| Sturnella Signals |
Vol. 1 · Issue 018 Wednesday, August 19, 2026 |
Buybacks · Research Security · ICS
Critical minerals · Energy infrastructure · Defense supply chains · Cyber
|
| |
|
This week in Sturnella Signals
A surprise at the long end of the curve, and a widening perimeter around the industrial base.
Treasury moved before the market forced it to, doubling the size of its long-end buyback operations after 30-year yields touched a 19-year high.
|
Gold ~$4,480 3-month high |
Silver ~$63 2nd day lower |
WTI ~$85 Brent ~$92 |
30Y UST 5.19% -9 bps |
Fed 3.50-3.75% minutes 2pm ET |
Metals and crude intraday Wednesday, August 19 · 30-year yield after the Treasury buyback announcement, against a Tuesday high above 5.33%, the highest since June 2007 · July FOMC minutes released 2:00 p.m. ET
|
|
What we are watching for next
• Research security: Whether the 30 notified universities meet the August 31 reporting deadline, and whether findings begin to touch federally funded materials and mining research programs.
• CMMC: Whether the Reform Task Force report, due to the DoW CIO in mid-September, preserves third-party Level 2 assessment or replaces it with another verification model.
• Labrador Trough: Whether the Major Projects Office referral converts into permitted corridor work, and whether First and Last Mile Fund support reaches the named iron ore and graphite projects.
|
|
|
Macro Signal
Treasury Stepped In at the Long End
|
Read The Second Line
A buyback is not new money
When Treasury buys back its own bonds, the overall money supply does not permanently change. Treasury is shifting existing cash out of its own account and back to investors and banks, neutralizing effects such as large tax payments rather than creating anything new.
Sources · Treasury announcement, August 19 · CNBC on the yield reaction
|
|
|
Policy & Procurement Signal
The Perimeter Moves to the Laboratory
On August 17 the Department of War issued formal notifications to 30 domestic academic institutions directing them to begin immediate and comprehensive reviews of their academic, financial and research collaborations with foreign entities of concern. The notifications address active ties to entities identified under Section 1286 of the FY19 NDAA, along with organizations associated with rebranded Confucius Institutes. The action was executed by the Office of the Under Secretary of War for Research and Engineering.
|
What the Universities Must Do
• Complete a comprehensive audit of all identified foreign collaborations. • Assess the exposure of sensitive or export-controlled research. • Implement strict mitigation plans, including termination of problematic partnerships. • Report findings and actions directly to the Department no later than August 31, 2026. • The stated consequence for non-compliance is eligibility for future federal research funding.
Source · Department of War, August 17, 2026
|
|
The Signal Is Getting Harder to Ignore
Taken together, these actions point to something larger than a collection of separate defense initiatives. The United States is systematically strengthening the foundations of its industrial base: directing capital toward strategic technologies, opening new pathways for non-traditional suppliers, forcing greater visibility into critical supply chains, building the workforce needed to support them, and now tightening protection around the research and intellectual property that feed the next generation of capability. The message is increasingly consistent. Resilience is no longer just about securing access to minerals or manufacturing capacity. It is about keeping capital, talent, technology, intellectual property and production capability inside a trusted U.S. ecosystem, and reducing the points at which an adversary can interrupt, influence or extract value from that system.
|
| Sturnella lens: Research security is supply chain security with a different vocabulary. The question a board should ask this quarter is not whether the company has foreign partnerships, but whether anyone can produce the list on two weeks' notice. That is the same inventory problem as the connected-device question, applied to people, papers and process know-how. |
|
|
Capital & Project Flow
Two Governments Funding the Middle of the Supply Chain
|
Canada — Churchill Falls, Gull Island & the Labrador Trough C$70B Package
C$10B federal financing · 14,000 MW · 23,000 jobs · C$31B GDP to the early 2040s
Prime Minister Carney announced what the government describes as the largest clean energy investment in North American history. C$10 billion of federal financing goes toward expanding Churchill Falls, developing Gull Island and building transmission, inside a package approaching C$70 billion. The part that matters for this readership sits downstream of the megawatts: the Labrador Trough corridor has been referred to the Major Projects Office, with First and Last Mile Fund support attached to Kami iron ore, Focus Graphite's Lac Knife and SFP Pointe-Noire. Power, transmission and corridor access are being financed as one object rather than three, which is precisely the constraint that has stranded iron ore and graphite development in that region before.
