Skip to content
    All briefs
    Daily Brief

    Published · 8 items · 3 Global · 2 European Union · 3 The Netherlands

    In brief

    The Gulf war remains the day's main driver: US forces destroyed five Iranian tankers, Tehran struck Jordan in retaliation, and Trump signalled the conflict will outlast November's US elections. A second theatre opened as Ukraine struck deeper than ever into Russia's Arctic gas sector and Zelensky's aircraft narrowly avoided a drone near Norway. In cyber, several Chinese state-linked hacking groups were found exploiting the same Chrome zero-day.

    Global

    International security developments, NATO, and geopolitical threats.

    GeopoliticsReported
    Euronews

    US destroys five Iranian tankers as Tehran strikes Jordan, Trump signals prolonged war

    The Gulf conflict that pushed oil past $100 a barrel is still escalating. US forces destroyed five Iranian vessels identified as tankers, and Tehran retaliated with strikes on targets in Jordan, widening the conflict from the Gulf states into the wider Levant. Separately, President Trump told the Republican convention that the war with Iran will not end before November's midterm elections, a sign that Washington expects a long campaign rather than quick de-escalation. For organisations with staff, assets or supply chains in the Gulf, Jordan or the wider Levant, this points to sustained high risk rather than a short spike. Expect continued swings in energy prices, tighter maritime and aviation corridors, and a higher baseline threat to facilities and travel in Jordan in particular. Security teams should refresh country risk ratings for Jordan and the Gulf states and review duty-of-care arrangements for anyone currently in the region. Stress-test supply chain and insurance exposure against a conflict now expected to last months, not weeks.

    Our advisory intelligence desk provides real-time country risk updates for personnel and assets in the Gulf and Jordan.

    Geopolitics✓ Confirmed · 2 sources
    DW

    Zelensky's plane nearly hit by drone near Norway as Ukraine strikes deepest yet into Russia's Arctic gas industry

    Ukraine carried out its deepest strike yet inside Russia, hitting gas infrastructure in the Arctic region. Norway's prime minister also disclosed that President Zelensky's aircraft was nearly hit by a drone during a flight. This came days after a wave of Russian drone strikes hit a Kyiv TV building and the Moldovan border. The near miss, confirmed in both Dutch and German coverage, shows that the drone and airspace threat from the war is no longer confined to Ukraine or its immediate neighbours. NATO members' airspace, aircraft and infrastructure increasingly fall within the risk zone, whether through miscalculation, stray munitions or deliberate testing of response thresholds. If you operate executive aviation, charter flights near Baltic or Nordic airspace, or run Arctic and Northern European energy assets, brief crews on risk before each flight and watch NOTAMs in affected corridors closely. Stay alert around critical infrastructure with Russian-linked exposure. Expect further Russian strikes on Ukrainian energy infrastructure, alongside Ukrainian attacks reaching deeper into Russian territory.

    CyberReported
    The Record

    Multiple Chinese state-linked hacking groups exploit the same Chrome zero-day

    New threat intelligence reporting shows several Chinese state-linked hacking groups exploiting the same zero-day vulnerability in Google Chrome. That suggests either a shared exploit supply chain or unusually close coordination between advanced persistent threat clusters that normally operate separately. For defenders, this matters. When several state-aligned actors weaponise one unpatched flaw at the same time, the window to patch before broad exploitation shrinks, and mid-sized or under-resourced organisations are more likely to be swept up alongside the main intelligence targets. It lands in the same week as a record Patch Tuesday covering 974 CVEs, two of them already under active attack, adding to the load on already stretched patch-management teams. Make browser and endpoint patching a priority-one task this week. Check that Chrome is updated across managed and BYOD devices, and review logs for indicators linked to Chinese APT tooling. Boards of regulated or IP-heavy businesses should confirm that incident response and breach-notification playbooks are current, as EU reporting deadlines tighten.

    Mission Support's cyber security team can support rapid patch verification and threat-hunting for Chrome and endpoint exposure.

    European Union

    EU security directives, Europol threat assessments, and policy developments.

    Intelligence✓ Confirmed · 2 sources
    BBC News

    Documents show Spanish intelligence warned of Ceuta mass-crossing plans before surge

    Newly disclosed documents show Spanish intelligence warned government officials about plans for a mass crossing attempt at the Ceuta border enclave before the surge happened. That raises questions about why preventive measures were not scaled up in time. Migration-related border surges are often preceded by identifiable warning signs. The gap between intelligence and operational response is where organisational and reputational risk concentrates, for state authorities and for private companies running logistics, hospitality or security near the border. If you operate in Ceuta, Melilla or at other Spanish-Moroccan border points, review contingency plans for sudden crossing surges. Cover staff movement restrictions, facility access control and coordination channels with local authorities. More broadly, the case shows advisory teams why it pays to act on early intelligence instead of waiting for confirmation on the ground, particularly with autumn approaching, when Mediterranean crossing attempts typically increase.

