Security & Threat Intelligence

The Watch

The Signal

Kimsuky retired a decade of custom RATs to run intrusions on signed RMM software.

Hydra Remote ships backup C2 hosts and per-installation communication keys, so an indicator lifted from someone else's incident report matches nothing in your telemetry. There is a version of this where borrowed IOCs still buy you something; this is not that version. The access rides the same signed admin tooling the EDR was tuned to trust, and ransomware affiliates are running the identical play — which makes the detection gap a class problem, not one actor's.

In Play

  1. Espionage Moved Into Approved Remote-Access Software

    Kimsuky has abandoned a decade of custom RAT development and now runs intrusions on legitimate RMM software, per Risky Business. The new Hydra Remote RAT ships with backup command-and-control hosts, multiple listener ports, and per-installation communication keys, so shared network indicators no longer identify it. Your detection content assumes remote-access behavior comes from unfamiliar binaries. This tooling is either signed or unique to each victim.

    Ask Clarity
    Try
  2. Computer-Use Agents Are Already Inside the Perimeter

    Perplexity's annualized revenue went from under $250M in January 2026 to over $750M by August, driven partly by Perplexity Computer, an agent professionals run on their own machines, The Information reports. Separately, OpenAI's macOS client can now read, search, and send Apple Messages. Both need capabilities you have denied everything else for a decade: screen capture, synthetic input, and reuse of already-authenticated sessions. Bought seat by seat, most installs sit in no software inventory.

    Ask Clarity
    Try
  3. A Payments Company Now Owns Your Model Router

    Stripe agreed to acquire OpenRouter, the gateway that fans requests out to 400+ models from 80+ providers, in a deal reported at roughly $7.5B, per TheSequence. Ramp separately launched Router.com, which picks the cheapest model clearing a performance threshold and is free through the end of 2026. Neither path logs which model, provider, or region actually served a request, so your sub-processor list and GDPR Article 30 record no longer describe reality.

    Ask Clarity
    Try
  4. A Published Exploit Is No Longer a Triage Signal

    VulnCheck processed roughly 18,000 public proof-of-concept exploits through mid-August, against about 20,000 for all of last year, with a matching surge in fakes, per Risky Business. In the same reporting, an AI tool reportedly chained six unrelated low-severity bugs into the $1.7M Maya Protocol heist. If your vulnerability pipeline auto-escalates on PoC existence, it now escalates on an input that includes fabricated exploits and misses chains built from bugs you deferred.

    Ask Clarity
    Try
  5. Vendor Pilots Now Close Faster Than Your Review

    A widely circulated enterprise-sales playbook now teaches a two-to-three-day pilot with success criteria co-defined by the buyer, against a third-party risk review that typically runs two weeks. American Express is bundling statement credits for ChatGPT Business and Adobe onto a card aimed at owner-operators, per Morning Brew, and the USDA cut Salesforce usage in favor of AI-native suppliers, per The Information. The first trace of these deals is an OAuth grant or a card charge, never a procurement ticket.

    Ask Clarity
    Try

Deep Dives

Espionage Retired Its Own Malware

Shared indicators no longer resolve to the tooling behind the reported intrusions, and the cheapest replacement control is an inventory question rather than another threat-intel subscription.

Why shared indicator feeds stop resolving

The load-bearing detail in the reported tradecraft is an engineering choice inside the Hydra Remote RAT: backup command-and-control hosts, multiple listener ports, and per-installation communication keys. A hash or C2 address lifted from another organization's incident describes one victim's build and nothing further. Shared network indicators are the cheapest detection any team owns, precisely because some other team paid to produce them. Against this family they stop resolving at all.

The delivery paths reported alongside it follow the same logic. One campaign hides operator commands in FTP server login banners as a dead-drop resolver, chosen because banner text slips past most monitoring. SynkLoader paints a full-screen fake Windows lockscreen and captures the credentials typed into it, a user-interface attack that leaves no memory artifact to hunt. Kimsuky's move to commercial RMM software completes the pattern: state espionage running inside signed, reputable remote-administration tooling that most operations teams already run themselves.


Two roads, one detection failure

The reporting converges from opposite directions. Risky Business documents adversaries adopting trusted administration software. The Information documents professionals buying desktop agent software with the same capability set, on corporate cards, at consumer speed. Both defeat one rule: remote-access behavior originating from an unsigned or unfamiliar binary. When the binary is signed and familiar, the rule never fires. What separates an espionage operator from a productivity purchase is intent, and intent is not a telemetry field.

