the recent history of exploitation of ScreenConnect. This situation underscores the importance of transparency and trust in vendor relationships, as well as the need for managed service providers to audit their update processes.

New tools from Huntress, Netgear, and Varonis signal a shift towards more automated and resilient security solutions. Huntress has launched a Threat Simulator to enhance user engagement in security training, while Netgear's acquisition of Exium aims to simplify networking and security for managed service providers. Varonis has introduced a Model Context Protocol Server to integrate AI tools into its data security platform. These developments reflect a growing trend in cybersecurity towards realism, automation, and simplification, emphasizing the need for IT service providers to adapt and align with these evolving security landscapes.

Three things to know today

00:00 From Copilot to Cybercrime: How AI Agents Are Creating New Frontlines in Espionage and Misinformation

05:54 ConnectWise Urges Immediate Updates Amid Certificate Rotation, Rekindling Security Concerns After Prior Breach

08:45 Automation, Engagement, and Recovery: Security Vendors Roll Out Tools That Align with MSP Priorities

Supported by:

https://www.huntress.com/mspradio/

https://cometbackup.com/?utm_source=mspradio&utm_medium=podcast&utm_campaign=sponsorship

💼 All Our Sponsors

Support the vendors who support the show:

👉 https://businessof.tech/sponsors/

🚀 Join Business of Tech Plus

Get exclusive access to investigative reports, vendor analysis, leadership briefings, and more.

👉 https://businessof.tech/plus

🎧 Subscribe to the Business of Tech

Want the show on your favorite podcast app or prefer the written versions of each story?

📲 https://www.businessof.tech/subscribe

📰 Story Links & Sources

Looking for the links from today’s stories?

Every episode script — with full source links — is posted at:

🌐 https://www.businessof.tech

🎙 Want to Be a Guest?

Pitch your story or appear on Business of Tech: Daily 10-Minute IT Services Insights:

💬 https://www.podmatch.com/hostdetailpreview/businessoftech

🔗 Follow Business of Tech

LinkedIn: https://www.linkedin.com/company/28908079

YouTube: https://youtube.com/mspradio

Bluesky: https://bsky.app/profile/businessof.tech

Instagram: https://www.instagram.com/mspradio

TikTok: https://www.tiktok.com/@businessoftech

Facebook: https://www.facebook.com/mspradionews

Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

  continue reading

1842 episodes

Усі епізоди

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Copyright 2025 | Privacy Policy | Terms of Service | | Copyright
Listen to this show while you explore
Play