UNCLASSIFIED // FOR PUBLIC RELEASE▸ INTELLIGENCE BRIEFING ACTIVESPYWITNESS NEWS
INTELLIGENCE REPORT
SPYWITNESS
NEWS & ANALYSIS
ESTABLISHED 2023
▌ LIVE INTELLIGENCE FEED
▌ LATEST INTELLIGENCESATURDAY, 3 OCTOBER 2026
MI5 Names Chinese Spy Agency's Front Funding UK Academic Research
▌ INTELLIGENCE BRIEF

MI5 Names Chinese Spy Agency's Front Funding UK Academic Research

◆ HIGH CONFIDENCEIntelligence Community2 OCT 2026

MI5's first independently published alert alleges that China's Ministry of State Security is covertly funding the work of more than 100 UK-linked academics in AI, cyber and covert communications through a front body, the China General Technology Research Institute.

MI5's first independently published alert alleges that China's Ministry of State Security is covertly funding the work of more than 100 UK-linked academics in AI, cyber and covert communications through a front body, the China General Technology Research Institute.

ALSO FILED
▌ INTELLIGENCE BRIEF

China-Nexus UAT-11587 Runs Antino Backdoor Entirely Through Microsoft 365

Cisco Talos's exposure of China-nexus UAT-11587 and its Antino backdoor, which routes all command-and-control through Microsoft 365 across roughly 350 endpoints in eight countries, shows state-linked collection against Indo-Pacific policy circles migrating into trusted cloud traffic that perimeter defences cannot easily separate from legitimate use.

◆ HIGH CONFIDENCECyber and Information Warfare
▌ INTELLIGENCE BRIEF

Russian Drone Strikes Train Carrying Ex-CIA Chief, Western Envoys

A Russian drone strike on a train carrying former CIA Director David Petraeus and ex-UK PM Boris Johnson near Ukraine's Polish border, paired with two separate drone incursions against President Zelensky's aircraft, points to an escalating Russian targeting posture against senior Western and Ukrainian officials operating inside the theatre.

◆ MODERATEConflict and War
INTELLIGENCE ARCHIVE
▌ INTELLIGENCE BRIEF

China-Nexus UAT-11587 Runs Antino Backdoor Entirely Through Microsoft 365

Cisco Talos's exposure of China-nexus UAT-11587 and its Antino backdoor, which routes all command-and-control through Microsoft 365 across roughly 350 endpoints in eight countries, shows state-linked collection against Indo-Pacific policy circles migrating into trusted cloud traffic that perimeter defences cannot easily separate from legitimate use.

◆ HIGH CONFIDENCECyber and Information Warfare
▌ INTELLIGENCE BRIEF

Russian Drone Strikes Train Carrying Ex-CIA Chief, Western Envoys

A Russian drone strike on a train carrying former CIA Director David Petraeus and ex-UK PM Boris Johnson near Ukraine's Polish border, paired with two separate drone incursions against President Zelensky's aircraft, points to an escalating Russian targeting posture against senior Western and Ukrainian officials operating inside the theatre.

◆ MODERATEConflict and War
▌ INTELLIGENCE BRIEF

Russian Drone Strike Signals Targeted Threat to NATO Officials Aboard Ukraine Train

A Russian drone struck an evacuated diplomatic train near the Ukraine-Poland border on 13 September in what Ukraine's rail operator assesses was a probable attempt to hit a convoy carrying Boris Johnson, Carl Bildt, and former CIA Director David Petraeus, marking an unprecedented escalation of risk to NATO's rail lifeline into Kyiv.

◆ MODERATECovert Operations
▌ INTELLIGENCE BRIEF

Russian Spy Cluster Weaponized AI to Automate Espionage Operations

Anthropic's September 2026 threat intelligence report reveals that a Russian state-nexus espionage cluster, GTG-20006, built AI-driven workflows around Claude to automate reconnaissance, phishing, and exfiltration against more than twenty Ukrainian, European, and diplomatic targets, marking a qualitative shift in how state intelligence services conduct cyber operations.

◆ HIGH CONFIDENCECyber and Information Warfare
▌ INTELLIGENCE BRIEF

Russian Drone Strikes SBU Headquarters in Targeted Hit on Spy Chief

A Russian drone strike on the SBU's Kyiv headquarters, apparently aimed at killing the service's acting chief, marks an attempted decapitation strike on Ukraine's counterintelligence leadership and has drawn a vowed covert response from Kyiv.

◆ MODERATEIntelligence Community
▌ INTELLIGENCE BRIEF

US Destroys Iranian Tankers After IRGC Missile Attack on Navy Ships

CENTCOM's destruction of three Iranian tankers in retaliation for an IRGC missile attack on two US Navy warships marks the sharpest escalation yet in the Hormuz shadow war, raising the risk of a wider naval confrontation.

◆ HIGH CONFIDENCEConflict and War
▌ INTELLIGENCE BRIEF

Kyiv Gunfight Between SBU and HUR Exposes Agency Rift

A firefight between Ukraine's SBU and HUR intelligence services in Kyiv, triggered by a disputed FSB-assassination-plot detention, has exposed a dangerous breakdown in wartime interagency coordination at the heart of Kyiv's security establishment.

◆ MODERATEIntelligence Community
▌ INTELLIGENCE BRIEF

Fire Ant Turns Routers Into Silent Spy Platforms

A China-linked espionage cluster tracked as Fire Ant has hijacked Cisco IOS XR routers and authentication servers to establish covert, log-evading access across enterprise networks, with reconnaissance activity extending toward U.S. critical infrastructure.

◆ MODERATECyber and Information Warfare
▌ INTELLIGENCE BRIEF

Iran Strikes US-Linked Bases in Jordan, UAE After Hormuz Attack

Iran's IRGC struck US-linked bases in Jordan and the UAE hours after a US attack on Iranian rocket launchers in the Strait of Hormuz, marking the first direct US-Iran kinetic exchange in over a month and reopening the risk of a wider Gulf escalation.

◆ MODERATEConflict and War