    Our advisory intelligence service tracks early-warning signs at European border points so clients can prepare before migration-related disruption hits.

    ComplianceReported
    Dark Reading

    EU Cyber Resilience Act to enforce new incident-reporting requirements

    The EU's Cyber Resilience Act is entering its enforcement phase. It introduces mandatory reporting requirements for manufacturers and vendors of digital products sold in the European market, with incident notification timelines that mirror the tighter cadence already seen under NIS2. If your organisation manufactures, integrates or resells connected hardware or software in the EU, this is a near-term operational requirement, not a distant policy shift. You need mapped reporting lines, defined severity thresholds and tested notification workflows that can meet short statutory deadlines once a vulnerability or incident is identified. It comes in the same week as a record 974-CVE Patch Tuesday and reports of Chinese state actors exploiting a shared Chrome zero-day, so reporting volumes and urgency are both high. Confirm internally who owns CRA compliance and audit whether your current incident response plans meet the new timelines. Use this as the trigger to formalise vulnerability disclosure processes across your product portfolio.

    The Netherlands

    AIVD, NCTV, and domestic security developments relevant to Dutch operations.

    IntelligenceReported
    NOS

    Netherlands acquires reconnaissance aircraft to counter espionage, sabotage and drones

    The Dutch government is buying a dedicated reconnaissance aircraft as part of a wider effort against espionage, sabotage and unauthorised drone activity. It reflects a growing official view that the Netherlands faces sustained sub-threshold threats to critical infrastructure and government functions. Other Northern European states have made similar investments in detection and surveillance, in response to more suspected state-linked reconnaissance, infrastructure incidents and drone incursions near sensitive sites. That echoes the airspace concerns raised elsewhere in Europe this week. For operators of critical infrastructure, ports, data centres and other sensitive sites in the Netherlands, the move shows that national authorities see the drone and sabotage threat as persistent, not occasional. It is a good moment to revisit your own drone detection coverage, perimeter security and incident-reporting contacts with Dutch police and intelligence services. Security and facilities teams should check that local procedures for reporting suspicious aerial activity are current and that on-site staff know them.

    Physical Security✓ Confirmed · 2 sources
    NL Times

    Nearly 40% of Dutch family lawyers face threats, especially in domestic violence cases

    New figures show that nearly 40% of Dutch family lawyers say they have faced threats or intimidation, and the picture is markedly worse for those representing victims in domestic violence cases, according to corroborating reporting on the scale of the problem. This is a specific and rising personal-security exposure for a profession not usually seen as high-risk. It also fits a wider Dutch trend of legal, medical and other client-facing professionals facing targeted intimidation over the cases they handle. Law firms, chambers and in-house legal teams handling family, domestic violence or high-conflict matters should review personal security for exposed staff. That covers threat assessment, secure travel to and from court, and building access control at firms known for sensitive caseloads. Where threats are credible, coordinate closely with the police and, where warranted, consider professional close protection, rather than leaving individual lawyers to handle it informally.

    Mission Support's personal and executive protection service can assess and mitigate threats against exposed legal and client-facing professionals.

    Training✓ Confirmed · 2 sources
    NOS

    Dutch rail disruptions set to remain elevated again next year, ProRail warns

    Dutch rail infrastructure manager ProRail is heading for another year of excessive major disruptions, with 391 significant incidents recorded so far and little improvement expected in the year ahead, according to corroborating reporting on the persistent reliability problem. It is not a security incident in itself. Chronic rail disruption does feed straight into corporate resilience planning in the Netherlands. It affects how reliably staff get to work, the logistics of events and site access, and the credibility of evacuation or continuity plans that assume rail is a workable option. If you operate in the Netherlands, don't rely on rail as your only contingency transport, particularly for time-critical staff movements, executive travel to stations or major event logistics. Security and continuity planners should build alternative transport and buffer time into travel risk plans by default, and plan for continued disruption at any Netherlands-based event or high-profile visit for the rest of the year.

    Our training and resilience programmes help organisations build contingency plans that do not depend on a single, unreliable transport mode.

    Watch — next 24–48 h

    Indicators that would change the picture. Not predictions.

    1. 01.Whether Iran's strikes on Jordan expand to other US allies in the region; confirmation would extend the oil price surge and sharply raise Gulf/Jordan travel risk.
    2. 02.Whether further drones approach Ukrainian or allied aircraft near NATO airspace after the Zelensky near-miss; a repeat would raise the threat picture for European air corridors.
    3. 03.Whether the Ceuta border sees renewed mass-crossing attempts following revelations that intelligence warnings went unheeded; a repeat surge would test EU and Spanish border response capacity.

    Compiled from credible pro-EU, pro-NATO news sources. Mission Support does not publish operational specifics or unverified claims.

    Ready to speak with a specialist?

    We respond within one business day. Initial conversations are confidential and without obligation.

    Request a Consultation