The Gulf war remains the day's dominant driver: US forces destroyed five Iranian tankers and Tehran struck Jordan in retaliation, while Trump signalled the conflict will outlast November's US elections. A second theatre opened as Ukraine struck deepest yet into Russia's Arctic gas sector and Zelensky's aircraft narrowly avoided a drone near Norway. Non-military: multiple Chinese state-linked hacking groups were found exploiting an identical Chrome zero-day.
Global
International security developments, NATO, and geopolitical threats.
US destroys five Iranian tankers as Tehran strikes Jordan, Trump signals prolonged war
Escalation continues in the Gulf conflict that has driven oil past $100 a barrel: US forces destroyed five Iranian vessels identified as tankers, while Tehran retaliated with strikes on targets in Jordan, widening the conflict beyond the Gulf states into the broader Levant. Separately, President Trump told the Republican convention that the war with Iran will not conclude before November's midterm elections, signalling Washington's expectation of a prolonged campaign rather than rapid de-escalation. For organisations with personnel, assets or supply chains touching the Gulf, Jordan or wider Levant, this combination points to sustained elevated risk rather than a short-term spike: continued volatility in energy prices, tightened maritime and aviation corridors, and a higher baseline threat to facilities and travel in Jordan specifically. Security teams should refresh country risk ratings for Jordan and Gulf states, review duty-of-care arrangements for any personnel currently in-region, and stress-test supply chain and insurance exposure against a conflict now expected to run for months rather than weeks.
Zelensky's plane nearly hit by drone near Norway as Ukraine strikes deepest yet into Russia's Arctic gas industry
Ukraine carried out its deepest strike yet inside Russia, hitting gas infrastructure in the Arctic region, as Norway's prime minister disclosed that President Zelensky's aircraft was nearly struck by a drone during a flight, days after a wave of Russian drone strikes hit a Kyiv TV building and the Moldovan border. The near-miss, confirmed by both Dutch and German coverage, underscores how the drone and airspace threat generated by the war is no longer confined to Ukrainian or immediately adjacent territory: NATO members' airspace, aircraft and infrastructure are increasingly within the risk envelope, whether through miscalculation, stray munitions or deliberate testing of response thresholds. For organisations operating executive aviation, chartering flights near Baltic or Nordic airspace, or running Arctic and Northern European energy assets, this raises the practical case for pre-flight risk briefings, close monitoring of NOTAMs in affected corridors, and heightened vigilance around critical infrastructure with Russian-linked exposure. Expect continued Russian strikes on Ukrainian energy infrastructure alongside further Ukrainian reach into Russian territory.
Multiple Chinese state-linked hacking groups exploit the same Chrome zero-day
Multiple Chinese state-linked hacking groups have been observed exploiting an identical zero-day vulnerability in Google Chrome, according to new threat intelligence reporting, indicating either a shared exploit supply chain or unusually close coordination between otherwise distinct advanced persistent threat clusters. The pattern is significant for defenders: a single unpatched flaw being weaponised simultaneously by several state-aligned actors compresses the window organisations have to patch before broad exploitation, and increases the likelihood that mid-sized or under-resourced targets are swept up alongside primary intelligence targets. This lands the same week as a record Patch Tuesday covering 974 CVEs, two already under active attack, compounding pressure on already stretched patch-management teams. Organisations should treat browser and endpoint patching as a priority-one action this week, verify Chrome is updated across managed and BYOD fleets, and review logging for indicators associated with Chinese APT tooling. Boards overseeing regulated or intellectual-property-intensive businesses should also confirm incident response and breach-notification playbooks are current ahead of tightening EU reporting timelines.
European Union
EU security directives, Europol threat assessments, and policy developments.
Documents show Spanish intelligence warned of Ceuta mass-crossing plans before surge
Newly disclosed documents show Spanish intelligence services warned government officials of plans for a mass crossing attempt at the Ceuta border enclave before the surge materialised, raising questions about why preventive measures were not scaled up in time. The episode is a reminder that migration-related border surges are frequently preceded by identifiable indicators, and that the gap between intelligence and operational response is where organisational and reputational risk concentrates, both for state authorities and for private entities operating logistics, hospitality or security functions near the border. For organisations with operations in Ceuta, Melilla or other Spanish-Moroccan border points, this warrants a review of contingency plans for sudden crossing surges, including staff movement restrictions, facility access control and coordination channels with local authorities. More broadly, it is a useful case study for advisory teams on the value of acting on early intelligence rather than waiting for confirmation on the ground, particularly ahead of the autumn period when Mediterranean crossing attempts typically increase.
