Global
International security developments, NATO, and geopolitical threats.
Ukraine strikes deep into Russia, hitting two oil refineries
Ukrainian forces conducted long-range strikes on two oil refineries deep inside Russian territory, extending a pattern of attacks on energy infrastructure well beyond the front line. Such strikes disrupt refined product supply, tighten regional fuel markets, and raise the likelihood of Russian retaliation against energy and logistics targets, including potential cyber operations against Western utilities and pipeline operators. For organisations with operations, supply chains, or personnel connected to Eastern European energy markets, the strikes add another layer of volatility to fuel pricing and transport reliability, alongside heightened risk of collateral disruption to rail, port, and pipeline infrastructure used for wider European energy flows. Corporate security and procurement teams should treat this as a live indicator of an intensifying campaign against energy assets rather than an isolated event. Practically, firms should stress-test fuel supply contingencies, diversify logistics routes where dependent on affected corridors, brief travelling staff on the deteriorating security picture in border regions, and ensure advisory-intelligence monitoring captures both kinetic strikes and the retaliatory cyber activity that typically follows them within days.
AI used to design viruses not found in nature for the first time
Researchers have for the first time used artificial intelligence to design viral genomes not found in nature, a milestone that sharpens long-standing dual-use concerns in synthetic biology. The capability to generate novel pathogens computationally lowers technical barriers that previously constrained who could attempt such work, and raises the stakes for biosecurity screening across research institutions, pharmaceutical manufacturers, and gene-synthesis suppliers. While the reported work is presented as scientific advancement, the same tools could in principle be misused to design agents that evade existing detection or countermeasures, a scenario regulators and biosecurity bodies are only beginning to address. Organisations operating laboratories, biomanufacturing facilities, or research partnerships should treat this development as an accelerant to existing CBRN risk registers rather than a distant threat. Practical steps include tightening know-your-customer screening for DNA synthesis orders, auditing physical and cyber access controls around sensitive genomic data and lab systems, reviewing incident response plans for biological release scenarios, and briefing leadership on the pace at which AI is compressing the timeline between capability and misuse in the life sciences sector.
AI browsers exposed to 'PleaseFix' zero-click agent hijacking
Security researchers have disclosed a zero-click vulnerability, dubbed 'PleaseFix', that allows attackers to hijack AI-powered browser agents without any user interaction, alongside separate reporting that no complete fix exists for the broader class of prompt-injection flaws affecting these tools. As organisations increasingly deploy agentic AI browsers for research, procurement, and customer-facing automation, this class of vulnerability creates a direct path for data exfiltration, unauthorised transactions, and lateral movement into connected systems, all without the visible phishing cues that traditional security awareness training addresses. Because the flaw is structural to how these agents interpret web content rather than a single patchable bug, organisations cannot rely on a vendor fix alone. Security teams should inventory where agentic AI browser tools are deployed across the business, restrict their permissions and data access to the minimum required, isolate them from systems holding sensitive financial or client data, and monitor vendor advisories closely given the likelihood of follow-on exploits. Staff using these tools should be briefed that AI agents themselves are now a viable attack surface.
European Union
EU security directives, Europol threat assessments, and policy developments.
Thousands of migrants remain in Ceuta as border pressure persists
Local leaders report that thousands of migrants remain in Ceuta, the Spanish enclave in North Africa, months after the latest border crisis, underscoring that pressure on this EU external frontier has not eased. Sustained migratory pressure at Ceuta and the wider Strait of Gibraltar corridor raises the likelihood of periodic unrest, resource strain on local authorities, and intermittent disruption to border crossings used for freight and personnel movement between Morocco and Spain. For organisations with logistics, manufacturing, or travel exposure through this corridor, the situation is a standing risk factor rather than a one-off event, with potential knock-on effects for transport schedules and local security conditions. It also signals continued strain on EU migration and border management frameworks, which can shift compliance and screening obligations for firms operating cross-border logistics or workforce mobility programmes in the region. Practical measures include maintaining updated travel and logistics advisories for Ceuta, Melilla, and the Strait crossing points, building schedule buffers for freight dependent on this route, and monitoring for escalation indicators that could affect staff safety or asset security nearby.
