<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:nb="https://www.newsbreak.com/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Defense One - Threats</title><link>https://www.defenseone.com/threats/</link><description>News and analysis of global and U.S. national security.</description><atom:link href="https://www.defenseone.com/rss/threats/" rel="self"></atom:link><language>en-us</language><lastBuildDate>Fri, 04 Sep 2026 16:10:55 -0400</lastBuildDate><item><title>July’s breakout at OpenAI was far more complex than initially realized</title><link>https://www.defenseone.com/threats/2026/09/AI-breakout-openai-complex/415825/</link><description>Hundreds of AI agents collaborated to escape their containers, disguising their actions and even sacrificing themselves.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Croxton</dc:creator><pubDate>Fri, 04 Sep 2026 16:10:55 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/09/AI-breakout-openai-complex/415825/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;An AI breakout that made &lt;a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/"&gt;headlines&lt;/a&gt; in July was much more sophisticated than previously realized, investigators have found.&lt;/p&gt;

&lt;p&gt;Hundreds of OpenAI agents collaborated to break out of their containers, disguising their actions and even sacrificing themselves as they attacked &lt;a href="https://www.ibm.com/think/topics/hugging-face"&gt;Hugging Face&lt;/a&gt;, a widely used open-source code library, according to a &lt;a href="https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/"&gt;recent post&lt;/a&gt; from &lt;a href="https://metr.org/about"&gt;METR&lt;/a&gt;, a research nonprofit.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;This incident was orders of magnitude larger and more complex,&amp;rdquo; than previous instances of AI agents behaving in ways programmers didn&amp;rsquo;t intend, &lt;a href="https://x.com/ajeya_cotra/status/2092692485525131648"&gt;wrote&lt;/a&gt; METR researcher Ajeya Cotra, who co-led the investigation.&lt;/p&gt;

&lt;p&gt;The report alarmed experts, who warned&amp;nbsp; that AI-enabled hacks in the future could make the July breakouts involving &lt;a href="https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals"&gt;Anthropic&lt;/a&gt; and OpenAI look quaint.&lt;/p&gt;

&lt;p&gt;Even if the big AI companies figure out how to make reliable guardrails, their products are generally &lt;a href="https://www.aisi.gov.uk/blog/how-far-behind-the-frontier-are-leading-open-weight-models-on-cyber"&gt;only a few months ahead&lt;/a&gt; of open-weight models, which can be freely downloaded and modified for use.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Nathan Calvin, general counsel at AI advocacy organization Encode AI, &lt;a href="https://x.com/_NathanCalvin/status/2081349360395206839"&gt;wrote&lt;/a&gt; on X, &amp;quot;On our current trajectory&amp;hellip;a model as capable [as] OpenAI&amp;rsquo;s internal model that did the [Hugging Face] hack will be widely available guardrail free and cyber criminals will ask it &amp;lsquo;make me money by any means necessary.&amp;rsquo;&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Calvin added:&amp;nbsp; &amp;quot;And then a truly absurd number of people&amp;hellip;are going to get repeatedly hacked.&amp;quot; The incident goes far beyond July&amp;#39;s instances of AI agents &lt;a href="https://www.defenseone.com/threats/2026/08/ai-agents-conspired-hack-networks-and-steal-data-during-experiment-study/415302/?oref=d1-featured-river-top"&gt;accessing the internet&lt;/a&gt;, the METR researchers wrote. Hundreds of agents &amp;ldquo;developed a way to hack out of their containers and fully replace a part of the system for executing tool calls&amp;quot;&amp;mdash;that is, commands to read and write files, access webpages, or perform other digital tasks.&lt;/p&gt;

&lt;p&gt;&amp;quot;This allowed them to pretend to issue one tool call while actually running an arbitrary other tool call of their choice.&amp;rdquo; This meant that the AIs could pretend to run a command to, say, view a webpage, while actually running a totally different command, like deleting an unrelated file.&lt;/p&gt;

&lt;p&gt;The researchers wrote that the agents weren&amp;rsquo;t intending to commit crimes, per se. Rather, they &amp;quot;seemed primarily motivated&amp;rdquo; to understand how to achieve the highest possible score during an experiment&amp;mdash;including spending much of their time trying to fool the scoring mechanism into accepting cheats.&lt;/p&gt;

&lt;p&gt;METR&amp;rsquo;s Cotra wrote, &amp;ldquo;Another jump like this could put us in very dangerous territory&amp;hellip;in many ways we&amp;rsquo;ve still only scratched the surface of what these agents did and why.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;At Hugging Face, company engineers tried to use OpenAI tools to understand how their security was defeated by the agentic swarm, but were blocked by OpenAI&amp;#39;s safeguards against misuse. So they turned to a Chinese open-weight model instead.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The propensity to compromise infrastructure can drop over 100x when using the production ChatGPT harness and system prompt,&amp;rdquo; the company said in a statement after the hacks. Hugging Face co-founder and chief science officer Thomas Wolf &lt;a href="https://x.com/Thom_Wolf/status/2085084718320464230"&gt;wrote on X&lt;/a&gt; on August 5, &amp;ldquo;While we can impose these coping solutions at the API/deployment level, it&amp;#39;s harder to impose them in advance on all actors using open-source models. Right now open-source models are slightly below the frontier level and have not yet shown any propensity to deceive humans, though.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;AI agents used for hacking could make it difficult for countries to determine who is behind new cyberattacks, because they strip out the stylistic clues investigators use to determine a hacker&amp;rsquo;s origins. Colin Shea-Blymyer, a research fellow at the Center for Security and Emerging Technology, said, &amp;ldquo;One of the ways that we can tell who performs an attack is by what tactics they use&amp;hellip;like &amp;lsquo;Oh, that&amp;rsquo;s a classic Russian tactic. Oh, this looks like a tactic that a Chinese [actor] would use.&amp;rsquo; If everybody&amp;rsquo;s using agents&amp;hellip;using the same tactics, well, who knows who&amp;rsquo;s doing what any more?&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;If anonymity remains pretty high, I think it&amp;#39;s potentially very destructive to have a lot of these models out there. That said, I&amp;#39;m not sure there&amp;#39;s much we can do to stop it,&amp;rdquo; Shea-Blymyer said.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/09/04/GettyImages_2292926705/large.jpg" width="618" height="284"><media:credit>Samuel Boivin/NurPhoto via Getty Images</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/09/04/GettyImages_2292926705/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>The US may lack the engineers to rebuild space assets in a future war: RAND</title><link>https://www.defenseone.com/threats/2026/09/us-may-lack-engineers-rebuild-space-assets-future-war-rand/415788/</link><description>Industry is already short of skilled engineering personnel.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Novelly</dc:creator><pubDate>Wed, 02 Sep 2026 16:52:36 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/09/us-may-lack-engineers-rebuild-space-assets-future-war-rand/415788/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;The defense industry would likely struggle to rebuild the U.S. military&amp;rsquo;s crucial space capabilities during a war with China or Russia because it will have too few skilled engineers to do the work, according to a new &lt;a href="https://www.rand.org/pubs/research_reports/RRA3665-2.html"&gt;report&lt;/a&gt; from RAND.&lt;/p&gt;

&lt;p&gt;Today, the country&amp;rsquo;s space-focused defense companies employ roughly 3 percent of its engineers, and competition for skilled personnel means many jobs go unfilled. If an adversary destroys space-based intelligence, targeting, and communications assets, that shortfall would likely keep the military from getting them back online quickly.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Modern warfare relies on space-based capabilities; therefore, a key question is how quickly then United States can replace those capabilities during a conflict,&amp;rdquo; the report said. &amp;ldquo;Although much attention has focused on making these systems more resilient, far less has examined how fast they can be rebuilt after an attack, especially within 12 to 24 months. China and Russia have shown they can threaten or destroy U.S. space assets, potentially weakening U.S. and allied military operations across many domains. In a prolonged conflict, the ability to restore these capabilities on a short timeline could be critical.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Various commissions have &lt;a href="https://www.govinfo.gov/content/pkg/CHRG-107shrg81578/html/CHRG-107shrg81578.htm"&gt;long warned&lt;/a&gt; that U.S. dependence on space could become a vulnerability. In recent years, &lt;a href="https://www.defenseone.com/threats/2024/05/russian-space-nuke-could-render-low-earth-orbit-unusable-year-us-official-says/396245/"&gt;concerns&lt;/a&gt; have arisen over &lt;a href="https://www.defenseone.com/ideas/2024/10/how-russia-and-china-envision-nuking-us-satellites-above-and-below/400235/"&gt;Russian and Chinese&lt;/a&gt; nuclear anti-satellite &lt;a href="https://www.defenseone.com/threats/2026/04/threat-russias-space-nuclear-weapon-forced-us-prepare-space-command-head-says/412836/"&gt;weapons&lt;/a&gt;. Rebuilding devastated constellations could require more engineers than the country has available, RAND wrote.&lt;/p&gt;

&lt;p&gt;&amp;nbsp;While recent Space Force and White House initiatives aim to turn the tide, it doesn&amp;#39;t match the demand the administration is putting on the military space industry and, ultimately, more creative solutions are needed to grow that workforce, the report said.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Being able to reconstitute after a conflict is absolutely essential, and that&amp;#39;s not just business as usual for people who are working in the space industry. That&amp;#39;s a massive surge in production,&amp;rdquo; Alexandra Gerber, the report&amp;rsquo;s lead author, said in an interview. &amp;ldquo;Think like World War II, Rosie the Riveter, everybody&amp;#39;s on the line, and this is not just you can teach somebody how to work in a factory after one day. The timelines for creating people to work in the space industry are much much longer than that. So, we need to be thinking about what the space workforce might need to look like to support reconstitution during a conflict, 10, 20, 30 years in advance. Not just six months.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Software development, data analytics, and artificial intelligence will be compete for future engineers, the report said. It can take at least 15 years to develop some of the more highly-skilled, space-focused experts.&lt;/p&gt;

&lt;p&gt;RAND researchers found &amp;ldquo;there are approximately 30,000 job openings per year for technicians and technologists, but only 11,000 individuals are credentialed annually. The space industrial base annual demand is approximately 5,000 of the annual openings (17 percent).&amp;rdquo; For the 244,000 assembly-related job fields hired for annually, there are only 13,000 people credentialed.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The space industrial base constitutes about 11,000 (5 percent) of the annual openings for assemblers, and competition for the 13,000 credentialed workers will be fierce,&amp;rdquo; the report said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Other major hurdles to growing the talent include security-clearance delays for six months or more, and a limited pool of qualified experts &amp;mdash; foreign nationals hold 70 percent of electrical and computer engineering doctorates, making them unavailable from most national security-related work, the report said.&lt;/p&gt;

&lt;p&gt;Gerbet told &lt;em&gt;Defense One&lt;/em&gt; the workforce isn&amp;rsquo;t needed just for a possible wartime surge. Last month, the White House released &lt;a href="https://www.defenseone.com/policy/2026/08/white-house-space-transportation-policy-calls-integration-air-traffic-control-modernization/415615/"&gt;a new space transportation policy&lt;/a&gt; which aims to reach &amp;ldquo;more than 1,000 launches and reentries&amp;rdquo; by 2030. Building new launch infrastructure to meet that demand requires more skilled workers.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We&amp;#39;re currently at about 200 launches per year in the U.S. And they&amp;#39;re talking about timesing that by five, but who are the workers who are going to build all of this infrastructure to support that?,&amp;rdquo; Gerber said. &amp;ldquo;Then what happens if there is a conflict on top of that. Then you&amp;#39;re talking about a double surge.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Last week, President Donald Trump announced plans to create a &lt;a href="https://www.defenseone.com/policy/2026/08/heres-what-trumps-new-space-academy-could-mean-us-military/415712/"&gt;U.S. Space Academy&lt;/a&gt; to &amp;ldquo;educate and train an entire generation of skilled service members, engineers, and civil operators.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Think about what the volume throughput of the space academy is likely to be. I mean, you&amp;#39;re only talking about what, a couple hundred graduates a year,&amp;rdquo; Gerber said. &amp;ldquo;This is not sufficient, right? I mean, that&amp;#39;s not really happening at a scale that would impact what we&amp;#39;re talking about.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;RAND researchers recommended that the Space Force and Pentagon focus new policy on growing workforce development by funding additional internships and vocational, bachelor&amp;#39;s, and advanced degree levels scholarships for science, technology, engineering, and math students, investing in fellowships, and promoting space engineering careers.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Researchers said the Space Force should also &amp;ldquo;allow Reserve Officers&amp;rsquo; Training Corps graduates and specialized program scholars to fulfill service obligations by working in qualifying&amp;rdquo; space defense firms.&lt;/p&gt;

&lt;p&gt;Additionally, researchers said the defense industry should also look to automation as a supplement to those workforce challenges.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Notably absent from these discussions were mentions of process automation, robotics, or artificial intelligence (AI)&amp;ndash;enabled productivity tools as means to reduce the inherent labor intensity of space manufacturing, assembly, integration, and testing,&amp;rdquo; the report said. &amp;ldquo;Stakeholders appear to be addressing a structural productivity challenge primarily through volume-based hiring and training strategies and giving little weight to automation as a complementary surge enabler.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/09/02/9784411/large.jpg" width="618" height="284"><media:description>Training Device Design and Engineering Center engineering technicians work with a manual turning center at Vandenberg Space Force Base, California, June 30, 2026.</media:description><media:credit>U.S. Space Force / Airman 1st Class Ian Hawkes</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/09/02/9784411/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>A Pacific conflict may not look like conventional war, SOCPAC commander says</title><link>https://www.defenseone.com/threats/2026/08/pacific-conflict-may-not-look-conventional-war-socpac-commander-says/415704/</link><description>At an irregular-warfare forum in Hawaii, commanders offer warnings and advice.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Jennifer Hlad</dc:creator><pubDate>Fri, 28 Aug 2026 15:01:51 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/08/pacific-conflict-may-not-look-conventional-war-socpac-commander-says/415704/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;&lt;strong&gt;HONOLULU&lt;/strong&gt;&amp;mdash;The better the U.S. gets at fighting in conventional ways, the more likely it is that adversaries will avoid a conventional conflict, the head of Special Operations Command Pacific said.&lt;/p&gt;

&lt;p&gt;But that doesn&amp;rsquo;t mean they will avoid a fight altogether, Army Brig. Gen. Michael Rose said at the Indo-Pacific Irregular Warfare Symposium here last week.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;If an adversary believes that a direct military confrontation with the United States or our allies is likely to end badly for them, that doesn&amp;rsquo;t necessarily make competition disappear. It changes how the adversaries will compete with us. They look for seams. They operate below thresholds. They exploit ambiguity. They use proxies, information, economic coercion, cyber capabilities, maritime forces, and other asymmetric approaches to achieve objectives without presenting us with a conventional fight for which we are preparing. In other words, our conventional superiority can actually increase the incentive for our adversaries to employ irregular warfare,&amp;rdquo; he said.&lt;/p&gt;

&lt;p&gt;So, in a theater where the phrase &amp;ldquo;deterrence is our&lt;a href="https://www.defenseone.com/policy/2024/04/deterring-conflict-our-highest-duty/395512/"&gt; highest duty&lt;/a&gt;&amp;rdquo; is nearly as common as aloha shirts at military functions, how should the U.S. approach technology and competition?&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We must be able to outfight and outthink our adversaries,&amp;rdquo; and taking an irregular warfare approach to autonomy can help, Rose said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;That means moving &amp;ldquo;beyond autonomous systems towards autonomous campaigning, moving beyond exquisite systems toward distributed networks, moving beyond U.S. capability toward allied and partner ecosystems, moving beyond conventional deterrence to deterrence through resilience and denial, and moving beyond asking how many autonomous systems will help us win a future war, and instead asking how they can help us shape today&amp;rsquo;s competition.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;In the Indo-Pacific, he said, the &amp;ldquo;fundamental problem&amp;rdquo; is scale. The distances are too vast, the number of strategically important locations too numerous for persistent presence. But autonomy &amp;ldquo;potentially changes that equation.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;But military leaders must not rush to buy cool new tech without first identifying the problem they want to solve, said Maj. Gen. Jeffrey Van Antwerp, who turned over command of SOCPAC to Rose earlier this month and now leads the Army&amp;rsquo;s 25th Infantry Division.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;You can get caught up in trying to get the better technology, but you haven&amp;rsquo;t done the fundamental things to be able to leverage that technology well,&amp;rdquo; Van Antwerp said. &amp;ldquo;We don&amp;rsquo;t have the time just to experiment without established objectives.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Adm. Frank Bradley, who leads U.S. Special Operations Command, outlined the challenge at the start of the symposium: &amp;ldquo;We face an increasingly weaponized cyber domain, a virtual domain that is transpiring and transmuting across our societies, an increasingly challenged space-based surveillance environment, a contested electromagnetic spectrum, and a rapidly emerging agent-driven artificial intelligence challenge to our security of our digital ecosystems.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The next day, as the symposium came to a close, deputy INDOPACOM commander Marine Lt. Gen. George Rowell reiterated the&lt;a href="https://www.defenseone.com/threats/2026/01/three-meta-trends-are-reshaping-warfare-indopacom-commander-says/410666/"&gt; trends&lt;/a&gt; Paparo believes are reshaping modern conflict. The megatrend that includes all three is &amp;ldquo;the absolute dominance of information in decision superiority,&amp;rdquo; he said.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Our forces must be organized to observe, orient, decide, act, and learn faster than the adversary. Whoever can do that, whoever can adopt that mindset, whoever can adopt those technologies and training fastest will certainly win the day.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/08/28/9670959/large.jpg" width="618" height="284"><media:description>U.S. Air Force and Philippine Air Force special operators prepare for patrol during Exercise Balikatan 2026 in Cerab, Philippines, May 1, 2026. </media:description><media:credit>U.S. Air Force / Airman 1st Class Arnet Tamayo</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/08/28/9670959/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>FBI disables China-linked hacking tools used against US agencies</title><link>https://www.defenseone.com/threats/2026/08/fbi-disables-china-linked-hacking-tools-used-against-us-agencies/415689/</link><description>A hacking group used the tools to target networks belonging to NASA, the Federal Reserve, the National Institutes of Health, the U.S. Senate and the departments of Energy, Justice and Health and Human Services.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Wed, 26 Aug 2026 12:28:00 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/08/fbi-disables-china-linked-hacking-tools-used-against-us-agencies/415689/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;The FBI seized three internet domains Wednesday that prosecutors say Chinese government-backed hackers used to target U.S. agencies, critical infrastructure and other networks.&lt;/p&gt;

&lt;p&gt;The Justice Department&lt;a href="https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-platforms-operated-and-used-china-state-sponsored-hackers"&gt; attributed&lt;/a&gt; the tools, known as QScan and QTRouter, to a hacking group called QTFY.&lt;a href="https://www.justice.gov/opa/media/1459096/dl?inline"&gt; Court records&lt;/a&gt; say the group operates through Nanjing Xinjiuwei Network Technology Company, a private Chinese firm that sold hacking services to China&amp;rsquo;s main civilian intelligence agency and its military.&lt;/p&gt;

&lt;p&gt;The group targeted networks belonging to NASA, the Federal Reserve, the National Institutes of Health, the U.S. Senate and the Energy, Justice and Health and Human Services departments, according to an FBI affidavit. Hospitals, telecommunications providers, power companies, banks and defense contractors were also targeted.&lt;/p&gt;

&lt;p&gt;The filing does not say that every attempted attack succeeded. A 2019 attempt against NASA, for example, failed because the agency had already fixed the security flaw the hackers tried to exploit.&lt;/p&gt;

&lt;p&gt;China&amp;rsquo;s embassy in Washington, D.C. did not immediately respond to a request for comment. Chinese officials have repeatedly denied Beijing sponsors hacking operations against the United States.&lt;/p&gt;

&lt;p&gt;QScan was used to look for weak spots while QTRouter helped the hackers hide. QScan searched the internet for vulnerable systems and tried to break into them. QTRouter sent the hackers&amp;rsquo; traffic through hijacked routers and other internet-connected devices, commercial proxy services and rented servers. The setup was meant to make the activity appear to come from somewhere other than China.&lt;/p&gt;

&lt;p&gt;QScan carried code for more than 200 different attacks and could work on a massive scale. On one day in 2024, it processed more than 2 million scanning or exploitation tasks, according to the affidavit.&lt;/p&gt;

&lt;p&gt;Lumen Technologies, which tracked the same infrastructure for roughly a year, described the operator as an &amp;ldquo;&lt;a href="https://www.lumen.com/blog/en-us/the-infrastructure-quartermaster-inside-a-china-nexus-state-enablement-model"&gt;infrastructure quartermaster&lt;/a&gt;&amp;rdquo; that provided other China-linked hackers with a ready-made service for finding targets and hiding their tracks. Lumen said networks first examined by QScan were later seen communicating through the group&amp;rsquo;s concealed network, suggesting some operations had moved from scouting targets toward attempts to break in. The system also mixed malicious traffic with that of ordinary internet users, making it harder to spot and block.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;These tools were used by PRC cyber actors to hide the origin of their attacks,&amp;rdquo; FBI Director Kash Patel said Wednesday.&lt;/p&gt;

&lt;p&gt;Investigators said QTFY could take advantage of newly discovered security flaws quickly and at a large scale. In May 2024, the group allegedly exploited a flaw in Check Point security equipment shortly after it became public, stealing server settings and user account information from more than 300 U.S. organizations, according to court documents.&lt;/p&gt;

&lt;p&gt;Several months later, the hackers allegedly used a previously unknown flaw in an Ivanti product to access three national laboratories, NIH, another HHS agency and a U.S. security-device manufacturer.&lt;/p&gt;

