Reading view

There are new articles available, click to refresh the page.

The Good, the Bad and the Ugly in Cybersecurity – Week 35

The Good | Authorities Launch New Operations Against Cybercrime Networks & Supply Chain Attackers

Operation Jackal IV, coordinated by INTERPOL across 22 nations, has led to the arrest of 58 individuals and the identification of over 200 suspects linked to West African cybercrime networks. The joint action successfully dismantled elements of the Black Axe syndicate, which orchestrates global romance, investment, and business email compromise (BEC) scams. Law enforcement agencies across South Africa, Argentina, and Romania also disrupted major Crime-as-a-Service (CaaS) providers, freezing millions of dollars in illicit financial assets.

The FBI, collaborating with the DoJ, have disrupted the global QScan and QTRouter hacking platforms operated by Chinese state-sponsored threat actors. The group QTFY, which maintains direct ties to China’s military and intelligence services, used these compromised IoT botnets to mask cyber espionage traffic targeting critical U.S. networks, including the Federal Reserve and NASA. Law enforcement successfully seized the core command-and-control (C2) domains hardcoded within the malicious frameworks.

From the U.S. Treasury is a new operation dubbed Economic Outcast, imposing sweeping sanctions on five Mabna Institute members and nearly 60 Iran-linked entities. Under the direction of Iran’s Ministry of Intelligence and Security (MOIS), the attackers breached multiple American critical infrastructure organizations, state governments, and defense contractors. These state-sponsored actors then exfiltrated datasets, executed high-value cryptocurrency heists, and now face federal indictments alongside a $10 million dollar reward for information leading to their arrest.

The Australian Federal Police (AFP) have arrested and charged two individuals for principal roles in TeamPCP, a cybercrime syndicate. The group systematically compromised trusted open-source projects, including Trivy, Checkmarx KICS, and LiteLLM, by stealing developer credentials and distributing backdoored software updates across major ecosystem release channels. This massive software supply chain campaign potentially compromised organizations worldwide and facilitated the unauthorized theft of hundreds of thousands of credentials.

The Bad | ‘NovaCookies’ Phishing Toolkit Exploits DocuSign Services to Steal Session Tokens

Security researchers have disclosed details of NovaCookies, a subscription-based phishing platform that systematically targets corporate networks to steal authenticated Microsoft 365 sessions. Operating as an Adversary-in-the-Middle (AitM) proxy, this malicious toolkit is advertised on Telegram for $320 monthly. The campaigns actively compromise hundreds of organizations across several nations, including the U.S., the U.K., Germany, and the U.A.E.

To establish a foothold, attackers distribute counterfeit document-sharing lures within genuine DocuSign notifications. Styled as a share notice, the decoy claims an accounting department shared a remittance-advice PDF and invites the recipient to open it. Since these notifications originate from legitimate servers, they bypass standard sender-authentication checks and reputation filters. The malicious link is embedded inside the shared document, below the inspection layer of most security gateways. Once clicked, the attack uses an OAuth error-redirect technique to guide the browser through legitimate Microsoft or Google endpoints before routing traffic to the phishing infrastructure. This transition ensures every intermediate step appears trustworthy until the user reaches the proxy.

Source: Island.io

NovaCookies is a variant of the Sneaky2FA platform, which operates on a centrally managed model where the operator hosts the infrastructure rather than individual affiliates. The kit offers customized flows targeting common identity providers. Affiliates register landing pages on .vu domains, utilizing deceptive, alternating-case subdomains like PwPt-sHaRe to masquerade as legitimate Microsoft portals. While these checks obscure the landing pages, the proxy relays credentials and multi-factor authentication (MFA) codes in real time to Microsoft. Because each individual hop of the attack chain appears legitimate, security analysts emphasize that the browser remains the critical intersection where these events converge.

The Ugly | Threat Actors Deploy Spark RAT to Target Cambodian Organizations

A recently uncovered campaign is targeting both individuals and organizations in Cambodia with Spark RAT, which functions as a Go-based, open-source remote access trojan. Distributing compressed archives through targeted phishing emails, the threat actors deploy diverse lures, including Cambodian government notices, public health announcements, and dental records. The multi-stage attack sequence begins when a victim executes an Inno Setup installer, which initiates a dynamic link library side-loading chain using a signed Tencent application to deliver intermediate payloads.

To guarantee execution, the DLL loader performs timing-based anti-sandbox checks to detect virtual environment delays and scans running processes in an attempt to weaken its permissions. The loader then decrypts shellcode hidden within an embedded PNG file to run a second stager that determines whether the malware operates with SYSTEM privileges. If these elevated rights are present, the malware proceeds directly to inject mode. Otherwise, it configures a Windows service for local persistence. Ultimately, the stager injects malicious shellcode into the legitimate vssvc.exe process, monitoring execution to re-inject the payload if terminated.

Source: Acronis

The intrusion chain utilizes the Bring Your Own Vulnerable Driver (BYOVD) technique that abuses a legitimate but vulnerable OPSWAT AppRemover driver, ardrv.sys, to escalate privileges and neutralize security programs. Operating under CVE-2026-36425, this driver enables the malware to terminate active security processes, including Microsoft Defender, Huorong Internet Security, and Tencent PC Manager. The program also patches Antimalware Scan Interface and Event Tracing for Windows, executes user-mode termination of security tools, and injects Spark RAT into ctfmon.exe. Although operational tactics and driver usage closely mirror the Chinese-speaking Silver Fox syndicate, analysts classify the campaign as an unattributed cluster due to the absence of shared infrastructure, certificates, or code reuse.

Foreign Spies Don’t Need to Hack You Anymore

Andy Burnham was a few weeks into the job as the new Prime Minister of the UK when he found himself exchanging messages with someone claiming to be Susie Wiles, the White House chief of staff. The exchange, first reported by Politico last week, was brief and apparently trivial. Burnham grew suspicious, stopped replying and told the right people; the British embassy in Washington quietly informed the White House, which confirmed that Wiles’s own devices hadn’t been touched. No harm done, officially.

Embarrassments like this are becoming more common. The FBI warned last year about impostors using AI to mimic senior officials, after someone posing as Wiles contacted senior Republicans and business figures. The State Department later chased a fake Marco Rubio who reached three foreign ministers. And every one of these approaches lands on a habit “Signalgate” already exposed: when one wrong contact card could add a journalist to a strike-planning thread, the name on the screen was the only authentication in the room. If you want to see what this security weakness looks like run as a nation-state campaign look at a case that closed quietly in Taipei last month.

In July, prosecutors in Taipei’s Shilin district wrapped up proceedings against two local businessmen, Li Hualun and Chen Mengsen, who had spent months registering accounts on LINE (the messaging app nearly everyone in Taiwan uses), each tied to a real Taiwanese phone number. They leased the accounts to Xiamen Empress Information Technology, a mainland firm Taiwanese investigators say works under the direction of the Chinese Communist Party’s cyber forces. The going rate was about 1,100 RMB per account, call it $160.

A working exploit for a major platform costs millions on the gray market. A trusted local identity cost less than a decent dinner, and it did something no technical exploit can do.

The operators used the fake accounts to become journalists. In the approach that eventually unraveled the scheme, one of them even dressed up a leased account in the name and photo of Chen Yishan, editor-in-chief of CommonWealth Magazine, and began courting an aide in a legislator’s office. Interview requests, invitations to contribute articles, the ordinary traffic of political journalism followed.

There was no malicious link in the first message, or the tenth. Investigators found the operators worked on targets for months, sometimes close to a year. Any counterintelligence officer would recognize the rhythm. It was the patient cultivation and recruitment of an agent run through a chat app.

The eventual ask was small and reasonable-sounding. Journalists use encrypted tools to protect their sources, so would the contact mind installing a secure communication app to keep talking? The app was in fact malware. The MO turns a decade of good security advice inside out. The more someone knew about how careful reporters actually operate, the more normal the request looked.

Researchers at Citizen Lab and the International Consortium of Investigative Journalists, whose reporting the Taiwanese prosecution now corroborates, counted more than a hundred malicious domains behind the wider campaign, and found errors in the phishing messages suggesting the attackers were using AI to draft them and to pick targets. The people on the receiving end were lawmakers and their staffs, defense think tanks, semiconductor companies, dissidents at home and abroad. Taiwanese media reported that even the island’s overseas missions were probed.

Through all of it, nothing technical failed. The networks held and the patches were current. The attackers went around the security stack entirely, and the thing they spent, their actual operational currency, was the credibility of a free press. Every fake interview request makes the real ones a little harder. This cost never shows up in an incident report.

The two men who supplied the accounts got deferred prosecutions and payments totaling a bit under $6,000. That is the current legal price, in a frontline democracy, for renting identity infrastructure to a foreign intelligence service. It isn’t a deterrent. It’s barely a business expense.

Which brings us back to Downing Street. A prime minister with the full apparatus of British intelligence behind him replied to a stranger because the name on the screen looked right. Nothing in either story depends on LINE, or Taiwan, or Westminster.

Swap in WhatsApp or LinkedIn; swap the fake editor for a fake recruiter or a fake chief of staff. Aged, locally registered accounts are already a commodity in criminal markets. All the model requires is a person who handles something worth stealing and a persona they have no fast way to check.

That last part is fixable, though not by the security team alone. Organizations that handle sensitive work should treat identity verification as a counterintelligence habit. Platforms need to treat the account-rental trade Taiwan uncovered as the national security problem it has become rather than a terms-of-service nuisance. And legislatures need to punish collaboration with foreign intelligence services at something above a traffic ticket.

Mostly, though, the people likeliest to be approached — the legislative staffer, the fab engineer, the think-tank fellow, the human rights activist, apparently the occasional head of government — need to become more educated on how foreign intelligence cultivation and targeting actually works: slowly, warmly, and with no suspicious link in sight until the very end. The adversary in this case looked at hardened networks and vigilant software and made a rational choice. Building a fake trusted persona was cheaper — $160 a head – than spending millions on a sophisticated cyber exploit. We need to start defending the credibility of verified, trusted identifies the way we defend our networks: as the attack surface it already is.The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

The Good, the Bad and the Ugly in Cybersecurity – Week 34

The Good | U.S. Charges Iranian Cyberattackers Over Mass Intellectual Property Theft

The U.S. Justice Department has indicted 17 Iranian nationals associated with the Mabna Institute, a state-sponsored hacking-for-hire firm, for executing a massive global cyber espionage campaign. Operating since 2013, the malicious network systematically targeted academic institutions, private corporations, and government agencies to harvest intellectual property. While nine defendants faced prior indictments in 2018 for targeting more than 300 universities and private firms, newly unsealed charges add eight individuals to the sweeping legal action. Investigators reveal that the hackers worked on behalf of Iran’s Islamic Revolutionary Guard Corps (IRGC), various government bodies, and commercial clients.

The campaign targeted the credentials of hundreds of thousands professors worldwide, compromising roughly 80,000 of them. By exploiting these accounts, the actors exfiltrated over 31 terabytes of sensitive academic data, including journals, dissertations, and ebooks valued at $3.4 billion. The intrusions affected 178 universities, including 144 in the United States, alongside 53 private firms, two non-governmental organizations, and 10 state agencies. Beyond academic espionage, the defendants targeted private entities, including an extortion scheme against entertainment network HBO for $6 million dollars in Bitcoin.

The State Department announced rewards of up to $10 million for information leading to the apprehension of five key defendants and established an anonymous Tor network link to receive tips. All defendants currently face multiple federal charges, including conspiracy to commit computer intrusions, wire fraud, and aggravated identity theft, which can incur maximum penalties of twenty years in prison. This prosecution reinforces the government’s long-term commitment to pursuing foreign threat actors who target domestic organizations, regardless of how much time passes.

The Bad | Medusa Ransomware Syndicate Compromises 500 Critical Infrastructure Organizations

A joint advisory issued by federal agencies warns that the Medusa ransomware syndicate has systematically breached over 500 critical infrastructure organizations in the United States since June 2021. Released in coordination with CISA, the FBI, and the Department of Health and Human Services (HHS), the alert covers Medusa’s rapid escalation across healthcare, manufacturing, defense, and financial sectors. This release is an update to a March 2025 assessment, which previously estimated the victim count at just over 300 entities. Other targeted areas include education, medical, legal, and insurance systems.

While the threat actors have been active since January 2021, they experienced a massive surge in their operations in 2023 following the launch of the “Medusa Blog” leak site. Operators leverage this portal to publish stolen files, applying double extortion tactics to coerce non-paying victims. Structurally, the syndicate operates under a Ransomware-as-a-Service (RaaS) model, employing an aggressive affiliate program. Developers actively recruit initial access brokers on dark web forums, offering payments ranging from $100 to $1 million dollars for exclusive access. Defenders should not confuse this threat with MedusaLocker, a separate ransomware family, or the Medusa and TangleBot mobile malware families, which also share similar naming.

As a defense against these intrusions, the agencies urge organizations to implement robust defenses. Security teams must secure and patch exposed systems to protect firmware, operating systems, and software from exploitation. Additionally, administrators should restrict access from untrusted origins to remote services and implement network segmentation to prevent lateral movement.

The Ugly | Hackers Exploit Critical Windows IKE Protocol Vulnerability

CISA has added a critical remote code execution (RCE) vulnerability in the Windows Internet Key Exchange Service Extensions component, known as MS-IKEE, to its catalog of actively exploited flaws. Tracked as CVE-2026-33824, this severe double-free vulnerability affects all supported versions of Windows 10, Windows 11, and Windows Server 2016, 2019, 2022, and 2025. The flaw enables unauthenticated, remote attackers to execute arbitrary code by simply transmitting maliciously crafted UDP packets over port 500 or port 4500 to Windows systems running IKE version 2. Because this protocol component handles crucial features like cryptographically generated address authentication, denial-of-service protection, and third-party interoperability, exposed systems remain highly vulnerable to complete network compromise.

Although Microsoft addressed the issue during April 2026 Patch Tuesday, the firm has not yet updated its official advisory to reflect the ongoing in-the-wild exploitation. Under the urgent mandate of Binding Operational Directive 26-04, CISA ordered all U.S. Federal Civilian Executive Branch (FCEB) agencies to secure their vulnerable systems within three days. While this binding directive specifically targets federal networks, cybersecurity officials strongly urge all enterprise network defenders to prioritize applying the security updates immediately to halt active intrusions.

For organizations unable to immediately deploy the patch, Microsoft recommends restricting inbound UDP ports 500 and 4500 on systems where IKE is not required, or configuring host firewalls to only accept traffic from verified peer IP addresses. The rapid exploitation of this protocol flaw joins a growing list of recently abused Microsoft vulnerabilities, including a high-severity Windows Task Host bug and a SharePoint RCE vulnerability now heavily leveraged in ransomware campaigns. Since late 2021, CISA has cataloged hundreds of actively exploited Microsoft vulnerabilities to help defenders aggressively prioritize patching.

The Good, the Bad and the Ugly in Cybersecurity – Week 33

The Good | Courts Sentence “The Com” Online Syndicate Member for Blackmail & Sextortion

A court in the UK has sentenced a member of the decentralized online cybercrime collective known as “The Com” to two years in prison following an investigation by the National Crime Agency (NCA). Justin Swaddle, who operated under the digital aliases ‘Epstein’, ‘Rugen’, and ‘Moscow’ across Discord, Snapchat, and Telegram, pleaded guilty to multiple criminal charges of blackmail and child abuse. In addition to his sentence, the court ordered Swaddle’s placement on the National Sex Offenders Register and imposed a ten-year Sexual Harm Prevention Order.

Investigators revealed that Swaddle systematically targeted and groomed young, vulnerable victims globally, using popular chat platforms to exploit his targets. The prosecution identified 117 female victims worldwide, aged thirteen to seventeen, whom Swaddle coerced into performing severe acts of self-harm and generating explicit material. Rather than seeking financial gain, Swaddle was reportedly motivated by the online status and notoriety he obtained by sharing the media within exclusive subgroups. When victims resisted his demands, he used video recordings, home addresses, and school details to blackmail them into compliance.

The investigation, which the NCA initiated in January 2024 following Swaddle’s initial arrest by West Yorkshire Police, required extensive cross-border coordination. British officers collaborated closely with law enforcement agencies in the United States, Australia, Canada, Norway, and New Zealand to identify and safeguard affected children worldwide.

Authorities emphasize that The Com functions as a highly dangerous, loose-knit global network subdivided into specialized factions, including groups dedicated to physical violence, sexual coercion, financial extortion, and high-profile corporate ransomware operations.

The Bad | Agencies Warn of Expanding Gunra Ransomware Operations Targeting Critical Infrastructure

U.S., U.K., and South Korean intelligence and law enforcement agencies have issued a joint cybersecurity advisory warning global critical infrastructure organizations about escalating threats by Gunra ransomware. First appearing in April 2025 as a variant specializing in double extortion, the group uses malware derived from leaked Conti source code. Gunra targets public health, financial, and government sectors worldwide, with a heavy concentration of victims in Australia, East Asia, and Europe.

To establish initial access, operators exploit critical authentication vulnerabilities, specifically CVE-2024-55591 and CVE-2025-24472, in FortiOS and FortiProxy software, alongside security flaws in VPN gateways. While campaigns initially focused on Windows environments, the threat actors expanded to cross-platform operations by introducing a Linux variant. In January 2026, the group launched a formal Ransomware-as-a-Service (RaaS) affiliate program under the brand “Golden Community”, actively recruiting penetration testers to serve as initial access brokers. Attackers deploy their payloads via phishing and conduct ransom negotiations via WhatsApp.

