Global
International security developments, NATO, and geopolitical threats.
Houthis open a second maritime front: Saudi tankers struck in the Red Sea, oil tops $100
Yemen's Houthis claimed missile and drone attacks on two Saudi oil tankers in the Red Sea, with Saudi authorities confirming a fire at the bow of the vessel ENCELIA and all crew reported safe — the movement's entry into the US-Iran war and the trigger that pushed oil above $100 a barrel for the first time since May. The strategic geometry has changed in one strike: the Gulf confrontation now has a second maritime front at Bab el-Mandeb, and the world's two most consequential shipping chokepoints are contested simultaneously. Shipping lines that spent 2024-25 building Cape-of-Good-Hope routing muscle will re-activate it faster than insurers can reprice, and the cascading effects — longer transits, port congestion, equipment imbalances — will reach European supply chains within two to three weeks. Organisations should dust off the continuity annexes written during the last Red Sea crisis rather than starting from blank paper: the operational playbook is the same, but the political context is sharper, because this time the attacks are formally coupled to an active interstate war with US forces engaged.
Iran rejects US ceasefire proposal delivered via Baghdad; Kuwait reports fresh drone assaults
Iran rejected a US ceasefire proposal presented to Tehran by the Iraqi prime minister, while President Trump signalled he is considering a "massive attack" on Iran — leaving the mediation tracks run by Baghdad, Islamabad and Doha without traction after more than a week of continuous US strikes. Kuwait's defence ministry reported repeated Iranian drone assaults on its northern territory, confirming that Gulf states hosting US forces remain inside the target set regardless of their mediation posture. For regional risk planning the rejection matters more than the rhetoric: it signals Tehran has priced in continued strikes and chosen endurance over de-escalation, which extends the planning horizon for disrupted Gulf operations from days to months. Organisations still running week-to-week contingency postures for Gulf staff and logistics should shift to a sustained-disruption footing — rotational staffing models that don't depend on rapid air evacuation, inventory buffers positioned outside the theatre, and communication plans that assume intermittent airspace and telecom disruption as the norm rather than the exception.
Ukrainian strikes hit Russian military fuel tanker and logistics targets as the drone war reaches Russian waters
Ukraine's General Staff confirmed overnight strikes on three Russian military targets including a Black Sea tanker carrying oil, petroleum products and fuel for the Russian armed forces, alongside a pontoon crossing near Novoekonomichne and a troop concentration in Horlivka. A wave of Ukrainian drones across southern Russia and Crimea killed at least three people the same night. The fuel-logistics targeting is the thread to watch: systematically striking the tankers, depots and crossings that move fuel to the front converts Ukraine's drone reach into a sustained constraint on Russian operational tempo, and explains Moscow's extraordinary warning that its own Black Sea waters are unsafe for navigation. For the commercial maritime sector the professional takeaway is about precedent as much as this war: cheap unmanned systems have now demonstrably contested a major power's home waters for weeks at a time. Port authorities, terminal operators and coastal-infrastructure owners across Europe should assume this capability template is being studied by every state and non-state actor with a grievance and a workshop — and that harbour-approach surveillance and counter-UAS planning are no longer optional lines in the security budget.
European Union
EU security directives, Europol threat assessments, and policy developments.
SharePoint zero-day CVE-2026-50522 under mass exploitation — CISA sets a three-day patch deadline
A critical Microsoft SharePoint Server vulnerability, CVE-2026-50522 (CVSS 9.8), is under active exploitation days after a public proof-of-concept went live: a deserialisation flaw giving unauthenticated attackers remote code execution, with attackers observed stealing IIS machine keys for persistence. CISA added it to the Known Exploited Vulnerabilities catalogue on 22 July and gave US federal agencies until 25 July to remediate — an unusually short fuse that European organisations should read as the real severity rating. Two operational points matter beyond patching. First, the machine-key theft means a patch alone does not evict an attacker who was in before it: ASP.NET machine keys must be rotated on every on-premises SharePoint instance regardless of whether compromise is confirmed, because a stolen key survives the patch. Second, on-premises SharePoint remains the collaboration backbone in exactly the sectors least able to absorb a breach quietly — government bodies, legal practices, engineering firms — and it is where the sensitive documents live. Organisations that went through last July's SharePoint exploitation wave have their runbook already; this is the week to run it again, not to rewrite it.