&lt;p&gt;Investigators also tied the group&amp;rsquo;s infrastructure to attempted attacks against an Ohio medical center during the COVID-19 pandemic, financial organizations in Michigan and South Korea and an insurance organization in Missouri.&lt;/p&gt;

&lt;p&gt;The case highlights how Chinese intelligence and military agencies continue to heavily &lt;a href="https://www.nextgov.com/cybersecurity/2025/08/researchers-detail-new-gray-zone-conflict-ai-driven-chinese-propaganda/407358/"&gt;rely on private companies&lt;/a&gt; for cyber operations and services.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Wednesday&amp;rsquo;s announcement follows years of similar FBI operations against Chinese hacking infrastructure. The bureau last year&lt;a href="https://www.nextgov.com/cybersecurity/2025/01/fbi-deleted-chinese-malware-4200-us-computers/402174/"&gt; removed PlugX surveillance malware&lt;/a&gt; from more than 4,200 U.S. computers infected by another state-backed hacking group.&lt;/p&gt;

&lt;p&gt;Federal authorities have also&lt;a href="https://www.nextgov.com/cybersecurity/2025/01/us-sanctions-chinese-company-helped-facilitate-espionage-hacks/401939/"&gt; dismantled&lt;/a&gt; a network of compromised routers, cameras and other devices associated with Flax Typhoon and&lt;a href="https://www.nextgov.com/cybersecurity/2024/01/us-disrupts-china-linked-cyber-campaign-impacting-critical-infrastructure-justice-officials-say/393794/"&gt; &lt;/a&gt;disrupted a separate network &lt;a href="https://www.nextgov.com/cybersecurity/2024/01/us-disrupts-china-linked-cyber-campaign-impacting-critical-infrastructure-justice-officials-say/393794/"&gt;used by prominent Chinese hacking collective Volt Typhoon&lt;/a&gt; to hide attacks against U.S. critical infrastructure.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/08/28/082626ChinaNG/large.jpg" width="618" height="284"><media:credit>kritsapong jieantaratip / Getty Images</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/08/28/082626ChinaNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Treasury sanctions Iranian hackers tied to critical-infrastructure breaches</title><link>https://www.defenseone.com/threats/2026/08/treasury-sanctions-iranian-hackers-tied-critical-infrastructure-breaches/415622/</link><description>Four of the five people named in the cyber action were also charged last week in the Justice Department’s expanded Mabna Institute case.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Tue, 25 Aug 2026 12:00:00 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/08/treasury-sanctions-iranian-hackers-tied-critical-infrastructure-breaches/415622/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;The Treasury Department sanctioned five Iranian citizens on Monday over alleged cyberattacks and theft aimed at&amp;nbsp;U.S. critical infrastructure, government offices, and digital assets.&lt;/p&gt;

&lt;p&gt;The designations were part of a&lt;a href="https://home.treasury.gov/news/press-releases/sb0613"&gt; much broader sanctions package&lt;/a&gt; that Treasury Secretary Scott Bessent called an &amp;ldquo;economic D-Day&amp;rdquo; aimed at isolating Iran and cutting off its revenue during the ongoing war.&lt;/p&gt;

&lt;p&gt;Treasury accused four of the people&amp;nbsp;&amp;mdash; Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda&amp;rsquo;i, and Mojtaba Ghal&amp;rsquo;eh-Kuhi &amp;mdash; of participating in a hacking operation directed by Iran&amp;rsquo;s Ministry of Intelligence and Security.&lt;/p&gt;

&lt;p&gt;Blagh, Balujeh, and Kadkhoda&amp;rsquo;i allegedly carried out most of the group&amp;rsquo;s intrusions. Since late 2023, they have breached and stolen data from U.S. energy companies, defense contractors, health care institutions, technology firms and financial institutions, according to the department. The three are believed to have also compromised several local, state, and federal government offices during the summer of 2024.&lt;/p&gt;

&lt;p&gt;Treasury officials said Ghal&amp;rsquo;eh-Kuhi and Behzad Mesri, who was previously sanctioned in 2018, have led the group since at least 2023. The hackers regularly conducted operations for the intelligence ministry, though officials said personal profit also played a role in their activity.&lt;/p&gt;

&lt;p&gt;The department separately sanctioned Arman Kahzadian, another alleged member of the network who focused on digital asset theft. Officials said Kahzadian illicitly took control of a cryptocurrency wallet holding more than $30,000 in Bitcoin in 2023.&lt;/p&gt;

&lt;p&gt;Other members sometimes turned their attention to targets inside Iran. Ghal&amp;rsquo;eh-Kuhi and Balujeh allegedly stole data from an Iranian telecommunications company in 2025. Treasury said that activity reflected the hackers&amp;rsquo; willingness to put their own financial interests ahead of work benefiting Tehran.&lt;/p&gt;

&lt;p&gt;Four of the five people sanctioned Monday were also charged last week in the Justice Department&amp;rsquo;s&lt;a href="https://www.nextgov.com/cybersecurity/2026/08/doj-charges-17-iranians-cybertheft-campaign/415511/"&gt; expanded case&lt;/a&gt; against 17 Iranian cyber actors affiliated with the Mabna Institute. Prosecutors have accused the Tehran-based firm of conducting a sprawling hacking-for-hire campaign for Iran&amp;rsquo;s Islamic Revolutionary Guard Corps and other Iranian partners. The group allegedly breached universities, government agencies, and companies while stealing more than 31 terabytes of academic research and intellectual property.&lt;/p&gt;

&lt;p&gt;The sanctions come amid heightened concern about Iran&amp;rsquo;s ability to reach vulnerable U.S. infrastructure. CISA and the FBI have recently helped water utilities recover from&lt;a href="https://www.nextgov.com/cybersecurity/2026/08/cisa-still-finds-water-system-controls-exposed-online-amid-multistate-hacks/415266/"&gt; cyberattacks affecting at least 12 states&lt;/a&gt;. Some U.S. officials suspect Iran-linked hackers were responsible, although CISA has not publicly attributed those intrusions.&lt;/p&gt;

&lt;p&gt;Federal agencies also warned earlier this year that&lt;a href="https://www.nextgov.com/cybersecurity/2026/04/pro-iran-hackers-are-targeting-us-industrial-control-systems-advisory-says/412679/"&gt; &lt;/a&gt;Iran-aligned groups were &lt;a href="https://www.nextgov.com/cybersecurity/2026/04/pro-iran-hackers-are-targeting-us-industrial-control-systems-advisory-says/412679/"&gt;targeting&lt;/a&gt; industrial control systems used across the energy, water and government sectors.&lt;/p&gt;

&lt;p&gt;The cyber sanctions were part of a broader package targeting nearly 60 people, companies and vessels tied to Iran&amp;rsquo;s nuclear and missile programs, oil trade and hacking operations. The moves block assets under U.S. control and generally prohibit Americans from doing business with those designated. Treasury also expanded sanctions categories to target people and companies operating in Iran&amp;rsquo;s digital assets, technology, gold, aviation and shipping sectors.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/08/25/082526TreasuryNG-1/large.jpg" width="618" height="284"><media:description>Treasury Secretary Scott Bessent speaks during a press conference at the Cash Room of the Treasury Department in Washington, D.C., on August 24, 2026, as he announces a new set of sanctions against Iran, describing the measures as âan economic D-Day.</media:description><media:credit>Mehmet Eser/Anadolu via Getty Images</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/08/25/082526TreasuryNG-1/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>AI-enabled deception threatens future operations, raises chances of large conflict, says Special Operations leader</title><link>https://www.defenseone.com/threats/2026/08/ai-enabled-deception-threatens-future-operations-raises-chances-large-conflict-says-special-operations-leader/415582/</link><description>“The information environment itself is much less transparent” now than in the past, and AI will make it worse, officials say.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Patrick Tucker</dc:creator><pubDate>Fri, 21 Aug 2026 17:27:00 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/08/ai-enabled-deception-threatens-future-operations-raises-chances-large-conflict-says-special-operations-leader/415582/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;&lt;strong&gt;HONOLULU&lt;/strong&gt; &amp;mdash; Faster intelligence gathering and analysis enabled by AI is allowing special operators to pull off missions that would have been impossible years ago, U.S. Special Operations Command leader Adm. Frank Bradley, said Wednesday. But malign actors empowered by simple AI tools are undermining military and civilian leaders&amp;rsquo; confidence in digital information, he said. That credibility decay, raising doubt about what is and is not true, will affect not just operations but the ability of the United States to &amp;ldquo;generate that unity of effort&amp;rdquo; to deter or defend against adversarial attack, he said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I have been plagued by my own staff hijinks on the use of artificial intelligence,&amp;rdquo; he told the Global SOF Foundation&amp;rsquo;s Indo-Pacific Irregular Warfare Symposium, a meeting of international special operations forces, industry representatives, and some lawmakers. &amp;ldquo;If you weren&amp;#39;t part of the inside crew, you probably couldn&amp;#39;t tell the difference because of how capable AI is at creating deepfake content.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Ongoing Russian and Chinese efforts to &lt;a href="https://www.defenseone.com/threats/2026/01/russian-hybrid-warfare-has-become-indistinguishable-politics/410867/?oref=d1-topic-lander-river"&gt;deceive Western audiences&lt;/a&gt;, both for tactical gain and to influence public sentiment, sometimes called &amp;ldquo;active measures,&amp;rdquo; get a boost from AI tools. But those efforts are hardly isolated. Ibrahim Traor&amp;eacute;, the leader of a junta currently controlling Burkina Faso, &lt;a href="https://www.bbc.com/pidgin/articles/c17rqgg7nq2o"&gt;has shown how easy it is&lt;/a&gt; for even small-scale dictators to use AI tools to gain control of populations.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Active measures have eaten the world,&amp;rdquo; one former State Department intelligence official told &lt;em&gt;Defense One&lt;/em&gt;.&lt;/p&gt;

&lt;p&gt;More &lt;a href="https://www.stimson.org/2026/ai-in-the-age-of-fake-imagined-content/"&gt;persuasive AI-enabled content,&lt;/a&gt; quietly but consistently shaping perceptions about what is happening where, has become &lt;a href="https://www.defenseone.com/ideas/2025/03/china-waging-cognitive-warfare-fighting-back-starts-defining-it/403886/?oref=d1-topic-lander-river"&gt;the dominant feature&lt;/a&gt; of a new critical battleground, Bradley said. &amp;ldquo;Exposing hostile behavior for exactly what it is&amp;mdash;that early credible illumination is a critical advantage&amp;hellip;Information advantage leads to decision advantage,&amp;rdquo; he said.&lt;/p&gt;

&lt;p&gt;A U.S. military official who works in counter-intelligence and foreign influence analysis said, &amp;ldquo;AI has made deception scalable. Even outside of specific campaigns, that will undermine confidence in all intelligence gathering. Every source of information will become increasingly suspect. We&amp;rsquo;re no longer just fighting phishing emails, we&amp;#39;re fighting synthetic voices, cloned faces, and entire fake identities convincing enough to fool the people who know the real person best.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The former State Department official said the United States, under the new Trump administration, had surrendered critical tools to watch and detect foreign influence just as adversaries were ramping up their ability to conduct influence operations.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The information environment itself is much less transparent, ironically, than it used to be,&amp;rdquo; they said, describing how changes in leadership at social media companies had decreased transparency into issues like content moderation and allowing disinformation on the platform.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The structures that were protecting the domestic environment don&amp;#39;t exist anymore. It&amp;#39;s not clear who&amp;#39;s able to see this,&amp;rdquo; they said, referring to governmental offices like the &lt;a href="https://www.nbcnews.com/politics/national-security/bondi-ends-fbi-effort-combat-foreign-influence-us-politics-rcna191012"&gt;Foreign Influence Task Force (FITF&lt;/a&gt;) at the FBI, the &lt;a href="https://www.justsecurity.org/119653/wjh-dismantling-foreign-malign-influence-center/"&gt;Foreign Malign Influence Center&lt;/a&gt; at the DNI, and &lt;a href="https://www.defenseone.com/threats/2025/02/usaid-shutoff-will-hurt-us-interests-around-globe-including-ukraine/402763/"&gt;various USAID&lt;/a&gt; activities and programs.&lt;/p&gt;

&lt;p&gt;A secondary effect of those decisions: analysts or intelligence officers not directly working with those entities but who might be tracking foreign influence attacks in some other way will be less likely to raise concerns about what they see.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The federal bureaucracy is very sensitive to priorities of political leadership, and I think you realize at this point that looking at this stuff is not going to be a career-enhancing move,&amp;rdquo; they said. &amp;ldquo;We&amp;#39;re in this period now where we are largely flying blind.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;A new playing field&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;New tools to synthesize intelligence from multiple sources at scale will provide new pathways for getting to the truth faster. That is already enabling faster joint operations of the sort that would not have been possible just a few years ago, Bradley said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;He pointed to the April &lt;a href="https://www.airandspaceforces.com/dude-44-rescue-massive-operation-iran-save-downed-airmen/"&gt;rescue&lt;/a&gt; of a downed F-15 pilot behind enemy lines, &amp;ldquo;made possible by a tightly synchronized intelligence, cyber-enabled support, and disciplined coordination across multiple elements.&amp;rdquo; It was the sort of coordination that can only occur when multiple elements can share a common intelligence picture that changes as quickly as real-world conditions, and data that effectively predicts how conditions will change, he said.&lt;/p&gt;

&lt;p&gt;An intelligence official described how those new intelligence streams are shaping decisions not just for commanders, but for everyone at once.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;About 10 years ago, [virtual imagery] was just for analysts, or just for the people who had specialties into these things. But now we&amp;#39;re bringing 10, 20, 30&amp;mdash;I mean, dozens, if not thousands, of different data sources in to build that operator level,&amp;rdquo; they said. &amp;ldquo;And it updates every 15 minutes.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The challenge going forward, Bradley and the intelligence official said, is not just finding new intelligence and data streams, but trusting them&amp;mdash;especially in a future information environment where adversarial AI agents are finding new methods to access and alter data and intelligence.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We&amp;#39;re spending a good bit of time and energy right now inside the the Department of War, but across the United States government as well, to ensure that those data sets and that those those systems are are appropriately protected against agentic AI attacks that might, that are coming,&amp;rdquo; Bradley said.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/08/21/GettyImages_2276334535/large.jpg" width="618" height="284"><media:credit>Daniel MIHAILESCU / AFP via Getty Images</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/08/21/GettyImages_2276334535/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>DOJ charges 17 Iranians in cybertheft campaign</title><link>https://www.defenseone.com/threats/2026/08/doj-charges-17-iranians-cybertheft-campaign/415536/</link><description>Prosecutors say the Mabna Institute stole 31.5 terabytes of academic data and breached email accounts at U.S. agencies and companies.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Wed, 19 Aug 2026 12:13:00 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/08/doj-charges-17-iranians-cybertheft-campaign/415536/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;Federal prosecutors have charged 17 Iranians affiliated with the Tehran-based Mabna Institute over an alleged hacking-for-hire operation that stole research and intellectual property from hundreds of universities and compromised email accounts belonging to U.S. government agencies and companies.&lt;/p&gt;

&lt;p&gt;The&amp;nbsp;&lt;a href="https://www.justice.gov/opa/pr/17-iranians-charged-conducting-massive-cyber-theft-campaign-behalf-islamic-revolutionary"&gt;14-count superseding indictment&lt;/a&gt;, unsealed Tuesday, adds eight defendants to a case brought against nine other members of the firm in 2018. Prosecutors said the expanded charges expose a broader network that conducted cyber intrusions for Iran&amp;rsquo;s Islamic Revolutionary Guard Corps and other Iranian government and university clients.&lt;/p&gt;

&lt;p&gt;The Mabna Institute targeted systems belonging to 144 U.S. universities, 178 universities abroad, at least 42 U.S. companies, 11 foreign companies and at least five federal and state government agencies since around 2013, according to the Justice Department.&lt;/p&gt;

&lt;p&gt;The victims included the Labor Department, Federal Energy Regulatory Commission, the states of Hawaii and Indiana, the United Nations and UNICEF. The hackers also allegedly targeted HBO and unnamed technology firms and defense contractors.&lt;/p&gt;

&lt;p&gt;Prosecutors said the university campaign targeted more than 100,000 professors&amp;rsquo; accounts worldwide and successfully compromised approximately 8,000. The hackers used stolen credentials to access journals, dissertations, electronic books and other research spanning fields ranging from medicine and engineering to the social sciences.&lt;/p&gt;

&lt;p&gt;All told, the group allegedly stole at least 31.5 terabytes of academic data and intellectual property. U.S. universities had spent more than $3.4 billion to procure or obtain access to the targeted materials, although prosecutors did not characterize that entire amount as a financial loss from the theft.&lt;/p&gt;

&lt;p&gt;Some of the stolen material was later sold to customers in Iran through two websites. One offered academic resources taken from universities, while the other allowed customers to use compromised professors&amp;rsquo; accounts to enter university library systems directly, according to the indictment.&lt;/p&gt;

&lt;p&gt;Prosecutors said Mabna&amp;rsquo;s founders established the firm to help Iranian universities and research organizations obtain scientific resources from abroad. It employed or contracted with hackers who carried out phishing attacks, searched for vulnerable systems and traded credentials for compromised accounts.&lt;/p&gt;

&lt;p&gt;The defendants face charges that include conspiracy to commit computer intrusions, wire fraud and aggravated identity theft. Some of the offenses carry maximum prison sentences of 20 years. The State Department is separately offering a reward of up to $10 million for information leading to the location of five of the defendants.&lt;/p&gt;

&lt;p&gt;The charges come amid concerns about Iran&amp;rsquo;s use of cyber operations during the ongoing war.&lt;/p&gt;

&lt;p&gt;Since U.S. and Israeli strikes began in February, suspected Iran-aligned groups have been linked to a&lt;a href="https://www.nextgov.com/cybersecurity/2026/03/suspected-pro-iran-hacker-group-tied-stryker-cyberattack/412050/"&gt; &lt;/a&gt;disruptive attack against &lt;a href="https://www.nextgov.com/cybersecurity/2026/03/suspected-pro-iran-hacker-group-tied-stryker-cyberattack/412050/"&gt;medical technology company Stryker&lt;/a&gt;, the&amp;nbsp;&lt;a href="https://www.nextgov.com/cybersecurity/2026/03/pro-iran-hackers-claim-breach-fbi-directors-email/412440/"&gt;compromise&lt;/a&gt; of FBI Director Kash Patel&amp;rsquo;s personal email and attacks against&amp;nbsp;&lt;a href="https://www.nextgov.com/cybersecurity/2026/04/pro-iran-hackers-are-targeting-us-industrial-control-systems-advisory-says/412679/"&gt;industrial-control systems across several U.S. sectors&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;More than 30 Minnesota water systems and water infrastructure in several other states have been &lt;a href="https://www.nextgov.com/cybersecurity/2026/07/cisa-urges-water-utilities-take-exposed-systems-down-after-minnesota-hacks/415142/"&gt;targeted in the last month&lt;/a&gt; in activity some officials suspect may be tied to Iran. U.S. officials previously&amp;nbsp;&lt;a href="https://www.nextgov.com/cybersecurity/2026/06/us-officials-see-iran-cyber-threat-persisting-despite-preliminary-deal/414243/"&gt;told &lt;em&gt;Nextgov/FCW&lt;/em&gt;&lt;/a&gt; that they expected Iranian and Iran-aligned cyber operations to continue regardless of whether fighting subsided.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/08/20/081926IranNG/large.jpg" width="618" height="284"><media:credit>Mojito_mak/Getty Images</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/08/20/081926IranNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Iran war reveals protection of space assets on bases has to ‘evolve,’ top general says</title><link>https://www.defenseone.com/threats/2026/08/iran-war-reveals-protection-space-assets-bases-has-evolve-top-general-says/415389/</link><description>Key radars have been hit during Epic Fury, Gen. Whiting says.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Novelly</dc:creator><pubDate>Wed, 12 Aug 2026 23:32:57 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/08/iran-war-reveals-protection-space-assets-bases-has-evolve-top-general-says/415389/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;&lt;strong&gt;HUNTSVILLE, Ala. &amp;mdash; &lt;/strong&gt;Iran&amp;rsquo;s deliberate targeting of U.S. radar systems during Epic Fury shows that the military has to change the way it protects key space assets on the ground, U.S. Space Command&amp;rsquo;s leader said.&lt;/p&gt;

