//
OFFLINE — VIEWING CACHED CONTENT
← Back to Archive

IC BRIEF

Current as of 1352 EDT (UTC-04), Thursday 14 May 2026

Contents

24 stories from 24 sources across 22 organizations


IC Oversight & Authorities

Counterterrorism Czar Blueprint Targets Leftists While Ignoring Far-Right Violence

ProPublica obtained the counterterrorism czar Sebastian Gorka blueprint that prioritizes targeting leftist groups while omitting far-right violence from its threat framework. The document praises Trump and outlines a reoriented counterterrorism strategy that critics say ignores domestic violent extremism data from FBI and DHS assessments.

Sources:

HPSCI Chairman Crawford Blasts IC Analytic Integrity Failures on COVID-19 Origins

House Permanent Select Committee on Intelligence Chairman Crawford issued a statement on May 13 criticizing the Intelligence Community analytic integrity failures around its COVID-19 origins assessments, coinciding with a Senate Homeland Security and Government Affairs Committee hearing on the topic. The statement raises questions about whether IC assessments were shaped by political pressure rather than tradecraft standards, adding to ongoing congressional scrutiny of analytic independence within the IC.

Sources:

Intelligence Assessments Contradict Trump Claims That Iran Military Capabilities Were Devastated

CNN reported on May 14 that a key Trump administration talking point on the Iran war, that Iran military capabilities were devastated in US-Israeli bombing campaigns before the ceasefire, is contradicted by intelligence assessments. Intelligence reports indicate Iran missile capabilities in particular are not as destroyed as the US has publicly claimed, creating a gap between public messaging and classified assessments that complicates ceasefire negotiations and future military planning.

Sources:

State Department Announces Actions Disrupting Iran Overseas Military Procurement Networks

The State Department announced measures in May to disrupt Iran overseas military procurement networks, targeting the supply chains that enabled Iranian acquisition of weapons components, dual-use technology, and intelligence systems during the 2026 conflict. The action complements sanctions against Chinese satellite firms and reflects a broader interagency effort involving IC collection on procurement pathways used by Iran IRGC and military.

Sources:

CIA Removes JFK and MKUltra Document Boxes From DNI Gabbard Office Sparking Raid Allegations and Denial

CIA personnel removed approximately 40 boxes of documents related to the JFK assassination and MKUltra program from the Office of the Director of National Intelligence on May 13, according to CIA whistleblower James Erdman testifying before the Senate Homeland Security Committee. The DNI press secretary denied the offices were raided, while the incident has intensified scrutiny over the Trump administration declassification efforts and CIA handling of historic intelligence records.

Sources:

CIA Whistleblower Testifies Agency Illegally Monitored Investigators and Seized 40 Boxes of JFK MKUltra Files From DNI Office

CIA senior operations officer James Erdman III testified before the Senate Homeland Security Committee on May 13 that the CIA illegally monitored computer and phone usage of investigators working under DNI Gabbard authority and seized 40 boxes of JFK and MKUltra files the DNI had been processing for declassification. House Oversight Task Force chairwoman Anna Paulina Luna issued a 24-hour ultimatum for the CIA to return the documents or face a congressional subpoena, accusing the agency of defying a presidential executive order directing full declassification.

Sources:

FBI Director Patel Seeks $12 Billion Budget While Clashing With Senators Over Misconduct Allegations at Heated Hearing

FBI Director Kash Patel testified before the Senate Appropriations Subcommittee on May 12 requesting $12.53 billion for fiscal year 2027 to fund expanded violent crime enforcement, counterterrorism operations, and drone capabilities. The hearing devolved into heated exchanges when Democratic Senator Van Hollen pressed Patel on reports of excessive drinking on the job and staff finding him unreachable, which Patel called categorically false. The confrontation highlighted ongoing tensions between the bureau and congressional overseers during a period of unprecedented FBI workforce upheaval.

Sources:

Classified Pentagon Intelligence Report Warns China Gaining Strategic Edge From Iran War

A confidential assessment produced by the Joint Staff intelligence directorate for Joint Chiefs Chairman Gen. Dan Caine concludes that China is leveraging the Iran conflict to maximize military, economic, and diplomatic advantages over the United States, including supplying weapons to Persian Gulf allies and providing energy assistance amid the Strait of Hormuz closure. Pentagon spokesman Sean Parnell publicly disputed the findings.

