Weekly Security Brief

Week of Sunday, July 19, 2026

Key Insights

1. The Tariff Cliff Lands July 24

For the past five months, almost everything the United States imports has carried an extra 10% tax at the border. That surcharge disappears on July 24. If you run a business that buys anything from overseas, the natural assumption is that your costs are about to drop. They are not. The 10% is being replaced by something more expensive that, unlike the surcharge, may never expire.

For the past five months, almost everything the United States imports has carried an extra 10% tax at the border. That surcharge disappears on July 24. If you run a business that buys anything from overseas, the natural assumption is that your costs are about to drop. They are not. The 10% is being replaced by something more expensive that, unlike the surcharge, may never expire.

The surcharge has been in place since February under Section 122, an emergency tariff power in the Trade Act of 1974. That power comes with a hard limit built into the law: 150 days, then it expires unless Congress votes to extend it. Congress has not, and the President cannot extend it on his own. So it ends July 24. On its face, that sounds like relief.

It is not, because the replacement was already being built. In March, the US Trade Representative, the agency that handles trade enforcement, opened two investigations under Section 301, a separate tariff power aimed at unfair foreign trade practices. Section 301 has no rate cap and no expiration date, which is exactly why it was chosen. One investigation targets countries the US says overproduce and flood the market; the other targets forced labor in supply chains. Between them they cover economies responsible for 99.4% of everything the United States imports. The findings were due July 20, four days before the old surcharge dies. That timing is not an accident.

The proposal is a 12.5% duty on 46 countries, including China, Vietnam, India, Thailand, Japan, and South Korea, with the forced-labor track reaching most of the rest. So your landed cost, the all-in price of getting a product to your door, does not fall on July 25. It gets rearranged by country, and this time it comes with no end date. The company that budgeted for the 10% to lapse guessed wrong. So did the company that moved production out of China to Vietnam to escape the last round, because Vietnam is on the new list too.

The Takeaway
Before July 24, someone needs to re-run your landed-cost numbers against the new country-by-country rates. The mistake to avoid is planning around cheaper imports next week, because imports are not getting cheaper. The cost is being re-sorted by where you buy, and the new rates have no expiration, so this is the baseline you plan around for the foreseeable future, not a spike you wait out. **Sources:** - [USTR makes findings and proposes action in the Section 301 investigations](https://ustr.gov/about/policy-offices/press-office/press-releases/2026/june/ustr-makes-findings-and-proposes-action-60-section-301-investigations-relating-failures-take-action) - [Sheppard Mullin, "Section 301'ing the World (or 99.4% of It)"](https://www.sheppard.com/insights/blogs/section-301ing-the-world-or-99-4-of-it) - [Nakachi Eckhardt & Jacobson: the Section 122 sunset and the 150-day clock](https://www.tradelawcounsel.com/insights-news/2026/7/4/section-122-surcharge-sunsets-july-24-what-importers-should-do-beforeand-afterthe-150-day-clock-runs-out)

2. Brazil Loads the Weapon

The countries getting hit by that tariff regime are not absorbing it quietly, and Brazil's answer reaches a place American companies rarely think to protect: their own patents.

The countries getting hit by that tariff regime are not absorbing it quietly, and Brazil's answer reaches a place American companies rarely think to protect: their own patents.

On July 22, the US puts a 25% tariff on Brazilian goods. It follows a year-long US investigation into a set of Brazilian practices Washington calls unfair. At the top of the list is Pix, Brazil's instant-payment system. Pix is run by the country's central bank, it is free to use, and most Brazilians now reach for it instead of a credit card, which cuts US card networks out of the transaction fees they collect almost everywhere else. The same investigation flagged Brazilian court orders against American tech platforms, barriers to US ethanol, weak intellectual-property enforcement, and deforestation. Brazil has said Pix, specifically, is not on the table.