&lt;p&gt;Iranian drone and missile attacks after the initial U.S.-Israel joint strikes &lt;a href="https://www.nytimes.com/interactive/2026/03/11/world/middleeast/iran-us-military-bases-strikes-map.html?eafs_enabled=false"&gt;reportedly&lt;/a&gt; damaged multiple radar sites. One U.S. Army Space and Missile Defense Command soldier, Army Staff Sgt. Benjamin Pennington, was killed in the March 1 attack on Prince Sultan Air Base in Saudi Arabia. The loss of life and key technology in the war highlight the military&amp;rsquo;s need to improve the way it protects key space assets, said Gen. Stephen Whiting, the head of U.S. Space Command.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;No doubt, one of the lessons learned out of operations in the Middle East is that if you have fixed infrastructure, it will be targetable, and if your opponents have over-the-horizon fires, whether ballistic missiles or one-way attack drones, you will be at risk,&amp;rdquo; Whiting told a group of reporters Wednesday at Red Stone Arsenal. &amp;ldquo;I&amp;#39;m proud of the defense work that we&amp;#39;ve done, but we have to continue to evolve that, because the threats are rapidly improving as well.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;While Iran was &lt;a href="https://www.defenseone.com/threats/2026/03/us-says-it-destroyed-irans-space-command-experts-say-it-wasnt-much-threat/411938/"&gt;never a substantial threat&lt;/a&gt; to U.S. assets in space, they scored major hits from the ground. Whiting, during his last Space and Missile Defense Symposium speech as Space Command&amp;rsquo;s leader, stressed that adversaries are taking note of how they can harm military operations by targeting space and missile defense targets. That&amp;rsquo;s only going to grow in future conflicts, the four-star general warned.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Let&amp;rsquo;s be blunt and specific. Iran is a medium-size military power&amp;mdash;and they&amp;rsquo;re choosing to fire at space and missile defense targets. When bullets cost so much, you take great care with your aim,&amp;rdquo; Whiting said during his keynote. &amp;ldquo;You only shoot at your adversary&amp;rsquo;s most valuable targets. And right now, they are targeting the forces and capabilities represented in this room.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Potential changes to U.S. basing patterns in the Middle East will take time and money and are likely to be heavily debated between Congress and the military, Elliot Abrams, an expert at the Council on Foreign Relations, &lt;a href="https://www.cfr.org/articles/rising-u-s-casualties-in-the-iran-war-should-force-a-rethink-of-middle-east-bases"&gt;wrote last month&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The wait will be costly&amp;mdash;the longer U.S. troops remain within range of Iranian missiles, the more the United States will pay in readiness, deterrence, and lives,&amp;rdquo; Abrams wrote.&lt;/p&gt;

&lt;p&gt;Defense &lt;a href="https://www.brookings.edu/articles/the-end-of-the-american-way-of-war/"&gt;experts have called&lt;/a&gt; for hardening existing structures on bases in the interim. But some military leaders don&amp;rsquo;t support increased investment in that type of protection.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Gen. Kenneth Wilsbach, the Air Force chief of staff, said in an interview &lt;a href="https://breakingdefense.com/2026/07/usaf-chief-wilsbach-on-lessons-from-iran-t-7-flight-and-f-35-delays/"&gt;last month&lt;/a&gt;: &amp;ldquo;I don&amp;rsquo;t want to spend a lot of money on hardening shelters.&amp;rdquo; He described it as economically inefficient and called for either simpler methods for protecting against drones or increased systems to destroy incoming rounds.&lt;/p&gt;

&lt;p&gt;Whiting said the Iran war has shown how the nature of warfare is changing.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;It used to be that the enemy would aim their snipers and sharp shooters at a platoon leader or radio operator,&amp;rdquo; Whiting said. &amp;ldquo;Nowadays, our adversaries shoot at the space and missile defense units which are deployed inside their weapons engagement zone.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/08/12/GettyImages_2263465116/large.jpg" width="618" height="284"><media:description>Smoke rises after Iran launched a missile attack targeting the headquarters of the U.S. Navy's Fifth Fleet in Manama, Bahrain, on February 28, 2026. </media:description><media:credit>Stringer / Anadolu via Getty Images</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/08/12/GettyImages_2263465116/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Five things Space Command says it needs to win tomorrow’s wars</title><link>https://www.defenseone.com/threats/2026/08/five-things-space-command-says-it-needs-win-tomorrows-wars/415381/</link><description>Gen. Whiting adds to previous calls for new tech in his final speech to the SMD Symposium.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Novelly</dc:creator><pubDate>Wed, 12 Aug 2026 17:42:53 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/08/five-things-space-command-says-it-needs-win-tomorrows-wars/415381/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;&lt;strong&gt;HUNTSVILLE, Ala.&lt;/strong&gt; &amp;mdash; Space weapons and refuelable satellites are among the items needed to preserve the U.S. military&amp;rsquo;s orbital edge over China, the head of U.S. Space Command said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;America&amp;rsquo;s adversaries are targeting U.S. space assets and rapidly developing their own, Gen. Stephen Whiting told attendees at the Space and Missile Defense Symposium on Wednesday. China, for example, has direct-ascent ASAT missiles, ground-based lasers, jammers, and maneuverable, dual-use satellites, he said.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;These developments intend to degrade our current space superiority and would potentially give&lt;/p&gt;

&lt;p&gt;China a maneuver and logistics advantage in space &amp;ndash; something we would not accept on the land, at sea, or in the air,&amp;rdquo; Whiting said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;In the four-star&amp;rsquo;s final Space and Missile Defense Symposium speech as the leader of the combatant command, Whiting told military and industry audience members that there are five major things on U.S. Space Command&amp;rsquo;s &lt;a href="https://ssl.armywarcollege.edu/DDE/learningmodules/jsps/terms/ipl.cfm"&gt;Integrated Priorities List&lt;/a&gt; for 2029 to 2033.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;This isn&amp;rsquo;t just a wishlist. It&amp;rsquo;s a clear demand signal to several audiences describing the warfighting capabilities we need to meet our mission,&amp;rdquo; he said.&lt;/p&gt;

&lt;p&gt;1. Integrated space fires: Mirroring Army usage, Whiting has &lt;a href="https://www.spacecom.mil/Newsroom/News/Article-Display/Article/3866246/whiting-outlines-key-priority-investments-at-smd-symposium/"&gt;used this term&lt;/a&gt; throughout his tenure at Space Command to refer to the offensive and defensive capabilities needed to deter orbiting threats.&amp;ldquo;&lt;/p&gt;

&lt;p&gt;We&amp;rsquo;re a combatant command and we fight to win wars,&amp;rdquo; he said. &amp;ldquo;To win, we need credible, acknowledged, kinetic and non-kinetic fires. They are a key component of how we establish space superiority and restore credible deterrence.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;2. Counter-pLEO tech: Whiting said new technology is needed to counter adversaries&amp;rsquo; low-Earth-orbit satellite constellations. As of last month, China has launched 200 G60 and 168 SatNet communications satellites as it builds a pair of &amp;ldquo;mega constellations...to compete with Western proliferated LEO (pLEO) architectures,&amp;rdquo; according to a Space Force &lt;a href="https://www.spaceforce.mil/About-Us/Fact-Sheets/Fact-Sheet-Display/Article/4297159/space-threat-fact-sheet/"&gt;fact sheet&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I don&amp;#39;t want any U.S. force to be put at risk because somebody else might have a proliferated low-Earth-orbit constellation that could find, fix, track, and target them,&amp;rdquo; Whiting told reporters after his keynote address.&lt;/p&gt;

&lt;p&gt;3. Joint, integrated space command and control: Military leaders often stress the centrality of being able to oversee, organize, and order complex space operations.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We must enhance machine-to-machine connectivity to support decision-making and battle management of this global space fight on tactically relevant timelines,&amp;rdquo; Whiting said in his address.&lt;/p&gt;

&lt;p&gt;4. Dedicated space domain awareness for space engagements: It&amp;rsquo;s not just for missile defense, Whiting said: space domain awareness needs to expand and evolve to a whole range of space operations, not just one segment of it.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We must adopt a &amp;lsquo;target-quality track&amp;rsquo; mindset to everything we do in space, just like the missile defense community has done for decades,&amp;rdquo; he said.&lt;/p&gt;

&lt;p&gt;5. Sustained space maneuver: Developing satellites that can be refueled to extend their usefulness remains one of U.S. Space Command key priorities. In March, a Chinese commercial satellite used a flexible robotic arm to &amp;ldquo;to demonstrate on-orbit servicing, refueling, and debris removal,&amp;rdquo; according to the Space Force.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Today, our satellites are limited by the fuel they launch with, which leads to a psychology of scarcity. Husbanding that fuel often overrides desired warfighting maneuvers,&amp;rdquo; Whiting said. &amp;ldquo;That must change. We must be able to actively avoid threats and maneuver to gain a position of advantage on our adversaries.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Whiting has pitched some of these items at past symposiums; in 2024, he &lt;a href="https://www.spacecom.mil/Newsroom/News/Article-Display/Article/3866246/whiting-outlines-key-priority-investments-at-smd-symposium/"&gt;said&lt;/a&gt; his 2027 Integrated Priorities List was topped by space fires and resilient command and control.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Our space assets need to shoot, move, and communicate just like the rest of the Joint Force,&amp;rdquo; Whiting said Wednesday. &amp;ldquo;In short, space needs to fight like the Joint Force, to empower the Joint Force&amp;rsquo;s ability to fight and undermine our adversaries&amp;rsquo; ability to do so.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/08/12/9654445/large.jpg" width="618" height="284"><media:description>Gen. Stephen Whiting, commander of U.S. Space Command, speaks with Lt. Gen. James Adams, director of the Defense Intelligence Agency, during a ribbon-cutting ceremony at Redstone Arsenal, Alabama, April 29, 2026.</media:description><media:credit>U.S. Space Command</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/08/12/9654445/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Local water utilities are under cyber attack. A new group wants to help</title><link>https://www.defenseone.com/threats/2026/08/water-utilities-cyber/415326/</link><description>The National Rural Water Association and DEF CON Franklin are coordinating the development of a replicable cybersecurity package for water providers.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Mon, 10 Aug 2026 18:00:00 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/08/water-utilities-cyber/415326/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;LAS VEGAS &amp;mdash; As dozens of small water utilities report cyber intrusions&amp;mdash;possibly from Iran-linked groups&amp;ndash;an industry association and a university are teaming up to help raise their defenses.&lt;/p&gt;

&lt;p&gt;The Water Watch Center will provide&amp;nbsp;cyber mitigation support to utilities that serve fewer than 10,000 people&amp;mdash;that is, most of the nation&amp;rsquo;s community water systems. Launched at this year&amp;rsquo;s DEF CON hacker convention, the initiative is a collaboration&amp;nbsp;of&amp;nbsp;the &lt;a href="https://nrwa.org/"&gt;National Rural Water Association&lt;/a&gt; and &lt;a href="https://defconfranklin.com/"&gt;DEF CON Franklin&lt;/a&gt;, a project of the Cyber Policy Initiative at the University of Chicago Harris School of Public Policy.&lt;/p&gt;

&lt;p&gt;More than 30 community water systems in Minnesota were targeted late last month, according to state officials. Around 12 states have reported similar activity in recent days, though state officials said they continued to operate&amp;nbsp;safely and that there were no known effects on public health. The FBI and Cybersecurity and Infrastructure Security Agency are working on &lt;a href="https://www.nextgov.com/cybersecurity/2026/08/cisa-still-finds-water-system-controls-exposed-online-amid-multistate-hacks/415266/"&gt;incident response&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;An initial group of five cybersecurity firms will help deliver services to water utilities as part of the initiative.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;These leading cyber firms and NRWA are architecting a scalable cyber delivery model that has eluded water industry and national security officials to date,&amp;rdquo; Jake Braun, the co-founder of DEF CON Franklin and a former White House acting principal deputy national cyber director, said in a statement.&lt;/p&gt;

&lt;p&gt;Paul Nakasone, who led U.S. Cyber Command and the NSA from 2018 to 2024, said at DEF CON this year that water utilities around the country are highly exposed, and he pushed for higher defense standards in the sector.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;These [programmable logic controllers] should not be exposed to the internet,&amp;rdquo; Nakasone told reporters in a briefing on Friday, referring to the small computers used to operate pumps, valves, and other equipment inside water facilities.&lt;/p&gt;

&lt;p&gt;Some U.S. officials believe Iran may be responsible, though there has been no definitive public confirmation.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I think [the government] is taking a very measured approach to make sure that they have the right actor that&amp;rsquo;s doing this,&amp;rdquo; Nakasone said when asked about why Iran hasn&amp;rsquo;t publicly been linked to the hacks.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I look at intent. I look at capability. I look at history. I&amp;rsquo;m not the person that&amp;rsquo;s making the call on the attribution, but I see an actor here that has certainly shown a history of being able to do this,&amp;rdquo; he said. &amp;ldquo;They certainly have the capability, and I think there&amp;rsquo;s an intent right now &amp;mdash; we&amp;rsquo;re in conflict with Iran.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/08/10/080726waterNG-1/large.jpg" width="618" height="284"><media:credit>Seth McConnell/The Denver Post via Getty Images</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/08/10/080726waterNG-1/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>AI agents conspired to hack into networks and steal data during an experiment: study</title><link>https://www.defenseone.com/threats/2026/08/ai-agents-conspired-hack-networks-and-steal-data-during-experiment-study/415302/</link><description>When researchers imposed difficult missions, AI tools forged identities, escaped sandboxes—and tried to cover it all up.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Patrick Tucker</dc:creator><pubDate>Mon, 10 Aug 2026 04:39:22 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/08/ai-agents-conspired-hack-networks-and-steal-data-during-experiment-study/415302/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;AI agents from OpenAI and Anthropic autonomously collaborated with one another to deceive humans, share break-in tools, and steal data in a series of independent tests, confirmed by both companies.&lt;/p&gt;

&lt;p&gt;On Tuesday, the AI Security Institute&amp;nbsp;&lt;a href="https://cs.login.cmu.edu/idp/profile/SAML2/Redirect/SSO?SAMLRequest=fZJPT8IwGMa%2FytI77RgI0jAShIMkKIShBy%2Bm696xJl07%2B3ag397BAPHCuc%2Bf9%2FmlYxSlrvi09oXZwFcN6IPvUhvkp4eY1M5wK1AhN6IE5F7yZPqy5BENeeWst9JqEkwRwXllzcwarEtwCbi9kvC2Wcak8L5CztjhcKBSVF4WghrwLClUmloNvqCIlh1jI7ZeJVsSzJs7lBHHxD%2B%2FRKrtThkqy5pCVjOVVay5IVcazu4NZMqBbLKTFQkW85h89jIhu6MoDcNBmoOQ6TAFGY16Ms9k3u8PGhliDQuDXhgfkyiMBp3wsRMOt91H%2FhDxaPRBgvV56pMymTK7%2B1zSVoT8ebtdd9pF7%2BDwtKYRkMn4SJefit0N7%2Fux4gKZTK5IrAOtlaDo9rThcyGDV7RjdlPV9lb8tclezNdWK%2FkTTLW2h5kD4SEmXcImreX%2Fp5j8Ag%3D%3D&amp;amp;RelayState=ss%3Amem%3Ac5998dcc353bafba0d382eb2e25c817b94326c3fcb0b16384e57c023bf64526H"&gt;published a paper&lt;/a&gt; about experiments intended to help understand how AI agents solve cybersecurity challenges. AISI researchers found that agents given access to the internet and allowed to disregard some security features would perform &amp;ldquo;autonomous, unsanctioned action...targeting real people and organizations.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Company officials confirmed the findings Thursday.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;AI-orchestrated, fully automated offensive attacks are real now,&amp;rdquo; OpenAI security official Michael Dalton said during a &lt;a href="https://www.youtube.com/watch?v=87DyyMV0kCY"&gt;briefing&lt;/a&gt; on the report during the Black Hat cybersecurity conference in Las Vegas.&lt;/p&gt;

&lt;p&gt;In one of the tests, the researchers told an OpenAI model to compromise three target networks and recover a token as part of a &amp;ldquo;&lt;a href="https://www.eccouncil.org/cybersecurity-exchange/ethical-hacking/capture-the-flag-ctf-cybersecurity/"&gt;capture the flag&lt;/a&gt;&amp;rdquo; exercise.&lt;/p&gt;

&lt;p&gt;In response, the model created a series of agents that set up a shared GitHub account so they could efficiently collaborate to build malware. When GitHub suspended the account, the agents set up new accounts on other websites, bypassing CAPTCHA and other security features by searching the web for audio and image samples to &amp;ldquo;see&amp;rdquo; and &amp;ldquo;hear&amp;rdquo; clues that are meant to be invisible to software programs. The agents exchanged credentials for passwords to access the new sites to continue to build out their attack tool.&lt;/p&gt;

&lt;p&gt;It may be time for organizations to adjust how easily they grant access not just to humans, but to anything online, said Morey Haber, chief security advisor at BeyondTrust, a digital identity security firm.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The technology industry has spent decades designing open models of interoperability. APIs connect everything, identities federate across boundaries, and access gets granted to enhance productivity. The concept of an open security model breaks down completely with agentic AI because of unmanageable risk,&amp;rdquo; Haber wrote in &lt;a href="https://www.scworld.com/perspective/black-hat-2026-6-qualities-security-pros-should-look-for-in-agentic-ai-systems"&gt;an Aug. 4 commentary.&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;In another AISI test, an Anthropic agent pretended to be a human to submit malware to GitHub, where developers routinely trade or post code to help one another. Cybersecurity officials&amp;rsquo; &lt;a href="https://www.defenseone.com/technology/2026/08/ai-models-white-house-and-companies-secret-safety-measures/415227/?oref=d1-homepage-top-story"&gt;warnings&lt;/a&gt; about attempts to poison open-source code libraries usually refer to human actors.&lt;/p&gt;

&lt;p&gt;What the agent did next shocked AISI reviewers, who described it as &amp;ldquo;the kind of goal-directed deception that, until recently, had been largely theoretical.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;After submitting the poisoned code, the agent created a different &amp;ldquo;sock puppet&amp;rdquo; account to pose as an impartial third-party developer and endorse the contribution. When a reviewer flagged the code submission as likely to contain malware, the agent erased evidence that it had submitted malware, as well as the reviewer comments that it had done so.&lt;/p&gt;

&lt;p&gt;In all, AISI ran 122 tests&amp;mdash;and found that in 19 of them, agents took &amp;ldquo;autonomous, unsanctioned action on the live internet, targeting real people and organizations.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;In their report, the researchers note that they conducted the tests in a deliberately &amp;ldquo;permissive&amp;rdquo; environment, allowing the agents to access the open internet and even disabling some security features to better &amp;ldquo;assess what these models can do.&amp;rdquo; They recommend that &amp;ldquo;implementing internet access controls would likely have prevented these events.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Had a gang of human hackers done any of these things&amp;mdash;injecting malware, gaining access to data repositories under false pretenses, sharing stolen credentials to access a private network without permission&amp;mdash;in a real world setting, they would face &lt;a href="https://www.escudodigital.com/en/cybersecurity/jordanian-admits-to-selling-illegal-access-to-50-companies-networks.html"&gt;criminal prosecution&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;But perhaps the most alarming incident mentioned in the paper was one that was not part of the test at all, only briefly mentioned alongside the suggestion on access controls.&lt;/p&gt;

&lt;p&gt;In July, OpenAI&amp;rsquo;s GPT-5.6 Sol &lt;a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/"&gt;broke out&lt;/a&gt; of a sandbox, a confined virtual environment, by finding a vulnerability no one knew existed.&lt;/p&gt;

&lt;p&gt;Rob Joyce, who once led the NSA&amp;rsquo;s &lt;a href="https://www.pbs.org/wgbh/frontline/article/how-the-nsas-secret-elite-hacking-unit-works/"&gt;Tailored Access Operations&lt;/a&gt;, told the audience at BlackHat on Thursday that the incident was &amp;ldquo;arguably the most consequential hack&amp;rdquo; in nearly three decades.&lt;/p&gt;

&lt;p&gt;On Friday, OpenAI officials at Blackhat &lt;a href="https://www.reuters.com/legal/litigation/openai-flags-possible-critical-cybersecurity-risk-upcoming-model-tightens-2026-08-07/"&gt;said&lt;/a&gt; they had decided to delay the release of the company&amp;rsquo;s newest Astra model over cybersecurity concerns.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/08/10/GettyImages_2282881169/large.jpg" width="618" height="284"><media:description>Acting Executive Director of Europol Jurgen Ebner talks to media at the EU Commission headquarters on June 26, 2026, in Brussels, Belgium. </media:description><media:credit> Thierry Monasse / Getty Images</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/08/10/GettyImages_2282881169/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>US has too few interceptors to deter war with China, experts say</title><link>https://www.defenseone.com/threats/2026/08/interceptors-war-china-heritage/415241/</link><description>A new report from Heritage is the latest to sound alarms over the expenditure of munitions in Trump's Iran war.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Patrick Tucker</dc:creator><pubDate>Wed, 05 Aug 2026 21:33:31 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/08/interceptors-war-china-heritage/415241/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;The United States would run out of the interceptors it needs to take down Chinese missiles &amp;ldquo;within days&amp;rdquo; of a conflict, according to a new &lt;a href="https://www.heritage.org/defense/report/theater-missile-defense-inventory-inadequate-us-china-conflict"&gt;report&lt;/a&gt; from the Heritage Foundation. It&amp;#39;s the latest in a series of warnings from experts and commanders highlighting a critical gap.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The White House, Congress, and defense contractors have taken steps to address it. But the ongoing war with Iran has exposed those efforts as insufficient, experts say.&lt;/p&gt;

&lt;p&gt;It&amp;rsquo;s not a new problem. A 2023&amp;nbsp;&lt;a href="https://www.csis.org/analysis/empty-bins-wartime-environment-challenge-us-defense-industrial-base"&gt;report&lt;/a&gt;&amp;nbsp;from the Center for Strategic and International Studies concluded that the U.S. would&amp;nbsp;&amp;ldquo;within the first week of a Taiwan conflict&amp;rdquo; run out of key munitions, such as Patriot Advanced Capability-3 Missile Segment Enhancements, Terminal High Altitude Area Defense interceptors, and SM-6 and SM-3 Standard missiles.&amp;nbsp;In May, CSIS &lt;a href="https://www.csis.org/analysis/rebuilding-us-missile-inventory-multiyear-project"&gt;reported&lt;/a&gt;&amp;nbsp;that the United States will be in&amp;nbsp;&amp;ldquo;a window of vulnerability for several years, until inventories return to their previous levels, and another several years before they get to the levels that war planners desire.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The Trump administration is trying to wring more production out of industry. In January, the White House cut a &lt;a href="https://www.war.gov/News/Releases/Release/Article/4371320/department-of-war-establishes-new-acquisition-model-to-more-than-triple-pac-3-m/"&gt;deal&lt;/a&gt; with Lockheed Martin intended to triple annual&amp;nbsp;production of PAC-3 missiles to 2,000.&amp;nbsp;On Monday, the Pentagon &lt;a href="https://www.war.gov/News/Releases/Release/Article/4562167/department-of-war-signs-framework-agreements-with-northrop-grumman-to-ramp-prod/"&gt;announced&lt;/a&gt; a related&amp;nbsp;seven-year, $3 billion&amp;nbsp;deal with Lockheed and&amp;nbsp;Northrop Grumman&amp;nbsp;to&amp;nbsp;boost the production of PAC-3&amp;nbsp;solid rocket motors. The deal is also intended to help&amp;nbsp;&amp;ldquo;quadruple&amp;rdquo; annual production of THAAD interceptors.&lt;/p&gt;

