//
OFFLINE — VIEWING CACHED CONTENT
← Back to Archive

IC BRIEF

Current as of 1607 EDT (UTC-04), Saturday 04 July 2026

Contents

8 stories from 38 sources across 32 organizations


KEY JUDGMENTS

The US intelligence community faces an accelerating workforce crisis that near-term judicial and legislative mechanisms are unlikely to constrain. The administration is very likely to appeal the 4th Circuit's reinstatement of 19 fired CIA and Office of the Director of National Intelligence (ODNI) officers within one month. A permanent Director of National Intelligence (DNI) confirmation likely will not occur before October, leaving Pulte's acting authority unchecked, and congressional hearings on the purge are unlikely before September. Whether the July terminations produce their own litigation is genuinely uncertain, as no named plaintiff has emerged. Moderate confidence reflects converging but single-source accounts of the administration's legal posture and personnel actions.

Formal NATO attribution of Russia's documented 15-month drone espionage campaign over RAF bases and allied nuclear sites is very likely to be withheld before October, absent a new incident producing unambiguous forensic evidence. Disclosed CIA and Dutch advance knowledge of Ukraine's Nord Stream sabotage, based on new book-length primary reporting, widens the gap between allied intelligence collection and public accountability.

Chinese espionage tooling continues to evolve toward cloud-native collection: ToddyCat's Umbrij tool demonstrates API-level email theft invisible to conventional endpoint detection, though a joint allied advisory is unlikely within 90 days. Australian Security Intelligence Organisation (ASIO)'s public naming of a foiled Australia-United Kingdom-United States Security Partnership (AUKUS) cultivation attempt marks a shift toward overt deterrent confrontation of foreign services.


Allied Intelligence

IISS Report Accuses Russia of 15-Month Drone Espionage Campaign Over RAF Bases and NATO Nuclear Sites Using Cargo Vessel

BLUF: Formal public attribution to Russia remains unlikely within 60 days because the report's lone confirmed launch against 143 unresolved incidents hands allied governments the ambiguity they need to defer.

The International Institute for Strategic Studies (IISS) documented 144 drone incidents across 13 European states between August 2024 and February 2026, concluding it is "highly likely" Russia ran a coordinated UAV surveillance campaign launched from vessels in its sanctioned shadow fleet 1. The report ties the cargo vessel HAV Dolphin, docked near Hull, to November 2024 drone incursions over RAF Lakenheath, RAF Mildenhall, RAF Fairford and RAF Feltwell, and identifies further incidents near France's Île Longue submarine base and nuclear-linked NATO air bases in Belgium and the Netherlands, though Germany's own search of the HAV Dolphin found nothing linking the vessel to any launch 123. Investigators could not track the drones' signals or launch sites at the time, and a Whitehall source described the technology as "sophisticated" with no confirmed attribution 2. A single Swedish Navy incident in February 2026 in the Öresund Strait, in which a drone launched from the Russian vessel Zhigulevsk was tracked and jammed near the docked carrier Charles de Gaulle, is the only incident in the dataset tied to an observed launch from a named platform; Danish, Belgian (military intelligence judged only about 42 of 250 sightings legitimate) and Dutch investigations into other cited incidents found no confirmed drone wreckage or hostile aircraft, per DroneXL's review of the report 3.

Analyst Note: Formal NATO attribution is unlikely within the next 60 days, since the campaign's operational advantage rests on exactly the ambiguity this report cannot resolve. Moderate confidence reflects a single documented launch platform against 143 unattributed incidents, several of which national investigations have already closed without confirming drone activity. Absent a recovered airframe or intercepted command link, governments retain incentive to acknowledge incursions while withholding attribution, as UK and US officials have already done. The Zhigulevsk case sets an evidentiary bar the rest of the dataset does not meet, and that gap will likely shape how allied statements are worded through September.