|
|
DOE — $162M for Recovery from Industrial Feedstocks Nine Projects
Office of Critical Minerals and Energy Innovation · Bench- and pilot-scale · Scandium, copper, antimony, rare earths
Nine selected projects will recover critical minerals, materials and other valuable byproducts from industrial feedstocks. The selections stem from DOE's August 2025 announcement of nearly $1 billion to advance and scale mining, processing and manufacturing technologies across the critical minerals supply chain. Assistant Secretary of Energy Audrey Robertson framed the rationale around leveraging existing bench- and pilot-scale facilities to de-risk commercial-scale production technology. Note the category: this is not new ore. It is recovery from streams that already exist, which shortens the permitting path considerably relative to a greenfield mine.
|
|
USDA — $7.5M Cold Chain Grants Watching Ag
Announced August 17 · Applications due 11:59 p.m. ET October 1, 2026 · grants.gov
The Cold Chain Grants for Emergency Food Assistance Program will fund cold chain equipment investments allowing food assistance entities to store, package and distribute fresh, frozen and minimally processed foods. Funded non-profits administer a competitive subaward program, with subawards capped at $200,000 covering equipment plus documented delivery, installation and ancillary supplies, against a 10% cash cost share. Secretary Brooke Rollins and HHS Secretary Robert F. Kennedy Jr. framed it around the Real Food and dietary guidelines agenda. The program is funded through the American Rescue Plan Act of 2021. We keep an eye on agriculture here for one reason: cold chain is refrigeration, refrigeration is load, and load is grid.
|
| Sturnella lens: All three items fund the middle of a supply chain rather than either end. Transmission and corridor access rather than the orebody. Recovery and refining rather than the mine. Cold storage rather than the farm or the family. That is where fragility actually lives, and it is the least photogenic part of any announcement. |
|
|
Cyber & OT Signal
A CVSS 10 in the Water Stack, and a Ransomware Crew Deleting the Backups
CISA published 14 ICS advisories on August 13. The one to act on is ICSA-26-225-02, covering the Haiwell IoT Cloud HMI Gateway, with named sector exposure across energy, critical manufacturing, and water and wastewater.
|
Named Product, Named Defect
• CVE-2026-19188 — OS command injection, CVSS 10.0, affecting Haiwell IoT Cloud HMI Gateway 3.40.1.12. • The defect sits in the Net Check feature reachable via the /setting endpoint, where the cmdPing event fails to sanitize user-supplied input before passing it to the operating system. • Successful exploitation permits arbitrary OS command execution with root privileges. • Haiwell has published a fix in Scada-v3.50.1.19. • Also in the August 13 batch: Hitachi Energy APM Edge (CVSS 8.8, energy), ANDRITZ HIPASE-250 (CVSS 8.1, hard-coded credentials) and AVEVA Enterprise SCADA (CVSS 7.1).
Source · CISA ICSA-26-225-02
|
No active exploitation of this particular gateway has been reported. That is not the point. A remotely reachable HMI gateway that grants root on a malformed input is exactly the class of exposure the water-sector campaign has spent a month demonstrating is reachable, and unlike that campaign, this one has a patch available today. EPA separately issued a checklist on August 13 intended to help states strengthen drinking water systems.
Gunra: a Conti derivative that goes after recovery
A joint advisory issued August 10 and designated AA26-222A, authored by the FBI, CISA, the Department of Defense Cyber Crime Center, NSA, the U.S. Secret Service and the Republic of Korea's National Police Agency, describes Gunra, a ransomware-as-a-service variant derived from leaked Conti source code. Named target sectors are healthcare and public health, financial services, government services and facilities, and professional and nonprofit services. Initial access comes through CVE-2024-55591 and CVE-2025-24472, authentication bypass flaws in Fortinet FortiOS and FortiProxy reachable on internet-facing appliances. Affiliates run double extortion through a Tor negotiation portal and threaten publication within five to seven days.
Two details deserve attention from anyone running an industrial site. First, Gunra actors have been observed deleting backup and archived data at both the primary data center and the disaster recovery center, before and after deployment. A recovery plan that assumes the DR site survives is not a recovery plan against this actor. Second, the advisory notes a cryptographic weakness in the Linux variant, a time-seeded random number generator, that can allow recovery of encrypted Linux files without payment. Mining and energy are not on the named target list, but the access path is a VPN appliance and the objective is to remove your ability to restore. Neither of those is sector-specific.
| Sturnella lens: Both items reduce to the same two questions from this month's field note. Do you know which of these devices you own and whether they are reachable, and can you restore if the primary and the DR copy are both gone? The first question is an inventory. The second is an exercise. Neither requires new technology, and most sites have done neither this year. |
|
|
Earnings & Operations
A Quiet Earnings Week Is Not the Same as a Quiet Week
No material earnings surprises surfaced in critical minerals, defense or energy infrastructure between August 12 and 19. Second-quarter reporting for the sector largely cleared the week before. What moved forward guidance instead was policy, and three items are worth carrying because they change revenue eligibility and cost structure rather than a single quarter's print.
