//
OFFLINE — VIEWING CACHED CONTENT
← Back to Archive

IC BRIEF — 23 March 2026

Current as of 2210 EDT (UTC-4), Monday 23 March 2026

Contents

8 stories from 9 sources across 9 organizations


BOTTOM LINE UP FRONT

Tuesday's Anthropic v. Pentagon hearing before Judge Rita Lin in San Francisco is the week's pivotal IC event. The DOJ's own argument, that an AI vendor could 'alter model behavior during warfighting operations,' inadvertently validates Anthropic's position that supply chain risk statutes were designed for foreign adversaries, not domestic contract disputes. If the injunction holds, the Pentagon must find an alternative to the Claude AI backbone powering Maven's 8,000+ targeting actions in Iran within 180 days.

The Department of Homeland Security (DHS) workforce crisis entered its sixth week with NPR's ground-truth survey revealing extreme geographic variance: 200-minute waits at Houston Intercontinental vs. empty checkpoints at Dulles, exposing Transportation Security Administration (TSA)'s triage strategy of cannibalizing quiet airports to staff hot spots. Mullin's confirmation as DHS Secretary, expected Monday evening, makes him the immediate crisis manager, but the underlying funding stalemate remains unresolved.

Cybersecurity and Infrastructure Security Agency (CISA) issued a Binding Operational Directive (BOD) ordering federal agencies to patch the DarkSword iOS exploit chain by April 3 after Cloud Security Alliance (CSA) researchers linked it to both Turkish (UNC6748) and Russian (UNC6353) state intelligence actors. The public leak of the full exploit kit transforms what was a targeted state tool into a commodity threat against every federal iPhone.


Leadership & Organization

Senate Advances Mullin DHS Confirmation on Party-Line Vote; Final Vote Expected Monday

The Senate advanced Markwayne Mullin's nomination as Homeland Security Secretary 54-37 during a rare weekend session, with confirmation expected late Monday. Only two Democrats, Fetterman and Heinrich, crossed party lines. Mullin replaces Kristi Noem, fired over immigration enforcement backlash, and inherits a department in simultaneous crisis: DHS funding blocked since mid-February, TSA callout rates at historic highs, ICE agents deployed to airports, and CISA operating at 38% staffing. Republican Homeland Security Chairman Rand Paul voted against and questioned Mullin's character during his confirmation hearing. Mullin pledged to require judicial warrants for home entries and signaled he would revoke Noem's contract approval rule affecting disaster aid distribution.

Analyst Note: Prior IC briefs tracked the Mullin nomination through committee (8-7 vote March 19) and predicted late-week confirmation. Paul's opposition, from the Republican committee chairman, signals Mullin will face skeptical oversight from his own party on civil liberties issues, potentially creating space for FISA and surveillance reform that DHS equities would normally oppose.

Sources:

Watch Items - Mullin confirmation vote expected late Monday March 24; watch for DHS operational directives within first 48h - NCTC directorship remains vacant since Kent nomination stalled; watch for interim appointment - Congressional recess compresses timeline for FISA, DHS funding, and intelligence authorization

Operations & Intelligence Failures

CISA Orders Federal Agencies to Patch DarkSword iOS Exploit Chain Linked to Turkish and Russian State Actors

CISA added three DarkSword iOS vulnerabilities (CVE-2025-31277, CVE-2025-43510, CVE-2025-43520) to its Known Exploited Vulnerabilities catalog under BOD 22-01, ordering federal agencies to patch within two weeks by April 3. The DarkSword exploit chain enables sandbox escape, privilege escalation, and remote code execution on iPhones running iOS 18.4-18.7, deploying three information-stealing malware families: GhostBlade, GhostKnife, and GhostSaber. The CSA Research Alliance linked DarkSword to UNC6748, a customer of Turkish commercial surveillance vendor PARS Defense, and suspected Russian espionage group UNC6353, making the chain a multi-state-actor intelligence collection tool. The public leak of the complete exploit kit means any capable adversary now has weaponized iOS zero-days affecting federal government devices.

Analyst Note: The prior IC brief tracked the CanisterWorm wiper targeting Iranian systems and the FBI Handala FLASH alert as the two primary cyber operations threads. DarkSword adds a third vector: state-sponsored mobile exploitation now available as a commodity. At 38% staffing, CISA may lack capacity to enforce its own BOD compliance deadline while simultaneously managing Iran-war-related cyber threats.

