• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • SPECTRA banner
  • Curtiss-Wright banner

BATTLESPACE Updates

   +44 (0)77689 54766
   

  • Home
  • Features
  • News Updates
  • Defence Engage
  • Company Directory
  • About
  • Contact

C2, Tactical Comms, AI, Cyber, EW, Cloud Computing & Homeland Security

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

January 24, 2025 by

 

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

—————————————————————————————————————————————————————————————————————————————————————————————————————————————-

21 Jan 25. New phishing operation points to elevated data-theft, security risks for Microsoft 365 users. On 20 January, international news outlets reported that a new Phishing-as-a-Service (PhaaS) kit, ‘Sneaky 2FA’, is targeting Microsoft 365 accounts in an information-theft campaign. The campaign reportedly starts with phishing emails containing a malicious QR code that redirects victims to threat actor-designed phishing websites. The websites emulate legitimate Microsoft login pages and enable threat actors to steal user credentials and authentication codes so as to conduct follow-on unauthorised activities. Notably, the QR codes require victims to use their phones to initiate the campaign, possibly reducing the number of people impacted. The kit can be purchased for approximately USD 200 on the messaging platform Telegram, allowing low-skilled actors to purchase Sneaky 2FA. The PhaaS kit can also check whether threat actors are subscribed in real-time and is managed centrally on Telegram, underscoring the scale of the operation. We assess this points to the elevated security and information-theft risks facing global Microsoft 365 users in the short-to-medium term. (Source: Sibylline)

 

23 Jan 25. Global: Supply chain attack raises espionage, third-party risks posed by China-nexus groups. On 22 January, the cyber security company ESET reported that a new China-nexus advanced persistent threat (APT) group (‘PlushDaemon’) targeted a South Korean virtual private network (VPN) service in a supply chain attack between 2023 and mid-2024. PlushDaemon compromised legitimate VPN installer files (available on the provider’s website) to infiltrate victims’ systems. The compromised files executed a custom backdoor (‘SlowStepper’) onto targeted systems to conduct network reconnaissance, exfiltrate sensitive data, and record audio and video. SlowStepper was downloaded by a variety of VPN customers, showcasing the broad scope of this campaign. We assess that the attack highlights the widespread and prolonged impact of supply chain compromises since it reportedly affected users in multiple countries (including China, New Zealand and the US). This will raise long-term supply chain and cyber espionage risks to global organisations as PlushDaemon continues to develop sophisticated techniques and improve its detection evasion capabilities. (Source: Sibylline)

 

23 Jan 24. HENSOLDT has successfully completed the modernisation project “Einsatzunterstützungsanlage Neue Technologien“ (EUA NT) after testing the system at four Bundeswehr helicopter bases. The aim of the project, which was commissioned by the Federal Office of Bundeswehr Equipment, Information Technology and In-Service Support (BAAINBw) in May 2022, is to upgrade the EUA, which has been in use for more than a decade, for the next 15 years of operation.  The modernised EUA NT is a deployable complete system for supporting the Bundeswehr’s rotorcraft, consisting of two types of container:  The system container contains a fail-safe IT base system with network technology for connection to IT systems of the Bundeswehr at the operational level up to the classification level of VS-GEHEIM (classified up to secret), modernised application software and the communication systems required for data and radio communication with the aircraft. The system container can be deployed as the smallest fully functional, relocatable command cell with two IT workstations to support NH90 and Tiger helicopters, for example, before, during and after the mission.

The personnel container supplements the system container with a control centre and additional ergonomic workstations for six additional operators. Up to three personnel containers can be combined with a system container. Furthermore, several EUA-NT systems can be linked to form a data network.

The radiation-shielded units are identically equipped in terms of air conditioning and power supply. They have a power generator that starts automatically when used on vehicles or when the power supply is unstable, and an uninterruptible power supply that ensures IT operation at all times.  In the next step, HENSOLDT will implement the series production, the retrofitting of the systems in use and measures for replication. With the EUA NT, the Bundeswehr is receiving a modern, commercially available system whose modular and open architecture not only represents the ground station platform for the Bundeswehr’s current rotorcraft but is also equipped for future requirements and weapon systems.

“With the New Technologies Mission Support System, we are creating a future-proof solution based on an established system that will sustainably strengthen the operational capability of the Bundeswehr. Close cooperation with the customer and end users, as well as the consideration of operational experience from Afghanistan and Mali, have made it possible to develop a new system that is modular and highly flexible and thus ready for the challenges of the coming years. In addition, provisions have been made to further improve usability for future weapon systems,” says Alex Irmscher, programme manager for ground stations at HENSOLDT.

 

23 Jan 25. Silvus StreamCaster First MANET Radio to Receive FIPS 140-3 Level 2 Validation. Silvus Technologies, a global supplier of advanced wireless networking solutions, has announced that its StreamCaster MANET radios are the first and only tactical radios with cryptographic modules to receive FIPS 140-3 Level 2 validation. By achieving FIPS 140-3 Level 2 validation, Silvus reinforces its position as a trusted provider of secure, resilient communication solutions that defense, law enforcement agencies, and critical infrastructure operators rely on for mission-critical communications in any operational environment. StreamCaster MANET radios provide high-fidelity video, voice, and IP data communications – delivering actionable intelligence at the speed of relevance. At the heart of every StreamCaster MANET radio is Silvus’ battle-proven MN-MIMO waveform, capable of linking hundreds of nodes with unmatched range, data throughput, EW resiliency, and scalability. Applicable radio models now available with FIPS 140-3 Level 2 encryption include SC4200, SC4400, SL4200, and SM4200.

“We are proud to achieve FIPS 140-3 Level 2 validation, a milestone that highlights our dedication to providing the most advanced tactical communication solutions,” said Weijun Zhu, Vice President of Engineering at Silvus Technologies. “Certification of StreamCaster MANET radios ensures that our customers can operate with confidence, knowing their sensitive communications are safeguarded from compromise in even the most contested environments.”

Federal Information Processing Standards (FIPS) 140-3 Level 2 validation, established by the National Institute of Standards and Technology (NIST), ensures that StreamCaster MANET radios meet the U.S. Government’s highest security requirements for cryptographic modules to protect sensitive data.

This standard provides operators with the confidence that their communications remain secure in high-risk, mission-critical operations. Silvus’ achievement of FIPS 140-3 Level 2 validation brings significant advancements over the previous FIPS 140-2 standard, including:

  • Alignment with ISO/IEC 19790:2012 for global interoperability and consistency with global cryptographic security
  • Enhanced Level 2 Security provides additional protection including physical tamper evidence and role-based authentication, where access to the cryptographic module is controlled by user roles allowing different levels of permission
  • Lifecycle security evaluations from design to deployment
  • Mandate for more advanced cryptographic algorithms, including SHA-3 as the primary hashing algorithm and AES as the only approved symmetric encryption algorithm.

Governments worldwide are transitioning to FIPS 140-3 to bolster cybersecurity. In the United States, federal agencies are required to use FIPS 140-3 validated modules, with September 2026 set as the sunset date for FIPS 140-2 certificates. Through the Cryptographic Module Validation Program (CMVP), Canada’s Communications Security Establishment (CSE) jointly validates FIPS 140 modules with NIST, ensuring compliance across North America.

Additionally, FIPS-validated modules are widely adopted by governments and organizations in countries like the UK, Australia, and Japan to ensure robust cryptographic protections for their national security and critical infrastructure.

Current Silvus customers are now able to access FIPS 140-3 Level 2 encryption and capability enhancements through a software update in the StreamScape 5 network management software.

(Source: UAS VISION)

 

21 Jan 25. US Army kicks off NGC2 prototyping effort. US Army leaders are seeking industry input for the development of prototype systems to support the ground service’s Next Generation Command and Control (NGC2) initiative, according to a newly released request for information (RFI). The 14 January RFI, issued by the Program Executive Office for Command, Control, Communications, and Network (PEO C3N) is designed to “provide commanders and units at echelon an open and modular C2 ecosystem across hardware, software, and applications with access to a common and integrated data layer”, according to a service statement accompanying the 14 January RFI.

“Contracting and delivery of Next Generation Command and Control capabilities will be deliberate and iterative, geared toward commander needs and dependent upon the innovation of industry,” said Program Executive Officer for PEO C3N Mark Kitz said in the statement.

NGC2 programme officials at PEO C3N anticipate issuing a follow-on draft request for proposals (RFP) by late January 2025, with the final version of the RFP slated for release by the end of February 2025, service officials said in the statement.

Once issued, contract awards for NGC2 prototypes are scheduled to be issued to industry by May 2025, “with initial prototype deliveries to occur within six months” of the contract award date, the officials said. “Each stage of the process will generate industry feedback and inform the [NGC2] contract approach and resultant contract … as well as future evolution of the capability,” they added. (Source: Janes)

 

21 Jan 25. Hanwha Systems’ proprietary cybersecurity solution for ships was E27 certified by the American Bureau of Shipping(ABS) for the first time in Asia. With this certification, Hanwha Systems will accelerate its advance into the global shipbuilding and maritime cybersecurity markets.  Hanwha Systems(led by CEO Jae-il Son) announced today that its cybersecurity solution ‘SecuAider®’ has obtained E27 TA(Type Approval for cyber resilience of on-board systems and equipment) certification from the American Bureau of Shipping(ABS). Hanwha Systems received an official certification from the American Bureau of Shipping (ABS) held at the Hanwha Building in Janggyo-dong, Jung-gu, Seoul, on the afternoon of the 20th. SecuAider also acquired certification from the Korean Register (KR) in December of last year.

The E27 TA certification involves a stringent evaluation process that assesses the performance and safety of ship equipment across all stages, including product design, manufacturing, operation, and maintenance, with a focus on cybersecurity of ships. Notably, SecuAider® marks the first such certification among Asian nations, which currently lead the global shipbuilding industry.

*E27 TA: Certification published by international class such as ABS when it is assessed that on-board systems and equipment qualified requirements to cyber resilience.

On-board systems or equipment that has ABS E27 TA certification will be eligible to export and supply to various global shipyards and shipping companies certified by ABS. The International Association of Classification Societies(IACS) which is registered with global classes including ABS, DNV, Lloyd’ Register or Korean Register, published new regulation to apply cyber resilience to ships built after July 2024, therefore, on-board systems and equipment of ships must also have cyber resilience certification of E27.

Hanwha Systems’ SecuAider® is a cybersecurity solution that protects data and networks, which is installed in the ship’s network and linked to on-board systems and equipment. With SecuAider®, ships would enhance cyber resilience to protect against advanced cyberattacks such as ransomware, DDoS attacks or malicious code infections, which have been rapidly increasing in recent years. It analyzes and controls cyber situations in real-time without degrading performance of legacy on-board systems and equipment of a ship. It provides advanced functions such as AI-based anomaly detection, cyber threat hunting, and real-time remote response.

Developed entirely with Hanwha Systems’ proprietary technology for decades, SecuAider® draws on Hanwha Systems’ extensive expertise in advanced ship systems and its years of experience in ICT technologies. The solution offers highly compatible and flexible standardized interfaces for different types of equipment in network and cybersecurity, seamlessly integrating with both domestic and international commercial ship equipment currently in operation.

“Leveraging SecuAider®, which has been certified as a world-class cybersecurity solution, we aim to strengthen the cybersecurity of various commercial ship line-up and defense companies, both domestically and internationally,” said a Hanwha Systems spokesperson. “We are also exploring opportunities to expand into major markets, including the United States.”

 

13 Jan 25. Trouble at The Top. As our Change of Name, Change of Culture article in this month’s Military Communications Newsletter explains, the People’s Liberation Army (PLA) has performed a major reorganisation of its Strategic Support Force (SSF). The SSF was a PLA combatant command. One of the SSF’s key missions was deploying, managing and modernising the strategic, operational and tactical communications the PLA relies on. The SSF was disbanded in April 2024 and then reconstituted as the Information Support Force. The exact reasons for this course of action remains unknown. In December 2024, the US Department of Defence’s 2024 Military and Security Developments involving the People’s Republic of China Annual Report to Congress speculated that the changes may have occurred because of politico-military concerns over the SSF’s leadership. The report noted that the SSF’s head General Ju Qiansheng was removed from his post in February 2023. It speculated that this may have been the result of the incident in the United States one month earlier when a Chinese surveillance balloon was flown over America. Gen. Ju was not replaced before the SSF was disbanded. Likewise, the Lieutenant General Shang Hong, commander of the SSF’s space force, was not replaced following his departure that same year. The report speculated that both officers may have been involved in corrupt procurement practices. The same document also noted wider corruption in the PLA, and purges by the Chinese politico-military leadership to this end. Assuming corruption did take hold in the SSF, this will have hampered the PLA’s continued pursuit of modernised communications systems and networks. Corruption in defence procurement never leads to the procurement and sustainment of the best capabilities. Instead, proficiency suffers as warriors must make do with inferior materiel. Graft contaminates the workforce; efficiency suffers and motivation declines. China maybe a feared and respected near-peer rival, but corruption in PLA circles may be more severe than the country’s leadership dares admit. This may yet retard the pace, breadth and depth of PLA military communications modernisation. Anything that slows this process will benefit the US and her allies as they confront an increasingly strategically assertive China. (Source: Armada)

 

16 Jan 25. Comms Collapse.

The rapid end of Syria’s civil war, and the fall of the Assad regime, may have highlighted shortcomings in Russian tactical communications, and the proficiency of Turkish electronic warfare.

The lightning dash across Syria by the Ha’yat Tahir al-Sham (HTS) Islamist militia group came as a surprise. Syria had been gripped by civil war since 2011. An uneasy peace took hold from July 2017 following a ceasefire brokered by Jordan, Russia and the United States which collapsed in late November 2024. HTS led an advance by a coalition of organisations opposing the regime of Syria’s dictator Bashir al-Assed. HTS forces initially captured the city of Aleppo in the north. Hama in western, central Syria was the next conurbation to fall. By 6th December the western city of Homs was in the opposition’s hands with the capital Damascus falling on 8th December. Mr. Assad fled to Moscow with his family on the night of 6th/7th December while HTS declared victory.

HTS and its associates seemed to meet little meaningful opposition from Syria’s military as they drove across the country. Reports state that 261 Syrian, Iranian and Russian cadres were killed during the battles, with 21 Syrian troops captured. Both the governments of Russia and Iran were enthusiastic backers of Mr. Assad’s regime. Meanwhile, HTS and supporting groups lost 371. Why the regime and its military collapsed so quickly will be studied for years. One strategic factor highlighted in recent analysis has been the lack of willingness of Moscow and Tehran to continue supporting Mr. Assad. With both his major supporters now essentially quitting, did the Syrian military still have the stomach for a fight?

Turkish EW

Another reason for Syria’s military collapse which has come to light is the alleged proficiency of Turkish Communications Jamming (COMJAM) systems. Information began to circulate on social media that these capabilities were successful in attacking Syrian military communications networks. With their radios jammed, Syrian command and control was significantly impeded. As the intelligenceonline.com website later confirmed, Turkish Electronic Warfare (EW) assets were integral to the HTS advance.

Turkey’s government had supported the Free Syrian Army in its efforts to unseat Mr. Assad’s regime since the eruption of the civil war. Ankara invaded northern Syria in 2016 to attack Kurdish insurgent organisations, and Islamic State of Iraq and Syria cadres, operating there. Open sources state that Aselsan’s Milkar-A42 and Ilgar-3LT COMJAM platforms proved particularly useful. These systems were deployed to areas controlled by the Turkish military in and around the northern Syrian city of Idlib.

The Milkar-A2 is a vehicle-mounted COMJAM system which attacks High Frequency (HF: three megahertz/MHz to 30MHz) communications in support of land force manoeuvre, according to Aselsan. The Milkar-A2 can also demodulate HF traffic allowing it to be exploited for communications intelligence. The Ilgar-3LT provides similar capabilities against Very/Ultra High Frequency (V/UHF: 30MHz to three gigahertz) communications traffic. It is understood that these systems were particularly effective against Р-168 Акведук (R-168 Aqueduct) HF and V/UHF, Р-187П Азарт (R-187P Excitement) V/UHF tactical radios. More information on both radios can be found here. These transceivers are believed to have been supplied to Syrian forces and were also used by Russian troops in Syria. Russia deployed forces into Syria to support Mr. Assad’s regime from 2015.

Russia is though to have deployed R-168 Aqueduct multiband radios to Syria to support her deployment there, and to furnish the Syrian military. It is possible that R-168 transceivers were targeted by Turkish Milkar-A2 and Ilgar-3LT COMJAM systems.

Assessment

Jamming these radios and their networks may have helped precipitate the Syrian military’s collapse in the face of the HTS advance. Turkish electronic warfare acumen has come to the fore in recent years, illustrated by the proficiency of Turkish EW cadres in Syria. Turkish electronic warfare equipment supplied to Ukraine has also performed well. The Ukraine theatre of operations has provided a laboratory in which Turkish EW equipment can be tested and improved. Improvements based on electromagnetic observations in Ukraine can then be cycled back into electronic warfare system design and performance enhancements. Despite the R-168 and R-187P being among the most modern and secure tactical radios deployed by Russian land forces they appear vulnerable to Turkish jamming. Such vulnerabilities can only be good news for the North Atlantic Treaty Organisation. Likewise, the inadequacy of Russian communications kit is an additional embarrassment for the regime of Russia’s President Vladimir Putin. Mr. Putin is already having to face the humiliation of backing the losing side. (Source: Armada)

 

15 Jan 25. Change of Name, Change of Culture?

A bureaucratic reorganisation in one of China’s combatant commands may be indicative of problems and challenges the Chinese military is experiencing in modernising its military communications.

In what has become an annual tradition the United States Department of Defence (DOD) released its 2024 Military and Security Developments involving the People’s Republic of China Annual Report to Congress in late December. In its own words the document “charts the course of the PRC’s national, economic, and military strategy and offers insight on the People’s Liberation Army’s (PLA) strategy, current capabilities, and activities as well as its future modernisation goals.”

The document remains a useful source, providing an authoritative snapshot of the People’s Republic of China’s (PRC’s) strategic goals and foreign policy objectives, defence and security priorities, military force structures and military modernisation goals. The report articulates observations regarding People’s Liberation Army (PLA) efforts to overhaul its strategic, operational and tactical military communications.

Writ large, the report states that the PLA “has sought to modernise its capabilities and improve its proficiencies across all warfare domains to become a joint force capable of the full range of land, air, and maritime as well as nuclear, space, counterspace, electronic warfare and cyberspace operations.” This quotation underscores how communications modernisation is central to the PRC’s embrace of the Multi-Domain Operations (MDO) philosophy. The PLA’s version of MDO is termed Multi-Domain Precision Warfare. It exploits “command, control, communications, computers, intelligence, surveillance, and reconnaissance … network that incorporates advances in big data and AI (Artificial Intelligence).” The strategic objective of Multi-Domain Precision Warfare is to “rapidly identify key vulnerabilities in the US operational system and then combine joint forces across domains to launch precision strikes against those vulnerabilities.”

Information Support Force

One of the most dramatic illustrations of Chinese military communications modernisation has been the reorganisation of the erstwhile PLA Strategic Support Force (SSF). The SSF is no more, having been dissolved by China’s Central Military Commission (CMC) in April 2024. In the alphabet soup of Chinese military acronyms, the CMC is the PRC’s supreme politico-military leadership. Why the SSF was dissolved remains unknown. The report speculates that “(t)he …  decision to dissolve the SSF after only eight years reveals compelling concerns over its contribution to joint operational effectiveness as well as severely inefficient management and leadership.” The report cites several changes in SSF leadership between 2023 and 2024 which may indicate concerns over the SSF’s leadership and management. The coordination and management of the PLA’s military communications now falls within Information Support Force (ISF). The ISF is directly subordinate to the CMC, as was the SSF. The status of the ISF is analogous to a combatant command in the US military.

The SSF had three directorates: The Network Systems Department (NSD) was responsible for cyberwarfare, electronic warfare, information warfare, technical reconnaissance and psychological warfare. The SSF’s Space Systems Department (SSD) was responsible for the PLA’s use of space, and counterspace activities. Finally, the Information Communications Base was the custodian of PLA communications networks and was responsible for defending these networks. The SSD and NSD have been moved out of the ISF and are now under the Central Military Commission’s direct control. However, the Information Communications Base is thought to continue as a constituent part of the ISF headquartered in Beijing.

It remains to be seen what effect the SSF disbandment and ISF activation will have on the PLA’s military communications capabilities. To paraphrase the quotation of Zhou Enlai, Chinese Communist Party ideologue and PRC stateman when asked about the consequences of the 1789 French Revolution, it is probably too soon to say. On the one hand, the reorganisation reflects the PLA’s commitment to continue prioritising communications modernisation and investment. On the other hand, SSF leadership problems may have adversely affected the pace and quality of PLA military communications modernisation. Time will tell. (Source: Armada)

 

20 Jan 25. Airbus Defence and Space equips in close collaboration with HENSOLDT the “German Airborne Weapon Systems Electronic Warfare Center” with new up-to-date software and hardware to provide a streamlined, service-oriented approach to improve the support of mission-specific “Electronic Warfare Mission Data” for the aircraft operated by the German Armed Forces. This joint effort ensures that weapon systems are tailored to each mission and maintain the readiness of the “German Airborne Weapon Systems Electronic Warfare Center” in face of current and future threats. The agreement starts in January 2025 and includes mission-critical software solutions. The highly integrated system will offer an increased amount of automation and allows reduced response times to the end user. Airbus` state-of-the-art operating systems will enhance usability while integrating future-proof technology compatible with advanced weapon systems. It not only paves the way for future integration with additional platforms, but also increases mission effectiveness and enables efficient mission preparation and conduction seamlessly. HENSOLDT provides essential IT services and deployable hardware for mobile operations, including server hardware and workstation computers for personnel. The collaboration between Airbus and HENSOLDT marks a significant step in strengthening Germany’s defence capabilities, ensuring mission effectiveness and readiness in a complex and technology-driven defence environment.

 

14 Jan 25. Of Strelets and Andromeda. The YESU-TZ operational-level command and control system is used at the Russian armed forces’ National Defence Command Centre in Moscow. A new book sheds light on the organisation of Russian land forces’ command and control, and the digital battle management systems they employ at operational and tactical levels. Armada was delighted to receive a review copy of the Lightning Press’ latest volume examining the Russian military. OpFor Smartbook-3: Russian Military Forces, Operations and Tactics is a comprehensive work examining Russia’s armed forces in their entirety. The work also discusses Moscow’s strategic goals and foreign policy preoccupations. As noted in another recent article, the book provides an excellent overview of the Russian military’s Electronic Warfare (EW) posture. Equally useful is the volume’s analysis of Russian land forces Command and Control (C2). Russian land manoeuvre force C2 can be shrouded in conjecture and contradiction. Norman Wade, the Lightning Press’ publisher and the book’s author, does great work demystifying this aspect of land manoeuvre force posture and organisation.

YESU-TZ

The strategic echelons of Russia’s joint high command use the ЙЕСУ-ТЗ (YESU-TZ – Unified Command and Control System for Troops and Weapons) digital C2 architecture. As Mr. Wade notes, YESU-TZ is vital for turning the political intentions of Russian’s civilian leadership into military objectives. YESU-TZ receives and processes data sent by subordinate echelons, and disseminates information, orders and situation reports. It appears YESU-TZ performs C2 from the National Defence Command Centre in Moscow through to Russia’s constituent Military Districts (MDs). Russia’s military is spread across five MDs; Moscow and St. Petersburg in the north and west of the country, plus the Central, Southern and Eastern Military Districts. Land forces in each MD are typically organised into Combined Arms Armies (CAAs). CAAs are operational-level formations consolidating Russian Army manoeuvre forces in that MD with other land manoeuvre elements like Russia’s airborne forces and naval infantry, both of which function as separate forces. For all intents and purposes, YESU-TZ also provides operational level C2 for the CAAs.

Tactical manoeuvre force C2

The principle tactical manoeuvre unit in the Russian Army is the motorised rifle/tank division/brigade. As Mr. Wade notes other C2 systems are used, at the brigade/division level. He writes that the Акация-М (Akatsiya-M) C2 architecture is employed for logistics, general force organisation and battle management. Akatsiya-M terminals can be installed on vehicles or used at deployed bases. Russia’s airborne forces have the Андромеда-Д (Andromeda-D) C2 system. Andromeda-D “provides a near real-time plot of the battlefield situation to coordinate the actions of airborne forces,” says Mr. Wade. He adds that Andromeda-D capabilities are like those of the Стрелец (Strelets) C2 system used by Russian Army dismounted infantry.

The Russian Army has deployed the Strelets C2 system with its dismounted troops. The capabilities of command and control architectures like the Andromeda-D used by Russian airborne forces are similar to those of Strelets.

Ground-Based Air Defence (GBAD) employs the Акация-Э (Akatsiya-E) C2 system. Akatsiya-E is used for operational and tactical air battle management. To this end, Akatsiya-E will link directly with tactical GBAD C2 systems like the 73Н6МЭ Байкал-1МЭ (73N6ME Baikal-1ME), Универсал-1Е (Universal-1E), Фундамент-1Э (Fundament-1E) and Поляна-Д4М1 (Polyana-D4M1). These latter systems are tactically deployed to provide C2 to individual GBAD surface-to-air missile and anti-aircraft artillery batteries. By integrating these disparate systems, Akatsiya-E provides a consolidated recognised air picture.

Artillery units make use of the 1В168 АСУНО-С (1V168 ASUNO-S) tactical C2 system. The author writes that the 1V168 ASUNO-S has an integral Global Navigation Satellite System (GNSS) terminal. The terminal automatically registers the position of firing platforms under command. Digital maps provide local topographic information. Target data is downloaded automatically in near real time by the 1V168 ASUNO-S with firing solutions calculated as rapidly. Mr. Wade writes that a BM-20 Smerch 300mm multiple rocket launch system can fire a 40-second volley of rockets against targets 90-kilometres (56-miles) away two minutes after receiving target data from the 1V168 ASUNO-S. Last but not least, Russian land forces EW employ use the РБ-109 Былина (RB-109 Bylina) tactical C2 system.

Assessment

The adoption of digital C2 systems by Russia’s land forces reflects the acknowledgement of the country’s military that the automation of battle management is essential for contemporary and future conflicts. Mr. Wade argues that the adoption of the systems discussed above helps increase “the stability, continuity, speed and security of (C2) actions.” Digital C2 enhances the commander’s “ability to quickly assess the battlefield situation, supports rapid decision-making and transmits those decisions to units and subunits.” Above all, these C2 systems help deepen combined arms operational and tactical coordination. By doing so, Russia’s military writ large hopes to accelerate the pace at which it can navigate the OODA (Observe, Orient, Decide, Act) loop with better quality decision-making than its adversary. Achieving this ambition, as Mr. Wade stresses, can mean the difference between success and failure on the battlefield. (Source: Armada)

 

13 Jan 25. January Radio Roundup.

Banshee Tactical Radio for Backpack

Armada’s monthly roundup of all the latest news in the military communications product, programme and operational domains. Nokia recently publicised its 5G Banshee Flex Radio which enables 5G connectivity across the battlefield, providing a coverage footprint of up to 154 square kilometres (60 square miles).

New Nokia tactical 5G networking

Nokia has unveiled the latest member of its Banshee tactical radio family. Known as the 5G Banshee Flex Radio the system uses fifth generation (5G) cellular protocols. Previous Banshee tactical radios used fourth generation (4G) cellular standards. The company stated in a press release that the 5G Banshee Flex Radio can be deployed to provide a tactical 5G network over the battlefield. Troops can then use their 5G devices to connect to this network, and to each other. By enabling 5G communications, the radio provides “advanced edge compute capabilities, mesh networking, band flexibility, operational security and deployment simplicity,” according to the press release. Moreover, the radio “delivers unparalleled 5G throughput with 100 (megahertz) carriers and extreme operational range with multiple power options.” Nokia told Armada, via a written statement, that the 5G Banshee Flex Radio supports legacy 4G communications. The company continued that data rates of 800 megabits-per-second are achievable. The 5G Banshee Flex Radio provides 5G coverage across a seven-kilometre (4.4 mile) radius. Power output levels of between five watts/W and 20W per transmission port are available. Regarding customers, the company said it is “actively working with defence ministries and other strategic partners on the deployment of the 5G Banshee Flex Radio. While we are not able to disclose specific customers … we are focused on meeting the secure and flexible 5G needs of mission-critical applications.” (Source: Armada)

 

20 Jan 25. Global: Large-scale DDoS attacks elevate disruption risks stemming from newly discovered botnet. On 17 January, the cyber security company Trend Micro reported that a newly discovered botnet conducted large-scale distributed denial-of-service (DDoS) attacks against global organisations since at least the end of 2024. The botnet infiltrates Internet-of-Things (IoT) devices via software vulnerabilities and/or weak password configurations. It then executes malware (likely derived from the known Mirai and Bashlite botnets) through a multi-step process to establish communication with actor-controlled infrastructure and execute additional malicious activities. This includes conducting DDoS attacks against targeted networks to cause temporary operational disruption while deactivating security mechanisms. Threat actors often exploit vulnerable IoT devices to launch DDoS attacks since such operations can propagate disruption to entire IT networks. This trend highlights the elevated security risks stemming from these devices. Additionally, the botnet has been used to target critical national infrastructure sectors (including telecommunications and financial services), illustrating heightened disruption risks in the short term as part of an ongoing campaign. (Source: Sibylline)

 

20 Jan 25. Silvus Technologies Partners with Safeware to Expand Public Agency Access to Advanced StreamCaster MANET Radios. Silvus Technologies, Inc., a leader in advanced wireless communications systems, has announced a new resale partnership with Safeware, a leading safety solutions provider.

With StreamCaster MANET radios now available through Safeware, first responders, law enforcement, and disaster relief agencies across the nation can establish robust, decentralized communication networks, improving coordination and efficiency in emergency response.

“We’re thrilled to partner with Safeware to extend the reach of StreamCaster MANET radios to agencies on the front lines of public safety,” said Jimi Henderson, Vice President of Sales at Silvus Technologies. “This partnership ensures that first responders will have access to reliable, secure, and robust communications when it matters most.”

The Silvus family of StreamCaster MANET radios deliver high-fidelity video, voice and data communications with class-leading output power, range, and mobility. At the heart of every StreamCaster MANET radio is Silvus’ leading-edge MN-MIMO waveform technology that creates a self-healing, self-forming and adaptive mesh network – capable of linking hundreds of nodes with unmatched data rate throughput, EW resiliency, and scalability.

Silvus StreamCaster SC4200

Also available as an extension of the MN-MIMO waveform is Spectrum Dominance – an expansive suite of advanced interference avoidance and cancellation capabilities that provide secure and protected mesh network communications in high RF traffic environments including disaster areas, sporting events, parades, and rallies, without sacrificing performance. This allows teams to stay connected and on mission in a wide range of operational scenarios without worrying whether communications will fail.

“At Safeware, just like Silvus, we’re dedicated to providing first responders and public safety teams with the best communication tools available,” said Connie Stallings, Senior Vendor Relations Manager at Safeware. “By including Silvus StreamCaster MANET radios to our list of partners, we’re helping agencies build strong, reliable communication networks that hold up in the toughest situations.”

Interested agencies can contact Safeware for more information.

About Silvus Technologies, Inc.

As the world’s leading provider of advanced MANET and MIMO communications systems, Silvus Technologies is reshaping mesh network technology for mission-critical applications – on the ground, in the air, and at sea. Its battle proven StreamCaster family of MANET radios and proprietary MN-MIMO waveform provides the vital communications link for defense, law enforcement, and public safety agencies around the world, and in the toughest operational environments. Developed by a team of top PhD scientists and design engineers, Silvus Technologies continues to innovate communications technology for the tactical edge with unmatched range, data throughput, EW resiliency, and scalability. Silvus Technologies is privately held with world headquarters located in Los Angeles, CA.

About Safeware

– Safeware is a leading provider of safety solutions, specializing in assessing, distributing, and training advanced technologies to mitigate risks and enhance safety across various industries. With a commitment to innovation, quality, and customer satisfaction, Safeware remains at the forefront of safety excellence, empowering organizations to protect lives, assets, and the environment. (Source: UAS VISION)

 

16 Jan 25.  US Army to competitively develop Next-Gen Command-and-Control prototype. After spending a year working on pilot programs for a future battlefield command-and-control capability, the U.S. Army is on the brink of starting an effort to competitively prototype a next-generation system, according to the service’s program office in charge of the activity. Next-Generation Command-and-Control, or NGC2, as the Army calls it, represents a new approach to providing commanders and units an “open and modular” command-and-control, or C2, ecosystem “across hardware, software and applications with access to a common and integrated data layer,” the Army said in a statement. The service’s Program Executive Office for Command, Control, Communications and Network, seeking industry feedback ahead of launching the prototyping effort, released a request for information Monday to industry addressing its NGC2 priorities.

“The goal of NGC2 is to help organize and operationalize data for warfighting applications — including real-time operational modeling of the potential outcomes of commanders’ decisions and courses of action, as well as the ability to tailor and reconfigure elements to meet their missions,” the Army said.

The service launched a pilot in roughly a year ago to examine what could realistically be achieved for C2 using a clean sheet design. Entirely ignoring all current C2 capabilities, the Army partnered with industry to provide soldiers with an agile system capable of functioning off of laptops inside a tank, for example, rather than consisting of giant server stacks in climate-controlled tents easily detectable to the enemy.

“I think we’re learning that we can probably go pretty quick on this given where technology is at,” Army Chief of Staff Gen. Randy George told Defense News in an interview last fall. The Army needs to move away from “big systems and server stacks and all of that stuff,” he said. “That can all be an app.”

As a major element of the pilot, the Army focused not just on how a fresh C2 system might bring capabilities to the soldier in the field but how to transport data to enable all of those functions, according to Doug Bush, the Army’s acquisition chief.

“The ability to move the data around at speed, at a vast scale and under attack by an enemy, that is a very difficult challenge,” Bush told Defense News in an interview last fall. “The good news is, this time around, the tech is much closer to being able to enable that.”

A request for NGC2 proposals is expected to be released in late February, according to the RFI posted to federal contract opportunities website Sam.gov. The service plans to award contracts by May, with the delivery of initial prototypes within six months of award.

The planned contract awards are structured to enable multiple opportunities for defense companies to contribute to NGC2, the Army said, with the service intending to onboard new vendors for additional components available after the initial prototyping awards.

Specifically, the Army emphasizes “tailorable and intuitive capabilities” and “agility in requirements and governance” for the next-gen technology, according to Army Futures Command’s NGC2 character of needs statement.

Recent updates to the character of needs statement include a focus on mission partner interoperability, operating in challenging tactical communications environments and “an integrated ‘tech stack’ approach that reaches from the communications transport layer through compute, integrated data and applications layers,” the Army said.

“We have an incredibly tech-savvy formation,” Maj. Gen. Patrick Ellis, director of AFC’s Command and Control Cross-Functional Team, said in the statement. “Commanders understand the network better than they ever have, and divisions are eager to be a part of the process and part of the user-informed solution.” (Source: glstrade.com/Defense News)

 

17 Jan 25. Cyber Update Key points.

  • Global spam operation highlights raised security risks posed by the Chinese state-sponsored group ‘Muddling Meerkat’ (see Sibylline Cyber Daily Analytical Update – 13 January 2025).
  • A cyber operation against Central Asian countries points to raised espionage risks from the Russia-nexus group ‘UAC-0063.’
  • Increases in cryptocurrency theft highlight elevated financial risks posed by North Korean state-sponsored groups.
  • A new ransomware operation (‘Codefinger’) is targeting cloud storage services, pointing to elevated financial risks to global users (see Sibylline Cyber Daily Analytical Update – 16 January 2025 and our Technical analysis below).
  • A noteworthy spoofing operation distributes malware and heightens security risks stemming from the ‘MikroTik’ botnet (see Sibylline Cyber Daily Analytical Update – 17 January 2025).

Technical analysis of weekly stories

The Russia-nexus group UAC-0063 is targeting organisations in Kazakhstan and other Central Asian countries in a large-scale cyber espionage operation. The campaign likely started with spear phishing emails to trick potential victims into opening a malicious Word document. UAC-0063 uses high-profile official documents (including correspondence letters, draft documents and administrative notes likely stolen during a previous cyber espionage campaign) to boost legitimacy and intrusion success rates. This then downloads the ‘HatVibe’ and ‘CherrySpy’ payloads onto compromised systems via a Double-Tap infection chain to bypass security mechanisms. HatVibe typically acts as a loader and establishes communication with actor-controlled infrastructure to download and execute additional malicious files. CherrySpy is a backdoor that can be used to monitor victims’ systems and exfiltrate strategic information to the actors’ command-and-control (C2) servers. Notably, UAC-0063’s modus operandi overlaps with that of the Russian state-sponsored group ‘APT28’, suggesting that the operation is possibly state-sponsored and that there is possibly a connection between the groups.

A new ransomware operation (‘Codefinger’) is exploiting encryption settings to target Amazon Simple Storage Service users. Codefinger reportedly uses stolen Amazon credentials to access and hijack cloud storage user accounts. The actors then generate new encryption keys to block user access to their data, abusing encryption settings typically used by customers to protect stored data by creating customer encryption keys. Subsequently, Codefinger demands a ransom payment for file decryption, warning affected customers that it will delete all files within seven days if the payment is not made or if users attempt to change account permissions. Additionally, affected customers can only recover encrypted data by paying the ransom since Amazon does not store any pre-existing customer-made keys. This underscores the continued exploitation and sustained security risks posed by third-party cloud services. Codefinger encrypts customer data directly within Amazon’s infrastructure to further prevent any alternative attempt at decrypting affected data, highlighting the sophisticated nature of the operation.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network; configure firewalls to block outbound communication to malicious IP addresses associated with known malware
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering
  • Implement password management policies to prevent compromises via stolen and/or exposed credentials

Our cyber word(s) of the week: Encryption

(Source: Sibylline)

————————————————————————————————————————————————————————————————————————————————————————————————————————

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

—————————————————————————————————————————————————————————————————————————————————————————————————————————

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

January 17, 2025 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

——————————————————————————————————————————————————————————————————————————————————————————————————————————————–

17 Jan 25. Iran Unveils Zagros, Its First Domestically Produced Intelligence Ship. Iran has introduced its first domestically produced signals intelligence (SIGINT) vessel, the Zagros, as part of a broader effort to bolster naval capabilities and protect key nuclear facilities. Announced through state media on Wednesday, the unveiling coincides with extensive nationwide military drills involving both the regular armed forces and the Islamic Revolutionary Guard Corps. The Zagros, described as a corvette-based surveillance ship, represents an unorthodox design for SIGINT operations, which are traditionally conducted by vessels converted from commercial hulls. According to Iranian Navy Commander Admiral Shahram Irani, the ship is equipped with advanced electronic sensors capable of intercepting, decrypting, and analyzing electromagnetic signals, as well as cyber and intelligence surveillance systems. The vessel’s integrated mast features ball-shaped radomes housing antennas for radio-frequency signals and satellite communications systems. Admiral Irani emphasized the vessel’s strategic role, calling it “the watchful eye of Iran’s navy in the depths of the seas and oceans.” Officials stressed that the ship’s construction relied entirely on domestic resources. Iran’s ongoing nationwide drills, set to continue until mid-March., featured simulations aimed at protecting key sites like the Natanz nuclear facility from missile and drone attacks. Iran has reiterated that the exercises are necessary to protect its nuclear infrastructure, which it insists is civilian-focused. However, Western nations remain skeptical of these claims, particularly following the International Atomic Energy Agency’s recent report that Iran’s uranium enrichment levels have reached 60%, far exceeding the limits outlined in the 2015 nuclear agreement. Recent defeats suffered by Iran and its allies, including Hezbollah in Lebanon, at the hands of Israel have heightened fears that Tehran could pursue a nuclear weapon to reestablish regional deterrence. Analysts caution that these tensions might also be exacerbated by president-elect Donald Trump’s return to the White House later this month. Since the U.S. withdrawal from the 2015 nuclear deal under Trump, tensions have escalated over Iran’s nuclear activities. The Biden administration has reportedly considered options, including military strikes, to prevent Tehran from advancing toward nuclear weapons development. Talks involving European nations, held as recently as January in Geneva, have called for Iran to de-escalate its nuclear ambitions. (Source: https://www.sofx.com/)

 

17 Jan 25. Global: Spoofing operation heightens security risks stemming from large-scale botnet. On 14 January, the security company Infoblox reported that the MikroTik botnet has been exploiting misconfigured sender policy framework (SPF) records to distribute malware since at least November 2024. Threat actors re-configure SPF records to allow for emails originating from malicious domains to be received by potential victims without being detected. This enables them to send spoofed phishing emails to trick users into opening a malicious .ZIP attachment. The file then runs a PowerShell script to establish a connection with actor-controlled infrastructure, and to deploy malware onto compromised systems. The botnet comprises approximately 13,000 devices acting as proxies, underscoring the potential widespread impact of MikroTik attacks. This also highlights the sophistication of the actors’ detection evasion techniques as they allow for prolonged obfuscation. We assess this operation heightens the security risks stemming from the MikroTik botnet in the short-to-medium term amid a broader increase in the exploitation of email security mechanisms.  (Source: Sibylline)

 

16 Jan 25. Raft, a leading defense technology company dedicated to empowering the U.S. military and government agencies with cutting-edge AI/ML and data solutions, today announced the latest version of Raft Data Platform ([R]DP), a robust, edge-ready, scalable platform purpose-built for the U.S. Department of Defense (DoD) to solve challenges in handling disparate, large-scale data from from the edge to the enterprise. With evolving geopolitical tensions and increasing reliance on data-driven military operations, modern warfare demands the ability to collect, process, and analyze data from multiple sources in real-time across a vast, complex, contested landscape. Using data quickly and efficiently is mission-critical, as delays in processing data cedes decision advantage to the adversary. To keep pace in the next fight, modern data platforms need to integrate more seamlessly, be more modular, and require more flexibility in government ownership and government purpose rights.

“From licensed-based solutions that come with high costs and require customization to government-owned platforms that do not have the flexibility needed for broader operational use, today’s DoD data marketplace lacks a singular solution that supports edge and DDIL environments while operating across all classification levels, until now,” said Shubhi Mishra, CEO, Raft. “With [R]DP, we are providing the DoD with a much-needed flexible, AI-enabled solution that scales with evolving needs. Now, the DoD has access to a powerful platform that gives them the versatility, speed, and reliability to take control of its data landscape and stay ahead of adversaries.”

[R]DP supports users of all types, from low code operators to data scientist super-users, from the edge to the enterprise and has demonstrated use cases at the tactical edge using handheld devices to users at the enterprise level using a global Common Operating Picture. [R]DP operates at and all classification levels with native Cross Domain Solutions. [R]DP seamlessly integrates various data types and modalities and moves data and industry leading speed, sub second speed, enabling decision superiority. Raft’s comprehensive platform performs faster than existing operational data platforms and is already deployed on IL6 within the DoD.

Key features and benefits include:

  • COP & UI Agnostic: Use any COP or UI, or leverage [R]DP’s user-friendly interface.
  • AI-Ready: Native ML Ops layer to seamlessly integrate and deploy machine learning models to drive faster decision-making.
  • Native Cross Domain Solution: Integrates with both object and messaging-based diodes transferring data in real-time across and in between enclaves.
  • Security & Compliance: Access to fine-grained security controls at all levels for data protection and compliance across DoD environments.
  • Real-time Data Processing: Process and analyze data under 200ms, enabling immediate situational awareness and F2T2EA.
  • Modular Design: With 45 microservices, purchase only the features needed for flexibility and cost-efficiency.
  • Data Integration and Transformation: Handle structured and unstructured data from diverse sources with seamless integration and rapid data transformation with over several billion transformations per day.

[R]DP is an essential U.S. defense data platform market solution. The new platform provides cutting-edge capabilities tailored to meet the evolving demands of modern warfare with its scalability, AI readiness, and edge capabilities. A powerful and versatile solution, [R]DP enables data collection, analysis, and visualization across a wide range of environments to drive operational efficiency and enhance decision-making across the DoD.

For more information, visit https://teamraft.com/focus-areas/data-platform/

About Raft

Raft is a leading defense technology company dedicated to empowering the U.S. military and government agencies with cutting-edge AI/ML and data solutions. We transform complex data into actionable insights, enabling mission-critical decisions on Earth and beyond. Our modular platforms are designed to eliminate operational friction and data fatigue, ensuring you have the correct information at the right time to achieve mission success. (Source: PR Newswire)

 

16 Jan 25. Saab opens new production facility for Sirius Compact in Tampere. Saab sees high demand for the passive EW sensor Sirius Compact. As a result, the sensor will enter into volume serial production and Saab will be opening a new production facility in Tampere in 2025. First launched in 2022 and manufactured in Finland, Sirius Compact has been well received by the market with significant deliveries scheduled for 2025. In response to the high demand, Saab is now opening a new manufacturing facility in Tampere to cater for volume serial production of Sirius Compact.

“Saab’s footprint is growing in Finland with a focus on research and development operations in the field of electronic warfare. This initiative underscores Saab’s commitment to provide cutting-edge defense solutions to customers,” says Kristian Tornivaara, Managing Director for Saab Finland.

Saab currently employs more than 200 people in Helsinki, Tampere and Turku, a footprint which has grown rapidly in the last years and continues to grow with planned recruitments. In addition to the Sirius Compact family of sensors, Saab Finland is delivering sensor network capabilities and threat library management tools supporting customers tactical Electronic Support Measures (ESM) operations.

The new manufacturing facility in Tampere will enter into service early 2025. The Sirius Compact family of passive surveillance sensors enable detection, geo-location, classification and prioritisation of hostile Radar (R-ESM) and Communication (C-ESM) emitters, with variants dedicated for Land, Air and Naval domains. (Source: News Now/Saab)

 

13 Jan 25. UAE and Malaysia sign MoU to enhance AI collaboration. The United Arab Emirates and Malaysia have signed a Memorandum of Understanding (MoU) to foster joint investment in artificial intelligence (AI), marking a significant step in strengthening bilateral ties. The signing ceremony, which took place in Abu Dhabi, was witnessed by H.H. Sheikh Khaled bin Mohamed bin Zayed Al Nahyan, Crown Prince of Abu Dhabi and Chairman of the Abu Dhabi Executive Council, and Anwar Ibrahim, Prime Minister of Malaysia, in the presence of H.H. Sheikh Tahnoon bin Zayed Al Nahyan, Deputy Ruler of Abu Dhabi. This collaboration aligns with Malaysia’s “Madani Artificial Intelligence” (MMAI) initiative and aims to leverage AI and advanced data analytics to enhance public safety, national security, and operational efficiencies. Under the MoU, the UAE and Malaysia will strengthen technical cooperation in several key areas, including:

Developing AI-driven national security systems.

Establishing high-performance computing data centers and national security operations centers.

Enhancing customs tax collection mechanisms.

Improving operational efficiencies across various sectors.

Bilateral Cooperation in AI and Technology

The MoU was officially signed by Mohamed Hassan Alsuwaidi, UAE Minister of Investment, and Saifuddin Nasution Ismail, Malaysia’s Minister of Home Affairs. Discussions during the event focused on strengthening political and economic ties and exploring the latest advancements in AI and technology to improve living standards and quality of life.

Economic Partnership and Growth

This agreement follows the Comprehensive Economic Partnership Agreement (CEPA) signed in October 2024, reflecting both nations’ shared commitment to fostering innovation and sustainable development. Non-oil trade between the UAE and Malaysia reached $2.5 bn in the first half of 2024, a 7% increase compared to the same period in 2023. Malaysia is the UAE’s 12th-largest Asian trading partner and ranks fifth among ASEAN nations. Conversely, the UAE remains Malaysia’s second-largest trading partner in the Arab world, accounting for 32% of Malaysia’s regional trade.

Statements from Officials

Mohamed Hassan Alsuwaidi emphasized the strategic importance of the partnership:

“Our collaboration with Malaysia underscores the strength of our bilateral ties and our shared commitment to advancing technological innovation in support of sustainable development. This MoU represents a significant step toward enhancing cooperation in artificial intelligence and operational efficiency, contributing to the well-being of our societies.”

Malaysian Minister Saifuddin Nasution Ismail added:

“This partnership is a crucial step in advancing Malaysia’s ambitions to become a global leader in AI. By leveraging cutting-edge AI technologies, we aim to address complex challenges while driving greater operational efficiencies. This collaboration highlights the strong relationship between our nations and our shared commitment to innovation and mutual progress.” (Source: Defense Arabia)

 

14 Jan 25. Central Asia: Cyber espionage operation points to raised espionage risks from Russia-nexus groups. On 13 January, the cyber security company Sekoia reported that the Russia-nexus group ‘UAC-0063’ is targeting organisations in Kazakhstan and other Central Asian countries in a cyber espionage campaign. The campaign likely started with spear phishing emails to trick potential victims into opening a malicious Word document. The document then executed the ‘HatVibe’ and ‘CherrySpy’ backdoors to maintain persistence within compromised systems, as well as to establish communication with actor-controlled infrastructure and deploy additional malicious payloads. Notably, UAC-0063’s modus operandi overlaps with the Russian state-sponsored group ‘APT28’, suggesting that the operation is possibly state-sponsored and that there is possibly a connection between the groups. The actors exploited access to steal strategic intelligence (including diplomatic letters and administrative notes), likely in a bid to bolster Russia’s security posture. We assess this highlights the elevated long-term security and espionage risks amid a wider increase in Russia-nexus cyber espionage operations targeting ex-Soviet countries in the region. (Source: Sibylline)

 

07 Nov 24. 712372454- UK DEFENSIVE AIDS SYSTEM – VTN

Ministry of Defence

Published date: 7 November 2024

Open opportunity – This means that the contract is currently active, and the buying department is looking for potential suppliers to fulfil the contract.

Contract summary

Industry

  • Electronic warfare systems and counter measures – 35730000

Location of contract Any region

Value of contract £100,000,000

Procurement reference tender_457248/1423024

Published date 7 November 2024

Closing date 31 March 2025

Closing time 12pm

Contract start date 30 June 2025

Contract end date 30 June 2028

Contract type Supply contract

Procedure type Single tender action (below threshold)

What is a single tender action (below threshold)?

Contract is suitable for SMEs? No

Contract is suitable for VCSEs? No

Description

VOLUNTARY TRANSPARENCY NOTICE (VTN) TO PLACE A SINGLE SOURCE CONTRACT FOR UK DEFENSIVE AIDS SYSTEMS (DAS) PROCURE, SUSTAIN AND ENHANCE (PSE

Air Platform Systems Delivery Team (APS DT), part of the Ministry of Defence (“the Authority”), intends to place a three (3) year contract with Leonardo UK Ltd (LUK) for the procurement of LUK supplied Defensive Aids Systems (DAS) hardware, software, ancillaries and a train-the-trainer service for users and maintainers. This contract will also include in-service support for the hardware in the form of maintenance, technical engineering, software support, training, and associated software updates. Additionally, LUK, as the Design Organisation (DO), will be responsible for a programme of enhancements covering hardware/software modifications to the DAS design to allow it to meet evolving threats. These enhancements may include the integration of additional subsystems to the DAS. UK DAS is essential for the provision of critical operational capability to Defence.

The Authority intends to include further options to the contract to allow for the extension of contract duration by up to an additional two (2) years in the form of two (2) twelve (12) month extensions.

The Authority has determined this single source contract is excluded from Defence and Security Public Contracts Regulations 2011 under Regulation7(1)(a) in conjunction with Regulation 6(3A) (a). In addition, a “Warlike Stores” exemption under regulation 6(3A) (b) applies.

About the buyer

Address

MOD Abbey Wood, BS34 8JH,

Bristol

BS34 8JH

England

Email

(Source: https://www.gov.uk/)

 

20 Dec 24. Tactical command, control and communication systems – 35712000

Published date: 20 December 2024

Open early engagement – This means that a procurement idea is currently active, it is in the early stage of development and judging interest from potential suppliers.

Contract summary

Industry

  • Tactical command, control and communication systems – 35712000

Location of contract Any region

Procurement reference tender_478242/1437512

Published date 20 December 2024

Closing date 17 January 2025

Contract is suitable for SMEs? Yes

Contract is suitable for VCSEs? No

About the buyer

Contact name

Fabiana Milczarek

Address

Mail Point 3008, Ash Level 0, MOD Abbey Wood

Bristol

BS34 8JH

England

Email:

(Source: https://www.gov.uk/)

 

19 Dec 24. 713285451 – Future Air Dominance System (FADS) – RFI – Market Engagement

Ministry of Defence

Published date: 19 December 2024

Last edited date: 19 December 2024

Open early engagement – This means that a procurement idea is currently active, it is in the early stage of development and judging interest from potential suppliers.

Contract summary

Industry

  • Warships – 35510000

Location of contract

BS34 8JH

Procurement reference

tender_473601/1436909

Published date

19 December 2024

Closing date

17 January 2025

Contract is suitable for SMEs? Yes

Contract is suitable for VCSEs? No

Description

The Future Air Dominance System (FADS) Team within Defence Equipment & Support (DE&S), part of the UK Ministry of Defence (“the Authority”) is seeking to engage with suppliers for the purposes of gaining a clearer understanding of current market capabilities and potential offerings which may be relevant to FADS.

FADS is a transformative multi-domain programme that will provide Maritime Integrated Air and Missile Defence (M-IAMD) against the toughest of threats in the air and space domain, and Long-Range Precision Strike (LRPS) against the hardest of targets in air, land, and maritime domains. The FADS programme will align itself with a ‘system of systems’ approach and brigade around the themes of; SENSE, DECIDE, EFFECT, CONNECT, HOST and ENABLE.

FADS will deliver Air Defence of the Carrier Strike Group and Littoral Strike Group from the mid-2030s; a role currently being provided primarily by the Royal Navy’s Type 45 Destroyers.

Following the issuance of a Prior Information Notice (PIN), dated 18 November 2024 (Ref. 2024/S 000-037234), the Authority would like to sincerely thank all suppliers who have expressed an interest in the FADS programme. If you attended the brief on 03 December and would like to provide some feedback, the Authority would be grateful if you could complete the questionnaire linked here

https://forms.office.com/e/9K96GW0B7g

– to provide feedback that will help us improve how we engage with you in the future.

The slide pack shared at the brief is available for viewing via AWARD. To access the documentation, interested suppliers will have to register to AWARD and pass necessary checks in a security gateway. To register, please follow this link – https://award.commercedecisions.com/dsp/web/project/c681dabd-6f69-4130-a815-9a82d6902ca3/register

– and follow the instructions when prompted.

This second notice serves to provide further information regarding the next Market Engagement Event 2 (MEE2): One to Ones.

These sessions will be held on 28, 29 and 30 January 2025.

FOR FULL NOTICE INFORMATION PLEASE OPEN ATTACHMENT

More information

Previous notice about this procurement

713285451 – Future Air Dominance System (FADS) – RFI – Market Engagement

  • Early engagement
  • Published 19 December 2024

Attachments

  • 20241219_FADS- MEE2- RFI_O.pdf
  • n/a

About the buyer

Address

Ministry of Defence, Defence Equipment and Support

Bristol

BS34 8JH

England

Email

(Source: https://www.gov.uk/)

 

13 Jan 25. Global: Spam operation highlights raised security risks posed by Chinese state-sponsored groups. On 11 January, international news outlets reported on the discovery of an ongoing spam operation conducted by the Chinese state-sponsored group ‘Muddling Meerkat’ against global organisations. The group sends phishing emails via spoofed email domains, impersonating legitimate companies to gain access to targeted systems. The emails emulate spam content from well-known companies (such as Amazon and Mastercard) to trick users into disclosing their credentials, scanning a QR code and/or downloading an Excel spreadsheet. That said, the QR code and spreadsheet do not contain any malicious payloads, suggesting that the campaign may still be in a testing phase and/or be aimed at reconnaissance. Muddling Meerkat also distributes extortion emails that demand cryptocurrency payments, indicating that the campaign may also be financially motivated. This operation highlights the continued expansion of Muddling Meerkat’s cyber capabilities and objectives, heightening security and financial risks to global organisations in the long term. (Source: Sibylline)

 

10 Jan 25. Japan: Long-term campaign highlights elevated espionage risks from China-backed cyber groups. On 8 January, the Japanese National Police Agency (NPA) and the Cabinet Cyber Security Center attributed a long-term cyber espionage campaign targeting Japanese organisations to the Chinese state-sponsored group ‘Earth Kasha’. The campaign reportedly started in 2019 and comprises three phases with distinct targets and attack methods. However, separate reports focusing on the group’s espionage operations began to emerge in November 2024. Earth Kasha mostly exploits software vulnerabilities in network-edge devices to access targeted organisations. The group subsequently deploys three malware variants (‘LOADEINFO’, ‘ANEL’ and ‘NOOPDOOR’) to exfiltrate sensitive data, as well as several backdoors to maintain prolonged persistence within compromised systems. The campaign has targeted multiple sectors (including government, academia, manufacturing and semiconductors) to gather information on Japanese technology and national security amid escalating economic competition and territorial disputes. We assess this points to elevated espionage risks facing Japanese entities, especially as the campaign is ongoing. (Source: Sibylline)

 

10 Jan 25. Cyber Update Key points.

  • A new software vulnerability points to elevated disruption and operational risks facing industrial systems via the deployment of the ‘Mirai’ botnet (see Sibylline Cyber Daily Analytical Update – 2 January 2025).
  • A new cyber attack method (‘DoubleClickJacking’) underscores increased security and financial risks facing web users.
  • A new mobile malware variant will raise security and financial risks for Russian-speaking Android users.
  • A spike in cyber attacks against Taiwan underscores the elevated espionage and operational risks stemming from Chinese threat actors (see Sibylline Cyber Daily Analytical Update – 7 January 2025).
  • A highly sophisticated WordPress plugin (‘PhishWP’) is targeting global entities, raising information-theft and financial risks from cyber criminals.
  • A disruptive cyber attack against a Russian internet service provider (ISP) highlights the heightened security risks stemming from pro-Ukraine hacktivists (see Sibylline Cyber Daily Analytical Update – 9 January 2025).
  • An ongoing long-term cyber campaign highlights the raised espionage risks from the Chinese state-sponsored group ‘Earth Kasha’.

Technical analysis of weekly stories

Unnamed threat actors are using a new mobile malware variant (‘FireScam’) to target Android users in an information-theft campaign. The malware is distributed via phishing websites advertising a fraudulent premium version of the messaging application Telegram. The websites mimic the Russian version of the App Store and Google Play Store, indicating that the intended victims are likely Russian speakers and/or based in Russia. The fraudulent application then downloads an android package kit (APK) onto compromised systems to deploy the main FireScam payload in a multi-step process. The APK also requests several permissions prior to installing FireScam to access and modify sensitive data, as well as to install and delete other applications and to approve subsequent software updates. We assess this likely enables the threat actors to conduct reconnaissance, install additional malicious files and maintain prolonged persistence within compromised systems. Other FireScam capabilities include SMS exfiltration, screen-monitoring, notification and e-commerce transaction monitoring and the ability to manipulate the legitimate Firebase platform for data exfiltration and communication with actor-controlled infrastructure. The exploitation of APKs, Android permissions and Firebase services underscores the threat actors’ ability to manipulate legitimate tools for malicious activities. Additionally, FireScam adjusts its behaviour based on the type of environment in which it is running to avoid carrying out malicious activity within sandbox environments. It also boasts several other advanced obfuscation techniques, highlighting the sophistication of its detection-evasion capabilities.

Russian cyber criminals are using a new, highly sophisticated WordPress plugin (‘PhishWP’) in an ongoing financially motivated campaign. The campaign starts with phishing emails or fraudulent social media advertisements to trick victims into clicking on a malicious link to make a purchase. PhishWP then reportedly creates fake online e-commerce pages that can be customised to mimic legitimate payment services such as ‘Stripe’. We assess this underscores the highly sophisticated and dynamic nature of this tool. This then enables the threat actors to collect sensitive payment card details (including card numbers, expiration dates, CVV numbers and billing addresses) and to exfiltrate stolen information in real time to an integrated actor-controlled Telegram account. The threat actors also request one-time passwords (OTPs) on a separate pop-up to avoid security mechanisms while collecting information for fraudulent transactions. Additionally, PhishWP captures system information such as IP addresses, screen resolutions and user agents to replicate victims’ environments so as to conduct future attacks. We assess it is likely that the threat actors subsequently use stolen data to conduct unauthorised transactions and/or sell the information on the dark web for illicit profit. Users are also sent a fake confirmation email after completing the fraudulent transaction to enhance legitimacy and prolong detection evasion.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network; configure firewalls to block outbound communication to malicious IP addresses associated with known malware
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
  • Ensure adequate security monitoring and detection capabilities, particularly for all external-facing services and devices; this includes personal devices connected to corporate networks or applications
  • Adopt and review network authentication services, including virtual private network (VPN) services and multi-factor authentication (MFA)
  • Avoid downloading applications from untrusted third-party websites or via unsolicited messages and only use official websites and application stores to install applications and tools on devices

Our cyber word(s) of the week: Sandbox

(Source: Sibylline)

 

10 Jan 25. DoD/DCSA Announces Release of NBIS Product Roadmap. The U.S. Department of Defense’s Defense Counterintelligence and Security Agency (DCSA) has announced that its National Background Investigation Services (NBIS) Program Management Office has begun releasing its product roadmap to customers and stakeholders in the defense industry and across the U.S. government.  The NBIS product roadmap will better assist NBIS customer agencies in planning their transition to use of the system for personnel vetting requirements outlined in federal Trusted Workforce 2.0 (TW 2.0) policy. The product roadmap is developed using the Agile software development methodology. Updates to the roadmap will be communicated to customers and stakeholders throughout the NBIS development process. The NBIS program is undergoing a digital transformation and delivering capabilities grounded in validated requirements and guided by new requirements governance and acquisition oversight. NBIS digital transformation commenced on October 1, 2024, and the program is making substantial progress with its software development approach. DCSA Director David Cattler assumed leadership of DCSA in March of 2024 and has made NBIS delivery a key priority with the support of DOD and intra-agency partners, including addressing GAO concerns with the program and establishing a clear plan and path forward. In October, DOD leadership approved that plan, and DCSA has continued progress in development, including announcing a major milestone in NBIS deployment with the full transition to NBIS eApp for initiation of background investigations. NBIS is the IT system enabling the end-to-end personnel vetting process and is critical to TW 2.0, the whole-of-government effort aiming to better support the federal government and cleared industry. TW 2.0 implementation across the federal government will reduce the time required to bring new hires on board, enable mobility of the federal workforce, and improve insight into workforce behaviors. For more information on NBIS, please visit www.dcsa.mil. (Source: glstrade.com)

 

07 Jan 25. Lithuanian Armed Forces opens cyber command. The Lithuanian Armed Forces (LAF) has opened Lithuanian Cyber Command (LTCYBERCOM) with the main aim of installing strategic- and tactical-level communications and information systems (CISs). Opened on 1 January the command is a separate entity within the LAF. In addition to installing and managing CISs, the command is tasked with ensuring their interoperability within NATO, the national defence system, and other organisations’ CISs. LTCYBERCOM is also tasked with executing cyber operations for the security of the national defence system, the overall infrastructure of Lithuanian state CISs.

“Lithuanian Cyber Command is critical as an enabler of military planning and action co-ordination in cyberspace.  Many NATO allies have been practising it already. Strengthening cyber defence and effective cyber-incident management are cornerstone steps in protection against emerging threats and national security of the state,” Lithuania’s Vice-Minister for National Defence Tomas Godliauskas said in a 3 January press release from the Lithuanian Ministry of National Defence (MND).

Following a decision in 2023 LTCYBERCOM was established in July 2024 after the Lithuanian parliament (Seimas) approved an amendment to the law on the “principal structure of the armed forces” proposed by the MND.

