← Back to Archive
IC BRIEF
Current as of 0424 EDT (UTC-04), Thursday 28 May 2026
Contents
9 stories from 38 sources across 33 organizations
KEY JUDGMENTS
Concurrent intelligence vetting failures across the CIA and United Kingdom Security Vetting (UKSV), combined with the Director of National Intelligence (DNI) vacancy following Gabbard's resignation, leave allied internal controls degraded as adversary surveillance capabilities expand. No permanent DNI is likely to be confirmed before the end of FY2026, leaving three pending coordination requirements unfulfilled: a classified China AI assessment, continuous vetting reform, and Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) cyber reporting finalization. High confidence rests on the historical four-to-nine-month confirmation timeline and the absence of a pre-vetted nominee. An expedited nomination announced within weeks would alter this assessment.
Russia's expanded System for Operative Investigative Activities (SORM) order requiring telecoms to share identity-resolution data with the Federal Security Service (Russia) (FSB), and Iran's Ministry of Intelligence and Security (Iran) (MOIS) declaration naming Western broadcasters as intelligence instruments, establish enforcement predicates in the same week. Whether Iran follows with publicly announced prosecutions specifically citing cooperation with the named outlets is genuinely uncertain within six months. Moderate confidence rests on Iran's consistent post-declaration enforcement pattern, tempered by the judiciary's standard practice of using generic national security charges that avoid naming specific outlets.
Adversary Intelligence
Iranian Intelligence Ministry Declares Shift to Cognitive and Soft Warfare Against Western Targets
BLUF: Naming specific Western outlets as intelligence instruments lays the legal groundwork for a prosecution wave targeting ordinary Iranians, while the Mojtaba Khamenei framing signals the succession has stabilized enough to act on it.
Iran's Ministry of Intelligence declared on May 27 that hostile powers, having failed militarily, are now intensifying a "hidden intelligence-security war" through economic pressure, cyberattacks, cross-border terrorism, and psychological operations 12. The ministry's statement named BBC Persian, Voice of America, Iran International, and X as instruments of intelligence gathering, citizen-journalist recruitment, and domestic disruption coordination 12. The statement also flagged trafficking of Starlink terminals and armed group deployments along Iran's northwestern and southeastern borders as priority threat vectors 123. The ministry reaffirmed operational continuity under Ayatollah Seyed Mojtaba Khamenei and issued legal warnings against espionage, sabotage, and coordination with designated hostile media 2.
Analyst Note: Tehran's naming of BBC Persian, Voice of America, Iran International, and X as intelligence instruments establishes a domestic legal predicate for prosecuting Iranians who engage with those outlets, consistent with ministry patterns before enforcement surges. The succession framing anchoring continuity under Mojtaba Khamenei signals the post-assassination command structure has consolidated sufficiently to resume assertive institutional posture. The Starlink call-out reveals active concern about internet-control circumvention. Sourced entirely from Press TV with Tasnim and WANA providing only amplification, the statement carries no independent corroboration. The rhetoric may function primarily as a loyalty demonstration to new leadership rather than a genuine doctrinal shift.
Sources:
1: 'Defeated militarily,' enemies waging hidden hybrid war: Iran Intel Ministry warns - Press TV
2: Iranian Intelligence Ministry Outlines Key Focus Areas of Foreign Security Threats - WANA
3: Intelligence Ministry Warns of Enemy Hybrid Warfare Plot Against Iran - Tasnim News Agency
FSB Director Bortnikov Claims Joint Operations With Tajikistan and Uzbekistan Thwarted 13 Terrorist Cells
BLUF: Bortnikov's Syria-to-Iran proxy warning matters more than the cell-disruption tally, signaling Moscow is preemptively framing radicalized Commonwealth of Independent States (CIS) nationals as a deniable Western-Israeli instrument against Russian-aligned interests.
Bortnikov, speaking at the 58th SORB/CIS Council of Security Heads meeting in Russia's Irkutsk Region on May 26, said joint operations with partner services suppressed 13 terrorist cells this year, citing cooperation with Azerbaijan among other countries 1. He stated that Russian and Tajik agencies jointly identified and neutralized a cell planning "high-profile attacks" in Russia, and that Uzbekistan's State Security Service helped disrupt five additional planned attacks across multiple Russian regions including Moscow 23. Bortnikov said Islamic State Khorasan Province (ISIS-K) was actively recruiting supporters from citizens of Tajikistan, Uzbekistan, Kyrgyzstan, and Kazakhstan, as well as migrant workers in Russia, and separately alleged that ISIS-K and allied jihadist groups receive "active support" from British intelligence services in efforts to destabilize Afghanistan 3. He separately warned that CIS nationals currently imprisoned in Syria risked being drawn into proxy operations against Iran 2.
