//
OFFLINE — VIEWING CACHED CONTENT
← Back to Archive

IC BRIEF

Current as of 0343 EDT (UTC-04), Tuesday 06 October 2026

Contents

10 stories from 42 sources across 37 organizations


KEY JUDGMENTS

Adversary services are exploiting human and technical access across allied nations. Beijing's surveillance of President Lai's family on US soil escalates Chinese transnational repression; Wanying Zhang will likely face formal charges within 31 days. High confidence reflects the complaint, FBI statements, and Taiwan's confirmation. The FBI breach exposed nearly every employee and over 8,000 task force officers to foreign exploitation; full public release is unlikely within 30 days. Moderate confidence reflects the FBI's confirmation and ShinyHunters' stated intent, against thin sourcing on full scope.

Germany's intelligence chiefs have reframed Russia as an active attacker on German soil, citing the Halle/Leipzig explosives drone, and are requesting expanded surveillance powers. The sharper rhetoric may reflect legislative advocacy rather than a shift in Russian behavior. Israeli and US officials are unlikely to attribute the FlyDubai co-pilot's attack to state direction within 30 days. High confidence reflects consistent official reporting of a lone-actor picture.

Camp David deliberations on Iran and Yemen signal intensifying policy pressure, but acknowledged US airstrikes against Houthi or Iranian targets are unlikely within 30 days. Low confidence rests on anonymous sourcing and the absence of confirmed force movements. A faltering Saudi Houthi offensive would shift the calculus toward strikes.


Allied Intelligence

Spain Selects Airbus A321 for New Signals Intelligence Aircraft Program

BLUF: Madrid's selection of the A321 airframe signals intent to rebuild a strategic SIGINT capability lost since 2014, with Indra positioned as the national mission-system integrator.

The Ministry of Defense's Revista de Aeronáutica y Astronáutica disclosed that the Airbus A321 will be the basis for three new signals intelligence aircraft, The War Zone reported 1. Airbus and Indra were selected for the Santiago II definition study 2, an 18-month, €16 million contract, with the full program estimated at about €436 million 1. Escudo Digital gave €436.9 million under the Sistema de Capacidades Avanzadas de Patrulla Aérea (Advanced Airborne Patrol Capabilities System, Spain) (SCAPA) subprogram, an 8,700-kilometer range, 11 hours of endurance, and an Indra mission system fusing Electronic Intelligence (ELINT), Communications Intelligence (COMINT) and Optical Intelligence (OPTINT) data 3. It found no indication of stand-off jamming or directed-energy capability 3.

Analyst Note: Spain's choice of the A321 over a business-jet airframe shows Madrid is buying payload margin and national design authority, not a low-cost stopgap. Three aircraft would restore a collection capability lost with the Boeing 707's 2014 retirement and give Indra control of mission-system integration. Reporting describes a collection-only configuration. Open sources do not show whether Madrid reserves space, power and cooling for jamming or directed-energy additions before the airframe is fixed. Confidence in the platform choice is moderate, because it rests on one Ministry of Defense disclosure and a commentary piece repeating it. The selection may instead reflect Airbus-Getafe industrial policy and the A330 MRTT conversion precedent more than mission needs, so the design could still change during the 18-month study.

Sources:

1: Spain Picks Airbus A321 For New Electronic Intelligence Aircraft - The War Zone

2: Airbus and Indra selected to conduct definition study on future Spanish intelligence aircraft - EDR Magazine (Airbus/Indra announcement)

3: GlobalEye vuela para la OTAN, España vuela sola: el A321 español y la ventana que aún puede corregirse - Escudo Digital

European Nations Expand Independent Intelligence Capabilities as Ukraine War Exposes Critical Gaps

BLUF: Europe's new national satellite contracts will deliver incremental capability within a year, but the absence of any shared intelligence-pooling mechanism leaves the continent still dependent on Washington for integrated space intelligence.

Defence24 reported on October 4 that the war in Ukraine is changing how European states approach intelligence collection 1. CNAS reported that European states operate 17% of NATO's military satellites, and that Washington's March 2025 freeze on intelligence sharing with Ukraine exposed gaps in satellite Intelligence, Surveillance, and Reconnaissance (ISR) 2. Finnish synthetic aperture radar satellite company (ICEYE) executive Joost Elstak told Defense News the Finnish firm has contracts with the armed forces of Poland, Portugal, the Netherlands and Finland, each due its own capability within 12 months 3. Elstak said ICEYE supplied radar data to Ukraine during the freeze, and a Defense News survey found most surveyed experts expect Europe to need five to 10 years to reduce reliance on U.S. space intelligence 3.