Sources:

1: Russia's UAV Campaign Over Europe - IISS (International Institute for Strategic Studies)

2: Russian drones spy on RAF bases and Britains nuclear weapons - GB News

3: IISS Report Names Real Russian Drone Incidents And Phantom Ones, And The Difference Is The Story - DroneXL

Prior Reporting - [IISS Report Says Russian Shadow Fleet Likely Launched Drone Surveillance Missions Over U.S. Bases in England](https://www.thedefensenews.com/IISS-Report-Says-Russian-Shadow-Fleet-Likely-Launched-Drone-Surveillance-Missions-Over-Over-US-Bases-in-England/) (2026-07-03) - [Russia "Highly Likely" Behind Drone Incursions Over U.S. Bases In England Report Concludes](https://www.twz.com/air/russia-highly-likely-behind-drone-incursions-over-u-s-bases-in-england-report-concludes) (2026-07-02) - [Putin's shadow fleet used to launch drones to spy on British nuclear and military sites](https://www.lbc.co.uk/article/putins-shadow-fleet-drones-spy-nuclear-5HjdcQ7_2/) (2026-07-02) - [New Report Blames Russia's Shadow Fleet for Europe Drone Incursions](https://theaviationist.com/2026/07/03/europe-drone-incursions-russia-shadow-fleet/) (2026-07-03)

Book Reveals CIA and Dutch Intelligence Had Advance Warning of Ukrainian Nord Stream Sabotage Operation Diameter

BLUF: Documented pre-attack contact between CIA officers and Operation Diameter's leadership transforms Western governments from bystanders into knowing participants whose inaction now carries legal and diplomatic exposure.

Wall Street Journal correspondent Bojan Pancevski's book "The Nord Stream Conspiracy," released last month, reports that Dutch military intelligence intercepted information about the Ukrainian sabotage plot months before the September 2022 attack and shared it with the CIA 1. The CIA relayed the tip to Germany's BND but labeled the source group "low-confidence" and "rogue," and a senior CIA official told Pancevski the agency warned Ukrainian services against the operation and believed it had been called off 1. Pancevski reports the CIA's Kyiv station chief separately confronted the operation's leader, referred to as "the General," who replied he "would not officially be part of Operation Diameter" 1. The book identifies the chain of command as running through the General to then-commander-in-chief Valeriy Zaluzhny, now Ukraine's ambassador in London, while leaving open whether President Zelensky had knowledge of the plan 1.

Analyst Note: Confirmation that Dutch and US intelligence held specific pre-attack warning of Operation Diameter narrows the gap between passive awareness and operational complicity, undercutting Washington's and The Hague's public posture of surprise. A CIA station chief's direct confrontation with the operation's leader before the bombing contradicts the "rogue, low-confidence" framing officials used to justify inaction, though that contemporaneous labeling may reflect a genuine intelligence assessment rather than after-the-fact minimization of agency culpability. The account hands Ukrainian defendants a state-authorization argument for the ongoing German prosecution, while the chain of command tracing through Zaluzhny, without resolving Zelensky's knowledge, keeps political liability contained to military leadership as he positions for a possible presidential run. Sourcing traces to a single book-length account, with secondary outlets amplifying rather than independently confirming the claims.

Sources:

1: The conspiracy of silence surrounding the Nord Stream bombings - The Spectator Australia

The Nord Stream Conspiracy: The Inside Story of the Explosions That Shook the World - Bojan Pancevski (Celadon Books / Macmillan)

The Nord Stream Conspiracy: The Inside Story of the Explosions That Shook the World - Bojan Pancevski (Celadon Books / Macmillan)

The Nord Stream Sabotage: Mystery Attacks Explained - The Cipher Brief

The Nord Stream Conspiracy: An international war story in blockbuster prose - Business Standard

WSJ Journalist Publishes Book on Nord Stream Pipeline Sabotage - AllSides

Prior Reporting - [Germany charges Ukrainian suspect in Nord Stream sabotage case](https://kyivindependent.com/germany-charges-ukrainian-suspect-in-nord-stream-sabotage-case/) (2026-07-01) - [German prosecutors charge Ukrainian suspect over Nord Stream explosions](https://www.aljazeera.com/news/2026/7/2/german-prosecutors-charge-ukrainian-suspect-over-nord-stream-explosions) (2026-07-02) - [Man suspected of Nord Stream pipeline sabotage charged in Germany](https://www.thenationalnews.com/news/europe/2026/07/01/nord-stream-alleged-saboteur-is-charged-in-germany/) (2026-07-01) - [Germany charges Ukrainian over Nord Stream pipeline blasts](https://www.japantimes.co.jp/news/2026/07/02/world/germany-ukrainian-nord-stream-pipeline/) (2026-07-02) - [Nach Nord-Stream-Anschlägen erste Anklage erhoben](https://www.tagesspiegel.de/politik/bundesgerichtshof-nach-nord-stream-anschlagen-erste-anklage-erhoben-15783260.html) (2026-07-01)

ASIO Director-General Warns Australia Threat Environment Is Dynamic Diverse and Degraded as Agency Seeks Expanded Powers

BLUF: Burgess's decision to publicly expose a foiled AUKUS cultivation operation signals ASIO is shifting from quiet counterintelligence to overt deterrence, accepting operational disclosure costs to impose reputational penalties on hostile services.

