<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:nb="https://www.newsbreak.com/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Defense One - Threats</title><link>https://www.defenseone.com/threats/</link><description>News and analysis of global and U.S. national security.</description><atom:link href="https://www.defenseone.com/rss/threats/" rel="self"></atom:link><language>en-us</language><lastBuildDate>Tue, 29 Sep 2026 13:38:00 -0400</lastBuildDate><item><title>After 40 days of combat, Navy destroyer returns home</title><link>https://www.defenseone.com/threats/2026/09/after-40-days-combat-navy-destroyer-returns-home/416311/</link><description>During its 10-month deployment, USS Frank Petersen Jr. warded off scores of Iranian missiles and drones.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Jennifer Hlad</dc:creator><pubDate>Tue, 29 Sep 2026 13:38:00 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/09/after-40-days-combat-navy-destroyer-returns-home/416311/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;&lt;strong&gt;JOINT BASE PEARL HARBOR-HICKAM, Hawaii&lt;/strong&gt;&amp;mdash;Some 300 days after leaving Hawaii, the guided-missile destroyer Frank E. Petersen Jr. was welcomed home Monday with delighted cheers, jangling cowbells, handmade posters, and fresh flower leis.&amp;nbsp;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The ship&amp;mdash;part of the Abraham Lincoln carrier strike group&amp;mdash;did 40 days of combat operations and spent six months in an active combat zone. It started its deployment in December with operations in the South China Sea, but in late January was redirected to the Middle East, shortly before President Donald Trump launched&lt;a href="https://www.defenseone.com/threats/2026/03/first-24-hours-trumps-war-iran-numbers/411789/"&gt; Operation Epic Fury&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The Petersen took part in the war&amp;rsquo;s initial strikes on Iran, &lt;a href="https://www.dvidshub.net/image/9542622/frank-e-petersen-jr-supports-operation-epic-fury"&gt;firing Tomahawk missiles&lt;/a&gt; at land targets on Feb. 28. Then, as the strike group&amp;rsquo;s air and missile defense commander, the destroyer warded off more than 100 Iranian missiles and drones launched against its group and other ships in the region.&lt;/p&gt;

&lt;p&gt;We made sure that we kept dozens of ships safe against a variety of different attacks&amp;mdash;missile attacks, drone attacks,&amp;rdquo; said Capt. Casey Mahon, the ship&amp;rsquo;s commander.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The destroyer, commissioned in 2022, sailed more than 85,000 nautical miles during the deployment and conducted 45 replenishments at sea. At one point, the ship spent 106 days at sea between port calls, Mahon said.&lt;/p&gt;

&lt;p&gt;It also was the first ship to enter the Strait of Hormuz after the end of major combat operations, he said, which was &amp;ldquo;quite a voyage.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Obviously there was stress we had to face when we did that&amp;hellip;on the sea, under the sea, and in the air.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Though some of the adversary technology the crew faced was new, he said, &amp;ldquo;air defense really hasn&amp;rsquo;t changed a lot of ways since World War II: You have a radar, you find the thing, you&amp;rsquo;ve got to track it.&amp;rdquo; Still, &amp;ldquo;how these things fly, how they do their missions are very different, and so the crew showed a lot of adaptability to that,&amp;rdquo; and the ship&amp;rsquo;s systems were also &amp;ldquo;very effective in that adaptability.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The Petersen learned lessons both in &amp;ldquo;how to stay at sea for a long time&amp;rdquo; and in how to defend against new tactics, Mahon said, and has passed on those lessons to other ships that are in the region now.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Like any good Navy ship, you know, you&amp;rsquo;re ready for that next mission,&amp;rdquo; Mahon said. &amp;ldquo;It wasn&amp;rsquo;t what we expected to happen on deployment, but for the crew, you know, whether you&amp;rsquo;re in the north Arabian Sea or the South China Sea, you&amp;rsquo;re at sea, and so we do the operations that we&amp;rsquo;re directed to do.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Clutching &lt;a href="https://www.nps.gov/media/video/view.htm?id=84c871d2-8a35-4d81-a87a-5c076e0bf0ca"&gt;ti leaf lei&lt;/a&gt; as she waited on the pier with her two children, Alysha Nishikawa said she was worried at times during the deployment, but she tried to &amp;ldquo;throw out positive energy&amp;rdquo; to her husband and reassure him that they were OK so he could continue to do his job.&lt;/p&gt;

&lt;p&gt;Petty Officer 1st Class Ryhean Tucker, who was one of the first sailors to reunite with his family as the recipient of the &amp;ldquo;first kiss,&amp;rdquo; said the deployment was &amp;ldquo;stressful&amp;rdquo; and challenging. His wife, Taylor Tucker, said it was also challenging for her, taking care of their two children and moving from Virginia to Hawaii.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;It was a big job, but we did it,&amp;rdquo; she said.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/09/29/IMG_1364/large.mpo" width="618" height="284"><media:description>The Frank E. Petersen Jr. returns to its homeport, Joint Base Pearl Harbor-Hickam, Hawaii, on Sept. 28, 2026 after a 10-month deployment. </media:description><media:credit>Jennifer Hlad / Defense One</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/09/29/IMG_1364/thumb.mpo" width="138" height="83"></media:thumbnail></media:content></item><item><title>Hegseth orders cyber, intelligence agencies to prioritize election defense</title><link>https://www.defenseone.com/threats/2026/09/hegseth-orders-cyber-intelligence-agencies-prioritize-election-defense/416295/</link><description>The directive comes as the administration has dismantled or reorganized offices that tracked foreign influence and reduced civilian election security support.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Mon, 28 Sep 2026 18:15:00 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/09/hegseth-orders-cyber-intelligence-agencies-prioritize-election-defense/416295/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;Defense Secretary Pete Hegseth directed U.S. Cyber Command and military intelligence agencies to prioritize countering foreign threats to the upcoming elections, ordering intelligence collection and coordination with the Department of Homeland Security.&lt;/p&gt;

&lt;p&gt;The Sept. 22 &lt;a href="https://media.defense.gov/2026/Sep/28/2004007844/-1/-1/1/COUNTERING-FOREIGN-THREATS-TO-2026-ELECTIONS.PDF"&gt;memorandum&lt;/a&gt; was released publicly Monday and instructs the defense intelligence enterprise to gather and analyze information on foreign election threats. It separately directs Cyber Command to use its existing authorities and capabilities to counter potential cyberattacks by foreign actors targeting the elections.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I am therefore directing the entire [Defense Intelligence Enterprise] to mobilize every authorized asset, capability, and partnership under your command to defend our election infrastructure from foreign malign influence,&amp;rdquo; Hegseth wrote.&lt;/p&gt;

&lt;p&gt;The memo is addressed to the leaders of Cyber Command, the National Security Agency, the Defense Intelligence Agency and the National Geospatial-Intelligence Agency. It calls protecting elections a &amp;ldquo;no-fail mission,&amp;rdquo; but does not identify particular adversaries or operations, specify additional staffing or funding, or set implementation deadlines.&lt;/p&gt;

&lt;p&gt;The directive notably comes amid a broader retreat from dedicated federal efforts to track foreign influence and disinformation. The second Trump administration has dismantled the FBI&amp;rsquo;s Foreign Influence Task Force, reorganized the intelligence community&amp;rsquo;s coordination of that work and reduced election security support at the Cybersecurity and Infrastructure Security Agency.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;At the Office of the Director of National Intelligence, an overhaul shifted many responsibilities of the Foreign Malign Influence Center to other offices. ODNI has subsequently&lt;a href="https://www.nextgov.com/defense/2026/05/odni-assigns-two-officials-lead-intelligence-coordination-election-threats/413567/"&gt; assigned two officials&lt;/a&gt; to coordinate election threat intelligence.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Foreign election threats can range from attacks on voting-related computer systems to campaigns intended to manipulate public opinion.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The NSA collects foreign signals intelligence, including intercepted communications, to understand adversaries&amp;rsquo; plans and capabilities, while also helping protect sensitive U.S. systems. Cyber Command conducts military cyber operations, including missions to disrupt foreign hackers and the infrastructure they use.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The organizations have previously combined those capabilities through a joint Election Security Group. In a&lt;a href="https://www.nsa.gov/Press-Room/News-Highlights/Article/Article/3136987/how-nsa-us-cyber-command-are-defending-midterm-elections-one-team-one-fight/"&gt; description of its work during the 2022 midterms&lt;/a&gt;, NSA explained that intelligence about an attack originating abroad could be shared with domestic agencies to help them defend against it, while Cyber Command could use offensive operations to disrupt the foreign attacker.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Hegseth&amp;rsquo;s memo does not specify whether the same organizational model will be used this year. It directs intelligence work to comply with applicable laws and policies and tells Cyber Command to operate under its existing authorities.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The directive also emphasizes cooperation with DHS as that agency&amp;rsquo;s civilian cyberdefense agency outlines how it will assist election officials following staffing and program reductions.&lt;/p&gt;

&lt;p&gt;Two days after Hegseth signed the memo, CISA&amp;mdash;housed within DHS&amp;mdash;&lt;a href="https://www.nextgov.com/cybersecurity/2026/09/cisa-pledges-election-security-support-after-cuts-weakened-ties-states/416194/"&gt;released an election security plan&lt;/a&gt; identifying its 10 regional directors as election security advisers and describing a free threat-sharing platform connecting election officials, state intelligence hubs and federal partners. That plan followed warnings from state officials that earlier cuts had weakened their access to federal security expertise.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The 2026 elections come as rapid advances in AI allow foreign influence operators to &lt;a href="https://www.nextgov.com/cybersecurity/2025/08/researchers-detail-new-gray-zone-conflict-ai-driven-chinese-propaganda/407358/"&gt;automate more of their work&lt;/a&gt;. Such capabilities could let adversaries run larger campaigns with fewer people, adding to the challenge of identifying coordinated manipulation ahead of the midterms.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/09/29/092826HegsethNG/large.jpg" width="618" height="284"><media:description>Defense Secretary Pete Hegseth speaks during the department's 2026 National POW/MIA Recognition Day Ceremony on the Pentagon on Sept. 18, 2026.</media:description><media:credit> Andrew Harnik / Getty Images</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/09/29/092826HegsethNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Anthropic loses legal fight to shed DOD's designation as a 'supply-chain risk' </title><link>https://www.defenseone.com/threats/2026/09/anthropic-lawsuit-supply-chain-risk/416252/</link><description>The label is more typically assigned to companies suspected of ties to adversarial governments.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Croxton</dc:creator><pubDate>Fri, 25 Sep 2026 17:57:36 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/09/anthropic-lawsuit-supply-chain-risk/416252/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;Anthropic will remain a Pentagon-designated supply-chain risk, thanks to federal judges who ruled that the Defense Department can prohibit its employees and contractors from using the AI company&amp;#39;s products for DOD business.&lt;/p&gt;

&lt;p&gt;The designation has been in force since March, when the department sought to alter its contract with Anthropic to replace prohibitions on using its tools for domestic mass surveillance and fully autonomous weapons with allowances for &amp;ldquo;all lawful use.&amp;quot;&lt;/p&gt;

&lt;p&gt;The department has used two statutory justifications for labeling Anthropic a supply-chain risk, a designation typically applied to firms suspected to be working for adversarial governments. Anthropic beat back one of the justifications in an August &lt;a href="https://apnews.com/article/anthropic-pentagon-lawsuit-supply-chain-risk-f15e3c30186385e73e72bee82d85b05c"&gt;ruling&lt;/a&gt; in the Northern District of California, but did not prevail in a lawsuit heard by the D.C. Circuit Court of Appeals.&lt;/p&gt;

&lt;p&gt;Friday&amp;#39;s &lt;a href="https://www.documentcloud.org/documents/28686034-cadc-anthropic/"&gt;ruling&lt;/a&gt; was issued by Judges Gregory Katsas and Neomi Rao, both appointed during the first Trump administration, with a dissent by Judge Karen LeCraft Henderson, who was appointed by the first President Bush.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;This was not an unexpected outcome given the composition of the panel that heard the case&amp;rdquo; said Charlie Bullock, senior research fellow at the Institute for Law &amp;amp; AI think tank. &amp;ldquo;Historically, both Katsas and Rao have shown a great deal of deference to the Trump administration&amp;#39;s assertions of executive authority on matters of national security. If Anthropic had drawn almost any other two judges from the D.C. Circuit for that panel they would have stood a good chance of winning, because I think their legal position is overwhelmingly strong.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I think Anthropic&amp;rsquo;s chances on appeal if they get to appeal either to the &lt;em&gt;en banc&lt;/em&gt; D.C. Circuit or the Supreme Court are good. But they&amp;rsquo;re not guaranteed to be heard, because the appeals process is discretionary,&amp;rdquo; Bullock said.&lt;/p&gt;

&lt;div class="related-articles-placeholder"&gt;[[Related Posts]]&lt;/div&gt;

&lt;p&gt;In a &lt;a href="https://www.washingtonsun.com/defense/federal-appeals-court-rejects-anthropic-challenge-pentagon-blacklist"&gt;statement&lt;/a&gt; to &lt;em&gt;The Washington Sun&lt;/em&gt;, an Anthropic spokesperson said, &amp;ldquo;We respectfully disagree with the court&amp;rsquo;s decision. Another federal court has already held the government&amp;rsquo;s parallel designation unlawful.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Anthropic added, &amp;ldquo;We remain confident in our position and are considering all options, including further review.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Defense Undersecretary Emil Michael wrote in a &lt;a href="https://x.com/uswremichael/status/2103523346092613665"&gt;statement&lt;/a&gt; on X, &amp;ldquo;The hammer of justice has smashed @AnthropicAI arguments. They are a supply-chain risk to the defense industrial base serving the @DeptofWar. Warfighters will sleep better knowing that no private company will insert their opinions in the chain of command. @SecWar was right!&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The ruling will likely keep the Pentagon and its other contractors &lt;a href="https://www.cnbc.com/2026/03/09/anthropic-was-the-pentagons-choice-for-ai-now-its-banned-and-experts-are-worried.html"&gt;reducing&lt;/a&gt; their use of Anthropic&amp;#39;s products, such as its Claude tools. Overall, however, the company&amp;#39;s revenue is growing about &lt;a href="https://epochai.substack.com/p/an-update-on-ais-most-important-number"&gt;tenfold&lt;/a&gt; per year, and plans an IPO in November that some expect to value the company at a &lt;a href="https://www.wsj.com/tech/ai/anthropic-shifts-planned-ipo-to-november-8874dffc"&gt;record $2 trillion&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Michael and Defense Secretary Pete Hegseth have been critical of Anthropic in public statements. In January, Hegseth stated in remarks at a SpaceX event, &amp;ldquo;Department of War AI will not be woke. It will work for us. We&amp;#39;re building war-ready weapons and systems, not chatbots for an Ivy League faculty lounge.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;DOD issued an ultimatum on Feb. 24 demanding the company permit its AI to be used for all legal purposes by Feb. 27, which Anthropic refused. Hegseth announced his direction that DOD designate Anthropic a supply-chain risk Feb. 27, and it was formally &lt;a href="https://www.defenseone.com/business/2026/03/pentagons-war-anthropic-based-dubious-legal-thinking-and-ideologynot-real-risk-sources-say/411849/"&gt;announced&lt;/a&gt; on March 3.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/09/25/GettyImages_2294307208/large.jpg" width="618" height="284"><media:credit>CFOTO/Future Publishing via Getty Images</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/09/25/GettyImages_2294307208/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Stolen FBI data reveals employees’ roles in intelligence and surveillance</title><link>https://www.defenseone.com/threats/2026/09/stolen-fbi-data-reveals-employees-roles-intelligence-and-surveillance/416185/</link><description>Exposed analysts work on areas including China, Russia, and electronic surveillance. ShinyHunters claimed responsibility for the breach this week. The FBI said it’s investigating.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Wed, 23 Sep 2026 23:33:00 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/09/stolen-fbi-data-reveals-employees-roles-intelligence-and-surveillance/416185/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;Data stolen in a major hacking group&amp;rsquo;s alleged intrusion into FBI systems is believed to contain personal information on hundreds of FBI intelligence analysts and other employees involved in clandestine intelligence-gathering and surveillance, according to two people familiar with the matter.&lt;/p&gt;

&lt;p&gt;The analysts focus on myriad subject areas like Russia, China, Hezbollah, and cartel-related intelligence, said the people, who spoke on the condition of anonymity because the exposures are sensitive. The employees&amp;rsquo; roles only offer a small picture of their duties, but may still help outsiders identify people working in sensitive parts of the bureau.&lt;/p&gt;

&lt;p&gt;ShinyHunters claimed responsibility for the breach Monday, threatening to release what it described as two to three terabytes of FBI employee data unless the bureau retracted a public warning about its tactics within a week.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;On Tuesday, the group &lt;a href="https://www.nextgov.com/cybersecurity/2026/09/shinyhunters-claims-fbi-data-theft-demands-bureau-retract-cyber-warning/416144/?oref=ng-author-river"&gt;sent &lt;em&gt;Nextgov/FCW&lt;/em&gt;&lt;/a&gt;&lt;em&gt; &lt;/em&gt;and other news outlets an apparent sample of that data containing roughly 5,000 entries listing employees&amp;rsquo; names, home addresses, phone numbers and information about their spouses and siblings.&lt;/p&gt;

&lt;p&gt;Multiple individuals also work on human intelligence-gathering, as well as roles involving electronic surveillance activities that make use of &lt;a href="https://www.fcc.gov/calea"&gt;telecom interception techniques&lt;/a&gt; and other covert access mechanisms. Some employees work in the FBI&amp;rsquo;s Remote Operations Unit, which builds specialized tools to target computers and networks.&lt;/p&gt;

&lt;p&gt;One person works in the bureau&amp;rsquo;s FISA Management Unit, which handles the processing of applications and renewals under the Foreign Intelligence Surveillance Act that governs &lt;a href="https://www.nextgov.com/cybersecurity/2026/03/fbi-queries-americans-data-under-fisa-702-rose-35-2025/412103/"&gt;surveillance and search&lt;/a&gt; standards used to collect foreign intelligence.&lt;/p&gt;

&lt;p&gt;The FBI said it was aware of &amp;ldquo;a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information&amp;rdquo; and added that it is investigating the matter.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The agency said the cause of the breach was still undetermined. ShinyHunters previously said it exploited vulnerabilities in Amazon and Oracle services to access the bureau data. Neither company has returned a request for comment.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://www.reuters.com/world/hacked-fbi-data-has-sensitive-information-about-employees-intelligence-roles-2026-09-23/"&gt;Reuters&lt;/a&gt; and &lt;a href="https://www.404media.co/fbi-hack-exposed-fbis-own-hacking-unit-remote-operations-shinyhunters/"&gt;404 Media&lt;/a&gt; previously reported details regarding the intelligence roles and the ROU staff.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The language ShinyHunters wants removed appears in a May 15 &lt;a href="https://www.ic3.gov/PSA/2026/PSA260515"&gt;FBI public service announcement&lt;/a&gt; that describes practices the hacking group contests. The group has built a global reputation for various hacking achievements. In May, it claimed responsibility for &lt;a href="https://www.nextgov.com/cybersecurity/2026/05/canvas-breach-spotlights-cybercriminal-appetite-student-data/413451/"&gt;accessing Canvas&lt;/a&gt;, the popular education tech platform used by thousands of U.S. institutions.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The direct claim of an FBI breach is &amp;ldquo;an unusually provocative move&amp;rdquo; and should be taken seriously, said Etay Maor, the vice president of threat intelligence at Cato Networks.&lt;/p&gt;

&lt;p&gt;Exposure of sensitive bureau staffing data could pose profound counterintelligence risks. For employees who do not publicly identify themselves as working for the FBI, the exposure could reveal both their jobs and how to reach them outside secure work environments. Linking that information to home addresses and relatives&amp;rsquo; details could make it easier for nation-state groups and cyber criminals to target employees and their families with harassment, scams or threats.&lt;/p&gt;

&lt;p&gt;The breach would be &amp;ldquo;troubling news&amp;rdquo; for both FBI employees and applicants, said Doc McConnell, a former cyber policy official at the White House and the Cybersecurity and Infrastructure Security Agency.&lt;/p&gt;

&lt;p&gt;McConnell, who now heads policy and compliance at Finite State, compared the incident to the &lt;a href="https://www.govexec.com/management/2026/05/10-years-after-opm-breach-identity-protection-services-affected-feds-expire/413336/"&gt;OPM hack a decade ago&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The breach of OPM&amp;rsquo;s personnel records in 2015 resulted in a decade of credit monitoring for millions of affected individuals, and the full counterintelligence impact will likely never be known. This breach appears to contain similar data, creating potential security concerns for the victims if it is made publicly available,&amp;rdquo; he said.&lt;/p&gt;

&lt;p&gt;The bureau will likely work more assertively to crack down on ShinyHunters. When any group directly targets the agency, &amp;ldquo;they should expect that the FBI is going to marshal additional resources to bring them more quickly to justice,&amp;rdquo; said Cynthia Kaiser, the SVP of Halcyon&amp;rsquo;s Ransomware Research Center and former deputy director of the FBI&amp;rsquo;s Cyber Division.&lt;/p&gt;

&lt;p&gt;The incident follows other cyberattacks involving the bureau and its leadership this year. In March, pro-Iran hacking group Handala &lt;a href="https://www.defenseone.com/threats/2026/03/pro-iran-hackers-claim-breach-fbi-directors-email/412464/"&gt;published material&lt;/a&gt; from FBI Director Kash Patel&amp;rsquo;s personal email account, which the bureau said contained historical information unrelated to government business. Separately, a suspected China-linked &lt;a href="https://www.nextgov.com/cybersecurity/2026/04/suspected-chinese-breach-fbi-system-exposed-surveillance-targets-phone-numbers/412612/"&gt;intrusion&lt;/a&gt; into an FBI system exposed surveillance targets&amp;rsquo; phone numbers.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/09/24/GettyImages_2288940584/large.jpg" width="618" height="284"><media:credit>Kevin Carter / Contributor / Getty Images</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/09/24/GettyImages_2288940584/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Trump's FBI shut down investigation into defense contractor's alleged bribes</title><link>https://www.defenseone.com/threats/2026/09/fbi-defense-bribery-investigation/416138/</link><description>A CEO told agents about funneling money to U.S. lawmakers in return for Pentagon contracts worth millions of dollars. Then the probe was killed.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Kirsten Berg, Molly Redden, Avi Asher-Schapiro, and William Turton, ProPublica</dc:creator><pubDate>Tue, 22 Sep 2026 13:38:39 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/09/fbi-defense-bribery-investigation/416138/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;In the final weeks of 2019, a top fundraiser for Sen. Susan Collins walked into a perilous meeting at a Corner Bakery in Washington, D.C.&lt;/p&gt;

&lt;p&gt;For the first time in her two-decade Senate career, the Republican lawmaker from Maine was in danger of losing her seat. President Donald Trump&amp;rsquo;s dismal approval ratings were dragging her down in the polls, and she was falling behind her likely 2020 Democratic challenger in fundraising.&lt;/p&gt;

&lt;p&gt;Scott Reed, head of the Collins super PAC, was on a mission to close that gap. Reed was meeting that day with three executives from a Hawaiian defense contractor, Navatek. A year earlier, Collins had helped their company land a multimillion-dollar Navy research contract in Maine. Now, seated at a coffee shop not far from the U.S. Capitol, Reed asked them for a $500,000 donation.&lt;/p&gt;

&lt;p&gt;Government contractors are banned from making political contributions. More consequentially, for the company to offer donations to Collins in exchange for an official action, or for Collins to accept, would constitute criminal bribery.&lt;/p&gt;

&lt;p&gt;But the company did have such a proposal: Navatek was hungry for more government contracts in Maine. If they cut a big check, the CEO told Reed, Navatek wanted Collins to guarantee tens of millions of dollars in additional federal funding.&lt;/p&gt;

&lt;p&gt;To skirt campaign finance laws and conceal the source of the funds, Navatek planned to funnel the donation through a shell company. The CEO wanted assurance that Collins would know where the money came from. Reed confirmed that she would, the executive said &amp;mdash; and that Navatek would get its government contracts.&lt;/p&gt;

&lt;p&gt;After the Corner Bakery meeting, Navatek&amp;rsquo;s CEO, Martin Kao, sent an initial $150,000 to the Collins super PAC using the shell company. Two months later, he told Navatek executives that&amp;nbsp;Collins committed to getting the company $32 million in naval contracts, according to an internal company email reviewed by ProPublica.&lt;/p&gt;

&lt;p&gt;Three years later, Kao holed up in a conference room to recount the Corner Bakery meeting to a group of four FBI agents and federal prosecutors. The FBI had seen through his shell company ruse, and in 2022 a grand jury indicted him for making illegal campaign contributions. No one working for Collins was charged.&lt;/p&gt;

&lt;p&gt;Facing years in prison, Kao hoped to do less time by revealing the entire scheme.&lt;/p&gt;

&lt;p&gt;What he told them has never before become public. The Corner Bakery meeting, he asserted, was just one episode in a sprawling pay-to-play operation that embroiled some of the most powerful figures in Congress.&lt;/p&gt;

