← Back to Archive
IC BRIEF
Current as of 1654 EDT (UTC-04), Tuesday 26 May 2026
Contents
9 stories from 44 sources across 33 organizations
KEY JUDGMENTS
Concurrent leadership vacancies at Cybersecurity and Infrastructure Security Agency (CISA) and Office of the Director of National Intelligence (ODNI) are likely to persist through October 1, leaving threat briefings dependent on acting officials excluded from White House AI discussions as AI-generated exploits reach operational maturity. At least one additional public attribution of an Iran-state cyber operation is very likely within 90 days. High confidence rests on a documented quarterly pace exceeding five Iran-attributed disclosures since 2023 and freshly exposed staging infrastructure. US sanctions on Ministry of Intelligence and Security (Iran) (MOIS) cyber actors will likely be withheld in the same period, absent collapse of the nuclear track.
Israel will likely not conduct a strike inside central Beirut in the next 90 days. Washington's geographic restriction, tied to the nuclear track likely to remain active through August 24, provides the operative constraint. Moderate confidence reflects the restriction's durability against two failed Qassem assassination attempts, though talks collapse or a kill opportunity would force recalculation on the Beirut prohibition and sanctions posture.
Iran will very likely exceed 10 additional national-security executions in the next 90 days, sustaining the domestic security posture underpinning Tehran's negotiating position. Moscow's appointment of a Main Intelligence Directorate of the General Staff (Russia) (GRU)-linked cyber executive to the Security Council positions Shoigu's staff for direct coordination between offensive cyber operations and national security policy.
Allied Intelligence
Former ICC Prosecutor Bensouda Reveals Mossad Chief Cohen Pressured Her to Drop Palestine War Crimes Investigation
BLUF: Bensouda's named testimony raises the evidentiary bar but a formal International Criminal Court (ICC) obstruction probe remains very unlikely before November 26, 2026, given US sanctions pressure and no member-state Article 70 referral.
In an Al Jazeera interview published May 24, former ICC chief prosecutor Fatou Bensouda confirmed that then-Mossad chief Yossi Cohen met her in Munich and New York and demanded she halt the Palestine investigation, warning it could compromise her family's security 123. She said unidentified men delivered a $500 envelope to her home in The Hague in 2015, which she interpreted as a signal they knew her address; Dutch authorities traced phone numbers tied to the visitors to Israel 2. A joint +972, Local Call, and Guardian investigation published February 4 cited more than two dozen current and former Israeli officials reporting that Cohen acted as Netanyahu's approved "unofficial messenger" to Bensouda within a broader ICC surveillance operation from 2015 45.
Analyst Note: Bensouda's on-record account raises the evidentiary floor for Article 70 proceedings, though analytic confidence is bounded by two primary products, the Al Jazeera interview and the +972 investigation, anchored to one named source and an unverified anonymous pool. Israel holds that Cohen's contacts constituted lawful diplomatic advocacy and his security language described geopolitical risk, not an operational threat. A formal Office of the Prosecutor (ICC) (OTP) investigation is very unlikely to open before November 26, 2026: US sanctions on Khan and eight ICC judges constrain institutional bandwidth, no member state has filed an Article 70 referral, and Dutch authorities' 2015 inaction signals weak political will to escalate from the outset. Moderate confidence reflects convergent structural signals but no direct reporting on OTP deliberations. EU member states face a choice between warrant cooperation and political remedies.
Sources:
1: Fatou Bensouda on Israeli threats against her and the ICC - Al Jazeera
2: Former ICC prosecutor says Mossad chief pressured her to stop investigating Israel war crimes - Middle East Eye
3: Former ICC prosecutor says she faced pressure and threats over Palestine investigation - Middle East Monitor
4: Surveillance and interference: Israel's covert war on the ICC exposed - +972 Magazine
5: Former Mossad chief threatened ICC prosecutor over probe into Israel, report claims - The Times of Israel
Shin Bet Chief Zini Met Exiled Palestinian Rival Dahlan in UAE Amid Post-Hamas Gaza Planning
BLUF: Zini's back-channel outreach signals Israeli hedging on Gaza governance rather than a viable Dahlan track, and his formal inclusion in a recognized Gaza body by December 31, 2026 remains unlikely.
