IC BRIEF
Current as of 0317 EDT (UTC-04), Friday 10 July 2026
Contents
- Adversary Intelligence (4)
- Adversary Intelligence Operations (2)
- IC Technology & Cyber (1)
- Allied Intelligence (2)
- IC Oversight & Policy (1)
- COLLECTION GAPS
10 stories from 37 sources across 33 organizations
KEY JUDGMENTS
Iranian intelligence operations documented across Germany, the Netherlands, and the United Kingdom, combined with Israeli intelligence warning of a new assassination plot against President Trump, establish the Islamic Revolutionary Guard Corps (IRGC) as the primary operational threat to allied interests this cycle. These operations arrive while the US intelligence community operates under an acting director whose confirmation remains genuinely uncertain. A publicly confirmed Iran-linked attempt on Trump is unlikely by October 2026. High confidence reflects multi-source convergence on the intelligence-sharing episode despite unvetted plot details and voiced IC skepticism.
European states are assembling prosecutorial and designation tools faster than at any point in the IRGC's operational history in Europe, with Hamburg courtroom evidence, the EU's February terrorist designation, and the UK State Threats Act converging. No government has exercised these authorities against the IRGC. Independent US validation of the Israeli intelligence would shift allied coordination from bilateral protection toward networked prosecution.
North Korean orders expanding nuclear forces and intelligence capabilities, Main Intelligence Directorate (Russia) (GRU) exposure in Brazil, and Chinese Mustang Panda intrusions against Indian critical infrastructure indicate adversary services are active across four fronts. The IC leadership vacancy constrains the coordinated assessment capacity these concurrent threats demand.
Adversary Intelligence
Kim Jong Un Orders Improvements to Nuclear Weapons, Navy, and Intelligence Agency at Central Military Commission Meeting
BLUF: Kim's seven signed orders convert the Ninth Congress nuclear policy into operational taskings, coupling warhead expansion with an intelligence mandate aimed squarely at Seoul and Washington.
Kim Jong Un presided over the first enlarged meeting of the ninth Workers' Party
Analyst Note: Kim's order set operationalizes the Ninth Congress's nuclear buildup, tasking the General Reconnaissance and Intelligence Bureau's expanded mandate explicitly against "potential enemies," language Pyongyang reserves for Seoul and Washington. An unspecified reshuffle of senior military posts alongside base-standardization directives points to Kim tightening command structures ahead of execution rather than restating existing policy, while naval base construction and shipyard upgrades running in parallel suggest a coordinated conventional-nuclear modernization push rather than an isolated weapons announcement. Reporting rests on KCNA's own release, with NK News, Bloomberg, Korea JoongAng Daily and Reuters all functioning as secondary pickups of the same state account rather than independent corroboration, and the rhetoric may instead be primarily domestic messaging reinforcing Kim's military-first narrative rather than signaling an imminent operational shift. No named officials or timeline surface, leaving the scale and sequencing of implementation unclear.
Sources:
1: Kim Jong Un oversees military meeting on improving nukes, navy and intel agency -
2: North Korea Decides on Measures to Expand Nuclear Forces, KCNA Reports -
3: North Korea to expand intelligence agency role against 'potential enemies' under Kim Jong-un -
4: Kim Jong Un Orders North Korea Spy Agency to Expand Intelligence Operations -
First Enlarged Meeting of Ninth WPK Central Military Commission Held -
Quds Force Commander Qaani Makes Rare Public Appearance at Khamenei Funeral Amid Mossad Spy Suspicions
BLUF: Qaani's orchestrated visibility across five funeral cities signals Tehran has chosen institutional continuity over counterintelligence caution during a succession window when projecting IRGC cohesion outweighs compromise risk.
Analyst Note: Qaani's sustained appearances across five funeral cities mark a sharp break from his near-total public absence since the war began in February, positioning him as a visible institutional anchor while
Sources:
1: Rarely Seen Quds Force Chief (And Suspected Mossad Spy) Qaani Featured Throughout Khamenei Funeral -
2: IRGC-affiliated Tasnim publishes images it says show Qaani in Mashhad -
German Court Hears IRGC Quds Force Recruited Operative to Burn Kosher Shop and Surveilled Jewish Leaders as BKA Details Wider Plot
BLUF: Courtroom evidence now documents the full Quds Force attack cycle on European soil, giving allied services actionable tradecraft signatures for detecting parallel networks still unidentified.