One of the first practical steps for LTCYBERCOM is the restructuring of the MND’s information technology (IT) service to consolidate capabilities and delegate some functions to the National Cyber Security Centre (NCSC) and the Core Centre of State Telecommunications (KVTC) under the MND. The NCSC will carry out the role of the national cyber-security agency.  (Source: Janes)

——————————————————————————————————————————————————————————————————————————————————————————————————————————————–

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

————————————————————————————————————————————————————————————————————————————————————————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

January 10, 2025 by

Sponsored by Spectra Group

Spectra Group (UK) Ltd Home Page


——————————————————————————————————————————————————————————————————————————————————————————————————————————————-
10 Jan 25. South Korea launches new army MANET development. South Korean defence prime LIG Nex1 announced that it has signed an agreement worth around US$10.5m with the government-funded Defense Rapid Acquisition Technology Research Institute (DRATRI) to demonstrate new mobile ad hoc network (MANET) technologies for the Republic of Korea Army (RoKA).
LIG Nex1 added that the next-generation MANET development will include three types of communication equipment for up to brigade-level formations. The first type will be installed into surveillance and reconnaissance drones, the second type will be portable and can be carried by troops, while the third will be installed into combat vehicles. All variants will be capable of supporting uncrewed system operations.
The demonstration project is expected to be completed by 2027 with the first MANET system prototype delivered to the RoKA after six months of field trials.
“As the advancement and sophistication of weapon systems based on hyper-connectivity, hyper-intelligence, and networking rapidly progress, the swift development of next-generation communication solutions to support this has emerged as a national task,” said LIG Nex1, noting that the MANET development is expected to be integrated to ongoing RoKA modernisation efforts such as the Warrior Platform soldier system under the Army 4.0 programme.
To offset the expected reduction in manpower, the RoKA in 2018 launched its Army Tiger 4.0 programme wherein each soldier receives a ‘Warrior Platform’ comprising 33 types of personal equipment, including new communications systems, field uniforms, multi-hit ballistic vests and helmets, and sights. With each soldier effectively transformed into a sensor node, the army envisions that Tiger 4.0 will eventually take the form of a hyperconnected and artificial intelligence (AI)-driven ground combat network.
The RoKA reportedly plans to expand the Tiger 4.0 System to four battalions by 2021, four brigades by 2025, and all units by 2040. It is estimated that the effort will cost around US$1bn.
(Source: AMR)

 

09 Jan 25. Don’t Cut Corners. “The Strategic Defence Review (SDR) was launched by Prime Minister Keir Starmer to make Britain secure at home and strong abroad for decades to come” announced the United Kingdom Ministry of Defence’s website in July 2024. Mr. Starmer was a newly-minted prime minister, having led the Labour Party to victory in the UK’s General Election on 4th July.
Little time was waisted by Mr. Starmer and his colleagues initiating the drafting of a new SDR. The SDR sets out the UK’s strategic priorities and the capabilities to be sustained, modernised and acquired to meet these. The review is being led by John Healey, the UK’s Secretary of State for Defence, and is expected to be published in 2025. A team of defence and foreign policy experts are reviewing the draft. The drafting process examines evidence submitted by scores of individuals from the UK defence and security community.
In late November, reports revealed that ageing amphibious assault ships, frigates, oilers, uninhabited aerial vehicles and helicopters would be retired from the Royal Navy, British Army and Royal Air Force. Beyond this, the full scope of the SDR is yet to be known. Armada would make one modest request: It is imperative that the commitment to the British Army’s future Cornerstone and Poynting cyber and electromagnetic activities capabilities remains.
The army was originally to have received new Electronic Warfare (EW) kit to support the manoeuvre force in 2001. The Ministry of Defence contracted Lockheed Martin to provide a suite of backpack and vehicular EW systems under Project Soothsayer. Soothsayer was cancelled in 2009, not helped by $60 m cost overruns. The reconstituted army EW capability, in the form of Project Landseeker, was similarly cancelled, the ongoing requirement morphing into Cornerstone/Poynting announced in 2022 and 2023 respectively. British Army EW cadres have told your correspondent that the EW equipment they currently use is in dire need of replacement. Any further delays to the modernisation of the British Army’s EW posture would be a grave mistake. Like her NATO allies, the UK faces the return of near-peer competition and the possibility of high intensity air-land battle thanks to Russian revanchism. The upcoming SDR must guarantee that the commitment to Cornerstone/Poynting continues. (Source: Armada)

 

07 Jan 25. Advanced EW Capabilities Showcased at AOC Symposium. L3Harris demonstrated its Distributed Spectrum Collaboration and Operations (DiSCO™) system at the AOC International Symposium, showcasing real-time threat detection, data processing, and electronic warfare (EW) capabilities. L3Harris has showcased its cutting-edge Distributed Spectrum Collaboration and Operations (DiSCO™) capability in live demonstrations at the Association of Old Crows (AOC) International Symposium in Washington, D.C.
DiSCO is a resilient, vendor-agnostic Electromagnetic Spectrum Operations (EMSO) architecture that connects multiple electronic warfare (EW) systems across a distributed network for real-time threat detection and response.
The architecture integrates with both existing and future systems without extensive retrofitting, delivering flexibility in a highly dynamic environment where adversaries continue to enhance their own EMSO capabilities.
During the AOC live demos, a Seasats Lightfish autonomous vessel equipped with the L3Harris compact EW payload collected radio frequency data streamed to the cloud for real-time processing and analysis.
The L3Harris graphical user interface (GUI), displayed on military hardware, demonstrated how DiSCO enables rapid reprogramming of EW systems in the field from continental United States locations to forward operating positions and cockpits. This is enabled via L3Harris artificial intelligence and machine learning tools that assist with analysis and decision making.
The AOC event follows the successful DiSCO demo at Valiant Shield 2024, the U.S. Indo Pacific Command’s biennial field training exercise. During this event, DiSCO? successfully shared real-time radio frequency signal data between Joint Base Pearl Harbor-Hickam, Hawaii, and multiple EW payloads operating in Hawaii and in San Diego, California.
Jennifer Lewis, President, Airborne Combat Systems, L3Harris, commented, “DiSCO turns months of data analysis into minutes, enabling unprecedented speed and accuracy in detecting and acting on unknown signals. It’s the first step in laying the foundation for distributed electronic attack capabilities and enhanced sensor-to-shooter integration.” (Source: https://www.defenseadvancement.com/)

 

09 Jan 25. Tricking-up the HARM. The US Air Force is expected to introduce the Northrop Grumman Stand-In Attack Weapon into service in 2026. The missile is based on the AGM-88G Advanced Anti-Radar Guided Missile-Extended Range anti-radar weapon developed by the company. The US Air Force’s new Stand-In Attack Missile is showing potential as a versatile weapon to hold time-sensitive targets at risk thanks to its employment of a millimetric radar seeker.
Northrop Grumman’s AGM-88G Advanced Anti-Radar Guided Missile-Extended Range (AARGM-ER) appears to be a gift that keeps on giving. The weapon is forming the basis of the Stand-In Attack Weapon (SIAW) air-to-surface missile. The company won the contract to develop the SIAW for the United States Air Force (USAF) in September 2023. Reports note that the SIAW is expected to enter service with the USAF in 2026. Defence Express revealed in late November 2024 that the weapon was being earmarked as a potential strike capability against Short-Range Ballistic Missiles (SRBMs). SRBMs typically have a maximum range not exceeding 540 nautical miles/nm (1,000 kilometres/km). One potential target mentioned in the Defence Express article is the 9K720 Iskander (North Atlantic Treaty Organisation reporting name SS-26 Stone) SRBM. The 9K720 has been used extensively in the Ukrainian theatre of operations and open sources state the missile has a range of up to 270nm (500km).
Millimetric Wave
A key capability of the AGM-88G is the Millimetric Wave (MMW) radar seeker accommodating the missile. MMW seekers also equip Northrop Grumman’s AGM-88E and Raytheon’s AGM-88F HARMs (High Speed Anti-Radiation Missiles). Alongside the AGM-88G, these latter designs are the latest variant of the venerable AGM-88B/C HARM. HARM has been a scourge of ground-based air surveillance and fire control/ground-controlled interception radars since its introduction into USAF service in 1985.
The MMW radars transmit at frequencies above 30 gigahertz/GHz. These frequencies can depict targets in impressive detail. Tactically, this helps ensure the missile strikes the correct target. For example, the Radar Cross Section (RCS) of a hostile radar can be cross-referenced with an internal library of targets. The radar’s processor will match the RCS of the target with the internal library and perform the attack. Likewise, the missile can abort its attack if the RCS differs greatly. Sources close to the AGM-88E/G programmes have shared with Armada in the past that the MMW radar also aids battle damage assessment. Radar imagery can be sent by datalink from the missile to its launch platform. This imagery can be examined after the attack to ascertain the quality and effectiveness of the strike.
HARM and Iskander
Armada spoke to a senior radar engineer who confirmed that the MMW capability of the AGM-88E/F/G could offer kinetic options beyond hitting only radars. They mentioned that RCSs for targets like 9K720 launch vehicles could be stored in the missile’s radar seeker. As before, the missile’s radar could match this RCS with the imagery it is collecting for target confirmation before performing the attack.
The engineer said that loading the SIAW with RCSs of threats like the 9K720 could have added benefits. The missile could be launched in a loitering mode. With its radar activated, the SIAW could continually search for a target like an 9K720 launcher across a specific area in the radar’s field-of-view. Once such a target is discovered, the missile will press home its attack. A variant of this tactic would be to launch the missile into a pre-defined area where an Iskander launcher is, but perhaps where exact coordinates are unknown. The missile will search for the target in this area and attack the threat once discovered. The engineer continued that the missile’s blast fragmentation warhead could do significant damage to a 9K720 launcher and its missiles. A single attack could possibly take both out of the fight altogether. In fact, the radar seeker could be programmed with a myriad of time-sensitive targets on the ground.
Despite being originally developed to hit hostile radars the AGM-88E/F/G design is showing itself to have impressive tactical utility. It may not only be radar operators who fear HARMs in the air, and the damage that they can do. (Source: Armada)

 

08 Jan 25. Congress’ EMSO Champion. In an exclusive interview, Armada chats to Don Bacon, a tireless electronic warfare advocate who has recently been re-elected to the US House of Representatives.
On 3rd January Representatives and Senators for the United States’ 119th Congress will be sworn in following the Presidential and Congressional elections on 3rd November. Don Bacon will be taking his seat as Representative for Nebraska’s Second Congressional District. Mr. Bacon is not new to Congress having served as the representative for this district since 2016. He came to Congress from the US military having retired as a United States Air Force (USAF) Brigadier General. During his military career, Mr. Bacon was closely involved with Electromagnetic Spectrum Operations (EMSO). He served at Offutt airbase. Offutt is home to the USAF’s Boeing RC-135V/W Rivet Joint and RC-135U Combat Sent signals intelligence gathering aircraft.
Previous experience
Mr. Bacon shared with Armada his perspectives regarding the EMSO challenges faced by the US military and the country writ large: “As a career Electronic Warfare (EW) officer in the US Air Force, I entered Congress deeply concerned about the significant decline in the readiness of our electronic warfare capabilities.” Upon election, Mr. Bacon immediately got to work tackling this decline: “My journey to restore US EW dominance started back in 2017 when I was sworn in as a member of the 115th Congress and became a member of the House Armed Services Committee.” He reflected on his experience as a keen EW advocate within the US Department of Defence (DOD). His work backing electronic warfare in the Pentagon would prove useful in the corridors of power: “I remember being a one-star in the Pentagon between 2012 and 2014 and advocating for EW and being told at the three-star level that it was not a priority. It took getting into Congress to make a real impact.”
Budgetary realities
Unsurprisingly given his previous USAF career Mr. Bacon has taken a close interest in the US Air Force’s EW posture, and how this needs to develop: “Department of the Air Force (DAF) progress on modernising its electronic warfare capability continues to struggle with speed of progress and budget prioritisation,” he argued. “While we have had some success in keeping the USAF on task with the Gulfstream/L3 Harris EA-37B Compass Call (communications jamming aircraft) replacement programme, recent discussions with stakeholders indicate additional Congressional engagement with Air Force leadership would be helpful in building additional momentum within the Air Force to improve combat readiness and capabilities in the electromagnetic spectrum.”
Call platform currently used for jamming hostile communications systems and networks.
Available funds for EW is concerning, particular when other priorities like the ongoing modernisation of the US nuclear deterrent is taken into account: “The real issue impacting electronic warfare now is that our top line budget is too small with all the other nuclear modernisation costs going on. We are spending three percent of our gross domestic product on defence, which is a historical low going back to before the Second World War.” Reflecting the spirit of bipartisanship which Mr. Bacon is known for, he emphasised his agreement with the recent comments of Frank Kendall, Secretary of the Air Force, “that progress requires resources and right now the resources just aren’t there.”
Acquisition efficiency
Ensuring that EW capabilities and readiness receive the prioritisation they deserve is not just about money. Mr. Bacon talked about the need to improve acquisition efficiency. To this end, he has “been asked to press the Department of the Air Force on modifying its acquisition management structure to ensure a clear demand signal and more direct pathways for faster development of new electronic warfare and electromagnetic spectrum capabilities.”
Beyond the questions of acquisition and budgets, Mr. Bacon is keen to wave the EW flag in Congress and highlight the importance of EMSO throughout the wider US political community: “As the CITI (Cyber, Information Technologies and Innovation) subcommittee chair and the Electronic Warfare Caucus chair, along with my position on the Tactical Air and Land Force and Strategic Forces subcommittees, I will press the Air Force leadership to be more aggressive on improving Air Force EW/EMS modernisation and readiness. To that end, I already have hosted a member level CITI classified JEMSO (Joint EMSO) update briefing to share (the US Strategic Command’s) evaluation of current joint EMSO capabilities and highlighted a report on EA-37B force structure requirements from the Secretary of the Air Force at an in-person briefing last September.” Moreover, “I am interested in working with the Air Force leadership to ensure the DAF reorganisation ensures faster, more integrated acquisition of advanced EW/EMS capabilities.”
As the US embarks on her next political era with a new Congress and Executive, electromagnetic support operations will be firmly on the defence and national security agendas. Mr. Bacon and his colleagues will no doubt work hard to ensure that EMSO questions receive the attention they need. Pressure will continue on DOD procurement and management structures to ensure their suitability for EMSO acquisition and modernisation. (Source: Armada)

 

08 Jan 25. Verizon to enhance 5G and/or 4G LTE networks at 35 USAF bases. The upgrades are set to offer higher speeds, greater bandwidth, and reduced latency. The US Air Force (USAF) has chosen Verizon Business to implement 5G and 4G LTE network improvements across 35 installations within the nation.
This initiative is part of the Air Force’s Offer to Lease programme, which aims to provide advanced network capabilities such as additional C-Band carriers, new macro cell sites, and small cell technology.
These upgrades are set to offer higher speeds, greater bandwidth, and reduced latency for both base personnel and the local communities.
It supports the varied missions at each installation and improving the living standards for service members and their families.
The bases benefiting from this project are spread across an array of states including Alabama, Alaska, and many others, up to Washington.
Verizon Public Sector senior vice-president Maggie Hallbach said: “This is Verizon’s seventh OTL win out of eight attempts, which serves as a testament to the trust the US Air Force has in the strength and speed of our network, as well as the quality of the professional and managed services expertise they gain from our people.
“We are honoured to have Verizon Business serve as one of their most trusted partners.”
This development is a continuation of Verizon Business’s ongoing engagement with the Air Force, further expanding the company’s role in enhancing federal government and Department of Defense communications infrastructure.
The project, known as Opportunity to Lease 3, Groups A, B, and C, follows Verizon’s previous successes with OTL 1a, 1b, 2, and 2b in recent years.
This expansion allows Verizon to extend wireless advancements to over three dozen Air Force bases, adding to the 5G Ultra Wideband work previously completed at Tyndall Air Force Base in Florida.
As a result of its participation in the OTL programme, Verizon is now responsible for delivering wireless network services to a total of 72 Air Force bases across the US. (Source: airforce-technology.com)

 

07 Jan 25. Russian Rules. A new volume published by the Lightning Press covers the organisation, doctrines and capabilities of the Russian military, and contains discussions of Russia’s strategic preoccupations and foreign policy objectives.
A new book shed more light on the organisation of the Russian military and how it sees the electromagnetic spectrum as a zone of competition.
Excitement always grips the Armada editorial office when a new book is published by the Lightning Press. We have reviewed several of these readable and robust volumes in the past. Subjects tackled by this publishing house include subjects as diverse as the militaries of the Democratic People’s Repubic of Korea (DPRK) and the Islamic Republic of Iran. The Lightning Press’ author and publisher Norm Wade has penned volumes on the Chinese military, and he has been a guest on Armada’s podcasts.
In late November the company published its latest volume examining Russia’s armed forces. OpFor Smartbook-3: Russian Military Forces, Operations and Tactics comes at an opportune moment. The Russian military remains committed to its occupation of parts of Ukraine and continues to pressure Kyiv’s forces. Nonetheless, Moscow’s presence in Syria is in doubt. Russia’s President Vladimir Putin has deployed forces to Syria since 2015. Russian forces there have aimed to shore-up the regime of Syria’s erstwhile dictator during that country’s long civil war. Syria hosts two large Russian military installation; a naval base at Tartus and a large deployment at Khmeimim airbase, both on the Mediterranean coast. Mr. Assad fled on 7th December following a dramatic advance across the country by the Hay’at Tahrir al-Sham Islamist movement. With the Assad regime now deposed the future of Russia’s presence in Syria remains unclear.
As with previous volumes examining national militaries, Mr. Wade gives a detailed yet succinct discussion of Russia’s strategic and operational considerations and preoccupations. A useful guide to the composition of the Russian armed forces, their operational art and tactical doctrines also forms part of the volume. Understandably, Russia’s ongoing war in Ukraine forms a significant part of the book, as does Russian military modernisation; a process which remains ongoing despite the conflict. Also of interest is Mr. Wade’s discussion of the role of private military companies like the Wagner Group in Russia’s military posture.
Russia and the spectrum
Of particular interest to Armada is the book’s discussion of Russia’s Electronic Warfare (EW) capabilities. Frequent Armada readers will know that this is an area of great interest to us, and any new works that can shed light on these subjects are highly sought. Mr. Wade’s latest work contains a chapter examining ‘Radio-Electromagnetic Warfare’ and this title reflects the Russian term for EW.
The author reflects that Russia’s combat experience during the 2008 Russo-Georgian War was a catalyst for the revitalisation of Russia EW capabilities, particularly in the land environment. For Russian land forces, EW plays a key role in attacking the ISR (Intelligence, Surveillance and Reconnaissance) and Command and Control (C2) capabilities of their adversary. EW units and systems are integrated at every echelon in the land manoeuvre force. Not only are EW capabilities vital for conventional air-land battle, but they are also indispensable for supporting counter-insurgency operations.
Electronic warfare units comprise part of the Russian land forces’ Reconnaissance-Strike Complex (RSC), Mr. Wade continues. Hostile targets can be detected, identified and located by manoeuvre force electronic warfare systems, particularly those performing signals intelligence collection. Radars, radios and communications networks can be located via their electromagnetic emissions. The coordinates of these hostile assets are then shared with kinetic manoeuvre force elements like artillery, close air support or battlefield interdiction.
The book provides the reader with a good summary of Russian land forces’ EW unit orders-of-battle, particularly the interplay between operational-level EW brigades and their subordinate battalions. Mr. Wade makes the important point that EW brigade battalions can also be ‘fragged’ to the manoeuvre force. This process lets these operational EW capabilities directly support the tactical battle. Particularly useful is the author’s description of how EW capabilities furnish Uninhabited Aerial Vehicles (UAVs). As the war in Ukraine shows, UAVs equipped with EW payload can be particularly effective. Similarly welcome is the description of the spectrum management role played by platforms like Dziudoist, Plavsk and the RB-636 Svet-KU.
The RB-636 Svet-KU system is one of several which Russian ground forces use for electromagnetic spectrum management and deconfliction.
Mr. Wade’s latest work provides a detailed yet readable discussion of the centrality of electronic warfare in the operational and tactical doctrines of Russia’s land forces. The work also provides a good starting point for wider study of the Russian military. As the Lightning Press’ collection of works also explores the militaries of near-peer adversaries like the DPRK, Iran and the People’s Republic of China, the EW postures of these nations can be compared to those of Russia and vice-versa. (Source: Armada)

 

06 Jan 25. January Spectrum SitRep. The US Navy’s Boeing F/A-18E/F Super Hornet combat aircraft fleet will receive a comprehensive enhancement of its self-protection systems via the Advanced Electronic Warfare, or ADVEW, initiative.
Armada’s monthly round-up of all the latest electronic warfare news in the product, programme and operational domains.
ADVEW Delta Design Review
Raytheon announced via a press release on 4th December that the company had completed the Delta Design Review of the Advanced Electronic Warfare (ADVEW) system. As Armada reported in February 2024 ADVEW will equip the United States Navy’s Boeing F/A-18E/F Super Hornet combat aircraft. The new EW system replaces two existing capabilities; L3Harris’ AN/ALQ-214 integrated countermeasures system and Raytheon’s AN/ALR-63(V)3 radar warning receiver. Raytheon has stated in the past that ADVEW consolidates the attributes of these two systems into a single architecture. Moreover, the company says ADVEW will deliver improvements in performance vis-à-vis these legacy systems. The press release explained that the Delta Design Review “assessed the (aircraft’s) weapons replaceable assemblies … and how each part of the hardware system works together to meet required specifications. The review confirmed that the system can provide critical electronic attack and electronic support measures capabilities.” The programme will now move towards US government laboratory testing “to validate open mission systems compliance and to demonstrate advanced system attributes,” the press release added. Raytheon told Armada in a written statement that this recent review “is an approach to provide critical design review level material overtime.” The Delta Design Review was performed in a company laboratory and “involved the review of airframe-conducted events.”
CIRCM for Chinooks
It was revealed in early December that Northrop Grumman has been selected to provide new self-protection systems to equip the Royal Air Force’s (RAF) fleet of Boeing Chinook HC. Mk.5/6/6A heavylift helicopters. Reports disclosed that the aircraft will receive Northrop Grumman’s Common Infrared Countermeasure (CIRCM). CIRCM will help protect these helicopters against attack by heat-seeking, surface-to-air and air-to-air missiles. The United Kingdom ordered the CIRCMs via the United States foreign military sale route in July 2024. The self-protection systems will equip new Chinooks that the RAF is receiving to replace Chinook HC.Mk.6A rotorcraft that are being withdrawn, having served since the 1980s. Northrop Grumman confirmed to Armada that CIRCM will be installed on ten of the new aircraft. The company added that installation and delivery is expected in 2027. Northrop Grumman declined to state whether installation work will take place in the UK or the United States.
(Source: Armada)

 

08 Jan 25. Global: Highly sophisticated plugin elevates information theft, financial risks from cyber criminals. On 6 January, the security company SlashNext reported that Russian cyber criminals are using a new, highly sophisticated WordPress plugin (‘PhishWP’) in an ongoing financially motivated campaign. PhishWP reportedly creates fake online e-commerce pages (mimicking the legitimate payment service ‘Stripe’) to trick unknowing users into disclosing sensitive payment card details. The plugin then sends stolen information to an actor-controlled account on the messaging platform Telegram. PhishWP also bypasses security mechanisms by requesting one-time passwords (OTPs) using a separate pop-up. Additionally, it can customise checkout pages in real time; this feature underscores the highly sophisticated and dynamic nature of this tool. We assess it is likely that the threat actors subsequently use the stolen data to conduct unauthorised transactions and/or sell the information on the dark web for illicit profit. As such, this elevates information theft and financial risks to global users in the short-to-medium term. (Source: Sibylline)

 

06 Jan 25. US Navy declares initial operational capability for the Next Generation Jammer Mid-Band system. The U.S. Navy declared initial operational capability for the Next Generation Jammer Mid-Band (NGJ-MB) system in December, bringing a quantum leap in capability over legacy systems with drastic increases in power, target flexibility and jamming technique for naval aviation operations worldwide.
“Next Generation Jammer Mid-Band improves our fleet’s warfighting advantage in the electromagnetic spectrum,” said Rear Adm. John Lemmon, Program Executive Officer for Tactical Aircraft Programs. “This system provides enhanced capabilities to deny, distract and disorient adversaries’ radars, protecting our naval aviators and allowing them to carry out their missions in contested airspace.”
The fleet got a preview of the jammer’s high-end capabilities during Abraham Lincoln Carrier Strike Group’s five-month deployment this year. Electronic Attack Squadron (VAQ) 133 deployed with the system aboard the USS Abraham Lincoln (CVN 72), marking the first time Next Generation Jammer Mid-Band was used both deployed and in combat.
IOC signals that the design, testing and production of this capability meet the logistical needs of the carrier air wings and EA-18G Growler squadrons.
“What an incredible day for the U.S. Navy, our Australian partners, and the Airborne Electronic Attack (AEA) community,” said Capt. David Rueter, Airborne Electronic Attack Systems (PMA-234) program manager. “The achievement of NGJ-MB IOC is a positive reflection on the hard work, innovation and resilience from a dedicated team of government and industry professionals who have developed and fielded this critical capability to the warfighters.”
The NGJ-MB system, developed by Raytheon, an RTX business, is part of a larger NGJ system that will augment and ultimately replace the legacy ALQ-99 Tactical Jamming System currently used on the EA-18G Growler. NGJ-MB uses the latest digital, software-based and electronically scanned array technologies and provides enhanced AEA capabilities to disrupt, deny, and degrade enemy air defense and ground communication systems.
“NGJ-MB will boost our fleet’s ability to maintain spectrum dominance. Yielding new capabilities is critical for addressing current and future threats. The era of isolated surface-to-air missile systems, which operate within a non-agile and limited frequency range, is behind us.” stated Lt. Cmdr. Michael Bedwell, EA-18G Naval Flight Officer and NGJ-MB Deputy Integrated Product Team Lead.
PMA-234 is responsible for acquiring, delivering and sustaining AEA systems, providing combatant commanders with capabilities that enable mission success. (Source: ASD Network)

 

07 Jan 25. Taiwan: Spike in cyber attacks underscores elevated risks stemming from Chinese threat actors. On 6 January, international news outlets reported that the number of attempted cyber attacks conducted against Taiwan doubled in 2024 compared to 2023, reaching a total of approximately 2.4 m attempts per day. The majority of attempts originated from China, likely as part of Beijing’s ‘grey-zone’ tactics aimed at undermining Taiwan’s government. Threat actors typically try to exfiltrate sensitive data such as intellectual property and personally identifiable information (PII) in a bid to destabilise Taiwanese industry. Additionally, various attacks disrupted operations within critical national infrastructure (CNI) sectors via distributed denial-of-service (DDoS) campaigns. Attacks often spiked and/or coincided with military drills around the island, pointing to Beijing’s increased adoption of cyber activity to bolster its military and security posture. Although most attacks were detected and blocked, we assess the reports are indicative of a more comprehensive Chinese cyber strategy vis-à-vis Taiwan. As such, Taiwan faces long-term security, espionage and operational risks. (Source: Sibylline)

06 Jan 25. Russia: New mobile malware variant raises security, financial risks for Android users. On 4 January, international news outlets reported that unnamed threat actors are using a new mobile malware variant (‘FireScam’) to target Android users in an information theft campaign. FireScam is distributed via phishing websites advertising a fraudulent premium version of the mobile messaging application Telegram. The phishing websites mimic the Russian version of the App Store and Google Play Store, indicating that the intended victims are likely Russian-language speakers and/or based in Russia. FireScam can steal sensitive information, monitor transactions and execute additional payloads. The malware also boasts advanced obfuscation techniques, underscoring the threat actors’ sophistication. We assess that threat actors will likely either sell the stolen data on the dark web or exploit it to hijack user accounts for financial profit. As such, this increases the threat of future cyber criminal exploitation, elevating security and financial risks to Russian-speaking Android users in the short term. (Source: Sibylline)

 

03 Jan 25. Global: New cyber attack method underscores increased security, financial risks facing web users. On 2 January, international news outlets reported on a new type of cyber attack (‘DoubleClickjacking’) targeting global web users. The attack starts with the perpetrators displaying threat actor-created prompts on legitimate websites to lure users into clicking a link. This then redirects users to a new web page, whereupon they are asked to complete a captcha verification (the process whereby users are asked to confirm that they are human operators). The new technique manipulates the timing difference between mouse-clicking actions on the webpage; when a user lands on the webpage and double clicks on the captcha button, the page content changes very quickly (so quickly that the user does not notice). When the user clicks for the second time (as part of the double click), they unintentionally click on a malicious button. Threat actors are then able to conduct malicious activity such as hijacking user accounts, authenticating additional applications and facilitating financial transactions. Notably, the new technique employs methods to bypass traditional webpage clickjacking security mechanisms, highlighting the continued development of threat actors’ sophistication. It also underscores the elevated security and financial risks facing global users in the short-to-medium term, particularly as the attack technique can impact any website. (Source: Sibylline)
——————————————————————————————————————————————————————————————————————————————————————————————————————————————-
Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.
Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

—————————————————————————————————————————————————————————————————————————————————————————————————————————————–

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

January 3, 2025 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

———————————————————————————————————————————————————————————————————————————————————————————————————————————————-

23 Dec 24. UK MoD says ‘no plans to cancel’ Morpheus communications project despite delays. The UK Ministry of Defence (MoD) told Janes on 20 December there are no plans to cancel the Morpheus project design to deliver a modernised army communication and information system (CIS). In a 4 December parliamentary response, Minister for Defence Procurement Maria Eagle said, “Morpheus is a project within the Land Environment Tactical Communication and Information Systems (LETacCIS) programme and is currently delayed. Work to reset the project remains ongoing, and an Independent Project Review, led by the Cabinet Office’s Infrastructure and Projects Authority (IPA), will take place in early 2025 and inform next steps.” Eagle added on 11 December that “as of 5 December 2024 total expenditure for the Morpheus project is GBP828m (USD1bn)”. In response to a Janes request for clarification on the meaning of “reset the project”, the MoD told Janes on 20 December that “the ongoing work with the IPA is focused on how best to deliver the benefits of the projects in the most timely and efficient manner for defence”. For the IPA, “it’s more about providing recommendations on the best way to deliver [the Morpheus project]”, an MoD press officer told Janes on 18 December, adding that all requirements and objectives for the project remain valid. In April 2017 General Dynamics UK (GDUK) won an MoD contract, known as Evolve to Open Transition Partner (EvO TP), which sought to transition the army’s existing tactical communications system, Bowman, with an open-modular modernisation. (Source: Janes)

 

02 Jan 25. Global: New software vulnerability heightens disruption, operational risks to industrial systems. On 30 December, international news outlets reported that threat actors are exploiting a newly identified software vulnerability (CVE-2024-12856) to deploy the ‘Mirai’ botnet. The vulnerability affects Four-Faith routers (versions F3x24 and F3x36) and exposes hardcoded default credentials. Unnamed threat actors first obtained access to the vulnerable devices via brute force techniques, before then exploiting CVE-2024-12856 to inject code remotely so as to conduct malicious activity. While CVE-2024-12856 can only be exploited by authenticated users, it allows threat actors to obtain post-authentication administrative-level privileges. We assess this highlights the possible impact of exploiting said vulnerability on infected systems. Mirai is typically used to conduct large-scale distributed denial-of-service (DDoS) attacks against Internet-of-Things (IoT) devices. Additionally, Four-Faith routers are often used within operational technology (OT) environments to monitor and control industrial processes. We assess this will raise the operational disruption risks in the short term, as patches and remediation guidelines are still in development. (Source: Sibylline)

 

31 Dec 24. On 30 December, international news outlets reported that an unnamed Chinese state-sponsored advanced persistent threat (APT) group infiltrated systems in the US Treasury Department. It reportedly accessed employee workstations and unclassified documents via a third-party vendor. The breach was first detected on 2 December, while the Treasury Department was notified on 8 December.

SIGNIFICANCE

  • The threat group stole an application programming interface (API) key (a unique identifier used to authenticate users and programmes) to gain access to the third party remote management vendor’s systems (‘BeyondTrust’). It subsequently exploited two zero-day vulnerabilities (CVE-2024-12356 and CVE-2024-12686) to hijack instances used by the Treasury Department and remotely steal sensitive information. We assess this underscores the elevated security risks facing government agencies emanating from the software supply chain.
  • The full impact of the compromise is yet to be determined as investigations by the Treasury Department, the Cyber Security and Infrastructure Security Agency (CISA) and the FBI are ongoing. The classification of the compromised documents and the seniority of the targeted workstations also remain unclear.
  • This incident follows several reports that emerged in November regarding a large-scale cyber espionage campaign conducted by the Chinese state-sponsored group ‘Salt Typhoon’ against several high-profile US telecommunications providers. We assess this points to the scale and resources of Chinese state-sponsored cyber espionage and information-theft outfits amid escalating geopolitical tensions.

FORECAST

We assess there is a realistic possibility that the scale and impact of this campaign will expand in the coming weeks as investigations continue. The threat group was able to compromise multiple customer accounts (including the Treasury Department) as part of the breach. Following the detection, the vendor shut down all compromised accounts, revoking the affected API key to prevent additional compromises. While there is currently no evidence that the threat actors retain access to the agency’s systems, there is a realistic possibility that they have created new user accounts and changed credentials while maintaining access to the compromised systems.

We assess that the impact and scale of this campaign will possibly expand as details continue to emerge in the coming weeks. Notably, the vendor also provides cyber security and remote management services for other government agencies, tech firms, healthcare entities and energy/utility providers. As investigations are ongoing, there is a realistic possibility that additional reports of data breaches will emerge due to the highly sensitive nature of the data contained within the aforementioned sectors. Should this be the case, stolen data will possibly be used in follow-on cyber attacks, heightening the security and social engineering risks facing affected sectors in the short term.

Chinese state-sponsored groups are likely to conduct additional cyber operations in the short term, exacerbating espionage and information-theft risks facing US government and critical national infrastructure (CNI) sectors. In October, Salt Typhoon reportedly compromised several high-profile US broadband providers (including AT&T, Lumen Technologies and Verizon) in a cyber espionage operation. The breach resulted in the exfiltration of customer call records as well as conversations of US government officials and sensitive information pertaining to law enforcement-authorised wiretapping. In November, it transpired that the same group attempted to steal sensitive data from the telecommunications provider T-Mobile, likely as part of the same cyber espionage campaign. In August, another Chinese state-sponsored group, ‘Volt Typhoon’, reportedly exploited a zero-day vulnerability (CVE-2024-39717) for several months to target US-based internet and managed services providers, as well as the IT sector more broadly. These reports point to the consistency of Chinese state-sponsored cyber operations against US government and CNI sectors; we assess that additional attacks are likely in the short term.  (Source: Sibylline)

————————————————————————————————————————————————————————————————————————————————————————————————————————————————

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

————————————————————————————————————————————————————————————————————————————————————————————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

December 30, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

—————————————————————————————————————————————————————————————————————————————————————————————————————————————–

23 Dec 24. Global: Espionage campaign by North Korean group points to risks facing nuclear, aerospace sectors. On 19 December, the cyber security firm Kaspersky reported that a North Korean state-sponsored group, ‘Lazarus’, targeted at least two employees at the same nuclear-related entity in a cyber espionage operation. The operation was highly likely part of a wider cyber espionage campaign (‘Operation Dream Job’) that has been ongoing since at least 2020. The threat actors deliver trojanised virtual network computing (VNC) software under the guise of a skills assessment for IT roles. Notably, the group was observed using the modular malware ‘CookiePlus’ to download additional malware on compromised systems, which is an uncommon strategy for Lazarus. We assess this highlights the group’s sustained efforts to improve its arsenal and detection-evasion capabilities. We also assess there are elevated targeting and security risks facing employees in the nuclear and aerospace sectors in the long term due to the longevity of Operation Dream Job and CookiePlus’ likely ongoing development. (Source: Sibylline)

 

16 Dec 24. Invited by NATO’s Allied Command Transformation (ACT), Indra demonstrated the concept and capabilities of a new last generation Cyber Situational Awareness System in one of the world’s largest collective cyberdefence exercises, CYBER COALITION 2024, held in Estonia from December 2 to 6. The platform (called CySAS, Cyber Situational Awareness System) provides a real-time view of operations being conducted in and through cyberspace by both allies and adversaries. The system analyses events occurring in Cyberspace and evaluates their impact on the mission’s course of action to assure its success. That means it offers a global vision of enormous value, helping to make the best decisions and react more quickly to any situation affecting an ongoing operation. Indra led the deployment of this concept and capability in the exercise, with the participation of Airbus (France) and Leonardo (Italy) as strategic subcontractors. The test and experimentation campaign, led by ACT, benefited from the collaboration of the Allied Command Operations (ACO), the Spanish Joint Cyberspace Command (MCCE) and the Allied Joint Force Command Naples (JFCNP). The feedback from the NATO community and other stakeholders during the CYBER COALITION 24 demonstration was extremely positive and the lessons learned will be used to further fine tune the concept, with the ultimate goal of securing the most advanced capabilities for the Alliance. Indra’s leadership in this initiative underscores the company’s confidence in driving NATO’s Digital Transformation and Cyberspace Operations Strategy. The conceptualisation of this capability facilitates NATO’s readiness to conduct multi-domain operations, where cyber defence is critical, given the presence of the Cyberspace domain in all other Defence domains. The conceptualisation of this capability facilitates NATO’s readiness to conduct operations in both the cyberspace domain and in multi-domain scenarios, where cyber defence is present and decisive. In addition to Indra’s role in the project, it is also the coordinator of the EU’s ECYSAP (European Cyber Situational Awareness Platform) project, one of the first and most important cyber defence initiatives fostered by the EU. This European project will now continue with ECYSAP EYE, where Indra will coordinate the development of even more advanced capabilities, which will, in turn, strengthen the capabilities of the European Union’s Command and Control System currently under development. All these projects contribute to strengthening Europe and NATO’s technological sovereignty and strategic autonomy, demonstrating Indra’s ability to bring together and coordinate consortia that drive the development of cutting-edge technologies and deliver new capabilities. It all means further progress towards achieving the objectives set out in Indra’s strategic plan, Leading the Future, of becoming a benchmark company in the sector that acts as a driving force in the industry. (Source: joint-forces.com

 

20 Dec 24. Cyber Update Key points.

  • A new backdoor is being used to target firms in China and the US, elevating security and information theft risks from the Chinese state-sponsored group, ‘Winnti’ (see Sibylline Cyber Daily Analytical Update – 16 December 2024).
  • The Russian state-sponsored actor ‘Earth Koshchei’ co-opted legitimate red team techniques to target government and military entities, pointing to increased security risks to the sectors (see Sibylline Cyber Daily Analytical Update – 17 December 2024 and our Technical analysis below).
  • South Asian threat group ‘Bitter’ is targeting Turkish defence entities, heightening cyber espionage risks in the medium term (see Sibylline Cyber Daily Analytical Update – 18 December 2024 and our Technical analysis below).
  • A new phishing operation to steal Microsoft Azure credentials has been targeting European entities, increasing the security and phishing risks to firms.
  • New malware attacks against industrial control systems (ICS) highlight ongoing security risks facing operational technology (see Sibylline Cyber Daily Analytical Update – 20 December 2024).

Technical analysis of weekly stories

In October, the Russian state-sponsored group Earth Koshchei (also known as ‘APT29’) was observed abusing legitimate red team techniques in a cyber espionage campaign. It is suspected that the group used a rogue remote desktop protocol (RDP) attack methodology, dubbed ‘rogue RDP’, to obtain partial control over targeted devices. The attacks begin via spear phishing emails sent to academic researchers, government and military forces, think tanks and Ukrainian targets. The email contained a rogue RDP configuration file that, if opened, instructed targeted devices to connect to a foreign RDP server via one of the almost 200 RDP relays established by Earth Koshchei during their pre-planning phase. The rogue RDP technique uses a man-in-the-middle (MITM) proxy in front of the rogue RDP servers to intercept connection requests to a legitimate server and subsequently redirects the user to the rogue server. Upon establishing the malicious connection, the rogue server conducts various malicious activities including deploying malicious scripts and altering system settings on the infected device. This grants partial control, facilitating the exfiltration of strategic data. During the pre-planning phase, Earth Koshchei set up over 200 typosquatted domains for the malicious RDP connections highlighting the highly premeditated nature of the campaign. The use of red team techniques and tools in malicious operations is not uncommon. However, it underscores the security risks to businesses associated with publicising red team tools and techniques.

The South Asian threat group Bitter targeted defence organisations in Turkey in a spear phishing campaign during November for cyber espionage purposes. The phishing emails used by the campaign contained a compressed archive (RAR) file pertaining to banking and public infrastructure initiatives in Madagascar. If opened, a payload was executed to install the ‘WmRAT’ malware. If there was no successful communication from WmRAT, additional commands were run to download and install the ‘MiyaRAT’ malware. WmRAT is a standard remote access trojan (RAT) that gathers basic system information, downloads files and runs arbitrary commands on a targeted system. MiyaRAT is similar in functionality to WmRAT; however, MiyaRAT is used against specified high-value targets, as it is only used sporadically. This highlights the likelihood of future development of this malware and its increased usage against more strategic targets.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security-detection systems to detect potentially malicious samples on the network
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
  • Ensure adequate security monitoring and detection capabilities, particularly for all external-facing services and devices; this includes personal devices connected to corporate networks or applications
  • Adopt and review network authentication services, including virtual private network (VPN) services and multi-factor authentication (MFA)
  • Avoid downloading applications from untrusted third-party websites or via unsolicited messages and only use official websites and application stores to install applications and tools on devices. (Source: Sibylline)

 

20 Dec 24. Global: New malware operations highlight ongoing security risks facing OT, ICS systems. On 17 December, the cyber security firm Forescout reported on new malware attacks against industrial control systems (ICS) that are capable of halting engineering processes. The research identified two attacks targeting Mitsubishi and Siemens engineering workstations between August and November. The first attack chain used ‘Ramnit’ against Mitsubishi workstations, a modular malware used to download additional plugins to steal data and establish prolonged persistence. Similarly, a new malware cluster (‘Chaya_003’) targeted Siemens workstations to conduct system reconnaissance and disrupt operations. Both attacks highlight an evolution in operational technology (OT)-specific cyber operations, in which existing malware is tailored to infect (and propagate within) ICS systems. Notably, the attacks used legitimate services for command-and-control (C2) to complicate threat detection, underscoring the sophistication of the campaigns. OT systems are increasingly attractive targets for various threat actors, especially in the absence of comprehensive security measures surrounding ICS and OT systems. As such, we assess that long-term elevated security risks will continue to face OT and ICS systems. (Source: Sibylline)

 

18 Dec 24. US Army extends Palantir’s contract for its data-harnessing platform.  The U.S. Army has awarded Palantir a $400.7 m contract to continue providing its artificial intelligence-enabled Vantage system as the service’s main data platform, the company announced Wednesday. The contract covers a period of up to four years and could ultimately be worth nearly $620 m if additional options are exercised. The service first brought Palantir on to provide its Army Data Platform, or ADP, in 2018, taking roughly 180 disparate data sources across the enterprise and consolidating them into one ecosystem.

“The Army has leveraged Palantir’s software to transform how it uses data and artificial intelligence (AI) to more effectively perform essential missions and enable faster decision-making across the force,” the Dec. 18 company statement reads.

The capability grew from a focus on a data platform that could help understand personnel and combat readiness to a system that “powers warfighters at every echelon and supports a diverse set of use cases across every data domain including readiness, logistics, recruiting, force management, talent management, financial management, risk management and installation management,” according to the statement.

The Army plans to continue to grow the capability.

“Our continuous addition of new AI capabilities enables the Army’s own ability to develop applications and incorporate the benefits of effective data analysis across nearly every high-priority mission in the Army,” Akash Jain, Palantir USG president, said in the statement.

As emerging technologies are developed, they will be introduced into Vantage on a continuous basis, according to the company.

Vantage now has over 100,000 users within the service and that number is growing, Palantir said.

Palantir’s business with the Defense Department and particularly with the Army has grown dramatically since 2018 when it won, in a head-to-head competition with Raytheon, a contract to provide the Army a new tactical version of its Distributed Common Ground System-Army, or DCGS-A, an intelligence analysis platform.

The company famously sued the Army over its DCGS-A procurement strategy in 2016 — and won — prior to scoring the new contract for the system. Since then, the Army has taken different approaches in how it procures software capabilities and is developing a software acquisition policy that outlines how to best work with the software industry to obtain the right capability for the service at a much faster pace. (Source: Defense News Early Bird/Defense News)

 

19 Dec 24. UK and Norway join forces to counter eavesdropping. The UK and Norwegian governments are to share best practice and new technologies to detect and expose eavesdropping devices. The UK and Norwegian governments have announced an agreement to work more closely together on research and development of technical security.  The agreement, between the UK National Authority for Counter-Eavesdropping (UK NACE) and the Norwegian National Security Authority (NSM), extends an already mature partnership which has seen the 2 authorities share national security information and best practice.  Technical security includes the identification of covert devices used to transmit data, which can either be used to eavesdrop or to launch other types of attack, including cyber-attacks.  UK NACE is part of the Foreign, Commonwealth and Development Office (FCDO) and is the UK’s dedicated National Technical Authority (NTA) for technical security. It provides guidance and training across government and national security communities in the UK and with international partners.

Stephen Doughty, Minister for Europe, North America and UK Overseas Territories said: “UK security is indivisible from European security – and we are stronger when we stand together. Norway is one of our closest defence and security partners, and I welcome this agreement, which will further strengthen our collective resilience against threats from hostile states as part of our new Strategic Partnership. The new agreement with the NSM builds on existing work between the UK and Norway, both members of the Joint Expeditionary Force group of nations. The agreement will see the 2 nations share resources, expertise and information to achieve mutual goals, and combine strengths for innovation and development.”

UK NACE is already partnered with leading UK universities on the development of technical security research and development, including developing new search equipment technology.

With its roots dating back to 1945, UK NACE was established as the lead government organisation in the field of technical security across the UK government after it became apparent that British embassies located in the newly-formed communist Eastern Europe were at risk from the threat of technical espionage attack. With eavesdropping and surveillance technology reaching new heights in its accessibility, capability and concealment, UK NACE is committed to collaboratively work on tackling modern technical threats with partners across government and friendly foreign governments. Its focus on research and innovation has helped it to enable effective risk mitigation strategies and has earned recognition and respect across the global national security community. (Source: https://www.gov.uk/)

 

18 Dec 24. In an important milestone for Northrop Grumman Corporation’s (NYSE: NOC) developed Integrated Battle Command System (IBCS), Poland’s Ministry of National Defense declared Initial Operational Capability (IOC) for the first IBCS-enabled battery of Poland’s WISŁA medium range air defense program.

  • With the deployment of IBCS, a U.S. Army program of record, Poland will now field one of largest, most capable air and missile defense forces in the world, with the ability to integrate air and missile defense across U.S. and Polish forces during combined operations.
  • A second battery is expected to achieve IOC by the end of this year.
  • In February, the United States and Polish governments signed a letter of offer and acceptance for IBCS to also serve as the core battle management command and control system for Poland’s NAREW short range air defense program in addition to phase two of the WISŁA medium range air defense program.

Kenn Todorov, vice president and general manager, global battle management and readiness, Northrop Grumman: “Poland’s declaration of initial operational capability for IBCS proves the system’s readiness and groundbreaking capability to help warfighters defeat the complex threats of today and tomorrow. IBCS is seeing an increased demand from allies and partner nations worldwide looking to modernize their air and missile defense systems in our contested environment.”

Details on IBCS and the WISŁA and NAREW Programs:

In 2018, the Polish government selected IBCS to serve as the centerpiece for its WISŁA medium range air defense modernization program, becoming the first U.S. ally to acquire the system. Poland declared Basic Operational Capability last year.

Prior to the LOA signed in February, Northrop Grumman and Poland’s Ministry of National Defense signed an offset agreement enhancing Polish defense capabilities through Northrop Grumman technology transfers that will help Polish industry to manufacture, integrate and test IBCS’ critical defense technologies.

The offset agreements will support Polish industry and their sovereign production and maintenance capabilities for NAREW and WISŁA by creating high-technology jobs for Poland in several fields, including engineering, manufacturing, supply chain and logistics and maintenance support. Poland is working with the U.S. government for deliveries of IBCS equipment racks and software to be installed in operations centers designed, manufactured and delivered in partnership with Polish industry. This delivery approach is tailorable and allows for significant industrial participation and adaptation to meet Poland’s unique air defense needs.

IBCS is a revolutionary command and control system that unifies current and future systems regardless of source, service or domain. Through its network enabled, modular, open and scalable architecture, IBCS gives warfighters capabilities they never had before by fusing sensor data for a single actionable picture of the full battlespace. This ready now capability gives warfighters more time to make decisions on how best to defeat threats and is a foundational element for enabling joint and coalition, multi-domain operations. IBCS is in production, being fielded in Poland, and planned for deployment in Defense of Guam as part of the U.S. Army program of record for integrated air and missile defense modernization.

Northrop Grumman is a leading global aerospace and defense technology company. Our pioneering solutions equip our customers with the capabilities they need to connect and protect the world, and push the boundaries of human exploration across the universe. Driven by a shared purpose to solve our customers’ toughest problems, our employees define possible every day.

 

16 Dec 24. Partnership to Provide Portable Defense Communications Elsight and tukom’s partnership will bring a proven, portable wireless communication system to the DACH region, optimized for UAVs, UGVs, and for its non-line-of-sight capabilities. Elsight and tukom have formed a partnership to bring battlefield-proven, portable wireless communications to the DACH region, optimized for unmanned aerial vehicles (UAVs) and unmanned ground vehicles (UGVs). Located and active in the DACH region, tukom is dedicated to delivering best-in-class solutions and consulting services in the fields of telemetry, aerospace, and defense. Elsight has designed and developed a lightweight, highly reliable communications system known as Halo. After several successful years in the commercial market, Halo has been optimized for its non-line-of-sight (NLOS) capabilities.  By aggregating multiple IP links from public and private cellular, satellite, and RF channels, the Halo provides securely bonded, uninterrupted C2, telemetry and video communications even in the most challenging environments. tukom offers expert sales, service, training, and consulting for the leading military-grade platforms across various industries including aerospace, defense, and telecommunications. tukom’s range of applications extend over the whole telemetry process, from data acquisition, the transfer and storage of telemetry data, data processing and analysis.

tukom CEO, Matthias Brechmann said, “Today’s CONOPS require a new set of capabilities to maintain communications throughout volatile terrains while being portable for all types of field operations. We view this partnership with Elsight as strategic in providing our customers with innovative connectivity given the changing military landscape.”

Yoav Amitai, CEO of Elsight, commented, “Given tukom’s knowledge base and experience in military-grade telemetry communications, they are the perfect partner to spearhead the penetration of the DACH market for our Halo and other connectivity products.

“Elsight excels in the development of highly reliable, secure wireless communication systems that fulfill many extreme requirements for performance, reliability and the surrounding environment. We are excited to work with tukom, helping them to expand their footprint in the region.” (Source: https://www.defenseadvancement.com/)

 

19 Dec 24. New Tactical Radio Test Set Unveiled for Military Communications Systems. Astronics has launched the ATS-3200 RTS, an advanced tactical radio testing solution that allows users to optimize both legacy and next-generation communication platforms with a single, versatile tool. Astronics Corporation is launching the ATS-3200 Radio Test Set (RTS), a next-generation tactical radio testing solution engineered for military communication systems.  The benchtop solution builds on the company’s ATS-3000 and ATS-3100 series, and incorporates the same advanced technology selected by the U.S. Army in the competitively awarded TS-4549/T program.  The ATS-3200 RTS is now available commercially, empowering users to optimize both legacy and next-generation communication platforms with a single, versatile tool. Designed with expandability and customization in mind, the ATS-3200 RTS delivers all the trusted capabilities of its predecessor, the ATS-3100 RTS, with breakthrough enhancements.   New features include an integrated Unit Under Test (UUT) power supply and built-in MIL-STD-1553 functionality, ensuring seamless support for critical communication protocols such as SINCGARS, SRW, WNW, and HAVEQUICK. This platform enhances flexibility, enabling users to protect investments in legacy systems while seamlessly adopting emerging technologies. The ATS-3200 RTS is a flexible, software-driven, future-proof system designed for rapid upgrades to meet evolving technological demands. With its intuitive touch interface, the platform streamlines operations, enabling fully automated testing without requiring extensive operator training. Astronics offers a comprehensive library of Test Program Sets (TPSs) for tactical radios across virtually all Original Equipment Manufacturers (OEMs), providing flexibility and scalability for any mission. For added efficiency, operators using both the ATS-3200 RTS and the newly launched ATS-6100 handheld RTS can benefit from a unified interface, ensuring a smooth transition from depot to field.

Jim Mulato, President of Astronics Test Systems, commented, “In a world where reliable communication is mission-critical, especially on the battlefield, the ATS-3200 RTS transforms how tactical radios are tested and maintained.  This innovative solution ensures that communication systems remain dependable, reduces maintenance costs, and maximizes mission readiness for our military personnel. Astronics is committed to delivering the tools our armed forces need to succeed in any environment.” (Source: https://www.defenseadvancement.com/)

———————————————————————————————————————————————————————————————————————————————————————————————————————————–

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

 

————————————————————————————————————————————————————————————————————————————————————————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

December 19, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

—————————————————————————————————————————————————————————————————————————————————————————————————————————————

18 Dec 24. Northrop Grumman Corporation (NYSE: NOC) has been selected as the prime contractor to deliver nuclear command, control and communications (NC3) aircraft for the U.S. Navy’s Take Charge And Move Out (TACAMO) mission. The Northrop Grumman-led industry team will deliver the E-130J to relieve the U.S. Navy’s current E-6B Mercury fleet of the TACAMO mission.​

  • Northrop Grumman has invested more than $1bn in digital engineering and manufacturing capabilities that will assist in rapidly designing, building, testing and sustaining the E-130J.
  • The company has been a key industry partner with the U.S. Navy as a prime aeronautics manufacturer for decades by serving as the prime contractor on the U.S. Navy’s E-2D Advanced Hawkeye and the MQ-4C Triton as well as providing support for the E-6B Mercury TACAMO fleet.
  • The effort will incorporate Northrop Grumman’s technology leadership in advanced manufacturing, agile design, digital engineering and weapon system integration expertise to take advantage of Day One readiness across the Northrop Grumman-led industry team​.

Jane Bishop, vice president and general manager, global surveillance division, Northrop Grumman: “Our performance on Navy programs like the E-2D and E-6B prove we deliver on what we promise, and we will bring this expertise in helping the Navy deliver the E-130J on time and optimized for this strategically important mission.”

The U.S. Navy’s TACAMO mission provides connectivity between the National Command Authority and U.S. nuclear forces. The Navy currently operates a fleet of E-6B Mercury aircraft to provide survivable, reliable and endurable airborne command, control and communications between the National Command Authority and U.S. forces. The E-130J will modernize this critical strategic deterrent mission.

Northrop Grumman’s E-130J TACAMO industry team of Lockheed Martin Skunk Works ®; Raytheon; Crescent Systems, Inc; and Long Wave Inc. has vast knowledge and expertise in delivering critical command and control and nuclear enterprise capabilities​ to meet the U.S. Navy’s E-130J TACAMO requirement.

Northrop Grumman is a leading global aerospace and defense technology company. Our pioneering solutions equip our customers with the capabilities they need to connect and protect the world, and push the boundaries of human exploration across the universe. Driven by a shared purpose to solve our customers’ toughest problems, our employees define possible every day.

 

18 Dec 24. DOD Releases Chemical and Biological Defense Program Enterprise Strategy. The Department of Defense released today, the 2024 Chemical and Biological Defense Program (2024 CBDP) Enterprise Strategy. It replaces the 2020 CBDP strategy and positions the Department to ensure the total force to carry out its missions in the face of advanced chemical and biological threats. Taking its lead from the 2022 National Defense Strategy, this strategy prioritizes delivery of operationally relevant chemical and biological defense (CBD) capabilities at speed and scale, to sustain and strengthen U.S. deterrence against the People’s Republic of China as the pacing challenge and Russia as the acute threat. The new strategy reinforces other strategic guidance including the 2023 Strategy for Countering Weapons of Mass Destruction, inaugural National Defense Industrial Strategy, and the Biodefense Posture Review. It also calls for tighter integration of CBD capabilities with international Allies and partners to ensure our combined armed forces can deter or prevail against advanced chemical and biological threats.

“Strategic competition and rapid technological changes are making chemical and biological threats harder to defend against and increasingly attractive to adversaries,” said Ian Watson, deputy assistant secretary of defense for chemical and biological defense. “This strategy creates the urgency and change necessary to continue to outpace our adversaries and the threat.”

The CBDP develops chemical and biological defense material capabilities for all the Military Services. DoD is increasingly prioritizing CBD modernization to ensure the Joint Force is equipped to carry out all its missions in the face of chemical and biological threats.

To deliver operationally relevant CBD capabilities at speed and scale, the strategy aligns the Department’s efforts in four ways:

  • Generate material solutions that increase decision space, reduce initial operational impact, and rapidly restore combat power.
  • Pursue technical enablers and innovative approaches that accelerate capability delivery at sufficient scales.
  • Posture the Chemical and Biological Defense Program around delivering operationally relevant capabilities at speed and scale.
  • Leverage and expand interagency, international, industry, and academic partners.

You can read the full strategy on the DoD website here:  chrome-extension://efaidnbmnnnibpcajpcglclefindmkaj/https://media.defense.gov/2024/Dec/18/2003615893/-1/-1/0/CHEMICAL-AND-BIOLOGICAL-DEFENSE-PROGRAM-ENTERPRISE-STRATEGY-2024.PDF

The Office of the Assistant Secretary of Defense for Nuclear, Chemical, and Biological Defense Programs (OASD(NCB)) leads DoD efforts to ensure a safe, secure, and effective U.S. nuclear deterrent. As the world returns to Great Power competition and the recognition that threats against the United States, its allies, and its interests are both proliferating and becoming more difficult to challenge, OASD(NCB) is at the forefront of U.S. efforts to sustain and modernize the nuclear deterrent. From the operational, to the administrative, to the speed of response and production, OASD(NCB) is reshaping the way DoD meets and responds to weapons of mass destruction threats. (Source: U.S. DoD)

 

18 Dec 24.  Turkey: Defence entities face heightened cyber espionage risks from South Asian threat group. On 17 December, the cyber security firm Proofpoint reported that the cyber espionage group ‘Bitter’ targeted Turkish defence entities with new malware (‘MiyaRAT’) in November. The campaign began via spear phishing emails containing a malicious RAR archive file. If opened, the MiyaRAT is downloaded alongside ‘WmRAT’, a previously observed Bitter malware. MiyaRAT is capable of data exfiltration, remote control and command execution, among other functions. Notably, this malware campaign is only deployed sporadically against specific high-value targets, pointing to the targeted nature of the operation. Bitter is a suspected South Asian cyber espionage group that tends to target government bodies and organisations across all of Asia, indicating a potential expansion in the group’s victim pool. As such, we assess there will be heightened cyber espionage risks facing defence entities in Turkey in the medium term. (Source: Sibylline)

 

17 Dec 24. US Army to begin SIGINT integration into Terrestrial Layer System. US Army’s Program Executive Office Intelligence, Electronic Warfare and Sensors (PEO IEW&S) is on pace to begin integration of signals intelligence (SIGINT) capability aboard the Terrestrial Layer System (TLS) by boreal spring 2026.

The SIGINT capability will be integrated into Stryker-based TLS Brigade Combat Team (TLS BCT) and the TLS Echelons Above Brigade (TLS EAB) version of the system, according to Program Executive Officer IEW&S US Army Brigadier General Ed Barker.

The first of these demonstrations, focused on the TLS BCT platform, have been tentatively slated for the April or May 2026 timeframe, he said during a December roundtable at Fort Belvoir, Virginia.

The TLS family of systems is designed as an integrated SIGINT, electronic warfare (EW), and cyber warfare system for army units. The TLS BCT provides combat commanders “with electromagnetic attack and offensive cyber warfare options to deny, degrade, disrupt, or otherwise manipulate the targeted force”, a PEO IEW&S fact sheet stated.

The TLS EAB variant is based on the BCT version of the system but allows TLS operators the ability to “digitally interface with brigade, division, corps, unified action partners, and mission command systems” during combat operations, according to the fact sheet. Once fielded, the TLS EAB will be aligned at the battalion level to “support information superiority, targeting, and long-range precision fires” missions, the fact sheet stated. As integration work progresses on the SIGINT capability for the TLS BCT and TLS EAB systems, it remains unclear whether the newest platform variant, the TLS BCT Manpack, will receive similar SIGINT capabilities. (Source: Janes)

 

17 Dec 24. US Army to field key EW programme by 2026. A critical electronic warfare (EW) programme, designed to improve situational awareness for combat units within the electromagnetic spectrum (EMS), could be headed to the field as early as 2026. Led by Product Manager Electronic Warfare Integration (PdM-EWI), the army’s Spectrum Situational Awareness System (S2AS) programme has been tagged for rapid prototyping beginning in fiscal year (FY) 2025. Designed to work in conjunction with the Electronic Warfare Planning and Management Tool (EWPMT), S2AS is to be the army’s “dedicated [EMS] situational awareness system … to provide the [combat] commanders with real-time [EMS operations] situational awareness”, according to a service fact sheet. The S2AS could also help determine whether signal degradation could be the result of army systems creating interference across the EMS, the fact sheet noted. The programme “is going to help us see ourselves, manage our [EMS] footprint, and understand when we are being jammed”, according to Program Executive Officer Intelligence, Electronic Warfare and Sensors (PEO IEW&S) Brigadier General Ed Barker. In terms of fast-tracking S2AS prototyping, “we have seen the technology out there, and we firmly believe we will be able to move out really quickly on that”, Brig Gen Barker said during a December briefing at Fort Belvoir in Virginia. To that end, army officials conducted a test and evaluation event in mid-December for S2AS, where three mature prototype systems were being run on service networks to ensure successful integration into current command-and-control (C2) platforms. (Source: Janes)

 

16 Dec 24. DoD Releases Version 4.3 Update to Online Cyber Resilient Weapon Systems Body of Knowledge for Engineering Workforce. The Department of Defense (DoD) announced the release of Version 4.3 of the Online Cyber Resilient Weapon Systems Body of Knowledge (CRWS-BoK) today, a free resource designed to support the public and private sector workforces in designing, engineering, and safeguarding secure cyber resilient systems.

Launched in May of 2021 by the Office of the Under Secretary of Defense’s System Security (SysSec) team, the CRWS-BoK has continued to evolve through regular updates, enhancing functionality, engagement, and collaboration. The latest version introduces several key upgrades and improvements, including:

  • Enhanced resource viewing: Users can now view resources they have rated, promoting greater engagement and feedback.
  • Simplified email management: Users can unsubscribe from emails directly from the email footer, improving communication preferences.
  • Expanded nomination capabilities: Users can now nominate Engineering Design Patterns for inclusion in the CRWS-BoK, in addition to resources such as documents and videos.
  • Section 508 Compliance Updates: The CRWS-BoK is now fully compliant with the Revised Section 508 of the Rehabilitation Act of 1973, ensuring accessibility for people with disabilities.
  • Visual and interface enhancements: The platform has been updated with new graphics and security features to improve the overall user experience.

The SysSec team is committed to refining the CRWS-BoK to ensure it remains an essential resource for system security engineering (SSE) and science and technology (S&T) professionals, with the goal of advancing cyber resilience. By collaborating with SSE and S&T professionals, the Research and Engineering (R&E) community can foster assured resilient missions, systems, and components.

Through the CRWS-BoK, the DoD aims to promote innovation and best practices in secure cyber resilient engineering (SCRE), enabling the nation’s SSE and S&T workforces to develop systems that can successfully operate in the face of persistent cyber threats. To learn more and register for a free account, visit the CRWS-BoK at https://www.crws-bok.org/.

About USD(R&E)

The Under Secretary of Defense for Research and Engineering (USD(R&E)) is the Chief Technology Officer of the Department of Defense. The USD(R&E) champions research, science, technology, engineering, and innovation to maintain the United States Military’s technological advantage. Learn more at www.cto.mil, follow us on X (formerly Twitter) @DoDCTO, or visit us on LinkedIn at https://www.linkedin.com/company/ousdre(Source: U.S. DoD)

 

16 Dec 24. BigBear.ai and Proof Labs Collaborate to Develop Cyber Resilient On-Orbit (CROO) Solution for the Department of the Air Force. BigBear.ai (NYSE: BBAI), a leading provider of AI-powered decision intelligence solutions for defense and national security, today announced a collaboration with Proof Labs Inc to deliver an advanced cyber resiliency solution for the Department of the Air Force (DAF). Proof Labs Inc, as the prime contractor, was awarded the AFWERX Small Business Innovation Research (SBIR) Direct-to-Phase II contract to develop the Cyber Resilient On-Orbit (CROO) solution, with BigBear.ai supporting as a sub-contractor. The CROO solution will incorporate BigBear.ai’s SpaceCREST technology, a comprehensive digital twin capability that serves as a real-time monitor and alerting system of a satellite network’s cyber infrastructure. This project aims to enhance the security of the U.S. Air Force (USAF) and the U.S. Space Force (USSF) on-orbit assets through Artificial Intelligence/Machine Learning (AI/ML) cyber intrusion detection.