Two convicted over death of French livestreamer
A French court has convicted two men in connection with the death of a livestreamer, a case that has drawn wide attention to the lack of safeguards around content produced under extreme or abusive conditions for online audiences. The ruling establishes that individuals and, by extension, the organisations that facilitate or sponsor such content can face criminal liability when duty-of-care obligations toward participants are neglected. This is directly relevant to any organisation involved in producing, sponsoring, or partnering with streamers, influencers, or talent for branded content, live events, or stunts, particularly where physical risk, sleep deprivation, or audience-driven escalation is part of the format. Insurers, legal counsel, and security teams should treat this as a precedent-setting signal that courts are willing to assign responsibility beyond the immediate perpetrators. Practical steps include formal risk assessments and welfare checks for any sponsored live or filmed content involving physical risk, contractual duty-of-care clauses with production partners and talent, on-site medical and security standby for high-risk shoots, and vetting of streaming partners' safety track records before entering sponsorship or collaboration agreements.
The Netherlands
AIVD, NCTV, and domestic security developments relevant to Dutch operations.
Man killed in Rotterdam apartment fire
A fire in a Rotterdam apartment building has left one person dead, the latest reminder that fire remains one of the most common and least predictable threats to occupied buildings in the Netherlands. For organisations responsible for staff housing, corporate accommodation, or hospitality properties in urban residential blocks, fatal fires of this kind highlight the gap that can exist between statutory fire safety compliance and effective real-world response times, particularly in older or densely occupied buildings. Response speed is frequently the deciding factor between a contained incident and a fatality, which places a premium on integrated alarm monitoring, direct links to emergency services, and rapid on-site response capability rather than compliance checklists alone. Organisations managing residential or mixed-use properties, or providing accommodation for executives and staff, should treat this incident as a prompt to verify that fire and smoke detection systems are monitored around the clock, that alarm response protocols are tested rather than assumed, and that evacuation plans account for residents who may be present at short notice, including protected individuals or visiting personnel.
Firefighter hit by fire truck battling Oudorp dune wildfire
A firefighter was struck by a fire truck while battling a wildfire in the dunes near Oudorp, an incident that reflects the growing strain dry conditions are placing on Dutch emergency services this summer. Wildfires in dune and heathland areas are becoming a more frequent feature of the Dutch risk landscape, with consequences that extend beyond the immediate burn area to include smoke exposure, road closures, and diverted emergency response capacity for nearby sites. Organisations operating facilities near coastal dunes, nature reserves, or other vegetation-dense areas, including logistics hubs, data centres, and tourism or hospitality venues, should treat this as an indicator that wildfire is a live operational risk rather than a remote possibility. Practical steps include reviewing site-specific wildfire and smoke contingency plans, confirming direct lines of communication with local fire brigades ahead of high-risk dry periods, ensuring perimeter and access routes remain clear for emergency vehicles, and briefing on-site security and facilities teams on evacuation triggers tied to official drought and fire-danger advisories.
Drought pushes up Dutch energy bills as cooling water grows scarce
Persistent drought is reducing the availability of cooling water for Dutch power plants, a constraint that is pushing energy bills higher across the Netherlands. Beyond the immediate cost impact, reduced cooling water access is a direct signal of climate-driven pressure on electricity generation capacity, raising the prospect of tighter margins, output constraints, or reliability issues during future heatwaves and dry spells. For organisations dependent on stable, high-availability power, including data centres, manufacturing sites, and logistics operations, this is a business continuity issue rather than a purely financial one, since generation constraints can translate into voltage instability or, in extreme scenarios, localised curtailment. Corporate security and facilities functions should factor climate-linked infrastructure stress into resilience planning alongside more traditional threats. Practical steps include reviewing backup power and UPS readiness ahead of peak heat periods, assessing exposure to rising and potentially volatile energy costs, engaging utility providers on reliability guarantees for critical sites, and incorporating drought and heat advisories into the same monitoring processes used for other national-security-relevant infrastructure risks.
Compiled from credible pro-EU, pro-NATO news sources. Mission Support does not publish operational specifics or unverified claims.
Ready to speak with a specialist?
We respond within one business day. Initial conversations are confidential and without obligation.
Request a Consultation