//
OFFLINE — VIEWING CACHED CONTENT
← Back to Archive

IC BRIEF

Current as of 0317 EDT (UTC-04), Friday 10 July 2026

Contents

10 stories from 37 sources across 33 organizations


KEY JUDGMENTS

Iranian intelligence operations documented across Germany, the Netherlands, and the United Kingdom, combined with Israeli intelligence warning of a new assassination plot against President Trump, establish the Islamic Revolutionary Guard Corps (IRGC) as the primary operational threat to allied interests this cycle. These operations arrive while the US intelligence community operates under an acting director whose confirmation remains genuinely uncertain. A publicly confirmed Iran-linked attempt on Trump is unlikely by October 2026. High confidence reflects multi-source convergence on the intelligence-sharing episode despite unvetted plot details and voiced IC skepticism.

European states are assembling prosecutorial and designation tools faster than at any point in the IRGC's operational history in Europe, with Hamburg courtroom evidence, the EU's February terrorist designation, and the UK State Threats Act converging. No government has exercised these authorities against the IRGC. Independent US validation of the Israeli intelligence would shift allied coordination from bilateral protection toward networked prosecution.

North Korean orders expanding nuclear forces and intelligence capabilities, Main Intelligence Directorate (Russia) (GRU) exposure in Brazil, and Chinese Mustang Panda intrusions against Indian critical infrastructure indicate adversary services are active across four fronts. The IC leadership vacancy constrains the coordinated assessment capacity these concurrent threats demand.


Adversary Intelligence

Kim Jong Un Orders Improvements to Nuclear Weapons, Navy, and Intelligence Agency at Central Military Commission Meeting

BLUF: Kim's seven signed orders convert the Ninth Congress nuclear policy into operational taskings, coupling warhead expansion with an intelligence mandate aimed squarely at Seoul and Washington.

Kim Jong Un presided over the first enlarged meeting of the ninth Workers' Party Central Military Commission on Thursday, signing seven orders on "important military measures," according to Korean Central News Agency (KCNA) reporting relayed by NK News 1. The meeting decided to expand North Korea's nuclear forces "quantitatively and qualitatively," renew the technical infrastructure of combat systems, and standardize and modernize military bases 2. It also called for expanding the functions and intelligence-gathering capabilities of the General Reconnaissance and Intelligence Bureau against "potential enemies," per KCNA accounts carried by Bloomberg and Korea JoongAng Daily 34. Additional agenda items covered naval base construction and shipyard upgrades, along with a personnel reshuffle affecting senior military posts 23.

Analyst Note: Kim's order set operationalizes the Ninth Congress's nuclear buildup, tasking the General Reconnaissance and Intelligence Bureau's expanded mandate explicitly against "potential enemies," language Pyongyang reserves for Seoul and Washington. An unspecified reshuffle of senior military posts alongside base-standardization directives points to Kim tightening command structures ahead of execution rather than restating existing policy, while naval base construction and shipyard upgrades running in parallel suggest a coordinated conventional-nuclear modernization push rather than an isolated weapons announcement. Reporting rests on KCNA's own release, with NK News, Bloomberg, Korea JoongAng Daily and Reuters all functioning as secondary pickups of the same state account rather than independent corroboration, and the rhetoric may instead be primarily domestic messaging reinforcing Kim's military-first narrative rather than signaling an imminent operational shift. No named officials or timeline surface, leaving the scale and sequencing of implementation unclear.

Sources:

1: Kim Jong Un oversees military meeting on improving nukes, navy and intel agency - NK News

2: North Korea Decides on Measures to Expand Nuclear Forces, KCNA Reports - Reuters

3: North Korea to expand intelligence agency role against 'potential enemies' under Kim Jong-un - Korea JoongAng Daily

4: Kim Jong Un Orders North Korea Spy Agency to Expand Intelligence Operations - Bloomberg

First Enlarged Meeting of Ninth WPK Central Military Commission Held - KCNA

Quds Force Commander Qaani Makes Rare Public Appearance at Khamenei Funeral Amid Mossad Spy Suspicions

BLUF: Qaani's orchestrated visibility across five funeral cities signals Tehran has chosen institutional continuity over counterintelligence caution during a succession window when projecting IRGC cohesion outweighs compromise risk.