“Proof Labs is excited to collaborate with BigBear.ai to develop and deliver an advanced intrusion detection system utilizing artificial intelligence for the Air Force Research Laboratory (AFRL) Space Cyber Resiliency program,” said Ricardo Aguilar, Co-Founder & CEO of Proof Labs Inc. “This work combines Proof Labs’ innovation with BigBear.ai’s expertise in AI-driven analytics to enhance the cybersecurity of critical space assets. The integration of innovative technologies will support USAF’s and USSF’s mission to maintain resilient and secure space capabilities.”

BigBear.ai will train the CROO’s AI/ML against a wide range of simulated cyberattacks, covering well-established tactics and procedures. The CROO solution will analyze, evaluate, and classify the behavior of USSF satellite systems in normal operation, versus while under the influence of simulated cyberattacks.

BigBear.ai will then integrate these advanced machine learning algorithms for continuous live monitoring and real-time anomaly and intrusion detection. These algorithms will monitor select USSF space assets’ cyber environments to detect and alert USSF of potential threats in real-time.

“This project represents a significant step forward in safeguarding our nation’s space infrastructure,” said Robert Wedertz, Senior Vice President, Federal at BigBear.ai. “BigBear.ai’s SpaceCREST digital twin capability, further enhanced by custom machine learning and anomaly detection gained through this project, will provide DAF a powerful tool to help combat real-time cyber threats and ensure the resilience of our nation’s critical space assets.”

(Mandatory disclaimer) “The views expressed are those of the author and do not necessarily reflect the official policy or position of the Department of the Air Force, the Department of Defense, or the U.S. government.”

About BigBear.ai

BigBear.ai is a leading provider of AI-powered decision intelligence solutions for national security, digital identity, and supply chain management. Customers and partners rely on BigBear.ai’s artificial intelligence and predictive analytics capabilities in highly complex, distributed, mission-based operating environments. Headquartered in Columbia, Maryland, BigBear.ai is a public company traded on the NYSE under the symbol BBAI. For more information, visit https://bigbear.ai and follow BigBear.ai on LinkedIn: @BigBear.ai, and X: @BigBearai. To receive email communications from BigBear.ai, register here.

About Proof Labs Inc

Proof Labs provides cybersecurity solutions aimed at safeguarding critical military, aerospace, satellite, and national defense assets. Drawing from extensive research and hands-on experience in military communications, real-world national defense, and space projects, we work to mitigate the continuously evolving threat landscape. For more information, visit https://prooflabs.space/ (Source: BUSINESS WIRE)

 

16 Dec 24. US-China: New backdoor raises security, information theft risks from Chinese state-sponsored actor. On 12 December, the cyber security firm XLabs reported that the Chinese state-sponsored group ‘Winnti’ has been targeting firms in the US and China with a new backdoor (‘Glutton’) since December 2023. The campaign primarily targets IT services, social security agencies and web application developers. While the initial attack vector is unclear, Glutton aims to conduct various malicious activities including exfiltrating system information and credentials. Glutton is a modular backdoor where specific components in the backdoor can be activated to tailor attacks, underscoring its sophistication. However, Glutton has notably weak stealth and encryption capabilities, indicating the malware may be in a development stage. Additionally, Glutton was observed being used to target other cyber criminals, embedding the backdoor into software packages sold on the dark web to steal high-value sensitive information. We assess that the shift in Winnti’s victimology (compounded by Glutton’s likely ongoing development) will elevate security and information theft risks. (Source: Sibylline)

 

16 Dec 24. Cyber Update Key points.

  • Additional data exfiltration by Chinese state-sponsored groups will likely be facilitated by ongoing access to US telecommunications networks and prolonged recovery efforts. This will elevate espionage and national security risks in the short term. There is also a realistic possibility that the group will propagate the infection via the software supply chain and conduct additional cyber attacks against critical national infrastructure (CNI) sectors.
  • The scale and impact of the cyber espionage campaign against US telecommunications providers (first reported on in September) may expand, especially since investigations into cyber attacks are ongoing. Additional reports of compromises are likely in the coming months.
  • The spike in cyber attacks against telecommunications providers heightens disruption risks to the broader US CNI amid geopolitical tensions amid increased botnet activity and the capability of Chinese state-sponsored actors to obtain and maintain access to targeted systems.

Context

On 4 December, the US deputy national security adviser for cyber and emerging technologies, Anne Neuberger, disclosed that the White House has created a Unified Coordination Group to respond to several Chinese state-sponsored cyber attacks against the US telecommunications sector. The attacks targeted eight high-profile US internet service providers (ISPs) and telecommunications providers in a concerted, large-scale cyber espionage campaign since at least 2022. The threat actors reportedly exploited access to the providers’ networks to monitor the communications of senior US government and political officials and steal sensitive information and corporate intellectual property (IP); this underscores the severe consequences and potential national security implications of this campaign. Mitigation efforts will highly likely take several months as they require the substitution of thousands of devices while Chinese state-sponsored groups reportedly still maintain access to the providers’ networks. We assess this will sustain elevated espionage and national security risks to US telecommunications and critical national infrastructure (CNI) sectors in the medium term amid ongoing bilateral tensions between China and the US. (Source: Sibylline)

 

13 Dec 24. Cyber Update Key points.

  • A spike in cyber attacks has underscored the elevated security and disinformation risks facing Romania’s electoral system (see Sibylline Cyber Daily Analytical Update – 9 December 2024).
  • A new ‘Termite’ ransomware operation points to the heightened financial and reputational risks facing global organisations via the software supply chain (see Sibylline Cyber Daily Analytical Update – 10 December 2024 and our Technical analysis below).
  • Cyber criminal operations employing the malware variant ‘Androxgh0st’ underscores the elevated security and disruption risks facing global critical national infrastructure (CNI; see Sibylline Cyber Daily Analytical Update – 11 December 2024).
  • The Chinese authorities are using the spyware ‘EagleMsgSpy’ for domestic surveillance operations, underscoring the surveillance and information-theft risks for Android mobile users (see Sibylline Cyber Daily Analytical Update – 12 December 2024).
  • The emergence of new spyware variants has elevated the surveillance and information-theft risks stemming from the Russian advanced persistent threat (APT) group ‘Gamaredon’ (see Sibylline Cyber Daily Analytical Update – 13 December 2024 and our Technical analysis below).

Technical analysis of weekly stories

A new ransomware group, Termite, targeted the software-as-a-service (SaaS) vendor Blue Yonder in a ransomware attack in November. The attack disrupted operations across several high-profile businesses in the provider’s supply chain, impacting payroll, shipping and warehouse management systems for several weeks. Termite has claimed attacks against several organisations across the government, energy and manufacturing sectors. It is unclear how Termite first infects targeted systems. However, upon infection, an application programming interface (API) is leveraged to ensure that the Termite ransomware payload is the last process to be terminated in the attack, thereby maximising the time available for Termite to complete the encryption process. The ransomware then terminates all services on victims’ machines to minimise interruptions during the attack, highlighting the highly sophisticated and premeditated nature of this operation. Additionally, Termite deletes all back-up and deleted file copies to hinder recovery processes and to increase the likelihood that victims will pay a ransom. Termite then encrypts all the system’s files, blocking users’ access and demanding a ransom payment for financial profit. Termite has been active since mid-October and shares several similarities with the now-defunct ransomware operation ‘Babuk’, pointing to a possible re-branding of the group to maintain operations.

The Russian APT group Gamaredon is using two spyware variants (‘BoneSpy’ and ‘PlainGnome’) in an ongoing cyber surveillance campaign. The campaign targets Android mobile users and likely distributes the malicious applications via social engineering tactics. BoneSpy has been active since at least 2021 and was developed using code from the defunct Russian spyware ‘DroidWatcher’. BoneSpy is typically distributed via several malicious applications emulating battery monitoring and photo gallery services. It also displays several advanced information-gathering techniques and can be controlled via SMS messages, underscoring Gamaredon’s sophistication. PlainGnome emerged in January and displays limited obfuscation and detection-evasion techniques, suggesting that it is possibly still in its development phase. Unlike BoneSpy, PlainGnome acts as a malware dropper to deploy the main surveillance payload. Both spyware variants collect sensitive information from compromised systems, including call logs, contact lists, device location, images, messages and audio recordings of phone calls.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security-detection systems to detect potentially malicious samples on the network
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
  • Ensure adequate security monitoring and detection capabilities, particularly for all external-facing services and devices; this includes personal devices connected to corporate networks or applications
  • Adopt and review network authentication services, including virtual private network (VPN) services and multi-factor authentication (MFA)
  • Avoid downloading applications from untrusted third-party websites or via unsolicited messages and only use official websites and application stores to install applications and tools on devices

Our cyber word(s) of the week: Spyware. (Source: Sibylline)

—————————————————————————————————————————————————————————————————————————————————————————————————————————————–

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

———————————————————————————————————————————————————————————————————————————————————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

December 13, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

————————————————————————————————————————————————————————————————————————————————————————————————————————————–

12 Dec 24. Commercial Tech at Heart of Future Defense Spectrum Management. The electromagnetic spectrum is required for nearly every aspect of space-based communications, from satellite to satellite to satellites to soldiers on the ground. Ensuring the spectrum needed for that communication is protected for use by the U.S. and its allies, increasingly means adopting technology developed in the commercial sector.

Over the past few decades, the commercial sector has spent four times as much on research and development than the federal government, including in areas like spectrum management, said Air Force Maj. Gen. Steven J. Butow, the military deputy director of the Defense Innovation Unit, while speaking Wednesday at the Association of Old Crows International Symposium and Convention, just outside Washington.

“During the time that we were not investing in electronic warfare capabilities as a fighting force, the commercial sector was taking off, digitizing, adopting communications capabilities — 3G, 4G, 5G — scaling up,” Butow said. “You have companies like Qualcomm that were developing new methodologies to harness previously unusable parts of spectrum for economic advantage, and all kinds of different business models that we can learn from and then look at how we apply that today.”

Today’s warfighters, Butow said, have more commercial capabilities at their disposal than they did in the past, when everything was military issued.

“Now we have a plethora of different commercial capabilities that we can use throughout peacetime, contingency and even in war, and so do our allies,” he said.

“Commercial technology provides the best way for us to actually rapidly expand and integrate with our allies and partners.”

Working with the commercial sector to bring the best of what it has to offer into the Defense Department is part of what the DIU does, said Butow.

“The Defense Innovation Unit was created in 2015 by then Secretary of Defense Ash Carter, with the sole purpose of trying to bring the commercial technology sector back in, in a way that we could really benefit from a lot of innovation happening outside of the Department of Defense,” he said.

Today, Butow said, much of technology development in spectrum management and in capabilities related to electronic warfare are being developed in the private sector. Integrating that into the department is a challenge that DIU is solving.

“The DOD has the monopoly on wicked problems,” he said. “If you really want to solve a tough problem, we probably own it. And the best talent … in the commercial sector today, they really want to work on those kind of problem sets.”

Creating pathways for that to happen, he said, is what DIU does. In the last decade, he said, about 100 different organizations related to innovation have developed in the Defense Department, which do just that.

“Let’s create an opportunity for them to be able to work on our problems in a way that could be financially favorable to them,” he said. (Source: U.S. DoD)

 

11 Dec 24. CDAO and DIU Launch New Effort Focused on Accelerating DOD Adoption of AI Capabilities. Today, the Chief Digital and Artificial Intelligence Office (CDAO) in partnership with the Defense Innovation Unit (DIU) announced the formation of a new AI Rapid Capabilities Cell (AI RCC) focused on accelerating DoD adoption of next-generation artificial intelligence (AI) such as Generative AI (GenAI). The AI RCC will be managed by the CDAO and will be executed in partnership with DIU. The AI RCC will lead efforts to accelerate and scale the deployment of cutting-edge AI-enabled tools, to include Frontier models, across the Department of Defense.

This announcement comes as the CDAO sunsets Task Force Lima, the Department’s initiative focused on harnessing the power of GenAI. The AI RCC will build upon the findings, and focus on executing pilots in the primary use case areas identified by Task Force Lima. These areas are:

  • Warfighting: Command and Control (C2) and decision support, operational planning, logistics, weapons development and testing, uncrewed and autonomous systems, intelligence activities, information operations, and cyber operations
  • Enterprise management: financial systems, human resources, enterprise logistics and supply chain, health care information management, legal analysis and compliance, procurement processes, and software development and cyber security

The executive summary of Task Force Lima’s findings can be found on CDAO’s website.

“The US commercial sector is at the cutting edge when it comes to artificial intelligence, and digital solutions,” said Chief Digital and AI Officer Dr. Radha Plumb. “We need an all-hands-on-deck approach to accelerate development and deployment of these tools for the Department of Defense to responsibly harness the tremendous promise of AI in everything from financial management to logistics to operations planning to autonomous systems.”

“DIU’s role is bringing the very best commercial tech to bear to meet critical warfighter problems with the focus, speed, and scale required to meet the strategic imperative,” said Doug Beck, Director of DIU. “Our partnership with CDAO, and collaboration on the Rapid Capabilities Cell, will allow us to shape critical AI initiatives in a way that incorporates the standards, policy, and requirements from the beginning. The result will help us scale the tech faster and more reliably, and will also help change the way the Department thinks about software development and delivery tempo for the future.”

The AI RCC will initially be resourced with approximately $100M in FY 2024 and FY 2025 for pilot efforts that apply generative AI models to priority use cases, and investments in foundational AI infrastructure and tools. In partnership with other parts of the Department, industry, and academia, CDAO and DIU will take a rapid experimentation-based approach to the AI pilots, consistent with the CDAO and DIU’s Open DAGIR construct and use all available agile acquisition approaches.

Additional details about planned pilots, infrastructure investments, and other AI-focused efforts can be found in the linked fact sheet.

About the CDAO and DIU

CDAO is the Department of Defense’s (DoD) organization responsible for the acceleration of the department’s adoption of data, analytics, and artificial intelligence (AI). It has the mission of providing enterprise-level infrastructure and services, as well as scaling proven secure digital and AI-enabled solutions for enterprise and joint use cases. CDAO leverages relevant dual-use commercial technologies and novel operating models to enable all DoD organizations to quickly develop, test, integrate and deliver secure, data, analytic, and AI capabilities to achieve their missions.

DIU is the DoD’s organization responsible for leading the adoption of commercial technologies to solve warfighter problems for strategic impact at speed and scale, in support of the National Defense Strategy. It serves as the principal liaison between the DoD and the national security innovation base, and with its companies and investors, and coordinates and advises efforts within the DoD, and with interagency and international partners, on matters related to the development, procurement, and fielding of commercially derived technology. (Source: U.S. DoD)

 

12 Dec 24. Strategic Effect. The regime of Syria’s dictator Bashir al-Assad is no more. On 7th December 2024 Mr. Assad fled Damascus following a dramatic advance across much of Syria by the Hayat Tahrir al-Sham (HTS) Islamist political grouping. One day later Mr. Assad and his family were reportedly granted asylum in Russia.

Syria has been mired in civil war since 2011. A dramatic offensive led by forces opposed to the regime commenced on 27th November. Several Syrian cities fell in rapid succession to the opposition including Homs in the central, western part of the country and Aleppo in the north. Mr. Assad’s fate was sealed following fall of Damascus.

Unconfirmed local reports say that HTS’ advance was assisted by a concerted jamming effort directed against tactical radio networks and military communications used by forces loyal to the regime. Speculation focused on Turkish forces deployed in Syria directing electronic attacks against these communications. Turkish forces have been deployed in northern Syria since 2016. The Turkish military has supported elements of the anti-Assad opposition and fought Kurdish militias active there. As Armada has chronicled in the past, Turkish military Electronic Warfare (EW) assets have proven effective during Ankara’s involvement in the Syrian civil war.

Several conclusions can be drawn assuming these reports of Turkish EW prowess are correct: Firstly, Syrian forces loyal to the regime lacked Communications/Transmission Security (COMSEC/TRANSEC) protocols to resist electronic attack. Secondly, these forces may have been largely relying on civilian communications unable to withstand electronic attack. Thirdly, Mr. Assad’s Russian backers may not have provided the secure communications needed to guarantee electromagnetic resilience. Fourthly, any COMSEC/TRANSEC protocols and/or military communications used by regime forces may have been unable to withstand the severity of attacks.

Perhaps the most important lesson is that HTS cadres may have enjoyed electromagnetic superiority over the regime thanks to the jamming. Regime forces could not use the spectrum as they wished for communications, unlike HTS units. The inability of the regime to thus exploit the spectrum for communications cost them dearly by depriving them of a vital tactical and operational command and control conduit. This depravation may have had a strategic effect by discombobulating the regime’s forces, thus contributing to Mr. Assad’s downfall. (Source: Armada)

 

12 Dec 24. Belarussian Tactical Communications Enhancements. The Belarussian Army is receiving R-185 Epocha command and control vehicles which provide V/UHF and HF communications. These vehicles are likely deployed at the regimental and brigade level in Belarussian ground forces manoeuvre formations. The modernisation of the Belarussian Army’s tactical communications is continuing with recent deliveries of new R-185 Epocha command and control platforms. Ukraine’s militarnyi website reported in late November that the Belarussian Army has received a new batch of R-185 Epocha (Р-185 Эпоха) Command and Control (C2) systems. The R-185 ensemble is housed onboard a BTR-60MB2 eight-wheel drive armoured vehicle. The reports continued that work on the R-185 commenced in 2016. According to the Belarussian Ministry of Defence, the first R-185-equipped vehicles entered service in 2020. The R-185 communications fit includes R-181-50VU-2 (Р-181-50ВУ-2), R-181-50TU (Р-181-50ТУ) and R-181-100VK (Р-181-100ВК) tactical radios.

The radios

Official Belarussian government documents specify that the R-181-50VU-2 uses frequencies of Very/Ultra High Frequencies (V/UHF: 30 megahertz/MHz to 512MHz). The radio handle two simplex (one-way) channels, and one duplex (two-way) channel. The document continues that ranges of 30 kilometres/km (18.6 miles) are achievable when the radio is stationary, with ranges of 20km (12.4 miles) possible when the radio is mobile. Unclassified data is handled at rates of 19.2 kilobits-per-second/kbps. The R-181-50VU2 carries both fixed frequency and frequency-hopping traffic.

The R-181-50TU is a VHF (30MHz to 108MHz) transceiver. Providing up to 100 channels, the radio produces between five and 50 watts/W of transmission power. Communications/Transmission Security (COMSEC/TRANSEC) comprises a minimum frequency hopping rate of 200 hops-per-second/hps. The R-181-50TU can handle data at rates of between 9.6kbps and 19.2kbps. This radio has a range of 25km (15.5 miles) when mobile, and up to 50km (31.1 miles) with a mast when the vehicle is stationary.

The R-181-100VK is a High Frequency (HF: three megahertz to 30MHz) transceiver providing up to 100W of output power. It is likely that the R-181-100VK facilitates beyond line-of-sight backhaul to higher echelons. When mobile the R-181-100VK has a range of 75km (46.6 miles), and up to 350km (217.5 miles) with a mast when the vehicle is stationary. The R-185 has also been designed to communicate with aircraft. VHF ground-to-air/air-to-ground links of up to 65 nautical miles/nm (120km) can be established using the R-181-50TU. The Epocha’s R-181-100VK HF radio permits longer ground-to-air/air-to-ground links of up to 243nm (450km).

Assessment

How many R-185 systems have been delivered to the Belarussian Army remains unknown. It is likely that the army’s signals troops, which are a separate command, are the primary Epocha users. The Belarussian Army’s order-of-battle is organised around the brigade as its primary unit of manoeuvre. Mechanised brigades have organic mechanised infantry, armour, artillery and combat support regiments and battalions. It is possible that the R-185s provide intra-brigade communications, and communications with higher echelons of command. The Epocha programme does not appear to have concluded. Additional supplies of the system can be expected in the future. (Source: Armada)

 

12 Dec 24. Keeping Secrets. Link-16 is one of several tactical datalink protocols employed throughout NATO. The protocol is primarily used to support air operations, with Link-11/22 primarily supporting the maritime domain. Why capturing an airborne radio compatible with NATO’s Link-16 tactical datalink protocol may not hand Russian radio frequency engineers an intelligence coup.

In late November, Pravda cited a Turkish source which stated that Ukraine’s Ministry of Defence had requested access to North Atlantic Treaty Organisation (NATO) Link-16 connectivity. Link-16 is a secure, encrypted tactical voice and communications protocol. Primarily used to support air operations, Link-16 traffic includes target track data and other tactically relevant information. This traffic is carried via so-called ‘J-Series’ messages across frequencies of 960 megahertz to 1.215 gigahertz. NATO began to use Link-16 in the 1980s and the protocol has supported alliance air operations ever since.

The Pravda article speculated that furnishing the Ukrainian F-16s with Link-16 could allow these aircraft to plug into NATO Link-16 networks. Open-source websites like flightradar24 regularly show NATO aircraft flying in alliance airspace close to Ukraine’s borders. These planes can include Boeing RC-135V/W Rivet Joint Signals Intelligence (SIGINT) aircraft flown by the United States Air Force and the Royal Air Force. Regular flights are also made by alliance airborne early warning and control aircraft such as Boeing E-3 series jets or Royal Swedish Air Force Bombardier/Saab S106 GlobalEye platforms. These NATO planes can all carry Link-16 compatible radios. The article speculated that Ukrainian F-16s could now receive tactical information direct from NATO aircraft via Link-16 networks. Technically, this is possible. Whether it has occurred is beyond the scope of this article.

Does Russian have Link-16 technology?

Pravda’s boldest assertion was that “if Russia obtains … the Link-16 system, it may have an extremely negative impact on the combat capability of NATO aviation.” The article surmised that the Russian military may succeed in shooting down an F-16, or a Ukrainian F-16 pilot could be tempted to defect. A Link-16 compatible radio in the possession of Russian engineers might then give up its secrets. The article warns that “(i)f this equipment falls into the hands of Russian specialists, they will be able to access NATO codes and ciphers used in the system.”

It is difficult to believe that Russia does not already have knowledge of Link-16 technology. NATO nations have lost several combat aircraft over the years that were likely equipped with Link-16 compatible radios. Many of these aircraft have been downed by countries, or organisations, considered sympathetic to Russia. During NATO operations in the Balkans in the 1990s three alliance combat aircraft were shot down by the Bosnian Serb Army and/or the Yugoslav military.

Famously, a US Navy Lockheed Martin EP-3E Aries-II SIGINT aircraft was forced to land on Hainan Island off the southern coast of the People’s Republic of China on 1st April 2001. The EP-3E landed after a collision with a People’s Liberation Army (PLA) Navy Air Force Shenyang J-8 (NATO reporting name Finback) series combat aircraft. The EP-3E crew were released after ten days of internment on the island. The aircraft was disassembled and later returned to the US Navy on 3rd July 2001. Reports revealed that the PLA examining the EP-3E captured cryptographic keys used by the aircraft’s communications. It was speculated that some classified materials the EP-3E crew could not destroy were shared with Russia.

Robust encryption

Capturing a Link-16 compatible radio is unlikely to result in an intelligence coup rendering the protocol redundant overnight. Open sources say that Link-16 J-Series messages, and the signal carrying this traffic, are encrypted. To break into a Link-16 network both the message, and the signal, must be decrypted. Moreover, Link-16 networks use pseudo-random frequency-hopping. Each separate Link-16 network has its own distinct frequency-hopping scheme. Link-16 messages and traffic can only be encrypted or decrypted using the message and traffic encryption keys embedded in the radios at that time. Keys are regularly changed precisely to frustrate any attempts to gain unauthorised access to a Link-16 network. A Link-16 compatible radio could be captured, and its encryption keys discovered, but it is unlikely the keys will have any use. By the time the radio can be used to gain illicit access to Link-16 traffic, encryption keys will have changed. Even if Russian engineers do succeed in capturing a Link-16 radio, they may find it little more than dead circuitry as far as secure Link-16 traffic is concerned.(Source: Armada)

 

12 Dec 24. December Radio Roundup. Thales’ Naval Drakon communications system is the company’s latest offering in this market space. Naval Drakon is scheduled to equip the French Navy’s ‘Amiral Ronarc’h’ and the Royal Navy’s ‘Type-31/Inspiration’ classes of frigate.

Armada’s monthly roundup of all the latest news in the military communications product, programme and operational domains.

Naval Drakon Unveiled

Thales has showcased the latest evolution of the company’s naval communications product portfolio at this year’s Euronaval exhibition held in Paris between 4th and 7th November. Known as Naval Drakon, this new suite of naval communications hardware and software continues the company’s involvement with this sector as enshrined in the Aquilon family. Drakon is a suite of hardware and software that integrates and manages disparate communications links using High Frequency (HF: three megahertz/MHz to 30MHz), Very/Ultra High Frequency (V/UHF: 30MHz to three gigahertz) and Satellite Communications (SATCOM) wavebands. Thales officials told Armada during Euronaval that Drakon works with Thales’ hardware such the company’s transceivers, or with those of third parties. Naval Drakon is the maritime equivalent of the Drakon system the company has developed for land forces. The officials continued that the Drakon has been designed with the trend towards Joint Electromagnetic Spectrum Operations (JEMSO) in mind. The JEMSO philosophy converges ostensibly disparate disciplines such as radar, radio communications and Electronic Warfare (EW), among others. At the heart of JEMSO is the desire to perform electromagnetic spectrum operations in a managed, coordinated manner. The intention here is to reduce spectrum congestion, improve spectrum management and emissions control. JEMSO also stresses reducing risks of electromagnetic fratricide, while improving the efficacy of EW, communications and ISR (Intelligence, Surveillance and Reconnaissance). Officials said that Naval Drakon is scalable according to the size of vessel it equips. Moreover, the system is already in service onboard the Marine Nationale’s (French Navy’s) ‘Jacques Chevallier’ class replenishment vessels. Naval Drakon is also equipping the French Navy’s ‘Amiral Ronarc’h’ class frigates and the Royal Navy’s ‘Type-31/Inspiration’ class frigates. BAE Systems and Kongsberg are working together promoting their Integrated Combat Solution which can shared battlefield data and also control vehicle weapons, sensors and other subsystems.

ICS Gains Momentum

Last month it was revealed that BAE Systems and Kongsberg have entered into a teaming agreement regarding the Integrated Combat Solution (ICS). The former has shared more information with Armada regarding this arrangement. Kongsberg is developing the ICS and BAE Systems is integrating the architecture onto vehicles, according to a press release. The ICS is a battle management system which also lets vehicle crews control their subsystems. These subsystems could include a remote weapons station, and/or electronic warfare and self-protection apparatus from individual screens inside the platform. The ICS has been demonstrated onboard an Iveco/BAE Systems Amphibious Combat Vehicle and BAE Systems Armoured Multi-Purpose Vehicle. A written statement provided by BAE Systems revealed that the ICS is used by the militaries of Australia, Finland, Norway and Ukraine. The latter deploys the ICS as part of Kongsberg Cortex Typhon counter-uninhabited aerial vehicle system. The statement continued that the ICS “can be integrated on any battlefield platform that is equipped with a weapon system and on-board sensors.” In terms of bearer networks for ICS’ data, these can be carried across “multiple communication methods.”

New E-Lynx Arrival

October saw Elbit Systems launch a new member of its E-Lynx tactical radio family dubbed the E-Lynx SR. A press release announcing the news disclosed that this multi-channel system was launched at the International Dismounted Soldier Conference held in London between 29th and 30th October. Elbit says that the radio incorporates cognitive techniques and multiple-in/multiple-out architectures. Other features include simultaneous voice, internet protocol, blue force tracking and video traffic carriage. In addition, the radio can connect to fourth- and fifth-generation cellular networks. The company told Armada in a written statement that the transceiver uses frequencies of 225 megahertz/MHz to 2.9 gigahertz. Elbit continued that the E-Lynx SR contains the company’s new soldier waveform. This waveform is compatible with existing E-Lynx products. Customer-specified waveforms can also be hosted in the transceiver. Elbit’s statement added that it is pitching this radio as a capability for dismounted squad and platoon leaders. (Source: Armada)

 

12 Dec 24. China: Spyware operation highlights surveillance, information-theft risks stemming from authorities. On 11 December, the cyber security company Lookout reported that the Chinese authorities are using new spyware (‘EagleMsgSpy’) to target Android mobile users in China. The malware is installed after gaining physical access to victims’ unlocked devices. Law enforcement officers reportedly deploy EagleMsgSpy to collect extensive sensitive data from compromised devices, including call logs, messages, contacts’ information and GPS co-ordinates. Stolen data is then encrypted and sent to command-and-control (C2) infrastructure that can only be accessed by authenticated users, underscoring the sophistication and covert nature of this operation. Additionally, the spyware’s obfuscation and encryption techniques have evolved since it first became active in 2017, pointing to its continued development. Notably, EagleMsgSpy contains functions to distinguish between Android and iOS operating systems, suggesting that an unidentified iOS version of the spyware possibly exists. This discovery showcases the scale of China’s surveillance activities, elevating the surveillance and information-theft risks facing individuals in the medium-to-long term. (Source: Sibylline)

 

11 Dec 24. C3 AI (NYSE: AI), the Enterprise AI application software company, and Collins Aerospace, an RTX business, today announced expanded joint initiatives to develop and deliver AI solutions across the defense and intelligence space.

“As the defense and intelligence sectors confront increasingly complex challenges, the need for advanced, scalable AI solutions has never been more critical,” said Thomas M. Siebel, CEO, C3 AI. “Our strengthened partnership with Collins underscores our shared commitment to equipping federal agencies with the AI capabilities essential to maintaining strategic advantage, improving decision making, and enhancing mission readiness. Together, we are accelerating a transformative shift that will redefine how national security and defense are achieved in the modern era.”

These new initiatives aim to leverage AI for critical defense operations, advancing technology adoption in support of federal priorities. Specifically, C3 AI and Collins are deploying applications from the C3 AI Defense and Intelligence Suite, including C3 AI Readiness and C3 Generative AI for Defense and Intelligence.

“By combining our expertise in mission-critical systems with C3 AI’s advanced AI platform and applications, we are equipping federal agencies with the tools they need to act decisively, enhance situational awareness, and strengthen national security. This collaboration is about more than technology — it’s about driving a future-ready approach to defense,” said Ryan Bunge, vice president and general manager, C4I&A, Collins Aerospace. (Source: BUSINESS WIRE)

 

10 Dec 24. Global: Malware variant heightens security, operational risks to critical infrastructure. On 10 December, the cyber security company Check Point reported that the ‘Androxgh0st’ malware is being used by cyber criminal groups to target critical national infrastructure (CNI) systems. Threat actors have reportedly integrated Androxgh0st with the ‘Mozi’ botnet to strengthen the malware’s capabilities. This allows Androxgh0st to exploit software vulnerabilities for access to targeted systems as well as to achieve prolonged presence within compromised systems to exfiltrate sensitive data. We assess that cyber criminals likely sell stolen data on the dark web to garner illicit profit. Notably, these operations targeted Internet-of-Things (IoT) devices alongside web servers and encompassed distributed denial-of-service (DDoS) attacks. We assess this highlights increased operational risks to CNI systems as the sophistication of cyber criminal groups continues to grow. Androxgh0st impacted at least 5% of global organisations in November, thus elevating security, financial and disruption risks in the short-to-medium term amid a general uptick in cyber criminal attacks. (Source: Sibylline)

 

10 Dec 24. CrowdStrike (NASDAQ: CRWD) today announced a key government certification, achieving C5 compliance in Germany. The C5 (Cloud Computing Compliance Criteria Catalogue) certification, established by the German Federal Office for Information Security (BSI), ensures that cloud service providers meet rigorous security criteria required by public sector organizations to remain secure while delivering critical services. This achievement reinforces CrowdStrike’s dedication to supporting customers through government-led security standards.,This latest milestone is part of CrowdStrike’s ongoing global efforts to expand access and accelerate adoption of the AI-native CrowdStrike Falcon® Platform. Achieving C5 compliance underlines CrowdStrike’s commitment to government-led security standards and supports public sector organizations in Germany and beyond. Through a rigorous certification process, CrowdStrike reaffirms its technical capabilities, security expertise, and adherence to privacy and data security best practices – adding to an expansive list of international certifications and government recognition that CrowdStrike has achieved, including being recommended by the German Federal Office for Information Security (BSI) as a qualified Advanced Persistent Threat (APT) response service provider.

“Achieving C5 certification is an important milestone for CrowdStrike as we work with public sector customers in Germany to stop breaches,” said Michael Sentonas, president of CrowdStrike. “We have tremendous momentum in the region and are committed to providing organizations of all sizes, across sectors, with the world’s most advanced AI-native cybersecurity.”

CrowdStrike’s drive to meet global compliance standards continues to ensure its global customers are supported by the highest level of security. To learn more about its global compliance efforts, please visit the CrowdStrike Compliance and Certification Page.

About CrowdStrike

CrowdStrike (NASDAQ: CRWD), a global cybersecurity leader, has redefined modern security with the world’s most advanced cloud-native platform for protecting critical areas of enterprise risk – endpoints and cloud workloads, identity and data.

Powered by the CrowdStrike Security Cloud and world-class AI, the CrowdStrike Falcon® platform leverages real-time indicators of attack, threat intelligence, evolving adversary tradecraft and enriched telemetry from across the enterprise to deliver hyper-accurate detections, automated protection and remediation, elite threat hunting and prioritized observability of vulnerabilities.

Purpose-built in the cloud with a single lightweight-agent architecture, the Falcon platform delivers rapid and scalable deployment, superior protection and performance, reduced complexity and immediate time-to-value. (Source: BUSINESS WIRE)

 

10 Dec 24. Movius, the leading global provider of secure, AI-powered, purpose-driven communications software, announced it has been listed in the FedRAMP marketplace with a Department of Defense sponsored agency to provide mission-critical, secure communications solutions (https://marketplace.fedramp.gov/products/FR2335850270). Movius has already been awarded multiple Phase II Small Business Innovation Research (SBIR) contracts through AFWERX, Tactical Funding Increase (TACFI) award, and most recently a Phase III award to scale enhanced secure communication capabilities. Movius’s solutions will contribute directly to the Department of the Air Force’s (DAF) strategic need for resilient information sharing, secure decentralized and distributed communications, intelligence, surveillance and reconnaissance, assured communications, and situational awareness with Movius’s edge AI.

Movius’s MultiLine solution is a secure, scalable application that allows users to call and message through a secure business identity across any device, carrier, and connection type (Wi-Fi, Data, GSM, Satellite and Private). MultiLine supports built-in recording and call/message capture and storage for the entire workforce, enabling full surveillance, regulatory reporting, compliance management, and robust application security. The solution is also supported on legacy government cell phone programs.

Movius Decentralized Distributed Secure Communications solution enables decentralized, military grade communications globally, including in a denied and degraded network environment. With this solution there are no central server dependencies or risk of communications being blocked or thwarted. It includes the notion of self-sovereign identity.

“These awards are a culmination of over two years of focused partnership for groundbreaking innovation between the Air Force and the Movius team,” said Amit Modi, Chief Technology Officer at Movius. “Ultimately, the vision is simple—freedom to communicate securely and safely from anywhere at any time,” added Modi.

To learn more about MultiLine by Movius and the company’s full suite of AI-powered solutions, visit www.movius.ai. (Source: BUSINESS WIRE)

 

10 Dec 24. Enhancing UK Biosecurity: DASA Launches Microbial Forensics Competition. DASA and UKMFC seek novel technology options to enhance the UK’s Microbial Forensic capability.

  • DASA has launched a new Themed Competition: Future-proofing Biosecurity by Strengthening the UK’s Microbial Forensic Capability
  • This competition is funded by Dstl for the UK Ministry of Defence (MOD)
  • The total possible funding available for this competition is £1m (excluding VAT).
  • Competition closes midday on Tuesday 18th February 2025 (GMT)

On behalf of the Defence Science and Technology Laboratory(Dstl), the Defence and Security Accelerator (DASA) is pleased to launch a new Themed Competition called Future-proofing Biosecurity by Strengthening the UK’s Microbial Forensic Capability. The competition is being run in response to the 2023 UK Biological Security Strategy which aims to implement a UK-wide approach to biosecurity that will strengthen deterrence and resilience to a spectrum of biological threats.

Dstl is leading the creation of the United Kingdom Microbial Forensics Consortium (UKMFC) which is being developed in support of the Detect Pillar of the Biological Security Strategy. It will comprise a network of biosurveillance laboratories from all four nations of the UK, operating under a One Health doctrine. This competition seeks novel technology options or technical approaches that can directly support the UKMFC initiative.

Key dates and funding

The total possible funding available for this competition is £1m (excluding VAT). We are looking to fund a minimum of 4 and up to 10 projects, each up to a maximum value of £250,000. The deadline to submit a proposal is midday (GMT) on 18 February 2025. Submit via the DASA Online Submission Service.

Background

The aim of the competition is to strengthen UK capability in the field of Microbial Forensics. Novel technology options are required to function within the context of the UKMFC laboratory network; an appropriately resourced, high technological infrastructure, staffed by subject matter experts in biosurveillance. Innovations that either augment current approaches (e.g. increasing the speed and / or opportunity for anomaly detection through genomics) including novel uses of technology platforms or that provide completely new avenues for a Microbial Forensic investigation are of interest.

Any new capability should not increase the risks encountered in the day-to-day activities of a laboratory, or significantly increase the financial burden encountered by a laboratory (above normal investment patterns). There is no interest in technology development that would provide a solely mobile Microbial Forensic capability or enhance a laboratory’s ability to simply identify a pathogen.

Dstl provides expert scientific advice and deployable capabilities which directly support resolution of some of the most challenging national security incidents: those involving explosive, chemical or biological materials. Dstl hosts the UK’s only sovereign Chem-Bio capability used to analyse and understand the world’s most deadly pathogens and biological weapons.

What are the technology challenges we would like addressed?

There is particular interest in funding new research in the following areas:

  1. Computational tools that improve the opportunity to detect anomalies in genome sequencing data, including evidence of biological engineering.
  2. Technologies that allow the identification and / or computational analysis of other omic signatures for novel Microbial Forensic capabilities.

Ideally any new capability would be agnostic of the sector, sample type, and class or type of biological agent being analysed. However, technical approaches that are specific to certain types or classes of biological agent may be considered. We are also interested in proposals that develop or repurpose existing technologies used in other scientific disciplines.

We are looking for innovations that will form the basis of the next generation of Microbial Forensic capability, potentially enhancing our ability to use any branch of science under the omics banner in a Microbial Forensic investigation, and fundamentally improve our understanding of an encountered pathogen.

Supporting events

Thursday 9 January 2025

A dial-in webinar providing further detail on the problem space and a chance to ask questions in an open forum. If you would like to participate, please register on the Eventbrite page here.

Wednesday 15 and Tuesday 21 January 2025

There will also be one-to-one teleconference sessions on 15 and 21 January giving you the opportunity to ask specific questions to the competition team in a closed forum. Registration details for these sessions will be published the day after the dial in webinar session, i.e. on 10 January 2025. Booking will be on a first come first served basis.

Please attend the dial-in session on 9 January 2025 or reach out to your local Innovation Partner if you have more general questions on DASA the application process.

Submit a proposal

We want novel ideas to enhance the UK’s Microbial Forensic capability. Can you provide innovative solutions? If so, please read the full competition document and submit a proposal.

https://www.gov.uk/government/publications/future-proofing-biosecurity-by-strengthening-the-uks-microbial-forensics-capability (Source: https://www.gov.uk/)

 

04 Dec 24. The second UK-EU Cyber Dialogue takes place in London.

The second UK-EU Cyber Dialogue took place this week. Both sides agreed to hold the next UK-EU Cyber Dialogue in Brussels in 2025.

From left to right: Maciej Stadejek, Christiane Kirketerp de Viron, Rod Latham, and Andrew Whittaker

The second UK-EU Cyber Dialogue took place on Thursday 5 and Friday 6 December in London.

The meeting was co-chaired by Andrew Whittaker, Cyber Director in the UK Foreign, Commonwealth and Development Office (FCDO) and Rod Latham, Director, Cyber Security and Digital Identity in the Department of Science, Innovation and Technology (DSIT).

Held under the UK-EU Trade and Cooperation Agreement, the Cyber Dialogue welcomed Maciej Stadejek, Director, Security and Defence Policy, European External Action Service (EEAS) and Christiane Kirketerp de Viron, Acting Director, Digital Society, Trust and Cybersecurity, DG Communications Networks, Content & Technology (DG CNECT), European Commission as co-chairs from the European Union (EU).

Other representatives from the Commission and EU agencies (Europol, ENISA) also participated in the discussions.

The agenda included exchanges of views on our respective approaches to cyber resilience, secure technology and digital identity; deterrence strategies against cyber threats; countering cybercrime including ransomware; working with the multi-stakeholder community to uphold a free, open, secure and peaceful cyberspace; the Pall Mall Process to tackle the proliferation and irresponsible use of commercial cyber intrusion capabilities; cyber skills; and cyber capacity building.

The UK was represented by officials from the Foreign, Commonwealth and Development Office (FCDO), Department for Science, Innovation and Technology (DSIT), National Cyber Security Centre (NCSC), and Home Office.  Both sides agreed to hold the next UK-EU Cyber Dialogue in Brussels in 2025. (Source: https://www.gov.uk/)

 

06 Dec 24. Cyber Update Key points.

  • The distribution of the ‘SpyLoan’ malware via malicious mobile applications underscores elevated financial risks facing Android users (see Sibylline Cyber Daily Analytical Update – 2 December 2024).
  • Threat actors targeted Taiwan with the ‘SmokeLoader’ malware, heightening security and information-theft risks to firms (see Sibylline Cyber Daily Analytical Update – 3 December 2024).
  • Evolving phishing tactics will increase security risks from the North Korean state-sponsored group ‘Kimsuky.’
  • The Russian state-sponsored group ‘Turla’ hijacked the cyber infrastructure of another state-sponsored threat group for espionage operations, elevating espionage risks to government and military organisations in Afghanistan and India.
  • A new Malware-as-a-Service (MaaS) operation elevates security and financial risks to global Android mobile users and financial institution.

Technical analysis of weekly stories

The North Korean state-sponsored group Kimsuky adopted new phishing techniques in a cyber operation between May and October. The group used phishing emails to trick researchers, financial institutions and corporate officials into visiting fraudulent websites designed to steal user credentials. The emails impersonated government and financial institutions to enhance legitimacy and asked users to urgently review documents online. Kimsuky did not deploy any malware upon gaining access to targeted systems, highlighting a potential shift in the group’s tactics towards prioritising stealth, establishing a prolonged presence in targeted systems and detection evasion. Additionally, the actors consistently rotated infrastructure throughout the campaign, using Japanese domains in April, Korean services between May and September and finally shifting to Russian domains in October. This further emphasises the sophistication of Kimsuky’s detection evasion capabilities as it focuses on countering analysis and security mechanisms. We assess that the group likely stole credentials to hijack user accounts to exfiltrate sensitive information and initiate fraudulent money transfers.

A new MaaS operation has been targeting Android mobile users in a financially motivated campaign since at least June. The campaign has already compromised at least 77 banking institutions, cryptocurrency exchanges and national organisations primarily based in Europe and Latin America. The campaign starts by distributing a new remote access trojan (RAT), ‘DroidBot’, via malicious applications on the Google Play store, impersonating legitimate security and banking applications. Users are then asked to enable Android accessibility services, subsequently allowing threat actors to monitor and mimic user activity. Some of the malware’s most notable features include keylogging, overlaying and SMS interception to hijack one-time passwords (OTPs) and other authentication information. DroidBot also uses virtual network computing (VNC) modules to remotely monitor infected devices as well as execute additional commands including darkening mobile screens to obfuscate malicious activity. The RAT uses the Message Queuing Telemetry Transport (MQTT) protocol to communicate with command-and-control (C2) infrastructure. MQTT is not typically used in cyber operations or associated with malicious activity, thus helping threat actors prolong detection evasion. DroidBot’s MaaS operation currently boasts around 17 affiliates, pointing to the scale of this operation and the possibility of future operations using this RAT. The RAT also displayed some unfinished features, suggesting that it is likely facing ongoing development.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security-detection systems to detect potentially malicious samples on the network
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
  • Ensure adequate security monitoring and detection capabilities, particularly for all external-facing services and devices; this includes personal devices connected to corporate networks or applications
  • Adopt and review network authentication services including virtual private network (VPN) services and multi-factor authentication (MFA)
  • Avoid downloading applications from untrusted third-party websites and only use the official websites and application stores to install applications and tools on devices.

Our cyber word(s) of the week: Message Queuing Telemetry Transport (MQTT) protocol. (Source: Sibylline)

 

08 Dec 24. Cyber Command Chief Discusses Challenges of Getting Intel to Users. The United States has spent trillions of dollars on ensuring intelligence and the network that distributes that intelligence is the best on the planet, but more needs to be done, said Air Force Gen. Timothy D. Haugh, commander of U.S. Cyber Command, director, National Security Agency and chief, Central Security Service, in a discussion at the Reagan Defense Forum yesterday.

Intelligence is the lifeblood of defense strategy and a crucial aspect of deterrence. Haugh spoke during a panel hosted by New York Times reporter Julian Barnes. The panelists agreed that the United States does a good job of collecting intelligence and analyzing the intelligence but has shortcomings in ensuring that the people who need that information get it in a timely and effective form.

Competitors, of course, try to guard their intelligence and use all methods to find what the United States knows, Barnes stated to the general about Salt Typhoon — the Chinese government led hack aimed at North America and Southeast Asian targets. The hack — discovered by Microsoft — was not only aimed at companies, but high-level political figures.

Haugh said the hack — which some in the intelligence community called “mind-boggling” — is just one part of China’s global cyber program. “So that is an area that we have to continue to be able to educate our allies, our partners and the American people of what the intent is, whether it be coming at our critical infrastructure or intending to do collection through a large-scale series of operations against our telecommunications industry,” he said.

The National Security Agency is working with the Cybersecurity and Infrastructure Security Agency, the FBI and industry partners on the threat Salt Typhoon poses. The agency did send out cyber security advisories in 2022 “that laid out this exact series of things that we had observed overseas,” the general said. His agency does not collect data in the United States.

“Our question now is … how do we bring the partnership together with industry so that we can together enhance early warning,” he said. “How do we bring our strengths to bear that allow us to think collectively on how we defend U.S. infrastructure. I think that partnership with industry is the component.”

Haugh said the cooperation between his agency and tech industries has gotten better, but “how we do that in a timeline that gets us to outcomes that makes it more difficult for the .”

One way may be the use of the enduring security framework that exists with CISA and NSA. This may help harden the collective telecommunications infrastructure.

Haugh did get asked about how well the NSA is doing in getting intel to the shooters. “One of the roles of the National Security Agency is we’re a combat support agency,” he said. “We are responsible as an element of the Department of Defense to enable military commanders.”

The question about effectiveness really needs to be directed to commanders downrange. “I think the test today would be to the commanders of the various ships that are operating in the Red Sea — how are we doing in informing their threat and their response,” he said. “We’re proud of the work that we do as a community.”

Commanders operating under Houthi threats and threats from other Iranian-backed groups have an understanding of the environment and indications of warning, he said. They are able to put their ships in position to deal with these threats.

“The other component that we’re doing every day is in ensuring that European Command in its role today in support of Ukraine,” he said. “My role is to make sure that from within the Department of Defense and within the nation, we’ve got an ability to deliver signals intelligence in a unified architecture to ensure that we’re getting maximum value for both military commanders and our policy makers.” (Source: U.S. DoD)

————————————————————————————————————————————————————————————————————————————————————————————————————————————

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

———————————————————————————————————————————————————————————————————————————————————————————————————————————

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

December 6, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

————————————————————————————————————————————————————————————————————————————————————————————————————————————————

05 Dec 24. Pacific Defense, a leader in Modular Open Systems Approach (MOSA) solutions, announces the COM6300VP, a 3U OpenVPX™ multi-waveform tactical radio plug-in card aligned with the Sensor Open Systems Architecture (SOSA™) Technical Standard. The plug-in card features a dual-channel communication approach, utilizing both Single Channel Ground and Airborne Radio System (SINCGARS) and the TrellisWare TSM™ waveforms. The COM6300VP provides secure, low-risk communication capabilities through a Thales Defense and Security Inc. (TDSI) integrated crypto module, which can facilitate future NSA Type-1 certification.

Why It Matters

The COM6300VP combines multiple radio capabilities and an integrated crypto module into a single card, enabling system integrators to replace multiple independent radio devices within a platform. This consolidation reduces Size Weight and Power (SWaP), complexity, and streamlines logistics. It also enables the rapid deployment of secure communications across a wide range of military programs, including those aligned with the Army’s CMFF initiative.

Advanced Tactical Capabilities

The COM6300VP supports assured voice communication on its narrowband channel and runs TrellisWare TSM™ waveform on its wideband channel, providing data, and video transmission. Built to withstand challenging environments, the COM6300VP incorporates technology from Thales’ latest 2-channel PRC-148F radio that meets next generation requirements while providing interoperability with legacy radios. It also facilitates integration with the US Government’s Android Team Awareness Kit (ATAK) to enhance situational awareness.

“The COM6300VP expands our tactical communications portfolio, delivering advanced, secure communications in a single 3U card that enables modular and scalable system architectures,” said Pedja Mitrovic, V.P. Product Management at Pacific Defense. “This product underscores our commitment to providing CMOSS-compliant, SOSA-aligned solutions that enhance mission effectiveness and reduce development time and cost.”

“We are proud to partner with Pacific Defense to bring secure tactical communications through CMOSS and to the U.S. Army CMFF program. Together, we are advancing modular, open vehicle electronics innovation that enhances mission command connectivity and advances open standards to reduce platform integration complexity,” said Paul Mehney, Vice President Strategy at Thales Defense and Security, Inc.

Key Features of the COM6300VP:

  • 3U OpenVPX™ SOSA-aligned, fully CMOSS-compliant plug-in card
  • Supports SINCGARS, AM/FM, and TrellisWare TSM™ waveforms
  • Integrated crypto module based on NSA-certified Thales technology
  • Rugged design for harsh environments

For detailed information about the COM6300VP, please visit the product page: COM6300VP

Availability

The COM6300VP is available to order now.

(Source: BUSINESS WIRE)

 

04 Dec 24. Goldilock, the British cybersecurity company behind the unique physical network isolation solution “FireBreak”, has today announced the extent of its strong momentum with the European channel market over the last 6 months. Goldilock has partnered with over 40 new distributors and resellers since June, demonstrating the broad, cross-sector appeal of its critical layer-1 physical segmentation product and helping it bring the product to an even wider market there.

To support Goldilock’s rapid European channel growth, Wim Horseling has been appointed as Channel Manager for Europe. Bringing over 30 years of experience in channel and sales leadership at organisations such Dell, Siemens, and NetYCE, Horseling’s knowledge of the connectivity, security and data centre space will be crucial in consolidating Goldilock’s momentum in Europe, educating channel partners, and continuing the company’s European expansion into 2025.

“I’m thrilled to be joining Goldilock at this exciting time to support the company’s growth in Europe” said Wim Horseling, Channel Manager for Europe. “We’ve established strong relationships with an extensive list of distributors and resellers across Europe this year and we’re actively seeking more to join our growing network. Ultimately, the power of Goldilock’s solution lies in its simplicity and I look forward to enabling the delivery of this critical technology to more industries and countries.”

As cyber threats continue to increase in complexity and number across the globe, the rapid adoption of the latest security innovations and dual-use technologies is necessary across sectors. Through a powerful yet simple approach, Dynamic Physical Network Segmentation (DPNS) technology enables users of FireBreak to step outside of the cyber security arms race by physically isolating their digital assets and systems instantly, acting as a crucial first layer for organisations of all types. Goldilock’s European new and existing channel partners recognise the value of its unique hardware-based solution as this foundational component of a multi-layered cyber security strategy.

“Pedab is excited to collaborate with Goldilock to bring their groundbreaking security solutions to our extensive customer base,” said Jesper Bartholdson, CEO of Pedab. “With their expertise in both IT and OT security, we can offer comprehensive protection for industries that require the highest level of safety and reliability.”

Goldilock now works with over 50 partners across 18 countries in Europe. Partnering with distributors and resellers with deep industry knowledge and local expertise of customer preferences, regulation, and market conditions. Partners including Brookcourt (UK), DigiFors (Germany) and Infinity (Netherlands) bring understanding of data centre, smart buildings, and telco technologies, as well as the enterprise and public sector markets including healthcare, finance, CNI, and hospitality. This will ensure customers receive both the vital technology and personalised guidance and industry-specific expertise needed to maximise its effectiveness and establish a holistic approach to cybersecurity.

“Now more than ever, organisations across all industries need to establish a multilayer security posture,” said Steven Brodie, Chief Revenue Officer at Goldilock. “We’re on a mission to deliver our layer-1 solution to the industries that need it most and we’re grateful for the confidence all our partners in Europe have shown in FireBreak. By providing specialised industry and local expertise, we can rest assured that our end-users are getting the personalised support they need to futureproof their network security. Meanwhile, we’ll continue to make playing well with others a priority so that our partners can continue to offer customers fully integrated and comprehensive protection against tomorrow’s threats.”

 

04 Dec 24. Raytheon, an RTX (NYSE: RTX) business, has successfully completed a Delta Design Review of its Advanced Electronic Warfare, or ADVEW, prototype for the U.S. Navy’s F/A-18 E/F Super Hornet. ADVEW is being developed to replace existing electronic warfare components on the aircraft to improve survivability and long-term sustainability. Executed ahead of schedule, the review assessed the weapons replaceable assemblies, or WRAs, and how each part of the hardware system works together to meet required specifications. The review confirmed that the system can provide critical electronic attack and electronic support measures capabilities.

“This event is a significant milestone that demonstrates our multi-function approach of integrating electronic support and electronic attack to revolutionize modern electronic warfare systems,” said Bryan Rosselli, president of Advanced Products & Solutions at Raytheon. “Our solution provides the needed capabilities to defeat the ever-evolving threats of the world’s most dangerous adversaries now and well into the future.”

Raytheon’s integration of digital and model-based systems engineering tools in the development of ADVEW provides requirements traceability, streamlines system integration, and mitigates risk to enable rapid aircraft integration. The company’s approach leverages common material base and manufacturing processes to efficiently scale, reduce cost, minimize supply chain disruption, and deliver ahead of schedule. In December of last year, Raytheon was awarded a $80 m contract in a down select to prototype the system for the U.S. Navy. The successful completion of this Delta Design Review marks another milestone of ADVEW development and begins the next phase, which includes government laboratory testing to validate Open Mission Systems compliance and to demonstrate advanced system attributes. (Source: PR Newswire)

 

05 Dec 24.  Afghanistan-India: Hijacked cyber infrastructure indicates elevated espionage risks. On 4 December, the cyber security company Lumen reported that the Russian state-sponsored group ‘Turla’ is exploiting infrastructure associated with the Pakistani state-sponsored group ‘Storm-0156’ to conduct cyber espionage operations. Although the initial attack vector is unclear, Turla first compromised the command-and-control (C2) infrastructure used by Storm-0156 in December 2022. In 2023, Turla exploited backdoor access previously obtained by Storm-0156 to deploy its own custom backdoors against government and military networks in India and Afghanistan. This likely enabled Turla to covertly exfiltrate strategic information masking as Storm-0156, underscoring the highly stealthy nature of the group’s tactics. Additionally, Turla used malware and other tools affiliated with Storm-0156 as part of its 2024 campaigns, likely obtained as a result of the 2022 intrusion. Turla has previously infiltrated other threat actors’ infrastructure to complicate attack attribution and conduct espionage operations. We assess this elevates long-term security and espionage risks to organisations in the aforementioned countries. (Source: Sibylline)

 

05 Dec 24. UK and Qatar launch project to boost artificial intelligence collaboration.

The UK and Qatar launch joint Artificial Intelligence (AI) research commission.

The UK and Qatar have launched a joint Artificial Intelligence (AI) research commission, seeking to establish a roadmap for UK-Qatar collaboration on AI that will benefit both countries.

The joint study will be led by Queen Mary University of London, in partnership with Hamad bin Khalifa University (HBKU) in Qatar. The study is being led by Professor David Leslie, Professor of Ethics, Technology, and Society at Queen Mary University of London’s Digital Environment Research Institute, and the Director of Ethics and Responsible Innovation Research at the Alan Turing Institute. The project will build on the exciting progress that both countries have made on AI, and identify and scope practical and ambitious ways for the countries to enhance their cooperation in this field in line with their AI and technology strategies. A range of areas will be explored across the spectrum of ecosystem development, policy and regulation, security, and international engagement. It has been designed and developed as a collaboration between Qatar’s Ministry of Foreign Affairs, the AI Committee of the Qatar Ministry of Communications & Information Technology (MCIT), Qatar Research, Development and Innovation Council (QRDI), and the British Embassy in Doha.

The announcement of the collaboration coincides with the State Visit of the Amir of Qatar to the UK.

The project is funded by the UK Government’s Gulf Strategy Fund, part of the Foreign, Commonwealth and Development Office’s (FCDO) International Programme.

Neerav Patel, British Ambassador to Qatar, said: “The UK and Qatar have shown themselves to be innovators in the policy implementation of AI, including the need to build strong systems of ethics and governance. I’m delighted that such prestigious UK and Qatari institutions are involved in this important initiative. It reflects both countries’ desire to work together on the shared challenges the 21st century will bring.”

Dr. Mariam Khalid Al-Hamar, Minister Plenipotentiary at the Ministry of Foreign Affairs in Qatar, said:  “This initiative marks a key opportunity to advance innovation through collaboration. As a global leader in dialogue and mediation, Qatar recognizes the vital importance of collaboration in promoting diplomacy and resolving conflicts. By leveraging the transformative potential of AI, we have the opportunity to make meaningful progress in peacebuilding, improve decision-making processes, and tackle complex global issues with greater accuracy. Furthermore, embracing the idea of ‘AI for All’ ensures that the benefits of this technology reach every nation, empowering them to actively engage in the AI era. This vision reflects our unwavering commitment to innovation, inclusivity, and ensuring that technology serves as a tool for justice and progress for all.”

Eman Alkuwari, Digital Innovation Director from Qatar’s MCIT, said: “This collaboration marks a significant step forward in Qatar’s commitment to advancing AI as a transformative force for good. By partnering with the UK and leveraging the expertise of world-renowned institutions, we aim to unlock new opportunities for innovation, shape ethical frameworks, and contribute to global progress in AI. This initiative reflects our shared vision to harness the power of technology for the benefit of our societies and economies.”

Professor David Leslie said:

We are undoubtedly at a pivotal juncture in the history of AI, so the time couldn’t be better to bring the UK and Qatar closer together to explore collaborative avenues for harnessing AI’s transformative potential to deliver public benefit, while diligently addressing emerging risks and harms. By leveraging the dynamic AI research and innovation ecosystems of both nations, this initiative promises to be a catalyst for ingenuity and commercial opportunity, fostering a new era of technological cooperation between two global leaders in the field.

Mr. Omar Al Ansari, Secretary General of QRDI, said: “This initiative marks a key opportunity to advance innovation through strategic collaboration in AI. By leveraging Qatar and the UK’s significant investments in AI research, development & innovation, we are paving the way for funding transformative projects. This partnership will strengthen the ties between Qatar and the UK’s innovation ecosystems, fostering the exchange of expertise and driving impactful outcomes for both nations.”

Professor Colin Bailey, the President and Principal of Queen Mary University of London, said: “We are proud and honoured to be embarking on this collaboration with Hamad bin Khalifa University in Qatar. Queen Mary University has a long history of building strong, successful international collaborations, and of being at the forefront of emerging research and technology. This new partnership will allow both universities to combine their collective knowledge and strengths to ensure AI technology is used in the best, safest way possible.” (Source: https://www.gov.uk/)

 

05 Dec 24. Innovation at Pace.

“We need capability, and we need it now,” was how one Ukrainian electronic warfare practitioner described their appetite for EW systems on the frontline. In a nutshell, the Ukrainians need as much EW kit as they can get their hands on as quickly as possible. The Ukrainian defence industry is expert at rapidly identifying tactical and operational need, developing and prototyping a solution, and getting this into the warrior’s hands. This is not just about hardware. It is also about the rapid development and deployment of software which is increasingly at the heart of the fight in the spectrum.

Ukraine’s experience has lessons for procurement authorities, and the EW industrial sector, across NATO and allied nations. All of us need to be asking some difficult questions: How good are the lines of communications between the warfighting community, government and industry? Electromagnetic lessons can be learned on the battlefield, but how quickly can these be translated into requirements? Once needs become requirements, how rapidly can requirements become prototypes? Are testing and evaluation systems, and processes up to scratch to move prototypes into production at pace? What threshold of performance are service personnel willing to accept to have a system they can rapidly deploy? Is 80 percent or 90 percent good enough for now? Can we quickly activate production lines and scale up industrial output to meet demand? Air Commodore Blyth Crawford, Commandant of the Royal Air Force Air and Space Warfare Centre, and other EW experts, have been asking these questions and more. They are also proposing innovative solutions. Ensuring our EW innovation, procurement and production processes fit for purpose is as much a part of prevailing in the electromagnetic spectrum, as the fight itself. (Source: Armada)

 

04 Dec 24. 32 Reasons Why. The US Navy’s AN/SLQ-32 is being cycled through several upgrades being performed by a number of firms which will ensure that this 20th century hardware can meet the challenge posed by 21st century threats.

Japan has requested the delivery of her first upgraded Raytheon AN/SLQ-32(V) series surface vessel electronic warfare systems by 2026.

Lockheed Martin has told Armada, via a written statement, that deliveries of the two AN/SLQ-32(V) systems ordered by Japan will be completed by 2026. The company is the prime contractor for the overarching Surface Electronic Warfare Improvement Programme (SEWIP) Block-2 initiative. SEWIP Block-2 is a long-term programme overhauling the AN/SLQ-32(V) systems equipping an array of US Navy surface vessels.

In late October, the company revealed in a press release it had been contracted by the United States Navy’s Naval Sea Systems Command to provide full rate production AN/SLQ-32(V)6 and AN/SLQ-32C(V)6 examples. The conclusion of the Foreign Military Sale (FMS) to Japan marks the first export success for the AN/SLQ-32(V) product family.

SEWIP Block-2 transitioned from a development programme to full rate production in 2016, the press release continued. Lockheed Martin’s written statement said that AN/SLQ-32(V)6 systems have been in low-rate initial production since 2013, with the first production examples being delivered in 2014. So far, the US Navy has ordered 165 AN/SLQ-32(V)6 and twelve AN/SLQ-32C(V)6 systems. Upgraded AN/SLQ-32(V)s will continue to equip legacy vessels as these are upgraded. New surface combatants are also receiving the AN/SLQ-32(V) such as the US Navy’s new ‘FFG-62/Constellation’ class frigates, according to open sources. Beyond the US Navy AN/SLQ-32(V) examples equip the US Coast Guard’s ‘Heritage’ class offshore patrol cutter, ‘Legend’ class national security cutter and ‘Polar Sentinel’ class polar security cutters.

Further AN/SLQ-32(V) procurements are expected via the FMS route, the company added, beyond Japan’s two systems. In Japan Maritime Self-Defence Force service, the AN/SLQ-32(V) will furnish the service’s two forthcoming Aegis System Equipped Vessels (ASEVs). Publicly available reports say that the ASEVs are cruiser-sized vessels that will primarily specialise in anti-air warfare and ballistic missile defence. These ships will be outfitted with Lockheed Martin’s Aegis combat management system. The two vessels are expected to commission in 2027 and 2028.

AN/SLQ-32 configurations

The baseline Raytheon AN/SLQ-32(V)1 detects and engages signals across wavebands of five gigahertz/MHz to 20 gigahertz/GHz. These wavebands were later expanded downwards to 250MHz for the AN/SLQ-32(V)2/3/4 variants. In its original form the AN/SLQ-32(V) generated decoy waveforms for jamming. These waveforms would spoof the radar seeker of an incoming anti-ship missile regarding the target’s location. The AN/SLQ-32(V)2 contains additional capabilities to detect threats emitting across Very/Ultra High Frequency (V/UHF) wavebands of 250MHz to three gigahertz. The AN/SLQ-32(V)3 configuration added a jamming capability to engage threats transmitting across a five gigahertz to 20GHz waveband. The AN/SLQ-32(V)4 configuration was designed for aircraft carriers. The AN/SLQ-32(V)5 was a jamming module added to the AN/SLQ-32(V)1/2 to enhance these systems’ jamming capabilities.

