//
OFFLINE — VIEWING CACHED CONTENT
← Back to Archive

IC BRIEF

Current as of 1705 EDT (UTC-04), Monday 03 August 2026

Contents

10 stories from 42 sources across 38 organizations


KEY JUDGMENTS

Clayton's swearing-in terminates a seven-week DNI vacancy but does not resolve the information-control disputes his confirmation was expected to unlock. The administration will very likely maintain bifurcated Iran war casualty accounting through at least September 30, absent a mass-casualty event or leaked internal directive forcing reconsolidation. High confidence reflects the Pentagon's entrenchment of the split with no binding compulsion on a timeline to reverse. Clayton's confirmation makes a Section 702 floor vote likely by year-end, removing the procedural obstacle Thune cited.

Iran will very likely announce additional espionage arrests or executions linked to Israeli or Western intelligence within eight weeks, extending a quarterly cadence of three to five publicized cases sustained since hostilities began. Moderate confidence reflects the documented multi-wave pattern, though no specific pending case constrains the timing. Russia's Foreign Intelligence Service of the Russian Federation (SVR)-linked Storm-2945 operation, actively harvesting credentials through compromised hotel Wi-Fi networks in multiple countries, adds a live cyber collection threat coinciding with IC leadership transitions in Washington, Kyiv, and Seoul.


Counterintelligence

UK Charges British-Azerbaijani National With Spying on RAF Akrotiri for Iran IRGC in First Overseas National Security Act Case

BLUF: Sultanov's extradition from Cyprus to face trial remains very unlikely by late January 2027, as untested extraterritorial jurisdiction under the National Security Act and standard procedural timelines favor protracted proceedings.

Cypriot authorities arrested Rashad Sultanov, 44, a dual British-Azerbaijani national from Islington, north London, on July 17 12. The Metropolitan Police's Counter Terrorism Policing command said the Crown Prosecution Service authorized charges under Sections 3 and 4 of the National Security Act covering assisting a foreign intelligence service and inspecting a prohibited place 2, alleging Sultanov photographed RAF Akrotiri with long-lens cameras and phones, took extensive notes, and encrypted the files before passing them to Iran's Islamic Revolutionary Guard Corps (IRGC) between May 11 and June 22 last year 12. The UK's extradition request names the alleged recipient as Elsad Elsin Hajiyev, an Azerbaijani-Iranian national already wanted on an international arrest warrant for directing an IRGC-linked network inside Azerbaijan 1. Counter Terrorism Policing (CTP) London called it the first National Security Act investigation into alleged offenses committed in an overseas territory 12, and Commander Helen Flanagan said British and Cypriot police, the Crown Prosecution Service (CPS), and the National Crime Agency have coordinated on the case 1. Sultanov remains in Cypriot custody as extradition proceedings continue 12.

Analyst Note: Sultanov's transfer to UK custody is very unlikely by January 31, 2027: Cypriot courts control extradition pacing for this first extraterritorial National Security Act prosecution, with no precedent to compress the timeline and no plea yet entered before any tribunal. Confidence is low given the case's procedural novelty and thin reporting on hearing dates or defense posture. Sourcing traces largely to the Metropolitan Police's own announcement, with other outlets supplying wire pickup rather than independent verification, consistent with a single-source consensus despite two carrying primary tags. The prosecution's timing, close on the IRGC's national-security designation and the March Akrotiri drone strike, suggests the case may function as a demonstrative marker of the Act's overseas reach rather than an urgent counterespionage response. A completed extradition would let prosecutors test that jurisdiction in open court and surface IRGC tradecraft at trial, while continued Cypriot detention leaves the precedent unresolved and denies UK authorities a public venue to demonstrate enforcement reach.