Shin Bet chief David Zini met Mohammed Dahlan in the UAE, where the two discussed the situation in Gaza, a source familiar with the details confirmed to Haaretz. 1 Kan public broadcaster reported the meeting Tuesday on the basis of regional and Israeli sources; Ynet noted Zini's UAE visit coincided with the recently concluded ceasefire with Iran. 23 Dahlan, exiled in Abu Dhabi since 2011 after a split with Palestinian Authority (PA) President Abbas, has been discussed in Israeli, US, and Arab circles as a potential post-war governance figure for Gaza. 234 The Shin Bet declined to comment on Zini's schedule 234; Israel's Sovereignty Movement publicly condemned the reports as a resumption of Oslo-era political thinking. 5
Analyst Note: Zini's choice of intelligence over diplomatic channels signals Israel testing a parallel governance track, pressing Washington and Ramallah to account for UAE-backed alternatives before any post-Hamas framework consolidates. The timing may instead reflect bilateral coordination on Iran or hostage files, with Dahlan's candidacy as cover for unrelated exchanges. Dahlan's formal inclusion in an internationally recognized governance body by December 31, 2026 is unlikely. Abbas's opposition, Washington's preference for the technocratic committee, and Dahlan's absence from the Trump plan converge against it. That assessment carries high confidence: three independent Israeli, regional, and US-facing reporting streams, partially concentrated around Kan as upstream attribution, show no observable shift in Abbas's veto or US appetite to formalize his role. Whether that veto holds determines whether Washington redirects post-Hamas governance funding toward a Dahlan-linked structure or sustains exclusive reliance on the technocratic committee.
Sources:
1: Shin Bet Chief David Zini Meets in UAE With Mohammed Dahlan, ex-Gaza Strongman and PA President's Political Rival - Haaretz
2: Shin Bet head said to meet exiled PA Gaza security chief Dahlan in UAE - The Times of Israel
3: Shin Bet head reportedly met in UAE with Mohammed Dahlan - Ynet News
4: Shin Bet chief David Zini met PA's exiled Gaza security chief in UAE - The Jerusalem Post
5: Shin Bet-Dahlan UAE Meeting Sparks Outrage: This Is Oslo All Over Again - JFeed
Israeli Military Intelligence Directorate Intensifies Multi-Agency Hunt for Hezbollah Chief Qassem With Targeted Strikes
BLUF: Washington's no-Beirut constraint combined with Qassem's proven evasive tradecraft makes confirmed elimination unlikely within 90 days of May 26, even as penetration of his security detail signals tightening access.
JFeed, citing regional diplomatic sources, and the Jerusalem Post, citing Saudi outlet Al Hadath, both report that Israel conducted at least two targeted assassination attempts against Hezbollah Secretary-General Naim Qassem in recent weeks 12. Defense Minister Katz declared publicly that Qassem "is from now on a target for elimination," and the Israel Defense Forces (IDF) confirmed a strike on a senior Hezbollah operative in Dahiyeh whom JFeed identified as Qassem's personal security coordinator 13. Netanyahu convened the security cabinet on May 26, announcing the IDF was taking "strategic positions" in Lebanon north of the designated buffer zone 4. The Times of Israel cited Israeli officials saying Washington approved the expanded operations but directed Israel not to strike Beirut, citing concerns about ongoing US-Iran nuclear talks 24.