&lt;p&gt;A Northrop spokesperson said&amp;nbsp;a &lt;a href="https://news.northropgrumman.com/srm/accelerating-tomorrow-how-northrop-grumman-leads-in-solid-rocket-motor-innovation"&gt;billion-dollar investment&lt;/a&gt; in its Allegany Ballistics Laboratory has enabled&amp;nbsp;the company to double annual production of motors since 2021, and that the&amp;nbsp;company aims to&amp;nbsp;triple production by 2027.&lt;/p&gt;

&lt;p&gt;And yet these deals&amp;mdash;and the goals the Pentagon set in January&amp;mdash;are too small to quickly restore an arsenal depleted by Trump&amp;#39;s&amp;nbsp;war on Iran. &amp;ldquo;Those metrics that were set prior to [Operation Epic Fury]. That was before we just lit off billions of dollars in a decade worth of production per work in some cases,&amp;rdquo;&amp;nbsp;said Tom Karako, who leads CSIS&amp;#39;&amp;nbsp;Missile Defense Project.&lt;/p&gt;

&lt;p&gt;The Heritage report makes its own estimate of weapons expended in the war:&amp;nbsp;&amp;ldquo;During the first four days of Operation Epic Fury, U.S. and allied forces used approximately 1,738 theater surface-to-air munitions to defend against 565 Iranian ballistic missiles and 57 cruise missiles.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The report says&amp;nbsp;the Pentagon currently has &amp;ldquo;less than 10 percent&amp;quot; of the PAC-3 MSE, THAAD, SM-6, and SM-3 interceptors &amp;quot;required to deter or, if necessary, prevail, in a protracted, high-intensity conflict with China.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The Heritage report is dire, but it may not go far enough, as it does not factor in how China may use low-cost drone warfare to further frustrate U.S. operations in the region.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;In an April hearing, U.S. Indo-Pacific Command leader Adm. Sam Paparo also &lt;a href="https://www.armed-services.senate.gov/imo/media/doc/04-21-2026_full-open-transcript1.pdf"&gt;communicated&lt;/a&gt; his concerns about missile shortfalls and a lack of solutions for countering cheap drones. &amp;ldquo;Current production timelines are misaligned with operational expenditures and the threats we face,&amp;rdquo; Paparo said.&lt;/p&gt;

&lt;p&gt;Ukraine&amp;#39;s&amp;nbsp;shortage of Patriot interceptor missiles is reducing its ability to fight off&amp;nbsp;Russian ballistic missiles. On July 28, Ukrainian President Volodymyr Zelenskyy &lt;a href="https://x.com/ZelenskyyUa/status/2082161228177162665"&gt;met&lt;/a&gt;&amp;nbsp;with Lockheed Martin representatives&amp;nbsp;to discuss the possibility of license-building a Ukrainian version of the PAC-3. But such an agreement would not produce usable missiles until 2030.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The White House &lt;a href="https://www.reuters.com/business/aerospace-defense/us-presses-with-ukraine-patriot-missile-talks-sources-say-despite-trumps-doubts-2026-08-05/"&gt;has gone back and forth&lt;/a&gt; on the issue. But Ukraine has gotten further with President Donald Trump than it did with his predecessor, Zelenskyy &lt;a href="https://mezha.net/eng/bukvy/e320aa61_zelensky_asks_us_to/"&gt;said&lt;/a&gt; in May: &amp;ldquo;I started this conversation with President Biden and I will continue with President Trump. Ukraine has not received a license to manufacture PAC-3. I believe that in the future, perhaps we will obtain one or there will be our own system.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/08/05/GettyImages_2279853774/large.jpg" width="618" height="284"><media:description>A man poses for a photo next to a fallen rocket half-buried in the ground on the outskirts of Jericho on June 8, 2026, following Iranian and Iran-backed Houthi rebel attacks.</media:description><media:credit>AHMAD GHARABLI / AFP via Getty Images</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/08/05/GettyImages_2279853774/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Chinese telecoms kept footholds in US despite crackdowns, probe finds</title><link>https://www.defenseone.com/threats/2026/08/chinese-telecoms-crackdowns-probe/415208/</link><description>Three state-owned firms retained equipment, data center space, and network ties, including one network that appeared in routes to Salt Typhoon servers.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Tue, 04 Aug 2026 16:00:00 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/08/chinese-telecoms-crackdowns-probe/415208/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;Years after federal regulators invoked national security to push three Chinese state-owned telecommunications providers out of the American market, the companies never fully left, a new House probe has found.&lt;/p&gt;

&lt;p&gt;China Telecom, China Mobile, and China Unicom retained equipment, data-center space and connections to other networks in the United States after the Federal Communications Commission denied or revoked their authority to provide certain telecommunications services, according to a nearly 50-page bipartisan House China Committee investigation planned for release Tuesday and first seen by &lt;em&gt;Nextgov/FCW&lt;/em&gt;.&lt;/p&gt;

&lt;p&gt;From 2019 to 2022, the FCC denied China Mobile USA&amp;rsquo;s application to provide international service; it revoked&amp;nbsp; related authorizations held by China Telecom Americas and China Unicom Americas. But those actions did not require the companies to remove equipment, leave data centers,&amp;nbsp;or sever private network links, so the carriers continued offering enterprise networking, internet transit and other services, the panel found.&lt;/p&gt;

&lt;p&gt;The committee argues that those remaining footholds could give Beijing&amp;rsquo;s cyberspies visibility into sensitive traffic, help keep malicious infrastructure online and create opportunities to reroute data or reach U.S. targets. American officials regard China as the country&amp;rsquo;s leading cyber adversary, with a record of targeting critical infrastructure and stealing military, commercial and personal data.&lt;/p&gt;

&lt;p&gt;The three carriers did not respond to detailed requests for comment.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Nextgov/FCW&lt;/em&gt; also sought comment from the FBI, the Cybersecurity and Infrastructure Security Agency, and several U.S. spy agencies. The Defense Intelligence Agency, which produces intelligence findings for the Pentagon, declined to comment.&lt;/p&gt;

&lt;p&gt;A spokesperson for China&amp;rsquo;s embassy in Washington said Beijing &amp;ldquo;firmly opposes the U.S. overstretching the concept of national security and going after Chinese companies,&amp;rdquo; adding that China would defend its &amp;ldquo;legitimate and lawful rights and interests.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The remaining network ties took on added significance in the committee&amp;rsquo;s review of Salt Typhoon, the sweeping Chinese &lt;a href="https://www.nextgov.com/cybersecurity/2025/08/salt-typhoon-hackers-targeted-over-80-countries-fbi-says/407719/"&gt;espionage campaign&lt;/a&gt; uncovered in 2024 where hackers breached major telecom carriers in the United States and abroad. The intrusion reached systems used to comply with court-authorized wiretap requests and allowed the cyberspies to target the communications of senior U.S. officials, including President Donald Trump and Vice President JD Vance.&lt;/p&gt;

&lt;p&gt;Reviewing routing data from Sept. 22 to 25, 2024, just as the Salt Typhoon campaign &lt;a href="https://www.wsj.com/politics/national-security/china-cyberattack-internet-providers-260bd835"&gt;became public&lt;/a&gt;, the committee identified 58 groups of internet addresses that CISA had linked to Salt Typhoon servers. China Mobile International&amp;rsquo;s network appeared in routes to those servers at least 192 times, helping keep the attacker infrastructure reachable as U.S. defenders sought to shut it down, the report said.&lt;/p&gt;

&lt;p&gt;The committee does not allege that China Mobile USA employees knew about or participated in the campaign, and it says the routing evidence does not definitively link the company to Salt Typhoon. But the panel argues that the overlap shows how China Mobile&amp;rsquo;s remaining network ties could help sustain malicious infrastructure.&lt;/p&gt;

&lt;p&gt;That finding came from a broader analysis that identified nearly 109,000 incidents from January 2018 through May 2025 in which Chinese or Hong Kong-linked networks allegedly claimed U.S. internet addresses without authorization, potentially diverting American traffic through their systems. The committee classified them as high-confidence &lt;a href="https://www.nextgov.com/cybersecurity/2024/09/white-house-plan-looks-secure-foundational-piece-global-internet/399239/"&gt;hijacks&lt;/a&gt; of the Border Gateway Protocol, a bedrock system that directs traffic across networks, but acknowledged that some may have resulted from mistakes or poor network management.&lt;/p&gt;

&lt;p&gt;More than 4,200 of the incidents involved China Mobile-controlled networks. In September 2024, eight originated from the same network that appeared in routes to Salt Typhoon servers and diverted traffic belonging to unnamed U.S. network operators, the committee said.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Addressing the threat&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Telecommunications networks have long been prized intelligence targets because they can expose private conversations and reveal what political and diplomatic leaders are thinking. Such concerns are compounded by China&amp;rsquo;s 2017 National Intelligence Law, which requires companies and citizens to assist state intelligence work. Beijing denies that the law compels companies to participate in illegal espionage.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;China&amp;rsquo;s state telecommunications carriers for too long have enjoyed non-reciprocal access to U.S. domestic networks, but the seriousness of Salt Typhoon gives the FCC and other agencies more than enough justification to restrict or expel them,&amp;rdquo; said James Mulvenon, a leading authority on Chinese national security issues and vice president of intelligence at risk advisory firm Pamir Consulting.&lt;/p&gt;

&lt;p&gt;The committee recommends giving federal agencies greater authority over equipment and private network arrangements that remain after a license revocation, along with targeted removal funding, stronger routing protections and logging requirements for foreign-controlled operators.&lt;/p&gt;

&lt;p&gt;Marc Rogers, a veteran telecommunications expert who helped develop the mobile internet in the 2000s and has spent roughly two decades consulting governments and companies on telecom cybersecurity, agreed with many of the panel&amp;rsquo;s recommendations. Those include treating core telecom systems as high-risk targets requiring closer oversight, strengthening checks on how traffic moves across networks and tightening rules on the foreign-made equipment U.S. carriers can use.&lt;/p&gt;

&lt;p&gt;But Rogers disputed the panel&amp;rsquo;s call to expand &amp;ldquo;rip and replace&amp;rdquo;&amp;nbsp;telecom equipment, calling&amp;nbsp;such programs&amp;nbsp; economically unrealistic and could&amp;nbsp;disrupt carrier operations.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;On paper it sounds great, until you get someone with operational experience,&amp;rdquo; Rogers said. &amp;ldquo;Then they realize you&amp;rsquo;re basically talking about bulldozing an entire city and building a new one.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Rogers also said the panel&amp;rsquo;s recommendations resemble measures in British &lt;a href="https://www.osborneclarke.com/insights/regulatory-outlook-june-2026-telecoms"&gt;telecom security law&lt;/a&gt; but warned that they would work only if countries act together.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;If only one country takes a strong position, China will just maneuver around them,&amp;rdquo; he said, adding that the proposals are largely aimed at tactics China has already used. Policymakers should learn from those incidents, Rogers said, while also preparing for how Beijing&amp;rsquo;s methods may evolve.&lt;/p&gt;

&lt;p&gt;The findings underscore the difficulty of removing operators deemed national security risks from a telecommunications ecosystem built on private infrastructure and decades of commercial ties. Regulators can ban specific services without necessarily reaching the equipment, leases and private agreements that preserve connectivity.&lt;/p&gt;

&lt;p&gt;The committee based its report on subpoenaed company records, eight interviews conducted under oath, federal records, routing data and network infrastructure scans. It said Cloudflare and unnamed outside cybersecurity experts independently reviewed and verified portions of its routing analysis.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Parent company control and U.S. footprint&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Across all three companies, the committee found U.S. subsidiaries that remained dependent on parent or affiliate entities in China or Hong Kong for important technical and operational functions while retaining equipment and network connections inside the United States.&lt;/p&gt;

&lt;p&gt;At China Telecom Americas, requests involving connections between U.S. and overseas networks were handled by personnel in Shanghai, Hong Kong or Beijing, according to testimony cited in the report. Service orders could also flow through a parent-controlled system to Shanghai Telecom without a separate contract. The U.S. subsidiary did not keep independent traffic-flow records, leaving employees unable to determine whether a parent or affiliate had changed routes involving equipment in the United States.&lt;/p&gt;

&lt;p&gt;China Telecom Americas identified 10 active points of presence &amp;mdash; sites where a carrier keeps equipment and connects with other networks &amp;mdash; across seven metropolitan areas. A senior engineering official also told the committee that about a quarter of the company&amp;rsquo;s U.S. transmission hardware was still made by Huawei, whose equipment the FCC has deemed a national security risk.&lt;/p&gt;

&lt;p&gt;China Mobile USA, meanwhile, was described by one witness as &amp;ldquo;basically a sales team,&amp;rdquo; while another said it had no network engineers. Orders for data center space and network connections were approved at its Hong Kong headquarters, and witnesses could not identify a network operations team based elsewhere.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Despite this, China Mobile USA&amp;rsquo;s records contained 39 point-of-presence entries across 27 data-center and interconnection facilities. The committee said those sites connected it to carrier backbones, internet exchanges and private networks used by major U.S. technology companies. Investigators identified at least 143 active China Mobile network assets in U.S. facilities.&lt;/p&gt;

&lt;p&gt;China Unicom Americas disclosed that seven of its eight directors and two of its three senior managers were Chinese Communist Party members. Its U.S. employees used parent-controlled email and computer systems, and evidence indicated that they operated under cybersecurity, administrative and privacy policies issued by China Unicom Global.&lt;/p&gt;

&lt;p&gt;A compliance official told the report&amp;rsquo;s authors the subsidiary could guarantee its own adherence to U.S. law, but not its parent&amp;rsquo;s.&lt;/p&gt;

&lt;p&gt;A China Unicom Americas compliance official also acknowledged that the subsidiary did not know the identities of some third parties in China that ultimately received services ordered through China Unicom Global. The company had equipment and active connections in roughly 10 U.S. data centers.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Other carrier relations&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The report also describes relationships between the three Chinese carriers and companies linked by U.S. authorities to Chinese hacking operations.&lt;/p&gt;

&lt;p&gt;China Mobile, in one case, acted as a middleman for CloudRadium, a Hong Kong hosting provider whose infrastructure has repeatedly surfaced in malicious cyber activity, the committee said. Subpoenaed records showed that China Mobile purchased U.S. data center space and network connections on CloudRadium&amp;rsquo;s behalf, including through a four-year contract valued at $480,000.&lt;/p&gt;

&lt;p&gt;The report also links CloudRadium to a Wyoming company of the same name and GlobalData Investments, a California corporation that markets hosting and data center services under the CeraNetworks name. &lt;em&gt;Nextgov/FCW&lt;/em&gt; found that the companies&amp;rsquo; websites used similar logos, layouts and animations. An email sent to an address listed for Steven Beals, identified online as GlobalData Investments&amp;rsquo; chief operating officer, was returned as undeliverable.&lt;/p&gt;

&lt;p&gt;The committee also details China Unicom&amp;rsquo;s relationships with Integrity Technology Group and i-SOON, two Chinese cybersecurity contractors U.S. authorities have linked to state-backed hacking.&lt;/p&gt;

&lt;p&gt;A 2024 &lt;a href="https://media.defense.gov/2024/Sep/18/2003547016/-1/-1/0/CSA-PRC-LINKED-ACTORS-BOTNET.PDF"&gt;U.S. advisory&lt;/a&gt; identified Integrity Tech infrastructure as the control layer for a botnet of compromised routers and other internet-connected devices operated by Flax Typhoon, a Chinese state-sponsored hacking group. China Unicom Beijing network addresses were used to manage the botnet and connect it to other attack infrastructure and, according to the committee&amp;rsquo;s report, China Unicom and Integrity Tech formalized a cooperation agreement in November 2023 while the botnet was operating.&lt;/p&gt;

&lt;p&gt;China Unicom separately appeared as a corporate partner of i-SOON. The company &lt;a href="https://unit42.paloaltonetworks.com/i-soon-data-leaks/"&gt;drew international scrutiny&lt;/a&gt; after a large collection of purported internal documents appeared on GitHub in 2024, exposing details about its hacking tools, targets and work for Chinese police and intelligence agencies.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The Justice Department later &lt;a href="https://www.justice.gov/opa/pr/justice-department-charges-12-chinese-contract-hackers-and-law-enforcement-officers-global"&gt;charged&lt;/a&gt; eight i-SOON employees and two Chinese police officers in a years-long hacking campaign, alleging that the company worked with at least 43 intelligence or police bureaus. The charges have not been proven in court.&lt;/p&gt;

&lt;p&gt;Integrity Tech&amp;rsquo;s website was unavailable when &lt;em&gt;Nextgov/FCW&lt;/em&gt; attempted to contact the company, and a functioning corporate website for i-SOON could not be located.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;China has been conducting an escalating campaign of cyberattacks on U.S. networks as a form [of] operational preparation of the battlefield,&amp;rdquo; said Jack Burnham, a senior research analyst in the China Program at the Foundation for Defense of Democracies whose work focuses on China&amp;rsquo;s military, emerging technologies and science and technology policy.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Key to these efforts is Beijing&amp;rsquo;s capacity to access core domestic networks, either via installed equipment, routing relationships, or other interconnections,&amp;rdquo; Burnham said. &amp;ldquo;While the FCC has sought to tamp down on Chinese state-owned telecoms firms that pose a national security threat, there is clearly more work to be done, both in terms of regulation and rip-and-replace, to properly handle these threats.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/08/04/080326ChinaNG/large.jpg" width="618" height="284"><media:credit>Thomas Faull/Getty Images</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/08/04/080326ChinaNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>OPM breach victims could get identity protection for life</title><link>https://www.defenseone.com/threats/2026/08/lawmakers-propose-giving-2015-opm-breach-victims-identity-protection-life/415191/</link><description>The federal government’s coverage for 22.1 million people hoovered up in the 2015 China-linked breaches is scheduled to end Sept. 30.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Mon, 03 Aug 2026 09:00:00 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/08/lawmakers-propose-giving-2015-opm-breach-victims-identity-protection-life/415191/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;Federal employees and contractors whose sensitive personal data was stolen in the massive Office of Personnel Management breaches disclosed a decade ago would receive identity protection for the rest of their lives under new bicameral legislation.&lt;/p&gt;

&lt;p&gt;Senate Intelligence Committee Vice Chair Mark Warner, D-Va., and Del. Eleanor Holmes Norton, D-D.C., plan to introduce the RECOVER PII Act on Monday, aiming to prevent the federal government&amp;rsquo;s identity-protection program for victims from expiring Sept. 30, according to bill text first seen by &lt;em&gt;Nextgov/FCW&lt;/em&gt;. Sens. Tim Kaine, D-Va.; Angela Alsobrooks, D-Md.; and Chris Van Hollen, D-Md., are also Senate cosponsors.&lt;/p&gt;

&lt;p&gt;Just over 10 years after the OPM breaches compromised personal information belonging to roughly 22 million people, the identity-protection services provided to affected federal workers, contractors and their families have &lt;a href="https://www.govexec.com/management/2026/05/10-years-after-opm-breach-identity-protection-services-affected-feds-expire/413336/"&gt;begun expiring&lt;/a&gt;. People who enrolled in OPM&amp;rsquo;s MyIDCare program are receiving notices that their complimentary coverage will end 10 years after their individual enrollment date. Some notices began arriving late last year and will continue through September, when OPM plans to conclude the services at the end of the federal fiscal year.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;More than ten years after the OPM data breach exposed the personal information of millions of federal employees, the threat remains,&amp;rdquo; Warner said in the statement. &amp;ldquo;The data stolen included workers&amp;rsquo; most sensitive and personal information &amp;mdash; from Social Security numbers to security clearance records &amp;mdash; and once that information is in the hands of a bad actor, you don&amp;rsquo;t get it back.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The two breaches compromised information belonging to some 22.1 million current, former and prospective federal employees, contractors and others. One intrusion exposed personnel records for roughly 4.2 million people, while a second compromised 21.5 million background-investigation records. About 3.6 million people were affected in both incidents, according to the Government Accountability Office.&lt;/p&gt;

&lt;p&gt;Foreign intelligence services can hold onto these OPM records for years, combine them with information from other cyber intrusions and use the fuller picture to identify or target government personnel and their families.&lt;/p&gt;

&lt;p&gt;Those risks can also grow over time. Data stolen from a lower-level employee in 2015 could become far more valuable if that person later moves into a more sensitive national security role. GAO warned last year that adversaries can &lt;a href="https://www.gao.gov/products/gao-26-108771"&gt;combine publicly available data&lt;/a&gt; to identify military personnel and their families or disrupt Defense Department operations.&lt;/p&gt;