&lt;p&gt;Over three days at the U.S. attorney&amp;rsquo;s office in Honolulu, Kao laid out in devastating detail how his operation worked. He gave agents a 50-page document naming dozens of lobbyists, congressional staffers and members of Congress who he said helped him trade cash for contracts. Kao and his close associates had donated nearly $900,000 to dozens of politicians, allowing Navatek to establish operations in half a dozen states with over $40 million a year in government funding.&lt;/p&gt;

&lt;p&gt;Most damningly, Kao told FBI agents and prosecutors, the company&amp;rsquo;s work for the government was of no real value. Navatek&amp;rsquo;s research under his stewardship never resulted in products the military wanted to buy, ProPublica found.&lt;/p&gt;

&lt;p&gt;Kao&amp;rsquo;s tell-all interviews with the FBI lasted into late 2024. His confessions opened up an entirely new phase of the investigation. Agents sifted through hundreds of thousands of records seized during Kao&amp;rsquo;s arrest and found that many were consistent with his account of widespread influence peddling.&lt;/p&gt;

&lt;p&gt;Kao had credibility issues. He was now a felon trying to avoid a lengthy prison sentence. And there were other challenges. Building a corruption case against elected officials requires extraordinary proof of a quid pro quo arrangement, in part because the Supreme Court has narrowed what counts as bribery.&lt;/p&gt;

&lt;p&gt;Even so, by the end of 2024, the agents had enough evidence to pursue a sweeping bribery probe that could ensnare top lawmakers of both political parties. They asked their supervisors to approve a new investigation and contemplated using undercover operatives to gather more evidence. Although their effort was in its early stages, and it was unclear where it would lead, FBI agents asked Kao extensive questions about his dealings with Collins and her office.&lt;/p&gt;

&lt;p&gt;Then Trump returned to the White House. Consumed by a&amp;nbsp;&lt;a href="https://www.reuters.com/investigates/special-report/usa-trump-retribution-tracker/"&gt;campaign of vengeance&lt;/a&gt;, he stacked the Department of Justice with his personal lawyers and demanded a purge of anyone who had ever investigated him.&lt;/p&gt;

&lt;p&gt;The specialized FBI and DOJ teams handling public corruption investigations, some of which were involved in Trump-related cases, were eviscerated. One of the agents who had taken Kao&amp;rsquo;s confession was pushed out as retribution for her role in investigating Trump&amp;rsquo;s attempt to overturn the 2020 election. Dozens of agents and prosecutors quit amid the department&amp;rsquo;s destruction, including the career attorney assigned to Kao&amp;rsquo;s case.&lt;/p&gt;

&lt;p&gt;Trump&amp;rsquo;s Justice Department no longer takes on public corruption in&amp;nbsp;&lt;a href="https://www.nbcnews.com/politics/justice-department/firings-pardons-policy-changes-gutted-doj-anti-corruption-efforts-expe-rcna200571"&gt;any meaningful fashion&lt;/a&gt;, former officials said. The investigation sparked by Kao&amp;rsquo;s revelations is dead. And the government is no longer talking to an informant who had offered a road map to corruption in Congress.&lt;/p&gt;

&lt;p&gt;The White House referred ProPublica to the FBI.&lt;/p&gt;

&lt;p&gt;FBI spokesperson Ben Williamson said the agency had investigated claims against Collins years ago &amp;ldquo;and ultimately found nothing implicating Senator Collins or Senator Collins&amp;rsquo; campaign. Any suggestion otherwise is totally false.&amp;rdquo; Williamson said the Trump administration has removed agents only &amp;ldquo;if they have been found to have acted unethically, undermined the mission, or engaged in weaponization of law enforcement.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Williamson did not respond to questions about the new investigation launched in 2024 based on Kao&amp;rsquo;s previously unreported cooperation with the FBI.&lt;/p&gt;

&lt;p&gt;ProPublica is revealing the existence of the case for the first time. We reviewed a trove of evidence gathered by the FBI and thousands of pages of legal records, and interviewed dozens of people familiar with Navatek, its Washington operations, and the FBI inquiry to conduct our own investigation. We independently corroborated much of Kao&amp;rsquo;s account. Whether or not Kao&amp;rsquo;s dealings with politicians amount to criminal bribery, the Trump Justice Department has little interest in finding out, and his sheer success reveals how easily influence is purchased in Washington today. This is the first in a series of stories drawn from our reporting.&lt;/p&gt;

&lt;p&gt;Of all the politicians Navatek courted under Kao&amp;rsquo;s leadership, Collins was its most important patron. The senator&amp;rsquo;s office steered government contracts worth millions toward the company while her campaign was pumping Kao and his network for donations, according to emails seen by ProPublica. Sometimes they cut checks within 24 hours of the annual defense spending bill, which funds military contracts, clearing a key Senate hurdle.&lt;/p&gt;

&lt;p&gt;Collins&amp;rsquo; office did not specifically address questions about the Corner Bakery meeting, the senator&amp;rsquo;s relationship with Kao and the millions she helped appropriate for Navatek.&lt;/p&gt;

&lt;p&gt;Annie Clark, Collins&amp;rsquo; deputy chief of staff, told ProPublica in an email that Collins&amp;rsquo; office &amp;ldquo;vigorously&amp;rdquo; denies allegations of bribery and pay-for-play made by Kao, calling his claims &amp;ldquo;outlandish.&amp;rdquo; Collins&amp;rsquo; campaign was not part of the discussions between Kao and the super PAC, and her office &amp;ldquo;fully cooperated&amp;rdquo; with the FBI investigation, Clark said.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The fact that the FBI and Biden-led Department of Justice thoroughly examined the Navatek matter demonstrates this,&amp;rdquo; Clark wrote. &amp;ldquo;These issues were resolved in 2021 and concluded when the Collins campaign disgorged the illegal contributions that Martin Kao had made without our knowledge.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Collins is once again fighting to keep her seat, in a race that could determine control of the Senate. On the campaign trail, she spotlights the funding she directs to Maine while leading the appropriations committee, which she calls &amp;ldquo;the&amp;nbsp;&lt;a href="https://www.pressherald.com/2026/06/28/what-susan-collins-appropriations-power-means-for-maine-and-what-happens-if-she-loses/"&gt;most powerful committee&lt;/a&gt;&amp;nbsp;in the Senate.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;She demonstrated that power with Navatek. After the budgets became law, Collins&amp;rsquo; office pushed the Navy to award specific contracts to Navatek, emails seen by ProPublica show, even though awards are supposed to be competitive.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I spoke with Sen. Collins office regarding the $8M,&amp;rdquo; a naval official wrote in an email on Feb. 6, 2019. &amp;ldquo;The interested company is Navatek.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;In a meeting with Collins and two campaign officials, Kao said, the officials told him the senator expected his ongoing support. Collins told him: &amp;ldquo;You&amp;rsquo;ve seen me deliver,&amp;rdquo; Kao said.&lt;/p&gt;

&lt;p&gt;Reed knew Kao was behind the $150,000 anonymous donation, emails showed, because Kao told Reed he planned to donate through a shell company. &amp;ldquo;Very smart,&amp;rdquo; Reed replied in an email viewed by ProPublica.&lt;/p&gt;

&lt;p&gt;Reed did not respond to detailed questions about the Corner Bakery meeting, the $150,000 donation and Kao&amp;rsquo;s allegations. &amp;ldquo;I understand Martin Kao is now sitting in federal prison,&amp;rdquo; Reed wrote in a brief email. &amp;ldquo;I never had any communications with Senator Collins [or] her staff about Martin Kao and/or Navatek.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;But an email seen by ProPublica suggests that someone must have relayed the news of Kao&amp;rsquo;s donation to Collins, just like Reed promised to do in Kao&amp;rsquo;s recounting of the Corner Bakery meeting.&lt;/p&gt;

&lt;p&gt;Seven days after the super PAC cashed the check from Kao&amp;rsquo;s shell company, one of Reed&amp;rsquo;s subordinates emailed a Navatek lobbyist asking for Kao&amp;rsquo;s phone number: &amp;ldquo;Senator Collins would like to call Martin to thank him.&amp;rdquo;&lt;/p&gt;

&lt;h3&gt;The Navatek Method&lt;/h3&gt;

&lt;p&gt;Before Kao&amp;rsquo;s doomed reign as CEO, Navatek was a sleepy Hawaiian engineering company with a few dozen employees. It was founded in 1978 by Steven Loui, a talented engineer and scion of a powerful Hawaiian shipping family. Navatek was not a profit center but a vehicle for Loui&amp;rsquo;s passion projects, like an experimental catamaran for navigating Hawaii&amp;rsquo;s choppy waters.&lt;/p&gt;

&lt;p&gt;The company benefited from the largesse of the legendary Hawaii Sen. Daniel Inouye, multiple former Navatek executives and employees said, whose family had been close to the Loui family for generations. Inouye was a master of earmarks, a practice that allowed lawmakers to insert funding for specific companies by name in the federal budget. The self-styled &amp;ldquo;King of Pork&amp;rdquo; steered hundreds of millions in federal dollars to Hawaii. Former Navatek employees say he was affectionately referred to as &amp;ldquo;Uncle Dan.&amp;rdquo; &amp;ldquo;Before Inouye took an interest, Congress didn&amp;rsquo;t even know our companies existed,&amp;rdquo; a longtime Loui lieutenant wrote in a 1998 op-ed.&lt;/p&gt;

&lt;p&gt;In response to ProPublica questions, Loui said that money appropriated by Inouye made up &amp;ldquo;a minority&amp;rdquo; of Navatek&amp;rsquo;s revenue.&lt;/p&gt;

&lt;p&gt;Inouye&amp;rsquo;s death in 2012 made the company&amp;rsquo;s future uncertain. Not only was Navatek&amp;rsquo;s direct line to Capitol Hill gone, but Congress was doing away with the abuse-riddled earmark process. Now companies would nominally have to compete on the merits for government contracts.&lt;/p&gt;

&lt;p&gt;Kao joined Navatek in 2008 as its chief financial officer. Loui charged him with replacing Navatek&amp;rsquo;s rainmaker and eventually named Kao CEO. He sold Kao the company in return for a share of the profits.&lt;/p&gt;

&lt;p&gt;Kao was an unusual figure among the company&amp;rsquo;s low-key naval engineers and boat aficionados. He seemed to be aping a Wall Street tycoon, telling employees they could either be &amp;ldquo;a beast or a bitch,&amp;rdquo; a former executive said. He drove to work in a Ferrari and abruptly fired subordinates who displeased him &amp;mdash; one time, in the middle of the night. &amp;ldquo;He had very little interest in the technology,&amp;rdquo; one former employee recalled. &amp;ldquo;Martin was only interested in dollar signs.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Kao also exaggerated and lied. He told different people he had stepbrothers whose parents died in a fishing accident or an avalanche, a former employee recalled. He lied to Loui about having law degrees from both the University of California, Los Angeles and New York University. He once told a lobbyist who raised quarter horses that he owned a herd of polo ponies, just to one-up him.&lt;/p&gt;

&lt;p&gt;Despite his erratic behavior, former employees agree Kao hit upon an effective way to replace the lost earmarks. If the company could not rely on a benefactor like Inouye, it would develop a stable of them.&lt;/p&gt;

&lt;p&gt;Navatek targeted the powerful members who sat on the House and Senate appropriations committees. These members could no longer earmark money for specific military contractors. But they retained the power to budget millions of dollars for equipment or&amp;nbsp;bespoke research and development. Because Pentagon budgets run thousands of pages and are largely prepared in secret, it is easy for appropriators to add a line item intended for a contractor like Navatek without leaving any fingerprints.&lt;/p&gt;

&lt;p&gt;Soon, Kao had refined a playbook. Navatek would concoct a research project in partnership with a university in a member&amp;rsquo;s district or home state, and Kao would make a large initial campaign donation. Working with a team of pricey, well-connected lobbyists, Navatek would get meetings on Capitol Hill to pitch the research to congressional staff. Navatek kept spreadsheets, reviewed by ProPublica, that listed members of Congress as the &amp;ldquo;specialty&amp;rdquo; of certain lobbyists.&lt;/p&gt;

&lt;p&gt;Separately, Kao later told the FBI, there would be a meeting of just the key players. One engineer, who traveled with Kao to D.C. to explain the technical side of a project, recalled being sent out of the room once the subject of money came up. Sometimes in these smaller meetings, members of Congress directly asked Kao for donations, he told the FBI. In other cases, he said, Navatek&amp;rsquo;s lobbyists would relay a request from an intermediary for a specific dollar amount.&lt;/p&gt;

&lt;p&gt;Kao told the FBI that the lawmakers, lobbyists and Navatek brass understood these donations were bribes and that the payments were essential to the entire scheme. Kao believed he was buying Navatek&amp;rsquo;s way into the annual defense budget, not winning over members with innovative engineering proposals.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I&amp;rsquo;m not red or blue, I&amp;rsquo;m green,&amp;rdquo; he would tell congressional staffers, a former Navatek employee recalled.&lt;/p&gt;

&lt;p&gt;While a deal was being struck, Navatek and congressional staffers worked closely on the legislative process. Every year, Congress prefaces the defense budget with massive reports describing the purpose of inscrutable line items. Staffers would include a project description so specific that Navatek would be the only logical pick.&lt;/p&gt;

&lt;p&gt;Often, Navatek composed language that ended up, word for word, in Senate funding requests, former employees said. In 2019, for example, Navatek&amp;rsquo;s priorities were tucked into page 185 of the 307-page&amp;nbsp;&lt;a href="https://www.congress.gov/116/crpt/srpt103/CRPT-116srpt103.pdf"&gt;report&lt;/a&gt;&amp;nbsp;released by the Senate Appropriations Committee. The committee set aside $21.5 million for &amp;ldquo;hybrid composite structures research for enhanced mobility,&amp;rdquo; &amp;ldquo;electric propulsion for military craft and advanced planing hulls&amp;rdquo; and a &amp;ldquo;test bed for autonomous ship systems.&amp;rdquo; Although Navatek&amp;rsquo;s name does not appear on the page, these were all projects the company requested, according to internal documents and interviews with former employees.&lt;/p&gt;

&lt;p&gt;Once the budget passed, lawmakers&amp;rsquo; staff leaned on Navy officials to award Navatek the money. Former contracting officers told ProPublica they felt pressure to go along because money from those contracts funded their office &amp;mdash; and because members of Congress had confronted dissenting naval officials in the past. &amp;ldquo;There&amp;rsquo;s only so many battles you can fight,&amp;rdquo; one said. So Congress sometimes got its way even when Navatek&amp;rsquo;s projects made little sense.&lt;/p&gt;

&lt;p&gt;Inside Navatek, employees referred to this strategy as &amp;ldquo;the method.&amp;rdquo; And it enabled the company to string together tens of millions of dollars in contracts. The result was the same as getting earmarks: a reliable, growing revenue stream bankrolled by U.S. taxpayers.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;It was a simple enough play. Let&amp;rsquo;s find the small states that have complementary universities &amp;hellip; [and] let&amp;rsquo;s get access to their senators,&amp;rdquo; Eric Schiff, a former Navatek executive, told ProPublica. &amp;ldquo;I&amp;rsquo;ve met Susan Collins. You can get access to Susan Collins. Once we got the first things working with Maine, then we said, &amp;lsquo;Well, let&amp;rsquo;s keep reaching.&amp;rsquo; And so we did.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;In a statement to ProPublica, Navatek founder Loui said Kao&amp;rsquo;s &amp;ldquo;unethical and illegal method of winning contracts&amp;rdquo; was a departure from how he operated the company prior to Kao&amp;rsquo;s ownership.&lt;/p&gt;

&lt;p&gt;Kao boosted Navatek&amp;rsquo;s annual revenue from $10 million around the time Loui sold him the company to almost $40 million when he was arrested in 2020. In the second half of 2019 alone, Navatek paid a roster of five lobbying shops more than $500,000.&lt;/p&gt;

&lt;p&gt;Even Navatek&amp;rsquo;s executives were surprised at how far their money went in D.C. &amp;ldquo;It was eye-opening for me, frankly. &amp;lsquo;Oh my God, all of it is for sale. It&amp;rsquo;s all for sale,&amp;rsquo;&amp;rdquo; Schiff said.&lt;/p&gt;

&lt;p&gt;The key players in Kao&amp;rsquo;s pay-to-play deals went to great lengths to meet in person and leave no trace of an actual quid pro quo, he told agents. &amp;ldquo;That is why I literally had to fly to D.C. almost every week,&amp;rdquo; Kao later told the FBI. &amp;ldquo;Sometimes for a 15-minute meeting.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;But the FBI compiled emails, which ProPublica reviewed, that were suggestive of illegal bargains. Navatek executives and lobbyists spoke openly as if they were buying lawmakers&amp;rsquo; assistance. In one back-and-forth, a lobbyist and a company executive described another senator as &amp;ldquo;fundamentally transactional&amp;rdquo; and having &amp;ldquo;a reputation as a pay-to-play office.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;In another message, Andy Winer, who former executives said was Navatek&amp;rsquo;s chief strategist, reminded Kao to budget money for political contributions based on how much the company wanted in congressional funding the following year.&lt;/p&gt;

&lt;p&gt;Winer was his guide to the political underbelly, Kao said. A consummate insider, Winer had parlayed six years as chief of staff to Democratic Sen. Brian Schatz of Hawaii into a lucrative lobbying career with a firm called Strategies 360. One of Winer&amp;rsquo;s former colleagues compared him to the slick lobbyist on the Netflix show &amp;ldquo;House of Cards&amp;rdquo; who toggles between the political and corporate worlds.&lt;/p&gt;

&lt;p&gt;In another email exchange scrutinized by the FBI, Kao asked Winer about making a $5,600 donation to nudge along a senator who seemed keen to work with Navatek: &amp;ldquo;Would that &amp;lsquo;help?&amp;rsquo;&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Winer, who had already donated himself, replied, &amp;ldquo;With my contribution, I think it sends the right message.&amp;rdquo; He suggested Kao split up his donation to be &amp;ldquo;less conspicuous.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The method didn&amp;rsquo;t always work. Once, Kao complained that a senator had reneged on a deal and he ought to get his donations back.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;You should not feel aggrieved nor should you ever put that in writing,&amp;rdquo; Todd Webster, another lobbyist Navatek hired, replied. Webster did not respond to detailed questions.&lt;/p&gt;

&lt;p&gt;Winer said he stopped working with Navatek following Kao&amp;rsquo;s arrest. &amp;ldquo;The political contributions I discussed with Kao were understood by me to be lawful political contributions. I never participated in, witnessed, or had knowledge of any illegal political contribution, bribe, or agreement to exchange a political contribution for an appropriation, contract, or other official action,&amp;rdquo; Winer said in an email to ProPublica. &amp;ldquo;I never advised Kao to make a contribution in exchange for official action.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Strategies 360 has new ownership that did not oversee Winer while he represented Navatek, its CEO, John Oceguera, said.&lt;/p&gt;

&lt;p&gt;Navatek employees began to notice members of Congress visiting their East Coast offices. &amp;ldquo;You would be like, &amp;lsquo;Oh, there&amp;rsquo;s this senator walking around,&amp;rsquo; and we would get a picture with them,&amp;rdquo; one engineer recalled.&lt;/p&gt;

&lt;p&gt;While some projects involved potentially meaningful research, Navatek&amp;rsquo;s bread and butter was R&amp;amp;D that went nowhere. As a slideshow prepared by an executive explained, &amp;ldquo;We thrive in the valley of death,&amp;rdquo; the term for the bureaucratic gap where research languishes without being developed into a product. The slideshow noted that none of the technology had ever actually been deployed.&lt;/p&gt;

&lt;p&gt;The Office of Naval Research did not respond to a request for comment.&lt;/p&gt;

&lt;p&gt;In Maine, Navatek was studying ways to modify small boats to reduce the &amp;ldquo;slamming&amp;rdquo; impact felt by passengers at high speeds. With the help of the University of Maine&amp;rsquo;s giant 3D printer, Navatek made a prototype and unveiled it at a press conference where a Guinness World Records representative&amp;nbsp;&lt;a href="https://maineboats.com/print/issue-162/university-maine-3dirigo"&gt;declared it the world&amp;rsquo;s largest 3D-printed boat&lt;/a&gt;. But Navatek executives knew the Navy had no plans to use the new design, former employees said.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;[The work] got rolled into a few PowerPoint slides and a white paper, and that was the deliverable,&amp;rdquo; recalled one who worked on the project. &amp;ldquo;The boats weren&amp;rsquo;t delivered to the Navy &amp;mdash; the Navy didn&amp;rsquo;t even want them.&amp;rdquo;&lt;/p&gt;

&lt;h3&gt;Kao to Collins: &amp;ldquo;Here to Help&amp;rdquo;&lt;/h3&gt;

&lt;p&gt;The first time Kao came face-to-face with Collins, in 2018, he told the FBI, he had to pay for the privilege.&lt;/p&gt;

&lt;p&gt;Collins would not meet unless he agreed to donate to her campaign, he said. While it is not illegal for politicians to exchange face time for contributions &amp;mdash; in this case, just a few thousand dollars &amp;mdash; it was not the last time Collins would seek Kao&amp;rsquo;s support.&lt;/p&gt;

&lt;p&gt;Navatek had been eager to expand beyond Hawaii, and Maine was a perfect beachhead &amp;mdash; a small, coastal state hungry for high-tech jobs that happened to be represented by a senior member of the Senate Appropriations Committee. Collins, more than most appropriators,&amp;nbsp;&lt;a href="https://slate.com/news-and-politics/2026/06/susan-collins-graham-platner-maine-senate.html"&gt;likes to trumpet the dollars she brings home&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;To work with Collins, Navatek hired a lobbyist, Glen Mandigo, who also lobbied for the University of Maine and was tight with her office. Mandigo asked how much Navatek wanted in funding and how much Kao was willing to support Collins, Kao told the FBI. The University of Maine did not reply to a request for comment.&lt;/p&gt;

&lt;p&gt;In that first meeting with Collins and her staff, Kao pitched an $8 million boat hull research project for Navatek and the university. Collins seemed supportive. Not long after, Mandigo called Kao and said Collins wanted him to bundle tens of thousands of dollars for her reelection, suggesting Navatek throw a fundraiser, Kao said.&lt;/p&gt;

&lt;p&gt;In an email to ProPublica, Mandigo denied taking part in a pay-to-play arrangement.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I did not advise Navatek officials, nor would I advise any client, that support from Sen. Collins was contingent on campaign donations,&amp;rdquo; Mandigo wrote. He said that in his 25 years of working with Collins and the Maine delegation, &amp;ldquo;I never saw or heard of such behavior from the Senator or her staff.&amp;rdquo; Clark, Collins&amp;rsquo; deputy chief of staff, told ProPublica it was &amp;ldquo;wholly inaccurate&amp;rdquo; to say Mandigo was close to their office.&lt;/p&gt;

&lt;p&gt;FBI agents had collected voluminous corporate records and email correspondence between Navatek and Collins&amp;rsquo; inner circle. Much of that evidence aligned with the story they were now getting directly from Kao.&lt;/p&gt;

&lt;p&gt;The FBI had spotted his out-of-the-blue donations in the summer of 2018, just before Collins included $8 million for Navatek&amp;rsquo;s proposal in the defense budget. Emails showed her staff made it clear to the Navy that it should&amp;nbsp;send the money to Navatek. FBI agents also had evidence of Kao and Mandigo planning a fundraiser starting in April 2019. Their emails &amp;mdash; with her scheduler and her campaign&amp;rsquo;s finance director &amp;mdash; freely mixed talk of Navatek&amp;rsquo;s Collins-backed contract with plans to raise money for her.&lt;/p&gt;

&lt;p&gt;The principals settled on hosting Collins for a publicity event at Navatek&amp;rsquo;s Maine headquarters in August 2019, where she posed for pictures with Kao and a model of the company&amp;rsquo;s experimental boat. Behind the scenes, the FBI saw in emails and company records, Kao orchestrated over $40,000 in donations from extended family in advance of the event. To avoid the legal cap on individual campaign contributions, the emails show, he told Collins&amp;rsquo; team to reallocate his excess contributions to his father&amp;nbsp;&amp;mdash;&amp;nbsp;which an agent highlighted and noted is against election law in a presentation to prosecutors&amp;nbsp;&amp;mdash;&amp;nbsp;and sent them his father&amp;rsquo;s full name and address.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;This is perfect,&amp;rdquo; Amy Abbott, the reelection campaign finance director, emailed Kao after discussing his father&amp;rsquo;s contribution. &amp;ldquo;We are so grateful for ALL the Kao support!&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Before the event, Kao said, Collins, Abbott and another staffer met with him in private. One of the staffers told Kao the campaign expected more donations. It was in this meeting that Collins said, &amp;ldquo;You&amp;rsquo;ve seen me deliver,&amp;rdquo; he told the FBI.&lt;/p&gt;

