Security & Threat Intelligence

The Watch

The Signal

Attackers are bypassing your MFA by going through your helpdesk vendors — UNC6783 ('Mr.

In Play

  1. BPO & Helpdesk: Your Identity Perimeter's Weakest Link

    UNC6783 stole 13M Zendesk tickets from Adobe via compromised Indian BPO. Storm-2755 chains SEO poisoning → AitM → payroll diversion, hitting Canada and security firms. Both bypass non-FIDO2 MFA. Google and multiple threat intel sources confirm only hardware keys resist these campaigns.

    Ask Clarity
  2. Critical Vulnerabilities: Ivanti EPMM, Adobe Reader, Ingress NGINX

    Ivanti EPMM CVE-2026-1340 (CVSS 9.8) hit CISA KEV April 8 with 3-day deadline — EU Commission, Netherlands, Finland already compromised. Adobe Reader zero-day has new C2 IOC (188.214.34.20:34123). Ingress NGINX hit EOL with 2 unpatched critical CVEs at your Kubernetes edge. Ninja Forms RCE affects hundreds of thousands of WordPress sites.

    Ask Clarity
  3. AI Agent Security: 78% Execute Malicious Code, Zero Detection

    78% of tested LLM systems execute malicious code from compromised packages undetected. Subliminal prompts propagate virally across multi-agent systems. 30%+ of Vercel deployments are now agent-initiated. Vercel's Claude Code plugin harvests all prompts and bash commands cross-project. Qwen Code ships with Telegram/WeChat remote control — structurally indistinguishable from C2.

    Ask Clarity
  4. Quantum Cryptography Threshold Collapses to ~10,000 Qubits

    CalTech/Oratomic and Google Quantum AI independently confirmed the qubit threshold for breaking RSA/ECC dropped from millions to ~10,000 — viable machines potentially operational before 2030. China deployed 100-qubit Huanyuan 1. 1.7M BTC ($102B) sit in quantum-vulnerable addresses. Harvest-now-decrypt-later is already active. Begin cryptographic inventory and PQC migration planning with NIST-vetted algorithms.

    Ask Clarity
  5. Healthcare Sector Under Direct Patient-Safety Attack

    Signature Healthcare (Brockton, MA) diverted ambulances, cancelled chemotherapy, closed pharmacies since April 7. ChipSoft ransomware took EHR systems offline at 11 Dutch hospitals simultaneously — a single vendor compromise with 11x blast radius. Both incidents demonstrate direct patient safety impact from cyber operations targeting healthcare supply chains.

    Ask Clarity

Deep Dives

Your Helpdesk Is the New Front Door: BPO Supply Chain Attacks Bypass MFA at Scale

Two Campaigns, One Broken Trust Model

Two distinct threat actors are exploiting the same architectural flaw: outsourced support vendors sit inside your identity perimeter with the ability to reset passwords, re-enroll MFA, and modify authentication workflows — and attackers are going through them instead of through you.

UNC6783 ('Mr. Raccoon') targets BPO providers handling customer support for large enterprises. Google's threat intelligence documents the playbook: compromise the BPO, then use their legitimate access to steal Zendesk tickets en masse. The Adobe breach alone yielded 13 million support tickets stolen through a compromised Indian BPO. Their phishing kit uses spoofed Okta pages following patterns like company.zendesk-support##.com and captures clipboard contents to bypass TOTP codes copied from authenticator apps. Only FIDO2/hardware keys resist this technique.

Storm-2755 ('Payroll Pirate') takes a different path to the same destination. Microsoft tracks this actor using SEO poisoning and malvertising to drive employees to fake Office 365 login pages. An adversary-in-the-middle proxy captures session tokens, defeating MFA entirely. Once inside, they search for HR and payroll contacts, create inbox rules to hide their activity, then email HR to redirect direct deposit information. Vulnerable U — a security-focused organization — was itself targeted by this campaign.


Why Your EDR Won't Save You

These attacks are invisible to endpoint detection because nothing anomalous happens on the endpoint. The compromise occurs in the identity layer — legitimate credentials, legitimate SSO flows, legitimate-looking user behavior. Your EDR fires when malware executes; it doesn't fire when a valid session token authenticates through Okta.

