MSSP, SSO/MFA, Email security, Phishing

MSSP Market News: Attackers bypassed MFA in 100% of BEC cases

Attackers are moving faster, while security teams are still struggling to see what is happening across the environment. LevelBlue found that phishing started 65% of intrusions in the second quarter, and business email compromise accounted for 45% of incidents. The main story is that attackers bypassed MFA in every BEC case where it was in place. They are also stealing OAuth tokens, API keys, and machine identities, giving them trusted access to cloud systems without setting off the usual alarms.

Proofpoint’s ransomware research shows how AI is adding to that pressure. Among organizations hit by ransomware, 65% said AI made the attack more effective. Employees were also more likely to engage because the messages looked convincing. Forty percent said users trusted an attack because it appeared authentic, while 38% said employees interacted with malicious content. More than half of the affected organizations paid a ransom, and 37% of those were hit with another demand. Ransomware is increasingly tied to identity theft and social engineering, rather than malware alone.

At the same time, companies are adding more AI tools and agents to environments they already struggle to monitor. Radware found that generative AI and LLMs are widely used by 83% of organizations, and 96% expect to deploy AI agents or autonomous workflows within the next year. Yet only 17% say they have full visibility into those agents and processes. Nearly half of organizations update production APIs at least once a day, but only 19% have a fully automated, continuously updated API inventory.

For MSSPs, this opens up a broader security conversation. Customers need help understanding who and what has access, where APIs are exposed, how AI agents are behaving, and whether stolen credentials or tokens are being used. The opportunity is moving beyond alert monitoring toward helping customers manage a more complicated identity, cloud, API, and AI environment.

Market Pulse: Cybersecurity Deals, Funding, and Platform Shifts

ExtraHop launches Agentic SOC alliance: ExtraHop has launched the Agentic SOC Alliance, bringing together vendors including CrowdStrike, Command Zero, Dropzone AI, Intezer, LangChain, TENEX.AI and Torq to develop a common operating model for autonomous security operations. The group is proposing a three-layer architecture built around Context, Harness and Model: structured security data that agents can reason over, an orchestration layer that controls workflows and permissions, and interchangeable AI models that handle triage, investigation and response. The goal is to give enterprises a clearer blueprint for deploying agentic SOC tools without tying the entire architecture to a single model or vendor.

ThreatDown adds Shadow AI and Machine Identity Visibility for MSPs: ThreatDown has expanded its platform with AI visibility and broader identity threat detection and response capabilities aimed at helping security teams and MSPs track shadow AI use and non-human identities from the same console. The new AI dashboard inventories applications across customer environments, showing which tools are in use, where they are running and which devices are accessing them, while the expanded ITDR coverage tracks service accounts, API tokens, OAuth credentials and machine identities by ownership, age and privilege level. ThreatDown is also adding an AI assistant that turns security data into plain-language guidance and recommends actions for administrators to review before execution.

7AI launches partner program for agentic SOC services: 7AI launched its first formal global partner program, creating Select and Premier tiers for MSSPs, resellers, and other security partners that want to build services around its agentic SOC platform. The program offers training, certification, and dedicated sales and technical resources, giving MSSPs a structured way to use 7AI’s autonomous investigation agents within their own security operations.

Keyfactor expands partner program around post-quantum services: Keyfactor expanded its global partner program to help MSPs, MSSPs, and systems integrators build services around crypto-agility, machine identity, and post-quantum cryptography. The program supports partners developing quantum-readiness assessments, cryptographic modernization projects, and post-quantum centers of excellence. For MSSPs, this creates a potential recurring service category around discovering certificates and cryptographic assets, monitoring risk, and helping customers manage a migration that will take place across several years rather than through a single technology upgrade.

Veraify targets shadow AI and agent security: Veraify has launched a new AI-native security platform designed to help enterprises monitor and control how employees, applications, and AI agents access data and use AI tools. The platform combines endpoint intelligence, AI-aware policy enforcement, data loss prevention, identity controls, and secure connectivity, with a focus on detecting shadow AI and stopping sensitive information from leaving through prompts, uploaded files or autonomous workflows. Veraify can identify sanctioned and unsanctioned AI services, inspect text, documents and images for personal or proprietary data, and apply policies to both human users and AI agents from one control plane.

Palo Alto Networks to acquire application monitoring provider Embrace: Palo Alto Networks is acquiring application monitoring provider Embrace to strengthen real user monitoring and application observability across its Cortex platform. The company plans to combine Embrace with its new Synthetics service and Cortex AgentiX, giving customers a clearer view of application performance from the user interaction through the backend, with the longer-term goal of automatically identifying and fixing issues. The deal also extends Palo Alto Networks’ broader push into observability following its $3.35 billion Chronosphere acquisition.

Abstract raises $25 million for composable security operations: Abstract raised $25 million to expand its streaming-first security operations platform, which is designed to let customers connect security data, analytics, and AI workflows without moving everything into a single SIEM ecosystem. The company is betting that more enterprises will move away from sending every log into a single SIEM and instead use a composable model that detects threats while data is still moving, routes that data to different destinations, and gives teams more control over storage costs. The funding will support broader in-stream detection, further development of its Astro AI capabilities, and expansion of its go-to-market team.

Glow raised $180 million in Series A funding at a reported $1.2 billion valuation: Glow raised $180 million in Series A funding at a reported $1.2 billion valuation, making it the biggest cybersecurity funding story of the week. The new company is building an AI-powered endpoint security platform that maps customer environments, assesses risk, and automatically enforces prevention policies.

Neo Launches with $100 million to secure AI-enabled software: Neo has emerged from stealth with $100 million in seed and Series A funding to build security for AI-enabled enterprise software. The startup was founded by former SentinelOne executives Nick Warner and Shlomi Salem, along with Eran Shirazi, and is backed by Andreessen Horowitz, Bessemer Venture Partners, Craft Ventures, and Merlin Ventures.


Have news to share or just want to connect? Reach anytime at [email protected].

Suparna Chawla Bhasin

Suparna is the Senior Managing Editor for CyberRisk Alliance’s Channel Brands, including MSSP Alert and ChannelE2E. She manages content development, sharpens editorial workflows, and ensures storytelling is tightly aligned with audience needs. With a background in technology, media, and education, she combines strategic insight with creative execution.

You can skip this ad in 5 seconds