Analyst Note: European militaries will likely field their first nationally owned radar satellite capabilities within the next 12 months, but full independence from U.S. space intelligence will not follow in that window. Sovereign contracts in four countries reduce dependence on a single provider, yet sensors are the easier problem. Pooling classified data across capitals is harder, and no source reports a mechanism for it. Launch access still runs partly through SpaceX. Defense News leans heavily on a vendor executive with a commercial stake, so the timeline deserves discounting. The shift may be mostly commercial positioning, with ministries still buying U.S. data and delaying pooling. If capabilities arrive on schedule, ministries can shift spending toward pooling and ground infrastructure. If they slip, U.S. and commercial feeds remain the primary source.

Sources:

1: Will Europe learn to spy on its own? The war in Ukraine is changing the face of intelligence - Defence24

2: There's a Way Forward for Sovereign European Space Intel, But Is There the Will? - CNAS

3: ICEYE sees role as Europe's defense space intelligence linchpin - Defense News

Israeli Intelligence Failed to Detect FlyDubai Copilot Radicalization Visible on Social Media

BLUF: Missed open-source radicalization indicators and Oman's prior grounding point to a systemic Israeli screening gap, not state direction, as the central security failure.

An Israeli official told The Times of Israel that the Omani co-pilot who attacked Captain Smit Machchhar on Flydubai FZ1073 on Wednesday had social media accounts showing jihadist radicalization and posts about killing Jews 1. Netanyahu told Fox News the co-pilot underwent Islamist radicalization 2, and The Wall Street Journal, relayed by Ynetnews, reported Oman had earlier grounded him over radical views before Flydubai hired him 3. SpyTalk, citing Israel Hayom, reported that LinkedIn photos, including one of Ayman al-Zawahiri, were visible and that Israeli authorities missed both the grounding and the online activity 4. Israeli security officials told Reuters they had found no evidence of Iranian involvement and believe he acted alone, while Netanyahu said investigators are still examining whether he was sent 3.

Analyst Note: Israeli and US officials are unlikely to publicly state by November 6 that the co-pilot was directed or sent by Iran or another state or organized group. Israeli security officials found no evidence of Iranian involvement and assess he acted alone, while Netanyahu and Trump say only that the question is under investigation. We have high confidence because Israeli officials, Netanyahu and the Reuters-relayed security officials describe the same lone-actor picture, though the reporting traces to few independent origins. The lone-actor view may be premature: UAE interrogation has only begun, and Trump says he has reason to believe Iran was involved. The nearer fight is domestic accountability, since neither Oman's grounding nor his posts reached Israeli screening and Knesset members want an urgent Shin Bet hearing. Attribution to Tehran would shift planners toward retaliation options. Otherwise the response stays on crew screening, Israel-UAE intelligence sharing and Shin Bet oversight.

Sources:

1: Omani Co-Pilot In Flydubai Attack Discussed 'Killing Jews' On Social Media: Israeli Official - Free Press Journal

2: Netanyahu: Omani co-pilot went through Islamic radicalization - Axios

3: Oman grounded Flydubai co-pilot over radical views before Israel-bound attack, report says - Ynetnews

4: New in SpyWeek: Terror Threat Triggers Emergency B-1 Evacuation from UK Base - SpyTalk

Omani Co-Pilot In Flydubai Attack Discussed 'Killing Jews' On Social Media: Israeli Official - Free Press Journal

'Radicalised' co-pilot who tried to crash flydubai jet should have been banned from flying to Israel - The Nightly

German Intelligence Chiefs Warn of Direct Russian Threat at Annual Bundestag Hearing

BLUF: Germany's three intelligence chiefs have reframed Russia as an active, present-day attacker on German soil, setting the political stage for a major expansion of domestic surveillance powers.

