Business of Tech: Daily 10-Minute IT Services Insights

Ransomware Attacks Surge, Google AI Vulnerabilities Exposed, and New Malware Analysis Tool Released


Listen Later

Two sophisticated ransomware groups, Akira and Lynx, are increasingly targeting managed service providers (MSPs) and small businesses by exploiting stolen credentials and vulnerabilities. Together, they have compromised over 365 organizations, with Akira targeting major firms like Hitachi Vantara and Lynx focusing on critical infrastructure, including a CBS affiliate in Chattanooga, Tennessee. Both groups utilize double extortion tactics, combining file encryption with data theft to pressure victims into paying ransoms. This shift in tactics highlights the evolving threat landscape for MSPs and small businesses.

In response to the growing cybersecurity threats, the U.S. Cybersecurity and Infrastructure Security Agency has released Thorium, an open-source platform designed for malware and forensic analysis. Thorium can automate tasks and process over 10 million files per hour, empowering IT professionals without in-house malware analysis capabilities to conduct effective preliminary analyses. This tool aims to enhance cybersecurity operations and better manage risks associated with complex malware threats.

Additionally, SonicWall has issued a warning to its customers to disable SSL Virtual Private Network (VPN) services due to active ransomware attacks targeting its systems. Meanwhile, Google's AI-powered bug hunter, Big Sleep, has identified 20 security vulnerabilities in popular open-source software, raising concerns about the reliability of AI-generated bug reports. A newly discovered prompt injection vulnerability in Google's Gemini AI chatbot poses serious security risks, enabling attackers to craft convincing phishing campaigns without relying on links or attachments.

The podcast also discusses the alarming rise in cybersecurity incidents, particularly social engineering attacks, which have tripled in the first half of 2025. A report from Level Blue indicates that social engineering now accounts for 39% of initial access incidents, with fake CAPTCHA schemes rising dramatically. Furthermore, the report highlights the risks associated with unauthorized AI tool usage, revealing that 97% of organizations lack adequate access controls, exposing sensitive data to potential threats. This underscores the need for organizations to strengthen their defenses and educate users on emerging threats.

 

Four things to know today

00:00 Attackers Up Their Game: Ransomware Hits MSPs, SonicWall Vulnerable, and Google’s AI Found Exploitable

05:53 Social Engineering Surges as Shadow AI Breaches Drive Up Cyber Costs and Risk Exposure

08:35 Neglected Tech, Rising Risk: Email and Printers Still Expose Businesses to Modern Threats

11:04 From Ransomware to Retirements: Vendor Shifts Reveal Risks and Realignment in the IT Channel

 

This is the Business of Tech.   

 

 

Supported by:  https://cometbackup.com/?utm_source=mspradio&utm_medium=podcast&utm_campaign=sponsorship

 

https://getflexpoint.com/msp-radio/

 

Tell us about a newsletter! https://bit.ly/biztechnewsletter

 

 

All our Sponsors:   https://businessof.tech/sponsors/

 

Do you want the show on your podcast app or the written versions of the stories? Subscribe to the Business of Tech: https://www.businessof.tech/subscribe/

Looking for a link from the stories? The entire script of the show, with links to articles, are posted in each story on https://www.businessof.tech/

 

Support the show on Patreon: https://patreon.com/mspradio/

 

Want to be a guest on Business of Tech: Daily 10-Minute IT Services Insights? Send Dave Sobel a message on PodMatch, here: https://www.podmatch.com/hostdetailpreview/businessoftech

 

Want our stuff? Cool Merch? Wear “Why Do We Care?” - Visit https://mspradio.myspreadshop.com

 

Follow us on:

LinkedIn: https://www.linkedin.com/company/28908079/

YouTube: https://youtube.com/mspradio/

Facebook: https://www.facebook.com/mspradionews/

Instagram: https://www.instagram.com/mspradio/

TikTok: https://www.tiktok.com/@businessoftech

Bluesky: https://bsky.app/profile/businessof.tech

...more
View all episodesView all episodes
Download on the App Store

Business of Tech: Daily 10-Minute IT Services InsightsBy MSP Radio

  • 4.9
  • 4.9
  • 4.9
  • 4.9
  • 4.9

4.9

89 ratings


More shows like Business of Tech: Daily 10-Minute IT Services Insights

View all
This Week in Tech (Audio) by TWiT

This Week in Tech (Audio)

3,017 Listeners

WSJ Tech News Briefing by The Wall Street Journal

WSJ Tech News Briefing

1,637 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

1,983 Listeners

WSJ Your Money Briefing by The Wall Street Journal

WSJ Your Money Briefing

1,716 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

640 Listeners

a16z Podcast by Andreessen Horowitz

a16z Podcast

1,059 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,017 Listeners

Tech Brew Ride Home by Morning Brew

Tech Brew Ride Home

953 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

164 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

76 Listeners

The Prof G Pod with Scott Galloway by Vox Media Podcast Network

The Prof G Pod with Scott Galloway

5,421 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

128 Listeners

Hard Fork by The New York Times

Hard Fork

5,462 Listeners

The AI Daily Brief (Formerly The AI Breakdown): Artificial Intelligence News and Analysis by Nathaniel Whittemore

The AI Daily Brief (Formerly The AI Breakdown): Artificial Intelligence News and Analysis

505 Listeners

Everyday AI Podcast – An AI and ChatGPT Podcast by Everyday AI

Everyday AI Podcast – An AI and ChatGPT Podcast

94 Listeners