The overarching SEWIP modernisation commenced in 2002, with an initial contract (Block-1) for the upgrade awarded to General Dynamics one year later. SEWIP Block-1 mainly addressed obsolescence issues in the legacy hardware and software of deployed AN/SLQ-32(V)s. Lockheed Martin was then awarded an initial contract to outfit the AN/SLQ-32(V) with a high gain, high sensitivity antenna under SEWIP Block-1B3. SEWIP Block-1B3 improved the AN/SLQ-32(V)’s transmitted jamming power. The AN/SLQ-32(V)’s sensitivity to incoming radar signals was also enhanced via SEWIP Block-1B3. Lockheed Martin won the SEWIP Block-2 contract in 2009. This effort is transitioning legacy AN/SLQ-32(V)s to the AN/SLQ-32(V)6 status by teaming the former with the SEWIP Block-1B3 modification.

A programme of continual improvement for AN/SLQ-32(V) systems in service with US and foreign customers is expected in the future, thanks to the open architecture at the heart of the SEWIP Block-2 philosophy: “The US Navy programme of records continues with upgrades well into the next decade,” Lockheed Martin’s statement added. This is “due to the modular approach of the system (which) makes it easily upgraded to take advantage of the latest technology.” (Source: Armada)

 

05 Dec 24. Band on the Run. The Orlan-10 UAV is deployed extensively by Russian land forces for collecting intelligence, surveillance and reconnaissance data, and for supporting electronic warfare as part of the Leer-3 EW system. The aircraft uses radio links across wavebands of 200 megahertz to 2.7 gigahertz.

Details have been shared with Armada regarding operating frequencies of uninhabited aerial vehicles used by Russian land forces occupying parts of Ukraine.

The Russian military is known to use several types of UAVs to support tactical and operational manoeuvre in the Ukrainian theatre of operations. These UAVs includes the Orlan-10, CH-3A, Forpost-R, CH-4B, Taxion, Eleron-3SV, Lancet, Zala, Kub, Granat-1/2/3/4, Merlin, Orion, Supercam-350, Mahajer-6, Zastava (a variant of the Israel Aerospace Industries Bird Eye UAV series) and Phantom. All these UAVs depend on a radio link connecting the aircraft to its Ground Control Station (GCS). These links share flight control and telemetry information between the GCS and aircraft. The links may also carry data collected by the UAV, such as imagery, with those who need this information.

Frequencies used by these aircraft stretch from 200 megahertz/MHz up to twelve gigahertz/GHz. The Ukraine conflict has seen both sides continually increasing the number of frequencies their UAVs can use. These changes reflect the realities of the ongoing counter-UAV battle in the electromagnetic spectrum. As a jammer becomes effective against a set of UAV frequencies, efforts will be taken to outflank these attacks. This action-reaction cycle cannot continue indefinitely. The aircraft have finite physical space for housing antennas which the limit antenna size, and hence frequency, the UAV can use. Power generation is limited by the aircraft’s battery life and powerplant, and the need to share electricity with other aircraft systems. Moreover, available power is governed by the range at which the aircraft needs to operate. In short, the frequencies the UAV uses will be a trade-off between practical antenna size, available power and operating range.

UHF frequencies

Several aircraft use Very/Ultra High Frequency (V/UHF: 30MHz to three gigahertz/GHz) links as follows:

  • Orlan-10: 200MHz-450MHz, 867MHz-872MHz, 915MHz-920MHz, 860MHz-1.000GHz, 1.080GHz-1.300GHz, 2.200GHz-2.024GHz, 2.500GHz-2.700GHz
  • CH-3A: 325MHz-390MHz, 520MHz-790MHz, 860MHz-930MHz, 1.420GHz-1.480GHz, 2.300GHz-2.650GHz
  • Forpost-R: 465MHz-510MHz
  • CH-4B: 800MHz-900MHz, 1.090GHz
  • Taxion, Eleron-3SV: 867MHz-872MHz, 915MHz-920MHz, 1.205GHz-1.250GHz
  • Lancet, Zala, Kub: 867MHz-872MHz, 902MHz-928MHz, 1.561GHz-1.575GHz, 1.597GHz-1.616GHz, 2.200GHz-2.400GHz
  • Granat-1/2/3/4: 867MHz-872MHz, 900MHz-928MHz, 1.080GHz-1.280GHz, 2.300GHz-2.500GHz
  • Merlin: 870MHz, 915MHz
  • Orion: 890MHz-920MHz, 2.300GHz-2.400GHz
  • Supercam-350: 976.5MHz-1.0215GHz, 1.0335GHz-1.11505GHz, 1.11055GHz-1.22225GHz
  • Mahajer-6: 1.200GHz-1.600GHz
  • Zastava: 2.200GHz-2.400GHz
  • Phantom: 2.400GHz-2.483GHz

S-band and upwards

Several of these UAVs also use radio links outside these V/UHF wavebands. For example, the following UAVs use S-band (two gigahertz to four gigahertz), C-band (four gigahertz to six gigahertz) and X-band (eight gigahertz to twelve gigahertz) frequencies:

  • Forpost-R: 4.400GHz-5.100GHz
  • CH-4B: 4.200GHz-6.100GHz, 8.000GHz-12.000GHz
  • Orion: 4.200GHz-5.700GHz
  • Supercam-350: 11.775GHz

Whether these latter frequencies are for conventional radio links between the GCS and aircraft, or whether these links move across S-band, C-band and X-band satellite communications remains unknown.

The CH-3A, CH-4B and the Phantom UAVs are all produce by Chinese companies. Mahajer-6 UAVs are produced by the Islamic Republic of Iran. Thus, along with their Russian counterparts, it is entirely possible that these UAVs may be encountered in other operational theatres around the world using similar wavebands. Detecting these aircraft via their radio signals, and then defeating them via electronic attack, will be paramount. (Source: Armada)

 

05 Dec 24. December Spectrum SitRep.

New Satellite for Unseenlabs

Unseenlabs plans to launch a new signals sensing satellite to augment the existing spacecraft it has in orbit, the company told Armada. A total of 15 satellites comprise Unseenlabs’ constellation, according to the European Space Agency. These spacecraft collect data on radar transmissions in the S-band (2.3 gigahertz/GHz to 2.5GHz/2.7GHz to 3.7GHz) and X-band (8.5GHz to 10.68GHz) wavebands. Principle targets for Unseenlabs’ surveillance include radar signals from maritime vessels. The company provides this information to undisclosed commercial and government customers. During this year’s Euronaval exhibition which took place in Paris between 4th and 7th November, Unseenlabs told Armada the new satellite will be added to the constellation in 2026. Unlike the company’s previous spacecraft, the new vehicle will not be a nano satellite. Traditionally, nano satellites have a launch weight below 20 kilograms/kg (44 pounds/lb). This new satellite, which has yet to be named, will weight circa 150kgs (330lbs). Unseenlabs’ frequency catchment area will be enlarged via the new satellite’s capabilities. The spacecraft will collect signals across a waveband of one to twelve gigahertz. Officials stated that the new satellite will also let the company collect data on land-based emitters of interest.

U/SME-400 takes the stage

Last month we reported that Saab had launched the Sirius Compact L20C Electronic Support Measure (ESM). The company took the opportunity of this year’s Euronaval exhibition held in Paris between 4th and 7th November to unveil a new naval ESM. The U/SME-400 ESM family can equip surface and subsurface vessels. Saab representatives told Armada that the U/SME-400 series has a fully digital architecture. The product family includes the U/SME-450 which covers wavebands of one gigahertz/GHz to 18GHz. All U/SME-400 variants provide 16GHz of acquisition Instantaneous Bandwidth (IBW). The U/SME-450 provides 16GHz IBW for Direction Finding (DF). The U/SME-420 covers the same wavebands as the U/SME-420 with eight gigahertz of DF IBW. Finally, the U/SME-410 covers wavebands of two gigahertz to 18GHz with 0.5GHz of DF IBW. The representatives continued that the U/SME-450 is ideal for large surface combatants. Smaller vessels are well placed to use the other variants for blue water and littoral missions. The company will complete its development of the U/SME-400 by the end of the year and is already seeing interest from potential customers.

The antenna unit for the U/SME-400 family is compact and can be configured according to the specific product. All the system’s hardware and software can be enclosed in a single cabinet, and it can be operated from a single workstation.

New RWR for US Army Apaches

Lockheed Martin has shared more details with Armada concerning the company’s selection to provide the AN/APR-48B radio frequency interferometer and radar warning receiver to the US Army. The AN/APR-48B has been developed to equip the force’s Boeing AH-64E Apache Guardian attack helicopter. The company told Armada, via a written statement, that development work on the AN/APR-48B commenced immediately “upon contract award and is expected to be completed within the three-year period of performance for the contract.” Lockheed Martin received the contract for the AN/APR-48B’s development in mid-October. The company has teamed with Intel’s Altera subsidiary and is using the latter’s MCP-2 chip in the AN/APR-48B’s architecture. The chip “provides significantly improved size, weight, power, radio frequency performance and processing capability,” the statement continued. In addition, the use of the chip “enables Lockheed Martin to both improve performance over the legacy system (equipping the AH-64E) and add new functionality … for processing and identification of advanced threats.”  (Source: Armada)

 

04 Dec 24. CDAO Awards Anduril Production Agreement to Deliver Edge Data Mesh. The U.S. Department of Defense’s (DoD) Chief Digital and AI Office (CDAO) has awarded Anduril Industries a three-year production agreement to scale a first of its kind tactical Edge Data Mesh, powered by Anduril’s Lattice Mesh. The mesh is already operational across multiple services and combatant commands, delivering critical data that enables mission-relevant generative artificial intelligence (AI) solutions specifically tailored to the unique requirements of the warfighter. This agreement will accelerate the expansion of the mesh to increase access to decentralized, distributed and disconnected systems, and to power new insights and real-time decision making at the edge.

Today’s systems may be dependent on cloud or hub/spoke connectivity and are not always optimized for operations with denied, degraded, or intermittent communication pathways. This demands a scalable decentralized solution that dynamically adapts to disruptions. The Lattice Mesh is a decentralized networking capability that seamlessly distributes critical data across platforms, domains, and partners by intelligently prioritizing data paths to ensure the most efficient flow of critical data. To achieve this outcome, the Lattice Mesh was built for the edge, connects directly with, and runs on, sensors, weapons, platforms, robots, and more across the edge to provide access to systems and data not previously accessible. Warfighters at the edge will be enabled to publish and subscribe to data in support of time sensitive operations or where large numbers of manned, unmanned and autonomous systems must collaborate in contested environments to advance the mission.

Years of iterative development and prototyping in multiple combatant commands produced a resilient, secure, and scalable infrastructure that ensures warfighters and weapons systems have access to real-time, actionable data across all domains. During this effort, CDAO determined that the Anduril Lattice Mesh could support joint operations, providing data transformation, access, persistence, and transport, linking the strategic level of war to the tactical edge. Anduril has delivered data integrations to sites around the world, and worked with end users to deeply understand and build a production-quality mesh. The extensibility of this system allows Anduril and CDAO to add integrations to support command and control of autonomous systems and counter-autonomous systems. For example, the Anduril Lattice Mesh™ can be used to connect sensors and effects for multiple missions, including long-range fires and integrated air defense, it can integrate third-party uncrewed systems into autonomous battle networks, and it can integrate deployed sensors and weapons to achieve time-sensitive targeting. Core to this effort is Anduril’s commitment to interoperability and support of Open DAGIR principles, the CDAO’s approach to scaling data, analytics, and artificial intelligence (AI) capabilities. The Edge Data Mesh is open and integrates government and vendor-owned data and systems through Anduril’s Lattice™ software development kit (SDK) and open APIs. This allows partners to connect, share, and act on data within the mesh, to include partner-developed, generative AI capabilities at the edge. The mesh’s open architecture allows services, combatant commands, as well as allies and partners to seamlessly collaborate across all domains. Any service or combatant command can leverage this production agreement to extend and modernize existing systems furthering joint, all domain operations.

This production agreement between Anduril and CDAO is a powerful step toward a new era of defense innovation and connected warfare. Scaling this tactical data mesh will accelerate the development of modern kill chains for every weapons system, in every service, and proliferate digital mass across every combatant command. (Source: ASD Network)

 

04 Dec 24. Global: Evolving tactics will heighten security risks posed by North Korean state-sponsored groups. On 3 December, the cyber security firm Genians reported that the North Korean state-sponsored group ‘Kimsuky adopted new phishing techniques in a cyber operation between May and October. The group used phishing emails as initial attack vectors to trick researchers, financial institutions and corporate officials into visiting fraudulent websites designed to steal user credentials. Kimsuky continuously changed its infrastructure throughout the campaign, likely to prolong detection evasion to counter analysts and security mechanisms. Additionally, the group did not deploy any malware onto compromised systems, further highlighting a potential shift in Kimsuky’s tactics towards prioritising stealth and detection evasion. It is likely that the actors subsequently used stolen credentials to hijack user accounts, enabling them to exfiltrate sensitive information and initiate fraudulent money transfers. We assess this will heighten long-term security, financial and espionage risks to global organisations amid ongoing geopolitical tensions and economic sanctions. (Source: Sibylline)

 

04 Dec 24. PhysicsX, a London-based start-up bringing the power of generative AI to enable breakthrough engineering in advanced industries, has launched the first Large Geometry Model (LGM) for aerospace engineering, LGM-Aero, and a publicly accessible reference application, Ai.rplane, to showcase its power in designing aero structures.

Ai.rplane allows engineers to generate innovative aircraft designs in an infinitely wide design space and instantaneously assess the designed aircraft’s potential performance.

Developed and provisioned on AWS, LGM-Aero was trained on more than 25 m meshes, representing more than 10 bn vertices, and a corpus of tens of thousands of Computational Fluid Dynamics (CFD) and Finite Element Analysis (FEA) simulations generated with Siemens Digital Industries tools. It is a fully trained model that generalizes to a broad set of aeroelastic applications. It also infers aero performance, flight stability and structural stress for a large class of flying shapes as a zero-shot model. This technology creates geometry and assesses performance results in less than a second, compared to the several hours required for traditional numerical simulations.

“We are delighted to work with PhysicsX as they develop their first Large Geometry Model and release its showcase application Ai.rplane,” said Ozgur Tohumcu, General Manager, Automotive and Manufacturing, AWS.  “This technology will accelerate the transformation of engineering in Advanced Industries for AWS customers, enabling them to bring their products to the market faster while increasing product performance. We’ve been impressed by PhysicsX’s pace of innovation and look forward to deepening our collaboration.”

In one seamless operation, the technology creates novel designs, predicts lift, drag, stability, structural stress and other attributes for each shape, then optimises the design according to the user’s preferences. When used in industrial applications, this workflow reduces development time from months to hours.

“In the same way that large language models understand text, Ai.rplane has a vast knowledge of the shapes and structures that are important to aerospace engineering,” says Jacomo Corbo, co-founder and CEO of PhysicsX. “The technology can optimise across multiple types of physics in seconds, many orders of magnitude faster than numerical simulation, and at the same level of accuracy. We’re excited about what LGM-Aero brings as capabilities to our customers while recognizing that it is also an important stepping stone towards developing physics foundation models.”

LGM-Aero was developed using an extensive set of simulation technologies from Siemens to automate and scale the generation of high-quality training data, as well as AWS Batch and Amazon EC2 to scale compute during training. It is available on the PhysicsX AI engineering enterprise platform, which is trusted by some of the most sophisticated engineering and manufacturing organizations across advanced industries.

“We are thrilled to continue to build on our deep collaboration with AWS, and to announce the release of LGM-Aero and of Ai.rplane. This is a first step in transforming the way engineering is practiced in Advanced Industries,” added Robin Tuluie, founder and chairman of PhysicsX. “Over time, we will bring new capabilities to LGM-Aero and to Ai.rplane, allowing users to select powertrains, add controls and further content to reach mature designs in days rather than months or years.”

LGM-Aero and Ai.rplane are available on the PhysicsX AI engineering platform. Ai.rplane is free-to-use and accessible via airplane.physicsx.ai.

 

03 Dec 24. Thales today announced the launch of Data Risk Intelligence, a groundbreaking Imperva Data Security Fabric (DSF) solution that proactively addresses the risks to data wherever it resides. This is the first solution uniting the risk and threat identification capabilities of the Imperva Data Security Fabric with the data protection capabilities of the Thales CipherTrust Data Security Platform, following Thales’s strategic acquisition of Imperva in December 2023.

In today’s modern digital landscape, organisations face challenges in managing security across an ever-growing attack surface while maintaining compliance with regulatory standards. With data and operations spread across cloud, on-premises and hybrid systems, security teams require constant, comprehensive visibility into where their data is, the types of data they have, and the potential risks to that data. In fact, according to the 2024 Thales Data Threat Report, 93% of enterprises reported an increase in threats compared to the previous year.

Empowering Security Teams and SOCs with Enhanced Visibility and Control

The combined intelligence and contextual insights from Data Risk Intelligence provide a unified visibility of risks to critical data with a unique view of the strength of encryption for data across an organisation’s entire data estate. With this enhanced visibility, Data Risk Intelligence empowers CIOs, CISOs, and data risk specialists to accurately identify the most critical data that are at risk by severity and likelihood, enabling them to effectively prioritise risk mitigation with clear recommendations for corrective action.

Data Risk Intelligence delivers a highly confident risk score and clear recommendations for corrective action that are based on a wide-ranging set of data risk indicators through advanced analytics, built upon user permissions, data source vulnerabilities, use of encryption following NIST standards, monitoring of suspicious activities, and other customisable inputs.

Todd Moore, Vice President, Data Security products at Thales: “The ability to view data risk in key dimensions across organisational risk, asset risk, and regulatory risk in one place is extremely impactful. Data Risk Intelligence is the first of many integrations between the Thales and Imperva platforms that empower our customers to protect their data and all the paths to it. ​ Through our combined platforms, Thales has all ​ the tools to help our customers understand their data security risks and provide a clear set of actions to mitigate these risks.”

“The risks to enterprise data are multi-dimensional and organisations are struggling to address the volume and breadth of these risks while still maintaining optimal business operations,” said Jennifer Glenn, Research Director, Data and Information Security at IDC Security and Trust Group. “Centralising data risk visibility and management offers valuable context about the data – and it’s vulnerabilities – enabling organisations to prioritise protection where it’s needed most.”

Key Benefits of Data Risk Intelligence:

  • Enhanced Risk Prioritisation: Combines risk-related intelligence from Data Security Fabric and CipherTrust Data Security Platform to deliver precise risk scores that drive confident decisions.
  • Comprehensive Visibility: Provides a unified view of data risks across the entire data estate, reducing complexity, delivering risk indicators, and recommending protective measures.
  • Customisable Risk Indicators: Allows organisations to tailor risk indicators to their specific environment, highlighting the most critical threats.
  • Encryption Integration: Leverages the encryption capabilities of the CipherTrust Data Security Platform to ensure data protection at all levels.
  • Advanced Analytics: Utilises posture-based and machine-learning behavioural risk indicators to identify and prioritise the highest-risk data.

DSF Data Risk Intelligence is available to customers who have a current Data Security Fabric Data 360 license.

 

29 Nov 24. Cyber Update Key points.

  • A new Linux-based backdoor highlights the ongoing adaptability of China-linked threat actors (see Sibylline Cyber Daily Analytical Update – 25 November 2024).
  • A new cyber espionage campaign conducted by the Chinese state-sponsored group ‘Earth Kasha’ points to the elevated security risks facing Japanese individuals with ties to the field of international relations (see Sibylline Cyber Daily Analytical Update – 26 November 2024 and our Technical analysis below).
  • The exploitation of two zero-day vulnerabilities underscores the heightened espionage risks from the Russia-aligned group ‘RomCom’ (see Sibylline Cyber Daily Analytical Update – 27 November 2024 and our Technical analysis below).
  • The development of a new bootkit for Linux systems has increased the security risks facing global entities (see Sibylline Cyber Daily Analytical Update – 28 November 2024).
  • A cyber attack against a hospital in the UK points to the elevated long-term security and disruption risks facing healthcare entities (see Sibylline Cyber Daily Analytical Update – 29 November 2024).

Technical analysis of weekly stories

The Chinese state-sponsored group Earth Kasha has been using the ‘ANEL’ and ‘NOOPDOOR’ backdoors to target Japanese entities in a cyber espionage campaign since at least June. Earth Kasha specifically targets individuals affiliated with political organisations, research institutions and think tanks with spear phishing emails to obtain access to victims’ systems. In 2023, the group primarily exploited software vulnerabilities to infiltrate targeted organisations, marking a shift in its ‘intrusion’ tactics. The emails are often sent from hijacked accounts to enhance their apparent legitimacy and to trick potential victims into clicking on a OneDrive link and subsequently downloading a .ZIP file. Notably, the group has created three versions of the malicious .ZIP file that can install a malware dropper (‘ROAMINGMOUSE’) via three attack chains. The first chain installs ROAMINGHOUSE directly onto compromised systems, while the second and third versions contain shortcut and decoy files to download the payload while simultaneously evading detection. ROAMINGHOUSE then deploys the ANEL backdoor using several anti-detection techniques such as waiting for users to hover their cursor over a form (embedded in the malicious document) before executing the malware. The ANEL file is also encoded to help Earth Kasha’s activity remain obfuscated. The group has specifically deployed a newer version of ANEL to steal information from compromised systems by taking screenshots and executing commands to gather network data. In some cases, the threat actors also used the custom malware NOOPDOOR to collect information from high-value targets.

The Russian-nexus advanced persistent threat (APT) group RomCom exploited two zero-day vulnerabilities (CVE-2024-9680 and CVE-2024-49039) to conduct a cyber espionage and financially motivated campaign between October and November. The vulnerabilities affect Mozilla’s Firefox, Thunderbird, Tor internet browsers and connected Windows systems; they enabled the group to install the RomCom backdoor onto targeted systems. The campaign began with a malicious web page containing the exploit code, though it remains unclear how RomCom distributed the web page links. When users visited the fake websites via a vulnerable browser, CVE-2024-49039 was exploited through the execution of malicious shellcode in the browser’s content process without requiring any user interaction. Notably, this was only achieved in conjunction with the exploitation of the second vulnerability (CVE-2024-9680), which provided the threat actors with arbitrary code-execution capabilities in vulnerable content processes. The shellcode then deployed the main RomCom payload via a multi-stage process that also simultaneously evaded security mechanisms. The RomCom backdoor allows the group to maintain long-term access to compromised systems, to exfiltrate sensitive data and to deploy additional malware, including ransomware (for financial profit). The latest campaign has underscored RomCom’s high sophistication; it identified and exploited two zero-day vulnerabilities to infiltrate victims covertly in a zero-click attack (a type of attack that does not require any user interaction to download malware or other malicious code).

Some non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security-detection systems to detect potentially malicious samples on the network
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
  • Ensure adequate security monitoring and detection capabilities, particularly for all external-facing services and devices; this includes personal devices connected to corporate networks or applications
  • Adopt and review network authentication services including virtual private network (VPN) services and multi-factor authentication (MFA)

Our cyber word(s) of the week: Bootkit

(Source: Sibylline)

 

03 Dec 24. Taiwan: Malware campaign heightens security, information-theft risks to firms. On 2 December, the cyber security company Fortinet disclosed that unnamed threat actors exploited two Microsoft Office software vulnerabilities (CVE-2017-0199 and CVE-2017-11882) to conduct an information theft campaign in September. The campaign targeted Taiwanese organisations within the manufacturing, healthcare and IT sectors. The attack started with phishing emails containing a malicious attachment; the attachment then exploited the two software vulnerabilities to obtain remote code execution capabilities and deploy the ‘SmokeLoader’ malware onto targeted systems. SmokeLoader subsequently installed several plugins to extract sensitive information and credentials from popular web browsers. SmokeLoader is typically advertised and used by cyber criminals for financial profit. However, we assess that there is a realistic possibility that this campaign may have aimed to obtain access to targeted systems for future malicious activity, given the significance of the targeted sectors and Taiwan’s geopolitical relevance. This highlights heightened security and information theft risks to Taiwanese organisations in the medium-to-long term. (Source: Sibylline)

———————————————————————————————————————————————————————————————————————————————————————————————————————————

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

———————————————————————————————————————————————————————————————————————————————————————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

November 29, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

————————————————————————————————————————————————————————————————————————————————————————————————————————————

27 Nov 24. Savox displays the future of safe and secure comms at PMRExpo 2024 booth C011. The Savox stand in Cologne showcases a wide array of innovative and proven communication controllers, mission-critical broadband products, hearing protective headsets, and wireless team communication solutions.

“Our philosophy centers on understanding professionals, their challenges, and overcoming obstacles. We prioritize delivering audio solutions that ensure clear communication, protect specialists—an organization’s most valuable asset—and empower them to perform at their best, regardless of the task or conditions.”, Sales Director Teppo Parviainen

Applying some of the latest advances in Bluetooth technology, as well as solving common challenges regarding, for example, audio clarity, integration, and versatility, Savox brings to Cologne major releases and updates to our proven line-up of secure communication products and solutions.

C-C200 Push-to-talk unit

Sleek in design, while being the most robust PTT nexus-connector in the market, the C-C200 provides a new level of safety and reliability, as well as innovative usage features. Its compact form fits easily on all workwear and tool vests, the wide variety of clip-on fixtures, silent stealth feature, and safe PTT button take functionality to a new level.

Pack-COM wireless team comms system

A unique wireless team communication system with encrypted full-duplex functionality. The portable base station creates a secure mid-range communication bubble allowing for a wide range of radio capabilities to be integrated into the system.

LIVECONNECT 200 body camera

This rugged high-definition wearable bodycam’s innovative features allow users to fully leverage the data and video capabilities of modern broadband networks and terminals, enabling seamless video streaming and video call between front-line workers and teams leads, command centers, and control rooms.

NOISE-COM 300 hearing protector

Specifically designed and built for safety and clarity in tough conditions, the NC-300 works with most available two-way radios. Crafted with high-quality components and sealed electronics, a built-in PTT button, and advanced noise cancellation microphone with extended battery-free performance in the noisiest of industrial environments.

 

27 Nov 24. US DLA completes inaugural hackathon with $3.5m AI contracts . The contracts were granted to Accenture, Knexus and Scale AI. The initiative, launched in spring 2024, aimed to address critical issues within the DLA. Credit: DOD photo by Chris Lynch/Defense Logistics Agency. The US Defense Logistics Agency (DLA) has marked the completion of the final phase of its first hackathon by awarding three AI contracts worth a total of $3.5m.   The initiative, launched in spring 2024, aims to address critical issues within the DLA through AI solutions. The contracts were granted to Accenture, Knexus and Scale AI.   The awarded contracts focus on exploring AI tools to create reporting mechanisms for demand planning use cases, develop a customised chatbot application and implement virtual agents for acquisition business systems.   Hackathon provided vendors with an opportunity to showcase their AI and machine learning capabilities in addressing DLA’s operational challenges.  A key objective of the initiative was to establish an acquisition model for testing, piloting and procuring AI and machine learning technologies tailored to DLA’s specific requirements.  DLA chief information officer Adarryl Roberts stated: “DLA’s goal to become a digital organisation is a journey that starts with standardising how the agency uses emerging technologies to answer DLA’s critical logistics challenges.

“These awards are our first attempt to expand our use of AI and create a repeatable end-to-end procurement solution.”

The process began with a broad agency announcement in March 2024, inviting companies to submit white papers on their capabilities, followed by technical and cost proposals for accepted submissions.  The DLA was particularly interested in vendors who could offer technology solutions with an understanding of the agency’s business and supply chain dynamics.   A team of DLA experts in research and development, AI and cybersecurity reviewed 46 submissions, evaluating them on scientific and technical merit, feasibility, viability, desirability and experience in AI.  The submissions were narrowed down to 17 entries, and then to 12.  Six vendors were selected, based on these assessments, to present proposals at an in-person event on 24 June 2024 to 50 leaders from the Defense Department, military services, DLA and academia. The technical evaluation team re-evaluated vendors’ white papers, technical and cost proposals, and in-person demonstrations to select the three winners. DLA plans to conduct its next hackathon in 2025.  (Source: airforce-technology.com)

 

28 Nov 24. Global: New malware will raise security risks to Linux systems. On 27 November, the cyber security company ESET reported the discovery of a new unified extensible firmware interface (UEFI) bootkit (‘Bootkitty’) designed to target Linux systems. Bootkitty bypasses verification checks during the start-up process, executing at the core of compromised systems. The actors then disable additional security mechanisms in the system’s memory, effectively obtaining full control over compromised devices. This enables them to modify system components, inject malicious code and deploy additional malware. We assess that Bootkitty is likely still in development due to the lack of refinement in its obfuscation capabilities and limitations in the number of Linux systems it can successfully target. Bootkitty is the first UEFI bootkit to be created for Linux systems. Similarly, on 23 November, a new Linux-based malware was reported, underscoring the continuous development and expansion of malware targeting Linux-based systems. This will raise security risks for global entities in the medium term. (Source: Sibylline)

 

28 Nov 24. Nokia upgrades Cloudbear network to offer customized hosting services in Europe.

  • Nokia to provide complete data center networking solution including fabric switching, interconnection and peering.
  • Dutch hosting provider praises Nokia’s community-driven approach from discord server channels to open source projects and tools.
  • Partnership lays groundwork for future data center expansion.

Nokia has been selected by Cloudbear, a growing hosting services provider in the Netherlands, to implement its state-of-the-art data center networking infrastructure. This complete data center deployment is implemented on the Kuberbetes-based CBWS hosting environment. Nokia’s deployment includes an ultra-reliable data center fabric switching, and data center gateway routers that provider IP data center interconnection, and IP peering. With this implementation, Cloudbear will further enhance its ability to provide customized hosting services to meet very specific customer requirements with maximum efficiency. In addition, Cloudbear’s ability to deliver fast, reliable, and secure hosting services to its customers across Europe is augmented.

As part of the partnership, Cloudbear has benefited from having access to Nokia’s community. For instance, the SR Linux Discord channel has provided them with quick access to questions about Cloudbear’s implementation. The Dutch provider has also used Nokia’s open source project Containerlab for its CI/CD pipeline implementation.

Marlin Cremers, co-founder of Cloudbear, said: “The flexibility and reliability of Nokia’s networking solutions allow us to bring services faster to market and with great efficiency, ensuring our customers benefit from high-quality, secure services. Working with Nokia, we were able to satisfy all our data center networking requirements from a single vendor. This includes ultra reliable DC fabric switching, world class IP data center interconnection, and highly scalable IP Peering. Other than a reputation of high-quality products, Nokia’s personal touch and community-driven approach has been a key differentiator and has stood out from day one, showing Nokia’s true commitment to this partnership.”

Matthieu Bourguignon, Senior Vice-President and Head of Europe for Network Infrastructure business at Nokia, commented: “This partnership highlights how Nokia’s complete data center solution from fabric switching to other essential IP networking capabilities can be leveraged to unlock the next generation of hosting services delivered by companies like Cloudbear. Our tailored approach and commitment to customer success ensures that businesses of all sizes can benefit from Nokia’s comprehensive range of data center solutions and ongoing support. We are dedicated to empowering companies through every phase of their journey, from pre-purchase to deployment and ongoing operations, ensuring customers like Cloudbear have the resources they need to thrive.”

Cloudbear is laying the groundwork for future growth and has deployed a complete data center networking solution from Nokia. This includes Nokia’s 7220 IXR-D series platforms for data center leaf, and spine roles, while also leveraging these platforms as a Data Center Gateway to connect to upcoming data center locations within their infrastructure. As part of this deployment Cloudbear has deployed Nokia’s SR Linux Network Operating System (NOS) offering a new level of openness, telemetry, and programmability conducive to network automation. Additionally, Cloudbear has deployed Nokia’s flagship 7750 SR-1 router, enabling Cloudbear to peer with the internet and other networks with massive scale.

Resources and additional information

Product page: 7220 Interconnect Router for Data Center Fabrics | Nokia

Product page: Service Router Linux (SR Linux) | Nokia

Product page: Nokia 7750 Service Router

About Nokia

At Nokia, we create technology that helps the world act together.

As a B2B technology innovation leader, we are pioneering networks that sense, think and act by leveraging our work across mobile, fixed and cloud networks. In addition, we create value with intellectual property and long-term research, led by the award-winning Nokia Bell Labs.

With truly open architectures that seamlessly integrate into any ecosystem, our high-performance networks create new opportunities for monetization and scale. Service providers, enterprises and partners worldwide trust Nokia to deliver secure, reliable and sustainable networks today – and work with us to create the digital services and applications of the future.

About Cloudbear

Cloudbear is revolutionising managed cloud services by empowering businesses to focus solely on developing their SaaS applications or supporting agencies that create (SaaS) applications for their clients. While customers concentrate on innovation, Cloudbear takes care of the heavy lifting—designing and managing infrastructure, Continuous Deployment pipelines, monitoring, and dashboarding.

At the heart of their services is CBWS, Cloudbear’s state-of-the-art cloud environment based in Eindhoven, The Netherlands. Powered by Nokia’s advanced networking technology, CBWS delivers low-latency, high-throughput solutions optimised for the needs of SaaS businesses and development agencies.

With a focus on scalability, security, and performance, Cloudbear enables companies and agencies to streamline operations, speed up deployment cycles, and bring transformative applications to market with confidence. Whether you’re developing your own SaaS product or helping others build theirs, Cloudbear is the trusted partner for a reliable, cutting-edge cloud foundation.

 

26 Nov 24. Bombardier delivers first Global 6500 aircraft to US Army. The aircraft is expected to support the modernisation of US aerial military intelligence. Bombardier Defense has delivered the first Global 6500 aircraft to the US Army, which will support prototyping efforts for the High Accuracy Detection and Exploitation System (HADES).   This comes after a contract was signed in January 2024 by the US Army Contracting Command-Redstone Arsenal with Bombardier for the acquisition of Global 6500 jets.  Through the HADES programme, the army will develop a fleet of aerial intelligence, surveillance, and reconnaissance (ISR) systems equipped with signals intelligence, synthetic aperture radar/moving target indicator, and other integrated capabilities. HADES will provide the army with enhanced range, speed, endurance, and ISR coverage.  Bombardier Defense vice-president Steve Patrick said: “Bombardier Defense is honoured to support the US Army with the delivery of the first Global 6500 aircraft, a high-performance platform that possesses the speed, endurance-at-range and altitude capabilities to support deep-sensing for the army of tomorrow.”  Bombardier Global 6500, a fixed-wing platform, offers enhanced performance for aerial ISR missions due to its ability to fly faster, longer, and higher than legacy airborne sensor platforms, the company noted.  The aircraft measures 99ft 5in in length, 25ft 6in in height, and has a wingspan of 94ft.   The HADES prototypes will mark the first use of large-cabin business jets by the US Army for aerial ISR, offering advanced deep-sensing capabilities for multidomain operations against peer and near-peer threats. Operating at higher altitudes than existing turboprop platforms, it will enable more extensive and continuous sensing over areas of interest. Deep sensing is a critical operational priority for the army’s future capabilities. US senator Jerry Moran said: “The partnership between Bombardier, the US Army and the Wichita workforce has produced a next-generation aircraft equipped to meet the demands of warfare in a new era of technology.  The HADES aircraft has the tools needed to deter threats, conduct surveillance and help keep our country safe.”  (Source: army-technology.com)

 

26 Nov 24. IronNet, a leader in cybersecurity pioneering Collective Defense, announced an expanded partnership with Morgan Business Consulting (MBC), a trusted provider of advisory services within the Defense Industrial Base (DIB). Building on a long-standing relationship, MBC has selected IronNet’s Network Detection and Response (NDR) solution to enhance threat visibility and proactively defend against sophisticated cyber threats. With IronNet’s AI-driven analytics and behavioral monitoring, MBC gains advanced capabilities to secure critical defense systems and fortify its cybersecurity posture.

“We’re excited to expand our partnership with IronNet to bring their Network Detection and Response (NDR) solution and Collective Defense platform to the Defense Industrial Base. With IronNet’s strong new leadership and continued innovation, our confidence in their ability to provide advanced, collaborative cybersecurity solutions has only strengthened,” said Sherome Lewis, Director of Information Technology at MBC.

MBC initially collaborated with IronNet through a NAVSEA contract, and this expanded partnership underscores a shared commitment to bolstering cybersecurity within the Defense Industrial Base. With the deployment of IronNet’s advanced NDR technology, MBC gains deeper network visibility, empowering them to proactively identify and mitigate potential threats before they escalate. This enhanced capability aligns with MBC’s mission to protect critical defense assets through coordinated and cutting-edge cybersecurity measures.

“Pacing the threat, pacing the technology and shared situational awareness across the entire DIB are hallmarks of the MBC, IronNet partnership,” said Retired Rear Admiral Mike Hewitt, Lead Independent Director on IronNet’s board. “I am excited to see the growth of these two companies as we continue our commitment to the war fighter and the industry that supports our men and women in uniform.”

“We are excited to deepen our relationship with Morgan Business Consulting, an organization that shares our commitment to securing the Defense Industrial Base,” said IronNet CEO, Linda Zecher. “This partnership exemplifies our dedication to delivering powerful, next-generation cyber defense that empowers DIB members to stay ahead of emerging threats.”

Through this expanded partnership, MBC leverages IronNet’s NDR capabilities for comprehensive threat detection, tailored to the unique needs of the Defense Industrial Base. MBC’s participation in IronNet’s Collective Defense model enables real-time, anonymized threat intelligence sharing across the DIB community, strengthening the resilience of the broader defense ecosystem. IronNet’s scalable, cost-effective cybersecurity solutions provide MBC and other DIB members with robust protection, ensuring secure, proactive defenses against evolving cyber threats.

About IronNet

IronNet, founded in 2014, merges industry-leading cybersecurity products with unrivaled service to deliver the most advanced real-time defense across global, private, and public sectors. Bringing together some of the best minds in cybersecurity and an unmatched team of experts from industry, government, and academia, IronNet was born to more effectively defend enterprises, sectors, and nations against highly organized cyber adversaries and increasingly sophisticated attacks.

About Morgan Business Consulting (MBC)

Founded in 2003, MBC is a Veteran-owned small business specializing in Management and IT consulting for government and commercial clients worldwide. With expertise in areas such as Supply Chain, Program Management, and Financial Advisory, MBC delivers impactful, mission-critical solutions. Headquartered in Washington, D.C., with offices in San Diego, Dayton, Ohio, and Japan, MBC is dedicated to exceeding client expectations through a collaborative and results-driven approach.

(Source: PR Newswire)

 

26 Nov 24. L3Harris Completes CDR for Space Development Agency Satellite Radios. Radios enhance satellite data processing and communication systems, advancing the Space Development Agency’s mission to bolster our nation’s missile warning and defense capabilities. L3Harris Technologies has reached a major milestone in its mission to provide the Space Development Agency (SDA) with space-based capabilities that enhance our national security. The company conducted a Critical Design Review for 45 mission payload (MPL) radios and 40 CXK-1000 radios they are designing, developing and producing in support of Lockheed Martin Space’s Tranche 2 (T2) Transport Layer Beta contract with the Space Development Agency (SDA). The MPL radios will handle and process warfighting data supporting Integrated Broadcast System-low Earth orbit (IBS-L) and tactical satellite communication users, while the CXK-1000 radios will enable Ka-band communication, which enables the transmission of data to and from the satellites. T2 Transport Layer Beta is one of several key activities L3Harris is working in support of the SDA’s Proliferated Warfighter Space Architecture, a resilient, layered network of military satellites in low-Earth orbit.

Other L3Harris activity completed and underway for other SDA programs includes:

  • Tranche 0 (T0) Tracking Layer: In early 2024, four missile-tracking satellites designed and built by L3Harris launched into orbit as part of the SDA’s T0 program. SDA’s Tracking Layer will demonstrate global indications, warning, tracking and targeting of advanced threats such as hypersonic missiles.
  • Tranche 1 (T1) Tracking Layer: L3Harris is designing and building 16 missile-tracking satellites as part of the T1 constellation, slated to launch in 2025. The satellites feature infrared sensors and advanced algorithms that rapidly detect, track and fuse threat data that is provided to the warfighter in real time.
  • Tranche 2 (T2) Tracking Layer: In early 2024, the SDA awarded L3Harris a $919 m contract to develop 18 infrared space vehicles for the T2 Tracking Layer program, which will provide near-global missile warning and tracking coverage.

“L3Harris is proud to be a leading partner to the Space Development Agency in the rapid development of missile warning and missile defense technologies in support of national security,” said Ed Zoiss, President, Space and Airborne Systems, L3Harris. “We’re able to leverage our extensive experience and innovative approach to continuously refine and enhance capabilities across each tranche, accelerating the launch of mission systems into orbit on faster timelines.” (Source: ASD Network)

 

26 Nov 24. Japan: Re-emergence of backdoor points to risks facing political sphere from Chinese state actors. On 26 November, the cyber security company Trend Micro reported on a new cyber espionage campaign that is being carried out by the suspected Chinese state-sponsored group ‘Earth Kasha’. The campaign has been ongoing since June; it targets individuals in Japan affiliated with politics, research institutions, think tanks and organisations linked to international relations. It begins with spear phishing emails that try to trick users into downloading a .ZIP file that deploys the ‘ANEL’ and ‘NOOPDOOR’ backdoors. Notably, ANEL was previously employed by ‘APT10’ until 2018; it was not observed until this latest campaign, pointing to the malware’s re-emergence and likely ongoing development. NOOPDOOR is also exclusively used by Earth Kasha against high-value targets, underscoring the targeted nature of this operation. As such, we assess there are heightened security risks facing those entities within the international relations sphere in Japan in the medium-to-long term as Earth Kasha continuous to shifts its tactics. (Source: Sibylline)

 

25 Nov 24. Bittium Wireless Ltd, a Subsidiary of Bittium Corporation, and Finnish Defence Forces Signed a Partnership Agreement. Bittium Wireless Ltd, a subsidiary of Bittium Corporation, and the Finnish Defence Forces have signed a Partnership Agreement for the years 2025–2036. The Partnership Services to be purchased under the agreement apply to the life cycle setup and maintenance of the command-and-control systems manufactured by Bittium and used by the Finnish Defence Forces. Those include for example tactical communications systems and the products related to the systems (Bittium Tactical Wireless IP Network™, Bittium Tough SDR™, Bittium Tough VoIP™) as well as their related maintenance and further development.

The Partnership Agreement establishes a framework for purchasing Bittium’s products, software, and services. The purchases are planned together with the Finnish Defence Forces for each year. The Finnish Defence Forces will issue separate purchase orders for the products and services in several batches according to what has been agreed in the Partnership Agreement. The monetary value of the Partnership Agreement depends on the needs and funding of Finnish Defence Forces’ projects and on the agreed maintenance and development services for each year.

The purpose of the agreement is for the partnership to become a solid part of the national defence and to ensure the availability of national competence and technologies in Finland that are critical for the military security of supply. The agreement was signed on Monday, November 25, 2024, at Tampere, Finland by the Chief of the Finnish Defence Forces Logistics Command, Brigadier General Tero Ylitalo and Director of the Finnish Defence Forces Logistics Command Joint Systems Centre, Colonel Jari Virolainen, along with the CEO of Bittium Corporation Johan Westermarck and Senior Vice President of Defense & Security Business Segment Tommi Kangas.

“The Partnership Agreement is the result of cooperation that has continued for decades and establishes a framework for collaboration long into the decade to come. We are very proud of the trust and confidence shown in our products and solutions. The agreement signed now creates mechanisms for joint planning for both normal conditions and states of emergency. Those mechanisms allow Bittium to plan and supply products, service, repair, maintenance, and development related activities for the Finnish Defence Forces in the long-term,” says Johan Westermarck, CEO of Bittium Corporation.

The Partnership Agreement replaces the purchase agreement and its option for additional purchases of Bittium Tough SDR Handheld and Vehicular radios that was signed by Bittium and the Finnish Defence Forces on December 12, 2018. The framework agreement signed on November 14, 2023, by Bittium and the Finnish Defence Forces for the purchase of the software-defined radio based Bittium Tactical Wireless IP Network™ (TAC WIN) system’s products and Bittium Tough Comnode™ communications devices and related accessories, will be included as part of the Partnership Agreement.

Bittium announced on April 5, 2024, with a stock exchange release that the Finnish Minister of Defence Mr. Antti Häkkänen had authorized the Finnish Defence Forces to sign a partnership agreement with Bittium Wireless Ltd.

 

25 Nov 24. Asia-Pacific: Linux backdoor points to ongoing security risks amid threat actors’ development. On 23 November, international media sites reported that the China-linked group ‘Gelsemium’ had been deploying a previously unknown Linux backdoor (‘WolfsBane’) in a cyber espionage operation since March 2023. It is not clear if this operation is ongoing. The campaign targeted the Philippines, Singapore and Taiwan. Gelsemium also previously targeted the Middle East region. While it is unclear how the group obtains initial access to targeted networks, there is a realistic possibility that it is able to exploit an unknown web application vulnerability that allows it to obtain persistence via web shells. WolfsBane operates similarly to Gelsemium’s Windows-based malware (‘Gelsevirine’), underscoring the group’s ongoing development of its malware arsenal. Additionally, there is a realistic possibility that threat actors will increasingly migrate towards exploiting vulnerabilities in internet-facing systems that use Linux, especially as Windows’ email endpoint security defences continue to improve. As such, we assess that the use of Linux-based malware against public-facing web applications will elevate long-term security risks for firms operating in the Asia-Pacific region. (Source: Sibylline)

 

25 Nov 24. UK and its allies must stay one step ahead in new AI arms race. UK announces new Laboratory for AI Security Research at NATO Cyber Defence Conference.

  • AI “revolutionising many parts of life – including national security” – Chancellor of the Duchy of Lancaster to say
  • New Laboratory for AI Security Research that will partner with world-leading experts from UK universities, the intelligence agencies and industry to boost Britain’s cyber resilience and support growth launched by government
  • New research will receive around £8m of initial government funding, with industry encouraged to invest in the partnership to support future research.

“NATO needs to continue to adapt to the world of AI, because as the tech evolves, the threat evolves”, the Chancellor of the Duchy of Lancaster will tell the NATO Cyber Defence Conference at Lancaster House on Monday.

To help the UK stay ahead in the “new AI arms race” the Chancellor of the Duchy of Lancaster will announce a new Laboratory for AI Security Research (LASR) to protect the UK and its allies against new threats, saying:

The lab will pull together world-class industry, academic and government experts to assess the impact of AI on our national security.

While AI can amplify existing cyber threats, it can also create better cyber defence tools and presents opportunities for intelligence agencies to collect, analyse, and produce more useful intelligence.

The Laboratory for AI Security Research will employ a ‘catalytic’ model, receiving an initial £8.22m round of government funding, inviting further investment and collaboration from industry.

Partners will include the Foreign Commonwealth and Development Office, the Department for Science Innovation and Technology, Government Communications Headquarters (GCHQ), National Cyber Security Centre, the MOD’s Defence Science and Technology Laboratory, the Alan Turing Institute, the AI Safety Institute, the University of Oxford, Queen’s University Belfast and Plexal. The laboratory will seek collaboration with like-minded partners, starting with the Five Eyes countries and NATO allies.

Addressing cyber and defence experts, he will say that:  “Cyber war is now a daily reality. One where our defences are constantly being tested. The extent of the threat must be matched by the strength of our resolve to combat it and to protect our citizens and systems. 75 years after its foundation, it is clear we need NATO more than ever. NATO has stayed relevant over the last seven decades by constantly adapting to new threats. It has navigated the worlds of nuclear proliferation and militant nationalism. The move from cold warfare to drone warfare. The gathering is the second ever NATO Cyber Defence Conference and the first to be held in London. The Chancellor of the Duchy of Lancaster will caution:  AI is already revolutionising many parts of life – including national security. But as we develop this technology, there’s a danger it could be weaponised against us. Because our adversaries are also looking at how to use AI on the physical and cyber battlefield.”

And he will say: “Be in no doubt: the United Kingdom and others in this room are watching Russia. We know exactly what they are doing, and we are countering their attacks both publicly and behind the scenes.

We know from history that appeasing dictators engaged in aggression against their neighbours only encourages them. Britain learned long ago the importance of standing strong in the face of such actions.  That’s why we support Ukraine in its fight to decide its own destiny. Putin is a man who wants destruction, not peace. He is trying to deter our support for Ukraine with his threats. He will not be successful.”

He will also reflect that: “Last year, we saw the US for the first time publicly call out a state for using AI to aid its malicious cyber activity. In this case it was North Korea who had attempted to use AI to accelerate its malware development and scan for cybersecurity gaps it could exploit. North Korea is the first, but it won’t be the last.

Alongside the new laboratory, the Chancellor of the Duchy of Lancaster will also announce a new £1m incident response project to share expertise so that allies can respond to cyber incidents more effectively.

Stephen Doughty, Minister for Europe, North America and UK Overseas Territories, will also attend the conference at Lancaster House. He said:

AI has enormous potential. To ensure it remains a force for good in the world, we need to understand its threats and its opportunities.

Today we have launched a new, world-leading research lab to enhance AI security to ensure the UK and our allies reap the benefits of AI, while detecting, disrupting and deterring adversaries who would use it to undermine our national security and economic prosperity.”

LASR builds on the UK’s position as the global birthplace of modern computing, following the pioneering legacy of Alan Turing. It is part of the government’s wider work to improve the UK’s cyber defences and grow the economy, which includes the forthcoming Cyber Security and Resilience Bill and recent designation of data centres as critical national infrastructure. (Source: https://www.gov.uk/)

 

25 Nov 24. NDA opens new specialised cyber facility. The Nuclear Decommissioning Authority (NDA) group has launched a specialised cyber facility to accelerate collaboration across nuclear operators and the supply chain, on the adoption of innovative technologies such as AI and robotics and enhancing their collective ability to successfully defend against cyber threats.

Cyber security attacks are a common and dynamic threat across all organisations, including the civil nuclear sector.

The Group Cyberspace Collaboration Centre (GCCC) provides a space for experts in cyber, digital and engineering to come together and share knowledge and learning on how best to adopt new technologies and defend against evolving threats.

David Peattie, NDA Group CEO, said: “The GCCC is further enhancing our collective ability to keep us safe, secure, resilient and sustainable in cyberspace. Enabling us to work together more closely means we can defend as one, benefitting the collective security of the individual organisations we serve. When it comes to security, we are never complacent, and we continually invest in our expertise and our technology to further strengthen our capability.”

Representatives from government, the nuclear sector, regulators and the supply chain attended the official opening which showcased the capability of the centre.

They heard about the NDA’s continued investment in cyber defences and the safe and secure use of technology in delivering its decommissioning mission.

Warren Cain, ONR Superintending Inspector, said: “All nuclear sites must have strong cyber security systems in place to protect important information and assets from cyber threats.  Cyber security is a key regulatory priority for the Office for Nuclear Regulation, and we welcome the NDA’s commitment to strengthen their cyber defences with this new specialist facility.”

The NDA is the body tasked by the government to clean-up the UK’s earliest nuclear sites safely, securely and cost effectively. The NDA group is made up of the NDA and its four key component parts Sellafield, Nuclear Restoration Services, Nuclear Waste Services and Nuclear Transport Solutions.

The NDA has invested in group-wide cyber services and capabilities to ensure systems are better protected and more resilient and delivering a strong, consistent approach to common cyber security threats.

The GCCC, situated in Herdus House in Cumbria, is a multi-functional space for partners to explore how new technologies can support mission delivery and facilitate security operations, cyber exercising and training.

It is part of the NDA group’s growing portfolio of digital and cyber capability including a joint Cyber Security Operations facility, which opened in Warrington in August.

It’s part of a constellation of related leading cyber and digital capabilities, including the Cyber Lab classroom at Energus, the Sellafield Engineering Centre of Excellence, and the Robotics and AI Collaboration centre (RAICo1). (Source: https://www.gov.uk/)

 

25 Nov 24. Australian Cyber Security Act passed into law. Today (25 November, the Albanese government passed Australia’s first standalone Cyber Security Act.

The act, launched as part of the 2023–2030 Australian Cyber Security Strategy, aims to address gaps in Australia’s cyber resilience and move towards the government’s goal of making Australia the most cyber secure country in the world.

“The Australian government is delivering on its commitment to secure Australia’s cyber environment and protect our critical infrastructure,” said Minister for Cyber Security Tony Burke.

“The government has passed into law Australia’s first standalone Cyber Security Act, a key pillar in our mission to protect Australians from cyber threats.

“This package forms a cohesive legislative toolbox for Australia to move forward with clarity and confidence in the face of an ever-changing cyber landscape.”

The Cyber Security Act will execute seven initiatives first introduced under the Cyber Security Strategy.

Most notable is the introduction of the “limited use” obligation, which will outline restrictions imposed on the Australian Signals Directorate (ASD) and the National Cyber Security Coordinator for how information shared by organisations that have suffered a cyber attack can be used, potentially protecting them from being punished and encouraging organisations to report incidents.

“Close cooperation between government and industry is one of our best defences against malicious cyber activity. In the wake of a cyber security incident, businesses need to know that they can call on government to quickly get the support they need,” said Minister Burke.

“The Cyber Security Act marks an important step in bringing Australia’s cyber laws into the 21st century.”

Certain organisations will also be required to report when they pay a ransom to threat actors, allowing cyber professionals to better understand how threat actors operate.

Additionally, the legislation will allow for the cyber security minister to set cyber security standards for smart devices to guide Australians on buying more secure devices and will see a Cyber Incident Review Board (CIRB) established to “conduct no-fault, post-incident reviews” of major, high-profile cyber security incidents and make recommendations to deal with future incidents.

The Security of Critical Infrastructure Act 2018 (SOCI) will also be reformed, simplifying the sharing of information between government and industry, including the regulation of telcos into the act, expanding the government’s last resort powers to allow it to better deploy aid in the event of a critical infrastructure cyber attack and allow the government to direct entities to deal with major flaws in their risk management programs. (Source: https://www.cybersecurityconnect.com.au/)

 

22 Nov 24. L3Harris Hits Key Testing Milestones in Modernizing F/A-18 EW Capabilities.

Successful hardware checks and simulation tests keep cutting-edge EW system prototype on pace for further development.

L3Harris continues to deliver on its promise to elevate electronic warfare (EW) capabilities on the U.S. Navy’s F/A-18 Super Hornet fighter jet, modernizing its defenses to protect aircrews from emerging threats in increasingly contested, complex environments. As part of an $80 m contract awarded in 2023 to develop a next-generation EW system for the Boeing-made aircraft, L3Harris recently successfully completed critical hardware checks and cutting-edge capability demonstrations that set the stage for the next phase of integration and testing.

Over a two-day period in August, teams from L3Harris and Boeing came together at the Navy’s air test and evaluation unit in Patuxent River, Md., to conduct hardware fit checks on our Advanced Electronic Warfare (ADVEW) system for the F/A-18. The L3Harris team used 3D-printed models of the system, including connectors and wiring, to ensure the system’s physical interfaces will integrate properly with the aircraft. No significant issues were found, validating our design and smoothing the path toward further prototype development.

The successful fit checks show that using 3D printed models is a smart, effective way to test and develop new technology. By creating detailed, physical replicas of components, engineers can identify and resolve potential issues well ahead of the formal prototype modification period.

Simulation tests reveal groundbreaking ADVEW capabilities

The L3Harris and Naval Air Systems Command team put ADVEW through its paces at the U.S. Navy’s Threat Air Defense Lab (TADL), which provides a closed-loop simulation environment to evaluate capabilities against government-validated threat models. ADVEW achieved expectations over five days of rigorous testing, demonstrating cutting-edge capabilities in advanced threat response techniques.

“These two critical testing milestones are our latest successes in decades of delivering cutting-edge EW capabilities to the F/A-18,” said Jennifer Lewis, President, Airborne Combat Systems, L3Harris. “We’re proud of the progress we’ve made and excited to move to the next phase of development as we continue push the boundaries of what’s possible in protecting U.S. Navy aircrews from emerging threats.”

L3Harris plans to conduct the next major design review with the Navy by the end of 2024. Prototype integration and testing are planned for Q1 2025, with delivery of the initial system expected in Q2. The Navy aims to conduct chamber testing in late 2025, where it’ll validate the system installed in an actual F/A-18. (Source: ASD Network)

 

22 Nov 24. Cyber Update Key points.

  • A fraudulent artificial intelligence (AI) content generator application is being used to distribute malware, pointing to elevated information-theft and financial risks from cyber criminals (see Sibylline Cyber Daily Analytical Update – 18 November 2024 and our Technical analysis below).
  • The exploitation of a zero-day vulnerability increases espionage risks from the Chinese state-sponsored group ‘BrazenBamboo’
  • The security breach of an additional US telecommunications provider amid recent security breach disclosures by prominent telecommunications firms underscores ongoing security risks from the Chinese state-sponsored group ‘Salt Typhoon’ (see Sibylline Cyber Daily Analytical Update – 20 November 2024).
  • Sensitive patient data was exposed in a data breach of a French hospital, highlighting security and social engineering risks to hospitals and patients see Sibylline Cyber Daily Analytical Update – 21 November 2024.
  • A new cyber operation points to heightened espionage risks from the Russian state-sponsored group ‘TAG-110’

Technical analysis of weekly stories

Threat actors are using a fake artificial intelligence (AI) content generator application to distribute the ‘Lumma Stealer’ and ‘AMOS’ information-stealing malware. The fake application is promoted on the social media platform ‘X’ (formerly known as Twitter) via advertisements showcasing deepfake political videos. The advertisement redirects users to a fraudulent website where they are tricked into clicking on malicious buttons purporting to download the fake AI application. However, this covertly installs the malware (Lumma Stealer for Windows and AMOS for macOS systems) onto victims’ devices. The website also contains a fake cookie banner asking users to consent to store browsing activity to mimic authorised online activity and enhance the website’s legitimacy. Upon installation, both malware strains exfiltrate cryptocurrency wallets and other sensitive information from Chromium-based browsers. Lumma Stealer uses techniques such as process injection to prolong detection evasion while AMOS enables low-skilled threat actors to easily deploy malware, manage infected systems and exfiltrate data with the help of a unified platform. Subsequently, the stolen information is sent to an actor-controlled archive to be retrieved at a later stage. This data is likely then sold on the dark web or used in follow-on attacks for financial profit.

The Chinese state-sponsored group BrazenBamboo is exploiting an uncategorised zero-day vulnerability in an ongoing cyber espionage campaign. The vulnerability affects Fortinet’s FortiClient Windows virtual private network (VPN) service and stores user credentials in process memory following user authentication. BrazenBamboo deploys a custom post-exploitation toolkit (‘DeepData’) to exploit the vulnerability, stealing exposed user credentials to likely infiltrate targeted systems by hijacking VPN accounts. The group also used another post-exploitation tool, ‘DeepPost’, to send stolen credentials to the command-and-control (C2) infrastructure. The actors likely move laterally within compromised systems to conduct additional espionage activities, including deploying a new Windows variant of the ‘LightSpy’ malware. LightSpy contains several plugins to steal additional data from compromised systems including key logs, audio, cookies and videos. Notably, this new variant remains fileless by executing the malware in the system’s memory, underscoring the sophistication of the group’s detection evasion capabilities.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
  • Ensure adequate security monitoring and detection capabilities, particularly for all external-facing services and devices; this includes personal devices connected to corporate networks or applications
  • Adopt and review network authentication services including virtual private network (VPN) services and multi-factor authentication (MFA).
  • Avoid downloading applications from untrusted third-party websites and only use the official websites and application stores to install applications and tools on devices.

Our cyber word(s) of the week: Execution in memory (Source: Sibylline)

 

22 Nov 24. Cuashub.com said today that Creomagic showcases UAS tech to counter electronic warfare. Creomagic Ltd., a developer of advanced communication technology, highlighted its work in secure and resilient communications for loitering munitions at SAE Media Group’s Loitering Munitions Conference in the UK on November 19-20. The company highlighted how its software-defined radio (SDR) seeks to nullify key C-UAS defences by protecting against electronic warfare techniques such as jamming, interception and GPS denial.

The focus on communication solutions comes at a time when loitering munitions and UAS are increasingly considered to be key components in the modern approach to warfare. As these systems have evolved, C-UAS strategies have naturally evolved alongside them and, with the development of loitering munitions that offer resistance against traditional electronic countermeasures, they will need to continue to do so.

This back and forth between UAS and C-UAS capabilities has been consistently demonstrated in the war in Ukraine, with each side constantly working to outpace the development of the adversary.

Creomagic’s Creo-ADL technology is designed to protect against countermeasures such as electronic jamming, interception and GPS denial, which are generally considered to be the most effective “soft-kill” solutions for neutralising UAS.

How does it work?

Creo-ADL incorporates AES-256 encryption alongside communication and transmission security to ensure data integrity and protect against interception. Cognitive SDR technology and frequency-hopping techniques enable anti-jamming measures, automatically mitigating interference in contested electromagnetic environments.

For scenarios where GPS signals are compromised, the technology enables navigation through RF-based positioning, utilising signal-of-arrival techniques. Additionally, its low-probability-of-interception and low-probability-of-detection capabilities make UAS much more difficult to track.

“These capabilities are not just technological advancements; they are operational imperatives,” explained Alex Shapochnik, CEO of Creomagic. “In environments saturated with countermeasures, the ability to securely and reliably exchange data determines mission success or failure.”

What are the implications for C-UAS?

As C-UAS systems grow more sophisticated, technologies like Creomagic’s represent a dual-edged evolution, enhancing offensive drone systems while challenging the efficacy of current defensive measures. The ongoing race between UAS and C-UAS technologies is accelerating the development of both.

While advancing the capabilities of their loitering munitions and protecting them against the C-UAS defences of the adversary is a development that any military commander would benefit from, it also raises the discussion around how we can counter the very same capabilities when possessed by that adversary.

https://cuashub.com/en/content/creomagic-showcases-uas-tech-to-counter-electronic-warfare/ (Source: https://cuashub.com/)

————————————————————————————————————————————————————————————————————————————————————————————————————————————–

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

——————————————————————————————————————————————————————————————————————————————————————————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

November 22, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

————————————————————————————————————————————————————————————————————————————————————————————————————————————–

19 Nov 24. AI used in UK defence review stays unnamed, but is “segregated” from networks. In response to a Freedom of Information (FoI) query from Army Technology, the SDR Secretariat declined to state which AI was being used.

The UK government has declined to disclose which artificial intelligence (AI) program is being used to assist in the analysis of submissions for the ongoing Strategic Defence Review (SDR), citing a public interest in favour of withholding the information.

In response to a Freedom of Information (FoI) query from Army Technology, the SDR Secretariat declined to state which AI was being used as its release “would likely prejudice current and future strategy development and operational capability”.

Of five specific queries, three regarded information that was being withheld in accordance with Section 22, Section 26(1)(b), and Section 43(2) on grounds of qualified exemption.

The FoI questions posed by Army Technology sought information on the AI program being used, the company which owns the program, and the value of the contract for SDR analysis.

However, the SDR Secretariat did respond to queries regarding the operating structure of the AI in its analysis of SDR submissions, stating that it was performing its function “within a segregated cloud architecture (e.g, virtual private cloud)” that was “isolated” from broader organisational systems and external networks.

“This compartmentalised structure ensures that operations remain independent, with no direct connectivity to other internal programs or the wider digital architecture. By maintaining this closed environment, we enhance data security and integrity whilst following robust data protection practices,” the SDR Secretariat’s response read.

AI use in UK defence review

In October 2024 it was revealed that the UK was using AI to assist in the analysis of thousands of responses into the future SDR), which is due to report in 2025 amid the potential for cuts to key defence procurement programmes amid a claimed £22bn ($27.8bn) black hole in the country’s public finances.

Disclosing the use of AI on 15 October, Minster for the Armed Forces Luke Pollard said it was “helping” to “comprehend and analyse over 8,000 responses across the propositions, totalling over 2.2 m words”.

Pollard said that the use of AI was “enhancing” the SDR team’s ability to “focus on complex tasks”, such as applying “robust challenge” to submissions through panel sessions during October and November this year.

“AI is not a replacement for human judgment, but an enabler of greater efficiency and one part of facilitating a more comprehensive review process. Decisions on drafting are solely made by the reviewers: Lord George Robertson, General Sir Richard Barrons and Dr Fiona Hill,” said Pollard.

The UK government confirmed on 15 October that over 1,700 individuals and organisations responded to the SDR request for comment, providing more than 8,000 answers across 23 propositions.

Respondents included serving and retired members of the UK military, the defence industry, the public, academics, members of the UK parliament, as well as UK allies and partners, including Nato.

