//
OFFLINE — VIEWING CACHED CONTENT
← Back to Archive

IC BRIEF

Current as of 1635 EDT (UTC-04), Friday 22 May 2026

Contents

9 stories from 38 sources across 30 organizations


KEY JUDGMENTS

Federal constraints on executive-branch AI model oversight and commercial spyware procurement are likely to remain absent through December 31, 2026. High confidence reflects Wednesday's AI executive order withdrawal, in which Sacks, Musk, and Zuckerberg demonstrated a structural tech-adviser veto with no institutional counterweight, and Gabbard's June 30 departure as Director of National Intelligence (DNI), which closes the remaining bureaucratic pathway. Absent a triggering incident such as an attributed model compromise or spyware abuse scandal, no named actor has committed to reviving either framework.

Russia will very likely produce additional publicly disclosed intelligence provocations, including lethal planning or dangerous NATO Intelligence, Surveillance, and Reconnaissance (ISR) intercepts, before November 30. Moderate confidence reflects the consistent tempo of Western disclosures since 2022, with this week's Swedish murder-conspiracy and RAF Rivet Joint incidents confirming sustained Russian risk tolerance across HUMINT and military-aviation lines. A coordinated allied disclosure moratorium around ceasefire diplomacy would suppress this indicator without changing the underlying tempo.

At least one state-sponsored compromise of a cleared U.S. defense or aerospace contractor is very likely to be publicly disclosed by year-end. Iranian Advanced Persistent Threat (APT) Screening Serpens is deploying Endpoint Detection and Response (EDR)-evasive malware against U.S. and allied aerospace targets while Defense Counterintelligence and Security Agency (DCSA) shifts contractor vetting to a five-year self-reported cycle, widening the gap between adversary targeting tempo and verification cadence.


IC Oversight & Authorities

DNI Tulsi Gabbard Resigns Citing Husband Cancer Diagnosis, Fourth Trump Cabinet Exit This Year

BLUF: Whether Trump names a permanent DNI before October 1 is genuinely uncertain, and Lukas inherits live CIA disputes over JFK records, COVID origins, and Havana Syndrome access without confirmed authority.

Gabbard resigned as Director of National Intelligence on Friday, citing her husband Abraham Williams's recent diagnosis with "an extremely rare form of bone cancer" in a formal letter to Trump; the resignation is effective June 30 12. Trump confirmed the departure on Truth Social and named Principal Deputy Director Aaron Lukas as acting DNI 2. Gabbard is the fourth Cabinet official to leave this year, after Trump removed DHS Secretary Kristi Noem in March and Attorney General Pam Bondi in April and Labor Secretary Lori Chavez-DeRemer resigned for the private sector also in April 2. Axios separately reported she had narrowly survived a firing last month after Roger Stone persuaded Trump to hold off 3.

Analyst Note: Lukas assumes acting control of an intelligence apparatus mid-dispute with CIA over JFK records, COVID origins, and Havana Syndrome access. Whether Trump publicly names a permanent DNI nominee before October 1 is genuinely uncertain. Moderate confidence rests on consistent multi-outlet sourcing across divergent political orientations for the resignation's terms, not on visibility into Trump's nomination calculus. Four Cabinet-level departures in five months reflect no discernible succession tempo, and acting designations have repeatedly substituted for confirmed nominees. The health rationale, though consistent across all sourcing, may have provided bilateral cover for a departure Gabbard's politically untenable position made inevitable regardless. Senate Intelligence Committee principals must decide whether to staff for a confirmation process or hold posture; allied services calibrate engagement depth with Office of the Director of National Intelligence (ODNI) leadership on the same timeline.

Sources:

1: Exclusive: Tulsi Gabbard resigns from Trump Cabinet - Fox News

2: Tulsi Gabbard resigning as Trump's intelligence chief - CNBC

3: Tulsi Gabbard resigns as director of national intelligence - Axios

Tulsi Gabbard resigns as director of national intelligence - The Washington Post

DCSA Eliminates Periodic Reinvestigations for Contractors, Shifts to Five-Year Continuous Vetting Questionnaire Cycle

BLUF: Contractor security offices will likely operate under the five-year Personnel Vetting Questionnaire (PVQ) cycle through end of 2027, but unresolved IC reciprocity gaps will continue exposing intelligence-supporting personnel to duplicative vetting submissions.