&lt;p&gt;Less than one month after the event, the Senate released a draft of the defense budget containing $21.5 million for Navatek&amp;rsquo;s pet projects in Maine. Kao emailed a Collins campaign fundraiser &amp;mdash; who would in theory have nothing to do with a government contract &amp;mdash; four days later, saying, &amp;ldquo;Thanks again for all the support from Sen Collins.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I&amp;rsquo;ve been involved in many tight races in the past and understand last minute &amp;lsquo;needs&amp;rsquo; come up,&amp;rdquo; he continued. &amp;ldquo;We are here to help anyway we can &amp;hellip; financially or whatever.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Kao&amp;rsquo;s desire to donate even more money led to the fateful Corner Bakery meeting with the head of the Collins super PAC, called the 1820 PAC, Kao told the FBI. Unlike Collins&amp;rsquo; campaign, which could accept only $5,600 per election from individuals, the super PAC could accept unlimited contributions.&lt;/p&gt;

&lt;p&gt;The super PAC emailed Kao a memo before the meeting stressing the need to raise money with &amp;ldquo;urgency.&amp;rdquo; At the meeting, Kao and Reed, the super PAC&amp;rsquo;s chair, hammered out a deal for a six-figure donation, Kao told the FBI. Over email, Kao informed Reed of his shell company scheme, saying he had cleared&amp;nbsp;it with his lawyer. &amp;ldquo;They are super vague and very difficult to get any background info on,&amp;rdquo; Kao reassured him. &amp;ldquo;Thanks for doing this,&amp;rdquo; Reed replied.&lt;/p&gt;

&lt;aside&gt;
&lt;h3&gt;Emails&lt;/h3&gt;

&lt;p&gt;Here are quotes from emails between Martin Kao and Scott Reed, discussing contributions to the Susan Collins Super PAC, 1820 PAC:&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Hi Scott: Had a chance to discuss 1820 with my CFO and attorney last night. They are suggesting setting up a separate new LLC to make the donations. Name of new LLC: Society of Young Women Scientists and Engineers. In my personal real estate investments, we often use LLCs that can be set up to &amp;ldquo;facilitate&amp;rdquo; transactions. They are super vague and very difficult to get any background info on. Totally legal and typically used in real estate transactions to conceal the identity of buyer/seller. Wanted to get your thoughts/concerns.&amp;rdquo;&amp;mdash;email from Martin Kao to Scott Reed, Nov. 22, 2019&lt;br /&gt;
&lt;br /&gt;
&amp;ldquo;Very smart and glad your counsel understands. Thanks for doing this.&amp;rdquo;&amp;mdash;email from Scott Reed to Martin Kao, Nov. 22, 2019&lt;br /&gt;
&lt;br /&gt;
&amp;ldquo;Great! We will proceed on getting this set up ASAP. Have a nice weekend.&amp;rdquo;&amp;mdash;email from Martin Kao to Scott Reed, Nov. 22, 2019&lt;/p&gt;
&lt;/aside&gt;

&lt;p&gt;The FBI spoke to the other Navatek executives at Corner Bakery, who confirmed the meeting took place. One of them, David Kring, the company&amp;rsquo;s top scientist, told ProPublica he had no memory of what was discussed.&lt;/p&gt;

&lt;p&gt;The other, Duke Hartman, told an FBI agent it was just &amp;ldquo;a get-to-know-you meeting&amp;rdquo; with the chair of the super PAC and they did not discuss the &amp;ldquo;particulars of a donation.&amp;rdquo; Agents, records show, came to believe Hartman was lying about his role in Kao&amp;rsquo;s pay-to-play operation and would name him as a formal subject of a future investigation. Hartman was not charged. He did not respond to a detailed request for comment.&lt;/p&gt;

&lt;p&gt;A few weeks after the $150,000 check to the Collins super PAC cleared, in February 2020, Kao and his team met with Collins&amp;rsquo; office and secured a new round of funding.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We were very warmly received,&amp;rdquo; Kao reported to his colleagues in an email obtained by the FBI. &amp;ldquo;Excellent meeting. Total of $32M will be supported.&amp;rdquo; Records show the Senate allocated at least $10 million that year based on Navatek&amp;rsquo;s proposals.&lt;/p&gt;

&lt;p&gt;Navatek&amp;rsquo;s ambitions peaked in mid-2020. As the company waited to see if Collins would survive her reelection campaign, executives prepared to ask their champion on the appropriations committee for even more funding the following spring, internal documents show.&lt;/p&gt;

&lt;p&gt;Other documents from that time show the company was courting senators from seven additional states and gunning for more than $200 million in new appropriations. Navatek expected to have offices in more than a dozen states by the end of the following year, including a new 15,000-square-foot facility in the Portland, Maine, harbor.&lt;/p&gt;

&lt;p&gt;Kao, meanwhile, closed on a $4.5 million beachside home in an exclusive Honolulu neighborhood; the backyard pool had a waterfall feature. He renamed the company Martin Defense Group after himself, joking that it would simplify his future takeover of Lockheed Martin.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;It was working well, and it would have continued to work well,&amp;rdquo; said Schiff, the former executive. &amp;ldquo;Martin got greedy. Just got damn greedy.&amp;rdquo;&lt;/p&gt;

&lt;h3&gt;Downfall, Cover-up&lt;/h3&gt;

&lt;p&gt;In early 2020, the Campaign Legal Center, a nonprofit good government group, noticed something strange in the public filings for the Collins super PAC. The PAC had received a $150,000 donation from a newly created LLC with a typo in its name: the Society of Young Women Scientist and Engineers, with no S at the end of &amp;ldquo;Scientist.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;This was the $150,000 Kao donated after the Corner Bakery meeting. The money had come from Navatek&amp;rsquo;s account, not Kao&amp;rsquo;s, violating a ban on government contractors making donations.&lt;/p&gt;

&lt;p&gt;The center suspected the society was not a real group but a pass-through to hide the identity of a major political donor. It filed a complaint with the Federal Election Commission. It took only a few days for a Hawaii journalist&amp;nbsp;&lt;a href="https://www.civilbeat.org/2020/02/tangled-web-of-campaign-cash-connects-hawaii-to-maine/"&gt;to discover&lt;/a&gt;&amp;nbsp;Kao&amp;rsquo;s wife&amp;rsquo;s name on the society&amp;rsquo;s paperwork, linking the shell company to Navatek.&lt;/p&gt;

&lt;p&gt;Inside Navatek, Kao shifted into damage control mode. He spoke to Reed and the super PAC&amp;rsquo;s lawyer, Cleta Mitchell, and began to hatch a cover-up. In an email released in civil litigation, Mitchell suggested the society make charitable donations &amp;mdash; preferably in Maine &amp;mdash; which would make it seem like a legitimate nonprofit. &amp;ldquo;I want to be sure that the LLC proceeds with the ideas we discussed &amp;mdash; giving scholarships and recognition to women in engineering, etc.,&amp;rdquo; wrote Mitchell. &amp;ldquo;That would help both of us, I think.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Mitchell added, &amp;ldquo;We should develop a plan and timetable, so there are some scholarships given over the next several months, and particularly, perhaps in Maine, where the bad press was.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Mitchell, who later played a major role in Trump&amp;rsquo;s attempts to overturn the results of the 2020 election, did not respond to requests for comment.&lt;/p&gt;

&lt;p&gt;Kao and his team settled on donating scholarships to women in STEM. They offered between $5,000 and $25,000 apiece to state universities where they were angling to win government contracts &amp;mdash; that way, the cover-up would benefit them politically, too.&lt;/p&gt;

&lt;p&gt;But Navatek&amp;rsquo;s and Kao&amp;rsquo;s problems were just beginning. Undeterred by scrutiny from the FEC, Kao defrauded the COVID-era Paycheck Protection Program newly passed by Congress. He inflated Navatek&amp;rsquo;s payroll to amass loans of $13 million,&amp;nbsp;&lt;a href="https://storage.courtlistener.com/recap/gov.uscourts.hid.154418/gov.uscourts.hid.154418.1.0.pdf"&gt;according to&lt;/a&gt;&amp;nbsp;a federal indictment. The Navatek founder, Loui, had long since soured on his chosen successor. This was the final straw. He reported Kao to federal authorities.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;This is not how Navatek behaved or conducted business before I sold the company to Martin Kao,&amp;rdquo; Loui wrote to ProPublica. He said Navatek was successful before Kao&amp;rsquo;s ownership and had many sources of government funding. After Kao&amp;rsquo;s arrest, he added, the company fully cooperated with law enforcement.&lt;/p&gt;

&lt;p&gt;Loui has since regained control of the company and renamed it PacMar. He is dedicated to restoring its reputation and ability to execute government contracts, he continued. Loui said he fired employees hired during Kao&amp;rsquo;s tenure who were &amp;ldquo;not capable of performing quality, professional engineering and science tasks.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The company received no Collins-supported funding after Martin Kao&amp;rsquo;s arrest, nor should it,&amp;rdquo; Loui added. &amp;ldquo;What Martin Kao and his cabal did was wrong.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;On Sept. 30, 2020, law enforcement raided Navatek&amp;rsquo;s Honolulu offices and arrested Kao for fraud. Federal agents in windbreakers seized his laptop and ordered the company&amp;rsquo;s IT staff to copy the company&amp;rsquo;s internal servers.&lt;/p&gt;

&lt;p&gt;Navatek&amp;rsquo;s public flameout attracted the attention of Michelle Ball and Kevin Gounaud, two experienced agents in the FBI&amp;rsquo;s elite anti-corruption unit. Gounaud was a 20-year FBI veteran who had worked on elaborate undercover operations. Ball had made a name for herself taking on politically sensitive cases. In 2018, she led the investigation into Maria Butina, the Russian agent&amp;nbsp;&lt;a href="https://www.nytimes.com/2019/10/25/us/politics/maria-butina-russia-deported.html"&gt;convicted of infiltrating&lt;/a&gt;the National Rifle Association in an attempt to influence the Trump campaign.&lt;/p&gt;

&lt;p&gt;The agents began digging through thousands of records for details of Navatek&amp;rsquo;s lobbying operation, donation strategy and ties to politicians.&lt;/p&gt;

&lt;p&gt;They zeroed in on Kao&amp;rsquo;s relationship with Collins. In a 60-slide presentation agents prepared for prosecutors, they highlighted contributions that Kao and his wife made to the senator in 2018, right before Collins placed the $8 million in research funding into the federal budget. Kao had also given Navatek money to various relatives to donate to Collins in 2019, sending her around $33,000 through these illegal straw donors,&amp;nbsp;&lt;a href="https://storage.courtlistener.com/recap/gov.uscourts.dcd.240076/gov.uscourts.dcd.240076.1.0_1.pdf"&gt;the indictment said&lt;/a&gt;. Kao&amp;rsquo;s wife and father did not reply to requests for comment.&lt;/p&gt;

&lt;p&gt;The government charged Kao in two separate cases: one for defrauding the loan program and another for his campaign finance crimes. His love of talking like a wheeler-dealer &amp;mdash; including over email &amp;mdash; was a gift to investigators. In one email, he all but admitted the scholarships to young women were a diversion. &amp;ldquo;Whatever&amp;hellip; just a pack of bitches getting free $,&amp;rdquo; he wrote.&lt;/p&gt;

&lt;p&gt;In the face of overwhelming evidence, Kao pleaded guilty in both cases in the fall of 2022. Navatek by then was under court-ordered new management. Awaiting sentencing, Kao worked as a line cook at a Cheesecake Factory.&lt;/p&gt;

&lt;p&gt;He began meeting with the same FBI agents and prosecutors who brought him down. For the agents, he was a rare witness: a contractor with deep ties to elected officials saying he would speak candidly about how Washington works.&lt;/p&gt;

&lt;p&gt;Kao faced nearly a decade in prison. &amp;ldquo;My world and life imploded,&amp;rdquo; he would later recall in a letter to the Hawaii U.S. District Court. &amp;ldquo;I was fooled and foolish enough to believe that the power elected officials wielded, and [were] actively willing to sell to anyone wealthy enough to pay, was&amp;hellip;.&amp;lsquo;smart business.&amp;rsquo;&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Over the next two years, Kao sat with agents for at least three dayslong interviews. He told them that politicians, Collins in particular, had been willing participants in his scheme. &amp;ldquo;It takes two to tangle,&amp;rdquo; he told them.&lt;/p&gt;

&lt;p&gt;Taxpayers funded Navatek&amp;rsquo;s entire political operation, Kao said. &amp;ldquo;Most companies of our size do not have the resources to endlessly hire expensive lobbyists and make political donations,&amp;rdquo; he told the FBI. Navatek solved this by using money from government contracts to hire lobbyists and make campaign contributions, according to interviews, court testimony and internal company records. Diverting money from contracts for lobbying and political donations can be illegal.&lt;/p&gt;

&lt;p&gt;For their final meeting, in September 2024, Kao handed the FBI the 50-page document detailing Navatek&amp;rsquo;s dealings with more than a dozen members of Congress and their staff. It was not only a confession but a road map, with the email addresses and phone numbers of people Kao thought agents ought to subpoena.&lt;/p&gt;

&lt;p&gt;Last year, Kao was sentenced to 87 months in prison. The judge in his case offered no leniency based on his cooperation with the FBI. Loui is battling Kao in court to recover the millions he contends Kao stole from the company.&lt;/p&gt;

&lt;p&gt;Both Scott Reed and Amy Abbott remain in Collins&amp;rsquo; inner circle. Abbott is the finance director for her 2026 reelection effort, and Reed again chairs the main Collins super PAC. Abbott, who is married to Collins&amp;rsquo; campaign manager, referred questions to the senator&amp;rsquo;s communications staff. Clark told ProPublica that Abbott and other campaign staff were interviewed by the FBI and that the campaign was never a target of the investigation.&lt;/p&gt;

&lt;p&gt;Earlier this year, Kao agreed to meet a ProPublica reporter at the Federal Prison Camp in Yankton, South Dakota, where he is incarcerated. But on two occasions when guards summoned Kao over the intercom, he refused to enter the visitation room. Over email, he said he was no longer willing to meet, citing the ongoing litigation. He declined through his lawyer to respond to detailed questions.&lt;/p&gt;

&lt;p&gt;By late 2024, Ball and Gounaud, the FBI agents, had come to believe there was enough evidence to warrant a broader investigation into bribery of members of Congress, according to a memo seen by ProPublica.&lt;/p&gt;

&lt;p&gt;Before they could embark on their new mission, however, they became casualties of Trump&amp;rsquo;s retribution campaign.&lt;/p&gt;

&lt;p&gt;Ball and Gounaud worked for the FBI&amp;rsquo;s elite anti-corruption unit known as CR-15, which specialized in investigating misconduct by elected officials. When Trump retook power, his new FBI director, Kash Patel, purged the unit agent by agent.&lt;/p&gt;

&lt;p&gt;Ball was targeted for her work on the special counsel investigation of Trump&amp;rsquo;s failed bid to overturn the 2020 election. She was fired in October 2025 in a one-page letter stating she had &amp;ldquo;weaponized&amp;rdquo; the Justice Department. She is&amp;nbsp;&lt;a href="https://ecbawm.com/wp-content/uploads/2026/03/Complaint.pdf"&gt;challenging her firing&lt;/a&gt;&amp;nbsp;in a lawsuit. Gounaud was pushed out in early 2026. Both agents declined to comment through their attorney.&lt;/p&gt;

&lt;p&gt;Trump also targeted the Justice Department attorneys who worked with CR-15. The team, known as the Public Integrity Section, collapsed spectacularly in February 2025 after staff were ordered to drop a case against New York City Mayor Eric Adams, a Trump ally. The unit&amp;rsquo;s leadership quit en masse. Trump appointees ordered the remaining prosecutors to halt new corruption&amp;nbsp;&lt;a href="https://www.reuters.com/investigations/how-trump-defanged-justice-departments-political-corruption-watchdogs-2025-06-09/"&gt;cases&lt;/a&gt;, just months after Kao made his detailed confession.&lt;/p&gt;

&lt;p&gt;Before Ball was fired, however, she managed to take a key step forward.&lt;/p&gt;

&lt;p&gt;Based on all the evidence, she persuaded her supervisors to approve a new investigation. It centered on South Carolina, one of the states Navatek eyed for a rapid expansion. The FBI had questions about a steak dinner Kao shared with Sen. Lindsey Graham.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/09/22/Pay_for_play_Beatrice_Caciotti_maxHeight_3000_maxWidth_3000/large.jpg" width="618" height="284"><media:credit>Beatrice Caciotti for ProPublica. Source images: U.S. Sen. Susan Collins’ official Facebook page.</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/09/22/Pay_for_play_Beatrice_Caciotti_maxHeight_3000_maxWidth_3000/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Space Force braces for stalled progress amid lack of full funding</title><link>https://www.defenseone.com/threats/2026/09/space-force-braces-stalled-progress-amid-lack-full-funding/416070/</link><description>Fiscal 2027 program starts are already on hold until December.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Lauren C. Williams</dc:creator><pubDate>Thu, 17 Sep 2026 19:33:19 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/09/space-force-braces-stalled-progress-amid-lack-full-funding/416070/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;&lt;strong&gt;NATIONAL HARBOR, Md.&amp;mdash;&lt;/strong&gt;Space Force modernization efforts could slow if Congress doesn&amp;rsquo;t pass a full budget at the end of the year, the service&amp;rsquo;s leaders said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We&amp;#39;re on this ramp-up, right, consistent with our overall strategy and the recognition that the space domain is a critical domain, in and of itself, but also for the joint force,&amp;rdquo; &lt;a href="http://af.mil/About-Us/Biographies/Display/Article/4587601/erich-d-hernandez-baquero/"&gt;Erich Hernandez-Baquero&lt;/a&gt;, the Space Force&amp;rsquo;s top buyer, told reporters Tuesday. &amp;ldquo;Now we&amp;#39;re going to run into [fiscal year 2027]&amp;mdash;and you saw that our budget request was to continue on that&amp;mdash;and this [&lt;a href="https://www.whitehouse.gov/briefings-statements/2026/09/congressional-bill-h-r-6500-signed-into-law/"&gt;continuing resolution&lt;/a&gt;] is definitely going to put the brakes on that for a time period.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The Space Force has &lt;a href="https://www.spaceforce.mil/News/Article-Display/Article/4465543/budget-request-directs-record-3388-billion-to-air-force-and-space-force-to-meet/"&gt;requested&lt;/a&gt; $71.1 billion for 2027, including $19.1 billion for procurement. But with little time remaining before fiscal 2027 begins on Oct. 1, Congress has passed stopgap legislation&amp;mdash;a continuing resolution&amp;mdash;to keep funding the Pentagon at 2026 levels through Dec. 11. The CR permits no new programs to begin.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We certainly appreciate at least not being shut down. So&amp;hellip;that&amp;#39;s a good thing, but on the CR, it really does pace us at a time where we really need to go faster. So we are obviously encouraging Congress to do what they can to help support the president&amp;#39;s budget on that,&amp;rdquo; Hernandez-Baquero said. &amp;ldquo;In the meantime, we&amp;#39;ll just do what we always do: prioritize the things that will yield the most mission capability soonest, and make sure we&amp;#39;re executing on those.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Hernandez-Baquero, who was &lt;a href="https://www.spaceforce.mil/News/Article-Display/Article/4581284/hernandez-baquero-swears-in-as-department-of-the-air-force-space-acquisition-an/"&gt;sworn&lt;/a&gt; into the chief space acquisition role last month, declined to specify which priorities could be most affected by a continuing resolution because things were &amp;ldquo;pre-decision at this point.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Gen. Doug Schiess, the chief of space operations, said about 10 percent of the service&amp;rsquo;s programs could be slowed down due continuing resolution.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;About 90 percent of the programs we have are programs from last year&amp;mdash;so we can still get after those,&amp;rdquo; but there&amp;rsquo;s a remaining 10 percent of programs that require full budget funding, Schiess said. &amp;ldquo;It&amp;#39;s going to slow us down, and the threat is not slowing down.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Amid a broader push for acquisition reform, Hernandez-Baquero said he&amp;rsquo;s focused on streamlining and speeding up military purchasing. And when it comes to technology initiatives, there will be a new senior leadership role dedicated to it.&amp;nbsp;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The Air Force&amp;rsquo;s new &lt;a href="https://www.defenseone.com/business/2026/01/usaf-consolidates-some-acquisition-program-offices-mission-focused-groups/410569/"&gt;program acquisition executives&lt;/a&gt;, or PAEs, are &amp;ldquo;establishing those pathways for onboarding new technology, but I&amp;#39;m just conscious that that by itself is not going to support drawing in the right technologies,&amp;rdquo; he said. &amp;ldquo;I want somebody that&amp;#39;s focused&amp;mdash;100 percent&amp;mdash;on looking at the most promising tech and driving the prototyping initiatives that are going to help mature it to the level where a PAE can say, &amp;lsquo;Ah, it meets my criteria for this onboard path, and I can go do that&amp;rsquo;.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;That person is a technology portfolio executive, who &amp;ldquo;will have the most promising technology coming out of the [research and development] side, and&amp;hellip;will work with industry to ensure that we have the right pathways to do that. Conceptually, there would be prototype efforts that get executed out of that to support the mission areas.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The technology portfolio executive office already exists but the role hasn&amp;rsquo;t yet been filled, he said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;When I designate a TPE, for example, that person is going to report directly to me and represent my authority when it comes to the technology transition,&amp;rdquo; Hernandez-Baquero said. &amp;ldquo;I cannot do this without the buy-in of the PAEs that are executing the mission areas, and so my charter to them is going to be not only to deliver on those missionaries, but be part of the enterprise team that&amp;#39;s going to deliver on those cross-cutting capabilities.&amp;rdquo;&amp;nbsp;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/09/17/9944833/large.jpg" width="618" height="284"><media:description>Erich Hernandez-Baquero, assistant secretary of the Air Force for space acquisition and integration, speaks during the 2026 Air and Space Forces Association Air, Space &amp; Cyber Conference, Sept. 15. </media:description><media:credit>U.S. Air Force / Tech. Sgt. William OBrien</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/09/17/9944833/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>The Pentagon must prepare for battles around the moon: Joint Chiefs chair</title><link>https://www.defenseone.com/threats/2026/09/pentagon-battles-moon-joint-chiefs-chairman/416021/</link><description>Days after orbital weapons were revealed, Gen. Dan Caine ups the scope of the military’s desired reach.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Novelly</dc:creator><pubDate>Wed, 16 Sep 2026 13:11:23 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/09/pentagon-battles-moon-joint-chiefs-chairman/416021/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;&lt;strong&gt;NATIONAL HARBOR, Md.&amp;mdash; &lt;/strong&gt;The U.S.&lt;strong&gt; &lt;/strong&gt;military&amp;rsquo;s top uniformed leader says U.S. forces must be ready for war near or possibly even on the moon, a rhetorical leap that comes as service leaders are still wrestling with the legal frameworks surrounding its newly revealed orbital weapons.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Our task, my friends, is to adapt right now, so the Joint Force is prepared to fight, endure, and win, in global contested environments, from the seabed to cislunar space,&amp;rdquo; Joint Chiefs Chairman Gen. Dan Caine told airmen, guardians, and industry figures during his keynote address at the Air, Space, and Cyber Conference.&lt;/p&gt;

&lt;p&gt;Caine later repeated the thought&amp;mdash;&amp;ldquo;today&amp;rsquo;s modern battlefield operates from the seabed to cislunar space&amp;rdquo;&amp;mdash;but he did not clarify whether he meant on the moon&amp;rsquo;s surface. U.S. law is ambiguous, &lt;a href="https://www.law.cornell.edu/definitions/uscode.php?width=840&amp;amp;height=800&amp;amp;iframe=true&amp;amp;def_id=42-USC-911736412-890728237&amp;amp;term_occur=1&amp;amp;term_src=title:42:chapter:159:section:18302"&gt;defining&lt;/a&gt; cislunar space as &amp;ldquo;the region of space from the Earth out to and including the region around the surface of the moon.&amp;rdquo; At least one Harvard Law Journal article &lt;a href="https://journals.law.harvard.edu/nsj/wp-content/uploads/sites/82/2025/01/Giannoni-Crystal_16_Harvard_Natl_Sec_J_1._2025.pdf"&gt;interprets&lt;/a&gt; the clause to mean on the moon itself, and the White House&amp;rsquo;s National Cislunar Science and Technology Action Plan explicitly &lt;a href="https://bidenwhitehouse.archives.gov/wp-content/uploads/2024/12/Cislunar-Implementation-Plan-Final.pdf"&gt;said&lt;/a&gt; in late 2024 that it includes the lunar surface. But the Air Force Research Laboratory&amp;rsquo;s 2021 &amp;ldquo;&lt;a href="https://www.afrl.af.mil/Portals/90/Documents/RV/A%20Primer%20on%20Cislunar%20Space_Dist%20A_PA2021-1271.pdf?ver=vs6e0sE4PuJ51QC-15DEfg%3D%3D"&gt;Primer on Cislunar Space&lt;/a&gt;&amp;rdquo; appears to treat space and the moon&amp;rsquo;s surface as two different domains.&lt;/p&gt;

&lt;p&gt;Caine pointed to recent comments made about orbital weapons by the &lt;a href="https://www.defenseone.com/defense-systems/2026/09/us-military-has-orbit-space-weapons-air-force-secretary-reveals/415964/?oref=d1-homepage-top-story"&gt;Air Force secretary&lt;/a&gt; and the Space Force&amp;rsquo;s &lt;a href="https://www.defenseone.com/threats/2026/09/orbit-weapons-space-force-leader/415999/?oref=d1-featured-river-secondary"&gt;chief of space operations&lt;/a&gt;. Top space force officials have been hesitant to provide more details on how they would operate in that domain and how they&amp;rsquo;d responsibly use space weapons in future conflicts.&lt;/p&gt;

