//
OFFLINE — VIEWING CACHED CONTENT
← Back to Archive

IC BRIEF

Current as of 0429 EDT (UTC-04), Saturday 09 May 2026

Contents

12 stories from 38 sources across 35 organizations


BOTTOM LINE UP FRONT

Chinese intelligence services are conducting concurrent cyber and human operations against Western targets. At least two additional Western governments will likely make public attributions within six months. Confidence is high, driven by Norway's prosecution of a Chinese satellite-espionage cell at Andøya, Trend Micro's disclosure of eight-nation targeting by Shadow-Earth-053, and Five Eyes' attribution coordination. Whether broader adversary operational tempo constitutes an intensification through year-end is genuinely uncertain, given the gap between public disclosure and classified activity.

IC governance capacity faces concurrent strain. A declassified March Foreign Intelligence Surveillance Court (FISC) opinion found that Section 702 filtering violations persist beyond the FBI despite claimed Department of Justice (DOJ) remediation; compliance is likely to remain contentious through year-end. The Five Eyes' assessment that agentic AI is too dangerous for rapid deployment, paralleled by National Reconnaissance Office (NRO)'s acknowledgment that explainability remains unsolved, will likely sustain pressure on the IC to adopt formal governance frameworks within 12 months. Confidence in both governance assessments is moderate.

A quarter without new Western attributions of Chinese operations would weaken the trajectory forecast. A DOJ remediation announcement resolving the March violations, or the absence of congressional 702 hearings through Q3, would alter the contention assessment. The leaked Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU) drone-technology proposal rests on an unverified document and represents a contingency.


IC Workforce & Leadership

NBIS Named Key Priority for New DCSA Director

Under Secretary of War for Intelligence and Security Bradley Hansell on May 7 named Joseph Tonon director of the Defense Counterintelligence and Security Agency, succeeding acting director Justin Overbaugh, who held the position following David Cattler's retirement. Tonon most recently served on Amazon Web Services' global defense team and previously spent nearly two years at Oracle as director for defense and intelligence, according to his LinkedIn profile as cited by ExecutiveGov. His government background includes serving as acting assistant secretary of defense for special operations and leading technology and data loss prevention efforts on the Secretary of the Navy's staff, per ClearanceJobs. ExecutiveGov reports his responsibilities as director will include overseeing continued development and deployment of the National Background Investigation Services platform, which supports the federal government's Trusted Workforce 2.0 personnel vetting initiative.

Analyst Note: The selection follows a DoD requirement, documented in February congressional testimony, for a director with 'the optimal mix of private sector, technology, and government experience.' Tonon's résumé spanning Amazon Web Services (AWS) global defense, Oracle defense and intelligence, and Pentagon analytics roles fits that specification closely enough to read as deliberate rather than circumstantial. His immediate mandate centers on National Background Investigation Services (NBIS), the cloud-based vetting platform underpinning Trusted Workforce 2.0, which has faced a persistent gap between policy intent and operational delivery. Congressional oversight pressure, a formal Trusted Workforce 2.0 mandate, and incoming leadership whose professional identity is tied to enterprise technology delivery all point toward NBIS remaining Defense Counterintelligence and Security Agency (DCSA)'s primary institutional priority through the current budget cycle. The harder question is whether private-sector execution discipline transfers into federal procurement and workforce timelines that have historically resisted it.

Sources:

DNI Gabbard Delivers Keynote at 2026 Independent Womens Policy Summit

Director of National Intelligence Tulsi Gabbard addressed the 2026 Independent Women's Policy Summit in Washington, D.C. on May 7. Office of the Director of National Intelligence (ODNI) issued a concurrent press release titled "Speak Objective Truth, Lead with a Servant's Heart," with a full transcript of her remarks published by The Conservative Treehouse. Gabbard argued that caring about service, not institutional credentials or political endorsements, is the defining qualification for leadership, drawing on her own congressional race in Hawaii. She cited the debate over transgender athletes in women's sports as, in her words, "a perfect case study," arguing that societal rejection of objective truth removes guardrails across governance, journalism, and policymaking.