&lt;p&gt;Congress responded to the breach in a 2017 appropriations law by requiring OPM to provide victims with at least 10 years of complimentary identity protection and no less than $5 million in identity-theft insurance. The new bill would replace that limit with coverage lasting for the remainder of each affected person&amp;rsquo;s life while retaining the insurance requirement.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We have a responsibility to stand by the federal workers who were put at risk through no fault of their own,&amp;rdquo; Warner said. &amp;ldquo;This legislation will ensure those affected continue to receive the identity protection they need, while helping better safeguard personal information from future exploitation.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The bill would also allow agencies to reimburse federal employees and contractors for privacy tools and services, such as those that remove or limit their personal information online. Agencies would decide whether to offer the reimbursements, which would not be limited to OPM breach victims and would come from their salary-and-expense budgets.&lt;/p&gt;

&lt;p&gt;Norton has &lt;a href="https://www.congress.gov/bill/118th-congress/house-bill/7236/text"&gt;introduced&lt;/a&gt; legislation in the past seeking lifetime protection for OPM victims, beginning after the breaches were disclosed. Similar bills introduced over the years have not become law.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Lifetime identity protection is the only solution that will give the workers whose data was compromised the peace of mind they deserve,&amp;rdquo; Norton said in a statement. &amp;ldquo;Because there is no limit on how long personal information can be exploited, Congress must protect these federal employees and contractors in perpetuity. Thank you to Senator Warner for working with me to secure this vital protection for those affected.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/08/04/080226WarnerNG/large.jpg" width="618" height="284"><media:description>Sen. Mark Warner (D-VA) speaks at the confirmation hearing for Jay Clayton before the Senate Intelligence Committee during his nomination hearing on Capitol Hill July 15, 2026 in Washington, DC.</media:description><media:credit>Aaron Schwartz / Getty Images</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/08/04/080226WarnerNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Amazon uncovers broad North Korean hacking campaign against open-source software</title><link>https://www.defenseone.com/threats/2026/07/amazon-uncovers-broad-north-korean-hacking-campaign-against-open-source-software/415110/</link><description>New findings connect the same Pyongyang-backed group to four compromises dating to 2025, revealing a larger operation than previously known.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Wed, 29 Jul 2026 14:58:00 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/07/amazon-uncovers-broad-north-korean-hacking-campaign-against-open-source-software/415110/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;A North Korea-linked hacker group has been tied to four open-source software compromises dating back to March 2025, Amazon researchers said Wednesday, significantly expanding the publicly known scope of Pyongyang&amp;rsquo;s efforts to use trusted code to reach large numbers of potential victims and gain access to companies&amp;rsquo; systems.&lt;/p&gt;

&lt;p&gt;The assessment for the first time links the same financially-motivated hacking group to compromises of four major JavaScript packages&amp;mdash;typo-crypto, debug, chalk and axios&amp;mdash;that developers use as building blocks for other software. The axios package alone receives more than 100 million downloads each week, and its compromise had &lt;a href="https://www.nextgov.com/cybersecurity/2026/03/north-korea-linked-hackers-suspected-axios-open-source-hijack-google-analysts-say/412523/"&gt;previously been attributed&lt;/a&gt; to the North Korean group.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Amazon said Wednesday that it had uncovered evidence connecting the actor to the three earlier incidents, based on technical findings that included instances of reused code and similarities in how the attacks were carried out.&lt;/p&gt;

&lt;p&gt;Amazon Threat Intelligence attributed the campaigns to the group with &amp;ldquo;medium confidence,&amp;rdquo; according a blog post authored by Amazon Integrated Security CISO CJ Moses scheduled for release Wednesday evening. The cyber intruders are tracked by researchers under several names, including Sapphire Sleet, Stardust Chollima, BlueNoroff, CageyChameleon and Alluring Pisces.&lt;/p&gt;

&lt;p&gt;In each incident, the hackers tricked a trusted software maintainer and used the access to publish an update containing malicious code, according to Amazon. Organizations configured to automatically download the latest version of those packages may have pulled the compromised updates directly into their systems. The approach allows hackers to compromise a small number of widely used packages while potentially gaining access to thousands of downstream systems, making it more efficient than targeting organizations individually.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Open-source software&amp;mdash;code that can be freely inspected, modified and reused&amp;mdash;underpins operating systems, web servers, encryption tools and many of the applications businesses rely on daily all over the world. The projects often depend on volunteer maintainers to review proposed changes, fix security flaws and publish updates.&lt;/p&gt;

&lt;p&gt;That model relies heavily on trust. Attackers can spend weeks or months posing as legitimate contributors, fixing bugs and building relationships before attempting to gain control of an established project or publishing a malicious update.&lt;/p&gt;

&lt;p&gt;That dynamic drew &lt;a href="https://www.nextgov.com/cybersecurity/2024/04/linux-backdoor-was-long-con-possibly-nation-state-support-experts-say/395511/"&gt;widespread attention&lt;/a&gt; in 2024, when an account operating under the name &amp;ldquo;Jia Tan&amp;rdquo; spent years gaining the trust of other developers before attempting to insert a backdoor into XZ Utils, a widely used data-compression tool included in numerous Linux distributions. The backdoor was discovered before it could be broadly deployed.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Quite frankly, the open-source community is looking for good citizens because these packages are often not maintained by people who are getting paid to do that as a full-time job,&amp;rdquo; Rick Anthony, senior manager for Amazon&amp;rsquo;s Inspector vulnerability management service, told reporters in Arlington, Va. on Wednesday. &amp;ldquo;They are very welcoming for anyone who is willing to contribute.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;North Korea has long treated cyber operations as both an intelligence tool and a source of revenue. Its hackers steal cryptocurrency, conduct espionage and extort victims, while operatives posing as remote IT workers obtain jobs at foreign companies and quietly funnel their salaries back to the regime. Amazon is among those companies, executives said Wednesday. U.S. officials say the proceeds help Pyongyang evade sanctions and finance its nuclear weapons and ballistic missile programs.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;For a sanctions-constrained regime, generating revenue through these operations means that the greater the efficiency, the more money they get, and the more that they can use that money to do things that got them the sanctions to begin with,&amp;rdquo; Moses told reporters. &amp;ldquo;One successful supply chain compromise can yield access to hundreds, if not more, targeted intrusions.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The findings also illustrate how open-source attacks are becoming harder to detect.&lt;/p&gt;

&lt;p&gt;Amazon said attackers are increasingly dividing a malicious operation among several packages that appear harmless when reviewed individually. One package may contain encrypted data, another the code needed to unlock it and a third the instructions to download and execute the final payload. The malicious behavior becomes visible only when the components are used together.&lt;/p&gt;

&lt;p&gt;AI is also making malicious software harder to spot, the blog warned. Hackers can use it to create polished-looking code, convincing documentation and fake developer profiles, eliminating many of the obvious mistakes that once raised red flags.&lt;/p&gt;

&lt;p&gt;Attackers can also exploit errors made by AI coding assistants. If an AI tool recommends a software package that does not exist, hackers can register the name and load it with malware, hoping a developer or automated system will download it without realizing the recommendation was wrong.&lt;/p&gt;

&lt;p&gt;Concerns about open-source software security have increasingly drawn attention in Washington. In December, the chairman of the Senate Intelligence Committee asked the White House national cyber director to &lt;a href="https://www.nextgov.com/cybersecurity/2025/12/sen-cotton-urges-top-white-house-cyber-official-protect-open-source-software/410264/?oref=ng-topic-lander-top-story"&gt;take steps&lt;/a&gt; to address vulnerabilities in open-source projects that help power systems used throughout U.S. military and civilian agencies.&lt;/p&gt;

&lt;p&gt;Last August, &lt;em&gt;Nextgov/FCW&lt;/em&gt; &lt;a href="https://www.nextgov.com/cybersecurity/2025/08/report-russia-based-yandex-employee-oversees-open-source-software-approved-dod-use/407703/"&gt;first reported&lt;/a&gt; that an employee of the Russian technology company Yandex was the sole maintainer of a widely used open-source tool embedded in at least 30 pre-built software packages available to the Defense Department.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/07/29/072926NKoreaNG-1/large.jpg" width="618" height="284"><media:credit>Matt Anderson Photography / Getty Images</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/07/29/072926NKoreaNG-1/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>‘Game of Thrones’ as Ukraine’s president, defense minister split</title><link>https://www.defenseone.com/threats/2026/07/game-thrones-ukraines-president-defense-minister-split/415009/</link><description>The largest government crisis since 2022 shows Ukrainian reform and democracy efforts are as rough and uneven as democracy itself.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Patrick Tucker</dc:creator><pubDate>Sat, 25 Jul 2026 18:34:44 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/07/game-thrones-ukraines-president-defense-minister-split/415009/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;Street protests &lt;a href="https://www.pravda.com.ua/eng/news/2026/07/24/8045795/"&gt;continued&lt;/a&gt; across Ukraine for a tenth day on Saturday in support of former defense minister Mykhailo Fedorov, whom President Volodymyr Zelenskyy fired and then attempted to placate with &lt;a href="https://x.com/ChristopherJM/status/2080262175218634987"&gt;offers&lt;/a&gt; of different jobs. Fedorov is having none of it, &lt;a href="https://united24media.com/war-in-ukraine/mykhailo-fedorov-says-he-will-accept-only-the-post-of-ukraines-defense-minister-21019"&gt;saying&lt;/a&gt; on Thursday, &amp;nbsp;&amp;ldquo;I will not accept any position other than Minister of Defense. No other role carries the actual authority to combat procurement corruption.&amp;rdquo; The rift has exposed rival factions at the center of Ukrainian leadership, pulling the country in opposite directions as it fights for its existence. &amp;ldquo;Game of Thrones&amp;rdquo; is how one former senior Ukrainian military official described it, and its outcome will shape the futures of Ukraine&amp;rsquo;s war effort and the country itself.&lt;/p&gt;

&lt;p&gt;On July 15, Zelensky &lt;a href="https://www.defenseone.com/policy/2026/07/ukraine-defense-minister-firing-protests/414836/"&gt;fired&lt;/a&gt; Fedorov, his third defense minister, for feuding with his military commander-in-chief, Gen. Oleksandr Syrskyi. He first &lt;a href="https://news.liga.net/en/politics/news/zelenskyy-offered-klymenko-the-position-of-secretary-of-the-national-security-and-defense-council"&gt;offered the job&lt;/a&gt; to Interior Minister&lt;a href="https://www3.nhk.or.jp/nhkworld/en/news/20260718_N01/"&gt; Ihor Klymenko&lt;/a&gt; but less than a day later appointed Maj. Gen. &lt;a href="https://www.politico.eu/article/volodymyr-zelenskyy-appoints-new-acting-defense-minister/"&gt;Yevhenii Khmara&lt;/a&gt;. Zelensky spent the weekend in meetings with frontline commanders. On Tuesday, he &lt;a href="https://thehill.com/policy/international/5983647-zelensky-fires-general-syrskyi-military/"&gt;replaced&lt;/a&gt; Syrskyi with Maj. Gen. &lt;a href="https://www.ukrinform.net/amp/rubric-polytics/4147727-khmara-introduces-drapatyi-and-skybiuk-to-general-staff-leadership.html"&gt;Mykhailo Drapatyi&lt;/a&gt;. Khmara and Drapatyi are highly respected, non-controversial selections. But the decision-making process that brought them to their new positions continues to stir controversy.&lt;/p&gt;

&lt;p&gt;Street protests, ignited just hours after news of Fedorov&amp;rsquo;s firing broke, grew throughout the week. At least one senior military official has &lt;a href="https://kyivindependent.com/ukraines-air-force-deputy-commander-announces-resignation-over-fedorovs-dismissal/"&gt;resigned in solidarity&lt;/a&gt;. A Tuesday &lt;a href="https://kyivindependent.com/ex-defense-minister-fedorovs-approval-rating-soars-by-30-amid-protests-poll-shows/"&gt;poll &lt;/a&gt;shows that 72 percent of the country disapproves of the former minister&amp;rsquo;s forced removal, and perceptions of Fedorov as trustworthy have surged from 35 percent to 65 percent in a matter of days. (Zelensky&amp;rsquo;s trust rating moved from 54 to 59 percent.)&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;People aren&amp;rsquo;t marching to save Fedorov,&amp;rdquo; Olena Tregub, a former Ukrainian government official turned anti-corruption activist, &lt;a href="https://x.com/OTregub/status/2078054782531440654"&gt;wrote&lt;/a&gt; on July 17. &amp;ldquo;They&amp;rsquo;re marching because they fear losing the hope that Ukraine can do better.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The Ballad of Misha&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;To many Ukrainians, Fedorov symbolizes aspirations for their post-Soviet country: innovation, meritocracy, entrepreneurialism, technological disruption, and especially the fight against corruption.&lt;/p&gt;

&lt;p&gt;At 35, Fedorov was Ukraine&amp;rsquo;s youngest-ever defense minister. In his public appearances, the former software and media entrepreneur wears the Silicon Valley startup uniform: a T-shirt, jeans, and sneakers. But &amp;ldquo;Misha,&amp;rdquo; as he is widely known, has been a key player in government since 2019. Serving as the head of Ministry of Digital Transformation, he led its transition to digital record-keeping, driving the expansion of broadband infrastructure across the country, and developing deep relationships with Western tech companies such as Microsoft.&lt;/p&gt;

&lt;p&gt;Following the Estonian &lt;a href="https://www.defenseone.com/technology/2023/05/ukraine-usaid-created-blueprint-digital-citizenship-now-theyre-exporting-it/386720/"&gt;e-residency model&lt;/a&gt;, Fedorov built out online government services and deepened the resiliency of the nation&amp;#39;s institutions and citizen records. When Russia launched its full-scale invasion in 2022, these digitization efforts helped ensure the continuity of government services &lt;a href="https://www.defenseone.com/technology/2023/05/ukraine-usaid-created-blueprint-digital-citizenship-now-theyre-exporting-it/386720/"&gt;essential &lt;/a&gt;to the country&amp;#39;s survival and economic stability.&lt;/p&gt;

&lt;p&gt;By making government records easily accessible to the public, Federov&amp;rsquo;s digitization push also helped Ukraine battle corruption with transparent and traceable record-keeping in military acquisition. That helped keep Western aid, including military assistance, flowing into the country, and is central to Ukraine&amp;rsquo;s bid to join the European Union.&lt;/p&gt;

&lt;p&gt;As war suffused the country in 2022, he stood up new government entities like the &lt;a href="https://portugal.mfa.gov.ua/en/news/ukraine-assembling-army-drones"&gt;Army of Drones&lt;/a&gt; procurement program and the &lt;a href="https://digitalstate.gov.ua/projects/tech/brave1"&gt;Brave1 &lt;/a&gt;platform for coordination between industry and government. He pushed for reforms on government profit caps so that Ukrainian drone manufacturers could earn a 25-percent margin, creating a Ukrainian defense ecosystem that many in Europe and even the Pentagon &lt;a href="https://www.defenseone.com/policy/2025/07/drones-are-now-bullets-how-new-pentagon-policy-may-accelerate-robot-warfare/406686/"&gt;are now copying&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;He used his personal relationship with SpaceX founder Elon Musk &lt;a href="https://www.defenseone.com/technology/2023/03/black-swan-starlinks-unexpected-boon-ukraines-defenders/383514/"&gt;to secure &lt;/a&gt;the use of the Starlink satellite-communications service, which quickly became vital to battlefield command and control and has since enabled drone strikes across Ukraine. He also pushed to develop AI tools, such as &lt;a href="https://cepa.org/article/the-heart-of-war-ukraines-key-battlefield-system/"&gt;Delta,&lt;/a&gt; to improve coordination and control of battlefield drones.&lt;/p&gt;

&lt;p&gt;In January, Fedorov was appointed defense minister and quickly proposed&lt;a href="https://www.youtube.com/watch?v=DX-aX-DlpV0"&gt; reforms&lt;/a&gt;: financial incentives for military enlistment, a more institutionalized approach to recruiting foreign volunteers, and support for remote-warfare ideas that reduce the risks faced by Ukrainian soldiers. His vision included a &lt;a href="https://www.defenseone.com/technology/2026/05/ukrainian-ground-robot-defended-position-russian-assault-six-weeks/413642/"&gt;far more roboticized&lt;/a&gt; front line. When this drew resistance from Syrskyi, the military commander-in-chief, Fedorov began directing funds away from conventional munitions and personnel and toward companies and projects that better reflected his preferred approach.&lt;/p&gt;

&lt;p&gt;Serious challenges for Ukraine, including Russia&amp;rsquo;s &lt;a href="https://www.cnn.com/2026/02/02/europe/spacex-starlink-russian-drones-latam-intl"&gt;unauthorized use of Starlink&lt;/a&gt;, were also addressed quickly and effectively during Fedorov&amp;rsquo;s tenure.&lt;/p&gt;

&lt;p&gt;Very quickly, the trajectory of the war shifted. Ukraine &lt;a href="https://www.defenseone.com/technology/2026/06/ukraine-robots-winning/413902/"&gt;halted&lt;/a&gt; and in some cases reversed Russia&amp;rsquo;s battlefield gains while risking fewer human lives.&lt;/p&gt;

&lt;p&gt;One Ukrainian military analyst described Fedorov&amp;rsquo;s reforms as delivering &amp;ldquo;a comprehensive vision of how the war should be fought.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;But at least some thought Fedorov was overstepping his legal purview. One former senior Ukrainian military official said that the defense minister was seeking to assert control over areas of responsibility that belong strictly to the office of the commander-in-chief.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Under Ukrainian law and NATO standards, the Minister of Defense exercises civilian democratic oversight of the Armed Forces&amp;mdash;but has no authority to conduct operations or plan military action. His job is ensuring the Armed Forces get what they need,&amp;rdquo; the former official said.&lt;/p&gt;

&lt;p&gt;Not everyone agrees that Ukrainian law defines the roles of defense minister and military chief so rigidly.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Ukraine&amp;rsquo;s minister of defense is expected to ask difficult questions and evaluate whether the military system is functioning effectively. This means analyzing the broader strategic picture rather than commanding troops on the battlefield or directing military strategy. The goal is to ensure that Ukraine&amp;rsquo;s defense system is constantly learning, adapting, and improving,&amp;rdquo; Tregub, the official-turned-activist, &lt;a href="https://www.atlanticcouncil.org/blogs/ukrainealert/civilian-control-over-the-armed-forces-is-crucial-for-ukraines-future/"&gt;wrote&lt;/a&gt; on July 21.&lt;/p&gt;

&lt;p&gt;Fedorov also believed that his job included exposing defense ministry business practices and staff that operated to the benefit of a small handful of insiders.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;In a press briefing the day after he was fired as defense minister, Fedorov &lt;a href="https://www.pravda.com.ua/eng/news/2026/07/16/8044357/"&gt;defended&lt;/a&gt; his actions.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We also discovered department heads within the MoD who were effectively appointed by private companies. They wouldn&amp;#39;t even attend MoD meetings without being accompanied by specific law-enforcement officers. We systematically fired them,&amp;rdquo; he said. &amp;ldquo;We once investigated a direct contract with a massive 200% to 300% profit margin linked to a well-known individual living outside Ukraine.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The Butcher&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;If &amp;ldquo;Misha&amp;rdquo; represents many Ukrainians&amp;rsquo; hopes for their future, Syrskyi resembles its past. As a young Soviet Army cadet, Syrskyi studied at Moscow&amp;rsquo;s Higher Military Command School; many see in him the face of Soviet bureaucracy and obsolete military thinking.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;As a Ukrainian colonel-general in 2022, Syrskyi led the ultimately futile effort to hold the city of Bakhmut by sending waves of soldiers against advancing Russian forces, earning him the nickname&lt;a href="https://www.thetimes.com/world/russia-ukraine-war/article/butcher-general-oleksandr-syrskyi-ukraine-zelensky-xcvdxz9v7"&gt; &amp;ldquo;The Butcher.&amp;rdquo;&lt;/a&gt; Still, two former senior military officers said they credit him with keeping Russian gains in check&amp;mdash;and they added that he is as tough on himself as he is on his subordinates.&lt;/p&gt;

&lt;p&gt;In 2024, Syrskyi&amp;mdash;a close Zelenskyy loyalist&amp;mdash;was appointed commander-in-chief after the president &lt;a href="https://www.cnn.com/2024/01/31/europe/zaluzhny-oust-ukraine-army-zelensky-intl"&gt;fell out&lt;/a&gt; with Gen. Valerii Zaluzhnyi, (who holds a higher approval rating among Ukrainians.)&lt;/p&gt;

&lt;p&gt;But Zelensky also &lt;a href="https://www.pravda.com.ua/eng/news/2026/07/16/8044451/"&gt;remained close&lt;/a&gt; to Andrii Yermak, his political &amp;quot;&lt;a href="https://www.nytimes.com/2026/06/01/world/europe/ukraine-corruption-yermak-zelensky.html"&gt;muscle&lt;/a&gt;&amp;quot; and longtime chief of staff. Last November, Yermak was forced to step down by corruption charges, but has remained influential among high-ranking officials.&lt;/p&gt;

&lt;p&gt;As one former senior Ukrainian defense official put it, &amp;ldquo;Syrskyi is a Yermak man.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;A malevolent force&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;For many Ukrainians, particularly younger ones, corruption is almost a phantom, malevolent force. Moscow has &lt;a href="https://www.bushcenter.org/publications/strategic-corruption-russia-in-europe"&gt;long used&lt;/a&gt; bribes, officials, secret deals, and off-the-books transactions to weaken Ukraine&amp;rsquo;s public institutions and bend them to its will. That was especially true during the presidency of &lt;a href="https://transparency.eu/corruption-opulence-and-decadence-in-ukraine/"&gt;Viktor Yanukovych,&lt;/a&gt; a staunch ally of Russian leader Vladimir Putin.&lt;/p&gt;