GlobalData: AI sector growth “explosive”

Business and news analytics company GlobalData has projected generative AI to grow from $1.8bn in 2022 to $33.0bn as the rise in use of such technology continues to increase, particularly in areas such as data analytics.

Generative AI sees the creation of video, text, and images by AI models when presented with a dataset or prompt, with the most common example of its kind OpenAI’s ChatGPT AI chat program.

Manish Dixit, practice head of disruptive tech at GlobalData, said that the AI sector was experiencing “explosive growth”, driven by unprecedented levels of investment and the emergence of new players in the industry.

“The successful implementation of [hybrid neural architectures and cognitive systems] will fundamentally reshape decision-making, operational efficiency, and strategy across industries,” Dixit said.

Across the defence sector, AI has cemented its position as one of the most crucial technologies for the coming battlespace and is already being used in areas such as data analysis and mission operations. (Source: army-technology.com)

 

20 Nov 24. The EuroDASS consortium, the industrial partnership responsible for the Eurofighter Typhoon’s ‘Praetorian’ defensive suite, has unveiled details on the next generation of Typhoon sensing and jamming capabilities following the completion of concepting work and technology flight trials. EuroDASS partners Leonardo, ELT Group, Indra and Hensoldt, drawing on Europe’s sovereign electronic warfare expertise, are working with systems integrator BAE Systems to develop the system in support of its Typhoon Next Generation initiative.

The next-generation electronic warfare system will future-proof Typhoon against new and emerging threats through to 2060 and beyond, providing improved situational awareness and increased survivability.

Key features will include advanced complex threat characterisation, Digital Radio Frequency Memory (DRFM) capabilities and the provision of interfaces for an external, high-powered electronic attack pod for Suppression of Enemy Air Defence (SEAD) missions; a key NATO requirement. Wideband Active Electronically Scanned Array (AESA) Electronic Counter-Measures (ECM) will be provided with increased power for self-protection.

The new system will be a form-fit retrofit option for Typhoon’s in-service Defensive Aids Sub-System (DASS), named Praetorian after the elite Roman bodyguard corps. It will have no impact on the outer mould line of Typhoon and impose no restrictions on the current flight envelope. This minimises aircraft clearance and ensures ease of integration for new build aircraft as well as retro-fit to existing platforms. Typhoon will be more capable, more survivable, and more available, meeting the operational needs of air forces across Europe and the Middle East for decades to come.

The EuroDASS consortium has already completed substantial development work on the next-generation system, including the ‘Praetorian eVolution’ concepting phase and flight trials of component parts of the new capability.

Following concept finalisation, trials in 2023 saw digital receiver and band extension technologies flown on a test aircraft. Then in 2024, flight trials on-board a Eurofighter Typhoon were executed successfully. As well as maturing the capabilities, the partners were able to gather substantial data on representative threat scenarios to support further development.

Because threats to combat aircraft are expected to rapidly evolve in the decades to come, the Typhoon’s new defensive capabilities are being designed with a data-centric architecture at its core.

This includes the provision of high-speed, high-bandwidth infrastructure to transmit raw signal data to an advanced central processing hub. This will enable pilots to identify and prioritise multiple complex threats at once, and at greater ranges. Cognitive Electronic Warfare (CEW), using AI and machine learning will exploit the high-fidelity data captured and respond to new threats as they emerge.

The in-service Praetorian system has protected the aircraft for more than 30 years from threats including Infra-Red (IR/heat-seeking) and radar-guided missiles. Under the ongoing Eurofighter four-nation Phase 4 Enhancement (P4E) package, this system is being upgraded to make the most of its integration with Typhoon’s AESA radar options, including the in-service European Common Radar System (ECRS).

 

18 Nov 24. India, Japan to co-develop UNICORN mast for INS ships. 

The UNICORN mast is designed to enhance the stealth characteristics of naval platforms.

The governments of India and Japan have signed a memorandum of implementation (MOI) for the co-development of the Unified Complex Radio Antenna (UNICORN) mast.

The signing took place at the Embassy of India in Tokyo.

The MOI was signed by India to Japan ambassador Sibi George, and Japan Ministry of Defence (MoD) Acquisition Technology and Logistics Agency commissioner Ishikawa Takeshi.

The UNICORN mast, featuring integrated communication systems, is designed for fitment onboard Ships of Indian Navy and enhance the stealth characteristics of naval platforms.

Originally developed by NEC, Sampa Kogyo, and The Yokohama Rubber, the UNICORN mast is currently fitted on Mogami-class frigates.

In August, a joint statement was made by Japan Minister of Foreign Affairs, Japan MoD, India MoD and India Minister of External Affairs on the development.

It noted that the four ministers “appreciated the progress made for the transfer of Unified Complex Radio Antenna (UNICORN) and related technologies and early signing of related arrangements.”

Bharat Electronics will now co-develop these systems in India with Japanese collaboration, marking the first instance of co-development of defence equipment between India and Japan.

Besides, the Indian Navy held a ‘keel laying’ ceremony for the first of five Fleet Support Ships (FSS) at Hindustan Shipyard in Visakhapatnam.

The Indian Navy had signed a contract with Hindustan Shipyard in August 2023 for the acquisition of these ships, which are scheduled for delivery starting mid-2027.

The FSS, each with a displacement of more than 40,000 tonnes, is expected to enhance the Indian Navy’s ‘Blue Water’ capabilities by replenishing fleet ships at sea.

These ships will carry fuel, water, ammunition, and stores, enabling prolonged operations without returning to harbour.

Additionally, the ships will be equipped for humanitarian aid and disaster relief operations, enabling personnel evacuation in emergencies and the quick delivery of relief supplies during natural calamities.

 

19 Nov 24. Protecting aircraft with artificial intelligence: Thales and partners selected for first European project to develop sovereign AI for embedded cyberdefence.

  • Thales has been selected for the Artificial Intelligence Deployable Agent (AIDA) project funded by the European Commission through the European Defence Fund (EDF). A total of 28 European industry partners, start-ups and research centres have joined forces on this project to develop a sovereign AI-enabled cybersecurity agent to protect aircraft systems from cyberattacks.
  • The goal of this three-and-a-half-year European project is to design an AI with an autonomous or semi-autonomous response capability to provide cybersecurity protection for aircraft systems such as onboard computers and electronic warfare systems on combat aircraft, which are vulnerable to increasingly sophisticated cyberattacks in today’s high-intensity conflicts.
  • AIDA is the first European structural framework project in support of the NATO concept of Autonomous Intelligent Cyberdefence Agent (AICA).1

Created by AI

Thales is technical coordinator for the AIDA project funded by the European Commission, with CR14 in Estonia in charge of overall project coordination.

This EDF project is a response to three major challenges faced by the armed forces today: attack surfaces are growing due to battlespace digitisation; the cyberattack detection-response chain needs to be automated due to the ever-greater use of autonomous systems such as drones and robots; and AI is being used ever more widely both to launch and respond to cyberattacks.

Christophe Salomon, Executive Vice President, Secure Communications & Information Systems, Thales: “This project initiated by the European Union is fundamental to the security of our combat systems and the sovereignty of our cyberdefence capabilities. It is a chance for Thales to consolidate its strengths in onboard aircraft systems and sovereign cybersecurity solutions, and a further opportunity to leverage our AI hacking expertise. Thales’s AI accelerator, and in particular cortAIx, will be directly involved in the AIDA project. The ultimate goal is to employ AI-enabled techniques for detecting threats and protecting aircraft systems from the growing risks and dangers encountered in today’s high-intensity, technology-driven conflicts.”

Responding to the 2023 European Defence Fund call for projects for the development of deployable autonomous AI agents,1 Thales submitted an innovative proposal based on the training of intelligent cyberdefence agents capable of identifying, protecting, detecting and responding to cyberthreats in real time in the five military operating domains:2 land, air, sea, space and cyberspace.

Thales will also lead the project to develop a prototype aircraft using frugal AI agents to protect electronic warfare equipment installed on combat aircraft. This prototype will be tested, using Thales’s Cybels Analytics solution in particular, in scenarios including cyber-electromagnetic threats and advanced adversarial AI attacks.

AI is being used increasingly in the theatre of operations to increase the detection performance of air defence radars, for example, and to help plan tactical missions and assign tasks to swarms of drones and robotic systems. This type of AI must be reliable, robust and cybersafe to prevent it being exploited by hostile forces in any environment (land, sea, air, space and cyberspace). To counter this type of threat, Thales’s Friendly Hacker Unit will conduct a battery of adversarial AI attacks and define appropriate countermeasures to ensure that these cyberdefence AI agents can never become targets themselves.

Global leader in data protection and cybersecurity

As a world leader in cybersecurity, with more than 5,800 experts in 68 countries, Thales is involved at every stage in the civil and defence value chain: Identify, Protect, Detect, Respond, Restore. Thales develops sovereign products including encryptors and sensors for governments and institutions to protect their critical information systems, as well as sovereign cyberthreat detection products to protect embedded and onboard systems. Thales is a trusted partner of the Galileo satellite navigation system, operating a number of national encryption laboratories in Europe and supplying NATO member countries with the only tactical IP encryptor with “Cosmic Top Secret” security certification. Thales is also a strategic partner of the German, UK, French and Belgian defence ministries for the construction and handover of key management centres and infrastructure.

AI at Thales

Thales is a major player in trusted, cybersafe, transparent, explainable and ethical AI for armed forces, aircraft manufacturers and critical infrastructure providers. The Group employs over 600 engineers specialising in AI and around 100 doctoral candidates are conducting their AI research with Thales. Organised within Thales’s AI accelerator for research (AI Lab), systems, including decision support systems, (AI Factory) and sensors, including sonar, radar, radios and optronics, (AI Sensors), these experts are helping to incorporate AI into over 100 of Thales’s products and services. Thales’s AI capabilities draw on the most advanced sensor and system technologies to address the full spectrum of user requirements in the defence, aviation, space, cybersecurity and digital identity industries. Trusted AI is designed to meet the specific security and sovereignty needs of Thales’s customers. It brings greater efficiency to data analysis and decision support and speeds up the detection, identification and classification of objects of interest and target scenes, while taking account of specific constraints such as cybersecurity, embeddability and frugality in critical environments.

In 2023, the Group was Europe’s top patent applicant in the field of AI for mission-critical systems. Also in 2023, the Group’s Friendly Hacker Unit demonstrated its credentials at the CAID challenge (Conference on Artificial Intelligence for Defence) organised by the French defence procurement agency (DGA), which involved finding AI training data even when it had been deleted from the system to preserve confidentiality.

Thales’s European partners in the AIDA project:

SIHTASUTUS CR14 (CR14)

THALES SIX GTS France (TSGF)

THALES SA (TRT)

THALES AVS FRANCE SAS (TAVS)

THALES DMS FRANCE SAS (TDMS)

INDRA SISTEMAS SA (IND)

LEONARDO – SOCIETA PER AZIONI (LDO)

TELESPAZIO SPA (TPZ)

AIT AUSTRIAN INSTITUTE OF TECHNOLOGY GMBH (AIT)

SPACE HELLAS ANONYMI ETAIREIA SYSTIMATA KAI YPIRESIES TILEPIKOINONIONPLIROFORIKIS ASFALEIAS – IDIOTIKI EPICHEIRISI PAROCHIS YPERISION ASFA (SPH)²

HONEYWELL INTERNATIONAL SRO (HON)

WOJSKOWA AKADEMIA TECHNICZNA IM.JAROSLAWA DABROWSKIEGO (WAT)

EVIDEN TECHNOLOGIES SRL (EVD)

Decent Cybersecurity s. r. o. (DEC)

GYALA S.R.L. (GYA)

FORSVARETS FORSKNINGINSTITUTT (FFI)

SensorFleet Oy (SEN)

NIXU OYJ (NIX)

Aliter Technologies, a.s. (ALI)

THALES EDISOFT PORTUGAL, S.A. (EDI)

HITEC LUXEMBOURG SA-HITEC (HIT)

MINISTERUL APARARII NATIONALE (MET)

INSTITUTO SUPERIOR DE ENGENHARIA DO PORTO (ISEP)

DOTOCEAN (DOT)

WB Electronics S.A. (WBE)

ADVOKAADIBUROO SORAINEN OU (SOR)

HarfangLab SAS (HAR)

AKHEROS SAS (AKH)

 

19 Nov 24. ThreatQuotient™, a leading threat intelligence platform innovator, today released the Evolution of Cybersecurity Automation Adoption 2024. Based on survey results from 750 senior cybersecurity professionals at companies in the U.K., U.S. and Australia from a range of industries, this in-depth research report examines the progress senior cybersecurity professionals are making towards adopting automation, its key use cases and the challenges they face. The fourth edition of this annual survey highlights how automation is maturing and how, in a world of continuous change, organisations are adopting cybersecurity automation for resilience, scale and collaboration. The report examines approaches to integration, whether respondents are taking a single-vendor platform approach or best-of-breed, the adoption of AI and the importance of cyber threat intelligence sharing.

Eight-in-ten respondents (80%) now say cybersecurity automation is important, up from 75% last year and 68% the previous year. Additionally, budget for cybersecurity automation has increased every year, and this year’s survey is no different with 99% of respondents increasing spend on automation. Interestingly, 39% of respondents now have net new budget specifically for automation, a significant rise on the 18.5% who said this last year. Previously, decision-makers were diverting budget from other cybersecurity tools or reallocating unused headcount funds. In 2024 respondents have a better understanding of key uses cases and the benefits automation delivers is helping them make a stronger business case for dedicated budget, which is another indication that cybersecurity automation is maturing.

Key research findings also include:

  • Key use cases: Incident response was the top use case for automation (32%), rising consistently through the course of the study. This was followed by phishing analysis (30%) and threat hunting (30%) which has also continued to rise.
  • Challenges are evolving: Nearly every survey participant reported problems with cybersecurity automation: the top three challenges were technological issues, lack of budget and lack of time.  As automation deployments mature, trust in the outcomes of automated processes has increased. Just 20% of respondents reported a lack of trust in outcomes, compared to 31% last year. In 2023 there was also significant concern around bad decisions, slow user adoption and lack of skills, but these concerns have abated in 2024.
  • Top measurement metrics: Employee satisfaction and retention remains the main metric for assessing cybersecurity automation ROI for 43% of leaders, but this has dropped from 61.5% citing it as the key metric in 2023. Resource management, in terms of staff efficiency, effectiveness and budget (42%), and how well the job is being done in terms of MTTR and MTTD (38%) have both become more prevalent as measurement tools as organisations home in on metrics more closely linked to productivity and efficiency.
  • Growth in threat intelligence sharing: Ninety-nine percent of cybersecurity professionals say they share cyber threat intelligence through at least one channel; 54% share cyber threat intelligence with their direct partners and suppliers and 48% share with others in their industry through official threat sharing communities.
  • Integration is key: Two thirds (67%) of respondents integrate best of breed solutions into their architecture to effectively deliver their cybersecurity strategy. Regardless of whether they focus solely on best of breed tools or they start with a single vendor platform and then supplement with best of breed tools, integrating tools is an important activity.
  • AI gathers momentum: Fifty eight percent of respondents say they are using AI in cybersecurity. Half are using it everywhere, and half in specific use cases.  A further 20% are planning deployments in the year ahead.
  • Expected attack vectors in the year ahead: Cyber-physical attacks are considered most likely in the year ahead, followed by phishing and ransomware. Although not a top three attack vector, 20% of respondents expect to see attacks via the supply chain and one in five see state-sponsored attacks affecting their business.

“It is tough for cybersecurity professionals who now face fast-changing cyber and cyber-physical threats of unprecedented sophistication, volume, velocity and variety,” said Leon Ward, Vice President, Product Management, ThreatQuotient. “Defending their business is an enormous task, and cybersecurity professionals must become more resilient.

“What we are seeing in this ‘new normal’ landscape is the need for more automation, scale and better threat intelligence sharing.  A collaborative approach to cybersecurity helps organisations better defend as industries scale their knowledge to respond to attacks.”

As organisations double down on cybersecurity automation use cases that deliver value and embrace more intelligence sharing, this will result in more effective and proactive cyber defence. This year the survey highlights the focus has shifted toward ROI metrics that are more closely linked to productivity and efficiency and – while employee retention and satisfaction remains important – it is no longer heavily outweighing performance and efficiency KPIs.

Ward concludes, “We believe that scaling security operations and collaboration across teams, ecosystems and industries is the most urgent challenge facing cybersecurity professionals. Successfully uniting human expertise, automation and AI and enabling seamless integration across tools and intelligence feeds will drive cyber resilience and agility at organisational, industry, and international levels.”

To download the full Evolution of Cybersecurity Automation Adoption in 2024 report, including more detail on the survey questions, regional and industry snapshots, and recommendations for senior security professionals to follow if they are looking to automate their security processes, click here. Leading threat intelligence platform innovator, ThreatQuotient, commissioned a survey undertaken by independent research organisation, Opinion Matters, in June 2024. 750 senior cybersecurity professionals in the UK., US. and Australia from companies employing 2,000+ people from a range of industries including Central Government, Defence, Critical National Infrastructure, Retail, and Financial Services sectors, with 150 respondents from each.

About ThreatQuotient

ThreatQuotient improves security operations by fusing together disparate data sources, tools and teams to accelerate threat detection and response. ThreatQ is the first purpose-built, data-driven threat intelligence platform that helps teams prioritise, automate and collaborate on security incidents; enables more focused decision making; and maximises limited resources by integrating existing processes and technologies into a unified workspace. The result is reduced noise, clear priority threats, and the ability to automate processes with high fidelity data. ThreatQuotient’s industry leading integration marketplace, data management, orchestration and automation capabilities support multiple use cases including threat intelligence management and sharing, incident response, threat hunting, spear phishing, alert triage and vulnerability management. ThreatQuotient is headquartered in Northern Virginia with international operations based out of Europe, MENA and APAC. For more information, visit www.threatquotient.com.

 

19 Nov 24. Global: Zero-day vulnerability heightens espionage risk posed by Chinese state-sponsored groups. On 18 November, international news outlets reported that the Chinese state-sponsored group ‘BrazenBamboo’ is exploiting a zero-day vulnerability in an ongoing cyber espionage campaign. The vulnerability affects Fortinet’s FortiClient Windows VPN service and allows threat actors to steal credentials from a system’s memory. BrazenBamboo deploys a custom post-exploitation toolkit (‘DeepData’) to exploit the vulnerability and obtain stolen credentials. It is likely that the group uses stolen credentials to infiltrate targeted systems by hijacking VPN accounts. Subsequently, BrazenBamboo likely moves laterally within compromised systems for additional espionage activities, including deploying a new Windows variant of the ‘LightSpy’ malware for data exfiltration. The vulnerability was disclosed in July and has not been patched yet, highlighting the need for monitoring for unusual VPN account activity in the short term. This campaign underscores the continued exploitation of zero-day vulnerabilities by Chinese state-sponsored groups, pointing to heightened long-term espionage risks facing global entities. (Source: Sibylline)

 

18 Nov 24.  Global: New malware distribution technique elevates information-theft, financial risks from cyber criminals. On 16 November, international news outlets reported that fake artificial intelligence (AI) content generator applications are being used to distribute the ‘Lumma Stealer’ and ‘AMOS’ information-stealing malware. Threat actors are reportedly sharing deepfake political videos on the social media platform ‘X’ (formerly Twitter) to trick users into visiting fraudulent websites. Users then unknowingly install the malware onto their systems by clicking on malicious links displayed on the websites, purporting to download fake AI applications. The malware can steal cryptocurrency wallets as well as other sensitive information (including login credentials and credit card details) from Chromium-based browsers. Subsequently, the stolen data is likely sold on the dark web or used in follow-on attacks for illicit profit. The adoption of information-stealing malware has seen a rapid increase since the beginning of 2024, sustaining elevated information-theft and financial risks to global entities in the medium term. (Source: Sibylline)

 

15 Nov 24. Global: New malware points to increased information-theft, financial risks facing users. On 13 November, the software company Gen Digital reported that a new information-stealing malware (‘Glove’) is bypassing a new security encryption mechanism in Chromium-based browsers to steal sensitive user data. Threat actors typically use social engineering tactics to deploy Glove, tricking potential victims into downloading a malicious file via phishing emails. Upon installation, Glove exfiltrates browser cookies, data and sensitive information (including cryptocurrency wallets, session tokens and password managers) from browser extensions and local applications. Notably, threat actors obtain administrative privileges prior to extracting data, underscoring the sophistication of this campaign. We assess that threat actors likely use the stolen information to hijack user accounts in order to garner illicit profit. Cyber criminals are increasingly incorporating this technique into information-stealing malware, highlighting their increased ability to bypass modern security measures. Glove is likely still in its development phase as it contains minimal obfuscation mechanisms, pointing to medium-term information-theft and financial risks.

(Source: Sibylline)

————————————————————————————————————————————————————————————————————————————————————————————————————————————–

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

———————————————————————————————————————————————————————————————————————————————————————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

November 15, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

—————————————————————————————————————————————————————————————————————————————————————————————————————————–

14 Nov 24. Comtech Telecommunications Corp. (NASDAQ: CMTL) (“Comtech” or the “Company”), a global technology leader, announced today that the U.S. Navy Information Warfare Systems Command awarded the Company a sole source contract for Comtech’s U.S sovereign software-defined SLM-5650B satellite communications (“SATCOM”) modems, upgrade kits, firmware options and technical support. The contract has a four-year period of performance and is valued in excess of $50.0m. Funded orders received to date are valued at approximately $2m.

Currently, multiple U.S. Navy programs field thousands of Comtech SATCOM modems. Comtech’s commercially available modems support communications over commercial and military satellite networks and are critical for interoperability across Navy platforms and shore sites.

“As data rate demands in the U.S. Navy Fleet increase, and satellite technologies evolve to provide enhanced capabilities, Comtech’s U.S. sovereign SLM-5650B modems are uniquely designed to meet the needs of the Navy today, as well as the joint force operations of tomorrow,” said John Ratigan, President and CEO of Comtech. “As a longstanding trusted partner of the U.S. Navy, Comtech’s modem technologies provide critical communications capabilities that enhance situational awareness and improve operational effectiveness in the world’s most challenging environments. We are honored to strengthen our relationship with the U.S. Navy through this award, which provides a new contracting vehicle to significantly expand the number of Comtech SATCOM modems delivered over the next four years.”

Developed and manufactured at its headquarters in Chandler, AZ, Comtech’s SLM-5650B is the Company’s current Wideband Global SATCOM-certified modem designed to deliver critical communications services for commercial backhaul and government and military applications. The software-defined SLM-5650B currently supports multiple critical DoD and NATO waveforms, including DVB-S2X, with the ability to easily add more waveforms and functions to meet emerging mission needs. The Company was also recently awarded a strategically significant SES Space & Defense contract to deliver SLM-5650B and other next-generation modems to support sovereign connectivity programs over the SES O3b mPOWER constellation.

Comtech’s portfolio of U.S. sovereign defense technologies and services, including the Company’s SLM-5650B and next-generation modems, align with the Space Force Commercial Space Strategy and deliver capabilities that will enhance Combined Joint All Domain Command and Control operations. Comtech’s expansive portfolio of defense and security technologies is designed to continuously evolve over time to enable digitalized SATCOM infrastructures and integrate services across blended military and commercial networks to enhance mission effectiveness in future all-domain operations.

 

14 Nov 24. Glasswall, a leading provider of intelligent file protection technologies, claimed two major honors at the prestigious UK IT Industry Awards 2024 for Glasswall Halo in the Security Innovation of the Year category and Connor Morley, who was presented with the Security Professional of the Year award.

Hosted at a ceremony in London on November 13th, the UK IT Industry Awards are designed to celebrate and promote the organizations, teams, projects, technologies and individuals who continue to help shape the future of IT, the technology industry and digital society. Glasswall was successful in two highly competitive categories, which included major international cybersecurity brands and outstanding industry professionals.

Winning for Security Innovation of the Year was Glasswall Halo, a scalable zero-trust file protection solution, deployable on-premises, in the cloud or air-gapped networks. Powered by Glasswall Content Disarm and Reconstruction (CDR) technology, it is a data filter that rebuilds files and documents into a safe, clean standard, free from the risks of malware. Glasswall Halo helps deliver a zero-trust approach to cybersecurity, outperforms antivirus, sandboxing and EDR methods and is essential for secure file transfer across trust boundaries.

In addition, Connor Morley, Glasswall’s Principal Malware Security Researcher, was named Security Professional of the Year. Renowned for his innovative contribution to cybersecurity and deep expertise in malware analysis, threat hunting and security research, his development of cutting-edge tools such as Glasswall Conform and novel approaches to defeating steganography have set new industry standards.

“This is a major achievement for the entire Glasswall team, who are a hugely talented and dedicated group of professionals,” commented Danny Lopez, Glasswall CEO. “It also demonstrates our commitment to technology innovation and building an organization where employees can thrive in a highly competitive industry sector.”

About Glasswall

Glasswall is a cybersecurity company that protects government agencies and commercial organizations from malicious files with its Content Disarm and Reconstruction (CDR) technology. Unlike traditional detection-based methods, Glasswall employs a zero-trust approach, which removes the ability for malware to exist in files altogether. www.glasswall.com

 

13 Nov 24. At SDSC-UK 2024, @MPG will showcase a range of exciting products, designed to support critical operations in defence.

This includes:

Communication Deconfliction System

  • Allows simultaneous use of radio systems while jamming
  • Simple integration or retrofit to any vehicle
  • Covers full 225-400 MHz radio band

Reconfigurable Filter Bank for ESM Front-End

  • Flexibility with 2 GHz notches and bandpass filtering across 2-18 GHz range
  • Instantly switches among 256 filter shapes in under 100 ns
  • Fully qualified for fast jet environments

Compact Tuner-Downconverter for EW Receiver

  • Provides EW-quality performance normally seen in 19” rack mounted systems within a compact 3U form-factor
  • Ultra-low phase noise and Spurious Free Dynamic Range
  • SOSA-aligned Open VPX interface

Want to know more?

Head to Stand 5C at SDSC-UK to speak to @David Rawlinson, @Emyr Rees and the MPG team. David has more than 15 years of experience in defence and aerospace and is MPG’s go-to specialist for European space solutions. Emyr has over 30 years of experience in RF/Microwave Engineering, with a focus on defence communications and electromagnetic spectrum operations. He is MPG’s leading expert for defence solutions within UK & Europe.

Register now: www.sdsc-uk.co.uk

 

14 Nov 24. Global: Botnet resurgence elevates security, disruption risks from Chinese state-sponsored groups. On 12 November, the cyber security company SecurityScorecard disclosed that a botnet (‘JDYFJ’) employed by the Chinese state-sponsored group ‘Volt Typhoon’ remains active despite a law enforcement takedown in February. Throughout September, JDYFJ initiated and maintained an active connection from a compromised router in New Caledonia, highlighting the botnet’s resilience. Volt Typhoon has also reportedly compromised additional end-of-life routers since February, suggesting that it is possibly expanding the botnet’s infrastructure. JDYFJ notably uses several obfuscation techniques designed to mimic legitimate traffic, underscoring the sophistication of its detection-evasion capabilities. Volt Typhoon frequently targets perceived adversarial critical national infrastructure (CNI), likely to pre-position itself to conduct reconnaissance and obtain access for future disruptive attacks. Earlier in November, Volt Typhoon also infiltrated a Singaporean telecommunications provider, pointing to an overall increase in Chinese state-sponsored cyber operations. We assess this will elevate long-term security and disruption risks for CNI amid ongoing geopolitical tensions. (Source: Sibylline)

 

12 Nov 24. Ready Mercury?  The US Navy’s E-6B Mercury TACAMO nuclear command and control aircraft are due to be replaced by a new platform based on the C-130J turboprop airlifter. The navy has operated Hercules-based nuclear C2 aircraft in the past in the guise of the EC-130G/Q.

The US Navy has shared details with Armada regarding its ongoing plans to replace the force’s existing Boeing E-6B Mercury TACAMO aircraft.

The TACAMO (Take Charge and Move Out) mission forms a vital part of the United States’ strategic nuclear deterrent. The US Navy’s E-6B Mercury planes act as a communications conduit between the country’s political leadership and America’s nuclear platforms. US nuclear platforms include US Air Force (USAF) Boeing LGM-30G(V)3 Minuteman Intercontinental Ballistic Missiles (ICBMs) housed in launch silos. The USAF also has responsibility for the air-delivered component of the deterrent. The air-delivered nuclear arsenal includes Boeing AGM-86B air-to-surface missiles, and B-61 and B-83 nuclear bombs. The at-sea component includes Lockheed Martin UGM-133A Trident-D5 Submarine-Launched Ballistic Missiles (SLBMs).

Should the US president make the order to use nuclear weapons this would be relayed to the E-6B jets and USAF Boeing E-4B National Airborne Operations Centre aircraft. Both these planes form a key part of the US NC3 (Nuclear Command, Control and Communications) infrastructure, performing similar roles. The E-4Bs and E-6Bs can sent aloft in times of tension which affords them a degree of survivability against any incoming nuclear attack aimed at US airbases. Moreover, flying at altitude allows the aircraft to provide a radio relay moving nuclear Command and Control (C2) traffic between bases on the ground, ICBM silos, US Navy ‘Ohio’ class Nuclear-Powered Ballistic Missile Submarines (SSBNs) carrying the SLBMs, and the USAF’s Whiteman and Barksdale airbases in Missouri and Louisiana. These two bases are home to the air force’s Northrop Grumman B-2A Spirit and Boeing B-52G Stratofortress strategic bombers.

Radio, what’s new?

The E-6B use five communications links to receive and transmit nuclear C2 traffic, known as Emergency Action Messages (EAMs). These include the Advanced Extremely High Frequency (AEHF) Satellite Communications (SATCOM) system, plus Very Low Frequency (VLF: three kilohertz/KHz to 30KHz), Low Frequency (LF: 30KHz to 300KHz), High Frequency (HF: three megahertz/MHz to 30MHz) and Ultra High Frequency (UHF: 225 megahertz/MHz to 400MHz) links. The AEHF carries traffic securely using an Earth-to-space uplink of 44 gigahertz/GHz. Signals are sent from the satellites to Earth on frequencies of 20GHz. Both the VLF and LF links form part of the Minimum Essential Emergency Communications Network (MEECN). MEECN is believed to be primarily used to transmit EAMs to the SSBN force. UHF is the conduit used for the Airborne Launch Control System which transmits EAMs to the ICBM force, while HF EAM traffic is carried across the HF Global Communications System (HFGCS). It is thought that the HFGCS sends EAMs to the B-52Hs and B-2As, and their bases. This combination of SATCOM, VLF, LF, HF, and UHF links provide redundancy in the nuclear C2 chain. For example, should SATCOM links suffer interference or deliberate jamming, other links can pick up the slack.

The show must go on

The US Navy is replacing the E-6B via the TACAMO Recapitalisation Programme. In 2020, the US Navy chose Lockheed Martin’s C-130J turboprop airlifter as the preferred platform to replace the Mercury. Ironically, the United States Navy is going back to the fold by choosing the C-130 as the preferred platform. The original TACAMO aircraft was the EC-130G/Q which entered service in 1968.

A US Navy spokesperson shared that the TACAMO replacement Request for Proposals (RFP) calls for a “minimum of eight and a maximum of twelve E-130J aircraft, comprised of three Engineering Development Models (EDMs), up to three system demonstration test articles, and up to six aircraft in the first lot of production. Additional aircraft will be acquired through future production lots.” The EDMs will be C-130J-30 aircraft and will be delivered in 2026: “The contract award will determine the timeline for modifications and when these EDMs enter service as test aircraft.” When these aircraft will enter service as test platforms is not being revealed due to operational security, the spokesperson continued.

The navy must still decide on a prime contractor for the the nuclear C2 system on the aircraft as per the RFP. Collins Aerospace has already been selected to provide the new VLF architecture. The RFP will “expedite the development, testing and deployment of the critical NC3 system-of-systems by using an existing baseline aircraft (the C-130J-30) and leveraging existing, mature mission systems technology to minimize the need for new development.” What this seems to suggest is that some of the E-6Bs’ existing systems may be ‘cross-decked’ onto the new platform. This would make sense, particularly where systems are relatively recent and not yet in need of replacement. Ultimately, the TACAMO recapitalisation will allow the eventual retirement of “the aging E-6B Mercury fleet allowing the navy to transition the nation’s NC3 capability with no break in coverage.” (Source: Armada)

 

13 Nov 24. Eastern Promise. The three Baltic nations of Estonia, Latvia and Lithuania are constructing the fortified Baltic Defence Line to help protect against military incursions across their borders from Russia and Belarus. NATO’s Multi-Domain Operations posture comes under scrutiny during this year’s Riga Conference held in the Latvian Capital.

The sun poured through the windows of the delightful National Museum of Latvia situated on the banks of the Daugava River, the venue for this year’s Riga Conference held between 17th and 19th October. One side event was a panel examining Multi-Domain Operations (MDO) readiness on the Eastern Flank. This event was sponsored by Globsec, a think tank based in Bratislava, Slovakia. Globsec has recently published a report entitled Connect to Succeed: Multi-Domain Operations Readiness on the Eastern Flank.

The North Atlantic Treaty Organisation (NATO) is embracing Multi-Domain Operations (MDO) and details on how NATO defines MDO can be found here. Marcin Zaborowski, Globsec’s distinguished fellow for the future of security programme, retired Lieutenant General Ben Hodges, former commander of the United States Army in Europe, and Martin Sklenár, former minister of defence of the Slovak Republic, and a Globsec distinguished fellow, comprised the panellists. They asserted that what differentiates MDO from joint operations is the addition of the space and cyber domains into the strategic, operational and tactical levels of war alongside the traditional sea, land and air domains. A key message of the panel discussions is that MDO must be integral to how NATO fights, trains and organises.

All panellists agreed that the Ukrainian armed forces are today are conducting MDO in that country’s fight against Russian occupation. The Ukrainian military is operating in the land, maritime and air environments, alongside the space and cyber domains. The country’s armed forces are performing operations at depth, for example striking Russian oil and gas infrastructure, while continuing to perform tactical and operational tasks. These efforts are depending on a heavily congested electromagnetic environment contested by Russian electronic warfare.

Instruments of national power

A key discriminator for the alliance’s multidomain operations vision, compared to that of the US Department of Defence, is the centrality of so-called instruments of national power. Military operations demand a constant search for the best effect, but that effect might not always originate from the military. Perhaps it is possible to employ political effects such as sanctions, which could have a military consequence? Sanctions on the import of advanced technology, could negatively affect the quality and quantity of weapons an adversary can deploy. However, this reality must be set against the risk that there may be a lack of awareness in government regarding MDO utility and its organisation. Government, critical national infrastructure, the public and private sector, and civil society are arguably all domains in their own way.

There can be a tendency for some armed forces to build up new siloed capabilities in different domains. Bureaucratic structures, plus service rivalries, can act as a restraint on the implementation of the MDO mindset. Is capability acquisition conducted across the alliance with MDO as a key consideration? The three Baltic nations of Lithuania, Latvia and Estonia are currently building the Baltic Defence Line fortifications. These fortifications will protect their borders against any armed incursions from Russia and Belarus. Ensuring high levels of inter- and intra-force operability will be vital to ensuring that the line is robust.

Making MDO a reality

Arguments were made at the event that NATO’s MDO plans and requirements should be front and centre vis-à-vis training across the alliance. It is not always natural for services to want to work together, but it must be emphasised that the sum can be greater than its parts strategically, operationally and tactically. Training should reflect the need to use integrated effects in a multinational environment should war with Russia erupt. The alliance needs to be ready for Russia’s own interpretation of the MDO philosophy. There is every chance in a future war that the Russian military will launch missile strikes against NATO transportation targets. Russian commanders realise that NATO’s response to any aggression depends on rapidly reinforcing the Baltic. Transportation targets will likely be hit with cyberattacks as well as kinetic effects. NATO units might have to fight for up to two weeks before NATO reinforcements appear en masse in the Baltic.

Delegates and panellists had some simple, but indispensable, advice for NATO as it embraces MDO: Governments and militaries should prioritise connectivity and get the best value from investments they are already making. The alliance should be making clear to Russia that it is well prepared for war and continually improving this preparedness. Last, but by no means least, militaries need to ensure they have robust, redundant and secure networking, and to realise that this connectivity can itself be a potent effect.  (Source: Armada)

 

14 Nov 24. LETACCIS Leaps. The UK’s Ministry of Defence has several communications, and command and control, modernisation programmes consolidated under the Land Environment Tactical Communications and Information Systems, or LETACCIS, programme.

The UK’s ongoing overhaul of its military communications, and command and control capabilities, has taken an important step forward.

On 14th October, QinetiQ was awarded a contract by the United Kingdom’s Ministry of Defence (MOD) to support the Land Environment Tactical Communications and Information Systems (LETACCIS) programme. According to reports, the company will provide the MOD with engineering and programme expertise to support LETACCIS.

LETACCIS defined

LETACCIS is an overarching effort encompassing several programmes to enhance the British Army’s connectivity. These include the Bowman Combat Infrastructure and Platform-5.6/5.7 (BCIP 5.6/5.7) initiative, Trinity, the Joint Common Remote Viewing Terminal (JCRVT), Dismounted Soldier Awareness (DSA), Falcon and Niobe. Trinity provides a deployable wide area network to replace the British Army’s Falcon operational/tactical level trunk communications architecture and is being delivered by BAE Systems. Niobe delivers a multi-platform common, mission-configurable communications information system. L3Harris is delivering the JCRVT which is a modular remote viewing system receiving and transmitting real time video. DSA will provide dismounted troops with improved voice and data communications services at company level. This capability is being provided through the acquisition of the Android Tactical Assault Kit (ATAK). LETACCIS also covered the now-defunct Project Morpheus initiative. Morpheus was intended to deliver an open architecture tactical communications system to replace BCIP 5.6.

A spokesperson for QinetiQ told Armada that the company is delivering “deep engineering and programme skills and experience to several areas of this large programme” as a “Tactical Systems (TACSYS) resource partner.” QinetiQ is providing these services to the TACSYS Service Executive. This latter body sits within Defence Digital which is one part of the UK’s Strategic Command. In its own words, the Defence Digital organisation “is responsible for making sure that effective digital and information technology is put into the hands of the military.” Regarding LETACCIS, Defence Digital is “tasked with delivering the equipment and logistic defence lines of development for the projects within the … programme.” The spokesperson emphasised that QinetiQ is not the only company involved with LETACCIS: “We are delivering into only some parts of the programme. Many other providers and suppliers are contributing.” Options exist to extend QinetiQ’s three-year LETACCIS contract for a further two years.

The shopping list

This latest development regarding LETACCIS is welcome. There is an overriding need to advance the connectivity and networking of the UK’s armed forces. This is further underscored by the country’s embrace of the Multi-Domain Operations (MDO) mindset. The UK’s own interpretation of MDO is known as Multi-Domain Integration (MDI). MDO stresses the intra- and interforce connectivity of all military assets at all levels of war to perform synchronous operations aided by faster and better-quality decision-making than one’s adversary. The MDI concept extends this approach to deepen connectivity with other parts of government, the public and private sectors, and civil society. Despite LETACCIS, other initiatives remain outstanding, not least of which is the Morpheus requirement which must be urgently addressed. (Source: Armada)

 

14 Nov 24. November Radio Roundup. Armada’s monthly roundup of all the latest news in the military communications product, programme and operational domains.

MUOS Streams Video

An important step forward has been taken concerning the ability of the Mobile User Objective System (MUOS) Satellite Communications (SATCOM) constellation to carry streaming video. MUOS is a narrowband SATCOM network using frequencies of 300 megahertz/MHz to 320MHz for uplink. Frequencies of 360MHz to 380MHz are used for downlink, according to open sources. These same sources note that voice and data traffic can move across the network at speeds of circa 39.2 megabits-per-second. SATCOM terminals and modems must use the Wideband Code Division Multiple Access waveform to gain access to the MUOS constellation. MUOS is primarily used by the United States military and allied nations like Canada. Reticulate Micro, together with Curtiss Wright and NanTenna, demonstrated that live video could be streamed over the network during a recent US Army exercise. The demonstration was noteworthy because narrowband links are not traditionally associated with data-heavy traffic like streaming video. Reticulate Micro told Armada, via a written statement, that the video was streamed over a single channel, as opposed to binding multiple channels to ensure sufficient bandwidth. The company said this recent experiment saw a single channel with 64 kilobits-per-second of bandwidth being used. Reticulate Micro employed its VAST video encoder for the demonstration. VAST worked with Curtiss-Wright’s PacStar Modular Radio Centre and L3Harris’ AN/PRC-117G multiband (20MHz to two gigahertz) networking radios. Plans are afoot to test the VAST’s abilities to carry two-way voice and video traffic and the company expects this capability to be ready for use in early 2025.

Himera has teamed with Reticulate Micro to offer the Himera-G1 Pro to the US market. This radio is the latest iteration of the Himera-G1 and includes robust electronic protection protocols.

Battle Proven

Staying with Reticulate Micro, the company has teamed up with Ukraine’s Himera to offer the latter’s Himera-G1 Pro handheld radio to customers in the United States. The radio was unveiled earlier in July 2024 and has been developed with robust electronic protection protocols as standard. A press release announcing the radio’s launch stated that the Himera-G1 has AES-256 (Automatic Encryption Standard-256) protection. Other safeguards include frequency hopping protocols. The press release continued that the radio can be easily configured via a Bluetooth connection using a smartphone running the Android operating system. Himera-G1 Pro radios can create mobile ad hoc networks for the carriage of voice and data traffic. The Himera-G1 Pro builds upon the Himera-G1 already fielded with Ukrainian forces. Misha Rudominski, Himera’s co-founder, told Armada that the Himera-G1 Pro being offered to the US market “is very much the same product to what we offer in Ukraine … The radio for Ukraine’s defence forces was built over many iterations of testing and feedback from active users on the battlefield.” Louis Sutherland, Reticulate Micro’s senior director for business development, added that the Himera G1 Pro is ideally placed to serve as a squad radio and is “designed in a way to meet the military’s robust voice requirements at a low cost … In general terms, it’s not out of the question for a handheld of another brand to cost between $40,000 and $60,000.” Mr. Sutherland shared that a US Department of Defence (DOD) testing agency has purchased some of the radios for evaluation: “We look forward to the outcome of the testing as it will serve as a bellwether for how other DOD users will receive the product … We hope that once the G1 Pro is tested and validated, that there will be opportunities to make squad radios more broadly accessible to the troops who need them.” (Source: Armada)

 

12 Nov 24. BeeKeeperAI Partners with Government Acquisitions, Inc. to Provide a Privacy-Enhancing, AI Solution to the U.S. Federal Government.

GAI will incorporate BeeKeeperAI’s EscrowAI into its multi-faceted EdgeShield platform to increase data privacy and integrity in concordance with the latest government requirements for data and AI

November 12, 2024 09:00 AM Eastern Standard Time

AUSTIN, Texas–(BUSINESS WIRE)–BeeKeeperAI®, Inc., a pioneer in privacy-enhancing, multi-party collaboration software for AI development and deployment, today announced its collaboration with Government Acquisitions, Inc (GAI). As a leading provider of end-to-end IT solutions to the federal government, GAI will add BeeKeeperAI’s EscrowAI® capabilities for data privacy, security, and AI collaboration to GAI’s flagship platform solution, EdgeShield, that represents a significant advancement in sensor data and algorithm security and integrity for the U.S. federal government.

To address the expansion of intelligent Internet of Things (IoT) devices along with the proliferation of 5G, GAI will incorporate BeeKeeperAI’s EscrowAI collaboration solution into EdgeShield, which provides end-to-end protection for data collected from sensors and other edge devices through to data aggregation, computing and reporting. GAI will utilize EscrowAI to advance its capabilities to protect the models and the data in transit, at rest, and during compute. Not only will EscrowAI be key to maintaining data and algorithm privacy during the computing cycle, but it will also produce an immutable record of interactions with both data and algorithms to meet the latest government requirements.

GAI’s EdgeShield platform, which is an integration of five leading platforms – now including BeeKeeperAI’s EscrowAI – is designed to improve data security and integrity, time to insights, and data analytics efficiency for better decision-making. This platform is designed to enable faster reactions, secure data-sharing, and proactive protections through AI-assisted insights – relevant across a broad scope ranging from high-level to tactical decision-making support.

BeeKeeperAI is a pioneer in privacy-enhancing, AI collaboration technologies to secure and accelerate the development and deployment of AI in regulated data industries. The company’s EscrowAI collaboration solution protects intellectual property (IP) and data privacy, integrating and automating the use of Trusted Execution Environments with confidential computing within a secure data environment, and delivering encrypted security during the computing cycle and full isolation of the computing resource. EscrowAI’s application layer provides encrypted protection for the data and algorithm to support inference, training, validation and deployment, including in warfare scenarios.

“BeeKeeperAI’s EscrowAI solution is a unique application providing a scalable, automated workflow that enables encrypted computing for the most advanced protection of data and algorithms,” said Jay Lambke, President at GAI. “When developing the EdgeShield solution we recognized that BeeKeeperAI’s solution was an integral part we needed to incorporate. As GAI stays on the leading edge of AI and intelligent IoT devices, we leverage state-of-the-art privacy and security technologies, so we’re excited to expand our solution portfolio with the addition of BeeKeeperAI’s solution for algorithm development and model training on data.”

“We are pleased that our privacy-enhancing data and AI collaboration platform, EscrowAI, was selected by GAI for inclusion in their multi-faceted EdgeShield platform,” said Dr. Michael Blum, MD, Co-founder and Chief Executive Officer at BeeKeeperAI. “Within the application, the workflow steps are monitored in an automated fashion, and an immutable record is produced of each action taken within the data processing and computing workflow, which is critical as it provides the necessary evidence chain to verify the absence of tampering with data and/or an algorithm.”

BeeKeeperAI’s privacy-enhancing technology platform leverages Intel’s confidential computing and Software Guard Extensions (SGX) to create a zero-trust environment that protects data. GAI also has a long track record of using Intel’s innovations to advance solutions for the government.

Steve Orrin, Federal CTO at Intel, said, “BeeKeeperAI and GAI are valued Intel partners. We are pleased that they will be leveraging Intel innovation to address a critical security threat for the federal government.”

About BeeKeeperAI

BeeKeeperAI is the pioneer in privacy-enhancing technologies, leveraging Trusted Execution Environments with confidential computing for the development and deployment of AI in regulated data industries, including healthcare and government. BeeKeeperAI is accelerating the broader availability of AI-powered solutions that will help to redefine the future of healthcare, commerce and government. For more information, go to beekeeperai.com.

About GAI

GAI focuses on artificial intelligence (AI), automation, analytics, cybersecurity, and infrastructure. With 30 years of experience in delivering solutions to the U.S. government, GAI works with federal agencies and its IT partners to modernize, optimize, and deliver unparalleled mission support. (Source: BUSINESS WIRE)

 

12 Nov 24. DOD Releases Private 5G Deployment Strategy. On October 16, 2024, the Department of Defense (DoD) signed its strategy for the deployment of private fifth generation (5G) networks at military installations. This strategy is a key enabler to the DoD’s modernization effort to leverage 5G networks, both commercial and private, to deliver ubiquitous, high-speed connectivity for mobile capabilities. In addition, Fulcrum: The Department of Defense Information Technology Advancement Strategy, released in June 2024, calls for the implementation of 5G across DoD installations and operating forces. The DoD Private 5G Deployment Strategy provides guidance for the implementation and operation of private 5G networks at military installations while maximizing Open RAN ecosystems to the extent possible.

The deployment of 5G infrastructure will allow installations to leverage commercial mobile broadband for quality of life and routine mission needs, benefitting military and civilian populations at DoD installations. This infrastructure will also allow the warfighter to ingest and transfer massive amounts of data – a capability that will be critical for the U.S. to retain information and decision advantage. The Department anticipates that military installations will primarily employ commercial networks; however, we recognize that, under certain circumstances, commercial 5G may not fulfill DoD’s requirements. Private networks may augment or supplement commercial services because they are tailored to each installation’s mission needs, security, and military-unique capabilities.

Through this strategy, the Department targets several objectives. First, DoD intends to align private 5G infrastructure with each installation’s unique mission, requiring decisionmakers to evaluate whether specific mission, security, coverage, and performance requirements can only be met by private 5G. Second, DoD aims to accelerate the acquisition, development, and secure deployment of 5G, directing DoD Components to additional implementation guidance to support the integration of new commercial 5G capabilities into DoD missions and systems. Finally, the strategy encourages the expansion of an Open Radio Access Network (Open RAN) ecosystem.

In the coming months, the DoD will provide additional implementation guidance and reference documents to aid the Military Departments as they deploy both commercial and private 5G networks on installations. The DoD Private 5G Deployment Strategy can be found here: https://dodcio.defense.gov/Portals/0/Documents/Library/Private5GDeploymentStrategy.pdf(Source: U.S. DoD)

 

12 Nov 24. Global: New ransomware strain points to heightened financial, disruption risks facing organisations. On 11 November, the cyber security company Kaspersky reported that a new ransomware strain (‘Ymir’) has been used in combination with another information-stealing malware (‘RustyStealer’) since at least July. Threat actors typically deploy RustyStealer on compromised systems to steal credentials and hijack user accounts. This enables them to move laterally, subsequently using PowerShell to take full control of compromised systems and to establish communication with actor-controlled infrastructure. The actors then install Ymir and display a ransom note demanding a payment to decrypt data and to prevent it from being leaked. While Ymir does not display any data-exfiltration capabilities, it is possible that the threat actors initially exfiltrated sensitive information via RustyStealer. Additionally, Ymir employs several sophisticated detection-evasion techniques, underscoring the highly stealthy nature of the ransomware. As such, we assess that this operation will sustain heightened financial and disruption risks for global organisations in the short-to-medium term. (Source: Sibylline)

 

11 Nov 24. South Korea: Increase in attacks points to raised security, disruption risks from pro-Russia groups. On 8 November, international news outlets reported that pro-Russia hacktivist groups have increased their cyber attacks against South Korean private and public organisations. The groups are increasingly breaching civilian devices and conducting distributed denial-of-service (DDoS) attacks against government and private websites. Notably, the attacks have not caused any significant damage and have only resulted in temporary delays and disruption. The reported spike in activity is likely due to South Korea’s decision to monitor North Korean troops who are currently fighting alongside Russian troops in Ukraine. The groups also made unverified claims to have compromised industrial control systems (ICS) in South Korea and Ukraine, highlighting the potential operational risks facing these environments. Although South Korea has announced plans to enhance its cyber security preparedness in light of these attacks, we assess that security and disruption risks for South Korean entities will be heightened in the medium term. (Source: Sibylline)

 

06 Nov 24. Becrypt to exhibit at SDSC-UK 2024: 18-20th November, Stand 29A. Becrypt, a leader in high assurance cybersecurity products and services, is excited to announce its participation in the upcoming Specialist Defence & Security Convention UK (SDSC-UK) 2024, taking place from November 18-20th at the Telford International Centre, Telford. This event offers industry professionals a valuable opportunity to meet various companies, including Becrypt, and explore their innovative products designed to protect organisations from elevated cyber threats.

At SDSC 2024, Becrypt will showcase its comprehensive suite of high assurance solutions tailored for both public and private sector organisations. Attendees are encouraged to visit Becrypt on Stand 29A to learn more about the following key products developed in collaboration with the UK Government:

High Assurance Solutions:

  • Secure Endpoint Solutions:

Becrypt OS (formerly known as Paradox): is the most secure enterprise grade operating system in the world. It is the only platform that provides cryptographic assurance that it is in a known-good state at boot-up.

Becrypt Enterprise Manager: is a robust management platform that stands out for its combination of solid security, ease of use, and effective management capabilities.

Becrypt Thin Client: is a secure thin client solution developed in collaboration with partners such as Amulet Hotkey and 10Zig, featuring Becrypt OS and Becrypt Enterprise Manager to enhance endpoint security.

  • Cross Domain Solutions:

Becrypt APP-XD: is the first API-centric Cross Domain Solution facilitating secure connections across trust domains, enabling innovative and safe ways of working. Becrypt’s secure endpoint solutions and mobile solutions are fully compatible with Becrypt APP-XD. Furthermore, integration with Glasswall’s CDR (Content Disarm and Reconstruction) technology ensures that all documents imported into controlled environments are in a known good format – free of malware or harmful content.

Becrypt VDI Guard: is a network isolation platform that uses Becrypt’s APP-XD high assurance gateway to protect environments hosting VDI, RDP and SSH services accessed from less trusted networks or devices. It employs Becrypt APP-XD’s network traffic whitelisting capability to enforce valid VDI, RDP or SSH traffic from connecting devices, providing robust protection against a range of elevated threats not addressed by traditional network appliances.

Becrypt Mail: combines a familiar webmail user experience with robust security features, ensuring safe information exchange among collaborating partners across varying levels of trust and information sensitivity.

Becrypt Calendar Sync: ensures secure synchronisation of calendar events across devices while maintaining data protection and adherence to organisational security policies. This facilitates the safe exchange of confidential information across various domains of trust.

  • Secure Mobile Solutions:

Becrypt MDM+: is the first Mobile Device Management (MDM) platform compatible with deep packet inspection and secure MDM hosting, reducing the risks and complexities of mobile platforms for high-risk environments.

Becrypt Docs: is an end-to-end solution that enables document, image and data files held within sensitive enterprise environments, such as government ‘high-side’ networks, to be securely accessed from authorised mobile devices, including managed smartphones and tablets.

High Assurance Services:

  • Becrypt Secure Endpoint Services: a fully managed service that provides expert support and consultancy to strengthen endpoint security, enabling organisations to deploy solutions quickly and cost-effectively.
  • Becrypt Collaborative Work Environment: is an accredited secure collaborative workspace with sovereign UK cloud hosting enabling safe collaboration among teams and organisations.
  • Becrypt Bespoke Services: are tailored cybersecurity solutions to meet unique organisation needs.

Reflecting on the importance of cybersecurity, Becrypt’s CEO, Dr Bernard Parsons MBE, stated, “In today’s rapidly evolving threat landscape, our mission is to empower organisations with the tools they need to operate securely.

 

08 Nov 24. CSIR and Sysdel collaborate on new Acepod electronic warfare pod for the SAAF. Armscor, the South African Air Force (SAAF) and the Council for Scientific and Industrial Research (CSIR) was unveiled at September’s Africa Aerospace and Defence (AAD) exhibition.

The Acepod, designed by Sysdel of Centurion and supported by Armscor and the SAAF, marks a significant advance in the country’s airborne defence capabilities. The CSIR played a crucial role in integrating and testing the pod on the SAAF’s Hawk Mk 120 aircraft.

The Acepod, short for Airborne Countermeasure and ELINT (Electronic Intelligence) Pod, is a technology demonstrator funded by the SAAF and acquisition agency Armscor. Its primary function is to develop and demonstrate advanced electronic warfare technology, while also providing crucial training to EW and radar personnel. This is critical for the SAAF, enabling the development of strategies and expertise in operating with jamming equipment.

Sysdel specialises in the development, manufacture and support of Electronic Warfare systems in the radar domain. Although Sysdel led the design of the original Acepod Mk 1, the CSIR was brought in to support integration, specifically focusing on adapting the pod to the fast jet environment. Sysdel’s experience in electronic warfare systems was complemented by the CSIR’s expertise in aircraft integration, as the latter tackled challenges like aerodynamics, physical constraints and flight requirements. The CSIR’s primary task was to address the physical challenges posed by the pod’s size and weight while not being involved in the pod’s internal electronics.

One of the major challenges faced during development was the size of the pod. Weighing 326 kilograms and stretching over three and a half meters in length, the pod is the heaviest payload ever integrated onto a South African Hawk. This posed unique challenges, particularly given the limited ground clearance of the Hawk’s relatively low undercarriage. To address this, the CSIR developed a custom trolley to safely load and mount the pod under the aircraft’s centre pylon.

Despite these challenges, the integration process was completed at a fraction of the cost that would have been charged by the original equipment manufacturer (OEM). The CSIR’s work on the Acepod Mk 2 resulted in the development of a new methodology for integrating large payloads onto fast jets, which has since been patented.

The first flight test of the Acepod Mk 2 took place in March this year. Primary envelope expansion tests have demonstrated the pod’s compatibility with the Hawk, confirming its structural and operational integrity in flight. The next phase, involving the testing of the pod’s actual jamming payload, is scheduled for early next year. This timeline depends on the availability of testing facilities in South Africa, including critical vibration tests that will further validate the pod’s performance.

The pod requires considerable support from the aircraft to function, as it draws power from the Hawk to run its onboard systems. The collaborative effort between Sysdel, the CSIR and the SAAF’s Test Flight and Development Centre (TFDC) was essential in overcoming these technical hurdles, with the CSIR orchestrating the process in close coordination with the Air Force’s Directorate System Integrity.

The Acepod Mk 2 represents a major leap in South Africa’s electronic warfare capabilities. The SAAF has never had access to such a powerful jamming pod and once fully operational, the pod will significantly enhance the SAAF’s ability to conduct EW missions and safeguard its airspace against evolving threats. (Source: https://www.defenceweb.co.za/)

 

08 Nov 24. L3Harris Electronic Warfare System Completes Safety of Flight Testing. L3Harris Technologies (NYSE: LHX) has completed Safety of Flight (SOF) qualification on its Viper Shield™ all-digital electronic warfare (EW) suite for F-16 fighter jets. The company will provide the advanced capability to F-16 fleets for six international partners.

The Viper Shield system passed a series of environmental and electrical tests across structural integrity, thermal and electrical safety, and aircraft aerodynamics areas. Through the extensive SOF regimen, Viper Shield handled the stresses and strains of normal and extreme flight maneuvers, and the company proved it to be safe, reliable and effective on the aircraft.

“Completing the comprehensive SOF evaluation is a significant milestone for Viper Shield and for our growing list of global customers,” said Ed Zoiss, President, Space and Airborne Systems, L3Harris. “This critical electronic warfare system will begin flight testing soon, and we will start delivering the capability in late 2025.”

Viper Shield equips aircrews and commanders with situational awareness about the electronic landscape and helps them identify, locate and counter threats to enable survivability and lethality in the most challenging environments. It is the only advanced EW solution that is funded and in active production for international F-16 partners. By design, L3Harris engineered Viper Shield to allow for future capability upgrades, ensuring it can adjust to an evolving electromagnetic spectrum environment. (Source: ASD Network)

 

08 Nov 24. Cyber Update Key points.

  • The distribution of fake videos to undermine trust in the 5 November US presidential election highlights mis- and dis-information risks.
  • The increased use of the ‘Quad7’ botnet to conduct password spray attacks will elevate security risks posed by the Chinese-nexus group ‘Storm-0904’.
  • Evolving tactics from the Iranian state-sponsored group ‘Cotton Sandstorm’ will elevate security risks to global entities
  • The new banking trojan ‘ToxicPanda’ increases financial risks to Android users.
  • The breach of a Singaporean telecommunications provider will elevate security and disruption risks from Chinese state-sponsored groups.

Technical analysis of weekly stories

The new banking trojan ToxicPanda is targeting Android mobile users in France, Italy, Latin America, Portugal and Spain in a financially motivated campaign. ToxicPanda manipulates Android accessibility services using on-device fraud (ODF) techniques; this allows the trojan to escalate privileges and take full control over compromised systems to manipulate user inputs and capture data from mobile applications. The trojan can bypass security mechanisms to intercept one-time passwords and two-factor authentication to hijack user mobile banking accounts. This enables threat actors to initiate fraudulent money transfers to garner illicit profit while employing obfuscation techniques (such as code-hiding techniques) to evade detection. Other ToxicPanda capabilities include taking screenshots and key-logging inputs as well as converting images to send back to the actors’ command-and-control (C2) infrastructure. The trojan notably shares similarities with another malware strain, ‘TgToxic’. However, ToxicPanda displays limited obfuscation techniques and incomplete code elements, suggesting that the malware may still be in a development phase given the lack of technical sophistication compared to TgToxic. The actors behind this campaign are likely of Chinese origin, highlighting a potential shift in Chinese cyber criminal tactics since they do not typically conduct banking fraud operations against Europe and Latin America.

The Iranian state-sponsored group Cotton Sandstorm has shifted its tactics since the onset of the Israel-Hamas war and amid recent regional escalations in the Middle East. While Cotton Sandstorm’s modus operandi typically includes data-leak operations primarily against Israeli and US organisations, the group has recently widened its victim pool to also include France and Sweden. The actors also impersonated a legitimate technology company to infiltrate and exfiltrate data from IP cameras since the Paris 2024 Olympics, underscoring an expansion of its targeted assets. The same fake company has been used to provide other Middle Eastern cyber threat groups with resources and infrastructure since at least mid-2023, suggesting that Iranian state-sponsored groups may increase their level co-operation with other groups in future. This encompassed several Europe-based servers used by Lebanon-based individuals to host Hamas-affiliated websites. Cotton Sandstorm also used other fake online personas to conduct malicious cyber activity against adversaries under the guise of hacktivism. Additionally, the group has adopted generative artificial intelligence (AI) to create fake online content pertaining to the Israel-Hamas war.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
  • Ensure adequate security monitoring and detection capabilities, particularly for all external-facing services and devices; this includes personal devices connected to corporate networks or applications
  • Adopt and review network authentication services including virtual private network (VPN) services and multi-factor authentication (MFA).

Our cyber word(s) of the week: Small office/home office (SOHO) routers

(Source: Sibylline)

 

08 Nov 24. At Euronaval Indra unveiled its signals intelligence (SIGINT) solution designed to adapt to the characteristics of military vessels. At Euronaval, the naval industry trade fair being held in Paris this week, Indra has unveiled its signals intelligence solution (SIGINT), specially designed to adapt to the characteristics of any type of military vessel and bolster its protection against potential threats.

The system detects both radar and communications signals, and its size, weight and power consumption has been streamlined for its installation on virtually any vessel, from patrol vessels that have been in service for several years to newly built ships. The system can operate in isolation, in the case of vessels with less electronic equipment, or integrated in the complex network of sensors on board state-of-the-art vessels. All of its threat detection, analysis, classification and identification functions have been automated for simpler operation.

Maria del Mar Pomares, responsible for this solution at Indra, explains that “with this system we provide any ship and navy with capabilities that until now were reserved only for the most advanced vessels or those specialising in intelligence work” and adds that “at Indra we believe that no ship can operate without this type of system, which is essential to detect attacks with enough time to react”.

Indra has been working for decades with major shipyards and marinas around the world, including those in countries such as Spain, Germany, Norway, Italy, India, South Korea and Mexico. Among the ships operating with its systems are the F100 frigates and the LHD Juan Carlos I of the Spanish Navy. It is currently working on the development of some of the sensors that the future F110 Frigate will carry, which will be housed in an integrated mast that has been specially designed to reduce the size occupied by radar and provide the ship with the greatest possible stealth.

With this electronic intelligence system, Indra brings to market a solution that includes advanced features derived from this extensive experience. The new system is capable of monitoring the entire electromagnetic band simultaneously and detecting low probability intercept (LPI) signals used by ships and submarines trying to hide themselves. It is set up to operate in environments where the adversary tries to conceal its presence and has an extensive library to compare the signals collected and identify the type of radar or communications system involved. (Source: joint-forces.com)

————————————————————————————————————————————————————————————————————————————————————————————————————————————

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

————————————————————————————————————————————————————————————————————————————————————————————————————————–

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

November 8, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

—————————————————————————————————————————————————————————————————————————————————————————————————————————————

07 Nov 24. Spectra Group opens new Australia office to serve Australian and regional customers. Spectra Group, the specialist provider of secure voice, data and satellite communications systems is proud to announce the launch of Spectra Group (Australia) at MilCIS 2024 (12-14 Nov) which will be in booth B24 at the National Convention Centre, Canberra.  This marks a significant expansion for Spectra Group as it enhances its ability to serve customers in Australia and the Asia-Pacific region.

As part of this launch, the communications operations of C3 Systems will amalgamate with Spectra Group (Australia), allowing for a more streamlined approach to meeting the needs of existing and future regional customers.   This move enables Spectra Group to provide its renowned exceptional service and innovative solutions to regional clients.  Notable offerings will include the Troposcatter Family of Systems (FoS) which provides highly mobile, high bandwidth strategic communication links between key headquarters, the award-winning SlingShotTM system that converts standard UHF and VHF tactical radios into strategic satellite communications with true Beyond Line of Sight (BLOS) and Communications on the Move (COTM) capabilities and the revolutionary new GENSS software defined radio that combines all the advantages of SlingShot with the need for increased battlefield data capacity and agility into a single system.  This expansion underscores Spectra Group’s commitment to providing unparalleled support and innovative solutions to its regional customers.

