← Back to Archive
IC BRIEF
Current as of 0526 EDT (UTC-04), Sunday 24 May 2026
Contents
8 stories from 31 sources across 24 organizations
KEY JUDGMENTS
The US intelligence community's formal governance authority is likely to remain diminished through mid-2026, with neither a confirmed Director of National Intelligence (DNI) nor Cybersecurity and Infrastructure Security Agency (CISA)-independence legislation expected before the August recess, and no mandatory AI security evaluation regime expected before year-end. Moderate confidence rests on three anchors: no DNI nomination signal, the ranking Democrat's public opposition to the CISA bill, and Trump's characterization of the shelved AI executive order as a competitive blocker. Whether the IC releases a public product addressing the March 2025 Iran nuclear assessment by year-end is genuinely uncertain, absent a congressional forcing mechanism.
Adversary intelligence exposure will very likely continue at elevated tempo, with at least two additional publicly reported arrests or indictments of Federal Security Service (Russia) (FSB)- or Islamic Revolutionary Guard Corps (IRGC)-directed operatives in NATO states or Ukraine expected by late September, anchored by a five-year pattern of 8-12 annual disclosures. High confidence reflects convergent prosecution activity across multiple jurisdictions this month. A formal DNI nomination or a galvanizing AI-enabled cyber incident would alter the governance assessment.
IC Technology & Cyber
DHS Denies ICE Has Relationship With Spyware Maker Paragon Despite Prior Confirmation of Commercial Spyware Use
BLUF: Narrow "no relationship" phrasing leaves routed access through REDLattice or AE Industrial Partners plausible, and credible confirmation that ICE retained Graphite-equivalent capability is unlikely by late May 2027.
Department of Homeland Security (DHS) told NPR on May 22 that 'ICE has no relationship with Paragon Solutions, Inc. or with the company that acquired them,' with federal procurement records confirming the contract closed out on January 20 12. In an April 1 letter to Democratic lawmakers led by Rep. Summer Lee (D-Pa.), departing ICE acting Director Todd Lyons acknowledged approving Homeland Security Investigations (HSI)'s procurement and operational use of a commercial spyware tool against foreign terrorist organizations and fentanyl traffickers, and certified that use complied with a 2023 executive order governing government spyware use 12. DHS declined to confirm whether ICE retains access to Paragon-developed tools through a third party and declined to identify any alternative spyware vendor in use 12.
Analyst Note: DHS's "no relationship" framing is legally narrow enough to exclude routed access through REDLattice or AE Industrial Partners without generating any observable procurement indicator. The formal contract closure does not resolve that accountability gap. Lyons' April 1 acknowledgment of active deployment makes the bounded denial more telling, not less. DHS's refusal to name any successor vendor compounds it. Credible confirmation of retained functional access after contract close is unlikely by late May 2027. Confidence is low, with sourcing limited to single-source NPR reporting: post-contract tool routing depends on internal DHS decisions not visible through public reporting or procurement records. The closure may instead reflect a genuine policy exit under reputational pressure from the Italian Graphite scandal. Congressional oversight staff and FOIA litigants at Just Futures Law should shift from procurement-record requests toward indicators of third-party routing.
Sources:
1: DHS says ICE has no relationship with spyware maker Paragon Solutions - NPR
2: DHS says ICE has 'no relationship' with spyware maker Paragon Solutions - NPR
CISA Opens Known Exploited Vulnerabilities Catalog to Community Nomination for Faster Threat Sharing
BLUF: Opening community nominations widens Known Exploited Vulnerabilities (KEV)'s input aperture but shifts the burden to CISA's unproven validation capacity, where adjudication discipline, not submission volume, will determine whether the catalog gains or loses signal value.
On May 21, CISA announced a new online nomination form through which researchers, vendors, and industry partners can submit vulnerabilities for possible KEV catalog inclusion 12. Acting Executive Assistant Director for Cybersecurity Chris Butera said the form "enhances CISA's ability to identify, validate, and quickly share critical threat information," with email submissions to [email protected] remaining available alongside it 1. Nominations must still satisfy CISA's existing criteria: an assigned Common Vulnerabilities and Exposures (CVE), confirmed exploitation evidence, and available remediation guidance 23. The Record cited former CISA CIO Robert Costello describing the form as operationalizing the agency's research community partnership, while Qualys analyst Mayuresh Dani noted that prior email submissions left no public record of how many KEV additions they generated 4.
Analyst Note: The structured form addresses a real discoverability gap, but the sourcing weight is thin: two duplicate CISA press releases amplified without independent reporting. Time-to-exploit has compressed to roughly five days, the pressure directly justifying an open submission pipeline. Federal agencies and private-sector teams prioritizing remediation against KEV additions will face a faster, noisier signal as community nominations enter the validation queue. CISA has not publicly committed to the adjudication capacity needed to manage that load. Community nominations at scale, compounded by the deliberate manipulation a structured public form invites, risk converting the KEV from a leading indicator into a lagging one.
