Month: May 2025

Ask an MSP Expert: The 2025 technology outlook from GTIA
The year kicked off with considerable uncertainty driven by macroeconomic factors such as tariffs and inflation. Nevertheless, managed service providers (MSPs) maintain a positive outlook on the tech industry’s trajectory. A recent report from GTIA sheds light on crucial insights...

Cybersecurity Threat Advisory: AWS default IAM roles risks
Cybersecurity researchers have uncovered critical vulnerabilities arising from default Identity and Access Management (IAM) roles in Amazon Web Services (AWS). Service setups often create these roles automatically or recommend them, granting excessive permissions that expose environments to privilege escalation and...

Cybersecurity Threat Advisory: Ivanti EPMM vulnerability
Ivanti has released updates for Endpoint Manager Mobile (EPMM) that address one medium and one high-severity vulnerability. When chained together, these vulnerabilities can enable unauthenticated remote code execution (RCE). Review the details in this Cybersecurity Threat Advisory for information on...

Tip Tuesday: Choosing the right software for your MSP stack
Every managed service provider (MSP) has a unique technology stack. Who your clients are and what you specialize in shape your technical needs. That said, no matter how unique you are, the need to upgrade is universal. Learn more in...

Cyber insurance: A must for MSPs
If you don’t carry cyber insurance yet, you may want to reconsider. Statistics show that if you are an MSP owner, you probably already have it, with 91.7 percent of managed service providers (MSPs) carry cyber insurance specifically for their operations,...

Tech Time Warp: Ignoring patches leads to a “Sadmind”
Woe to those who ignore the security patch. Technology history is filled with opportunities to say “I told you so.” A golden example is the story of the “Sadmind/IIS worm” of 2001. Learn more in this edition of Tech Time...

Cybersecurity Threat Advisory: SAP critical vulnerabilities
SAP has released patches to address a second vulnerability, CVE-2025-42999, affecting its SAP NetWeaver tool. The vulnerability involves a privilege escalation issue that, when chained with SAP’s CVE-2025-31324 vulnerability (unauthenticated file upload flaw in SAP NetWeaver Visual Composer), can enable...

Cybersecurity Threat Advisory: Critical zero-day vulnerability in Fortinet
A critical zero-day vulnerability affecting several Fortinet products, most notably FortiVoice enterprise phone systems, has recently been patched. Attackers are actively exploiting CVE-2025-32756 in the wild. Read the details of this Cybersecurity Threat Advisory to learn how to keep your...