Simon Davies, CEO of Spectra Group said: “As our portfolio of products and services continues to grow, providing closer support to our global customers has become the next logical step. We’ve recently expanded our footprint in the US, and we’re seeing increasing demand in Australia and the Asia-Pacific region.  Our goal is to ensure our customers receive the highest levels of support.” He added: “We’re excited to bring the track record and expertise of the C3 Systems Communications team into Spectra Group, led by Chris Hembling, whose reputation for quality resonates with Spectra’s core values of agility, loyalty and honesty.  Their expertise is invaluable, and we believe it will be crucial to the success of Spectra Group (Australia).  The new office is being established primarily to serve the Australian market with our high-quality products and services.  Additionally, the Australian team will support opportunities in the region and strengthen our wider group as needed.”

 

07 Nov 24. November Spectrum SitRep. Saab’s new Sirius Compact L20C COMINT ESM covers wavebands of 20 megahertz up to three gigahertz, with the option to extend this to six gigahertz.

Armada’s monthly round-up of all the latest electronic warfare news in the product, programme and operational domains.

New Sirius COMINT System Unveiled

Saab has unveiled the latest member of its Sirius communications intelligence Electronic Support Measure (ESM) family in the guise of the Sirius Compact L20C. The company told Armada, via a written statement, that this new product covers a waveband of 20 megahertz up to three gigahertz. Customers have the option to extend this to waveband to six gigahertz. The Sirius Compact L20C can perform a direction-finding scan while simultaneously listening to a specific signal. Saab added that the ESM uses several techniques to determine emitter location. These techniques include phase interferometry, super resolution direction finding, and static and dynamic triangulation. Future augmentations could include the addition of time difference of arrival emitter location techniques. Later enhancements will be possible due to the software-defined architecture used by the Sirius Compact L20C, and other members of the Sirius family. This approach enables the system to remain abreast of emerging threats as and when they appear.

KORA-40 for Sachsen class

Rohde and Schwarz announced on 21st October that the company has been contracted to provide radar and communications Electronic Support Measures (ESMs) to the Deutsche Marine (German Navy). The ESMs will be drawn from the company’s KORA family, specifically the KORA-40 design. The KORA-40 can detect, identify, locate and process radar and communications signals-of-interest. The new ESMs are to equip the navy’s ‘Sachsen’ class frigates. As Armada has previously reported, the KORA-40 can accommodate several modules according to the desired targeted frequencies. One module covers a waveband of 500 megahertz to 40 gigahertz/GHz, another covers two gigahertz to 18GHz. A company press release disclosed that the navy will receive six systems: Three of these will equip the same number of frigates. Sources close to the contract revealed that the other three are to equip shore establishments to aid training. German media reports say the shore systems are expected to be operational by 2026. The installation of the ESMs on the ships, the reports continued, should be completed by 2030.

The German Navy is receiving six KORA-40 radar and communications electronic support measures to equip its ‘Sachsen’ class frigates and shore-based training facilities. Deliveries of all systems are expected to be completed by 2030.

Finding the Jammers

Zephr has shared with Armada details of the cellphone-based Electronic Support Measure (ESM) it has developed and deployed in Ukraine to detect Global Navigation Satellite System (GNSS) Position, Navigation and Timing (PNT) jamming signals. As Armada has chronicled in the past, GNSS PNT jamming has been performed by Russian forces occupying Ukraine. The primary goal of the jamming has been to disrupt the GNSS navigation systems of some Precision Guided Munitions (PGMs). Uninhabited Aerial Vehicles (UAVs) are also dependent on PNT signals for navigation. Known as Zephr SDK, the system uses existing cellphones and their networks to detect incidences of GNSS jamming. Artificial intelligence-enabled software determines PNT jamming signals as these are detected by the phones and their network. The software can also compute jamming signal power levels, signal azimuths and points of origin. This latter factor is particularly important as it may allow kinetic effects to be directed against the jammer. The software will no doubt prove its worth as a useful capability to aid mission planning. UAV pilots and personnel using GNSS-guided PGMs will be able to plan their missions mindful of where GNSS jamming is concentrated. Zephr told Armada that the system does not depend on any hardware. Instead, it uses a Software Development Kit (SDK) optimised for cellphones using the Android operating system. A 5G 3GPP (Fifth Generation Third Generation Partnership Project) integration is needed to connect GNSS receivers. The company continued that the capability can be added as a software application on a standard mobile device. An SDK integrating these capabilities into the Android-based Tactical Assault Kit battle management software is also available. (Source: Armada)

 

05 Nov 24.  Global: Increased botnet activity highlights elevated security risks from Chinese-nexus actors. On 3 November, international news outlets reported that the Chinese-nexus group ‘Storm-0904’ is using the ‘Quad7’ botnet to conduct password spray attacks. The botnet infrastructure is made up of compromised network edge devices such as small office/home office (SOHO) and virtual private network (VPN) appliances. It contains at least 8,000 active devices at any given time, pointing to the scale and potential impact of this operation. Storm-0904 is conducting password spray attacks via pre-established Quad7 infrastructure, likely in an effort to hijack user accounts for additional malicious activities. Notably, the group frequently changes the internet protocol (IP) address associated with its infrastructure and limits the amount of login attempts per day to enhance detection evasion. Additionally, we assess that the botnet in this campaign is possibly still in a testing phase due to the increasing number of infected devices. Quad7 activity has surged markedly since September (at least), elevating the security risks facing global organisations in the medium-to-long term. (Source: Sibylline)

 

05 Nov 24. Finnish Defence Forces Started Serial Procurement of Bittium Tough SDR™ Tactical Radios from Bittium Wireless Ltd, a Subsidiary of Bittium Corporation. The Finnish Defence Forces has started the serial procurement of Bittium Tough SDR Handheld and Vehicular radios and related accessories by issuing a purchase order to Bittium Wireless Ltd, a subsidiary of Bittium Corporation. The value of the purchase order is approximately EUR 25.6m and it is the third additional purchase related to the additional purchase option included in the purchase agreement signed on December 12, 2018. The deliveries for the purchase order will be started during the year 2024 and they will be finalized during the year 2025. Bittium announced on November 4, 2024, with a stock exchange release that the Finnish Minister of Defence Mr. Antti Häkkänen had authorized the Finnish Defence Forces to start the serial procurement of Bittium Tough SDR tactical radios.

Bittium Tough SDR Handheld and Vehicular radios will be integrated as part of the Finnish Army’s M18 C5 system and the Finnish Defence Forces’ family of radios. The Tough SDR radios will gradually replace the Finnish Defence Forces’ existing stock of analogue tactical radios with modern software-defined radios enabling broadband tactical communications. The serial procurement enables expanding the usage of the new radios in all the military branches of the Finnish Defence Forces and the subordinate establishments operating under the Defence Command.

The radios will offer significantly better performance compared to the earlier generation of digital tactical radios thanks to the software and waveforms used in the radios. It enables carrying out performance enhancements for the radios throughout their whole life cycle. The Tough SDR radios are compatible with the software-defined radio based Bittium Tactical Wireless IP Network™ (TAC WIN) system already used by the Finnish Defence Forces.

Bittium issued a stock exchange release on December 12, 2018, on the purchase agreement for Bittium Tough SDR radios signed by the Finnish Defence Forces and Bittium. The purchase agreement includes terms for additional purchases, according to which, the Finnish Defence Forces have an option to purchase additional tactical radios and related accessories, training, and system management for the Army, Air Force, and Navy based on the prices agreed in the purchase agreement.

Bittium Tough SDR™ product family

Bittium Tough SDR product family of tactical radios consists of Bittium Tough SDR Handheld™ radio for dismounted soldiers and Bittium Tough SDR Vehicular™ radio for vehicle installations. The Tough SDR radios help to produce and share real-time situational awareness to all levels of the organization. This improves the performance and the effectiveness of the tactical troops, and leading the troops is easier based on the up-to-date situational awareness and more reliable connections. The uniquely wide range of frequency bands in the radios improves combat survivability. Using several waveforms, even simultaneously, improves compatibility and enables operations on different levels and missions. The radios are compatible with ESSOR High Data Rate Waveform that is standardized by NATO and enables tactical communications between troops from different nations. Together with the software-defined radio based Bittium Tactical Wireless IP Network™ (TAC WIN) system, used for forming a tactical broadband mobile IP backbone network, it is possible to bring broadband data and voice to all mobile troops starting from brigade level and all the way across the battlefield to an individual soldier.

Inside Information: Finnish Defence Forces Authorized to Start Serial Procurement of Bittium Tough SDR™ Tactical Radios from Bittium Wireless Ltd, a Subsidiary of Bittium Corporation. The Finnish Minister of Defence, Mr. Antti Häkkänen has authorized the Finnish Defence Forces to start serial procurement of Bittium Tough SDR Handheld and Vehicular radios and related accessories from Bittium Wireless Ltd, a subsidiary of Bittium Corporation. The total value of the procurement would be approximately EUR 25.6 m and it would be the third additional purchase related to the additional purchase option included in the purchase agreement signed on December 12, 2018. The Finnish Defence Forces will issue a separate purchase order for the products and related accessories. The products are planned to be delivered during the year 2025. The product deliveries are planned to start during the remainder of the year 2024.

Bittium Tough SDR Handheld and Vehicular radios will be integrated as part of the Finnish Army’s M18 C5 system and the Finnish Defence Forces’ family of radios. The Tough SDR radios will gradually replace the Finnish Defence Forces’ existing stock of analogue tactical radios with modern software-defined radios enabling broadband tactical communications. The procurement authorized now enables expanding the usage of the new radios in all the military branches of the Finnish Defence Forces and the subordinate establishments operating under the Defence Command.

“We have achieved a major milestone in the development of our Bittium Tough SDR radios. The products are now ready for serial procurement. We thank the Finnish Defence Forces for the close cooperation during the product development phase. In cooperation we have been able to ensure that the radios meet the requirements of the Finnish Defence Forces and the battlefield. The product development and performance enhancements for the products will continue for their existing features. This continuous development ensures that the performance of the products is sustained according to the requirements of the battlefield in the ever-changing conditions,” says Tommi Kangas, Senior Vice President of Bittium’s Defense & Security business segment.

The radios will offer significantly better performance compared to the earlier generation of digital tactical radios thanks to the software and waveforms used in the radios. It enables carrying out performance enhancements for the radios throughout their whole life cycle. The Tough SDR radios are compatible with the software-defined radio based Bittium Tactical Wireless IP Network™ (TAC WIN) system already used by the Finnish Defence Forces.

Bittium issued a stock exchange release on December 12, 2018, on the purchase agreement for Bittium Tough SDR radios signed by the Finnish Defence Forces and Bittium. The purchase agreement includes terms for additional purchases, according to which, the Finnish Defence Forces have an option to purchase additional tactical radios and related accessories, training, and system management for the Army, Air Force, and Navy based on the prices agreed in the purchase agreement.

Bittium Tough SDR™ product family

Bittium Tough SDR product family of tactical radios consists of Bittium Tough SDR Handheld™ radio for dismounted soldiers and Bittium Tough SDR Vehicular™ radio for vehicle installations. The Tough SDR radios help to produce and share real-time situational awareness to all levels of the organization. This improves the performance and the effectiveness of the tactical troops, and leading the troops is easier based on the up-to-date situational awareness and more reliable connections. The uniquely wide range of frequency bands in the radios improves combat survivability. Using several waveforms, even simultaneously, improves compatibility and enables operations on different levels and missions. The radios are compatible with ESSOR High Data Rate Waveform that is standardized by NATO and enables tactical communications between troops from different nations. Together with the software-defined radio based Bittium Tactical Wireless IP Network™ (TAC WIN) system, used for forming a tactical broadband mobile IP backbone network, it is possible to bring broadband data and voice to all mobile troops starting from brigade level and all the way across the battlefield to an individual soldier.

 

04 Nov 24. ELT Group will take part in the 29th edition of Euronaval Hall 6 G36, Europe’s most important showcase for the naval community that will take place in Paris Nord, Villepont between 4th and 7th November. With more than 70 years of experience in electromagnetic spectrum operation (EMSO) domain, ELT Group will show its solutions and capabilities for the Naval and Underwater domains protecting naval and maritime assets while projecting power at sea and providing a key contribution to the Maritime Domain Assessment. The Group has a long-standing tradition in the naval sector and a strong record of successful domestic and international collaboration on key platforms like the Franco-Italian Horizon and FREMM class ships, the NFH-90 naval helicopter and a wide range of projects in the Middle East and Asia-Pacific. Our products boast high sensitivity, high accuracy, fully automatic surveillance functions and state-of-the art data processing. The focus at Euronaval will be on its new generation Naval EWS suite developed for the FREMM EVO class, and capable now to include an integrated Anti-Drone capability through dedicated components and benefiting from the assets already available on board (CESM, RECM, EWC2), with a significant growth capacity through the widespread use of Artificial Intelligence. A peculiar attention is given by ELT Group to the Underwater domain, which is gaining increasing strategic relevance because of its very wide range of applications; at the same time is the new frontier where the defence world is beginning to confront itself. The EWS for the U212 NFS submarines class represents the key reference. This EWS suite is characterised by a new highly innovative integrated antenna, able to cover the whole Radar and Comms Spectrum, allowing detection and direction finding with outstanding performances.

 

01 Nov 24. Saab evolves naval electronic support measures solutions. Saab Grintek Defence (SGD) is evolving its naval electronic support measures (ESM) solutions with its new third generation U/SME-400 wideband digital ESM family. The U/SME-400 is the company’s flagship naval radar warning/electronic support measures system and will be displayed for the first time at the Euronaval exhibition in Paris that takes place between 4 and 7 November. Emphasising the importance of ESM systems for naval applications, Saab notes that navies still rely on ESM systems as primary sensors when operating in radar silence. The company’s first- and second-generation systems have been integrated onto Greek, Portuguese, and South Korean submarines, amongst others – fifteen solutions are in service with three NATO navies. The ESM and ELINT (electronic intelligence) range comprises the SME-50 ESM receiver, SME-150 ESM system with ELINT functionality, and SME-250 ESM receiver with digital ELINT receiver – the latter covers the .5-18 GHz range while the SME-50 and SME-150 cover the 2-18 GHz range. The SME designation is used for surface vessels and UME for subsurface vessels. These systems can be integrated with the NLWS (Naval Laser Warning System), MASS (Multi Ammunition Softkill System) or other decoy systems, active electronic countermeasures (ECM) systems, and Saab CRS-8000 communications ESM system (Saab Deutschland offers the CRS series of naval communications intelligence [COMINT] and communications ESM [C-ESM] solutions).

What distinguishes the new U/SME-400 from previous generations is a shift to a fully digital system with a wideband receiver. According to Francois Raubenheimer, Business Development and Marketing Executive at Saab Grintek Defence, some of the advantages of going digital are enhanced signal processing, faster processing, better classification and tracking of complex signals especially in crowded environments with overlapping signals, resilience to interference, and easy adaptation to new signal types without hardware changes, making it possible to react quickly to new tactics developed by adversaries.

Other advantages are greater accuracy and sensitivity, including improved detection of weak and low power signals. Raubenheimer pointed out that radars are becoming stealthier and use lower power, making them more difficult to detect.

The U/SME-400 series is being developed in three main variants: U/SME-410 (2-18 GHz with 16 GHz instantaneous bandwidth [IBW] acquisition and .5 GHz instantaneous bandwidth direction finding [DF]); U/SME-420 (1-18 GHz with 16 GHz IBW acquisition and 8 GHz IBW DF); and U/SME-450 (1-18 GHz with 16 GHz IBW acquisition and 16 GHz IBW DF). These are able to intercept, detect, and identify modern wideband radars including low probability of intercept (LPI) frequency modulated continuous wave (FMCS) radars at long ranges.  The U/SME-420 and U/SME-450 are both also available with an option to cover Ka-band.

Development of the U/SME-400 series is still underway, with about a year to go before production ready status, but Saab is already promoting the system as naval vessel programmes take years to be completed. Sea trials are expected in the next year or so, and the company has already offered it to prospective customers.

SGD has built its naval business tremendously over the last quarter of a century, with one of its other key naval products being its Naval Laser Warning System (NLWS), which can be either a standalone system or fully integrated into a vessel’s combat system. It includes a laser waring system for surface vessels and a Light Detection and Ranging (LIDAR) blue-green laser sensor for sub-surface applications. Sensors are placed around a vessel to ensure adequate coverage, with the number of sensors determined by the size of the vessel. The system, which interfaces with the vessel’s combat management system and ESM, can provide the bearing, laser classification and identification information required to deploy the necessary countermeasures.

The NLWS features the NLWS 310 laser warning sensors, which in LWS 310 guise is also used in Saab’s IDAS defensive aids suite for aircraft, and operates across the .5-1.7 nm wavelength to provide threat classification and direction of arrival for laser rangefinders, designators and missile guidance lasers. The LWS series has gone through several versions, namely Mk I, II, and III, with a new high accuracy sensor (LWS-700) launched in 2023.

The new LWS 700 allows for the automated detection, classification, and identification of laser-based weapons. It is capable of classifying and identifying laser threats such as target designators or laser rangefinders. With a 1° bearing and elevation accuracy, the sensor is able to support countermeasures, specifically the deployment of hard-kill counter fires. This is a much-improved version to the LWS 310, which offers a bearing accuracy of 7.5°.

SGD’s NLWS is in service with several nations, including with the United Arab Emirates Navy (Baynunah class corvettes), German Navy, and New Zealand Navy and on order, 5+ nations. For German Mine Sweepers, Saab’s radar ESM and laser warning systems are used in combination with Rheinmetall’s Multi Ammunition Softkill System (MASS) decoy system, which guards against both radar and laser-guided threats.

SGD’s naval products are somewhat unique in that they are used in air, land and sea applications as they share common building blocks. Saab Grintek Defence has for many years manufactured laser warning and missile approach warning sensors, with previous generations being the LWS-310 and MAW 300 respectively. The company recently launched its next generation MAW 400 and LWS-330 for airborne platforms, now in production, with a European customer the first to take these new products.

In addition, Saab Grintek Defence is producing a LEDS 50 MK 4 system with the LWS-700 sensors, which is a 1-degree sensor for land applications. (Land Electronic Defence Systems, or LEDS, is an integrated, modular, active protection system consisting of laser warning sensors, an active defence controller, human-machine-interface and an effector control segment that can launch smoke or cue jammers).

Saab’s laser and missile approach warning systems form part of its integrated defensive aids suite (IDAS) for helicopters, transport aircraft and combat aircraft. IDAS warns against radar, laser and infrared guided threats and automatically deploys appropriate countermeasures such as chaff and flares. IDAS is operational on 30+ aircraft types in more than 15 countries.

(Source: https://www.defenceweb.co.za/)

 

31 Oct 24. Bombardier Defense Delivers 8th Global Aircraft to the USAF BACN Program.

  • Bombardier Defense delivered the eighth Bombardier Global aircraft to the United States Air Force for the Battlefield Airborne Communications Node (BACN) program at the company’s service centre in Hartford, Connecticut
  • Bombardier’s multi-year agreement with the Air Force supports a distinctive and reliable airborne communications platform that is essential for completing critical missions across air, space, land and sea
  • Due to their proven reliability, endurance, reduced maintenance costs and fuel efficiency, Global business jets have become the go-to platforms for specialized missions around the world

Bombardier Defense today announced the delivery of the eighth Bombardier Global jet to the United States Air Force’s (USAF) Battlefield Airborne Communications Node (BACN) program, which is part of a previously announced multi-year contract between Bombardier and the USAF. This deal represents a potential total value of close to US$465m. To date, Bombardier Defense has delivered seven Global aircraft to the BACN program under other agreements, with a ninth aircraft scheduled for delivery in 2025.

“We are proud that Bombardier’s category-defining Global aircraft continue to be a platform of choice for the U.S. Air Force,” said Jean-Christophe Gallagher, Executive Vice President, Aircraft Sales and Bombardier Defense. “The speed, agility and low operating costs of our Global jets make them ideally suited for specialized missions meant to strengthen national and international security initiatives, such as the critical BACN program. With the delivery of this aircraft, Bombardier Defense continues to deepen its relationship with the U.S. Air Force and set itself apart as a missionized platform provider of choice.”

The BACN aircraft, known as E-11A, is a specialized communications platform that enables enhanced situational awareness and interoperability. Dubbed “Wi-Fi in the sky” by the USAF, BACN-equipped Global aircraft act as high-altitude communications gateways that can be used around the world, relaying or bridging voice and tactical data between air and land forces, and surmounting obstacles such as mountains, rough terrain or distance. Due to their unmatched combination of speed, range and endurance, Bombardier Global aircraft remain the platform of choice for more than 10 different mission types across the world.

Bombardier Defense has dedicated in-house engineering and support teams with the ability to incorporate customer-requested modifications and provide comprehensive integration solutions with complete certification capabilities across the full spectrum of civilian, military and hybrid operations. Recognized around the world for its diverse portfolio of proven and versatile specialized aircraft platforms, Bombardier brings decades of experience working with hundreds of special mission operators and renowned mission systems integrators. (Source: ASD Network)

 

01 Nov 24. Cyber Update Key points

  • The exploitation of a software vulnerability points to sustained information-theft and financial risks stemming from the ransomware groups ‘Fog’ and ‘Akira.’
  • The Russian state-sponsored group ‘UNC5812’ is targeting military recruits in Ukraine, underscoring the current cyber espionage and disinformation risks (Technical analysis below).
  • A new and highly sophisticated spyware variant has raised the security risks for iOS users.
  • A long-term cyber operation targeting Canadian entities has heightened the espionage risks stemming from Chinese threat actors .
  • A new and more sophisticated variant of the ‘FakeCall’ malware is being used as part of a financially motivated operation, elevating the financial risks facing Android users in South Korea (see Technical analysis below).

Technical analysis of weekly stories

The Russian state-sponsored group UNC5812 is targeting military recruits in Ukraine in a cyber espionage and influence operation. The group created a fake profile on the messaging platform Telegram to reach potential victims, purporting to provide conscripts with crowdsourced locations of Ukrainian military recruiters. Users are prompted to click on a fraudulent website to download the software, unknowingly installing malware on compromised systems. The actors also use social engineering techniques to instruct users to disable Google Play Protect security mechanisms to allow for third-party downloads and detection evasion. The group has targeted Windows and Android users to inject compromised systems with the ‘PURESTEALER’ information-stealer and the ‘CRAXSRAT’ backdoor. PURESTEALER enables the actors to steal browser data and cryptocurrency wallets, while CRAXSRAT allows for file and text message management, credential harvesting and other monitoring capabilities. Additionally, the fraudulent website distributes anti-mobilisation content to undermine Ukrainian recruitment efforts. It also solicits users to upload videos of unfair actions to discredit the Ukrainian military, highlighting the disinformation risks associated with this campaign. Notably, UNC5812 likely purchases promoted posts on legitimate Ukrainian Telegram channels to direct users to the actor-controlled Telegram channel, propagating the infection to a wider audience and enhancing the site’s legitimacy.

A new and more sophisticated version of the FakeCall malware is targeting Android users in South Korea in a financially motivated campaign. The campaign typically starts with a phishing attempt to trick users into downloading a malicious call handler application that acts as a malware dropper. This then installs the main FakeCall payload, while simultaneously establishing communication with the actors’ command-and-control (C2) infrastructure to perform additional malicious activities. This new variant manipulates Android accessibility service features to bypass security mechanisms and to take control of a device’s user interface (UI). Additionally, it incorporates two receiver services to monitor the status of a victim’s screen and Bluetooth functionality, as well as a phone-listener service to execute commands on compromised devices (including sending and deleting messages and ending phone calls). Subsequently, the malicious application asks the user to set the app as the device’s default call handler; this provides the threat actors with the ability to monitor all incoming and outgoing phone calls. Threat actors then interject any calls to the victim’s financial institution, displaying a fake UI with the institution’s legitimate phone number. This enables them to steal sensitive financial information to hijack user accounts so as to steal funds. This operation highlights the continuous development of malware by cyber criminals to garner illicit profit as well as the actors’ growing sophistication (this variant is highly obfuscated to evade detection).

Some non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
  • Ensure adequate security monitoring and detection capabilities, particularly for all external-facing services and devices, including personal devices connected to corporate networks or applications
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering

(Source: Sibylline)

 

05 Nov 24. Thales’s Naval DRAKON Solution Enhances Interoperability and Secure Connectivity for Naval Forces.

  • With the return of high-intensity conflicts and an increasingly complex threat environment, naval forces must be prepared to take part in allied operations involving the coordinated deployment of multiple platform types including surface ships, submarines, aircraft and unmanned platforms.
  • Thales has developed Naval DRAKON to meet these new requirements, providing a cybersecure, interoperable connectivity solution for deployed forces by tying together multiple communication systems (military and commercial satcoms, VLF/LF, HF, V/UHF, etc.).
  • The new solution enables naval forces to control their electromagnetic footprint at sea and adapt communications to the operational tempo of the mission by prioritising data rate, discretion, resilience or low latency.

With the growing number of platform types deployed (allied naval formations, unmanned surface vessels, unmanned air systems, etc.), the broad array of communication systems available and the multitude of threats (missiles, torpedoes, drones, etc.), naval force coordination is becoming increasingly complex.

Naval DRAKON was specifically developed to provide high-data-rate, robust and secure communications between naval vessels, airborne sensors and command centres. It is designed around an open architecture to support all the latest and most advanced communications technologies such as wideband HF (HF XL), ultra-compact multi-orbit satcom terminals, high-data-rate LOS radio and software-defined V/UHF.

This sea-proven solution enables naval forces to control their electromagnetic footprint at sea and adapt communications to the operational tempo of the mission by prioritising data rate, discretion, resilience or low latency.

Naval DRAKON is the naval version of Thales’s DRAKON solution for land forces, which was presented at Eurosatory in June 2024, and draws on the same operational expertise and proven capabilities.

Thales is a recognised leader in critical systems integration, working with more than 20 naval shipyards around the world and equipping more than 400 naval platforms, including about 100 submarines, over the last 40 years. Earlier this year, the Jacques Chevallier, the first of France’s new fleet replenishment tankers, completed a deployment of several months equipped with the COMTICS voice distribution system and the PARTNER-C communications management system.

The other fleet replenishment tankers in the Jacques Chevallier class, as well as the FDI defence and intervention frigates for France and Greece and the UK Royal Navy’s T31 frigates, will be the first vessels to be equipped with this new, scalable solution, which will support advanced functionalities such as spectrum management, decision support, flow management, cybersecurity management and smart maintenance.

Naval DRAKON will tie together all these services and functionalities to provide a fully integrated solution for naval forces.

(Source: ASD Network)

———————————————————————————————————————————————————————————————————————————————————————————————————————————–

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

————————————————————————————————————————————————————————————————————————————————————————————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

November 1, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

————————————————————————————————————————————————————————————————————————————————————————————————————————————–

31 Oct 24. General Atomics Aeronautical Systems, Inc. (GA-ASI) collaborated with BAE Systems to demonstrate unique electronic warfare (EW) capabilities remotely controlled via a secure, jam-resistant Link 16 network on an MQ-20 Avenger® unmanned aircraft system (UAS). The Avenger is a jet-powered platform used extensively as a test bed for autonomous UAS development and the Collaborative Combat Aircraft (CCA) program. The demonstration helps accelerate emerging networked electronic attack capabilities for U.S. Air Force Autonomous Collaborative Platforms (ACPs).

The demonstration took place at GA-ASI’s Desert Horizon flight operations facility in El Mirage, California, and is part of an ongoing series of technology insertion and autonomous flights performed using internal research and development funding to prove important concepts.

“This effort featured novel mission system capabilities and the viability of autonomous payload control on our MQ-20,” said Mike Atwood, Vice President of Advanced Programs at GA-ASI. “We’re identifying key areas for improvement, while sharing investment and reducing risk.”

BAE Systems provided customized mission technology that included EW capabilities, a multi-functional processor (MFP), and a Link 16 terminal. The company successfully tested the integrated solution in its System Integration Lab to identify and jam threats autonomously and under control of an operator. Command, control, and status of the EW system was made possible through software-based, open-mission-system (OMS) compliant message translation hosted on the MFP. A secure Link 16 networking waveform was used to disseminate this information.

“We are working closely with General Atomics to highlight the maturity of autonomous EW mission systems in support of U.S. Air Force objectives,” said Scott Bailie, director of Advanced Electronic Warfare Solutions at BAE Systems. “We are combining proven EW technology and secure command and control on a rapid timeline in a small form factor well-suited for CCAs.”

 

31 Oct 24. Pentagon rolls out JWCC cloud accelerator initiative. The US Department of Defense (DoD) directorate, tasked with executing the Pentagon’s Joint Warfighting Cloud Capability (JWCC), is initiating a cloud accelerator initiative, designed to rapidly introduce secure commercial cloud services to the US armed forces down to the tactical level.

Announced in December 2022, the JWCC was designed to “provide the DoD the opportunity to acquire commercial cloud capabilities and services directly from” cloud service providers (CSPs) to facilitate global accessibility to cloud-based capabilities through a centrally managed data distribution process and allow secure network access via tactical edge devices. The JWCC was developed after Pentagon officials scrapped the controversial Joint Enterprise Defense Infrastructure (JEDI) cloud computing programme in July 2021.

Two years into the JWCC programme, which has cost the Pentagon roughly USD9 billion thus far, officials from the Defense Information Systems Agency (DISA) have partnered with CSPs at Amazon, Google, Microsoft, and Oracle, JWCC Program Manager Alee Long said. Those partnerships have allowed the US DoD to have “a direct relationship with those CSPs, [and] we are able to bring to our DoD partners the same commercial [services] but in a secure, sovereign cloud” network, Long said during a 24 October briefing.

DoD officials have also pushed commercial CSPs to provide “tactical edge offerings”, such as secure end-user devices and data centres, to the US armed forces, she explained. Getting those services down to the battlefield with low latency or network interference has been a key priority for newly minted DISA Director US Army Lieutenant General Paul Stanton, who took command of DISA in October. (Source: Janes)

 

31 Oct 24. Canada: Long-term cyber operation points to elevated espionage risks from Chinese threat actors. On 30 October, the Canadian Communication Security Establishment (CSE) reported that cyber threat actors affiliated with China have conducted a cyber espionage operation against Canadian government agencies since at least 2019. The unnamed threat actors compromised at least 20 government agencies, as well as several private sector entities. They reportedly exfiltrated sensitive information and intellectual property pertaining to the development of advanced technologies. The campaign also specifically targeted government officials who are critical of the Chinese Communist Party (CCP) in an email-based phishing operation. Notably, Chinese cyber activity spiked following diplomatic incidents between the two countries, underscoring China’s strategic use of cyber operations to aid its geopolitical pursuits. China consistently targets adversarial entities in cyber espionage campaigns, gathering information to bolster Beijing’s security and economic posture. As such, we assess that the latest development outlines the heightened espionage risks facing Canadian entities (among others) in the long term. (Source: Sibylline)

 

30 Oct 24. DOD Chief Digital and AI Office Hosts Responsible AI in Defense Forum. Today, the Department of Defense (DoD) Chief Digital and Artificial Intelligence Office (CDAO) concluded its “Responsible AI in Defense Forum,” a 3-day event that brought together defense leaders, AI experts, policymakers, and global innovators to focus on advancements in Responsible AI (RAI), held at the Hyatt Regency in Reston, VA, Oct. 28-30.

The Responsible AI in Defense Forum provided an opportunity to discuss technical capabilities and challenges with diverse stakeholders and to examine RAI in the context of international military cooperation.

“Over the last dozen years, as advances in machine learning yielded new breakthroughs, we’ve worked hard at the Pentagon to be a global leader in establishing responsible policies for military use of autonomous systems and AI,” said Deputy Secretary of Defense Kathleen Hicks during a keynote address delivered via video. “From the beginning, DoD’s approach to responsible AI has been guided by our understanding that AI will only be used and effective where it is trusted and trustworthy. Today we’re at the forefront of accelerating the adoption of trusted AI, and we can’t afford to fall behind.”

The multiple-day Forum was designed to explore a different topic each day, with participation aligned to the topic. On day one, CDAO led a meeting among the Partnership for Defense’s (PfD) 16 members to examine strategies and tools for enabling RAI across defense enterprises. On day two, CDAO convened government, industry, and academic experts for a series of discussions on operationalizing RAI in defense. Finally, day three featured a closed-door meeting focused on aligning NATO allies and partners with RAI implementation strategies. Each day of the Forum helped advance the CDAO’s critically important work around the responsible implementation of AI in defense.

CDAO Dr. Radha Plumb kicked off the Forum with the AI Partnership for Defense.

“The RAI in Defense Forum — and first-ever in-person PfD on Responsible AI — provided an unprecedented opportunity for the Department to connect its practical Responsible AI tools and guidance with critical partners to build leadership on global Responsible AI standards and practices,” stated Plumb.

The CDAO is pleased to have hosted this pivotal gathering, having achieved its key objectives of strengthening CDAO’s relationships with PfD partners, sharing RAI implementation lessons learned, and promoting RAI globally. As a result of this effort, the CDAO looks forward to accelerated progress in RAI, both at home and abroad.

About the CDAO

The CDAO became operational in June 2022 and is dedicated to integrating and optimizing AI capabilities across the DoD. The office is responsible for accelerating the DoD’s adoption of data, analytics, and AI, enabling the Department’s digital infrastructure and policy adoption to deliver scalable AI-driven solutions for enterprise and joint use cases, safeguarding the nation against current and emerging threats.

For more information about the CDAO, please visit our website at ai.mil. You can also connect with the CDAO on LinkedIn (@ DoD Chief Digital and Artificial Intelligence Office) and X, formally known as Twitter (@dodcdao). Additional updates and news can be found on the CDAO Unit Page on DVIDS. (Source: U.S. DoD)

 

31 Oct 24. Elbit Systems Ltd. has launched its next-generation soldier radio, the E-LynX™ SR, at the International Dismounted Soldier Conference in London. This new multi-channel radio is the latest addition to Elbit Systems’ renowned and market-leading E-Lynx lineup of Mobile Tactical SDR Solutions.

E-LynX™ SR Elevates Combat Connectivity:

The product is designed based on extensive field experience and accumulated knowledge. It is meticulously engineered to meet the needs of the soldier while supporting the broader forces that communicate and process transmitted data.

The E-LynX™ SR is a scalable, lightweight, and user-friendly tactical communication device, designed with the soldier in mind. It is the most advanced model ever produced by Elbit in the Soldiers Radio category. This device delivers enhanced connectivity and advanced networking capabilities by using multi channels technology. With broad frequency compatibility and multi-channel functionality, the E-LynX™ SR is interoperable with existing E-LynX™ systems and recognizes equivalent networks, optimizing operational efficiency across all battlefield levels—from individual soldiers to entire units. E-LynX SR can operate in wide spectrum range with different bandwidth, enabling full supports of Manned-Unmanned Teaming (MUM-T) devices such as robotics and autonomous platforms, further enhancing the force’s capabilities and effectiveness in modern combat environments.

Its compact, wearable design ensures comfort and accessibility, easily integrating into a soldier’s vest or harness for maximum portability and ease of use. Equipped with a headset, the body-worn device enables continuous communication, allowing voice, data, and video transmission with minimal handling. Equipped with advanced resilience and spectrum-sensing features, the E-LynX™ SR enables uninterrupted communication by neutralizing jamming threats, optimizing the use of available frequencies, and reducing interference, all without interrupting user operations. The system also supports connectivity to cellular networks (4G/5G) and satellite communication, providing flexible backhaul solutions and increased bandwidth as needed.

By providing real-time situational awareness, quicker decision-making, and improved safety, the E-LynX™ SR elevates the capabilities of tactical communications. This cutting-edge device equips soldiers with relevant tools needed to respond swiftly and effectively in dynamic combat environments, enhancing mission success and safeguarding lives.

 

30 Oct 24. 5G COMPAD showcases several 5G network deployment scenarios in a Global Demonstration in Latvia. On October 17, 2024, in Riga, Latvia, the European Defence Fund project 5G COMPAD (5G Communications for Peacekeeping and Defence) held its first global demonstration, showcasing various 5G network deployment scenarios at sea, in the air, and on land. The demonstration was organized by 5G COMPAD consortium member LMT and took place at the military base “Daugavgrīva.” During the demonstration, several innovative 5G network deployment options were presented. These included potential network coverage simulations, 5G drone tests, satellite communication integration, and other 5G applications on ships at sea. The 5G COMPAD demonstration in Latvia’s 5G testing environment allowed for the evaluation of 5G performance under various conditions and the exploration of new potential use cases. The global demonstration was attended by 5G COMPAD project partners, stakeholders, and representatives from the Ministries of Defense of European Union member states participating in the implementation of the consortium project. Several project partners took part in the organization process alongside LMT, including Ericsson, Leonardo, Thales, Nokia, Bittium, Cafa Tech, Inster, CNIT, Eight Bells, Space Hellas SA and Intracom Defense (IDE). Before the project’s demonstration, from October 14 to 16, preparation works were held in Latvia with the participation of the organizing team. The 5G COMPAD project was kicked off in December 2022 and will run for 36 months. The project consortium partners are Saab, Ericsson, Rheinmetall, Bittium, Nokia, Thales, Leonardo, Inster, Eight Bells, Intracom Defense (IDE), Cafa Tech, Telenor, Sintef, FFI (NO Gov), LMT, AIT, Synkzone, BHE, and APR Technologies, while the Sub-Contractors are CNIT, Fraunhofer FKIE, CEA and Space Hellas SA. Within the 5G COMPAD project, world-leading partners from the telecom and the European defence industries join forces to enable recurrent integration of 5G and beyond into multi-dimensional robust defence communication systems to sustain effective and efficient information superiority for European armed forces.

Project: 101103519 — 5G COMPAD — EDF-2021-C4ISR-D-2

 

30 Oct 24. Global: Highly sophisticated spyware variant will raise security risks for iOS users. On 29 October, the security company ThreatFabric reported on the discovery of a new, more sophisticated version of the ‘LightSpy’ spyware. This new version specifically targets Apple iOS devices and contains 28 plugins to compromise device functionality and security. Threat actors typically exploit software vulnerabilities to gain access to targeted systems, subsequently using jailbreaking techniques to bypass security mechanisms. This enables them to access core system functions and data to deploy malicious payloads (including LightSpy). LightSpy’s plugins can track users’ locations, collect sensitive information (such as payment data) and prevent a device from rebooting to ensure long-term persistence, underscoring this malware’s highly sophisticated and multifunctional nature. Notably, the spyware’s command and control (C2) infrastructure showed infected devices connecting to a suspected test Wi-Fi network, suggesting that this spyware variant may still be in its development phase. As such, we assess that this operation will raise security risks for iOS users in the medium term. (Source: Sibylline)

 

29 Oct 24. BAE Systems, Aerospike to Advance Real-Time Data Capabilities for US DoD. California-based Aerospike has joined BAE Systems’ Mission Advantage technology partnership to enhance operational efficiency and decision-making capabilities for the US Army and other defense programs.

Together with BAE, Aerospike will advance data mesh solutions using its real-time database to support the Army’s Unified Network, Army Data Platform, and other data-centric mission requirements.

Data mesh is a decentralized data management approach that allows various defense units and networks to control their data while ensuring secure and efficient access across the organization.

This strategy addresses the challenges of information distribution across the Department of Defense’s extensive network, including data surges that can overwhelm systems and personnel, latency (the delay between data request and response), and geographic challenges, particularly for military units in remote or hostile locations.

The partnership will “deliver real-time, mission-critical data at scale and help ensure technological advantage on the battlefield,” according to BAE Systems’ Director of Strategy & Technology Partnerships for the Intelligence & Security sector Daniel Perkins.

“Aerospike is foundational to our data-centric solutions for the US Army and DoD, as our customers push towards managing massive amounts of disparate data while leveraging advanced AI tools,” he added.

Aerospike Public Sector Vice President Cuong Nguyen described their multi-model database as offering “the lowest-latency, highest-throughput system to enable accurate, real-time decisioning even in contested environments.”

“As a vital component of the UNO technology stack, we’re proud to partner with BAE Systems to help them optimize and demonstrate the effectiveness of their data solutions,” Nguyen stated. (Source: News Now/https://thedefensepost.com/)

 

24 Oct 24. ASELSAN unveils ANTIDOT 2-U series of electronic warfare pods at SAHA EXPO 2024. ASELSAN, Türkiye’s leading defence company, has launched its latest cutting-edge electronic warfare pods at SAHA EXPO 2024. The newly revealed pods, named ANTIDOT 2-U LB/MB/HB, ANTIDOT 2-U, and ANTIDOT 2-U/S, are designed to enhance UAVs’ capabilities, transforming them into advanced electronic warfare platforms.

These systems, developed by ASELSAN’s experts, provide UAVs with advanced threat detection, classification, and jamming capabilities, offering protection to both the UAV and nearby friendly air assets. This significant development was unveiled in the presence of key officials, including Prof. Dr. Haluk Görgün, Secretary of Defence Industries, and Ahmet Akyol, ASELSAN President & CEO.

The ANTIDOT 2-U series represents a major leap in electronic warfare technology, enabling UAVs to counter air defence systems while supporting critical missions. The lightweight and versatile systems integrate seamlessly into tactical-class UAVs, providing mission flexibility without compromising on performance.

The electronic warfare pods are fully autonomous, featuring high output power, wide frequency coverage, and the ability to suppress and deceive enemy radars. With their compact design and advanced functionality, these systems significantly enhance the survivability and operational effectiveness of UAVs in contested environments. (Source: Defense Arabia)

 

29 Oct 24. Hicks Highlights DOD’s Commitment to Responsible AI Use. Deputy Defense Secretary Kathleen Hicks today spoke about the Defense Department’s commitment to being a world leader in forging sound ethical policies for military use of artificial intelligence.

Hicks’ remarks were broadcast remotely at the Responsible Artificial Intelligence in Defense Forum in Washington.

“Over the last dozen years, as advances in machine learning yielded new breakthroughs, we’ve worked hard at the Pentagon to be a global leader in establishing responsible policies for military use of autonomous systems and AI,” Hicks said.

She then pointed out DOD has lately doubled down on that commitment, and that the Pentagon’s leadership has been able to get in front of implementing an executive order that President Joe Biden issued almost one year ago to the day on safe, secure and trustworthy AI.

“As a result, our AI is more resilient and effective than ever,” Hicks said.

Hicks also pointed out that, since 2021, DOD has not only accelerated the drive toward a more data-driven, modernized and AI-empowered U.S. military; but it has also affirmed an adherence to ethical AI principles, updated DOD responsible-use policies and directives, and issued new strategies, guidelines, guardrails and practical toolkits and apps.

“We’re glad those resources are now used by many outside DOD; like other U.S. agencies, international allies and partners, and leading tech companies,” Hicks said.

She then announced that almost 60 nations — including the U.S. — currently endorse the Political Declaration on Responsible Military Use of Artificial Intelligence and Autonomy.

That document, launched in February 2023 at the Responsible AI in the Military Domain Summit in the Hague, “aims to build international consensus around responsible behavior and guide states’ development, deployment and use of military AI,” according to the declaration’s website.

“I can’t overstate the importance of this work,” Hicks said. “Because our values not only bring us together; they set us apart from our strategic competitors.”

Pointing out that DOD has always been guided by an understanding that AI can only be useful and effective where it is both trusted and trustworthy, Hicks cautioned that the Defense Department can’t fall behind in the adoption of quality AI.

Hicks then appealed to those attending the forum, saying that they are needed to help keep DOD in the lead with AI.

“Not just with speed and security, but also safety,” she said.

“Not just rapidly, but also responsibly,” she continued. “We don’t have the luxury of choosing one side or the other. It has to be both.”  (Source: U.S. DoD)

 

28 Oct 24. Global: Software vulnerabilities sustain information-theft, financial risks from ransomware groups. On 27 October, international news outlets reported that the ransomware groups ‘Fog’ and ‘Akira’ have exploited a software vulnerability (CVE-2024-40766) to breach at least 30 organisations since August. The vulnerability affects SonicWall virtual private network (VPN) devices and reportedly enables actors to bypass security mechanisms and access sensitive files. Fog and Akira likely used stolen credentials to hijack user accounts and infiltrate targeted organisations. The actors then likely exfiltrated sensitive files, deploying ransomware to encrypt the organisations’ data for financial profit. Notably, though SonicWall patched CVE-2024-40766 in August, all the affected organisations did not apply the patch and lacked other security mechanisms to prevent infiltration. This underscores the importance of secure patch management policies and the implementation of other security measures, including multi-factor authentication (MFA), to prevent future compromises. We assess that additional infections will likely emerge in the short term, raising information-theft and financial risks to vulnerable organisations. (Source: Sibylline)

 

28 Oct 24. Defense Department Tests AI Software, Advances to Improve Physical Security Posture. Hours before dawn, under the veil of a new moon, two figures in military fatigues grapple like Greco-Roman wrestlers within the razor wire perimeter of the Blue Grass Army Depot in Richmond, Kentucky.

Their movements are rigid but discreet, each maneuvering for leverage beneath the orange glow of the floodlights lining the depot’s security fence.

In the distance, a patrolling sentry squints, straining to make sense of the dimly lit commotion. He thumbs the two-way radio on his pistol belt but hesitates, worried he may frustrate his supervisor with an inaccurate report.

But before the fight can go to ground — and before the sentry can reassess and request support — a bright red reticle highlights the entwined bodies on a control room monitor several miles away. Scylla, the artificial intelligence algorithm powering the depot’s security architecture, has made sense of what the sentry cannot.

Scylla knows instantly that the image captured by the depot’s security cameras depicts a struggle. In seconds, the algorithm references a database of friendly and malicious faces, identifies the belligerents and fires a report to the watch captain: “An on-duty military police officer is trying to subdue an intruder — a known bad actor with presumed hostile intent.”

This fictional scenario described by Drew Walter, deputy assistant secretary of defense for nuclear matters, illustrates AI’s demonstrated capabilities and underscores its potential in the realm of physical security. Last month, the Defense Department tested Scylla at the Depot. Walter described the platform as a “considerable advancement in our ability to safeguard critical assets.”

“Its capacity to learn in real time and reduce nuisance alarms — which fatigue security personnel and inhibit responses to legitimate threats — addresses a long-standing challenge in physical security,” he said.

DOD is looking at AI’s ability to enhance existing surveillance capabilities and threat detection, aligning with the department’s broader strategy to integrate data, analytics and AI across its operations.

The Physical Security Enterprise and Analysis Group, which is testing Scylla, plays a pivotal role in the department’s mission to safeguard America’s strategic nuclear capabilities. “PSEAG does physical security well and has taken the reins in both the strategic and conventional realms,” Walter said. “By unifying disparate efforts under one umbrella, we can procure and field capabilities that meet Defense Department nuclear security requirements.”

PSEAG’s interest in AI is nested in the department’s strategic priorities. Last year, in a speech on “The state of artificial intelligence AI in the Department of Defense,” Deputy Defense Secretary Kathleen Hicks emphasized the importance of integrating AI swiftly and responsibly.

“As we’ve focused on integrating AI into our operations responsibly and at speed, our main reason for doing so has been straightforward: because it improves our decision advantage,” Hicks said. “From the standpoint of deterring and defending against aggression, AI-enabled systems can help accelerate the speed of commanders’ decisions and improve the quality and accuracy of those decisions.”

Chris Willoughby, electronic security systems manager at the Depot and project lead for Scylla, is working to give life to Hicks’ vision. “PSEAG is testing, evaluating and training Scylla’s artificial intelligence deep neural machine learning software to detect and classify persons’ features, behavior anomalies, armed and unarmed threats and objects by evaluating video surveillance systems in real time,” he said.

The demonstration at the Depot showcased Scylla’s ability to detect intruders, weapons and abnormal behavior using existing video surveillance systems and drones. In one instance, the software identified an armed individual climbing a water tower a mile away. “Scylla test and evaluation has demonstrated a probability of detection above 96% accuracy standards, significantly lowering … false alarm rates due to environmental phenomena,” Willoughby said.

Walter echoed Willoughby’s enthusiasm, lauding Scylla’s unique — and cost-effective — application to existing physical security architecture. “Scylla AI leverages any suitable video feed available to monitor, learn and alert in an instant, lessening the operational burden on security personnel,” he said. “While humans still make the final decisions regarding threat response, AI augments detection capabilities.”

Walter said Scylla’s most vital application could lie in improving the physical security of DOD’s strategic nuclear arsenal. “Scylla’s transformative potential lies in its support to PSEAG’s core mission, which is to safeguard America’s strategic nuclear capabilities when they are in the department’s care,” he said. “The ability to detect and respond to threats swiftly is paramount when dealing with assets critical to deterrence — be they Trident missile submarines, intercontinental ballistic missiles or strategic bombers.”

Beyond the Depot, the department is exploring Scylla’s potential in cold weather and maritime environments. In the coming months, Joint Base Charleston, South Carolina, will host Navy and Marine Corps-led assessments, ensuring that the algorithm meets their service-specific demands.

PSEAG officials said they are especially interested in testing AI’s ability to mitigate an emerging threat: unmanned systems capable of transcending domains by emerging from the sea to operate on land or in the air.

Though it faces challenges in the form of novel threats, conditions and environments, Walter and Hicks said AI is essential to maintaining the United States’ competitive technological edge.

The deputy secretary said the department has worked for more than a decade to be a global leader in the development and use of AI technologies. “By putting our values first and playing to our strengths — the greatest of which is our people — we’ve taken a responsible approach to that will ensure America continues to come out ahead.”

PSEAG’s investment in AI is born from the 2022 National Defense Strategy’s commitment to “driving commercialization … in emerging technologies,” like “artificial intelligence and autonomy,” and the algorithm’s noteworthy performance in Richmond, Kentucky, marks a fundamental milestone on the department’s path toward improved physical security and comprehensive AI adoption.

“By embracing advanced technologies, like Scylla, we are not just enhancing our current security measures,” Walter said, “we are setting the foundation for future innovations that will keep our nation safe.” (Source: U.S. DoD)

 

25 Oct 24. New operation points to increased financial risks from North Korean state-sponsored groups. On 23 October, the cyber security company Kaspersky reported that the North Korean state-sponsored group ‘Lazarus’ exploited a zero-day vulnerability (CVE-2024-4947) in order to target crypto currency users in May. Lazarus reportedly used several social media profiles to trick unknowing users into visiting an actor-controlled fraudulent domain to download a new video game. Notably, the group spent months building its online presence and hired influencers to promote the game, underscoring the sophisticated planning behind (and long-term nature of) this particular campaign. The group then exploited CVE-2024-4947 and an additional vulnerability in the Google Chrome browser so as to obtain full control over victims’ systems and to evade security mechanisms, further underscoring the high sophistication of this campaign. Lazarus likely deployed information-stealing and crypto mining tools onto compromised systems for financial gain. As such, this operation has re-emphasised the heightened financial risks facing global entities, especially as Lazarus expands its victim pool to include both users and organisations. (Source: Sibylline)

 

25 Oct 24.  Cyber Update Key points

  • The North Korean state-sponsored group ‘APT37’ exploited a zero-day vulnerability to target users in South Korea, elevating security and supply chain risks (see Sibylline Cyber Daily Analytical Update – 21 October 2024).
  • The resurgence of the ‘Bumblebee’ malware in new financially motivated operations will increase security risks stemming from cyber criminals (see Sibylline Cyber Daily Analytical Update – 22 October 2024 and our Technical analysis below).
  • An uptick in cloud-based cyber attacks points to heightened security and financial risks for organisations.
  • The adoption of new malware in a long-term malware operation will raise information theft and financial risks from the cyber threat group ‘TA866’
  • New financially motivated operation heightens financial risks to crypto currency users stemming from the North Korean state-sponsored group ‘Lazarus.’

Technical analysis of weekly stories

The Bumblebee malware loader has reportedly resurfaced using a new infection chain; this follows its takedown by European law enforcement in May. The infection starts with phishing emails tricking potential victims into downloading a malicious .ZIP file. This then executes the main Bumblebee payload by fetching a legitimate-looking Windows Software Installer (MSI) file. Bumblebee is stored directly into a system’s memory to avoid the creation of new files, thus evading early detection by security mechanisms. Additionally, the campaign boasts several other new anti-detection techniques including the use of legitimate installer names to conceal malicious files. These techniques underscore the sophistication and continuous development of this malware. Bumblebee is likely being used to deploy additional malware on compromised systems, including information stealers and banking trojans since it has previously been used to facilitate ransomware operations.

The cyber threat group TA866 has used the backdoor malware ‘WarmCookie’ in a long-term cyber campaign since at least 2023. The campaign has targeted multiple sectors including manufacturing, government and financial institutions across Europe and North America for financial profit and cyber espionage. TA866 typically uses malicious advertisements (malvertising) or phishing emails to gain access to targeted systems, subsequently installing first-stage JavaScript loaders to achieve persistence. This then enables the group to download a second-stage loader (‘WasabiSeed’) to deploy additional malware from the actors’ command-and-control (C2) infrastructure while remaining obfuscated. The group often uses several malware variants including ‘Screenshotter’ to capture screenshots, ‘Looper’ and ‘AHK Bot’ to collect keystrokes and credentials, the popular remote access tool ‘Cobalt Strike’ and the information-stealer ‘Rhadamanthys’. Additionally, TA866 has adopted WarmCookie since 2023 to maintain long-term access to compromised systems, deploy additional payloads, manipulate files and remotely execute code, demonstrating the group’s adaptability and development.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network.
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
  • Ensure adequate security monitoring and detection capabilities, particularly for all external-facing services and devices, including personal devices connected to corporate networks or applications.
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.

Our cyber word(s) of the week: Malvertising

(Source: Sibylline)

————————————————————————————————————————————————————————————————————————————————————————————————————————————–

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

—————————————————————————————————————————————————————————————————————————————————————————————————————————————

 

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

October 25, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

———————————————————————————————————————————————————————————————————————————————————————————————————————————————-

24 Oct 24. Hensoldt expects Luftwaffe to increase PEGASUS buy. Hensoldt expects the Luftwaffe to increase the number of signals intelligence (SIGINT) aircraft it intends to buy under the Persistent German Airborne Surveillance System (PEGASUS) programme, following a general deterioration in the global geopolitical picture.

Speaking to Janes and other media, a representative of the prime contractor on the project said that the currently contracted three aircraft will not be enough to fulfil future taskings, and that a follow-on order is anticipated.

“The initial contract is for three aircraft, and we are proud to be in a position to deliver those. If you look at the current geopolitical situation, even though any [one] aircraft can persistently monitor a vast area, there are unfortunately too many hot spots globally. So, we expect an additional rise [in aircraft numbers] to be coming eventually,” Jürgen Halder, vice-president, Airborne SIGINT at Hensoldt, said on 23 October.

In outlining his expectation that the Luftwaffe will acquire additional PEGASUS airframes, Halder cited the aborted Euro Hawk project that preceded it, saying, “Discussions are starting in a very early phase, but it’s apparent that three aircraft are not sufficient, especially if you consider that the Euro Hawk programme had already included much higher numbers of aircraft.” Based on the Northrop Grumman RQ-4B Global Hawk unmanned aerial vehicle (UAV), the RQ-4E Euro Hawk procurement was pegged at five air vehicles at the time of its cancellation due to airspace certification issues in 2013. (Source: Janes)

 

24 Oct 24. AUKUS Partners Complete Successful Tests of Autonomous and Networked Systems in Maritime Experimentation.

In a significant development for maritime security, the United States, Australia, and the United Kingdom (AUKUS) have completed successful tests of several autonomous and networked systems during a three-week maritime experimentation called Autonomous Warrior 24 in Australia. The event was part of the Maritime Big Play (MBP) initiative and ongoing efforts to develop AUKUS Pillar II capabilities, a trilateral collaboration to improve maritime awareness through networked autonomy, decision advantage, and enhanced strike.

The Maritime Big Play is a series of integrated trilateral experiments and exercises that are enhancing capability development, improving interoperability, and increasing the sophistication and scale of autonomous systems in the maritime domain. Australia led the Autonomous Warrior event, the signature MBP event in 2024. Other events associated with Maritime Big Play included the Robotic Experimentation and Prototyping Augmented by Maritime Unmanned Systems (REPMUS); and Technology Readiness Experimentation (T-REX).

Through these experiments and exercises, AUKUS partners are further testing and refining the ability to jointly operate uncrewed maritime systems, share and process maritime data from all three nations, and provide real-time maritime domain awareness to support decision-making.

“Autonomous Warrior/Maritime Big Play creates a unique opportunity for our three countries to work together, which will ultimately improve operational efficiency and allow us to work more cohesively against common threats,” said Heidi Shyu, Under Secretary of Defense for Research and Engineering. “This collaborative approach enables us to reduce acquisition, maintenance, and training cost by creating economies of scale.”

The technologies tested during the October event support operations from deep under water to the edge of space. This included software-defined acoustic modems, multi-model autonomous underwater and surface vessels, and low-cost attritable unmanned surface vehicles. The tests also featured a low-cost gondola, which supports operations in the upper stratosphere with minimum manpower or logistics requirements, and T-200 high-altitude balloons, which provide resilient communications in denied environments from the stratosphere.

A versatile and robust software-defined network architecture called Multi-Domain Uncrewed Secure Integrated Communications (MUSIC) was tested for its ability to enable seamless communication and coordination across diverse unmanned systems and operational environments. The Common Control System (CCS) was also featured in the exercise, built on an open architecture to provide uncrewed vehicles hardware and software that works across several different systems. This effort supports future work to create an AUKUS-wide Common Control System, fusing best elements of the three countries’ existing systems.

“AUKUS partners have long histories of working together on defense and security issues, and have deep, enduring partnerships based on shared values, said Shyu. “By investing in novel and innovative capabilities directly aligned to AUKUS mission priorities, as well as making future advancements in emerging technologies like AI and Quantum, we support a more stable region — one where all nations are empowered to make their own sovereign decisions free from coercion — a world that centers on hope for the opportunity and prosperity of the future.” (Source: U.S. DoD)

 

24 Oct 24. 5G COMPAD showcases several 5G network deployment scenarios in a Global Demonstration in Latvia.

On October 17, 2024, in Riga, Latvia, the European Defence Fund project 5G COMPAD (5G Communications for Peacekeeping and Defence) held its first global demonstration, showcasing various 5G network deployment scenarios at sea, in the air, and on land. The demonstration was organized by 5G COMPAD consortium member LMT and took place at the military base “Daugavgrīva.”

During the demonstration, several innovative 5G network deployment options were presented. These included potential network coverage simulations, 5G drone tests, satellite communication integration, and other 5G applications on ships at sea. The 5G COMPAD demonstration in Latvia’s 5G testing environment allowed for the evaluation of 5G performance under various conditions and the exploration of new potential use cases.

The global demonstration was attended by 5G COMPAD project partners, stakeholders, and representatives from the Ministries of Defense of European Union member states participating in the implementation of the consortium project. Several project partners took part in the organization process alongside LMT, including Ericsson, Leonardo, Thales, Nokia, Bittium, Cafa Tech, Inster, CNIT, Eight Bells, Space Hellas SA and Intracom Defense (IDE). Before the project’s demonstration, from October 14 to 16, preparation works were held in Latvia with the participation of the organizing team.

The 5G COMPAD project was kicked off in December 2022 and will run for 36 months. The project consortium partners are Saab, Ericsson, Rheinmetall, Bittium, Nokia, Thales, Leonardo, Inster, Eight Bells, Intracom Defense (IDE), Cafa Tech, Telenor, Sintef, FFI (NO Gov), LMT, AIT, Synkzone, BHE, and APR Technologies, while the Sub-Contractors are CNIT, Fraunhofer FKIE, CEA and Space Hellas SA.

Within the 5G COMPAD project, world-leading partners from the telecom and the European defence industries join forces to enable recurrent integration of 5G and beyond into multi-dimensional robust defence communication systems to sustain effective and efficient information superiority for European armed forces.

Project: 101103519 — 5G COMPAD — EDF-2021-C4ISR-D-2

 

24 Oct 24. Global: Long-term malware operations raise cyber espionage, financial risks to key sectors. On 23 October, the cyber security company Cisco Talos reported that the cyber threat group ‘TA866’ has been using the backdoor malware ‘WarmCookie’ in a cyber campaign since at least 2023. TA866 typically uses malicious advertisements to gain access to targeted systems, allowing the group to achieve persistence by installing first-stage malware loaders. The actors subsequently deploy several malware variants to collect sensitive information from compromised systems for both financial gain and espionage. Since 2023, TA866 has used WarmCookie to maintain long-term access to infected systems, deploy additional malware, manipulate files and remotely execute code, demonstrating the group’s adaptability and development. TA866 also uses ‘Screenshotter’ to capture screenshots from compromised systems and ‘AHK Bot’ to collect keystrokes and credentials. TA866 has primarily targeted the manufacturing, government and financial sectors across Europe and North America. We assess that this campaign raises information theft and financial risks to these sectors in the medium term. (Source: Sibylline)

 

23 Oct 24. HENSOLDT, Lufthansa Technik Defense and Bombardier Defense Celebrate Successful First Flight of PEGASUS Aircraft.

  • Bombardier’s Global aircraft, modified for the German armed forces’ Persistent German Airborne Surveillance System (PEGASUS) program, takes to the skies at Bombardier’s Wichita Flight Test Center
  • With this new milestone, the first aircraft out of three to integrate the HENSOLDT “Kalætron Integral” signals intelligence (SIGINT) system for airborne surveillance missions is one step closer to entering service
  • The aircraft will remain at Bombardier’s Wichita facility for further flight testing before its upcoming systems integration and aircraft certification, to be completed by Lufthansa Technik Defense in Hamburg, Germany
  • An official celebration of PEGASUS’ first flight was held in Wichita today, bringing together officials from HENSOLDT, Lufthansa Technik Defense and Bombardier Defense. This event marked the beginning of the flight testing phases for the next-generation German program

HENSOLDT, Lufthansa Technik Defense and Bombardier Defense today announced that the PEGASUS aircraft has completed its first flight out of Bombardier’s facility in Wichita, Kansas. Led by HENSOLDT, PEGASUS is an airborne missionized platform that will integrate the Kalætron Integral SIGINT system to perform highly critical signal surveillance missions for the German armed forces. As the aircraft officially enters its next phase and is moving one step closer to the Lufthansa Technik Defense-led systems integration and certification, a celebration was held to mark the PEGASUS aircraft’s first flight. Representatives from HENSOLDT, Lufthansa Technik and Bombardier Defense as well as representatives from the German Armed Forces traveled from Germany, Canada, and across the United States to gather in Wichita and celebrate this pivotal program milestone.

This stage of aircraft testing is conducted by the Bombardier Flight Test Centre (BFTC) team, located in Wichita, where Bombardier’s highly skilled pilots validate key aspects of the program. These successful tests demonstrate the high capability of the Bombardier Global aircraft to complete the German air force’s critical missions. This represents a significant milestone for the first of three modified Global 6000 aircraft destined to be delivered to the German Bundeswehr.

“Germany’s next generation signal intelligence aircraft is flying high,” said Steve Patrick, Vice President, Bombardier Defense. “This successful first flight is the result of the strong collaboration and shared knowledge between HENSOLDT, Lufthansa Technik Defense, Bombardier Defense and our suppliers to get the modified, high-performing Global 6000 aircraft for the Pegasus program in the air. With flight testing regularly underway from Bombardier’s Wichita base, the aircraft continues to gather essential certification data to improve and perfect the platform before it moves to the next stage.”

“Today marks an important milestone for the PEGASUS programme,” said Dietmar Thelen, Head of Spectrum Dominance Division at HENSOLDT. “With the integration of our Kalætron-Integral system, we are delivering key components that are essential for the ‘reconnaissance of tomorrow’. This achievement underscores the excellent cooperation between HENSOLDT, Lufthansa Technik Defense and Bombardier Defense.”

“Seeing the first PEGASUS aircraft taking to the skies bearing the Lufthansa Technik Defense logo fills me with pride and also joyful anticipation, as it brings us one decisive step closer to welcoming this aircraft back at our site,” says Michael von Puttkamer, Vice President Special Aircraft Services at Lufthansa Technik. “I’d like to congratulate and thank the outstanding Bombardier Defense team for their great performance in reaching this important project milestone, and I look forward to the upcoming flight test activities as well as the ongoing cooperation with HENSOLDT in the subsequent integration and certification of their highly sophisticated signals intelligence system.”