Detection LayerEffectivenessGap
EDR/EndpointLowValid credentials + legitimate SSO = no anomaly
Network/DNSMediumCan detect spoofed Okta domains if DNS telemetry monitored
Identity AnalyticsHighImpossible travel, MFA re-enrollment spikes detectable
BPO Access MonitoringHighMost orgs don't monitor support vendor identity ops at all
FIDO2 MFAPreventiveKeys can't be replayed through spoofed pages
If your BPO agent can reset an executive's password without a second verification channel, that's your highest-priority finding today.

The Payroll Endgame

Storm-2755's targeting of payroll is particularly insidious because the fraud often isn't detected until an employee reports a missing paycheck — days or weeks after the redirect. Zephyr Energy lost €700K to a contractor payment redirect using similar TTPs. The actor creates inbox rules to auto-delete confirmation emails, ensuring neither the compromised employee nor HR sees evidence of the change until it's too late.

What to do

  1. Map every BPO, call center, and helpdesk contractor that can trigger password resets, MFA re-enrollment, or Okta session modifications — then apply conditional access policies restricting these actions to verified contexts

  2. Deploy FIDO2/WebAuthn hardware keys to all admin accounts, helpdesk staff, HR/payroll teams, and executives within 30 days

  3. Mandate out-of-band phone verification for all payroll/direct deposit changes — no exceptions for email or chat requests

  4. Monitor for spoofed domains matching patterns like company.zendesk-support##.com and deploy impossible travel detection on Okta

AI Agents Are Your New Unmonitored Privileged Users — And 78% Execute Malicious Code Without Detection

The Research That Should Change Your Agent Policy

New research findings this cycle quantify what security teams have been warning about: 78% of tested LLM systems executed malicious code from compromised agent packages without any detection mechanism firing. Separately, researchers demonstrated that subliminal prompts embedded in one AI agent's output propagate virally to downstream agents in multi-agent architectures — a worm-like propagation mechanism with no production defenses.

These aren't theoretical attacks. They exploit the fundamental design of AI agents: the willingness to install packages, execute code, and pass instructions between systems based on natural language context. Your EDR, SAST, and SCA tools have zero coverage for this attack pattern because it doesn't match any signature — it's the agent doing exactly what it was designed to do, just with adversarial input.


The Scale of Unmonitored Agent Access

Multiple data points converge to show how far ahead agent adoption has raced past security controls:

  • 30%+ of Vercel deployments are now agent-initiated — non-human actors pushing code to production at scale
  • Vercel's Claude Code plugin harvests all developer prompts and full bash commands across every project, regardless of Vercel relevance — a broad-scope telemetry collection mechanism inside your most trusted dev environment
  • Alibaba's Qwen Code v0.14.x ships with remote control via Telegram, DingTalk, and WeChat plus cron-scheduled task execution — traffic patterns structurally indistinguishable from C2
  • Claude Managed Agents now autonomously read files, run commands, browse the web, and execute code on Anthropic's infrastructure with your data
Agent CapabilityATT&CK ParallelRisk Level
Remote control via messagingT1102 — Web Service C2High
Scheduled autonomous executionT1053 — Scheduled Task/JobHigh
Terminal access & file inspectionT1059 — Command InterpreterHigh
Cross-project data collectionT1005 — Data from Local SystemHigh
Your CI/CD pipeline likely has AI agents with more credential access than your junior developers — and fewer guardrails than your interns.

Why This Is Different From Shadow IT

Traditional shadow IT involved employees using unauthorized SaaS apps. AI agents are autonomous actors with delegated credentials that make decisions, execute code, and interact with production systems. When a Vercel plugin collects all bash commands across every project, that's not an employee using an unapproved tool — it's a persistent data collection mechanism operating inside your development environment by design, not by misconfiguration.

The emergence of dedicated sandboxing tools like JAI ('Jail your AI agent') and IronClaw (Wasm-sandboxed agent harness isolating credentials from the LLM) confirms the industry recognizes this gap. If the market is building containment products, the containment problem is real.