&lt;p&gt;The 2014 &amp;ldquo;Revolution of Dignity&amp;rdquo; that ousted Yanukovych was as much an exorcism of corruption as it was an ejection of Russian imperial control. The two concepts are intimately bound for many Ukrainians.&lt;/p&gt;

&lt;p&gt;Yanukovych lives in a Moscow suburb today. But the self-dealing decadence of his era continues to constrain Ukraine&amp;rsquo;s integration with the West since foreign assistance in the form of loans and military aid remains heavily &lt;a href="https://www.atlanticcouncil.org/blogs/ukrainealert/why-poroshenko-s-support-for-shokin-is-dangerous/"&gt;conditioned&lt;/a&gt; on anti-corruption efforts. Many of the nation&amp;rsquo;s young feel punished for Russia&amp;rsquo;s corruption of their society even after staging a revolution rejecting it. The use of modern information technology to create transparency, Fedorov&amp;rsquo;s work over the years, is essential if Ukraine is going to reach its full potential as a European nation.&lt;/p&gt;

&lt;p&gt;After Yermak was ousted, Fedorov used his reformer&amp;rsquo;s aura to expand his influence across government and build popularity internationally. The former senior Ukrainian defense official said, &amp;ldquo;When Yermak was in that powerful position, Fedorov was very careful. He didn&amp;#39;t rock the boat. But now that Yermak is weakened and Zelensky is weakened, Fedorov is moving forward and stepping out. And so he&amp;#39;s pushing the boundaries.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;In his July 16 press conference, Fedorov stopped just short of accusing Syrskyi of criminality, describing him as a man who &amp;ldquo;prefers to attend backroom meetings, weave intrigues.&amp;rdquo; But the hidden meaning in the summary was hard to mistake by anyone familiar with Yermak&amp;rsquo;s reputation.&lt;/p&gt;

&lt;p&gt;Ukrainians who speak to Western journalists are cautious when addressing corruption, lest they reinforce negative stereotypes. This caution makes the recent widespread protests across Ukraine all the more remarkable, signaling a public willingness to confront internal problems directly, even when doing so carries political risk.&lt;/p&gt;

&lt;p&gt;One Ukrainian military analyst, who declined to name Syrskyi specifically, said, &amp;ldquo;There are forces within the Ukrainian state that continue to operate according to the rules of the past and seek to resolve issues through old methods. Although Minister Fedorov has attempted to counter such practices through his reform agenda, the influence of these forces within the defense sector remains strong.&amp;rdquo; The former official pushed back on notions of Fedorov as a knight among villains, suggesting instead that he was a court noble vying for influence, backed by his own faction.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;You have to assume that every single leader and commander in Ukraine has a commercial interest. Every seat has a certain value attached to it. You protect it, but you also have vested interests that must be protected because those people helped put you in that position. So Fedorov obviously has a lot of different vested interests,&amp;rdquo; the former official said.&lt;/p&gt;

&lt;p&gt;The former official pointed to government-funded &lt;a href="https://u24.gov.ua/news/one_year"&gt;media platforms&lt;/a&gt; he launched and a generation of drone and defense-tech startups that are now attracting&lt;a href="https://finance.yahoo.com/news/drone-software-company-swarmer-surges-161458829.html"&gt; lucrative&lt;/a&gt; Western investment after starting with government funds and grants secured by Fedorov. Fedorov has no public financial interest in any of them, but &amp;ldquo;hidden ownership&amp;rdquo; is something of an Eastern European tradition, they explained. It&amp;rsquo;s also at &lt;a href="https://kyivindependent.com/what-we-know-about-luxury-estates-at-the-center-of-ukraines-biggest-corruption-probe/"&gt;the center&lt;/a&gt; of the charges against Yermak. Even without a specific or secret financial interest, Fedorov&amp;rsquo;s future success is intimately tied to the companies he championed.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;His interests are clashing with Syrskyi&amp;rsquo;s interests,&amp;rdquo; the former official said.&lt;/p&gt;

&lt;p&gt;Like &lt;em&gt;Game of Thrones&lt;/em&gt;? &amp;ldquo;Exactly,&amp;rdquo; they answered.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Winter is coming&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Difficult decisions await Khmara or whoever settles into the defense minister&amp;rsquo;s office. Even as Putin &lt;a href="https://x.com/TheStudyofWar/status/2080327223140118793"&gt;contemplates&lt;/a&gt; a broader mobilization, filling the ranks of the Ukrainian military is growing harder as recruitment slows and &lt;a href="https://www.bbc.com/news/articles/cr7k5ngde3vo"&gt;draft-dodging&lt;/a&gt; increases.&lt;/p&gt;

&lt;p&gt;The protests supporting Fedorov and the challenge of filling military ranks are deeply linked, &amp;ldquo;Ukraine&amp;rsquo;s mobilization crisis is not fundamentally a manpower problem. It is a trust problem,&amp;rdquo; Tregub &lt;a href="https://x.com/OTregub/status/2077703401832419461"&gt;wrote&lt;/a&gt; on Tuesday.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Still, sources we spoke to and voices of prominent Ukraine supporters online called the protests a sign of resilience.&lt;/p&gt;

&lt;p&gt;The country &lt;a href="https://www.ukrinform.net/rubric-polytics/4147594-martial-law-and-mobilization-extended-in-ukraine-zelensky-signs-laws.html"&gt;remains under martial law&lt;/a&gt; and in a state of existential war. But when protesters fill the streets to voice their grievances outside the president&amp;#39;s office, they are not met with truncheons, tear gas, or fears for their livelihoods as they might in Russia, or even &lt;a href="https://www.nytimes.com/2020/06/01/us/politics/trump-st-johns-church-bible.html"&gt;Washington, D.C&lt;/a&gt;. That, more than anything, shows a democracy capable of enduring.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/07/27/GettyImages_2287193462_1/large.jpg" width="618" height="284"><media:description>July 24 Protests in Ivana Franka Square, Kyiv to re-instate Ukrainian Defence Minister Mykhailo Fedorov.</media:description><media:credit>Yevhen Kotenko/ Ukrinform/Future Publishing via Getty Image</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/07/27/GettyImages_2287193462_1/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>As drones take over, ejection-seat makers prepare for a pilotless battlefield</title><link>https://www.defenseone.com/threats/2026/07/ejection-seat-unmanned-aircraft/415008/</link><description>Martin-Baker is reaching out to drone companies: "How can we help?"</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Novelly</dc:creator><pubDate>Fri, 24 Jul 2026 19:07:46 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/07/ejection-seat-unmanned-aircraft/415008/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;&lt;strong&gt;FARNBOROUGH, England&lt;/strong&gt;&amp;mdash;In the eight decades since Martin-Baker &lt;a href="https://martin-baker.com/our-history/"&gt;conducted&lt;/a&gt; its first in-flight test, its ejection seats have saved the lives of more than 7,800 aviators. But more recently, advancements in robotic and autonomous aircraft have Martin-Baker and fellow ejection-seat makers looking for ways to keep themselves alive and well.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Recognizing where drones are going, we have offered our services to support the drone manufacturers, both the small and the larger ones of the future,&amp;rdquo; Steve Roberts, Martin-Baker&amp;rsquo;s head of business development, told &lt;em&gt;Defense One&lt;/em&gt; on the sidelines of the Farnborough International Airshow here. &amp;ldquo;It could be anything. How do they get launched? We have an electronics capability in our company. There are some small drone manufacturers that don&amp;rsquo;t have that&amp;hellip; We might be able to help them with payload destruction.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We have reached out to say, &amp;lsquo;How can we help?&amp;rsquo;&amp;rdquo; Roberts said. &amp;ldquo;There has been lots of interest, but I can&amp;rsquo;t report exactly the direction we&amp;rsquo;re going just yet.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The &lt;a href="https://www.defensenews.com/air/2025/04/08/fa-xx-could-be-navys-last-piloted-fighter-bring-greater-range/?utm_source=chatgpt.com"&gt;end of the manned fighter jet&lt;/a&gt; is not yet nigh. For all the airshow announcements about unmanned systems&amp;mdash;from &lt;a href="https://www.defenseone.com/defense-systems/2026/07/anduril-pitches-robot-wingman-us-army-helicopters/414868/?oref=d1-featured-river-top"&gt;autonomous tiltrotorcraft&lt;/a&gt; to unmanned &lt;a href="https://www.defenseone.com/business/2026/07/australian-cca-flew-pacific-exercise-boeing-exec-says-its-important-first-step/414951/"&gt;multi-role platforms&lt;/a&gt;&amp;mdash;exquisite next-generation fighter jet projects like &lt;a href="https://www.defenseone.com/ideas/2026/07/canada-gcap-f-35-relationship/414928/?oref=d1-category-lander-featured-river"&gt;GCAP&lt;/a&gt;, the &lt;a href="https://www.defenseone.com/defense-systems/2025/09/f-47s-first-flight-expected-2028/408283/"&gt;F-47&lt;/a&gt;, and &lt;a href="https://www.defenseone.com/policy/2026/04/Air-Force-F-47-fighter-jet-navy/412632/"&gt;F/A-XX&lt;/a&gt; are still garnering investment and attention. Companies like Martin-Baker and RTX&amp;rsquo;s Collins Aerospace know that the pilots will need ejection seats to fight this generation&amp;rsquo;s wars.&lt;/p&gt;

&lt;p&gt;For the U.S. military, Martin-Baker supplies ejection seats for the F-5, some F-16 blocks, F/A-18, and F-35 as well as the T-6, T-38, and T-45 training jets. The United-Kingdom-based company has created a community around its product by &lt;a href="https://martin-baker.com/tie-club/"&gt;giving ties&lt;/a&gt; to pilots rescued by their seats, &lt;a href="https://www.safran-group.com/news/welcome-ejected-pilots-club-2025-06-20"&gt;hosting regular gatherings&lt;/a&gt; of ejectees, and offering an &lt;a href="https://us.bremont.com/collections/martin-baker?srsltid=AfmBOop-VkEWswn-2L9IOBcIL8wPBREIeMcyb4yrx7ZEZYimtWC3EnyX"&gt;exclusive watch&lt;/a&gt; available to aviators who&amp;rsquo;ve survived crashes.&lt;/p&gt;

&lt;p&gt;Martin-Baker won&amp;rsquo;t be abandoning that culture anytime soon, Roberts said. Major militaries aren&amp;rsquo;t giving up on exquisite fighter jets, and those pilots will be relying on the life-saving technology.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;At the end of the day, we&amp;rsquo;re a life-saving company, that&amp;rsquo;s the ethos. So how can we provide our life-saving technology into the unmanned aircraft,&amp;rdquo; Roberts said. &amp;ldquo;We feel that in our lifetimes, unmanned may not take over, but the partially-manned aircraft will be there &amp;hellip; and the training aircraft need to deliver the pilots of the future.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Collins Aerospace&amp;rsquo;s ACES II and ACES 5 ejection seats are on the F-15, F-16, and F-22 fighters as well as the B-1 and B-2 bombers, per their website. Since 1978, those ejection seats have saved more than 730 lives, a company spokesman told &lt;em&gt;Defense One&lt;/em&gt; in an emailed statement. Similar to Martin-Baker, Collins has the &amp;ldquo;&lt;a href="https://www.rtx.com/collinsaerospace/what-we-do/industries/military-and-defense/interiors/aces-5-next-generation-ejection-seat/grasshopper-club"&gt;Grasshopper Club&lt;/a&gt;&amp;rdquo; where ejectees can tour the factory and are given a pin, patch, and coin.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We remain committed to working with our customer to ensure pilots receive the highest level of protection when their need is greatest,&amp;rdquo; the spokesperson wrote.&lt;/p&gt;

&lt;p&gt;But Collins Aerospace&amp;mdash;along with RTX&amp;rsquo;s other subsidiaries of Pratt &amp;amp; Whitney and Raytheon&amp;mdash;are all heavily investing in developing unmanned aircraft.&lt;/p&gt;

&lt;p&gt;In June, Collins Aerospace&amp;rsquo;s Sidekick autonomy software was &lt;a href="https://www.defenseone.com/defense-systems/2026/06/anduril-general-atomics-get-air-force-contracts-build-first-drone-wingmen/414266/"&gt;down-selected&lt;/a&gt; for the production phase of the Air Force&amp;rsquo;s collaborative combat aircraft, or CCA, competition. At Farnborough, Pratt &amp;amp; Whitney &lt;a href="https://www.rtx.com/news/news-center/2026/07/21/rtxs-pratt-whitney-valox-1500-engine-completes-key-design-milestone"&gt;announced&lt;/a&gt; it reached a key design milestone for its Pratt &amp;amp; Whitney Valox 1500, an engine designed to power CCAs. And Raytheon has been working with the Air Force &lt;a href="https://www.defenseone.com/business/2026/02/air-forces-drone-wingmen-have-started-flying-weapons/411625/"&gt;to integrate&lt;/a&gt; its Advanced Medium-Range Air-to-Air Missiles onto CCAs.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Together, these efforts, among others, underscore RTX&amp;rsquo;s commitment to delivering affordable technologies that can be produced at scale, rapidly fielded and critical to maximizing manned and unmanned teaming,&amp;rdquo; the company spokesperson wrote.&lt;/p&gt;

&lt;p&gt;Martin-Baker, which began as an aircraft manufacturer, aims to share their knowledge with newer and smaller companies entering the unmanned warfare business.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We&amp;rsquo;ve got a healthy, healthy order book going for many, many years because of these new programs that are coming on top,&amp;rdquo; Roberts said. &amp;ldquo;But certainly the new market that&amp;rsquo;s come up, both the, shall we say, the expensive unmanned and also the inexpensive unmanned, there are companies that don&amp;rsquo;t have the expertise we have in manufacture.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/07/24/MB_GettyImages_2162908927/large.jpg" width="618" height="284"><media:description>Visitors tried out Martin-Baker's ejection seats at the 2024 Farnborough International Airshow in Farnborough, England. </media:description><media:credit>Richard Baker / In Pictures via Getty Images</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/07/24/MB_GettyImages_2162908927/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Lawmakers get taste of AI-enabled cyberattacks in China-Taiwan war game</title><link>https://www.defenseone.com/threats/2026/07/lawmakers-get-taste-ai-enabled-cyberattacks-china-taiwan-war-game/414952/</link><description>Representatives weighed responses to simulated Chinese cyberattacks on U.S. infrastructure during a tabletop exercise hosted by CSIS.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Wed, 22 Jul 2026 17:00:00 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/07/lawmakers-get-taste-ai-enabled-cyberattacks-china-taiwan-war-game/414952/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;Members and staffers from the House Homeland Security Committee and the House China Select Committee were put through a simulated Taiwan crisis Tuesday that tested how U.S. officials might respond to AI-backed cyberattacks targeting transportation and logistics networks needed to deploy American forces.&lt;/p&gt;

&lt;p&gt;The Center for Strategic and International Studies hosted the event to give lawmakers a window into the trade-offs and uncertainty that would shape the U.S. response to a fast-moving conflict involving China and its implications in American cyberspace.&lt;/p&gt;

&lt;p&gt;Among those participating were Republican Reps. Eli Crane of Arizona, Michael Guest of Mississippi and Michael McCaul of Texas, along with Democratic Rep. Shri Thanedar of Michigan and Puerto Rico Resident Commissioner Pablo Jos&amp;eacute; Hern&amp;aacute;ndez, also a Democrat.&lt;/p&gt;

&lt;p&gt;The scenario begins with China launching a massive military exercise around Taiwan in the summer of 2027, leaving U.S. officials unsure whether Beijing was being coercive, imposing a de facto blockade or preparing for a full invasion of the island, per a readout provided to reporters just before the simulation began. Beijing avoids using the term &amp;ldquo;blockade&amp;rdquo; but the moves effectively quarantine Taiwan, the summary says.&lt;/p&gt;

&lt;p&gt;Lawmakers are then told that U.S. intelligence analysts suspect Chinese hackers had begun targeting ports, freight rail systems, airports and other transportation networks that could be used to move U.S. forces and supplies. Some of the attacks cause immediate disruptions, while others appear designed to preserve access that could be leveraged later.&lt;/p&gt;

&lt;p&gt;Participants also have to decide which networks to defend first, how closely to coordinate with private sector critical infrastructure operators and whether moving U.S. forces would deter China or further escalate the crisis.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Cyber &amp;ldquo;is always going to be a leader in any kinetic war,&amp;rdquo; McCaul told participants before reporters were asked to leave the war game room so lawmakers and staff could participate more candidly.&lt;/p&gt;

&lt;p&gt;The exercise notably included a smattering of AI-related attacks involving stolen credentials and interference with logistics and routing systems. AI is also used in one attack scenario for a misinformation campaign, per the readout. The final scenario involved a prompt injection, in which attackers try to &lt;a href="https://www.island.io/blog/agentbaiting-how-800-fake-ai-skills-and-mcp-servers-delivered-malware"&gt;trick an AI system&lt;/a&gt; into following malicious instructions instead of its intended safeguards.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;This committee has been &lt;a href="https://www.nextgov.com/artificial-intelligence/2026/05/house-homeland-panel-gets-briefing-anthropics-mythos/413542/"&gt;briefed extensively&lt;/a&gt; on our latest AI capabilities, Anthropic in particular, the Mythos model, and the amount of destruction that Mythos can do if it&amp;rsquo;s in the wrong hands,&amp;rdquo; McCaul said, referring to the powerful cyber-focused AI model unveiled in early April. &amp;ldquo;And we know China is three to five months behind us. That&amp;rsquo;s not very long, in my judgment.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Current and former officials have long warned that China could disrupt U.S. military deployments by &lt;a href="https://www.thecipherbrief.com/americas-military-plans-depend-on-infrastructure-it-doesnt-secure"&gt;digitally sabotaging&lt;/a&gt; the largely private-sector ports, railways, airports and other infrastructure used to move troops and equipment overseas. Advanced AI tools, broadly, can &lt;a href="https://www.nextgov.com/cybersecurity/2026/07/ai-once-relegated-helping-hackers-certain-tasks-can-now-power-every-stage-cyberattack/414744/"&gt;help hackers&lt;/a&gt; work faster, carry out more parts of an attack automatically and target more systems at once.&lt;/p&gt;

&lt;p&gt;The war game scenario mirrors longstanding concerns surrounding &lt;a href="https://www.nextgov.com/cybersecurity/2024/04/some-volt-typhoon-victims-wont-know-theyre-impacted-mandiant-ceo-says/395659/"&gt;Volt Typhoon&lt;/a&gt;, a Chinese government-backed hacking group that U.S. officials say has spent years quietly burrowing into American critical infrastructure. The hackers are believed to be positioning themselves inside sectors such as communications, energy, transportation and water systems to disrupt them during a future conflict, including one over Taiwan.&lt;/p&gt;

&lt;p&gt;China claims Taiwan as part of its territory and seeks to bring the self-governing island under Beijing&amp;rsquo;s control. Its major role in &lt;a href="https://www.nextgov.com/ideas/2023/01/lessons-taiwans-rise-dominate-computer-chip-industry/381582/"&gt;producing advanced computer chips&lt;/a&gt; makes it strategically important to both China and the United States.&lt;/p&gt;

&lt;p&gt;U.S. spy agencies &lt;a href="https://www.dni.gov/files/ODNI/documents/assessments/ATA-2026-Unclassified-Report.pdf"&gt;assessed&lt;/a&gt; earlier this year that China is not planning to invade Taiwan in 2027. While Beijing has repeatedly refused to rule out using force, the intelligence community said it believes China still prefers to achieve unification without military action.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/07/22/072226WarGameNG-1/large.jpg" width="618" height="284"><media:description>Rep. Shri Thanedar, D-Mich. of the House Homeland Security Committee gets an overview of the CSIS war game simulating AI-cyber threats involving China and Taiwan.</media:description><media:credit>David DiMolfetta/Staff</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/07/22/072226WarGameNG-1/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Spies are targeting US AI labs, experts warn Congress</title><link>https://www.defenseone.com/threats/2026/07/ai-labs-spies/414929/</link><description>Former officials told the House Intelligence Committee that U.S. agencies have not kept pace with China’s efforts to steal technology.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Tue, 21 Jul 2026 20:00:00 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/07/ai-labs-spies/414929/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;The U.S. intelligence community needs to devote more resources to protecting American artificial intelligence companies from foreign espionage, former officials told the House Intelligence Committee on Tuesday, arguing that China will use a range of intelligence-gathering techniques to steal proprietary AI technology and advance its own military and economic goals.&lt;/p&gt;