In June 2021, HENSOLDT was awarded the contract to supply an airborne system for electronic signals intelligence on board three Bombardier Global jets based on its Kalætron Integral system. Since that award, HENSOLDT, Lufthansa Technik Defense and Bombardier have collaborated closely on a joint design activity. Extensive structural modification work has been performed to prepare the first aircraft at Bombardier Defense’s U.S. base in Wichita, Kansas, which houses an important contingent of the company’s experienced and skilled defense workforce. This is the site of the initial ground and flight test activities.

Upon completion of initial testing, each aircraft will be transferred to Lufthansa Technik Defense’s facilities in Hamburg for further integration work. The company is moreover responsible for the regulatory certification of PEGASUS on the overall aircraft level. So far, Lufthansa Technik has completed its design activities for the integration of the mission system, the additional civil and military avionics systems as well as the aircraft cabin. The production process of interior parts has also already started in order to ensure the components’ readiness for immediate installation when the aircraft arrives in Hamburg. In the meantime, HENSOLDT has adapted the systems architecture to the operational needs of the German Bundeswehr. The corresponding hardware and software developments are currently in progress, various demonstrations have shown the immense potential and capabilities of the upcoming solution.

HENSOLDT is acting as general contractor and bears overall responsibility for the realization of the project. Lufthansa Technik Defense will act as a subcontractor, procuring the modified aircraft from Bombardier and fitting and integrating the reconnaissance system developed by HENSOLDT into the platform. Many small and medium sized enterprises from all over Germany, Canada and the U.S. are involved in the project as part of the supply chain for all companies bringing PEGASUS to the finish line.

 

23 Oct 24. Global: Uptick in cloud-based cyber attacks points to raised security, financial risks for organisations. On 22 October, the security company Sysdig reported that threat actors are increasingly adopting new tactics to conduct cyber attacks against cloud environments. Sysdig highlighted the uptick in the use of open-source tools as well as the exploitation of cloud-based software vulnerabilities to facilitate unauthorised access and credential theft. Notably, the threat group ‘Crystalray’ used the open-source tool ‘SSH-snake’ to steal over 1,500 credentials between July and October, underscoring the threat actors’ ability to incorporate new tools quickly in order to scale up cyber campaigns. Botnets have also played a significant role in cloud-based cyber attacks in 2024; they have allowed threat actors to automate and propagate infections. Additionally, threat actors often target cloud environments within cryptocurrency firms to deploy crypto-miners so as to garner illicit profit, highlighting the financial and security risks facing this industry. We assess this trend will likely continue in the long term as organisations seek to grapple with a broadening attack surface. (Source: Sibylline)

 

22 Oct 24. Hanwha Defense USA and BlueSpace.ai announced their collaboration to bring to market BlueSpace’s advanced autonomous software solutions integrated into current and future HDUSA offerings. BlueSpace.ai leverages next-gen 4D sensing to provide verifiable and explainable AI solutions to provide ADAS and full autonomy solutions for defense and commercial applications, including mining and fleet operations, where the operational environments are challenging and often GPS-denied.

The two technology leaders will work together to bring enhanced capabilities to equip our warfighters with AI-powered solutions for the modern battlefield. The signing ceremony held during the Association of the U.S. Army’s (AUSA) Annual Meeting & Exposition in Washington, D.C. formalizes the strategic collaboration in providing an attritable and scalable AI-powered solution to further enhance lethality, survivability, and agility for the battlefield of tomorrow.

In 2023 BlueSpace.ai was awarded a $1.6 m contract by the Army to enhance the perception sensing for future US Army unmanned ground vehicles. Led by the Army’s Robotic Combat Vehicle (RCV) program, the effort is in support of vehicles for reconnaissance, surveillance, and other high-risk missions.

“In our ongoing work with the Army, we are helping to enhance capabilities enabled by next-gen autonomy software in ground vehicles. Partnering with HDUSA will help accelerate the deployment and adoption of cost-effective and combat-proven autonomous capabilities in the market.” Christine Moon, Co-Founder and President of BlueSpace.ai

“HDUSA is constantly looking to build meaningful partnerships with US companies that bring complementary strengths.  In the area of dual-use software, we’ve found an ideal partner in BlueSpace. Pairing BlueSpace’s robust autonomy solutions with our proven ground vehicle and munitions technologies will make our joint offerings stronger and ultimately help our customers stay ahead of an evolving and increasingly complex threat environment.” Mike Smith, President and CEO Hanwha Defense USA

(Source: PR Newswire)

 

22 Oct 24. BAE Systems (LON:BA) has announced a strategic partnership with Aerospike to develop future data-driven capabilities for the U.S. Army and other Department of Defense (DoD) programs. Aerospike joins BAE Systems’ Mission Advantage™ technology partnership program, which provides mission-critical solutions for defense.

BAE Systems’ collaboration with Aerospike will advance the development of data mesh solutions that would maximize the utility of the Army’s Unified Network, Army Data Platform, and other data-centric mission requirements.

The collaboration with Aerospike will advance the development of data mesh solutions that would maximize the utility of the Army’s Unified Network, Army Data Platform, and other data-centric mission requirements. Aerospike’s real-time database, already proven in large-scale commercial applications, will be a key enabler for these data-driven objectives, offering high-performance data processing with the lowest latency.

“Aerospike is foundational to our data-centric solutions for the U.S. Army and DoD, as our customers push towards managing massive amounts of disparate data while leveraging advanced AI tools,” said Daniel Perkins, director of Strategy & Technology Partnerships for BAE Systems’ Intelligence & Security sector. “This strategic partnership will help us deliver real-time, mission-critical data at scale and help ensure technological advantage on the battlefield.”

The integration of Aerospike’s massively scalable, millisecond-latency database solutions will also support the transformation of legacy systems, enhancing warfighters’ ability to access precise, actionable data in real time. These solutions will provide the Army and DoD with an edge in decision-making during critical missions, improving operational efficiency and response times.

“Aerospike’s multi-model database offers the lowest-latency, highest-throughput system to enable accurate, real-time decisioning even in contested environments,” said Cuong Nguyen, vice president, Public Sector for Aerospike. “As a vital component of the UNO technology stack, we’re proud to partner with BAE Systems to help them optimize and demonstrate the effectiveness of their data solutions.”  (Source: PR Newswire)

 

23 Oct 24. Silvus Technologies Unveils StreamCaster LITE 5200 External Inbox. Silvus Technologies, Inc., a global supplier of advanced wireless networking communication systems, has announced its next-generation MANET radio OEM module: the StreamCaster LITE 5200 (SL5200).

Designed for leading-edge unmanned systems, the SL5200 unifies C2, sensor, and telemetry data with communications relay capabilities in an ultra-low SWaP (52g), easy-to-integrate MANET radio module. With up to 2 Watts of native output power (4W effective power, thanks to TX Eigen-Beamforming) and up to 100 Mbps data rate, the SL5200 delivers class-leading power, high-bandwidth throughput, and tactical mobility.

Compact and versatile, with multiple I/O interface options, the SL5200 is designed for seamless integration into a wide range of tactical unmanned systems, and other Size, Weight and Power (SWaP) constrained embedded applications. Systems operators can now experience Group 2 UAV level radio performance in a compact form factor engineered for Group 1 sized platforms.

At the heart of the SL5200 is Silvus’ proprietary MN-MIMO waveform, capable of linking hundreds of nodes in any operational environment. With the SL5200, operators can connect multiple UAVs, UGVs, USVs, sensors, personnel, and manned/unmanned platforms, to actualize a common operating picture through one massively scalable mesh network. The SL5200 is seamlessly compatible with 4000-series StreamCaster MANET radios, ensuring interoperability across a diverse range of applications.

“Redefining C2 and comms mesh networking, the SL5200 delivers on Silvus’ promise of class-leading range, data throughput, scalability, and EW resilience, in an ultra-low SWaP OEM module providing robust network connectivity for multi-domain operations at the tactical edge,” said Jimi Henderson, Vice President of Sales for Silvus Technologies. “To fast-track enhanced capabilities to end-users, the SL5200 is designed for easy integration into a wide range of unmanned sub-systems, reducing development costs and speeding time to market for today’s leading-edge manufacturers.”

In addition to AES256 and FIPS 140-3 encryption for secure operations, the SL5200 provides available access to Silvus’ Spectrum Dominance expansive suite of LPI/LPD and Anti-Jamming resiliency capabilities. Silvus is the only tactical MANET radio provider that delivers Spectrum Dominance secure and protected communications in complex, congested and contested environments, without compromising performance.

About Silvus Technologies, Inc.

As the world’s leading provider of advanced MANET and MIMO communications systems, Silvus Technologies is reshaping mesh network technology for mission-critical applications – on the ground, in the air, and at sea. Its battle proven StreamCaster family of MANET radios and proprietary MN-MIMO waveform provides the vital communications link for defense, law enforcement, and public safety agencies around the world, and in the toughest operational environments. Developed by a team of top PhD scientists and design engineers, Silvus Technologies continues to innovate communications technology for the tactical edge with unmatched range, data throughput, EW resiliency, and scalability. Silvus Technologies is privately held with world headquarters located in Los Angeles, CA. (Source: UAS VISION)

 

21 Oct 24. South Korea: Exploitation of zero-day vulnerability elevates security, supply chain risks. On 19 October, international news outlets reported that the North Korean state-sponsored group ‘APT37’ exploited a zero-day vulnerability (CVE-2024-38178) to target users in South Korea before being patched. The vulnerability affects any application using an outdated version of the Internet Explorer WebView feature to display advertisements. APT37 infiltrated a South Korean online advertising agency to exploit CVE-2024-38178 by injecting malicious code into advert content scripts. This enabled the group to automatically launch malicious content, resulting in a zero-click supply chain attack. The group then displayed malicious pop-up advertisements, prompting users to unknowingly download malware onto compromised systems. This provided APT37 with the ability to remotely execute code, likely to conduct malicious activities including exfiltrating sensitive data. This incident underscores security and supply chain risks stemming from the exploitation of zero-day vulnerabilities by North Korean state-sponsored groups. We assess that this will sustain elevated risks to South Korean entities in the long term. (Source: Sibylline)

 

18 Oct 24. Cyber Update Key points.

  • Disruptive attacks against Iranian government branches and critical national infrastructure (CNI) will heighten cyber security risks amid regional escalation.
  • A new variant of the ‘Astaroth’ banking trojan is targeting users in Brazil, increasing financial risks from the cyber criminal group ‘Water Makara.’
  • Evolving tactics will raise security and financial risks from state-sponsored groups affiliated with China, Iran and Russia.
  • The North Korean state-sponsored group ‘Lazarus’ is targeting ATMs and point-of-sale (PoS) systems in financially motivated operations, elevating financial risks.

Technical analysis of weekly stories

The cyber criminal group Water Makara is targeting users in Brazil with a new version of the Astaroth banking trojan. The group primarily targets users in the manufacturing, retail, government and healthcare sectors, The group gains access to targeted systems via highly-tailored spear phishing emails impersonating legitimate financial institutions to trick potential victims into downloading a malicious .ZIP file. The .ZIP file contains an additional .LNK file and obfuscated JavaScript. These are disguised as official financial documents to appear legitimate, prompting victims to open the documents and execute the main payload. This then establishes communication with the actors’ command-and-control (C2) infrastructure, achieving persistence on compromised systems. Additionally, the embedded JavaScript contains a malicious URL generated via domain generation algorithms (DGA); this is likely used by Water Makara to execute additional malicious activities. Astaroth allows the group to steal banking credentials from victims, likely to exploit them directly or sell them on the dark web to garner illicit profit. The new variant contains novel obfuscation techniques, underscoring Water Makara’s continuous malware development as well as the sophistication of its evasion tactics.

The North Korean state-sponsored group Lazarus is using a newly discovered Linux variant of the ‘FASTCash’ malware in a likely ongoing financially motivated operation. The group is infiltrating Linux-based payment systems to garner illicit profit by interjecting communications between ATMs, PoS systems and a bank’s central system. We assess that Lazarus likely used social engineering attacks to obtain access to targeted payment switches. Upon obtaining initial access, Lazarus deploys the FASTCash payload, re-routing and manipulating transaction requests using the ISO8583 communication protocol. The malware specifically targets messages concerning declined transactions, converting them into approved transactions and charging them an additional amount between TRY 12,000 and 30,000 (USD 350 and USD 876). The manipulated message, containing the necessary approval codes, is then sent back to the bank for approval, enabling money mules acting on behalf of Lazarus to collect cash from an ATM. This FASTCash variant underscores the continuous development of malware by North Korean state-sponsored groups as they continue their efforts to garner illicit profit to bolster North Korea’s economy and weapons programmes.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network.
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
  • Ensure adequate security monitoring and detection capabilities, particularly for all external-facing services and devices, including personal devices connected to corporate networks or applications.
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.

Our cyber word(s) of the week: Domain generation algorithm (DGA)

(Source: Sibylline)

———————————————————————————————————————————————————————————————————————————————————————————————————————————-

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

———————————————————————————————————————————————————————————————————————————————————————————————————————————–

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

October 18, 2024 by

 

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

———————————————————————————————————————————————————————————————————————————————————————————————————————————–

16 Oct 24. Thales Radios Successfully Tested by the German Armed Forces to Be Deployed Within the NATO Enhanced Forward Presence

  • The German Armed Forces conducted operational tests with PR4G and SYNAPS-H Thales radios to demonstrate their suitability for the needs of the multinational Battalion Group deployed by NATO.
  • Within one year, Thales has successfully delivered to the German Armed Forces radio equipment for the NATO enhanced Forward Presence (eFP).
  • These 4-week operational tests demonstrated that Thales radios are interoperable and secure.

Thales radios for use in NATO enhanced Forward Presence were tested in an intensive four-week operational trial under the direction of the Army Development Office. These tests were conducted with the participation of the Army Development Office, the Federal Office of Bundeswehr Equipment, Information Technology and In-Service Support (BAAINBw), the German Army’s “Test and Trial” teams and Dutch and French Armed Forces.

The particular focus of the procurement was to provide modern, encrypted, electronic counter countermeasure (ECCM)-capable command and control radios for the multinational deployment of the enhanced Forward Presence, which can transmit voice in parallel with data and their own position.

“During the four-week operational test, Thales PR4G and SYNAPS-H radios met the requirements so effectively that the system is deemed suitable for introduction into the German Armed Forces.. We are very pleased that there are no more obstacles for the operational use of the radios in Lithuania, where the deployed forces will have protected, modern radios.” added Christoph Ruffner, CEO and Country Director, Thales Deutschland.

Although the soldiers had not received any training, only a short briefing, it was possible to establish operational readiness in under an hour..The radios also impressed with a stable radio network and in the range tests.

The purpose of NATO enhanced Forward Presence is to strengthen its defensive and deterrent posture on Europe’s eastern flank. NATO battlegroups are deployed to the Baltic states of Estonia, Latvia and Lithuania as well as to Poland and led by the United Kingdom, Canada, Germany and the United States respectively. (Source: ASD Network)

 

17 Oct 24. Cyber Update Key points.

  • The Chinese state-sponsored group ‘Salt Typhoon’ infiltrated several US internet service providers (ISPs) in a cyber espionage campaign, elevating the security risks for government and critical infrastructure (see Sibylline Cyber Daily Analytical Update – 7 October 2024).
  • The advanced persistent threat (APT) group ‘Awaken Likho’ used new software to target Russian government organisations, elevating the security risks facing related entities (see Sibylline Cyber Daily Analytical Update – 8 October 2024 and our Technical analysis below).
  • A cyber attack on air-gapped systems by the APT group ‘GoldenJackal’ will increase the cyber espionage risks facing European government bodies (see Sibylline Cyber Daily Analytical Update – 9 October 2024 and our Technical analysis below).
  • Increased exploitation of artificial intelligence (AI) chatbots in financially motivated operations will raise the financial and supply chain risks stemming from cyber criminals (see Sibylline Cyber Daily Analytical Update – 10 October 2024).
  • A new ‘Lynx’ ransomware-as-a-service (RaaS) operation targeting Windows users points to the raised security and financial risks stemming from cyber criminals (see Sibylline Cyber Daily Analytical Update – 11 October 2024).

Technical analysis of weekly stories

The APT group Awaken Likho used new software to target Russian government organisations in a campaign between June and August. Unlike previous operations, this campaign used the open-source remote device management tool ‘MeshAgent’ to maintain access to compromised systems, marking a shift in Awaken Likho’s tactics as it continues to target Russian entities amid the war in Ukraine. The campaign likely started with phishing emails to trick potential victims into clicking on malicious attachments. The attachments then loaded self-extracting archives (SFX) onto compromised systems. They contained five malicious files masked with legitimate file names to evade detection. Notably, several files did not contain a payload and were likely added to the archives to mislead victims. Subsequently, MeshAgent is executed via a multi-stage process which establishes communication with the actors’ command-and-control (C2) infrastructure. The payload’s code was heavily obfuscated with additional empty text boxes, further underscoring the sophistication of the actors’ detection-evasion techniques. Additionally, we assess the group will likely exploit access to compromised systems to collect sensitive information and to deploy more payloads.

The APT group GoldenJackal compromised air-gapped systems within an unnamed European government organisation in a cyber espionage campaign between May 2022 and May 2024. The group also targeted air-gapped systems within an unspecified South Asian embassy in Belarus in a separate campaign in 2019. GoldenJackal used a highly sophisticated custom toolset to bypass air-gap isolation mechanisms and to exfiltrate sensitive information from targeted systems. The group likely gained access to targeted systems via malicious documents and/or remote access trojans (RATs) to deploy a new custom malware (‘GoldenDealer’). The malicious payload contained a worm component that enabled the file to copy itself onto any USB drives inserted into infected systems. When inserted into an air-gapped system by unknowing users, compromised USB drives display a folder icon containing the malicious payload. This tricks users into clicking on the file, thereby propagating the infection. GoldenDealer then collected information from compromised air-gapped systems, relaying it back to the actors’ C2 infrastructure after re-inserting infected drives into internet-connected devices. The malware exfiltrated data and communicated with the C2 server via several custom tools including a file collector (‘GoldenRobo’) and a new backdoor (‘GoldenHowl’), highlighting GoldenJackal’s ability to bypass security mechanisms. Notably, the group employed a multi-layered approach using several compromised devices to perform different tasks based on collected system data, further underscoring GoldenJackal’s sophistication. We assess that the volume of new custom tools showcased in this operation points to the group’s continuous development of malware.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network.
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
  • Ensure adequate security monitoring and detection capabilities, particularly for all external-facing services and devices, including personal devices connected to corporate networks or applications.
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.

Our cyber word(s) of the week: Air-gapped system

(Source: Sibylline)

 

17 Oct 24. Iran: Disruptive attacks indicate heightened cyber security risks to government, CNI. On 12 October, international news outlets reported that several government branches and nuclear facilities in Iran were targeted in a series of disruptive cyber attacks. The attacks also reportedly disrupted Iranian critical national infrastructure (CNI) including fuel distribution, municipal networks and transportation hubs. The attacks also reportedly exfiltrated sensitive data from affected systems. There is a realistic possibility that these attacks are linked to the Israeli government as Israel vowed to deliver a strong response to Iran following the launch of ballistic missiles against Israel on 1 October. As regional tensions will almost certainly persist in the short term, we assess that additional disruptive cyber operations against Iranian CNI and organisations affiliated with Iran-backed groups in the region remain likely in the coming weeks. Additionally, there is a realistic possibility that Iran will also use cyber attacks to retaliate against Israel; however, we assess that these operations are unlikely to escalate tensions. (Source: Sibylline)

 

17 Oct 24.  Global: Malware variant will sustain elevated risks from North Korean state-sponsored groups. On 14 October, international news outlets reported that the North Korean state-sponsored group ‘Lazarus’ is using a new version of the ‘FASTCash’ malware to target global Linux payment systems. The group likely used social engineering attacks to access targeted payment switches and deploy the FASTCash payload. This enabled Lazarus to interject transaction requests between ATMs, point-of-sale (PoS) systems and financial institutions by exploiting native communication protocols. The group manipulated declined transactions to obtain approvals from banks, allowing money mules acting on their behalf to collect cash from an ATM. We assess that this newly discovered Linux version of FASTCash underscores Lazarus’ continuous development of more sophisticated malware to garner illicit profit. The group routinely targets financial institutions in financially motivated operations to bolster North Korea’s economy as well as its weapons and missiles programme amid international sanctions. We assess that this will sustain elevated financial risks to this sector in the long term. (Source: Sibylline)

 

16 Oct24. BAE Systems and Kongsberg sign teaming agreement for new platform situational awareness tool.

The Integrated Combat Solution tool will give Warfighters the situational awareness they need for any mission, as well as options to respond to potential threat

BAE Systems has entered into a teaming agreement with Kongsberg Defence and Aerospace to bring Integrated Combat Solution (ICS) to the U.S. defense market. The transformational battlefield situational awareness tool for combat vehicles will provide the Warfighter with the capability to link and share video streams, metadata, target information, slew-to-cue commands, and much more, reducing the typical threat response speed from minutes to seconds. Together, with Kongsberg developing the ICS tool and BAE Systems integrating it onto combat vehicles, the companies will support technology upgrades through the product lifecycles.

“The ability for troops to rapidly pass targeting information across the battlefield to other platforms and engage a target remotely is critical to their mission,” Andy Corea, vice president and general manager of BAE Systems’ Combat Mission Systems business, said. “The combined talents of Kongsberg’s innovation and expertise in remote weapon systems and our lead systems integration capability provides the Warfighter the opportunity to obtain fully integrated enhanced combat capability – helping them stay aware and unmatched in battle.”

ICS is a tool that can be used across the U.S. Marine or U.S. Army’s fleet of vehicles as a critical enabler of their mission. Built with an open-systems approach, ICS can be integrated on any battlefield platform equipped with a weapon system and on-board sensors – keeping troops aware and safer in the fight. ICS will give Warfighters more options to respond to potential threats, matching the rapid pace of warfare in the future. ICS uses an integrated network to link the sensors on different battlefield assets together, allowing command and control of weapon stations, turrets, jammers and other effectors from a single screen inside the vehicle.

“Together we will deliver ICS as a core enabler of modern warfare, providing all-domain visibility, command and control,” said Kjetil Reiten Myhra, executive vice president defence systems, Kongsberg Defence and Aerospace. “This force multiplier streamlines complicated threat responses, networking mobility platforms and other assets for increased combat capability.”

The ICS capability has already been demonstrated on the Amphibious Combat Vehicle (ACV) and Armored Multi-Purpose vehicle platforms, and the combined team of BAE Systems and Kongsberg looks forward to the opportunity to provide it across the ground combat forces. The ICS system is also featured at the BAE Systems booth (#6041) at AUSA this week on the Armored Multi-Purpose Vehicle (AMPV) platform, further demonstrating the team’s ability to integrate it on different combat vehicles.

 

14 Oct 24. Leonardo unveils new digital technology to revolutionise how armed forces suppress and defeat modern enemy air defences

  • The new BriteStorm payload can fly ahead of friendly forces on-board Uncrewed Aerial Vehicles (UAVs) and launched effects, deceiving enemy defences with sophisticated digital jamming and deception techniques.
  • Successful flights with the UK Royal Air Force’s Rapid Capabilities Office (RAF RCO), proving the capability, have already taken place.
  • Leonardo launched the product at the Association of the U.S. Army (AUSA)’s Annual Meeting and Exposition in Washington D.C.

Leonardo has launched a new product, called ‘BriteStorm’, that will allow armed forces to operate deep within enemy territory, even when that territory is guarded by modern Integrated Air Defence Systems (IADS).

BriteStorm is able to perform ‘stand-in jamming’: an airborne electronic warfare capability, deployed ahead of the main force, to deliver high-powered interference against a wide spectrum of threats. By doing so, BriteStorm degrades the enemy’s IADS, supressing its ability to detect and lock onto other platforms, protecting friendly forces and enabling their mission.

The BriteStorm payload is designed to be installed on the widest possible range of UAVs and launched effects. It will equip each platform with an advanced array of digital deception techniques, deployable at long range.

The UK Royal Air Force’s Rapid Capabilities Office (RCO) is working with Leonardo in relation to the capability and has purchased payloads to conduct trials. Successful flights with the RCO proving the capability have already taken place.

Developed at Leonardo’s electronic warfare research and manufacturing base in Luton, UK, BriteStorm builds on the Digital Radio Frequency Memory (DRFM) technology underpinning Leonardo’s in-service BriteCloud countermeasure, the only DRFM-based expendable on the market to have been demonstrated effective in live tests. In contrast to BriteCloud, which is designed to disrupt incoming missiles’ radar guidance systems, BriteStorm has been engineered to confuse and suppress ground-based surveillance radars, preventing the enemy from tracking and then engaging friendly forces.

BriteStorm works by using Leonardo’s mission-tested DRFM technology to detect and evaluate the electronic warfare threat environment and then choose the most relevant countermeasure technique. Depending on the situation, BriteStorm’s effects can range from barraging the enemy system with electronic noise to more sophisticated techniques such as creating dozens of realistic ‘ghost’ fighter jet signatures, confusing and misdirecting the enemy response.

BriteStorm is small, lightweight and platform-agnostic. A standard BriteStorm fit incorporates a platform-specific antenna, transmit-receive modules and Leonardo’s Miniature Technique Generator. It is simple to integrate, making BriteStorm an accessible route to establishing a powerful, attritable, stand-in jamming capability. The BriteStorm development team has drawn on Leonardo’s company-wide programme of digital transformation to create a powerful and sophisticated product, whilst ensuring the payload can be considered attritable.

In addition to the UK Ministry of Defence, Leonardo views the U.S. Department of Defense as a key potential customer for BriteStorm, with the payload able to deliver a capability advantage to operators in contested electronic warfare environments, while being rapidly reprogrammable to match the pace of the threat. BriteStorm has been designed to be readily exportable, with demonstration units already in the USA. Leonardo is expecting to see further interest in BriteStorm from customers in Europe, the Middle East and Asia Pacific.

 

11 Oct 24. Cybersecurity Maturity Model Certification Program Final Rule Published. Today, the final program rule for the Cybersecurity Maturity Model Certification (CMMC) Program was released for public inspection on federalregister.gov and is anticipated to be published in the Federal Register, Tuesday, October 15.

The purpose of CMMC is to verify that defense contractors are compliant with existing protections for federal contract information (FCI) and controlled unclassified information (CUI) and are protecting that information at a level commensurate with the risk from cybersecurity threats, including advanced persistent threats.

This rule streamlines and simplifies the process for small-and medium-sized businesses by reducing the number of assessment levels from the five in the original program to three under the new program.

This final rule aligns the program with the cybersecurity requirements described in Federal Acquisition Regulation part 52.204-21 and National Institute of Standards and Technology (NIST) Special Publications (SP) 800-171 Rev 2 and -172.  It also clearly identifies the 24 NIST SP 800-172 requirements mandated for CMMC Level 3 certification.

With the publication of this updated 32 CFR rule, DoD will allow businesses to self-assess their compliance when appropriate. Basic protection of FCI will require self-assessment at CMMC Level 1.General protection of CUI will require either third-party assessment or self-assessment at CMMC Level 2.A higher level of protection against risk from advanced persistent threats will be required for some CUI. This enhanced protection will require a Defense Industrial Base Cybersecurity Assessment Center led assessment at CMMC Level 3.

CMMC provides the tools to hold accountable entities or individuals that put U.S. information or systems at risk by knowingly misrepresenting their cybersecurity practices or protocols, or knowingly violating obligations to monitor and report cybersecurity incidents and breaches.  The CMMC Program implements an annual affirmation requirement that is a key element for monitoring and enforcing accountability of a company’s cybersecurity status.

With this revised CMMC Program, the Department also introduces Plans of Action and Milestones (POA&Ms).  POA&Ms will be granted for specific requirements as outlined in the rule to allow a business to obtain conditional certification for 180 days while working to meet the NIST standards.

The benefits of CMMC include:

  • Safeguarding sensitive information to enable and protect the warfighter
  • Enforcing DIB cybersecurity standards to meet evolving threats
  • Ensuring accountability while minimizing barriers to compliance with DoD requirements
  • Perpetuating a collaborative culture of cybersecurity and cyber resilience
  • Maintaining public trust through high professional and ethical standards

The Department understands the significant time and resources required for industry to comply with DoD’s cybersecurity requirements for safeguarding CUI and is intent upon implementing CMMC requirements to assess the degree to which they have done so.  The Department would like to thank all the businesses and industry associations that provided input during the public comment period.  Without this collaboration, it would not have been possible to meet our goals of improving security of critical information and increasing compliance with cybersecurity requirements while simultaneously making it easier for small and medium-sized businesses to meet their contractual obligations.

Businesses in the defense industrial base should take action to gauge their compliance with existing security requirements and preparedness to comply with CMMC assessments.  Members of the defense industrial base may use cloud service offerings to meet the cybersecurity requirements that must be assessed as part of the CMMC requirement.  The DoD CIO DIB Cybersecurity Program has compiled a list of current resources available at dibnet.dod.mil under DoD DIB Cybersecurity-as-a-Service (CSaaS) Services and Support.

The DoD’s follow-on Defense Federal Acquisition Regulation Supplement (DFARS) rule change to contractually implement the CMMC Program will be published in early to mid-2025.  Once that rule is effective, DoD will include CMMC requirements in solicitations and contracts.  Contractors who process, store, or transmit FCI or CUI must achieve the appropriate level of CMMC as a condition of contract award.  More information on the timing of the proposed DFARS rule can be found at https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202404&RIN=0750-AK81.

More information on the CMMC Program can be found at https://dodcio.defense.gov/CMMC/.(Source: U.S. DoD)

—————————————————————————————————————————————————————————————————————————————————————————————————————————–

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

————————————————————————————————————————————————————————————————————————————————————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

October 11, 2024 by

 

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

——————————————————————————————————————————————————————————————————————————————————————————————————————————————–

09 Oct 24. Leonardo to Deliver Secure Communication Network Technology Enhancement to UAE. Leonardo has strengthened its partnership with the United Arab Emirates (UAE) in the field of cyber security by signing a contract to deliver a comprehensive technological upgrade of the UAE Defence’s secure communications network. The programme aim is to enhance secure communications and information systems for the UAE’s national security, providing cutting-edge protections for strategic applications. The upgrades will significantly bolster network and IT infrastructure security, improving resilience against cyber and physical threats while safeguarding data and services’ availability, authenticity, integrity, and confidentiality. Leonardo will lead the design and modernization of the secure communications network using state-of-the-art technologies, resulting in an integrated, interoperable system capable of seamless operations and continuous upgrades. A key focus of the project will be the development of advanced encryption techniques to ensure the highest security standards for communications and information handling. Initially launched in 2017, the UAE’s initiative to establish national secure communication capabilities has underscored the long-standing relationship between Leonardo and the UAE Armed Forces, further strengthening Leonardo’s role as a trusted partner.  With a robust presence in the UAE for over 50 years, Leonardo has built one of its largest export markets in the region, providing a wide range of products, services, and collaborations across both civil and defense sectors.  Leonardo’s mission-critical solutions are currently deployed in over 50 countries worldwide, supporting critical infrastructures, homeland security, law enforcement, and emergency response. As cyber security becomes increasingly vital across all sectors, the need for robust protections will extend beyond digital and physical infrastructure to encompass systems, platforms, communications, and mobility from their earliest design phases. Data gathering, analysis, utilization, and protection are key elements in these emerging technologies. With advanced capabilities in high-performance computing and trustworthy artificial intelligence, Leonardo is uniquely positioned to support governments and institutional agencies in their digital transformation efforts, ensuring enhanced security and improved service quality for communities. (Source: ASD Network)

 

10 Oct 24. The International Institute for Strategic Studies (IISS) has launched the IISS Cyber Power Matrix, which demonstrates how states project power in cyberspace to achieve strategic objectives and exert influence globally. The IISS Cyber Power Matrix collates examples of state cyber power from 2001 onwards in the physical, logical and virtual layers of cyberspace.   Launching initially in beta format ahead of a full launch in 2025, the IISS Cyber Power Matrix provides the means for analysis of how governments and government-linked actors have shaped cyberspace over the past two decades and accompanying analysis provides insight into what this could mean for global geopolitical stability. This iteration collates publicly available information on 1) state-linked operations in cyberspace, 2) state-linked disinformation operations, 3) ownership and supply of submarine cables as examples of state power and 4) the physical disruption of submarine cables to demonstrate cyberspace’s vulnerability. The team behind the project is led by Julia Voo, Senior Research Fellow for the IISS Cyber Power and Future Conflict programme. Previously, information on state influence at the physical, logical and virtual layers of cyberspace was scattered and disjointed. Through this platform, the IISS seeks to encourage scholarship and debate on the aspects of cyber power as well as the changing nature of competition and conflict. Future reports and analysis will be published in the upcoming months, while current datasets are updated and new datasets added.

Julia Voo said, ‘The IISS Cyber Power Matrix offers a unique insight into how states project power and influence in physical and virtual cyberspace and how the actors, intent and targets evolve over time. After several months of preparation, we are looking forward to continuing to build and refine this project’.

Project lead

Julia Voo is the Senior Research Fellow for the Cyber Power and Future Conflict (CPFC) programme. Prior to joining the IISS, Julia was the Director for Cybersecurity and Technology Policy at HP Inc. At Harvard Belfer, Julia was the Research Director for China Cyber where she led the team behind the National Cyber Power Index. Julia is a graduate of Harvard’s Kennedy School of Government.

Research team

Virpratap Vikram Singh is the Research Fellow for the CPFC programme. His research focuses on escalation in cyberspace, emerging threats across cyberspace, and disruptive technologies. Prior to joining the IISS, he was a research and program coordinator at Columbia University’s School of International and Public Affairs. Virpratap received his Masters in International Affairs from Columbia University in the City of New York.

Priscilla Tomaz was the inaugural intern for the CPFC programme. Her research interests include the impact of technology on civilians, technological innovation, and the changing nature of warfare. Prior to joining the IISS, she interned with the International Development Team at the UK Office for National Statistics and the UK Department for Transport. Priscilla is a recent graduate from the University of Oxford, where she received an MSc in Refugee and Forced Migration Studies.

Also part of the research team were Natallia Khaniejo, Margaret Lin, Jasim Murad and Marcus Willett.

The IISS Cyber Power Matrix has been developed as part of the Institute’s new commercial solutions team, IISS Six Analytic. IISS Six Analytic’s mission is to empower its clients to achieve future security and success with world-leading expertise and refined data insights.

 

10 Oct 24. Global: Exploitation of AI chatbots raises financial, supply chain risks from cyber criminals. On 9 October, the cyber security company Resecurity reported that cyber criminals are increasingly exploiting artificial intelligence (AI) chatbots to conduct financially motivated operations. Threat actors compromised an AI-powered call centre solution earlier in October, obtaining unauthorised access to over 10 m conversations between customers and AI agents. This enabled the threat actors to hijack customer sessions using stolen information, likely to trick victims into disclosing payment information and verifying fraudulent transactions. The breach also exposed customers’ personally identifiable information (PII); we assess that threat actors will likely exploit this data in follow-on social engineering attacks in the short-to-medium term. AI chatbots are often used across several sectors (including fintech, commerce and government) to manage large volumes of customer queries, highlighting the supply chain risks from third-party compromises. As cyber criminals continue incorporating AI into financially motivated operations, security and financial risks to individuals will likely intensify. (Source: Sibylline)

 

10 Oct 24. More Trees for the Little Forest. RP-377A jamming units designed for use by dismounted troops. These can either be used individually, or networked and deployed remotely to provide jamming coverage over a large area.

In late September, an upgraded version of the RP-377 Lesochek series of electronic attack systems was exhibited at the ADEX international defence exhibition held in Azerbaijan.

Lesochek, meaning ‘little forest’ in Russian, is extensively used by Russian land forces, and has been deployed to Ukraine to support the latter’s ongoing occupation. The upgrade expands the system’s capabilities to attack Uninhabited Aerial Vehicles (UAVs). This modernisation is almost certainly the result of combat experience gained by Russian forces in the Ukrainian theatre.

According to reports, the modifications visited on Lesochek allow it to engage Global Navigation Satellite System (GNSS) Position, Navigation and Timing (PNT) signals. These signals routinely use a waveband of 1.1 gigahertz/GHz to 1.6GHz. Frequencies of 2.4GHz and 5.8GHz are used for civilian pilot-aircraft UAV radio control links. However, the Ukraine war has seen both sides using an increasingly wide waveband of 30 megahertz/MHz to six gigahertz for UAV control. Both Ukraine and Russia regularly change their UAV control frequencies in a bid to outflank channel jamming. While not explicitly mentioned, it is possible that the waveband covered by Lesochek has now been expanded upwards from 400MHz to circa six gigahertz.

It is known that the RP-377 series includes at least three distinct configurations: One is designed to equip vehicles and for static installation, designated the RP-377UVM1L/VM. The difference between these two systems remains unclear. It appears that the RP-377UVM1L variant equips relatively light wheeled armoured vehicles like the BTR-60/82 series. The RP-377VM appears to furnish heavier armoured vehicles including tracked platforms. The RP-377A variant is used by dismounted troops. Russian reports state that the Lesochek version exhibited at ADEX was the RP-377VM1. Does this imply that it is only the RP-377VM variant that has received the modifications?

Capabilities

The RP-377 series commenced delivery to Russian land forces in 2013 with circa 1,500 systems supplied by 2015. Armada has learned that the original RP-377 design covers six wavebands: 20 megahertz/MHz to 30MHz, 30MHz to 50MHz, 50MHz to 80MHz, 80MHz to 120MHz, 120MHz to 220MHz and 220MHz to 400MHz. Lesochek was conceived as a Counter-Improvised Explosive Device (CIED) jammer to equip individual vehicles and dismounted troops. Official Russian Army documents seen by Armada state that the baseline version of the RP-377A could only perform barrage noise jamming. What this would mean in practice is that the system continually sweeps through each waveband. Any hostile signal inhabiting these wavebands will then be jammed as the sweeping occurs. One disadvantage regarding barrage tactics is that the jammer transmits proportionally less power than when performing spot jamming. Spot jamming sees electronic attack target a specific frequency. An analogy would be a garden hose which distributes a stronger jet of water when focused on a particular spot, compared to when spraying across a wider area. The official documents say the RP-377 generates between three and five watts of jamming power. Batteries equipping the RP-377A provide sufficient power for 24 hours’ continuous electronic attack.

The RP-377A can be deployed and operated remotely using a radio link giving up to ten kilometres (6.2 miles) of range. When used in this remote-controlled configuration, Lesochek provides six minutes’ continuous jamming time before automatically deactivating. The RP-377A can be programmed to activate when it detects specific signals. Likewise, the system can be programmed with taboo frequencies, such as those used by friendly forces or civilians. When being controlled directly, the RP-377A provides continuous jamming for a maximum of 30 minutes before switching off. The RP-377 architecture includes six jamming transmitters, an antenna for remote control, a receiving antenna to detect threats, and the system’s processor, control unit and amplifier.

Concept of operations

As Armada has chronicled in the past, each of the Russian Army’s principal unit of tactical manoeuvre, typically its motorised rifle/tank divisions/brigades has an organic EW (Electronic Warfare) company. The company includes three EW jamming platoons. One of the platoons comprises two EW jamming squads with dismounted EW capabilities. One squad targets hostile radio communications, the other remote-controlled IEDs and radio-activated weapons. Each squad will typically each have around 15 RP-377As.

The squads sometime appear to be ‘fragged’ to support individual manoeuvre elements in the formation at the squad/platoon level. The logic appears to be to provide EW support to these units during manoeuvre. Likewise, vehicles are thought to be outfitted with the RP-377UVM1L/VMs to provide platform and small group protection. When attacking hostile communications, the Russian documents state that the RP-377A can target amplitude and frequency modulated signal along with signal sideband modulated transmissions. Alternatively, EW squads can be deployed holistically for jamming support in specific areas during reconnaissance or special forces missions.

Alongside supporting manoeuvre RP-377As can be used for static defence. Several units can be placed remotely across a wide area providing a jamming coverage that the red force will need to manoeuvre through. The latter tactic is also useful for providing an electromagnetic cordon sanitaire. Russian documents say that between two and three RP-377As are sufficient to provide jamming across a one square kilometre (0.38 square mile) area. The documents continue that units should have a minimum spacing of no less than 200 metres/m (656 feet/ft) to be effective. When jammers are deployed remotely, they must not be emplaced more than 24 hours before they are needed. This is to reduce the chances of concealed jammers being discovered by red forces. Russian Army doctrine says that Lesochek must be a maximum of 600m (1,968ft) range from the target to be effective. When operating in undulating terrain, RP-377As should be on a hilltop, or a hill side with a line-of-sight to the target.

It remains to be seen how effective these recent modifications to the Lesochek architecture will be in theatre. The upgrades appear to be relatively new, and their impact may be yet to be felt in Ukraine. Moreover, it is unclear whether the modifications can be retrofitted onto legacy systems. (Source: Armada)

 

10 Oct 24. Sentinel Below the Waves. Thales’ Sentinel-U radar electronic support measure is equipping the French Navy’s ‘Suffren’ class nuclear-powered attack submarines.

Thales has delivered the first of the company’s Sentinel-U radar electronic support measures to equip the Marine Nationale’s ‘Suffren’ class nuclear-powered attack submarines.

The French Navy is acquiring six ‘Suffren’ class boats. Three vessels, namely Suffren, Duguay-Trouin and Tourville, have been launched with the first two commissioned. A further three are under construction with four conventionally-powered versions of the submarine equipping the Koninklijke Marine (Royal Netherlands Navy). The Sentinel-U, which is equipping the ‘Suffren’ class, is one member of Thales’ Sentinel family of Radar Electronic Support Measures (RESM). The Sentinel-H variant is equipping the French Navy’s forthcoming ‘Amiral Ronarc’h’ class frigates.

RESMs are particularly important for submarine survivability. A former French Navy submariner shared with Armada that submarines routinely deploy a very small RESM antenna just above the water before surfacing. The presence of a Maritime Patrol Aircraft (MPA) in the submarine’s locale is a particular concern. These aircraft often use X-band (8.5 gigahertz/GHz to 10.68GHz) airborne surveillance radars to locate submarine periscopes. The RESM antennas tend to be designed to produce as small a radar cross section as possible to these radars. This helps preserve the submarine’s discretion. If such a radar is detected by the RESM, the submarine can have as little as 20 minutes to dive and escape the area. Once it detects a submarine, the MPA will begin using its magnetic anomaly detector and sonobuoys to locate the boat before launching torpedoes.

Sentinel deliveries

Thales officials shared with Armada that the Sentinel-U has been delivered to Naval Group, which is building the ‘Suffren’ class with an expected in-service date of 2025 for the RESM. It is unclear if the Sentinel-U will only outfit new SSNs or will be retrofitted onto the three boats already launched. Open sources say the existing ‘Suffren’ class submarines use an electronic warfare system called Nemesis. Almost no details appear to exist in the public domain regarding this system, although it is likely that Nemesis is a Thales product. The company remains the incumbent supplier of Electronic Warfare (EW) systems to the French Navy.

The officials continued that the Sentinel family performs fully digital processing of Signals-of-Interest (SOIs) across wavebands of two gigahertz/GHz to 18GHz. The system can be extended downwards to 50 megahertz and upwards to 40GHz if desired by the customer. Regular software updates are planned as Sentinel moves through its service life. These updates include the additional of cognitive EW algorithms intended to lighten the operator’s workload through the rich analysis of SOIs. Sentinel variants are also likely to equip the French Navy’s future Porte-Avions de Nouvelle Génération (New Generation Aircraft Carrier) which replaces the Charles de Gaulle. The latter is the navy’s current aircraft carrier and flagship.

The full mission fit for the Sentinel-U includes the submarine’s EW operator console and accompanying equipment cabinets. The electronic support measure links to two Safran Series-30AOM/SOM attack and search optronics mast which are both equipped with integral RESM antennas. Thales officials continued that an ashore EW system complements the Sentinel-U. This can be used for the interpretation of unknown SOIs collected by the RESM and for the system’s overall management. With the Euronaval exhibition in Paris on the horizon between 4th and 7th November, more details regarding the Sentinel family may be forthcoming at this event. (Source: Armada)

 

10 Oct 24. October Spectrum SitRep. SRC is pitching its Ghost Mantis electronic warfare system, a rendering of which is shown here, for the US Collaborative Combat Aircraft programme.

Armada’s monthly round-up of all the latest electronic warfare news in the product, programme and operational domains.

Hosts for Ghosts

On 18th September, SRC unveiled its Ghost Mantis electronic warfare system designed to outfit Uninhabited Aerial Vehicles (UAVs). SRC’s official literature says that Ghost Mantis is “(a) low-cost, modular, next-generation electronic warfare payload that enables advanced concepts of operations and tactics.” The company told Armada that Ghost Mantis uses artificial intelligence to identify, deceive and deactivate threats, while sharing threat data offboard in real time. The company claims that Ghost Mantis costs one-tenth of similar systems but offers more advanced threat detection and elimination. Colonel (rtd.) David Tommey, SRC’s assistant vice president for business development told Armada that Ghost Mantis is “customised using Commercial Off-The-Shelf (COTS) and plug-in modules, allowing it to handle a wide variety of transmit and receive modes, and processing functions, without modifying the payload’s chassis, core processing backplane or antenna.” The Ghost Mantis architecture includes sensor open systems architecture-aligned radio frequency and high-performance mission computing subsystems. Regarding the airframes Ghost Mantis can outfit, Col. Toomey said the system is platform agnostic and can be customised for various size, weight and power constraints. He continued that flight demonstrations should commence by the end of 2024 and continue into 2025. Production could then begin in the 2026 to 2027 timeframe. Col. Toomey said that Ghost Mantic has been developed in support of the United States’ Collaborative Combat Aircraft programme.

Cool prizes

In early September, CRFS announced it had won in the sensor category at the US Army’s 2023 Technology Excellence Awards for the company’s RFeye Node 100-18LW radio frequency sensing system. The sensor can be integrated on small Uninhabited Aerial Vehicles (UAVs). This product is a reduced-sized version of its RFeye Node 100-18. The company says it realised the RFeye Node 100-18LW within four months of receiving an urgent requirement from an undisclosed North Atlantic Treaty Organisation customer. CRFS says the RFeye Node 100-18LW can monitor diverse signal types in a design weighing under two kilograms (four pounds). These signals include low probability of interception/detection transmissions. As well as being integrated on small UAVs, the RFeye Node 100-18LW can outfit small uninhabited ground vehicles. CRFS told Armada that the main challenge in developing the RFeye Node 100-18LW was “thermal management and heat dissipation with such little amounts of material available to hit the payload constraints. Basically, lots of heat and not much aluminium to work with to keep it under two kilograms and enable it to stay cool at extreme temperatures.”

Battle Buddy ready for EW

EdgeRunner has shared with Armada that its AI Battle Buddy software can support Electronic Warfare (EW) missions. The hardware-agnostic system includes artificial intelligence algorithms and needs eight gigabits of random access memory. The company said in a written statement that AI Battle Buddy “is built on advanced machine learning algorithms, enabling real-time data analysis, predictive insights, and adaptive decision-making.” The software can be used to “process vast amounts of battlefield data, recognise patterns, and generate actionable intelligence.” EdgeRunner continued that the “AI Battle Buddy is in the advanced stages of development, having undergone extensive testing in collaboration with key defence partners.” Although not yet commercially available, the software is being used in pilot programmes by undisclosed military units “to assess its effectiveness in real-world scenarios.” Full-scale production should commence over the next month. The written statement continued that the software “offers unparalleled support for EW missions by providing real-time threat analysis, signal intelligence, and rapid decision-making capabilities through natural language processing akin to a human conversation.” AI Battle Buddy can “adapt to evolving EW threats, predict enemy tactics, and recommend optimal countermeasures. Its predictive analytics capabilities also allow it to anticipate adversary moves, providing a significant tactical advantage in highly contested electromagnetic environments.” The product can be used at both the operational and tactical levels. Several allied nations have also expressed interest in the technology “with plans to initiate joint testing exercises in the coming months to explore its integration into their EW frameworks.” (Source: Armada)

 

09 Oct 24. Cubic Defense to Demonstrate Multi-Domain Convergence Solutions at AUSA 2024. Cubic Defense, a recognized industry leader in providing digital intelligence, edge compute and networking, live, virtual and constructive (LVC) training and secure communications will showcase its Multi-Domain convergence solutions during this year’s AUSA Annual Meeting and Exposition from October 14-16 in the Walter E. Washington Convention Center in Washington, D.C.

“Mission requirements are constantly evolving, and tomorrow’s battlespace will be more complex and contested. A new advantage is needed to train, connect and adapt quickly with precision across all domains,” said Anthony Verna, Senior Vice President and General Manager of DTECH Mission Solutions. “Cubic’s portfolio delivers a decisive advantage with mission inspired solutions that enable assured data access, converged digital intelligence and superior warfighting readiness.”

Visit Cubic Defense at Halls D & E, booth #8033, and speak with experts who will demonstrate how Cubic’s digital intelligence, edge compute and networking, LVC training and secure communication solutions can empower the U.S. Army to modernize at the speed of the threat.

Demonstrations will include:

Edge Compute and Networking: DTECH’s edge compute and networking family of systems deliver a persistent information advantage, accelerating the transformation of data to decisions, enabling the Next Generation Tactical Edge:

  • The DTECH Fusion Edge High Performance Compute (eHPC) stands alone in its ability to provide enterprise-level computing power to the tactical edge enabling complex data-rich workloads including AI/ML, even in Denied, Disrupted, Intermittent and Limited (DDIL) environments.
  • DTECH M3-SE, M3X, Cross Domain Guards and ROIP Gateway are ideal platforms for edge applications that enable users to connect, secure and analyze mission-critical data throughout the mission chain.

Digital Intelligence: Cubic Digital Intelligence is advancing information superiority with scalable C5ISR integration, from space to the edge, tailored for Joint and Mission Partner environments. Revolutionizing Data Management: Cubic’s digital intelligence solutions make vast amounts of data manageable by automating data routing and distribution, ensuring seamless sharing and accessibility. Whether in DDIL environments or high-demand operations, our resilient systems are built to maintain critical functionality and data flow.

  • Automation and Tactical Integration: Cubic enhances intelligence operations with automated workflows and integrated Tactical Awareness Kit (TAK) support, enabling faster, more informed decision-making across the mission spectrum.
  • Enabling Future Applications: From small form factor computing designed for AI/ML processing to scalable, space-efficient systems, Cubic’s Digital Intelligence solutions drive operational efficiency and innovation, supporting future capabilities like TAK, and more while reducing Size, Weight and Power (SWaP).

LVC Ground Training: Force-on-Force Training: Cubic’s LVC ground training solutions empower realistic training with scalable interoperability, immersive realism and insightful analytics.

  • Cubic’s direct-fire training systems (Soldier, vehicles) provide effective, force-on-force engagement training with instrumented direct-fire solutions that establish the roadmap for advancing live training capabilities that bridge current operations with the synthetic training environment.
  • Cubic’s indirect-fire training systems provides the ability to conduct individual, crew and collective indirect-direct fires training in live environments including support for instrumented call for fire (Joint fires, JTAC) and conduct of fires (mortars, artillery, launchers) missions, that are integrated with Mission Command systems, as well as EXCON and AAR capabilities.

Secure Communications: Resilient Communications: Cubic’s Secure Communications solutions deliver assured and stealthy communications that resolve critical gaps in wideband tactical communications. Cubic accelerates the evolution from federated terminals to open architectures enabling the US Army to modernize software communications at the speed of the threat.

  • Halo is Cubic’s modular, low-SWaP, phased array antenna that provides robust wideband communications for the DoD’s Hybrid-SATCOM networks enabling simultaneous connectivity between bands and orbits.
  • Cubic’s Software Defined Radios (SDR) and protected waveforms deliver high data rates in compact, lightweight designs enabling resilient communications that extends the reach of Future Vertical Lift (FVL) platforms in contested electromagnetic spectrum environments.

 

09 Oct 24. Proving the value of the Royal Navy’s AI roadmap.

The Royal Navy came to ACE to explore how groundbreaking artificial and machine-learning solutions could enhance maintenance and defence capabilities.

The Naval AI Cell (NAIC) is helping the Royal Navy (RN) embrace the transformative power of artificial intelligence (AI) and the benefits it can bring, and an initial phase highlighted six priority challenge areas/capabilities that could confirm the value and impact of an aligned transformative roadmap.

The Accelerated Capability Environment (ACE) was asked to carry out focused discovery into two of these capabilities – increased platform availability through predictive maintenance and Counter-uncrewed Air Systems (CuAS) – to prove a set of use cases and suggested next steps in terms of proposed development and data requirements for each.

The predictive maintenance challenge involved the wear and debris team at a naval air squadron. This team contains many experienced engineers who test oil and debris samples from helicopter engines and gear boxes to check for any flight safety or airworthiness issues.

Most samples pass at the first stage but still take a long time to process, and there is also a potential knowledge transfer issue as engineers retire or leave. ACE was asked to explore whether AI or machine learning (ML) could be applied to mark the test data or carry out any part of its analysis, which is largely manual.

A four-week study carried out by Vivace suppliers Mind Foundry and Frazer-Nash across five use cases found that AI/ML techniques including computer vision algorithms, automatic classification of debris imagery and natural language processing could be used for condition assessment of wear debris, bringing time savings. A brief proof of concept was developed to automatically identify the volume of iron particles in oil, which showed how the process of fragment identification and collection could be streamlined.

Overall, the discovery phase found clear potential for innovative use of AI to support airworthiness and increased aircraft availability. Other data, including vibration monitor data, was also identified which could be used to provide additional insights.

Inferring greater meaning from data

A second challenge undertaken by supplier Roke explored how greater meaning can be inferred from signals data from legacy capabilities, and how additional and alternative approaches to combining, processing and making data more accessible can improve the RN’s capability to detect, classify and track Uncrewed Aerial Systems (UASs). This would increase the exploitation potential and extract more meaningful insights.

Reengineering these platforms can be hugely expensive and so the RN wanted to see if AI could be used to enhance existing processes, making better use of data that is already collected. This work resulted in the development of a framework to combine and process data from complex platforms using additional and alternative approaches, which will improve the RN’s capability to counter threats posed by UASs.

Both discovery workstreams proved the value of having the AI roadmap and associated investment in place, that it is robust, and determined a set of next steps which can take each use case forward, building the foundations for future operational capabilities.

(Source: https://www.gov.uk/)

 

09 Oct 24. Europe: Attack on air-gapped systems will increase cyber espionage risks to government bodies. On 7 October, the software company ESET reported that the advanced persistent threat group (APT) ‘GoldenJackal’ compromised air-gapped systems within an unspecified European government organisation in a cyber espionage campaign starting in May 2022 and ending in May 2024. The group likely used malicious documents and/or remote access trojans (RATs) to deploy new custom malware (‘GoldenDealer’). By automatically copying itself onto USB drives inserted into compromised systems, GoldenDealer propagated the infection after system users unknowingly inserted compromised USB drives into new air-gapped devices. Subsequently, GoldenDealer downloaded a backdoor and a file stealer onto infected systems to collect sensitive information, highlighting GoldenJackal’s sophistication and its ability to bypass security mechanisms. When inserted back into internet-connected devices, the infected USB drives relayed stolen information to actor-controlled infrastructure. GoldenDealer also contains a new toolset to facilitate file exfiltration, highlighting the group’s continuous development. We assess that this will increase security and cyber espionage risks to European government organisations in the long term. (Source: Sibylline)

 

08 Oct 24. US donates radios for Uruguayan APCs. The Uruguayan Army has received 14 L3 Harris Falcon II RF-7800H radsystems from the US Department of State’s Global Peace Operations Initiative (GPOI), a US Southern Command (SOUTHCOM) spokesperson confirmed to Janes on 7 October. Osprea Mamba Mk7 armoured personnel carriers (APCs) were also transferred via GPOI and received on 8 July. L3 Harris radios will be installed aboard 14 APCs, according to a 30 September press release. SOUTHCOM told Janes the Mambas include one command-and-control (C2) vehicle, one platform for recovery missions, one ambulance, and 11 troop transports. With the assistance from L3 Harris technicians, the Uruguayan Army carried out a month-long training course throughout September to train “over 40 soldiers” with the new equipment, the service explained. The course took place at the headquarters of Communications Battalion N2. (Source: Janes)

 

08 Oct 24. Italy’s $680m EA-37B electronic attack aircraft deal moves forward. BAE Systems is named the principal contractor in the deal to strengthen Nato interoperability. The US State Department has agreed a potential Foreign Military Sale to Italy, including Electronic Attack (EA)-37B mission systems and associated equipment, valued at up to $680m (€619m).

The sale, which BAE Systems will lead in Hudson, New Hampshire, includes various systems and technologies, such as network centric collaborative targeting, radio frequency receiver subsystems, and counter radar assembly components. The agreement also covers a support package, including communications equipment, navigation tools, cryptographic devices, maintenance services, and personnel training.

The EA-37B systems are expected to disrupt enemy command and control communications during international operations.

Enhancing Italy’s electronic warfare capabilities

The EA-37 B’s mission profile focuses on electronic attack operations, targeting and disrupting adversarial communications and radar systems in combat environments.

According to the DSCA, “Italy will have no difficulty absorbing these articles into its armed forces,” further emphasising the nation’s ability to integrate defence systems into its infrastructure.

In August, the US State Department also approved a $738m arms sale to Italy, which will enhance its aerial surveillance with the acquisition of six MQ-9 Block 5 drones.

The EA-37B systems are set to be involved in Italy’s overseas operations, particularly multinational coalition missions under Nato’s command.

Impact and regional stability

Moreover, the sale is expected to contribute to increased Nato collaboration and US-Italy defence partnerships, ensuring the alliance meets 21st-century threats.

This potential acquisition is welcome news as a recent GlobalData report reveals that Italy is struggling to meet Nato’s defence spending target of 2% of GDP due to political instability and economic challenges.

Italy’s enhanced electronic warfare capabilities will be important in any scenario involving modern air and ground operations, which increasingly depend on disrupting adversary communications and radar systems.

Industry perspective and implementation

BAE Systems, the primary contractor for this sale, is no stranger to delivering military technologies for the US government. On February 13, 2024, BAE Systems announced the delivery of electronic warfare (EW) systems to enhance the US Air Force’s (USAF) EA-37B fleet. The EA-37B is a next-generation platform based on the Gulfstream G550 airframe.

The deal will include classified and unclassified technical documentation, logistics support, and maintenance services, ensuring that Italy is fully prepared to deploy the EA-37B systems.

The DSCA concluded its statement by confirming that the actual dollar value of the agreement will be determined based on final requirements, budget authority, and signed contracts.  (Source: airforce-technology.com)

 

08 Oct 24. Mavenir, the cloud-native network infrastructure provider building the future of networks, is delivering the full 5G core network for ice, Norway’s third largest mobile operator to enable a network slicing service.

ice is utilising its new 5G standalone (SA) network to provide a dedicated network slice for the Norwegian Armed Forces, designed to deliver the specific service levels required by military communications. Essentially an isolated network-within-a-network, the Armed Forces will have exclusive use and control over their slice nationwide. It will be able to establish secure end-to-end communications across the network.

Mavenir’s 5G mobile core is designed ready for network operators to enable network slicing for providing disruptive services to B2B, B2C or public organisations. Dedicated network slices can be designed to meet specified needs and applications, and quickly and easily deployed and managed, and used to deliver new and innovative services and applications. Mavenir’s cloud-native 5G SA network is fully containerised, runs on any cloud service and designed with a microservices approach, giving the flexibility to address evolving customer needs in a scalable way.

“This deployment of network slicing is realising the true value of 5G,” said Tore Kristoffersen, VP Service delivery platforms for ice. “We now have myriad possible new business cases to present to our enterprise customers, which can be tailored to precise service level agreements, ensuring the best and most cost-effective use of resources. We are also testing solutions for use in Public Safety services, highlighting the value of 5G and its network slicing capabilities for secure critical communications.”

“The flexibility of network slicing powered by 5G is a game-changer for mobile operators,” said Ashok Khuntia, President of Core Networks, Mavenir. “We are enabling 5G use cases in practice, proving that the long-promised monetisation of 5G is a reality. With security, reliability and low latency, 5G is a massive opportunity for the industry. We are delighted to be extending our strategic partnership with ice by supporting this first deployment in Norway.”

 

07 Oct 24. Northrop Grumman Corporation (NYSE: NOC) announced a new artificial intelligence (AI) feature to help warfighters make real-time, informed decisions on the move. The Forward Area Air Defense (FAAD) Advanced Battle Manager (ABM) system addresses the growing complexity of threats in the counter-unmanned aerial systems (C-UAS) mission space.

The new AI feature streamlines decision-making for optimal defeat of UAS swarms with a single button click on a mobile tablet. This enhances maneuverability for the U.S. military, allies and coalition partners.

  • Successfully tested in spring and late summer at the Yuma Proving Grounds in Arizona, the ABM makes real-time weapon-target pairings across disparate kinetic and non-kinetic weapons by leveraging AI and years of live fire data.
  • Designed for efficiency and growth, the ABM can plan for complex aerial swarm scenarios with numerous weapons against varying threats, and it supports real-time data processing with minimal delay, generating engagement plans in under a quarter of a second.
  • The ABM continuously monitors the battlespace and replans engagements as necessary and currently supports multiple weapon types. Its open architecture design enables new weapons to be easily added in the future.

Kenn Todorov, vice president and general manager, global battle management and readiness, Northrop Grumman: “As threats evolve, the need for operations to become simple and clear during high-stress multi-target engagements has increased. This critical AI enhancement will create a streamlined and intuitive engagement plan giving service members more time to save lives with a single click. Northrop Grumman and the U.S. Army’s collaboration in innovation ensures the combat-proven FAAD system remains at the forefront of C-UAS technology.”

Details on FAAD:

FAAD simultaneously integrates short-range air defense, counter-rocket, artillery, and mortar and C-UAS missions. As these missions evolve, the need for the warfighter’s user experience to be simple and clear during high-stress multi-target engagement scenarios has increased. FAAD is providing the United States, allied and coalition forces interoperability today by providing cutting-edge capabilities and enabling coordinated protection across the joint force with rapid, real-time defense against complex, maneuvering threats. By investing in and leveraging technologies like AI, Northrop Grumman ensures FAAD remains a leader in short-range air defense and C-UAS.

FAAD is a cyber-certified, real-time safety critical command and control software, providing a single integrated air picture, airspace coordination and deconfliction and fire control to support multi-domain missions. Its open, multi-domain architecture enables integration and interoperability across diverse platforms and systems. This facilitates rapid, cost-effective technology insertion and modernization at the speed of need. FAAD can be quickly deployed, providing command and control to areas limited in robust communication as well as permanent and reinforced support areas. FAAD is the centerpiece of the U.S. Army’s fixed site and maneuver forces and is actively employed worldwide.

Northrop Grumman is a leading global aerospace and defense technology company. Our pioneering solutions equip our customers with the capabilities they need to connect and protect the world, and push the boundaries of human exploration across the universe. Driven by a shared purpose to solve our customers’ toughest problems, our employees define possible every day.

 

07 Oct 24. US: Chinese cyber espionage campaign elevates security risks for government, critical infrastructure. On 5 October, international news outlets reported that the Chinese state-sponsored group ‘Salt Typhoon’ infiltrated several US internet service providers (ISPs) in a cyber espionage campaign. Although investigations are still underway, there is a realistic possibility that the group exploited vulnerabilities in Cisco routers to gain access to targeted systems. Salt Typhoon maintained access to compromised systems for several months, collecting sensitive data prior to detection. The group reportedly accessed information used by the federal government for court-authorised wiretapping requests related to criminal and national security investigations. Salt Typhoon compromised popular broadband providers, underscoring the scale and impact of the operation. Chinese state-sponsored groups frequently target ISPs to spread infections to government infrastructure, pointing to the elevated cyber espionage and supply chain risks stemming from Chinese state-sponsored groups. As investigations surrounding the operation are ongoing, we assess that additional compromises are possible in the coming weeks. (Source: Sibylline)

 

04 Oct 24. Cyber Update Key points.

  • The significant increase in cyber operations against Ukrainian entities will sustain espionage and disruption risks from Russian state-sponsored groups (see Sibylline Cyber Daily Analytical Update – 30 September 2024).
  • An ongoing spear phishing campaign is targeting journalists, activists and other individuals associated with Middle Eastern affairs, elevating security risks from Iranian state-sponsored groups (see Sibylline Cyber Daily Analytical Update – 1 October 2024).
  • The German defence sector faces heightened cyber espionage risks from the North Korean state-sponsored group ‘Kimsuky’ (see Sibylline Cyber Daily Analytical Update – 2 October 2024 and our Technical analysis below).
  • A new Artificial Intelligence (AI)-enhanced variant of the information-stealing malware ‘Rhadamanthys’ has heightened information-theft and financial risks from cyber criminal operations (see Sibylline Cyber Daily Analytical Update – 3 October 2024 and our Technical analysis below).
  • Regional escalation in the Middle East will increase security and disruption risks from Iran- and Israel-linked cyber threat actors (see Sibylline Cyber Daily Analytical Update – 4 October 2024).