Quds Force commander Esmail Qaani appeared at Khamenei's funeral ceremonies in Qom on July 6 alongside President Masoud Pezeshkian, and Iranian state media quoted him praising what he called the spiritual bond between Iran and Iraq as processions moved through Najaf and Karbala 1. IRGC-affiliated Tasnim News published images on Thursday it said showed Qaani at Mashhad airport as Khamenei's coffin arrived for burial ceremonies 2. JFeed reported Qaani has kept an unusually low public profile since the war began on February 28 and has been described as a suspected Mossad spy 1. Iranian authorities said they expect between eight and ten million attendees at the Mashhad burial 1.

Analyst Note: Qaani's sustained appearances across five funeral cities mark a sharp break from his near-total public absence since the war began in February, positioning him as a visible institutional anchor while Mojtaba Khamenei's succession remains unconfirmed by any public appearance. State and IRGC-aligned outlets are amplifying his role in Najaf, Karbala, Qom and Mashhad to project operational continuity to domestic and Iraqi Shia audiences, though the convergence rests on one openly state-linked visual source and one unattributed narrative account rather than independent corroboration. The re-emergence complicates without resolving the Mossad-spy suspicions that shadowed his prior invisibility, since exposure at this scale would be an unusual choice for a suspected compromised actor; the display may instead be stage-managed reassurance orchestrated by Tehran to project unity and inoculate him against scrutiny rather than evidence those suspicions are settled.

Sources:

1: Rarely Seen Quds Force Chief (And Suspected Mossad Spy) Qaani Featured Throughout Khamenei Funeral - JFeed

2: IRGC-affiliated Tasnim publishes images it says show Qaani in Mashhad - Iran International

German Court Hears IRGC Quds Force Recruited Operative to Burn Kosher Shop and Surveilled Jewish Leaders as BKA Details Wider Plot

BLUF: Courtroom evidence now documents the full Quds Force attack cycle on European soil, giving allied services actionable tradecraft signatures for detecting parallel networks still unidentified.

A German court heard testimony Monday, in the second hearing of the trial, that an alleged Islamic Revolutionary Guard Corps Quds Force operative sought a Palestinian or Somali woman facing financial hardship to burn a Jewish kosher grocery store for roughly 30,000 Danish kroner, about 4,000 euros 1. A senior Federal Criminal Police Office (BKA) investigator testified in Hamburg's Higher Regional Court that the arson plan was part of a wider operation involving surveillance of Jewish figures and discussions of obtaining a weapon 1. Prosecutors have charged defendant Ali S., a 54-year-old Afghan-born Danish national, with espionage, sabotage-related espionage, and attempted participation in murder and arson, while co-defendant Tawab M., a 42-year-old Afghan national, faces a charge of attempted participation in murder 1. The BKA witness said phone data, travel records and surveillance images showed Ali S. made repeated trips to Iran including a January journey routed through Turkey, met Quds Force-linked officials including the official responsible for Israel-related affairs, searched for kosher shops and for the address of Central Council of Jews in Germany head Josef Schuster, photographed German-Israeli Society head Volker Beck, and that the trial is expected to run through October 1.

Analyst Note: Courtroom testimony converts prior domestic intelligence warnings about expanding Iranian operations in Europe into documented case specifics, giving German and allied security services a template of Quds Force tradecraft: financially desperate cutouts, weapons inquiries, and pre-attack reconnaissance of communal leaders. The proceedings identify unnamed handlers and contacts, including figures known only as Haji Ali, Kazem, and Vahid, whose reach outside Germany remains unresolved. Testimony continuing through October will surface further investigative detail on the weapons dimension the court has yet to examine. The case substantiates, rather than merely repeats, Germany's public assessment that Tehran is positioned to expand intelligence and terrorist activity in Europe.

