Intelligence & National Security
A third attack on ADNOC shipping in eight days — this one Friday evening, confirmed by the company early Saturday — indicates Iran is almost certainly sustaining a deliberate campaign of maritime coercion against UAE state-owned shipping in the Strait of Hormuz.
Fox News Digital's live coverage reported that Abu Dhabi National Oil Company (ADNOC) said early Saturday one of its vessels was attacked while crossing the Strait of Hormuz on Friday evening, with no casualties and the situation 'brought under control,' per a statement carried by the Emirates News Agency (WAM); ADNOC did not identify who was responsible. This follows the UAE's statement Thursday that Iran attacked two ADNOC-affiliated vessels transiting the strait in what Abu Dhabi called 'unprovoked' and 'flagrant' maritime violations. Fox also cited the UK Maritime Trade Operations (UKMTO) as reporting 20 projectile-strike incidents since July 6, 2026, causing bridge, engine-room, and structural damage to vessels in and around the strait. Iran International's liveblog and NBC News carried parallel coverage of the attacks and the U.S. Treasury's vow of measures 'never been seen.'
Thread advance on the U.S.–Iran ceasefire-collapse arc: a third strike on the same Emirati state champion within eight days — after coordinated GCC (Gulf Cooperation Council) condemnation of the first two — is a pattern, not noise. Tehran appears to be deliberately punishing Gulf states aligned with the U.S. blockade while keeping attacks sub-lethal, calibrated below a threshold that would force direct Emirati retaliation.
Watch: Further UKMTO-reported incidents against Gulf-state shipping; any Emirati or GCC military response; announcement of the Treasury measures Secretary Bessent promised.
Priority: 1 · Confidence: high
- Iran targets tankers in ‘unprovoked attacks’ in Strait of Hormuz, UAE says | Live Updates from Fox N — foxnews.com
- Iran attacks ships in Hormuz as US vows measures 'never ... — iranintl.com
- Iran makes new strait demands, the UAE says a ship was targeted and other Middle East news — nbcnews.com
Trump's statement that he will 'pretty soon' declare the Strait of Hormuz 'a territory of the United States' — followed within hours by a White House official calling it a joke and Tehran vowing the strait stays closed until U.S. 'strategic defeat' — indicates the declaratory contest over the strait is likely intensifying amid mixed U.S. signals that raise miscalculation risk.
ABC News reported that President Trump, speaking Friday at the David Mack Center in Garden City, New York, said 'after we finish defeating Iran... Pretty soon I'll be declaring the Hormuz Strait a territory of the United States,' and touted the reinstated U.S. naval blockade as 'a wall of steel.' Iran International reported that Iran's Deputy Foreign Minister Kazem Gharibabadi responded Friday that Iran will decide when the strait opens and will continue its blockade until the United States accepts its 'strategic defeat,' and that a senior White House official told the Wall Street Journal's Brian Schwartz that Trump was joking and had not discussed such a move with advisers. ABC quoted an Iranian official saying the strait 'cannot be seized by tweet, nor by aircraft carrier.'
Thread advance on the dueling-declaratory-positions arc from Editions 36–37: the 'keep it'/'territory' framing has now been explicitly walked back by the White House even as Iran hardens its blockade-until-defeat position. The gap between U.S. rhetoric and stated policy creates ambiguity that both raises miscalculation risk and gives Tehran propaganda material; conflicting signals from the administration are themselves the story.
Watch: Whether Trump repeats or formalizes the territorial claim; status of reported Iran–Oman navigation talks; any change in blockade enforcement rules of engagement.
Priority: 1 · Confidence: high · conflicting-reports
- Iran live updates: Trump says he'll declare Strait of Hormuz a US territory - ABC News — abcnews.com
- Iran attacks ships in Hormuz as US vows measures 'never ... — iranintl.com
ISW's August 14 assessment — Russia rejecting even a limited Black Sea maritime-strike moratorium while Ukraine hits a Leningrad Oblast refinery and a Tver logistics hub — indicates Moscow is likely foreclosing all partial de-escalation tracks while the reciprocal deep-strike campaign continues.
