Skip to content
    All briefs
    Daily Brief

    Published · 8 items · 3 Global · 2 European Union · 3 The Netherlands

    In brief

    Renewed US-Iran diplomacy is the main driver today. Talks have resumed after Trump's 'annihilation' threat at the UN, but risk for the Gulf and energy markets stays high. A second theatre is opening in Ethiopia: Tigray rebels have seized an airport and Ethiopian Airlines has suspended northern routes as fighting reignites. Away from the military picture, Microsoft's takedown of the EvilTokens phishing service and two UK arrests keep up the pressure on identity-based cybercrime. An EU sanctions-list change is drawing sharp criticism from Kyiv.

    Global

    International security developments, NATO, and geopolitical threats.

    Geopolitics✓ Confirmed · 4 sources
    BBC News

    US and Iran Resume Talks After Trump's 'Annihilation' Threat

    The United States and Iran held their first direct talks since June on the sidelines of the UN General Assembly. They came days after President Trump threatened in his UNGA address to "annihilate" the country, and Tehran answered with warnings of "crushing" retaliation. That the talks went ahead despite the rhetoric shows both sides are keeping a diplomatic channel open while the military signalling intensifies. In the past, that pattern has more often preceded sharp swings in Gulf shipping lanes, oil markets and regional security than genuine de-escalation. If you have staff, assets or supply chains touching the Gulf, Iran, Iraq or the wider Strait of Hormuz shipping routes, review contingency and evacuation plans. Now is not the time to relax them. Talks can collapse abruptly, and past cycles show that military signalling often follows a failed round. Security teams should watch for shifts in Iranian proxy activity across the region and for insurance and freight-risk notices on Gulf transit. Also watch for disruption to satellite or GPS services, which has accompanied past spikes in US-Iran tension.

    Our advisory intelligence service tracks Gulf and Iran-related risk indicators relevant to travel and asset exposure.

    Physical Security✓ Confirmed · 3 sources
    BBC News

    Eleven Killed as Gunmen Open Fire on Durban Homestead in South Africa

    Gunmen opened fire on a homestead near Durban, South Africa, killing eleven people. It is one of the country's deadliest single shootings in recent years. Police have launched a manhunt for the attackers, and no motive has been established yet. South Africa already has one of the world's highest violent-crime rates. In similar past incidents, gang violence, contract killings and personal disputes have all been common triggers. Mass-casualty attacks on this scale tend to bring local spikes in retaliatory violence and more police activity in the days that follow. If you have staff, executives or facilities in KwaZulu-Natal province, review close-protection arrangements, residential security and travel routing for the near term. Check that your local liaison contacts are current. Given the scale of the attack, expect continued national and international media attention. Unrest or vigils near the scene are possible and could affect movement planning in the area.

    Our personal and executive protection teams assess and mitigate risk for clients and staff travelling in or operating from South Africa.

    Cyber✓ Confirmed · 2 sources
    Dark Reading

    Microsoft Disrupts 'EvilTokens' Phishing Service, Two Arrested in UK

    Microsoft has disrupted EvilTokens, a device-code phishing-as-a-service platform that cybercriminals used to steal authentication tokens and bypass multi-factor authentication. UK authorities have arrested two people in connection with the takedown. Device-code phishing abuses a legitimate Microsoft 365 and Azure AD sign-in flow. Users are tricked into entering an attacker-generated code, which hands the attacker a valid session token without any password. The technique has spread as MFA adoption closed off simpler routes to credential theft. The stolen tokens can persist and slip past conditional-access policies, so victims often discover the compromise only after data exfiltration or lateral movement has started. Treat the takedown as a prompt, not a resolution. Disable device-code flow wherever it isn't operationally needed, and make sure conditional-access policies restrict token use by location and device compliance. Review sign-in logs from the past quarter for unusual device-code authentications. Affiliates of the service are likely to resurface under a new brand.

    Our cyber security practice helps organisations harden identity systems against device-code phishing and similar token-theft techniques.

    European Union

    EU security directives, Europol threat assessments, and policy developments.

    ComplianceReported
    BBC News

    Ukraine Protests as EU Drops Russian Oligarchs from Sanctions List

    The European Union has removed a number of Russian oligarchs from its sanctions list. Kyiv has sharply criticised the move, arguing it weakens pressure on Moscow while Russian strikes on Ukrainian territory continue. Delistings usually follow successful legal challenges, expired evidentiary grounds or diplomatic negotiation, not a change in underlying conduct. They often trigger compliance updates across the EU's restrictive-measures framework. Financial institutions, trade-finance desks and anyone screening against the EU consolidated lists should treat this as a mandatory list refresh. Delisted individuals may resume commercial activity, asset transfers or board positions that were previously prohibited. Screening systems running on cached or delayed list versions risk false positives. More seriously, they risk missed detections if related entities were also amended. Compliance teams should confirm that their screening vendor has loaded the updated list. Review any historical holds tied to the removed names, and decide whether to release them or keep them restricted on other grounds.