Bundesnachrichtendienst (Federal Intelligence Service, Germany) (BND) President Martin Jäger told the Bundestag's Parliamentary Control Panel on October 5 that Russia is waging a "shadow war" aimed mainly at intimidation, and that Germany risks a violent conflict with Russia 12. He said the BND currently has no indication of a large-scale Russian attack on NATO, though low-threshold military activity in the Baltics, including false-flag operations, cannot be ruled out 23. Bundesamt für Verfassungsschutz (Federal Office for the Protection of the Constitution, Germany) (BfV) President Sinan Selen said Russia has shown readiness for sabotage and killing operations, citing the early-August discovery of an explosives-laden drone beside Ukrainian cargo aircraft at Halle/Leipzig airport, according to Handelsblatt 12. Selen said "we are being attacked now, not in 2029," and Militärischer Abschirmdienst (Military Counterintelligence Service, Germany) (MAD) President Martina Rosenberg described "concrete attacks" on Germany 12. netzpolitik.org reported that the three chiefs also requested substantially expanded powers 4.

Analyst Note: Germany's services have moved from abstract warning to naming Russia as an active attacker, and the chiefs' request for expanded powers turns the annual hearing into a legislative push. Jäger sees no sign of a large-scale attack on NATO but does not rule out low-threshold Russian activity in the Baltics, including false-flag operations. Selen's account of the Halle/Leipzig drone shows sabotage and killing operations are already in use. The 2029 date is a planning horizon, not a timing warning. Handelsblatt, netzpolitik.org, and Pravda NATO all report the same public hearing, so their agreement is not independent corroboration. The sharper language may instead be advocacy for expanded powers, not a change in Russian behavior.

Sources:

1: Nachrichtendienste sehen Russland als gefährlichsten Gegner - Deutscher Bundestag

2: Anhörung im Bundestag: BND-Chef sieht Deutschland im „Schattenkrieg“ mit Russland - Handelsblatt

3: Germany risks being drawn into an armed conflict with Russia at annual public hearings of German intelligence services - Pravda NATO

4: Parlamentarisches Kontrollgremium: Operieren in der Grauzone - netzpolitik.org

Counterintelligence

FBI Breach Extended to 8000 Local Law Enforcement Officers as Agents Blame Incompetence

BLUF: Exposure of nearly every FBI employee and 8,000 task force officers creates a lasting counterintelligence vulnerability that foreign services can exploit regardless of whether ShinyHunters publishes the full dataset.

Six current and former FBI officials told MS NOW that the breach exposed personal data on nearly every FBI employee and on more than 8,000 state and local officers assigned to FBI task forces 1. An FBI official confirmed task force officers were victims and are being notified 1. ShinyHunters claimed the intrusion on September 23, saying it hit the FBIJobs.gov portal through an Oracle PeopleSoft zero-day, and gave 404 Media a sample of about 5,000 employee records 234. MS NOW's sources said the core investigative network and classified systems were not penetrated, and an FBI spokesman attributed the incident to a third-party vendor platform failure 1. One FBI cyber agent called the cause "incompetence," saying a patched vulnerability had a missed avenue and the data had been moved to an internet-facing system 1. ShinyHunters separately claimed 2 TB of data, including FBI medical records, which no source has verified 2.

Analyst Note: Full public release of the FBI employee dataset within the next 30 days is unlikely, because ShinyHunters has said it does not plan to publish the full set and wants the FBI to retract an advisory, not to earn money. The group may instead be holding the data back as leverage or for private sale, so a pause would reflect bargaining, not restraint. Either way, China and Russia need no leak to exploit data on nearly every employee and more than 8,000 task force officers, so the counterintelligence exposure persists. The FBI's acknowledgment moves this from unproven claim to confirmed compromise. Confidence is low: MS NOW's anonymous officials are the only original source on scope and cause, other outlets amplify the hackers' unverified claims, and the FBI has not disclosed full scope. If the dataset surfaces publicly, FBI and local agencies must shift from notification to protecting families, including identity monitoring and relocation support.

Sources:

1: Incompetence: Massive FBI hack hit most employees and extends to local officials - MS NOW

2: ShinyHunters Claims FBI Breach, Says It Stole Data on FBI Employees and Applicants - The Hacker News

3: FBI investigates hackers' claim to have stolen sensitive employee data, compromised jobs website - The Star (Malaysia)

4: Hacking group claims to have stolen thousands of FBI employee records - Anchorage Daily News (AP)