Analyst Note: Bortnikov's Syria-to-Iran proxy warning is the operationally distinct claim: it names a new pathway for already-radicalized CIS nationals to be redirected against Russian-aligned interests without direct ISIS-K command. The surrounding framing treats ISIS-K recruitment across CIS migrant communities as sustained radicalization infrastructure, pressing Central Asian services toward integrated intelligence sharing beyond reactive cell disruption. Both claims rest on a single-source chain: RT citing TASS, with no independent reporting. Central Asian governments have strong incentive to accept Russian threat framing regardless of corroboration, which limits analytical weight. The announcement may instead be primarily political signaling calibrated to reinforce Russian intelligence primacy ahead of institutional meetings.
Sources:
1: Russian FSB chief: Activities of 13 terrorist cells suppressed jointly with partners from Azerbaijan and other countries - Azerbaycan24
2: Terrorist attacks in Russia thwarted by joint work with Tajikistan, Uzbekistan, says FSB director - bne IntelliNews
3: ISIS-K recruiting Asian migrants for terror networks, Russia says - The Jerusalem Post
West planning to use former ISIS militants against Iran – FSB chief - RT (citing TASS)
Russia Expands Telecom Surveillance Requirements for FSB Data Access Through Updated SORM System
BLUF: Moscow's order converts SORM into an FSB-queryable identity dragnet and squeezes small operators out of the market, though whether the compliance inspection moratorium falls by late May 2027 remains genuinely uncertain.
Russia's Digital Development Ministry published an order on May 22 expanding what telecom operators must collect and make searchable through SORM for security service queries, according to Kommersant, which first flagged the document on the official legal portal 12. The expanded categories add passport data, addresses, taxpayer IDs, banking details, IP addresses, domains, usernames, and geolocation coordinates, with the order also specifying GraphQL, WebSocket, and HTTP as required data-exchange interfaces 1234. Igor Bederov, investigations director at T.Hunter, told Kommersant the prior requirements were "far more general in scope" 12. RUVDS CEO Nikita Tsaplin put minimum SORM implementation costs at five million rubles and said small operators cannot absorb them 14; Meduza, citing RBC, reported the Ministry is also discussing lifting the compliance inspection moratorium 23.
Analyst Note: The order transforms SORM into a full identity-resolution platform, compelling operators to make financial records, geolocation, and biometric identifiers directly searchable by the FSB. Small operators face a structural choice between five-million-ruble compliance costs and market exit, a pressure the Ministry compounds by pursuing an end to the inspection moratorium, which may serve a consolidation agenda as much as surveillance, accelerating regional operator exit to benefit incumbents like Rostelecom. Whether Russia lifts that moratorium by late May 2027 is genuinely uncertain. That forecast carries moderate confidence: the order is verifiable, but the moratorium decision rests on internal deliberations current reporting does not illuminate. Sourcing traces to a single Kommersant cluster, constraining the picture to narrow corroboration. Compliance officers at small and mid-tier telecoms must treat moratorium status as the pivot: a lift demands immediate advancement of upgrade timelines; continued suspension permits deferral.
Sources:
1: Минцифры расширило требования к передаче данных через СОРМ - Kommersant
2: Russia digital ministry expands the list of user data that telecom operators must share with security services - Meduza
3: Власти расширили доступ силовиков к данным россиян через СОРМ. Провайдеров обяжут передавать геолокацию и банковские реквизиты - Novaya Gazeta
4: Приватности не осталось. По приказу властей операторы будут передавать силовикам паспортные данные, адреса и геолокацию россиян - CNews
IC Technology & Surveillance
USAF Deploys New ULTRA Turbo Surveillance Drones With 60-Hour Endurance to Middle East
BLUF: Whether ULTRA Turbo clears the CENTCOM operational assessment and reaches program-of-record status by September 30, 2027 is genuinely uncertain, leaving Intelligence, Surveillance, and Reconnaissance (ISR) planners unable to bank the capability.
Air Force FY27 budget documents, cited by The War Zone, confirm a planned operational assessment of the ULTRA Turbo within U.S. Central Command's area of responsibility beginning in FY26, with FY27 funding to continue the evaluation and address capability requirements 12. DZYNE Technologies announced in February that the aircraft completed a 60-hour, mission-representative flight at 25,000 feet and 100 knots, using a Rotax 916 turbocharged piston engine that extends the platform's operational ceiling to 30,000 feet at 120 knots 13. On April 30, DZYNE announced a multi-million-dollar Air Force Research Laboratory (AFRL) contract for three additional ULTRA Turbo airframes, describing the award as a milestone toward program-of-record transition 4. The Air Force is requesting $16.57 million for the ULTRA program in FY27 12.
