Daily intelligence briefing: 22 July 2026
United States forces have struck Iran for an eleventh consecutive night, with fires burning aboard two oil tankers in the Strait of Hormuz and the Revolutionary Guard warning that the strait will remain closed to exports while the campaign continues. In Europe the Monaco investigation has taken a decisive turn: the suspect in the parcel bomb attack has been found dead near Kyiv, with a serving Ukrainian military intelligence officer confessing to her killing. London opens the day in routine posture with full transport service and no heat alerts in force, while severe storms have cut more than 600 flights across the New York airports. On the digital side, actively exploited flaws in Microsoft SharePoint and Palo Alto Networks appliances lead the patching priorities for family offices and the professional firms around them.
United Kingdom and London
The national terrorism threat level remains at SEVERE, meaning an attack is highly likely. The Counter Terrorism Policing investigation into the suspected threat to the Islamic gathering at Shrubland Hall in Suffolk continues following the release without charge of all seven men who had remained in custody, and the public position is unchanged: there is no evidence of a wider threat. The Metropolitan Police picture is otherwise one of routine casework. A conviction was secured on Tuesday against a man who assisted the escaped prisoner Daniel Khalife, with sentencing set for September, and a murder charge has been brought in the East Finchley investigation. Nothing in the past 24 hours alters the assessment that London is operating in a normal policing posture.
Transport remains quiet. All Underground, Elizabeth line and DLR services are operating normally, and the late evening closures on the Weaver line between Hackney Downs and Enfield Town and Cheshunt after 10.45pm conclude on Thursday. The Windrush line closure on Sunday 26 July, between Sydenham and Crystal Palace and between Wandsworth Road and Clapham Junction, remains the point to plan around for weekend movements in south London. No heat health alerts are in force, but the Met Office expects heat to rebuild across England through the week, with temperatures approaching 30 degrees in places by Friday, and fresh alerting should be anticipated if that forecast firms. The summer peak continues at Heathrow, Gatwick and the Eurostar terminals, and extended check in buffers remain advisable.
Travel corridors
United States Central Command has confirmed an eleventh consecutive night of strikes on Iran, with explosions reported at Tabriz, Tehran, Bushehr and Sirik and across Khuzestan province. The stated aim is to degrade Iran’s ability to threaten commercial shipping in the Strait of Hormuz, and the maritime picture illustrates why: the Revolutionary Guard reported massive fires aboard two oil tankers in the strait following an explosion on Tuesday, and has warned that not a drop of oil or gas will leave the region while American operations continue. At Bab al Mandeb, Saudi Arabia has condemned the Houthi blockade declaration and pledged all necessary measures to protect its vessels; Saudi crude loadings through the strait have already fallen by roughly a third, Brent has traded near 90 dollars a barrel, and clashes near Hodeidah alongside missile fire towards Abha airport point to a confrontation that is deepening rather than stabilising. In the air, the EASA guidance advising operators to avoid the airspace of Bahrain, Kuwait, Qatar and the United Arab Emirates at all altitudes still runs to 29 July, Etihad’s Abu Dhabi to Kuwait cancellations stand until 24 July, and open reporting indicates 13 foreign carriers have now suspended Dubai services into October. The Foreign Office position is unchanged, and so is ours: all Gulf travel, including Dubai, should remain deferred, and principals still in the region should depart early on refundable routings rather than wait for conditions to force the decision.
The Monaco investigation has moved decisively. The suspect in the parcel bomb attack that injured a Ukrainian businessman, his son and his partner in late June has been identified in open reporting as a 39 year old Ukrainian national, and she has been found dead near Kyiv with gunshot wounds. Ukraine’s Security Service states that a serving military intelligence officer has confessed to her killing, assisted by a former law enforcement officer, and both men are in custody; the question of who commissioned the original attack remains open and Monaco’s judicial inquiry continues. The manhunt that sustained the visible uplift on the Riviera is therefore over, but while the commissioning question is unresolved the standing advice on parcel and courier discipline holds for principals with commercial exposure to Ukraine or Russia. Elsewhere in Europe the picture is routine: no fresh high value theft was reported in France overnight, although the series that includes the Lalique museum burglary remains unresolved and justifies a low profile with valuables out of sight, and Geneva and Zurich report nothing beyond the familiar summer queues at the Swiss airports. New York is the corridor under most pressure. Severe thunderstorms and flash flooding on Monday forced more than 600 cancellations across the three New York airports, with roughly a quarter of LaGuardia departures cut, and carriers have issued waivers running through midweek. Recovery delays of 12 to 24 hours are expected even after the weather clears, and generous buffers should be applied to all transatlantic movements through Wednesday and Thursday.
Digital and privacy exposure
The patching priorities this morning are led by Microsoft SharePoint. A critical deserialisation flaw in on premises SharePoint Server, CVE-2026-50522, rated 9.8, is under active exploitation for remote code execution, days after the July Patch Tuesday release fixed two separately exploited zero days including one in Active Directory Federation Services. Family offices and the professional firms that serve them, many of which still run document collaboration on premises, should treat this as an immediate action. The Qilin ransomware group is exploiting an authentication bypass in Palo Alto Networks PAN-OS, CVE-2026-0257, to establish VPN sessions without credentials before moving to encryption and extortion, which keeps the network edge at the front of the queue alongside the SonicWall appliances reported earlier in the week. Exploitation of the critical WordPress pair, CVE-2026-60137 and CVE-2026-63030, is now described as well underway across the installed base, and any family, foundation or estate website that has not yet been patched should be assumed to be under probing. A sandbox escape in the ServiceNow AI platform, CVE-2026-6875, completes the list for organisations that use it.
The privacy development of most direct relevance to families concerns Apple’s Hide My Email service. Researchers report a flaw, present for around a year, that allowed the real address behind a disposable alias to be unmasked. Families who rely on aliases to keep personal addresses out of retail and registration databases should assume some of that separation may have been lost and treat unexpected approaches on addresses believed to be private with additional caution. Deutsche Bank’s investigation into the supplier breach claimed by the Unsafe ransomware group continues without further public detail, and set beside the EY exposure of client tax and investment documentation the standing conclusion holds: the professional firms and suppliers around private wealth remain the most likely route to family data, and call back verification on any change to payment instructions remains the control that matters most. The removal of the ModHeader browser extension, which carried dormant data collection code to some 1.6 million users, is a reminder that the short approved list for extensions on household and staff devices should be enforced rather than merely stated.
London holds a routine posture, with normal transport service, no heat alerts in force and only late evening engineering works to plan around, although heat and its associated alerting may return by the weekend. The Gulf remains closed to discretionary travel, Dubai included; burning tankers in the Strait of Hormuz and a hardening confrontation at Bab al Mandeb both point away from de-escalation, and the EASA airspace guidance to 29 July remains the practical horizon. The death of the Monaco suspect closes the manhunt but not the case, and parcel and courier discipline should be retained while the commissioning question is unresolved. On the digital side, patch SharePoint, PAN-OS and WordPress estates without delay, and treat the Hide My Email disclosure as cause to review which household addresses may now be exposed.
Speak with us in confidence.
Tell us, in outline, what you need to protect. We reply promptly and privately, and only ever hold the detail you are comfortable sharing.