DCSA announced May 19 the elimination of periodic reinvestigations for National Industrial Security Program contractor national security personnel, replacing them with a uniform five-year Personnel Vetting Questionnaire submission requirement across all clearance eligibility levels 12. The five-year cycle is anchored to the "PVQ Date" recorded in Defense Information System for Security (DISS); organizations are directed to use DISS Subject Reports to identify personnel approaching the deadline and submit documentation to Personnel Security Management Office for Industry (PSMO-I) 12. The guidance supersedes DCSA's August 2022 policy and incorporates DISS Release 14.5 changes 12. DCSA noted that continuous vetting reciprocity across intelligence community agencies remains limited, and contractors may still be required to submit updated questionnaires proactively if enrollment cannot be confirmed in DISS 2.

Analyst Note: The five-year PVQ cycle will likely remain in effect through end of 2027, anchored by Trusted Workforce 2.0 alignment and completed DISS Release 14.5 integration. Confidence is moderate, as the policy rests on a single agency announcement without corroborating reporting. The shift substitutes contractor-self-reported questionnaire data for independently verified background checks, serving adjudicative backlog reduction as much as security modernization. The unresolved IC reciprocity gap leaves contractors supporting intelligence community programs exposed to duplicative submissions until broader cross-agency alignment is achieved. Facility Security Officers at National Industrial Security Program (NISP)-enrolled contractors must build PVQ date monitoring into DISS Subject Report workflows now. A policy reversal before 2028 would require reversion to clearance-level-specific reinvestigation procedures and corresponding staffing plans.

Sources:

1: DCSA updates NISP contractor Continuous Vetting process - Defense Counterintelligence and Security Agency

2: DCSA Revises Continuous Vetting Requirements for Defense Contractors - ExecutiveGov

DIA Assessment to Congress: Ukraine Regained 400 Square Kilometers After Blocking Starlink for Russian Forces

BLUF: Commercial satellite denial now stands as a validated targeting lever with measurable territorial payoff, though Russia's enduring advantage across warfighting functions shows the tool shapes windows rather than the theater balance.

A Pentagon Inspector General Q2 FY2026 assessment, first reported by Bloomberg on May 21, states that the Defense Intelligence Agency and U.S. European Command found Russian military capabilities "temporarily yet significantly degraded" after Ukraine and SpaceX disabled thousands of illicitly operated Starlink terminals in February 123. Ukrainian forces regained approximately 400 square kilometers during the period 345, which Bloomberg described as Kyiv's first territorial gains since 2023 3, though President Zelensky stated that southern operations had begun a month before the Starlink restrictions took effect 5. The assessment also notes that Kremlin-imposed Telegram restrictions compounded communications losses for Russian units that had relied on the platform for battlefield coordination 35. The same report states that as of March, Russia maintained an overall advantage over Ukrainian forces across most warfighting functions 32.

Analyst Note: The Pentagon IG's declassified Q2 FY2026 assessment, Bloomberg sole source and unreplicated, establishes commercial satellite denial as a validated targeting tool with repeatable operational value. Tandem Starlink cutoff and Kremlin-imposed Telegram restrictions degraded Russian command coordination across redundant channels, amplifying combined effect beyond either measure alone. Zelensky's statement that southern operations began a month before the February cutoff complicates attribution: the advance may reflect pre-planned offensive preparation and Russian manpower attrition rather than the communications disruption itself. Russia's sustained overall advantage across warfighting functions as of March confirms the disruption was operationally significant but insufficient to alter the theater balance.

Sources:

1: Special Inspector General Report to the United States Congress — Operation Assessment Report Q2 FY2026 (Jan–Mar 2026) - U.S. Department of Defense / Pentagon Inspector General

2: Ukraine Retook Territory After Hobbling Starlink, Pentagon Says - Bloomberg

3: Ukraine has regained significant territory after blocking Starlink for Russian forces – US intelligence - Ukrainska Pravda

4: Ukraine regains 400 km² after Russian forces lose Starlink access – Bloomberg - Ukrinform

5: US Intelligence Says Ukraine Regained Territory After Russia Lost Starlink Access - Kyiv Post

Special Inspector General Report to the United States Congress — Operation Assessment Report Q2 FY2026 (Jan–Mar 2026) - Lead Inspector General (State OIG / DoD OIG / USAID OIG)

Allied Intelligence

Russian Fighters Made Dangerous Intercepts of RAF RC-135W Rivet Joint SIGINT Aircraft Over Black Sea

BLUF: Russia will almost certainly stage additional dangerous intercepts of NATO reconnaissance aircraft over the Black Sea before November 30, 2026, with the Kh-31 carriage signaling deliberate escalation beyond standard harassment.