Sources:

Watch Items - DarkSword CISA patch deadline April 3; watch for agency compliance reporting - Monitor for additional state actors adopting the leaked DarkSword exploit kit - Trump's 5-day Iran strike postponement expires ~March 28

Congressional Oversight & Policy

(Developing) Anthropic Files Sworn Declarations Challenging Pentagon Supply Chain Risk Claims Ahead of Tuesday Hearing

Anthropic filed sworn declarations disputing the Pentagon's assertion that the company poses a national security risk, ahead of a March 24 preliminary injunction hearing before Judge Rita Lin. The company's policy and public sector leaders contested claims around control and security risks, arguing key government concerns were never raised during negotiations and that deployed systems cannot be remotely altered. The DOJ responded that Anthropic's refusal to accept contract terms is 'conduct, not protected speech' and warned an AI vendor with model control could 'preemptively alter behavior during ongoing warfighting operations.' The designation, historically reserved for foreign adversaries, has never been applied to a domestic company. Nearly 150 retired judges plus Microsoft filed amicus briefs supporting Anthropic. The hearing constitutes the first major judicial test of whether the Trump administration exceeded its authority in weaponizing supply chain risk statutes against domestic policy disagreements.

Analyst Note: Three consecutive IC briefs have tracked this case's escalation from political rhetoric to legal record. The DOJ's 'preemptive alteration during warfighting' argument concedes the Pentagon depends on a vendor it has simultaneously declared a national security threat. If the injunction holds, DOD's 180-day Claude removal timeline starts running against Maven operations processing 8,000+ targeting actions in the Iran campaign.

Sources:

Prior Reporting - [Anthropic Challenges Pentagon Claims in Ongoing AI National Security Dispute](https://theaiinsider.tech/2026/03/23/anthropic-challenges-pentagon-claims-in-ongoing-ai-national-security-dispute/) (2026-03-23) - [Elizabeth Warren calls Pentagon's decision to bar Anthropic 'retaliation'](https://www.yahoo.com/news/articles/elizabeth-warren-calls-pentagon-decision-152257281.html) (2026-03-23)
Watch Items - Anthropic preliminary injunction hearing Tuesday March 24 at 1:30 PM PT; ruling could come same day or within 48h - Section 702 expiration April 20, 28 days away; House has 12 session days remaining before deadline - SAVE Act Senate vote expected to fail this week; watch for fallout on FISA vehicle

Technology & OSINT

Space Force Kronos C2 Contracts Expected April as Space Battle Management Modernization Accelerates

Space Systems Command plans to issue initial Other Transaction Authority (OTA) contracts beginning in April for Kronos, a modernization initiative focused on operational command and control and battle management software for space domain awareness. Kronos was separated from the troubled ATLAS project in May 2025 after Director, Operational Test and Evaluation (DOT&E) testing found ATLAS 'did not contain the minimum viable capability necessary' for replacing the 1980s-era Space Defense Operations Center (SPADOC) system. The program covers three lines of effort: theater support software, space defense software, and infrastructure/data requirements, including 'Space Intelligence Integration.' Space Systems Command (SSC) plans staggered monthly awards with regular reopened solicitations, a departure from traditional single-vendor approaches.

Sources:

Trump Admin AI Policy Sends Conflicting Signals: Anthropic Banned While GSA Mandates 'American AI' in Contracts

The Trump administration's push for federal AI adoption is undermined by contradictory actions. While the White House released a vendor-friendly AI Action Plan last July, the Pentagon designated Anthropic's Claude a supply chain risk and ordered all agencies to stop using it, with defense contractors required to certify non-use. Simultaneously, General Services Administration (GSA) released a nine-page draft clause for schedule contracts requiring vendors to use only 'American AI systems,' disclose all AI in service delivery, and grant government ownership of data and custom developments. George Washington University's Jessica Tillipman observed both actions 'send a really bad message to industry.' Experts warn the restrictions may push vendors and agencies away from GSA schedules toward alternative procurement vehicles. The GSA comment period was extended to April 3.

Analyst Note: The prior IC brief reported Maven's designation as a permanent program of record. The GSA clause creates a parallel procurement chokepoint: IC agencies using GSA schedules must now certify their AI tools are 'American,' a term with no statutory definition, while simultaneously being barred from the American company (Anthropic) whose model underpins their primary targeting system.