Brazil's counter is a law it wrote for exactly this moment, the Economic Reciprocity Law. Part of it is conventional: it lets Brazil put tariffs on the 76% of US goods that currently enter the country tax-free. The other part is not. The same law lets Brazil suspend American intellectual-property rights inside its borders, meaning pharmaceutical patents, patented agricultural seeds, and film and streaming royalties. If Brazil pulled that lever, its companies could make generic copies of US drugs and plant patented seed technology without paying for it, legally, across a market of 215 million people.

Where it stands matters. Brazil has not used the law. It has held back on purpose, wary of a wider trade war. But the law is written, passed, and pointed, and the tariff that would justify using it lands this week. The shift worth marking is this: retaliation used to mean matching tariffs, which is a cost you can put in a spreadsheet. Suspending a patent is a different kind of harm. It takes an asset you spent years and money building and switches it off, by a decision you get no vote in.

The Takeaway
If you earn money in Brazil from patents, drug approvals, seed technology, or media rights, that revenue now sits under a law designed to switch it off. Nobody can stop Brazil from pulling that trigger. What you can do is know today which of your rights are exposed there and what losing them would cost, so that if it happens you are managing a number you already ran, not discovering it in a headline. **Sources:** - [Federal Register 2026-11158: Section 301 determination on Brazil's digital-trade, payment, IP, ethanol, and deforestation practices](https://www.federalregister.gov/documents/2026/06/04/2026-11158/notice-of-determination-and-request-for-comments-concerning-action-pursuant-to-section-301-brazils) - [Courthouse News: US slaps 25% tariffs on Brazilian goods after unfair-trade probe](https://www.courthousenews.com/us-slaps-25-tariffs-on-brazilian-goods-after-probe-on-unfair-trade-practices/) - [PIIE: the latest US squeeze on Brazil jeopardizes its financial autonomy](https://www.piie.com/blogs/realtime-economics/2026/latest-us-squeeze-brazil-jeopardizes-its-financial-autonomy) - [UPI: Brazil opts for caution in the US tariff dispute](https://www.upi.com/Top_News/World-News/2026/07/17/latam-brazil-us-trade-conflict-tariffs/8691784312434/)

3. The Clean Shell Game

On July 15, the Treasury's sanctions office, OFAC, blacklisted seven people and companies for buying weapons on behalf of Iran's Revolutionary Guard, the branch of Iran's military that runs its operations abroad. It is the same force that killed US troops in Jordan this week, which is why the case surfaced when it did. The war connection is the reason it made the news. What makes it worth reading is how the network was built to look: nothing like Iran.

On July 15, the Treasury's sanctions office, OFAC, blacklisted seven people and companies for buying weapons on behalf of Iran's Revolutionary Guard, the branch of Iran's military that runs its operations abroad. It is the same force that killed US troops in Jordan this week, which is why the case surfaced when it did. The war connection is the reason it made the news. What makes it worth reading is how the network was built to look: nothing like Iran.

At the center is an Iranian, Behrouz Namazi, who runs a Tehran company making drone and aircraft parts and was trying to acquire weapons for the Guard. Everyone Treasury named around him looks unremarkable. A Moscow air-freight company called Avratek moved the money and arranged the logistics, using two of its own staff. A Nigerian firm acted as a go-between. An Italian national in Milan knowingly took part. On paper that is a Russian shipping company, a Nigerian supplier, and an Italian businessperson, none of which reads as Iranian at all.

That is the whole design, and it is how sanctions evasion works now. Compliance screening mostly compares the names of the parties you deal with against published sanctions lists. A front company in Moscow or Milan is not on any list until the day Treasury names it, and it does not advertise who it is really working for. The Iranian at the end of the chain would trip any screen. The companies standing in front of him would have passed clean, right up until this week.