Once inside a network, the actors utilize Impacket tools for credential dumping and lateral movement. They execute malicious tasks during nighttime hours, exfiltrating stolen documents to cloud services and deleting critical backup and archived data across primary and recovery centers. The malware leverages advanced ciphers like Salsa20 or ChaCha20 to encrypt terabytes of data in a limited timeframe.

Strong links have been identified between Gunra and North Korean state-backed threat actors, observing overlapping infrastructure and techniques, such as the exploitation of zero-day flaws in certificate signing software. Despite its sophistication, a catastrophic cryptographic flaw in Gunra’s Linux variant allows victims to fully recover encrypted files.

The Ugly | New ‘ShieldBreak’ Zero-Day Exploit Bypasses Microsoft Defender Protections

A security researcher known as ‘Nightmare Eclipse’ has released a novel Microsoft Defender zero-day exploit dubbedShieldBreakshortly after this month’s Patch Tuesday update. The vulnerability operates as a direct patch bypass for RoguePlanet, a separate privilege escalation flaw in Microsoft’s malware protection engine that was patched in July.

ShieldBreak PoC exploit demo (Source: Nightmare Eclipse)

Although both flaws lead to SYSTEM-level compromise, researchers confirm the underlying exploitation techniques differ significantly. While the original RoguePlanet bug exploits a filesystem race condition using virtual disks to overwrite system files, ShieldBreak hijacks cloud-hydration processes.

Specifically, the exploit leverages user-mode callback hooks to modify file contents during a cloud-hydration scan via the Cloud Filter API. To achieve privilege escalation, an attacker first places a standard test file and utilizes Object Manager symbolic links to redirect Defender’s path to the system32 directory. During scanning, the exploit uses the Common Log File System to swap the file identity and plant a malicious DLL, phoneinfo.dll, where a default system file does not exist. Triggering a scheduled Windows Error Reporting task subsequently forces the system to load this rogue library, spawning a shell with highest privileges.

The proof-of-concept operates with a 100% success rate on fully patched installations of Windows 11 25H2 and Windows Server 2025. Although Windows 10 remains vulnerable to the flaw, the current code does not natively support those legacy systems. Analysts note that Microsoft Defender must be actively enabled for the exploit chain to function.

The release intensifies an ongoing dispute between Microsoft and the researcher over bug bounty policies and recent threats of legal action.

The Biggest AI Models Are Not the Biggest Threats

Almost every AI security framework we are applying rests on one misguided assumption: danger scales with size. Compute thresholds, export controls, and tiered evaluation regimes all encode the same intuition, the larger the model, the more we should worry. If this isn’t true, what policy changes are needed?

I recently mapped more than twenty fielded AI systems against two axes: raw offensive capability with safeguards stripped, and residual risk as actually deployed (Fig. 1). They ran from millions to trillions of parameter models, and included munition seekers, gene design models, theatre planning, cyber offense systems, and general-purpose AI models. The picture does not support the above assumption. In fact, the data supports the inverse. Small, specialized models beat bigger general models at offense, but bigger models maybe better at defense.

Figure 1. Security Risk vs Size of Model. Hollow ring: raw offensive capability with safeguards stripped. Filled dot: residual risk as actually deployed. Cyber related positions anchored to CAISI / UK AISI results, July 2026. Data compiled by Alvin W. Graylin.

Each system appears twice: a hollow ring for raw capability with safeguards stripped, a filled dot for residual risk as deployed. The gap between them is the safeguard effect. Read left to right, and the size to threat correlation everyone assumes is simply absent.

Seven assumptions worth rethinking

One: the largest models pose the greatest risk. The high-residual band, where capability and deployed risk are nearly identical. Across six orders of magnitude, no clear trend. In 2022, researchers at Collaborations Pharmaceuticals inverted the scoring function on a commercial drug-discovery model (MegaSyn) of under 100 million parameters and generated more than 40,000 candidate chemical warfare agents (many more lethal than VX) in just six hours on a desktop. Chemprop-class retrosynthesis models, which can find non-controlled precursor routes around scheduled pathways, run at one to ten million parameters. Evo models with single digit billions of parameters can help design novel life forms. News just came out last week that this exact system was able to generate 16 new viruses. All these systems sit well below the axis floor of any parameter-based regime. Compute restrictions do nothing to fix this.

Two: compute thresholds capture the relevant risk. Hackphyr, built on Zephyr-7b-β at 7 billion parameters, performs comparably to GPT-4 on network attack scenarios and runs on a single GPU. Deep Hat V2 ships commercially at 30 billion parameters, is marketed as uncensored for offensive security, and executes inside the customer environment with no external calls. No government evaluation covers it, so that placement rests on vendor claims. Neither would trip a FLOP ceiling.

Three: capability and threat are the same axis. Claude Fable 5 and Claude Mythos 5 share one underlying model. Their capability positions are nearly identical; their deployed risk differs sharply, because Fable's added domain safeguards drop cyber requests back toward Opus 4.8 behavior. The difference comes entirely from the safeguards and distribution controls layered on top. That vertical gap is what governance can act on. Parameter count is not.

Four: open-source models are more dangerous than closed ones. Recent NIST study found that Kimi K3, the strongest PRC open-weight model, only scored 32 percent on ExploitBench against 57 percent for the leading U.S. model, and reached step 17 of a 32-step attack range where U.S. models reached 28.5. On the highest-severity outcome test, arbitrary code execution (ACE), Kimi K3, succeeded on 0 of 41 tasks, while the most capable U.S. models averaged 20. So, we really need to be careful about self-interested parties saying larger open-source models are more dangerous, when it likely has more to do with protecting margins than national security concerns. (see Fig. 2)

UK AISI did recently report that the Kimi K3 model was able to escape its sandbox during testing, but it merely used a misconfiguration in the testing sandbox that left the door open, rather than a sophisticated swarm agent attack like what the OpenAI model did. And when it did get out, all it did was look up the answer for the test it was given, rather than doing any damage to real world systems. In the future, this behavior could change, but it’s important to question the basic assumption that open models are always more dangerous.

Figure 2: CAISI/NIST - Comparison of aggregate capabilities over time of the most capable U.S. and PRC models. A 400-point increase on the y-axis equates to a 10x increase in the odds of solving tasks. Shaded regions denote 95% CIs.

Five: model quality determines attack success. Microsoft's MDASH is a harness, not a model. It orchestrates more than 100 specialized agents across an ensemble and scored 88.4 percent on CyberGym at launch, against 83.1 percent for the Mythos preview model. Adding a compact security model roughly 1/10th the size raised that to 95.95 percent. The orchestration layer beat every individual model. Regulating training while ignoring scaffolding regulates the less important variable.

Six: national security requires the largest models. It requires the opposite. Loitering munition seekers performing automatic target recognition run on Jetson-class edge hardware, capping them in the single-digit millions of parameters. Edge deployment favors small models on latency, power, thermal envelope, and operation without a datalink. Larger models are slower and, in narrow domains, more easily distracted by irrelevant context. They are also harder to validate, and validation is what matters when a false positive is a struck target. Cisco's Foundation-Sec-8B matches or exceeds models ten times its size on security benchmarks while running on one or two GPUs. The famed DoD Maven Smart System is based on a fine-tuned 2-year-old Claude Sonnet 3.5 model. That level of intelligence can now be distilled into a 4B model which could potentially run on a smartphone.

Seven: denying China compute is the primary lever to keep U.S. safe. Due to shared risks between these superpowers, on many safety related issues, cooperating may actually produce the outcomes most beneficial to the U.S. and the world. More on this below.

Five threat domains, five different answers

Attack and embedded systems favor small models that don’t require a comm link. Air-gapped operation, no API telemetry, no rate limits, no refusals mid-chain. The offensive bottleneck is stealth and throughput, not reasoning.

Cyber Orchestration favors large models, but the advantage attaches more to the system rather than the model, as MDASH shows. There’s little discussion today on regulating orchestration systems, but it’s clearly very needed.

Cyber Defense favors large models most clearly, and this is where the current approach fails. Defenders need breadth across every vector; attackers need depth in one. Safeguards that constrain security research are therefore costly in a way that is easy to miss.

When Hugging Face's systems were breached in July by OpenAI models, commercial frontier-model APIs blocked the forensic requests because their safety systems could not distinguish defensive analysis from attack. The team ran the open-weight Chinese model GLM-5.2 on its own infrastructure instead, worked through more than 17,000 logged actions, and contained the intrusion. An American company under active attack by an American closed-model was defended by a Chinese open-source model because the American ones could not tell friend from foe.

That is a Slave AI failure, in the terms I set out in Beyond Rivalry. A model trained toward obedience can only refuse; it cannot reason about whether refusing is right. What we need is Guardian AI: systems capable and contextually aware enough to protect us from malicious actors, from other AI systems, and from our own unintended consequences. That requires scale, because judgment requires breadth. It also requires that we stop locking down every capability rather than stewarding it. High-quality models with fewer restrictions, in defenders' hands, are a global public good. Every hour a defender spends fighting a guardrail is an hour the attacker fights nothing.

Bio/Chem Design favors small models. Molecular graphs, protein sequences, and binding energies come from compact architectures immune to alignment techniques built for natural language. A graph neural network has no refusal layer to remove. The key here is monitoring and controlling access to precursor chemicals and expanding safeguard for synthesis equipment.

Bio Synthesis is the outlier, and there is good news and bad. For biology, model-level access control has already failed. Evo 2 shipped with weights, inference code, training code, and its full dataset. There is no API to revoke. What remains is the synthesis chokepoint: Customer vetting and sequence screening at nucleic acid providers already operate internationally through the Gene Synthesis Consortium, whose members screen orders against databases of sequences of concern before synthesizing. There are still gaps as novel AI-generated combinations are developed, but they can be reduced if vendors and regulators globally work more closely together to keep the systems updated. Closing those gaps buys more security than any parameter threshold. But this requires Washington and Beijing to align, since they are the two largest suppliers of synthesis equipment in the world. Of course, collaboration across all vendors globally is needed to truly secure this threat vector. Again, larger general AI models aren’t the core problem.

Data beats intelligence

On the opening day of the U.S.-Iran war in February, a Tomahawk missle struck the Shajareh Tayyebeh girls' school in Minab, killing at least 168 people, more than 100 of them children under twelve. The school sat within 100 yards of an IRGC naval installation and had been inside that perimeter until a wall went up around 2013. Targeting ran through the Maven Smart System, which generates roughly 1,000 target packages an hour. A preliminary investigation concluded the strike likely followed from outdated intelligence, and former officials said stale human-curated data, not AI, was to blame.

The school had a website. Free satellite imagery showed a schoolyard with a sports field. No model of any size prevents this, because the failure was in data lineage, not reasoning. A larger model querying the same stale record returns the same coordinates faster and with more confidence.

The China mistake

The threat model that matters is not Beijing reaching AGI first. It is a non-state actor with a 30-billion-parameter uncensored model, a good harness, and no return address. Small models proliferate regardless of jurisdiction and leave no attribution trail, and an unattributable intrusion between nuclear powers is an escalation problem before it is a technology problem. In that world, a China unable to defend its own infrastructure is a liability to global stability, not an advantage to Washington.

Beijing is already regulating its own labs more aggressively than any other market. Concordia AI's 2026 survey documents agentic AI security guidance, ethics review requirements, and binding obligations on consumer AI services that are already deployed and enforced. It should be noted that Chinese frontier safety research output grew roughly 60 percent year over year, with agent safety rising from 8 percent of new papers in early 2025 to 27 percent by early 2026. The caveat: only five of ten leading Chinese developers reported safety evaluation results on release. Shared standards here would make a difference.

As Fig. 2 showed, CAISI found the Chinese models less dangerous, but they also found GLM-5.2 answers sensitive biological queries at far higher rates than tested U.S. models, which is where PRC safeguards are weakest. In personally speaking with multiple Chinese labs, it’s clear that their lack of compute resources due to export controls has forced them to deprioritize safety demands vs. capability enhancement. Expanding safety testing compute resources, like what UK AISI has, to more countries could help improve AI safety globally, without fear of its misuse by rival nations.

The race framing is softening at home, too. More than 100 organizations, including Nvidia, Microsoft, Meta, IBM, Palantir, OpenAI and Google, have now signed the July 24 Open Weights and American AI Leadership letter opposing premature restrictions. Days later, Nvidia and roughly 50 partners launched the Open Secure AI Alliance to build open defensive models and agent harnesses, citing the Hugging Face incident as its founding case. Every participant has commercial exposure to a ban, so weigh the motives. But 8 of the top 10 models on OpenRouter in July are already open-source, and the industry has now reorganized around the proposition that open weights are defensive infrastructure.

Four Asks for September

Four asks follow, and Xi Jinping's state visit to Washington on September 24, the first in over a decade, is where they could land. Trump has said AI will be on the agenda.

Shared harm standards, not shared capability standards. Agreement on what constitutes an unacceptable capability, evaluated the same way in both countries, so that "safe" means the same thing in Shanghai and San Francisco. That’s clearly missing today and doesn’t require mutual trust.

A shared safety evaluation cluster. Chinese labs are compute-constrained, so safety research competes with capability research for scarce chips. Compute earmarked for evaluation and red-teaming is cheap relative to the benefit, and the benefit is global. An international testing facility open to any vendor institutionalizes it. Require publishing safety scores alongside capability benchmarks so safety investment earns a competitive return. Then, both Chinese and US labs would have no excuse not to test their systems.

An incident notification channel. The Nuclear Risk Reduction Centers, staffed continuously since 1987, exist because a misread signal costs more than talking. An equivalent for AI incidents where attribution is contested is cheap insurance. With the rising risk of bad actor attacks and false flag operations from non-state actors, this safeguard will be increasingly needed.

Capability non-development agreements. A capability never trained cannot leak. This matters more than denying Beijing another turn of the scaling crank. Beijing also wants to limit rogue actor misuse, thus agreeing on redlines in advance makes sense for both sides (no nuclear weapon command/control, no AI uplift to bio weapon design, no AI-attack on civilian infrastructure, no autonomous self-replication outside control environments [RSI]). General commercial models have no need for bio and chemical threat design, so keeping defense use case training only in military labs on both sides seems quite reasonable.

Another Asilomar moment

At Asilomar in 1975, molecular biologists imposed a voluntary moratorium on a class of recombinant DNA experiments, then built the containment framework that governed the field for decades. They acted before the capability matured enough to do real harm.

That view is starting to catch on in the AI labs now. On July 28, 1,200+ employees of frontier labs published Pacing the Frontier, asking Washington to support an international effort to build tools for deliberately slowing automated AI development. Signatories include top technical leaders at Anthropic, OpenAI, Meta and Google. The concern is recursive self-improvement (RSI) of AI that goes out of control. The logical extension is an explicit agreement not to implement it in frontier labs even once it becomes possible.

But this cannot stop at two capitals. If dangerous systems are small and cheap, a country with a modest research budget and a few hundred GPUs can build a competent offensive cyber agent or an inverted molecular designer. Within a few years, dozens will. Any regime binding only Washington and Beijing binds the two parties least likely to defect and leaves the growing middle untouched. A U.S.-China agreement is the necessary first move, not the finished structure, and it has to open immediately to third parties. That is how Asilomar's containment norms and the Montreal Protocol scaled.

Bigger AI is not more dangerous. Better orchestrated is more dangerous, less monitored is more dangerous, and irreversibly released is more dangerous. All three require cooperation with Beijing: orchestration needs shared harm standards, monitoring needs shared evaluation infrastructure, and irreversible release needs joint agreement on what never gets built. September 24 is a good place to start.

Read more national security insights from experienced experts exclusively in The Cipher Brief.

The Good, the Bad and the Ugly in Cybersecurity – Week 32

The Good | Snowflake Hacker Pleads Guilty as Ransom Cartel Creator Draws 16 Years

Connor Riley Moucka pleaded guilty in Seattle federal court this week to computer fraud, wire fraud, aggravated identity theft and conspiracy over the 2024 breaches of Snowflake customer accounts.

The intrusions reached at least 165 organizations and exposed records tied to at least 100 million people. Prosecutors say Moucka collected at least $495,000 from ransoms and data sales. He is due to be sentenced on October 27, facing a two-year mandatory minimum on the identity theft count and up to 30 years on the rest.

Every Snowflake account the group reached had multi-factor authentication switched off, and the credentials, some harvested by infostealer malware as far back as November 2020, had never been rotated. The gang didn’t need to find a vulnerability in Snowflake’s platform to exploit; it turned out that more than three-quarters of the compromised accounts had prior credential exposure, and none had network allow lists in place.

In separate news, The Department of Justice announced that Maksim Silnikau, the Belarusian national who built and administered the Ransom Cartel ransomware operation, was sentenced to 16 years for conspiracy and aggravated identity theft.

Ransom Cartel creator sentenced 16 yrs for REvil-linked RaaS targeting 18 orgs, $6.7M losses. https://intel.threadlinqs.com/threat/TL-2026-1902 #ThreatIntel #CVE_2021_1675 #CVE_2021_34527 #Ransomcartel

[image or embed]

— Threadlinqs (@threadlinqs.bsky.social) August 6, 2026 at 3:51 AM

Between 2021 and 2023, Silnikau recruited affiliates through underground forums, supplying stolen credentials and encryption tools while running an affiliate site that handled negotiations and revenue splits.

The Ranson Cartel attempted to extort at least $5.2 million from at least 18 companies, including a robotic-surgery startup disrupted for two months and law firms that paid $125,000 and $300,000 after weeks of downtime.