Analyst Note: Washington's geographic bar on Beirut and Qassem's demonstrated ability to displace ahead of surveillance make a confirmed kill or incapacitation within 90 days of May 26 unlikely. Elimination of his personal security coordinator shows advanced penetration of the protective network, but targeting a hardened mobile principal under active US geographic constraints has not historically resolved within short windows. The public disclosure of failed attempts may itself be an Israeli information operation, pressuring Qassem into defensive postures that degrade Hezbollah's coherence rather than reflecting genuine near misses. We hold this at high confidence: convergent reporting across independent outlets corroborates both the operational failures and the US-imposed restriction, anchoring the limiting factors in observable rather than speculative terrain. A confirmed kill forces Washington to immediately revisit the Beirut prohibition; Qassem's survival instead validates the US operational leash as a durable constraint through the nuclear negotiation period.
Sources:
1: Hunting the New Chief: Top Secret Intelligence Tracks Multiple Targeted Strikes on Naim Qassem - JFeed
2: Hezbollah chief Naim Qassem reportedly targeted twice as Beirut braces for escalation - The Jerusalem Post
3: Katz: 'Hezbollah chief Naim Qassem is a target'; IDF continues strikes in Lebanon - Ynet News
4: IDF says ground forces advancing north of Lebanon; Katz warns Naim Qassem's 'turn will also come' - The Times of Israel
Adversary Intelligence
Kremlin Appoints Cyber Executive With Alleged GRU Ties to Security Council Role
BLUF: Back-to-back placement of Unit 26165-linked aides in Shoigu's office signals deliberate GRU cyber embedding at the policy core, though Western designation of Kozlov by November 26, 2026 remains unlikely.
Putin signed a decree on May 22 appointing Andrei Kozlov, a former Rostec cybersecurity executive, as aide to Security Council Secretary Sergei Shoigu 123. Kozlov served as acting general director of RT-IB, Rostec's cybersecurity subsidiary, in late 2022 and headed the RUSIB information security association from May 2024 to April 2026 34. The Insider, citing leaked security clearance records, reports that Kozlov held a classified clearance under Military Unit 26165, the GRU unit Western governments and cybersecurity researchers have linked to Fancy Bear/APT28 34. Kozlov's predecessor in the post, Pavel Konovalchik, was dismissed in March 2026 and named first deputy general director of TASS in April; The Insider had previously reported Konovalchik's ties to the same unit 234.
Analyst Note: Designation by November 26, 2026 is unlikely: precedent for sanctioning Security Council advisory staff at this tier is thin, and Kozlov's limited public profile falls short of the threshold historically triggering Office of Foreign Assets Control (OFAC) or EU action against Rostec-linked officials. Two consecutive aides to Shoigu with Military Unit 26165 clearances indicate the Kremlin is deliberately embedding GRU cyber expertise in this staff position. Kozlov's RT-IB background positions him for liaison between offensive cyber capability and national security policy. Moderate confidence, given the GRU linkage rests entirely on The Insider's leaked records without independent corroboration. His clearance may instead reflect routine defense-sector access common across Russia's information security sector. OFAC inaction leaves allied compliance officers without grounds to treat Security Council advisory staff as a sanctions category.
Sources:
1: Андрей Козлов назначен помощником секретаря СБ РФ - Vesti.ru
2: Путин назначил Андрея Козлова помощником секретаря Совбеза России - Kommersant
3: Kremlin appoints cyber executive with alleged GRU ties to Security Council role - The Record
4: Putin appoints Rostec cybersecurity specialist linked to GRU hackers from Fancy Bear as aide to Sergei Shoigu in Russia's Security Council - The Insider
Указ о помощнике Секретаря Совета Безопасности - President of Russia (Kremlin)
Iranian Government Hackers Attributed to MOIS Behind Los Angeles Transit System Breach
BLUF: Formal US attribution to MOIS remains unlikely within roughly 90 days of the Gambit report, leaving private-sector forensics as the operative public record while Tehran's hacktivist cover holds.