A German court heard testimony Monday, in the second hearing of the trial, that an alleged Islamic Revolutionary Guard Corps Quds Force operative sought a Palestinian or Somali woman facing financial hardship to burn a Jewish kosher grocery store for roughly 30,000 Danish kroner, about 4,000 euros
Analyst Note: Courtroom testimony converts prior domestic intelligence warnings about expanding Iranian operations in Europe into documented case specifics, giving German and allied security services a template of Quds Force tradecraft: financially desperate cutouts, weapons inquiries, and pre-attack reconnaissance of communal leaders. The proceedings identify unnamed handlers and contacts, including figures known only as Haji Ali, Kazem, and Vahid, whose reach outside Germany remains unresolved. Testimony continuing through October will surface further investigative detail on the weapons dimension the court has yet to examine. The case substantiates, rather than merely repeats, Germany's public assessment that Tehran is positioned to expand intelligence and terrorist activity in Europe.
Sources:
1: Alleged IRGC plot sought woman to burn kosher shop German court hears -
Alleged IRGC plot sought woman to burn kosher shop, German court hears -
Prior Reporting
- [2 men go on trial in Germany over alleged Iran-backed plots targeting Jews](https://www.timesofisrael.com/2-men-go-on-trial-in-germany-over-alleged-iran-backed-plots-targeting-jews/) (2026-06-26) - [German Court Tries Two Men over Alleged Iran-backed Anti-Jewish Plots](https://english.aawsat.com/world/5288843-german-court-tries-two-men-over-alleged-iran-backed-anti-jewish-plots) (2026-06-26) - [Man on trial accused of tracking Jewish figures as targets for Iran-backed attacks](https://www.thejc.com/news/world/tracking-jewish-figures-iran-backed-germany-fkpnjzvy) (2026-06-26) - [Germany charges suspected Iranian spies over plot to kill Jewish community leaders](https://www.ynetnews.com/article/bjllct21zl) (2026-06-26) - [Hanseatisches Oberlandesgericht: Hauptverhandlung 'Geheimdienstliche Agententätigkeit für den Iran' beginnt am 26. Juni 2026](https://justiz.hamburg.de/gerichte/oberlandesgericht/gerichtspressestelle/hanseatisches-oberlandesgericht-hauptverhandlung-geheimdienstliche-agententaetigkeit-fuer-den-iran-beginnt-am-26-juni-2026-1190446) (2026-06-26)Foreign Policy Investigation Documents Escalating IRGC Threats and Surveillance Against Iranian Dissidents Across Europe After Iran War
BLUF: Europe's IRGC terrorist designation and pending UK proscription legislation remain untested against Iran's criminal-proxy operational model, leaving governments locked in unsustainable case-by-case dissident protection.
Iranian dissidents across Europe reported intensified threats, surveillance, and harassment from Iran since the February war among Iran, Israel, and the United States, according to a Foreign Policy investigation
Analyst Note: Sustained Iranian
Sources:
1: Iran Is Still Fighting a War Against Dissidents Abroad -
Adversary Intelligence Operations
Chinese APT Mustang Panda Deploys New ZOHOMURK and MINIRECON Malware Against Indian Government and Hydropower Infrastructure
BLUF: By routing command traffic through Open Authorization (OAuth)-authenticated Zoho accounts, Mustang Panda has rendered India's domain-blocking defenses structurally blind to these intrusions.
GBHackers reported that Acronis Threat Research Unit identified two espionage campaigns by Mustang Panda targeting Indian government offices and hydropower-sector organizations, including entities cooperating with Taiwanese institutions, using spear-phishing archives with geopolitically themed lures
Analyst Note: Mustang Panda's pivot to Zoho WorkDrive as a command channel defeats domain-blocklist defenses, since OAuth-authenticated traffic to a mainstream cloud platform is indistinguishable from routine business use without application-layer inspection. Parallel tracks against hydropower operators and Taiwan-cooperation government offices indicate deliberate targeting of distinct strategic portfolios rather than opportunistic scanning, and code continuity linking MINIRECON and SHARDLOADER to prior Toneshell implants points to a shared development pipeline within the group's toolset. Reporting remains single-sourced to Acronis TRU, with other outlets merely repeating its findings, though Acronis has now released specific indicators, including the couldinstallup[.]com domain, and coordinated with CERT-In to notify victims, shifting the campaign from detection into remediation. A separate operator reusing shared Toneshell code cannot be ruled out, since the high confidence attribution rests on tradecraft and code overlap rather than infrastructure or signals evidence, leaving most targeted organizations without the OAuth-abuse detection capability needed to catch this activity.
