Skip to content
    All briefs
    Daily Brief

    8 items · 3 Global · 2 European Union · 3 The Netherlands

    Global

    International security developments, NATO, and geopolitical threats.

    Washington deploys additional warplanes to the Middle East as fighting with Iran intensifies

    The United States is reportedly sending additional warplanes to the Middle East as fighting with Iran intensifies, reinforcing a posture that already includes a naval blockade of Iranian ports and nightly strike operations. Force reinforcement of this kind signals planning for a sustained campaign rather than a short punitive cycle, and it shifts the realistic planning horizon for organisations with regional exposure from days to weeks or months. Prolonged conflict changes the character of the risks that security managers must address: rotation and relief of personnel who cannot be extracted quickly, sustained degradation of commercial aviation options, insurance and charter cost escalation, and the cumulative fatigue of staff operating under repeated alert cycles. Organisations should move from incident-response mode to campaign-management mode — standing rhythm of threat reviews, pre-agreed decision points for downsizing or evacuating regional footprints, and welfare provisions for personnel under extended threat. Waiting for a single decisive event to trigger action is not a strategy in a conflict structured like this one.

    Mission Support's advisory and intelligence team helps organisations structure sustained threat monitoring and regional drawdown planning.

    Working exploit public for wp2shell — unauthenticated remote code execution in WordPress core

    As of 18 July, the WordPress core vulnerability chain dubbed wp2shell carries assigned CVE identifiers and a working public proof-of-concept, materially raising the urgency of patching. The flaw — a pre-authentication remote code execution issue in WordPress core itself — allows anonymous attackers to run code on default installations even with no plugins present, and is fixed in WordPress 6.9.5 and 7.0.2. Public proof-of-concept availability typically compresses the window before mass automated exploitation from weeks to days, and WordPress's install base makes indiscriminate scanning a certainty. Organisations should treat this as an emergency change: identify every WordPress instance in the estate — including marketing microsites, event pages and subsidiaries' sites that often sit outside central IT visibility — and patch or take them offline. For security-sector and other reputation-sensitive organisations, a compromised public website is not merely an IT incident: it is an attacker foothold for watering-hole attacks against clients and a direct credibility loss. Verify patch status today, not at the next maintenance window.

    Mission Support's cyber security services help organisations identify exposed assets and respond to critical vulnerabilities.

    GeopoliticsAl Jazeera

    Iran reports 50 killed and over 500 injured in July US strikes; interim agreement declared effectively suspended

    Iran stated on 18 July that at least 50 people have been killed and more than 500 injured in US strikes this month, accusing Washington of hitting critical civilian infrastructure, while a senior Iranian negotiator described the memorandum of understanding between the two countries as effectively 'suspended' amid what Tehran characterises as US violations. The collapse of the diplomatic track removes the most plausible near-term de-escalation mechanism and, combined with mounting casualty figures, hardens domestic political constraints on both sides against compromise. For risk planners, the significance is the loss of predictable off-ramps: escalation dynamics are now governed by military logic and retaliation cycles rather than negotiation calendars. Scenario planning for the region should discount assumptions of a quick negotiated pause and instead model sustained disruption to Gulf aviation, shipping and energy markets through the remainder of the summer, with corresponding effects on regional operating costs, insurance and personnel willingness to deploy.

    European Union

    EU security directives, Europol threat assessments, and policy developments.

    Physical SecurityEuronews

    Third heatwave of the summer strains European power grids — nuclear curtailments, urban outages and record price spikes

    Europe's third heatwave of 2026 is testing the continent's power infrastructure: EDF curtailed output at multiple French reactors as cooling-water temperatures rose, with heat-related reductions touching roughly 12% of France's nuclear capacity; Italian cities including Milan, Bergamo and Turin experienced temporary outages driven by air-conditioning demand and infrastructure stress; up to 106,000 French customers lost power; and German day-ahead electricity prices peaked above €545 per megawatt-hour. Rail networks across Western Europe also faced heat-related disruption. For security managers the exposure is direct: CCTV, access control, alarm transmission and control-room operations are all grid-dependent, and summer outage risk now recurs annually. Sites should verify that uninterruptible power supplies and generators actually carry the security load — not only IT — for realistic outage durations, that alarm transmission paths fail over correctly during power loss, and that guarding instructions cover degraded-technology operation. Heat resilience belongs in the security continuity plan, not only the facilities plan.

    Mission Support's advisory team helps organisations stress-test security continuity plans against infrastructure disruption scenarios.

