IC BRIEF
Current as of 0429 EDT (UTC-04), Saturday 09 May 2026
Contents
- IC Workforce & Leadership (2)
- Allied Intelligence (3)
- Adversary Intelligence (3)
- IC Technology & Surveillance (2)
- Agency Operations (1)
- IC Oversight & Authorities (1)
- COLLECTION GAPS
12 stories from 38 sources across 35 organizations
BOTTOM LINE UP FRONT
Chinese intelligence services are conducting concurrent cyber and human operations against Western targets. At least two additional Western governments will likely make public attributions within six months. Confidence is high, driven by Norway's prosecution of a Chinese satellite-espionage cell at Andøya, Trend Micro's disclosure of eight-nation targeting by
IC governance capacity faces concurrent strain. A declassified March Foreign Intelligence Surveillance Court (FISC) opinion found that Section 702 filtering violations persist beyond the FBI despite claimed Department of Justice (DOJ) remediation; compliance is likely to remain contentious through year-end. The Five Eyes' assessment that
A quarter without new Western attributions of Chinese operations would weaken the trajectory forecast. A DOJ remediation announcement resolving the March violations, or the absence of congressional 702 hearings through Q3, would alter the contention assessment. The leaked Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU) drone-technology proposal rests on an unverified document and represents a contingency.
IC Workforce & Leadership
NBIS Named Key Priority for New DCSA Director
Under Secretary of War for Intelligence and Security Bradley Hansell on May 7 named
Analyst Note: The selection follows a DoD requirement, documented in February congressional testimony, for a director with 'the optimal mix of private sector, technology, and government experience.' Tonon's résumé spanning Amazon Web Services (AWS) global defense, Oracle defense and intelligence, and Pentagon analytics roles fits that specification closely enough to read as deliberate rather than circumstantial. His immediate mandate centers on National Background Investigation Services (NBIS), the cloud-based vetting platform underpinning Trusted Workforce 2.0, which has faced a persistent gap between policy intent and operational delivery. Congressional oversight pressure, a formal Trusted Workforce 2.0 mandate, and incoming leadership whose professional identity is tied to enterprise technology delivery all point toward NBIS remaining Defense Counterintelligence and Security Agency (DCSA)'s primary institutional priority through the current budget cycle. The harder question is whether private-sector execution discipline transfers into federal procurement and workforce timelines that have historically resisted it.
Sources:
- Primary Reporting: NBIS a key priority for new DCSA director -
Federal News Network - Primary Reporting: Joseph M. Tonon Named Director of the Defense Counterintelligence and Security Agency -
Defense Counterintelligence and Security Agency (DCSA) - Secondary Reporting: The Signal in the Selection: New Technology-Leading DCSA Director -
ClearanceJobs - Secondary Reporting: Joseph Tonon Named DCSA Director -
ExecutiveGov
DNI Gabbard Delivers Keynote at 2026 Independent Womens Policy Summit
Director of National Intelligence Tulsi Gabbard addressed the 2026
Analyst Note: A sitting Director of National Intelligence (DNI) delivering politically charged remarks at a partisan advocacy summit applies IC institutional credibility to culture-war argumentation, a posture analytically distinct from any reform agenda inside the intelligence community. Gabbard's choice to frame the transgender sports debate as a 'perfect case study' for objective truth is a governance argument, not an intelligence one, and it offers no evidence that her leadership priorities are directed at concrete IC reform. We assess it is uncertain whether Gabbard will announce a substantive IC reform initiative by end of Q3 2026. The May 7 remarks contain no reform-specific content, and approximately five months of window remain in which a discrete initiative could still materialize. The assessment rests on moderate confidence, grounded in official ODNI sourcing that authenticates the speech but leaves operational IC intent unaddressed.
Sources:
- Primary Reporting: DNI Gabbard Remarks at 2026 Independent Womens Policy Summit -
ODNI - Primary Reporting: Speak Objective Truth, Lead with a Servant's Heart -
Office of the Director of National Intelligence - Secondary Reporting: DNI Tulsi Gabbard Delivers Remarks at 2026 Independent Women's Policy Summit -
The Last Refuge (The Conservative Treehouse)
Watch - DNI Gabbard will announce at least one substantive IC policy reform by end of Q3 2026
Allied Intelligence
Five Eyes Agencies Warn Agentic AI Too Dangerous for Rapid Rollout
The Five Eyes cybersecurity agencies, representing the US, UK, Australia, Canada, and New Zealand, published a joint report in early May warning against rapid agentic AI deployment, according to IT Pro and The Register. The report directed organizations to restrict use to strictly necessary, non-sensitive functions and to consider alternatives, explicitly citing "reducing or eliminating low-value processes" as potentially lower-risk. Until evaluation methods and standards mature, the report stated, organizations should "assume that agentic AI systems may behave unexpectedly" and prioritize "resilience, reversibility and risk containment over efficiency gains." On controls, it called for layered defenses, prompt-context restrictions against injection attacks, human oversight, and a distinct cryptographic identity for each agent.
