Daily intelligence briefing: 24 July 2026
Brent crude has settled above 100 dollars a barrel after the Houthis attacked two Saudi tankers in the Red Sea and the Revolutionary Guard declared the Strait of Hormuz completely closed, a step change that puts both of the region’s chokepoints in contention at once. Washington has warned it will hold Iran responsible for the Houthi strikes, and Iranian retaliation has now reached American positions in Kuwait and Jordan. London remains in routine posture, with the Sunday Windrush closure the main planning point and heat rebuilding towards 30 degrees into the weekend. On the digital side, the SharePoint patch and rotate sequence remains the immediate action, and confirmed breaches at EY, Estee Lauder and Accenture sharpen the phishing risk that flows through the professional firms and brands serving private wealth.
United Kingdom and London
The national terrorism threat level remains at SEVERE, meaning an attack is highly likely. The Metropolitan Police picture is routine casework. The neighbourhood crime figures released on Wednesday, showing theft, robbery and vehicle offences down 14% across London over 12 months, continue to describe a baseline moving in the right direction. The appeal for Fatumata, the 27 year old missing from Kentish Town since Monday evening, remains live, as does the request to identify a man in connection with a serious assault in Hackney that followed an England World Cup fixture. Elsewhere the courts continue to clear existing casework, including the conviction of a man for assisting the escaped prisoner Daniel Khalife, with sentencing listed for 4 September. Nothing in the past 24 hours alters the assessment that London is operating in a normal policing posture.
Transport remains quiet, and the late evening Weaver line works concluded as planned last night. The point to plan around this weekend is unchanged: the Windrush line closure on Sunday 26 July, between Sydenham and Crystal Palace and between Wandsworth Road and Clapham Junction, will complicate south London movements, and the more significant disruption follows at the end of the month with no Piccadilly line service between Cockfosters and Uxbridge on 30 and 31 July, including the whole line on the Friday Night Tube, which will bear on late Heathrow connections. No heat health alert was in force at the time of compilation, but the Met Office expects temperatures around 30 degrees in the south east today and into the weekend, and fresh UKHSA alerting should be anticipated if the forecast holds. The summer peak continues at Heathrow, Gatwick and the Eurostar terminals, and extended check in buffers remain advisable.
Travel corridors
The Gulf picture has deteriorated. United States forces completed a twelfth consecutive night of strikes early on Thursday, targeting maritime capabilities, missile storage and air defences, and the Revolutionary Guard retaliated against American positions at Ali Al Salem air base in Kuwait and in Jordan, where further American personnel have been killed. The Guard claims to have set a tanker ablaze inside the Strait of Hormuz and has declared the strait completely closed to tanker traffic while operations continue. The Houthis have opened the second chokepoint, striking the Saudi tanker Encelia with missiles and drones, the crew reported safe, and claiming an attack on a second vessel, with five Saudi tankers diverting in response. Brent moved above 100 dollars a barrel on Thursday and WTI above 90, Goldman Sachs sees Brent beyond 120 dollars by the fourth quarter if disruption persists, and Washington has said it will hold Iran responsible for Houthi attacks while threatening major military punishment. The aviation position is unchanged: the EASA guidance advising operators to avoid the airspace of Bahrain, Kuwait, Qatar and the United Arab Emirates runs to 29 July, and 13 foreign carriers have suspended Dubai services into October. Our advice is also unchanged: all Gulf travel, including Dubai, should remain deferred, and principals still in the region should depart early on refundable routings.
In Europe, the Monaco investigation produced no overnight development, and the question of who commissioned the parcel bomb remains open while Ukraine presses for a joint investigation following the death of the named suspect on Ukrainian territory. The standing advice on parcel and courier discipline holds for principals with commercial exposure to Ukraine or Russia. In Paris, the Louvre reopened the Apollo Gallery on Wednesday, nine months after the theft; the jewels remain unrecovered, royal gems will not return to that gallery, and the Culture Ministry has announced a national plan to harden museum security, a tacit acknowledgement of the vulnerability that the Lalique burglary and the wider series have already demonstrated. A low profile with valuables out of sight remains the sensible discipline in France. Geneva and Zurich report nothing beyond established summer congestion, with queues of up to five hours reported at peak and generous airport buffers advisable. New York continues to recover from the week’s storms, which combined with air traffic control staffing shortfalls to force more than 500 cancellations and over 4,000 delays across the three airports; carrier waivers remain in place and generous buffers should be applied to transatlantic movements through the weekend.
Digital and privacy exposure
The SharePoint position is unchanged in substance and remains the first item on the technical agenda: patch, remediate, then rotate IIS machine keys. Exploitation of the critical deserialisation flaw CVE-2026-50522 has continued to broaden since public exploit code appeared on 20 July, attackers are stealing machine keys to retain access after compromise, and CISA guidance is clear that patching alone is insufficient. CVE-2026-58644, the fourth SharePoint flaw abused in a month, remains on the known exploited catalogue. The network edge otherwise demands attention on two fronts: the Qilin campaign against the Palo Alto Networks authentication bypass CVE-2026-0257 continues, and two SonicWall zero days, CVE-2026-15409 and CVE-2026-15410, are being exploited to deliver custom malware. A remote code execution flaw in the ServiceNow AI platform, CVE-2026-6875, extends the same lesson to hosted business systems, and any unpatched WordPress estate should still be assumed to be under probing.
The privacy development that matters most to households this week is the pattern of breaches inside the professional and luxury supply chain around private wealth. EY has disclosed a breach exposing names, addresses, social security numbers and card data; Estee Lauder has confirmed exfiltration of personal, financial and health information through an Oracle E-Business Suite zero day; and Accenture has confirmed an isolated breach after a criminal actor offered some 35 gigabytes of internal material for sale. The direct lesson is familiar: data on wealthy individuals concentrates with advisers and brands, and each of these incidents will seed convincing targeted phishing that references a firm the family actually uses. Correspondence purporting to come from accountants, consultants or luxury houses should be treated with heightened suspicion in the coming weeks, and call back verification on any change to payment instructions remains the control that matters most. The reminder on the Adobe Acrobat browser extension stands: update to version 26.5.2.2 or remove it, given the demonstrated route into WhatsApp Web sessions on household devices.
London holds a routine posture, with the Sunday Windrush closure and the late month Piccadilly works the only planning points, although heat around 30 degrees and fresh UKHSA alerting are likely through the weekend. The Gulf situation has worsened rather than stabilised: with the Guard declaring Hormuz closed, the Houthis striking tankers at Bab al Mandeb and Brent above 100 dollars, both chokepoints are now contested and the direction of travel is escalatory. All Gulf travel, Dubai included, should remain deferred, with the EASA guidance to 29 July the practical horizon. New York requires generous buffers through the weekend while storm and staffing disruption clears. On the digital side, complete the SharePoint patch and rotate sequence, bring the SonicWall and Palo Alto edges to the front of the queue, and treat the EY, Estee Lauder and Accenture breaches as the precursor to targeted phishing against families and their advisers; call back verification on payment changes remains the essential discipline.
Speak with us in confidence.
Tell us, in outline, what you need to protect. We reply promptly and privately, and only ever hold the detail you are comfortable sharing.