Sources:

RSAC 2026: Trump Cyber Strategy Shifts from Defensive Posture to Active Offensive Operations

Industry leaders at RSA Conference (RSAC) 2026 described a fundamental shift in U.S. cyber strategy from passive deterrence to active offensive operations. Palo Alto Networks' Wendi Whitmore reported 'I have never before seen as much action and cooperation as we are seeing today,' noting increased government proactivity compared to previous administrations. Sidley Austin's David Lashway said the strategy enables the government to 'take offensive and defensive action with the most powerful cyber capability' available, coordinating across agencies rather than relying on fragmented private-sector efforts. Paladin Capital's Jamil Jaffer framed the approach using deterrence theory, arguing visible public responses to intrusions discourage future attacks. The strategy does not authorize private offensive cyber operations.

Sources:

M-Trends 2026: High-Tech Overtakes Finance as Top Cyber Target; Dwell Time Rises to 14 Days

Mandiant's M-Trends 2026 report, based on 500,000+ hours of incident response investigations in 2025, reveals high-tech companies now comprise 17% of investigations, surpassing financial services (14.6%) for the first time. Median global dwell time increased to 14 days from 11 in 2024. North Korean espionage campaigns registered 122-day median dwell times, outpacing all other actors. Mandiant tracked 661 new threat clusters and 714 new malware families in 2025 alone, bringing totals to over 5,000 tracked clusters and 6,000 malware families. Vulnerability exploits dominated initial access at 32% for the sixth consecutive year, while voice phishing surged to 11% and traditional email phishing declined to 6%. ClickFix social engineering using deceptive CAPTCHAs expanded globally.

Analyst Note: The dwell time increase from 11 to 14 days reverses a multi-year downward trend and coincides with CISA's degraded staffing and the DOGE-driven attrition of cleared cybersecurity specialists. The 122-day Democratic People's Republic of Korea (DPRK) dwell time is concerning given the prior IC brief's reporting on WaterPlum/StoatWaffle campaigns targeting developers; these actors are getting in and staying undetected for months.

Sources:

Watch Items - Anthropic injunction ruling this week; determines whether Maven loses its AI backbone - GSA 'American AI' draft clause comment period closes April 3 - Kronos C2 first contracts expected April; watch for vendor announcements - RSAC 2026 continues this week; additional cyber policy announcements expected

Hiring & Workforce

(Developing) DHS Shutdown Airport Impact Varies Wildly by Location; ICE Agents Begin Patrols at New Orleans

NPR's on-the-ground survey of 6 airports across 5 cities found extreme variation in DHS shutdown impact: George Bush Intercontinental in Houston saw 200-minute waits, while Dulles had more officers than travelers. The inconsistency reflects TSA's National Deployment Force reassigning officers from quieter airports to understaffed hotspots, a triage approach that masks systemic workforce erosion. ICE agents began patrols at New Orleans' Louis Armstrong International for crowd management after the airport advised three-hour early arrivals. TSA officers confirmed colleagues leaving the force, with one noting increased callouts from financial hardship. The variation data undercuts both the administration's claim that the shutdown is manageable and critics' claim of universal crisis. The reality is localized collapse at high-traffic hubs.

Analyst Note: The prior IC brief reported national callout rates of 47.4% at Houston Hobby and 400+ officers lost. Today's NPR ground-truth adds granularity: TSA is robbing Peter to pay Paul, deploying the National Deployment Force to redistribute staff rather than address the root cause. This means airports currently reporting short waits (Dulles, Orlando) are likely seeing artificially maintained staffing that will degrade as the shutdown continues and the donor airports' local staff continues to attrit.

Sources:

Prior Reporting - [Record numbers of TSA officers called out Saturday as DHS shutdown continues](https://abcnews.com/US/record-numbers-tsa-officers-called-saturday-dhs-shutdown/story?id=131307007) (2026-03-22) - [ICE officers will begin assisting TSA as shutdown frustrates travelers and screeners](https://whyy.org/articles/tsa-ice-officers-shutdown-air-travel/) (2026-03-23) - [ICE officers will begin assisting TSA as shutdown frustrates travelers and screeners](https://www.washingtontimes.com/news/2026/mar/23/ice-officers-start-assisting-tsa-shutdown-frustrates-travelers/) (2026-03-23)
Watch Items - Mullin's first DHS operational directives: watch for TSA/ICE staffing changes - DHS funding negotiation window narrows before congressional recess - CISA staffing at 38% during active Iranian cyber threat; watch for any new hires or contractor augmentation

COLLECTION GAPS

UNCLASSIFIED // OPEN SOURCE