Daily intelligence briefing: 21 July 2026
The conflict in the Gulf has widened to a second maritime chokepoint. United States forces have opened a tenth consecutive night of strikes on Iran, with explosions reported at Bandar Abbas and Sirik, and Yemen’s Houthis have declared a naval blockade of Saudi shipping at the Bab al Mandeb strait, placing a second artery of world oil supply under direct threat. London opens the week in routine posture, with full transport service and no heat alerts in force. On the digital side, Deutsche Bank’s confirmation that it is investigating a supplier breach claimed by the Unsafe ransomware group, alongside actively exploited flaws in SonicWall VPN appliances and WordPress, keeps third party compromise at the centre of family digital exposure.
United Kingdom and London
The national terrorism threat level remains at SEVERE, meaning an attack is highly likely. The Counter Terrorism Policing investigation into the suspected extreme right-wing threat against the Islamic gathering at Shrubland Hall in Suffolk continues following the release without charge of all seven men who remained in custody, with searches at linked addresses ongoing and police continuing to state there is no evidence of a wider threat to the public. The weekend’s public order commitments concluded without significant disorder, and the celebrations that followed Spain’s World Cup victory passed off in the West End and Soho without incident of note in open sources. Routine casework continues beneath the headlines, and the recent National Security Act charge remains a reminder that state threat investigations run alongside the terrorism picture.
The transport picture is the quietest it has been for some weeks. All Underground, Elizabeth line and DLR services are operating normally, and the only planned works of note are the late evening closures on the Weaver line between Hackney Downs and Enfield Town and Cheshunt after 10.45pm, which run until Thursday and principally affect movements into north east London after dinner hours. Looking ahead, the Windrush line closes on Sunday 26 July between Sydenham and Crystal Palace and between Wandsworth Road and Clapham Junction, which should be factored into any south London movements planned for the weekend. No heat health alerts are currently in force, although conditions remain warm and forecasters point to heat returning later in the week. The summer peak continues at Heathrow, Gatwick and the Eurostar terminals, and extended check in buffers remain advisable.
Travel corridors
United States Central Command has confirmed a further round of strikes on Iran, the tenth consecutive night of the campaign, with Iranian media reporting explosions at Bandar Abbas and Sirik on the Strait of Hormuz. President Trump has warned that every American death will be repaid many times over, while Iran’s foreign ministry states that diplomatic exchanges with Washington continue through mediators despite the strikes. The significant development of the past 24 hours sits to the south west: Yemen’s Houthis have declared an immediate maritime embargo on Saudi shipping at the Bab al Mandeb strait, calling a general mobilisation and warning of a comprehensive response to any move against them, and the Saudi-led coalition has vowed to protect shipping in response. Roughly seven per cent of global oil output transits Bab al Mandeb; taken together with the contested Strait of Hormuz, as much as a quarter of world oil and gas supply is now exposed to the conflict. In the air, the European Union Aviation Safety Agency guidance advising operators to avoid the airspace of Bahrain, Kuwait, Qatar and the United Arab Emirates at all altitudes runs to 29 July, Kuwait International Airport continues to suffer intermittent closures, Emirates cancelled eight Dubai to Kuwait rotations on Sunday with further cancellations on Monday, and Etihad has extended its Abu Dhabi to Kuwait cancellations to 24 July. Insurance costs are slowing the return of foreign carriers to Dubai even where airspace permits. The Foreign Office position is unchanged, against all but essential travel to all four states, and our position also stands: all Gulf travel, including Dubai, should be deferred, and principals still in the region should depart early on refundable routings rather than wait for conditions to force the decision.
In New York, the post-final departure surge is at its peak, with JFK logging several hundred delays and dozens of cancellations on Monday; JFK and Newark should be treated as operating at exceptional volume through midweek, with generous buffers on all transfers as tournament infrastructure stands down. In Europe the picture is steadier. The Monaco suspect, identified as a Ukrainian national and reported to have been sighted in Germany, remains at large under an international arrest warrant and Interpol red notice, so the visible uplift on the Riviera persists. No fresh high value theft was reported in France overnight, although the series that includes the Lalique museum burglary, in which 27 pieces worth some four million euros were taken, continues to justify a low profile with valuables out of sight. Geneva and Zurich remain routine, with Swiss airports still warning of extended queues through the summer peak, and travellers through Madrid should expect residual crowds and road closures in the centre as the city absorbs the celebrations around the team’s return.
Digital and privacy exposure
Deutsche Bank has confirmed it is investigating a cyber incident at a third party supplier after the Unsafe ransomware group claimed access to internal data, with the nature and quantity of any exposed material still under investigation. Set against EY’s confirmation last week that client tax and investment documentation was exposed through its IT support platform, the pattern for families is consistent: the professional firms and suppliers around private wealth concentrate precisely the information an attacker wants, and the compromise rarely begins inside the institution itself. Families should ask their advisers directly whether their data sits with affected firms, expect convincing approaches that quote accurate financial detail, and hold the standing discipline of call back verification for any change to payment instructions.
The week’s technical priorities are led by the network edge. Two SonicWall SMA 1000 VPN appliance vulnerabilities, CVE-2026-15409, rated at the maximum severity of 10.0, and CVE-2026-15410, were exploited as zero days by a tracked threat actor to gain root access before disclosure, and any family office or professional firm operating these appliances should patch immediately and review for signs of compromise. The critical WordPress pair, CVE-2026-60137 and CVE-2026-63030, allowing unauthenticated takeover of WordPress 6.9 and 7.0 sites through the REST API, remains a patching priority for any family, foundation or estate website. Two fresh campaigns warrant attention in the household: some 7,600 malicious GitHub repositories are distributing the SmartLoader malware through copied projects and convincing fake developer profiles, a caution for staff and advisers who install developer tooling, and the HollowGraph implant has been found hiding its command traffic inside Microsoft 365 calendar entries, a reminder that cloud account audits should extend beyond the mailbox. The ModHeader browser extension removal and the macOS campaign posing as Apple crash reports remain live, and the standing controls, a short approved list for extensions on household and staff devices and treatment of unexpected system prompts as hostile, remain in force.
London holds a routine posture, with normal transport service, no heat alerts in force and the weekend’s policing commitments concluded without disorder. The Gulf remains closed to discretionary travel, Dubai included; the Houthi blockade at Bab al Mandeb widens the conflict to a second chokepoint and adds Red Sea routings and shipping to the exposure picture, and with the EASA airspace guidance running to 29 July nothing in the last 24 hours brings that horizon closer. On the digital side, third party and supplier compromise is the theme of the week: confirm exposure with professional firms, patch edge appliances and web platforms promptly, and hold the verification discipline on payments and personal approaches.
Speak with us in confidence.
Tell us, in outline, what you need to protect. We reply promptly and privately, and only ever hold the detail you are comfortable sharing.

