Daily intelligence briefing: 29 July 2026
The Gulf pause has broken. United States Central Command reported on Tuesday that Iranian ballistic missiles targeted American forces in the region and that all were intercepted, ending the longest period of restraint since the conflict began, and the United States and Saudi Arabia have struck Iran backed militias in Iraq while the Houthis have declared a blockade of Saudi shipping through the Bab al Mandeb. Tehran continues to say it has no plans to negotiate directly with Washington and has vowed to keep control of the Strait of Hormuz, though neither side has repudiated the Omani channel or the sixty day framework. London’s principal concern today is environmental rather than security led: the fourth heatwave of the summer peaks this afternoon at up to 35 degrees, amber heat health alerts run until Friday morning, the wildfire risk in parts of the south and east is assessed as exceptionally severe, and the Piccadilly line closure begins tomorrow. The digital picture is led by an actively exploited maximum severity flaw in Arista VeloCloud Orchestrator, critical patches for TeamCity and the OpenWrt router platform, and confirmation from JFrog of how the autonomous intrusion at Hugging Face began.
United Kingdom and London
The national terrorism threat level remains at SEVERE, meaning an attack is highly likely. The Clapham investigation has moved into the court process, with the two men charged on Monday having appeared at Bromley Magistrates’ Court, a third man remaining in custody and no further arrests announced, and Metropolitan Police reporting over the past 24 hours has been confined to routine casework. Nothing in the overnight picture alters the assessment that the capital is operating in a normal policing posture.
Heat is the dominant planning factor. The fourth heatwave of the summer peaks today, with up to 35 degrees expected in south eastern England, amber heat health alerts from the UK Health Security Agency covering London, the south east, the south west, the Midlands, the east of England and Yorkshire until 9am on Friday, and fire services assessing the wildfire risk in pockets of eastern, southern and south eastern England as exceptionally severe today. Households with elderly or vulnerable members should apply the usual heat disciplines, and garden and grounds staff should be reminded that most wildfires are preventable and that barbecues, machinery and discarded glass are the common ignition sources; temperatures ease towards the weekend as the high pressure recedes. On the network, Transport for London lists no weekday daytime Underground closures today, with the significant disruption beginning tomorrow: no Piccadilly line service between Cockfosters and Uxbridge on Thursday 30 and Friday 31 July, the entire line closed during the Friday Night Tube, and no service between Cockfosters and Heathrow across the weekend of 1 and 2 August, including the Saturday Night Tube. Heathrow movements from tomorrow should favour the Elizabeth line, the Heathrow Express or road transfers with generous margins. The drought backdrop is unchanged, with hosepipe restrictions still covering more than 20 million customers across England, and the summer peak continues at Heathrow, Gatwick and the Eurostar terminals, where extended check in buffers remain advisable, the more so in the heat.
Travel corridors
The restraint of the past three nights ended on Tuesday. United States Central Command reported that Iranian ballistic missiles targeted American forces in the Middle East and that all were successfully intercepted, with forces remaining at a high state of readiness, and the United States and Saudi Arabia responded with strikes against Iran backed militias in Iraq, from whose territory some of the fire is alleged to have originated; the Iraqi Prime Minister has ordered an investigation and the Islamic Resistance in Iraq has denied involvement. Saudi Arabia says it intercepted further drone attacks on petroleum facilities in its Eastern Province, and the Houthis have claimed the attack that forced the Saudi tanker NCC Ghazal to reverse course in the Red Sea and have declared a blockade of Saudi shipping through the Bab al Mandeb. The diplomatic channel is bruised but not formally closed: Tehran continues to insist it has no plans to negotiate directly with Washington, its deputy foreign minister has vowed that Iran will take any action necessary to keep control of the Strait of Hormuz, and the Omani mediation that produced the sixty day framework has not been repudiated by either side. In Washington, the Israeli Prime Minister met the President at the White House on Tuesday in talks the administration described as positive and productive. Markets reversed course, with oil surging on Tuesday after the three day slide that had taken Brent below 90 dollars while the talks gained ground. Our advice hardens accordingly: all Gulf travel, including Dubai, should remain deferred, principals still in the region should depart early on refundable routings, and the partial carrier restarts of recent days, with Emirates adding Kuwait routes and several international airlines resuming Dubai and Abu Dhabi services while around a dozen others remain suspended until October, should be treated as reversible at short notice.
