If you just remember one thing from this briefing…
US intelligence now assesses Putin may probe NATO's Article 5 threshold with a small, deniable attack rather than open war.
The assessment surfaced days after an explosive-laden drone was found beside a Ukrainian cargo aircraft at
Leipzig/Halle airport, which Germany's interior minister called a new threat scenario. Expect ambiguous,
hard-to-attribute incidents, not a clear opening move. Ask your crisis team this week whether your response
plan assumes attribution will be available before you have to act.
Priority5–7 Aug
Explosive drone at German airport; US assesses Russia may test NATO's Article 5
A drone carrying explosives was found near a Ukrainian cargo aircraft at Leipzig/Halle airport overnight
on 5–6 August, forcing diversions and a partial closure. US officials separately assessed Russia may
attempt a limited, deniable strike on a NATO member to test alliance resolve short of Article 5.
So what: treat sub-threshold attacks on domestic infrastructure as a live
contingency. Crisis plans should assume attribution will be contested, not certain, when the moment comes.
Priority1, 6, 8 Aug
Ukraine's strikes reach 1,600km into Russia, hitting refineries three times in a week
Ukrainian forces struck oil refineries in Bashkortostan on 1 August, roughly 1,600km from the border, then
Yaroslavl on 6 August and Krasnodar region on 8 August, degrading Russian refining capacity and export
revenue. The campaign has been sustained, not a single spike; Russian confirmation of damage remains
limited.
So what: long-range strike and precision-munition demand is not slowing. Check
whether your defence supply chain is positioned for sustained, not surge, production.
Priority2 Aug
EU AI Act reaches full enforcement
The Act's remaining obligations took effect on 2 August, with penalties of up to €35 million or 7 per cent
of global turnover for non-compliance. It applies extraterritorially to any organisation placing an AI
system on the EU market, regardless of where that system was developed.
So what: confirm which of your AI systems are in scope, including embedded
third-party models, and that conformity documentation exists before a regulator asks for it.
Priority30 Jul–5 Aug
AI agent used to automate cyberattacks at scale against internet-facing systems
Unit 42 identified a China-based actor running the DeepSeek model inside an open-source agent framework to
autonomously find and exploit flaws in Citrix, Tomcat and other internet-facing software across more than
460 targets. CISA added related CVEs to its exploited-vulnerabilities catalogue on 5 August. The actor is
assessed as independent, not state-sponsored.
So what: AI-driven exploitation shortens the gap between disclosure and mass
exploitation. Patch timelines built around days of grace no longer hold.