Kyiv death toll rises to 12 as Ukraine's air defences are stretched thin
At least twelve people were killed in Kyiv when renewed Russian missile and drone strikes hit the Ukrainian capital. A children's hospital was among the buildings damaged. Ukraine's air defences are showing growing strain after long, high-intensity bombardment and with interceptor stocks running low. More than four years into the war, Russia can still strike deep into Ukrainian territory with little warning. How well Western-supplied air defences hold up depends more and more on resupply, and deliveries are not keeping pace with the strikes. If you have staff, assets, supply chains or investments in Ukraine, revisit your contingency planning instead of treating the war as a stable, low-attention risk. Review evacuation and shelter-in-place procedures for any staff still working in the country. Stress-test logistics routes that cross or overfly Ukrainian and neighbouring airspace, and keep track of insurance and compliance obligations for work in a conflict zone. Firms with Ukrainian suppliers should look for single points of failure, given the risk of further damage to infrastructure in the weeks ahead.
Our advisory intelligence team tracks conflict-zone risk in real time so your operations and staff stay informed and prepared.
Trump threatens 'economic warfare' on Iran and its international partners
President Trump has promised tougher, wide-reaching economic measures against Iran and against third countries that keep supporting or trading with it, in language regional media describe as "economic warfare." The pressure is set to widen from Tehran to its network of commercial and political partners, probably through secondary sanctions with extraterritorial reach. Those can hit banks, shipping firms, energy traders and manufacturers that have no direct presence in Iran but are exposed through their counterparties. Escalating rhetoric like this usually comes shortly before rapid regulatory change. If you have trade links with the Middle East, the Gulf or Central Asia, do not wait for formal designations before you act. The first priority is a thorough review of your counterparty and supply-chain exposure to Iran-linked entities, including indirect exposure through intermediaries. Compliance and legal teams should pressure-test sanctions screening systems now, before enforcement starts. Treasury should model the effect of tighter capital controls or restrictions on correspondent banking. Boards should expect more volatility in energy markets and Gulf shipping insurance premiums as the measures take shape, and add that to their near-term risk registers.
Critical GitLab zero-click vulnerability complicates rapid mitigation
Security researchers have disclosed a critical zero-click vulnerability in GitLab, the widely used DevOps and source-code management platform. Reports say it poses significant mitigation challenges for defenders. A zero-click flaw needs no user interaction, so attackers may be able to compromise an affected instance simply because it is reachable over the network. If you run self-hosted GitLab, patch now rather than waiting for the routine update cycle. GitLab holds proprietary source code, CI/CD pipelines, credentials and secrets. A successful exploit could let attackers move into your software supply chain, insert malicious code or steal intellectual property. According to the reporting, the usual workarounds, such as switching off a single feature, may not fully close the exposure. Some environments could therefore stay vulnerable even after a first attempt at remediation. Security and engineering leads should treat this as a priority patch item. Confirm which versions are affected and apply the vendor guidance in full, not in part. Audit recent repository and pipeline activity for signs of compromise, and check whether any GitLab instance is exposed to the public internet without good reason.
Our cyber security specialists can assess your exposure and coordinate fast patch validation if you run a vulnerable GitLab instance.