'We Hacked the FBI:' Hackers Say They Have Data on All FBI Employees - 404 Media

Prior Reporting - [Hacking group ShinyHunters claims it breached the FBI, stole agents' and applicants' data](https://techcrunch.com/2026/09/22/hacking-group-shinyhunters-claims-it-breached-the-fbi-stole-agents-and-applicants-data/) (2026-09-22) - [ShinyHunters hackers say they breached FBI, stole data on bureau employees](https://www.cnbc.com/2026/09/22/shinyhunters-hack-fbi-stole-data.html) (2026-09-22) - [ShinyHunters hackers say they breached FBI](https://www.investing.com/news/world-news/shinyhunters-hackers-say-they-breached-federal-bureau-of-investigation-no-immediate-comment-from-fbi-4911404) (2026-09-22)

Indian Navy Sailor Arrested for Leaking Classified Intelligence to Pakistan Via Social Media Honey Trap

BLUF: Involvement of a contract driver alongside the arrested sailor suggests Pakistani intelligence cultivated multiple access points into Eastern Naval Command operations at Visakhapatnam.

The Andhra Pradesh Police Counter Intelligence cell arrested Pradeep Mukherjee, a 31-year-old Navy sailor from West Bengal, at Indian Naval Station (INS) Agrani in Coimbatore, where he was attending a management development course 1. Indian Defence News dates the arrest to October 3 2, and Deccan Chronicle's account describes it as Saturday 1. Deccan Chronicle, citing official sources, reports that Mukherjee, posted to Eastern Naval Command at Visakhapatnam, was contacted on social media by a female Pakistani operative and passed information on strategic naval assets, fleet movements, and operational arrangements tied to the Visakhapatnam base 1. Local sources told Deccan Chronicle that investigators also detained a contract driver of naval vehicles who was in contact with the same operative 1.

Analyst Note: It is genuinely uncertain whether Indian authorities will file a formal chargesheet against the sailor by January 4. The outcome turns on whether the case stays with Andhra Pradesh Police or moves to the National Investigation Agency (India) (NIA), which would reset the statutory detention clock. The detained contract driver is a second accused whose evidence could speed or slow filing. Confidence is low: all three outlets are secondary, Deccan Chronicle is strongest, and the account rests on unnamed official and local sources, with no charges, statutes, or custody terms public. The case may instead be resolved quietly through internal naval and Official Secrets Act channels, or folded into an existing NIA probe, leaving no standalone chargesheet. A filing would show the case advancing in court and would prompt the Navy and state counterintelligence to expand social media vetting at Visakhapatnam, while no filing would point to a transfer or stall.

Sources:

1: AP Police Arrest Navy Sailor Over Alleged Pak-Linked Honey Trap - Deccan Chronicle

2: Indian Navy Sailor Held In Pakistan Honey Trap Spy Case Over Alleged Leak of Sensitive Naval Intelligence - Indian Defence News

Honey-trap espionage racket busted as Indian Navy sailor arrested for leaking maritime intelligence to Pakistani operative - India.com

Adversary Intelligence

US Arrests California Woman for Spying on Taiwan President Lai Family for China

BLUF: Beijing's documented surveillance of President Lai's family on US soil marks an escalation of Chinese transnational repression that will pressure Washington to tighten counterintelligence cooperation with Taipei.

The FBI arrested Wanying "Heather" Zhang, 34, of Irvine, California, at Los Angeles International Airport on Sunday as she tried to leave for China, on a charge of acting as an unregistered agent of China 123. According to a federal complaint cited by CNN, Zhang and an associate flew to Seattle on September 1, 2025, and filmed a close relative of a Taiwanese official outside the relative's home 1. The FBI said the target was President Lai Ching-te's son and his family, and NBC News reported that the FBI shared a New York Post report naming him as Lai Ting-yu 2. First Assistant US Attorney Bill Essayli said Zhang sent photos, video and license plate information to Chinese officials and was due in Los Angeles federal court Monday 24. Taiwan's Presidential Office called the case "transnational repression", and Beijing has not responded 23.

Analyst Note: A federal indictment or information against Wanying Zhang is likely by November 6, because prosecutors who arrest on a complaint must file formal charges within a short statutory window unless she waives it or the case resolves by plea. The complaint's own language, that surveillance of a leader's family could give Beijing leverage "during any potential conflict," frames the case as a counterintelligence matter and supports a fast, public prosecution. The unnamed associate, "Individual 1," is the next indicator to watch for a superseding charge or sealed action. We have high confidence in this assessment: the complaint, FBI statements and Taiwan's own confirmation agree on the core facts.