No exploit was required anywhere in the other reported intrusions. Apollo Global Management's cloud environment was breached at the start of July through social engineering, part of a continuing campaign against US investment and Wall Street firms. SickKids attributed its employee-data breach to a vulnerability in a third-party application. Neither produced a CVE that a defender could have patched on their own schedule.

An allow-list converts an unanswerable question, is this remote-access tool malicious, into an answerable one: is this remote-access tool ours?

What to instrument

Observed TTPTelemetry that catches itRule most teams lack
Kimsuky running on legitimate RMMProcess execution with signing publisherApproved-RMM allow-list, alert on every other remote-access binary
Hydra Remote beaconingPer-host egress periodicity, destination rarityBehavioral beacon detection that does not depend on shared IOCs
FTP login-banner dead dropEgress control-channel sessions with no file transferAny inspection of port 21 sessions that never move data
SynkLoader fake lockscreenFull-screen topmost window from a non-shell processCredential-capture detection at the UI layer, not the memory layer

Validate each rule with a purple-team run before it goes live. Untested detections ship as noise and get tuned out within a month. The allow-list carries the most weight here. The same control that catches Kimsuky's tradecraft catches the ransomware affiliates running an identical RMM playbook, and it requires no new product, only a decision about which tools are yours.

What to do

  1. Publish an approved-RMM allow-list this week, enforce it through application control, and alert on execution of any remote-access binary outside it.

  2. Ship and purple-team validate a detection pack for FTP login-banner retrieval on egress, full-screen credential-capture windows, and per-host beacon periodicity.

  3. Require out-of-band callback plus supervisor approval for MFA and credential resets on privileged, cloud-admin, and finance accounts by month end.

The Remote Access Tool With a Valid Certificate and a Subscription

Professionals are buying desktop agents faster than security can enumerate them, and the operating-system grants that make those agents work never expire and rarely appear in an MDM report.

The privilege an agent inherits

Identity controls evaluate at authentication time. MFA, conditional access, device compliance, risk-based sign-in all fire at the gate. A computer-use agent operates after that gate, inside a session already blessed. It does not bypass conditional access. It inherits the output of conditional access. Nothing alerts, and there is no anomalous logon to hunt.

On macOS the enabling grants have precise names. Reading the Messages store requires Full Disk Access under Apple's TCC framework, because the database sits under ~/Library/Messages. Sending requires an Automation / Apple Events grant. Both are one-click user consents. Both persist silently afterward. Installed base and granted base are two different numbers, and most MDM reporting covers only the first.


Read and send inside one trust boundary

OpenAI's macOS client reads, searches, sends, and analyzes Apple Messages, for example to surface a user's most frequent contacts. What sits in those threads at most companies: MFA codes, deal terms, vendor pricing, HR conversations, credentials shared in a hurry. None of it is classified or DLP-inspected, because until now no cloud service read it programmatically.

The chain is read plus write inside the same boundary. Anyone who can text an employee can attempt to place instructions in the assistant's context window, and that same assistant holds send capability. That is indirect prompt injection with an outbound channel attached, and it needs no malware. Perplexity's equivalent primitive is the open web. An agent that fetches pages and PDFs to finish a task is architecturally executing instructions from untrusted sources, at the user's full desktop privilege.

CapabilityPrivilege requiredYour usual controlThe gap
Screen and input automationUI Automation / SendInput; macOS Accessibility and Screen RecordingEDR behavioral rules for RAT-like activitySigned vendor binary is allow-listed; identical behavior, zero alerts (T1113, T1056)
Browser session reuseProfile and cookie access, or DevTools Protocol controlConditional access, MFA, token protectionMFA already satisfied at handoff; the agent acts as the authenticated user
SaaS connectorsOAuth grants such as Mail.Read, Files.ReadWrite.All, offline_accessApp governance policyDefault Entra ID and Workspace tenants still permit end-user consent
Local file read and writeUser-context filesystem accessEndpoint and network DLPExfiltration rides the vendor's own TLS channel with no inspection point

Where the evidence agrees, and one caveat

Three independent reports converge on the same control: end-user OAuth consent. Refresh-token-backed grants to AI productivity tools look entirely legitimate in sign-in logs because they are legitimate. Somebody consented. Moving to an admin-consent workflow is the single highest-leverage configuration change available in a default tenant, and it is hours of work.

The caveat matters for how this gets briefed upward. Reporting that Nvidia may invest in Perplexity at a $30B-plus valuation rests on anonymous sources with no closed round. Build the program on the adoption evidence, which is what actually lands on endpoints, and not on deal terms.

One question comes before the others: whether logging can separate an action the agent took from an action the human took. If it cannot, this entire class of incident is uninvestigable.

Prohibition also loses here. Demand arriving on corporate cards at this velocity routes around a ban. The durable answer is one sanctioned, hardened path that security owns and can log.