Analyst Note: A sitting Director of National Intelligence (DNI) delivering politically charged remarks at a partisan advocacy summit applies IC institutional credibility to culture-war argumentation, a posture analytically distinct from any reform agenda inside the intelligence community. Gabbard's choice to frame the transgender sports debate as a 'perfect case study' for objective truth is a governance argument, not an intelligence one, and it offers no evidence that her leadership priorities are directed at concrete IC reform. We assess it is uncertain whether Gabbard will announce a substantive IC reform initiative by end of Q3 2026. The May 7 remarks contain no reform-specific content, and approximately five months of window remain in which a discrete initiative could still materialize. The assessment rests on moderate confidence, grounded in official ODNI sourcing that authenticates the speech but leaves operational IC intent unaddressed.

Sources:

Watch - DNI Gabbard will announce at least one substantive IC policy reform by end of Q3 2026

Allied Intelligence

Five Eyes Agencies Warn Agentic AI Too Dangerous for Rapid Rollout

The Five Eyes cybersecurity agencies, representing the US, UK, Australia, Canada, and New Zealand, published a joint report in early May warning against rapid agentic AI deployment, according to IT Pro and The Register. The report directed organizations to restrict use to strictly necessary, non-sensitive functions and to consider alternatives, explicitly citing "reducing or eliminating low-value processes" as potentially lower-risk. Until evaluation methods and standards mature, the report stated, organizations should "assume that agentic AI systems may behave unexpectedly" and prioritize "resilience, reversibility and risk containment over efficiency gains." On controls, it called for layered defenses, prompt-context restrictions against injection attacks, human oversight, and a distinct cryptographic identity for each agent.

Analyst Note: The Five Eyes advisory marks a formal intelligence-community determination that agentic AI represents a distinct attack surface requiring governance frameworks that existing protocols for human actors cannot address, signaling that the risk conversation has shifted from academic concern to national security calculus. That the agencies recommend eliminating processes outright rather than simply securing AI agents reflects an unusually conservative posture for a multilateral technology advisory and suggests current tooling gaps are viewed as fundamental rather than incremental. Organizations operating in Five Eyes jurisdictions are likely, within the next six months, to face increased procurement scrutiny and informal regulatory pressure to demonstrate compliance with the advisory's most auditable requirements, particularly per-agent cryptographic identity and documented human-oversight mechanisms. Confidence in this assessment is low. The guidance carries no enforcement mechanism, and available reporting draws entirely from the published document with no indication of how implementing agencies intend to operationalize the requirements.

Sources:

Watch - Five Eyes will publish formal agentic AI security guidelines within 6 months

Israeli High Court Hears Challenge Against Incoming Mossad Chief Gofman Appointment

Israel's High Court of Justice is scheduled to hear petitions Tuesday challenging Netanyahu's appointment of Maj. Gen. Roman Gofman as Mossad director, set to take office June 2. Petitioners Ori Elmakayes and the Telem integrity group allege Gofman authorized a 2022 IDF influence operation in which Elmakayes, then 17, was detained by the Shin Bet and prosecuted for roughly 21 months before being cleared. In a Friday filing, Netanyahu argued the appointment is a security decision meriting minimal judicial review and said advisory committee chair Asher Grunis had exceeded his authority in recommending Gofman's disqualification. The committee majority separately told the court Thursday its approval was legally sound; Gofman denied in his own filing that he directed or knew of any handling relationship with Elmakayes.