Sources:
1: CISA Enhances Known Exploited Vulnerabilities Catalog to Include New Nomination Form
2: CISA new KEV nomination form opens reporting to vendors and researchers - Help Net Security
3: You can now nominate vulnerabilities for CISA's KEV with this form - SC Media
4: CISA to allow researchers to report vulnerabilities to exploited bugs catalog - The Record by Recorded Future
IC Oversight & Authorities
CNN Investigation Reveals DNI Gabbard Was Routinely Sidelined on Iran and Venezuela While Pursuing Deep State Grievances
BLUF: Gabbard's exit ratifies a CIA-centric national security architecture that has already hollowed out the DNI's coordinating role, and absent structural repair the next director inherits the title without the function.
A CNN investigation, published a day after Gabbard announced her resignation as DNI citing her husband's diagnosis of a rare bone cancer, found that she was routinely excluded from Trump's Iran and Venezuela deliberations, reportedly vacationing in Hawaii and posting beach photos when the New Year's Day Venezuela operation unfolded at Mar-a-Lago, and kept in Washington during the February joint US-Israeli strikes on Iran while Trump conferred with CIA Director Ratcliffe, Defense Secretary Hegseth, and Joint Chiefs Chairman Caine 123. Her March 2025 congressional assessment that Iran was not pursuing a nuclear weapon drew a public rebuke from Trump, who called her "wrong" days before launching strikes on Iran's nuclear sites in June 2025, CNN reported 12. CNN also reported she redirected her tenure toward Trump's domestic political grievances, declassifying Russia probe documents, revoking clearances of at least 37 current and former national security officials, and attending the FBI's Fulton County ballot seizure in January, which former senior intelligence officials and election law experts told CNN fell outside her legal authority 123.
Analyst Note: Gabbard's departure, documented in a single CNN investigation without independent corroboration, leaves the DNI's statutory coordinating role structurally degraded while the US manages active military postures against both Iran and Venezuela. Ratcliffe's direct channel to the president, bypassing Gabbard across 18 months of key deliberations, has normalized a CIA-centric architecture that subordinates IC formal coordination. Her physical attendance at a domestic law enforcement search and revocation of clearances for more than three dozen officials further compressed the post-Watergate boundary between foreign intelligence and domestic law enforcement. The domestic assignments may instead reflect work she actively sought on the president's behalf rather than White House exclusion. The successor's capacity to restore IC authority turns on whether that CIA-to-president channel is restructured.
Sources:
1: Sidelined on Iran and Venezuela, Gabbard instead pursued Trumps Deep State grievances amid her own suspicions - CNN
2: Sidelined on Iran and Venezuela, Gabbard instead pursued Trump's Deep State grievances amid her own suspicions - KVIA ABC-7
3: Sidelined on Iran and Venezuela, Gabbard instead pursued Trump's Deep State grievances amid her own suspicions - ABC17 News
Sidelined on Iran and Venezuela, Gabbard instead pursued Trump's Deep State grievances amid her own suspicions - CNN
Rep Thompson Opposes Making CISA Independent from DHS Despite Ramirez Legislation Push
BLUF: Ramirez's standalone-CISA bill is very unlikely to become law before the 119th Congress ends, as Thompson's opposition strips the minority of the unified Democratic backing any cross-aisle push would demand.
Rep. Delia Ramirez (D-IL), selected on April 28 as the top cyber Democrat on the House Homeland Security Committee 1, is drafting legislation to make CISA a standalone agency outside DHS, a Ramirez spokesperson told Inside Cybersecurity 2. The spokesperson said Ramirez believes cybersecurity, like FEMA, needs its own agency structure to avoid politicization 2. House Homeland Security ranking member Bennie Thompson (D-MS) told Inside Cybersecurity he opposes the move, stating he does not support "dismantling DHS and removing CISA from the Department" even while acknowledging ICE and CBP have been "weaponized" under the Trump administration 1.
Analyst Note: Legislation making CISA a standalone agency outside DHS is very unlikely to pass Congress and be signed into law by the end of the 119th Congress. Thompson's opposition, as ranking Democrat on the originating committee, denies Ramirez the unified minority footing that cross-aisle coalition-building requires. Republican committee leadership has shown no interest in DHS restructuring, and minority-only bills without Senate companion activity rarely reach a floor vote. Moderate confidence rests on direct-quote sourcing from both principals, though the assessment carries no visibility into Republican positioning or Senate-side appetite. Thompson's resistance may reflect a tactical preference to preserve DHS's structural integrity as counter-narrative to the Trump administration rather than a judgment about CISA's operational fit within the department. CISA leadership and congressional appropriators must decide whether to plan for a structural transition or continue budgeting under DHS's umbrella through the 119th Congress.
