RESEARCH
Threat Thursday: June 4th, 2026

Welcome to Threat Thursday, Galactic's weekly threat intelligence roundup. This week's stories have a clear pattern: attackers didn't find obscure entry points or novel techniques but instead went after the things you were already using and already trusting. As always, ...
Communicating Risk
The Silent Killer in Your MSP: Ambiguity

You think you’re being clear. You told the client they needed MFA. You recommended better backups. You flagged that firewall. But when things go sideways—when data’s lost, insurance denies the claim, or the lawyers come knocking—they don’t remember your recommendations. ...
The #1 Role Every MSP Must Embrace Before a Competitor Replaces You

Your Clients Don’t Need Another IT Vendor. They Need a Cybersecurity Leader. If you’re still selling managed services like it’s 2015, you’re already losing. The MSP market has shifted. The stakes are higher. Clients aren’t asking how many tickets you ...
Your Marketing Sounds Like It Was Written by a Robot—Because It Was

Let’s be honest. You’re slammed with tickets, chasing down weird user issues, and trying not to lose your mind over Janet’s printer—again. So when someone suggests using AI to handle your marketing, it sounds like a miracle. Here’s the problem: ...
Dark Web Monitoring & Threat Intelligence
Google Predicts Top Cybersecurity Threats for 2025

Staying on top of cybersecurity threats as a business owner is no walk in the park. These strides demand the right antivirus programs, firewalls, and security teams, to name a few. However, because online attacks are always evolving, your business ...
Human Layer Security
The Deepfake Was Convincing. So Was My Backpack.

Why Social Engineering Still Works, Why AI is Making it Sharper, and the One Habit that Stops it In early 2024, an employee at Arup, a global engineering firm, joined a video call with several colleagues, including someone who appeared ...
New State Cyber Rules Are Coming—Will You Be Ready, or Be the One They Blame?

California. New York. Massachusetts. One by one, states are turning up the heat on cybersecurity regulations—and if you're not preparing your clients for what’s coming, you're not just behind. You're exposed. Last week I blogged about upcoming California rules requiring ...
16 Billion Reasons to Change Your Password—Now

You ever wake up and feel like the bad guys are winning? I do. Today especially. Because if you thought May’s headline—184 million stolen credentials splashed across the dark web—was terrifying, you’d better sit down for this one. The latest ...
More Articles
Hackers Are Using AI to Trick Your Clients — And It’s Working
Let’s cut through the holiday wrapping and get right to it: Your clients are going to screw up. They’re going to click the link. They’re going to open the attachment. They’re going to enter their credentials into a “Microsoft password ...
AI Is Already Inside Your Walls. You Just Haven’t Looked Hard Enough.
Think your clients are the ones playing fast and loose with AI? Guess again. Your techs are doing it—right now—on your network. Not because they’re reckless. Because they’re efficient. They’re pasting configs into ChatGPT. Running SOPs through Gemini. Copying proposals ...
Negligence, Gross Negligence, and the Clauses That Decide Your Fate
Most MSP disputes aren’t about who’s perfect. They’re about who looks reasonable on paper. When claims from a client, an insurer, ...
Your Front Desk Just Shared a Quote with ChatGPT (And You Didn’t Even Know It)
I was onsite with one of our MSP partners the other day. Yeah, I still do that. I like to see the war zone up close once in a while. So I walk into their office, say hi, and ask ...
You’re Using Your Smartest Engineer Wrong (And So Are Your Clients)
What if I told you that you’re misusing the most powerful engineer on your team? No, not Josh. Not the guy with the beard who still thinks ZFS is the answer to everything. I’m talking about AI. And right now? ...
SpamGPT Just Weaponized the PDF. Now What?
You ever get that gut feeling when something smells off? That’s what one of our partners felt when a client forwarded them a resume last week. We helped them analyze it. The issue? It looked like a normal PDF. Clean, ...
What a New Lawsuit Can Teach Us About Cyber Liability and Documentation
When a cyber insurance provider sues vendors after a ransomware incident, it’s not just about fault—it’s about proof. In Ace American Insurance Co. v. Congruity 360 and Trustwave, we see how courts allocate responsibility—and why the side with the best ...
The Night Your Security Tools Died
Let’s start with a bedtime story. You've probably lived it. It’s 2:13 a.m. Your phone’s going off like a smoke alarm. Caller ID: CFO. “Nothing works. Are we—are we hacked?” You roll over, crack open the laptop. Your RMM is ...
Why Plaintiff Attorneys Are Watching Your Breaches—And Why You Can’t Hide
Managed Service Providers (MSPs) sit at the heart of their clients’ IT and cybersecurity. But when it comes to data breaches, MSPs often underestimate who’s paying attention. It’s not just regulators and customers—it’s also plaintiff attorneys eager to file class-action ...
The Tale of Two MSPs: Why Buying Every Shiny Security Tool Is Killing Your Business
This week, I’m at a security event. You know the scene: vendor hall packed with shiny solutions, MSP owners wandering the aisles, scratching their heads, trying to figure out what’s “must-have” and what’s just sales smoke. I talked to two ...
Overwhelmed by Alerts? Here’s How MSPs Can Finally Break Free from the Noise
The flood of alerts is killing your team’s focus—and your clients’ security. Default vendor alerts are too noisy. Engineers are drowning in false positives, ignoring real threats, and burning out in the process. If you’re running an MSP, you’ve seen ...
Your Clients Don’t Have a Cyber Playbook—And That Makes You the Scapegoat
Why MSPs Keep Taking the Fall If you are an MSP owner or operator, here is the hard truth. When your client experiences a cyber incident, you are going to be blamed. It doesn’t matter if the breach happened because ...


