Skip to content
    All briefs
    Daily Brief

    Published · 8 items · 3 Global · 2 European Union · 3 The Netherlands

    Global

    International security developments, NATO, and geopolitical threats.

    Geopolitics
    Bloomberg

    Houthis open a second maritime front: Saudi tankers struck in the Red Sea, oil tops $100

    Yemen's Houthis claimed missile and drone attacks on two Saudi oil tankers in the Red Sea. Saudi authorities confirmed a fire at the bow of the ENCELIA; all crew were reported safe. The strike marks the movement's entry into the US-Iran war and pushed oil above $100 a barrel for the first time since May. One strike has changed the map. The Gulf confrontation now has a second maritime front at Bab el-Mandeb, and the world's two most important shipping chokepoints are contested at the same time. Shipping lines built up routing around the Cape of Good Hope in 2024-25. They will switch back to it faster than insurers can reprice, and the knock-on effects (longer transits, port congestion, containers in the wrong places) will reach European supply chains within two to three weeks. Don't start from a blank page: dust off the continuity annexes written during the last Red Sea crisis. The playbook is the same. The political context is sharper, because this time the attacks are formally tied to an active war between states with US forces engaged.

    Mission Support's advisory and intelligence team helps you reassess supply-chain and staff exposure now that both the Gulf and the Red Sea are contested.

    Geopolitics
    CNN

    Iran rejects US ceasefire proposal delivered via Baghdad; Kuwait reports fresh drone assaults

    Iran rejected a US ceasefire proposal delivered to Tehran by the Iraqi prime minister, while President Trump signalled he is considering a "massive attack" on Iran. After more than a week of continuous US strikes, the mediation efforts run by Baghdad, Islamabad and Doha are getting nowhere. Kuwait's defence ministry reported repeated Iranian drone attacks on its northern territory. Gulf states that host US forces remain targets, whatever role they play in mediation. For regional risk planning the rejection matters more than the rhetoric. It signals that Tehran has priced in continued strikes and chosen endurance over de-escalation, which stretches the planning horizon for disrupted Gulf operations from days to months. If you are still planning week to week for Gulf staff and logistics, switch to planning for sustained disruption. That means staff rotation that does not rely on rapid air evacuation, stock held outside the conflict zone, and communication plans that treat intermittent airspace and telecom outages as normal.

    Geopolitics
    Kyiv Post

    Ukrainian strikes hit Russian military fuel tanker and logistics targets as the drone war reaches Russian waters

    Ukraine's General Staff confirmed overnight strikes on three Russian military targets: a Black Sea tanker carrying oil, petroleum products and fuel for the Russian armed forces, a pontoon crossing near Novoekonomichne, and a troop concentration in Horlivka. A wave of Ukrainian drones over southern Russia and Crimea killed at least three people the same night. The thread to watch is fuel logistics. By systematically hitting the tankers, depots and crossings that carry fuel to the front, Ukraine turns its drone reach into a lasting brake on the pace of Russian operations. It also explains Moscow's extraordinary warning that its own Black Sea waters are unsafe for navigation. For the commercial maritime sector the lesson goes beyond this war. Cheap unmanned systems have now contested a major power's home waters for weeks at a time. Port authorities, terminal operators and owners of coastal infrastructure across Europe should assume that every state and non-state actor with a grievance and a workshop is studying this model. Surveillance of harbour approaches and counter-drone planning belong in the security budget as standard items, not options.

    European Union

    EU security directives, Europol threat assessments, and policy developments.

    SharePoint zero-day CVE-2026-50522 under mass exploitation — CISA sets a three-day patch deadline

    A critical Microsoft SharePoint Server vulnerability, CVE-2026-50522 (CVSS 9.8), is under active exploitation days after a public proof-of-concept appeared. The deserialisation flaw gives unauthenticated attackers remote code execution, and attackers have been seen stealing IIS machine keys to keep their access. CISA added it to the Known Exploited Vulnerabilities catalogue on 22 July and gave US federal agencies until 25 July to fix it. European organisations should read that unusually short deadline as the real severity rating. Two points go beyond patching. First, because machine keys are being stolen, a patch alone does not remove an attacker who was already in. Rotate the ASP.NET machine keys on every on-premises SharePoint instance, whether or not a compromise is confirmed, because a stolen key survives the patch. Second, on-premises SharePoint is still the main collaboration platform in the sectors least able to absorb a breach quietly, such as government bodies, law firms and engineering firms, and it is where the sensitive documents live. If you went through last July's SharePoint exploitation wave, you already have the runbook. This is the week to run it again, not rewrite it.