Sources:

1: British man arrested in Cyprus accused of 'hostile surveillance' at RAF base for Iran's IRGC - ITV News

2: UK charges man accused of spying on RAF base for Iran's IRGC - Iran International

Man arrested in Cyprus in first overseas National Security Act investigation - Metropolitan Police

Man arrested in Cyprus on suspicion of spying on a UK military base for Iran - Washington Post

Prior Reporting - [Cyprus: 44-year-old accused of spying on British base for Iran](http://www.euronews.com/my-europe/2026/07/31/cyprus-44-year-old-accused-of-spying-on-british-base-for-iran) (2026-07-31) - [Man suspected of spying on UK military base for Iran arrested in Cyprus](https://cyprus-mail.com/2026/07/31/man-suspected-of-spying-on-uk-military-base-for-iran-arrested-in-cyprus) (2026-07-31) - [British-Azerbaijani man arrested in Cyprus over alleged espionage for Iran's IRGC](https://www.azernews.az/region/261820.html) (2026-07-31)

Iran Executes Two Convicted of Providing Military Target Coordinates to Mossad During 2025-2026 Hostilities

BLUF: By publicizing specific collection tradecraft alongside the executions, Tehran is burning known channels to deter future recruitment while signaling expectation of renewed Israeli strikes.

Iran's Judiciary announced the execution of Omid Behzad and Pouria Safvat on Monday for espionage on behalf of Mossad 1234. The judiciary said the two supplied coordinates, images and intelligence on Iranian military and security sites to Mossad during the 12-day war in June 2025 and the 40-day war in February, and that IRGC Intelligence Organization agents arrested them during that cooperation 1. The Times of Israel, citing Mizan, reported that Behzad transmitted coordinates through a Telegram channel linked to Mossad, while Safvat passed information to Mossad and the London-based Iran International network 2. The Washington Times, citing Mehr News, reported that some of the locations Safvat identified were later bombed and that he filmed Iranian air defense systems from rooftops during the 12-day war 3.

Analyst Note: Iran's decision to publicize collection tradecraft, a Telegram channel administrator tied to Mossad and a media handoff naming Iran International, functions as a warning that those channels are now compromised, while extending the espionage label to exile media gives Tehran grounds to further restrict domestic contact with that outlet. The account remains single-sourced to the Iranian state; Mizan and Press TV originate the judiciary's statement, and Western outlets relay it as secondary amplification rather than independent confirmation. This is the fourth Mossad-linked execution since May, with the added detail on Telegram-based coordinate transmission and rooftop filming of air defenses marking the first disclosure of specific tradecraft rather than just charges. The executions also fit Iran's wider wartime pattern of deterrent hangings independent of any case-specific counterintelligence need.

Sources:

1: Two Mossad operatives convicted of supplying security information to Israel executed: Iran Judiciary - Press TV

2: Iran hangs two accused of spying for Israel as wartime executions ramp up - The Times of Israel

3: Iran executes two men accused of spying for Israel as wave mounts of wartime hangings - The Washington Times

4: Iran Executes Two Individuals Convicted of Espionage for Mossad - Caspian Post

2 key Zionist operatives in the 12-day and 40-day wars pay for their actions: Omid Behzad and Pouria Safvat hanged for sending coordinates of sensitive military and security sites to Mossad officers - Mizan Online (Iran judiciary news agency)

Prior Reporting - [Iran Executes Two Convicted of Spying for Israels Mossad](https://en.sedaily.com/international/2026/05/02/iran-executes-two-convicted-of-spying-for-israels-mossad) (2026-05-02) - [Iran executes 2 men convicted of spying for Israels Mossad](https://english.news.cn/20260502/e89444dcb1c34c6ea84ebcdd56b0a7b7/c.html) (2026-05-02) - [Iran executes two more over spying for Israel](https://www.euronews.com/2026/05/02/iran-executes-two-more-over-spying-for-israel) (2026-05-02) - [Iran executes 2 men convicted of spying for Israel](https://www.freemalaysiatoday.com/category/world/2026/05/02/iran-executes-2-men-convicted-of-spying-for-israel) (2026-05-02)

Allied Intelligence

Former Mossad Chief Barnea Named Global President and Chairman of US Defense Company Ondas

BLUF: Barnea's chairman appointment converts a recently expired intelligence network into boardroom-level market access for a mid-cap defense firm, binding Ondas' growth trajectory to a single relationship portfolio.