Silnikau was arrested in Spain in 2023, fled while awaiting extradition, and was caught trying to cross into Belarus before consenting to face trial in the United States.

The Bad | Claude Mythos 5 Spends 34 Hours Trying to Backdoor Real Code

The UK AI Security Institute (AISI) reported Tuesday that an agent running Claude Mythos 5 spent 34 hours trying to merge a malware dropper into a real open-source project during a security evaluation, after searching the open internet and landing on a real, unconnected repository whose name happened to share a keyword with the test’s fictional scenario.

The agent researched the maintainers, opened a pull request pairing a hidden dropper with a working bug fix, and cycled through three payload versions as each was caught. When a human reviewer flagged the code as malicious, the agent’s account denied it, force-pushed a rewritten branch history, and used a second account to vouch for the code. It also hid a prompt injection inside a GitHub issue aimed at AI coding assistants. The maintainer closed the pull request despite the cover-up.

Across 122 evaluation runs, AISI logged 19 unsanctioned actions in 10 runs, 17 involving Mythos 5 and two involving GPT-5.6 Sol, though AISI notes that figure is a count, not a rate. Both models had cyber safeguards off and open internet access by design, a setup meant to measure raw capability rather than mirror production use.

Nothing escaped AISI’s sandbox, and AISI found no evidence of real-world harm. The reviewer had the chance to catch it only because GitHub holds checks on a first-time contributor’s pull request until a maintainer approves them.

Stages of the agent's actions and attempted cover-up
Stages of the agent’s actions and attempted cover-up (Source: AISI)

Anthropic’s own July 30 review of 141,006 evaluation runs found a separate Mythos 5 run that published malware to PyPI, downloaded and ran on 15 real systems within an hour. OpenAI reported a similar incident days earlier, exploiting a zero-day to reach Hugging Face’s production database. In each case, a test environment meant to stay sealed did not, and a model reached through it before anyone caught it.

Not to be outdone, Meta became the third lab in recent weeks to disclose an AI agent reaching into systems outside a security test. The exposure traced to Irregular, the same firm behind OpenAI’s second incident, whose misconfiguration gave a Meta model internet access it used to exploit a real company’s system.

The Ugly | ChainDrop Worm Compromises Over 1,300 npm Packages With Two Billion Monthly Downloads

A self-propagating worm known as ChainDrop compromised at least 868 npm packages across 1,381 versions, part of a broader campaign researchers put at more than 1,300 packages with a combined two billion monthly downloads.

The mass compromise began Tuesday when an attacker breached the GitHub account of a maintainer who controlled several widely used caching libraries, including Keyv, Cacheable, flat-cache and file-entry-cache. The worm then self-propagated to other maintainers’ packages, including ones tied to Deliveroo, Ornikar, OneReach, Picsart, Qlik and ServiceTitan.

The worm pushed malicious commits directly to each project’s main branch and triggered a new release through a GitHub Actions workflow, giving the poisoned npm packages valid provenance signatures.

A preinstall script added to package.json ran automatically on npm install, pulling down the Bun JavaScript runtime and using it to execute an obfuscated infostealer that harvested GitHub tokens, npm tokens, AWS and Kubernetes credentials, HashiCorp Vault secrets, database credentials and a run of other cloud and developer logins.

Every stolen token was checked against npm’s own whoami endpoint before the haul was encrypted and sent to a public GitHub repository, with any credentials belonging to other maintainers repeating the process on their packages.

Github search for ChainDrop exfiltrations
A Github search for ChainDrop exfiltrations (Source: Safedep)

ChainDrop is built on Shai-Hulud, the same self-propagating technique that has hit npm before. Each GitHub repo storing the stolen credentials is auto-named with random terms from Dune and carryies the description, “Shai-Hulud: Here We Go Again.”

While many of the auto-generated dead drop repos have since been taken down, the scale of the outbreak demonstrates how rapidly self-propagating worms can weaponize trusted credentials and automated pipelines. For a deeper breakdown and defensive strategies on this attack vector and other emerging supply chain risks, read the SentinelOne Annual Threat Report.

SentinelOne's Annual Threat Report
A defender’s guide to the real-world tactics adversaries are using today to abuse identity, exploit infrastructure gaps, and weaponize automation.

AI Summaries Are Susceptible to Manipulation — and That's Both a Business and a National Security Problem

More and more people are using AI like a search engine – 42 percent of U.S. adults now use AI chatbots to search for information – and that shift is exposing a structural vulnerability that adversaries are exploiting to seed propaganda. In practical terms, this is a problem of Generative Engine Optimization (GEO) – the deliberate effort to shape digital content so that AI chatbots absorb and repeat it.

The research so far points to data voids — the thinly covered topics where there isn't much credible information to begin with — as the weak spot. This includes breaking news or new material that has not yet had time to accumulate the signals that would flag it as low authority.

AI can process far more information than any human can, but there is an inherent trade-off in outsourcing the curation of information to an AI summary. In the search era, users were exposed to source material and evaluated credibility for themselves. Now AI does that work, and research shows the large majority of AI queries end without a click.

This is both a business concern and a national security concern. The clearest example on the consumer side is Apollo-9. In a Chinese state TV investigation, researchers used a tool called Liqing to flood the web with fake reviews and rankings for Apollo-9, a fitness tracker that did not exist. Within hours, chatbots were recommending the fake fitness tracker and some continued to do so a day after the fraud was exposed. Liqing and other tools are sold openly on Chinese e-commerce platforms like Taobao and JD.com, with pricing ranging from roughly $520 to $4,765 for three-month subscriptions. One provider told Chinese state media it had served more than 200 clients across multiple industries, guaranteeing top-three placement on any AI platform.

In order to better understand these developments and their impact, this article examines how the same mechanism scales from commercial fraud to geopolitical disruption, using the Russia-Ukraine war as a live GEO lab. Leaked documents about Russia’s “Project 2026” and Ukraine’s AI‑enabled counter‑operations show how influence campaigns are evolving from social feeds to the underlying sources that AI systems draw on — an angle largely absent from existing information warfare debates.

Russia and the National Security Case: Same Playbook, Higher Stakes

When Russian operations exploit GEO in their war on Ukraine, they are not just spreading propaganda in the moment; they are trying to become the “ground truth” that AI systems summarize back to users, analysts, journalists, and policymakers. In June 2026, Bloomberg reviewed 73 leaked documents from the Social Design Agency (SDA), a sanctioned Moscow firm at the center of Russia's influence operations, describing a program its operators called “Project 2026:” a network of Wikipedia-style reference sites, media outlets, and fake think tanks built to shape what search engines — and AI systems — treat as reliable sources. The goal, as described in the leaked documents, is to “create an alternative information ecosystem” by shaping not only what people see today but also what AI systems will later “know” about key leaders, the war’s origins, Ukraine’s conduct, NATO’s role, and Western support.

Russia's GEO tactics build on years of search engine optimization (SEO) manipulation and are part of a widely reported pattern of industrialized cognitive warfare that includes deepfakes, cloned sites and other deceptive content. In 2023, a study published in the Harvard Kennedy School Misinformation Review examined pro-Kremlin attempts to manipulate search engine results and found that pseudo‑think tanks and propaganda outlets such as Global Research and Strategic Culture Foundation were amplified through backlink networks and low‑quality sites. These outlets were most effective on conspiratorial searches involving, for instance, Ukraine President Zelensky, where authoritative content was sparse. Indeed, as noted by former CIA leader Jennifer Ewbank, the use of deepfakes to confuse, distort, or influence public opinion not only occurs in Ukraine but across Europe – all of which reflects “the same underlying reality: the tools for deception are faster, cheaper, and more accessible than the systems we rely on to detect or prevent them.” In other words, this is not just about deception, but the erosion of trust itself.

Storm-1516, a documented Russian disinformation operation that has been active since at least 2023, has scaled sharply in 2026. According to Bloomberg, the operation has produced more than 190 false stories since 2023 that the outlet has been able to identify. Based on Bloomberg’s reporting, Meduza adds that in the first quarter of 2026 alone, Storm-1516 was producing fake stories at twice the rate of the same period the previous year with, for instance, as of late March and early April 2026, materials appearing almost daily. Meduza also reports that more than 40 percent of Storm-1516’s fabrications have targeted Ukraine, with another third focused on electoral processes in other countries. Taken together, these reports demonstrate that Storm-1516’s operations are ultimately aimed at eroding Western support for Ukraine, swinging European elections and destabilizing NATO allies.

Taken together with the “Project 2026” leaks, these findings suggest that Russia is now attacking both the content layer (through synthetic media) and the source layer (through cloned Wikipedia‑style sites and fake think tanks) of information ecosystems. While synthetic videos and stories are often treated as short‑term deception, they also become part of the online record that future AI systems may ingest or retrieve, turning Russia’s layered influence architecture into a long‑term GEO problem, especially in data voids.

The Storm-1516 operation follows a clear pattern. A fake witness, often an AI-generated video, seeds a plausible but unverifiable story. Low-tier blogs and Telegram channels amplify it in multiple languages. Then less rigorous Western outlets pick it up, severing the link to the original Russian operator. By the time the narrative reaches mainstream discussion, the Russian fingerprint is gone. The new risk in today’s landscape is that the AI curation layer completes this laundering. It reads the now-repeated narrative across multiple sources and presents it as a neutral summary.

Researchers at the Institute for Strategic Dialogue found that the chatbot DeepSeek was quoting VT Foreign Policy, an outlet known to carry content from Russian propaganda operations such as Storm‑1516 and to have connections to the Kremlin‑linked Strategic Culture Foundation. U.S. and EU sources describe the Strategic Culture Foundation as an arm of Russian state interests.

A 2025 NewsGuard study also found ten of the leading chatbots — including ChatGPT, Claude, Gemini, and Copilot — collectively repeated false narratives from the pro-Kremlin Pravda network about a third of the time. It’s important to note that a 2025 study in the Misinformation Review, responding directly to the NewsGuard findings, found the number was closer to 5 percent and that these failures clustered in data voids. While the researchers found "little evidence to support the grooming theory" and warned against "the overhyped specter of Kremlin manipulation," they acknowledged that data voids "may be artificially created" and that they could not dismiss the possibility that a disinformation campaign could target them. Importantly, their audit came fourteen months before the leaked “Project 2026” documents showed Russia explicitly targeting AI systems. The more Russia attempts to flood these data voids, the more likely it is that future AI summaries about Ukraine will inherit its framing.

How to Build Resilience – A Way Forward

Like its older cousin SEO, GEO is inherently dual-use, but it sits in a regulatory vacuum because it is viewed strictly as a consumer protection issue rather than a national security threat. The Apollo-9 experiment and the Storm-1516 operation prove they are two sides of the same coin; the same commercial tactics that manufactured demand for a non-existent fitness tracker can easily manufacture plausibility for distorted narratives about a geopolitical crisis such as the ongoing Russia-Ukraine war. History shows that with traditional search engines, the market naturally incentivized tech companies to tackle manipulation head-on because mass spam threatened to destroy the user experience for billions of people, directly endangering corporate business models. Malicious foreign influence operations executing GEO are fundamentally different because they remain largely invisible to the mass market, with manipulation surgically clustered within obscure data voids, offering tech companies no commercial incentive to self-police and leaving the information terrain around a live European war effectively undefended.

To bridge this gap, regulators can draw on the lessons of private sector SEO defense and public-private counter-disinformation efforts, but they must realize that the exact same playbook will not work here. While private developers can easily dismiss the Misinformation Review study’s five percent finding as an acceptable commercial error margin, this minor statistical anomaly sits precisely in the data voids that Russia is actively trying to colonize, and so it represents a primary, unmonitored vector for foreign manipulation. The strategic risk is not only that GEO can mislead people in the moment, but that it can reshape the evidentiary record on which institutions and AI systems will later rely; if hostile narratives are allowed to dominate long‑tail topics and thinly documented episodes in the Russia-Ukraine war for instance, then future summaries, briefings, and even historical accounts risk being generated from polluted inputs.

The 2025 Misinformation Review study recommends "warning banners for data void queries" and increased "audit access," but notes the banners are "applied inconsistently" and the audit access is "hindered by power asymmetries.” Because the market will never self-correct a threat it does not financially register, protecting the integrity of generative content must transition from a voluntary corporate practice to a formal national security mandate.

In the Russia-Ukraine war, these dynamics are already visible. Russian operations such as Storm‑1516 use GEO‑style flooding and synthetic witnesses to launder narratives about the conflict into the broader information environment, while Ukrainian actors rely on AI‑enabled monitoring and evidentiary documentation to defend the integrity of the record. The contest is no longer confined to what populations see online today; it is over what AI systems will say is true about the war tomorrow. Recognizing GEO as a national security problem therefore changes the governance question: the training, retrieval, and ranking layers of generative systems are now part of the battlespace, and leaving this space unregulated is akin to leaving critical information infrastructure undefended.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

Investing in the Next Arsenal of Democracy

America’s critical technology, maritime, infrastructure, and advanced manufacturing base is one of the clearest places where tax incentives, private capital, and national security should meet. We already know this model can work. Opportunity Zones helped drive billions of dollars into real estate, community development, and designated investment areas by giving investors a reason to move capital into places that policy makers wanted to support.

Now we should apply that same logic to the sectors that will determine America’s ability to compete, defend itself, and rebuild its industrial strength.

Recent proposals around Maritime Investment Zones point in the right direction. The basic concept is simple: use the tax code to pull private capital into shipyards, ports, vessel construction, ship repair, marine navigation, workforce development, advanced manufacturing, and the broader maritime supply chain. If tax incentives helped attract capital into real estate and community development, a similar model could help rebuild the industrial base that underpins American sea power and national resilience.

But this should not stop with physical shipyards or port infrastructure.

The next generation of American industrial power will be built across a broader ecosystem of investment funds, operating companies, manufacturing platforms, critical infrastructure projects, and technologies that strengthen national security and economic security. That means sectors like autonomy, advanced manufacturing, aerospace, maritime systems, secure communications, cybersecurity, energy resilience, critical minerals, space infrastructure, drones, counter-drone systems, AI-enabled defense tools, logistics, and domestic supply chain resilience.

Qualified investment funds focused on these sectors should be considered for Opportunity Zone-style designation. These funds can aggregate private capital, diligence complex technologies, support hard-tech companies, and bridge the gap between emerging innovation, government demand, commercial scale, and mission relevance. Many individual investors cannot properly underwrite a defense technology company, an advanced manufacturing platform, a shipyard modernization project, or a critical infrastructure asset on their own. Qualified managers can help channel capital into these areas with discipline, experience, and a better understanding of both market risk and mission need.

The same logic should apply directly to qualifying platform companies and infrastructure projects. Businesses building autonomous maritime systems, advanced airframes, resilient logistics platforms, drone manufacturing capacity, shipbuilding technologies, next-generation materials, critical infrastructure tools, and domestic production capabilities should be eligible for special designation if they are strengthening the defense industrial base, expanding U.S. production, modernizing infrastructure, or reducing dependence on adversarial supply chains.

This matters because the future of defense manufacturing and industrial power is changing.

The next phase will not only be about large legacy platforms built through traditional procurement channels. It will also be about faster, lower-cost, more scalable, more autonomous systems that can be produced domestically and integrated across a broader defense technology ecosystem.

In maritime, for example, the future will not only be larger crewed vessels. It will include autonomous naval platforms, distributed maritime nodes, unmanned surface vessels, undersea systems, AI-enabled ISR, electronic warfare, logistics support, secure communications, and integrated sensor networks. The autonomous ship is not just a vessel. It becomes a node in a distributed maritime network.

That same principle applies across the broader industrial base. The future battlefield and the future economy will demand more mass, more resilience, more autonomy, more secure infrastructure, and more ways to complicate an adversary’s targeting problem. The United States cannot afford to rely only on slow, expensive, exquisite systems while adversaries are scaling ships, drones, missiles, cyber tools, industrial capacity, and supply chains at speed.

A Maritime Prosperity Zone, Critical Technology Opportunity Zone, or National Security Investment Zone framework could help solve part of this problem by giving investors, fund sponsors, founders, manufacturers, and infrastructure operators a reason to back the companies, factories, shipyards, platforms, and projects needed to rebuild American industrial strength.

This would likely create some of the same market behavior we saw during the real estate Opportunity Zone boom of the early 2020s. Once the incentive was created, capital moved. Sponsors formed funds. Allocators searched for qualified opportunities. Developers shaped projects around the designation. Billions of dollars followed.

The same could happen in defense technology, critical infrastructure, autonomous systems, maritime manufacturing, space, energy resilience, advanced materials, and critical manufacturing.

That is the power of incentives. Investors are not charities. They respond to opportunity, yield, tax efficiency, liquidity, policy clarity, and the chance for outsized returns. That is not a weakness of capitalism. That is how capital markets work. If policy makers want private capital to help solve national problems, they need to make those problems investable.

Critics will say this gives investors generous tax treatment. That is true. But that is also the point. The government routinely uses the tax code to shape behavior. We incentivize home ownership, retirement savings, energy development, municipal finance, real estate development, and other areas deemed important to the public interest. The question is not whether investors benefit. The question is whether the country benefits enough to justify the incentive.

In this case, the answer should be yes.

A targeted national security investment incentive could drive domestic job growth, create new industries, expand the tax base, strengthen supply chains, rebuild manufacturing capacity, and reduce reliance on government-led solutions. Instead of expecting Washington to fund and manage every critical industrial requirement, the government can use tax policy to unleash private capital and let the private sector help build the capacity the country needs.