&lt;p&gt;The &lt;a href="https://intelligence.house.gov/2026/07/21/chairman-crawford-rep-stefanik-open-full-committee-hearing-to-discuss-the-next-generation-of-threats-25-years-after-september-11th/"&gt;hearing&lt;/a&gt;, focused on emerging threats to the U.S. in the 25 years since the Sept. 11, 2001, terrorist attacks, also highlighted AI&amp;rsquo;s growing role across a range of national security concerns, including cyberattacks, autonomous drones and foreign influence operations.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Of course, our intelligence services and agencies are going to have secrets that are always going to be of top desire for foreign intelligence adversaries, but if you&amp;rsquo;re [China&amp;rsquo;s Ministry of State Security] today, you&amp;rsquo;re looking at frontier model companies,&amp;rdquo; said Frank Cilluffo, a former George W. Bush homeland security official who leads Auburn University&amp;rsquo;s McCrary Institute for Cyber and Critical Infrastructure.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I think we&amp;rsquo;ve got to actually rethink counterintelligence. It&amp;rsquo;s not just the traditional spy-versus-spy, information-versus-information,&amp;rdquo; he added. &amp;ldquo;It&amp;rsquo;s who holds the keys right now, it&amp;rsquo;s not going to be in government alone.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Access to proprietary U.S. AI research is valuable to foreign adversaries because it can help them close technological gaps without bearing the cost and time of developing those capabilities themselves.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;U.S. officials have several times assessed that China has stolen proprietary national security information, notably data on military &lt;a href="https://www.osi.af.mil/News/Features/Display/Article/2350807/cyber-espionage-for-the-chinese-government/"&gt;aircraft&lt;/a&gt;. More recently, the White House and major U.S. AI companies have accused Chinese firms of conducting &lt;a href="https://www.nextgov.com/artificial-intelligence/2026/04/white-house-accuses-china-deliberate-industrial-scale-campaigns-steal-us-ai-models/413083/"&gt;distillation operations&lt;/a&gt;, in which developers covertly use advanced American-made AI models to improve their own.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The counterintelligence threat has lagged way behind,&amp;rdquo; said retired Lt. Gen. H.R. McMaster, who served as national security advisor during President Donald Trump&amp;rsquo;s first term. &amp;ldquo;I think we have a lot of work to do,&amp;rdquo; he said, describing how, over the years, U.S.&amp;nbsp;devotion to counterterrorism efforts after Sept. 11 drew away resources that track China&amp;rsquo;s efforts to &lt;a href="https://www.hsgac.senate.gov/wp-content/uploads/imo/media/doc/2019-11-18%20PSI%20Staff%20Report%20-%20China's%20Talent%20Recruitment%20Plans%20Updated2.pdf"&gt;embed spies&lt;/a&gt; and other researchers into American firms.&lt;/p&gt;

&lt;p&gt;The range of counterintelligence targets is broader now, and especially includes private companies, said Ben Buchanan, who served as the Biden administration&amp;rsquo;s White House special advisor for AI.&lt;/p&gt;

&lt;p&gt;Counterintelligence operations will also evolve with AI, he said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Of course cyber operations have already changed, but even if you look at things like human intelligence and detecting human intelligence operations, it is a different technical paradigm that yields different kinds of analysis that AI alone can do,&amp;rdquo; Buchanan said.&lt;/p&gt;

&lt;p&gt;He also criticized the Trump administration&amp;rsquo;s recent moves to ease restrictions on advanced chip exports to China.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;America has a large structural advantage in AI due to the democratic ecosystem of producing chips, and we should exploit that structural advantage to the fullest,&amp;rdquo; Buchanan said. &amp;ldquo;We should be much more aggressive on enforcement and smuggling to stop China from trying to catch up.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Many individual states are also not well equipped to track and respond to Chinese spying efforts, said Seth Jones, a former U.S. Special Operations Command official who now leads the Defense and Security Department at the Center for Strategic and International Studies.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Recent &lt;a href="https://www.nextgov.com/emerging-tech/2026/06/trump-signs-2-orders-prepare-us-quantum-future/414331/"&gt;quantum computing executive orders&lt;/a&gt;&amp;nbsp;have focused, in part, on tasking the FBI and the intelligence community with better protecting the nation&amp;rsquo;s quantum research from foreign spying.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The White House has directed national security agencies to help safeguard advanced U.S.-made AI from foreign threats, but it has not established a dedicated counterintelligence framework equivalent to the quantum technology directives.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/07/21/GettyImages_2286442678_1/large.jpg" width="618" height="284"><media:description>Ranking member Rep. Jim Himes, D-Mass., left, and chairman Rep. Rick Crawford, R-Ark., conduct the House Select Intelligence Committee hearing on "25 Years After 9/11: Confronting the Next Generation of Threats" on Tuesday, July 21, 2026. </media:description><media:credit>Bill Clark/CQ-Roll Call, Inc via Getty Images</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/07/21/GettyImages_2286442678_1/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Declassified China intelligence fails to back up Trump's false claims about 'stolen election'</title><link>https://www.defenseone.com/threats/2026/07/trump-stretches-declassified-china-intelligence-broader-2020-election-claims/414852/</link><description>The information adds detail about Chinese intelligence collection of U.S. voter data, but doesn't change the intelligence community's rejection of the president's 2020 claims.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Thu, 16 Jul 2026 23:00:00 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/07/trump-stretches-declassified-china-intelligence-broader-2020-election-claims/414852/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;President Donald Trump used newly declassified intelligence Thursday night to revive his claims about 2020 election issues, pointing to findings that China possessed or analyzed more than 200 million U.S. voter records. But the documents do not appear to subvert the intelligence community&amp;rsquo;s prior conclusions that China did not alter votes or interfere with the results of the election.&lt;/p&gt;

&lt;p&gt;The declassified &lt;a href="https://www.whitehouse.gov/election-integrity/"&gt;records&lt;/a&gt; provide substantially more detail about Chinese intelligence collection involving U.S. voter data and reveal internal debate within the intelligence community over how analysts should characterize Beijing&amp;rsquo;s election-related activities.&lt;/p&gt;

&lt;p&gt;But many of the documents&amp;nbsp;reviewed by &lt;em&gt;Nextgov/FCW&lt;/em&gt; do not appear to contradict the intelligence community&amp;rsquo;s longstanding public conclusion that it found no evidence that China altered voting systems, changed ballots, or interfered with the mechanics of the 2020 election.&lt;/p&gt;

&lt;p&gt;In a speech to the nation, Trump used the disclosure to press Congress to pass the SAVE America Act, casting the records as evidence of broad weaknesses in U.S. election systems and arguing that tighter federal voting requirements are needed ahead of future elections. The SAVE Act would require documentary proof of citizenship to register and photo identification to vote in federal elections, but it faces steep odds in Congress.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We will be working closely to mitigate any harm, and we&amp;rsquo;re taking swift action to ensure that sensitive voter data is better protected, so it can never be bought, it can never be hacked, and we can never watch a stolen election again,&amp;rdquo; Trump said.&lt;/p&gt;

&lt;p&gt;The documents suggest Chinese intelligence used U.S. voter-registration information for identity matching and political analysis, while also collecting other large sets of Americans&amp;rsquo; personal data. But they do not show that China altered voter rolls, manipulated ballots or changed the election&amp;rsquo;s outcome.&lt;/p&gt;

&lt;p&gt;In April 2020, intelligence agencies &lt;a href="https://www.dni.gov/files/ODNI/documents/assessments/NICM-Declassified-Cyber-Operations-Enabling-Expansive-Digital-Authoritarianism-20200407--2022.pdf"&gt;concluded&lt;/a&gt; that Beijing analyzed several states&amp;rsquo; voter registration datasets to conduct public opinion analysis on the 2020 election, but the publicly released intelligence did not establish that China stole the data.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;China has all along adhered to the principle of non-interference in other&amp;rsquo;s internal affairs. The U.S. election is an internal matter of the U.S. Its outcome is determined by the votes of the American people. China has never and will never interfere in the presidential elections of the U.S.,&amp;rdquo; Chinese embassy spokesperson Liu Chang said in a statement.&lt;/p&gt;

&lt;p&gt;Some of the newly declassified records appear to bolster rather than overturn the intelligence community&amp;rsquo;s earlier public findings. An August 2020 National Intelligence Council assessment concluded that China preferred Trump&amp;rsquo;s defeat but &amp;ldquo;did not intend to try to affect the election,&amp;rdquo; while separately warning that Russian actors were already amplifying claims that mail-in voting would lead to fraud and that U.S. elections were &amp;ldquo;rigged&amp;rdquo; months before Americans cast their ballots.&lt;/p&gt;

&lt;p&gt;That same assessment did warn that foreign actors could exploit poorly secured election infrastructure and potentially manipulate vote-counting systems in isolated cases. But it also drew clear limits around that risk: a coordinated effort to change results at scale would be difficult, audits and paper records would likely detect it&amp;nbsp;and attacks on results-reporting systems would probably delay publication rather than affect certified totals.&lt;/p&gt;

&lt;p&gt;Trump also said a separate DHS review had identified approximately 278,000 noncitizens registered to vote in federal elections, though it&amp;rsquo;s not clear how that finding was reached. Federal law already prohibits noncitizens from voting in federal elections, and studies and audits have generally found such voting &lt;a href="https://bipartisanpolicy.org/article/four-things-to-know-about-noncitizen-voting/"&gt;to be rare&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Foreign countries have tried to interfere in elections for years. This is not new,&amp;rdquo; said Rep. Bennie Thompson, D-Miss., the top Democrat on the House Homeland Security Committee. &amp;ldquo;His repackaging of old lies with old, cherry-picked intelligence to try to confuse the American people will not change the outcome of the 2020 election, will not change the outcome of the nearly 60 lawsuits rejecting his election fraud claims, and will not change the fact that the 2020 election was secure.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The U.S. intelligence community has previously disagreed over how to characterize China&amp;rsquo;s actions during the 2020 election. A declassified &lt;a href="https://www.dni.gov/files/ODNI/documents/assessments/ICA-declass-16MAR21.pdf"&gt;intelligence assessment&lt;/a&gt; released in 2021 concluded that China considered, but ultimately did not undertake, influence efforts intended to change the presidential election&amp;rsquo;s outcome.&lt;/p&gt;

&lt;p&gt;The assessment also found no indication that China or any other foreign actor attempted to alter election infrastructure like vote tabulation machines. Intelligence agencies instead assessed that Beijing continued longstanding efforts to collect information on U.S. voters, public opinion, political parties and candidates while seeking to shape American policy through economic pressure, lobbying and other traditional tools.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Not everyone inside the intelligence community agreed with the assessment&amp;rsquo;s conclusion on Chinese influence. The National Intelligence Officer for Cyber issued a minority view concluding that China had taken at least some steps to undermine Trump&amp;rsquo;s reelection prospects, primarily through social media, official statements and state media. The dissent still agreed there was no information suggesting Beijing tried to interfere with election processes.&lt;/p&gt;

&lt;p&gt;At the time, then-Director of National Intelligence John Ratcliffe &amp;mdash; now Trump&amp;rsquo;s CIA director &amp;mdash; backed that minority view in a memorandum attached to the assessment, arguing the broader intelligence community had not fully or accurately described the scope of China&amp;rsquo;s activity. Ratcliffe cited an intelligence community ombudsman&amp;rsquo;s findings that analysts had applied terminology inconsistently, that alternative assessments had faced institutional pressure and that some analysts working on the majority view did not have access to all relevant compartmented reporting.&lt;/p&gt;

&lt;p&gt;Several of the declassified records focus on the process behind producing intelligence assessments. Emails declassified Thursday night show officials ultimately agreed to publish a separate alternative analysis, placing the dissenting view on the record without holding up the intelligence community&amp;rsquo;s broader assessment.&lt;/p&gt;

&lt;p&gt;Ratcliffe ultimately concluded that China sought to influence the 2020 election. But neither his memorandum nor the minority assessment concluded that Beijing altered votes, manipulated vote counting or interfered with the technical administration of the election.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I have long publicly highlighted China&amp;rsquo;s nefarious efforts to influence the 2020 election against President Trump, as evidenced by my dissent to the flawed January 2021 Intelligence Community Assessment. The documents declassified today shed further light on China&amp;rsquo;s intentions,&amp;rdquo; Ratcliffe said in a statement after the speech.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/07/17/071626TrumpNG-1/large.jpg" width="618" height="284"><media:description>U.S. President Donald Trump addresses the nation from the East Room of the White House on July 16, 2026 in Washington, DC.</media:description><media:credit>Saul Loeb/Pool - Getty Images</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/07/17/071626TrumpNG-1/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>China justifies Space Force’s budget, nominee tells lawmakers in smooth confirmation hearing</title><link>https://www.defenseone.com/threats/2026/07/china-justifies-space-forces-budget-nominee-tells-lawmakers-smooth-confirmation-hearing/414823/</link><description>Lt. Gen. Douglas Schiess, who is likely to be confirmed, would be the young service's third leader.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Novelly</dc:creator><pubDate>Thu, 16 Jul 2026 15:43:51 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/07/china-justifies-space-forces-budget-nominee-tells-lawmakers-smooth-confirmation-hearing/414823/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;China&amp;rsquo;s military advancements justify the Space Force&amp;rsquo;s $71 billion budget request, the White House nominee to lead the service said during a short and uncontentious Senate confirmation hearing on Thursday.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I would say that the $71.1 billion that the president has asked for is exactly what we need,&amp;rdquo; said Lt. Gen. Douglas Schiess, who currently serves as the deputy chief of space operations for operations at the Pentagon. He told the Senate Armed Services Committee that it was &amp;ldquo;needed because of the threat from China and Russia, and the capabilities that the joint forces needs.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The Space Force&amp;rsquo;s budget request was thrown into uncertainty earlier this week when House leaders &lt;a href="https://www.defenseone.com/policy/2026/07/space-force-budget-retirement/414796/?oref=d1-featured-river-secondary"&gt;said&lt;/a&gt; they would not fully comply with the Trump administration&amp;rsquo;s proposal to provide much of the money through reconciliation&amp;mdash;a partisan-controlled budget maneuver rarely used for defense spending before last year. Under the proposal, reconciliation would have funded some of the service&amp;rsquo;s most ambitious programs, including the Space Data Network and &lt;a href="https://www.defenseone.com/policy/2026/04/trump-wants-18b-golden-dome-it-would-require-reconciliation-funds-again/412631/"&gt;Golden Dome&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;On Thursday, Senate Armed Service Committee Chairman Roger Wicker, R-Miss., told Schiess that his service is underfunded at the moment, but said that it would be adequately resourced if the House and Senate passed the Trump administration&amp;rsquo;s budget request. The three-star general agreed.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The White House tapped Schiess in April to serve as the next chief of space operations, &lt;em&gt;Defense One&lt;/em&gt; &lt;a href="https://www.defenseone.com/policy/2026/04/meet-3-star-insiders-say-will-be-space-forces-next-top-leader/413218/"&gt;first reported&lt;/a&gt;. The three-star officer would replace Gen. Chance Saltzman, who &lt;a href="https://www.defenseone.com/policy/2026/07/space-force-budget-retirement/414796/?oref=d1-featured-river-secondary"&gt;announced&lt;/a&gt; in London this week that he will retire next month.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Schiess said in &lt;a href="https://www.armed-services.senate.gov/imo/media/doc/schiess_apqs.pdf"&gt;written testimony&lt;/a&gt; to the Committee that the services budget, people, and platforms need to grow to support major joint operations. The military&amp;rsquo;s space forces have been praised as the &lt;a href="https://www.defenseone.com/threats/2026/03/cyber-space-commands-were-first-mover-strikes-iran-top-general/411819/"&gt;&amp;ldquo;first movers&amp;rdquo;&lt;/a&gt; during the war in Iran and crucial to the administration&amp;rsquo;s operation in Venezuela.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The most significant challenge is balancing urgent readiness for a contested space domain today with the modernization required to win tomorrow,&amp;rdquo; Schiess wrote. &amp;ldquo;Our adversaries are fielding counterspace capabilities at a rapidly increasing pace that are designed to hold U.S. and allied satellites at risk, while also building space-enabled kill chains to threaten our Joint Force.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;If confirmed, Schiess said in written testimony that his first year would focus on improving combat readiness, prioritizing operational testing, building up space launch infrastructure, and expanding facilities.&lt;/p&gt;

&lt;p&gt;The service has &lt;a href="https://www.defenseone.com/threats/2026/05/launches-slated-grow-hundredfold-space-force-seeks-more-sites-money-people-and-ai/413403/"&gt;budgeted upwards&lt;/a&gt; of 100 national security space launches over the next five years, and a recent service &lt;a href="https://www.spaceforce.mil/Portals/2/Documents/SAF_2026/OFD_2040_Baseline_Final.pdf"&gt;planning document&lt;/a&gt; estimates its two main launch bases will send as many as 3,000 commercial and military rockets into the skies each year by 2036.&lt;/p&gt;

&lt;p&gt;Schiess said in his written statements that &amp;ldquo;the most pressing issue&amp;rdquo; he wants to address is &amp;ldquo;scaling to meet the unprecedented increase in launch tempo, as well as the exponential growth in commercial missions&amp;rdquo; including the use of super-heavylift rockets to &amp;ldquo;unlock new possibilities for the Space Force.&lt;/p&gt;

&lt;p&gt;Schiess added in written and verbal testimony that he &amp;ldquo;would have no hesitation&amp;rdquo; in providing his best military advice &amp;ldquo;even when that advice differs from the views of the Chairman, other members of the Joint Chiefs of Staff, Secretary of War, President, or other leaders.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;This basic requirement of the job has come under pressure during the second Trump administration. The Pentagon&amp;rsquo;s political leaders &amp;ldquo;have created a command climate that penalizes the honest evaluations of the military about issues on which the military is expert and the civilians are not,&amp;rdquo; AEI&amp;rsquo;s Kori Schake, an expert on civil-military relations, &lt;a href="https://www.theatlantic.com/national-security/2026/07/generals-deferential-military-trump/687822/"&gt;told&lt;/a&gt; &lt;em&gt;The Atlantic&lt;/em&gt; recently. &amp;ldquo;That&amp;rsquo;s very dangerous,&amp;rdquo; she said. &amp;ldquo;That&amp;rsquo;s how you lose wars.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Only six Senators asked Schiess questions during the roughly 40-minute hearing. Sen. Angus King, I-Maine, told the general that bodes well for his likely confirmation.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The fact that we didn&amp;#39;t have a large turnout is an indication, I believe, of the committee&amp;#39;s confidence in you,&amp;rdquo; King said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Sen. Richard Blumenthal, D-Conn., added &amp;ldquo;being non-controversial is not a bad thing.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/07/16/GettyImages_2286386468/large.jpg" width="618" height="284"><media:description>Lt. Gen. Douglas A. Schiess stands after his Senate Armed Services Committee confirmation hearing on Capitol Hill on July 16, 2026. </media:description><media:credit>Anna Moneymaker / Getty Images</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/07/16/GettyImages_2286386468/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>A year after State layoffs, ex-feds say US is paying the price in Iran and Ebola crises</title><link>https://www.defenseone.com/threats/2026/07/state-department-layoffs-iran-ebola/414824/</link><description>New legislation would enable foreign service officers pushed out by the Trump administration to rejoin the department without retaking the Foreign Service Officer Test.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Sean Michael Newhouse</dc:creator><pubDate>Thu, 16 Jul 2026 15:35:33 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/07/state-department-layoffs-iran-ebola/414824/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;To Megan Fotheringham,&amp;nbsp;a small, circular plaque represents what the United States lost when the Trump administration&amp;nbsp;&lt;a href="https://www.govexec.com/workforce/2026/01/out-government-former-usaid-employees-continue-offer-their-expertise/410892/"&gt;shuttered&lt;/a&gt;&amp;nbsp;the U.S. Agency for International Development last year.&lt;br /&gt;
&lt;br /&gt;
The plaque&amp;nbsp;&amp;quot;was given to a USAID foreign service advisor in 1976 after the first recognized Ebola outbreak was contained in Zaire. For me, it represents 50 years of U.S. commitment to stop Ebola at its source before it reaches our shores,&amp;rdquo; Fotheringham, who served as&amp;nbsp;the deputy director in USAID&amp;#39;s Office of Infectious Disease, told a crowd assembled before the U.S. Capitol&amp;nbsp;on Thursday. &amp;ldquo;This plaque was on my desk during what became USAID&amp;#39;s last Ebola response effort. When I was allowed back in my office for 15 minutes to collect my things, this was the very first thing that I grabbed because it is just symbolic of everything that was being lost.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;There&amp;rsquo;s currently an Ebola outbreak in Central Africa, and public health experts have argued that the Trump administration&amp;rsquo;s decision to fold USAID into the State Department, which pushed out nearly all USAID employees, &lt;a href="https://hsph.harvard.edu/news/ebolas-spread-fueled-by-cuts-in-humanitarian-aid/"&gt;has hindered response efforts&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Fotheringham was one of several former federal employees who relatd their experiences at the event recognizing the one-year anniversary of the&amp;nbsp;&lt;a href="https://www.govexec.com/workforce/2025/08/state-department-laid-them-then-it-promoted-them/407720/"&gt;layoff&lt;/a&gt;&amp;nbsp;of some 1,350 people at the State Department. Speakers, including union officials and members of Congress, contended that the staff reductions are damaging the United States&amp;#39; global standing.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The layoffs were&amp;nbsp;&amp;quot;unfair to individuals who had built up experience and careers over a period of time. It disrupted their lives in a way that they should never have had to experience and hurt their families,&amp;rdquo; said Sen. Chris Van Hollen, D-Md. &amp;ldquo;But they would be the first to tell you that, most of all, what it did was hurt our country. It hurt our capacity to advance our interests and values overseas.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;In particular, speakers cited negotiations to end the war in Iran as a process that is being hampered by there being fewer career foreign affairs staffers.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Instead of sending someone that&amp;#39;s competent that knows how to write an [a memorandum of understanding], they sent two real estate developers &amp;mdash; who have no idea what diplomacy is about &amp;mdash; to write an MOU,&amp;rdquo; said House Foreign Affairs Committee ranking member Gregory Meeks, D-N.Y.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Special envoy Steve Witkoff and Trump&amp;rsquo;s son-in-law Jared Kushner, both of whom are real estate developers, are spearheading the peace negotiations with Iran. Hostilities recently resumed in that war after the collapse of a ceasefire.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;While the Trump administration has argued that cuts to the government workforce in general are necessary to improve efficiency, Maryum Saifee, a former foreign service officer, said that feds with relevant expertise have been ordered not to work.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;When war broke out in Iran, many of us &amp;mdash;&amp;nbsp;foreign service officers &amp;mdash;&amp;nbsp;[our jobs] were still sitting in limbo. I&amp;#39;m fluent in Arabic. I served in Baghdad. So some of us volunteered to staff the evacuation task force,&amp;rdquo; she said. &amp;ldquo;Guess what the department did? They said &amp;lsquo;No thank you.&amp;rsquo; So we just sat on the sidelines.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Additionally, an information panel set up next to the press conference speakers reported that, as result of job cuts at State&amp;rsquo;s Bureau of Energy Resources, &amp;ldquo;the office built to weaken Iran&amp;rsquo;s oil leverage and keep [the Strait of] Hormuz open was shuttered seven months before the conflict that saw gas prices spike.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;In response to a request for comment, the State Department praised career employees&amp;rsquo; roles in responding to 2025 &lt;a href="https://www.state.gov/releases/office-of-the-spokesperson/2026/05/reaffirming-the-united-states-commitment-to-humanitarian-assistance-in-our-hemisphere"&gt;Hurricane Melissa&lt;/a&gt; in the Caribbean and &lt;a href="https://www.state.gov/releases/office-of-the-spokesperson/2025/12/upholding-the-cambodia-thailand-ceasefire"&gt;upholding&lt;/a&gt;&amp;nbsp;a ceasefire between Cambodia and Thailand.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;quot;The RIFs have not had any negative impact on our ability to respond to operations, our ability to plan and our ability to execute in service to Americans,&amp;rdquo; the spokesperson said in a statement to &lt;em&gt;Government Executive&lt;/em&gt;. &amp;ldquo;In fact, we have been able to respond quicker and more effectively, which was the entire point of the reorg &amp;mdash; to empower personnel in the field while allowing us to move at the &amp;#39;speed of relevancy.&amp;#39;&amp;quot;&lt;/p&gt;