US-based defense technology company Ondas Inc. (Nasdaq: ONDS) announced Monday that former Mossad Director David Barnea has joined Ondas Defense Ltd. as Global President and Chairman 12. Barnea led the Mossad from 2021 through the completion of his five-year term in June 2026, a tenure spanning the multi-front war and confrontation with Iran and Hezbollah 23. Ondas said Barnea will support the company's global expansion, technology strategy, and government relationships, focusing initially on the Middle East, Europe, and Asia 23. The company reported more than $70 million in new orders over the preceding four weeks across unmanned ground systems, counter-UAS, and precision-strike technologies, and stated it has no relationship with the Mossad and that Barnea will not use classified government information in his role 2.

Analyst Note: Barnea's appointment as chairman, not merely advisor, gives Ondas governance-level access to his contacts inside allied defense ministries, extending a pattern of senior Israeli security officials converting government relationships into board seats and equity at Western defense-technology firms after leaving public service. That structure ties near-term growth to one individual's network rather than to product differentiation, and Ondas' assurance that Barnea will not use classified information addresses legal exposure without resolving whether allied and rival governments read the hire as continuity of state influence by other means. Reporting rests on a single source, Ondas' own investor release, repackaged rather than independently corroborated by Jerusalem Post, Times of Israel, and Globes. Barnea's marketing value as a recognizable figure may exceed his practical contract-steering power given post-service disclosure and cooling-off restrictions, and the stock's reaction will signal whether investors price the hire as customer access or promotion.

Sources:

1: Former Mossad head Barnea joins US defense company Ondas Inc. as new global president, chairman - Jerusalem Post

2: Former Mossad Director David Barnea Joins Ondas, Bringing Decades of National Security Leadership and Advanced Technology Experience to Support the Company's Global Expansion - Ondas Inc. (Investor Relations)

3: Former Mossad chief appointed Ondas president - Globes

Former Mossad chief David Barnea to take top role at defense company - The Times of Israel

South Korea Launches Three New Military Intelligence Bodies to Replace Disbanded Counterintelligence Command

BLUF: Seoul's disbandment of the Defense Counterintelligence Command redistributes functions across three bodies but channels espionage-case authority into a single investigation headquarters, replicating the concentration risk the reform aimed to eliminate.

South Korea's Ministry of National Defense launched three new organizations on Monday to replace the Defense Counterintelligence Command (DCC), disbanded on July 31 1. Defense Minister Ahn Gyu-back presided over the inauguration of the Defense Counterintelligence Headquarters in Gwacheon, an agency charged with countering North Korean and foreign espionage, protecting military secrets, and supporting defense-industry security including U.S. Navy maintenance work 234. The ministry also created a Defense Security Support Group to handle internal military-security audits and incident investigations for corps-level units and above 24. A National Security Investigation Unit, established within the Ministry of National Defense Investigation Headquarters, took over authority to investigate espionage, military-secret leaks, and pro-enemy activity 124. Kyunghyang Shinmun reported that military and outside observers have raised concerns over the Investigation Headquarters' concentrated investigative authority after absorbing the national-security caseload 1.

Analyst Note: The reorganization disperses counterintelligence, security, and investigative functions across three bodies but recreates the concentration problem it was meant to fix: the Investigation Headquarters now holds sole authority over espionage, leak, and pro-enemy-activity cases previously split among agencies, with internal review and inspection offices offsetting that concentration through structures still embedded in the security apparatus rather than independent statutory oversight. Four outlets, three flagged primary, filed same-day accounts of the single launch ceremony independently rather than via one wire feed, supporting broad corroboration on the reorganization itself while leaving interpretive framing outlet-specific. The move converts June's announced reform plan into operating agencies following the Command's July 31 disbandment, and tying the new headquarters to U.S. Navy MRO security work signals an expanded defense-industrial mission. Whether investigative power re-concentrates in practice hinges on the untested National Security Investigation Council once caseloads build, and the reshuffle could equally amount to administrative relabeling of the same ministry-controlled apparatus under new names.

