The CyberCall Podcast
The Voice of Cybersecurity for MSPs & MSSPs!
The CyberCall is the weekly podcast where cybersecurity meets business reality. Hosted by Andrew Morgan, Founder of Right of Boom, this is the go-to show for Managed Service Providers (MSPs), virtual CISOs (vCISOs), and IT leaders navigating the complex world of cyber risk, compliance, and AI.
Each episode features raw, practical conversations with the sharpest minds in cybersecurity—from operators in the trenches to CISOs, researchers, policymakers, and toolmakers shaping the future. If you care about protecting your clients, growing your practice, and becoming the security partner businesses trust—this podcast is your playbook.
Co hosts: Phyllis Lee, VP of Content at CIS & Gary Pica, President of TruMethods
The CyberCall Podcast
Collaboration Platforms are the New Phishing Frontier
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
For years, security awareness training has focused almost entirely on email phishing: spot the bad link, question the urgent request, verify the sender. But Unit 42 just published research showing attackers have found a different door, and most teams aren't watching it. Collaboration platforms like Slack and Teams have become part of the identity attack surface. Unit 42 tracked a fourfold increase in malicious activity tied to these platforms over the past year, and 99% of it started as chat-based phishing.
Here's what makes this especially relevant for MSPs: most organizations use Teams to collaborate with outside companies, including their IT provider. Attackers know that. They pose as the MSP itself, or as IT support, because that relationship already carries a zone of trust. When "your IT provider" messages you on Teams asking you to approve an MFA prompt, most people don't question it, they just comply.
That's why we wanted Wil Klusovsky on the show. Wil's known for translating technical risk into something executives can actually understand and act on, and this topic needs exactly that.
Palo Alto's Unit42 Research:
https://unit42.paloaltonetworks.com/communication-channel-identity-risks/
https://unit42.paloaltonetworks.com/microsoft-teams-phishing/