Analyst Note: The petition against Gofman is the second consecutive legal challenge to a Netanyahu security service appointment, and the High Court's recent rejection of analogous petitions against the Shin Bet pick provides the strongest precedent indicator. The court is likely to uphold the Gofman appointment before June 2. Analytic confidence is high, grounded in convergent primary-source reporting drawn directly from court filings across three Israeli outlets and the close structural parallel with that prior ruling. The committee majority's Thursday filing directly foreclosed the strongest non-integrity ground for reversal: it argued the accessible record was legally sufficient despite two members lacking clearance to review classified materials. Netanyahu's assertion that security appointments fall outside meaningful judicial review additionally hands the court a constitutional deference rationale it can adopt without adjudicating Gofman's conduct at all. By asserting sole personal accountability for all security decisions, Netanyahu has implicitly accepted personal responsibility for the October 7 intelligence failures. Bereaved family groups have already seized on this framing as a rhetorical liability, and it will persist regardless of how the court rules.

Sources:

German Intelligence Officials Warn of Rising Iran-Linked Hybrid Terror Threat, Clash With Government Leaders

Germany's Federal Office for the Protection of the Constitution warned of a rising threat from Harakat Ashab al-Yamin al-Islamiya, an Iran-linked group that has claimed at least 15 attacks against Jewish and Western targets across Europe since emerging in early March, per Algemeiner reporting on April 28. An agency spokesperson told Handelsblatt the group is signaling a shift away from what it called "simple" attacks toward more dangerous methods, including explosives and weapons. German officials suspect ties to a broader Iraqi Shiite network connected to Iran's proxy infrastructure, with operatives recruited via social media and encrypted platforms for modest payments. Marc Henrichmann, who chairs Germany's parliamentary intelligence oversight committee, told Handelsblatt the surge in incidents is "closely linked to the escalation of the Iran conflict."

Analyst Note: Harakat Ashab al-Yamin al-Islamiya has claimed at least 15 attacks across five European countries since early March, and Bundesamt für Verfassungsschutz (Federal Office for the Protection of the Constitution) (BfV)'s explicit warning of a pivot toward explosives and weapons signals that Iran's European proxy network is moving from intimidation to capability escalation. Recruiting young individuals for modest payments via social media and encrypted apps mirrors documented Islamic Revolutionary Guard Corps (IRGC)-linked activation tactics in other theaters and points to external direction rather than organic radicalization. Germany's public identification of the group's probable ties to Iraqi Shiite networks confirms these cells operate within a preexisting proxy infrastructure that was activated, not assembled, in response to the US-Israeli campaign against Iran earlier this year. Whether Germany will formally elevate its threat assessment or announce new counterterrorism measures targeting Iranian networks within the next 90 days is genuinely uncertain. The BfV has already issued public warnings, but friction between intelligence officials and government leadership introduces political drag that could delay formal institutional escalation. Confidence in this assessment is moderate, grounded in consistent named-official attribution but constrained by the absence of independent corroborating sources.

Sources:

Adversary Intelligence

Leaked GRU Document Reveals Plan to Supply Iran With 5000 Fiber-Optic Drones for Use Against US Forces

The Economist on May 8 published a confidential ten-page GRU document proposing to supply Iran with 5,000 short-range fiber-optic drones, an unspecified number of satellite-guided drones carrying Starlink terminals, and a drone-operator training program. The document, which The Economist estimates was drafted early in the current U.S.-Iran conflict, identifies U.S. amphibious landing craft as priority targets and includes diagrams of swarm attacks from 15 to 30 kilometers. The Economist states explicitly it has no evidence the proposal reached Iranian officials, that drones were transferred, or that training began. Regional intelligence sources cited by the publication found the plan credible but could not corroborate it; Russia intelligence expert Christo Grozev told The Economist the proposal is consistent with other GRU support for Iran.

Analyst Note: The GRU document, if authentic, marks a qualitative shift in what Russia was prepared to formally propose to Iran: not components feeding existing Iranian airframes but a complete operational fleet, with targeting doctrine and a training pipeline built around Iranian students already inside Russia. The fiber-optic guidance system is the operationally critical element, rendering U.S. electronic warfare countermeasures ineffective against any drone equipped with it. The document's explicit focus on American amphibious craft indicates Russian planners mapped specific U.S. vulnerabilities before drafting the proposal. Iran operationally deploying fiber-optic guided drones against regional targets within 12 months from date of forecast is unlikely. The document is undated and unverified, The Economist found no evidence it reached Iranian officials, and Russia's acknowledged commitments in Ukraine reduce the bandwidth available for a transfer program of this scale. Confidence in this assessment is high, grounded in the explicit intelligence gaps The Economist identifies in its own reporting, the absence of corroborating physical evidence across all reporting threads, and a consistent prior pattern showing Russia transferring intelligence and discrete components to Iran rather than complete weapon systems.