Sources:

1: '방첩사 해체 후' 국방방첩본부 등 3개 조직 출범…'조사본부 수사권 집중' 우려 해소 관건 - Kyunghyang Shinmun

2: Korea Launches 3 New Military Intelligence Bodies to Replace Disbanded Counterintelligence Command - Seoul Economic Daily

3: Defense ministry launches new counterintelligence unit in overhaul - The Korea Herald

4: Defense ministry launches new spy agency in overhaul - Korea JoongAng Daily

Prior Reporting - [Military counterintelligence command to be dismantled over alleged role in martial law bid](https://en.yna.co.kr/view/AEN20260610006451315) (2026-06-10) - [Defense Counterintelligence Command to disband after 49 years](https://www.koreaherald.com/article/10651647) (2026-06-10) - [Defense ministry to dismantle counterintelligence command](https://www.koreatimes.co.kr/southkorea/defense/20260610/defense-ministry-to-dismantle-counterintelligence-command) (2026-06-10) - [S. Korea to Disband Military Anti-Espionage Command](https://thedefensepost.com/2026/06/10/korea-disband-anti-espionage/) (2026-06-10) - [Military counterintelligence command to be dismantled over alleged role in martial law bid](https://en.yna.co.kr/view/AEN20260610006400315?section=national/defense) (2026-06-10)

Zelenskyy Appoints Former Defense Minister Umerov as Head of Ukraine Foreign Intelligence Service in Security Reshuffle

BLUF: Fusing foreign intelligence oversight with lead-negotiator authority under one Zelensky loyalist collapses the institutional barrier between Kyiv's espionage posture and its diplomatic signaling to Moscow and Washington.

President Volodymyr Zelensky signed a decree on Monday appointing National Security and Defense Council Secretary Rustem Umerov as head of Ukraine's Foreign Intelligence Service, replacing acting chief Oleh Luhovskyi, who was removed the same day 123. In a separate decree, Zelensky named former Interior Minister Ihor Klymenko as National Security and Defense Council (NSDC) secretary in Umerov's place 124. Zelensky said Umerov will continue leading Ukraine's delegation to the stalled trilateral talks with Russia and the US and will coordinate drone-cooperation agreements, which Ukraine has concluded with nine countries and is negotiating with fifteen more 34. The appointments follow the July reshuffle that removed then-Defense Minister Mykhailo Fedorov and, under public pressure, Commander-in-Chief Oleksandr Syrskyi 12.

Analyst Note: Umerov's appointment concentrates negotiating authority, drone-diplomacy coordination, and foreign intelligence oversight under a single Zelensky loyalist already under scrutiny in the Mindich corruption case, extending a pattern of installing political allies rather than career officials atop security institutions. Merging the intelligence chief and lead negotiator roles erases institutional separation between Kyiv's spy service and its Russia-US talks track, letting both counterparts read Ukraine's intelligence posture and negotiating position as coming from the same official. The pick also ends a permanent-leadership vacancy dating to January but replaces an acting intelligence veteran with a defense and diplomacy figure lacking an intelligence background. Reuters-anchored reporting, reinforced by presidential confirmation and the published decree, gives this high corroboration rather than single-source amplification. The reshuffle may instead simply consolidate functions ahead of an anticipated resumption of trilateral talks.

Sources:

1: President's top ally Umerov appointed head of Foreign Intelligence Service - Kyiv Independent

2: Ukraine's Top Negotiator Umerov to Head Foreign Intelligence Service - U.S. News & World Report (Reuters)

3: Zelenskyy confirms Umierov will head Ukraine's Foreign Intelligence Service - Ukrainska Pravda

4: Rustem Umerov, Ukraine's negotiator with Russia and the U.S., to head Foreign Intelligence Service - Meduza

IC Workforce & Organization

Jay Clayton Sworn In as Director of National Intelligence, Replacing Acting DNI Pulte

BLUF: Clayton's confirmation restores Senate-confirmed IC oversight but leaves unresolved whether he will reassert Office of the Director of National Intelligence (ODNI) authority or ratify Ratcliffe's expanded role as the administration's primary intelligence principal.

Jay Clayton was sworn in Monday as the ninth Director of National Intelligence, overseeing 18 U.S. intelligence agencies, according to an ODNI release 1 and Reuters 2. The role had been vacant since Tulsi Gabbard's resignation in May, after which Trump named Bill Pulte acting DNI, a move ODNI and Reuters both report Clayton's swearing-in supersedes 13. The Senate confirmed Clayton, previously U.S. Attorney for the Southern District of New York and SEC chairman, last week following a contested hearing, per MS NOW 4 and ODNI 1. MS NOW reports Clayton's nomination lost some Democratic support after he declined under oath at his July 16 hearing to state directly that Trump lost the 2020 election 4.