ASIO Director-General Mike Burgess used his seventh annual threat assessment address, delivered on June 24, to describe Australia's security threat environment as increasingly interconnected, citing more than 40 active priority counter-terrorism cases in a single randomly selected week alongside foreign interference operations 1. Burgess detailed a decade-long coercive-repatriation intimidation campaign against an individual, an Iranian proxy arson campaign against Jewish targets directed by a former Australian resident based in Iraq who was recruited through IRGC-linked militia networks for his wealth and criminal connections, foreign hacking of critical infrastructure, and an attempted cultivation of an Australian security clearance holder to compromise AUKUS secrets 1. The foreign officer, posing as a consultant, first paid the clearance holder for reports on Australia-Pacific relations before seeking AUKUS Pillar 1 progress, Pillar 2 technology details, investment figures, and trilateral government relations; the clearance holder reported the approach to ASIO, continued feeding back tradecraft information, and ASIO officers then used his phone to call the officer directly, confronting her with knowledge of her identity and demanding she cease targeting Australians 1. Burgess also said ASIO is in talks with Home Affairs Secretary Stephanie Foster on reforming the national terrorism threat-level system, arguing the current "Probable" tier, defined as a greater than 50 percent chance of an attack or attack planning within 12 months, understates a threat environment that is simultaneously degrading and diversifying 1. Separate reporting noted his remarks addressed rising antisemitism, inflammatory rhetoric linked to protest violence, and radicalized individuals using easily obtained weapons 2.

Analyst Note: Burgess's public naming of a foiled AUKUS cultivation attempt, and ASIO's decision to confront the responsible foreign officer directly rather than through back-channel demarches, marks a shift toward overt deterrence, raising the cost for services targeting cleared personnel in allied programs. Reporting rests on ASIO's own transcript, with secondary outlets offering summary rather than independent corroboration. The cultivation attempt, the confrontation, and confirmed talks with Home Affairs on reforming the "Probable" threat tier are details absent from initial Reuters and Guardian coverage, which centered on threat-environment degradation without naming specific counterintelligence actions. Whether tier reform advances cannot be assessed with confidence: no timeline or ministerial commitment has surfaced beyond confirmation that talks are underway. The disclosures may function primarily as deterrent signaling to foreign services and domestic audiences rather than as a preview of imminent legislative change.

Sources:

1: Many, varied audiences for ASIO's Annual Threat Assessment - The Strategist (ASPI)

2: Far-Left Activists Antisemitism and Expanding Powers All Featured in ASIOs Threat Assessment - Sydney Criminal Lawyers

Director-General's Annual Threat Assessment 2026 - ASIO

Prior Reporting - [Australias security environment degrading, spy chief warns](https://whbl.com/2026/06/24/australias-security-environment-degrading-spy-chief-warns/) (2026-06-25) - [ASIO, Mike Burgess reveals how foreign spy sought AUKUS secrets in foiled plot](https://www.canberratimes.com.au/story/9298565/asio-mike-burgess-reveals-how-foreign-spy-sought-aukus-secrets-in-foiled-plot/) (2026-06-25) - [A 'present, costly danger': ASIO director details 'relentless' acts of international espionage](https://www.sbs.com.au/news/article/tip-of-the-iceberg-asio-director-reveals-the-espionage-acts-costing-australia-billions/2hpogecyc) (2026-06-25)

IC Workforce & Leadership

Acting DNI Pulte Begins Mass Purge Notifying Dozens of ODNI Officials of Termination

BLUF: Unlikely to face judicial reversal within 90 days absent named plaintiffs, the purge strips ODNI of institutional expertise and accelerates its reduction to a pass-through for agency reporting.

Acting Director of National Intelligence Bill Pulte began notifying dozens of ODNI officials of their terminations on Thursday, according to an intelligence official cited by MS NOW 12. CNBC reported the same account, noting the firings target career officials the administration believes are withholding complete intelligence assessments from leadership, whom officials characterize as "deep state" 3. The move follows Pulte's removal of six political appointees under former DNI Tulsi Gabbard two weeks earlier and comes after Trump installed Pulte as acting DNI on June 19 3. Four former senior officials told MS NOW, as relayed by Raw Story and Conservative Treehouse, that they had never known ODNI staff to withhold intelligence from superiors, and one questioned how Pulte, who has no intelligence background, could identify such conduct within weeks of arriving 14. One likened the purge to "taking over a hospital and firing dozens of surgeons in a matter of days," while another dismissed the withholding allegation as "a fantasy" that harms national security 14.