The Institute for the Study of War (ISW), in its August 14 assessment carried by Kyiv Post, reported that Russia rejected Turkish and Ukrainian proposals for a moratorium on strikes against maritime targets in the Black Sea, which ISW said underscores Moscow's systematic refusal of even the most limited diplomatic proposals absent Ukraine's complete capitulation. ISW also reported Ukrainian forces struck a Russian oil refinery in Leningrad Oblast and a Wildberries warehouse in Tver Oblast overnight August 13–14, and assessed that the technological offense-defense drone race is advancing rapidly and expanding the kill zone.
Thread advance on the deep-strike campaign (Bashkortostan, ZapSibNeftekhim in prior editions): the new elements are the formal Russian rejection of the Black Sea moratorium — closing a channel Turkey had sponsored — and continued Ukrainian strikes at Russia's northwestern refining and commercial-logistics base. Consistent with prior ISW reporting that Russia intends large-scale involuntary call-ups after September Duma elections.
Watch: Any Russian counter-proposal via Ankara; Ukrainian strike tempo against refining ahead of winter; signs of an early start to Russia's 2026–27 energy-infrastructure strike campaign.
Priority: 2 · Confidence: high
- ISW Russian Offensive Campaign Assessment, August 14, 2026 — kyivpost.com
Trump's proclamation of tariffs up to 100% on drones and components — explicitly framed as cutting reliance on Chinese technology, with 'particularly sensitive' models hit hardest — likely marks the most aggressive supply-chain decoupling action yet in the small-UAS (uncrewed aircraft system) sector.
The Financial Times (Demetri Sevastopulo) reported the White House announced new tariffs on drones and components, including a 100% levy on 'particularly sensitive' models, aimed at cutting reliance on Chinese technology; The Verge reported the proclamation covers 100% tariffs on many drones and all aircraft parts, with lower tiers reported for smaller drones (25%) and allied producers (15% for Korea, less for the EU and UK, per Korea JoongAng Daily and Euronews). The White House framed the action as bolstering national security and U.S. supply chains. This coverage was reviewed via aggregator digests during research; the primary FT/Verge article pages are not in this edition's citable registry, so the story is cited via the Techmeme front page where it surfaced.
The tiered structure — punitive rates on sensitive/heavy platforms, moderate rates on allies — indicates an industrial-policy design meant to reshore military-relevant UAS production without fully rupturing allied supply chains. Combined with Ukraine-war lessons on drone mass, this is defense-industrial mobilization by trade instrument; the near-term effect is likely higher costs for U.S. drone operators and a windfall for domestic producers.
Watch: Implementation timelines and exclusion processes; PRC retaliation, particularly on components or rare earths; effect on Ukraine-bound commercial drone supply.
Priority: 2 · Confidence: high · citation unresolved
- Techmeme — techmeme.com
Espionage & Counterintelligence
The FBI's confirmation that a North Korean remote IT worker obtained work inside a U.S. federal agency — one of the first acknowledged government penetrations by Pyongyang's IT-worker scheme — indicates the DPRK insider-threat program has likely breached the public-sector perimeter that vetting was assumed to protect.
Federal News Network first reported that Todd Hemmen, deputy assistant director of the FBI's Cyber Capabilities Branch, disclosed at a July 28 Digital Government Institute conference that the bureau had identified a DPRK (Democratic People's Republic of Korea) remote IT worker 'working for the federal government,' calling the case 'a little bit baffling'; the FBI is investigating how the worker was hired and has not named the agency or said whether data was accessed. TechCrunch reported the case marks a rare confirmed instance of a sanctioned North Korean working for a government agency; experts told Federal News Network the worker was likely a contractor given federal identity-proofing requirements, noting a Maryland man was sentenced last year for letting a North Korean in China work on FAA software contracts. Korea Herald carried the story August 12; on July 31 the U.S. and more than ten allies issued a global alert that DPRK IT-worker income funds Pyongyang's nuclear and missile programs.
Not covered in prior editions; included as a catch-up despite breaking slightly before this window because of its counterintelligence significance. The scheme's confirmed reach into a federal agency converts a revenue-generation fraud into a potential access operation: even without data theft, a DPRK national holding legitimate credentials inside government systems is an insider-threat event. Expect procurement-vetting policy responses focused on contract IT support. Flagged: the affected agency and scope of access remain unverified.
Watch: Identification of the affected agency; whether DOJ files charges against U.S.-based facilitators ('laptop farms'); new OMB/OPM vetting guidance for contract IT roles.