Sources:
1: Mustang Panda Targets India's Government and Energy Sectors With ZOHOMURK and MINIRECON -
2: Mustang Panda Uses ZOHOMURK and MINIRECON Malware to Threaten India Critical Infrastructure -
Mustang Panda targets India's government and energy sectors with ZOHOMURK and MINIRECON -
Prior Reporting
- [Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks](https://thehackernews.com/2026/06/mustang-panda-uses-zoho-workdrive-as.html) (2026-06-29)Brazil Authorizes Expulsion of GRU Officer Sergey Cherkasov Who Posed as Student to Infiltrate ICC and Johns Hopkins University
BLUF: Brazil's expulsion order gives Moscow a path to recover a trained illegal without the political cost Brasília would absorb by granting either side's extradition request.
Brazil's Justice Ministry published
Analyst Note: Expelling rather than extraditing Cherkasov lets Brasília close the case without formally handing an intelligence officer to either Moscow or Washington, setting a template for the several other GRU-linked
Sources:
1: Brazil Clears an Alleged Russian Spy's Path Home. The US Objects -
2: Brasil expulsa espião russo Sergey Cherkasov do país e proíbe retorno por 30 anos -
3: Brazil Authorizes Expulsion of Russian Accused of Espionage -
4: Brazil authorises expulsion of Russian accused of espionage -
IC Technology & Cyber
CISA Deploys Anthropic Mythos AI to Scan Federal Code for Vulnerabilities Ahead of Foreign Intelligence Services
BLUF: Cybersecurity and Infrastructure Security Agency (CISA)'s use of
CISA's
Analyst Note: CISA's use extends Mythos from classified NSA testing into an operational, cross-agency role scanning public GitHub repositories, widening the aperture from signals-intelligence systems to routine federal software. Undisclosed scope and severity of vulnerabilities already found leaves agencies unable to gauge patching burden or exposure risk before the same repositories draw outside probing, and neither party's on-record silence explains how CISA gained access outside Anthropic's roughly fifty-partner cohort or what safeguards govern the expansion. Reuters furnishes the lone primary account, with Security Affairs, SecurityWeek, and Forbes offering secondary amplification rather than independent corroboration. The access may reflect an informal arrangement by individual Attack Surface Evaluation staff rather than a sanctioned, agency-wide partnership between CISA and Anthropic.
Sources:
1: Exclusive-US Cyber Agency Is Using Anthropic's Mythos to Audit Government Code, Sources Say -
2: A US Cyber Agency Is Finally Using Anthropic's Mythos -
3: CISA Deploys Anthropic's Mythos AI to Hunt Vulnerabilities in U.S. Government Code -
CISA Reportedly Using Anthropic's Mythos to Scan Government Software for Flaws -
Prior Reporting
- [Exclusive: US cyber agency is using Anthropic Mythos to audit government code, sources say](https://whbl.com/2026/07/06/exclusive-us-cyber-agency-is-using-anthropics-mythos-to-audit-government-code-sources-say/) (2026-07-06) - [US cyber agency is using Anthropic's Mythos to audit government code, sources say](https://bworldonline.com/technology/2026/07/07/761602/us-cyber-agency-is-using-anthropics-mythos-to-audit-government-code-sources-say/) (2026-07-07) - [Exclusive-US cyber agency is using Anthropic's Mythos to audit government code, sources say](https://www.thestar.com.my/tech/tech-news/2026/07/07/exclusive-us-cyber-agency-is-using-anthropic039s-mythos-to-audit-government-code-sources-say) (2026-07-07) - [US cyber agency is using Anthropic's Mythos to audit government code, sources say](https://www.arabnews.com/node/2649909/world) (2026-07-07) - [Exclusive: US cyber agency is using Anthropic Mythos to audit government code, sources say](https://www.reuters.com/technology/us-cyber-agency-is-using-anthropics-mythos-audit-government-code-sources-say-2026-07-06/) (2026-07-06)Allied Intelligence
Israel Shares Intelligence with United States Warning of New Iranian Plot to Assassinate President Trump
BLUF: Israel's unvetted warning creates political pressure favoring strikes over diplomacy, but a confirmed Iran-linked attempt against Trump remains
Israel shared intelligence with the United States indicating Iran had developed a new plan to assassinate President Trump, according to a Wall Street Journal report cited by CNN, Fox News, The Jerusalem Post and The Hill
Analyst Note: Israel's warning traces to a single originating account that none of the four citing outlets independently corroborated, so structural depth is shallower than the outlet count suggests, and US officials have neither vetted the intelligence nor tracked it beforehand, with some in the community skeptical. Its timing, as Trump works to preserve a ceasefire Netanyahu has pushed to abandon, gives it weight beyond its unverified content and pressures Trump toward renewed strikes rather than diplomacy. The warning may instead reflect an Israeli effort to shape his Iran calculus rather than a vetted operational threat. A concrete, publicly confirmed Iran-linked attempt on Trump is
Sources:
1: Israel shared intelligence with US of Iranian plot to assassinate Trump, sources say -
2: Israel Shares Intelligence Warning Iran Plotted New Assassination Attempt Against Trump -
3: Israel warns US of new Iranian plot to assassinate Trump as tensions in region grow - report -
4: Iran recently plotted to kill Donald Trump, per Israel -
UK State Threats Bill Clears Parliament Giving MI5 New Powers to Designate Hostile State-Linked Organizations
BLUF: Designation authority without timely exercise risks replicating the deterrence gap the Act was designed to close, with IRGC action before the July 16 recess the first credibility test.