Analyst Note: The purge is unlikely to face a court order blocking or reinstating terminated ODNI officials within 90 days, absent named plaintiffs or filed litigation. Low confidence reflects single-source origination and the absence of any filed lawsuit, named plaintiff, or retained counsel as of publication. The stated "deep state" rationale rests on assertions from anonymous leadership sources, not documented instances of withholding, and multiple former officials with institutional knowledge of ODNI workflows dispute that such conduct occurs. Pulte's removal of career officials without intelligence background compounds the earlier ouster of Gabbard-era political appointees, deepening the office's dependence on the eighteen agencies it draws analysis from rather than collects itself. The purge parallels the separate firings for alleged intelligence withholding and the 4th Circuit reinstatement order on the earlier DEI-related terminations.

Sources:

1: Unnerved ex-officials uncork stark analogy as Trump spy chief cleans house on deep state - Raw Story

2: Trump's Acting Intel Chief Begins Purge of Top Officials, MS NOW Reports - Mediaite

3: Acting DNI Pulte fires dozens of intelligence officials: MS Now - CNBC

4: REPORT: Acting DNI Bill Pulte Fires Dozens of ODNI Staff for Politicizing Intelligence, Insubordination, Gross Misconduct - The Conservative Treehouse

Acting DNI Bill Pulte begins firing dozens of intelligence officials - MS NOW

Prior Reporting - [Pulte Dismisses Top ODNI Experts on World's Hot Spots](https://www.spytalk.co/p/pulte-dismisses-top-odni-experts) (2026-06-25) - [ODNI deputy director pushed out amid Pulte cuts](https://www.nextgov.com/people/2026/06/odni-deputy-director-pushed-out-amid-pulte-cuts/414412/) (2026-06-25) - [Firings underway at Office of Director of National Intelligence, source says](https://www.ms.now/news/director-national-intelligence-office-firings-pulte-trump) (2026-06-23) - [Top intelligence agency begins mass firings under new Trump appointee, source says](https://www.nbcnews.com/politics/trump-administration/odni-begins-firings-under-bill-pulte-director-national-intelligence-rcna351290) (2026-06-23) - [Trump's acting director of national intelligence begins firings at agency, sources say](https://abcnews.com/Politics/trumps-acting-director-national-intelligence-bill-pulte-begins/story?id=134115343) (2026-06-23)

IC Technology

Chinese-Linked ToddyCat APT Deploys Umbrij Tool to Steal Government Cloud Email Tokens Via OAuth Hijacking

BLUF: Umbrij's session-hijacking approach renders credential-focused defenses irrelevant and is simple enough for any post-exploitation actor to replicate against cloud email at scale.

Kaspersky's Securelist reported that ToddyCat, tracked since prior campaigns targeting corporate email, developed a tool called Umbrij to compromise Gmail accounts via the Google API rather than by stealing credentials directly 1. Kaspersky said the tool connects to a victim's browser in headless mode through a remote debugging port, then submits a series of requests that yield an Open Authorization (OAuth) authorization code, which the attackers exchange for an access token to reach Gmail resources under the user's existing session; Kaspersky labeled the technique Shadow Token via Remote Debug 1. Umbrij, a ConfuserEx-obfuscated .NET Dynamic Link Library (DLL), is deployed via DLL sideloading alongside signed executables including a Bitdefender ConnectAgent component, a Visual Studio testing tool, and the discontinued GoogleDesktop.exe; Kaspersky identified three variants targeting Chrome and Edge that disguise their OAuth requests using client IDs belonging to legitimate Google Workspace Migration/Sync for Outlook tools, requiring only that the targeted user remain logged into Gmail 12. Kaspersky discovered the tool during a threat hunting operation after spotting a scheduled task impersonating its own endpoint security software, and The Hacker News and GBHackers both relayed the findings without independent details 123.

