Intelligence Briefing

Daily intelligence briefing: 23 July 2026

Daily intelligence briefing: 23 July 2026

Daily briefing23 July 2026Open source

United States forces have carried out a twelfth consecutive night of strikes on Iran, and the effect on shipping is now unambiguous: only three commercial vessels transited the Strait of Hormuz on Tuesday, a three week low, and Brent has traded above 95 dollars a barrel. London opens the day in routine posture, with neighbourhood crime figures moving in the right direction, late evening engineering works concluding tonight and heat expected to rebuild towards the weekend. New York remains the corridor under most pressure after fresh thunderstorms forced renewed ground stops on Tuesday. On the digital side, the SharePoint response has moved beyond patching to the rotation of stolen machine keys, and a flaw in the widely installed Acrobat browser extension puts WhatsApp Web sessions on household devices at risk.

United Kingdom and London

The national terrorism threat level remains at SEVERE, meaning an attack is highly likely. The Metropolitan Police opened Wednesday with figures showing neighbourhood crime down 14% across London over 12 months, with theft, robbery and vehicle offences all falling following the uplift in local policing, a helpful indicator of the direction of the baseline even if it changes nothing operationally. The remainder of the picture is routine casework: an image has been released in connection with a serious assault in Hackney, and an appeal is running for a woman missing from Kentish Town. The position on the Suffolk investigation is unchanged following the release without charge of the men who had been held, and there remains no evidence of a wider threat. Nothing in the past 24 hours alters the assessment that London is operating in a normal policing posture.

Transport remains quiet. All Underground, Elizabeth line and DLR services are operating normally, and the late evening closures on the Weaver line between Hackney Downs and Enfield Town and Cheshunt after 10.45pm conclude this evening. The Windrush line closure on Sunday 26 July, between Sydenham and Crystal Palace and between Wandsworth Road and Clapham Junction, remains the point to plan around for weekend movements in south London, and a more significant disruption follows at the end of the month with no Piccadilly line service between Cockfosters and Uxbridge on 30 and 31 July, including the Friday Night Tube. No heat health alerts are in force this morning, but the Met Office expects temperatures to build to around 30 degrees in the south east by Friday, and fresh UKHSA alerting should be anticipated if that forecast firms. The summer peak continues at Heathrow, Gatwick and the Eurostar terminals, and extended check in buffers remain advisable.

Travel corridors

United States Central Command has confirmed a twelfth consecutive night of strikes on Iran, targeting aircraft hangars, drone storage and operations centres in a stated effort to degrade the threat to commercial shipping. The shipping picture shows why the campaign has not yet achieved that aim: only three commercial vessels transited the Strait of Hormuz on Tuesday, a three week low, and between 13 and 19 July just two ships used the American backed southern corridor, both with tracking systems disabled. Brent rose around 4% on Wednesday, briefly above 95 dollars a barrel, some 20 dollars higher than when fighting resumed on 7 July, and analysts see triple digit pricing if the Red Sea chokepoints close fully. The Houthi threat to Bab al Mandeb persists, with Washington warning of direct action if Saudi Red Sea ports are blockaded, and the Pentagon has confirmed 18 American personnel killed since the campaign began. The aviation position is unchanged: the EASA guidance advising operators to avoid the airspace of Bahrain, Kuwait, Qatar and the United Arab Emirates at all altitudes runs to 29 July, and 13 foreign carriers have suspended Dubai services into October. Our advice is also unchanged: all Gulf travel, including Dubai, should remain deferred, and principals still in the region should depart early on refundable routings rather than wait for conditions to force the decision.

The Monaco investigation produced no overnight development. The question of who commissioned the parcel bomb attack remains open, Ukraine’s Prosecutor General is pressing for a joint investigation with the Monaco authorities, and security service footage of the device being placed is now in the public domain. While the commissioning question is unresolved, the standing advice on parcel and courier discipline holds for principals with commercial exposure to Ukraine or Russia. France reported no fresh high value theft overnight, although the series that includes the Lalique museum burglary remains unresolved and continues to justify a low profile with valuables out of sight. Geneva and Zurich report nothing beyond the established summer congestion, with queue times at the Swiss airports reported at up to five hours at peak, and generous airport buffers are advisable. New York remains the corridor under most pressure. Renewed thunderstorms on Tuesday forced ground stops across the New York airports, with one major carrier suspending its JFK operation for the day and federal flow restrictions compounded by air traffic control staffing shortfalls. Carrier waivers have been extended, recovery delays of 12 to 24 hours persist, and generous buffers should be applied to all transatlantic movements through Friday.