Gambit Security, a Tel Aviv-based firm, published a report Tuesday attributing the March Los Angeles County Metropolitan Transportation Authority (LACMTA) breach to
Black Shadow, an Iran-MOIS cluster previously identified by Israel's National Cyber Directorate, dismissing Ababil of Minab's hacktivist persona as a front
12. Gambit said it discovered roughly 700 gigabytes of stolen emails, backups, and files on an inadvertently exposed server, then traced configuration fingerprints back to previously identified Iranian infrastructure
34. Attackers who first accessed LACMTA systems around March 16 reached what the group claimed was a rail yard train-control display at Division 11, deleted virtual machines and storage volumes, and targeted backup infrastructure in what Gambit characterized as a deliberate recovery-denial strategy
14. Gambit assessed the campaign as broader than LACMTA, with exfiltration hitting organizations across the United States, Israel, Saudi Arabia, and Turkey, and destructive operations at a subset of victims including a named Israeli media company, an Israeli university, and a Turkish insurance firm
23.
Analyst Note: US formal attribution of the breach to Iran's MOIS is unlikely within approximately 90 days of Tuesday's Gambit report, despite FBI acknowledgment and private-sector forensic linkage to the Black Shadow cluster. Moderate confidence rests on Gambit's direct access to attacker staging infrastructure and documented technical overlap with Israel National Cyber Directorate (INCD)-attributed Iranian activity, offset by single-vendor provenance and absent US government corroboration. The infrastructure fingerprint evidence remains the assertion of a commercial firm with institutional incentives to assign state attribution. Tehran's layered targeting of virtualization, storage volumes, and backup systems reflects a recovery-denial strategy. The continued use of a hacktivist front preserves deniability amid elevated US-Israeli military posture against Iran. Without US attribution, transit agencies and CISA lack the federal anchor to compel emergency hardening or calibrate a deterrence response.
Sources:
1: Attacking the recovery layer: an Iran-MOIS case study - Gambit Security
2: Iranian government, not hacktivist group, breached LA Metro system, security firm says - Cybersecurity Dive
3: Iranian hackers responsible for Los Angeles transit system breach, Israeli researchers say - NBC News
4: Iran-linked hackers reached LA Metro's rail-yard control display in March, Israeli firm finds - The Next Web
Iranian hackers blamed for breach of Los Angeles transit system that took weeks to recover - TechCrunch
FSB Director Bortnikov Claims Thwarting 500 Explosive Devices at CIS Security Chiefs Meeting and Warns of AI Bioterrorism Risks
BLUF: Bortnikov's Irkutsk performance is less about the interdictions cited than about locking Commonwealth of Independent States (CIS) services into a Moscow-defined threat agenda spanning Ukraine, AI, biolabs, and Western NGOs.
At the 58th CIS Security Service Heads meeting in Irkutsk, Federal Security Service (Russia) (FSB) Director Bortnikov stated that Russian and Belarusian services disrupted a Kyiv-organized attempt to smuggle more than 500 explosive devices into Russia in early 2026 123. He told the assembly that FSB and Tajik services had neutralized a terrorist cell and that FSB and Uzbek counterparts had interdicted five planned attacks across Russia, including in Moscow, in the same period 2. Bortnikov warned that AI advances are increasing bioterrorism risks, citing what he described as NATO's ongoing biological weapons program operating through labs in CIS countries 24. He additionally accused British intelligence of expanding NGO operations across CIS states and alleged Western deployment of AI-enabled digital laboratories to build behavioral profiles of CIS populations 24.
Analyst Note: Bortnikov used the Irkutsk forum to consolidate CIS security alignment under Moscow's threat framing, deploying interdiction statistics reported exclusively through Russian state and pro-Kremlin outlets replicating a single official speech, figures that carry no independent evidentiary weight. Extending the shared threat space beyond Ukraine to AI-bioterrorism and British NGO operations creates new rhetorical terrain on which CIS services will be asked to cooperate. His explicit call for deepened joint cooperation signals Moscow's intent to operationalize that consensus into binding bilateral security arrangements. The figures may instead reflect genuine FSB successes selectively disclosed to reinforce Bortnikov's domestic institutional standing rather than to inform partners of actual threat conditions.