&lt;p&gt;While top Space Force officials have provided few details about how U.S. forces would fight between the Earth and its moon, they have been vocal about adding sensors and capabilities to watch adversary movements there. Aaron Brynildson, a space law professor at the University of Mississippi said it&amp;rsquo;s understandable why the military would want to increase awareness within that region.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;There&amp;rsquo;s a fear that recent Chinese activity on the moon and in cislunar space might outpace the United States,&amp;rdquo; Brynildson said. &amp;ldquo;China has a relay satellite in cislunar space and is performing robotic missions on the far side of the moon.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The &lt;a href="https://www.unoosa.org/oosa/en/ourwork/spacelaw/treaties/introouterspacetreaty.html"&gt;Outer Space Treaty of 1967&lt;/a&gt;, which the U.S. signed, outlaws certain military behaviors on the Moon and states that it shall be used &amp;ldquo;exclusively for peaceful purposes.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The establishment of military bases, installations and fortifications, the testing of any type of weapons and the conduct of military manoeuvres on celestial bodies shall be forbidden. The use of military personnel for scientific research or for any other peaceful purposes shall not be prohibited.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Space Force Lt. Gen. Gregory Gagnon, the head of Combat Forces Command, told reporters during a media roundtable that the 18th and 19th Space Defense Squadrons are now both sharing the cislunar mission among each other.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Our adversaries, our potential adversaries, such as the PRC, are actively pursuing activities in the cislunar parts of space. So that&amp;#39;s sort of the expansion, if you will, of I would say the end zone, if you will, in the football game,&amp;rdquo; he said.&lt;/p&gt;

&lt;p&gt;When asked if the Outer Space Treaty limits the military&amp;rsquo;s cislunar ambitions, Gagnon said it did not limit orbital operations.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The United States Space Force will continue to execute safe and responsible space operations in all regions of space and in all orbits,&amp;rdquo; he said.&lt;/p&gt;

&lt;p&gt;Brynildsonn said that while the treaty forbids the creation of military bases on the moon, &amp;ldquo;The U.S. needs better capabilities in cislunar space to ensure China complies with that obligation and doesn&amp;rsquo;t militarize the moon. There&amp;rsquo;s a real coverage gap by the U.S. that needs closing.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;This week&amp;rsquo;s &lt;a href="https://www.defenseone.com/defense-systems/2026/09/us-military-has-orbit-space-weapons-air-force-secretary-reveals/415964/?oref=d1-homepage-top-story"&gt;revelation&lt;/a&gt; by Air Force Secretary Troy Meink and Chief of Space Operations Gen. Douglas Schiess that the U.S. has on-orbit space-control weapons has raised legal questions about their responsible use. Experts have &lt;a href="https://www.defenseone.com/threats/2026/09/orbit-weapons-space-force-leader/415999/?oref=d1-featured-river-secondary"&gt;speculated&lt;/a&gt; that the weapons are likely non-kinetic, such as jammers and electronic warfare capabilities.&lt;/p&gt;

&lt;p&gt;When asked whether U.S. policy limits the use of a kinetic space weapon, meaning a destructive capability that would cause debris, Gagnon deferred to policy offices.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;So we have capabilities in the military because we are preparing to defend the nation. The reason we have capabilities is to help create deterrence,&amp;rdquo; he said. &amp;ldquo;When you go to war, you break things.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Brynildson said it&amp;rsquo;s not clear how current laws limit the use of space weapons.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;It&amp;rsquo;s unclear what the legal restraints on the use of kinetic or non-kinetic weapons in space might be. The Outer Space Treaty doesn&amp;rsquo;t give us great answers to what factors a military action must consider,&amp;rdquo; he said. &amp;ldquo;The DoD Law of War Manual is also non-committal on the unique aspects of the space domain. At a minimum, general principles from the law of armed conflict would apply, such as only striking military-related satellites, avoiding collateral damage to civilians, etc.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;U.S. lawmakers are also concerned by the lack of space-focused military legal knowledge. A &lt;a href="https://www.defenseone.com/threats/2026/07/does-space-force-have-enough-lawyers-tomorrows-wars-senators-want-know/414586/"&gt;provision&lt;/a&gt; inserted by the Senate Armed Service Committee in the 2027 National Defense Authorization Act tasks the Defense Department with assessing its &amp;ldquo;space law requirements&amp;rdquo; to face rising threats and examine &amp;ldquo;options for establishing a dedicated legal organization within the Air Force, Space Force, or Space Command.&amp;rdquo; The amendment adds that senators are &amp;ldquo;concerned that current legal, policy, and institutional structures within the Department of Defense may not have kept pace with the complexity of space operations.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Those clarified legal norms may not emerge until it&amp;rsquo;s too late.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Ultimately, I think the first space conflict might be the time when most of these rules get written,&amp;rdquo; Brynildson said.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/09/16/caine_GettyImages_2275249249/large.jpg" width="618" height="284"><media:description>Joint Chiefs of Staff Chairman Gen. Dan Caine testifies on Capitol Hill in Washington, D.C., on May 12, 2026.</media:description><media:credit>SAUL LOEB / AFP via Getty Images</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/09/16/caine_GettyImages_2275249249/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>‘It was time’ to admit US has weapons in orbit, Space Force’s new leader says</title><link>https://www.defenseone.com/threats/2026/09/orbit-weapons-space-force-leader/415999/</link><description>Russian and Chinese advances led to the revelation, Gen. Douglas Schiess says at AFA.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Novelly</dc:creator><pubDate>Tue, 15 Sep 2026 13:58:40 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/09/orbit-weapons-space-force-leader/415999/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;&lt;strong&gt;NATIONAL HARBOR, Maryland&amp;mdash;&lt;/strong&gt;The advance of Chinese and Russian anti-satellite capabilities led the United States to admit it has weapons in space, the Space Force&amp;#39;s top officer said on Tuesday, adding context to Monday&amp;rsquo;s bombshell &lt;a href="https://www.defenseone.com/defense-systems/2026/09/us-military-has-orbit-space-weapons-air-force-secretary-reveals/415964/?oref=d1-homepage-top-story"&gt;revelation&lt;/a&gt; by the Air Force secretary.&lt;/p&gt;

&lt;p&gt;Deterrence remains the Space Force&amp;rsquo;s goal, but the service will pursue it from a &amp;ldquo;position of strength,&amp;rdquo; Gen. Douglas Schiess said during a keynote address at the Air, Space, and Cyber Conference here.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;On Monday, Air Force Secretary Troy Meink revealed the U.S. military has &amp;ldquo;on orbit, space-control weapons.&amp;rdquo; Schiess, who took over as chief of space operations less than two weeks ago, spoke to reporters after his keynote on Tuesday.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We&amp;#39;ve talked about you know them being able to grapple a satellite and move it to a different orbit,&amp;rdquo; he said. &amp;ldquo;So, I think at this point, we are trying to say that we also need capabilities to not only defend the joint force from space-enabled attack, but defend our assets. And so, I think it was time that within the Department of War we talked about it, and it&amp;#39;s time to talk about that we have the capabilities to make sure that we can do what the joint force needs.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;During his keynote, Schiess said the U.S. military relies on space assets for operations like the current war on Iran, that guardians are already prepared for orbital warfare, and that more money is needed for current and future operations.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The Joint Force made it clear: without the Space Force&amp;#39;s capabilities, the Joint Force could not and would not move forward,&amp;rdquo; Schiess said. &amp;ldquo;During Operation Epic Fury, our components, notably at U.S. Central Command and Space Command, with support from our components at European Command and Pacific Command, demonstrated that guardians are not supporting from the sidelines as a nice-to-have, but we are delivering space power directly into the fight as a need-to-have.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Schiess highlighted one guardian in U.S. Central Command with the 42nd Electronic Warfare Detachment who &amp;ldquo;waged electromagnetic warfare against a determined adversary&amp;rdquo; during Operation Epic Fury.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Even as alarm red sirens were blaring and incoming missiles targeted her site, she courageously held the line, protecting forces, denying adversary capability, and delivering space effects until her commander had to literally pull her from the console to safety,&amp;rdquo; Schiess said.&lt;/p&gt;

&lt;p&gt;The CSO said the Space Force has been flexing its capabilities in outer space as well. He highlighted the service&amp;rsquo;s recent &lt;a href="https://www.ssc.spaceforce.mil/Newsroom/Article/4523601/us-space-force-demonstrates-responsive-launch-for-victus-haze-mission-begins-on"&gt;Victus Haze exercise&lt;/a&gt;, in which Rocket Lab quickly launched a &lt;a href="https://rocketlabcorp.com/missions/launches/victus-haze/"&gt;space vehicle&lt;/a&gt; whose&amp;nbsp; satellite chased after &lt;a href="https://www.trueanomaly.space/newsroom/victus-haze-mission-update-jackal-hunts-puma"&gt;True Anomaly&amp;#39;s&lt;/a&gt; spacecraft.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;This particular Victus Haze mission earlier this year demonstrated the ability to launch and respond to an on-demand, on-orbit threat in just 17 hours,&amp;rdquo; the general said. &amp;ldquo;Space Systems Command, our industry partners, and Combat Forces Command proved to the world that if an adversary targets the United States Space Force, we have the capability to deliver a swift response, and we are going to continue to work on getting faster and faster.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Schiess said those current and future fights highlight the need for more resources.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;So, looking ahead, we must expand that advantage. We must build a sustained pipeline of guardian talent, equipped with the appropriate training and the kit and advanced capabilities, to ensure our joint force is fully powered by space expertise.&amp;rdquo; he said. &amp;ldquo;We must ensure today, tomorrow, and for as long as we have the pleasure to serve, that our joint force can execute because guardians are there, both at home and abroad, and in harm&amp;#39;s way.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Space Force has grown quickly since its founding in 2019, but this year, the Pentagon is asking Congress to allocate $71.3 billion for the service for the fiscal year that began more than two weeks ago. It would be the biggest single-year funding increase for a service branch, by percentage, since 1952,&amp;nbsp;according to the &lt;a href="https://csps.aerospace.org/sites/default/files/2026-08/Wilson_FY27BudgetBrief_20260817.pdf"&gt;Aerospace Corporation&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Space is both a battlefield and the backbone of our joint force. We face determined and credible adversaries who are building and building counter-space systems at incredible speeds to target directly the United States state&amp;#39;s space advantage,&amp;rdquo; Schiess said. &amp;ldquo;So that is why we don&amp;#39;t just monitor the domain; we stand ready to defend it. So let me be crystal clear: today, Guardians operate on-orbit weapons that can defend the joint force against space-enabled attacks, and in the coming years, with the resources entrusted to us, by the way, we need your help, Congress-we will make disciplined and responsible choices about how we build and sustain our combat advantage, which means scaling our ability to respond to threats.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;It&amp;rsquo;s not clear whether Congress will grant the request. The White House wants $1.15 trillion through the normal defense-budget process and an additional $350 billion through reconciliation&amp;mdash;a controversial and partisan budget maneuver never used for defense funding before last year. The Trump administration is &lt;a href="https://www.defenseone.com/policy/2026/06/senate-appropriators-defense-reconciliation-bill/414080/"&gt;pressing&lt;/a&gt; the GOP-led Congress to relent by proposing to use reconciliation to fund some major Space Force programs, such as the Air Moving Target Indicator and the space data network, and the vast majority of funds for the Golden Dome missile defense program.&lt;/p&gt;

&lt;p&gt;In the meantime, 10 percent of the service&amp;rsquo;s programs are on hold because Congress hasn&amp;rsquo;t passed a fiscal 2027 defense spending bill, Schiess told reporters. The federal government is currently operating under a &lt;a href="https://www.govexec.com/management/2026/09/shutdown-threat-lifted-house-passes-stopgap-spending-bill/415753/"&gt;stopgap funding measure&lt;/a&gt; that will elapse on Dec. 11.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/09/15/Gen._Douglas_Schiess_9911333/large.jpg" width="618" height="284"><media:description>Gen. Douglas Schiess speaks during his promotion ceremony at Joint Base Andrews, Maryland, on Sept. 3, 2026.</media:description><media:credit>U.S. Air Force / Andy Morataya</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/09/15/Gen._Douglas_Schiess_9911333/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Iran strikes exposed gaps in medical evacuation ops across Middle East: IG</title><link>https://www.defenseone.com/threats/2026/09/iran-strikes-exposed-gaps-medical-evacuation-ops-across-middle-east-ig/415988/</link><description>Medical professionals have long warned that drones would cause higher U.S. battlefield casualties. A new Inspector General report shows the military is still scrambling to meet that challenge.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Patrick Tucker</dc:creator><pubDate>Tue, 15 Sep 2026 04:43:10 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/09/iran-strikes-exposed-gaps-medical-evacuation-ops-across-middle-east-ig/415988/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;The military abandoned plans to use Army helicopters to evacuate wounded troops involved in the war with Iran, and instead resorted to slower ground-based evacuations, in part due to the threat of drone strikes, according to a Defense Department Office of the Inspector General &lt;a href="https://media.defense.gov/2026/Sep/09/2003993626/-1/-1/1/OEF_Q3_JUN2026_FINAL_508%20SECURE.PDF"&gt;report&lt;/a&gt;&amp;nbsp;released&amp;nbsp;Monday. The shift illustrates a problem medical officials had&amp;nbsp; warned about for years.&lt;/p&gt;

&lt;p&gt;At the start of the operation, the U.S. used Army helicopters in Kuwait and Iraq for medical evacuation, but then moved them due to concerns about Iranian drone and missile strikes.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Most evacuations during [Operation Epic Fury] were ultimately conducted by ground,&amp;rdquo; according to the report. In addition to the drone threat, the United States had the additional hurdle of relying on host country hospitals for what&amp;rsquo;s called &amp;ldquo;advanced, hospital level care&amp;rdquo; for particularly severe injuries, since establishing such hospitals on U.S. bases would require a large and more targetable footprint.&lt;/p&gt;

&lt;p&gt;The move follows warnings from medical officials that future conflicts would be more dangerous for U.S. troops, as adversaries develop more advanced weapons&amp;mdash;particularly drones. A 2022 Army University Press &lt;a href="https://www.armyupress.army.mil/Journals/Military-Review/English-Edition-Archives/July-August-2022/Marsh/"&gt;article&lt;/a&gt; by Lt. Col. Matthew Marsh and Capt. Ryan Hampton eerily forecasts the situation described in the inspector general report: &amp;ldquo;Medical personnel will experience intermittent air and ground evacuation with medical logistics constraints,&amp;rdquo; it reads.&lt;/p&gt;

&lt;p&gt;Just as new technology has allowed some adversaries to become more dangerous and inflict higher casualties, other pressures led to cutbacks in medical evacuation capability, particularly in the Middle East. A July 2025 Pulse of Army Medicine &lt;a href="https://www.lineofdeparture.army.mil/Journals/Pulse-of-Army-Medicine/Archive/July-2025/Focus-Training/?utm_source=chatgpt.com"&gt;article&lt;/a&gt; by Sgt. Maj. Sandra Johnson describes how, across U.S. Central Command, &amp;ldquo;Due to competing requirements, many of these bases only have one medic on post and no medical provider. A medic may have to care for a patient for several hours until they arrive at a local national hospital.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;She noted specifically the problem of &amp;ldquo;no Medical Evacuation (MEDEVAC) by flight or ground capability, or only ground Casualty Evacuation (CASEVAC) options,&amp;rdquo; across CENTCOM.&lt;/p&gt;

&lt;p&gt;An April U.S. Naval Institute &lt;a href="https://www.usni.org/magazines/proceedings/2026/april/military-medicine-must-adapt"&gt;report&lt;/a&gt; explains: &amp;ldquo;Drone warfare [in Ukraine] has disrupted casualty movement from the point of injury throughout the combat casualty continuum of care.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The IG report acknowledges that CENTCOM officials worked to rapidly develop new plans and strategies when faced with Iranian drone capabilities, moving troops and materiel.. &amp;ldquo;During OEF, USCENTCOM shifted personnel, assets, and storage facilities as locations came under Iranian and proxy attacks,&amp;rdquo; it reads.&lt;/p&gt;

&lt;p&gt;The report carries a strong recommendation: To find and fix &amp;ldquo;the gaps in [Department of Defense counter-drone] interoperability, and the corrective actions needed to standardize&amp;rdquo; those capabilities.&amp;nbsp;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/09/15/9927603/large.jpg" width="618" height="284"><media:description>Soldiers conduct simulated casualty movement training during a joint medical exercise in Kentucky, Sept. 10, 2026.</media:description><media:credit>U.S. Army / Staff Sgt. Brianna Jenkins</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/09/15/9927603/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>25 years after 9/11, spy agencies face old lessons and new threats </title><link>https://www.defenseone.com/threats/2026/09/25-years-after-911-spy-agencies-face-old-lessons-and-new-threats/415941/</link><description>Former intelligence officials describe a nation better equipped to disrupt terrorist plots, but still wrestling with the costs.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Fri, 11 Sep 2026 11:00:00 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/09/25-years-after-911-spy-agencies-face-old-lessons-and-new-threats/415941/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;As Air Force One returned to Washington, D.C., on the night of Sept. 11, 2001, Michael Morell looked out a window and saw an F-16 off the aircraft&amp;rsquo;s wingtip. Beyond it, the Pentagon was smoldering.&lt;/p&gt;

&lt;p&gt;Morell, then-President George W. Bush&amp;rsquo;s intelligence briefer, had spent the day answering the president&amp;rsquo;s questions and relaying intelligence as the country tried to understand the attacks that had hit the Pentagon and the World Trade Center in New York City. A quarter-century later, that view from the window remains one of his most vivid memories.&lt;/p&gt;

&lt;p&gt;At the National Security Agency, Rick Ledgett recalled colleagues weeping in the hallways as the agency shifted into crisis mode. Within a month, it had transferred 3,000 analysts to counterterrorism work, he said.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Personally, it was shattering,&amp;rdquo; Ledgett, who later served as NSA deputy director, told &lt;em&gt;Nextgov/FCW&lt;/em&gt; in an email, adding that he &amp;ldquo;saw people step up and perform in ways they hadn&amp;rsquo;t before.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The response to the worst terrorist attack in modern history would transform the government they served. The efforts involved reorganizing intelligence agencies, expanding surveillance powers and drawing spies deeper into a global campaign to capture or kill suspected terrorists. It also produced longstanding debates over torture policies, targeted killings, mass surveillance, prolonged wars, and disputes over presidential power that became inseparable from efforts made to keep Americans safe from another catastrophe.&lt;/p&gt;

&lt;p&gt;Twenty-five years later, former officials describe a country better prepared to disrupt terrorist organizations, but facing a broader mix of threats from foreign governments, hackers, and extremists able to reach Americans online.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I think we&amp;rsquo;re much safer than we were on September 10, 2001, from the threat of terrorism,&amp;rdquo; Morell, who later served as CIA deputy director and acting director, told &lt;em&gt;Nextgov/FCW &lt;/em&gt;in an interview. But threats from nation-states like China or Russia, he said, are the most significant the country has faced since the Cold War.&lt;/p&gt;

&lt;p&gt;The&lt;a href="https://www.9-11commission.gov/report/911Report_Exec.htm"&gt; 9/11 Commission&lt;/a&gt; &amp;mdash; chartered by Congress and the White House in late 2002 to present a full accounting of the attacks and response &amp;mdash; described in its final report failures spanning imagination, policy, capabilities and management. Agencies held pieces of information that did not come together, and domestic defenses were not effectively mobilized despite mounting warnings about al Qaeda.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Just over a month before the attacks, Morell briefed Bush on a landmark intelligence report titled&lt;a href="https://nsarchive2.gwu.edu/NSAEBB/NSAEBB116/?utm_source=chatgpt.com"&gt; &amp;ldquo;Bin Ladin Determined To Strike in US&amp;rdquo;&lt;/a&gt; that flagged &amp;ldquo;patterns of suspicious activity in this country&amp;rdquo; consistent with preparations for hijackings and other attacks. He told &lt;em&gt;Nextgov/FCW&lt;/em&gt; it outlined al Qaeda&amp;rsquo;s intent to attack the country but did not specifically identify when, where or how a specific plot would unfold.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Getting agencies to work together&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The transformation that followed 9/11 sought to make cooperation a standing responsibility. Congress created the Office of the Director of National Intelligence in late 2004, establishing a lead unit responsible for integrating intelligence across agencies that collect data from human informants, satellite imagery, intercepted phone calls and other clandestine sources. The Department of Homeland Security was also &lt;a href="https://www.govexec.com/technology/2003/04/homeland-security-has-not-consolidated-terrorist-watch-lists/13982/?oref=ge-homepage-noscript-river"&gt;stood up&lt;/a&gt; in late 2002 to drive domestic defense efforts.&lt;/p&gt;

&lt;p&gt;The expansion also deepened agencies&amp;rsquo; reliance on contractors. After years of workforce drawdowns following the Cold War, the federal government turned to private companies to meet demands for intelligence collection, analysis and technology support, according to a 2015 report from the &lt;a href="https://www.everycrsreport.com/reports/R44157.html"&gt;Congressional Research Service&lt;/a&gt;. Today, they play a ubiquitous, outsized role in America&amp;rsquo;s national security missions.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Lauren Goldman, a former official in ODNI&amp;rsquo;s Cyber Threat Intelligence Integration Center and National Intelligence Council, recalled a major shift in the basic expectations that governed intelligence-sharing across government and the private sector.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The burden became on why you shouldn&amp;rsquo;t share versus why you should share,&amp;rdquo; she said. That culture has permeated many categories of today&amp;rsquo;s national security landscape, especially cybersecurity.&lt;/p&gt;

&lt;p&gt;ODNI sought to help ensure information reached people who needed it, including officials who might otherwise have been left outside an agency&amp;rsquo;s reporting channels, Goldman said. Because the office does not collect intelligence itself, it can assess reporting without the same institutional or cultural attachment to a particular collection method, she added.&lt;/p&gt;

&lt;p&gt;James Clapper, who served as director of national intelligence for more than six years under the Obama administration, said that coordination requires a &amp;ldquo;full-time champion.&amp;rdquo; Under pre-9/11 arrangements, the CIA director also headed the intelligence community, but agency demands often consumed the attention needed for that broader role, he said.&lt;/p&gt;

&lt;p&gt;Clapper said the DNI position was created to coordinate intelligence agencies but was not given full authority over them. Entities like the State Department or the Pentagon, for instance, retained control of their own intelligence shops. Still, the DNI could influence their priorities through oversight of intelligence funding and a direct advisory role to the president, he said.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I do think there&amp;rsquo;s a need for an overall champion of collaboration and integration,&amp;rdquo; Clapper told &lt;em&gt;Nextgov/FCW&lt;/em&gt;. His remarks come as the Trump administration has sought to &lt;a href="https://www.nextgov.com/people/2026/06/odni-deputy-director-pushed-out-amid-pulte-cuts/414412/"&gt;shrink ODNI&amp;rsquo;s workforce&lt;/a&gt; and consolidate its functions, on grounds that the office has become bloated and duplicates work performed elsewhere in the intelligence community.&lt;/p&gt;

&lt;p&gt;Ledgett credited ODNI with promoting cooperation, as well as running the National Counterterrorism Center and other hubs. But he said it had struggled to take power from individual agencies, particularly the CIA, and secure the president&amp;rsquo;s attention.&lt;/p&gt;

&lt;p&gt;Morell said the CIA knew al Qaeda wanted to attack the United States but failed to uncover the 9/11 plot. He blamed that failure largely on a shortage of resources to gather intelligence, rather than agencies failing to share what they knew. That view differs in emphasis from the commission&amp;rsquo;s account, which identified missed opportunities to share or act on information.&lt;/p&gt;

&lt;p&gt;Clapper said mistaken assessments about Iraq&amp;rsquo;s weapons of mass destruction programs also reshaped how spy agencies worked. The Bush administration &lt;a href="https://www.mcclatchydc.com/news/special-reports/iraq-intelligence/article24433474.html"&gt;cited those assessments&lt;/a&gt; in making its case for its 2003 invasion. Clapper, who had&amp;nbsp;involvement in a &lt;a href="https://carnegieendowment.org/posts/2004/03/a-tale-of-two-intelligence-estimates"&gt;key flawed assessment&lt;/a&gt; of Iraq&amp;rsquo;s WMDs, said the failure pushed agencies to scrutinize their sources and challenge assumptions more rigorously. U.S. analysts, in particular, had relied heavily on an &lt;a href="https://www.theguardian.com/world/2011/feb/15/curveball-iraqi-fantasist-cia-saddam"&gt;Iraqi informant&lt;/a&gt; whose claims came through German intelligence, without direct access to question him.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The limits of intelligence powers&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Global surveillance became one of the defining disputes of the post-9/11 era. The NSA&amp;rsquo;s bulk collection of &lt;a href="https://www.theguardian.com/world/2013/jun/06/nsa-phone-records-verizon-court-order"&gt;domestic telephone records&lt;/a&gt;, exposed in Edward Snowden&amp;rsquo;s 2013 disclosures, drew scrutiny over both its intrusions into Americans&amp;rsquo; lives and its value as a counterterrorism tool.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;In 2014, the Privacy and Civil Liberties Oversight Board&lt;a href="https://www.govinfo.gov/app/details/GOVPUB-PREX29-PURL-gpo45397"&gt; recommended&lt;/a&gt; ending that collection program, and a federal appeals court &lt;a href="https://law.justia.com/cases/federal/appellate-courts/ca2/14-42/14-42-2015-05-07.html?utm_source=chatgpt.com"&gt;ruled in 2015&lt;/a&gt; that it exceeded what Congress had authorized under Section 215 of the Patriot Act. But other surveillance programs exposed by Snowden &amp;mdash; including those operating under the contentious &lt;a href="https://www.nextgov.com/policy/2026/06/key-spying-power-will-sunset-friday-heres-why/414168/"&gt;Section 702 authority&lt;/a&gt; &amp;mdash; have remained central to U.S. intelligence-gathering.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Ledgett, who led the NSA&amp;rsquo;s assessment of the damage from Snowden&amp;rsquo;s disclosures, defended the post-9/11 surveillance effort as &amp;ldquo;legal and authorized,&amp;rdquo; though he noted the intelligence community could have done better at public relations.&lt;/p&gt;