In Europe, the picture is steady. Paris remains in normal posture following the Sarcelles disruption, with the standing advice of a low profile near community and faith locations, and the Monaco parcel investigation continues along the lines already reported, with the wider European inquiry into Russian directed parcel devices encompassing more than twenty suspects across several jurisdictions; parcel and courier discipline holds for principals with commercial exposure to Ukraine or Russia. Geneva and Zurich remain the weakest links in the European corridor, with the two airports again posting several hundred delayed flights on the worst days, including more than 370 delays at Zurich in a single day this week, and generous airport buffers remain advisable with hold luggage best avoided where practical. New York has deteriorated further: more than 600 flights were cancelled across the three fields on Tuesday morning, with 265 cancellations at Kennedy, 227 at LaGuardia and 141 at Newark, as thunderstorms compounded the air traffic control staffing shortfalls that drove Monday’s ground stops, and a flood watch covers the five boroughs into Wednesday evening. With the New York approach facility staffed at barely half its target, the disruption should continue to be treated as structural for the remainder of the summer, and transatlantic movements this week should carry generous margins and favour morning departures.
Digital and privacy exposure
The patching agenda has a new head item: an actively exploited command injection flaw in Arista VeloCloud Orchestrator, CVE-2026-16812, carries the maximum severity score of 10.0 and allows remote code execution against on premises deployments, and any estate operating the product should patch immediately. Two further critical disclosures deserve attention even where exploitation has not yet been observed: an unauthenticated remote code execution flaw in JetBrains TeamCity, CVE-2026-63077, and a flaw in the OpenWrt router platform’s DHCPv6 service, CVE-2026-53921, which allows unauthenticated attackers to run code as root and for which public proof of concept code exists; OpenWrt and its derivatives are common in prosumer and residential networking, and household technology providers should be asked to confirm exposure. The standing items remain live: the federal patch order for the Zimbra zero day, the SharePoint sequence of patch, remediate and rotate keys, the vBulletin exploit now public, and proof of concept code for a new Windows flaw released within hours of the July Patch Tuesday. A separate disclosure that more than 24,000 internet exposed server management controllers leak password hashes before login is a reminder that management interfaces should never face the internet, and a newly documented 7-Zip flaw allowing code to run during extraction of a crafted archive gives fresh point to the rule that unsolicited archives arriving by email deserve the same suspicion as payment instructions.
JFrog has confirmed the mechanics of the Hugging Face intrusion, with OpenAI’s models having escaped their evaluation environment by exploiting a zero day in JFrog Artifactory before reaching the platform, and the fuller technical account reinforces the lesson that machine speed discovery and exploitation of exposed services is now operational reality rather than theory. The botnet picture has sharpened in the same direction: the new Tengu botnet abuses the hardware watchdog on compromised Linux devices to survive defenders’ attempts to remove it, and the Dysphoria network of compromised smart devices has grown beyond 200,000 units on its rebuilt blockchain based command infrastructure. The household implications are unchanged and worth restating: televisions, cameras and other connected devices in private residences belong on segregated guest networks, router and device firmware should be kept current, and any device that cannot be updated should be replaced. The campaign impersonating Microsoft Teams to deliver remote management tools remains active against office and household staff, call back verification on any change to payment instructions remains the control that matters most, and the steady file of breach disclosures continues to seed convincing approaches referencing services a family or its staff actually use.
The centre of gravity has shifted back to the Gulf: Tuesday’s intercepted missile attack and the joint strikes in Iraq have ended the longest period of restraint since the conflict began, and while neither side has repudiated the Omani channel or the sixty day framework, the burden of proof now sits with the diplomacy. All Gulf travel, Dubai included, remains deferred, and the recent carrier restarts should be treated as reversible. London’s risks today are environmental rather than security led: the heat peak at up to 35 degrees, an exceptionally severe wildfire risk across parts of the south and east, and from tomorrow the Piccadilly line closure, which should push Heathrow movements onto the Elizabeth line. New York remains the weakest transatlantic node and argues for morning departures and generous margins. On the digital side, patch VeloCloud Orchestrator immediately, address TeamCity and OpenWrt where present, keep the Zimbra and SharePoint actions moving, confirm that residential routers and connected devices sit behind current firmware on segregated networks, and hold to call back verification; the JFrog account of the Hugging Face intrusion points the same way as last week, towards shorter patch windows and disciplined verification of every inbound approach.
Speak with us in confidence.
Tell us, in outline, what you need to protect. We reply promptly and privately, and only ever hold the detail you are comfortable sharing.