Priority: 1 · Confidence: high · unverified
- FBI investigating North Korean remote IT staffer working for US agency | Federal News Network — federalnewsnetwork.com
- North Korean remote IT staffer worked for US government agency, says FBI | TechCrunch — techcrunch.com
- Disguised North Korean IT worker caught working for US federal agency, FBI probes - The Korea Herald — koreaherald.com
New Broadcom Threat Hunter Team research assessing that PRC-linked espionage group Jewelbug ('Ink Dragon'/'Earth Alux') moonlights as a hacker-for-hire outfit running profitable crypto-fraud campaigns suggests the MSS (Ministry of State Security) contractor ecosystem's espionage and criminal revenue lines are likely fusing.
Infosecurity Magazine reported August 14 that researchers from Broadcom's Threat Hunter Team — combining Symantec and Carbon Black analysts — revealed in a report published August 13 that Jewelbug, a threat group associated with Chinese state-sponsored cyber-espionage operations and also tracked as Ink Dragon, Earth Alux, REF770, and CL-STA-0049, may be a hacker-for-hire group that additionally runs profitable cryptocurrency-fraud campaigns.
Standing-priority item (PRC intelligence activity). If borne out, this extends the pattern documented in the Salt Typhoon attributions — private firms executing state espionage — one step further, into contractors self-funding through crime. That model complicates attribution and sanctions design: disrupting the criminal revenue stream becomes a counterintelligence lever. Single vendor assessment; treat the hack-for-hire characterization as provisional.
Watch: Corroboration from other threat-intel vendors; any DOJ or Treasury action against Jewelbug-linked infrastructure or personas.
Priority: 2 · Confidence: moderate · single-source
- Researchers Link Suspected Chinese APT to Hack-for-Hire Operations - Infosecurity Magazine — infosecurity-magazine.com
New detail that Germany's intelligence-reform package would authorize BND (foreign intelligence) and BfV (domestic security) agents to neutralize threats 'using kinetic means if necessary' — with Bundestag approval expected in September — indicates the reform is likely broader than the hack-and-sabotage authorities reported at cabinet approval.
IntelNews.org (Joseph Fitsanakis) reported August 13 that Germany's proposed intelligence reforms — the most sweeping since World War II — would permit the agencies to neutralize 'threats to Germany and its allies [...] using kinetic means if necessary,' meaning special agents would be allowed to employ firearms and other weapons in the course of operations; intelNews reported the reforms will not become law until formally approved by the Bundestag in September, which it assessed is expected with a high degree of certainty given the governing coalition's majority.
Thread advance on the German intelligence-law overhaul covered in Edition 37: the new elements are the kinetic-authorities detail — going beyond the hacking, sabotage, and active-measures powers previously reported — and the September legislative timeline. A lethal-force authority for German services abroad would be a genuinely historic break with post-1945 constraints; treat the characterization as single-source pending the published bill text.
Watch: Bundestag committee debate and any narrowing of kinetic language; reactions from the coalition's left flank and Karlsruhe constitutional challenges.
Priority: 3 · Confidence: moderate · single-source
- Germany set to enact most sweeping intelligence reforms since World War II | intelNews.org — intelnews.org
Technology & AI
Zhipu/Z.ai's GLM-5.3 — which the company says nears Anthropic's frontier model in cyber-defense tests and will be released as open weights within roughly two weeks — likely represents the most consequential proliferation event yet for offensive-adjacent AI cyber capability.
Reuters reported August 14 (via aggregator coverage) that China's Z.ai says its new GLM-5.3 model nears Anthropic's Mythos 5 in cyber-defence tests. Z.ai's announcement described GLM-5.3 as 'Built to Code. Ready for Cyber Defense,' built by post-training the same 743B-parameter base model as GLM-5.2, claiming top-tier coding/agentic capability and 'a major leap in cybersecurity, setting a new standard among open models,' with API access and open weights to be released in stages following safety evaluations; community reporting aggregated by Techmeme says weights are expected in roughly two weeks, with early access limited to subscribers and vetted partners. The Decoder reported Zhipu claims it is the strongest open-weights coding model.
Capability claims are vendor-supplied and unverified — but the strategic signal stands regardless: a PRC lab is deliberately marketing frontier cyber capability in a model scheduled for open-weight release, days after OpenAI gated its offense-permissive GPT-5.6-Cyber to vetted defenders and as Washington moves to fold open-weight models into pre-release security review. Cyber capability at the open-weights frontier cannot be gated once released; this directly stresses the oversight framework covered in Editions 35–37 and intersects the PRC AI-agent-attack thread from Taiwan. Flagged: cited via aggregator digests; primary article pages were unavailable in this edition's citable registry.