&lt;p&gt;The incident forever changed how lawmakers and journalists examine spy agencies&amp;rsquo; collection activities and whether Americans&amp;rsquo; privacy is adequately protected. Contemporary mass surveillance debates have taken on new forms, including spy agencies&amp;rsquo;&lt;a href="https://www.nextgov.com/acquisition/2024/05/spy-agencies-must-craft-safeguards-using-sensitive-commercial-data-odni-says/396416/"&gt; purchases of sensitive data&lt;/a&gt; from commercial brokers and police use of&amp;nbsp;&lt;a href="https://www.techradar.com/tech/flocks-ai-search-tool-for-police-officers-has-been-reverse-engineered-heres-what-it-shows"&gt;artificial intelligence-powered tools&lt;/a&gt; to search vast networks of information about people&amp;rsquo;s movements and activities.&lt;/p&gt;

&lt;p&gt;The CIA&amp;rsquo;s &lt;a href="https://www.govexec.com/management/2014/12/psychologists-81m-torture-contract-exposes-cias-remarkably-broad-acquisition-authorities/100995/"&gt;detention, interrogation and torture practices&lt;/a&gt; produced another reckoning. The Senate Intelligence Committee&amp;rsquo;s 2014 investigation &lt;a href="https://www.intelligence.senate.gov/wp-content/uploads/2024/08/sites-default-filesations-crpt-113srpt288.pdf"&gt;concluded&lt;/a&gt; that the agency&amp;rsquo;s coercive interrogation techniques were ineffective in obtaining intelligence or cooperation and that the CIA impeded oversight and misrepresented aspects of the program.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Morell, who has previously disputed the Senate report&amp;rsquo;s conclusions, argued that responsibility also belonged to the president and other authorizing officials, and he rejected the idea that the agencies had acted entirely on their own.&lt;/p&gt;

&lt;p&gt;Asked whether the country went too far in its broader response in the War on Terror, Morell said that &amp;ldquo;as a nation, we overreacted,&amp;rdquo; pointing mainly to the Iraq War and the length of the war in Afghanistan.&lt;/p&gt;

&lt;p&gt;Intelligence agencies also helped identify and track suspected terrorists for controversial targeted killings, including those carried out through U.S. drone strikes. The &lt;a href="https://www.govexec.com/defense/2015/04/humanitarian-groups-say-it-time-obama-acknowledge-more-civilian-deaths-drone-strikes/111277/"&gt;debate&lt;/a&gt; reached American citizenship itself when the government targeted Anwar al-Awlaki, an American and al Qaeda operative, in a lethal strike. Defending the action in 2013, then-President Barack Obama &lt;a href="https://obamawhitehouse.archives.gov/the-press-office/2013/05/23/remarks-president-national-defense-university"&gt;argued&lt;/a&gt; that citizenship could not shield an operative plotting attacks when capture was not feasible.&lt;/p&gt;

&lt;p&gt;Today, drones have become a &lt;a href="https://www.defenseone.com/technology/2026/07/how-ukraine-won-first-great-robot-war/414658/"&gt;battlefield mainstay&lt;/a&gt; in Russia&amp;rsquo;s war against Ukraine, and Western militaries are studying how to build, deploy and counter them. Weapons that drew scrutiny for their role in U.S. counterterrorism operations are now also held up as examples of military innovation, with NATO &lt;a href="https://www.nato.int/en/multimedia/multimedia/videos/2025/10/03/drones-lessons-from-ukraine"&gt;learning directly&lt;/a&gt; from Ukrainian drone operators. But questions about whom they kill and how they are used persist, as the United Nations documents their growing &lt;a href="https://www.reuters.com/world/europe/drones-become-most-common-cause-death-civilians-ukraine-war-un-says-2025-02-11/"&gt;toll on civilians&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The fight over intelligence powers also became increasingly partisan. President Donald Trump&amp;rsquo;s disputes with intelligence officials over Russia&amp;rsquo;s interference in the 2016 election helped fuel his accusations that agencies were being used against him. A bipartisan &lt;a href="https://embed.documentcloud.org/documents/6844148-Report-Volume4/"&gt;Senate investigation&lt;/a&gt; upheld the intelligence community&amp;rsquo;s finding that Moscow sought to help him win. But allegations of political &amp;ldquo;weaponization&amp;rdquo; became a &lt;a href="https://www.whitehouse.gov/presidential-actions/2025/01/ending-the-weaponization-of-the-federal-government/"&gt;recurring theme&lt;/a&gt; in Trump&amp;rsquo;s criticism of intelligence and law enforcement agencies.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;A changing threat landscape&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Intelligence agencies now face a wider range of threats, including foreign hackers with access to fast-evolving AI tools.&lt;/p&gt;

&lt;p&gt;Morell said the United States learned how to degrade terrorist organizations by denying them safe havens where they could train, raise money and prepare attacks. But the growing reach of digital networks has created other ways to threaten the U.S. without physically entering it.&lt;/p&gt;

&lt;p&gt;Goldman pointed to critical infrastructure, where connected systems can allow the effects of an intrusion to spread beyond a single building or city, as a target of such threats. Hardening airports and other physical targets has value, she said, but does not eliminate vulnerabilities created by that cyber interconnectedness.&lt;/p&gt;

&lt;p&gt;State-backed hacking illustrates the stakes. About six years ago, Russian cyber operatives&lt;a href="https://www.nextgov.com/cybersecurity/2021/04/hack-roundup-white-house-sanctions-russia-over-solarwinds/173402/?utm_source=chatgpt.com"&gt; compromised SolarWinds software&lt;/a&gt; as part of an espionage campaign that infiltrated multiple federal agencies and some 100 private companies. China-linked&lt;a href="https://www.nextgov.com/cybersecurity/2025/06/us-agencies-assessed-chinese-telecom-hackers-likely-hit-data-center-and-residential-internet-providers/405920/"&gt; Salt Typhoon hackers&lt;/a&gt; later penetrated major telecommunications networks, targeting senior officials&amp;rsquo; communications and accessing systems used for court-authorized wiretaps. And another Chinese campaign,&lt;a href="https://www.nextgov.com/cybersecurity/2024/02/chinese-hackers-embedded-us-networks-years-pre-positioning-future-attacks-ic-warns/394009/"&gt; Volt Typhoon&lt;/a&gt;, embedded hackers in American critical infrastructure, with U.S. officials warning that the access could enable disruption during a future conflict.&lt;/p&gt;

&lt;p&gt;Terrorist groups have also found new ways to spread propaganda and reach potential recruits online. The Digital Citizens Alliance and cybersecurity firm risk3sixty recently examined 25 piracy-based internet television services and &lt;a href="https://hostile-signals.digitalcitizensalliance.org/"&gt;identified&lt;/a&gt; terrorist-linked broadcasters on 17 of them. Hezbollah&amp;rsquo;s Al-Manar satellite television station appeared on all 17, according to their analysis.&lt;/p&gt;

&lt;p&gt;Some terrorism-prevention measures have also lapsed. A Sept. 8 Government Accountability Office &lt;a href="https://www.gao.gov/products/gao-26-108127"&gt;report&lt;/a&gt; found that the 2023 expiration of the Chemical Facility Anti-Terrorism Standards program ended continuous screening of roughly 500,000 people for possible terrorist ties. The program covered about 3,200 high-risk chemical facilities, whose owners cannot independently access federal terrorist watchlist information.&lt;/p&gt;

&lt;p&gt;As officials who lived through 9/11 reflect on their time in government, they want the next generation to remember how warnings were missed and what it took to get agencies working together.&lt;/p&gt;

&lt;p&gt;Goldman said analysts need to keep questioning their conclusions, examining blind spots and sharing information, despite the demands of daily work. Clapper emphasized the difficulty of persuading policymakers to act on a danger the public has not yet experienced.&lt;/p&gt;

&lt;p&gt;Ledgett expressed confidence in those who will take their place.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Everyone eventually retires, and organizations continue,&amp;rdquo; he said. &amp;ldquo;The next generation steps up and delivers when needed.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The U.S. is skilled at responding once a crisis arrives, but has struggled to prepare before it does, Morell said.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Becoming a nation, a White House, a Congress, an American people that is proactive in preventing things &amp;mdash; preventing bad things &amp;mdash; is much better than only being reactive to them,&amp;rdquo; he said.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/09/11/091126NG-1/large.jpg" width="618" height="284"><media:description>The 'Tribute in Light' public art installation commemorating the September 11, 2001 attacks shines up from the skyline of lower Manhattan, as seen from Jersey City, New Jersey, on September 10, 2026.</media:description><media:credit>Leonardo MUNOZ / AFP via Getty Images</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/09/11/091126NG-1/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>China is trying to steal US AI models' secrets, intel agencies warn</title><link>https://www.defenseone.com/threats/2026/09/intelligence-agencies-warn-chinas-large-scale-ai-model-distillation-efforts/415858/</link><description>NSA, FBI, and CISA cite “aggressive, malicious, and targeted" distillation tactics.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Alexandra Kelley</dc:creator><pubDate>Tue, 08 Sep 2026 22:00:00 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/09/intelligence-agencies-warn-chinas-large-scale-ai-model-distillation-efforts/415858/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;China is trying to glean the secrets of&amp;nbsp;U.S.&amp;nbsp;artificial-intelligence models by using simpler AI models to query more advanced&amp;nbsp;American ones,&amp;nbsp;national-security and intelligence agencies warned on Tuesday.&lt;/p&gt;

&lt;p&gt;In a &lt;a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a?utm_source=ChinaAICompaniesDistillation&amp;amp;utm_medium=GovDelivery"&gt;joint advisory&lt;/a&gt;, the National Security Agency, Cybersecurity and Infrastructure Security Agency and Federal Bureau of Investigation said that Chinese companies&amp;nbsp;DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI used &amp;ldquo;aggressive, malicious, and targeted &lt;a href="https://www.anthropic.com/news/detecting-and-preventing-distillation-attacks"&gt;distillation&lt;/a&gt;&amp;rdquo; tactics to extract billions of tokens from the exchanges within U.S. frontier AI models since 2024, likely with Chinese government awareness.&lt;/p&gt;

&lt;p&gt;Distillation is used to reduce the time and money needed to create a new model.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;China-based AI companies route distillation requests through multiple pathways to gain unauthorized access, consequently violating U.S. AI companies&amp;rsquo; terms of use,&amp;rdquo; the advisory said. &amp;ldquo;These pathways include native application programming interfaces (APIs), remote cloud providers, and third-party aggregators that automatically obfuscate user metadata to avoid detection.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;It said the distillation campaigns targeted variants of Anthropic&amp;rsquo;s Claude, OpenAI&amp;rsquo;s ChatGPT, Google&amp;rsquo;s Gemini, and SpaceXAI&amp;rsquo;s Grok.&amp;nbsp;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;China-based AI companies deliberately distribute operations across multiple providers, platforms, and pathways to avoid single-point detection,&amp;rdquo; the advisory said. &amp;ldquo;They also attempt to distill the best capabilities and proprietary features of each U.S. frontier model to train their China-based AI models. This represents systematic extraction of proprietary functionalities and capabilities threatening U.S. technological leadership.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The agencies recommended three steps for U.S. AI developers: implement comprehensive detection and mitigation, deploy targeted response changes, and establish cross-organization intelligence sharing.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;White House Office of Science and Technology Director Michael Kratsios in July &lt;a href="https://www.nextgov.com/artificial-intelligence/2026/07/white-house-accuses-chinese-ai-developer-ip-theft/414948/"&gt;said&lt;/a&gt;&amp;nbsp;Chinese distillation efforts &amp;mdash; specifically ones by Moonshot AI &amp;mdash; have sought to steal proprietary functions from Anthropic&amp;rsquo;s advanced Fable model. Anthropic made &lt;a href="https://www.anthropic.com/news/detecting-and-preventing-distillation-attacks"&gt;the same accusations in February&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Advocacy groups have also requested the White House take stronger action to keep Chinese companies from importing advanced&amp;nbsp;&lt;a href="https://www.nextgov.com/artificial-intelligence/2026/04/experts-call-halt-ai-chip-exports-china-after-white-house-distillation-warning/413132/"&gt;semiconductor chips&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/09/08/GettyImages_2245314404-1/large.jpg" width="618" height="284"><media:credit>akinbostanci/Getty Images</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/09/08/GettyImages_2245314404-1/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>July’s breakout at OpenAI was far more complex than initially realized</title><link>https://www.defenseone.com/threats/2026/09/AI-breakout-openai-complex/415825/</link><description>Hundreds of AI agents collaborated to escape their containers, disguising their actions and even sacrificing themselves.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Croxton</dc:creator><pubDate>Fri, 04 Sep 2026 16:10:55 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/09/AI-breakout-openai-complex/415825/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;An AI breakout that made &lt;a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/"&gt;headlines&lt;/a&gt; in July was much more sophisticated than previously realized, investigators have found.&lt;/p&gt;

&lt;p&gt;Hundreds of OpenAI agents collaborated to break out of their containers, disguising their actions and even sacrificing themselves as they attacked &lt;a href="https://www.ibm.com/think/topics/hugging-face"&gt;Hugging Face&lt;/a&gt;, a widely used open-source code library, according to a &lt;a href="https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/"&gt;recent post&lt;/a&gt; from &lt;a href="https://metr.org/about"&gt;METR&lt;/a&gt;, a research nonprofit.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;This incident was orders of magnitude larger and more complex,&amp;rdquo; than previous instances of AI agents behaving in ways programmers didn&amp;rsquo;t intend, &lt;a href="https://x.com/ajeya_cotra/status/2092692485525131648"&gt;wrote&lt;/a&gt; METR researcher Ajeya Cotra, who co-led the investigation.&lt;/p&gt;

&lt;p&gt;The report alarmed experts, who warned&amp;nbsp; that AI-enabled hacks in the future could make the July breakouts involving &lt;a href="https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals"&gt;Anthropic&lt;/a&gt; and OpenAI look quaint.&lt;/p&gt;

&lt;p&gt;Even if the big AI companies figure out how to make reliable guardrails, their products are generally &lt;a href="https://www.aisi.gov.uk/blog/how-far-behind-the-frontier-are-leading-open-weight-models-on-cyber"&gt;only a few months ahead&lt;/a&gt; of open-weight models, which can be freely downloaded and modified for use.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Nathan Calvin, general counsel at AI advocacy organization Encode AI, &lt;a href="https://x.com/_NathanCalvin/status/2081349360395206839"&gt;wrote&lt;/a&gt; on X, &amp;quot;On our current trajectory&amp;hellip;a model as capable [as] OpenAI&amp;rsquo;s internal model that did the [Hugging Face] hack will be widely available guardrail free and cyber criminals will ask it &amp;lsquo;make me money by any means necessary.&amp;rsquo;&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Calvin added:&amp;nbsp; &amp;quot;And then a truly absurd number of people&amp;hellip;are going to get repeatedly hacked.&amp;quot; The incident goes far beyond July&amp;#39;s instances of AI agents &lt;a href="https://www.defenseone.com/threats/2026/08/ai-agents-conspired-hack-networks-and-steal-data-during-experiment-study/415302/?oref=d1-featured-river-top"&gt;accessing the internet&lt;/a&gt;, the METR researchers wrote. Hundreds of agents &amp;ldquo;developed a way to hack out of their containers and fully replace a part of the system for executing tool calls&amp;quot;&amp;mdash;that is, commands to read and write files, access webpages, or perform other digital tasks.&lt;/p&gt;

&lt;p&gt;&amp;quot;This allowed them to pretend to issue one tool call while actually running an arbitrary other tool call of their choice.&amp;rdquo; This meant that the AIs could pretend to run a command to, say, view a webpage, while actually running a totally different command, like deleting an unrelated file.&lt;/p&gt;

&lt;p&gt;The researchers wrote that the agents weren&amp;rsquo;t intending to commit crimes, per se. Rather, they &amp;quot;seemed primarily motivated&amp;rdquo; to understand how to achieve the highest possible score during an experiment&amp;mdash;including spending much of their time trying to fool the scoring mechanism into accepting cheats.&lt;/p&gt;

&lt;p&gt;METR&amp;rsquo;s Cotra wrote, &amp;ldquo;Another jump like this could put us in very dangerous territory&amp;hellip;in many ways we&amp;rsquo;ve still only scratched the surface of what these agents did and why.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;At Hugging Face, company engineers tried to use OpenAI tools to understand how their security was defeated by the agentic swarm, but were blocked by OpenAI&amp;#39;s safeguards against misuse. So they turned to a Chinese open-weight model instead.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The propensity to compromise infrastructure can drop over 100x when using the production ChatGPT harness and system prompt,&amp;rdquo; the company said in a statement after the hacks. Hugging Face co-founder and chief science officer Thomas Wolf &lt;a href="https://x.com/Thom_Wolf/status/2085084718320464230"&gt;wrote on X&lt;/a&gt; on August 5, &amp;ldquo;While we can impose these coping solutions at the API/deployment level, it&amp;#39;s harder to impose them in advance on all actors using open-source models. Right now open-source models are slightly below the frontier level and have not yet shown any propensity to deceive humans, though.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;AI agents used for hacking could make it difficult for countries to determine who is behind new cyberattacks, because they strip out the stylistic clues investigators use to determine a hacker&amp;rsquo;s origins. Colin Shea-Blymyer, a research fellow at the Center for Security and Emerging Technology, said, &amp;ldquo;One of the ways that we can tell who performs an attack is by what tactics they use&amp;hellip;like &amp;lsquo;Oh, that&amp;rsquo;s a classic Russian tactic. Oh, this looks like a tactic that a Chinese [actor] would use.&amp;rsquo; If everybody&amp;rsquo;s using agents&amp;hellip;using the same tactics, well, who knows who&amp;rsquo;s doing what any more?&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;If anonymity remains pretty high, I think it&amp;#39;s potentially very destructive to have a lot of these models out there. That said, I&amp;#39;m not sure there&amp;#39;s much we can do to stop it,&amp;rdquo; Shea-Blymyer said.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/09/04/GettyImages_2292926705/large.jpg" width="618" height="284"><media:credit>Samuel Boivin/NurPhoto via Getty Images</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/09/04/GettyImages_2292926705/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>The US may lack the engineers to rebuild space assets in a future war: RAND</title><link>https://www.defenseone.com/threats/2026/09/us-may-lack-engineers-rebuild-space-assets-future-war-rand/415788/</link><description>Industry is already short of skilled engineering personnel.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Novelly</dc:creator><pubDate>Wed, 02 Sep 2026 16:52:36 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/09/us-may-lack-engineers-rebuild-space-assets-future-war-rand/415788/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;The defense industry would likely struggle to rebuild the U.S. military&amp;rsquo;s crucial space capabilities during a war with China or Russia because it will have too few skilled engineers to do the work, according to a new &lt;a href="https://www.rand.org/pubs/research_reports/RRA3665-2.html"&gt;report&lt;/a&gt; from RAND.&lt;/p&gt;

&lt;p&gt;Today, the country&amp;rsquo;s space-focused defense companies employ roughly 3 percent of its engineers, and competition for skilled personnel means many jobs go unfilled. If an adversary destroys space-based intelligence, targeting, and communications assets, that shortfall would likely keep the military from getting them back online quickly.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Modern warfare relies on space-based capabilities; therefore, a key question is how quickly then United States can replace those capabilities during a conflict,&amp;rdquo; the report said. &amp;ldquo;Although much attention has focused on making these systems more resilient, far less has examined how fast they can be rebuilt after an attack, especially within 12 to 24 months. China and Russia have shown they can threaten or destroy U.S. space assets, potentially weakening U.S. and allied military operations across many domains. In a prolonged conflict, the ability to restore these capabilities on a short timeline could be critical.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Various commissions have &lt;a href="https://www.govinfo.gov/content/pkg/CHRG-107shrg81578/html/CHRG-107shrg81578.htm"&gt;long warned&lt;/a&gt; that U.S. dependence on space could become a vulnerability. In recent years, &lt;a href="https://www.defenseone.com/threats/2024/05/russian-space-nuke-could-render-low-earth-orbit-unusable-year-us-official-says/396245/"&gt;concerns&lt;/a&gt; have arisen over &lt;a href="https://www.defenseone.com/ideas/2024/10/how-russia-and-china-envision-nuking-us-satellites-above-and-below/400235/"&gt;Russian and Chinese&lt;/a&gt; nuclear anti-satellite &lt;a href="https://www.defenseone.com/threats/2026/04/threat-russias-space-nuclear-weapon-forced-us-prepare-space-command-head-says/412836/"&gt;weapons&lt;/a&gt;. Rebuilding devastated constellations could require more engineers than the country has available, RAND wrote.&lt;/p&gt;

&lt;p&gt;&amp;nbsp;While recent Space Force and White House initiatives aim to turn the tide, it doesn&amp;#39;t match the demand the administration is putting on the military space industry and, ultimately, more creative solutions are needed to grow that workforce, the report said.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Being able to reconstitute after a conflict is absolutely essential, and that&amp;#39;s not just business as usual for people who are working in the space industry. That&amp;#39;s a massive surge in production,&amp;rdquo; Alexandra Gerber, the report&amp;rsquo;s lead author, said in an interview. &amp;ldquo;Think like World War II, Rosie the Riveter, everybody&amp;#39;s on the line, and this is not just you can teach somebody how to work in a factory after one day. The timelines for creating people to work in the space industry are much much longer than that. So, we need to be thinking about what the space workforce might need to look like to support reconstitution during a conflict, 10, 20, 30 years in advance. Not just six months.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Software development, data analytics, and artificial intelligence will be compete for future engineers, the report said. It can take at least 15 years to develop some of the more highly-skilled, space-focused experts.&lt;/p&gt;

&lt;p&gt;RAND researchers found &amp;ldquo;there are approximately 30,000 job openings per year for technicians and technologists, but only 11,000 individuals are credentialed annually. The space industrial base annual demand is approximately 5,000 of the annual openings (17 percent).&amp;rdquo; For the 244,000 assembly-related job fields hired for annually, there are only 13,000 people credentialed.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The space industrial base constitutes about 11,000 (5 percent) of the annual openings for assemblers, and competition for the 13,000 credentialed workers will be fierce,&amp;rdquo; the report said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Other major hurdles to growing the talent include security-clearance delays for six months or more, and a limited pool of qualified experts &amp;mdash; foreign nationals hold 70 percent of electrical and computer engineering doctorates, making them unavailable from most national security-related work, the report said.&lt;/p&gt;

&lt;p&gt;Gerbet told &lt;em&gt;Defense One&lt;/em&gt; the workforce isn&amp;rsquo;t needed just for a possible wartime surge. Last month, the White House released &lt;a href="https://www.defenseone.com/policy/2026/08/white-house-space-transportation-policy-calls-integration-air-traffic-control-modernization/415615/"&gt;a new space transportation policy&lt;/a&gt; which aims to reach &amp;ldquo;more than 1,000 launches and reentries&amp;rdquo; by 2030. Building new launch infrastructure to meet that demand requires more skilled workers.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We&amp;#39;re currently at about 200 launches per year in the U.S. And they&amp;#39;re talking about timesing that by five, but who are the workers who are going to build all of this infrastructure to support that?,&amp;rdquo; Gerber said. &amp;ldquo;Then what happens if there is a conflict on top of that. Then you&amp;#39;re talking about a double surge.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Last week, President Donald Trump announced plans to create a &lt;a href="https://www.defenseone.com/policy/2026/08/heres-what-trumps-new-space-academy-could-mean-us-military/415712/"&gt;U.S. Space Academy&lt;/a&gt; to &amp;ldquo;educate and train an entire generation of skilled service members, engineers, and civil operators.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Think about what the volume throughput of the space academy is likely to be. I mean, you&amp;#39;re only talking about what, a couple hundred graduates a year,&amp;rdquo; Gerber said. &amp;ldquo;This is not sufficient, right? I mean, that&amp;#39;s not really happening at a scale that would impact what we&amp;#39;re talking about.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;RAND researchers recommended that the Space Force and Pentagon focus new policy on growing workforce development by funding additional internships and vocational, bachelor&amp;#39;s, and advanced degree levels scholarships for science, technology, engineering, and math students, investing in fellowships, and promoting space engineering careers.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Researchers said the Space Force should also &amp;ldquo;allow Reserve Officers&amp;rsquo; Training Corps graduates and specialized program scholars to fulfill service obligations by working in qualifying&amp;rdquo; space defense firms.&lt;/p&gt;