Analyst Note: Whether the Air Force transitions ULTRA Turbo to program-of-record status by September 30, 2027 is genuinely uncertain. The operational assessment must first validate performance against CENTCOM capability requirements unspecified in open reporting, and the acquisition decision rests on leadership choices not yet signaled in budget or requirements documentation. At $16.57 million, the FY27 request resources an evaluation, not a production commitment. Low confidence reflects the absence of observable acquisition milestones: no milestone decisions, requirements documentation, or independent government statements on transition intent have entered open reporting, and sourcing traces entirely to DZYNE press releases and a trade outlet's budget-document reading. The CENTCOM deployment may instead reflect MQ-9 attrition urgency rather than deliberate program maturation. Confirmation by FY2027 lets ISR planners begin substituting ULTRA into persistent overwatch taskings now carried by Reapers. Failure sustains that attrition risk as the operational baseline.
Sources:
1: USAFs New Turbocharged ULTRA Surveillance Drones Are Heading To The Middle East - The War Zone
2: US Air Force sends ULTRA Turbo drone with multi-day endurance to Middle East - Interesting Engineering
3: DZYNE's ULTRA Turbo Achieves Historic 60-Hour, High-Altitude Flight -- Redefining Group 5 UAS Endurance - DZYNE Technologies / PR Newswire
4: DZYNE Secures Multi-Million Dollar AFRL Contract for Additional ULTRA Turbo Aircraft, Redefining Group-5 ISR - DZYNE Technologies / PR Newswire
CISA Reschedules CIRCIA Cyber Incident Reporting Town Halls for Critical Infrastructure After DHS Shutdown
BLUF: Critical infrastructure entities should plan for continued CIRCIA compliance ambiguity into 2027, as a final rule published by December 31, 2026 is very unlikely despite the rescheduled June town halls.
CISA on May 26 announced a revised schedule of four virtual town halls on CIRCIA rulemaking, set for June 15–18, replacing sessions postponed from March and April 2026 123. CISA's announcement attributed the postponement to "the recent Democrat shutdown of the Department of Homeland Security"; Inside Privacy described the cause as a DHS funding lapse that ended April 30 13. The revised format consolidates five original two-hour sector sessions into two four-hour grouped sessions covering all 16 critical infrastructure sectors and two general sessions, all running 11:30 a.m. to 3:30 p.m. ET 23. Registration is available at cisa.gov/circia, with Acting Director Nick Andersen stating CISA will finalize the rule after incorporating stakeholder input 1.
Analyst Note: This assessment draws on CISA's own press release with secondary amplification but no independent reporting. The DHS funding lapse consumed two months of rulemaking calendar, and Acting Director Andersen has committed only to incorporating town hall input, not to a publication date. Post-comment processing for rules of this scope historically spans six to twelve months after stakeholder sessions close, making a final rule in the Federal Register by December 31, 2026 very unlikely. Moderate confidence reflects those three compounding constraints. The consolidation of sector sessions into grouped blocks may instead signal that substantive terms are settled and the town halls are procedural compliance rather than genuine input-gathering. Compliance officers should plan against a final rule arriving no earlier than 2027.
Sources:
1: CISA Announces Revised Town Hall Schedule to Engage with Stakeholders on Cyber Incident Reporting for Critical Infrastructure
2: CISA sets June town hall meetings on CIRCIA cyber incident reporting rule for critical infrastructure stakeholders - Industrial Cyber
3: CISA Announces Revised Schedule of Town Halls for CIRCIA Rulemaking - Inside Privacy
CISA Reschedules CIRCIA Town Halls as Critical Infrastructure Cyber Reporting Rules Move Forward - HSToday
Counterintelligence & Tradecraft
Former CIA Officer David Rush Arrested After FBI Seizes 300 Gold Bars Worth $40 Million From Virginia Home
BLUF: Rush is likely to plead guilty or be convicted on theft charges by May 2028, exposing systemic gaps in CIA continuous vetting that allowed fabricated credentials and tens of millions in diversions to persist.