Sources:

China-Aligned Shadow-Earth-053 Cyberespionage Campaign Targets Eight Asian Nations and Poland

On May 1, Trend Micro disclosed Shadow-Earth-053, a China-aligned campaign active since at least December 2024 that has targeted government and defense networks in Pakistan, Thailand, Malaysia, India, Myanmar, Sri Lanka, Taiwan, and Poland. The Diplomat's reporting described attackers exploiting unpatched Microsoft Exchange and Internet Information Services (IIS) servers via Microsoft Exchange Server vulnerability chain (CVE-2021-26855 and related) (ProxyLogon) vulnerabilities, installing custom backdoors and espionage malware, and in one instance leveraging a previously unknown Linux vulnerability for initial access. Two linked phishing clusters, Glitter Carp and Sequin Carp, targeted Uyghur, Tibetan, Taiwanese, and Hong Kong diaspora activists and journalists using tracking-pixel emails and credential-harvesting pages. Trend Micro assessed China-aligned actors, possibly including commercial contractors, as responsible and noted that nearly half of targets were also hit by the related Shadow-Earth-054 campaign.

Analyst Note: Shadow-Earth-053's dual-track architecture pairs ProxyLogon exploitation against government and defense networks with precision phishing of diaspora critics. Beijing ran both tracks as a unified operational framework, not parallel programs, which the near-complete infrastructure overlap with Shadow-Earth-054 reinforces. The Poland node carries particular strategic weight: Warsaw is a principal corridor for Western military aid to Ukraine, making any sustained access a window into NATO logistics and arms supply chains. Targeting India raises the Quad stakes; sustained access to New Delhi's defense ministry networks could expose joint naval planning with Washington and Canberra. The deployment of a previously unknown Linux vulnerability alongside conventional ProxyLogon techniques points to a more mature and modular Chinese offensive enterprise than cluster-by-cluster attribution captures. Whether additional Western government or defense-sector victims will be publicly identified within 6 months of disclosure (by November 2026) is genuinely uncertain. Western governments routinely decline to confirm victimhood, and disclosures typically originate with the targeted entity or its national CERT rather than the reporting vendor, leaving the public identification timeline unpredictable. Confidence in this assessment is moderate; Trend Micro's disclosure rests on specific technical indicators, but no second vendor or government source has independently confirmed the attribution or full target scope.

Sources:

Norway Charges Chinese Woman and Several Others With Espionage at Andoya Satellite Launch Site

Norway's Politiets Sikkerhetstjeneste (Norwegian Police Security Service) (PST) arrested a Chinese woman on May 8 on suspicion of complicity in attempted aggravated espionage, and charged several additional individuals whose identities have not been disclosed. PST attorney Thomas Blom said a Norwegian-registered company was operating as a cover for a Chinese state actor attempting to install a receiver to download polar-orbit satellite data that could "harm fundamental Norwegian interests." Police searched two addresses, on Andøya island in Nordland and in Otta, Innlandet, seizing the receiver before it was put into operation. Andøya Space CEO Ketil Olsen said the company had no connection to the individual involved; the Chinese embassy in Oslo did not respond to AFP.

