The U.S. intelligence community’s 2026 Annual Threat Assessment warned that North Korea continues expanding its nuclear and ballistic missile programs while also using a sophisticated cyber apparatus for illicit activity, including cryptocurrency theft, to fund the regime and strengthen its military capabilities. The report said Pyongyang’s weapons of mass destruction, conventional forces, asymmetric capabilities, and cyber operations pose significant threats to the United States and its allies, especially South Korea and Japan, and noted that support from Russia in exchange for North Korean assistance in the war against Ukraine has improved the North’s military capacity.
The same annual threat hearing also addressed Iran, with U.S. intelligence leaders telling senators that Tehran’s leadership remains in power and could rebuild degraded military capabilities over the coming years despite ongoing U.S. and Israeli strikes. Testimony indicated Iran has long pursued nuclear and missile ambitions and continues to threaten U.S. interests and regional shipping, but officials did not substantiate claims that Iran was on the verge of launching an imminent first strike before the war began. A separate report on DHS leadership and CISA staffing focused on domestic agency policy and budget cuts rather than the threat assessment’s findings, making it unrelated to the core national threat-reporting story.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
At a Senate Select Intelligence Committee hearing, U.S. intelligence leaders said Iran's regime remains in power despite severe military damage and did not confirm White House claims that Iran had posed an imminent nuclear or missile threat before the war. The hearing also exposed inconsistencies in Director of National Intelligence Tulsi Gabbard's written and oral testimony about the status of Iran's nuclear program.
The U.S. Intelligence Community's Annual Threat Assessment said North Korea continues expanding its nuclear, ballistic missile, and other strategic weapons programs, posing significant threats to the United States, South Korea, and Japan. The assessment also described North Korea's cyber operations, including cryptocurrency theft, espionage, and the use of fraudulent IT workers to generate revenue and evade sanctions.
According to testimony cited in the Roll Call report, the war with Iran began on 2026-02-28. U.S. intelligence leaders said subsequent U.S. and Israeli strikes significantly degraded Iran's conventional military capabilities.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.