David Rush, a senior CIA management official, was arrested May 19, 2026 after FBI agents searched his Northern Virginia home the day prior and seized approximately 300 gold bars worth more than $40 million, roughly $2 million in cash, and 35 luxury watches, mostly Rolexes 1234. Rush is charged with criminal theft of public money in the Eastern District of Virginia, allegedly diverting gold bars and foreign currency he requested for purported work-related expenses between November 2025 and March 2026 123. CIA Director John Ratcliffe referred the case to the FBI after an internal CIA investigation found potential law violations; only a portion of the requested funds were found in a government storage space near his office 12. Rush also allegedly fabricated credentials for nearly two decades, including falsely claiming to be a licensed Navy pilot and active Navy Reserve captain, and fraudulently collected approximately $77,000 in military leave pay 123.
Analyst Note: Rush is likely to enter a guilty plea or be convicted on theft charges by May 28, 2028. High confidence in that judgment rests on physical evidence recovered from the residence and documentary corroboration from university registrars and military records at every material point, triangulated by three independent major-outlet investigations with no single-wire dependency. The prolonged credential fabrication, surviving multiple promotion cycles, and the scale of diversion before internal review flagged the conduct expose sustained failures in CIA's continuous vetting and financial oversight, echoed by concurrent allied vetting lapses across Five Eyes services. A compartmented-authority defense remains viable if Rush can demonstrate the transfers occurred under classified operational sanction whose disclosure is statute-restricted. Congressional appropriators calibrating the scope of mandatory CIA disbursement audits will track whether criminal accountability arrives by that same 2028 window.
Sources:
1: Former CIA official arrested for embezzlement, hoarding more than $40 million in gold bars - The Washington Post
2: Former CIA officer accused of stealing 300 gold bars, sources say - NBC News
3: Feds seize $40M in gold bars, cash, Rolexes from former CIA official who faked being a Navy pilot - Fox News
4: Ex-CIA official arrested after $40M in gold bars allegedly found at his home - CBS News
UK Vetting Agency Flagged Mandelson Ties to China Russia and Israel Figures Before Denying Security Clearance
BLUF: Mandelson is unlikely to be removed as UK Ambassador before late November 2026, as Starmer's sacking of Robbins absorbs institutional blame and shields the appointee absent Intelligence and Security Committee of the UK Parliament (ISC) evidence of personal concealment in the June release.
The Guardian reports, citing multiple anonymous sources, that UKSV's nine-page vetting summary completed January 28, 2025, rated Mandelson a "high" overall concern and recommended denial of clearance 12. The agency flagged ties to China's Finance Minister Lan Fo'an, sanctioned oligarch Oleg Deripaska, and former Israeli military intelligence chief Tamir Hayman, plus a £1m loan, provided by a British businessman, that Mandelson received to buy shares in Israeli firm Moon Active but did not declare, despite registering the resulting shareholding of more than £50,000 12. UKSV also flagged a fourth unnamed British individual whose "very close" relationship with Mandelson was considered potentially compromising 1. Then-Permanent Secretary Olly Robbins received the file on January 29 and granted clearance hours later; Starmer subsequently sacked him, calling it "unforgivable" that he did not inform ministers of the findings 12. The Intelligence and Security Committee has publicly accused the government of over-redacting vetting documents, with sources indicating officials sought legal arguments to comply with the letter but bypass the spirit of a parliamentary humble address; a second tranche is expected in June 123.
Analyst Note: Mandelson is unlikely to be removed by November 28, 2026. Starmer's attribution of institutional failure to Robbins creates a political firewall that holds absent direct evidence Mandelson himself concealed material from vetting. Robbins may have held informal ministerial guidance that rendered the clearance grant a defensible professional judgment rather than a politically driven override, which would sustain the government's current framing. Moderate confidence, grounded in multiple anonymous accounts of a classified document with no independent verification of UKSV's precise language or specific findings. The ISC's June document release is the highest-probability trigger: documentary proof of personal concealment would force parliamentary demands for a formal national security harm review. Confirmed robust mitigation would instead let Starmer close the episode at Robbins's dismissal.
Sources:
1: Revealed: Mandelson vetting warned of ties to senior figures in China, Russia and Israel - The Guardian
2: Mandelson failed security vetting for US ambassador role over links to figures in China, Russia and Israel - The Independent
3: Peter Mandelson's ties to China, Russia and Israel among concerns raised by Britain's vetting agency - GB News
Revealed: Mandelson vetting warned of ties to senior figures in China, Russia and Israel - The Guardian
IC Oversight & Authorities
GOP Senators Banks and Cotton Press DNI Gabbard and CIA to Assess China AI Capabilities
BLUF: Gabbard's resignation one day after the letter leaves the request without its lead coordinating authority, making a formal IC response within twelve months genuinely uncertain.