Sources:

1: Alleged IRGC plot sought woman to burn kosher shop German court hears - Shabtabnews

Alleged IRGC plot sought woman to burn kosher shop, German court hears - Iran International

Prior Reporting - [2 men go on trial in Germany over alleged Iran-backed plots targeting Jews](https://www.timesofisrael.com/2-men-go-on-trial-in-germany-over-alleged-iran-backed-plots-targeting-jews/) (2026-06-26) - [German Court Tries Two Men over Alleged Iran-backed Anti-Jewish Plots](https://english.aawsat.com/world/5288843-german-court-tries-two-men-over-alleged-iran-backed-anti-jewish-plots) (2026-06-26) - [Man on trial accused of tracking Jewish figures as targets for Iran-backed attacks](https://www.thejc.com/news/world/tracking-jewish-figures-iran-backed-germany-fkpnjzvy) (2026-06-26) - [Germany charges suspected Iranian spies over plot to kill Jewish community leaders](https://www.ynetnews.com/article/bjllct21zl) (2026-06-26) - [Hanseatisches Oberlandesgericht: Hauptverhandlung 'Geheimdienstliche Agententätigkeit für den Iran' beginnt am 26. Juni 2026](https://justiz.hamburg.de/gerichte/oberlandesgericht/gerichtspressestelle/hanseatisches-oberlandesgericht-hauptverhandlung-geheimdienstliche-agententaetigkeit-fuer-den-iran-beginnt-am-26-juni-2026-1190446) (2026-06-26)

Foreign Policy Investigation Documents Escalating IRGC Threats and Surveillance Against Iranian Dissidents Across Europe After Iran War

BLUF: Europe's IRGC terrorist designation and pending UK proscription legislation remain untested against Iran's criminal-proxy operational model, leaving governments locked in unsustainable case-by-case dissident protection.

Iranian dissidents across Europe reported intensified threats, surveillance, and harassment from Iran since the February war among Iran, Israel, and the United States, according to a Foreign Policy investigation 1. In the Netherlands, activist Soran Mansournia said he received a direct phone threat from a Farsi-speaking caller on April 9 and has been under Dutch police protection since the 12-day war 1; Dutch officials said they could not rule out Iranian involvement in a March shooting of an Iranian-descent regime critic in Schoonhoven 1. In the UK, activist Vahid Beheshti said London police raised his threat level after the war began, and journalist Pouria Zeraati relocated to Israel following a 2024 stabbing outside his London home 1. EU counterterrorism coordinator Bartjan Wegter said Iranian hybrid tactics against dissidents, including cybersurveillance and assassination attempts using criminal proxies for deniability, have intensified in recent years 1. The EU designated the IRGC a terrorist organization on February 19, and UK Defense Secretary Dan Jarvis said in May that proscription-like legislation would be fast-tracked 1.

Analyst Note: Sustained Iranian transnational repression is pushing Dutch and British authorities toward reactive protection of individual dissidents rather than disruption of the IRGC networks directing the threats, with escorts assigned and threat levels raised in both countries but no specific attack, including the Schoonhoven shooting, publicly attributed to Iranian state actors. Foreign Policy remains the sole source, and while its correspondent conducted first-person interviews with named dissidents and an EU counterterrorism coordinator, no reporting in the record qualifies as primary, leaving government attribution unconfirmed. The pattern may instead reflect heightened dissident anxiety and self-reporting after the war rather than a genuine rise in Iranian operational tempo. The EU's IRGC terrorist designation and London's pending proscription legislation supply new sanctions and prosecutorial tools, but neither has yet shown capacity to deter criminal-proxy operations built for deniability.

Sources:

1: Iran Is Still Fighting a War Against Dissidents Abroad - Foreign Policy

Adversary Intelligence Operations

Chinese APT Mustang Panda Deploys New ZOHOMURK and MINIRECON Malware Against Indian Government and Hydropower Infrastructure

BLUF: By routing command traffic through Open Authorization (OAuth)-authenticated Zoho accounts, Mustang Panda has rendered India's domain-blocking defenses structurally blind to these intrusions.