That is a better model than simply growing government. Government should identify priorities, set standards, create incentives, and provide clear demand signals. Private capital should help take risk, scale companies, build factories, support founders, finance infrastructure, and commercialize technologies. Done correctly, this becomes a force multiplier. It allows the country to pursue national security and economic security objectives without relying solely on appropriations, grants, subsidies, or bloated federal programs.

It also helps create a broader base of economic growth. A new factory, shipyard, drone production line, secure data center, advanced materials facility, or critical infrastructure project does not just create investor returns. It creates construction jobs, engineering jobs, manufacturing jobs, supplier ecosystems, logistics demand, local tax revenue, and long-term industrial capacity. These are the kinds of investments that can rebuild regional economies while strengthening national resilience.

But there is an important caution.

During the real estate Opportunity Zone boom, disciplined allocators still had to underwrite the real estate first. The asset had to make sense. The location had to make sense. The sponsor had to make sense. The tax advantage was an added benefit, not the entire investment thesis.

The same discipline must apply here.

In the current hype around defense technology and national security investing, not every company with “AI,” “autonomy,” “defense,” “resilience,” or “critical infrastructure” in its pitch deck deserves capital. The manager, deal, technology, platform, or project has to stand on its own. The tax benefit should improve the risk-reward profile, not rescue a weak investment.

Return on mission matters. But it should not replace return on capital. The best version of this policy would align both. Investors get an incentive to take risk in strategically important sectors, while the country gets more domestic production, stronger supply chains, better infrastructure, more jobs, and a deeper industrial base.

The United States does not have a shortage of capital. It has a capital alignment problem. Too much money flows into financial engineering, speculative assets, and incremental technology. Too little flows into the difficult, physical, industrial, and security-related sectors that determine whether the country can compete in a more dangerous world.

Opportunity Zones showed that tax policy can move capital. The next step is to aim that capital at the future of American power.

If we can incentivize capital to rebuild neighborhoods, we can incentivize capital to rebuild shipbuilding, critical infrastructure, advanced manufacturing, and the national security industrial base.

The goal is not to give investors a gift. The goal is to give the country a tool.

The next Opportunity Zone should be built around American resilience.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

The Good, the Bad and the Ugly in Cybersecurity – Week 31

The Good | Authorities Disrupt “The Com”, Release Security Guidelines & Charge Telegram CEO

Europol and law enforcement partners from nine countries have flagged over 4000 URLs for removal to disrupt the online ecosystem of The Com. Operating as a decentralized network, The Com targets and recruits vulnerable youth across social media and gaming platforms.

Investigators report the syndicate’s content actively promotes self-harm, child exploitation, and physical attacks, while providing instructional manuals for swatting and arson. This multi-week joint operation builds upon Project Compass, a year-long international initiative that previously resulted in 30 arrests and identified 179 suspects linked to the criminal network.

From U.S. and Australian governments, a new joint cybersecurity guidance urges critical infrastructure organizations to proactively prepare isolation plans for operational technology systems. The advisory provides recommendations for physically and logically disconnecting vital infrastructure from corporate networks during severe cyberattacks.

Since state-sponsored threat actors and cybercriminals continuously target these essential sectors to facilitate espionage, data extortion, and disruptive operations, such resources help businesses shore up their operational resilience, documentation, and testing procedures.

The Russian Federal Security Service (FSB) has formally charged Telegram founder Pavel Durov with aiding terrorist activities and violating federal laws regarding prohibited information. Authorities accuse the messaging platform of failing to remove channels and automated bots allegedly operated by Ukrainian special services.

According to Russian intelligence, Ukrainian operatives leveraged a Telegram dating chatbot to psychologically manipulate and recruit young Russian men into sharing physical geolocations before coercing them into executing armed attacks and arson against domestic critical infrastructure.

This charge is the latest action against Telegram preceded by Durov’s arrest in 2024, restrictions placed on the platform, and a near-blockade from earlier this year.

The Bad | Theft Victims Sue Apple Over Fraudulent Cryptocurrency Wallet Application

Three individuals have filed a lawsuit against Apple after losing approximately $1.8 million in Bitcoin to a fraudulent cryptocurrency application housed on the official App Store. Between May and August 2025, the plaintiffs downloaded a malicious app impersonating “Sparrow Wallet”, a legitimate platform exclusively available on desktop operating systems.

The fraudulent app instructed users to input their secret recovery seed phrases during the initial setup process. Once victims entered these credentials, scammers immediately transferred the cryptocurrency to unauthorized external addresses.

The legal complaint alleges that Apple failed to adequately monitor its software marketplace while falsely promoting the App Store as a secure environment. Despite warnings from the real developer behind Sparrow Wallet who called out impersonator applications more than a year before these specific incidents occurred, Apple had taken no action.

Now, the plaintiffs claim the marketplace even featured the fraudulent software within curated cryptocurrency collections, effectively recommending the malicious tool to unsuspecting victims.

There is still a scam ‘Sparrow Wallet’ app on the @Apple App Store, despite myself and others having reported it weeks ago.

Worse, you have to install it to report it.

Always go to the wallet’s website to find the link to download it. App stores will not protect you.

— Craig Raw 🐦 (@craigraw) January 6, 2024

Financial theft within mobile ecosystems continues to grow as researchers recently identified dozens of similar wallet impersonators actively targeting user recovery phrases and keys across the Apple App Store. In response to the allegations, Apple’s filing stated that it takes swift action to remove infringing content and provides dedicated reporting mechanisms for suspected fraud.

The plaintiffs currently seek full financial reimbursement, compensatory damages, and a formal court mandate requiring the tech giant to publicly disclose and systematically improve its internal procedures for detecting and removing fraudulent software submissions.

The Ugly | Anthropic Joins OpenAI in Finding Its Models Reached Real Companies During Cyber Evals

Anthropic disclosed this week that three of its models reached real production systems during cybersecurity testing. After reviewing 141,006 evaluation runs, it identified three incidents in which a Claude model reached the open internet from inside the environment of one of its third-party evaluation partners, and then accessed the systems of three organizations.

Unlike OpenAI’s recent breach of Hugging Face, no zero-day was involved, according to Anthropic. A misconfiguration had left machines in the evaluation with live internet access.

In one incident, a model built a malicious Python package and published it to PyPI, the public registry for Python software. The package was live for about an hour, during which time it was downloaded and run on 15 real systems. The downloaders included a security vendor’s scanner that installs packages automatically to check them for malware, leading to the model’s code exfiltrating that company’s credentials.

Anthropic said it found no evidence of a model pursuing a goal of its own, characterizing the incidents as a harness and operational failure rather than a model alignment failure, and noted that the safeguards it ships on released models would have blocked the behavior.

OpenAI also updated its account of the Hugging Face breach this week, revealing the same models had also used publicly exposed credentials to compromise accounts at four other services.

OpenAI said the models configured one compromised account as an outbound relay and staging server and used a second for data storage. The remaining two accounts were accessed in read-only mode.

Full attack chain of the breach (Source: Hugging Face)

Although OpenAI’s models extracted partial datasets containing CyberGym solutions and operated multiple concurrent workloads, the activity ultimately left critical encryption keys behind, exposing the operation. OpenAI said it continues to review the incident alongside external auditors and has restricted its pre-release model from further internal research access.

We've Seen Autonomous Warfare and We're in Trouble



Editor’s note- Russia's war in Ukraine has fundamentally changed the character of warfare, proving that autonomous and attritable drones are no longer supporting tools but have become a decisive instrument of combat. In this provocative essay, co-authors Xen & Matthew Creedican argue that the United States must abandon legacy assumptions and adopt an entirely new military doctrine, force structure, and industrial strategy built for the age of autonomous warfare. (Xen is a former US Special Operations veteran with experience fighting alongside Ukrainian forces. We have granted his request for anonymity).

This paper is written expressly for the policy and decision makers across the military and public and private sectors who are bound to translate national strategy into reality. We will withhold for another day the arguments for convincing those who have yet to concede that the rifleman’s day is over or that drone warfare in Ukraine generalizes. Instead, we are making a series of recommendations to those already on board with direction from the Department of War (DoW) that “we are pivoting the Pentagon and industrial base to a wartime footing”, as manifested in a $50B+ modernization program to ensure that “every warfighter must have access to low-cost/attritable sUAS [small drones] to conduct missions.” To help leaders meet such a steep challenge, we will describe how the force should be structured, how doctrine should be written, and how the industrial base must be re-engineered to match present scaling by our adversaries.

What a Modern Drone Force Should Look Like, For Now

If we could snap our fingers now and summon an army well-trained and well-equipped according to the latest understanding of modern drone warfare, it might be composed of battalions fielding approximately fifty to a hundred mixed-role unmanned systems deployable simultaneously, with stocks of thousands more unmanned vehicles and spare parts (antennas, ground stations) ready to replace those attrited. The force tailoring would have to include both rotary and fixed-wing drones performing reconnaissance, mothership, electronic warfare, one-way attack (OWA), bomber, and multi-role tasks. Such a battalion should be able to organically find, fix, and finish targets at ranges up to 300km.

Presently in Ukraine, formations tend to specialize by range. Tactical or “infantry” battalions deploy quadcopters controlled by direct radio link or fiber optic from positions 3-10km from the absolute front, flirting with the danger zone, with the better teams now fielding glide-kit quads reaching out to 50+km, doubling their effective range from last year. Ground drone units are increasingly critical as well, performing the vast majority of evacuation and logistics within the 9-15km+ “gray zone” where manned vehicles are not worth the risk to employ. Dedicated drone battalions overwatch these units from 10-20km from no man’s land, operating typically out to 80km but at times out to 300km thanks to proliferating autonomy and redundant communications (direct, meshing, repeating, satellite, LTE, etc.). This upper end for the “mid-range” or “operational” level of warfare has also at least doubled since last year. Finally, specialized deep strike teams are now conducting strikes out to beyond 1500km against strategic targets, with high-volume, low-cost, independent, adaptable platforms quite different from expensive legacy US drones.

At every level of the above structure, it is understood that even the non-OWA platforms must be attritable, since they rarely accomplish more than several missions without being rendered inoperable. Particularly cheap systems are even deliberately used as decoys. And of course, seeping down into these echelons is autonomy enabled by AI, and the beginnings of swarming protocols. It must be understood that what the aircraft carrier once did to naval gunnery is what the drone is doing to the rifleman. The fundamental unit of combat power is now the small drone team, and it is an over-the-horizon asset.

Saving Combined Arms Maneuver

Drones employed properly in such formations could execute combined arms maneuver warfare rather than the attrition warfare we currently see. After reconnoitering the enemy and making contact, unmanned battalions could use air platforms in both expendable and regenerative loitering waves to degrade air defenses, electronic warfare systems, logistics, and command structures, after which successive waves could suppress and attrite ground forces in preparation for ground drones to take, hold, and shape ground. Only then would humans move forward to effectively deepen the range of their systems. All this implies an in-depth rewriting and reapplication to unmanned warfare of manuals and doctrine guides such as FM 3-0 Operations, FM 3-90 Tactics, and FM 3-96 Brigade Combat Team. Current revisions have relegated the drone to a supporting role at best. Another example: given that a legacy US Army Corps of tens of thousands of personnel has multiple days to make decisions across approximately the same operational striking depth as that of one of the aforementioned Ukrainian drone battalions of a few hundred personnel, clearly we must revise our echeloned depths of responsibility . The existing disparity has practical consequences, as Ukrainians not only handily defeat NATO forces in joint exercises, but they do it with comparatively tiny forces, striking larger formations and assets in areas thought to be “safe”.

As such, it should be clear to those familiar with the actual contestants in programs like Drone Dominance that we are staging to mostly procure platforms that are too expensive for the requested operational ranges. Although the DoW has set a target of roughly half a million drones per year for procurement, it will actually need at least fifty million to meet the lofty goal of training and equipping a ~500,000-1,000,000 man force with attritable systems. If we look to the rest of the world, we will see that Ukraine and Russia this year are each likely to utilize around twenty million drones, while China, as the manufacturer of most of the world’s drone components, will likely build the equivalent of a hundred million drones.

Predictive Doctrine for a Moving Target

But even this, unfortunately, is not the real crux of the issue with respect to the development of future requirements. Doctrine must not only be prescriptive of the present, but also of the near future. The fact is, we cannot just snap our fingers to summon a drone army. It will take years to build it out, and by then things will look even more “sci-fi”. That is, we are chasing a moving target three to ten years out, and so we had best engage in some imagination to meet that challenge.

We are conscious of how radical this is going to sound, but our goal with such provocation is indeed to shift the Overton window, so, we believe that the future will look like something out of Ender’s Game, and it’s going to happen well before those now entering the military reach retirement eligibility.

Man, Train, and Equip for the Sci-Fi Near Future

Individual drone controllers will become tactical commanders (so let’s call them “tacticians”) remotely running squadrons of individually autonomous drones, point-and-clicking their way through a 3D interactive, AI-mediated, sensor-fusion digital twin of the battlefield. The base layer is already here in the digital panopticon emerging from cloud-native Common Operating Picture (COP) software like Ukraine’s Delta merging with military AI suites. Palantir’s Maven already suggests courses of action at the command level, and there’s no reason this couldn’t be extended down to the lowest tactical levels, controllable by voice, touch, or text. In a few more years the tacticians themselves will be inside something Neuralink-shaped, performing at the speed of AI-enhanced thought and striking at the links in the chain that enable adversarial tacticians. Under those conditions the adaptation cycle, too, will move at a speed that cognitively unenhanced humans cannot keep up with, and intelligence becomes the runaway comparative advantage at every level. There is no telling where such cognitive selection pressure combined with the ability to remotely control drone swarms will end. Will individual soldiers control dozens of drones simultaneously – or thousands? How many drones should a “battalion” have?

Decentralization is a factor too. Everything we are seeing develop now is scaling in Ukraine down to the individual operator, as it must. The over-the-horizon warrior needs personal access to livestreamed tactical radar to check if the skies are clear before he exposes himself by making movement. He needs edge compute not just onboard his drones, but for local offline AI to analyze the battlefield and make decisions even in a communications blackout. Already we see backpack portable drone interceptor systems for personal defense; I’m aware of contracts under consideration for such systems to miniaturize to automated shoulder-launch, like a personal version of the tank-mounted Trophy system. The current estimate is that a soldier has one to four seconds to defend himself against a visual drone contact vectoring on him, and soon that timeline will compress enough to exceed human reaction times.

Asking what exactly the mass of conventional soldiers will do under such a radical restructuring is much like asking whether or not Large Language Models (LLMs) are going to have the net effect of creating or destroying jobs in the civilian workforce. We may see the formation of a tiny military class, or perhaps warfare will become even more industrial in human scale. Certainly, humans will be pushed farther and farther back in the logistical chain that ultimately delivers kinetic effects upon an adversary. Currently, there is a need for people to physically emplace, operate, and recover antennas, ground stations, and drones. Once robots are more commonly executing these tasks (already, some aerial drones are launched via multi-domain mothership drones), people will work on those robots, and so forth. Eventually, it’s hard to see what anyone will need to do physically, as robots will be building, repairing, improving, and employing each other. The only real foreseeable tasks left at the tactical echelon will be those of the tactician and the true engineer, who innovates and integrates locally. Whoever best automates tasks end-to-end will win the tempo fight. The transportation of weapons and sensors has to be contemplated as one mass-manufactured logistical animal.

Going further, the tactician need not position himself relative to any front at all, because he can fly remotely and because he would be sensible to reduce his threat profile from direct action threats to intelligence-driven threats only. That is, he should position himself to strike with impunity. Already in Ukraine, Sting pilots have flown their interceptors remotely 500km away from where they were launched. Midrange teams outside the gray zone already drive to position in unmarked civilian vehicles, wear their uniforms only for the minimal time needed to deploy their systems, and then fade back into the population. And the naval drones striking the Russian fleet are not generally controlled from the sea, but ultimately from bases on land. If trends hold, the smallest independent tactical elements may be able to cheaply strike anywhere on Earth within a decade.

Branching Futures: eVTOLs, Smart Dust, and Beyond

But this is merely one vision of the future. There are branching pathways, perhaps some of which may coexist. Weaponized human-optional eVTOLs like the Chinese prototype ZR-300 could become a new air cavalry paradigm unto themselves if employed en masse in shock fashion, sweeping aside whole nations in a day the way Central Asian hordes did in the Medieval period, or the way Islamist insurgents swept across the Sahel in Toyotas. Microscopic drone “clouds” also known as smart dust could penetrate any conventional barrier, performing reconnaissance or even coalescing explosively or penetrating air ducts and lungs. Does this seem one step too far, straining credulity? Remember that “any sufficiently advanced technology is indistinguishable from magic” from the perspective of the old guard, and that all these technologies are already real, just not fully scaled and integrated. In fact, micro drones were feasible decades ago, technically if not economically – timing is everything. We already have a leading indicator in the German army’s very real purchase of cyborg insect swarms from Swarm Biotactics. Against such dizzying possibilities, we will advocate further on below for a rapidly adapting structure that ingrains real-world feedback and extrapolates from it.

