IC BRIEF — 23 March 2026
Current as of 2210 EDT (UTC-4), Monday 23 March 2026
Contents
- Leadership & Organization (1)
- Operations & Intelligence Failures (1)
- Congressional Oversight & Policy (1)
- Technology & OSINT (4)
- Hiring & Workforce (1)
- COLLECTION GAPS
8 stories from 9 sources across 9 organizations
BOTTOM LINE UP FRONT
Tuesday's Anthropic v. Pentagon hearing before
The Department of Homeland Security (DHS) workforce crisis entered its sixth week with NPR's ground-truth survey revealing extreme geographic variance: 200-minute waits at Houston Intercontinental vs. empty checkpoints at Dulles, exposing Transportation Security Administration (TSA)'s triage strategy of cannibalizing quiet airports to staff hot spots. Mullin's confirmation as DHS Secretary, expected Monday evening, makes him the immediate crisis manager, but the underlying funding stalemate remains unresolved.
Cybersecurity and Infrastructure Security Agency (CISA) issued a Binding Operational Directive (BOD) ordering federal agencies to patch the DarkSword iOS exploit chain by April 3 after Cloud Security Alliance (CSA) researchers linked it to both Turkish (UNC6748) and Russian (UNC6353) state intelligence actors. The public leak of the full exploit kit transforms what was a targeted state tool into a commodity threat against every federal iPhone.
Leadership & Organization
Senate Advances Mullin DHS Confirmation on Party-Line Vote; Final Vote Expected Monday
The Senate advanced
Analyst Note: Prior IC briefs tracked the Mullin nomination through committee (8-7 vote March 19) and predicted late-week confirmation. Paul's opposition, from the Republican committee chairman, signals Mullin will face skeptical oversight from his own party on civil liberties issues, potentially creating space for FISA and surveillance reform that DHS equities would normally oppose.
Sources:
- Senate expected to vote on DHS secretary confirmation for Mullin -
PBS NewsHour (MAR 23)
Watch Items - Mullin confirmation vote expected late Monday March 24; watch for DHS operational directives within first 48h - NCTC directorship remains vacant since Kent nomination stalled; watch for interim appointment - Congressional recess compresses timeline for FISA, DHS funding, and intelligence authorization
Operations & Intelligence Failures
CISA Orders Federal Agencies to Patch DarkSword iOS Exploit Chain Linked to Turkish and Russian State Actors
CISA added three DarkSword iOS vulnerabilities (CVE-2025-31277, CVE-2025-43510, CVE-2025-43520) to its Known Exploited Vulnerabilities catalog under BOD 22-01, ordering federal agencies to patch within two weeks by April 3. The DarkSword exploit chain enables sandbox escape, privilege escalation, and remote code execution on iPhones running iOS 18.4-18.7, deploying three information-stealing malware families: GhostBlade, GhostKnife, and GhostSaber. The CSA Research Alliance linked DarkSword to UNC6748, a customer of Turkish commercial surveillance vendor
Analyst Note: The prior IC brief tracked the CanisterWorm wiper targeting Iranian systems and the FBI
Sources:
- CISA Orders Federal Agencies to Patch Critical iOS Flaws Exploited by Attackers - News4Hackers (MAR 23)
Watch Items - DarkSword CISA patch deadline April 3; watch for agency compliance reporting - Monitor for additional state actors adopting the leaked DarkSword exploit kit - Trump's 5-day Iran strike postponement expires ~March 28
Congressional Oversight & Policy
(Developing) Anthropic Files Sworn Declarations Challenging Pentagon Supply Chain Risk Claims Ahead of Tuesday Hearing
Anthropic filed sworn declarations disputing the Pentagon's assertion that the company poses a national security risk, ahead of a March 24 preliminary injunction hearing before Judge Rita Lin. The company's policy and public sector leaders contested claims around control and security risks, arguing key government concerns were never raised during negotiations and that deployed systems cannot be remotely altered. The DOJ responded that Anthropic's refusal to accept contract terms is 'conduct, not protected speech' and warned an AI vendor with model control could 'preemptively alter behavior during ongoing warfighting operations.' The designation, historically reserved for foreign adversaries, has never been applied to a domestic company. Nearly 150 retired judges plus Microsoft filed amicus briefs supporting Anthropic. The hearing constitutes the first major judicial test of whether the Trump administration exceeded its authority in weaponizing supply chain risk statutes against domestic policy disagreements.