GBHackers reported that Acronis Threat Research Unit identified two espionage campaigns by Mustang Panda targeting Indian government offices and hydropower-sector organizations, including entities cooperating with Taiwanese institutions, using spear-phishing archives with geopolitically themed lures 12. Both campaigns used a new loader, SHARDLOADER, to sideload malicious DLLs through signed applications, a Solid PDF Creator executable in the hydropower campaign and a Citrix Receiver binary in the Taiwan-MOU campaign, deploying MINIRECON, a Toneshell-derived implant using WebSocket-over-HTTPS command and control 12. A second malware family, ZOHOMURK, authenticates to attacker-controlled Zoho WorkDrive accounts using embedded OAuth credentials to receive tasking and exfiltrate data through the legitimate cloud platform 12. Acronis attributed the intrusions to Mustang Panda with high confidence, reflecting shared tradecraft, code overlaps with prior Toneshell implants, and Command and Control (C2) infrastructure sharing a network block previously linked to the group by IBM X-Force, with active beaconing observed June 12-22, 2026, and coordinated with India's Indian Computer Emergency Response Team (CERT-In) to notify affected parties and share indicators, including the command-and-control domain couldinstallup[.]com 12.

Analyst Note: Mustang Panda's pivot to Zoho WorkDrive as a command channel defeats domain-blocklist defenses, since OAuth-authenticated traffic to a mainstream cloud platform is indistinguishable from routine business use without application-layer inspection. Parallel tracks against hydropower operators and Taiwan-cooperation government offices indicate deliberate targeting of distinct strategic portfolios rather than opportunistic scanning, and code continuity linking MINIRECON and SHARDLOADER to prior Toneshell implants points to a shared development pipeline within the group's toolset. Reporting remains single-sourced to Acronis TRU, with other outlets merely repeating its findings, though Acronis has now released specific indicators, including the couldinstallup[.]com domain, and coordinated with CERT-In to notify victims, shifting the campaign from detection into remediation. A separate operator reusing shared Toneshell code cannot be ruled out, since the high confidence attribution rests on tradecraft and code overlap rather than infrastructure or signals evidence, leaving most targeted organizations without the OAuth-abuse detection capability needed to catch this activity.

Sources:

1: Mustang Panda Targets India's Government and Energy Sectors With ZOHOMURK and MINIRECON - GBHackers

2: Mustang Panda Uses ZOHOMURK and MINIRECON Malware to Threaten India Critical Infrastructure - SharkStriker

Mustang Panda targets India's government and energy sectors with ZOHOMURK and MINIRECON - Acronis Threat Research Unit (TRU)

Prior Reporting - [Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks](https://thehackernews.com/2026/06/mustang-panda-uses-zoho-workdrive-as.html) (2026-06-29)

Brazil Authorizes Expulsion of GRU Officer Sergey Cherkasov Who Posed as Student to Infiltrate ICC and Johns Hopkins University

BLUF: Brazil's expulsion order gives Moscow a path to recover a trained illegal without the political cost Brasília would absorb by granting either side's extradition request.

Brazil's Justice Ministry published Portaria 6.737 in the official gazette Monday, signed by migration coordinator Alessandra Teixeira de Araújo, ordering Cherkasov's expulsion and barring his return for 30 years 12. Outlets diverge on his sentence for identity fraud: AFP, The Defense Post and Rádio Itatiaia report 15 years 234, while the Rio Times reports it was reduced to five 1. The order takes effect only once Cherkasov completes his sentence or a court grants early release, and names no destination country 12; his lawyers plan to challenge it before Brazil's Supreme Court 1. The US State Department said Wednesday it was "deeply concerned" by the decision, noting Brazil's Supreme Court had authorized Russia's 2022 extradition request before Washington's followed in 2023 1.

Analyst Note: Expelling rather than extraditing Cherkasov lets Brasília close the case without formally handing an intelligence officer to either Moscow or Washington, setting a template for the several other GRU-linked illegals cases Brazilian federal police have connected to the same network. The order keeps a broader exposure problem visible: Brazilian police tie at least nine operatives to false Brazilian identities seeded across Latin America, one of whom Russia recovered in a 2024 prisoner swap with Washington. Brasília is separately managing US friction over Russian diesel imports and the terrorism designation of Brazilian criminal groups; the timing reinforces Washington's reading that Brazil is tilting toward Moscow on contested cases.