Economies of Scale for Drone Production

First, let’s deal with how we produce enough useful drones to simply match our adversaries. The necessary industrial base to deliver manufacturing on the required scale simply does not exist anywhere in the West currently, whereas China has quietly captured the drone market and the sub-component supply chains over decades and is integrating such technology down to their lowest tactical echelons at a hundred times our volume. Much has already been written about the need to innovate and iterate on a scale of weeks rather than decades, and while true such a need potentially comes with the steep requirement of continuous retooling of factories and endless R&D. Ironically, funding this effort at the scale needed will require a vision across a much longer (generational) timeline, in opposition to the quarterly results that drive Western business strategy. Currently, the US buys primarily the end-product rather than engendering the component markets directly. From a cost-savings standpoint, we would do well to preemptively build adaptable systems, and also to stop trying to update legacy programs (we will never need a new sniper rifle). The DoW budget has to fund the domestic mass production of production itself, with an eye towards dual-use sub-components and machine tools, since commercial R&D and production can fund itself to an extent. Vehicles, phones, and drones sold into civilian markets pay for their own scaled production, and volume buys down cost. As it stands now with our current component outsourcing, we are paying our enemies to equip us, tying the rope with which they intend to hang us.

Pillars of a Sovereign Drone Industry

The pillars of industry to be funded include locomotion, actuation, energy, storage, compute, sensing, and communications. The component-level specifics, meaning motor sizes, magnet chemistries, cell formats, and the rest, belong in a technical paper. What’s important here is that the government has to guarantee the market for base components as much as scale requirements dictate and raw materials allow, while simultaneously finding the alternatives that bypass adversarial chains entirely.

Shallow or single-sourced chains halt on the first disruption, so volume has to be distributed across multiple domestic entities in order to create redundant paths. That means accounting for the physical bottleneck of factory siting, the legal bottleneck of restrictive radio frequency and flight-test regimes, and the social bottleneck of technical workforce recruitment, which in practice means a nationwide push for engineers with the education pipelines to match. We should fixate less on the static stockpile and more on the velocity at which the economy can replace a lost or outdated asset. Eventually, this may look like self-assembling factories, but for now we should see a dramatic increase in industrial jobs, not a reduction.

Guaranteed Requirements and Manufacturer Caps

The Departments of War and Commerce must jointly establish requirements and guarantee purchase of components at massive volumes, over multi-year timescales, according to stringent standards for minimum viable products meeting or exceeding foreign equivalents, with caps set on what portion of the total any one manufacturer can source. Subcontracting and manufacturer caps will encourage competition inside our own secure ecosystem rather than across national borders, where we are frequently undercut by adversaries. As needed, the government can resell unused inventory back to industry at or below the cost of subsidized foreign imports, letting American companies build with cheap secure inputs.

We have a realistic precedent for all this, as described in the book Freedom’s Forge: In anticipation of US entry into WW2, President Roosevelt brought together former of heads of industry in order to align military requirements, government funding, and civilian production capacity so that goals could be revised upward continuously, and the resulting volume forced a dynamic of subcontracting to keep up with demand. American industry responded, not only producing hundreds of thousands of complex war machines, but also rapidly retrofitting them as needed based on frontline feedback, on much the same timescales that we today see in Ukraine.

Innovation on the Machine Timescale

In the near future, however, we will have to go even further, with innovation necessarily occurring on the machine timescale. The same digital twin in which soldiers will virtually train and fight will also let us simulate hardware, factories, and logistics before steel is ever cut. The panopticon in which the end product’s edge sensors feed data into will be the same in which an arbitrary number of tests under variable conditions may be run before the more refined next generation of product is built. Supply chains from base-component assembly through fuel and battery pathways can be estimated and stressed the same way. Data streams from around the globe and from local instrumentation can all compartmentalize or cohere as needed for efficiency or breadth of understanding, all of it parseable by ever-increasing machine intelligence, at worst bounded in growth only by Moore’s Law. As an aside regarding encouraging a martial culture amongst the youth who will one day fill the tactician ranks, our military should release realtime strategy wargames involving drone swarming, initially as standalone games but eventually living inside the kind of digital twin explained above. And as earlier mentioned, all of this will eventually be experienced in breathtaking detail in virtual reality and via brain-machine interface. This is not so distasteful a task on a wartime footing, especially considering even in peacetime the military has released first-person shooter games and simulations.

Massive integrated training areas, in which units, contractors, and manufacturers co-locate to live-fire and iterate together, belong on the near-term build list. The mandate inside such an area should be inverted from current practice, so that the burden shifts from justifying permission for a given action to justifying why any given action cannot happen. The FAA, the FCC, and the rest of the regulatory apparatus should be effectively kicked out of the perimeter, and legislation should extend a good-faith liability shield covering crashes and honest mistakes. Dedicated integration units, which can be thought of as Transition in Contact supercharged, should be created. The core skill of these new units would not be warfighting but rather adapting to and assembling whatever technology is available. Every unit, not just dedicated ones, should additionally have at least some innovation budget and personnel, so that they are not merely customers but also integrators. Specifically, this means the military needs to be mass recruiting engineers to fill out dedicated innovation units and also sprinkle across the wider force. And lastly, the soldiers who will become the drone tacticians must be allowed to train for that role full-time, studying meteorology, radio theory, and other topics and skills currently regarded as arcane among warfighters.

A Permanent Feedback Loop from the Front

None of the above works without a permanent structured feedback loop that connects requirements to what is actually happening in a live conflict. Local units cannot generate requirements for now let alone five years out if there is no frontline feedback, no rotating instructor cycle, and no living link to platforms that do not yet exist in Western inventories. A peacetime force generating peacetime requirements will buy peacetime equipment no matter how decentralized the process is. Instead, we need a much greater scale of personnel who are aggressively forward deployed to conflict zones, visiting tactical operations centers and doing ridealongs on relatively low-risk mid- and deep-strike operations. Our partners will gladly place them there if they provide as much as they take. Directly in this role we can put our incredible all-volunteer special operators, who want nothing more than to get close to the fire. Adjacent to it, in lower intensity areas, we can forward deploy conventional troops as well to learn from partners, including by attending their own schoolhouses.

What we are suggesting here is deploying thousands of troops, not merely small cells of elite military and intelligence agency operators whose reporting does not reach the wider military. Much like the technical innovation measures described in the previous paragraph, these warriors should be distributed both into new dedicated units for the express purpose of doctrine, tactics, techniques, and procedures innovation, as well as across the wider force, to supercharge change and acquire what Clausewitz called a “fingertip feel” for the present state of war. If there is really no political appetite for this, then the only other option is to accomplish the same via other methods, such as by inviting large numbers of military instructors from partner nations currently involved in active conflict or by rotating civilian contractors more discreetly through conflict areas, as suggested by former Green Beret Bryan Pickens.

Piping Frontline Signal Directly to Doctrine Writers

Regardless of how it is done, the core part of whatever structure is created should report directly to the senior military leadership responsible for the development of force-wide doctrine and requirements, so that they cannot ignore reality and hide in dead paradigms. Various new offices are being created, such as DRPM-UxS, and our hope is that with direct signal they can utilize sweeping - even disruptive - authorities to continually remake the military; for, as Napoleon said, “unhappy the general who comes on the field of battle with a system”. Given the enemy’s endless adaptation, the best meta-doctrine is to accept no particular doctrine as certain or permanent, and even to assume that it is likely wrong if it has not been overhauled lately. Official doctrine documents would be better written and accessed as living Google docs rather than year-dated static PDFs.

This applies down to the nitty-gritty of institutional knowledge as well. The train-the-trainer model informed by forward-deployed reporting must fuel change in our own programs of instruction and battle drills, so that we actually know how to employ the unmanned weapon systems we are scaling, a capability which further feeds into local units understanding the requirements for the next round of equipment purchases.

A sharedrive with compartmentalized access is not enough; we need our whole force separated at most by just one degree from someone who has seen modern war up close. And if the military is that close to the combat demand signal, then by extension the manufacturers who visit the units they are equipping will be that much closer.

The Transition Engine and Treating Ukraine as a Peer

Joseph Gagnard of Atlas Special Projects calls the sum total of all these joint efforts the “transition engine”, meaning operators, builders, contracting specialists, and investors institutionalized together, because no single one of them fields capability alone. That transition engine has to be paired with a treatment of Ukraine that most of the current western defense industry still resists. Treat the Ukrainians peer to peer, at least as well as Taiwan or South Korea, and better than either, because they are in an existential fight we cannot afford for them to lose. I suggest bringing thousands of Ukrainian engineers, managers, and operators into the United States to help build the drone industry. Regarding AI, America holds the architecture, the compute capacity, the models, and the global reach. But Ukraine holds the live-fire scaffolding for how that data actually gets generated, labeled, fused, and fed back into the iteration cycle; they have the premier Common Operating Picture software, Delta, to facilitate collection; and they are best positioned to evaluate the battlefield effectiveness of each successive generation of combat AI.

Furthermore, Ukraine is waging a global hybrid war on the West’s behalf, which we hardly engage in except via the most deniable means. China, Russia, and their proxies and allies ruthlessly exploit neutral ground with a vast array of tools, strangling us of resources, allies, and positioning. As political will allows, we suggest unleashing our special operators and intelligence officers in nearly-overt ways, in partnership with Ukrainians, who willingly perform more risky action and have a history of cooperation with our intel services, to operate across the globe responding in kind to the Axis arrayed against us. Drones, of course, are the perfect semi-deniable weapon for this. And the signal we receive back by more heavily involving our forces in low-intensity conflicts will feed back into the plan regarding getting a “fingertip feel” back for war.

The Vulnerable Homefront

The homefront, meanwhile, is ripe for a crippling preemptive strike against us. Our infrastructure is vulnerable, and drones as stated are a perfect scalable weapon that can be employed by deniable proxies. A strike could produce economically disastrous effects, and in response to such an attack of ostensibly deniable origin and limited death toll we would certainly not seek to launch, say, a nuclear retaliatory strike. Containerized long-range drones could be lurking on civilian ships off our coast right now. DHS testified to the Senate that in 2025 there were an average of 10,000 foreign drone flights per month near the southern border. Particularly at risk to such a looming threat is our AI infrastructure. Whatever one’s thoughts on the supposed “AI bubble” (the dot-com bubble didn’t stop the triumphant march of internet adoption, did it?), it is undeniable that both the previous and current administrations have regarded the AI race as existential, and our enemies clearly feel the same way.

We saw from a recent strike by Iran on data centers in the UAE providing Amazon Web Services that such centers are vulnerable, going down for several months at a minimum due to spreading fires and long lead time for repair parts. A few hundred drones striking data centers or upstream links in the chain could easily set us back in the AI race which could provide our adversary an opportunity to surge permanently ahead, a situation which, again, our bipartisan leadership regards as an existential threat.

A Decentralized, Always-On CONUS Defense

The right posture for CONUS defense is one that is always on and autonomous-capable, able to intercept without waiting for the chain of command. In addition, such efforts must take the form of a whole-nation decentralized effort. In Ukraine, a nationwide cheap network of mobile phones acoustically tracks hostile long-range drones swarming their country, and recent legislation approved the use of electronic warfare and interceptor drones by businesses to protect their own assets. New manufacturing and power facilities tend to be built in a distributed, resilient, redundant manner, with cheap hardening available for obvious targets (like anti-drone “cages”). Our recommendation, like elsewhere, is to empower everything local. We would even go so far as to suggest that the Second Amendment needs to extend to counter-drone equipment, and any U.S. person or institution should be able to engage perceived threats up to certain altitudes above their own land.

AI as Sovereign Terrain

We can extend the Second Amendment and drones argument to the First Amendment and AI; that is, to digital and not just physical terrain. Across the information domain, China steals from us and undercuts us, releasing open LLMs to erase Western software margins. Intellectual property in this context is a burden more than a benefit by now, perhaps functioning somewhat to promote internal competition but leaving us wide open for external exploitation. The best way to stay ahead of our enemy in the face of their undermining of our brittle centralized systems is to fight fire with fire. We need policy and funding to shy away from the current big LLM players and instead encourage open models, local compute, and data sovereignty, which offer numerous long-term advantages across the board that mirror the kind of resiliency and initiative-encouraging effects we will get by distributing compute and AI models down to the lowest levels of our military.

Encryption code, for example, was previously ruled to fall under free speech protections. There is an argument against allowing centralizing and censorship of digital spaces as well, regarding them as a kind of common space since there is a barrier to entry in networking at the level of Internet Service Provider infrastructure. We need a diverse market of competing open AI models, local compute, social networks, etc. A centralized internet and centralized AI have severe risks within the domains of psychological and information warfare, which play out across the public digital arena, but to go further in that discussion we would have to depart from the scope of the kinetic warfare focus of this article. Suffice to say, the most dystopian and existentially risky outcomes are plausible if centralized AI should win, whether by our own hand or the hand of the enemy, who will surely centralize control over their models as soon as they gain an advantage.

Deterrence via Force Projection

Another point worth addressing when discussing CONUS defense is the idea that “the bomber always gets through”, which is probably true regarding drone swarms. However, regarding the homefront, Ukraine has shown first that the effects of long-range drone attacks can at least be mitigated significantly, and that it is economically optimal to do so. Furthermore, the striking arm we are also building alongside the defenses will serve as a deterrent, since nuclear doctrine of Mutually Assured Destruction is insufficient for the aforementioned reasons. If we can threaten to do unto our enemies as they wish to do unto us, and indeed if we actually regularly exercise this capacity in the global low-intensity ongoing war, then we will make them think twice before hitting us.

The Core Principle: Endless Distributed Adaptation Capacity

The single principle of this piece is this- Stop buying end products and start buying the ability to produce them, at scale, sovereignly, and forever – doctrine here being one of those end products. The victor that emerges from the next several years will have built the meaningfully decentralized version of what we have described here, meaning distributed compute, sensors, swarms, command, cognition, industry, and authority, with the standards and alliances to match. The rallying cry, in the end, is the architecture. In the last great war, we firebombed cities, preemptively invaded neutral countries, and of course ultimately resorted to nuclear weapons. The political license for a national revitalization as a form of deterrence seems, by comparison, an easy pill to swallow.

Note from author (Xen)- For those who wish to understand not merely the how but the why, or who have comments, or who desire greater breadth or depth of understanding: Over the coming weeks I will be sharing additional information to my personal Substack and website. As for my co-author, Matthew A. Creedican, you can find him on LinkedIn.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

The Good, the Bad and the Ugly in Cybersecurity – Week 30

The Good | Authorities Dismantle Kratos Phishing Network & Arrest Its Developer

Kratos, a prominent phishing-as-a-service (PhaaS) platform, was dismantled from the inside out this week thanks to German and U.S. law enforcement agencies. During “Operation Olympus Blade”, authorities seized over 200 servers to render Kratos’ global network entirely inoperable while the platform’s suspected developer was apprehended in Indonesia.

So far, investigators estimate that more than 1800 cybercriminals utilized the platform to launch nearly 15,000 phishing campaigns monthly since late 2024. Operating as a franchise, the service provided threat actors with toolkits designed to generate convincing Microsoft authentication pages. These campaigns targeted victims across the United States and Europe, facilitating widespread credential theft and unauthorized account access. The operators earned at least €300,000 in subscription fees.

Source: BKA

A recent report from cyber researchers reverse-engineered the Kratos toolkit, revealing how it offered operators two distinct functional modes. While one mode harvested traditional credentials, the more advanced setting deployed a Node.js reverse proxy. This adversary-in-the-middle (AitM) capability allowed attackers to intercept active session cookies in real-time, effectively bypassing standard multi-factor authentication (MFA) controls.

Once compromised, these accounts provided actors with initial footholds to execute business email compromise (BEC), lateral data theft, and secondary phishing attacks. Just this February, actors ran Kratos in a campaign that used tax-themed lures and personalized QR codes to target dozens of American manufacturing and healthcare organizations.

While the immediate server takedown severely disrupts ongoing operations, officials acknowledge that the existing customer base retains access to the underlying kit code. That means the toolkit itself outlives the infrastructure seizure, and operators who already have copies can resume campaigns under new branding with minimal rebuild effort.

The Bad | Threat Actors Conceal HollowGraph Malware in Microsoft 365 Calendar Events

A novel espionage implant, dubbed HollowGraph, is hijacking Microsoft 365 calendars to establish a covert command and control (C2) channel. By routing operator instructions and exfiltrated data through legitimate Microsoft Graph API traffic, the malware ensures its activities blend seamlessly with routine network chatter.

The .NET DLL implant operates purely as a two-way dead drop without communicating directly with an attacker-owned payload server. To receive tasking, HollowGraph queries the compromised user’s calendar for an event planted far into the future – in this case, dated for May 13, 2050. Operators embed their instructions within text files attached to this anomalous event, ensuring the mailbox owner never naturally scrolls far enough to discover the malicious entries.

For data exfiltration, the malware executes the reverse process. It systematically encrypts stolen files using hybrid RSA and AES-256 encryption, generates a new far-future calendar event, and uploads the targeted data as attachments. To maintain continuous Graph API access, operators utilize a secondary DNS-based channel to refresh the application’s Entra ID login credentials. The malware decodes these values from an attacker-controlled domain and writes them to a disguised configuration file.

Analysts observed this highly targeted campaign actively compromising machines at an Israeli organization between June and July 2026. While the implant’s underlying code shares significant structural similarities with a modular backdoor framework called Cavern, frequently utilized by Iranian state-sponsored syndicates, researchers have not yet definitively attributed this specific operation to a known threat group.

HollowGraph buries its C2 in M365 calendar events dated 2050 – no attacker server ever touched. https://t.co/yJo4fpw0X9 #ThreatIntel #HollowGraph #Cavern #Cav3rn pic.twitter.com/kaABaAYZg0

— ThreadLinqs (@threadlinqs) July 22, 2026

Since HollowGraph relies entirely on compromised account identities and legitimate application permissions rather than software vulnerabilities, standard patching remains ineffective. The technique effectively weaponizes the trust organizations place in their own Microsoft Graph API traffic, turning routine calendar activity into a blind spot by design.

