Two stories this week reward anyone willing to count rather than react. The first is that Chinese air activity around Taiwan has fallen off a cliff while the analytical consensus continues to describe an accelerating countdown. The second is that the declaratory escalation ladder in the Persian Gulf is now running well ahead of the observable incident log — the threats are compounding faster than the attacks that supposedly trigger them. Both gaps are visible in public data. Neither requires a source with a clearance.
PLA Air Activity Around Taiwan Halved in the First Half of 2026
Taiwan’s Ministry of National Defense publishes a daily tally of detected PLA aircraft, naval vessels and government ships. Summed across the first six months of 2026, the fighter component comes to 1,334 sorties — less than half the figure for the same period last year, and the lowest operational tempo since 2023. The number of days on which no PLA fighters were detected at all reached a record. For the first time since 2022, there were no large-scale exercises around the island in a first half.
For context, the annual total exceeded 5,400 sorties in 2025. That trajectory is what fed the widely repeated argument that the PLA was rehearsing toward a 2027 window. The 2026 data does not support a straight-line extension of it.
The obvious cautions apply. Sortie counts measure detected aircraft, not capability, and a reduced air presence is compatible with several very different explanations: a shift of coercive weight toward coast guard and maritime militia hulls, which are counted separately; the disruptive effect of the senior-officer purges that removed two Central Military Commission members in January; a deliberate lowering of the temperature while Washington is consumed by the Gulf; or simple cost management after a year in which drills reportedly consumed a rising share of the defense budget. Absence of sorties is not absence of pressure.
But the direction of the number is the finding, and it is being underreported because it points the wrong way. A tempo drop of this size is either the most significant de-escalation signal in four years or evidence that the coercion campaign has migrated to instruments the standard tally does not capture. Both readings are more interesting than the assumption that nothing changed.
Hormuz: A Retaliation Doctrine Without Triggering Events
On Wednesday, the US president declared that every Iranian attack on a ship in the Strait of Hormuz would be answered by the destruction of one Iranian bridge or power plant, explicitly including infrastructure adjacent to or inside Tehran. Iranian officials responded that they would strike energy and infrastructure targets across the region in turn.
The interesting part is what the monitoring data showed at the time. UKMTO, the independent body that logs incidents in the region’s shipping lanes, had recorded no attacks in the Hormuz area over the preceding 24 hours. The incident it did report was in the Red Sea, and was claimed by the Houthis. The IRGC separately claimed on Thursday local time that a tanker had caught fire after an explosion in the waterway.
A tripwire doctrine only functions if both parties agree on what counts as tripping it. Here the announced trigger is a specific class of event in a specific body of water, the incident log for that body of water was empty at the moment of announcement, and the attacks actually being reported are either in a different sea, attributed to a different actor, or claimed by the party being threatened. That is not a deterrence architecture. It is a permission structure — the criterion is loose enough that a strike can be justified on any given day, and Tehran can read it as a decision already made.
Meanwhile CENTCOM has continued strikes on Iranian command centers, drone storage and communications nodes, with Iranian state media reporting at least four killed in early Friday attacks. Tehran has accused Washington of using the suspected underground enrichment site at Pickaxe Mountain as a pretext for further operations.
The June Memorandum Is Dead and Both Sides Are Pretending Otherwise
Washington’s position is that Iran killed the memorandum of understanding by attacking three commercial vessels late in the week — the secretary of state said so directly while also insisting diplomacy remains available. Tehran’s position is that the asset unfreezing that was its central concession never materialized. The more accurate description is that neither side is honoring the agreement and neither has formally abandoned it, because the framework is more useful as a grievance than as a mechanism.
The asset question is a genuine open-source problem worth its own treatment. Iranian outlets and analysts put the frozen total somewhere between roughly $124 billion and $167 billion, a spread wide enough to indicate that nobody outside a handful of central banks and correspondent institutions actually knows. A range that loose is not a data point. It is a negotiating instrument for both parties.
Bab al-Mandeb Becomes the Second Chokepoint
Oil crossed $100 for the first time since May as the Houthis announced a naval blockade against Saudi shipping and claimed strikes on two Saudi tankers in the Red Sea. The strategic significance is straightforward: Bab al-Mandeb is the principal bypass for cargo displaced by the Hormuz disruption. Squeezing both simultaneously removes the alternative routing that has absorbed most of the shock since February.
Washington has responded by declaring Iran accountable for Houthi actions — a doctrine of transferred responsibility that widens the target set considerably while leaving the attribution burden unaddressed. Watchable indicators: war-risk premiums for Red Sea transits, Suez transit counts, and the volume of traffic accepting the Cape routing and its added voyage time.
JadeProx: An Operation That Documented Itself
The best cyber story of the week is a tradecraft failure. Researchers located an exposed server in a Singapore cloud region in mid-April; by the time the findings were published on 23 July the host was offline. What it contained was effectively an operational diary — bash history, phishing packages, post-exploitation tooling and webshell paths.
The reconstructed target set spans government, healthcare and education across Asia and Latin America: a Vietnamese public hospital’s medical imaging system, reached through webshells planted on an exposed Java management interface; Malaysia’s foreign ministry; scanning and follow-on exploitation against Hong Kong education infrastructure; and a spear-phishing package prepared for Honduras’ national legislature. The intrusion tool was a previously undocumented Windows loader.
The methodological lesson generalizes beyond this cluster. Attribution and scoping increasingly come not from malware analysis but from operator hygiene — unsecured staging infrastructure, retained shell history, reused paths. The adversary’s own logging is the collection source.
Arctic LNG 2 Restarts, and Imagery Beats AIS
Two Chinese heavy-lift vessels, both under US sanctions since 2024, delivered the first construction modules for Arctic LNG 2’s stalled third production train to the Belokamenka assembly yard near Murmansk. Satellite imagery dated 19 July established the delivery. The three-month voyage ran under false flags and declared destinations that did not match the actual routing.
This is the clearest available evidence that the operator intends to restart Train 3 despite more than two years of sanctions pressure, and it is a clean demonstration of where enforcement fails. The deception layer is competent enough to defeat transponder-based monitoring and irrelevant against a photograph.
The broader pattern is well documented. Behavioral screening now flags vessels on transponder manipulation, ship-to-ship transfers in international waters, falsified port clearances, flag-of-convenience registries with minimal enforcement capacity, and insurance placed outside Western clubs. The scale of the fabrication is the striking part: analysis of sanctioned tankers found fake port calls at a single Iraqi terminal on a scale suggesting that close to half of all transponder-generated voyages to that port over a six-month period were simulated. Fleet estimates now run from roughly 1,300 vessels in the Ukrainian intelligence catalog to 1,900 on broader behavioral definitions.
A Federal Breach With a World Cup Attached
A compromise of a Department of Homeland Security information-sharing platform has drawn a call for a Justice Department investigation from the vice chair of the Senate intelligence committee, on the argument that even unclassified material hosted there carries national security weight. The specific concern is that the platform is currently supporting security operations for World Cup matches hosted across the United States. It follows the late-2025 compromise of the Congressional Budget Office, attributed to a suspected state actor.
What to Watch
The PLA tempo figure is the item most likely to be revised in interpretation over the next quarter — watch whether coast guard and maritime militia hull counts absorb the difference, which would convert a de-escalation story into a substitution story. In the Gulf, the operative question is whether the bridge-and-power-plant formula is applied to a Red Sea incident. If it is, the announced trigger was never the real one.
Leave a Reply