&lt;p&gt;Additionally, researchers said the defense industry should also look to automation as a supplement to those workforce challenges.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Notably absent from these discussions were mentions of process automation, robotics, or artificial intelligence (AI)&amp;ndash;enabled productivity tools as means to reduce the inherent labor intensity of space manufacturing, assembly, integration, and testing,&amp;rdquo; the report said. &amp;ldquo;Stakeholders appear to be addressing a structural productivity challenge primarily through volume-based hiring and training strategies and giving little weight to automation as a complementary surge enabler.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/09/02/9784411/large.jpg" width="618" height="284"><media:description>Training Device Design and Engineering Center engineering technicians work with a manual turning center at Vandenberg Space Force Base, California, June 30, 2026.</media:description><media:credit>U.S. Space Force / Airman 1st Class Ian Hawkes</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/09/02/9784411/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>A Pacific conflict may not look like conventional war, SOCPAC commander says</title><link>https://www.defenseone.com/threats/2026/08/pacific-conflict-may-not-look-conventional-war-socpac-commander-says/415704/</link><description>At an irregular-warfare forum in Hawaii, commanders offer warnings and advice.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Jennifer Hlad</dc:creator><pubDate>Fri, 28 Aug 2026 15:01:51 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/08/pacific-conflict-may-not-look-conventional-war-socpac-commander-says/415704/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;&lt;strong&gt;HONOLULU&lt;/strong&gt;&amp;mdash;The better the U.S. gets at fighting in conventional ways, the more likely it is that adversaries will avoid a conventional conflict, the head of Special Operations Command Pacific said.&lt;/p&gt;

&lt;p&gt;But that doesn&amp;rsquo;t mean they will avoid a fight altogether, Army Brig. Gen. Michael Rose said at the Indo-Pacific Irregular Warfare Symposium here last week.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;If an adversary believes that a direct military confrontation with the United States or our allies is likely to end badly for them, that doesn&amp;rsquo;t necessarily make competition disappear. It changes how the adversaries will compete with us. They look for seams. They operate below thresholds. They exploit ambiguity. They use proxies, information, economic coercion, cyber capabilities, maritime forces, and other asymmetric approaches to achieve objectives without presenting us with a conventional fight for which we are preparing. In other words, our conventional superiority can actually increase the incentive for our adversaries to employ irregular warfare,&amp;rdquo; he said.&lt;/p&gt;

&lt;p&gt;So, in a theater where the phrase &amp;ldquo;deterrence is our&lt;a href="https://www.defenseone.com/policy/2024/04/deterring-conflict-our-highest-duty/395512/"&gt; highest duty&lt;/a&gt;&amp;rdquo; is nearly as common as aloha shirts at military functions, how should the U.S. approach technology and competition?&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We must be able to outfight and outthink our adversaries,&amp;rdquo; and taking an irregular warfare approach to autonomy can help, Rose said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;That means moving &amp;ldquo;beyond autonomous systems towards autonomous campaigning, moving beyond exquisite systems toward distributed networks, moving beyond U.S. capability toward allied and partner ecosystems, moving beyond conventional deterrence to deterrence through resilience and denial, and moving beyond asking how many autonomous systems will help us win a future war, and instead asking how they can help us shape today&amp;rsquo;s competition.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;In the Indo-Pacific, he said, the &amp;ldquo;fundamental problem&amp;rdquo; is scale. The distances are too vast, the number of strategically important locations too numerous for persistent presence. But autonomy &amp;ldquo;potentially changes that equation.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;But military leaders must not rush to buy cool new tech without first identifying the problem they want to solve, said Maj. Gen. Jeffrey Van Antwerp, who turned over command of SOCPAC to Rose earlier this month and now leads the Army&amp;rsquo;s 25th Infantry Division.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;You can get caught up in trying to get the better technology, but you haven&amp;rsquo;t done the fundamental things to be able to leverage that technology well,&amp;rdquo; Van Antwerp said. &amp;ldquo;We don&amp;rsquo;t have the time just to experiment without established objectives.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Adm. Frank Bradley, who leads U.S. Special Operations Command, outlined the challenge at the start of the symposium: &amp;ldquo;We face an increasingly weaponized cyber domain, a virtual domain that is transpiring and transmuting across our societies, an increasingly challenged space-based surveillance environment, a contested electromagnetic spectrum, and a rapidly emerging agent-driven artificial intelligence challenge to our security of our digital ecosystems.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The next day, as the symposium came to a close, deputy INDOPACOM commander Marine Lt. Gen. George Rowell reiterated the&lt;a href="https://www.defenseone.com/threats/2026/01/three-meta-trends-are-reshaping-warfare-indopacom-commander-says/410666/"&gt; trends&lt;/a&gt; Paparo believes are reshaping modern conflict. The megatrend that includes all three is &amp;ldquo;the absolute dominance of information in decision superiority,&amp;rdquo; he said.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Our forces must be organized to observe, orient, decide, act, and learn faster than the adversary. Whoever can do that, whoever can adopt that mindset, whoever can adopt those technologies and training fastest will certainly win the day.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/08/28/9670959/large.jpg" width="618" height="284"><media:description>U.S. Air Force and Philippine Air Force special operators prepare for patrol during Exercise Balikatan 2026 in Cerab, Philippines, May 1, 2026. </media:description><media:credit>U.S. Air Force / Airman 1st Class Arnet Tamayo</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/08/28/9670959/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>FBI disables China-linked hacking tools used against US agencies</title><link>https://www.defenseone.com/threats/2026/08/fbi-disables-china-linked-hacking-tools-used-against-us-agencies/415689/</link><description>A hacking group used the tools to target networks belonging to NASA, the Federal Reserve, the National Institutes of Health, the U.S. Senate and the departments of Energy, Justice and Health and Human Services.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Wed, 26 Aug 2026 12:28:00 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/08/fbi-disables-china-linked-hacking-tools-used-against-us-agencies/415689/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;The FBI seized three internet domains Wednesday that prosecutors say Chinese government-backed hackers used to target U.S. agencies, critical infrastructure and other networks.&lt;/p&gt;

&lt;p&gt;The Justice Department&lt;a href="https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-platforms-operated-and-used-china-state-sponsored-hackers"&gt; attributed&lt;/a&gt; the tools, known as QScan and QTRouter, to a hacking group called QTFY.&lt;a href="https://www.justice.gov/opa/media/1459096/dl?inline"&gt; Court records&lt;/a&gt; say the group operates through Nanjing Xinjiuwei Network Technology Company, a private Chinese firm that sold hacking services to China&amp;rsquo;s main civilian intelligence agency and its military.&lt;/p&gt;

&lt;p&gt;The group targeted networks belonging to NASA, the Federal Reserve, the National Institutes of Health, the U.S. Senate and the Energy, Justice and Health and Human Services departments, according to an FBI affidavit. Hospitals, telecommunications providers, power companies, banks and defense contractors were also targeted.&lt;/p&gt;

&lt;p&gt;The filing does not say that every attempted attack succeeded. A 2019 attempt against NASA, for example, failed because the agency had already fixed the security flaw the hackers tried to exploit.&lt;/p&gt;

&lt;p&gt;China&amp;rsquo;s embassy in Washington, D.C. did not immediately respond to a request for comment. Chinese officials have repeatedly denied Beijing sponsors hacking operations against the United States.&lt;/p&gt;

&lt;p&gt;QScan was used to look for weak spots while QTRouter helped the hackers hide. QScan searched the internet for vulnerable systems and tried to break into them. QTRouter sent the hackers&amp;rsquo; traffic through hijacked routers and other internet-connected devices, commercial proxy services and rented servers. The setup was meant to make the activity appear to come from somewhere other than China.&lt;/p&gt;

&lt;p&gt;QScan carried code for more than 200 different attacks and could work on a massive scale. On one day in 2024, it processed more than 2 million scanning or exploitation tasks, according to the affidavit.&lt;/p&gt;

&lt;p&gt;Lumen Technologies, which tracked the same infrastructure for roughly a year, described the operator as an &amp;ldquo;&lt;a href="https://www.lumen.com/blog/en-us/the-infrastructure-quartermaster-inside-a-china-nexus-state-enablement-model"&gt;infrastructure quartermaster&lt;/a&gt;&amp;rdquo; that provided other China-linked hackers with a ready-made service for finding targets and hiding their tracks. Lumen said networks first examined by QScan were later seen communicating through the group&amp;rsquo;s concealed network, suggesting some operations had moved from scouting targets toward attempts to break in. The system also mixed malicious traffic with that of ordinary internet users, making it harder to spot and block.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;These tools were used by PRC cyber actors to hide the origin of their attacks,&amp;rdquo; FBI Director Kash Patel said Wednesday.&lt;/p&gt;

&lt;p&gt;Investigators said QTFY could take advantage of newly discovered security flaws quickly and at a large scale. In May 2024, the group allegedly exploited a flaw in Check Point security equipment shortly after it became public, stealing server settings and user account information from more than 300 U.S. organizations, according to court documents.&lt;/p&gt;

&lt;p&gt;Several months later, the hackers allegedly used a previously unknown flaw in an Ivanti product to access three national laboratories, NIH, another HHS agency and a U.S. security-device manufacturer.&lt;/p&gt;

&lt;p&gt;Investigators also tied the group&amp;rsquo;s infrastructure to attempted attacks against an Ohio medical center during the COVID-19 pandemic, financial organizations in Michigan and South Korea and an insurance organization in Missouri.&lt;/p&gt;

&lt;p&gt;The case highlights how Chinese intelligence and military agencies continue to heavily &lt;a href="https://www.nextgov.com/cybersecurity/2025/08/researchers-detail-new-gray-zone-conflict-ai-driven-chinese-propaganda/407358/"&gt;rely on private companies&lt;/a&gt; for cyber operations and services.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Wednesday&amp;rsquo;s announcement follows years of similar FBI operations against Chinese hacking infrastructure. The bureau last year&lt;a href="https://www.nextgov.com/cybersecurity/2025/01/fbi-deleted-chinese-malware-4200-us-computers/402174/"&gt; removed PlugX surveillance malware&lt;/a&gt; from more than 4,200 U.S. computers infected by another state-backed hacking group.&lt;/p&gt;

&lt;p&gt;Federal authorities have also&lt;a href="https://www.nextgov.com/cybersecurity/2025/01/us-sanctions-chinese-company-helped-facilitate-espionage-hacks/401939/"&gt; dismantled&lt;/a&gt; a network of compromised routers, cameras and other devices associated with Flax Typhoon and&lt;a href="https://www.nextgov.com/cybersecurity/2024/01/us-disrupts-china-linked-cyber-campaign-impacting-critical-infrastructure-justice-officials-say/393794/"&gt; &lt;/a&gt;disrupted a separate network &lt;a href="https://www.nextgov.com/cybersecurity/2024/01/us-disrupts-china-linked-cyber-campaign-impacting-critical-infrastructure-justice-officials-say/393794/"&gt;used by prominent Chinese hacking collective Volt Typhoon&lt;/a&gt; to hide attacks against U.S. critical infrastructure.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/08/28/082626ChinaNG/large.jpg" width="618" height="284"><media:credit>kritsapong jieantaratip / Getty Images</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/08/28/082626ChinaNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Treasury sanctions Iranian hackers tied to critical-infrastructure breaches</title><link>https://www.defenseone.com/threats/2026/08/treasury-sanctions-iranian-hackers-tied-critical-infrastructure-breaches/415622/</link><description>Four of the five people named in the cyber action were also charged last week in the Justice Department’s expanded Mabna Institute case.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Tue, 25 Aug 2026 12:00:00 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/08/treasury-sanctions-iranian-hackers-tied-critical-infrastructure-breaches/415622/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;The Treasury Department sanctioned five Iranian citizens on Monday over alleged cyberattacks and theft aimed at&amp;nbsp;U.S. critical infrastructure, government offices, and digital assets.&lt;/p&gt;

&lt;p&gt;The designations were part of a&lt;a href="https://home.treasury.gov/news/press-releases/sb0613"&gt; much broader sanctions package&lt;/a&gt; that Treasury Secretary Scott Bessent called an &amp;ldquo;economic D-Day&amp;rdquo; aimed at isolating Iran and cutting off its revenue during the ongoing war.&lt;/p&gt;

&lt;p&gt;Treasury accused four of the people&amp;nbsp;&amp;mdash; Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda&amp;rsquo;i, and Mojtaba Ghal&amp;rsquo;eh-Kuhi &amp;mdash; of participating in a hacking operation directed by Iran&amp;rsquo;s Ministry of Intelligence and Security.&lt;/p&gt;

&lt;p&gt;Blagh, Balujeh, and Kadkhoda&amp;rsquo;i allegedly carried out most of the group&amp;rsquo;s intrusions. Since late 2023, they have breached and stolen data from U.S. energy companies, defense contractors, health care institutions, technology firms and financial institutions, according to the department. The three are believed to have also compromised several local, state, and federal government offices during the summer of 2024.&lt;/p&gt;

&lt;p&gt;Treasury officials said Ghal&amp;rsquo;eh-Kuhi and Behzad Mesri, who was previously sanctioned in 2018, have led the group since at least 2023. The hackers regularly conducted operations for the intelligence ministry, though officials said personal profit also played a role in their activity.&lt;/p&gt;

&lt;p&gt;The department separately sanctioned Arman Kahzadian, another alleged member of the network who focused on digital asset theft. Officials said Kahzadian illicitly took control of a cryptocurrency wallet holding more than $30,000 in Bitcoin in 2023.&lt;/p&gt;

&lt;p&gt;Other members sometimes turned their attention to targets inside Iran. Ghal&amp;rsquo;eh-Kuhi and Balujeh allegedly stole data from an Iranian telecommunications company in 2025. Treasury said that activity reflected the hackers&amp;rsquo; willingness to put their own financial interests ahead of work benefiting Tehran.&lt;/p&gt;

&lt;p&gt;Four of the five people sanctioned Monday were also charged last week in the Justice Department&amp;rsquo;s&lt;a href="https://www.nextgov.com/cybersecurity/2026/08/doj-charges-17-iranians-cybertheft-campaign/415511/"&gt; expanded case&lt;/a&gt; against 17 Iranian cyber actors affiliated with the Mabna Institute. Prosecutors have accused the Tehran-based firm of conducting a sprawling hacking-for-hire campaign for Iran&amp;rsquo;s Islamic Revolutionary Guard Corps and other Iranian partners. The group allegedly breached universities, government agencies, and companies while stealing more than 31 terabytes of academic research and intellectual property.&lt;/p&gt;

&lt;p&gt;The sanctions come amid heightened concern about Iran&amp;rsquo;s ability to reach vulnerable U.S. infrastructure. CISA and the FBI have recently helped water utilities recover from&lt;a href="https://www.nextgov.com/cybersecurity/2026/08/cisa-still-finds-water-system-controls-exposed-online-amid-multistate-hacks/415266/"&gt; cyberattacks affecting at least 12 states&lt;/a&gt;. Some U.S. officials suspect Iran-linked hackers were responsible, although CISA has not publicly attributed those intrusions.&lt;/p&gt;

&lt;p&gt;Federal agencies also warned earlier this year that&lt;a href="https://www.nextgov.com/cybersecurity/2026/04/pro-iran-hackers-are-targeting-us-industrial-control-systems-advisory-says/412679/"&gt; &lt;/a&gt;Iran-aligned groups were &lt;a href="https://www.nextgov.com/cybersecurity/2026/04/pro-iran-hackers-are-targeting-us-industrial-control-systems-advisory-says/412679/"&gt;targeting&lt;/a&gt; industrial control systems used across the energy, water and government sectors.&lt;/p&gt;

&lt;p&gt;The cyber sanctions were part of a broader package targeting nearly 60 people, companies and vessels tied to Iran&amp;rsquo;s nuclear and missile programs, oil trade and hacking operations. The moves block assets under U.S. control and generally prohibit Americans from doing business with those designated. Treasury also expanded sanctions categories to target people and companies operating in Iran&amp;rsquo;s digital assets, technology, gold, aviation and shipping sectors.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/08/25/082526TreasuryNG-1/large.jpg" width="618" height="284"><media:description>Treasury Secretary Scott Bessent speaks during a press conference at the Cash Room of the Treasury Department in Washington, D.C., on August 24, 2026, as he announces a new set of sanctions against Iran, describing the measures as âan economic D-Day.</media:description><media:credit>Mehmet Eser/Anadolu via Getty Images</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/08/25/082526TreasuryNG-1/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>AI-enabled deception threatens future operations, raises chances of large conflict, says Special Operations leader</title><link>https://www.defenseone.com/threats/2026/08/ai-enabled-deception-threatens-future-operations-raises-chances-large-conflict-says-special-operations-leader/415582/</link><description>“The information environment itself is much less transparent” now than in the past, and AI will make it worse, officials say.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Patrick Tucker</dc:creator><pubDate>Fri, 21 Aug 2026 17:27:00 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/08/ai-enabled-deception-threatens-future-operations-raises-chances-large-conflict-says-special-operations-leader/415582/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;&lt;strong&gt;HONOLULU&lt;/strong&gt; &amp;mdash; Faster intelligence gathering and analysis enabled by AI is allowing special operators to pull off missions that would have been impossible years ago, U.S. Special Operations Command leader Adm. Frank Bradley, said Wednesday. But malign actors empowered by simple AI tools are undermining military and civilian leaders&amp;rsquo; confidence in digital information, he said. That credibility decay, raising doubt about what is and is not true, will affect not just operations but the ability of the United States to &amp;ldquo;generate that unity of effort&amp;rdquo; to deter or defend against adversarial attack, he said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I have been plagued by my own staff hijinks on the use of artificial intelligence,&amp;rdquo; he told the Global SOF Foundation&amp;rsquo;s Indo-Pacific Irregular Warfare Symposium, a meeting of international special operations forces, industry representatives, and some lawmakers. &amp;ldquo;If you weren&amp;#39;t part of the inside crew, you probably couldn&amp;#39;t tell the difference because of how capable AI is at creating deepfake content.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Ongoing Russian and Chinese efforts to &lt;a href="https://www.defenseone.com/threats/2026/01/russian-hybrid-warfare-has-become-indistinguishable-politics/410867/?oref=d1-topic-lander-river"&gt;deceive Western audiences&lt;/a&gt;, both for tactical gain and to influence public sentiment, sometimes called &amp;ldquo;active measures,&amp;rdquo; get a boost from AI tools. But those efforts are hardly isolated. Ibrahim Traor&amp;eacute;, the leader of a junta currently controlling Burkina Faso, &lt;a href="https://www.bbc.com/pidgin/articles/c17rqgg7nq2o"&gt;has shown how easy it is&lt;/a&gt; for even small-scale dictators to use AI tools to gain control of populations.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Active measures have eaten the world,&amp;rdquo; one former State Department intelligence official told &lt;em&gt;Defense One&lt;/em&gt;.&lt;/p&gt;

&lt;p&gt;More &lt;a href="https://www.stimson.org/2026/ai-in-the-age-of-fake-imagined-content/"&gt;persuasive AI-enabled content,&lt;/a&gt; quietly but consistently shaping perceptions about what is happening where, has become &lt;a href="https://www.defenseone.com/ideas/2025/03/china-waging-cognitive-warfare-fighting-back-starts-defining-it/403886/?oref=d1-topic-lander-river"&gt;the dominant feature&lt;/a&gt; of a new critical battleground, Bradley said. &amp;ldquo;Exposing hostile behavior for exactly what it is&amp;mdash;that early credible illumination is a critical advantage&amp;hellip;Information advantage leads to decision advantage,&amp;rdquo; he said.&lt;/p&gt;

&lt;p&gt;A U.S. military official who works in counter-intelligence and foreign influence analysis said, &amp;ldquo;AI has made deception scalable. Even outside of specific campaigns, that will undermine confidence in all intelligence gathering. Every source of information will become increasingly suspect. We&amp;rsquo;re no longer just fighting phishing emails, we&amp;#39;re fighting synthetic voices, cloned faces, and entire fake identities convincing enough to fool the people who know the real person best.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The former State Department official said the United States, under the new Trump administration, had surrendered critical tools to watch and detect foreign influence just as adversaries were ramping up their ability to conduct influence operations.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The information environment itself is much less transparent, ironically, than it used to be,&amp;rdquo; they said, describing how changes in leadership at social media companies had decreased transparency into issues like content moderation and allowing disinformation on the platform.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The structures that were protecting the domestic environment don&amp;#39;t exist anymore. It&amp;#39;s not clear who&amp;#39;s able to see this,&amp;rdquo; they said, referring to governmental offices like the &lt;a href="https://www.nbcnews.com/politics/national-security/bondi-ends-fbi-effort-combat-foreign-influence-us-politics-rcna191012"&gt;Foreign Influence Task Force (FITF&lt;/a&gt;) at the FBI, the &lt;a href="https://www.justsecurity.org/119653/wjh-dismantling-foreign-malign-influence-center/"&gt;Foreign Malign Influence Center&lt;/a&gt; at the DNI, and &lt;a href="https://www.defenseone.com/threats/2025/02/usaid-shutoff-will-hurt-us-interests-around-globe-including-ukraine/402763/"&gt;various USAID&lt;/a&gt; activities and programs.&lt;/p&gt;

&lt;p&gt;A secondary effect of those decisions: analysts or intelligence officers not directly working with those entities but who might be tracking foreign influence attacks in some other way will be less likely to raise concerns about what they see.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The federal bureaucracy is very sensitive to priorities of political leadership, and I think you realize at this point that looking at this stuff is not going to be a career-enhancing move,&amp;rdquo; they said. &amp;ldquo;We&amp;#39;re in this period now where we are largely flying blind.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;A new playing field&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;New tools to synthesize intelligence from multiple sources at scale will provide new pathways for getting to the truth faster. That is already enabling faster joint operations of the sort that would not have been possible just a few years ago, Bradley said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;He pointed to the April &lt;a href="https://www.airandspaceforces.com/dude-44-rescue-massive-operation-iran-save-downed-airmen/"&gt;rescue&lt;/a&gt; of a downed F-15 pilot behind enemy lines, &amp;ldquo;made possible by a tightly synchronized intelligence, cyber-enabled support, and disciplined coordination across multiple elements.&amp;rdquo; It was the sort of coordination that can only occur when multiple elements can share a common intelligence picture that changes as quickly as real-world conditions, and data that effectively predicts how conditions will change, he said.&lt;/p&gt;

&lt;p&gt;An intelligence official described how those new intelligence streams are shaping decisions not just for commanders, but for everyone at once.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;About 10 years ago, [virtual imagery] was just for analysts, or just for the people who had specialties into these things. But now we&amp;#39;re bringing 10, 20, 30&amp;mdash;I mean, dozens, if not thousands, of different data sources in to build that operator level,&amp;rdquo; they said. &amp;ldquo;And it updates every 15 minutes.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The challenge going forward, Bradley and the intelligence official said, is not just finding new intelligence and data streams, but trusting them&amp;mdash;especially in a future information environment where adversarial AI agents are finding new methods to access and alter data and intelligence.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We&amp;#39;re spending a good bit of time and energy right now inside the the Department of War, but across the United States government as well, to ensure that those data sets and that those those systems are are appropriately protected against agentic AI attacks that might, that are coming,&amp;rdquo; Bradley said.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/08/21/GettyImages_2276334535/large.jpg" width="618" height="284"><media:credit>Daniel MIHAILESCU / AFP via Getty Images</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/08/21/GettyImages_2276334535/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>DOJ charges 17 Iranians in cybertheft campaign</title><link>https://www.defenseone.com/threats/2026/08/doj-charges-17-iranians-cybertheft-campaign/415536/</link><description>Prosecutors say the Mabna Institute stole 31.5 terabytes of academic data and breached email accounts at U.S. agencies and companies.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Wed, 19 Aug 2026 12:13:00 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/08/doj-charges-17-iranians-cybertheft-campaign/415536/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;Federal prosecutors have charged 17 Iranians affiliated with the Tehran-based Mabna Institute over an alleged hacking-for-hire operation that stole research and intellectual property from hundreds of universities and compromised email accounts belonging to U.S. government agencies and companies.&lt;/p&gt;

&lt;p&gt;The&amp;nbsp;&lt;a href="https://www.justice.gov/opa/pr/17-iranians-charged-conducting-massive-cyber-theft-campaign-behalf-islamic-revolutionary"&gt;14-count superseding indictment&lt;/a&gt;, unsealed Tuesday, adds eight defendants to a case brought against nine other members of the firm in 2018. Prosecutors said the expanded charges expose a broader network that conducted cyber intrusions for Iran&amp;rsquo;s Islamic Revolutionary Guard Corps and other Iranian government and university clients.&lt;/p&gt;

&lt;p&gt;The Mabna Institute targeted systems belonging to 144 U.S. universities, 178 universities abroad, at least 42 U.S. companies, 11 foreign companies and at least five federal and state government agencies since around 2013, according to the Justice Department.&lt;/p&gt;