The Takeaway
Most companies will never come near a network like this, so this is not a fire drill for everyone. But if you move physical goods across borders, deal in anything with a defense or dual-use angle, or route business through freight forwarders and trading middlemen, the lesson is that the risk is rarely the obvious foreign buyer. It is the ordinary-looking intermediary who landed on a sanctions list last week. The narrow question for a compliance team is how often you re-check the partners you already work with against new designations, not just the new ones at signup. **Sources:** - [US Treasury: Treasury targets global network procuring weapons for the Iranian regime (sb0564)](https://home.treasury.gov/news/press-releases/sb0564) - [OFAC recent actions, July 15, 2026](https://ofac.treasury.gov/recent-actions/20260715) - [Jerusalem Post: US sanctions network accused of procuring weapons for the IRGC](https://www.jpost.com/international/article-902657)

4. The Vault Updates From Moscow

An investigation by OCCRP deserves a place on your security radar, because it lands on the single most sensitive tool most companies run: the password manager, the vault that holds the keys to everything else. This is not a story you will catch in your regular feeds.

An investigation by OCCRP deserves a place on your security radar, because it lands on the single most sensitive tool most companies run: the password manager, the vault that holds the keys to everything else. This is not a story you will catch in your regular feeds.

Passwork Europe, a company registered in Spain in 2024 with a single owner, sells an enterprise password manager to European clients including the Irish government's Office of Public Works, Ireland's State Laboratory, Dresden University of Technology, and a Belgian firm that serves the Brussels regional government. OCCRP traced its product to a shared origin with Passwork LLC of Arkhangelsk, Russia, with a company in the UAE sitting between the two. The connection is not just history. Both products shipped version 7.6 within a day of each other this April with identical feature lists, and a security researcher, Lukasz Olejnik, found 517 lines of nearly identical installer code across the two. The Russian company holds certifications from FSTEC, a Russian Defense Ministry body, and the FSB, Russia's security service. Getting the FSTEC certification requires handing your source code to the Russian state for review.

The danger runs in two parts. A shared codebase means shared weaknesses: whatever the Russian review process learns about one version can apply to the other. The sharper risk is the update pipeline. A password manager updates itself automatically, which means its update channel is a delivery route that runs straight into the vault. A single tailored update could, in theory, be aimed to dump the stored passwords of specific targets. Nobody has shown that happening here, and the reporters found no evidence of it. The problem is the structure itself: government credentials sitting behind an update pipeline that traces back to a state-certified Russian company, and the customers were never told.

The Takeaway
This is a supply-chain problem wearing a security label. A password manager or secrets vault is only as trustworthy as the people who write and update its code, and that lineage almost never appears on a vendor questionnaire. Before a tool this sensitive gets standardized across a company, the question to answer is plain: where does the code come from, and who controls the updates that reach our systems? The way in here would not be the login screen. It would be a routine update nobody thought to question. **Sources:** - [OCCRP: European password manager shares origins and updates with a state-certified Russian firm](https://www.occrp.org/en/investigation/european-password-manager-shares-origins-and-updates-with-state-certified-russian-firm) - [Irish Times: how Russian password technology made its way into Irish State agencies](https://www.irishtimes.com/ireland/2026/07/17/how-russian-password-technology-made-its-way-into-irish-state-agencies/)

5. China Cuts Off Helium

On July 10, China banned all helium exports, effective the same day. The order, Announcement No. 29, came with no end date, no licensing exceptions, and no grace period for contracts already signed. Helium is not a nice-to-have for a lot of industries. It cools the magnets inside MRI scanners, it is used throughout semiconductor manufacturing, and it goes into fiber optics, aerospace, and anything that has to run at very low temperatures. There is no easy substitute for it.

On July 10, China banned all helium exports, effective the same day. The order, Announcement No. 29, came with no end date, no licensing exceptions, and no grace period for contracts already signed. Helium is not a nice-to-have for a lot of industries. It cools the magnets inside MRI scanners, it is used throughout semiconductor manufacturing, and it goes into fiber optics, aerospace, and anything that has to run at very low temperatures. There is no easy substitute for it.

It would be easy to file this next to China's grip on rare earths, but it is a different situation, and most of the damage was done before China acted at all. About a third of the world's helium comes from Qatar. In March, Iranian missiles hit Qatar's Ras Laffan gas complex and knocked much of that production offline, with some of the repairs expected to take years. China imports more than 85% of its own helium and gets over half of it from Qatar. So when Ras Laffan was hit, Beijing stopped exporting to protect what it had left. China was never a big helium exporter to begin with. But the global market was already short because of Qatar, and pulling China's supply out of it made a tight market tighter.