The National Security (State Threats) Bill completed its passage through Parliament on Monday after MPs voted 394 to 85 to accept Lords amendments protecting humanitarian workers and journalists, and received Royal Assent on Wednesday
Analyst Note: The Act gives MI5 a proxy-network prosecution tool it lacked under the National Security Act 2023, shifting enforcement from disrupting individual agents to criminalizing UK-based intermediaries acting for Moscow, Beijing and Tehran. Practical impact now hinges on how quickly the Home Secretary exercises designation authority, with the IRGC the first test case pressed by cross-party MPs ahead of the July 16 recess; whether the government moves within that window cannot be assessed with confidence, since ministers have repeatedly deferred IRGC designation through stronger prior triggers, including Monday's 394-85 Commons vote, without signaling a ready-to-sign package. A single MI5 primary statement corroborated by independently-sourced secondary reporting supports converging but reliability-limited confidence. Royal Assent landed Wednesday, over three months ahead of the prior October 31 estimate. Critics including CAGE International and Craig Murray read the humanitarian and journalism carve-outs as cosmetic, arguing the designation power itself remains unchecked by judicial oversight.
Sources:
1: State threats bill clears Parliament with aid worker shield -
2: National Security Bill clears Parliament amid criticism -
3: Director General MI5 Welcomes New Legislation
4: UK Strengthens National Security Powers as State Threats Act Becomes Law -
Prior Reporting
- [UK fast-tracks sweeping national cybersecurity bill](https://techchannel.news/uk-fast-tracks-sweeping-national-cybersecurity-bill/) (2026-06-11) - [New powers to crack down on hostile foreign state organisations](https://www.gov.uk/government/news/new-powers-to-crack-down-on-hostile-foreign-state-organisations) (2026-06-11) - [National Security (State Threats) Bill](https://bills.parliament.uk/bills/4140) (2026-06-09) - [UK cracks down on Iran, Russia, North Korea, China cyber ops](https://cybernews.com/security/uk-hostile-foreign-state-crack-down/) (2026-06-11)IC Oversight & Policy
Jay Clayton ODNI Nomination Hearing Scheduled for July 15 as Intelligence Community Leadership Vacancy Persists
BLUF: Whether Clayton's July 15 hearing proceeds remains
The Senate Select Committee on Intelligence has scheduled a new confirmation hearing for July 15 for Jay Clayton, President Trump's nominee for director of national intelligence, according to Reuters and NBC News
Analyst Note: Whether the July 15 hearing proceeds without a further postponement remains
Sources:
1: Jay Clayton's US intelligence director nomination hearing set for July 15 -
2: Senate sets new date for Jay Clayton's confirmation hearing after Trump derailed the previous one -
3: Senate Committee Sets New Hearing Date for Trump DNI Pick Jay Clayton -
Jay Clayton DNI Hearing Set for July 15 -
Prior Reporting
- [Jay Claytons US intelligence director nomination hearing set for July 15](https://kelo.com/2026/07/07/jay-claytons-us-intelligence-director-nomination-hearing-set-for-july-15/) (2026-07-08) - [Jay Clayton's US intelligence director nomination hearing set for July 15](https://wtvbam.com/2026/07/07/jay-claytons-us-intelligence-director-nomination-hearing-set-for-july-15/) (2026-07-07) - [Senate Panel Schedules Jay Clayton Confirmation Hearing](https://politicalwire.com/2026/07/07/senate-panel-schedules-jay-clayton-confirmation-hearing/) (2026-07-07)COLLECTION GAPS
- US counterintelligence investigations and espionage arrests are absent despite ongoing PRC and Russian penetration cases in federal agencies and defense contractors.
- IC workforce actions, including hiring freezes and clearance processing backlogs, are not represented in the current intelligence picture despite documented attrition across multiple agencies.
- Five Eyes and allied intelligence-sharing coordination beyond bilateral UK developments, particularly Australian and Canadian service restructuring.
- NSA and NGA collection capability adjustments and operational disclosures are absent from the intelligence picture this cycle.