Sources:
1: Rep. Thompson pushes back on potential legislation to make CISA independent from DHS - Inside Cybersecurity
2: Rep. Ramirez considers legislation making CISA independent from DHS, amid call to revamp department activities - Inside Cybersecurity
Adversary Intelligence
Germany Charges Two in IRGC Quds Force-Directed Plot to Attack Jewish Leaders
BLUF: Whether Hamburg secures Ali S.'s conviction on any charge before end of 2027 is genuinely uncertain, leaving Berlin without near-term legal grounds to escalate coercive measures against Tehran.
German federal prosecutors charged Danish national Ali S. and Afghan national Tawab M. this month at Hamburg's state court with attempted murder; Ali S. also faces a foreign intelligence agent charge 12. Prosecutors allege Ali S. worked for Iran's Quds Force and in early 2025 gathered intelligence on Josef Schuster of the Central Council of Jews and Volker Beck of the German-Israeli Society 1. Tawab M. allegedly offered to procure a weapon for an attack on the named targets after contacting Ali S. in mid-2025 1. Both were arrested in Denmark, Ali S. in June 2025 and Tawab M. in November 2025; Germany summoned Iran's ambassador after Ali S.'s arrest, and Tehran called the allegations "unfounded and dangerous" 1.
Analyst Note: Ali S.'s conviction on at least one Hamburg charge before end of 2027 is genuinely uncertain, leaving Berlin's diplomatic leverage over Tehran legally unresolved in the near term. Independently corroborated by Haaretz and European Conservative, a conviction on the intelligence agent count would establish Hamburg as a landmark EU venue for prosecuting IRGC-directed operations, extending a week in which adversary networks were exposed across two jurisdictions. The Quds Force's reliance on cutouts constrains the prosecutorial record on direct command, and Iran's fabricated-charges framing retains some purchase if Ali S. cultivated Quds contacts opportunistically rather than under direct tasking. Moderate confidence reflects the formal indictment as an observable anchor, limited by absent public evidentiary detail on the intelligence agent charge specifically. A conviction gives European governments a judicial predicate for escalating sanctions pressure on Iran's apparatus; acquittal forecloses that leverage before it is exercised.
Sources:
1: Iranian-Linked Spy Ring Accused of Plotting Violence Against Jews in Germany - European Conservative
2: Germany Indicts Suspects in Iran-linked Plot to Target Jewish Leaders - Haaretz
SBU Arrests FSB Sleeper Agent Dormant for 12 Years Who Built Informant Network Targeting Ukrainian Officials
BLUF: Activation of a 2014-vintage sleeper to target a civilian emergency-management principal signals FSB is broadening strike-support collection beyond military leadership, requiring expanded protective coverage across Ukraine's senior civilian cadre.
Ukraine's Security Service of Ukraine (SBU) announced on May 22 that officers detained an IT specialist from Mykolaiv whom Russian intelligence had recruited in 2014, held dormant for 12 years, and activated earlier this year to operate in Kyiv 123. Since February, the SBU reported, he had been gathering missile strike coordinates targeting the Kyiv residence of Ukraine's State Emergency Service chief and tracking addresses and movement routes of senior politicians and defense officials 243. Operating under cover as a computer systems administrator, he recruited an Odesa-based IT colleague, and together they built an informant network collecting data on Ukrainian troop deployments 124. Officers simultaneously detained both, seizing smartphones as evidence; both face treason charges under martial law carrying life imprisonment and property confiscation 13.
Analyst Note: The Mykolaiv-to-Kyiv operational pattern indicates FSB is repositioning 2014-era sleeper assets from southern Ukraine into the capital rather than cultivating locally resident sources. Targeting the State Emergency Service chief's residence extends Russian strike priority beyond military commanders into civilian emergency management leadership, requiring immediate adjustment to protective coverage for that sector. Simultaneous detention of both principals suggests SBU achieved network-wide surveillance before acting, though the breadth of undetected nodes cannot be assessed. That uncertainty is compounded by the SBU's own press statement being the sole primary source, leaving the claimed network scope corroborated only by the arresting agency.
Sources:
1: SBU arrests Russian FSB agent preparing strikes on Kyiv - New Voice of Ukraine
2: A deep-cover FSB agent who was kept on "standby" for 12 years has been detained in Kyiv - Ukrainian News Agency (UNN)
3: SSU exposes FSB agent network that adjusted russian strikes in Kyiv and Odesa Regions - Ukrainian News (Ukranews)
4: IT agents who spied for the FSB were detained in Kyiv and Odessa - Dev.ua
SBU: FSB agent kept on standby for 12 years detained in Kyiv for preparing missile strike coordinates - Security Service of Ukraine (SBU) official Telegram channel (@SBUkr)
IC Workforce & Policy
Trump Shelves Biden AI Executive Order, Expanding NSA Role in AI Security
BLUF: Shelving the order unlikely to be reversed within six months strips NSA of classified evaluation authority over frontier models and leaves critical infrastructure defenders without the planned Treasury information-sharing channel.
