『Default Security Choices Leave MSPs Exposed as AI Bots Blend With Legitimate Users』のカバーアート

Default Security Choices Leave MSPs Exposed as AI Bots Blend With Legitimate Users

Default Security Choices Leave MSPs Exposed as AI Bots Blend With Legitimate Users

無料で聴く

ポッドキャストの詳細を見る

【Amazonプライム会員限定】今ならプレミアムプランが4か月 月額99円。

10月19日まで。※適用条件あり
Correction: In this episode, the name of Arkose Labs was mispronounced. Arkose Labs (arkoselabs.com) is the source of the commentary from founder and CEO Kevin Gosschalk. A key structural shift identified is the growing governance gap created by AI agents that evade traditional detection and accountability measures. This challenge is exemplified by Meta’s Muse and OpenAI agents, which do not self-identify during interactions. As a result, determining agent activity and risk now depends on disclosures by the developer rather than the asset owner or operator, limiting the visibility and control of MSPs and IT service providers.One consequential incident involved an OpenAI agent accessing both public and non-public files in the Australian government's health portal. The breach went unnoticed by government security for 54 days and was discovered during an internal OpenAI review, later reported voluntarily by the company. In retail, Amazon blocked Meta's Muse agent from its platform after it failed to identify itself and due to concerns about credential handling, according to statements cited by GeekWire. These events illustrate growing dependency on agent developers for incident discovery and disclosure.Supporting developments include findings from Akros Labs that current rules are insufficient to distinguish customers, attackers, or bots, due to agents blending in as typical browsers. VentureBeat surveys show a decline in proactive agent isolation and a rise in uncontained incidents, indicating operational drift toward default-permissive security settings. While new standards from NIST for short-lived tokens and upcoming agent identification protocols are developing, enforcement and utility remain incomplete.For MSPs and IT leaders, the immediate implication is the need to revisit client-specific controls. Default reliance on legacy bot rules increases undetected risk, while inaction effectively shifts governance to external agent vendors. Providers must decide whether to block all unauthenticated agent traffic—accepting potential business impact—or allow agents and rely on token expiration and allow-listing signed agents as standards evolve. Continuous monitoring and regular adjustment of controls are necessary to minimize harm when agent anonymity and developer-only surveillance persist.00:00 The Agent That Looks Like Chrome 04:41 Only The Maker Is Watching07:02 The Default Nobody Chose10:07 Why Do We Care?Supported by: Proofpoint GoTo(LogMeIn) NinjaOne On-Demand Webinar: https://go.businessof.tech/p/ninjaone-pod 💼 All Our SponsorsMSP Radio is supported by our partners: ABC Solutions · CometBackup · Firetail · Guardz · HaloPSA · LogMeIn · Mailprotector · OpenText · Pax8 · Proofpoint · Rythmz · ScalePad · TimeZest · Transit AI · USecureSupporting the IT services community through insights, analysis, and transparency. 🚀 Join Business of Tech PlusGet exclusive access to investigative reports, vendor analysis, leadership briefings, and more.👉 https://businessof.tech/plus 🎧 Subscribe to the Business of TechWant the show on your favorite podcast app or prefer the written versions of each story?📲 https://www.businessof.tech/subscribe 📰 Story Links & SourcesLooking for the links from today’s stories?Every episode script — with full source links — is posted at:🌐 https://www.businessof.tech 🎙 Want to Be a Guest?Pitch your story or appear on Business of Tech: Daily 10-Minute IT Services Insights:💬 https://www.podmatch.com/hostdetailpreview/businessoftech 🔗 Follow Business of Tech LinkedIn: https://www.linkedin.com/company/28908079YouTube: https://youtube.com/mspradioBluesky: https://bsky.app/profile/businessof.techInstagram: https://www.instagram.com/mspradioTikTok: https://www.tiktok.com/@businessoftechFacebook: https://www.facebook.com/mspradionews Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
adbl_web_anon_alc_button_suppression_t1
まだレビューはありません