Include:
Tech
Cybersecurity
Business Strategy
Channel Insights
Stay Connected
Acer America
Acer America Corp. is a computer manufacturer of business and consumer PCs, notebooks, ultrabooks, projectors, servers, and storage products.

Location

333 West San Carlos Street
San Jose, California 95110
United States

WWW: acer.com

ChannelPro Network Awards

hello 2
hello 3

News & Articles

September 17, 2026 |

Identity attacks are exposing scary, new gaps in MSP security

Identity attacks are on the rise. Learn about recent incidents and how MSPs can leverage new tools to defend the modern workplace.

Attackers are going after the identity layer

The modern workplace has moved well beyond the endpoint. Employees now operate across email, browsers, SaaS applications, cloud platforms and a rapidly expanding collection of AI tools. That has created an attack surface that traditional endpoint security alone was never designed to protect.

Recent attacks illustrate just how important identity has become. In September, Microsoft disclosed a campaign in which attackers impersonated IT support and used passkey-themed social engineering, device code phishing and adversary-in-the-middle techniques to compromise Microsoft cloud identities. In some cases, attackers were able to obtain or replay session tokens and move into services including Exchange Online, SharePoint and OneDrive.

The broader numbers are just as concerning. Microsoft’s 2025 Digital Defense Report found that 97% of identity attacks were password spray attacks, underscoring how frequently attackers target authentication.

For MSPs, defending against threats that bypass traditional defenses can be a complex process. But with the right resources, it isn’t expensive or time consuming. Experts recommend that MSPs gain a deeper understanding of attack patterns and next gen workspace security technologies to fight back.

Browsers and shadow AI are expanding the attack surface

Meanwhile, the workspace itself is becoming harder to control. Verizon’s 2026 Data Breach Investigations Report found that employee use of unauthorized “shadow AI” tools had tripled to 45%, while mobile social engineering attacks were 40% more successful than traditional email phishing.

Browsers are another growing blind spot. LayerX’s 2026 browser extension research found that 99% of enterprise users have at least one browser extension installed, while about 15% use an AI extension. The report also found that AI extensions were three times more likely to have access to browser cookies, which puts authentication and session data within reach of cybercriminals.

MSPs need greater visibility into what is happening inside the browser and across SaaS and AI applications, along with the tools and expertise to identify risky activity before it turns into a client security incident.

What MSPs need to rethink now

These trends require a significant shift in security strategy. Identity has to become the connective tissue between endpoint, email, browser, SaaS and cloud security. That means it is the #1 target for threat actors.

On Wednesday, September 23, at 2 p.m. ET, ChannelPro and Guardz will present Workspace Security: Redefining the MSP Offering Around Identity, a new webinar devoted to ways MSPs can build that more connected approach.

Attendees will learn how identity can anchor security signals across the modern workspace, how to address risks involving browsers, SaaS access, session tokens and unvetted extensions, and how to discover and manage employee AI usage without positioning security controls as employee surveillance.

For MSPs, the opportunity is bigger than simply adding another security tool. An identity-driven approach can help providers connect previously separate services, uncover emerging risks and build a more comprehensive security offering around the way clients actually work today.

➡️ Register now

Related News & Articles

Free MSP Resources

Editor’s Choice


Explore ChannelPro

Events

Reach Our Audience