Moscow declares its own Black Sea waters unsafe for shipping — insurance and sanctions consequences for European operators
Russia formally warned that navigation in its Black Sea waters is unsafe, citing threats from Ukrainian unmanned aerial and marine systems after weeks of escalating strikes on Russia-linked shipping. For European maritime operators the declaration lands as a rare inversion: a coastal state advising the world it cannot secure its own waters. The immediate effects concentrate in three places. War-risk underwriters now have a state admission to anchor exclusions and premium increases for the entire north-eastern Black Sea, which will push more Russian-linked cargo onto older, thinly insured shadow-fleet tonnage — raising environmental and collision risk in waters European vessels share, including the approaches used by grain traffic from Ukrainian and Romanian ports. Sanctions-compliance teams should expect a surge of reflagging, ownership churn and AIS gaps as operators restructure around the risk, precisely the behaviours that screening systems flag — or miss. And charterers serving Constanța, Varna and the Danube corridor should re-confirm that their carriers' routing assumptions and insurance certificates were issued after this week's declaration, not before it.
The Netherlands
AIVD, NCTV, and domestic security developments relevant to Dutch operations.
Port of Rotterdam confirms cyberattack by pro-Russian group — no ransom paid, systems held
Port of Rotterdam authorities confirmed the port was targeted in a cyberattack attributed to hackers linked to pro-Russian groups, stating that no ransom was paid and sensitive data remained uncompromised. Europe's largest port handling the incident without operational disruption or payment is the good-news version of a story that European infrastructure operators should still read carefully. Pro-Russian groups have spent 2026 probing exactly this category of target — ports, rail control, water management — and the MIVD's stated doctrine shift toward disrupting and publicly attributing such operations means more of these confirmations will reach the public record, not fewer. For the broader Rotterdam port community the incident is a supply-chain reminder: the port authority's own resilience says nothing about the hundreds of terminal operators, freight forwarders, customs brokers and trucking firms whose systems interconnect with port platforms, and whose weakest member is the practical entry point. Organisations in that ecosystem should treat this week as a prompt to verify their own posture — segmentation between IT and operational systems, tested offline fallbacks for critical processes, and incident-notification clauses in contracts with port-community partners.
13-year-old posing as a police officer steals €20,000 in jewellery in Spijkenisse — uniform trust as an attack vector
Police arrested a 13-year-old in Spijkenisse who posed as a police officer and stole €20,000 worth of jewellery — a case that reads as a local-news curiosity until you strip out the perpetrator's age and look at the method. Impersonation of authority remains one of the most reliable social-engineering vectors in circulation, and the fact that a child executed it successfully against a retail environment says everything about how little verification friction stands between a convincing uniform and a victim's compliance. The professional application is direct for every organisation whose staff can be approached by people claiming official status: bank-employee scams, fake meter readers, bogus inspectors and counterfeit police remain staples of both criminal fraud and hostile reconnaissance. The countermeasure is procedural, not intuitive — a standing rule that official status is verified through an independent channel (calling the organisation's published number, not a number the visitor provides) before any access, information or goods change hands, and a briefing culture in which front-line staff know that requesting verification from a genuine officer causes no offence, while skipping it with a false one causes the loss.
Amsterdam police chief pledges safety for the rainbow community as WorldPride approaches
Amsterdam's police chief publicly promised that the rainbow community will be safe during WorldPride and beyond — a statement of intent ahead of one of the largest events the city has hosted, arriving in a summer of visible polarisation across Dutch public space. For security professionals the event brings a familiar but demanding combination: sustained multi-week crowd operations across canals, streets and venues; a symbolic profile that attracts both celebration and hostility; and an international attendee population with elevated duty-of-care expectations from employers sending staff and delegations. Hotels, venues and corporate hosts in Amsterdam should be planning now rather than in the opening week — coordinating private security postures with the municipal operation, briefing staff on de-escalation and incident reporting, and reviewing how their premises handle both celebratory crowd overflow and targeted disruption. The police chief's pledge also sets the accountability frame: when the state names a community's safety as its explicit commitment, private-sector partners in the event economy inherit a share of that commitment at their own front doors.
Compiled from credible pro-EU, pro-NATO news sources. Mission Support does not publish operational specifics or unverified claims.
Ready to speak with a specialist?
We respond within one business day. Initial conversations are confidential and without obligation.
Request a Consultation