Sens. Jim Banks (R-Ind.) and Tom Cotton (R-Ark.) sent a letter on May 21 to DNI Tulsi Gabbard, CIA Director John Ratcliffe, National Cyber Director Sean Cairncross, and NSA Director Joshua Rudd calling for prioritized intelligence collection on China's AI capabilities 12. The senators requested monitoring of leading Chinese AI scientists, China's data center expansion, and advanced chip smuggling, and asked for capability-threshold assessments identifying benchmarks the United States must achieve or deny to China 2. The letter cited Anthropic's Mythos, which the senators described as capable of identifying decades-old security vulnerabilities, and quoted experts predicting that near-term AI systems will carry military and intelligence implications beyond the cyber domain 2. Yahoo News reported that Gabbard announced her resignation on May 22, the day after the letter was sent 2.
Analyst Note: A formal classified IC assessment responsive to the Banks-Cotton request is genuinely uncertain to emerge within twelve months. Gabbard's announced resignation, confirmed the day after the letter was sent, disrupts the primary institutional channel at the moment coordinated Office of the Director of National Intelligence (ODNI)-led follow-through is required. Ratcliffe at CIA and Rudd at NSA remain operative recipients but neither independently commands ODNI's interagency coordination authority. The threshold-benchmark framing compounds this, asking analysts to define capability ceilings that IC culture historically resists committing to in writing. Moderate confidence reflects confirmed letter text and first-reported sourcing from The Hill, with no observable indicators of IC response timelines from any remaining addressee. The letter's public release and citation of a commercial AI product may instead signal authorization-cycle positioning. Without a formal assessment, Senate Intelligence Committee staff lack an anchor for AI collection mandates in authorization markup.
Sources:
1: GOP senators press intelligence officials to assess China AI capabilities - The Hill
2: GOP senators press intelligence officials to assess China AI capabilities - Yahoo News
Senator Banks Raises Concerns Over Chinese Espionage Targeting U.S. Artificial Intelligence Sector - Senator Jim Banks – Official Senate Press Release
Allied Intelligence
EU Seeks to Expand Intelligence Centre INTCEN With Own HR and IT Infrastructure
BLUF: Inclusion of the EU Intelligence and Situation Centre (INTCEN) expansion in the EU Security Strategy by year-end 2026 is genuinely uncertain, and even if adopted, member-state hoarding will blunt any operational gain.
The European External Action Service (EEAS) is seeking to expand INTCEN with a dedicated HR department and its own IT infrastructure, Politico reported 123. INTCEN currently analyzes intelligence shared voluntarily by EU member states and has no collection capabilities of its own 1. The expansion is to be proposed within a new EU Security Strategy expected this summer; the strategy's roadmap covers up to ten major reforms, and one unnamed official told Politico the INTCEN changes require no new legal mandate or budget lines, making them treatable as an administrative EEAS matter 1. EEAS spokesperson Anita Hipper denied any changes were planned, while two senior intelligence officials from separate EU countries told Politico they remain skeptical of INTCEN's utility, citing national agencies' habit of withholding valuable intelligence and persistent distrust among partners 1.
Analyst Note: The proposed expansion is genuinely uncertain to appear in the EU Security Strategy by year-end 2026. Low confidence reflects single-source Politico reporting actively contradicted by the EEAS spokesperson, with no corroborating statement from Brussels. The administrative framing, requiring no new mandate or new budget lines, signals intent to minimize political exposure and bypass member-state veto points. Two senior national intelligence officials' skepticism names the structural obstacle additional capacity cannot fix: member states share what national interests permit, not what Brussels requests. The EEAS may instead be floating anonymous briefings to build political momentum while preserving official deniability, a phased pressure strategy rather than a genuine near-term proposal. Services wishing to formally oppose must engage during the consultation window or risk this becoming a fait accompli before the strategy is finalized this summer.
Sources:
1: EU's intelligence hub eyes bigger role in security overhaul - Europe Says (republishing Politico)
2: From toothless to allies suspicion: EU expands intelligence hub - European Pravda
3: The EU intends to expand the role of the intelligence center - European Pravda (EU edition)
EU's intelligence hub eyes bigger role in security overhaul - Politico
COLLECTION GAPS
- The status and timeline of the permanent DNI nomination process following Gabbard's announced resignation have not been publicly established.
- The intelligence-sharing implications for Five Eyes arising from the concurrent UK and US vetting failures have not been publicly addressed.
- ODNI's continuous vetting program performance metrics and reform proposals in response to the Rush case are not publicly documented.
- Central Asian partner services' independent assessments of the ISIS-K recruitment claims made by FSB Director Bortnikov are not publicly available.
- EU member-state intelligence services' internal deliberations on the INTCEN expansion proposal ahead of the Security Strategy are not publicly available.