    ComplianceEuropol

    Europol-supported operation dismantles French-Spanish hazardous waste trafficking network; four arrested

    A joint French-Spanish operation supported by Europol has led to the arrest of four suspects accused of running a cross-border network that illegally transported demolition and industrial waste from France into Spain, where at least 46,000 tonnes were clandestinely buried in agricultural land in Catalonia, principally around Sant Esteve Sesrovires. The network used falsified transport documents describing the loads as 'soil' to evade French environmental taxes and Spanish tax obligations, moving thousands of truckloads per year since at least 2022; analysis confirmed some buried material contained hazardous substances including hydrocarbons and heavy metals. The case is a reminder that document fraud in logistics chains scales quietly and profitably — the same falsification techniques that move waste can move stolen goods, sanctioned cargo or worse. Organisations contracting waste handling, haulage or demolition services should apply genuine due diligence to disposal chains: verify end destinations, audit documentation against physical movements, and treat implausibly cheap disposal quotes as a red flag rather than a saving.

    The Netherlands

    AIVD, NCTV, and domestic security developments relevant to Dutch operations.

    IntelligenceNL Times

    Moroccan intelligence service allegedly targeted Dutch journalist with Pegasus spyware, target-list investigation reveals

    Morocco's domestic security service DGST allegedly attempted to hack the phone of a Dutch journalist using NSO Group's Pegasus spyware, according to reporting published on 18 July based on a target list obtained by Spanish newspaper El Confidencial. The journalist, a former NRC correspondent covering Spain, Portugal and Morocco who reported on protests in the Rif region, appeared on a list of numbers Moroccan intelligence allegedly sought to compromise in 2018–2019; the wider investigation indicates attempts against more than 12,000 devices across over 20 countries. Morocco has previously denied using Pegasus. The case reinforces a point that Dutch counter-surveillance practitioners have made consistently: state-grade mobile spyware is deployed not only against government targets but against journalists, lawyers, executives and their contacts — anyone whose communications hold intelligence value. Individuals and organisations handling sensitive information should treat mobile devices as a primary attack surface: hardened device configurations, regular forensic screening for high-risk users, and disciplined separation between sensitive discussions and connected devices.

    Mission Support provides TSCM sweeps and counter-surveillance advice for individuals and organisations facing state-grade monitoring threats.

    Two further arrests in The Hague drug lab investigation as production sites keep surfacing in residential areas

    Police arrested two additional suspects on 18 July in the investigation into a drug production laboratory discovered in The Hague, bringing the total number of arrests in the case to four. Clandestine synthetic drug production remains a structural feature of the Dutch criminal landscape, and its security significance extends well beyond law enforcement: production sites are routinely established in rented residential properties, industrial units and storage premises, exposing neighbouring occupants, property owners and first responders to acute chemical hazards — toxic vapours, fire and explosion risk from improvised processes, and hazardous waste dumping. Property managers and facility operators should know the recognition indicators: chemical odours, ventilation modifications, covered windows, irregular access patterns at odd hours, and tenants resistant to inspections. Reporting suspicions early protects both people and premises; discovering a lab through an incident means contamination remediation measured in months. Organisations whose staff may encounter such sites benefit from basic hazardous-environment awareness training.

    Mission Support delivers hazardous-environment awareness and CBRN training for personnel who may encounter chemical hazards in the field.

    GeopoliticsNL Times

    Dutch variable gas prices climb 12% above pre-war levels as Gulf conflict feeds through to energy costs

    Dutch variable gas prices have risen to roughly 12% above the levels seen before the Middle East war began, according to reporting on 18 July, as the Strait of Hormuz crisis feeds through into European energy markets. With roughly a fifth of global LNG transit exposed to the Gulf disruption and Brent crude trading more than 15% above pre-war levels, the cost pass-through to Dutch businesses and households is arriving faster than in previous supply shocks. For organisations, the security-relevant dimension is continuity economics: energy-intensive operations face margin pressure that historically drives cost-cutting rounds, and security budgets are perennial candidates. Security managers should prepare the business case now — quantifying what guarding, monitoring and response coverage actually prevents — rather than defending line items reactively in an autumn budget cycle. The energy shock also revives the risk profile seen in 2022: theft of heating oil, diesel and copper rises with energy prices, warranting renewed attention to fuel storage and infrastructure sites.

    Mission Support's advisory team helps organisations align security investment with measurable risk reduction during cost-pressure cycles.

    Compiled from credible pro-EU, pro-NATO news sources. Mission Support does not publish operational specifics or unverified claims.

    Ready to speak with a specialist?

    We respond within one business day. Initial conversations are confidential and without obligation.

    Request a Consultation