//
OFFLINE — VIEWING CACHED CONTENT
← Back to Archive

IC BRIEF

Current as of 1733 EDT (UTC-04), Monday 11 May 2026

Contents

11 stories from 15 sources across 12 organizations


BOTTOM LINE UP FRONT

The IC is adopting AI tools and expanding its technology vendor ecosystem faster than the security frameworks protecting them. We assess the IC will likely face at least one public AI-related security or oversight controversy within six months. Confidence is high, grounded in an exploited AI proxy tool on Cybersecurity and Infrastructure Security Agency (CISA)'s Known Exploited Vulnerabilities (KEV) catalog, contractor vetting failures that enabled destruction of 96 government databases, and no formal IC AI development security standards. An Office of the Director of National Intelligence (ODNI) governance directive would reduce this probability.

State-sponsored cyber operations targeting NATO critical infrastructure will likely produce at least two additional publicly reported incidents within 90 days. Poland's Agencja Bezpieczeństwa Wewnętrznego (Internal Security Agency) (ABW) documented Russian-linked Industrial Control Systems (ICS) breaches at five water treatment facilities, and Iranian influence operations showed a sub-ten-person team achieving billion-view reach within 72 hours through modular architectures that survive platform takedowns.

An additional insider threat or contractor vetting failure will likely surface within six months, reflecting persistent vetting gaps illustrated by the Virginia database destruction case. Congressional surveillance reform will likely fold into broader authorization vehicles before year-end. A decline in state cyber tempo or preemptive ODNI AI governance would undercut these assessments.


IC Technology & Surveillance

NGA Releases Astrea Geospatial Intelligence Platform RFP

The National Geospatial-Intelligence Agency released the Astrea Request for Proposals (RFP) on May 8 through the Acquisition Center of Excellence's Classified Acquisition Research Center, according to SAM.gov. The solicitation covers measurement of surface optical properties and bulk properties of materials, development of models that generate material signatures of interest, and curation of material databases produced by outside organizations. The RFP explicitly excludes software development, software maintenance, and exploitation activities. Questions must reach contracting officers Joseph Cloft and Kelvin Chau by 2:00 p.m. Eastern on May 22, with proposals due by 2:00 p.m. Eastern on June 26.

Analyst Note: The Astrea solicitation positions National Geospatial-Intelligence Agency (NGA) to build a centralized spectral signature library, measuring surface optical and bulk material properties, developing predictive signature models, and ingesting external databases, as foundational data-layer work feeding multi-domain GEOINT collection. The explicit exclusion of software development and exploitation activities separates this effort from downstream analytical tools NGA either already operates or is acquiring elsewhere. That exclusion may instead reflect an existing vehicle already covering those functions, making Astrea a targeted insert into a larger contracted framework rather than a new program's leading edge. NGA is unlikely to award within 12 months, per a single SAM.gov-sourced acquisition notice: proposals close June 26, and classified evaluations of this technical complexity rarely conclude in under six months.

Sources:

White House Formally Adds Offensive Cyberattacks to US Counterterrorism Strategy

The Trump administration on Wednesday released a counterterrorism strategy that formally includes offensive cyber operations among measures used against "those planning to kill Americans or who support those plotting to do so," according to National Security News and Defense One. The strategy expands the designated threat set to include narcotrafficking cartels, transnational gangs, Iranian-backed proxy groups, and "violent left-wing extremists," and proposes Foreign Terrorist Organization designations for certain cartels and gangs to unlock additional intelligence authorities. The document commits to continued cyber operations against Iranian-backed proxy groups but provides no operational detail on the nature of those activities. Both outlets note unresolved legal and policy questions over private-sector involvement in cyber operations and where offense ends and defense begins.

Analyst Note: The operationally consequential provision is the proposed Foreign Terrorist Organization designation for cartels and transnational gangs, unlocking financial, travel, and communications disruption authorities unavailable against purely criminal organizations. The Iran-proxy language names a continuing campaign against a specific adversary class, the document's clearest operational signal. Private-sector boundary ambiguity carries genuine legal exposure for contractors where offensive and defensive toolsets substantially overlap. The doctrinal inclusion may instead serve primarily as deterrence signaling aimed at foreign state actors rather than genuine authority expansion. Per two outlets drawing exclusively from the released text, public acknowledgment of any specific operation under this authority is unlikely within 12 months, consistent with the cross-administration record of asserting offensive cyber posture while withholding operational confirmation.