Analyst Note: Three consecutive IC briefs have tracked this case's escalation from political rhetoric to legal record. The DOJ's 'preemptive alteration during warfighting' argument concedes the Pentagon depends on a vendor it has simultaneously declared a national security threat. If the injunction holds, DOD's 180-day Claude removal timeline starts running against Maven operations processing 8,000+ targeting actions in the Iran campaign.
Sources:
- Anthropic challenges Pentagon's national security risk claim in reply to suit - Startup News (via Economic Times) (MAR 22)
Prior Reporting
- [Anthropic Challenges Pentagon Claims in Ongoing AI National Security Dispute](https://theaiinsider.tech/2026/03/23/anthropic-challenges-pentagon-claims-in-ongoing-ai-national-security-dispute/) (2026-03-23) - [Elizabeth Warren calls Pentagon's decision to bar Anthropic 'retaliation'](https://www.yahoo.com/news/articles/elizabeth-warren-calls-pentagon-decision-152257281.html) (2026-03-23)Watch Items - Anthropic preliminary injunction hearing Tuesday March 24 at 1:30 PM PT; ruling could come same day or within 48h - Section 702 expiration April 20, 28 days away; House has 12 session days remaining before deadline - SAVE Act Senate vote expected to fail this week; watch for fallout on FISA vehicle
Technology & OSINT
Space Force Kronos C2 Contracts Expected April as Space Battle Management Modernization Accelerates
Space Systems Command plans to issue initial Other Transaction Authority (OTA) contracts beginning in April for Kronos, a modernization initiative focused on operational command and control and battle management software for space domain awareness. Kronos was separated from the troubled
Sources:
- Space Force anticipates first Kronos C2 contracts in April -
Breaking Defense (MAR 23)
Trump Admin AI Policy Sends Conflicting Signals: Anthropic Banned While GSA Mandates 'American AI' in Contracts
The Trump administration's push for federal AI adoption is undermined by contradictory actions. While the White House released a vendor-friendly AI Action Plan last July, the Pentagon designated Anthropic's Claude a supply chain risk and ordered all agencies to stop using it, with defense contractors required to certify non-use. Simultaneously, General Services Administration (GSA) released a nine-page draft clause for schedule contracts requiring vendors to use only 'American AI systems,' disclose all AI in service delivery, and grant government ownership of data and custom developments. George Washington University's Jessica Tillipman observed both actions 'send a really bad message to industry.' Experts warn the restrictions may push vendors and agencies away from GSA schedules toward alternative procurement vehicles. The GSA comment period was extended to April 3.
Analyst Note: The prior IC brief reported Maven's designation as a permanent
Sources:
- Trump administration clouds up its push for AI in government -
Federal News Network (MAR 23)
RSAC 2026: Trump Cyber Strategy Shifts from Defensive Posture to Active Offensive Operations
Industry leaders at RSA Conference (RSAC) 2026 described a fundamental shift in U.S. cyber strategy from passive deterrence to active offensive operations. Palo Alto Networks' Wendi Whitmore reported 'I have never before seen as much action and cooperation as we are seeing today,' noting increased government proactivity compared to previous administrations. Sidley Austin's David Lashway said the strategy enables the government to 'take offensive and defensive action with the most powerful cyber capability' available, coordinating across agencies rather than relying on fragmented private-sector efforts. Paladin Capital's Jamil Jaffer framed the approach using deterrence theory, arguing visible public responses to intrusions discourage future attacks. The strategy does not authorize private offensive cyber operations.
Sources:
- Experts insist Trump administration's cyber strategy is already paying off -
CyberScoop (MAR 23)
M-Trends 2026: High-Tech Overtakes Finance as Top Cyber Target; Dwell Time Rises to 14 Days
Mandiant's M-Trends 2026 report, based on 500,000+ hours of incident response investigations in 2025, reveals high-tech companies now comprise 17% of investigations, surpassing financial services (14.6%) for the first time. Median global dwell time increased to 14 days from 11 in 2024. North Korean espionage campaigns registered 122-day median dwell times, outpacing all other actors. Mandiant tracked 661 new threat clusters and 714 new malware families in 2025 alone, bringing totals to over 5,000 tracked clusters and 6,000 malware families. Vulnerability exploits dominated initial access at 32% for the sixth consecutive year, while voice phishing surged to 11% and traditional email phishing declined to 6%. ClickFix social engineering using deceptive CAPTCHAs expanded globally.