Sources:
1: ФСБ и КГБ Белоруссии сорвали попытку Киева ввезти более 500 бомб в Россию - RIA Novosti
2: Боевики, 500 бомб и ИИ: директор ФСБ высказался об Украине и угрозах для СНГ - RTVI
3: ФСБ вновь пресекла множество терактов Украины: в РФ пытались провезти 500 взрывных устройств - Izvestia
4: Key takeaways from FSB Director Bortnikov statements at CIS Security Service Heads meeting - Pravda NATO
IC Workforce & Organization
CISA Enters AI Era With a Third of Workforce Cut and No Permanent Director as Cyber Threats Intensify
BLUF: Senate confirmation of a permanent CISA director is unlikely before December 2026, leaving critical infrastructure operators without authoritative federal AI threat translation as Mythos-class exploits proliferate.
CISA has shed roughly one-third of its workforce since January 2025 through buyouts and budget cuts, and the Trump administration has proposed a further $707 million reduction for fiscal year 2027 123. Sean Plankey withdrew his director nomination on April 22 after 13 months; Sen. Rick Scott's hold over an unrelated Coast Guard contract dispute had blocked Senate confirmation, leaving Nick Andersen as acting director 45. Axios reported, citing two sources, that CISA was excluded from Anthropic's distribution of its Mythos hacking model to more than 40 organizations, and that Andersen has had limited influence in White House-led AI threat discussions 13. CryptoBriefing separately noted that Google confirmed in May 2026 the first AI-generated zero-day exploit capable of defeating two-factor authentication 2.
Analyst Note: Senate confirmation of a permanent CISA director by December 2026 is unlikely. Moderate confidence rests on the absence of any replacement nomination and the administration's demonstrated tolerance for extended leadership vacuums. Axios-sourced claims that CISA was excluded from Anthropic's Mythos distribution and that Andersen holds limited White House AI influence remain uncorroborated by a second outlet, which tempers their weight. The planned 300-hire surge and a proposed vulnerability-clearinghouse role in the draft AI executive order may signal deliberate mission reorientation rather than institutional collapse. Critical infrastructure operators have no federal threat-briefing pipeline at the moment Google has confirmed the first AI-generated zero-day exploit capable of defeating two-factor authentication, accelerating migration toward commercial intelligence retainers and Five Eyes coordination as the primary early-warning sources through at least 2027.
Sources:
1: Trump hobbled top cyber agency just as AI learned to hack - Axios
2: CISA faces cuts and diminished role amid rising AI cyber threats - CryptoBriefing
3: Scoop: Top U.S. cyber agency doesn't have access to Anthropic's powerful hacking model - Axios
4: America's Cyber Defense Agency Has No Director, No Budget, and a Chinese Backdoor in Its Firewalls - State of Surveillance
5: CISA Is in Trouble: One-Third of Staff Gone, No Permanent Director - The Cyber Signal
Cybersecurity 2026: AI, CISA, manufacturing sector all in the hot seat - Cybersecurity Dive
Counterintelligence & Tradecraft
Iran Executes Alleged Mossad Ringleader Gholamreza Khani Shakarab Amid Wartime Espionage Crackdown
BLUF: Khani Shakarab's hanging marks an institutionalized execution pipeline, with Tehran very likely to announce at least 10 additional espionage or national-security executions in the 90 days following 26 May.
Iran's judiciary announced Tuesday that Gholamreza Khani Shakarab was hanged after the Supreme Court upheld his conviction for Mossad espionage 123. Mizan Online described him as "one of the operational ringleaders of Mossad abroad" tasked with recruiting operatives inside Iran; the judiciary said Islamic Revolutionary Guard Corps (IRGC) intelligence forces used deception to lure him back into the country before his arrest 123. Press TV, citing his indictment and confession, additionally alleged he coordinated sabotage operations including bomb-making inside Iran and conducted reconnaissance for a Mossad-directed assassination plot against a Jewish rabbi abroad 1. The UN reported by late April at least 21 executions and more than 4,000 arrests on national security charges since February 28; Iran Human Rights counted 29 political executions over the same period 4.