    If a network intrusion raises the question of what else an attacker can reach, Mission Support's cyber security team assesses both the digital and the physical attack surface.

    Geopolitics
    Bloomberg

    Moscow declares its own Black Sea waters unsafe for shipping — insurance and sanctions consequences for European operators

    Russia formally warned that navigation in its Black Sea waters is unsafe, citing threats from Ukrainian unmanned aerial and marine systems after weeks of escalating strikes on Russia-linked shipping. It is a rare reversal: a coastal state telling the world it cannot secure its own waters. The effects will show up in three places. War-risk underwriters now have a state admission to justify exclusions and higher premiums for the entire north-eastern Black Sea. That will push more Russian-linked cargo onto older, thinly insured shadow-fleet ships, raising environmental and collision risk in waters European vessels share, including the approaches used by grain traffic from Ukrainian and Romanian ports. Sanctions-compliance teams should expect a surge in reflagging, ownership changes and AIS gaps as operators restructure around the risk; these are exactly the behaviours screening systems flag, or miss. And charterers serving Constanța, Varna and the Danube corridor should confirm that their carriers' routing assumptions and insurance certificates date from after this week's declaration, not before it.

    The Netherlands

    AIVD, NCTV, and domestic security developments relevant to Dutch operations.

    Port of Rotterdam confirms cyberattack by pro-Russian group — no ransom paid, systems held

    Port of Rotterdam authorities confirmed the port was targeted in a cyberattack attributed to hackers linked to pro-Russian groups. They said no ransom was paid and sensitive data was not compromised. Europe's largest port getting through the incident without disruption or payment is the good-news version of a story that other European infrastructure operators should still read carefully. Pro-Russian groups have spent 2026 probing exactly this kind of target: ports, rail control, water management. With the MIVD now committed to disrupting and publicly attributing such operations, more of these confirmations will become public, not fewer. For the wider Rotterdam port community the incident is a supply-chain warning. The port authority's own resilience says nothing about the hundreds of terminal operators, freight forwarders, customs brokers and trucking firms whose systems connect to port platforms. The weakest of them is the practical way in. If you are part of that community, use this week to check your own defences: segmentation between IT and operational systems, tested offline fallbacks for critical processes, and incident-notification clauses in contracts with port partners.

    Mission Support's cyber security team helps port-community and logistics firms check their segmentation, fallback procedures and readiness to respond to an incident.

    Physical Security
    NL Times

    13-year-old posing as a police officer steals €20,000 in jewellery in Spijkenisse — uniform trust as an attack vector

    Police arrested a 13-year-old in Spijkenisse who posed as a police officer and stole €20,000 worth of jewellery. It reads like a local curiosity until you set aside the age of the perpetrator and look at the method. Impersonating authority is still one of the most reliable social-engineering methods around. That a child pulled it off in a retail setting shows how little verification stands between a convincing uniform and a victim's compliance. This applies directly to any organisation whose staff can be approached by people claiming official status. Bank-employee scams, fake meter readers, bogus inspectors and false police officers remain staples of both criminal fraud and hostile reconnaissance. The countermeasure is a procedure, not instinct. Make it a standing rule that official status is checked through an independent channel before any access, information or goods change hands: call the organisation's published number, never a number the visitor gives you. Brief front-line staff that asking a genuine officer for verification causes no offence, while skipping it with a false one causes the loss.

    Mission Support's security officers are trained to spot impersonation and to check the claims of visitors and officials through an independent channel.

    Physical Security
    NL Times

    Amsterdam police chief pledges safety for the rainbow community as WorldPride approaches

    Amsterdam's police chief publicly promised that the rainbow community will be safe during WorldPride and beyond. The pledge comes ahead of one of the largest events the city has hosted, in a summer of visible polarisation in Dutch public space. For security professionals the event is a familiar but demanding mix. Crowd operations run for weeks across canals, streets and venues. The event's symbolism attracts celebration and hostility alike. And many international visitors come with higher duty-of-care expectations from the employers sending staff and delegations. Hotels, venues and corporate hosts in Amsterdam should plan now, not in the opening week. Align your private security with the municipal operation, brief staff on de-escalation and incident reporting, and review how your premises would cope with both overflow from celebrating crowds and targeted disruption. The pledge also sets the terms of accountability. When the state makes a community's safety an explicit commitment, private partners in the event economy take on a share of it at their own front doors.

    Mission Support's hospitality security team helps hotels and venues align their own security with the city's operation during major events such as WorldPride.

    Compiled from credible pro-EU, pro-NATO news sources. Mission Support does not publish operational specifics or unverified claims.

    Ready to speak with a specialist?

    We respond within one business day. Initial conversations are confidential and without obligation.

    Request a Consultation