    IntelligenceReported
    Euronews

    AI Chatbots Found Serving Content from Sanctioned Russian State Media, RSF Says

    Press-freedom group Reporters Without Borders (RSF) has found that mainstream AI chatbots surface content from Russian state-run outlets that are formally sanctioned and banned from broadcasting in the EU. In effect, disinformation is being laundered through general-purpose AI tools that many corporate users now treat as a trusted first source of information. That matters if your organisation uses AI assistants for research, briefing preparation or open-source monitoring. Content from sanctioned outlets can carry built-in narrative framing, fabricated sourcing or influence-operation messaging with no clear attribution trail. That undermines the reliability of AI summaries used in decisions. Intelligence and communications teams should treat chatbot output as a starting point that needs source checks, not a finished product. This applies especially to Russia-Ukraine, sanctions and geopolitical topics. Before such output goes into client-facing or board-level material, ask your AI vendors what provenance filtering, if any, they apply to sanctioned or state-controlled sources.

    The Netherlands

    AIVD, NCTV, and domestic security developments relevant to Dutch operations.

    Physical SecurityReported
    NL Times

    Man, 54, Sentenced to 20 Years for Strangling Wife in Gelderland

    A Dutch court has sentenced a 54-year-old man to 20 years in prison for strangling his wife in Gelderland. It is one of the heavier sentences in a Dutch domestic-violence case this year. It is an individual criminal case, but it comes amid sustained concern from Dutch authorities and advocacy groups about intimate-partner violence. For corporate security and HR, it is a useful prompt to treat domestic-violence risk as part of the organisation's duty of care rather than a purely private matter. An employee facing domestic abuse can bring risk into the workplace in several ways. An abusive partner may follow them to a work site. Threats they disclose may never reach the security team. Changes in performance may not be recognised as risk indicators. Give employees a documented, confidential route to raise personal safety concerns with HR and security. Make sure reception, facilities and close-protection staff know how to respond if someone who poses a threat tries to get into the workplace.

    CyberReported
    NL Times

    Netherlands to Install €201 Million AI Supercomputer in Groningen

    The Dutch government is going ahead with a €201 million AI supercomputer in Groningen, part of a wider push for domestic compute capacity and digital sovereignty. Large AI infrastructure like this is a high-value target from day one. It attracts espionage aimed at model weights and training data, and sabotage because of its status as strategic infrastructure. It also carries insider-threat risk, with many highly credentialed technical staff holding privileged system access. Facilities of this profile usually need protection closer to critical national infrastructure than to a standard data centre. That means layered physical access control and TSCM sweeps of sensitive meeting rooms and control rooms. It also means vetting the hardware supply chain and contractors, and continuous monitoring for cyber intrusion and physical reconnaissance during construction and commissioning. If you are bidding for contracts, staffing or partnership roles around the facility, expect stricter due diligence and personnel vetting as the project moves from funding announcement to build-out.

    TrainingReported
    NOS

    Prosecutors: Driver in Fatal School-Camp Crash Drove 130 km/h in 80 Zone

    Dutch prosecutors have revealed that the driver in a fatal collision during a school-camp trip was doing 130 km/h in an 80 km/h zone. That level of speeding is likely to weigh heavily in the criminal case. Deaths during school or corporate group travel bring disproportionate reputational and legal exposure for the organising institution, even when the driver is a third party. Duty of care usually extends to vetting transport providers and setting minimum safety standards for contracted or chartered transport. If you organise group outings, off-sites or study trips as a school, university or company, check what your transport contracts require. Look for vehicle standards, driver vetting, speed monitoring or telematics, and minimum insurance. Don't assume that outsourcing transport also outsources liability. Use this case to audit group-travel risk assessments before the autumn season of excursions and off-sites, when many Dutch schools and companies schedule trips.

    Our training and resilience programmes help organisations build duty-of-care protocols for group travel and school or corporate outings.

    Watch — next 24–48 h

    Indicators that would change the picture. Not predictions.

    1. 01.Whether the US-Iran talks produce a concrete de-escalation step or collapse back into 'annihilation'-level rhetoric; the outcome will move Gulf shipping and oil-market risk pricing.
    2. 02.Whether federal forces counter-attack the airport Tigray rebels seized, or a ceasefire holds; a wider rupture would disrupt Ethiopian Airlines routes and regional supply chains.
    3. 03.Whether South African police apprehend the Durban gunmen within days; an unsolved manhunt would signal an organised or ongoing threat rather than an isolated incident.

    Compiled from credible pro-EU, pro-NATO news sources. Mission Support does not publish operational specifics or unverified claims.

    Ready to speak with a specialist?

    We respond within one business day. Initial conversations are confidential and without obligation.

    Request a Consultation