Sources:

1: California woman arrested for spying for China and surveilling Taiwanese president's son, officials say - CNN

2: U.S. accuses California woman of spying for China, including surveilling Taiwan president's son - NBC News

3: FBI arrests a woman accused of spying on Taiwan leader's family for China - NPR

4: US arrests woman accused of spying for China on Taiwan leader's family - Hong Kong Free Press

Moroccan Intelligence DGST Deployed Extensive Surveillance Against Journalists and Rights Defenders Using Pegasus

BLUF: Amnesty's public attribution of Pegasus deployment to the Direction Générale de la Surveillance du Territoire (Morocco) (DGST) by name exposes Morocco to structured European legal and diplomatic consequences that blanket denials can no longer deflect.

Amnesty International's report, published October 1, identifies Morocco's DGST as the entity that deployed Pegasus spyware from September 2017, drawing on testimony from a former DGST employee using the pseudonym Safir, leaked records, forensic analysis, and interviews with ten targets 1. Amnesty matched 103 phone numbers entered in the Pegasus system between September and December 2017 to individuals, including 34 human rights defenders and 22 journalists or media workers 1. Safir described physical infection of devices, phones sold pre-infected through shops, and hidden microphones in journalist Omar Radi's apartment 1. Moroccan authorities did not respond to Amnesty's letter or to CPJ's request for comment 12; CPJ called on Morocco to end the surveillance 2, and Security Online relayed the findings on October 5 3.

Analyst Note: Rabat faces rising exposure to European litigation and diplomatic pressure now that Amnesty has publicly tied the DGST to Pegasus. Morocco's earlier blanket denials now sit against leaked targeting records, forensic attribution, and insider testimony, which adds corroboration to July's single-officer account of procurement through an Emirati intermediary. Everything traces to Amnesty, since CPJ and Security Online only amplify it, and the case leans heavily on one insider, Safir. The release may reflect Amnesty's and Forbidden Stories' campaign timing more than any operational shift, and Morocco could again prevail by denial alone. Pre-infected phones and hidden microphones show the apparatus extends beyond spyware, so patching or vendor changes will not end it. Morocco has not replied, so its response is not assessed.

Sources:

1: Morocco: Whistleblower Reveals How Authorities Used a Web of Surveillance to Silence Journalists and Activists - Amnesty International USA

2: CPJ urges Morocco to end press surveillance following Amnesty report - Committee to Protect Journalists

3: Moroccan Intelligence Deploys Vast Surveillance Panopticon - Security Online

Prior Reporting - [Moroccan whistleblower reveals how Rabat used Israel Pegasus spyware for surveillance](https://www.middleeasteye.net/news/whistleblower-reveals-morocco-spied-dissidents-pegasus) (2026-07-17) - [Morocco Denied Using Pegasus. Documents and Insider Accounts Tell a Different Story](https://forbiddenstories.org/how-did-morocco-become-addicted-to-tracking-down-its-opponents-with-spyware/) (2026-07-16) - [Moroccan Government Used Powerful Israeli Pegasus Spyware, Former Intelligence Officer Says](https://www.occrp.org/en/project/the-pegasus-project/moroccan-government-used-powerful-israeli-pegasus-spyware-to-hack-phone-of-journalist-former-intelligence-officer-says) (2026-07-16) - [Moroccan intelligence is believed to have spied on Spanish agents who were training them](https://forbiddenstories.org/moroccan-intelligence-is-believed-to-have-spied-on-spanish-agents-who-were-training-them/) (2026-07-17) - [Codename "Morgan": how Morocco accessed Pegasus, involving Israel and the United Arab Emirates](https://forbiddenstories.org/codename-morgan-a-look-back-at-moroccos-acquisition-of-pegasus-involving-israel-and-the-united-arab-emirates/) (2026-07-16)

China-Nexus UAT-11587 Espionage Campaign Deploys Antino Backdoor Against Asian Government Organizations

BLUF: Antino's use of legitimate Microsoft 365 channels for command and control lets implants persist inside enterprise allowlists, and undetected footholds across affected Asian government networks may remain active.

Cisco Talos, in a report published September 30, traced Unattributed Threat (Cisco Talos designation) (UAT)-11587 activity from September 2025 through July 2026 and assessed with high confidence that the actor is China-nexus 12. eSecurity Planet's summary of that report says Talos found about 350 compromised endpoints across eight countries, including Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria 1. The Hacker News lists seven of those countries and omits Syria 3. Per the same account, targets included defense, diplomatic, law enforcement and legislative bodies, universities and think tanks 1. Talos reported that the previously undocumented Rust backdoor Antino arrives via spear-phishing and runs command and control through Microsoft Graph, using Outlook for commands and OneDrive for heartbeats and file exfiltration 14. Talos did not attribute the actor to a specific Chinese agency 1.

