Episode 58
Is Your MSP Actually Securing Your Network?
September 18th, 2026
46 mins 25 secs
Season 3
About this Episode
Welcome back to the Scinary Information Nexus! This week, Richard, Joseph, Mario, and Hunter tackle the messy reality of third-party risk and what they call "The MSP Dilemma."
First up, the guys look at an incident involving an AI translation device called Timekettle, which was caught routing local Texas government traffic back to Shenzhen, China. The vendor tried to blame "legacy IP attribution," but it's a great example of why you can't just blindly trust your tech vendors.
From there, they discuss Managed Service Providers (MSPs) and a major friction point in IT: organizations need MSPs for daily operations, but most providers are built for availability, not security.
Later in the episode, the team covers a massive wave of Google EDU student account compromises. Hackers are bypassing traditional MFA and email filters using tactics like AiTM (Adversary in the Middle), ClickFix, and ConsentFix. By automating these attacks and manipulating email headers, threat actors are turning basic student accounts into high-volume threats.
Topics covered:
- The Timekettle incident: When translation devices phone home to China
- Why 80% of security breaches involve compromised identities
- The MSP Dilemma: Balancing IT availability with cybersecurity
- A sneak peek at Scinary's upcoming GRC tool
- How hackers bypass MFA on Google EDU accounts
- The rise of AiTM, ClickFix, and ConsentFix tactics
- Why NIST 800-53 emphasizes strict third-party agreements
Is your IT provider actually securing your network, or just keeping the lights on? Drop your thoughts in the comments!
Connect with Scinary Cybersecurity:
https://www.scinary.com
https://x.com/scinarycyber
https://www.linkedin.com/company/scinarycyber/
00:00 Intro
01:30 The Timekettle Debacle
09:45 The MSP Dilemma
24:45 Free GRC MSP Assessments
30:45 Google EDU Compromises
45:15 Wrap-Up & Weekend Banter