Sources:

1: Brazil Clears an Alleged Russian Spy's Path Home. The US Objects - The Rio Times

2: Brasil expulsa espião russo Sergey Cherkasov do país e proíbe retorno por 30 anos - Rádio Itatiaia

3: Brazil Authorizes Expulsion of Russian Accused of Espionage - The Defense Post

4: Brazil authorises expulsion of Russian accused of espionage - Free Malaysia Today (AFP)

IC Technology & Cyber

CISA Deploys Anthropic Mythos AI to Scan Federal Code for Vulnerabilities Ahead of Foreign Intelligence Services

BLUF: Cybersecurity and Infrastructure Security Agency (CISA)'s use of Mythos against public GitHub repositories creates a race between federal patching timelines and foreign services running comparable AI tools against the same exposed code.

CISA's Attack Surface Evaluation team is running Anthropic's Mythos AI model against federal code repositories on GitHub to identify vulnerabilities, according to a Reuters report citing three unnamed sources and a CISA employee who confirmed the effort to Forbes 12. Two sources told Reuters the scans have already uncovered a "large number" of vulnerabilities, though the scope of code reviewed and severity of the flaws found have not been disclosed 1. Neither CISA nor Anthropic responded on the record to Reuters or Forbes queries about the initiative 12. Forbes reported that CISA had previously lacked access to Mythos, which Anthropic has limited to roughly 50 select partner organizations; how CISA obtained permission to use it is unclear 2. The deployment follows NSA's use of Mythos since at least April despite an ongoing Pentagon supply-chain risk designation against Anthropic that a federal judge blocked in March 13.

Analyst Note: CISA's use extends Mythos from classified NSA testing into an operational, cross-agency role scanning public GitHub repositories, widening the aperture from signals-intelligence systems to routine federal software. Undisclosed scope and severity of vulnerabilities already found leaves agencies unable to gauge patching burden or exposure risk before the same repositories draw outside probing, and neither party's on-record silence explains how CISA gained access outside Anthropic's roughly fifty-partner cohort or what safeguards govern the expansion. Reuters furnishes the lone primary account, with Security Affairs, SecurityWeek, and Forbes offering secondary amplification rather than independent corroboration. The access may reflect an informal arrangement by individual Attack Surface Evaluation staff rather than a sanctioned, agency-wide partnership between CISA and Anthropic.

Sources:

1: Exclusive-US Cyber Agency Is Using Anthropic's Mythos to Audit Government Code, Sources Say - Reuters (via U.S. News & World Report)

2: A US Cyber Agency Is Finally Using Anthropic's Mythos - Forbes

3: CISA Deploys Anthropic's Mythos AI to Hunt Vulnerabilities in U.S. Government Code - Security Affairs

CISA Reportedly Using Anthropic's Mythos to Scan Government Software for Flaws - SecurityWeek

Prior Reporting - [Exclusive: US cyber agency is using Anthropic Mythos to audit government code, sources say](https://whbl.com/2026/07/06/exclusive-us-cyber-agency-is-using-anthropics-mythos-to-audit-government-code-sources-say/) (2026-07-06) - [US cyber agency is using Anthropic's Mythos to audit government code, sources say](https://bworldonline.com/technology/2026/07/07/761602/us-cyber-agency-is-using-anthropics-mythos-to-audit-government-code-sources-say/) (2026-07-07) - [Exclusive-US cyber agency is using Anthropic's Mythos to audit government code, sources say](https://www.thestar.com.my/tech/tech-news/2026/07/07/exclusive-us-cyber-agency-is-using-anthropic039s-mythos-to-audit-government-code-sources-say) (2026-07-07) - [US cyber agency is using Anthropic's Mythos to audit government code, sources say](https://www.arabnews.com/node/2649909/world) (2026-07-07) - [Exclusive: US cyber agency is using Anthropic Mythos to audit government code, sources say](https://www.reuters.com/technology/us-cyber-agency-is-using-anthropics-mythos-audit-government-code-sources-say-2026-07-06/) (2026-07-06)

Allied Intelligence

Israel Shares Intelligence with United States Warning of New Iranian Plot to Assassinate President Trump

BLUF: Israel's unvetted warning creates political pressure favoring strikes over diplomacy, but a confirmed Iran-linked attempt against Trump remains unlikely by October 10, 2026.