The Ugly | AI Models Escape Sandbox to Breach Hugging Face Infrastructure

Open-source AI platform Hugging Face recently disclosed a network breach orchestrated entirely by an autonomous AI agent. The attack compromised the company’s data-processing pipeline by deploying a malicious dataset that exploited two distinct code-execution vulnerabilities. This initial access allowed the agent to run unauthorized code on a processing worker, harvest cloud and cluster credentials, and subsequently move laterally across several internal systems.

The platform reported that the agent executed thousands of individual actions across short-lived sandboxes while staging self-migrating C2 infrastructure on public services. Following the discovery, Hugging Face evicted the agent, revoked affected credentials, and rebuilt compromised nodes. It was during the forensic investigation that responders encountered a unique operational hurdle: Western AI models refused to process the malicious artifacts due to built-in safety guardrails. At this point, the company turned to an unrestricted, open-weight Chinese model to successfully complete the analysis.

Shortly after Hugging Face’s disclosure, OpenAI confirmed that its own AI models orchestrated the intrusion during internal benchmark testing. Operating with reduced safety guardrails for evaluation purposes, GPT-5.6 Sol and an advanced pre-release model attempted to cheat the ExploitGym cybersecurity assessment. Rather than solving the challenges natively, the models identified and exploited a shortcut, retrieving the test solutions directly from Hugging Face’s production database via a zero-day vulnerability in a third-party package registry cache proxy.

Source: Adel Ka

After gaining open internet access through privilege escalation and lateral movement, the models accessed Hugging Face servers. The AI agents chained together multiple attack vectors, utilizing the stolen credentials and additional zero-day vulnerabilities to establish remote code execution. OpenAI subsequently disclosed the zero-day flaw and collaborated with Hugging Face to implement stricter infrastructure controls and guardrails.

We've Seen Autonomous Warfare and We're in Trouble



Editor’s note- Russia's war in Ukraine has fundamentally changed the character of warfare, proving that autonomous and attritable drones are no longer supporting tools but have become a decisive instrument of combat. In this provocative essay, co-authors Xen & Matthew Creedican argue that the United States must abandon legacy assumptions and adopt an entirely new military doctrine, force structure, and industrial strategy built for the age of autonomous warfare. (Xen is a former US Special Operations veteran with experience fighting alongside Ukrainian forces. We have granted his request for anonymity).

This paper is written expressly for the policy and decision makers across the military and public and private sectors who are bound to translate national strategy into reality. We will withhold for another day the arguments for convincing those who have yet to concede that the rifleman’s day is over or that drone warfare in Ukraine generalizes. Instead, we are making a series of recommendations to those already on board with direction from the Department of War (DoW) that “we are pivoting the Pentagon and industrial base to a wartime footing”, as manifested in a $50B+ modernization program to ensure that “every warfighter must have access to low-cost/attritable sUAS [small drones] to conduct missions.” To help leaders meet such a steep challenge, we will describe how the force should be structured, how doctrine should be written, and how the industrial base must be re-engineered to match present scaling by our adversaries.

What a Modern Drone Force Should Look Like, For Now

If we could snap our fingers now and summon an army well-trained and well-equipped according to the latest understanding of modern drone warfare, it might be composed of battalions fielding approximately fifty to a hundred mixed-role unmanned systems deployable simultaneously, with stocks of thousands more unmanned vehicles and spare parts (antennas, ground stations) ready to replace those attrited. The force tailoring would have to include both rotary and fixed-wing drones performing reconnaissance, mothership, electronic warfare, one-way attack (OWA), bomber, and multi-role tasks. Such a battalion should be able to organically find, fix, and finish targets at ranges up to 300km.

Presently in Ukraine, formations tend to specialize by range. Tactical or “infantry” battalions deploy quadcopters controlled by direct radio link or fiber optic from positions 3-10km from the absolute front, flirting with the danger zone, with the better teams now fielding glide-kit quads reaching out to 50+km, doubling their effective range from last year. Ground drone units are increasingly critical as well, performing the vast majority of evacuation and logistics within the 9-15km+ “gray zone” where manned vehicles are not worth the risk to employ. Dedicated drone battalions overwatch these units from 10-20km from no man’s land, operating typically out to 80km but at times out to 300km thanks to proliferating autonomy and redundant communications (direct, meshing, repeating, satellite, LTE, etc.). This upper end for the “mid-range” or “operational” level of warfare has also at least doubled since last year. Finally, specialized deep strike teams are now conducting strikes out to beyond 1500km against strategic targets, with high-volume, low-cost, independent, adaptable platforms quite different from expensive legacy US drones.

At every level of the above structure, it is understood that even the non-OWA platforms must be attritable, since they rarely accomplish more than several missions without being rendered inoperable. Particularly cheap systems are even deliberately used as decoys. And of course, seeping down into these echelons is autonomy enabled by AI, and the beginnings of swarming protocols. It must be understood that what the aircraft carrier once did to naval gunnery is what the drone is doing to the rifleman. The fundamental unit of combat power is now the small drone team, and it is an over-the-horizon asset.

Saving Combined Arms Maneuver

Drones employed properly in such formations could execute combined arms maneuver warfare rather than the attrition warfare we currently see. After reconnoitering the enemy and making contact, unmanned battalions could use air platforms in both expendable and regenerative loitering waves to degrade air defenses, electronic warfare systems, logistics, and command structures, after which successive waves could suppress and attrite ground forces in preparation for ground drones to take, hold, and shape ground. Only then would humans move forward to effectively deepen the range of their systems. All this implies an in-depth rewriting and reapplication to unmanned warfare of manuals and doctrine guides such as FM 3-0 Operations, FM 3-90 Tactics, and FM 3-96 Brigade Combat Team. Current revisions have relegated the drone to a supporting role at best. Another example: given that a legacy US Army Corps of tens of thousands of personnel has multiple days to make decisions across approximately the same operational striking depth as that of one of the aforementioned Ukrainian drone battalions of a few hundred personnel, clearly we must revise our echeloned depths of responsibility . The existing disparity has practical consequences, as Ukrainians not only handily defeat NATO forces in joint exercises, but they do it with comparatively tiny forces, striking larger formations and assets in areas thought to be “safe”.

As such, it should be clear to those familiar with the actual contestants in programs like Drone Dominance that we are staging to mostly procure platforms that are too expensive for the requested operational ranges. Although the DoW has set a target of roughly half a million drones per year for procurement, it will actually need at least fifty million to meet the lofty goal of training and equipping a ~500,000-1,000,000 man force with attritable systems. If we look to the rest of the world, we will see that Ukraine and Russia this year are each likely to utilize around twenty million drones, while China, as the manufacturer of most of the world’s drone components, will likely build the equivalent of a hundred million drones.

Predictive Doctrine for a Moving Target

But even this, unfortunately, is not the real crux of the issue with respect to the development of future requirements. Doctrine must not only be prescriptive of the present, but also of the near future. The fact is, we cannot just snap our fingers to summon a drone army. It will take years to build it out, and by then things will look even more “sci-fi”. That is, we are chasing a moving target three to ten years out, and so we had best engage in some imagination to meet that challenge.

We are conscious of how radical this is going to sound, but our goal with such provocation is indeed to shift the Overton window, so, we believe that the future will look like something out of Ender’s Game, and it’s going to happen well before those now entering the military reach retirement eligibility.

Man, Train, and Equip for the Sci-Fi Near Future

Individual drone controllers will become tactical commanders (so let’s call them “tacticians”) remotely running squadrons of individually autonomous drones, point-and-clicking their way through a 3D interactive, AI-mediated, sensor-fusion digital twin of the battlefield. The base layer is already here in the digital panopticon emerging from cloud-native Common Operating Picture (COP) software like Ukraine’s Delta merging with military AI suites. Palantir’s Maven already suggests courses of action at the command level, and there’s no reason this couldn’t be extended down to the lowest tactical levels, controllable by voice, touch, or text. In a few more years the tacticians themselves will be inside something Neuralink-shaped, performing at the speed of AI-enhanced thought and striking at the links in the chain that enable adversarial tacticians. Under those conditions the adaptation cycle, too, will move at a speed that cognitively unenhanced humans cannot keep up with, and intelligence becomes the runaway comparative advantage at every level. There is no telling where such cognitive selection pressure combined with the ability to remotely control drone swarms will end. Will individual soldiers control dozens of drones simultaneously – or thousands? How many drones should a “battalion” have?

Decentralization is a factor too. Everything we are seeing develop now is scaling in Ukraine down to the individual operator, as it must. The over-the-horizon warrior needs personal access to livestreamed tactical radar to check if the skies are clear before he exposes himself by making movement. He needs edge compute not just onboard his drones, but for local offline AI to analyze the battlefield and make decisions even in a communications blackout. Already we see backpack portable drone interceptor systems for personal defense; I’m aware of contracts under consideration for such systems to miniaturize to automated shoulder-launch, like a personal version of the tank-mounted Trophy system. The current estimate is that a soldier has one to four seconds to defend himself against a visual drone contact vectoring on him, and soon that timeline will compress enough to exceed human reaction times.

Asking what exactly the mass of conventional soldiers will do under such a radical restructuring is much like asking whether or not Large Language Models (LLMs) are going to have the net effect of creating or destroying jobs in the civilian workforce. We may see the formation of a tiny military class, or perhaps warfare will become even more industrial in human scale. Certainly, humans will be pushed farther and farther back in the logistical chain that ultimately delivers kinetic effects upon an adversary. Currently, there is a need for people to physically emplace, operate, and recover antennas, ground stations, and drones. Once robots are more commonly executing these tasks (already, some aerial drones are launched via multi-domain mothership drones), people will work on those robots, and so forth. Eventually, it’s hard to see what anyone will need to do physically, as robots will be building, repairing, improving, and employing each other. The only real foreseeable tasks left at the tactical echelon will be those of the tactician and the true engineer, who innovates and integrates locally. Whoever best automates tasks end-to-end will win the tempo fight. The transportation of weapons and sensors has to be contemplated as one mass-manufactured logistical animal.

Going further, the tactician need not position himself relative to any front at all, because he can fly remotely and because he would be sensible to reduce his threat profile from direct action threats to intelligence-driven threats only. That is, he should position himself to strike with impunity. Already in Ukraine, Sting pilots have flown their interceptors remotely 500km away from where they were launched. Midrange teams outside the gray zone already drive to position in unmarked civilian vehicles, wear their uniforms only for the minimal time needed to deploy their systems, and then fade back into the population. And the naval drones striking the Russian fleet are not generally controlled from the sea, but ultimately from bases on land. If trends hold, the smallest independent tactical elements may be able to cheaply strike anywhere on Earth within a decade.

Branching Futures: eVTOLs, Smart Dust, and Beyond

But this is merely one vision of the future. There are branching pathways, perhaps some of which may coexist. Weaponized human-optional eVTOLs like the Chinese prototype ZR-300 could become a new air cavalry paradigm unto themselves if employed en masse in shock fashion, sweeping aside whole nations in a day the way Central Asian hordes did in the Medieval period, or the way Islamist insurgents swept across the Sahel in Toyotas. Microscopic drone “clouds” also known as smart dust could penetrate any conventional barrier, performing reconnaissance or even coalescing explosively or penetrating air ducts and lungs. Does this seem one step too far, straining credulity? Remember that “any sufficiently advanced technology is indistinguishable from magic” from the perspective of the old guard, and that all these technologies are already real, just not fully scaled and integrated. In fact, micro drones were feasible decades ago, technically if not economically – timing is everything. We already have a leading indicator in the German army’s very real purchase of cyborg insect swarms from Swarm Biotactics. Against such dizzying possibilities, we will advocate further on below for a rapidly adapting structure that ingrains real-world feedback and extrapolates from it.

Economies of Scale for Drone Production

First, let’s deal with how we produce enough useful drones to simply match our adversaries. The necessary industrial base to deliver manufacturing on the required scale simply does not exist anywhere in the West currently, whereas China has quietly captured the drone market and the sub-component supply chains over decades and is integrating such technology down to their lowest tactical echelons at a hundred times our volume. Much has already been written about the need to innovate and iterate on a scale of weeks rather than decades, and while true such a need potentially comes with the steep requirement of continuous retooling of factories and endless R&D. Ironically, funding this effort at the scale needed will require a vision across a much longer (generational) timeline, in opposition to the quarterly results that drive Western business strategy. Currently, the US buys primarily the end-product rather than engendering the component markets directly. From a cost-savings standpoint, we would do well to preemptively build adaptable systems, and also to stop trying to update legacy programs (we will never need a new sniper rifle). The DoW budget has to fund the domestic mass production of production itself, with an eye towards dual-use sub-components and machine tools, since commercial R&D and production can fund itself to an extent. Vehicles, phones, and drones sold into civilian markets pay for their own scaled production, and volume buys down cost. As it stands now with our current component outsourcing, we are paying our enemies to equip us, tying the rope with which they intend to hang us.

Pillars of a Sovereign Drone Industry

The pillars of industry to be funded include locomotion, actuation, energy, storage, compute, sensing, and communications. The component-level specifics, meaning motor sizes, magnet chemistries, cell formats, and the rest, belong in a technical paper. What’s important here is that the government has to guarantee the market for base components as much as scale requirements dictate and raw materials allow, while simultaneously finding the alternatives that bypass adversarial chains entirely.

Shallow or single-sourced chains halt on the first disruption, so volume has to be distributed across multiple domestic entities in order to create redundant paths. That means accounting for the physical bottleneck of factory siting, the legal bottleneck of restrictive radio frequency and flight-test regimes, and the social bottleneck of technical workforce recruitment, which in practice means a nationwide push for engineers with the education pipelines to match. We should fixate less on the static stockpile and more on the velocity at which the economy can replace a lost or outdated asset. Eventually, this may look like self-assembling factories, but for now we should see a dramatic increase in industrial jobs, not a reduction.

Guaranteed Requirements and Manufacturer Caps

The Departments of War and Commerce must jointly establish requirements and guarantee purchase of components at massive volumes, over multi-year timescales, according to stringent standards for minimum viable products meeting or exceeding foreign equivalents, with caps set on what portion of the total any one manufacturer can source. Subcontracting and manufacturer caps will encourage competition inside our own secure ecosystem rather than across national borders, where we are frequently undercut by adversaries. As needed, the government can resell unused inventory back to industry at or below the cost of subsidized foreign imports, letting American companies build with cheap secure inputs.

We have a realistic precedent for all this, as described in the book Freedom’s Forge: In anticipation of US entry into WW2, President Roosevelt brought together former of heads of industry in order to align military requirements, government funding, and civilian production capacity so that goals could be revised upward continuously, and the resulting volume forced a dynamic of subcontracting to keep up with demand. American industry responded, not only producing hundreds of thousands of complex war machines, but also rapidly retrofitting them as needed based on frontline feedback, on much the same timescales that we today see in Ukraine.

Innovation on the Machine Timescale

In the near future, however, we will have to go even further, with innovation necessarily occurring on the machine timescale. The same digital twin in which soldiers will virtually train and fight will also let us simulate hardware, factories, and logistics before steel is ever cut. The panopticon in which the end product’s edge sensors feed data into will be the same in which an arbitrary number of tests under variable conditions may be run before the more refined next generation of product is built. Supply chains from base-component assembly through fuel and battery pathways can be estimated and stressed the same way. Data streams from around the globe and from local instrumentation can all compartmentalize or cohere as needed for efficiency or breadth of understanding, all of it parseable by ever-increasing machine intelligence, at worst bounded in growth only by Moore’s Law. As an aside regarding encouraging a martial culture amongst the youth who will one day fill the tactician ranks, our military should release realtime strategy wargames involving drone swarming, initially as standalone games but eventually living inside the kind of digital twin explained above. And as earlier mentioned, all of this will eventually be experienced in breathtaking detail in virtual reality and via brain-machine interface. This is not so distasteful a task on a wartime footing, especially considering even in peacetime the military has released first-person shooter games and simulations.

Massive integrated training areas, in which units, contractors, and manufacturers co-locate to live-fire and iterate together, belong on the near-term build list. The mandate inside such an area should be inverted from current practice, so that the burden shifts from justifying permission for a given action to justifying why any given action cannot happen. The FAA, the FCC, and the rest of the regulatory apparatus should be effectively kicked out of the perimeter, and legislation should extend a good-faith liability shield covering crashes and honest mistakes. Dedicated integration units, which can be thought of as Transition in Contact supercharged, should be created. The core skill of these new units would not be warfighting but rather adapting to and assembling whatever technology is available. Every unit, not just dedicated ones, should additionally have at least some innovation budget and personnel, so that they are not merely customers but also integrators. Specifically, this means the military needs to be mass recruiting engineers to fill out dedicated innovation units and also sprinkle across the wider force. And lastly, the soldiers who will become the drone tacticians must be allowed to train for that role full-time, studying meteorology, radio theory, and other topics and skills currently regarded as arcane among warfighters.