Sources:

CISA Adds BerriAI LiteLLM Flaw to Known Exploited Vulnerabilities Catalog

CISA added Common Vulnerabilities and Exposures (CVE)-2026-42208, a SQL injection flaw in BerriAI's LiteLLM AI proxy, to its Known Exploited Vulnerabilities catalog on May 8. The vulnerability resides in the proxy's API key verification path and allows unauthenticated remote access to database contents via a crafted Authorization header; Security Affairs and Windows News AI report diverging Common Vulnerability Scoring System (CVSS) scores of 9.3 and 9.8, respectively. Sysdig's Threat Research Team observed the first exploitation attempt 36 hours after public disclosure, describing deliberate schema enumeration targeting virtual API key, stored provider credential, and environment-variable tables, with no confirmed exfiltration or follow-on credential abuse. BerriAI patched the flaw in version 1.83.7 on April 19; sources report conflicting Federal Civilian Executive Branch (FCEB) remediation deadlines of May 11 (Security Affairs) and June 5 (Windows News AI).

Analyst Note: The deliberate schema enumeration Sysdig observed, targeting LiteLLM's credential and key tables 36 hours after disclosure, points to an actor who had mapped the application before the advisory went public, not opportunistic scanning. Halting without confirmed exfiltration does not demonstrate the actor lacked read access; automated tooling completing a pre-programmed phase is equally viable. LiteLLM aggregates credentials for every LLM provider an organization runs, making its KEV listing a meaningful expansion of CISA's tracked federal attack surface. Conflicting remediation deadlines, May 11 versus June 5, with Windows News AI's figures unverifiable against both CISA and Security Affairs, leave genuine compliance ambiguity. Whether at least one FCEB agency is found non-compliant within 90 days is genuinely uncertain at moderate confidence.

Sources:

Exostar Selected for IC NCODE Identity and Access Management Contract

Exostar announced on May 6 that the U.S. Army selected it to participate on the NCODE Indefinite Delivery, Indefinite Quantity (IDIQ) contract, a DoD-funded program through which Defense Industrial Base (DIB) small businesses can procure cybersecurity services from verified external service providers toward National Institute of Standards and Technology (NIST) SP 800-171 and Cybersecurity Maturity Model Certification (CMMC) compliance. ExecutiveBiz reported eight total awardees, naming the other seven as ATX Capital Partners/ATX Defense, Beryllium Infosec, Cytex, David T Scott & Associates, Eccalon, Security Centric, and Summit 7. Exostar cited its CMMC Level 2 accreditation, achieved in December following a Cyber AB audit, and Federal Risk and Authorization Management Program (FedRAMP) Moderate Equivalent authorization among its stated qualifications for participation.

Analyst Note: IDIQ selection places Exostar among eight equally positioned vendors eligible to compete for task orders, not entitled to receive them. The reporting rests almost entirely on Exostar's own press release, with ExecutiveBiz the sole outlet adding independent detail. The program's 2024 pilot launch leaves task-order velocity untested across the full awardee pool, and there is a roughly even chance Exostar receives and begins executing task orders within one year of selection. NCODE may instead function primarily as a commercial credentialing event: Exostar's CMMC Ready Suite targets healthcare and life sciences alongside defense, and the DoD-funded structure, while removing cost friction for small businesses, does not accelerate demand the program has yet to demonstrate.

Sources:

Endurion Launches as New IC-Focused Technology Venture

Quiet Professionals and Spathe Systems announced on May 11 that they are now Endurion, a defense and technology company focused on Special Operations and national security missions, with the launch timed to coincide with Special Operations Forces (SOF) Week 2026. The company, backed by McNally Capital and Nio Advisors, cited two recompete contract wins: an approximately $85 million, five-year United States Special Operations Command (USSOCOM) award and a multi-million dollar bridge contract for United States Southern Command (SOUTHCOM) Enhanced Domain Awareness work, with IDIQ task orders expected in June. Endurion describes its core platform, Pathfinder, as ingesting data from edge devices and external sources and fusing it into a real-time common operating picture.

Analyst Note: The $85M USSOCOM recompete win, surviving open competition as an incumbent, signals demonstrated performance and anchors the consolidation as a credible platform for larger integrated SOF contracts rather than a nominal rebrand. Pathfinder's edge-to-COP fusion architecture directly addresses persistent SOF pain around fragmented Intelligence, Surveillance, and Reconnaissance (ISR) and pattern-of-life data. The already-executing SOUTHCOM bridge contract points toward near-term revenue, though June IDIQ task orders reflect company optimism rather than binding schedule. McNally Capital's involvement makes additional acquisitions or aggressive recompete pursuit likely within 18 to 24 months. Per Endurion's own press release, the sole source with no independent corroboration of contract valuations, the consolidation is equally consistent with a PE valuation play positioning Pathfinder as exit narrative rather than fielded capability.

