• Skip to main content
  • Skip to secondary menu
  • Skip to footer

OSINT.org

Intelligence Matters

  • Sponsored Post
  • About
    • GDPR
  • Contact

OSINT Digest: PLA Sorties Fall to Three-Year Low as Hormuz Threats Outrun the Incident Record

July 24, 2026 By admin Leave a Comment

Two stories this week reward anyone willing to count rather than react. The first is that Chinese air activity around Taiwan has fallen off a cliff while the analytical consensus continues to describe an accelerating countdown. The second is that the declaratory escalation ladder in the Persian Gulf is now running well ahead of the observable incident log — the threats are compounding faster than the attacks that supposedly trigger them. Both gaps are visible in public data. Neither requires a source with a clearance.

PLA Air Activity Around Taiwan Halved in the First Half of 2026

Taiwan’s Ministry of National Defense publishes a daily tally of detected PLA aircraft, naval vessels and government ships. Summed across the first six months of 2026, the fighter component comes to 1,334 sorties — less than half the figure for the same period last year, and the lowest operational tempo since 2023. The number of days on which no PLA fighters were detected at all reached a record. For the first time since 2022, there were no large-scale exercises around the island in a first half.

For context, the annual total exceeded 5,400 sorties in 2025. That trajectory is what fed the widely repeated argument that the PLA was rehearsing toward a 2027 window. The 2026 data does not support a straight-line extension of it.

The obvious cautions apply. Sortie counts measure detected aircraft, not capability, and a reduced air presence is compatible with several very different explanations: a shift of coercive weight toward coast guard and maritime militia hulls, which are counted separately; the disruptive effect of the senior-officer purges that removed two Central Military Commission members in January; a deliberate lowering of the temperature while Washington is consumed by the Gulf; or simple cost management after a year in which drills reportedly consumed a rising share of the defense budget. Absence of sorties is not absence of pressure.

But the direction of the number is the finding, and it is being underreported because it points the wrong way. A tempo drop of this size is either the most significant de-escalation signal in four years or evidence that the coercion campaign has migrated to instruments the standard tally does not capture. Both readings are more interesting than the assumption that nothing changed.

Hormuz: A Retaliation Doctrine Without Triggering Events

On Wednesday, the US president declared that every Iranian attack on a ship in the Strait of Hormuz would be answered by the destruction of one Iranian bridge or power plant, explicitly including infrastructure adjacent to or inside Tehran. Iranian officials responded that they would strike energy and infrastructure targets across the region in turn.

The interesting part is what the monitoring data showed at the time. UKMTO, the independent body that logs incidents in the region’s shipping lanes, had recorded no attacks in the Hormuz area over the preceding 24 hours. The incident it did report was in the Red Sea, and was claimed by the Houthis. The IRGC separately claimed on Thursday local time that a tanker had caught fire after an explosion in the waterway.

A tripwire doctrine only functions if both parties agree on what counts as tripping it. Here the announced trigger is a specific class of event in a specific body of water, the incident log for that body of water was empty at the moment of announcement, and the attacks actually being reported are either in a different sea, attributed to a different actor, or claimed by the party being threatened. That is not a deterrence architecture. It is a permission structure — the criterion is loose enough that a strike can be justified on any given day, and Tehran can read it as a decision already made.

Meanwhile CENTCOM has continued strikes on Iranian command centers, drone storage and communications nodes, with Iranian state media reporting at least four killed in early Friday attacks. Tehran has accused Washington of using the suspected underground enrichment site at Pickaxe Mountain as a pretext for further operations.

The June Memorandum Is Dead and Both Sides Are Pretending Otherwise

Washington’s position is that Iran killed the memorandum of understanding by attacking three commercial vessels late in the week — the secretary of state said so directly while also insisting diplomacy remains available. Tehran’s position is that the asset unfreezing that was its central concession never materialized. The more accurate description is that neither side is honoring the agreement and neither has formally abandoned it, because the framework is more useful as a grievance than as a mechanism.

The asset question is a genuine open-source problem worth its own treatment. Iranian outlets and analysts put the frozen total somewhere between roughly $124 billion and $167 billion, a spread wide enough to indicate that nobody outside a handful of central banks and correspondent institutions actually knows. A range that loose is not a data point. It is a negotiating instrument for both parties.

Bab al-Mandeb Becomes the Second Chokepoint

Oil crossed $100 for the first time since May as the Houthis announced a naval blockade against Saudi shipping and claimed strikes on two Saudi tankers in the Red Sea. The strategic significance is straightforward: Bab al-Mandeb is the principal bypass for cargo displaced by the Hormuz disruption. Squeezing both simultaneously removes the alternative routing that has absorbed most of the shock since February.

Washington has responded by declaring Iran accountable for Houthi actions — a doctrine of transferred responsibility that widens the target set considerably while leaving the attribution burden unaddressed. Watchable indicators: war-risk premiums for Red Sea transits, Suez transit counts, and the volume of traffic accepting the Cape routing and its added voyage time.