A Permanent Feedback Loop from the Front

None of the above works without a permanent structured feedback loop that connects requirements to what is actually happening in a live conflict. Local units cannot generate requirements for now let alone five years out if there is no frontline feedback, no rotating instructor cycle, and no living link to platforms that do not yet exist in Western inventories. A peacetime force generating peacetime requirements will buy peacetime equipment no matter how decentralized the process is. Instead, we need a much greater scale of personnel who are aggressively forward deployed to conflict zones, visiting tactical operations centers and doing ridealongs on relatively low-risk mid- and deep-strike operations. Our partners will gladly place them there if they provide as much as they take. Directly in this role we can put our incredible all-volunteer special operators, who want nothing more than to get close to the fire. Adjacent to it, in lower intensity areas, we can forward deploy conventional troops as well to learn from partners, including by attending their own schoolhouses.

What we are suggesting here is deploying thousands of troops, not merely small cells of elite military and intelligence agency operators whose reporting does not reach the wider military. Much like the technical innovation measures described in the previous paragraph, these warriors should be distributed both into new dedicated units for the express purpose of doctrine, tactics, techniques, and procedures innovation, as well as across the wider force, to supercharge change and acquire what Clausewitz called a “fingertip feel” for the present state of war. If there is really no political appetite for this, then the only other option is to accomplish the same via other methods, such as by inviting large numbers of military instructors from partner nations currently involved in active conflict or by rotating civilian contractors more discreetly through conflict areas, as suggested by former Green Beret Bryan Pickens.

Piping Frontline Signal Directly to Doctrine Writers

Regardless of how it is done, the core part of whatever structure is created should report directly to the senior military leadership responsible for the development of force-wide doctrine and requirements, so that they cannot ignore reality and hide in dead paradigms. Various new offices are being created, such as DRPM-UxS, and our hope is that with direct signal they can utilize sweeping - even disruptive - authorities to continually remake the military; for, as Napoleon said, “unhappy the general who comes on the field of battle with a system”. Given the enemy’s endless adaptation, the best meta-doctrine is to accept no particular doctrine as certain or permanent, and even to assume that it is likely wrong if it has not been overhauled lately. Official doctrine documents would be better written and accessed as living Google docs rather than year-dated static PDFs.

This applies down to the nitty-gritty of institutional knowledge as well. The train-the-trainer model informed by forward-deployed reporting must fuel change in our own programs of instruction and battle drills, so that we actually know how to employ the unmanned weapon systems we are scaling, a capability which further feeds into local units understanding the requirements for the next round of equipment purchases.

A sharedrive with compartmentalized access is not enough; we need our whole force separated at most by just one degree from someone who has seen modern war up close. And if the military is that close to the combat demand signal, then by extension the manufacturers who visit the units they are equipping will be that much closer.

The Transition Engine and Treating Ukraine as a Peer

Joseph Gagnard of Atlas Special Projects calls the sum total of all these joint efforts the “transition engine”, meaning operators, builders, contracting specialists, and investors institutionalized together, because no single one of them fields capability alone. That transition engine has to be paired with a treatment of Ukraine that most of the current western defense industry still resists. Treat the Ukrainians peer to peer, at least as well as Taiwan or South Korea, and better than either, because they are in an existential fight we cannot afford for them to lose. I suggest bringing thousands of Ukrainian engineers, managers, and operators into the United States to help build the drone industry. Regarding AI, America holds the architecture, the compute capacity, the models, and the global reach. But Ukraine holds the live-fire scaffolding for how that data actually gets generated, labeled, fused, and fed back into the iteration cycle; they have the premier Common Operating Picture software, Delta, to facilitate collection; and they are best positioned to evaluate the battlefield effectiveness of each successive generation of combat AI.

Furthermore, Ukraine is waging a global hybrid war on the West’s behalf, which we hardly engage in except via the most deniable means. China, Russia, and their proxies and allies ruthlessly exploit neutral ground with a vast array of tools, strangling us of resources, allies, and positioning. As political will allows, we suggest unleashing our special operators and intelligence officers in nearly-overt ways, in partnership with Ukrainians, who willingly perform more risky action and have a history of cooperation with our intel services, to operate across the globe responding in kind to the Axis arrayed against us. Drones, of course, are the perfect semi-deniable weapon for this. And the signal we receive back by more heavily involving our forces in low-intensity conflicts will feed back into the plan regarding getting a “fingertip feel” back for war.

The Vulnerable Homefront

The homefront, meanwhile, is ripe for a crippling preemptive strike against us. Our infrastructure is vulnerable, and drones as stated are a perfect scalable weapon that can be employed by deniable proxies. A strike could produce economically disastrous effects, and in response to such an attack of ostensibly deniable origin and limited death toll we would certainly not seek to launch, say, a nuclear retaliatory strike. Containerized long-range drones could be lurking on civilian ships off our coast right now. DHS testified to the Senate that in 2025 there were an average of 10,000 foreign drone flights per month near the southern border. Particularly at risk to such a looming threat is our AI infrastructure. Whatever one’s thoughts on the supposed “AI bubble” (the dot-com bubble didn’t stop the triumphant march of internet adoption, did it?), it is undeniable that both the previous and current administrations have regarded the AI race as existential, and our enemies clearly feel the same way.

We saw from a recent strike by Iran on data centers in the UAE providing Amazon Web Services that such centers are vulnerable, going down for several months at a minimum due to spreading fires and long lead time for repair parts. A few hundred drones striking data centers or upstream links in the chain could easily set us back in the AI race which could provide our adversary an opportunity to surge permanently ahead, a situation which, again, our bipartisan leadership regards as an existential threat.

A Decentralized, Always-On CONUS Defense

The right posture for CONUS defense is one that is always on and autonomous-capable, able to intercept without waiting for the chain of command. In addition, such efforts must take the form of a whole-nation decentralized effort. In Ukraine, a nationwide cheap network of mobile phones acoustically tracks hostile long-range drones swarming their country, and recent legislation approved the use of electronic warfare and interceptor drones by businesses to protect their own assets. New manufacturing and power facilities tend to be built in a distributed, resilient, redundant manner, with cheap hardening available for obvious targets (like anti-drone “cages”). Our recommendation, like elsewhere, is to empower everything local. We would even go so far as to suggest that the Second Amendment needs to extend to counter-drone equipment, and any U.S. person or institution should be able to engage perceived threats up to certain altitudes above their own land.

AI as Sovereign Terrain

We can extend the Second Amendment and drones argument to the First Amendment and AI; that is, to digital and not just physical terrain. Across the information domain, China steals from us and undercuts us, releasing open LLMs to erase Western software margins. Intellectual property in this context is a burden more than a benefit by now, perhaps functioning somewhat to promote internal competition but leaving us wide open for external exploitation. The best way to stay ahead of our enemy in the face of their undermining of our brittle centralized systems is to fight fire with fire. We need policy and funding to shy away from the current big LLM players and instead encourage open models, local compute, and data sovereignty, which offer numerous long-term advantages across the board that mirror the kind of resiliency and initiative-encouraging effects we will get by distributing compute and AI models down to the lowest levels of our military.

Encryption code, for example, was previously ruled to fall under free speech protections. There is an argument against allowing centralizing and censorship of digital spaces as well, regarding them as a kind of common space since there is a barrier to entry in networking at the level of Internet Service Provider infrastructure. We need a diverse market of competing open AI models, local compute, social networks, etc. A centralized internet and centralized AI have severe risks within the domains of psychological and information warfare, which play out across the public digital arena, but to go further in that discussion we would have to depart from the scope of the kinetic warfare focus of this article. Suffice to say, the most dystopian and existentially risky outcomes are plausible if centralized AI should win, whether by our own hand or the hand of the enemy, who will surely centralize control over their models as soon as they gain an advantage.

Deterrence via Force Projection

Another point worth addressing when discussing CONUS defense is the idea that “the bomber always gets through”, which is probably true regarding drone swarms. However, regarding the homefront, Ukraine has shown first that the effects of long-range drone attacks can at least be mitigated significantly, and that it is economically optimal to do so. Furthermore, the striking arm we are also building alongside the defenses will serve as a deterrent, since nuclear doctrine of Mutually Assured Destruction is insufficient for the aforementioned reasons. If we can threaten to do unto our enemies as they wish to do unto us, and indeed if we actually regularly exercise this capacity in the global low-intensity ongoing war, then we will make them think twice before hitting us.

The Core Principle: Endless Distributed Adaptation Capacity

The single principle of this piece is this- Stop buying end products and start buying the ability to produce them, at scale, sovereignly, and forever – doctrine here being one of those end products. The victor that emerges from the next several years will have built the meaningfully decentralized version of what we have described here, meaning distributed compute, sensors, swarms, command, cognition, industry, and authority, with the standards and alliances to match. The rallying cry, in the end, is the architecture. In the last great war, we firebombed cities, preemptively invaded neutral countries, and of course ultimately resorted to nuclear weapons. The political license for a national revitalization as a form of deterrence seems, by comparison, an easy pill to swallow.

Note from author (Xen)- For those who wish to understand not merely the how but the why, or who have comments, or who desire greater breadth or depth of understanding: Over the coming weeks I will be sharing additional information to my personal Substack and website. As for my co-author, Matthew A. Creedican, you can find him on LinkedIn.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

The Good, the Bad and the Ugly in Cybersecurity – Week 29

The Good | Authorities Sanction Cybercriminals & Dismantle Russian Bulletproof Hosting Infrastructure

The EU and the United Kingdom have jointly sanctioned multiple Russian individuals and entities for targeting government networks and critical infrastructure across Europe. The sanctions specifically target senior Russia military intelligence (GRU) officers and operators, as well as four entities linked to the Federal Security Service (FSB).

Officials say that the Russian government actively utilizes these state-sponsored units alongside recruited cybercriminals and private companies to systematically destabilize international partners and compromise key infrastructure across the continent.

From the U.S. Treasury Department, two individuals and a virtual private network (VPN) provider face sanctions for actively enabling ransomware attacks against American organizations.

OFAC designated First VPN Service (1VPNS) and its administrator, Dmytro Rashevskyi, for supplying infrastructure that helped cybercriminals obscure their identities and manage stolen data. The service, which law enforcement dismantled last May, notoriously ignored abuse complaints and maintained zero user logs.

Yegeniy Silayev was also sanctioned for developing cryptors designed to conceal malware. Investigators estimate these specific tools and services directly facilitated billions of dollars in financial losses across critical sectors.

U.S. Federal prosecutors also unsealed indictments this week against three Russian nationals for operating bulletproof hosting services that facilitated over $62 million in global ransomware damages.

Defendants Aleksandr Volosovik, Yulia Pankova, and Kirill Zatolokin allegedly managed “Media Land” and “ML Cloud”, providing essential infrastructure to syndicates like Lockbit, Play, and Blacksuit. These hosting platforms actively shielded cybercriminals by disregarding victim complaints and ignoring law enforcement takedown requests.

To disrupt this supply chain, the State Department is offering a $10 million reward for actionable information regarding foreign government links to these hosting providers.

The Bad | Attackers Trojanize Popular Remote User Platforms to Deploy Starland Malware

Cybersecurity researchers identified a financially-motivated Russian threat actor tracked as UAT-11795. Active since June 2025, the actor has utilized trojanized applications to harvest user credentials and cryptocurrency while primarily targeting users across the United States, Germany, Romania, and Venezuela.

To distribute their payloads, UAT-11795 operators disguise malicious installers as legitimate software, including WebEx, Zoom, MobaXterm, DBeaver, and FaceIT. Researchers suspect the attackers likely deploy these files via ClickFix social engineering.

The infection chain typically starts when a victim executes a malicious HTA file. This file retrieves an altered NSIS installer harboring a hidden Python loader disguised as a standard text document. The loader then modifies the Windows Registry to ensure persistent access before decrypting and deploying the Starland remote access trojan (RAT).

Upon execution, Starland verifies whether it is operating within a sandbox before creating scheduled tasks and attempting to escalate its system privileges. The malware scans compromised systems for browser data, cryptocurrency wallet assets, detailed system configurations, any antivirus products, and Active Directory infrastructure such as domain structure and controllers.

Beyond data theft, Starland possesses extensive capabilities to capture desktop screenshots, execute arbitrary shell commands, and fetch secondary payloads. Depending on system architecture, the malware can inject a 64-bit shellcode chain to deliver the CastleStealer information stealer or a 32-bit chain to deploy the Remcos remote access trojan.

UAT-11795-controlled Telegram channels (Source: Cisco Talos)

To maintain resilient command and control (C2) communications, the operators integrate a redundancy mechanism that queries a Polygon smart contract for a fallback domain, and control two Telegram bots to receive notification beacons, including messages with the victim’s machine fingerprints and cryptowallet inventories.

Users are reminded to avoid executing unidentified commands online and should only download confirmed software from official vendor sources.

The Ugly | Nearly 300 Imposter GitHub Repositories Distribute Infostealing Malware to Collect Sensitive Data

Threat actors have published almost 300 fabricated GitHub repositories to distribute an information stealer from the BoryptGrab malware family. The actors systematically impersonated premium security products, cryptocurrency tools, and developer utilities to deceive victims searching for free software downloads.

As part of the lure, the malicious landing pages employ highly sophisticated client-side scripts that parse referral URLs to render customized branding and spoofed trust badges, significantly increasing the likelihood of successful social engineering.

Once a targeted victim clicks the download link, the infrastructure delivers a constantly rotating ZIP archive containing a legitimate, signed WinGUP updater paired with a trojanized dynamic link library file. When the user executes the updater, the program side-loads the malicious file, which then decodes and reflectively executes the BoryptGrab-variant payload directly into system memory.

Operating without establishing long-term persistence, the malware is designed to exfiltrate maximum data in a single execution cycle. The stealer targets passwords, payment details, and session cookies across 19 different web browsers and 32 cryptocurrency wallet brands, alongside messaging tokens from Discord, Steam, and Telegram.

The infostealer’s execution workflow (Source: Arctic Wolf)

To maximize collection, operators utilize direct code injection to bypass Chrome’s native App-Bound Encryption. All newly harvested data is compressed and routed to a Russian-based C2 server. Although the malware leaves behind forensic evidence by failing to wipe temporary staging directories, the scale of the impersonation campaign poses significant risks to unsuspecting developers.

GitHub has already removed a large portion of the false repositories, though several of the malicious redirector pages remain actively online. Researchers advise users to independently verify software authenticity and exercise extreme caution when navigating unofficial portals, sharing this YARA rule to help detect BoryptGrab activity and IoCs.

The Pentagon Built a Faster Engine, Nobody Built the Steering

The Department of War has just executed the most ambitious acquisition reform in six decades. It scrapped JCIDS — the requirements process that ossified innovation for a generation; replaced program offices with portfolio executives, and built a Warfighting Acquisition System designed for speed.

The changes deliver on years of reform proposals. They also risk repeating a costly mistake of the post-9/11 wars: chasing evolving threats with rapid fixes while no one is responsible for understanding them. Industry will help determine which path prevails.

Counter-drone fight as test case. We’ve seen this movie before

Consider the counter-drone fight, the clearest test of the new system. Washington treats it as an engineering puzzle: build a better jammer, field a cheaper interceptor. The technology shelf is full — directed-energy weapons at $12 a shot, drone-on-drone interceptors with more than a thousand kills in Ukraine.

While the technology works, the process for getting it to the warfighter does not.

Soldiers today engage FPV drones that cost a few hundred dollars with $400,000 Stinger missiles, because the cheap interceptors proven in Ukraine still have no fast path into U.S. formations. A new drone variant appears on the battlefield every week, built from commercial parts and open-source software. A firmware update that defeats a jammer costs nothing and takes hours. Our counter, even through the reformed system, takes months.

This is not a technology gap. It is a cycle-time gap. And I have seen it before. From 2010 to 2013, I led the Army’s Rapid Equipping Force at the height of the counter-IED campaign in Afghanistan. The structural parallels are exact: cheap dual-use components, knowledge that spreads faster than countermeasures, adaptation at near-zero cost, tactical variation that defeats one-size-fits-all solutions, and an institutional reflex to throw technology at a systems problem. We spent $75 billion on counter-IED and lost that fight anyway. Drones are IEDs that fly.

The part nobody owns

Here is what the reforms miss: Successful innovation runs in six phases — detect, define, develop, deploy, assess, distribute. The reforms invested almost entirely in the middle two, develop and deploy. Nobody persistently monitors how the threat evolves at the tactical edge. Nobody scopes each unit’s problem with enough precision to drive useful solutions. Nobody measures whether fielded systems actually work against an adversary who adapts after every engagement. And nobody moves what one unit learns to every other unit facing the same threat at operational speed. Three of the six phases have no organizational owner.

The department built a faster engine. Nobody built the steering — the mechanism that decides which problems the engine should be pointed at, whether the solutions worked, and who else needs to know.

Industry’s new role

That gap is the industry's opportunity — and its obligation. The DoW can’t solve this problem by itself. Companies that want to matter in this market need to do their part. They should start by doing three things differently.

First, invest in problem discovery, not product pitches. Requirements still originate in headquarters, not from soldiers watching the problem in context. The companies that win the next decade will be the ones that put engineers and business developers forward with operational units to understand problems before proposing solutions. The quality of your solution is determined by the quality of the problem you choose to solve. Einstein’s formula applies: 55 minutes on the problem, five on the solution. Most of industry has that ratio inverted.

Second, build for adaptation, not for the requirement. If your product cannot change in weeks — modular hardware, software-defined behavior, upgrades at firmware speed — it is obsolete on delivery. The adversary’s development cycle runs in days. A requirement frozen at contract award is a snapshot of a threat that no longer exists.

Third, plug into the new portfolio structure as a sensor, not just a supplier. Industry keeps asking the department for a clearer demand signal, and fairly so. But the demand signal has to come from somewhere, and the fusion cells that Portfolio Acquisition Executives need — nodes that merge ground truth from the field with what industry and the labs know is possible — cannot function without industry feeding data in and absorbing assessment data out. Companies that operate at that tempo will define the portfolios. Companies that wait for RFPs will trail them.