Trump halted the planned signing of an AI cybersecurity executive order on May 22, telling Oval Office reporters he pulled it because "I didn't like certain aspects of it" and worried it "could have been a blocker" to America's AI lead over China 123. The draft, per CyberScoop and NBC News, would have established a voluntary 90-day federal testing regime for frontier AI models, assigned the NSA to conduct classified evaluations, and directed Treasury to set up information-sharing between AI companies and critical infrastructure cybersecurity defenders 12. Several tech CEOs invited on short notice could not attend the scheduled signing, NBC News reported, citing two people familiar with the matter 2.
Analyst Note: Trump's on-record rejection, framing the order as a competitive blocker against China, converts an imminent signing, per corroborating coverage across four primary outlets, into a named political obstacle, making a substantially equivalent order unlikely within six months. That judgment carries moderate confidence: the public statement imposes a visible political cost on near-term reversal, though the administration has demonstrated capacity for rapid policy repivot. Without a signed order, critical infrastructure defenders lose the Treasury information-sharing channel and the IC forfeits the NSA's classified evaluation authority. Any substitute order must rebrand government access as non-oversight to survive internal review, likely stripping the NSA's formal role. The last-minute CEO attendance failures leave open a scheduling explanation distinct from durable policy reversal. Agencies should treat CAISI's informal arrangements as the operative baseline and not plan around a mandated evaluation channel materializing in 2026.
Sources:
1: Trump postpones executive order focused on AI security - CyberScoop
2: Trump abruptly scraps signing of landmark executive order regulating AI - NBC News
3: Trump calls off plan to sign artificial intelligence order due to concern it could hurt the industry - The Washington Post
White House Postpones AI Cybersecurity Order Signing by Trump - Bloomberg
Trump shelves Biden AI executive order, expanding NSA role - Axios
Allied Intelligence
Former MI6 Chief Moore Says British Intelligence Using AI to Identify Potential Russian Defectors
BLUF: Moore's disclosure hands the FSB a targeting template for its own defensive screening, and his admission that recruits now sit outside Russia exposes the AI effort as compensation for lost access rather than expanded reach.
Sir Richard Moore, former MI6 chief, made the AI/defector recruitment claim at a WSJ Events appearance, not at the SCSP AI+Intelligence conference as the summary implies
1. The HUMINT Substack by Sasha Ingber is an independent primary account of Moore's April 9 SCSP fireside chat, where he discussed AI through a 'three Ts' (targeting, tool, threat) framework and raised concerns about international AI norms in warfare, but contains no mention of using AI to identify Russian recruits
2. The AI/defectors quote traces through a single chain of Russian media intermediaries (PolitNavigator → en.topwar.ru → Pravda UK) reporting on the WSJ Events appearance
1. The Banking News characterization of AI systems aggregating 'behavioral data, personal contacts, financial records, and digital footprints' to generate recruit dossiers is unverified embellishment absent from any primary source
3.
Analyst Note: Moore's acknowledgment that MI6 deploys AI to profile and target potential Russian recruits hands Moscow's counterintelligence an actionable warning. Individuals whose digital behavior, financial patterns, and social contacts match Western recruitment profiles now face scrutiny for characteristics they may not know are being analyzed. That the system targets Russians who have largely relocated West signals a degraded collection environment inside Russia, not a robust one. The AI/defectors framing traces through Russian media intermediaries, with Ingber's direct Substack account of the April SCSP fireside chat as the sole primary source and Banking News's AI-generated dossier characterization as editorial extrapolation. Moore may have been performing capability for a favorable industry audience rather than disclosing operational reality.
Sources:
1: My conversation with former MI6 Chief Sir Richard Moore on AI, adversaries, and alliances - HUMINT (Sasha Ingber / Substack)
2: Former MI6 chief: Britain is using AI to find potential traitors in Russia - Pravda UK
3: Terrifying disclosure by MI6: British intelligence recruits secret agents in Russia using artificial intelligence - Banking News (Greece)
COLLECTION GAPS
- Congressional progress on FY2027 intelligence authorization or appropriations bills, including IC-specific committee markup activity.
- IC Inspector General investigations or findings, particularly DOJ IG FISA reviews and ODNI IG assessments during the DNI leadership transition.
- Chinese state-sponsored cyber operations targeting US critical infrastructure or IC networks, including MSS-directed campaigns exposed by allied services.
- IC workforce metrics during the DNI vacancy, including clearance processing backlogs, attrition rates at major agencies, and the status of hiring freezes.