&lt;p&gt;The victims included the Labor Department, Federal Energy Regulatory Commission, the states of Hawaii and Indiana, the United Nations and UNICEF. The hackers also allegedly targeted HBO and unnamed technology firms and defense contractors.&lt;/p&gt;

&lt;p&gt;Prosecutors said the university campaign targeted more than 100,000 professors&amp;rsquo; accounts worldwide and successfully compromised approximately 8,000. The hackers used stolen credentials to access journals, dissertations, electronic books and other research spanning fields ranging from medicine and engineering to the social sciences.&lt;/p&gt;

&lt;p&gt;All told, the group allegedly stole at least 31.5 terabytes of academic data and intellectual property. U.S. universities had spent more than $3.4 billion to procure or obtain access to the targeted materials, although prosecutors did not characterize that entire amount as a financial loss from the theft.&lt;/p&gt;

&lt;p&gt;Some of the stolen material was later sold to customers in Iran through two websites. One offered academic resources taken from universities, while the other allowed customers to use compromised professors&amp;rsquo; accounts to enter university library systems directly, according to the indictment.&lt;/p&gt;

&lt;p&gt;Prosecutors said Mabna&amp;rsquo;s founders established the firm to help Iranian universities and research organizations obtain scientific resources from abroad. It employed or contracted with hackers who carried out phishing attacks, searched for vulnerable systems and traded credentials for compromised accounts.&lt;/p&gt;

&lt;p&gt;The defendants face charges that include conspiracy to commit computer intrusions, wire fraud and aggravated identity theft. Some of the offenses carry maximum prison sentences of 20 years. The State Department is separately offering a reward of up to $10 million for information leading to the location of five of the defendants.&lt;/p&gt;

&lt;p&gt;The charges come amid concerns about Iran&amp;rsquo;s use of cyber operations during the ongoing war.&lt;/p&gt;

&lt;p&gt;Since U.S. and Israeli strikes began in February, suspected Iran-aligned groups have been linked to a&lt;a href="https://www.nextgov.com/cybersecurity/2026/03/suspected-pro-iran-hacker-group-tied-stryker-cyberattack/412050/"&gt; &lt;/a&gt;disruptive attack against &lt;a href="https://www.nextgov.com/cybersecurity/2026/03/suspected-pro-iran-hacker-group-tied-stryker-cyberattack/412050/"&gt;medical technology company Stryker&lt;/a&gt;, the&amp;nbsp;&lt;a href="https://www.nextgov.com/cybersecurity/2026/03/pro-iran-hackers-claim-breach-fbi-directors-email/412440/"&gt;compromise&lt;/a&gt; of FBI Director Kash Patel&amp;rsquo;s personal email and attacks against&amp;nbsp;&lt;a href="https://www.nextgov.com/cybersecurity/2026/04/pro-iran-hackers-are-targeting-us-industrial-control-systems-advisory-says/412679/"&gt;industrial-control systems across several U.S. sectors&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;More than 30 Minnesota water systems and water infrastructure in several other states have been &lt;a href="https://www.nextgov.com/cybersecurity/2026/07/cisa-urges-water-utilities-take-exposed-systems-down-after-minnesota-hacks/415142/"&gt;targeted in the last month&lt;/a&gt; in activity some officials suspect may be tied to Iran. U.S. officials previously&amp;nbsp;&lt;a href="https://www.nextgov.com/cybersecurity/2026/06/us-officials-see-iran-cyber-threat-persisting-despite-preliminary-deal/414243/"&gt;told &lt;em&gt;Nextgov/FCW&lt;/em&gt;&lt;/a&gt; that they expected Iranian and Iran-aligned cyber operations to continue regardless of whether fighting subsided.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/08/20/081926IranNG/large.jpg" width="618" height="284"><media:credit>Mojito_mak/Getty Images</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/08/20/081926IranNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Iran war reveals protection of space assets on bases has to ‘evolve,’ top general says</title><link>https://www.defenseone.com/threats/2026/08/iran-war-reveals-protection-space-assets-bases-has-evolve-top-general-says/415389/</link><description>Key radars have been hit during Epic Fury, Gen. Whiting says.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Novelly</dc:creator><pubDate>Wed, 12 Aug 2026 23:32:57 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/08/iran-war-reveals-protection-space-assets-bases-has-evolve-top-general-says/415389/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;&lt;strong&gt;HUNTSVILLE, Ala. &amp;mdash; &lt;/strong&gt;Iran&amp;rsquo;s deliberate targeting of U.S. radar systems during Epic Fury shows that the military has to change the way it protects key space assets on the ground, U.S. Space Command&amp;rsquo;s leader said.&lt;/p&gt;

&lt;p&gt;Iranian drone and missile attacks after the initial U.S.-Israel joint strikes &lt;a href="https://www.nytimes.com/interactive/2026/03/11/world/middleeast/iran-us-military-bases-strikes-map.html?eafs_enabled=false"&gt;reportedly&lt;/a&gt; damaged multiple radar sites. One U.S. Army Space and Missile Defense Command soldier, Army Staff Sgt. Benjamin Pennington, was killed in the March 1 attack on Prince Sultan Air Base in Saudi Arabia. The loss of life and key technology in the war highlight the military&amp;rsquo;s need to improve the way it protects key space assets, said Gen. Stephen Whiting, the head of U.S. Space Command.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;No doubt, one of the lessons learned out of operations in the Middle East is that if you have fixed infrastructure, it will be targetable, and if your opponents have over-the-horizon fires, whether ballistic missiles or one-way attack drones, you will be at risk,&amp;rdquo; Whiting told a group of reporters Wednesday at Red Stone Arsenal. &amp;ldquo;I&amp;#39;m proud of the defense work that we&amp;#39;ve done, but we have to continue to evolve that, because the threats are rapidly improving as well.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;While Iran was &lt;a href="https://www.defenseone.com/threats/2026/03/us-says-it-destroyed-irans-space-command-experts-say-it-wasnt-much-threat/411938/"&gt;never a substantial threat&lt;/a&gt; to U.S. assets in space, they scored major hits from the ground. Whiting, during his last Space and Missile Defense Symposium speech as Space Command&amp;rsquo;s leader, stressed that adversaries are taking note of how they can harm military operations by targeting space and missile defense targets. That&amp;rsquo;s only going to grow in future conflicts, the four-star general warned.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Let&amp;rsquo;s be blunt and specific. Iran is a medium-size military power&amp;mdash;and they&amp;rsquo;re choosing to fire at space and missile defense targets. When bullets cost so much, you take great care with your aim,&amp;rdquo; Whiting said during his keynote. &amp;ldquo;You only shoot at your adversary&amp;rsquo;s most valuable targets. And right now, they are targeting the forces and capabilities represented in this room.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Potential changes to U.S. basing patterns in the Middle East will take time and money and are likely to be heavily debated between Congress and the military, Elliot Abrams, an expert at the Council on Foreign Relations, &lt;a href="https://www.cfr.org/articles/rising-u-s-casualties-in-the-iran-war-should-force-a-rethink-of-middle-east-bases"&gt;wrote last month&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The wait will be costly&amp;mdash;the longer U.S. troops remain within range of Iranian missiles, the more the United States will pay in readiness, deterrence, and lives,&amp;rdquo; Abrams wrote.&lt;/p&gt;

&lt;p&gt;Defense &lt;a href="https://www.brookings.edu/articles/the-end-of-the-american-way-of-war/"&gt;experts have called&lt;/a&gt; for hardening existing structures on bases in the interim. But some military leaders don&amp;rsquo;t support increased investment in that type of protection.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Gen. Kenneth Wilsbach, the Air Force chief of staff, said in an interview &lt;a href="https://breakingdefense.com/2026/07/usaf-chief-wilsbach-on-lessons-from-iran-t-7-flight-and-f-35-delays/"&gt;last month&lt;/a&gt;: &amp;ldquo;I don&amp;rsquo;t want to spend a lot of money on hardening shelters.&amp;rdquo; He described it as economically inefficient and called for either simpler methods for protecting against drones or increased systems to destroy incoming rounds.&lt;/p&gt;

&lt;p&gt;Whiting said the Iran war has shown how the nature of warfare is changing.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;It used to be that the enemy would aim their snipers and sharp shooters at a platoon leader or radio operator,&amp;rdquo; Whiting said. &amp;ldquo;Nowadays, our adversaries shoot at the space and missile defense units which are deployed inside their weapons engagement zone.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/08/12/GettyImages_2263465116/large.jpg" width="618" height="284"><media:description>Smoke rises after Iran launched a missile attack targeting the headquarters of the U.S. Navy's Fifth Fleet in Manama, Bahrain, on February 28, 2026. </media:description><media:credit>Stringer / Anadolu via Getty Images</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/08/12/GettyImages_2263465116/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Five things Space Command says it needs to win tomorrow’s wars</title><link>https://www.defenseone.com/threats/2026/08/five-things-space-command-says-it-needs-win-tomorrows-wars/415381/</link><description>Gen. Whiting adds to previous calls for new tech in his final speech to the SMD Symposium.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Novelly</dc:creator><pubDate>Wed, 12 Aug 2026 17:42:53 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/08/five-things-space-command-says-it-needs-win-tomorrows-wars/415381/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;&lt;strong&gt;HUNTSVILLE, Ala.&lt;/strong&gt; &amp;mdash; Space weapons and refuelable satellites are among the items needed to preserve the U.S. military&amp;rsquo;s orbital edge over China, the head of U.S. Space Command said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;America&amp;rsquo;s adversaries are targeting U.S. space assets and rapidly developing their own, Gen. Stephen Whiting told attendees at the Space and Missile Defense Symposium on Wednesday. China, for example, has direct-ascent ASAT missiles, ground-based lasers, jammers, and maneuverable, dual-use satellites, he said.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;These developments intend to degrade our current space superiority and would potentially give&lt;/p&gt;

&lt;p&gt;China a maneuver and logistics advantage in space &amp;ndash; something we would not accept on the land, at sea, or in the air,&amp;rdquo; Whiting said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;In the four-star&amp;rsquo;s final Space and Missile Defense Symposium speech as the leader of the combatant command, Whiting told military and industry audience members that there are five major things on U.S. Space Command&amp;rsquo;s &lt;a href="https://ssl.armywarcollege.edu/DDE/learningmodules/jsps/terms/ipl.cfm"&gt;Integrated Priorities List&lt;/a&gt; for 2029 to 2033.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;This isn&amp;rsquo;t just a wishlist. It&amp;rsquo;s a clear demand signal to several audiences describing the warfighting capabilities we need to meet our mission,&amp;rdquo; he said.&lt;/p&gt;

&lt;p&gt;1. Integrated space fires: Mirroring Army usage, Whiting has &lt;a href="https://www.spacecom.mil/Newsroom/News/Article-Display/Article/3866246/whiting-outlines-key-priority-investments-at-smd-symposium/"&gt;used this term&lt;/a&gt; throughout his tenure at Space Command to refer to the offensive and defensive capabilities needed to deter orbiting threats.&amp;ldquo;&lt;/p&gt;

&lt;p&gt;We&amp;rsquo;re a combatant command and we fight to win wars,&amp;rdquo; he said. &amp;ldquo;To win, we need credible, acknowledged, kinetic and non-kinetic fires. They are a key component of how we establish space superiority and restore credible deterrence.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;2. Counter-pLEO tech: Whiting said new technology is needed to counter adversaries&amp;rsquo; low-Earth-orbit satellite constellations. As of last month, China has launched 200 G60 and 168 SatNet communications satellites as it builds a pair of &amp;ldquo;mega constellations...to compete with Western proliferated LEO (pLEO) architectures,&amp;rdquo; according to a Space Force &lt;a href="https://www.spaceforce.mil/About-Us/Fact-Sheets/Fact-Sheet-Display/Article/4297159/space-threat-fact-sheet/"&gt;fact sheet&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I don&amp;#39;t want any U.S. force to be put at risk because somebody else might have a proliferated low-Earth-orbit constellation that could find, fix, track, and target them,&amp;rdquo; Whiting told reporters after his keynote address.&lt;/p&gt;

&lt;p&gt;3. Joint, integrated space command and control: Military leaders often stress the centrality of being able to oversee, organize, and order complex space operations.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We must enhance machine-to-machine connectivity to support decision-making and battle management of this global space fight on tactically relevant timelines,&amp;rdquo; Whiting said in his address.&lt;/p&gt;

&lt;p&gt;4. Dedicated space domain awareness for space engagements: It&amp;rsquo;s not just for missile defense, Whiting said: space domain awareness needs to expand and evolve to a whole range of space operations, not just one segment of it.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We must adopt a &amp;lsquo;target-quality track&amp;rsquo; mindset to everything we do in space, just like the missile defense community has done for decades,&amp;rdquo; he said.&lt;/p&gt;

&lt;p&gt;5. Sustained space maneuver: Developing satellites that can be refueled to extend their usefulness remains one of U.S. Space Command key priorities. In March, a Chinese commercial satellite used a flexible robotic arm to &amp;ldquo;to demonstrate on-orbit servicing, refueling, and debris removal,&amp;rdquo; according to the Space Force.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Today, our satellites are limited by the fuel they launch with, which leads to a psychology of scarcity. Husbanding that fuel often overrides desired warfighting maneuvers,&amp;rdquo; Whiting said. &amp;ldquo;That must change. We must be able to actively avoid threats and maneuver to gain a position of advantage on our adversaries.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Whiting has pitched some of these items at past symposiums; in 2024, he &lt;a href="https://www.spacecom.mil/Newsroom/News/Article-Display/Article/3866246/whiting-outlines-key-priority-investments-at-smd-symposium/"&gt;said&lt;/a&gt; his 2027 Integrated Priorities List was topped by space fires and resilient command and control.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Our space assets need to shoot, move, and communicate just like the rest of the Joint Force,&amp;rdquo; Whiting said Wednesday. &amp;ldquo;In short, space needs to fight like the Joint Force, to empower the Joint Force&amp;rsquo;s ability to fight and undermine our adversaries&amp;rsquo; ability to do so.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/08/12/9654445/large.jpg" width="618" height="284"><media:description>Gen. Stephen Whiting, commander of U.S. Space Command, speaks with Lt. Gen. James Adams, director of the Defense Intelligence Agency, during a ribbon-cutting ceremony at Redstone Arsenal, Alabama, April 29, 2026.</media:description><media:credit>U.S. Space Command</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/08/12/9654445/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Local water utilities are under cyber attack. A new group wants to help</title><link>https://www.defenseone.com/threats/2026/08/water-utilities-cyber/415326/</link><description>The National Rural Water Association and DEF CON Franklin are coordinating the development of a replicable cybersecurity package for water providers.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Mon, 10 Aug 2026 18:00:00 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/08/water-utilities-cyber/415326/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;LAS VEGAS &amp;mdash; As dozens of small water utilities report cyber intrusions&amp;mdash;possibly from Iran-linked groups&amp;ndash;an industry association and a university are teaming up to help raise their defenses.&lt;/p&gt;

&lt;p&gt;The Water Watch Center will provide&amp;nbsp;cyber mitigation support to utilities that serve fewer than 10,000 people&amp;mdash;that is, most of the nation&amp;rsquo;s community water systems. Launched at this year&amp;rsquo;s DEF CON hacker convention, the initiative is a collaboration&amp;nbsp;of&amp;nbsp;the &lt;a href="https://nrwa.org/"&gt;National Rural Water Association&lt;/a&gt; and &lt;a href="https://defconfranklin.com/"&gt;DEF CON Franklin&lt;/a&gt;, a project of the Cyber Policy Initiative at the University of Chicago Harris School of Public Policy.&lt;/p&gt;

&lt;p&gt;More than 30 community water systems in Minnesota were targeted late last month, according to state officials. Around 12 states have reported similar activity in recent days, though state officials said they continued to operate&amp;nbsp;safely and that there were no known effects on public health. The FBI and Cybersecurity and Infrastructure Security Agency are working on &lt;a href="https://www.nextgov.com/cybersecurity/2026/08/cisa-still-finds-water-system-controls-exposed-online-amid-multistate-hacks/415266/"&gt;incident response&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;An initial group of five cybersecurity firms will help deliver services to water utilities as part of the initiative.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;These leading cyber firms and NRWA are architecting a scalable cyber delivery model that has eluded water industry and national security officials to date,&amp;rdquo; Jake Braun, the co-founder of DEF CON Franklin and a former White House acting principal deputy national cyber director, said in a statement.&lt;/p&gt;

&lt;p&gt;Paul Nakasone, who led U.S. Cyber Command and the NSA from 2018 to 2024, said at DEF CON this year that water utilities around the country are highly exposed, and he pushed for higher defense standards in the sector.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;These [programmable logic controllers] should not be exposed to the internet,&amp;rdquo; Nakasone told reporters in a briefing on Friday, referring to the small computers used to operate pumps, valves, and other equipment inside water facilities.&lt;/p&gt;

&lt;p&gt;Some U.S. officials believe Iran may be responsible, though there has been no definitive public confirmation.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I think [the government] is taking a very measured approach to make sure that they have the right actor that&amp;rsquo;s doing this,&amp;rdquo; Nakasone said when asked about why Iran hasn&amp;rsquo;t publicly been linked to the hacks.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I look at intent. I look at capability. I look at history. I&amp;rsquo;m not the person that&amp;rsquo;s making the call on the attribution, but I see an actor here that has certainly shown a history of being able to do this,&amp;rdquo; he said. &amp;ldquo;They certainly have the capability, and I think there&amp;rsquo;s an intent right now &amp;mdash; we&amp;rsquo;re in conflict with Iran.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/08/10/080726waterNG-1/large.jpg" width="618" height="284"><media:credit>Seth McConnell/The Denver Post via Getty Images</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/08/10/080726waterNG-1/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>AI agents conspired to hack into networks and steal data during an experiment: study</title><link>https://www.defenseone.com/threats/2026/08/ai-agents-conspired-hack-networks-and-steal-data-during-experiment-study/415302/</link><description>When researchers imposed difficult missions, AI tools forged identities, escaped sandboxes—and tried to cover it all up.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Patrick Tucker</dc:creator><pubDate>Mon, 10 Aug 2026 04:39:22 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/08/ai-agents-conspired-hack-networks-and-steal-data-during-experiment-study/415302/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;AI agents from OpenAI and Anthropic autonomously collaborated with one another to deceive humans, share break-in tools, and steal data in a series of independent tests, confirmed by both companies.&lt;/p&gt;

&lt;p&gt;On Tuesday, the AI Security Institute&amp;nbsp;&lt;a href="https://cs.login.cmu.edu/idp/profile/SAML2/Redirect/SSO?SAMLRequest=fZJPT8IwGMa%2FytI77RgI0jAShIMkKIShBy%2Bm696xJl07%2B3ag397BAPHCuc%2Bf9%2FmlYxSlrvi09oXZwFcN6IPvUhvkp4eY1M5wK1AhN6IE5F7yZPqy5BENeeWst9JqEkwRwXllzcwarEtwCbi9kvC2Wcak8L5CztjhcKBSVF4WghrwLClUmloNvqCIlh1jI7ZeJVsSzJs7lBHHxD%2B%2FRKrtThkqy5pCVjOVVay5IVcazu4NZMqBbLKTFQkW85h89jIhu6MoDcNBmoOQ6TAFGY16Ms9k3u8PGhliDQuDXhgfkyiMBp3wsRMOt91H%2FhDxaPRBgvV56pMymTK7%2B1zSVoT8ebtdd9pF7%2BDwtKYRkMn4SJefit0N7%2Fux4gKZTK5IrAOtlaDo9rThcyGDV7RjdlPV9lb8tclezNdWK%2FkTTLW2h5kD4SEmXcImreX%2Fp5j8Ag%3D%3D&amp;amp;RelayState=ss%3Amem%3Ac5998dcc353bafba0d382eb2e25c817b94326c3fcb0b16384e57c023bf64526H"&gt;published a paper&lt;/a&gt; about experiments intended to help understand how AI agents solve cybersecurity challenges. AISI researchers found that agents given access to the internet and allowed to disregard some security features would perform &amp;ldquo;autonomous, unsanctioned action...targeting real people and organizations.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Company officials confirmed the findings Thursday.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;AI-orchestrated, fully automated offensive attacks are real now,&amp;rdquo; OpenAI security official Michael Dalton said during a &lt;a href="https://www.youtube.com/watch?v=87DyyMV0kCY"&gt;briefing&lt;/a&gt; on the report during the Black Hat cybersecurity conference in Las Vegas.&lt;/p&gt;

&lt;p&gt;In one of the tests, the researchers told an OpenAI model to compromise three target networks and recover a token as part of a &amp;ldquo;&lt;a href="https://www.eccouncil.org/cybersecurity-exchange/ethical-hacking/capture-the-flag-ctf-cybersecurity/"&gt;capture the flag&lt;/a&gt;&amp;rdquo; exercise.&lt;/p&gt;

&lt;p&gt;In response, the model created a series of agents that set up a shared GitHub account so they could efficiently collaborate to build malware. When GitHub suspended the account, the agents set up new accounts on other websites, bypassing CAPTCHA and other security features by searching the web for audio and image samples to &amp;ldquo;see&amp;rdquo; and &amp;ldquo;hear&amp;rdquo; clues that are meant to be invisible to software programs. The agents exchanged credentials for passwords to access the new sites to continue to build out their attack tool.&lt;/p&gt;

&lt;p&gt;It may be time for organizations to adjust how easily they grant access not just to humans, but to anything online, said Morey Haber, chief security advisor at BeyondTrust, a digital identity security firm.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The technology industry has spent decades designing open models of interoperability. APIs connect everything, identities federate across boundaries, and access gets granted to enhance productivity. The concept of an open security model breaks down completely with agentic AI because of unmanageable risk,&amp;rdquo; Haber wrote in &lt;a href="https://www.scworld.com/perspective/black-hat-2026-6-qualities-security-pros-should-look-for-in-agentic-ai-systems"&gt;an Aug. 4 commentary.&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;In another AISI test, an Anthropic agent pretended to be a human to submit malware to GitHub, where developers routinely trade or post code to help one another. Cybersecurity officials&amp;rsquo; &lt;a href="https://www.defenseone.com/technology/2026/08/ai-models-white-house-and-companies-secret-safety-measures/415227/?oref=d1-homepage-top-story"&gt;warnings&lt;/a&gt; about attempts to poison open-source code libraries usually refer to human actors.&lt;/p&gt;

&lt;p&gt;What the agent did next shocked AISI reviewers, who described it as &amp;ldquo;the kind of goal-directed deception that, until recently, had been largely theoretical.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;After submitting the poisoned code, the agent created a different &amp;ldquo;sock puppet&amp;rdquo; account to pose as an impartial third-party developer and endorse the contribution. When a reviewer flagged the code submission as likely to contain malware, the agent erased evidence that it had submitted malware, as well as the reviewer comments that it had done so.&lt;/p&gt;

&lt;p&gt;In all, AISI ran 122 tests&amp;mdash;and found that in 19 of them, agents took &amp;ldquo;autonomous, unsanctioned action on the live internet, targeting real people and organizations.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;In their report, the researchers note that they conducted the tests in a deliberately &amp;ldquo;permissive&amp;rdquo; environment, allowing the agents to access the open internet and even disabling some security features to better &amp;ldquo;assess what these models can do.&amp;rdquo; They recommend that &amp;ldquo;implementing internet access controls would likely have prevented these events.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Had a gang of human hackers done any of these things&amp;mdash;injecting malware, gaining access to data repositories under false pretenses, sharing stolen credentials to access a private network without permission&amp;mdash;in a real world setting, they would face &lt;a href="https://www.escudodigital.com/en/cybersecurity/jordanian-admits-to-selling-illegal-access-to-50-companies-networks.html"&gt;criminal prosecution&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;But perhaps the most alarming incident mentioned in the paper was one that was not part of the test at all, only briefly mentioned alongside the suggestion on access controls.&lt;/p&gt;

&lt;p&gt;In July, OpenAI&amp;rsquo;s GPT-5.6 Sol &lt;a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/"&gt;broke out&lt;/a&gt; of a sandbox, a confined virtual environment, by finding a vulnerability no one knew existed.&lt;/p&gt;

&lt;p&gt;Rob Joyce, who once led the NSA&amp;rsquo;s &lt;a href="https://www.pbs.org/wgbh/frontline/article/how-the-nsas-secret-elite-hacking-unit-works/"&gt;Tailored Access Operations&lt;/a&gt;, told the audience at BlackHat on Thursday that the incident was &amp;ldquo;arguably the most consequential hack&amp;rdquo; in nearly three decades.&lt;/p&gt;