The UK Ministry of Defence revealed on May 20 that Russian fighters conducted the most dangerous intercepts of an RAF Rivet Joint since 2022, targeting the unarmed RC-135W operated by 51 Squadron from RAF Waddington in international airspace over the Black Sea in April 123. In the first intercept, a Russian Su-35 flew close enough to trigger the Rivet Joint's emergency systems and disable its autopilot; in the second, an Su-27 made six passes within six meters of the aircraft's nose 123. The Aviationist noted the Su-35 involved, serial RF-81718, was carrying a Kh-31PM anti-radiation missile alongside its air-to-air payload, a weapon designed to home on radar and electronic emitters, a particularly notable armament given the SIGINT nature of the intercepted aircraft 4. UK Defence Secretary John Healey condemned the actions as "dangerous and unacceptable," and MoD and Foreign Commonwealth and Development Office officials formally démarched the Russian Embassy in London 12.

Analyst Note: Russia will almost certainly conduct additional dangerous intercepts of NATO reconnaissance aircraft over the Black Sea before November 30, 2026. Moscow has shown no threshold at which formal protests change its calculus, and the Kh-31PM anti-radiation missile carried by the intercepting Su-35, confirmed by The Aviationist from imagery analysis, signals deliberate escalatory intent beyond standard intercept doctrine. The intercepts may instead reflect squadron-level pilot discretion rather than centrally directed Kremlin escalation, consistent with 2022 precedent in which aircrew acted without clear authorization. Analytic confidence is low, resting on episodic public disclosure rather than systematic collection. If the pattern holds, NATO air planners face a structural decision on whether permanent fighter escorts for Black Sea RC-135 sorties become standing policy rather than discretionary protection.

Sources:

1: Russian fighter jets intercept RAF reconnaissance aircraft within metres over Black Sea - Forces News

2: UK condemns Moscow for 'dangerous and unacceptable' intercept of RAF Rivet Joint - FlightGlobal

3: U.K. spy plane 'dangerously intercepted' by Russian military jets over Black Sea, defense ministry says - CBS News

4: Russian Fighters Made More Dangerous Intercepts of a Royal Air Force RC-135 over the Black Sea - The Aviationist

RAF aircraft dangerously intercepted by Russian jets over Black Sea - UK Ministry of Defence (GOV.UK)

Netanyahu Accused of Appointing Loyalists to Lead Shin Bet and Mossad Amid Former Officials Backlash

BLUF: Gofman is likely to take Mossad command by August 31, and his pairing with Zini at Shin Bet hands Netanyahu loyalist control over both services as judicial and institutional checks collapse.

Netanyahu replaced the Shin Bet chief he fired for refusing to intervene in his corruption trial with Major General David Zini; NPR reports the new chief complied with the same request, and a court challenge by over a hundred former officials failed 1. He also named military adviser Roman Gofman as Mossad chief; Gofman's nomination is before Israel's Supreme Court over allegations he ran a teenage Israeli as a covert source and concealed it while Israeli authorities held him on espionage charges for more than a year 12. Three Supreme Court justices signaled Tuesday they will not intervene, citing insufficient evidence of direct knowledge, and outgoing Mossad chief David Barnea publicly opposed the appointment 2. NPR also reports that under Zini the Shin Bet reversed its decades-long opposition to the death penalty for Palestinians convicted of terrorism 1.

Analyst Note: Three Supreme Court justices declined Tuesday to intervene, citing insufficient evidence of direct responsibility, and with the vetting committee and IDF Chief Zamir both endorsing Gofman, all plausible legal pathways to block the appointment are now closed. Gofman is likely to formally assume Mossad command by August 31. High confidence rests on the court's unambiguous posture and the absence of any remaining institutional veto over Netanyahu's appointment authority, though both primary accounts were published the same day without access to closed judicial deliberations. Gofman's outsider military standing may enable a more aggressive post-October 7 organizational overhaul than a career insider constrained by institutional culture would undertake. Allied services must now decide whether the Elmakayes precedent warrants revising intelligence-sharing protocols to account for source protection standards.

Sources:

1: Netanyahu is accused of appointing loyalists to lead Israeli intelligences agencies - NPR

2: How Netanyahu's battle with legal system may shape future of Mossad, Shin Bet, IDF - analysis - The Jerusalem Post

IC Technology & Surveillance

Trump Pulls AI Oversight Executive Order After Tech Allies Object to Intelligence Community Role in Model Evaluation

BLUF: Withdrawal under tech-adviser pressure makes a federal pre-release AI evaluation framework unlikely to take effect by year-end 2026, leaving advanced model security review without a viable political sponsor.