Step back and the supply map is thin to begin with. The United States is actually the world's largest helium producer, around 42% of global output, with Qatar second at roughly a third. Between them they account for about three-quarters of world supply. After that it drops off fast: Russia is close to a tenth but effectively closed to Western buyers under sanctions, and Algeria is under 6%. So with Qatar's output cut by the strikes, China hoarding, and Russia off-limits, the world is leaning harder than ever on US production, and there is very little slack anywhere else to absorb the shock.

The chain leads straight back to the war. Iran's strikes took a large share of the world's helium offline, and China's response removed more of what remained. It is worth separating this from a tariff. A tariff can be negotiated, delayed, or waived. A physical shortage caused by a missile strike and a hoarding response cannot be talked down. When the supply is simply not there, there is no one to appeal to.

The Takeaway
Helium is the kind of input nobody thinks about until it runs out, and it usually hides inside the things you buy rather than showing up as its own line, in chips, in imaging equipment, in fiber. Finding out where it sits in your supply chain, both directly and buried in components, and whether your contracts guarantee supply or only lock in a price, is time well spent this quarter. The wider pattern is the real signal: a war takes out production, and whoever still holds the material stops sharing it. Helium is the first commodity to move this way in this conflict. It will not be the last. **Sources:** - [CIRS Group: China temporarily bans helium exports, effective immediately](https://www.cirs-group.com/en/chemicals/china-temporarily-bans-helium-exports-effective-immediately) - [SCMP: China issues temporary helium export ban as Iran war strains global supplies](https://www.scmp.com/economy/china-economy/article/3360114/china-announces-temporary-ban-helium-exports) - [Al Jazeera: Qatar says Iran attack caused significant damage at the Ras Laffan gas facility](https://www.aljazeera.com/news/2026/3/18/qatar-says-iran-missile-attack-sparks-fire-causes-damage-at-gas-facility)

6. When Ransomware Stops the Production Line

Coca-Cola told the SEC on July 16 that it had shut down all US production at Fairlife, its roughly $4 billion dairy brand, after a ransomware attack. Canadian production kept running. The company gave no timeline for restarting and did not name the attackers. The word in the filing that should hold a board's attention is "suspended." A ransomware attack, the kind of event most executives still file under "IT problem," stopped a physical production line at one of the largest beverage companies in the world.

Coca-Cola told the SEC on July 16 that it had shut down all US production at Fairlife, its roughly $4 billion dairy brand, after a ransomware attack. Canadian production kept running. The company gave no timeline for restarting and did not name the attackers. The word in the filing that should hold a board's attention is "suspended." A ransomware attack, the kind of event most executives still file under "IT problem," stopped a physical production line at one of the largest beverage companies in the world.

The gap between how ransomware is imagined and what it actually does is the story. It usually lands first in ordinary business systems: email, the ordering platform, the software that schedules and tracks production. Those systems were supposed to be walled off from the factory floor, the office IT on one side and the operational technology that runs the machines, the OT, on the other. Years of wiring everything together for efficiency thinned that wall, and an infection on the office side can now reach the plant. That is how an email-borne attack ends up stopping a production line.

Where the two sides part ways is recovery, and that is the part a board should understand. An IT system you can rebuild: once investigators work out how the attackers got in, you wipe the affected machines and restore from clean backups. It is painful, but it is bounded. OT is a harder problem, and in a dairy the systems govern food safety, not just uptime. The question that decides how long Fairlife stays down is how deep the attack reached. Did it stop at the screens the operators watch, or did it get into the controllers and sensors beneath them? If a pasteurizing tank's probe reads a safe temperature, is the milk actually at that temperature, or is the system showing the operator a number the attacker chose while the real process runs hot or cold? You cannot settle that by restoring a backup. You have to verify the physical process against reality, instrument by instrument, and until that is done you cannot safely ship. That is why an attack that reaches OT can freeze a plant far longer than an encrypted email server ever would. The machines are not broken. You just can no longer trust what they are telling you.