JadeProx: An Operation That Documented Itself

The best cyber story of the week is a tradecraft failure. Researchers located an exposed server in a Singapore cloud region in mid-April; by the time the findings were published on 23 July the host was offline. What it contained was effectively an operational diary — bash history, phishing packages, post-exploitation tooling and webshell paths.

The reconstructed target set spans government, healthcare and education across Asia and Latin America: a Vietnamese public hospital’s medical imaging system, reached through webshells planted on an exposed Java management interface; Malaysia’s foreign ministry; scanning and follow-on exploitation against Hong Kong education infrastructure; and a spear-phishing package prepared for Honduras’ national legislature. The intrusion tool was a previously undocumented Windows loader.

The methodological lesson generalizes beyond this cluster. Attribution and scoping increasingly come not from malware analysis but from operator hygiene — unsecured staging infrastructure, retained shell history, reused paths. The adversary’s own logging is the collection source.

Arctic LNG 2 Restarts, and Imagery Beats AIS

Two Chinese heavy-lift vessels, both under US sanctions since 2024, delivered the first construction modules for Arctic LNG 2’s stalled third production train to the Belokamenka assembly yard near Murmansk. Satellite imagery dated 19 July established the delivery. The three-month voyage ran under false flags and declared destinations that did not match the actual routing.

This is the clearest available evidence that the operator intends to restart Train 3 despite more than two years of sanctions pressure, and it is a clean demonstration of where enforcement fails. The deception layer is competent enough to defeat transponder-based monitoring and irrelevant against a photograph.

The broader pattern is well documented. Behavioral screening now flags vessels on transponder manipulation, ship-to-ship transfers in international waters, falsified port clearances, flag-of-convenience registries with minimal enforcement capacity, and insurance placed outside Western clubs. The scale of the fabrication is the striking part: analysis of sanctioned tankers found fake port calls at a single Iraqi terminal on a scale suggesting that close to half of all transponder-generated voyages to that port over a six-month period were simulated. Fleet estimates now run from roughly 1,300 vessels in the Ukrainian intelligence catalog to 1,900 on broader behavioral definitions.

A Federal Breach With a World Cup Attached

A compromise of a Department of Homeland Security information-sharing platform has drawn a call for a Justice Department investigation from the vice chair of the Senate intelligence committee, on the argument that even unclassified material hosted there carries national security weight. The specific concern is that the platform is currently supporting security operations for World Cup matches hosted across the United States. It follows the late-2025 compromise of the Congressional Budget Office, attributed to a suspected state actor.

What to Watch

The PLA tempo figure is the item most likely to be revised in interpretation over the next quarter — watch whether coast guard and maritime militia hull counts absorb the difference, which would convert a de-escalation story into a substitution story. In the Gulf, the operative question is whether the bridge-and-power-plant formula is applied to a Red Sea incident. If it is, the announced trigger was never the real one.

Filed Under: News

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Footer

Recent Posts

  • OSINT Digest: PLA Sorties Fall to Three-Year Low as Hormuz Threats Outrun the Incident Record
  • US-Iran War Situation Report: Hormuz Traffic Collapses as Oil Breaks $95 and Strikes Reach Night Twelve
  • Israel Says Iran Moved Thousands of Centrifuges to Pickaxe Mountain After 12-Day War
  • Palantir Is Winning a Share Fight Over Big Four Consulting, Not Ending It
  • The Case for Trump’s UN Free Speech Push Against Europe’s Digital Services Act
  • The AI War Has Two Fronts: Xi’s Open-Source Coalition vs. Trump’s Chokepoint Strategy
  • Chips, Memory, and Optical Stocks Down 20% From June Highs: Which Names to Buy in the Selloff
  • Nvidia Introduces Cosmos 3 Edge to Advance Physical AI
  • Mahan Air Flight to Sanaa Points to Iran-Houthi Planning for a Bab el-Mandeb Blockade Scenario
  • Penguin Solutions Q3 FY26: The Margin Number Nobody’s Headline Mentioned