Analyst Note: Umbrij marks ToddyCat's shift from credential theft to API-level session hijacking that leaves no signature for credential-focused monitoring to catch, and because it rides ordinary DLL sideloading rather than actor-specific tooling, the technique is straightforward for other espionage actors with post-exploitation access to replicate. Kaspersky's reverse engineering is the only primary technical account; outlets relaying the findings add no independent corroboration. The tool's dependence on already-compromised hosts and duplicated tokens suggests a post-exploitation collection capability rather than a new initial-access vector: existing hardening against ToddyCat's earlier intrusion methods may already limit its reach. Kaspersky's disclosed artifacts, scheduled task names, hashes, and command-line parameters give enterprise defenders concrete hunting signatures for remote-debugging-port abuse and signed-executable sideloading, a detection axis distinct from the credential-theft focus this technique specifically evades.

Sources:

1: How the ToddyCat APT group gains access to Gmail accounts - Securelist (Kaspersky)

2: ToddyCat Uses Shadow Token via Remote Debug to Compromise Gmail Accounts - GBHackers

3: ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API - The Hacker News

ToddyCat APT Umbrij Tool Steals Cloud Email Tokens - Security Online

IC Workforce & Oversight

Federal Appeals Court Orders Reinstatement of 19 CIA and ODNI Officers Fired After Diversity Assignments Ruling Due Process Violated

BLUF: An administration appeal is very likely within one month, but the ruling already narrows executive authority to terminate intelligence officers for policy assignments directed by prior leadership.

The 4th Circuit Court of Appeals ruled 2-1 on Thursday that the CIA and the Office of the Director of National Intelligence must reinstate 19 career intelligence officers fired over prior diversity, equity, inclusion and accessibility assignments, finding the agencies violated their own termination regulations by denying the employees a right to reassignment or appeal 123. The ruling upheld a preliminary injunction from a lower-court judge. The 19 are among 58 CIA and ODNI officers placed on paid administrative leave to implement a DEI-elimination executive order Trump signed shortly after returning to office in January 2025, and they remain on leave pending the case 123. The officers had argued the firings were arbitrary and unsupported by any evidentiary record, and said they should have been reassigned rather than penalized for duties ordered by a prior administration 1. Government attorneys had contended CIA Director John Ratcliffe and acting Director of National Intelligence Bill Pulte held unfettered authority to terminate employees with or without cause 1. Kevin Carroll, counsel for the officers, called on Ratcliffe and Pulte to reinstate the employees. NBC News reported the timing of any rehiring remains unclear amid an expected administration appeal 1.

Analyst Note: The reinstatement order very likely triggers an appeal to the full 4th Circuit or the Supreme Court within one month, given Judge Niemeyer's dissent inviting further review and the administration's pattern of contesting adverse intelligence-personnel rulings. Moderate confidence reflects a single documented dissent signal without direct evidence of Justice Department deliberations. Absent a stay, Ratcliffe and Pulte face a near-term choice between complying with reinstatement and reassignment obligations or risking contempt exposure while litigation continues. The ruling constrains executive discretion over Diversity, Equity, Inclusion, and Accessibility (DEIA)-linked personnel actions across the intelligence community pending any higher-court reversal.

Sources:

1: Court orders Trump administration to rehire fired intelligence officers - NBC News

2: Appeals court sides with intelligence officers fired for working on DEI - The Hill

3: US Appeals Court Prevents Firing of 19 Intelligence Officers Assigned to DEI Programs - U.S. News & World Report

US appeals court prevents firing of 19 intelligence officers assigned to DEI programs - Reuters

Appeals Court Orders Trump Administration to Rehire Fired Intelligence Officers - YourNews

Prior Reporting - [Appeals Court Blocks Trump Administration From Firing 19 Intelligence Officers In DEI Roles](https://yournews.com/2026/07/02/7093070/appeals-court-blocks-trump-administration-from-firing-19-intelligence-officers/) (2026-07-02) - [US appeals court prevents firing of 19 intelligence officers assigned to DEI programs](https://wtvbam.com/2026/07/02/us-appeals-court-prevents-firing-of-19-intelligence-officers-assigned-to-dei-programs/) (2026-07-02) - [Appeals court says DEI employees can apply for other jobs in intelligence community](https://www.washingtontimes.com/news/2026/jul/2/appeals-court-says-dei-employees-apply-jobs-intelligence-community/) (2026-07-02) - [Intelligence Officers With DEI Links Win Appeal Over Firings](https://news.bloomberglaw.com/litigation/intelligence-officers-with-dei-links-win-appeal-over-firings) (2026-07-02)

Adversary Intelligence

Former Kyrgyz Security Chief Sentenced for Attempting to Violently Seize Power From Ally President

BLUF: Japarov's calibrated use of probation over imprisonment neutralizes Tashiev as a rival without creating a political martyr, and a Kyrgyz appellate court will likely uphold the sentence by year-end.

