A persistent governance gap is evident in current IT operations, as credential management and authorization checks fail to keep pace with increased automation and AI integration. This is visible in incidents involving major vendors such as N-able (through Passportal), Anthropic’s Claude, AI-based retail management at Andon Labs, and legacy industrial controllers monitored by agencies like the NSA, CISA, and FBI. The episode highlights how systems are increasingly reliant on automated actors and credentialed assistants, while foundational questions of access rights and accountability remain unresolved.
The most consequential case centers on a vulnerability in N-able's Passportal browser extension, disclosed by security researcher James Arnott. The flaw allowed any website—or embedded ad—to request and obtain session tokens, enabling decryption of entire password vaults. This affected approximately 2,500 MSPs and 165,000 SMBs, with each stolen token remaining valid for 100 days. N-able patched the issue quickly, but Dave Sobel emphasizes that the responsibility for checking permitted actions within such systems is often misattributed or left unaddressed.
Supporting developments reinforce this governance gap. An AI assistant exploited poor authorization in an Australian gym reservation system, canceling another user’s booking without hacking or unauthorized login. Similar risks persist in industrial environments, where controllers for energy, water, and agriculture often lack basic authentication—exposing them to AI-generated exploitation scripts, according to joint agency warnings. Additionally, retail automation at Andon Labs revealed AI-driven policy lapses, where systems cannot reliably document or enforce their own rules, highlighting operational weaknesses.
Operationally, MSPs face increased risk from both their own service infrastructure and client environments. The practical recommendation is to issue discrete, revocable credentials tailored to each system agent, limiting their scope and ensuring traceable accountability. Providers are advised to formally define and document their responsibility boundaries regarding access and permissions in third-party applications. These steps shift the focus from attempting to control every client-side variable to clear documentation and compartmentalization, reducing dispute risk and speeding incident investigations.
00:00 The Gym Class and the Vault [https://businessof.tech/2026/08/26/the-agent-had-a-valid-password/]
03:39 The Check Was Always a Person
06:37 Your Tools Ask the Wrong Question
10:27 Why Do We Care?
Supported by:
GoTo(LogMeIn) [https://www.logmein.com/products/resolve/trial/msp?utm_medium=affiliates&utm_campaign=msp-trial&utm_source=mspradio&campaignid=701Vv00000ujfDKIAY]
Proofpoint [https://www.proofpoint-total-protection.com/?utm_campaign=367226068-US%20MSPs%20Paid%20Campaigns&utm_source=Podcast&utm_medium=Dave%20Sobel]
💼 All Our Sponsors
MSP Radio is supported by our partners:
ABC Solutions [https://go.businessof.tech/p/abc-solutions-pod] · CometBackup [https://go.businessof.tech/p/cometbackup-pod] · Guardz · HaloPSA [https://go.businessof.tech/p/halopsa-pod] · LogMeIn · OpenText [https://go.businessof.tech/p/opentext-pod] · Pax8 [https://go.businessof.tech/p/pax8-pod] · Proofpoint [https://go.businessof.tech/p/proofpoint-pod] · Rythmz · ScalePad [https://go.businessof.tech/p/scalepad-pod] · TimeZest [https://go.businessof.tech/p/timezest-pod] · Transit AI [https://go.businessof.tech/p/transit-ai-pod] · USecure [https://go.businessof.tech/p/usecure-pod]
Supporting the