Analyst Note: Clayton's swearing-in closes a seven-week gap in Senate-confirmed IC leadership and ends Pulte's authority over an office already thinned by staff cuts, with reporting resting on ODNI's own release independently corroborated by Reuters while The Hill and MS NOW add only secondary confirmation. Monday's oath completed a transition the prior week's confirmation vote merely authorized; the multi-day gap between the two may reflect deliberate staging around the Pulte handoff rather than routine scheduling. Clayton now inherits an ODNI where CIA Director Ratcliffe has assumed de facto primacy on intelligence matters, and his early decisions on rebuilding functions like the National Intelligence Council will signal whether the contraction continues. His confirmation also clears Thune's stated procedural obstacle to a Section 702 reauthorization floor vote, while Democratic skepticism over his refusal to affirm the 2020 election outcome under oath will sharpen congressional scrutiny of his handling of IC weaponization safeguards.

Sources:

1: Jay Clayton Sworn In As Director Of National Intelligence - Office of the Director of National Intelligence

2: Jay Clayton sworn in as U.S. director of national intelligence - Reuters

3: Jay Clayton sworn in as head of intelligence community, booting Pulte - The Hill

4: Jay Clayton is sworn in as National Intelligence Director - MS NOW

Prior Reporting - [Jay Clayton confirmed as director of national intelligence](https://rollcall.com/2026/07/28/jay-clayton-confirmed-director-national-intelligence/) (2026-07-28) - [Senate confirms Jay Clayton as Trump's director of national intelligence, replacing Pulte](https://www.cnbc.com/2026/07/28/jay-clayton-bill-pulte-senate-vote-trump-spy-chief.html) (2026-07-28) - [Jay Clayton confirmed as director of national intelligence](https://www.cnn.com/2026/07/28/politics/jay-clayton-director-national-intelligence) (2026-07-28) - [Senate confirms Jay Clayton as new intelligence czar](https://www.washingtonpost.com/national-security/2026/07/28/senate-confirms-jay-clayton-new-intelligence-czar/) (2026-07-28)

IC Technology & AI

NSA CISA Fail to Deliver Classified AI Frontier Model Benchmarking by EO 14409 August 1 Deadline

BLUF: Blanket classification of the benchmarking methodology and coverage threshold is unlikely to lift by mid-September, leaving frontier labs to navigate release decisions against an opaque regulatory baseline.

The White House said the voluntary AI evaluation framework required by Executive Order 14409's August 1 deadline was complete, but declined to disclose its contents, participants, or timeline, per a White House official cited by Axios and Politico 12. Yahoo Finance reported no Federal Register notices, NIST or Cybersecurity and Infrastructure Security Agency (CISA) publications, or OSTP statements had appeared addressing the order's classified benchmarking process or cyber workforce plan as of the deadline 3. Axios reported the benchmarking process for assessing models' cyber capabilities, and the threshold defining "covered" models, remain classified 1. Anthropic, Google, Meta and OpenAI are expected to review a draft at a Tuesday meeting with the Office of the National Cyber Director, per five people familiar with the planning cited by Politico 2.

Analyst Note: Continued refusal to disclose the framework's contents leaves frontier labs unable to determine whether specific model architectures trigger "covered" status, forcing continued delay or reshaping of release timelines ahead of Tuesday's closed-door review with the Office of the National Cyber Director. Public disclosure of the benchmarking methodology, capability threshold, or participant roster is unlikely by September 15, 2026. The executive order classifies both the benchmarking process and the coverage threshold outright, and the administration has signaled no intent to alter that posture. That judgment carries moderate confidence, resting on statutory classification language rather than any indicator of imminent reversal.