Watch: Independent benchmarking of GLM-5.3's cyber capabilities on release; whether the open-weight release proceeds on schedule; U.S. policy reaction tying it to the open-model oversight expansion.
Priority: 1 · Confidence: moderate · single-source, unverified, citation unresolved
- Techmeme — techmeme.com
- Top Tech News Today, August 14, 2026: Apple, Anthropic, DeepSeek, Google, IBM, Pony.ai, OpenAI, Spac — techstartups.com
Google's launch of Gemini 3.7 Flash at half its predecessor's price just three weeks after 3.6 — in the same window DeepSeek raised V4 API prices up to twelvefold — indicates the frontier price war has likely inverted, with U.S. closed labs now undercutting Chinese open-model providers on cost.
Google announced Gemini 3.7 Flash, calling it its 'most intelligent workhorse model' for coding and agents, priced at $0.75/1M input and $3.75/1M output tokens through year-end — half the original 3.6 Flash price — with Google-reported gains including DeepSWE 65.3% vs. 49.0%; Ars Technica noted the release came just three weeks after the previous model, and Artificial Analysis scored it 56 on its Intelligence Index. This was the dominant tech story of the window by cross-outlet volume (Reuters, Bloomberg, Axios, Ars, and dozens more via Techmeme). Concurrently, the Wall Street Journal reported DeepSeek lifted V4 model prices roughly fourfold with new peak/off-peak dynamic pricing from August 16 (Seoul Economic Daily: up to 12-fold on some rates). Cited here via daily tech digests that carried the cross-outlet coverage.
Thread advance on the price-performance commoditization thread: the direction of pressure has reversed. Last week's story was Chinese labs undercutting on price; this window shows capacity-constrained Chinese providers raising prices while Google and OpenAI cut. Compute scale, not just model quality, is becoming the competitive moat — an advantage that currently favors U.S. hyperscalers.
Watch: Whether DeepSeek's price hike drives workload migration; Gemini Pro-tier release timing; OpenAI/Anthropic matching cuts.
Priority: 2 · Confidence: high · citation unresolved
- Top Tech News Today, August 14, 2026: Apple, Anthropic, DeepSeek, Google, IBM, Pony.ai, OpenAI, Spac — techstartups.com
- Daily Tech News 14 August 2026 — acecomments.mu.nu
Reuters' report that Apple trained a China-specific large language model with Alibaba's support — positioning Apple as the first foreign company to offer a proprietary AI model in China — indicates U.S. platform firms are likely accepting deep regulatory localization as the price of the China market.
Reuters reported, citing three people familiar with the matter, that Apple has trained a large language model specifically for the China market with Alibaba's support, which would make Apple the first foreign company to offer a proprietary AI model in China; follow-on coverage noted Apple built its own model rather than simply adopting a Chinese partner's, and that China requires generative AI services offered to the public to clear regulatory requirements. Cited here via a daily tech digest carrying the cross-outlet coverage.
A structural precedent: a U.S. frontier-adjacent model trained specifically to satisfy PRC content-governance requirements, with a Chinese hyperscaler in the loop. Beyond Apple's commercial stakes, it creates a template — and a pressure point — for every U.S. AI firm weighing China access against export-control and censorship exposure. Sourced reporting, not confirmed by Apple.
Watch: Apple/Alibaba confirmation and launch timing; Chinese regulatory clearance; any U.S. congressional or Commerce reaction.
Priority: 2 · Confidence: moderate · single-source
- Top Tech News Today, August 14, 2026: Apple, Anthropic, DeepSeek, Google, IBM, Pony.ai, OpenAI, Spac — techstartups.com
OpenAI's $40 billion-plus revenue run rate, its second chief revenue officer swap in a year, and Greg Brockman's 'founder mode' consolidation together indicate the company is likely restructuring its executive layer for an imminent IPO even as growth claims and executive churn tell conflicting stories.