• Sourcing restrictions. Executive Order 14415 restricts defense contractors from sourcing critical materials from non-allied nations beginning January 1, 2027, with documentation of sourcing attempts and mitigation plans required. This is a forced supply-chain reshuffle with margin and contract-eligibility consequences, and the compliance work has to start well before the effective date.
• Grid build-out. The first 278 projects have been selected under the AI-focused Genesis Mission, which touches transmission planning and grid infrastructure exposure.
• Cost allocation. FERC and Congress have increased scrutiny of who pays for data-center-driven grid expansion, which bears directly on regulated utility earnings trajectories.
|
| Sturnella lens: In a policy-driven cycle, the disclosure risk shifts. A sourcing restriction with a 2027 effective date is a known, dated, material constraint on future revenue. That is the kind of thing that shows up in a risk factor eighteen months late and looks, in hindsight, like something management should have flagged earlier. |
|
|
Workforce Signal
Nothing in the Three Sectors, Plenty One Layer Out
| Sturnella lens: No major workforce move landed directly in mining, energy infrastructure or defense this week. The pressure remains one layer out: manufacturing led U.S. WARN activity, followed by transportation, agriculture and wholesale trade. We are watching that closely because weakness in the industries that manufacture, move and consume industrial materials often reaches the underlying supply chain before it appears in sector-specific employment data. |
|
|
Where We'll Be
Events & Speaking Engagements
Aug 20 | ISACA Houston — "When the Choke Point Becomes the Attack Surface" Tomorrow Houston, TX · Speaking What happens when the narrow points a system depends on become the places an adversary aims. |
Sep 18 | BSidesCache — "From SaaS to SCADA: Understanding OT Threats in the Wasatch Front's Next Cybersecurity Cycle" Logan, UT · Bridgerland Technical College, Health Sciences Building · 1301 North 600 West The Wasatch Front is marketed as a software and SaaS corridor, but the stronger cybersecurity signal may be coming from somewhere less visible: defense, industrial infrastructure, energy, mining, utilities and OT environments. Built for cybersecurity professionals, students, career changers and defenders. |
Sep 22 | Defense TechConnect Innovation Summit & Expo — Poster Presentation Sep 22-24 · Gaylord National Resort, National Harbor, MD · Poster session Tuesday 4:00-6:00 PM "From Compliance Gap to Contract Risk: CMMC Readiness for Defense Tech and Dual-Use Companies." |
Oct 16 | Cyber Cheyenne — "SEC Means Business: A GRC Guide to Cybersecurity and Disclosure Rules" Cheyenne, WY · 11:00 AM Where materiality, timing and the four-business-day clock actually bite for operating companies. |
Oct 28 | Women In Mining Nevada — Lunch & Learn Nevada · 12:30 PM "From Mine Site to Board Packet." Translating operational, cyber, contractor and resilience risk into information a board can govern and act on. |
Nov 5 | University of Utah — "Mining Meets Risk: Cybersecurity and Operational Resilience on the Modern Mine Site" Salt Lake City, UT · Time TBC Fitting, given this week's research security notifications: the conversation about protecting university research and the conversation about securing the mine site are converging. |
|
|
Field Note
Five Things Mining Companies Can Do Now to Build Operational Resilience
The mine plan tells you how the mine is supposed to operate. Operational resilience asks a different question: what could stop it, and how do we keep running when something does? Five practical places to start identifying operational dependencies and single points of failure. Read the full article →
Mine-Site Access & Operational Fieldwork
Mine-site visits, operational risk discussions and field-based advisory work are currently being scheduled, with additional dates and locations announced as they are confirmed. The standing ask: if your operation has built a connected-device inventory that spans EHS-owned equipment as well as process control, I would like to hear how you scoped it and who owns it.
|
|
Sturnella
At the intersection of cyber, capital, and national security.
This newsletter is for informational purposes only and does not constitute investment, legal, accounting, or cybersecurity advice. Market information is time-sensitive and may change after publication. Verify transaction, earnings, event, and regulatory details before acting. This edition was fact-checked against primary government, company, and market sources available as of August 19, 2026; interpretive passages are identified as the Sturnella lens.
|