Get the brief

One email per week. The threats that change the risk picture, assessed at the executive level. No CVE dumps, no vendor pitches, no noise.

One email. Every Sunday. Unsubscribe anytime. Stored with Buttondown, no tracking pixels.

Also from the same intelligence shop: Attack · Defense

Here's what last week looked like

  • Iran's Hormuz toll is being formalized into law, not eased as a wartime measure, while Iran-backed Houthis close the Red Sea route Saudi Arabia built to bypass it, and paying the toll still doesn't clear a separate US Navy blockade.
  • Russia is reviving a three-year-old US legal opinion to build the case for striking Starlink, the same playbook Iran used in April against Amazon's data centers, just aimed at a new asset class.
  • A recurring AI-model-copying dispute escalated for the first time from company research findings to a formal US investigation and an on-the-record Chinese retaliation threat.
  • Washington has quietly given up on fixing 117 overlapping cybersecurity regulations. A new CISA rule due this fall adds an 118th layer rather than consolidating any of them.
  • The tariff regime is now on its third legal foundation in 18 months, and two countries already retaliated within days of the latest change taking effect.
  • A likely Iran-linked attack on Minnesota and Michigan water utilities caused real pressure loss and flooding, exploiting a vendor-installed blind spot the sector was warned about twenty months before it was used.
  • When a vendor's breach hits your customers, courts are increasingly letting both of you get sued, and the vendor's contract almost never covers what it actually costs.
1. The Blockade Has a Business Model
2. Moscow Is Writing the Legal Brief Against Starlink
3. A Recurring AI Dispute Just Became a Government-to-Government Fight
4. 117 Rules for the Same Bad Day
5. The Tariff Survived. The Law Under It Didn't.
6. The Modem Nobody Put on the Asset List
7. The Liability Doesn't Stay With Whoever Got Hacked

Read the full brief