News, Trends, and Insights for IT & Managed Services Providers
News, Trends, and Insights for IT & Managed Services Providers

The FBI has recovered over 7,000 LockBit decryption keys and is urging past victims of LockBit ransomware attacks to come forward. The keys can be used to recover encrypted data for free. Despite law enforcement efforts to shut down LockBit’s operations, the ransomware is still active and targeting victims. The gang and its affiliates have reportedly earned up to $1 billion in ransoms between June 2022 and February 2024. The FBI is reaching out to known victims and encouraging others to report incidents at ic3.gov.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about an increase in cyber attacks targeting Snowflake customers. CISA recommends that customers proactively search for malicious activity in their systems and report any findings. The advisory comes in response to recent allegations and disclosures regarding unauthorized activity in a third-party cloud database environment.

ConnectWise has been authorized as a CVE Numbering Authority (CNA) by the Common Vulnerabilities and Exposures (CVE) Program. This authorization highlights ConnectWise’s commitment to cybersecurity and its role in assigning CVE IDs to vulnerabilities and publishing associated CVE Records for its products and services, as well as vulnerabilities discovered in third-party products.

KnowBe4’s 2024 Phishing by Industry Benchmarking Report reveals that without training, 34.3% of employees are likely to click on malicious links or comply with fraudulent requests. However, organizations that integrate simulated phishing testing with security awareness training see a significant drop in the Phish-prone™ Percentage (PPP), with an average drop to 18.9% within 90 days and 4.6% after 12 months.

Why do we care?

Tactically, I wanted to boost the FBI and CISA’s call outs.   If you have clients affected, that’s critical information.

ConnectWise’s move is a data point – to give you some perspective, N-Able can also issue CVE’s, and Kaseya, Ninja, Atera, Barracuda and Huntress cannot.     Let’s not overblow the importance, and also acknowledge it’s a proactive move.  

Finally, basic security awareness and hygiene remain the win.     Phishing training works.

Choose your upgrade:

Get the full benefits of Business of Tech Plus

Insider Access

$12/month

Perfect for MSPs and ITSPs that want full interviews, early access, and ad-free listening

  • Programmatic Ad-free private podcast feedSame show, little interruptions
  • Channel Chatter previews1–2 topics with light insights
  • Early access to interview episodesHear it days before public release
  • Monthly Insider BriefTighter analysis you can share internally
  • Extra audio segmentsCut interviews, behind-the-scenes commentary, quick competitive notes
  • Become an Insider for $12/month

    Leadership Access

    $149/month

    Perfect for MSPs and Vendors that run a team and need the extended tactics, executive summaries, and weekly alignment brief

  • All Insider Access benefits plus . . .
  • Invite your teamIncludes access for 5 team members with option to add more
  • Vendor Strategy BriefsThe entire library, plus new analysis every month
  • Channel ChatterAll topics, full insights, complete vendor discussion + sentiment list
  • Quarterly State of the Channel Briefing
  • Monthly AMA submission priorityAsk Dave direct questions, and skip the line
  • Get the Leadership Edge for $149/month

    Vendor Partner

    $500/month

    Perfect for channel companies or vendors looking to deepen their engagement with the show.

  • All Leadership Access benefits plus . . .
  • Get highlighted as a show sponsor You'll get placement in the show notes, throughout the website, and on our dedicated sponsors page.
  • Enjoy regular shout outs You'll be featured in a rotating format during the show
  • Become a show sponsor for $500/month

    Search all stories