Bloomberg reported, citing people familiar, that OpenAI is on track for annualized revenue above $40 billion, roughly double its end-2025 run rate; Bloomberg also reported OpenAI hired Dali Rajic, president/COO of Alphabet-owned Wiz, as chief revenue officer, replacing Denise Dresser after roughly eight months — which CNBC called the second major executive departure in days. Axios reported, citing a source, that Brockman is 'in founder mode,' getting more involved across every level of OpenAI to build a leadership team ahead of an expected IPO. Cited here via daily tech digests and Techmeme's coverage of the frenzied AI funding cycle.
Thread advance on the frontier-lab public-markets race: OpenAI's $40B run rate lands opposite Anthropic's reported $2T October IPO ambitions, and the Wiz hire signals a cybersecurity-credentialed enterprise sales push. Rapid executive turnover on the eve of a listing is a governance flag that public-market investors will price.
Watch: Formal IPO filing or timeline; further senior departures; whether reported growth rates appear in any offering documents.
Priority: 2 · Confidence: moderate
- Top Tech News Today, August 14, 2026: Apple, Anthropic, DeepSeek, Google, IBM, Pony.ai, OpenAI, Spac — techstartups.com
- Techmeme: How dual-valuation deals became pervasive in the current frenzied AI funding cycle, with p — techmeme.com
World & US Developments
Israeli airstrikes that killed at least nine in southern Lebanon Saturday — the deadliest since the June 20 truce, including three children in Ansar — indicate the Israel-Hezbollah framework agreement is likely under its most serious strain since it was announced.
AP (via Boston Globe and member stations) reported Israeli airstrikes on southern Lebanon killed at least nine people Saturday in some of the deadliest attacks since the precarious truce took effect June 20: Lebanon's Health Ministry said seven were killed in Ansar, including three children and two women, and two more in Deir al-Zahrani with nine wounded; Israel's military said it struck Hezbollah infrastructure in response to an action against its soldiers. Lebanese Prime Minister Nawaf Salam said the Ansar dead 'are not military targets' and demanded Israel halt an escalation AFP quoted him calling 'extremely dangerous.' AP noted more than 4,000 people have been killed by Israeli strikes in Lebanon since the March 2 war began, that Hezbollah rejected the June framework and refuses to disarm, and that seven rounds of Israel-Lebanon talks have been held, most recently in Rome; AFP reported Lebanon's NNA said a strike between Ansar and Zarariyeh was the deepest since the ceasefire.
The combination of the highest single-day civilian toll since the truce, strikes at new geographic depth, and stalled disarmament talks raises the probability of a Hezbollah response that could unravel the framework — with direct implications for the U.S.-brokered regional architecture and the Iran war's northern front.
Watch: Hezbollah retaliation or restraint over 24–72 hours; whether the next round of Rome talks proceeds in September; U.S. mediation statements.
Priority: 1 · Confidence: high
- Israeli airstrikes on southern Lebanon kill 9, Health Ministry says - The Boston Globe — bostonglobe.com
- Lebanon says 9 dead in strikes as Israel says targeted Hezbollah — yahoo.com
- Israeli strikes kill nine in south Lebanon, state news reports — irishtimes.com
With three deaths confirmed, 300,000-plus customers without power, and the heaviest rain shifting toward the upper Midwest and Ohio before a Sunday break, the week-long Midwest flood emergency is likely cresting — making the next 48 hours the peak-risk window for river flooding.
Straight Arrow News reported active flooding across Indiana and parts of the Midwest has caused deaths, mass outages, and evacuations, with more than 300,000 customers without power early Friday (citing CNN) and at least three deaths reported; conditions should improve somewhat Saturday as the heaviest rain shifts north and east toward the upper Midwest, Ohio, and central Appalachians, with a break expected by Sunday. Fox Weather reported a Level 3-of-4 flash-flood threat for Iowa and Indiana into Saturday morning after upwards of 5 inches of rain across the region; CBS News reported 277 flash-flooding incidents since Monday, seven flash-flood emergencies, and river levels potentially challenging century-old records, with Indiana Governor Mike Braun's statewide disaster emergency and National Guard mobilization continuing.
Thread advance from Edition 37: the forecast inflection — rain ending Sunday — shifts the emergency from rainfall-driven flash flooding to river-crest management. Record crests on saturated basins mean the death toll and a federal disaster declaration both remain live possibilities even as skies clear.
Watch: River crest records on the White and Muskingum basins; a federal major-disaster declaration; final casualty count once floodwaters recede.