Israel shared intelligence with the United States indicating Iran had developed a new plan to assassinate President Trump, according to a Wall Street Journal report cited by CNN, Fox News, The Jerusalem Post and The Hill 1234. CNN reported that one source described the warning as arriving this week, while another said the US had separately picked up a steady flow of intelligence in recent weeks about possible plots against Trump, with the Israeli warning marking a new and specific threat 1. Two sources told CNN the plot's details were unclear and that the US had neither vetted the intelligence itself nor been tracking it before Israel's warning; some intelligence community officials voiced skepticism of the Israeli reporting 1. Trump and Israeli Prime Minister Benjamin Netanyahu spoke by phone Thursday and agreed to continue coordination, with Trump updating Netanyahu on US military activity in the Gulf, according to a statement from Netanyahu's office 3.

Analyst Note: Israel's warning traces to a single originating account that none of the four citing outlets independently corroborated, so structural depth is shallower than the outlet count suggests, and US officials have neither vetted the intelligence nor tracked it beforehand, with some in the community skeptical. Its timing, as Trump works to preserve a ceasefire Netanyahu has pushed to abandon, gives it weight beyond its unverified content and pressures Trump toward renewed strikes rather than diplomacy. The warning may instead reflect an Israeli effort to shape his Iran calculus rather than a vetted operational threat. A concrete, publicly confirmed Iran-linked attempt on Trump is unlikely by October 10, 2026, since prior threat streams have not translated into operational plots reaching that threshold. This judgment carries high confidence, reflecting consistent multi-source reporting on the intelligence-sharing episode itself even as the plot's details remain unverified; confirmation would hand Trump grounds to abandon the mid-August nuclear deal track for strikes.

Sources:

1: Israel shared intelligence with US of Iranian plot to assassinate Trump, sources say - CNN

2: Israel Shares Intelligence Warning Iran Plotted New Assassination Attempt Against Trump - Fox News

3: Israel warns US of new Iranian plot to assassinate Trump as tensions in region grow - report - The Jerusalem Post

4: Iran recently plotted to kill Donald Trump, per Israel - The Hill

UK State Threats Bill Clears Parliament Giving MI5 New Powers to Designate Hostile State-Linked Organizations

BLUF: Designation authority without timely exercise risks replicating the deterrence gap the Act was designed to close, with IRGC action before the July 16 recess the first credibility test.

The National Security (State Threats) Bill completed its passage through Parliament on Monday after MPs voted 394 to 85 to accept Lords amendments protecting humanitarian workers and journalists, and received Royal Assent on Wednesday 123. The Act empowers the Home Secretary to designate hostile state-linked organizations, creates offenses for supporting or assisting designated bodies, and establishes a Foreign Influence Registration Scheme, with penalties reaching 14 years' imprisonment 14. Security Service (United Kingdom) (MI5) Director General Sir Ken McCallum said the legislation targets "proxy organisations" used by states seeking to "deniably target the UK" 3. Security minister Dame Angela Eagle told MPs threats addressed by the Bill come "predominantly, though not exclusively" from Russia, China and Iran, while Liberal Democrat spokesperson Will Forster cited a 48 percent rise in MI5 state-threat investigations over the past year and called for designation of Iran's Islamic Revolutionary Guard Corps before Parliament rises on July 16 1. Critics including NGO CAGE International and former diplomat Craig Murray argued the Bill grants the Home Secretary designation powers without judicial oversight 2.

Analyst Note: The Act gives MI5 a proxy-network prosecution tool it lacked under the National Security Act 2023, shifting enforcement from disrupting individual agents to criminalizing UK-based intermediaries acting for Moscow, Beijing and Tehran. Practical impact now hinges on how quickly the Home Secretary exercises designation authority, with the IRGC the first test case pressed by cross-party MPs ahead of the July 16 recess; whether the government moves within that window cannot be assessed with confidence, since ministers have repeatedly deferred IRGC designation through stronger prior triggers, including Monday's 394-85 Commons vote, without signaling a ready-to-sign package. A single MI5 primary statement corroborated by independently-sourced secondary reporting supports converging but reliability-limited confidence. Royal Assent landed Wednesday, over three months ahead of the prior October 31 estimate. Critics including CAGE International and Craig Murray read the humanitarian and journalism carve-outs as cosmetic, arguing the designation power itself remains unchecked by judicial oversight.