Analyst Note: The dwell time increase from 11 to 14 days reverses a multi-year downward trend and coincides with CISA's degraded staffing and the DOGE-driven attrition of cleared cybersecurity specialists. The 122-day Democratic People's Republic of Korea (DPRK) dwell time is concerning given the prior IC brief's reporting on WaterPlum/StoatWaffle campaigns targeting developers; these actors are getting in and staying undetected for months.
Sources:
- High-Tech Sector Overtakes Finance as Top Target for Cyber-Attacks, Mandiant Reports -
Infosecurity Magazine (MAR 23)
Watch Items - Anthropic injunction ruling this week; determines whether Maven loses its AI backbone - GSA 'American AI' draft clause comment period closes April 3 - Kronos C2 first contracts expected April; watch for vendor announcements - RSAC 2026 continues this week; additional cyber policy announcements expected
Hiring & Workforce
(Developing) DHS Shutdown Airport Impact Varies Wildly by Location; ICE Agents Begin Patrols at New Orleans
NPR's on-the-ground survey of 6 airports across 5 cities found extreme variation in DHS shutdown impact: George Bush Intercontinental in Houston saw 200-minute waits, while Dulles had more officers than travelers. The inconsistency reflects TSA's National Deployment Force reassigning officers from quieter airports to understaffed hotspots, a triage approach that masks systemic workforce erosion. ICE agents began patrols at New Orleans' Louis Armstrong International for crowd management after the airport advised three-hour early arrivals. TSA officers confirmed colleagues leaving the force, with one noting increased callouts from financial hardship. The variation data undercuts both the administration's claim that the shutdown is manageable and critics' claim of universal crisis. The reality is localized collapse at high-traffic hubs.
Analyst Note: The prior IC brief reported national callout rates of 47.4% at Houston Hobby and 400+ officers lost. Today's NPR ground-truth adds granularity: TSA is robbing Peter to pay Paul, deploying the National Deployment Force to redistribute staff rather than address the root cause. This means airports currently reporting short waits (Dulles, Orlando) are likely seeing artificially maintained staffing that will degrade as the shutdown continues and the donor airports' local staff continues to attrit.
Sources:
- 5 cities, 6 airports: Checking out TSA lines during partial government shutdown -
NPR (MAR 23) - ICE agents begin patrol at New Orleans airport as security lines surge for second day - NOLA.com (MAR 23)
Prior Reporting
- [Record numbers of TSA officers called out Saturday as DHS shutdown continues](https://abcnews.com/US/record-numbers-tsa-officers-called-saturday-dhs-shutdown/story?id=131307007) (2026-03-22) - [ICE officers will begin assisting TSA as shutdown frustrates travelers and screeners](https://whyy.org/articles/tsa-ice-officers-shutdown-air-travel/) (2026-03-23) - [ICE officers will begin assisting TSA as shutdown frustrates travelers and screeners](https://www.washingtontimes.com/news/2026/mar/23/ice-officers-start-assisting-tsa-shutdown-frustrates-travelers/) (2026-03-23)Watch Items - Mullin's first DHS operational directives: watch for TSA/ICE staffing changes - DHS funding negotiation window narrows before congressional recess - CISA staffing at 38% during active Iranian cyber threat; watch for any new hires or contractor augmentation
COLLECTION GAPS
- IC-specific workforce data: No fresh reporting on CIA/NSA/DIA/NGA hiring, clearance processing timelines, or polygrapher capacity within the 36h collection window. The DOGE-driven attrition story relies on 2025 reporting; current-state IC headcounts are unreported.
- FISA Section 702 legislative mechanics: No new reporting beyond today's PDB. The House whip count, Senate positioning, and specific reform amendment language remain opaque 28 days before expiration.
- IC Inspector General activity: No IG reports, whistleblower developments, or oversight investigations surfaced in the 36h window.
- Iran cyber operations against US critical infrastructure: No fresh reporting on MOIS/IRGC-directed offensive cyber operations despite active conflict and the Handala FLASH alert from March 20. CISA's degraded staffing may be suppressing public advisories.
- Adversary recruitment of DOGE-displaced cleared personnel: Prior briefs flagged this as an active CI concern, but no new incidents or assessments were reported in this window.