Sources:

IC Oversight & Authorities

FISA Section 702 Surveillance Reform Hinges on Congressional Definition of Query

A Foreign Intelligence Surveillance Court judge in a March 17 ruling authorized continued Section 702 collection through March 2027 but objected to agency filter tools and ordered re-engineering to comply with rules for queries targeting Americans' information, according to unclassified talking points obtained by The New York Times on April 9. Senators Tom Cotton and Mark Warner, chair and vice chair of the Senate Intelligence Committee, sent a letter to ODNI and the Attorney General requesting expedited declassification of the opinion within 15 days, a commitment secured by Senator Ron Wyden during negotiations over a 45-day extension passed April 30. The ODNI 2025 Annual Statistical Transparency Report disclosed Brady-related U.S. person queries increased tenfold from 113 to 1,083 and unique identifiers collected under the expired Section 215 authority surged 324 percent to exceed 268,000. The Brennan Center for Justice's Elizabeth Goitein told The American Prospect that the filter tools enable analysts to select from pre-filtered lists of persons in communication with foreign intelligence targets, but that the specific mechanisms for identifying U.S. persons within those lists remain unclear.

Analyst Note: Combined with a tenfold increase in Brady-related U.S. person queries and a 324 percent surge in Section 215 identifiers, the Foreign Intelligence Surveillance Court (FISC) filter tool re-engineering order marks the strongest evidentiary foundation for surveillance reform since Snowden, per single-outlet reporting on primary documents. Congress is unlikely to pass standalone query-definition reform before year-end: the April 30 extension through mid-June removed the sunset forcing function, and Reforming Intelligence and Securing America Act (RISAA)'s 2024 codification of FBI protocols signals an institutional preference for bundling reform into broader authorization vehicles. Cotton-Warner's declassification request remains the immediate inflection point, though the filter tool objection may reflect a narrow technical compliance gap rather than fundamental misuse, allowing re-engineering within the existing framework without legislative redefinition.

Sources:

Adversary Intelligence

Cyber Espionage Group Targets Aviation Firms to Steal Map and Navigation Data

Kaspersky Lab reported on April 29 that HeartlessSoul has targeted Russian government agencies and aerospace companies through phishing and malvertising since at least September 2025, a finding corroborated by Positive Technologies and BI.ZONE, which tracks the group as Versatile Werewolf. The campaigns deliver a JavaScript Remote Access Trojan (RAT) through fake aviation software installers, including a fraudulent SourceForge project, exploiting the ZDI-CAN-25373 Windows shortcut vulnerability to conceal malicious commands. The trojan collects GPS tracks, Geographic Information System (GIS) shape files, digital terrain models, and proprietary mapping formats alongside browser credentials and Telegram session data. Kaspersky identified infrastructure overlap with the GOFFEE Advanced Persistent Threat (APT) group; none of the three firms has publicly attributed the campaign to a state sponsor.

Analyst Note: The targeting of GPS tracks, digital terrain models, and proprietary GIS shapefiles points to collection requirements beyond criminal profit, suggesting an actor with sustained operational interest in Russian aerospace and military-adjacent government targets. Infrastructure overlap with GOFFEE, previously linked to pro-Ukrainian operations against Russian defense contractors, is the strongest available attribution signal, corroborated across three Russian-origin vendors (Kaspersky, Positive Technologies, BI.ZONE), though the absence of independent Western tracking limits verification. Formal state attribution is unlikely within six months of public disclosure: Russian firms face structural constraints on naming Ukraine-aligned actors, and infrastructure co-location alone falls short of most public attribution thresholds. Shared or compromised hosting staging a false-flag against GOFFEE would equally explain the observed overlap.

Sources:

Argentina Arrests Russian National Linked to Kremlin Disinformation Network

Argentine federal authorities arrested Dmitrii Novikov, 26, on May 1 at a Lanús residence after he entered Argentina on April 12 from Istanbul as a tourist, according to Argentina's Ministry of National Security. Security Minister Alejandra Monteoliva named Novikov a senior figure in La Compañía, which Argentine officials describe as a Kremlin-linked network also called Project Lakhta, and a federal judge ordered his detention pending deportation with a permanent re-entry ban. A leaked archive published by openDemocracy and Argentina's Filtraleaks in April 2026 showed La Compañía spent at least $283,100 placing more than 250 articles across 23 Argentine outlets between June and October 2024. The Dominican Republic had detained and released Novikov on similar influence-operation charges in September 2025, The Record reported.

Analyst Note: Buenos Aires framed the case as immigration enforcement from the outset: deportation, not prosecution, replicating the template the Dominican Republic applied and abandoned in September 2025. Argentina is unlikely to formally charge or extradite Novikov within the next 90 days. The principal residual risk is a symbolic in-absentia indictment under Law 27.401, which Milei's pro-US alignment could incentivize after removal. The "senior figure" label may instead reflect Argentine incentive to inflate an immigration action into a counterintelligence success, per a single Record report. Novikov's departure will not dismantle the network: the April 2026 archive shows spending wound down after January 2025, local collaborators remain unindicted, and the 2009 visa-free agreement stands.