Digital and privacy exposure

The SharePoint situation has evolved rather than eased. Exploitation of the critical deserialisation flaw in on premises SharePoint Server, CVE-2026-50522, has broadened since public exploit code appeared on 20 July, and attackers are now stealing IIS machine keys to retain access after compromise. The practical consequence is that patching alone is insufficient: CISA and independent researchers advise that machine keys be rotated on any estate that may have been exposed, after intrusion artefacts have been remediated. Around 1,500 internet facing self managed instances remain visible, most of them SharePoint 2019, and CISA has added a further exploited SharePoint zero day, CVE-2026-58644, to its known exploited catalogue, the fourth SharePoint flaw abused in a month. Family offices and the professional firms that serve them should treat the patch and rotate sequence as an immediate action. The Qilin campaign against the Palo Alto Networks authentication bypass, CVE-2026-0257, continues and keeps the network edge at the front of the queue, any unpatched WordPress estate should still be assumed to be under probing, and a newly disclosed 7-Zip flaw that allows crafted archives to run code on extraction argues for caution with compressed files from unfamiliar senders.

The privacy development of most direct relevance to households concerns the Adobe Acrobat extension for Chrome, installed on more than 314 million browsers. A flaw tracked as CVE-2026-48294 allows cross site scripting that has been demonstrated to lift data from WhatsApp Web sessions, a service in daily use across many family and household staff devices, and the extension should be updated to version 26.5.2.2 or removed. The reminder about a short, enforced approved list for browser extensions on household and staff devices stands. More positively, German and American law enforcement have dismantled the Kratos phishing kit, whose infrastructure served some 1,800 criminal customers running around 15,000 campaigns a month; displacement to rival kits should be expected, and the takedown changes nothing about the disciplines that matter. The professional firms and suppliers around private wealth remain the most likely route to family data, and call back verification on any change to payment instructions remains the control that matters most.

Valorous assessment

London holds a routine posture, with normal transport service, falling neighbourhood crime and only the Sunday Windrush closure and the late month Piccadilly works to plan around, although heat and its associated alerting are likely to return by the weekend. The Gulf remains closed to discretionary travel, Dubai included; the collapse of Hormuz transits to a three week low and oil above 95 dollars both point away from de-escalation, and the EASA airspace guidance to 29 July remains the practical horizon. New York requires generous buffers through Friday while storm and staffing disruption clears. On the digital side, patch SharePoint and then rotate machine keys, keep PAN-OS and WordPress estates at the front of the patching queue, and update or remove the Acrobat browser extension on household devices given the demonstrated route into WhatsApp Web sessions.

Compiled from open sources by the Valorous Group intelligence function. This briefing is general in nature and is not client advice. Sources: Metropolitan Police releases; Transport for London planned closure notices; UK Health Security Agency alert dashboard; Met Office forecast guidance; Iran conflict, Strait of Hormuz and Bab al Mandeb reporting via CBS News; EASA conflict zone guidance and Gulf carrier schedule reporting via open aviation reporting; Monaco investigation reporting via Al Jazeera, Ynet News and The Jerusalem Post; New York airport disruption reporting via open aviation sources; SharePoint, PAN-OS, 7-Zip, Adobe Acrobat extension and Kratos takedown reporting via The Hacker News, Help Net Security, SecurityWeek, Arctic Wolf and Cyber Security News; open breach reporting, July 2026.
Confidential by design

Speak with us in confidence.

Tell us, in outline, what you need to protect. We reply promptly and privately, and only ever hold the detail you are comfortable sharing.

Previous Post
Daily intelligence briefing: 22 July 2026
Next Post
Feeling safe is not the same as being safe in London