Sources:

1: White House finalizes AI framework behind closed doors - Axios

2: White House finalizes voluntary AI oversight framework - Politico

3: White House AI Framework Deadline Lapses Without Public Deliverables - Yahoo Finance

Prior Reporting - [Trump executive order on AI gives central role to NSA](https://breakingdefense.com/2026/06/trump-executive-order-on-ai-gives-central-role-to-nsa/) (2026-06-02) - [Trump's new AI safety order seeks voluntary review of new models](https://www.npr.org/2026/06/02/nx-s1-5844347/ai-safety-trump-executive-order) (2026-06-02) - [Trump signs executive order that allows voluntary federal vetting of top AI models for national security risks](https://www.pbs.org/newshour/nation/trump-signs-executive-order-that-allows-voluntary-federal-vetting-of-top-ai-models-for-national-security-risks) (2026-06-02) - [Promoting Advanced Artificial Intelligence Innovation and Security](https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/) (2026-06-02)

IC Technology & Cyber

Apple Launches Second Legal Challenge to UK Government iCloud Backdoor Order Under Investigatory Powers Act

BLUF: London's decision to reissue a narrower notice rather than retreat signals that December's Investigatory Powers Tribunal (IPT) hearing will set binding precedent on government authority to compel encryption backdoors.

Apple filed a new complaint with the UK's Investigatory Powers Tribunal in July over a technical capability notice compelling access to encrypted iCloud backups of UK users, according to a court order reported by the Financial Times 12. The notice, issued last year under the Investigatory Powers Act, followed the Home Office's withdrawal of its original demand covering both UK and US customers after objections from Washington 34. The court notified Privacy International of Apple's filing; Privacy International and Liberty have a separate complaint against such notices pending before the IPT, with a hearing scheduled for December 34. Apple and the Home Office are barred by law from discussing the notice's contents, and neither has commented publicly 3.

Analyst Note: Apple's filing confirms the Home Office reissued a narrower technical capability notice restricted to UK iCloud users after the US-brokered retreat from its original global backdoor demand, signaling London intends to pursue a scaled-down version of the same authority rather than abandon it. The company's second IPT complaint effectively merges its case with Privacy International and Liberty's pending challenge, positioning December's hearing as the venue where the tribunal weighs the legality of secret technical capability notices more broadly rather than this notice alone. Statutory gag provisions on both parties mean the case's substance, and any government fallback position, stays invisible to outside observers until the tribunal rules or details leak.

Sources:

1: Apple launches legal challenge to UK attempt to access encrypted user data - Financial Times

2: Apple Files New Challenge Against UK Effort to Access User Files - Bloomberg

3: Apple Launches New Legal Challenge Against UK Backdoor Demand - MacRumors

4: UK faces new legal challenge from Apple over backdoor access to iCloud data - AppleInsider

Prior Reporting - [Donald Trump ally warns Labour may be spying on Americans in fresh attack on Britain](https://www.gbnews.com/politics/us/labour-spying-americans-jim-jordan) (2026-06-06) - [Trump ally warns UK against 'backdoor spying' on Americans](https://www.yahoo.com/news/politics/articles/trump-ally-warns-uk-against-213041607.html) (2026-06-06) - [House Judiciary Committee Chairman Jim Jordan Warns British Home Secretary Shabana Mahmood To Stop Backdoor Spying on US Citizens](https://www.thegatewaypundit.com/2026/06/house-judiciary-committee-chairman-jim-jordan-warns-british/) (2026-06-06) - [US congressman warns UK against spying on Americans](https://www.chinapulse.com/data-news/2026/06/06/us-congressman-warns-uk-against-spying-on-americans) (2026-06-06)

IC Oversight & Policy

Pentagon Splits Iran War Casualty Database to Obscure Toll Amid War Powers Scrutiny

BLUF: Pentagon's bifurcated casualty accounting very unlikely will be reversed by September 1, denying Congress an independently verifiable combat timeline needed to enforce the 90-day War Powers authorization threshold.