&lt;p&gt;At Thursday&amp;rsquo;s press conference, Democratic lawmakers also expressed optimism that laid off State and USAID employees could someday rejoin the federal workforce.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Rep. Don Beyer, D-Va., touted &lt;a href="https://beyer.house.gov/uploadedfiles/foreign_service_test-free_reentry_act.pdf"&gt;new legislation&lt;/a&gt; that would exempt foreign service officers who were involuntarily separated or retired between Jan. 20, 2025, and Jan. 31, 2030, from having to take any written or oral test if they want to rejoin.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;There&amp;rsquo;s no reason you have to take the [Foreign Service Officer Test] again when you come back in,&amp;rdquo; Beyer said. &amp;ldquo;But I&amp;rsquo;m sure you&amp;rsquo;d pass it.&amp;rdquo;&lt;/p&gt;

&lt;div class="related-articles-placeholder"&gt;[[Related Posts]]&lt;/div&gt;

&lt;p&gt;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/07/16/071626_Getty_GovExec_CVH-1/large.jpg" width="618" height="284"><media:description>Sen. Chris Van Hollen, D-Md., speaks at a press conference on Thursday in front of the Capitol Building against layoffs at the State Department. </media:description><media:credit>Sean Michael Newhouse / GovExec </media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/07/16/071626_Getty_GovExec_CVH-1/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Ukraine will build 5M drones in 2026. NATO must learn how: deputy commander</title><link>https://www.defenseone.com/threats/2026/07/ukraine-will-build-more-5-million-drones-year-nato-must-take-notes-deputy-chief-says/414819/</link><description>The alliance must also take hard lessons from the U.S. war on Iran, said Air Chief Marshal Johnny Stringer.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Novelly</dc:creator><pubDate>Thu, 16 Jul 2026 12:50:04 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/07/ukraine-will-build-more-5-million-drones-year-nato-must-take-notes-deputy-chief-says/414819/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;&lt;strong&gt;LONDON&amp;mdash;&lt;/strong&gt;Ukraine is making a thousand&amp;nbsp;times more drones now than when Russia invaded four years ago&amp;mdash;and NATO must learn how, the alliance&amp;rsquo;s deputy military commander said Thursday.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;In 2022, Ukraine produced 5,000 drones, various. In 2026, they will produce, and I&amp;#39;m afraid I can&amp;#39;t give the figure, but let&amp;#39;s just say it is going to be well north of 5 million, of all flavors,&amp;rdquo; Air Chief Marshal Johnny Stringer told attendees at the Global Air and Space Chiefs Conference &amp;ldquo;So, for NATO nations, if 32 nations can&amp;#39;t kind of meet those figures, then frankly, what do we do?&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The U.S. war on Iran has shown how quickly a conflict can consume arsenals of costly, exquisite weapons, Stringer said.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Op Epic Fury has obviously had an impact on munitions as well, so assumptions that we may have had even months, not even a year ago, about what would be available when are now, in a sense, a little bit moot,&amp;rdquo; he said.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;These things cost a fortune,&amp;rdquo; he added. &amp;ldquo;You have to have them, but there&amp;#39;s a bunch of other things you can get in far greater numbers with a little bit more imagination.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The U.S. military has &lt;a href="https://edition.cnn.com/2026/07/12/politics/us-weapon-stocks-depleted-iran-war"&gt;heavily depleted&lt;/a&gt; its critical munition stockpiles during the Iran war. Coalition forces fired over 11,000 munitions in the first 16 days of the conflict, at a cost of about $26 billion, according to a &lt;a href="https://www.rusi.org/explore-our-research/publications/commentary/over-11000-munitions-16-days-iran-war-command-reload-governs-endurance"&gt;report&lt;/a&gt; by the Royal United Services Institute think tank.&lt;/p&gt;

&lt;p&gt;The leader of the Royal Air Force struck similar notes in his own speech.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Air Chief Marshal Harv Smyth praised the &amp;ldquo;overwhelmingly lethality&amp;rdquo; of the U.S. and allied use of airpower during Epic Fury, but he also pointed out problems with the operation.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The Iran conflict has also exposed the opposite side to that point: the saturation and sheer weight of modern retaliatory attacks. Air forces had to intercept a torrent of hundreds of ballistic missiles and thousands of attack drones,&amp;rdquo; Smyth said. &amp;ldquo;More Patriots were fired in the first few days of this campaign than during the last four and a half years in Ukraine. This is a sobering reminder of the importance of magazine depth, even in a short form.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The U.S. war also ate into fleets of exquisite aircraft. At least 42 aircraft have been destroyed or damaged, according to a &lt;a href="https://www.congress.gov/crs-product/IN12692"&gt;Congressional Research Service&lt;/a&gt; report. This includes fighters like the F-35 and &lt;a href="https://www.defenseone.com/defense-systems/2026/03/not-good-news-irans-damage-us-radar-plane-harms-militarys-battlefield-awareness/412538/"&gt;critical radar aircraft&lt;/a&gt; like the E-3 Sentry airborne early warning-and-control system.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Stringer said countries that are looking at sixth-generation aircraft should be cautious.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;A lot of discussion on sixth-gen seems to be almost solely about flashy aircraft,&amp;rdquo; Stringer said. &amp;ldquo;We have to define what we actually mean by sixth-gen air warfare, and then we can build the right mix of systems.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The U.S. war in Iran has stretched on for more than four months, and no immediate diplomatic end to the conflict has emerged. Stringer ended his speech by pointing to Epic Fury as an example of how the changing threat environment means the U.S. can&amp;rsquo;t quite manage two ongoing conflicts at once.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;A younger, better-looking, and thinner version of me that joined the air force joined it at a time when U.S. doctrine could reasonably expect to fight and win two separate theater campaigns,&amp;rdquo; Stringer said. &amp;ldquo;We are no longer in that place, and what you&amp;#39;re seeing through the likes of Epic Fury, but elsewhere, just geopolitics full-stop, and the demand signals being placed on air and space forces, means that simultaneity is now a thing. It&amp;#39;s not actually an abstract concept. Which means we&amp;#39;re going to have to prioritize. We&amp;#39;re going to have to make choices.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Gen. Kenneth Wilsbach, the U.S. Air Force&amp;rsquo;s chief of staff, told attendees&amp;nbsp;that Epic Fury &amp;ldquo;demonstrated the ability of modern air and space power to generate effects across vast distances at a speed unmatched by any other form of military power.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Wilsbach also praised allies&amp;#39;&amp;nbsp;support during the war in Iran, adding,&amp;nbsp;&amp;ldquo;The most effective air power is combined air power.&amp;rdquo;&amp;nbsp;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/07/16/stringer_8909309/large.jpg" width="618" height="284"><media:description>Royal Air Force Air Marshal Johnny Stringer, then the deputy commander of NATO Allied Air Command, right, speaks with media during the Bomber Task Force 25-2 media day at RAF Fairford, England, March 11, 2025.</media:description><media:credit>U.S. Air Force / Staff Sgt. Kristen Heller</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/07/16/stringer_8909309/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Space Force can’t figure out what personnel it needs for its missions, GAO says</title><link>https://www.defenseone.com/threats/2026/07/space-force-cant-figure-out-what-personnel-it-needs-its-missions-gao-says/414814/</link><description>As service leaders seek more money and headcount, thousands of “required” jobs went unfilled in 2025, watchdog agency found.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Novelly</dc:creator><pubDate>Thu, 16 Jul 2026 12:30:28 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/07/space-force-cant-figure-out-what-personnel-it-needs-its-missions-gao-says/414814/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;One-quarter of the jobs Space Force leaders say they need went unfilled in fiscal 2025, partly because the young service lacks a solid way to track and use troops, civilian workers, and contractors, the Government Accountability Office found.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The Space Force has not established a process or guidance to consistently and accurately determine its personnel needs to accomplish its missions. Relatedly, although it has estimated the number of contractor personnel supporting it, the Space Force does not have a process or guidance to accurately measure the number of contractor personnel and the nature of work they perform,&amp;rdquo; the GAO wrote in &lt;a href="https://www.gao.gov/assets/gao-26-107868.pdf"&gt;findings&lt;/a&gt; published Tuesday. &amp;ldquo;GAO also found that the Space Force is partly addressing personnel challenges, but its efforts are not guided by a comprehensive strategic workforce plan. Without such a plan, the Space Force may not be able to systematically plan for and manage a workforce that meets current and future mission needs.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The Space Force filled just 13,500 of the 18,000 positions it said it needed in 2025, and shortages in cyber, enlisted, intelligence, and support roles put the service&amp;rsquo;s missions at risk, investigators wrote after analyzing Space Force staffing data and visiting five bases as part of a Congressionally-ordered probe into the service&amp;rsquo;s workforce woes.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Even as the Space Force has continued to grow its workforce, officials have identified personnel shortfalls as a primary workforce challenge,&amp;rdquo; the report said. &amp;ldquo;GAO&amp;rsquo;s analysis found a 25 percent shortfall when comparing assigned personnel with total personnel requirements for fiscal year 2025. &amp;ldquo;&lt;/p&gt;

&lt;p&gt;Investigators said that the Space Force, the smallest of the military service branches, has a process for determining the number of guardians, civilians, and contractors it needs that is is &amp;ldquo;not consistent,&amp;rdquo; &amp;ldquo;outdated&amp;rdquo; and does &amp;ldquo;not reflect mission growth.&amp;rdquo;.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The report comes as the service&amp;rsquo;s top leaders &lt;a href="https://www.defenseone.com/policy/2026/01/space-force-probably-needs-twice-many-guardians-vice-chief-says/410910/"&gt;push to double&lt;/a&gt; the number of guardians and as it seeks a &lt;a href="https://www.defenseone.com/threats/2026/04/space-force-workers-budget-increase/413026/"&gt;$71 billion budget&lt;/a&gt; request in 2027.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Last year, the Space Force had 4,649 officers (30 percent), 5,336 enlisted (35 percent), and 5,407 civilian personnel (35 percent), according to the report. Service officials told the GAO that it needs more enlisted guardians for its force-generation models.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The proportion of officer to enlisted Guardians was approximately 1:1 (47 percent to 53 percent),&amp;rdquo; the GAO report read. &amp;ldquo;This is substantially higher than the average proportion of about 1:4 (20 percent to 80 percent) officer to enlisted personnel across the military services.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Service officials and officers who spoke with GAO investigators said other key roles are also undermanned.&lt;/p&gt;

&lt;p&gt;Senior Combat Forces Command officials also said there is &amp;ldquo;a critical deficiency of cyberspace expertise&amp;rdquo; within the service and senior field command officials &amp;ldquo;cited a shortage of intelligence analysts,&amp;rdquo; according to the GAO report.&lt;/p&gt;

&lt;p&gt;The shortfalls aren&amp;rsquo;t just within the Space Force. The small service relies heavily on the Air Force for many of its support roles like security forces, lawyers, and installation support. GAO investigators found &amp;ldquo;a 22 percent shortfall in the number of support personnel the Air Force provides to the Space Force&amp;rdquo; and added that could &amp;ldquo; increase risk&amp;rdquo; to the space service&amp;rsquo;s missions.&lt;/p&gt;

&lt;p&gt;One official from a Space Base Delta told GAO that a shortfall of funded civil engineering positions is &amp;ldquo;leading to a higher risk of mission failure, and that the Space Force is taking risk against wartime readiness requirements and Joint Force needs.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Another official from a Space Launch Delta told GAO &amp;ldquo;supporting increased space launch operations is becoming more challenging and unsustainable.&amp;rdquo; In one example, a Space Force delta had to close one of its six fire stations due to manning problems and the squadron can&amp;rsquo;t &amp;ldquo;meet National Fire Protection Association safety standards&amp;rdquo; and &amp;ldquo;providing enough fire crew support for launches leaves the remainder of the base vulnerable in case of an emergency.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;When the Pentagon unveiled the service&amp;rsquo;s budget request earlier this year, Jules W. Hurst III, who is performing the duties of the Under Secretary of Defense (Comptroller)/Chief Financial Officer, said workforce cuts implemented by Defense Secretary Pete Hegseth didn&amp;rsquo;t affect &amp;ldquo;critical efforts&amp;rdquo; like &amp;ldquo;space acquisition.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Space System Command, the service&amp;rsquo;s acquisition arm, lost roughly &lt;a href="https://www.defenseone.com/policy/2025/09/more-60k-defense-civilians-have-left-under-hegseth-officials-are-mum-effects/408375/"&gt;10 percent&lt;/a&gt; of its workforce during last year&amp;rsquo;s cuts. Maj. Gen. Stephen Purdy, acting assistant Air Force secretary for space acquisition and integration &lt;a href="https://csis-website-prod.s3.amazonaws.com/s3fs-public/2025-11/251120_Purdy_Panel_2.pdf?VersionId=OUVM8xNFziHM2p_fD7ruFVRfFUEq0P9q"&gt;said&lt;/a&gt; late last year that &amp;ldquo;we barely have enough acquirers to do all of the work that we have now.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The GAO said major Trump-administration initiatives, such as the Golden Dome missile-defense effort, will strain the understaffed acquisition workforce.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Officials expected that the development of the Golden Dome for America missile-defense system will increase demands on the Space Force&amp;rsquo;s acquisition, test and evaluation, and operator workforces.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The GAO made four recommendations to the Space Force.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Investigators said the service should &amp;ldquo;establish a process to accurately determine personnel requirements,&amp;rdquo; accurately track its total number of contractor personnel, evaluate what manning needs are for long-term goals, and &amp;ldquo;evaluate the effectiveness of the current arrangement for Air Force-provided base operating and other support functions for the Space Force.&lt;/p&gt;

&lt;p&gt;In their official response to the report, Defense Department officials concurred with all four recommendations.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/07/16/space_force_9654109/large.jpg" width="618" height="284"><media:description>U.S. Space Force Guardians of the 16th Electromagnetic Warfare Squadron (EWS) conduct training on the Bounty Hunter system at Peterson Space Force Base, Colo., April 23, 2026. </media:description><media:credit>U.S. Space Force / Dave Grim</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/07/16/space_force_9654109/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>DHS network intrusion was twice ruled a false positive before breach confirmed</title><link>https://www.defenseone.com/threats/2026/07/dhs-network-intrusion-was-twice-ruled-false-positive-breach-confirmed/414748/</link><description>Suspicious activity on the Homeland Security Information Network, which is being used to support World Cup games around the U.S., was first detected around mid-to-late May.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Mon, 13 Jul 2026 11:24:00 -0400</pubDate><guid>https://www.defenseone.com/threats/2026/07/dhs-network-intrusion-was-twice-ruled-false-positive-breach-confirmed/414748/</guid><category>Threats</category><content:encoded>&lt;![CDATA[&lt;p&gt;Department of Homeland Security personnel twice dismissed signs of cyber intruders inside the agency&amp;rsquo;s Homeland Security Information Network as harmless activity, allowing hackers to remain undetected inside for weeks and eventually steal credential files, according to an internal incident readout viewed by &lt;em&gt;Nextgov/FCW&lt;/em&gt;.&lt;/p&gt;

&lt;p&gt;HSIN was breached about two months ago, &lt;em&gt;Nextgov/FCW&lt;/em&gt; &lt;a href="https://www.nextgov.com/cybersecurity/2026/06/hackers-breached-dhs-information-sharing-network-people-familiar-say/414534/"&gt;first reported&lt;/a&gt; in late June. The network houses sensitive, unclassified data that&amp;rsquo;s shared between federal, state, local, industry and overseas partner organizations.&lt;/p&gt;

&lt;p&gt;Department investigators have still not determined the affiliation of the hackers, according to two people with knowledge of an ongoing probe into the incident. DHS may send staff to brief Congress on the hack in a classified setting in the coming weeks, added the people, who spoke on the condition of anonymity to communicate the department&amp;rsquo;s thinking.&lt;/p&gt;

&lt;p&gt;Between May 15 and May 24, the infiltration was detected by analysts inside FEMA, where they observed the hackers had altered files on testing and live servers, used a legitimate web-server program to run malicious code and deleted activity logs that could have exposed their movements, according to the readout. The activity was ruled a false positive.&lt;/p&gt;

&lt;p&gt;Between May 25 and June 3, the hackers used similar methods aiming to leave scant trace of their activity, setting off more alerts that were again dismissed as benign. On June 4, they installed hidden backdoors and stole credential data &amp;mdash; typically employed to verify users&amp;rsquo; identities and grant access to accounts or systems &amp;mdash; where personnel then declared a breach was active.&lt;/p&gt;

&lt;p&gt;It&amp;rsquo;s not clear why the intrusion was deemed benign two times over such a wide timeframe, but the incident highlights how a mistaken assessment can give hackers significantly more time to deepen their access into a target&amp;rsquo;s environment. The hack involved techniques meant to mask activity as normal, which, generally speaking, can make it very difficult for analysts to determine what is legitimate or not, one of the people said.&lt;/p&gt;

&lt;p&gt;It&amp;rsquo;s also unclear what materials, if any, were copied from HSIN systems, though the fact that hackers targeted credential files indicates they sought out access to accounts or systems beyond what they could initially reach.&lt;/p&gt;

&lt;p&gt;&amp;quot;The Department of Homeland Security is aware of a recent cyber incident involving a specific, unclassified legacy information sharing environment,&amp;quot; a DHS spokesperson wrote in the same statement&amp;nbsp;it provided earlier this month&amp;nbsp;that confirmed the hack.&amp;nbsp;&amp;quot;We immediately took action to isolate the affected systems, mitigate the vulnerability, and launch a comprehensive forensic investigation. There is no indication that classified networks were impacted, and the system remains operational for our partners. As this is an ongoing investigation, we cannot provide further operational details at this time.&amp;quot;&lt;/p&gt;

&lt;p&gt;Approved users lean on the network to securely access data, exchange requests with partner agencies, coordinate safety and security for planned events, respond to incidents and share information needed to protect their communities, &lt;a href="https://www.dhs.gov/homeland-security-information-network-hsin"&gt;per its website&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;HSIN has been used to support ongoing World Cup games and recent America250 events, Senate Intelligence Committee Vice Chairman Mark Warner, D-Va., said in a statement after the breach was reported.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The information in HSIN, while not classified, is highly sensitive, and its exposure risks national security,&amp;rdquo; he said at the time.&lt;/p&gt;

&lt;p&gt;As the United States hosts World Cup matches nationwide, the hack could raise questions about whether the intruders gained access to security plans, interagency communications or emergency response plans for one of the world&amp;rsquo;s most visible sporting events. It&amp;rsquo;s also possible that World Cup data was not a target.&lt;/p&gt;

&lt;p&gt;Nation-state and criminal hackers routinely target U.S. systems to gather intelligence, steal sensitive information and maintain access to government networks. In February, a suspected China-linked breach of an FBI surveillance system likely &lt;a href="https://www.nextgov.com/cybersecurity/2026/04/suspected-chinese-breach-fbi-system-exposed-surveillance-targets-phone-numbers/412612/"&gt;exposed&lt;/a&gt; the phone numbers of people the bureau was monitoring. Last fall, a &lt;a href="https://www.nextgov.com/cybersecurity/2025/09/widespread-breach-let-hackers-steal-employee-data-fema-and-cbp/408456/"&gt;widespread breach&lt;/a&gt; at FEMA let hackers make off with employee data from both the disaster management office and U.S. Customs and Border Protection.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.defenseone.com/media/img/cd/2026/07/14/071326DHSNG/large.jpg" width="618" height="284"><media:credit>Win McNamee / Getty Images</media:credit><media:thumbnail url="https://cdn.defenseone.com/media/img/cd/2026/07/14/071326DHSNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item></channel></rss>