A Bishkek district court on Thursday convicted former security chief Kamchybek Tashiev and seven co-defendants, including former Prosecutor General Kurmankul Zulushev and former Parliamentary Speaker Nurlanbek Turgunbek uulu, of attempting to violently seize power, in a case tied to a February open letter signed by 75 officials and public figures calling for early presidential elections 1234. The court sentenced Tashiev to four years in prison with confiscation of property but immediately commuted the term to three years' probation, and handed identical sentences to Zulushev and Turgunbek uulu 1234. All eight defendants were acquitted of a separate abuse-of-office charge, and five who had been held in custody were released from the courtroom after their travel restrictions were downgraded 24. President Sadyr Japarov dismissed Tashiev from his posts as State Committee for National Security (Kyrgyzstan) (GKNB) chief and deputy cabinet chairman in February, and prosecutors had sought nine-year sentences for all eight before the reduced verdicts; Tashiev's lawyer said he intends to appeal 12.

Analyst Note: The commuted sentence entrenches Japarov's control by removing Tashiev as an independent power center while avoiding a martyr narrative that could galvanize his base ahead of January's election. An appellate court will likely uphold the three-year probation by December 31 rather than convert it to imprisonment or acquittal, since the verdict already reflects a negotiated outcome between prosecutors' nine-year demand and the probation result. Analytic confidence is high, resting on the acquittals, custody releases, and identical treatment of all eight defendants signaling a coordinated resolution rather than contested litigation.

Sources:

1: Former Kyrgyz Security Chief Sentenced for Trying to Violently Seize Power - OCCRP

2: Kyrgyz Court Convicts Former Security Chief Tashiyev, Parliamentary Speaker, and Six Others - The Times of Central Asia

3: Bishkek court convicts Kamchibek Tashiev, sentences him to four years with property confiscation - Mezha

4: Former Security Chief Kamchybek Tashiev Granted Probation in Bishkek Court - Kursiv Media

Первомайский райсуд Бишкека вынес приговор по уголовному делу о «письме 75» (Pervomaisky District Court of Bishkek issues verdict in the 'Letter 75' criminal case) - Open.kg

IC Oversight & Policy

Clinton Warns of Naked Partisan Takeover of DNI as Acting Director Pulte Continues Intelligence Community Restructuring

BLUF: Clinton's call for agency personnel to withhold intelligence from an acting DNI signals Democratic intent to contest IC leadership through litigation and bureaucratic friction rather than Senate procedure alone.

Former Secretary of State Hillary Clinton, appearing on the Democracy Docket podcast with host Marc Elias, called Acting DNI Bill Pulte "very dangerous," a "loose cannon," and said his appointment amounts to "a naked partisan takeover" of the office 12. Clinton said she hopes career and political appointees across intelligence agencies are "slow-walking or refusing to share information" with Pulte, who has access to reporting from all 17 intelligence agencies as acting director 123. She noted Pulte has no intelligence experience and is serving in an acting capacity pending Senate confirmation of Trump's nominee, Jay Clayton 2. Clinton also called for a lawsuit challenging Pulte's qualifications under the statute governing the DNI position, arguing he is "manifestly unqualified" even for the acting role 2.

Analyst Note: Clinton's remarks open the confirmation fight over Clayton's nomination, casting Pulte's caretaker tenure as illegitimate before Senate proceedings begin. Her appeal for agency personnel to withhold information from a sitting acting DNI, if heeded, would breach ODNI's coordinating function across the seventeen-agency community, and her push for litigation tests statutory language on acting officials that Democrats have not previously invoked against IC leadership. No lawsuit has been filed and no agency has confirmed altering information-sharing practices. The Hill's account, drawn from a single podcast appearance with no independent corroboration or agency response, reads at least as plausibly as an effort to mobilize Democratic opposition ahead of Clayton's confirmation as a genuine precursor to legal action.

Sources:

1: Hillary Clinton knocks Pulte: We should definitely be worried about everything - The Hill

2: 'Be Worried About Everything': Hillary Clinton Sounds Alarm Over Trump's National Security Chief - Mediaite

3: Hillary Clinton urges federal employees to "refuse to share information with Pulte" - Just The News

Hillary Clinton Urges Intel Not to Share Data With Pulte - Newsmax

COLLECTION GAPS

UNCLASSIFIED // OPEN SOURCE