Analyst Note: Tehran very likely will announce at least 10 additional espionage or national-security executions in the 90 days following May 26. High confidence rests on three converging indicators: the documented execution trajectory shows no deceleration, IRGC intelligence channels are institutionalized as the primary vehicle for national-security proceedings, and official messaging consistently frames each hanging as deterrence against foreign recruitment. The detailed operational claims, the rabbi assassination plot and the deception operation used to lure Khani Shakarab back across the border, rest entirely on IRGC-affiliated state media with no corroboration from non-state sources. The narrative may instead be crafted primarily for domestic deterrence rather than accurately reflecting the defendant's capabilities. The case additionally signals active IRGC pursuit of diaspora operatives through deception-based rendition, and intelligence services running human assets inside or adjacent to Iran should compress exposure reviews and accelerate exfiltration timetables.
Sources:
1: Mossad agent convicted of espionage, sabotage operations executed: Iran's judiciary - Press TV
2: Iran executes man over alleged cooperation with Mossad spy agency - The Times of Israel
3: Iran executes man over alleged cooperation with Israeli spy agency - Al Arabiya
4: Iran executes alleged Mossad operative amid wartime crackdown - Prism News
IC Oversight & Authorities
DNI Gabbard Pushes to Declassify FISA Court Opinion Revealing Compliance Failures Across Intelligence Community
BLUF: Declassification before Gabbard's June 30 exit is unlikely, leaving the Foreign Intelligence Surveillance Court (FISC) opinion's findings on IC-wide Section 702 compliance failures unavailable to inform reauthorization debates.
Just the News reported May 23 that Director of National Intelligence (DNI) Gabbard is pressing to declassify a Foreign Intelligence Surveillance Court opinion expected, per a senior intelligence official, to document compliance failures in how intelligence agencies queried Section 702 databases and whether internal guardrails against abuse were circumvented 12. The Justice Department reportedly discovered in 2024 that FBI personnel used a filtering mechanism to query Section 702 data without meeting oversight requirements under the Reforming Intelligence and Securing America Act, lacking required counting, tracking, and approval procedures 12. Officials said that specific tool was subsequently shut down, but the still-classified opinion reportedly indicates comparable mechanisms may persist at NSA and CIA 12. Senate Intelligence Committee Chairman Tom Cotton (R-AR) and Sen. Ron Wyden (D-OR) struck a bipartisan agreement to send a letter to Gabbard and the Justice Department pressing for declassification of the opinion. Gabbard announced Friday she will leave the DNI post on June 30 1.
Analyst Note: Declassification of the FISC opinion is unlikely before Gabbard's June 30 departure; multi-agency equities review rarely resolves within five weeks even under pressure from a departing DNI. Confidence is low: the reporting traces to a single unnamed senior intelligence official, with no corroboration of the opinion's scope or a confirmed declassification timeline. Agencies will argue the 2024 FBI tool shutdown already resolved the core compliance concern, making the opinion a record of remediated rather than active IC-wide noncompliance. Should the push fail, Congressional negotiators move toward any Section 702 reauthorization vote without the court's compliance findings; should it succeed, those findings must be reconciled with reauthorization language before a vote.
Sources:
1: DNI Gabbard presses to declassify secret but critical court opinion during FISA renewal debate - Just The News
2: Gabbard Seeks Release of Classified FISA Court Opinion Amid Surveillance Renewal Fight - YourNews
Tulsi Gabbard's Last Action Against the Deep State: What a FISA Court Declassification Could Mean - Breitbart
COLLECTION GAPS
- Chinese intelligence operations against Western targets, including MSS recruitment cases and MPS transnational policing activity.
- Five Eyes service organizational reforms or leadership transitions, particularly within GCHQ, ASIS, or BND.
- NSA collection posture adjustments ahead of the ODNI leadership transition.
- US domestic counterintelligence cases and DOJ National Security Division prosecution updates.