The Pentagon has stopped adding Iran war casualties from July 7 onward to its Operation Epic Fury database, shifting them into a new "Overseas Operations" category after quietly removing four service member deaths from the tally and blaming "site errors" and "temporary data disruptions" 1234. The revised system now shows 14 killed and over 400 wounded as of July 27, down from the 18 killed President Trump cited on July 23 and 26 3. Military Times counted 18 killed and 624 wounded when combining both categories, including three troops killed in an Iranian missile strike in Jordan and a fourth in Erbil 2. A dozen Democratic senators pressed Defense Secretary Pete Hegseth on the discrepancy, and Representative Thomas Massie accused the Pentagon of violating the War Powers Resolution by operating more than 90 days without congressional authorization 3. Pentagon spokesmen Joel Valdez and Sean Parnell denied the revisions were meant to obscure the toll, citing data anomalies 23.

Analyst Note: The bifurcated accounting structure serves the administration's War Powers Resolution defense. The Pentagon very unlikely will unwind it to restore a single combined casualty count by September 1, 2026, a judgment that reflects high confidence. Bipartisan congressional pressure lacks the leverage to force reconsolidation absent litigation or a formal declaration dispute, and Pentagon spokesmen continue to frame each revision as a technical anomaly rather than a reversible policy choice. The split denies lawmakers an independently verifiable count of days in combat, blunting any push to enforce the 90-day authorization threshold.

Sources:

1: Pentagon secrecy deepens as Iran war drags on - Freedom of the Press Foundation

2: Pentagon moves recent KIA numbers from Iran war into 'Overseas Operations' category - Military Times

3: Pentagon Revises Casualty Figures, Sparking Transparency Debate - RFE/RL

4: Pentagon relabels U.S. casualties caused by Iran amid scrutiny of wartime transparency - Washington Post

Prior Reporting - [Pentagon Erases Wounded U.S. Troops From Iran War Casualty List: "Definition of a Cover-up"](https://theintercept.com/2026/04/22/iran-war-military-casualties-wounded/) (2026-04-22)

Adversary Intelligence

Russian SVR-Linked Hackers Compromise Hotel Wi-Fi Networks Worldwide for Credential Theft and Espionage

BLUF: Storm-2945's use of shared captive-portal infrastructure and device code phishing creates a collection threat against traveling personnel that per-hotel remediation and standard MFA cannot close.

Microsoft reported that Storm-2945, a sub-cluster of the Russia-linked Midnight Blizzard group tied to the SVR, has since early May been manipulating DNS and HTTP traffic on hotel and conference-center Wi-Fi captive portals worldwide in a campaign it tracks as CaptiveCrunch, redirecting guests toward credential theft and malware 12. Compromised networks have been identified across multiple US cities, India, and Saudi Arabia, according to ReliaQuest, which first disclosed the activity on July 23 3. The campaign delivers CornFlake, a Golang remote access trojan capable of keylogging, webcam and microphone capture, and browser credential theft, and ChocoShell, an in-memory PowerShell infostealer that harvests Microsoft 365 tokens and Wi-Fi credentials, both via fake browser or OS update pages using ClickFix techniques 12. Microsoft attributes the activity to Storm-2945 rather than APT28, the attribution ReliaQuest's earlier reporting had suggested based on tactical similarities 34, and says some landing pages have since July 16 added device code phishing against Microsoft Entra ID 4.

Analyst Note: Storm-2945's use of shared captive-portal infrastructure across hotels and conference venues means remediation cannot proceed property by property; any site sharing the same portal management system stays exposed until the initial access vector is identified. Attributing the campaign to Storm-2945 rather than APT28 recasts it as SVR-directed foreign intelligence collection against traveling officials and executives, a different threat than the Main Intelligence Directorate of the Russian General Staff (GRU)-style disruptive access initially suggested. The tactical overlap with Forest Blizzard's router-hijacking operations and shared equipment signatures across venues plausibly point to a common access broker or compromised managed-service vendor rather than direct intrusion into each property. The July 16 addition of device code phishing against Entra ID lets operators hijack an already-MFA-satisfied session without a password, closing only if device code flow is separately restricted beyond standard MFA policy. Sourcing rests on a single primary account, with other outlets republishing without independent corroboration of scope or malware samples.

Sources:

1: CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft - Microsoft Security Blog

2: Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware - The Hacker News

3: Russian hackers hijack hotel Wi-Fi networks to spy on travelers, Microsoft says - The Record

4: Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens - Security Affairs

COLLECTION GAPS

UNCLASSIFIED // OPEN SOURCE