Analyst Note: The Five Eyes advisory marks a formal intelligence-community determination that agentic AI represents a distinct attack surface requiring governance frameworks that existing protocols for human actors cannot address, signaling that the risk conversation has shifted from academic concern to national security calculus. That the agencies recommend eliminating processes outright rather than simply securing AI agents reflects an unusually conservative posture for a multilateral technology advisory and suggests current tooling gaps are viewed as fundamental rather than incremental. Organizations operating in Five Eyes jurisdictions are
Sources:
- Primary Reporting: Careful adoption of agentic AI services -
Australian Cyber Security Centre - Secondary Reporting: Five Eyes Warn Agentic AI Is Too Dangerous for Rapid Rollout -
The Register - Secondary Reporting: Five Eyes agencies sound alarm over risky agentic AI deployments -
IT Pro
Watch - Five Eyes will publish formal agentic AI security guidelines within 6 months
Israeli High Court Hears Challenge Against Incoming Mossad Chief Gofman Appointment
Israel's High Court of Justice is scheduled to hear petitions Tuesday challenging Netanyahu's appointment of Maj. Gen.
Analyst Note: The petition against Gofman is the second consecutive legal challenge to a Netanyahu security service appointment, and the High Court's recent rejection of analogous petitions against the Shin Bet pick provides the strongest precedent indicator. The court is
Sources:
- Primary Reporting: High Court urged to reject petitions against Gofman Mossad appointment -
The Jerusalem Post - Primary Reporting: Netanyahu, defending Mossad pick, tells court security responsibility his alone -
The Times of Israel - Primary Reporting: 'Responsibility for national security entrusted to PM': Netanyahu defends Mossad chief pick in court -
Ynet News - Secondary Reporting: Petition filed against incoming Mossad director on integrity grounds -
Times of Israel
German Intelligence Officials Warn of Rising Iran-Linked Hybrid Terror Threat, Clash With Government Leaders
Germany's Federal Office for the Protection of the Constitution warned of a rising threat from
Analyst Note: Harakat Ashab al-Yamin al-Islamiya has claimed at least 15 attacks across five European countries since early March, and Bundesamt für Verfassungsschutz (Federal Office for the Protection of the Constitution) (BfV)'s explicit warning of a pivot toward explosives and weapons signals that Iran's European proxy network is moving from intimidation to capability escalation. Recruiting young individuals for modest payments via social media and encrypted apps mirrors documented Islamic Revolutionary Guard Corps (IRGC)-linked activation tactics in other theaters and points to external direction rather than organic radicalization. Germany's public identification of the group's probable ties to Iraqi Shiite networks confirms these cells operate within a preexisting proxy infrastructure that was activated, not assembled, in response to the US-Israeli campaign against Iran earlier this year. Whether Germany will formally elevate its threat assessment or announce new counterterrorism measures targeting Iranian networks within the next 90 days is
Sources:
- Primary Reporting: German Intelligence Warns of Rising Iran-Linked Terror Threat -
The Algemeiner - Secondary Reporting: German Intelligence Officials Warn of Iran Terror Threat, Clash With Government -
New York Times
Adversary Intelligence
Leaked GRU Document Reveals Plan to Supply Iran With 5000 Fiber-Optic Drones for Use Against US Forces
The Economist on May 8 published a confidential ten-page GRU document proposing to supply Iran with 5,000 short-range
Analyst Note: The GRU document, if authentic, marks a qualitative shift in what Russia was prepared to formally propose to Iran: not components feeding existing Iranian airframes but a complete operational fleet, with targeting doctrine and a training pipeline built around Iranian students already inside Russia. The fiber-optic guidance system is the operationally critical element, rendering U.S. electronic warfare countermeasures ineffective against any drone equipped with it. The document's explicit focus on American amphibious craft indicates Russian planners mapped specific U.S. vulnerabilities before drafting the proposal. Iran operationally deploying fiber-optic guided drones against regional targets within 12 months from date of forecast is
Sources:
- Primary Reporting: Secret document reveals Russias plans to aid Iran -
The Economist - Secondary Reporting: Russia reportedly planned to aid Iran with fiber-optic drones and training -
Fox News - Secondary Reporting: Russia Planned to Supply Iran With Thousands of Drones -
Kyiv Post - Secondary Reporting: Russia Has Offered to Provide Iran With Un-Jammable Drones -
Newsmax - Secondary Reporting: Russia GRU fiber-optic drones Iran US forces -