Analyst Note: Beijing's decision to physically implant collection infrastructure rather than rely on cyber access marks an escalation in Chinese intelligence tradecraft targeting Norway, consistent with PST's 2025 threat assessment flagging China's interest in positioning assets near critical infrastructure. The Norwegian-registered corporate shell paired with a geographically separated support address at Otta reflects deliberate architecture designed to create a legitimacy layer between the collection device and identifiable state sponsorship. Because the receiver targeted polar-orbit satellites and Andøya holds an agreement with the United States to launch American satellites, the intended collection likely extended well beyond Norwegian national programs. PST's interdiction before the receiver became operational means the full scope of collection tasking remains unknown. We assess that Norway is genuinely uncertain to secure at least one conviction within approximately four years of charges being filed. Confidence is moderate, grounded in direct PST statements and a physically seized device but tempered by the thin historical record of Norwegian espionage prosecutions and the undisclosed nature of the full evidence record.

Sources:

IC Technology & Surveillance

NRO Director Flags AI Explainability as Major Concern for Satellite Intelligence

Speaking at the United States Geospatial Intelligence Foundation (USGIF) Geospatial Intelligence (GEOINT) Symposium in Denver on Wednesday, outgoing NRO Director Chris Scolese called AI "explainability" a "major concern" and "still an open area of research," per Breaking Defense. Scolese said NRO is expanding AI for satellite fleet management, including orchestrating a SpaceX-operated low-Earth orbit constellation he said will exceed human operators' management capacity as it grows. He described real-time sensor data fusion as the harder validation problem, noting that live conditions cannot be replicated by test the way satellite operations can. NRO is using an internal GPU cluster called the "Ultra-Dense Environment" for model testing, and Scolese called on industry to help develop validation methods.

Analyst Note: Scolese's characterization of AI explainability as 'still an open area of research,' combined with his explicit call for industry to develop validation methods NRO lacks internally, places the agency well short of the policy maturity needed to codify formal acquisition requirements. The institutional distance from an unresolved research problem to binding program standards is substantial; it requires concept validation, internal consensus, and regulatory drafting that historically unfolds over years rather than months. We assess it is unlikely NRO will establish formal AI explainability requirements for acquisition programs by end of calendar year 2026. Analytic confidence in this assessment is high: Scolese's own words frame explainability as an unsolved research problem, and his public call for industry assistance confirms NRO holds no internal validation methodology to translate into policy requirements. The distinction Scolese drew between testable satellite operations and real-time sensor fusion signals that explainability is most urgently needed precisely where NRO is least equipped to verify it, deepening the gap between operational pressure and acquisition-ready policy.

Sources:

Watch - At least one IC agency will establish formal AI explainability standards for acquisition by end of 2026

HawkEye 360 Raises $416M in IPO, Signals Intelligence Satellite Company Begins NYSE Trading

HawkEye 360 began New York Stock Exchange (NYSE) trading on May 7 under the ticker "HAWK," pricing 16 million shares at $26, the top of its stated range, to raise $416 million gross, with Goldman Sachs and Morgan Stanley serving as lead book-running managers. Shares closed up 30 percent at $34 on debut; Payload Space reported the offering valued the company at $2.4 billion. Via Satellite, citing the prospectus, recorded $98.7 million in 2025 revenue, nearly double 2024 levels, and $2.7 million in net income, HawkEye's first profitable year. The company stated proceeds will fund debt retirement, a deferred payment on its December 2025 Innovative Signals Analysis acquisition, and working capital.

Analyst Note: Pricing at the ceiling of its range and a 30% opening-day gain mark HawkEye 360's debut as the clearest public market signal yet that institutional capital has validated commercial space-based SIGINT as a defense-critical sector. Directing Initial Public Offering (IPO) proceeds toward debt retirement and the deferred payment on its December 2025 acquisition of Innovative Signals Analysis consolidates the analytics pipeline rather than expanding the satellite constellation, indicating management expects near-term revenue growth from software and analytics margins rather than new collection capacity. HawkEye is likely to secure at least one new classified U.S. government contract within 12 months of its IPO, sustained by demonstrated profitability, an established operational record with defense and intelligence agencies, and a public balance sheet that removes a material contracting risk for government procurement offices. Confidence in that assessment is high, supported by legally binding prospectus disclosures that independently verify the revenue trajectory and by consistent corroboration across trade reporting.