Analyst Note: Defenders in Asian government, diplomatic and policy bodies should treat Microsoft Graph traffic from unexpected process trees as a live intrusion indicator, since Antino hides command and control in Outlook and OneDrive sessions that enterprise allowlists permit. Everything traces to one Cisco Talos report, which attributes the actor to China-nexus activity but names no specific agency, and other outlets only amplify it. Collection against defense, diplomatic and legislative targets points to intelligence gathering. Nothing shows the operation ended in July, so undetected implants remain possible. The roughly 350 endpoints may overstate coordinated state tasking, since a regional contractor or several loosely linked operators could have run overlapping campaigns that Talos grouped together.

Sources:

1: China-Linked Hackers Target Asian Governments With Antino Backdoor - eSecurity Planet

2: UAT-11587 Antino Backdoor - SecurityOnline

3: Antino Backdoor Uses Outlook and OneDrive for C2 in China-Linked Campaign Against Asian Governments - The Hacker News

4: 5th October Threat Intelligence Report - Check Point Research

China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor - Cisco Talos

IC Operations & Tradecraft

CIA Director Ratcliffe Joins Secret Camp David Meeting on Iran and Yemen Options

BLUF: Camp David deliberations signal intensifying policy pressure on Iran, but acknowledged U.S. airstrikes on Houthi or Iranian targets within the next 30 days remain unlikely absent a presidential launch order.

Axios reported, citing three U.S. officials, that Vice President JD Vance chaired a secret, several-hour Camp David meeting on Friday on the Iran war and the Saudi-Houthi conflict in Yemen 12. Attendees included Rubio, Hegseth, Witkoff, CIA Director John Ratcliffe and Gen. Dan Caine 23. One official said "things were decided, or at least deeply discussed," and the White House declined comment 3. SpyTalk, relaying Axios, reported that the last similar meeting came in June 2025, days before Israel's war on Iran, and that Treasury Secretary Bessent also attended 4. Trump said Thursday that Iran must sign a deal or "won't exist any longer" 2. Reuters and Axios reported Saudi Arabia is preparing a Houthi offensive, and the U.S. has twice declined Riyadh's request for airstrikes 23.

Analyst Note: US acknowledged airstrikes on Houthi targets in Yemen or on Iranian territory are unlikely within the next 30 days. Washington has twice refused Riyadh's strike requests, and a session that "decided, or at least deeply discussed" options does not commit the President to strike. Confidence is low because the account rests on anonymous officials and no launch order or force movement confirms a decision. Axios is the only primary source, and every other outlet repeats it. Bessent's attendance and the Saudi rejections lower the earlier expectation that a resumption decision was near, though that could change if the Houthi offensive falters. The meeting may instead have been contingency planning meant to press Tehran toward a deal, with the carrier buildup as leverage. If strikes come, CENTCOM and Gulf partners must shift air assets toward a second front. If not, Riyadh fights on indirect US support.

Sources:

1: Report: Trump Aides Held Secret Camp David Meeting on Iran, Yemen - Haaretz

2: Trump's Cabinet Secretly Meets at Camp David on Iran, Yemen - La Voce di New York

3: Iran, Yemen on agenda as secret Camp David meeting led by Donald Trump, JD Vance - The Jerusalem Post

4: New in SpyWeek: Terror Threat Triggers Emergency B-1 Evacuation from UK Base - SpyTalk

Scoop: Trump's top national security aides meet secretly at Camp David on Iran, Yemen - Axios

Prior Reporting - [Trump's top national security aides held secret meeting at Camp David on Iran, Yemen — report](https://www.timesofisrael.com/liveblog-october-03-2026/) (2026-10-03) - [Trump's Top National Security Aides Meet Secretly at Camp David on Iran, Yemen, Axios Reports](https://english.aawsat.com/world/5325346-trumps-top-national-security-aides-meet-secretly-camp-david-iran-yemen-axios-reports) (2026-10-03) - [Trump, Vance discuss Iran, Yemen with top security aides at secret Camp David meeting - Axios](http://www.jpost.com/international/article-910444) (2026-10-03)

COLLECTION GAPS

UNCLASSIFIED // OPEN SOURCE