Priority: 2 · Confidence: high
- Midwest flooding turns deadly as another round of heavy rain moves in — san.com
- Midwest, Ohio Valley brace for yet another round of severe storms, flood threat to end week of deadl — foxweather.com
- Floodwaters submerge Midwest neighborhoods still bracing for more severe storms - CBS News — cbsnews.com
France's top court striking down the under-15 social media ban on freedom-of-expression grounds — with Macron ordering the bill reworked — likely stalls Europe's most aggressive youth-online-safety experiment and sets a constitutional marker for similar laws.
Reuters, as carried on Techmeme's August 14 front page, reported that France's top court blocked a bill banning social media for under-15s, saying it infringed upon freedom of expression, and that President Macron ordered the prime minister to rework the bill.
The ruling lands as multiple jurisdictions implement or litigate youth social-media restrictions; a French constitutional rejection strengthens the legal argument that blanket minor bans are disproportionate, pushing regulators toward age-assurance and design-duty approaches instead.
Watch: Text of the reworked French bill; EU-level minor-protection proposals citing the ruling.
Priority: 3 · Confidence: moderate · single-source
- Techmeme: France's top court blocks a bill banning social media for under-15s, saying it infringed u — techmeme.com
The BBC's move to subpoena Donald Trump Jr., Ivanka Trump, and Jared Kushner in the president's defamation suit against the broadcaster indicates the case is likely escalating into a discovery fight reaching the president's family.
The Hollywood Reporter (Katie Kilkenny), as aggregated by Techmeme on August 14, reported that the BBC is seeking to subpoena Donald Trump Jr., Ivanka Trump, and Jared Kushner in the defamation lawsuit President Trump is pressing against the broadcaster.
A discovery posture this aggressive suggests the BBC intends to litigate rather than settle; depositions of family members would raise the political cost of continuing the suit. Single-outlet report seen via aggregator; details of the court filing not independently reviewed.
Watch: Court ruling on the subpoenas; any settlement signals; parallel administration actions against the broadcaster.
Priority: 3 · Confidence: low · single-source, unverified
- Techmeme: How dual-valuation deals became pervasive in the current frenzied AI funding cycle, with p — techmeme.com
Reading this brief
Phrases such as likely follow ICD 203 estimative-probability language. Confidence tags — High, Moderate, Low — grade source reliability and corroboration and keep the same green / amber / rust coding under every accent theme.
Compiled entirely from open sources; no privileged sourcing is implied. Estimative language and confidence levels follow ICD 203 (Intelligence Community Directive 203) conventions; reported fact is attributed to named outlets and separated from assessment. Source families used this edition: wire services via syndicated copies (AP via Boston Globe and member stations, AFP via Yahoo News, Reuters via Techmeme), live coverage (Fox News, ABC News, Iran International, NBC News), ISW assessments via Kyiv Post, weather/disaster coverage (Straight Arrow News, Fox Weather, CBS News), counterintelligence beat sources (Federal News Network, TechCrunch, Korea Herald, Infosecurity Magazine/Broadcom Threat Hunter Team, intelNews.org), and tech aggregators/digests (Techmeme, TechStartups, Ace of Spades daily tech digest). Direct fetches of reuters.com, apnews.com, bbc.com, and therecord.media were avoided per known blocking; syndicated copies and digests were used instead, and all items were date-checked against the window (24 hours ending 04:30 Pacific, Saturday, August 15, 2026). One deliberate window exception is flagged in-item: the DPRK IT-worker-in-federal-agency disclosure surfaced August 11–12 but was never covered in prior editions and is included as a counterintelligence catch-up. Citation constraints: for several stories (the drone-tariff proclamation, Z.ai GLM-5.3, Apple's China model, OpenAI pre-IPO items) the specific primary article pages (FT, The Verge, Reuters, Bloomberg, Axios, Z.ai, White House) were not available in this edition's citable source registry, so those items cite the aggregator/digest pages where the coverage was observed; two verified tech candidates (Wired's OpenAI safety-culture reporting and OpenAI's 'Computer History' macOS feature) were omitted entirely for lack of any citable registry source. The edition therefore runs at 15 items, slightly under the ~18 target, rather than padding. Standing collection priorities: PRC intelligence activity is covered (Jewelbug hack-for-hire assessment); the Israel intelligence/CI priority produced no significant new reporting in this window (no Qatargate, Mossad, or spyware-ecosystem developments met the bar), so no item is forced.