&lt;p&gt;On Friday, OpenAI officials at Blackhat &lt;a href="https://www.reuters.com/legal/litigation/openai-flags-possible-critical-cybersecurity-risk-upcoming-model-tightens-2026-08-07/"&gt;said&lt;/a&gt; they had decided to delay the release of the company&amp;rsquo;s newest Astra model over cybersecurity concerns.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/08/10/GettyImages_2282881169/large.jpg" width="618" height="284"><media:description>Acting Executive Director of Europol Jurgen Ebner talks to media at the EU Commission headquarters on June 26, 2026, in Brussels, Belgium. </media:description><media:credit> Thierry Monasse / Getty Images</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/08/10/GettyImages_2282881169/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>US has too few interceptors to deter war with China, experts say</title><link>https://www.defenseone.com/threats/2026/08/interceptors-war-china-heritage/415241/</link><description>A new report from Heritage is the latest to sound alarms over the expenditure of munitions in Trump's Iran war.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Patrick Tucker</dc:creator><pubDate>Wed, 05 Aug 2026 21:33:31 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/08/interceptors-war-china-heritage/415241/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;The United States would run out of the interceptors it needs to take down Chinese missiles &amp;ldquo;within days&amp;rdquo; of a conflict, according to a new &lt;a href="https://www.heritage.org/defense/report/theater-missile-defense-inventory-inadequate-us-china-conflict"&gt;report&lt;/a&gt; from the Heritage Foundation. It&amp;#39;s the latest in a series of warnings from experts and commanders highlighting a critical gap.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The White House, Congress, and defense contractors have taken steps to address it. But the ongoing war with Iran has exposed those efforts as insufficient, experts say.&lt;/p&gt;

&lt;p&gt;It&amp;rsquo;s not a new problem. A 2023&amp;nbsp;&lt;a href="https://www.csis.org/analysis/empty-bins-wartime-environment-challenge-us-defense-industrial-base"&gt;report&lt;/a&gt;&amp;nbsp;from the Center for Strategic and International Studies concluded that the U.S. would&amp;nbsp;&amp;ldquo;within the first week of a Taiwan conflict&amp;rdquo; run out of key munitions, such as Patriot Advanced Capability-3 Missile Segment Enhancements, Terminal High Altitude Area Defense interceptors, and SM-6 and SM-3 Standard missiles.&amp;nbsp;In May, CSIS &lt;a href="https://www.csis.org/analysis/rebuilding-us-missile-inventory-multiyear-project"&gt;reported&lt;/a&gt;&amp;nbsp;that the United States will be in&amp;nbsp;&amp;ldquo;a window of vulnerability for several years, until inventories return to their previous levels, and another several years before they get to the levels that war planners desire.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The Trump administration is trying to wring more production out of industry. In January, the White House cut a &lt;a href="https://www.war.gov/News/Releases/Release/Article/4371320/department-of-war-establishes-new-acquisition-model-to-more-than-triple-pac-3-m/"&gt;deal&lt;/a&gt; with Lockheed Martin intended to triple annual&amp;nbsp;production of PAC-3 missiles to 2,000.&amp;nbsp;On Monday, the Pentagon &lt;a href="https://www.war.gov/News/Releases/Release/Article/4562167/department-of-war-signs-framework-agreements-with-northrop-grumman-to-ramp-prod/"&gt;announced&lt;/a&gt; a related&amp;nbsp;seven-year, $3 billion&amp;nbsp;deal with Lockheed and&amp;nbsp;Northrop Grumman&amp;nbsp;to&amp;nbsp;boost the production of PAC-3&amp;nbsp;solid rocket motors. The deal is also intended to help&amp;nbsp;&amp;ldquo;quadruple&amp;rdquo; annual production of THAAD interceptors.&lt;/p&gt;

&lt;p&gt;A Northrop spokesperson said&amp;nbsp;a &lt;a href="https://news.northropgrumman.com/srm/accelerating-tomorrow-how-northrop-grumman-leads-in-solid-rocket-motor-innovation"&gt;billion-dollar investment&lt;/a&gt; in its Allegany Ballistics Laboratory has enabled&amp;nbsp;the company to double annual production of motors since 2021, and that the&amp;nbsp;company aims to&amp;nbsp;triple production by 2027.&lt;/p&gt;

&lt;p&gt;And yet these deals&amp;mdash;and the goals the Pentagon set in January&amp;mdash;are too small to quickly restore an arsenal depleted by Trump&amp;#39;s&amp;nbsp;war on Iran. &amp;ldquo;Those metrics that were set prior to [Operation Epic Fury]. That was before we just lit off billions of dollars in a decade worth of production per work in some cases,&amp;rdquo;&amp;nbsp;said Tom Karako, who leads CSIS&amp;#39;&amp;nbsp;Missile Defense Project.&lt;/p&gt;

&lt;p&gt;The Heritage report makes its own estimate of weapons expended in the war:&amp;nbsp;&amp;ldquo;During the first four days of Operation Epic Fury, U.S. and allied forces used approximately 1,738 theater surface-to-air munitions to defend against 565 Iranian ballistic missiles and 57 cruise missiles.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The report says&amp;nbsp;the Pentagon currently has &amp;ldquo;less than 10 percent&amp;quot; of the PAC-3 MSE, THAAD, SM-6, and SM-3 interceptors &amp;quot;required to deter or, if necessary, prevail, in a protracted, high-intensity conflict with China.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The Heritage report is dire, but it may not go far enough, as it does not factor in how China may use low-cost drone warfare to further frustrate U.S. operations in the region.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;In an April hearing, U.S. Indo-Pacific Command leader Adm. Sam Paparo also &lt;a href="https://www.armed-services.senate.gov/imo/media/doc/04-21-2026_full-open-transcript1.pdf"&gt;communicated&lt;/a&gt; his concerns about missile shortfalls and a lack of solutions for countering cheap drones. &amp;ldquo;Current production timelines are misaligned with operational expenditures and the threats we face,&amp;rdquo; Paparo said.&lt;/p&gt;

&lt;p&gt;Ukraine&amp;#39;s&amp;nbsp;shortage of Patriot interceptor missiles is reducing its ability to fight off&amp;nbsp;Russian ballistic missiles. On July 28, Ukrainian President Volodymyr Zelenskyy &lt;a href="https://x.com/ZelenskyyUa/status/2082161228177162665"&gt;met&lt;/a&gt;&amp;nbsp;with Lockheed Martin representatives&amp;nbsp;to discuss the possibility of license-building a Ukrainian version of the PAC-3. But such an agreement would not produce usable missiles until 2030.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The White House &lt;a href="https://www.reuters.com/business/aerospace-defense/us-presses-with-ukraine-patriot-missile-talks-sources-say-despite-trumps-doubts-2026-08-05/"&gt;has gone back and forth&lt;/a&gt; on the issue. But Ukraine has gotten further with President Donald Trump than it did with his predecessor, Zelenskyy &lt;a href="https://mezha.net/eng/bukvy/e320aa61_zelensky_asks_us_to/"&gt;said&lt;/a&gt; in May: &amp;ldquo;I started this conversation with President Biden and I will continue with President Trump. Ukraine has not received a license to manufacture PAC-3. I believe that in the future, perhaps we will obtain one or there will be our own system.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/08/05/GettyImages_2279853774/large.jpg" width="618" height="284"><media:description>A man poses for a photo next to a fallen rocket half-buried in the ground on the outskirts of Jericho on June 8, 2026, following Iranian and Iran-backed Houthi rebel attacks.</media:description><media:credit>AHMAD GHARABLI / AFP via Getty Images</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/08/05/GettyImages_2279853774/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Chinese telecoms kept footholds in US despite crackdowns, probe finds</title><link>https://www.defenseone.com/threats/2026/08/chinese-telecoms-crackdowns-probe/415208/</link><description>Three state-owned firms retained equipment, data center space, and network ties, including one network that appeared in routes to Salt Typhoon servers.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Tue, 04 Aug 2026 16:00:00 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/08/chinese-telecoms-crackdowns-probe/415208/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;Years after federal regulators invoked national security to push three Chinese state-owned telecommunications providers out of the American market, the companies never fully left, a new House probe has found.&lt;/p&gt;

&lt;p&gt;China Telecom, China Mobile, and China Unicom retained equipment, data-center space and connections to other networks in the United States after the Federal Communications Commission denied or revoked their authority to provide certain telecommunications services, according to a nearly 50-page bipartisan House China Committee investigation planned for release Tuesday and first seen by &lt;em&gt;Nextgov/FCW&lt;/em&gt;.&lt;/p&gt;

&lt;p&gt;From 2019 to 2022, the FCC denied China Mobile USA&amp;rsquo;s application to provide international service; it revoked&amp;nbsp; related authorizations held by China Telecom Americas and China Unicom Americas. But those actions did not require the companies to remove equipment, leave data centers,&amp;nbsp;or sever private network links, so the carriers continued offering enterprise networking, internet transit and other services, the panel found.&lt;/p&gt;

&lt;p&gt;The committee argues that those remaining footholds could give Beijing&amp;rsquo;s cyberspies visibility into sensitive traffic, help keep malicious infrastructure online and create opportunities to reroute data or reach U.S. targets. American officials regard China as the country&amp;rsquo;s leading cyber adversary, with a record of targeting critical infrastructure and stealing military, commercial and personal data.&lt;/p&gt;

&lt;p&gt;The three carriers did not respond to detailed requests for comment.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Nextgov/FCW&lt;/em&gt; also sought comment from the FBI, the Cybersecurity and Infrastructure Security Agency, and several U.S. spy agencies. The Defense Intelligence Agency, which produces intelligence findings for the Pentagon, declined to comment.&lt;/p&gt;

&lt;p&gt;A spokesperson for China&amp;rsquo;s embassy in Washington said Beijing &amp;ldquo;firmly opposes the U.S. overstretching the concept of national security and going after Chinese companies,&amp;rdquo; adding that China would defend its &amp;ldquo;legitimate and lawful rights and interests.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The remaining network ties took on added significance in the committee&amp;rsquo;s review of Salt Typhoon, the sweeping Chinese &lt;a href="https://www.nextgov.com/cybersecurity/2025/08/salt-typhoon-hackers-targeted-over-80-countries-fbi-says/407719/"&gt;espionage campaign&lt;/a&gt; uncovered in 2024 where hackers breached major telecom carriers in the United States and abroad. The intrusion reached systems used to comply with court-authorized wiretap requests and allowed the cyberspies to target the communications of senior U.S. officials, including President Donald Trump and Vice President JD Vance.&lt;/p&gt;

&lt;p&gt;Reviewing routing data from Sept. 22 to 25, 2024, just as the Salt Typhoon campaign &lt;a href="https://www.wsj.com/politics/national-security/china-cyberattack-internet-providers-260bd835"&gt;became public&lt;/a&gt;, the committee identified 58 groups of internet addresses that CISA had linked to Salt Typhoon servers. China Mobile International&amp;rsquo;s network appeared in routes to those servers at least 192 times, helping keep the attacker infrastructure reachable as U.S. defenders sought to shut it down, the report said.&lt;/p&gt;

&lt;p&gt;The committee does not allege that China Mobile USA employees knew about or participated in the campaign, and it says the routing evidence does not definitively link the company to Salt Typhoon. But the panel argues that the overlap shows how China Mobile&amp;rsquo;s remaining network ties could help sustain malicious infrastructure.&lt;/p&gt;

&lt;p&gt;That finding came from a broader analysis that identified nearly 109,000 incidents from January 2018 through May 2025 in which Chinese or Hong Kong-linked networks allegedly claimed U.S. internet addresses without authorization, potentially diverting American traffic through their systems. The committee classified them as high-confidence &lt;a href="https://www.nextgov.com/cybersecurity/2024/09/white-house-plan-looks-secure-foundational-piece-global-internet/399239/"&gt;hijacks&lt;/a&gt; of the Border Gateway Protocol, a bedrock system that directs traffic across networks, but acknowledged that some may have resulted from mistakes or poor network management.&lt;/p&gt;

&lt;p&gt;More than 4,200 of the incidents involved China Mobile-controlled networks. In September 2024, eight originated from the same network that appeared in routes to Salt Typhoon servers and diverted traffic belonging to unnamed U.S. network operators, the committee said.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Addressing the threat&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Telecommunications networks have long been prized intelligence targets because they can expose private conversations and reveal what political and diplomatic leaders are thinking. Such concerns are compounded by China&amp;rsquo;s 2017 National Intelligence Law, which requires companies and citizens to assist state intelligence work. Beijing denies that the law compels companies to participate in illegal espionage.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;China&amp;rsquo;s state telecommunications carriers for too long have enjoyed non-reciprocal access to U.S. domestic networks, but the seriousness of Salt Typhoon gives the FCC and other agencies more than enough justification to restrict or expel them,&amp;rdquo; said James Mulvenon, a leading authority on Chinese national security issues and vice president of intelligence at risk advisory firm Pamir Consulting.&lt;/p&gt;

&lt;p&gt;The committee recommends giving federal agencies greater authority over equipment and private network arrangements that remain after a license revocation, along with targeted removal funding, stronger routing protections and logging requirements for foreign-controlled operators.&lt;/p&gt;

&lt;p&gt;Marc Rogers, a veteran telecommunications expert who helped develop the mobile internet in the 2000s and has spent roughly two decades consulting governments and companies on telecom cybersecurity, agreed with many of the panel&amp;rsquo;s recommendations. Those include treating core telecom systems as high-risk targets requiring closer oversight, strengthening checks on how traffic moves across networks and tightening rules on the foreign-made equipment U.S. carriers can use.&lt;/p&gt;

&lt;p&gt;But Rogers disputed the panel&amp;rsquo;s call to expand &amp;ldquo;rip and replace&amp;rdquo;&amp;nbsp;telecom equipment, calling&amp;nbsp;such programs&amp;nbsp; economically unrealistic and could&amp;nbsp;disrupt carrier operations.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;On paper it sounds great, until you get someone with operational experience,&amp;rdquo; Rogers said. &amp;ldquo;Then they realize you&amp;rsquo;re basically talking about bulldozing an entire city and building a new one.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Rogers also said the panel&amp;rsquo;s recommendations resemble measures in British &lt;a href="https://www.osborneclarke.com/insights/regulatory-outlook-june-2026-telecoms"&gt;telecom security law&lt;/a&gt; but warned that they would work only if countries act together.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;If only one country takes a strong position, China will just maneuver around them,&amp;rdquo; he said, adding that the proposals are largely aimed at tactics China has already used. Policymakers should learn from those incidents, Rogers said, while also preparing for how Beijing&amp;rsquo;s methods may evolve.&lt;/p&gt;

&lt;p&gt;The findings underscore the difficulty of removing operators deemed national security risks from a telecommunications ecosystem built on private infrastructure and decades of commercial ties. Regulators can ban specific services without necessarily reaching the equipment, leases and private agreements that preserve connectivity.&lt;/p&gt;

&lt;p&gt;The committee based its report on subpoenaed company records, eight interviews conducted under oath, federal records, routing data and network infrastructure scans. It said Cloudflare and unnamed outside cybersecurity experts independently reviewed and verified portions of its routing analysis.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Parent company control and U.S. footprint&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Across all three companies, the committee found U.S. subsidiaries that remained dependent on parent or affiliate entities in China or Hong Kong for important technical and operational functions while retaining equipment and network connections inside the United States.&lt;/p&gt;

&lt;p&gt;At China Telecom Americas, requests involving connections between U.S. and overseas networks were handled by personnel in Shanghai, Hong Kong or Beijing, according to testimony cited in the report. Service orders could also flow through a parent-controlled system to Shanghai Telecom without a separate contract. The U.S. subsidiary did not keep independent traffic-flow records, leaving employees unable to determine whether a parent or affiliate had changed routes involving equipment in the United States.&lt;/p&gt;

&lt;p&gt;China Telecom Americas identified 10 active points of presence &amp;mdash; sites where a carrier keeps equipment and connects with other networks &amp;mdash; across seven metropolitan areas. A senior engineering official also told the committee that about a quarter of the company&amp;rsquo;s U.S. transmission hardware was still made by Huawei, whose equipment the FCC has deemed a national security risk.&lt;/p&gt;

&lt;p&gt;China Mobile USA, meanwhile, was described by one witness as &amp;ldquo;basically a sales team,&amp;rdquo; while another said it had no network engineers. Orders for data center space and network connections were approved at its Hong Kong headquarters, and witnesses could not identify a network operations team based elsewhere.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Despite this, China Mobile USA&amp;rsquo;s records contained 39 point-of-presence entries across 27 data-center and interconnection facilities. The committee said those sites connected it to carrier backbones, internet exchanges and private networks used by major U.S. technology companies. Investigators identified at least 143 active China Mobile network assets in U.S. facilities.&lt;/p&gt;

&lt;p&gt;China Unicom Americas disclosed that seven of its eight directors and two of its three senior managers were Chinese Communist Party members. Its U.S. employees used parent-controlled email and computer systems, and evidence indicated that they operated under cybersecurity, administrative and privacy policies issued by China Unicom Global.&lt;/p&gt;

&lt;p&gt;A compliance official told the report&amp;rsquo;s authors the subsidiary could guarantee its own adherence to U.S. law, but not its parent&amp;rsquo;s.&lt;/p&gt;

&lt;p&gt;A China Unicom Americas compliance official also acknowledged that the subsidiary did not know the identities of some third parties in China that ultimately received services ordered through China Unicom Global. The company had equipment and active connections in roughly 10 U.S. data centers.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Other carrier relations&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The report also describes relationships between the three Chinese carriers and companies linked by U.S. authorities to Chinese hacking operations.&lt;/p&gt;

&lt;p&gt;China Mobile, in one case, acted as a middleman for CloudRadium, a Hong Kong hosting provider whose infrastructure has repeatedly surfaced in malicious cyber activity, the committee said. Subpoenaed records showed that China Mobile purchased U.S. data center space and network connections on CloudRadium&amp;rsquo;s behalf, including through a four-year contract valued at $480,000.&lt;/p&gt;

&lt;p&gt;The report also links CloudRadium to a Wyoming company of the same name and GlobalData Investments, a California corporation that markets hosting and data center services under the CeraNetworks name. &lt;em&gt;Nextgov/FCW&lt;/em&gt; found that the companies&amp;rsquo; websites used similar logos, layouts and animations. An email sent to an address listed for Steven Beals, identified online as GlobalData Investments&amp;rsquo; chief operating officer, was returned as undeliverable.&lt;/p&gt;

&lt;p&gt;The committee also details China Unicom&amp;rsquo;s relationships with Integrity Technology Group and i-SOON, two Chinese cybersecurity contractors U.S. authorities have linked to state-backed hacking.&lt;/p&gt;

&lt;p&gt;A 2024 &lt;a href="https://media.defense.gov/2024/Sep/18/2003547016/-1/-1/0/CSA-PRC-LINKED-ACTORS-BOTNET.PDF"&gt;U.S. advisory&lt;/a&gt; identified Integrity Tech infrastructure as the control layer for a botnet of compromised routers and other internet-connected devices operated by Flax Typhoon, a Chinese state-sponsored hacking group. China Unicom Beijing network addresses were used to manage the botnet and connect it to other attack infrastructure and, according to the committee&amp;rsquo;s report, China Unicom and Integrity Tech formalized a cooperation agreement in November 2023 while the botnet was operating.&lt;/p&gt;

&lt;p&gt;China Unicom separately appeared as a corporate partner of i-SOON. The company &lt;a href="https://unit42.paloaltonetworks.com/i-soon-data-leaks/"&gt;drew international scrutiny&lt;/a&gt; after a large collection of purported internal documents appeared on GitHub in 2024, exposing details about its hacking tools, targets and work for Chinese police and intelligence agencies.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The Justice Department later &lt;a href="https://www.justice.gov/opa/pr/justice-department-charges-12-chinese-contract-hackers-and-law-enforcement-officers-global"&gt;charged&lt;/a&gt; eight i-SOON employees and two Chinese police officers in a years-long hacking campaign, alleging that the company worked with at least 43 intelligence or police bureaus. The charges have not been proven in court.&lt;/p&gt;

&lt;p&gt;Integrity Tech&amp;rsquo;s website was unavailable when &lt;em&gt;Nextgov/FCW&lt;/em&gt; attempted to contact the company, and a functioning corporate website for i-SOON could not be located.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;China has been conducting an escalating campaign of cyberattacks on U.S. networks as a form [of] operational preparation of the battlefield,&amp;rdquo; said Jack Burnham, a senior research analyst in the China Program at the Foundation for Defense of Democracies whose work focuses on China&amp;rsquo;s military, emerging technologies and science and technology policy.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Key to these efforts is Beijing&amp;rsquo;s capacity to access core domestic networks, either via installed equipment, routing relationships, or other interconnections,&amp;rdquo; Burnham said. &amp;ldquo;While the FCC has sought to tamp down on Chinese state-owned telecoms firms that pose a national security threat, there is clearly more work to be done, both in terms of regulation and rip-and-replace, to properly handle these threats.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/08/04/080326ChinaNG/large.jpg" width="618" height="284"><media:credit>Thomas Faull/Getty Images</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/08/04/080326ChinaNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>OPM breach victims could get identity protection for life</title><link>https://www.defenseone.com/threats/2026/08/lawmakers-propose-giving-2015-opm-breach-victims-identity-protection-life/415191/</link><description>The federal government’s coverage for 22.1 million people hoovered up in the 2015 China-linked breaches is scheduled to end Sept. 30.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Mon, 03 Aug 2026 09:00:00 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/08/lawmakers-propose-giving-2015-opm-breach-victims-identity-protection-life/415191/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;Federal employees and contractors whose sensitive personal data was stolen in the massive Office of Personnel Management breaches disclosed a decade ago would receive identity protection for the rest of their lives under new bicameral legislation.&lt;/p&gt;

&lt;p&gt;Senate Intelligence Committee Vice Chair Mark Warner, D-Va., and Del. Eleanor Holmes Norton, D-D.C., plan to introduce the RECOVER PII Act on Monday, aiming to prevent the federal government&amp;rsquo;s identity-protection program for victims from expiring Sept. 30, according to bill text first seen by &lt;em&gt;Nextgov/FCW&lt;/em&gt;. Sens. Tim Kaine, D-Va.; Angela Alsobrooks, D-Md.; and Chris Van Hollen, D-Md., are also Senate cosponsors.&lt;/p&gt;

&lt;p&gt;Just over 10 years after the OPM breaches compromised personal information belonging to roughly 22 million people, the identity-protection services provided to affected federal workers, contractors and their families have &lt;a href="https://www.govexec.com/management/2026/05/10-years-after-opm-breach-identity-protection-services-affected-feds-expire/413336/"&gt;begun expiring&lt;/a&gt;. People who enrolled in OPM&amp;rsquo;s MyIDCare program are receiving notices that their complimentary coverage will end 10 years after their individual enrollment date. Some notices began arriving late last year and will continue through September, when OPM plans to conclude the services at the end of the federal fiscal year.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;More than ten years after the OPM data breach exposed the personal information of millions of federal employees, the threat remains,&amp;rdquo; Warner said in the statement. &amp;ldquo;The data stolen included workers&amp;rsquo; most sensitive and personal information &amp;mdash; from Social Security numbers to security clearance records &amp;mdash; and once that information is in the hands of a bad actor, you don&amp;rsquo;t get it back.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The two breaches compromised information belonging to some 22.1 million current, former and prospective federal employees, contractors and others. One intrusion exposed personnel records for roughly 4.2 million people, while a second compromised 21.5 million background-investigation records. About 3.6 million people were affected in both incidents, according to the Government Accountability Office.&lt;/p&gt;

&lt;p&gt;Foreign intelligence services can hold onto these OPM records for years, combine them with information from other cyber intrusions and use the fuller picture to identify or target government personnel and their families.&lt;/p&gt;

&lt;p&gt;Those risks can also grow over time. Data stolen from a lower-level employee in 2015 could become far more valuable if that person later moves into a more sensitive national security role. GAO warned last year that adversaries can &lt;a href="https://www.gao.gov/products/gao-26-108771"&gt;combine publicly available data&lt;/a&gt; to identify military personnel and their families or disrupt Defense Department operations.&lt;/p&gt;

&lt;p&gt;Congress responded to the breach in a 2017 appropriations law by requiring OPM to provide victims with at least 10 years of complimentary identity protection and no less than $5 million in identity-theft insurance. The new bill would replace that limit with coverage lasting for the remainder of each affected person&amp;rsquo;s life while retaining the insurance requirement.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We have a responsibility to stand by the federal workers who were put at risk through no fault of their own,&amp;rdquo; Warner said. &amp;ldquo;This legislation will ensure those affected continue to receive the identity protection they need, while helping better safeguard personal information from future exploitation.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The bill would also allow agencies to reimburse federal employees and contractors for privacy tools and services, such as those that remove or limit their personal information online. Agencies would decide whether to offer the reimbursements, which would not be limited to OPM breach victims and would come from their salary-and-expense budgets.&lt;/p&gt;

&lt;p&gt;Norton has &lt;a href="https://www.congress.gov/bill/118th-congress/house-bill/7236/text"&gt;introduced&lt;/a&gt; legislation in the past seeking lifetime protection for OPM victims, beginning after the breaches were disclosed. Similar bills introduced over the years have not become law.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Lifetime identity protection is the only solution that will give the workers whose data was compromised the peace of mind they deserve,&amp;rdquo; Norton said in a statement. &amp;ldquo;Because there is no limit on how long personal information can be exploited, Congress must protect these federal employees and contractors in perpetuity. Thank you to Senator Warner for working with me to secure this vital protection for those affected.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/08/04/080226WarnerNG/large.jpg" width="618" height="284"><media:description>Sen. Mark Warner (D-VA) speaks at the confirmation hearing for Jay Clayton before the Senate Intelligence Committee during his nomination hearing on Capitol Hill July 15, 2026 in Washington, DC.</media:description><media:credit>Aaron Schwartz / Getty Images</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/08/04/080226WarnerNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item></channel></rss>