What to do

  1. Enumerate endpoints holding Full Disk Access and Automation grants, plus Windows UI Automation and SendInput consumers, this week, starting with legal, finance, HR, and executive-assistant seats.

  2. Disable end-user consent for unverified apps in Entra ID and Google Workspace this week, then audit 12 months of Mail.Read, Files.ReadWrite.All, and Drive or Chat grants issued to AI vendors.

  3. Stand up one sanctioned path for computer-use agents this quarter: dedicated VDI or a non-privileged profile, no corporate SSO session reuse, mandatory action logging, allow-listed egress.

One Log You Cannot Purge, Another Nobody Wrote

Agent runtimes are manufacturing permanent copies of every secret they handle, while the layer that chooses your data processor records nothing an auditor or an investigator could use.

Two records, opposite defects

DeepSeek's new agent Harness keeps an append-only session log alongside a Trajectory view that exposes system prompts, reasoning steps, and tool-call arguments. Treated as a debugging feature, it is convenient. Treated as a data store, which is what it is, it is a permanent replayable copy of every secret and every personal data element any agent has handled. Append-only rules out post-hoc deletion. That leaves pre-write redaction as the only filter that can work. Developers are installing the harness at open-source record pace, on machines holding source code and cloud credentials.

The mirror-image defect sits one layer over, in routing. Cost-based model selection is, in control terms, non-deterministic processor selection. The DPA names approved providers. The router picks on price and never reads it. DeepSeek's new V4-Flash-Vision-Exp sharpens the problem, because an efficiency-first multimodal model wins a cheapest-sufficient auction by construction. The failure mode is not a breach alert. It is an audit finding with no rebuttal available, because no log line records who processed the data.

One record cannot be deleted. The other was never written. Both land on the same team in the same quarter.


The AI SRE tool is an identity, not a dashboard

Strip the marketing off the AI incident-response tooling now being pitched to leadership and what remains is a third party with read access to your entire telemetry corpus, plus, in the agentic tier, a credential scoped for production remediation. Logs routinely carry bearer tokens, connection strings, internal topology, and personal data. That makes telemetry egress a GDPR Article 28 processor relationship and a credential-exposure path, T1552.001 and T1567.002. It is not an integration.

The write side is worse. An agent that can restart services or roll back deploys is a valid-accounts problem, T1078, and its instructions derive partly from log and alert content an attacker can influence. MITRE ATLAS maps that as AML.T0051, with tool abuse, AML.T0053, as the follow-on. Review it the way an identity gets reviewed. Read-only default credentials, with an enforced human gate on writes.


Normalization may already be broken

A DZone analysis names four logging anti-patterns as near-universal: wrong severity levels, missing trace IDs, inconsistent field names, and logs siloed from traces. Those four decide whether a SOC can reconstruct an attacker's path. Inconsistent field names make SIEM normalization fail silently. A detection rule matches nothing and reports no error, which is the worst failure mode a control has. Missing trace IDs break the timeline at every service hop, which is the artifact SOC 2 CC7.3 and ISO 27001 A.8.16 expect on request.

Re-test the top 20 detections against normalized fields. Teams that run that test routinely find rules that have matched nothing for months.


Strike watermarking from the policy draft

Anthropic's forthcoming Claude watermark applies at token-sampling time using a secret key only Anthropic holds, per Sebastian Raschka's teardown. Detection is computationally cheap and needs no model re-run. Defenders cannot run it, and a rewrite pass through any local model defeats it. A finding nobody can independently reproduce does not survive an HR appeal.

Provenance you cannot verify and audit trails you cannot purge are both controls security inherits by default, and neither one arrives with a CVE to justify the work.

What to do

  1. Open a written vendor-risk review of every routing gateway in use this week, covering retention, prompt logging, training use, sub-processors, and cross-border transfers, then amend the DPA and Article 30 record.

  2. Classify agent trajectory and session logs as Tier-1 data now: RBAC on the Trajectory view, automated secret scanning over the store, and pre-write redaction.

  3. Gate AI SRE and AI SOC procurement this quarter on served-model and provider logging, read-only default credentials, an enforced human gate on writes, and injection testing against attacker-controllable log fields.

The bottom line

One pattern runs through these items: the things most likely to hurt you arrive with a valid signature, a subscription, and an executive sponsor. Detection that assumes hostile software looks unauthorized is depreciating, and so is your audit trail, because some records are impossible to delete while the ones an investigation needs were never written. Treat software identity, who signed it, who approved it, what it may reach, as the primary key of both your detection content and your vendor register, and give that inventory one named owner this week.