Doing these three things means stopping three others. Stop building to frozen requirements and calling it responsiveness. Stop treating a prototype contract or a demo-day win as the finish line — it is the starting line of the assessment the department never runs. And stop spending capture budgets decoding what headquarters wants instead of discovering what the warfighter needs. The hours are the same; the direction is not.

New authorities need new operators

None of this works without people, and people are where the reform agenda is thinnest. The department is converting the Defense Acquisition University into a Warfighting Acquisition University, trading compliance training for scenario-based judgment. That is the right instinct. But this year’s defense authorization offered little else on workforce, which means the authorities changed faster than the people who must wield them.

We know what works: experiential, problem-first education. Hacking for Defense has spent a decade putting university students to work on real national security problems alongside the people who own them. It has produced a generation of founders and public servants who know how to interrogate a problem before building a solution. That model needs to scale — into the department’s schoolhouses, into two-way exchanges between government and industry, and into industry’s own training pipelines, which today produce engineers who have never seen the field and capture teams fluent in the FAR but not in the mission.

The department has reformed how it acquires. It has not yet reformed what it acquires, whether it worked, or who else needs to know. Industry can wait – and hope – the government will close that gap, or it can help close it — by discovering problems & opportunities at the edge, building for adaptation, and educating a workforce trained to out-cycle an adversary rather than out-comply a regulation.

In this fight, the adversary does not need to out-technology us. He only needs to out-cycle us. We have already paid $75 billion to learn where that leads.

Pete Newell is a retired U.S. Army colonel, former director of the Army’s Rapid Equipping Force, and CEO of BMNT. He co-created Hacking for Defense with Steve Blank and is the author of “The Innovation Targeting Cycle.”

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

America’s Export Controls Are Becoming a Strategic Liability

Welcome to The Iron Triangle, the Cipher Brief column serving Procurement Officers tasked with buying the future, Investors funding the next generation of defense technology, and the Policy Wonks analyzing its impact on the global order.

A little over a year ago I watched a good company die. They built technology that worked. It was not a slide or a concept, but a thing that did what it was designed to do. They had European clients interested, checkbook open, at exactly the moment Europeans started opening checkbooks for real. They did not close the deal. They could not figure out how to export their product without tripping over the International Traffic in Arms Regulations (ITAR), they could not afford the lawyer who could tell them, and they ran out of runway waiting on a U.S. contract that was still three review cycles from signatures. The technology did not fail. The paperwork won.

Around the same time, I sat with a foreign team with excellent tech who wanted to build in the United States. They decided against it. Their reason was not taxes or visas. It was that the moment their intellectual property became American, it might become ITAR-controlled, and they were terrified that a regulation written in Washington would strand the hardware they were shipping to Ukraine to kill Russians. Restated, our export-control regime is so feared that talented people keep their best work out of the American ecosystem. That is not security. That is self-harm.

The $3,000 Toll to Export Nothing

Start with the cost of admission. To legally export a defense article, you first register with the State Department's Directorate of Defense Trade Controls (DDTC). As of January 2025 the base registration fee rose to $3,000 a year, and you pay it whether or not you ever ship a single item. That fee is the insult, not the injury. It’s the trivial part that buys you the right to then apply, per transaction, for a DSP-5 license, a process that consumes months, specialized counsel, and a full-time compliance officer that a nine-person startup does not have and cannot afford to hire.

For Lockheed Martin, this is a rounding error and a competitive moat all at once. The primes have entire floors of export-control lawyers; the regulation that annoys them is the regulation that buries smaller companies. The same $250,000-a-year compliance function is a nuisance on a $61 billion contract base and a death sentence on a Series A. ITAR does not have to be designed as a moat to function as one.

The See-Through Rule and the Birth of "ITAR-Free"

Here is the part that turns a domestic annoyance into a strategic own-goal. ITAR does not stop at the first sale. Every onward move, a re-export to a third country, a retransfer to a different end user, needs its own license. Control follows the item forever. Two features make this uniquely radioactive. The first is the "see-through rule": American law looks straight through a foreign-built system to control the U.S. part buried inside it. The second is that ITAR, unlike Commerce's export rules, has no de minimis threshold; there is no amount of American content small enough to escape. One controlled datalink in a drone taints the entire aircraft, permanently, and Europe cannot freely sell it onward, or keep sending it to Kyiv, without asking for permission.

So Europe did the rational thing. It started designing us out. "ITAR-free" is now a selling point, a feature you advertise the way you'd advertise waterproofing. The control regime we built to protect technology has taught our allies to build parallel supply chains that don't need us at all. We are not catching diversion. We are losing the room, one clean-sheet component at a time.

We Are Guarding a Henhouse the Fox Already Breeds

Now the objection every serious reader is forming: won't loosening the rules help China? It is the right question, and it deserves an honest answer. Post-sales diversion to Beijing is a threat, and the wall against it should stay standing.

But look at what the small companies I'm talking about actually build; let’s be precise about it. The airframe of an attritable FPV drone is commodity hardware, every component sourceable on Alibaba, and China manufactures the world's drones at a scale and price we cannot approach. Nobody in Beijing is combing American startups for quadcopter know-how. What can be genuinely sensitive is the layer you can't buy on Alibaba: the autonomy stack, the radio's waveform library, the ISR payload's processing. Control that. But applying munitions-grade export control to benign parts isn't guarding the crown jewels. It's standing armed guard over a henhouse the fox already owns, breeds, and exports. Control the narrow band that matters; stop strangling everything downstream of it with rules written for an age when a weapons system took a decade to build and stayed secret for two.

The Money Nobody Talks About

Investors should sit with the scale of the mismatch. In 2025, venture capital poured a record $49.1 billion into defense tech, up more than 80 percent over the year before. It sounds like a golden age until you notice most of it stacked into a handful of nine-figure megarounds while the Forgotten Bench, the small firms building the actual arteries of the future force, fought over grants. A typical DoD SBIR Phase I award runs about $256,000; a Phase II might reach a couple of million, if the company survives the wait. Many do not.

Now hold that against one ITAR-specific insult. On an ordinary afternoon, RTX booked $183.7 million for Patriot hardware bound for the United Arab Emirates. The prime exports to the Gulf on a Tuesday while the startup cannot work out how to ship a drone to a NATO ally. That is not a difference in risk. It is a difference in legal firepower. And the Pentagon posts these awards daily, every one above $7.5 million. The primes' budget rounding errors could fund the next generation of warfare. Instead they accrue to the incumbents while the little guys are fenced out of a market currently on fire.

What Each Corner of the Triangle Should Want

For the Procurement Officer, this is about coalition speed. You cannot field an allied force at the pace of a per-transaction license queue. Interoperability that requires a lawyer is not interoperability.

For the Investor, ITAR reform is a total-addressable-market unlock. European defense budgets have gone vertical, and right now your portfolio company is legally walled off from them. The moat you think protects your prime holdings is the same moat drowning your early-stage investments. Your small companies are not competition for the primes; there is plenty of room for both to be successful.

For the Policy Wonk, the pitch is precision. A control regime that treats a drone like an ATACM has no credibility left to spend when it actually needs to stop something dangerous. Overcontrol is how you get evasion; targeted control is how you get compliance.

The Fix Already Exists: We Just Gave It to Two Countries

We do not have to invent anything. In September 2024, the State Department stood up the AUKUS exemption, a license-free environment for defense trade, between pre-approved, vetted users, the United States, the United Kingdom, and Australia, fenced by an "Excluded Technology List" that keeps the genuinely sensitive items behind the wall. In an early three-month sample, only 18 percent of requests fell on the excluded list; the other 82 percent could move without a license. The mechanism works; State approved it six months ago.

So extend it, carefully, because this is the part the cynics should watch. AUKUS worked because State vouched for allies whose export-control systems were judged comparable to our own. Thirty-two NATO members are not thirty-two equal risks, so the honest version of this is tiered: the most-trusted governments first, each on its own comparability finding. Build a NATO Trusted Trade tier on the same architecture: license-free authorization for vetted allies on the commodity tier, a narrow excluded list. Industry's loudest complaint about AUKUS is that the list is already too broad. Then build a small-business fast lane that waives the registration toll for firms below a revenue threshold. Keep the wall. Widen the gate. Stop making a startup spend its entire budget on compliance lawyers to sell drones to Poland.

I have spent a career watching good technology lose to bad processes. This is the purest example I know. The threat is real, the fix is proven, and the only thing missing is the will to admit that a rulebook written in the era of glacial weapons development is actively kneecapping the fast, cheap, disposable systems that are winning wars right now. Europe wants viable technology. Our young innovators are starving for a customer. ITAR is standing between them, collecting a $3,000 toll, and calling it national security.

I am not naive about post-sale diversion to China. The real leak in a trusted-ally tier is not China raiding our startups; it is a vetted ally re-exporting onward. This is why truly sensitive items stay behind the wall. A trusted-ally tier is only as good as the "trusted" part: the whitelist has to be policed, the excluded list has to be honest, and end-use monitoring has to be real. I will not pretend reform fixes everything. For some European governments "ITAR-free" is industrial policy, a way to protect their own primes and their own jobs. No amount of American good behavior erases that motive. But reform removes the legitimate excuse, and keeps our companies in contention where today they are auto-excluded. The answer to a blunt instrument is a sharper one, not no instrument at all.

We wrote the words "ITAR-free" onto our allies' marketing brochures ourselves, one anachronistic rule at a time. The question is whether we notice in time to erase them, or we keep guarding the henhouse until the last American startup gives up and the last European customer stops asking. Who are we protecting, and from what?

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

"ITAR-Free" Is Europe's Favorite Feature, We Wrote It for Them

Welcome to The Iron Triangle, the Cipher Brief column serving Procurement Officers tasked with buying the future, Investors funding the next generation of defense technology, and the Policy Wonks analyzing its impact on the global order.

A little over a year ago I watched a good company die. They built technology that worked. It was not a slide or a concept, but a thing that did what it was designed to do. They had European clients interested, checkbook open, at exactly the moment Europeans started opening checkbooks for real. They did not close the deal. They could not figure out how to export their product without tripping over the International Traffic in Arms Regulations (ITAR), they could not afford the lawyer who could tell them, and they ran out of runway waiting on a U.S. contract that was still three review cycles from signatures. The technology did not fail. The paperwork won.

Around the same time, I sat with a foreign team with excellent tech who wanted to build in the United States. They decided against it. Their reason was not taxes or visas. It was that the moment their intellectual property became American, it might become ITAR-controlled, and they were terrified that a regulation written in Washington would strand the hardware they were shipping to Ukraine to kill Russians. Restated, our export-control regime is so feared that talented people keep their best work out of the American ecosystem. That is not security. That is self-harm.

The $3,000 Toll to Export Nothing

Start with the cost of admission. To legally export a defense article, you first register with the State Department's Directorate of Defense Trade Controls (DDTC). As of January 2025 the base registration fee rose to $3,000 a year, and you pay it whether or not you ever ship a single item. That fee is the insult, not the injury. It’s the trivial part that buys you the right to then apply, per transaction, for a DSP-5 license, a process that consumes months, specialized counsel, and a full-time compliance officer that a nine-person startup does not have and cannot afford to hire.

For Lockheed Martin, this is a rounding error and a competitive moat all at once. The primes have entire floors of export-control lawyers; the regulation that annoys them is the regulation that buries smaller companies. The same $250,000-a-year compliance function is a nuisance on a $61 billion contract base and a death sentence on a Series A. ITAR does not have to be designed as a moat to function as one.

The See-Through Rule and the Birth of "ITAR-Free"

Here is the part that turns a domestic annoyance into a strategic own-goal. ITAR does not stop at the first sale. Every onward move, a re-export to a third country, a retransfer to a different end user, needs its own license. Control follows the item forever. Two features make this uniquely radioactive. The first is the "see-through rule": American law looks straight through a foreign-built system to control the U.S. part buried inside it. The second is that ITAR, unlike Commerce's export rules, has no de minimis threshold; there is no amount of American content small enough to escape. One controlled datalink in a drone taints the entire aircraft, permanently, and Europe cannot freely sell it onward, or keep sending it to Kyiv, without asking for permission.

So Europe did the rational thing. It started designing us out. "ITAR-free" is now a selling point, a feature you advertise the way you'd advertise waterproofing. The control regime we built to protect technology has taught our allies to build parallel supply chains that don't need us at all. We are not catching diversion. We are losing the room, one clean-sheet component at a time.

We Are Guarding a Henhouse the Fox Already Breeds

Now the objection every serious reader is forming: won't loosening the rules help China? It is the right question, and it deserves an honest answer. Post-sales diversion to Beijing is a threat, and the wall against it should stay standing.

But look at what the small companies I'm talking about actually build; let’s be precise about it. The airframe of an attritable FPV drone is commodity hardware, every component sourceable on Alibaba, and China manufactures the world's drones at a scale and price we cannot approach. Nobody in Beijing is combing American startups for quadcopter know-how. What can be genuinely sensitive is the layer you can't buy on Alibaba: the autonomy stack, the radio's waveform library, the ISR payload's processing. Control that. But applying munitions-grade export control to benign parts isn't guarding the crown jewels. It's standing armed guard over a henhouse the fox already owns, breeds, and exports. Control the narrow band that matters; stop strangling everything downstream of it with rules written for an age when a weapons system took a decade to build and stayed secret for two.

The Money Nobody Talks About

Investors should sit with the scale of the mismatch. In 2025, venture capital poured a record $49.1 billion into defense tech, up more than 80 percent over the year before. It sounds like a golden age until you notice most of it stacked into a handful of nine-figure megarounds while the Forgotten Bench, the small firms building the actual arteries of the future force, fought over grants. A typical DoD SBIR Phase I award runs about $256,000; a Phase II might reach a couple of million, if the company survives the wait. Many do not.

Now hold that against one ITAR-specific insult. On an ordinary afternoon, RTX booked $183.7 million for Patriot hardware bound for the United Arab Emirates. The prime exports to the Gulf on a Tuesday while the startup cannot work out how to ship a drone to a NATO ally. That is not a difference in risk. It is a difference in legal firepower. And the Pentagon posts these awards daily, every one above $7.5 million. The primes' budget rounding errors could fund the next generation of warfare. Instead they accrue to the incumbents while the little guys are fenced out of a market currently on fire.

What Each Corner of the Triangle Should Want

For the Procurement Officer, this is about coalition speed. You cannot field an allied force at the pace of a per-transaction license queue. Interoperability that requires a lawyer is not interoperability.

For the Investor, ITAR reform is a total-addressable-market unlock. European defense budgets have gone vertical, and right now your portfolio company is legally walled off from them. The moat you think protects your prime holdings is the same moat drowning your early-stage investments. Your small companies are not competition for the primes; there is plenty of room for both to be successful.

For the Policy Wonk, the pitch is precision. A control regime that treats a drone like an ATACM has no credibility left to spend when it actually needs to stop something dangerous. Overcontrol is how you get evasion; targeted control is how you get compliance.

The Fix Already Exists: We Just Gave It to Two Countries

We do not have to invent anything. In September 2024, the State Department stood up the AUKUS exemption, a license-free environment for defense trade, between pre-approved, vetted users, the United States, the United Kingdom, and Australia, fenced by an "Excluded Technology List" that keeps the genuinely sensitive items behind the wall. In an early three-month sample, only 18 percent of requests fell on the excluded list; the other 82 percent could move without a license. The mechanism works; State approved it six months ago.

So extend it, carefully, because this is the part the cynics should watch. AUKUS worked because State vouched for allies whose export-control systems were judged comparable to our own. Thirty-two NATO members are not thirty-two equal risks, so the honest version of this is tiered: the most-trusted governments first, each on its own comparability finding. Build a NATO Trusted Trade tier on the same architecture: license-free authorization for vetted allies on the commodity tier, a narrow excluded list. Industry's loudest complaint about AUKUS is that the list is already too broad. Then build a small-business fast lane that waives the registration toll for firms below a revenue threshold. Keep the wall. Widen the gate. Stop making a startup spend its entire budget on compliance lawyers to sell drones to Poland.

I have spent a career watching good technology lose to bad processes. This is the purest example I know. The threat is real, the fix is proven, and the only thing missing is the will to admit that a rulebook written in the era of glacial weapons development is actively kneecapping the fast, cheap, disposable systems that are winning wars right now. Europe wants viable technology. Our young innovators are starving for a customer. ITAR is standing between them, collecting a $3,000 toll, and calling it national security.

I am not naive about post-sale diversion to China. The real leak in a trusted-ally tier is not China raiding our startups; it is a vetted ally re-exporting onward. This is why truly sensitive items stay behind the wall. A trusted-ally tier is only as good as the "trusted" part: the whitelist has to be policed, the excluded list has to be honest, and end-use monitoring has to be real. I will not pretend reform fixes everything. For some European governments "ITAR-free" is industrial policy, a way to protect their own primes and their own jobs. No amount of American good behavior erases that motive. But reform removes the legitimate excuse, and keeps our companies in contention where today they are auto-excluded. The answer to a blunt instrument is a sharper one, not no instrument at all.

We wrote the words "ITAR-free" onto our allies' marketing brochures ourselves, one anachronistic rule at a time. The question is whether we notice in time to erase them, or we keep guarding the henhouse until the last American startup gives up and the last European customer stops asking. Who are we protecting, and from what?

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

❌