Sources:

Iranian Information Operations Leverage Modular Influence Architecture

Explosive Media, a Tehran-based animation firm of under 10 employees whose leadership acknowledged the Iranian government as a customer, has released roughly 10 Lego-style videos since hostilities began. A March 10 video watermarked by the Islamic Revolutionary Guard Corps (IRGC)-linked Revayat-e Fath Institute reached tens of millions of views within three days per GINC, with two pro-Iran networks accumulating over a billion X views in the first month per Small Wars Journal. YouTube removed the company's channel on April 12 for spam and deceptive-practices violations, though the videos remain accessible on X. Small Wars Journal reports that US embassies in Bahrain, Indonesia, and Azerbaijan cabled the State Department for more proactive counter-IO, following the April 2025 closure of State's Counter Information Manipulation and Interference Office.

Analyst Note: Iran's modular attribution architecture, IRGC-watermarked state media, affiliated outlets, and an ostensibly independent animation studio, has collapsed IO production economics such that a team of under ten achieves continental reach within seventy-two hours, per Small Wars Journal. The ambiguity absorbs attribution resources and insulates the campaign from node removal; YouTube's April 12 takedown confirmed this: the videos migrated intact to X. Explosive Media may align with IRGC messaging through shared grievance rather than direction, meaning Tehran achieved comparable reach without attributable state links. At least one additional major platform is likely to act within 90 days, while the April 2025 closure of State's counter-IO office has removed the institutional anchor for a coordinated federal response.

Sources:

Allied Intelligence

Polish Intelligence Agency Thwarts Cyberattacks on Water Treatment Plants

Poland's Internal Security Agency (ABW) reported ICS breaches at water treatment stations in Jabłonna Lacka, Szczytno, Małdyty, Tolkmicko, and Sierakowo during 2025, with attackers gaining access to operational controls capable of modifying equipment parameters. SecurityWeek, citing ABW's report, identified weak password policies and direct internet exposure as the primary intrusion vectors. ABW attributed the attacks primarily to hacktivist groups it characterized as personas for foreign governments, and the report specifically named Russian APT groups APT28 and APT29 and Belarusian-linked UNC1151 as operating against Polish targets. The agency also documented supply chain intrusions focused on obtaining contract data, project documentation, and authentication credentials enabling downstream system access.

Analyst Note: ABW's publication of specific municipal names and attack vectors signals deliberate pressure for sector-wide remediation. Attackers reaching ICS-level parameter control at five facilities held physical disruption capability, averted only by timely detection. Parallel supply chain intrusions using stolen credentials and project documentation reveal a campaign architected for persistence, though independent hacktivist actors without state direction remain viable given the vulnerabilities are longstanding and widely known. ABW names APT28, APT29, and UNC1151 as broadly active against Polish targets but stops short of state attribution for these breaches, a distinction with diplomatic and legal weight. Formal attribution within 60 days is unlikely: Warsaw gains solidarity leverage from naming Moscow but faces pressure to protect active counterintelligence work, per secondary outlets without corroboration.

Sources:

Counterintelligence & Tradecraft

Virginia Man Convicted of Destroying Government Databases After Termination

A federal jury on May 8 convicted Sohaib Akhter, 34, of conspiracy to commit computer fraud, password trafficking, and unlawful firearm possession, according to the Department of Justice. Akhter and his twin brother Muneeb were fired on February 18, 2025, from an unnamed Washington, D.C.-based contractor serving more than 45 federal agencies, after the firm discovered Sohaib's prior felony convictions. The DOJ states the brothers immediately accessed protected systems without authorization and deleted approximately 96 government databases, including DHS investigative records and FOIA files. Prosecutors allege, citing court documents reported by BleepingComputer and The Register, that the brothers queried an AI assistant on how to clear system logs after deleting a DHS database and wiped company laptops before returning them; Sohaib faces up to 21 years at sentencing on September 9, 2026, and Muneeb faces up to 45 years.

Analyst Note: The coordinated execution, including write-protecting databases before deletion, querying an AI assistant on log clearing, and wiping employer laptops, reflects preparation that predated the termination meeting, per the DOJ conviction record corroborated through court documents by BleepingComputer and The Register. A contractor serving more than 45 federal agencies failed to detect a 2016 federal computer-crime conviction during rehiring, and DHS investigative files and FOIA records were lost with no public recovery timeline stated. New vetting directives from DHS or ODNI are unlikely within six months, as background-check reform in federal contracting tracks protracted rulemaking cycles that outlast individual incidents. The failure may represent a company-level compliance lapse rather than a structural gap across the contracting ecosystem.

Sources:

COLLECTION GAPS

UNCLASSIFIED // OPEN SOURCE