Sources:

Adversary Intelligence

Russian Government Hackers Targeted Spyware Researcher to Hijack Signal Accounts

Suspected Russian government hackers targeted Donncha Ó Cearbhaill, a security researcher who investigates spyware attacks, attempting to hijack his Signal account. Ó Cearbhaill identified himself as one of more than 13,500 targets in a broader campaign exploiting Signal linked devices feature. The codebase and operator interface were in Russian, and victim chats were translated into Russian.

Sources:

Sandworm Shifts From IT Breaches to Targeting Critical OT Infrastructure

Nozomi Networks reported that Russia GRU-linked Sandworm group has shifted tactics from IT network breaches to directly targeting operational technology including HMIs, PLCs, and engineering workstations across manufacturing and transportation sectors. Analysis of 5.5 million alerts from 10 industrial organizations across seven countries identified 29 confirmed Sandworm events between July 2025 and January 2026.

Sources:

Ghostwriter APT Targets Ukrainian Government With Geofenced PDF Phishing and Cobalt Strike

Belarus-linked APT group Ghostwriter (UNC1151/UAC-0057) launched a new campaign targeting Ukrainian government entities using geofenced PDF phishing documents that deploy Cobalt Strike beacons. The campaign uses weaponized documents distributed through phishing emails with Google Drive links.

Sources:

Chinese APTs Expand Targets and Update Backdoors in Recent Campaigns

Multiple Chinese state-sponsored APT groups including FamousSparrow and Twill Typhoon expanded their targeting to include energy firms in Azerbaijan and South Korea while deploying updated backdoor variants. FamousSparrow conducted multi-wave attacks exploiting Microsoft Exchange vulnerabilities against an Azerbaijani oil firm. Seedworm APT also abused signed binaries for DLL sideloading.

Sources:

Bahrain Sentences 24 in IRGC Espionage Cases, Arrests 41 in Spy Network Dismantlement

Bahrain High Criminal Court sentenced 24 people in cases tied to IRGC espionage, with three receiving life sentences. Separately, Bahrain arrested 41 suspects linked to an alleged IRGC network that used high-resolution photographic equipment to capture coordinates of vital locations, which were transmitted to Iran via encrypted software. Five others were arrested for providing sensitive information to the IRGC.

Sources:

US Sanctions Three Chinese Satellite Firms for Providing Iran Geospatial Intelligence During War

The State Department sanctioned three Chinese commercial satellite companies on May 8 for providing Iran with satellite imagery and geospatial intelligence used to monitor and target US and allied military positions during Operation Epic Fury. The sanctioned entities are The Earth Eye (Beijing Mumei Starry Sky Technology), MizarVision (Meentropy Technology), and Chang Guang Satellite Technology. The action targets the satellite intelligence dimension of China-Iran cooperation which also encompasses BeiDou navigation systems, advanced radar networks, and electronic warfare capabilities.

Sources:

US Intelligence Reveals Chinese Firms Plotting Secret Arms Sales to Iran Including MANPADs

US intelligence indicates Chinese companies and Iranian officials have discussed secret arms transfers, plotting to ship weapons through third countries to mask their origins, according to US officials cited in reporting on May 13. The systems Beijing is preparing to transfer include shoulder-fired anti-air missile systems (MANPADs) which posed an asymmetric threat to low-flying US military aircraft during the five-week war. The Chinese Embassy denied providing weapons to any party to the conflict.

Sources:

Counterintelligence & Tradecraft

FBI Offers $200,000 Reward for Former Air Force Intelligence Specialist Who Defected to Iran

The FBI announced on May 14 a $200,000 reward for information leading to the arrest of Monica Elfriede Witt, a former Air Force counterintelligence special agent and linguist who defected to Iran in 2013. Witt, who studied Persian at the Defense Language Institute and served in the Air Force Office of Special Investigations, used fraudulent social media accounts to prepare target packages for Iranian intelligence and revealed the classified true name and activities of a US Intelligence Community operative. The enhanced reward announcement comes during the ongoing Iran conflict.