This is not new, and the precedents show how long it lasts. When ransomware hit Arizona Beverages in 2019, staff were taking orders on pen and paper for days, and the company needed weeks to rebuild. When it hit the food distributor UNFI in 2025, Whole Foods shelves went empty and UNFI reported up to $400 million in lost sales before operations recovered. Coca-Cola can absorb weeks of one brand offline. A mid-sized manufacturer or distributor running on thinner margins and less cash often cannot.

The Takeaway
The real test in a ransomware attack is not whether your data is backed up. It is whether you can keep making and shipping product with your business systems down. For most companies that answer has never been tested, only assumed, because the office network and the operations that earn the revenue are treated as two separate risks when they are one. The thing worth knowing before an attacker forces the test: if IT went dark tomorrow, how long until the line stops, and how long to bring it back. **Sources:** - [TechCrunch: Coca-Cola suspended production at its Fairlife dairy after a ransomware attack](https://techcrunch.com/2026/07/16/coca-cola-suspended-production-at-its-fairlife-dairy-after-a-ransomware-attack/) - [Coca-Cola Form 8-K disclosing the Fairlife production suspension (SEC EDGAR)](https://www.sec.gov/Archives/edgar/data/0000021344/000162828026048466/ko-20260716.htm)

7. The EU AI Clock Hits July 27

There is a second deadline this week that has nothing to do with tariffs and is easy to miss. On Monday, July 27, at 6pm Central European time, companies can sign the European Union's new Code of Practice on labeling AI-generated content. Signing is voluntary. It also decides how hard the next part gets.

There is a second deadline this week that has nothing to do with tariffs and is easy to miss. On Monday, July 27, at 6pm Central European time, companies can sign the European Union's new Code of Practice on labeling AI-generated content. Signing is voluntary. It also decides how hard the next part gets.

The binding rule is Article 50 of the EU AI Act, and it takes effect August 2. In plain terms: if you put a chatbot, a virtual assistant, or AI-generated text, images, audio, or video in front of people in the EU, you have to make clear they are dealing with AI or with AI-made content. A chatbot has to tell users it is a bot. Synthetic media has to be marked as synthetic. The duty falls on the company offering the system, and it does not matter where that company is based. A US business with EU customers is covered the moment its content reaches them.

The Code of Practice is the EU's how-to guide for meeting that rule, and this is why signing matters. Companies that sign are treated as compliant by default; if a regulator asks, they point to the Code. Companies that do not sign are still bound by Article 50, they just have to prove on their own that whatever labeling they use is good enough, and the burden of that proof sits with them. Fines run up to 15 million euros or 3% of worldwide revenue, whichever is larger. There is no small-company carve-out from the transparency duty itself.

The reach is the part most companies underestimate. You do not have to think of yourself as an AI company to be caught by this. A customer-service chatbot on your site, or a marketing campaign built with generative AI, is enough, the moment it reaches someone in the EU. The honest out is real: if you are a genuinely domestic US company with no European customers, and nothing you run reaches people in the EU, this is not your problem. The catch is that reaching the EU is easier to trip than it sounds. A public website with a chatbot is open to anyone, so the test is not where you are based, it is whether people in the EU actually use the thing. If some do, you are in scope. If your customers are truly all domestic, you are not.

The Takeaway
If anything you run touches EU users and involves AI, a support chatbot, AI-written marketing, generated images, this is a real decision, not a technicality. Signing the Code by Monday is the low-friction path, because it presumes you compliant. Not signing leaves you to prove compliance yourself if anyone challenges it, and doing nothing chooses that harder path by default. With fines this size, it is a call for legal and product to make together, this week, rather than after a regulator raises it. **Sources:** - [European Commission: signing the Code of Practice on transparency of AI-generated content (FAQ)](https://digital-strategy.ec.europa.eu/en/faqs/signing-code-practice-transparency-ai-generated-content) - [European Commission: Code of Practice on Transparency of AI-Generated Content](https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content)

Get this brief in your inbox every Sunday.

No tracking. No spam. One email per week.

Subscribe