What to do

  1. Audit all Claude Code plugin installations across development teams this week — specifically check for Vercel plugin — and restrict write access to Claude.md configuration files via CODEOWNERS

  2. Deploy network detection rules for Telegram Bot API, DingTalk webhook, and WeChat Work API traffic from developer workstations and CI/CD environments

  3. Sandbox all LLM agent code execution environments with explicit package allowlists — treat agent-installed packages as untrusted by default

  4. Publish an AI agent acceptable-use policy covering approved frameworks, permitted access scopes, and remote control channel restrictions before end of quarter

Quantum Cryptography Timeline Compressed to Pre-2030 — Start Your PQC Migration Now

The Qubit Threshold Just Collapsed

Two independent research tracks published this cycle converge on the same conclusion: the hardware requirements for a cryptographically relevant quantum computer (CRQC) capable of breaking RSA and ECC are dropping far faster than anyone's migration plans assumed.

CalTech/Oratomic/UC demonstrated neutral-atom array advances that reduce the estimated qubit threshold from millions down to approximately 10,000. Separately, Google Quantum AI reported major reductions in physical qubits needed to crack 256-bit ECC, though specific counts weren't disclosed. China has commercially deployed the 100-qubit Huanyuan 1 system and demonstrated capabilities publicly at MWC Shanghai.

Research SourceFindingPrevious AssumptionNew Estimate
CalTech / Oratomic / UCNeutral-atom array advancesMillions of qubits~10,000 qubits
Google Quantum AIPhysical qubit reduction for ECCImpractically large"Major reduction"

Why This Matters Today, Not in 2030

Harvest-now-decrypt-later (HNDL) means the threat is already active. Any data with a secrecy requirement beyond ~2030 that's currently protected by RSA or ECC should be treated as potentially compromised to future decryption. This is especially acute for:

  • Blockchain/cryptocurrency — 1.7 million BTC (~$102B) sit in quantum-vulnerable pay-to-public-key (p2pk) addresses where public keys are permanently exposed on-chain with no migration path
  • Healthcare records subject to HIPAA's indefinite protection requirements
  • Diplomatic and classified communications with multi-decade secrecy needs
  • PKI/TLS infrastructure where certificate rotation is operationally complex

Even skeptics place a CRQC at 2029–2035. The critical point: Western PQC migration timelines are being set by adversary capability development, not by our own readiness. NIST-vetted post-quantum algorithms exist (ML-KEM, ML-DSA, SLH-DSA). The question is whether your organization is treating migration as a roadmap item or an active program.

What was a theoretical two-decade planning horizon has compressed into an active deployment concern. Your cryptographic inventory is the prerequisite — and most organizations haven't started.

JPMorgan's Signal

JPMorganChase launched a $1.5 trillion 'Security and Resiliency Initiative' spanning defense, energy, supply chain, and frontier tech including quantum computing. When the largest U.S. bank names quantum as a strategic security priority alongside defense, that's a market signal. The DOJ separately requested a 285% funding increase ($149M vs. ~$38.7M) for zero-trust migration across 275,000 endpoints — indicating even federal agencies recognize the urgency of cryptographic modernization.

What to do

  1. Commission a cryptographic asset inventory covering all systems using RSA, ECC, or Diffie-Hellman — prioritize by data longevity and sensitivity — within 90 days

  2. Mandate crypto-agility for all new systems and major architecture decisions — the ability to swap cryptographic algorithms without full re-architecture

  3. Audit Bitcoin holdings for legacy p2pk address format and migrate to p2pkh or newer address types that don't expose public keys until spend-time

  4. Build a phased PQC migration roadmap prioritizing HNDL-vulnerable data stores with >5 year secrecy requirements, then TLS/PKI infrastructure

The bottom line

Your identity perimeter's weakest link isn't your firewall — it's the BPO agent who can reset your CEO's password: UNC6783 stole 13 million Zendesk tickets from Adobe through a compromised outsourced helpdesk, Storm-2755 is redirecting employee paychecks via session token theft that defeats non-FIDO2 MFA, 78% of LLM agents in your dev environment execute malicious code with zero detection, and the quantum threat timeline just compressed from 'decades away' to 'before your current strategy expires' — deploy hardware security keys to privileged users, sandbox your AI agents, and start your cryptographic inventory this quarter.