Media Partners

  • Analysis.org
  • Opinion.org
  • Policymaker.net
Super Micro Computer Q4 FY26: Gross Margin Guide Nearly Doubles to 15%-17%
Semiconductor Stocks Rebound After Confirming Bear Market Correction
Tempus AI to Acquire Personalis for $16.25 Per Share in $1.5 Billion MRD Deal
Unity (NYSE: U) Bets on Coding Agents With Unity 7: Does the Roadmap Move the Stock?
South Korean Retail Investors Face 70% Losses as Leveraged Chip ETFs Crash
Hidden Debt at Five AI Hyperscalers Hits $1.65 Trillion, Nikkei Study Finds
TSMC Q2 2026: A 15% Capex Hike Outweighs a Record Profit Beat
Micron’s $500 Million GlobalWafers Financing Points to a New Bottleneck
META Compute, Samsung, SK Hynix: Where AI Infrastructure Investors Think the Margin Actually Sits
AMD Acquired MEXT to Make Flash Behave Like DRAM. It Eases the Memory Crunch Without Threatening Micron or SanDisk.
Trump’s Saudi Nuclear Deal Trades Nonproliferation for a Photo Op
France’s Social Media Ban Shows Why Europe Keeps Losing the Tech Race
Trump’s Greenland Obsession Makes No Sense. Why Not Qatar Instead?
Why Washington Criticizes Its Allies But Never Touches Qatar
Netanyahu’s October Election Odds Slide After Trump and Vance Rebukes
JD Vance Courts the Anti-Israel Right in Early 2028 Positioning
JD Vance Blames Israel for Prolonging Iran War as Ceasefire Unravels
Trump’s $1.4 Billion Crypto Year: A Disclosure That Doubles as a Conflict-of-Interest Ledger
JD Vance and the Grifter Generation: No Allies, No Principles, Only Power
Trump’s Iran Deal: The U-Turn From Unconditional Surrender to All Carrots, No Stick
Trump's 20% Hormuz Toll Is Fifteen Times the Iranian Fee He Went to War to Stop
Trump's Real Target With Erdogan Is the Hormuz Bypass, Not the F-35
Mamdani's Slate Is Capturing Congress Through Primaries Almost No One Votes In
Starmer Falls, Burnham Rises, and Britain Changes Prime Minister Without an Election
Hormuz Reopens and Equities Rotate: Energy Sells Off, Tech Leads, North Asia Soars
The Islamabad Agreement: Trump Cancels His Own Strikes, Pays Iran for the Privilege, and Calls It a Deal
Film Star Vijay Forms Government in Tamil Nadu: The Celebrity-to-Power Trajectory Completes
The Gulf Realignment Washington Missed
Seven Million and Counting: Britain's Managed Demographic Replacement
UK Taxpayers Are Funding £4 Billion a Year in Student Loans for Foreign Nationals

Media Partners

  • Market Analysis
  • Market Research Media
  • Cybersecurity Market
Google Frozen v2 AI Chip Could Deliver 10x Efficiency Gains Over Current TPUs
The Case for Shorting Budget Airlines as Oil Prices Rise
Morgan Stanley’s $2.3 Billion Capital Markets Haul Signals the AI Boom Is Just Getting Started
Blackstone’s Futronic Deal Bets on Actuators as AI Robotics’ Physical Bottleneck
Zhongji Innolight’s $8 Billion IPO Is a Customer Event for Marvell, Not a Competitive One
Wall Street Splits Between Oversupply Fears and an AI-Proof Supercycle Thesis
The AI Iron Curtain: Xi’s Shanghai Keynote Is the Fulton Speech of the AI Cold War
Enterprise Money Is Leaving Old School IBM for AI Infrastructure Companies
Why EU Tech Is Falling Behind the US: A Structural Diagnosis, Not a Cultural One
The HyperLight Threat to Coherent and Lumentum Ends Where Indium Phosphide Begins
Getty Images Kills the $3.7 Billion Shutterstock Merger Rather Than Sell the Editorial Business the UK Demanded
Fox’s $22B Roku Deal: 4.6x Sales, Paid in 1.5x Stock
Tuesday Open: AI Earnings Engine Holds the Line as Iran Overhang Fades to Noise
China’s U.S. Treasury Holdings: The Great Repositioning (2021–2025)
Infographic: Why the 2025 CIPA Data Proves the APS-C Renaissance is Real
How WiFi Changed Media
Canva Acquires Simtheory and Ortto to Build End-to-End Work Platform
Netflix Price Hikes, The Economics of Dominance in a Saturated Streaming Market
America’s Brands Keep Winning Even as America Itself Slips
Kioxia’s Storage Gambit: Flash Steps Into the AI Memory Hierarchy
Glow Emerges From Stealth With $180 Million Series A At $1.2 Billion Valuation
Cisco Releases Antares-350M and Antares-1B Open-Weight AI Models for Vulnerability Detection
OpenAI Models Breached Hugging Face Infrastructure While Cheating on Cybersecurity Benchmark
Empirical Security Raises $25 Million Series A to Expand AI-Driven Threat Prediction
Synthetic Insiders: How AI-Generated Fake Employees Are Bypassing Corporate Cyber Defenses
China’s Kimi K3 Model Is Strong but Not Yet a Frontier AI Security Risk
Risk Ledger Raises £24 Million Series B for Supply Chain Cyber Risk Platform
Cribl Acquires Israeli Threat Detection Startup CardinalOps for $100 Million
Cybersecurity Stocks Rally as IBM CEO Flags Cyber Fears as a Top Customer Priority
Trump Administration Launches “Gold Eagle” Federal Clearinghouse for AI Cyber Threat Sharing

Copyright © 2026 OSINT.org

Media Partners: k4i · OPINT · Referently · Hormuz · Taiwan Strait