Sources:

Agency Operations

US Intelligence Assesses Injured Supreme Leader Khamenei Still Shaping Iran Strategy Despite Isolation

CNN, citing multiple US intelligence sources, reported Friday that Mojtaba Khamenei is playing a critical role in shaping Iran's war and negotiating strategy alongside senior officials, though sources described him as only sporadically accessible within a fractured leadership. The US intelligence community has been unable to visually confirm his location since he assumed the supreme leadership in March, with sources saying he communicates only via couriers and in-person meetings, avoiding all electronics. Iran's protocol chief Mazaher Hosseini publicly insisted Friday that Khamenei is "in complete health"; US intelligence sources cited by CNN described serious burns to his face, arm, torso, and leg. CNN's sources added that senior IRGC commanders and Parliament Speaker Ghalibaf are effectively running day-to-day operations while some analysts question whether officials are claiming access to Khamenei to appropriate his authority.

Analyst Note: The fractured Iranian command structure that emerged from the opening strikes has created a genuine principal-agent problem at the heart of US-Iran diplomacy. Mojtaba Khamenei's physical isolation and deliberate avoidance of all electronic communications have severed standard US collection pathways. Assessments of his actual authority now rest entirely on characterizations from those who claim access to him, a sourcing dependency the IC itself flags as potentially manipulated. Senior IRGC commanders and Ghalibaf have absorbed day-to-day operational control, but neither holds the theological standing to bind Tehran to a nuclear agreement, which means any deal reached without confirmed supreme leader authorization carries serious ratification risk. We assess it is genuinely uncertain, within 6 months (by mid-November 2026), that the IC will produce a formal succession assessment resolving who holds binding negotiating authority in Iran. Analytic confidence is low. The entire US intelligence picture as reported flows through anonymous officials cited by a single outlet, no imagery or signals intelligence corroborates the account, and Iranian official statements directly contradict US characterizations without either side providing verifiable evidence.

Sources:

Watch - US IC will produce a formal succession assessment for Iran within 6 months

IC Oversight & Authorities

Declassified FISA Court Opinion Reveals Continuing FBI Section 702 Filtering Violations Extending Across IC

A declassified March 17 FISA Court opinion, released as part of the Wyden-secured deal during the 45-day Section 702 extension, found that filtering tool abuses the DOJ claimed to have fixed in early 2025 are ongoing and extend beyond the FBI across the intelligence community. According to Brennan Center analysis published May 8, the FBI had been using an "advanced filter function" that enabled U.S. person queries of raw Section 702 data without following Reforming Intelligence and Securing America Act (RISAA) procedural requirements, including tracking, recording justifications, or obtaining approvals, and is now using another tool with the same functionality with DOJ approval. The court documented that surveillance targets included a sitting state court judge who had complained to the FBI about alleged civil rights violations by a municipal police chief. The FISC determined that narrowing results to an American's collected communications effectively converts a foreign-target search into a U.S.-person query subject to stricter safeguards, and ordered agencies to reengineer the filtering tools.

Analyst Note: The March opinion's IC-wide scope and the targeting of a sitting state court judge expose DOJ's early-2025 remediation claims as either incomplete or abandoned, sharply raising the stakes entering the reauthorization negotiation in Congress. Whether FISC imposes additional compliance requirements on FBI Section 702 queries before the 45-day extension expires in mid-June 2026 is genuinely uncertain. The court has historically channeled enforcement through negotiated remediation rather than formal directives, and the political pressure from the Wyden disclosure deal cuts both toward and against a binding compliance order. Confidence in this assessment is moderate, grounded in the documented violation record and the court's well-established procedural preferences but constrained by single-source reporting and opacity into FISC's internal deliberations.

Sources:

Watch - FISC will impose additional compliance requirements on FBI Section 702 queries before next reauthorization review

COLLECTION GAPS

UNCLASSIFIED // OPEN SOURCE