DroneXL
China-Aligned Shadow-Earth-053 Cyberespionage Campaign Targets Eight Asian Nations and Poland
On May 1, Trend Micro disclosed Shadow-Earth-053, a China-aligned campaign active since at least December 2024 that has targeted government and defense networks in Pakistan, Thailand, Malaysia, India, Myanmar, Sri Lanka, Taiwan, and Poland. The Diplomat's reporting described attackers exploiting unpatched Microsoft Exchange and Internet Information Services (IIS) servers via Microsoft Exchange Server vulnerability chain (CVE-2021-26855 and related) (ProxyLogon) vulnerabilities, installing custom backdoors and espionage malware, and in one instance leveraging a previously unknown Linux vulnerability for initial access. Two linked phishing clusters, Glitter Carp and Sequin Carp, targeted Uyghur, Tibetan, Taiwanese, and Hong Kong diaspora activists and journalists using tracking-pixel emails and credential-harvesting pages. Trend Micro assessed China-aligned actors, possibly including commercial contractors, as responsible and noted that nearly half of targets were also hit by the related
Analyst Note: Shadow-Earth-053's dual-track architecture pairs ProxyLogon exploitation against government and defense networks with precision phishing of diaspora critics. Beijing ran both tracks as a unified operational framework, not parallel programs, which the near-complete infrastructure overlap with Shadow-Earth-054 reinforces. The Poland node carries particular strategic weight: Warsaw is a principal corridor for Western military aid to Ukraine, making any sustained access a window into NATO logistics and arms supply chains. Targeting India raises the Quad stakes; sustained access to New Delhi's defense ministry networks could expose joint naval planning with Washington and Canberra. The deployment of a previously unknown Linux vulnerability alongside conventional ProxyLogon techniques points to a more mature and modular Chinese offensive enterprise than cluster-by-cluster attribution captures. Whether additional Western government or defense-sector victims will be publicly identified within 6 months of disclosure (by November 2026) is
Sources:
- Primary Reporting: Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign -
Trend Micro vinfo - Secondary Reporting: Chinas Cyber Operations Hit Asian Governments and Dissidents Abroad -
The Diplomat
Norway Charges Chinese Woman and Several Others With Espionage at Andoya Satellite Launch Site
Norway's Politiets Sikkerhetstjeneste (Norwegian Police Security Service) (PST) arrested a Chinese woman on May 8 on suspicion of complicity in attempted aggravated espionage, and charged several additional individuals whose identities have not been disclosed. PST attorney Thomas Blom said a Norwegian-registered company was operating as a cover for a Chinese state actor attempting to install a receiver to download polar-orbit satellite data that could "harm fundamental Norwegian interests." Police searched two addresses, on Andøya island in Nordland and in Otta, Innlandet, seizing the receiver before it was put into operation.
Analyst Note: Beijing's decision to physically implant collection infrastructure rather than rely on cyber access marks an escalation in Chinese intelligence tradecraft targeting Norway, consistent with PST's 2025 threat assessment flagging China's interest in positioning assets near critical infrastructure. The Norwegian-registered corporate shell paired with a geographically separated support address at Otta reflects deliberate architecture designed to create a legitimacy layer between the collection device and identifiable state sponsorship. Because the receiver targeted polar-orbit satellites and Andøya holds an agreement with the United States to launch American satellites, the intended collection likely extended well beyond Norwegian national programs. PST's interdiction before the receiver became operational means the full scope of collection tasking remains unknown. We assess that Norway is
Sources:
- Primary Reporting: PST: Kinesisk borger pågrepet for medvirkning til forsøk på spionasje -
NRK - Secondary Reporting: Norwegian police arrest a Chinese citizen on spying allegations -
ABC News (AP Wire) - Secondary Reporting: Several charged with espionage -
News in English Norway - Secondary Reporting: Norway arrests Chinese woman for spying on satellite data -
The Local Norway
IC Technology & Surveillance
NRO Director Flags AI Explainability as Major Concern for Satellite Intelligence
Speaking at the United States Geospatial Intelligence Foundation (USGIF) Geospatial Intelligence (GEOINT) Symposium in Denver on Wednesday, outgoing NRO Director