Sources:

Jury Convicts Lu Jianwang for Running Secret Chinese Police Station in New York Chinatown

A federal jury convicted Lu Jianwang, 64, of acting as an illegal foreign agent of China and obstructing justice by destroying WeChat messages from a Chinese government handler. Prosecutors proved Lu established a secret police outpost in Manhattan Chinatown in 2022 after attending a Chinese Ministry of Public Security event announcing 30 covert police stations worldwide, using the facility to harass and intimidate pro-democracy dissidents. Lu, a U.S. citizen for decades, faces up to 30 years in prison at sentencing.

Sources:

Arcadia California Mayor Pleads Guilty to Acting as Illegal Agent of China and Resigns

Eileen Wang, mayor of Arcadia, California, pleaded guilty to one federal count of acting as an illegal agent of the People Republic of China and resigned her post on May 12. The DOJ charged that from 2020 through 2022, Wang worked with her then-fiancé at the direction of PRC government officials to promote Chinese propaganda in the United States through a website targeting Chinese Americans, carrying a maximum penalty of 10 years in prison.

Sources:

IC Workforce & Reform

Fired Acting FBI Chief Says Patel Tied Job Security to Purging Agents Who Worked Trump Investigations

Former acting FBI Director Brian Driscoll told CNN on May 12 that FBI Director Kash Patel directly tied job security to the removal of agents who worked on criminal investigations related to President Trump. The account reinforces concerns about politicized purges at the bureau, with Deputy AG Todd Blanche previously boasting that every DOJ and FBI employee who worked on Trump criminal probes has been fired, resigned, or taken early retirement. The FBI is now scrambling to rebuild its depleted workforce with eased hiring requirements and accelerated recruitment.

Sources:

Allied Intelligence

Explosive Hearing on Israel Next Spy Chief Exposes Mossad Leadership Dispute

An explosive Knesset hearing on May 13 exposed deep tensions over the succession of Mossad Director David Barnea, with Netanyahu publicly reprimanding Barnea after the spy chief sent a letter opposing the appointment of a proposed successor. The hearing laid bare internal disputes over the future leadership of Israeli intelligence amid the ongoing Iran war, with questions raised about politicization of intelligence appointments and the moral implications of wartime intelligence operations.

Sources:

France Investigates Israeli Firm BlackCore for Election Interference and Disinformation Campaign

French intelligence agencies are investigating whether Israeli firm BlackCore orchestrated a disinformation campaign targeting hard-left France Unbowed candidates ahead of March municipal elections using deceptive websites, social media accounts, and disparaging digital ads. Meta confirmed it removed a network of accounts originating in Israel for coordinated inauthentic behavior primarily targeting France. Google and TikTok independently identified aspects of the operation. Reuters could not verify BlackCore existence in Israeli corporate records.

Sources:

IC Technology & Surveillance

FrostyNeighbor APT Carefully Targets Government Organizations in Poland and Ukraine

A previously unknown APT group dubbed FrostyNeighbor has been targeting government organizations in Poland and Ukraine with precision attacks. The campaign demonstrates careful target selection and operational security consistent with state-sponsored activity.

Sources:

US Space Force Closely Monitoring Iran Including Buried Uranium Sites

The US Space Force is conducting intensive monitoring of Iran including tracking buried uranium enrichment sites, ballistic missile launches, and providing real-time intelligence to deployed forces. Space Command was among the first movers in strikes against Iran, conducting electronic warfare and disabling Iranian communication systems. Trump stated the US would eventually gain access to Iran deeply buried uranium stockpile.

Sources:

US Military and Intelligence Agencies Surge Surveillance Flights Near Cuba Using SIGINT and ISR Platforms

The US Navy and Air Force have conducted at least 25 intelligence-gathering flights near Cuba since February using P-8A Poseidon maritime patrol aircraft, RC-135V Rivet Joint signals intelligence collectors, and MQ-4C Triton high-altitude reconnaissance drones, with flights concentrated near Havana and Santiago de Cuba coming within 40 miles of the coast in a pattern matching pre-conflict surveillance buildups seen before operations in Venezuela and Iran.

Sources:

UNCLASSIFIED // OPEN SOURCE