EU Cyber Resilience Act to enforce new incident-reporting requirements
The EU's Cyber Resilience Act is moving into its enforcement phase, introducing new mandatory reporting requirements for manufacturers and vendors of digital products sold into the European market, with incident notification timelines that mirror the tightened cadence already seen under NIS2. For compliance and security leadership at any organisation manufacturing, integrating or reselling connected hardware or software in the EU, this is a near-term operational requirement rather than a distant policy shift: it demands mapped reporting lines, defined severity thresholds, and tested notification workflows capable of meeting short statutory windows after a vulnerability or incident is identified. Coming in the same week as a record 974-CVE Patch Tuesday and reports of Chinese state actors exploiting a shared Chrome zero-day, the requirement lands at a moment when reporting volumes and urgency are both elevated. Organisations should confirm ownership of CRA compliance internally, audit whether current incident response plans meet the new timelines, and treat this as a trigger to formalise vulnerability disclosure processes across the product portfolio.
The Netherlands
AIVD, NCTV, and domestic security developments relevant to Dutch operations.
Netherlands acquires reconnaissance aircraft to counter espionage, sabotage and drones
The Dutch government is acquiring a dedicated reconnaissance aircraft as part of a broader effort to counter espionage, sabotage and unauthorised drone activity, reflecting a growing official assessment that the Netherlands faces sustained sub-threshold threats to critical infrastructure and government functions. The acquisition follows a pattern seen across Northern Europe of states investing in dedicated detection and surveillance capability in response to a rise in suspected state-linked reconnaissance, infrastructure incidents and drone incursions near sensitive sites, echoing the airspace concerns raised elsewhere in Europe this week. For organisations operating critical infrastructure, ports, data centres or other sensitive sites in the Netherlands, the move signals that national authorities are treating the drone and sabotage threat as persistent rather than episodic, and it is a useful prompt to revisit private-sector drone detection coverage, perimeter security and incident-reporting relationships with Dutch police and intelligence services. Security and facilities teams should ensure local protocols for reporting suspicious aerial activity are current and understood by on-site personnel.
Nearly 40% of Dutch family lawyers face threats, especially in domestic violence cases
New figures show nearly 40% of Dutch family lawyers report having faced threats or intimidation, a pattern markedly worse for those representing victims in domestic violence cases, according to corroborating reporting on the scale of the problem. The findings point to a specific and rising personal-security exposure for a professional group not traditionally viewed as high-risk, and highlight a broader trend in the Netherlands of legal, medical and other client-facing professionals increasingly facing targeted intimidation tied to the cases they handle. Law firms, chambers and in-house legal departments handling family, domestic violence or high-conflict matters should treat this as a prompt to review personal security provisions for exposed staff, including threat assessment processes, secure travel arrangements for court appearances, and building access controls at firms known to handle sensitive caseloads. Where credible threats are identified, close coordination with police and, where warranted, professional close protection support should be considered rather than left to individual lawyers to manage informally.
Dutch rail disruptions set to remain elevated again next year, ProRail warns
Dutch rail infrastructure manager ProRail is on track for another year of excessive major disruptions, with 391 significant incidents recorded so far and little improvement expected in the year ahead, according to corroborating reporting on the persistent reliability problem. While not a security incident in itself, chronic rail disruption has direct implications for corporate resilience planning in the Netherlands: it affects staff commuting reliability, event and site access logistics, and the credibility of evacuation or continuity plans that assume rail as a viable transport option. Organisations with Dutch operations should treat this as confirmation that rail should not be relied upon as a sole contingency transport mode, particularly for time-critical personnel movements, executive travel to stations, or major event logistics. Security and continuity planners should build alternative transport options and buffer time into travel risk plans by default, and factor continued disruption into planning for any Netherlands-based event or high-profile visit through the remainder of the year.
Watch — next 24–48 h
Indicators that would change the picture. Not predictions.
- 1.Whether Iran's strikes on Jordan expand to other US allies in the region; confirmation would extend the oil price surge and sharply raise Gulf/Jordan travel risk.
- 2.Whether further drones approach Ukrainian or allied aircraft near NATO airspace after the Zelensky near-miss; a repeat would raise the threat picture for European air corridors.
- 3.Whether the Ceuta border sees renewed mass-crossing attempts following revelations that intelligence warnings went unheeded; a repeat surge would test EU and Spanish border response capacity.
Compiled from credible pro-EU, pro-NATO news sources. Mission Support does not publish operational specifics or unverified claims.
Ready to speak with a specialist?
We respond within one business day. Initial conversations are confidential and without obligation.
Request a Consultation