Trump told reporters on Thursday he "didn't like certain aspects" of the order and did not want it to "get in the way" of the U.S. lead over China in AI. 12 Axios, citing sources, reported that AI adviser David Sacks, Meta CEO Mark Zuckerberg, and xAI CEO Elon Musk spoke with Trump between Wednesday night and Thursday morning, with Sacks described as having "hated" the order. 3 The draft would have established a voluntary 90-day pre-release government review of advanced AI models and a Treasury-led cybersecurity clearinghouse, CNN and Fast Company reported. 42 A tech industry source told Axios the primary objection was Treasury's lead role in identifying AI security vulnerabilities, a function typically held by Cybersecurity and Infrastructure Security Agency (CISA) and National Institute of Standards and Technology (NIST). 3

Analyst Note: A pre-release review framework for advanced AI models is unlikely to take effect by year-end 2026. The withdrawal exposes a durable structural constraint: tech executives adjacent to Trump can neutralize oversight proposals before signature. Objections over Treasury's lead role, the 90-day review window, and allied-nation model-sharing remain unresolved, and no successor architecture has been proposed. Moderate confidence rests on alignment between Trump's anti-regulatory posture and coordinated intervention by his closest tech advisers, removing political preconditions for any federal AI security review to advance. Sourcing is narrow: Axios holds the only named behind-the-scenes detail; other outlets add no independent sourcing, limiting confidence in internal deliberations. The cancellation may instead reflect commercial competition, with rival executives using Treasury's jurisdictional misfit as pretext to block competitors from gaining intelligence about unreleased models. Frontier AI labs can treat current voluntary NIST arrangements as the operational ceiling unless an order materializes before year-end.

Sources:

1: Trump postpones AI executive order signing: 'I didn't like certain aspects' - CNBC

2: Trump cancels AI executive order over concerns of slowing U.S. tech innovation - Fast Company

3: Why Trump AI executive order was pulled - Axios

4: White House postpones executive order on AI - CNN Business

Trump postpones AI executive order signing: 'I didn't like certain aspects' - CNBC

Trump delays executive order on AI oversight hours before planned signing - The Washington Post

Trump Administration Rolls Back Spyware Restrictions as ICE Acknowledges Surveillance Tool Use

BLUF: Meaningful checks on executive spyware procurement are very unlikely before the end of 2026, leaving accountability to erode as contracting channels grow more opaque and Biden-era guardrails fall.

ICE's acting Director Todd Lyons confirmed in an April 1 letter to Congress that he approved Homeland Security Investigations to use commercial spyware against foreign terrorist organizations and fentanyl traffickers, without naming the specific tool. 12 The Trump administration reinstated ICE's $2 million Paragon Solutions contract last August after Biden's stop-work order; procurement records show it closed out on January 20. 12 DHS told NPR that ICE has "no relationship" with Paragon or the company that acquired it, while declining to confirm whether agents retain access to Paragon-developed tools. 2 Treasury removed three Intellexa-affiliated executives from a Biden-era sanctions list in December, as The Register and NPR reported; one was subsequently convicted in Greece in February in connection with Predator abuses. 312

Analyst Note: A federal court injunction or congressional legislation curtailing executive spyware procurement is very unlikely by December 31, 2026. We have high confidence in this judgment, grounded in formal executive acknowledgment of spyware use, three documented procurement and sanctions reversals of Biden-era policy, and the absence of any forming congressional coalition. NPR and The Register, reporting from independent access points, corroborate those executive actions. The January 20 contract closure may represent a genuine operational wind-down, with Homeland Security Investigations (HSI) conducting operations under a separate legal authority never routed through the Paragon contract, a reading that, if correct, makes the procurement record less useful as an accountability ledger. Opacity in contracting channels will make future accountability progressively harder to establish, and privacy organizations allocating legal resources between FOIA litigation and judicial injunction campaigns face substantially lower expected returns on the injunction track through year-end.

Sources:

1: What we know about how the U.S. government uses spyware (and what we dont) - KPBS

2: What we know about how the U.S. government uses spyware (and what we don't) - NPR

3: Trump admin lifts sanctions on Predator-linked spyware execs - The Register

Counterintelligence & Tradecraft

Swedish Ex-Military Spy Suspect Now Also Investigated for Conspiracy to Commit Murder in Moscow

BLUF: Whether Swedish prosecutors formalize the murder conspiracy charge before November 22, 2026 remains genuinely uncertain, but Moscow's apparent fusion of lethal tasking with an active espionage line should force allied services to revise assumptions about Russian thresholds for wet work on Western soil.