Analyst Note: Scolese's characterization of AI explainability as 'still an open area of research,' combined with his explicit call for industry to develop validation methods NRO lacks internally, places the agency well short of the policy maturity needed to codify formal acquisition requirements. The institutional distance from an unresolved research problem to binding program standards is substantial; it requires concept validation, internal consensus, and regulatory drafting that historically unfolds over years rather than months. We assess it is
Sources:
- Primary Reporting: AI explainability is a major concern for National Reconnaissance Office: Director -
Breaking Defense - Secondary Reporting: Chris Scolese on AI's Role in NRO's Space-Based Intel Capability Delivery -
ExecutiveGov
Watch - At least one IC agency will establish formal AI explainability standards for acquisition by end of 2026
HawkEye 360 Raises $416M in IPO, Signals Intelligence Satellite Company Begins NYSE Trading
Analyst Note: Pricing at the ceiling of its range and a 30% opening-day gain mark HawkEye 360's debut as the clearest public market signal yet that institutional capital has validated commercial space-based SIGINT as a defense-critical sector. Directing Initial Public Offering (IPO) proceeds toward debt retirement and the deferred payment on its December 2025 acquisition of Innovative Signals Analysis consolidates the analytics pipeline rather than expanding the satellite constellation, indicating management expects near-term revenue growth from software and analytics margins rather than new collection capacity. HawkEye is
Sources:
- Primary Reporting: Surveillance Firm Hawkeye 360 Raises $416 Million in IPO -
Bloomberg - Primary Reporting: HawkEye 360 Announces Pricing of Initial Public Offering -
PR Newswire - Secondary Reporting: HawkEye 360 Raises $416M in IPO -
Payload Space - Secondary Reporting: HawkEye 360 Raises $416M, Pricing at High End for IPO -
Via Satellite
Agency Operations
US Intelligence Assesses Injured Supreme Leader Khamenei Still Shaping Iran Strategy Despite Isolation
CNN, citing multiple US intelligence sources, reported Friday that
Analyst Note: The fractured Iranian command structure that emerged from the opening strikes has created a genuine principal-agent problem at the heart of US-Iran diplomacy. Mojtaba Khamenei's physical isolation and deliberate avoidance of all electronic communications have severed standard US collection pathways. Assessments of his actual authority now rest entirely on characterizations from those who claim access to him, a sourcing dependency the IC itself flags as potentially manipulated. Senior IRGC commanders and Ghalibaf have absorbed day-to-day operational control, but neither holds the theological standing to bind Tehran to a nuclear agreement, which means any deal reached without confirmed supreme leader authorization carries serious ratification risk. We assess it is
Sources:
- Primary Reporting: Irans injured supreme leader out of public view but still shaping strategy, US intel assesses -
CNN - Secondary Reporting: US intel said to assess Mojtaba Khamenei is playing key role in crafting Irans war strategy -
The Times of Israel - Secondary Reporting: US intelligence believes Khamenei remains key figure in Irans war strategy despite serious injuries -
Ynet News - Secondary Reporting: Irans new Supreme Leader shaping war strategy even as questions swirl over his health: Report -
ANI News
Watch - US IC will produce a formal succession assessment for Iran within 6 months
IC Oversight & Authorities
Declassified FISA Court Opinion Reveals Continuing FBI Section 702 Filtering Violations Extending Across IC
A declassified March 17 FISA Court opinion, released as part of the
Analyst Note: The March opinion's IC-wide scope and the targeting of a sitting state court judge expose DOJ's early-2025 remediation claims as either incomplete or abandoned, sharply raising the stakes entering the reauthorization negotiation in Congress. Whether FISC imposes additional compliance requirements on FBI Section 702 queries before the 45-day extension expires in mid-June 2026 is
Sources:
- Primary Reporting: New FISA Court Opinion Reveals Continuing Violations by the FBI -
Brennan Center for Justice
Watch - FISC will impose additional compliance requirements on FBI Section 702 queries before next reauthorization review
COLLECTION GAPS
- ODNI internal restructuring and workforce initiatives under DNI Gabbard remain opaque beyond her public appearances.
- MSS operational direction of commercial cyber contractors remains opaque despite Trend Micro's attribution of Shadow-Earth-053 to possible contractor involvement.
- Iranian proxy command structure and degree of centralized IRGC-QF direction over European-based cells like Harakat Ashab al-Yamin al-Islamiya is unconfirmed beyond the German BfV's characterization.
- Congressional intelligence committee posture on Section 702 compliance following the March FISC opinion has not entered the public record.
- Russian fiber-optic drone technology transfer pipeline to Iran lacks any corroborating source beyond the single leaked GRU document published by The Economist.