Sources:

1: State threats bill clears Parliament with aid worker shield - UK Defence Journal

2: National Security Bill clears Parliament amid criticism - The Canary

3: Director General MI5 Welcomes New Legislation

4: UK Strengthens National Security Powers as State Threats Act Becomes Law - Samaa TV

Prior Reporting - [UK fast-tracks sweeping national cybersecurity bill](https://techchannel.news/uk-fast-tracks-sweeping-national-cybersecurity-bill/) (2026-06-11) - [New powers to crack down on hostile foreign state organisations](https://www.gov.uk/government/news/new-powers-to-crack-down-on-hostile-foreign-state-organisations) (2026-06-11) - [National Security (State Threats) Bill](https://bills.parliament.uk/bills/4140) (2026-06-09) - [UK cracks down on Iran, Russia, North Korea, China cyber ops](https://cybernews.com/security/uk-hostile-foreign-state-crack-down/) (2026-06-11)

IC Oversight & Policy

Jay Clayton ODNI Nomination Hearing Scheduled for July 15 as Intelligence Community Leadership Vacancy Persists

BLUF: Whether Clayton's July 15 hearing proceeds remains genuinely uncertain given Trump's unmet precondition, and a second cancellation would deepen IC leadership instability while stalling FISA Section 702 reauthorization.

The Senate Select Committee on Intelligence has scheduled a new confirmation hearing for July 15 for Jay Clayton, President Trump's nominee for director of national intelligence, according to Reuters and NBC News 12. Committee Chairman Tom Cotton set the new date after Trump ordered the original June 17 hearing scrapped hours beforehand, first demanding that James "Jamie" McDonald be confirmed as US Attorney for the Southern District of New York before releasing Clayton for the Director of National Intelligence (DNI) role (a condition since eased as McDonald rejoined the Southern District of New York (SDNY) office July 8), and separately linking the delay to unresolved disputes over reauthorizing FISA Section 702, which lapsed June 12, and passing the SAVE Act voter-identification bill 23. Clayton, the US attorney for the Southern District of New York and former SEC chairman, was nominated on June 11 to replace acting DNI Bill Pulte, who took the post after Tulsi Gabbard's May resignation 3. Senate Intelligence Committee Democrats Mark Warner and Jim Himes have both spoken favorably of Clayton's nomination 2.

Analyst Note: Whether the July 15 hearing proceeds without a further postponement remains genuinely uncertain, since Trump's original precondition, confirming James McDonald as Clayton's SDNY successor, was never formally resolved even after McDonald's July 8 return to that office. Confidence in this judgment is low, given single-source wire reporting on the new date with no independent indicator of White House intent beforehand. The publicly stated FISA Section 702 and SAVE Act rationale for the original cancellation may serve chiefly as cover for the unresolved McDonald succession, which the White House has not moved to formalize despite three weeks elapsing. A further postponement would extend Bill Pulte's tenure as acting DNI atop 18 intelligence agencies and continue stalling Section 702 reauthorization talks Democrats have tied to Clayton's confirmation, while a completed hearing would let the committee advance his nomination and unlock those negotiations.

Sources:

1: Jay Clayton's US intelligence director nomination hearing set for July 15 - WHBL / Reuters

2: Senate sets new date for Jay Clayton's confirmation hearing after Trump derailed the previous one - NBC News

3: Senate Committee Sets New Hearing Date for Trump DNI Pick Jay Clayton - The Epoch Times

Jay Clayton DNI Hearing Set for July 15 - Newsmax

Prior Reporting - [Jay Claytons US intelligence director nomination hearing set for July 15](https://kelo.com/2026/07/07/jay-claytons-us-intelligence-director-nomination-hearing-set-for-july-15/) (2026-07-08) - [Jay Clayton's US intelligence director nomination hearing set for July 15](https://wtvbam.com/2026/07/07/jay-claytons-us-intelligence-director-nomination-hearing-set-for-july-15/) (2026-07-07) - [Senate Panel Schedules Jay Clayton Confirmation Hearing](https://politicalwire.com/2026/07/07/senate-panel-schedules-jay-clayton-confirmation-hearing/) (2026-07-07)

COLLECTION GAPS

UNCLASSIFIED // OPEN SOURCE