Swedish prosecutors have added a conspiracy-to-murder charge against a 34-year-old former armed forces employee already detained since January 2026 on espionage suspicion, according to Expressen reporting cited across Swedish media. 123 The alleged plot targeted a person in Sweden and was "partly planned in Moscow," prosecutor Mats Ljungqvist told Swedish Radio's Ekot, with court documents placing the offense in Moscow in December 2025. 32 At a Friday remand hearing, prosecutors simultaneously upgraded the existing espionage suspicion from ordinary grade to attempt, and the court remanded the suspect on the new count as well. 43 The suspect denies all charges; Ljungqvist declined to elaborate on the circumstances that produced the new suspicion, citing "a very sensitive stage of the investigation." 12

Analyst Note: The December 2025 Moscow placement points to active handler contact in the weeks before the January arrest. Moscow's apparent integration of assassination planning with an ongoing collection operation marks a qualitative escalation beyond prior Nordic recruitment cases. Formalization of the murder conspiracy charge before November 22, 2026 is genuinely uncertain. Moderate confidence rests on the opacity of Swedish security proceedings and the absence of public indicators that prosecutors are ready to advance from investigative detention to formal indictment. Coverage converges across two primary Swedish broadcast outlets, yielding a structurally thin evidentiary picture. The conspiracy suspicion may instead primarily serve prosecutors' interest in securing extended detention and cooperation leverage rather than reflecting a confirmed Russian assassination mandate. If the escalation holds, allied counterintelligence services face pressure to reclassify Russian Nordic assets from collectors to potential kill-chain nodes, a categorization shift that drives both operational priorities and asset-protection resource allocation.

Sources:

1: Suspected Swedish spy now also investigated for conspiracy to murder in Moscow - Daily Northern

2: Misstänkt spion utreds för stämpling till mord i Moskva - SVT Nyheter

3: Spionmisstänkt planerade mord från Moskva - TV4

4: Eskilstunabo häktas för stämpling till mord i Moskva - Eskilstuna-Kuriren

Adversary Intelligence

Unit 42 Exposes Iranian APT Screening Serpens Targeting US and Allied Aerospace and Defense Sectors With New Malware

BLUF: Screening Serpens' AppDomainManager hijacking blinds standard EDR to .NET execution, leaving US and allied aerospace and defense networks exposed unless defenders augment detection beyond Event Tracing for Windows (ETW)-dependent telemetry.

Palo Alto Networks Unit 42 on May 22 identified six new Remote Access Trojan (RAT) variants in two families, MiniUpdate and MiniJunk V2, deployed by Iranian APT Screening Serpens against targets in the U.S., Israel, UAE, and at least two additional Middle Eastern entities between February and April 2026 12. Both families used tailored spear-phishing lures, with the U.S. campaign impersonating a global air carrier's job portal and the Israeli campaign spoofing a video conferencing installer 1. Unit 42 reported that MiniUpdate variants employed AppDomainManager hijacking to disable Event Tracing for Windows and bypass assembly signature validation, stripping the telemetry endpoint detection tools rely on to monitor .NET execution 1. Cybersecurity Dive noted that the February MiniJunk V2 campaign against a Middle Eastern IT professional involved reconnaissance from late 2025, with attackers exploiting the target's job-search activity to craft the lure 2.

Analyst Note: AppDomainManager hijacking operates at the Common Language Runtime (CLR) configuration layer, stripping the ETW telemetry that endpoint tools require to flag malicious assembly loading. Aerospace and defense organizations across U.S. and partner networks must treat standard .NET monitoring as insufficient against this actor. Six malware variants across two families emerged in roughly ten weeks, with per-target Command and Control (C2) rotated across Azure-hosted domains and late-2025 reconnaissance confirming multi-month target preparation predating the regional conflict. Drawn entirely from Unit 42's primary technical report, with Cybersecurity Dive adding no independent collection, the affected-nation framing rests on VirusTotal metadata that cannot exclude researcher sandboxing or honeypot uploads.

Sources:

1: Tracking Iranian APT Screening Serpens 2026 Espionage Campaigns - Palo Alto Unit 42

2: Iran-linked hackers target key US, allied sectors with sophisticated spear-phishing messages - Cybersecurity Dive

COLLECTION GAPS

UNCLASSIFIED // OPEN SOURCE