Security & Threat Intelligence
The Watch
Kimsuky retired a decade of custom RATs to run intrusions on signed RMM software.
Hydra Remote ships backup C2 hosts and per-installation communication keys, so an indicator lifted from someone else's incident report matches nothing in your telemetry. There is a version of this where borrowed IOCs still buy you something; this is not that version. The access rides the same signed admin tooling the EDR was tuned to trust, and ransomware affiliates are running the identical play — which makes the detection gap a class problem, not one actor's.
In Play
Espionage Moved Into Approved Remote-Access Software
Kimsuky has abandoned a decade of custom RAT development and now runs intrusions on legitimate RMM software, per Risky Business. The new Hydra Remote RAT ships with backup command-and-control hosts, multiple listener ports, and per-installation communication keys, so shared network indicators no longer identify it. Your detection content assumes remote-access behavior comes from unfamiliar binaries. This tooling is either signed or unique to each victim.
Ask ClarityComputer-Use Agents Are Already Inside the Perimeter
Perplexity's annualized revenue went from under $250M in January 2026 to over $750M by August, driven partly by Perplexity Computer, an agent professionals run on their own machines, The Information reports. Separately, OpenAI's macOS client can now read, search, and send Apple Messages. Both need capabilities you have denied everything else for a decade: screen capture, synthetic input, and reuse of already-authenticated sessions. Bought seat by seat, most installs sit in no software inventory.
Ask ClarityA Payments Company Now Owns Your Model Router
Stripe agreed to acquire OpenRouter, the gateway that fans requests out to 400+ models from 80+ providers, in a deal reported at roughly $7.5B, per TheSequence. Ramp separately launched Router.com, which picks the cheapest model clearing a performance threshold and is free through the end of 2026. Neither path logs which model, provider, or region actually served a request, so your sub-processor list and GDPR Article 30 record no longer describe reality.
Ask ClarityA Published Exploit Is No Longer a Triage Signal
VulnCheck processed roughly 18,000 public proof-of-concept exploits through mid-August, against about 20,000 for all of last year, with a matching surge in fakes, per Risky Business. In the same reporting, an AI tool reportedly chained six unrelated low-severity bugs into the $1.7M Maya Protocol heist. If your vulnerability pipeline auto-escalates on PoC existence, it now escalates on an input that includes fabricated exploits and misses chains built from bugs you deferred.
Ask ClarityVendor Pilots Now Close Faster Than Your Review
A widely circulated enterprise-sales playbook now teaches a two-to-three-day pilot with success criteria co-defined by the buyer, against a third-party risk review that typically runs two weeks. American Express is bundling statement credits for ChatGPT Business and Adobe onto a card aimed at owner-operators, per Morning Brew, and the USDA cut Salesforce usage in favor of AI-native suppliers, per The Information. The first trace of these deals is an OAuth grant or a card charge, never a procurement ticket.
Ask Clarity
Deep Dives
- ●
Espionage Retired Its Own Malware
Shared indicators no longer resolve to the tooling behind the reported intrusions, and the cheapest replacement control is an inventory question rather than another threat-intel subscription.
Why shared indicator feeds stop resolving The load-bearing detail in the reported tradecraft is an engineering choice inside the Hydra Remote RAT: backup command-and-control hosts, multiple listener ports, and per-installation communication keys . A hash or C2 address lifted from…
3 action items
- ●
The Remote Access Tool With a Valid Certificate and a Subscription
Professionals are buying desktop agents faster than security can enumerate them, and the operating-system grants that make those agents work never expire and rarely appear in an MDM report.
The privilege an agent inherits Identity controls evaluate at authentication time. MFA, conditional access, device compliance, risk-based sign-in all fire at the gate. A computer-use agent operates after that gate, inside a session already blessed. It does not bypass conditional…
3 action items
- ●
One Log You Cannot Purge, Another Nobody Wrote
Agent runtimes are manufacturing permanent copies of every secret they handle, while the layer that chooses your data processor records nothing an auditor or an investigator could use.
Two records, opposite defects DeepSeek's new agent Harness keeps an append-only session log alongside a Trajectory view that exposes system prompts, reasoning steps, and tool-call arguments. Treated as a debugging feature, it is convenient. Treated as a data store, which…
3 action items
The edition continues
Take the signal into the room.
Sign up or log in to read all 3 deep dives in full, plus the final take.
Read the full editionContinue with LinkedIn