The financially motivated threat group ‘kingcrete2022’ has developed a new, more sophisticated version of the information-stealing Malware-as-a-Service (MaaS) Rhadamanthys. While the malware’s infection chain is unchanged, the new variant incorporates generative AI as well as more sophisticated detection-evasion techniques and additional information-stealing tools. Rhadamanthys is typically installed via a multi-stage process which encompasses evasion checks, and establishes communication with actor-controlled infrastructure. The new variant enables threat actors to execute a payload as a Microsoft Windows Installer (MSI) file to emulate legitimate files and to obfuscate Rhadamanthys on compromised systems. Rhadamanthys also uses a mutex to ensure that only one payload is running on infected systems, thereby enhancing detection evasion and achieving prolonged persistence. The new variant uses generative AI to extract login information from cryptocurrency wallets. This is then sent to command-and-control (C2) infrastructure, allowing threat actors to hijack cryptocurrency accounts to garner illicit profit. In April, an older version of Rhadamanthys was reported to be using large language model (LLM)-generated PowerShell scripts, pointing to the increased incorporation of AI into malware by the group. In addition, the new variant contains several new plugins, including a keylogger to steal credentials, as well as clipper malware to hijack additional cryptocurrency wallets for financial profit. The new variant underscores kingcrete2022’s sophistication as it rapidly develops new Rhadamanthys strains, encompassing several new highly sophisticated features to better evade detection and bolster its success rate.

The North Korean state-sponsored group Kimsuky has targeted a German weapons manufacturer in a highly sophisticated cyber espionage campaign. The campaign started with phishing emails in which threat actors purported to offer potential victims highly lucrative jobs at US defence and arms suppliers, tricking them into opening a malicious PDF file. This subsequently downloads malware onto compromised systems, enabling Kimsuky to collect sensitive information. Notably, the group spends time building a rapport with victims prior to sending them the malicious file to bolster its success rates. Kimsuky named the C2 server after one of the manufacturer’s legitimate locations and hosted content in German to conceal the operation, underscoring the campaign’s considerable sophistication and premeditation. There is a realistic possibility that the group has also targeted German users via additional information-theft campaigns, as the C2 server contained malicious login pages mimicking legitimate German telecommunications providers. North Korean state-sponsored actors routinely target strategic entities in social engineering operations to steal sensitive information, and to bolster Pyongyang’s economic and military posture amid ongoing economic sanctions.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network.
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
  • Ensure adequate security monitoring and detection capabilities, particularly for all external-facing services and devices, including personal devices connected to corporate networks or applications.
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.

Our cyber word(s) of the week: Generative artificial intelligence (AI) (Source: Sibylline)

—————————————————————————————————————————————————————————————————————————————————————————————————————————————–

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

 

——————————————————————————————————————————————————————————————————————————————————————————————————————————–

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

October 4, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

——————————————————————————————————————————————————————————————————————————————————————————————————————————————–

02 Oct 24. US Marine Corps Successfully Demonstrate Link 16 in Third XQ-58 Valkyrie Test Flight. The Marine Corps’ XQ-58A Valkyrie successfully completed its third test flight on Sept. 20, 2024, at Eglin Air Force Base in Florida. This flight was conducted in partnership with the Office of the Under Secretary of Defense for Research and Engineering, the Naval Air Warfare Center Aircraft Division, and industry partners.

The test demonstrated newly added Link-16 capabilities for the uncrewed collaborative combat aircraft prototype, marking the first time the Department of Defense controlled an air vehicle using offboard expeditionary methods.

Initial results indicate that the prototype met threshold requirements for autonomously exchanging relevant tactical information. These Link-16 capabilities significantly enhance the Marine Air-Ground Task Force’s ability to conduct integrated and joint operations, contributing to the Marine Corps’ mission to deter conflict and, when necessary, defeat enemies in complex and evolving scenarios.

This successful test was conducted in preparation for Emerald Flag 2024, a multiservice and multi-domain training exercise scheduled for October. The exercise will incorporate technology and focus on the efficiency of joint warfare. The XQ-58A has proven itself ready for this capstone event, allowing the Marine Corps to demonstrate cooperative kill chain closure between manned and unmanned strike platforms for the first time in a large-force exercise. (Source: UAS VISION/USMC)

 

01 Oct 24. US Army seeks new industry input for Next Generation Command and Control initiative. The PEO C3T released the RFI after the office held an industry day to provide more information on NGC2 to interested vendors.

The Army took the next step its pursuit of tech for its Next Generation Command and Control (NGC2) initiative by reaching out for industry’s ideas Monday.

In a request for information (RFI) posted online, the Army’s program executive office for command, control, communications-tactical (PEO C3T) announced it is seeking input on “experimentation, pilots and, prototyping” in establishing NGC2.

Monday’s RFI is the first one related to C2NG to come out of PEO C3T and came after the office held an industry day to provide more information to interested vendors on Sept. 16. The document was released “in accordance with the Army Futures Command (AFC) Characteristics of Need (CoN) requirement,” related to that office’s own interest in next-gen C2, which came out May 21, according to the RFI.

PEO C3T’s RFI includes questions about how industry would “design and manage a common services architecture for warfighting applications” while allowing for a “plug-and-plan” architecture, and how industry would use a common data layer to leverage capabilities to “meet war fighting needs.” Furthermore, it asks how industry sees the role of the Army’s Unified Data Reference Architecture — a broader service framework — in creating and managing NGC2.

The requirement will also include “maximizing vendor access to capabilities and users” all while aiming to bolster the relationship between industry and government.

Additionally, all services and products that are chosen to be part of NGC2 will be “heavily dependent” upon progressive software analytics, artificial intelligence and machine learning capabilities to assist feedback in performance, the RFI states.

NGC2, sometimes called C2 Next, is the service’s plan to create an integrated C2 structure focusing on data centricity “at every echelon,” which will be a “system of systems,” per the RFI. It’s designed to combine intelligence, C2 and fires all in one system so commanders can have information more readily available — a key driving idea behind the Pentagon’s wide Combined Joint All-Domain Command and Control effort.

The service will test out the NGC2 principle in March of 2025 at the Project Convergence capstone five event, Col Michael Kaloostian, the AFC’s networks and security director for NCC2, told Breaking Defense in August.

“We are in the S&T [science and technology] phase, and we’re still doing [research and development] on this project,” Kaloostian told Breaking Defense during an Aug. 22 interview.

“We’re going to learn [with] each step. … It’s always gonna be iterative, because technology is always going to improve,” he later added.

The RFI released Monday is currently open for comment and will close on Oct. 4 at 5 p.m. ET. (Source: Breaking Defense.com)

 

02 Oct 24. Germany: Defence sector faces heightened cyber espionage risks from North Korea-backed groups. On 1 October, international news outlets reported that the North Korean state-sponsored group ‘Kimsuky’ targeted a German weapons manufacturer in a highly sophisticated cyber espionage campaign. The campaign started with phishing emails pertaining to lucrative job opportunities for US defence contractor roles to trick potential victims into opening a malicious PDF file. This then downloaded malware on compromised systems, enabling Kimsuky to steal sensitive information. The group’s command-and-control (C2) infrastructure hosted content in German to conceal the operation, underscoring the campaign’s considerable sophistication and premeditation. It is also possible that Kisumky has targeted German users in additional information-theft campaigns, as the C2 server also contained malicious login pages mimicking legitimate telecommunications providers. Kimsuky routinely targets defence organisations and weapons manufacturers in espionage operations to bolster North Korea’s weapons and missile programmes. We assess this will sustain elevated cyber espionage risks for these sectors in the long term. (Source: Sibylline)

 

02 Oct 24. MilDef launches Dismounted Soldier concept suite at AUSA, engineered for excellence in every mission.

To empower each individual soldier on the battlefield, MilDef launches its Dismounted Soldier System (DSS) to provide state of the art situational awareness and seamless interoperability across all environments. Experience the concept at the AUSA convention in Washington D.C.

MilDef’s suite for dismounted soldiers offers uncompromised durability and performance and is built on a range of hardware and software components that are not only rugged and durable but also highly adaptable to meet specific mission requirements. Whether it’s extreme temperatures, rough terrains, or high-stress combat scenarios, the MilDef system is designed to serve in those conditions. Developed with input from mission experienced military commanders and soldiers, it’s built to meet the demands of the toughest environments.

“Our system integrates with existing or new platforms and technologies, including radios, and other mission-critical systems, offering unit leaders high resolution situational awareness, enhancing coordination and effectiveness on the ground. The system is hardware and software agnostic, allowing for easy integration with any third-party solutions and battle management systems. This adaptability ensures a future-proof system, capable of evolving with technological advancements and changing operational demands,” says Fredrik Persson, CTO and Deputy CEO MilDef Group.

Components in the MilDef Dismounted Soldier System suite

  • Tactical Android Device, the T.A.D. End User Device – Rugged Android device (MIL-STD-810/IP67), 5G and WiFi 6 connectivity, support of multiple ethernet devices, >24h operating time, field replaceable battery, night vision etc.
  • MilDef DSS HUB – 6-port USB 2.0 HUB with power management, 1 EUD port, 3 PAN ports, 2 power ports, STANAG 4695 / STANAG 4851 / Nett Warrior compliant connectors.
  • OneCIS – Automated and rapid deployment and configuration of operating system, network configuration, applications, and services.

MilDef has substantial experience from delivering tactical system solutions mounted in military platforms. MilDefs Dismounted Soldier System is a natural extension of MilDefs capabilities and offer, as when integrated with GFE (Government Furnished Equipment), existing systems and new technology, it delivers enhanced operational effectiveness and mission success – when and where the stakes are the highest.

AUSA takes place Oct 14-16 Washington DC, Walter E. Washington Convention Center, booth 7941.

 

30 Sep 24. Lockheed Martin (NYSE: LMT) in collaboration with Altera, an Intel Company, completed a successful flight demonstration of our 12th Generation Electronic Warfare (Gen12) transceiver utilizing Altera’s Agilex™ 9 Direct RF FPGA (Multi-Chip Package, MCP-2).

The project, coined SWIFT (SHIP-enabled Wideband Transceiver Integrated Flight Test) by the Office of the Under Secretary of Defense for Research and Engineering (OUSD-R&E), established an aggressive requirement for Lockheed Martin to perform an electronic warfare flight demonstration utilizing Altera’s FPGA aboard a Group 2 Unmanned Air Vehicle (UAV) in less than 12 months.

Conducted at the U.S. Army’s Yuma Proving Ground, the SWIFT demonstration represented the first time Lockheed Martin used the Altera Direct RF FPGA in a government test environment, showcasing the device’s readiness to perform real-world missions. The event successfully proved the Gen12’s Electronic Support (ES) capability by performing the detect, identify and locate mission against real enemy emitters in a DoD relevant environment.

Through the success of this demonstration, Lockheed Martin and Altera proved how size, weight and power (SWaP) constrained airborne platforms can be utilized to deliver electronic warfare effects, while also allowing growth for new capabilities. The technology enables a low SWaP, Sensor Open System Architecture (SOSA) aligned digital transceiver that performs the Electronic Support (ES) and Electronic Attack (EA) missions using domestically produced semiconductors.

This demonstration serves as a proof point for the importance of OUSD-R&E State-of-the-Art Heterogeneous Integrated Packaging (SHIP) program and the ongoing need for sustainable U.S.-made microelectronics packages customized for DoD applications.

The Big Picture

  • The success of the SWIFT demonstration and its profound impact as a proof point on the SHIP program was reiterated at a recent event held at Lockheed Martin’s newly renovated Global Vision Center in Crystal City, Virginia. The event’s purpose highlighted the Altera Direct RF FPGA’s readiness to transition into a variety of DoD programs of record.
  • During the event, attendees watched footage of the flight test demonstration in a pre-recorded video highlighting the capability of MCP-2, along with the rapid insertion and successful integration in a UAV.
  • Keynote speakers from DoD leadership along with executives from Lockheed Martin, Altera and OUSD-R&E gathered to highlight the success of this demonstration and spoke about how the benefits enabled by the SHIP program and MCP-2 development, enable advanced electronic warfare architectures with game-changing capability enhancements.

Strategic Perspectives

“This demonstration signifies an important step forward for Lockheed Martin’s strategic partnership with OUSD-R&E and Altera on ensuring warfighter access to state-of-the-art, U.S.-made microelectronics,” said Dr. Steven Walker, vice president and chief technology officer at Lockheed Martin. “The SHIP program’s transformative influence on DoD capabilities bolsters confidence in these ongoing advancements and paves the way for their integration throughout the military in support of our customers’ most critical missions.”

“Altera’s proud to participate in Lockheed Martin’s demonstration along with OUSD-R&E SHIP program. Leveraging decades of leadership in chiplet development and manufacturing has led to the rapid readiness and availability of production quality, SWAP-centric MCP-2 products for future mission requirements.” said John Sotir, Senior Director, Military Aerospace and Government Business and State-of-the-Art Heterogeneous Integration Packaging (SHIP).

What’s Next?

  • The success of this demonstration shows promise for continued collaboration with industry and commercial partners using U.S.-built semiconductors to achieve DoD objectives.
  • This technology can be used for future platforms in many different ways depending on the mission at hand. It can deliver targeting information and situational awareness for our allies.
  • Lockheed Martin will continue to demonstrate Gen12 Electronic Support (ES) and Electronic Attack (EA) capabilities for customers and cultivate near-term transition opportunities into DoD Programs of Record.

Background

  • The SHIP program focuses on the development, delivery and eventual transition of microelectronics devices into DoD systems. The SHIP program’s objective is to create U.S.-made, trusted microelectronics that enable significant SWaP reductions in DoD systems.
  • The SHIP program is part of a broader effort to enhance U.S.-based, secure and economically viable capabilities to support critical warfighting missions.
  • As part of the SHIP program, multiple MCP devices were created in record time by Altera. Lockheed Martin was the early access partner for the transition of the MCP-2 device through the Stimulating Transition for Advanced Microelectronics Packaging (STAMP) contract.
  • Through the STAMP contract, awarded by OUSD-R&E, Lockheed Martin and Altera worked to develop optimized architectures that leveraged the Altera commercial MCP-2 chip to apply specifically to electronic warfare applications, accelerating the transition of capabilities to the warfighter.

 

27 Sept 24. Cyber Update Key points.

  • A destructive operation against Russian entities will raise disruption risks posed by pro-Ukraine hacktivists (see Sibylline Cyber Daily Analytical Update – 23 September 2024 and our Technical analysis below).
  • Unnamed threat actors are targeting Android users with a new variant of the ‘Necro’ trojan, elevating financial risks to individuals (see Sibylline Cyber Daily Analytical Update – 24 September 2024).
  • Artificial intelligence (AI)-related cyber operations will increase security risks from low-skilled cyber criminals (see Sibylline Cyber Daily Analytical Update – 25 September 2024).
  • The rise in cyber operations against critical national infrastructure (CNI) will prolong operational and security risks from threat actors (see Sibylline Cyber Daily Analytical Update – 26 September 2024).
  • An ongoing, highly sophisticated operation targeting Pakistani entities elevates espionage risks posed by the Indian state-sponsored group ‘SloppyLemming’ (see Sibylline Cyber Daily Analytical Update – 27 September 2024 and our Technical analysis below).

Technical analysis of weekly stories

The pro-Ukraine hacktivist group ‘Twelve’ may have targeted Russian entities in a destructive cyber attack in June. While the group reportedly halted operations in the spring, the tactics used in this recent operation point to Twelve’s likely re-emergence. The group typically infiltrates targeted systems by hijacking user accounts from third-party services including virtual private networks (VPNs) and secure shell (SSH). Twelve then deploys web shells on compromised systems to execute arbitrary commands, conduct additional malicious activities and install open-source malware. This enables them to encrypt and erase victims’ data using ransomware (‘LockBit 3.0’) and wiper malware. Notably, the group does not request ransom payments for file decryption, underscoring the politically motivated and destructive nature of their attacks. Twelve’s tactics and infrastructure also align with the ‘DARKSTAR’ ransomware group, suggesting that there may be an overlap between the two groups. Additionally, Twelve’s operations frequently include the deployment of a backdoor (‘FaceFish’) to remotely control infected systems, as well as the use of PowerShell to achieve prolonged persistence. The group also evades detection from security analysts by using existing product names to conceal malware payloads and deleting event logs.

The Indian state-sponsored group SloppyLemming is targeting the law enforcement, government, technology, energy and education sectors in Pakistan in an ongoing cyber espionage operation. The campaign uses phishing emails to trick victims into clicking on a malicious link and downloading a custom tool (‘CloudPhish’). CloudPhish then enables the group to create a malicious Cloudflare Workers instance to steal victims’ credentials by hijacking an email provider’s login page. SloppyLemming subsequently deploys a script to collect email addresses from victims’ accounts to propagate the attack. The group also used Cloudflare Workers to steal Google OAuth tokens, effectively gaining unauthorised access to a victim’s Google account. The data collected during these operations is then sent to the actors’ command-and-control (C2) infrastructure for storage using the legitimate messaging application Discord. Additionally, SloppyLemming uses follow-on phishing emails to distribute a malicious file hosted on the file hosting platform Dropbox, further highlighting the group’s frequent exploitation of legitimate cloud services. This exploits a software vulnerability (CVE-2023-38831) to install a remote access trojan (RAT), likely to perform additional malicious activities, such as remotely accessing compromised systems and exfiltrating sensitive data. SloppyLemming’s complex attack chain, which exploits several legitimate cloud services, serves as a testament to the group’s sophistication.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network.
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
  • Ensure adequate security monitoring and detection capabilities, particularly for all external-facing services and devices including personal devices connected to corporate networks or applications.
  • Ensure organisations implement secure backup strategies by storing data backups in different formats including air-gapped and off-site copies to ensure resiliency.

Our cyber word(s) of the week: Email Account Takeover (EAT)

(Source: Sibylline)

———————————————————————————————————————————————————————————————————————————————————————————————————————————

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

 

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

———————————————————————————————————————————————————————————————————————————————————————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

September 27, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

—————————————————————————————————————————————————————————————————————————————————————————————————————————————–

26 Sep 24. Global: Rise in cyber attacks against critical infrastructure will elevate operational, security risks.  On 25 September, the US Cybersecurity and Infrastructure Security Agency (CISA) warned that threat actors are increasingly infiltrating critical national infrastructure (CNI) using unsophisticated attack vectors. The advisory reported that actors have capitalised on inadequate security measures, such as exploiting stolen and weak credentials in brute force attacks. This enables them to infiltrate industrial control systems (ICS) within CNI, possibly intending to disrupt operational continuity, including halting water and electricity provisions. The warning follows a cyber attack against a water treatment facility in Arkansas (US) on 22 September, which forced the facility to switch to manual operations. Although the attack did not affect water quality or provisions, it underscores the potentially life-threatening consequences that these attacks can have. Cyber operations from politically and financially motivated actors against ICS environments have markedly increased since early 2024, sustaining prolonged security and operational risks to CNI.  (Source: Sibylline)

 

24 Sep 24. Smiths Detection, a global leader in threat detection and security screening technologies, and a business of Smiths Group, in partnership with Riskaware, an incident modelling specialist, have today launched UrbanAware, an end-to-end platform to augment, integrate and digitise the delivery of chemical, biological, radiological and nuclear (CBRN) hazard intelligence in real time during an incident.

This joint solution not only closes the gap between data collection, analysis and strategic awareness of CBRN threats, it also brings insights closer to the tactical edge, enabling stakeholders to quickly identify and understand chemical and other hazards in the field. Threats can be seen in real time on a map in relation to the team’s position, thus providing critical and potentially life-saving intelligence. Likely next stages of a chemical attack or accidental industrial release can also be forecast using the simulation capabilities.

Dr Sarah Robinson, Global Industry Director – Defence at Smiths Detection, said: “Our partnership represents a joint mission to create safer spaces and address complex global challenges in order to protect people, environments, infrastructure and societies worldwide. First responders and military planners need to act quickly when faced with disaster management and UrbanAware enables incredibly fast access to critical information. When combined with sensor data, it becomes a very powerful tool as a situation unfolds – supporting faster, more informed response strategies.”

Landscape and population considerations make it challenging to evaluate the potential impact of any incident and determine the best course of action. As the name suggests, UrbanAware is optimised for these complex urban environments where the topography of streets and buildings influences dispersion of airborne hazards. Typical use cases range from planning evacuation routes in a civil emergency to establishing optimal cordon areas based on predictive hazard modelling.

Underpinning Riskaware’s CBRN system is the Hazard Assessment Simulation and Prediction (HASP) Suite, which was developed over two decades by the Defence Science and Technology Laboratory (Dstl) and is licensed to Riskaware by Ploughshare. The HASP Suite was originally developed to provide rapid hazard prediction in complex urban environments in a matter of minutes, greatly improving upon previous models. It also takes into consideration the interactions between indoor and outdoor dispersion and is able to estimate source parameters, such as location, discharge time, and the amount of substance released. Integrating these robust capabilities with Smith Detection’s well established chemical sensor gives defence and security organisations a rich hazard modelling solution which surpasses any traditional options.

Dr James Christley, Senior Principal Scientist, Dstl, said: “Sustained Defence investment in science and technology consistently produces innovation that protects lives. We’re pleased that Dstl’s work developed originally for UK Defence will be exploited to benefit a wider audience.”

Simon Agass, Riskaware Business Development Director, added: “We’ve worked with multiple military agencies and have seen that the available CBRN solutions are highly manual and not fit for purpose in today’s threat landscape. Bringing together our comprehensive CBRN modelling capabilities with Smith Detection sensor technology provides a much-needed, end-to-end CBRN incident response capability that saves critical time, informs targeted action and protects more people.” (Source: BUSINESS WIRE)

 

25 Sep 24. MilDef ARMOR IT, at AUSA 2024, the largest U.S. army and defense exhibition. October 14-16 MilDef will be exhibiting at the Association of the U.S. Army’s Annual Meeting and Exposition in Washington D.C. MilDef will showcase rugged IT solutions for the digitalized battlefield including a new dismounted soldier concept, the next generation of intelligent displays and a NIAP certified KVM switch.

AUSA is the place to address top US and global military leaders on MilDef’s cutting edge Tactical IT for digitalization of armed forces. This year’s AUSA theme is “Transforming for a Complex World”.

MilDef design, produce and deliver long life cycle products & solutions for a tactical environment. The offer includes a wide selection of IT platforms including computer, display, network equipment and peripheral devices. At AUSA MilDef will present:

  • Dismounted Solider System (DSS) – suite is built on the T.A.D. End User Device (Tactical Android Device), MilDef DSS HUB and the MilDef OneCis software – for seamless situational awareness in tactical environment and with long product life cycle.
  • Cyber security – Showcasing latest progress within cyber security, including tempest computers, NIAP certified KVM switch, next-generation firewall (NGFW) in-vehicle deployment.
  • Command post – Selection of MilDef’s portfolio of rugged mobile laptops & workstations.
  • Solutions – Showcasing MilDef system integration in battle ready customer cases.
  • Product stage experience – Demonstrations of a wide selection of the MilDef tactical product range.

“We have never presented such a strong line up of products and solutions at the AUSA show. It´s a perfect platform for MilDef to team up with key players that are devoted to build the future army, in the US, in coalition forces and NATO-markets. Our offering help accelerate the much-needed digitalization of battle-ready capabilities,” says Fredrik Persson, CTO/Deputy CEO MilDef.

Through long-term relationships and close customer interaction MilDef provides products, services and knowledge that turn into unique customer solution combinations that solves strategically important customer specific challanges. MilDef’s rugged military-off-the-shelf (MOTS) building blocks are used to forge reliable systems that will be supported over many years. The offering includes a wide selection of SWaP-C-optimized platforms including computer, display, network equipment and peripheral devices. The units can be delivered in a standardized form factor like the modular 19”/2 MOTS unit, or highly customized units specifically designed to customer specifications.

AUSA takes place Oct 14-16 Washington DC, Walter E. Washington Convention Center, booth 7941.

 

24 Sept 24. DARPA, DSTL and DRDC form US-UK-Canada AI collaboration.

The US, UK, and Canada have formed a collaboration of DARPA, DSTL and DRDC to reduce duplication of efforts in AI research.

Currently, the Five Eyes intelligence community consists of the UK, US, Canada, Australia and New Zealand. Credit: Vasin Lee / Shutterstock.

The UK Ministry of Defence (MoD), the US Defense Advanced Research Projects Agency (DARPA), and the Canadian Department of National Defence have formalised a trilateral collaboration to drive forward critical artificial intelligence (AI) and cybersecurity systems, the research outfits announced on 20 September 2024.

The MoD’s Defence Science and Technology Laboratory (Dstl) will lead the UK’s efforts, with Defence Research and Development Canada (DRDC) taking charge in Canada. According to the MoD, this agreement is pivotal for cementing the close ties among the nations and further integrating their research and development (R&D) efforts. The collaboration aims to reduce duplication of research by sharing key insights and technologies across borders.

In a recent statement, Dr Nick Joad, Director of Science and Technology at the UK Ministry of Defence, emphasised the importance of the partnership, stating the collaboration is “one of our most vital and enduring partnerships”. He added that advancing areas such as cybersecurity and AI is critical for maintaining national defence and ensuring security in an evolving global landscape.

Among the first projects under this initiative is the CASTLE (Cyber Agents for Security Testing and Learning Environments) programme, which focuses on using AI to defend against advanced cyber threats autonomously. AI-driven systems are increasingly essential to mitigating the surge in cyberattacks, particularly as malicious actors now leverage AI to launch more frequent and sophisticated attacks. DARPA notes that CASTLE is designed to enable AI to autonomously detect, classify, and respond to cyber threats, reducing reliance on human operators, who can no longer keep pace with the volume of threats.

The partnership will also address other areas of AI integration in defence. DARPA Director Stefanie Tompkins stressed the significance of trustworthy AI, citing the need to create resilient systems that can withstand attacks by skilled adversaries. Developing AI systems capable of rapid decision-making in battlefield scenarios while ensuring safety and trust is a central goal. She further noted that international collaboration is a “big step toward enhancing our understanding in the outlined research and development thrust areas” and is crucial for developing advanced technologies.

The GlobalData report on AI in defence supports this approach, highlighting the rapid growth in AI-related defence technologies. According to GlobalData, the AI market is expected to reach $908.7bn by 2030, driven by a 35.2% compound annual growth rate. AI is increasingly seen as a critical tool for modern warfare, automating key functions such as intelligence, surveillance, and reconnaissance (ISR), command and control, and simulation.

The report also points out that AI poses ethical and security challenges. It raises concerns about lethal autonomous weapons, which could be used to identify and eliminate threats without human intervention. Despite these concerns, the urgency of developing cutting-edge AI technologies is being felt globally, particularly given rising geopolitical tensions and the current war in Ukraine. As nations race to gain an advantage in AI development, the UK, US, and Canada are positioning themselves as leaders in this field.

Dr Paul Hollinshead, Chief Executive of Dstl, underscored the importance of leveraging this partnership to ensure the UK remains secure. “Together, we are driving value for money for our respective taxpayers while creating mission critical capabilities through science and technology, keeping our countries and our people safe,” Hollinshead said.

 

19 Sep 24. Indra and Thales Strengthen the Intelligence of the Army’s BMS.

  • The Army has operated with the Battlefield Management System (BMS) developed by Indra and Thales since 2021 with excellent results
  • The two companies will now endow it with greater processing capacity and an improved performance to operate in tactical environments in which increasingly intelligent platforms and systems are exchanging a growing volume of data to gain an advantage over the adversary
  • Indra and Thales are also striving to lighten the system’s architecture so it can be installed on tablets, giving greater mobility to the units, which won’t have to depend solely on the system installed on board their vehicles
  • The BMS system, which ensures maximum interoperability with allied armies and constitutes one of the most advanced solutions of its kind in the world, enables commanders to make the right decisions faster

Indra and Thales are strengthening the capacity of the Spanish Army’s BMS (Battlefield Management System) and preparing it to operate in highly digitalized scenarios in which its data exchange and degree of coordination are extremely high and key to gaining an advantage over the adversary.

The two companies will evolve the system, which they were tasked with developing. It went into operation in 2021. It’s become one of the most advanced of its kind and a benchmark for armies around the world.

The BMS enables commanders to oversee and issue orders in real time, helping them to rapidly make the right decisions, and provides units deployed in the field with a complete view of the mission on digital mapping, allowing them to exchange tactical information, images and text messages to enhance their coordination and boost their effectiveness.

Improved processing capacity and performance

The current aim of this evolution is to increase the system’s processing capacity and performance so that it can handle more information and provide the army with greater situational awareness and coordination, thereby adapting it to a context in which the volume of data exchanged by platforms and weapon systems is constantly growing.

Antonio Hernández Bejarano, Indra’s director of Business Development for Electronic Combat Management, explained that “the improvements will also enable us to exploit the capabilities of the new means of transmission, maximizing the available bandwidth while providing the ability, in a transparent manner, to dynamically adapt the information flows so as to work in contested environments in which the adversary attempts to prevent communications”.

Juan José Forteza, Thales Projects Director, emphasized that “the system has been designed to guarantee interoperability with other allied armies in alignment with NATO’s FMN (Federated Mission Networking) standards, which facilitate the integration of the different command and control networks of allied countries, a crucial factor within the current context”.

The two companies will also lighten the system’s architecture so that it can be installed on tablets, allowing it to comply with high mobility requirements. Another benefit to be added will be the integration of the BMS into SIGLE, the Army’s Logistics Management System, in order to reduce the workload associated with armored vehicle maintenance and improve the upkeep of vehicles and tanks throughout their life cycle, thereby increasing their availability and the safety of their crews.

The BMS system has performed excellently during real missions of the utmost complexity, including NATO’s Enhanced Forward Presence (EFP) Mission, in which the Spanish Army was deployed in Latvia with Pizarro infantry fighting vehicles and Leopard tanks, among other means equipped with the battlefield management system. (Source: ASD Network)

 

20 Sept. 24. Cyber Update Key points.

  • A newly disclosed cyber operation has heightened the espionage risks stemming from the Chinese state-sponsored group ‘Earth Kasha’ (see Sibylline Cyber Daily Analytical Update – 16 September 2024).
  • An attack chain exploited multiple zero-day vulnerabilities prior to its detection in June, raising financial risks stemming from the financially motivated group ‘Void Banshee’ (see Sibylline Cyber Daily Analytical Update – 17 September 2024).
  • Ransomware groups’ shifting tactics towards double extortion attacks using cloud management services will increase the financial risks facing firms (see Sibylline Cyber Daily Analytical Update – 18 September 2024).
  • A recent botnet takedown by the US authorities points to elevated security risks stemming from the Chinese state-sponsored group ‘Flax Typhoon’ (see Sibylline Cyber Daily Analytical Update – 19 September 2024 and our Technical analysis below).
  • The likely resumption of operations by the cyber criminal group ‘TeamTNT’ will increase the financial risks facing global firms.

Technical analysis of weekly stories

The Chinese state-sponsored group Flax Typhoon has been infiltrating critical national infrastructure (CNI) in Taiwan and the US to develop a multi-tiered botnet (‘Raptor Train’) since at least 2020. US security agencies dismantled the botnet in mid-September. Flax Typhoon reportedly exploited several software vulnerabilities to gain access to targeted systems. Raptor Train is composed of three interconnected tiers, centrally operated by management nodes in the third tier. Conversely, the first tier primarily comprises Internet-of-Things (IoT) devices and small office/home office (SOHO) routers; it communicates with tier three via the command-and-control (C2) infrastructure hosted on tier two. Raptor Train enabled Flax Typhoon to re-route traffic and install malware on compromised systems. Namely, Flax Typhoon deployed the ‘Nosedive’ payload on some tier one devices, providing the group with the ability to disrupt compromised systems via distributed denial-of-service (DDoS) attacks. Although the group did not conduct any disruptive attacks prior to the botnet’s takedown, we assess that there is a realistic possibility that it developed the botnet to conduct future disruptive operations. Raptor Train compromised around 260,000 devices before the takedown, highlighting both the scale and high sophistication of this operation. Notably, the botnet regularly added new devices to tier one, underscoring the threat actors’ ability to exploit software vulnerabilities quickly in order to propagate the botnet. Additionally, the threat actors adopted several anti-forensics mechanisms which markedly prolonged detection evasion.

The cyber criminal group TeamTNT has likely been conducting operations in a series of highly sophisticated crypto jacking campaigns since 2023. The threat actors use brute force attacks against VPS cloud infrastructure as initial attack vectors to hijack vulnerable user accounts and to access targeted systems. They then deploy a malicious script to disable native security tools and erase activity history for detection evasion. They also simultaneously interrupt existing crypto mining processes before running their own crypto mining scripts. They also deploy a rootkit (‘Diamorphine’) to obtain full control of compromised systems and to execute further malicious activities. Notably, the threat actors conduct post-exploitation activities to ensure persistence on compromised systems and to hinder system recovery. This includes re-downloading a copy of the main script every 30 minutes and actively preventing system administrators from rebooting or modifying files on compromised systems. These system lockdown mechanisms underscore the high sophistication of the threat actors’ tactics, techniques and procedures (TTPs), particularly the group’s advanced detection-evasion and persistence capabilities. Additionally, the group installs a backdoor for continuous access to infected systems via secure shell (SSH).

Some non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network.
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
  • Ensure adequate security monitoring and detection capabilities, particularly for all external-facing services, devices and ports.
  • Employ complex passwords for edge devices and staff accounts to mitigate against brute force and other password-focused cyber attacks.

Our cyber word(s) of the week: Internet-of-Things (IoT)

(Source: Sibylline)

 

23 Sep 24. Kromek selected for UK Government Radiological Nuclear Detection Framework. Kromek (AIM: KMK), a leading developer of radiation and bio-detection technology solutions for the advanced imaging and CBRN detection segments, ishas been selected as a supplier under the UK Government’s Radiological Nuclear Detection Framework (the “Framework”) for the procurement of radiological nuclear (“RN”) detection equipment and supporting services for the Home Office. The Framework was established to co-ordinate the RN detection procurement requirements and capabilities of the Home Office, Counter Terrorism Police and other public bodies to support Home Office strategic aims and to deliver enhancements to the UK’s end-to-end system for domestic nuclear security. Kromek applied for three of the four Framework categories, covering the supply of handheld, wearable and large volume static radiation detectors, and was successfully approved and awarded a Framework contract. Accordingly, Kromek is pre-qualified to be selected for orders in these categories, which over the four-year term of the Framework have a combined maximum procurement value of £84m. The Group will provide further updates as and when there is progress in respect of any contracts within these three Framework categories.

Arnab Basu, CEO of Kromek, said: “We are delighted to have become one of the few companies approved for the supply of radiological nuclear detection equipment under this important Home Office initiative. We have been providing our detectors to the UK government for several years and it is great to see the continued expansion of programmes that will enhance the UK’s protection against radiological threats. Alongside our recent selection under the UK Government Resilience Framework for supplying emergency services operators and our contract award from the Ministry of Defence, we are experiencing excellent momentum in this area of our business, and we look forward to reporting on further progress.”

 

—————————————————————————————————————————————————————————————————————————————————————————————————————————————

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

 

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013

———————————————————————————————————————————————————————————————————————————————————————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

September 20, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

———————————————————————————————————————–

16 Sep 24. Asia-Pacific: Newly revealed operation points to espionage risks from Chinese state-backed groups. On 14 September, the cybersecurity company Cybereason reported on an ongoing Chinese state-sponsored cyber espionage campaign targeting the academic, government and manufacturing sectors in India, Japan and Taiwan. The campaign is associated with a Chinese state-sponsored group called ‘Earth Kasha’, which is likely related to another state-sponsored group, ‘APT10’. This assessment is based on similarities in their tactics, techniques and procedures (TTPs). Earth Kasha reportedly first gained access to targeted systems in 2022 via software vulnerabilities and spear phishing messages, highlighting the group’s ability to maintain a prolonged presence on compromised systems. Additionally, the threat actors deploy a new backdoor to maintain persistence and to conduct post-exploitation activities, including collecting sensitive system data. Chinese state-sponsored groups routinely conduct cyber espionage operations against perceived adversaries to bolster their economic and security posture. We assess that Earth Kasha will likely attempt to move laterally within compromised networks in follow-on attacks, heightening espionage risks for various sectors. (Source: Sibylline)

 

18 Sep 24. L3Harris Technologies (NYSE:LHX) has met a key spectrum dominance milestone by initiating production of its Viper Shield™ all-digital electronic warfare (EW) suite for F-16 fighter jets. The company will be providing the advanced capability to F-16 fleets in six countries.

“Equipping aircrews and commanders with situational awareness about the electronic landscape gives them the ability to identify, locate and counter threats at the speed of relevance,” said Ed Zoiss, President, Space and Airborne Systems, L3Harris. “We are proud of the Viper Shield technology our engineers developed and the fact that it serves as the only advanced electronic warfare solution that is funded and in active production for international F-16 partners. The system’s small 3U form factor enables installation in multiple F-16 block configurations.”

L3Harris is actively engaged in discussions with other U.S. allies and partner nations to deliver its advanced EW capabilities. The Viper Shield system provides two installation options for existing or upgraded F-16 configurations: integrated within the aircraft or as an external pod with the same EW system hardware. This flexible approach uses software-defined technology to enhance the offensive and defensive capabilities of F-16 Block 70/72 aircraft. By design, Viper Shield is engineered to allow for future capability upgrades, ensuring it can counter evolving threats. (Source: ASD Network)

 

19 Sept 24. US-Taiwan: Botnet takedown points to elevated security risks from Chinese state-sponsored groups. On 18 September, the cyber security company Lumen reported that the Chinese state-sponsored group ‘Flax Typhoon’ developed a multi-tiered botnet (‘Raptor Train’) to target Taiwan and the US; it has been in use since at least 2020. Flax Typhoon exploited several software vulnerabilities to infiltrate Internet-of-Things (IoT) devices to create Raptor Train; this was until US security agencies dismantled the botnet in mid-September. Raptor Train comprised around 260,000 devices before takedown, highlighting the scale and sophistication of this operation. The botnet’s first tier primarily included IoT devices, while the second and third tier operated the command-and-control (C2) infrastructure. Notably, Flax Typhoon deployed the ‘Nosedive’ payload on some tier-one devices to obtain disruptive capabilities for potential future attacks. However, reports indicated no disruptive activity. (Source: Sibylline)

 

16 Sept 24.  Weather Forecasts. An artist’s rendering of the UK’s forthcoming Skynet-6A military communications satellite. The MOD has commissioned work to ensure that the ground infrastructure supporting this satellite is resistant to rain fade.

The United Kingdom is moving ever closer to the introduction of its Skynet-6A military communications satellite with ongoing propagation surveys to support the new spacecraft.

Several British military communications satellites support the UK’s armed forces and the country’s Ministry of Defence (MOD). These spacecraft include Skynet-4C which carries X-band (7.9-8.4 gigahertz/GHz uplink/7.25-7.75GHz downlink) and Ultra High Frequency (UHF: 305-315 Megahertz/MHz uplink/250-260MHz downlink) traffic. Skynet-4C is supplemented by three additional satellites in the Skynet-4 constellation: Skynet-E/F carry C-band (5.925-6.425GHz uplink/3.7-4.2GHz downlink) traffic in addition to X-band and UHF links. The Skynet-5 constellation, which superseded Skynet-4, comprises four satellites (Skynet-5A/B/C/D) all handling X-band and UHF traffic. The Skynet-5 constellation also carries Ku-band (14GHz uplink/10.9-12.75GHz downlink) traffic.

Skynet-6A

Airbus received a contract from the MOD to provide the next member of the Skynet family, Skynet-6A, in 2020 with the satellite scheduled for launch in 2025. Alongside the new satellite, the contract covers extensive improvements to the ground infrastructure the Skynet constellations depend on. A key element of introducing Skynet-6A into service is ensuring that existing SATCOM ground stations can support the satellite. This work includes ensuring that rain fade disruption to the satellite’s Ka-band (26.5-40GHz uplink/18-20GHz downlink) provision is minimised.

Rain fade is a phenomenon that can affect radio signals above frequencies of circa eleven gigahertz. Rain, snow, sleet, ice and other physical contaminants in Earth’s atmosphere can absorb some of the energy of radio transmissions at these frequencies and above. This absorption can cause potential losses in signal power. The phenomena occurs because some precipitation particles are a similar size to these frequencies’ wavelengths. It is imperative that Skynet-6A ground infrastructure is managed in such a way as to reduce rain fade disruption. Anyone familiar with Britain’s weather will know that rain is a regular occurrence.

Rain Fade

In late August, Atheras Analytics won a contract to provide Ka-band propagation analysis to the UK MOD to help the ministry manage the ground stations that will support Skynet-6A. According to a press release the company will use software to analyse existing ground station sites to ascertain the extent rain fade may cause problems there. The outcome of this analysis will let the ministry plan how it can ensure continued links between ground stations and the satellites at times when rain fade may be a significant problem.

The press release continued that the company is using its Design Tool which employs a proprietary artificial intelligence-based Outage Prediction Algorithm (OPA). The OPA is applied to historic rainfall measurements at the ground stations’ location to help determine historic link availability at these sites. Through the analysis of the ground stations’ locations, and their susceptibility to rain fade, ground network design can be optimised to maximise network and service availability.

John Yates, Atheras Analytics’ managing director, told Armada that “(t)he next-generation Skynet 6 satellites will incorporate a Ka-band capability which has not existed in previous Skynet generations.” He added that this survey work commenced in July and will conclude in October. “The initial work is to assess the suitability of the existing gateway locations for supporting the planned Ka-band services. If there is any question or uncertainty about the suitability of the existing sites, the MOD has an option to extend the work to assess the suitability of other additional sites.”

Mr. Yates observed that the SATCOM sector “has entered a phase of major change in the delivery of consumer and enterprise broadband using high/very high throughput satellites … which can deliver data rates of the order of between 500 gigabits-per-second and one terabit-per-second.” One solution to these high data throughput demands is to use Ka-band frequencies despite rain fade susceptibility. Mr. Yates says that ground station architectures can be managed in such a way so that if one station is affected by rain fade, uplink and downlink services are automatically transferred to another ground station unaffected by the weather. In a country with a climate as wet as the UK managing rain fade to ensure smooth SATCOM is paramount. (Source: Armada)

 

17 Sept 24. MUOS Earns its Wings. Communications and networking for US Army airborne forces has taken a step forward following trials of a new architecture that could reduce the hardware burden for airborne forces.

The US Army revealed in late July that the 11th Airborne Division of the 2nd Airborne Infantry Brigade Combat Team (AIBCT) is the first formation in the army to deploy a push-to-talk air-to-air/air-to-ground Enroute Mission Command (EMC) capability. This network was established using L3Harris AN/PRC-158 Very/Ultra High Frequency (V/UHF: 30 megahertz/MHz to 2.5 gigahertz/GHz) multi-channel radios. In a written statement shared with Armada L3Harris described the radio as being the “backbone of this network.”

Links and waveforms supported by the AN/PRC-158 include the Single Channel Ground and Airborne Radio System, better known as SINCGARS. The SINCGARS waveform uses Very High Frequency (VHF) transmissions of 30 megahertz/MHz and 87.975MHz. Also carried by the AN/PRC-158 is the Warrior Robust Enhanced Networking (WREN) waveform. WREN uses VHF and UHF (Ultra High Frequency: 300MHz to three gigahertz) transmissions. Offering bandwidths of between 50 kilohertz to ten megahertz, WREN gives position location information and handles voice traffic, according to the US Army. The waveform is provided in two configurations: WREN TSM enables point-to-point communications at ranges of up to five kilometres (3.1 miles). WREN-NB is a narrowband waveform for use in electromagnetically contested and congested environments. Both waveforms carry traffic across the Integrated Tactical Network discussed in more detail below.

KEN and DAN

The US Army article announcing the news stated that, until now, EMC had needed Key Leader Enroute Node (KEN) and Dependent Airborne Node (DAN) teams to facilitate these communications. The article continued that KEN and DAN teams would be drawn from signals formations outside the army’s AIBCTs. Signallers would need to be accommodated on aircraft supporting the mission, potentially sacrificing space for additional airborne forces and their kit. KEN nodes provide broadband backhaul data and intra-aircraft voice and data communications. These nodes also provide secure video teleconferencing and air-to-air/air-to-ground task force and combatant commander communications. DAN nodes are employed by subordinate commanders for inflight communications to connect with superiors who are using the KEN node.

The adoption of the AN/PRC-158 for these tasks removes the need for KEN and DAN nodes to support the AIBCTs during Joint Forcible Entry Operations (JFEO). The radios connect with standard Satellite Communications (SATCOM) systems used by US Air Force Boeing C-17A Globemaster-III airlifters. C-17As form a key part of the JFEO airborne capability. For example, AN/PRC-158 radios can use the Mobile User Objective System (MUOS) satellite constellation. The MUOS constellation provides UHF (240MHz to 270MHz) narrowband SATCOM. Open sources say that MUOS facilitates voice and data communications at speeds of up to 384 kilobits-per-second. Communications with the MUOS constellation is via the Wideband Code Division Multiple Access (WCDMA) waveform carried by the AN/PRC-158.

The US Army report stated that the AN/PRC-158 radios used the force’s Integrated Tactical Network (ITN) during the EMC experiments. The ITN is a deployable network handling non-classified traffic using military radios and civilian devices, latter including smartphones and tablets. Moving non-classified traffic onto the ITN frees space on other tactical communications networks for secure traffic. As it handles unclassified traffic, ITN can connect US Army units with allied forces during coalition operations.

The new Enroute Mission Command capability was tested during a series of JFEO exercises held recently in Alaska, California and Hawaii over the Pacific Ocean. The architecture was also trialled during a JFEO exercise which commenced in Alaska and finished in Thailand. The adoption of the AN/PRC-158 to support the EMC represents a qualitative enhancement compared to the erstwhile KEN and DAN nodes. Using these transceivers with the army’s ITN shows how this innovative network is finding additional uses beyond the land environment. (Source: Armada)

 

18 Sept 24. September Radio Roundup. Viasat developed the Secure Wearable Hub to equip dismounted troops with a particular emphasis on special forces soldiers. The system could become available for procurement by the end of the year.

Viasat Unveils SWH

In late July Viasat announced the introduction of its Secure Wireless Hub (SWH). A company press release revealed that the SWH is a wearable, tactical gateway for use by dismounted troops. The Secure Wireless Hub has been developed as part of a “multi-phase effort” involving the US Special Operations Command. This effort is identifying and developing advanced communications for mobile ground forces. One of the capabilities offered by the SWH is a secure virtual private network “allowing the use of multiple transports and waveforms across a range of devices to provide resilient connectivity and safely share critical battlefield information” the press release noted. The Secure Wireless Hub lets users connect with cellular and wi-fi/bluetooth services. Viasat told Armada in a written statement that the SWH is “a modular system that was designed specifically to integrate Type-1 encryption handheld tactical radios and connects to non-Type-1 MANET (Mobile Ad Hoc Networking) and other IP (Internet Protocol) based radios.” The company said that “a single management app on an end user device easily configures peripheral devices.” Moreover, “LTE (Long Term Evolution) and wi-fi/bluetooth modules that can be added, or removed, based on the user’s needs.” Regarding ongoing developments “the SWH was designed to meet the needs of special operations forces and is currently being evaluated by both conventional and unconventional units.” The Secure Wireless Hub “is completing a series of user evaluations and is currently being targeted for procurement availability by the end of the calendar year.”

More T Node details

In Armada’s August Military Communications Newsletter we included an article on a new transportable fifth-generation cellular communications node equipping the US Air Force called T Node. This capability has been developed by two companies; SEMPRE and Instant Connect. Instant Connect has provided us with some additional details regarding its contribution to T Node. In a written statement, the company said it is providing an Internet Protocol (IP) platform notably mobile and desktop software applications providing “interoperable push-to-talk” communications over SEMPRE’s network. The software also provides “seamless integration with other voice systems like radios and PBXs (Private Branch Exchanges) with everything running over the 5G network.” Instant Connect’s IP platform “links warfighters, commanders and base operations in a single integrated, transportable voice environment allowing users of radios, smart phones, tablets, computers, and other devices to communicate and achieve the mission.” In addition, Instant Connect’s software “provides a voice overlay to the popular ATAK (Android Team Awareness Kit). This lets users leverage ATAK and voice communications simultaneously from the same interface, without having to switch screens or use other devices.” Communications/transmission security protocols offered by the IP platform include FIPS 140-2 and AES-256. (Source: Armada)

 

18 Sept 24. Thales partners with Dstl and defence SMEs Catalyst and DCE to create a new hybrid testing environment for crewed and uncrewed platforms.

  • Thales, in collaboration with synthetic environment creators, Catalyst, and robotics and automation experts, Digital Concepts Engineering (DCE), are under contract from the Defence Science and Technology Laboratory (Dstl), for the research and development of open interfaces and architectures between GVA compliant crewed and uncrewed platforms.
  • A new, hybrid, test and experimentation environment (‘digital twin’) is being developed that will allow operators and researchers to plan and test new concepts, systems and architectures in both virtual and physical domains.
  • The first use (both live and virtual) of the digital twin system is planned for early 2025, operating air and ground uncrewed systems from a GVA crewed platform in a Recce-FIND role. This will also incorporate artificial intelligence and Thales’ DigitalCrew, aiming to improve effective use of unscrewed systems and reduce the burden of key decision makers on the battlefield, leading the way in bridging the gap between crewed and uncrewed systems.
  • The digital twin environment aims to enable integration of virtual and live systems from dispersed locations, better enabling early system of systems integration and testing at system and sub-system level (e.g. Hardware in the Loop).

Thales in the UK, under contract from Dstl, is leading the way with crewed-uncrewed integration, developing a system of systems digital twin environment for experimentation on the operation of Land Robotics and Autonomous Systems (RAS). Research is ongoing for the project entitled, ‘Land Robotics and Autonomous Systems Ecosystem of Digital Twin Development and Experimentation’ (Land RAS EDT), and the consortium of Thales, Catalyst and DCE are making great progress towards final live trials and demonstrations which are scheduled for early 2025.

Land RAS EDT is a hybrid ecosystem, allowing operators and researchers to utilise a common architecture and interface to plan and experiment in both the virtual and physical domain. The platform enables the operation of virtual and physical systems through one interface, which allows for endless experimentation opportunities. The development of Land RAS EDT will initially be designed to enable the exploration of RAS in the beyond visual line of sight (BVLOS) reconnaissance role. It will also provide a platform for better understanding the contribution of RAS to the Army’s intent to fight by recce-strike at all levels.

Ultimately, the aim of the programme is to enable early experimentation in the virtual domain and allow for more effective multi-domain integration through the evolution and extension of existing open architectures and research in the combination of crewed and uncrewed systems. This will reduce the risks, costs and timescales associated with the introduction of new systems and concepts into the armed forces through embracing spiral development. For this project, the facility will incorporate Thales’ DigitalCrew and other AI enablers to better understand system effectiveness of such platforms and the benefits that they provide through a reduction of cognitive burden on the operator.

Catalyst has deep expertise in electronic architecture, synthetic environment modelling, simulation and experimentation. This expertise has been used to create a synthetic environment and digital twins of all physical platforms. DCE specialise in open architectures, developing technologies for robotic and autonomous systems, and is extending its Marionette control system for command and control (C2) of the project’s uncrewed ground vehicles. Thales, Catalyst and DCE are working to develop a system designed to include various crewed and uncrewed vehicles for multi-domain experimentation and testing.

Land RAS EDT consists of a physical mobile crewed platform, running a generic vehicle architecture (GVA) equipped with in service and next generation Thales optronics sensors. Through the use of mission planning software, the mobile crewed platform (or any accredited user on the network) can control and view the movement of the uncrewed, autonomous vehicles. All systems and vehicles have a “digital twin” in the virtual world. Thales and partners’ open architecture experience will allow Land RAS EDT to inform both new and existing programmes, improving efficiencies for defence procurement and, subsequently, reducing the cost and time of physical trials. Furthermore, Thales offers a platform, sensor, and software agnostic approach to integration, boosting the cost efficiencies associated with the research programme and final experimentation system.

“Robotic and Autonomous Systems are transforming warfare, but are rapidly evolving. The open and modular architectures developed in this project should better enable the Army to rapidly adapt and integrate emerging RAS technologies with in service platforms such as Ajax at the pace of relevance. This, together with the use of digital twin environments, should provide a critical enabler to reduce risks, costs and timescales associated with integration and spiral development of RAS capability into the force.”  – Guy Powell, Principal Advisor – Land Autonomy, Dstl

The world of uncrewed vehicles is rapidly evolving with many systems moving away from traditional, crewed fleets. Land RAS EDT enables the customer and end users to build on the vast open architecture experience of Thales and its partners, Catalyst and DCE, to extend exploration into autonomous systems and robotics. By incorporating artificial intelligence and Thales’ DigitalCrew, Land RAS EDT reduces the burden on key decision makers on the battlefield, leading the way in bridging the gap between crewed and uncrewed systems. Thales’ DigitalCrew will be deployed on UGVs, UAVs and command vehicles to autonomously detect and classify objects of interest. This information will be shared with the wider network to create a Common Operating Picture (COP).

“In recent times, the growing significance of autonomy and artificial intelligence has become increasingly apparent, reshaping the landscape of security strategies worldwide. This important research partnership between Dstl, Thales and multiple SMEs will advance the UKs understanding of Digital Twins and open architectures and explore how crewed, optionally crewed and uncrewed systems can co-exist in complex, multi-domain architectures.” Stephen McCann, Managing Director, Thales in the UK.

 

28 Aug 24. CRFS, a leading innovator in radio frequency (RF) technology, won the Army Technology Excellence Awards 2024. The award celebrates groundbreaking achievements and innovations in the defense industry, recognizing companies that have made significant technological advancements and set new standards.

CRFS won the award thanks to the innovative design and exceptional RF performance of its RFeye Node 100-18 LW sensor: a breakthrough in UAV sensing technology.

A NATO member requested that CRFS design this product to enable effective signal management and signals intelligence operations in a conflict zone. The end user already used the TRL-9 RFeye Node 100-18, which delivers transformative capability through its advanced RF performance. However, this sensor was not designed with smaller unmanned system integration in mind, so CRFS rapidly designed the same capability into a much-reduced form factor with no loss of performance.

“On receiving this urgent requirement, our engineering team worked hard to develop a sensor that not only meets the rigorous demands of our military customer but also excels in the harshest environmental conditions. The company’s ability to quickly deliver this hugely valuable tool for modern military forces in record time is very impressive,” said Matt Hunt, VP of Global Sales.

The RFeye Node 100-18 LW’s low Size, Weight, and Power (SWaP) enhances UAV mission endurance, enabling extended electronic warfare and ISR missions. It contains an upgraded GNSS chipset supporting multiple bands to help maintain operational effectiveness in GNSS-disrupted environments. Also, its advanced RF performance means it can monitor a wide range of signal types, including low-power, low probability of intercept (LPI), and low probability of detection (LD) signals.

One key design feature, particularly important for unmanned systems with limited bandwidth at range, is the sensor’s in-built edge processing, which reduces the burden of backhauling data, allowing it to deliver clear and accurate RF data for spectrum intelligence.

“The fact that the RFeye Node 100-18 LW weighs less than 2kg, along with its superior phase noise, channel re-tune time, noise figure, and spurious-free dynamic range, underscores its advanced design and engineering. Although it’s an ideal solution for small to large UAV platforms, the sensor can be integrated into any unmanned platform—a UGV or a USV,” said Tina Ross, Global Awards Manager.

CRFS’ achievement in winning the Innovation Award at the 2024 Army Technology Excellence Awards demonstrates the company’s commitment to pushing the boundaries of RF technology and delivering cutting-edge solutions that meet the evolving needs of NATO members.

 

17 Sept 24. Mattermost extends Microsoft Teams and Microsoft 365 platform to accelerate mission-critical workflows in defense, government, and vital services.

The generally available Mattermost for Microsoft Teams integration empowers critical infrastructure organizations to integrate people, processes, and technology across the organization, accelerating operational efficiency and bolstering cyber resilience.

Mattermost, the leading secure, self-hosted collaboration platform for critical infrastructure, today announced the availability of Mattermost for Microsoft Teams, a flexible interoperability framework to flow information and communications across enterprise-wide Microsoft 365 users and technical and operational organizations in Mattermost.

For national security, public safety, and critical infrastructure organizations, Mattermost supplements “Enterprise IT” systems such as Microsoft Teams with “Mission IT” workflows vital to cyber resilience, including out-of-band incident response, ChatOps in segregated networks, Red Team and penetration testing workflows, and emergency communications.

Microsoft Teams and the entire Microsoft 365 suite are essential tools for communication and collaboration for many enterprise organizations. However, technical operators need integrated tool chains to surface mission-critical information, solve problems, and protect their digital landscape. Without access to these tools, data can leak into insecure channels, and workflows become impossible to standardize.

With Mattermost and Teams, technical operators gain access to webhooks, slash commands, custom plugins, and workflow orchestration — all without being disconnected from the broader organization. Users log in where they do their best work, but can still communicate with each other.

The benefits of implementing Mattermost for Microsoft Teams include:

  • Maximize your Microsoft investment for technical and operating teams: Combine Mattermost’s out-of-band incident response, emergency communications, and security operation workflows with Microsoft Teams’ collaboration tools to maintain enterprise-wide communication, while securely flowing messages from Teams into Mattermost, optimizing overall collaboration efficiency.
  • Accelerate situation awareness in mission-critical environments: Ensure critical information flows seamlessly when you configure integration between Microsoft Teams and Mattermost, enabling faster response times and improved decision-making in mission-critical environments.
  • Interoperate while meeting advanced and custom security and compliance needs for critical infrastructure: Enable mission-critical environments in Mattermost to securely ingest and transform data from external sources through continuous monitoring, filtering, and alerting.

Mattermost for Microsoft Teams is available now as part of the latest Mattermost platform release, which includes additional investments in the platform’s scalability, reliability, and security for mission-critical work. These enhancements include the introduction of a reliability dashboard, metrics plugin, health check plugin, and improved load testing tools that allow Mattermost customers to scale their environments with up to 100,000 active users.

“This latest iteration of Mattermost represents the next stage in our commitment to building a scalable, resilient collaboration platform for the teams that manage the world’s most essential infrastructure, says Chen Lim, VP of Product at Mattermost, “By enabling Mattermost customers to scale their workspace, connect to business-critical tools like Microsoft Teams, and improve their own visibility into the health and security of their Mattermost environments, we’re helping them achieve more effective workflows now and in the future.”

The Mattermost team continues to develop and extend cross-platform interoperability with feedback from the Mattermost user community. Existing Mattermost customers can contact their account teams to request to join the joint-development program for this new framework.

To learn more about the latest version of Mattermost for Microsoft Teams, please visit mattermost.com/solutions/mattermost-for-microsoft-teams/

About Mattermost

Mattermost is the leading collaboration platform for mission-critical work. We serve national security, government, and critical infrastructure enterprises, from the U.S. Department of Defense, to global tech giants, to utilities, banks, and other vital services. We accelerate out-of-band incident response, DevSecOps workflow, mission operations, and self-sovereign collaboration to bolster the focus, adaptability, and resilience of the world’s most important organizations.

Our enterprise software and single-tenant SaaS platforms are built to meet the custom needs of rigorous and complex environments while offering a secure and unrivaled collaboration experience across web, desktop, and mobile with channel-based messaging, file sharing, audio calling and screen share, with integrated tooling, workflow automation and AI assistance.

Mattermost is developed on an open core platform vetted by the world’s leading security organizations, and co-built with over 4,000 open source project contributors who’ve provided over 30,000 code improvements towards our shared vision of accelerating the world’s mission-critical work.  For more information visit mattermost.com.

 

16 Sept 24. USAF clears Viper EW suite for live flight tests. US Air Force (USAF) programme leaders have given the green light to begin live flight tests of Northrop Grumman’s AN/ALQ-257 Integrated Viper Electronic Warfare Suite (IVEWS), after the system cleared service-led pre-flight system testing and integration efforts.

The pre-flight test and integration process, conducted at the air service’s Joint Preflight Integration of Munitions and Electronic Sensors (J-PRIMES) facility at Eglin Air Force Base in Florida, consisted of the IVEWS being “subjected to accurate representations of complex radio frequency (RF) spectrum threats”, according to USAF programme officials.

The system’s completion of the pre-flight evaluation and system integration process at J-PRIMES was “the culmination of three years of extensive US government IVEWS system-level testing”, said USAF Colonel Michael Rigoni, director of F-16 International Electronic Warfare Systems.

“I am optimistic the upcoming operational assessment flight-test events will yield positive results and look forward to seeing this important capability continue to mature,” Col Rigoni said in an August service statement.

First operational flights of IVEWS-equipped F-16s had been slated for the end of the first quarter of fiscal year (FY) 2024. Despite the recent completion of the J-PRIMES process, it remains unclear when those live flight tests will take place.

Prior to the J-PRIMES process, the IVEWS underwent system evaluation during several Integration Demonstrations and Applications Lab (IDAL) events culminating in Laboratory Intelligent Validated Emulator (LIVE) closed-loop testing at Hill Air Force Base at the end of 2023. The system also underwent initial live flight tests aboard a F-16 surrogate aircraft during the air service’s ‘Northern Lightening’ military exercise in 2021, according to the USAF statement. (Source: Janes)

 

16 Sept 24. Kromek’s D5 RIID selected by the UK Ministry of Defence. Kromek, the designer and manufacturer of radiological and biological detectors, based in Sedgefield, Co. Durham, has won a £2m contract from the UK Ministry of Defence (MOD) for its D5 RIID and associated accessories.

The D5 RIID is a small, light, wearable Radioisotope Identification Device (RIID) with an expansive radioisotope library, an ultra low false alarm rate and a networked capability to allow for reachback to a command centre.  It can be hand-held, body-worn or mounted on an uncrewed platform and remotely operated, and has exceptional endurance.

The UK MOD contract also includes the external Alpha Beta probe, which attaches to the D5 RIID and allows the device to also detect Alpha and Beta radiation. This makes the D5 RIID the most versatile detector of its size.

The D5 RIID combines small form factor with powerful radiometric performance and enhanced sensitivity at a medium resolution of less than 4% for accurate adjudication. Fast to start and identifies within seconds, the high sensitivity of the device means that any source, even very low activity sources, can be accurately detected, with very low false alarm rates. You will have data you can rely on to make those important decisions.

Commenting on the win, Craig Duff, Kromek’s Commercial Director (Nuclear), said “This major order from the UK MoD is a national endorsement of the groundbreaking capability of the D5 RIID. Coming so soon after the recent DIMS [Detection, Identification and Monitoring Equipment Uplift] contract award on the UK’s National Resilience Framework from Merseyside Fire and Rescue Services, this reflects a growing confidence in the capability of Kromek’s suite of radiation detection products.”

Arnab Basu, CEO of Kromek, said: “We are delighted to have won this important contract from the UK MOD, which is a significant strategic customer for Kromek. That it was awarded after a rigorous tender process provides excellent endorsement of the strength of our solution. It is also great validation to receive this key order for our Alpha Beta probe so soon after its launch at the end of last year. With the Alpha Beta probe upgrade, our D5 RIID is one of the most versatile handheld radiation detectors available today. We are looking forward to delivering this contract and supporting UK national defence efforts and to continuing to strengthen our relationship with this important customer.”

Kromek will be displaying the D5 RIID alongside its other hand-held and static radiation detectors at the Emergency Services Show at the NEC in Birmingham on 18-19 September (Stand H154) and also at the International Security Expo at London Olympia on 24-25 September (Counter Threat Pavilion).

 

13 Sept 24. Cyber Update Key points.

  • A cyber operation targeting Taiwan’s military sector points to the elevated espionage risks stemming from a new Chinese-speaking group, ‘TIDRONE’ (see Sibylline Cyber Daily Analytical Update – 9 September 2024 and our Technical analysis below).
  • A new remote access trojan (RAT) is targeting the Colombian financial sector, underscoring the increased financial risks stemming from the cyber criminal group ‘BlindEagle’ (see Sibylline Cyber Daily Analytical Update – 10 September 2024).
  • The exploitation of vulnerable network edge devices highlights the elevated security risks stemming from the ‘Quad7’ botnet (see Sibylline Cyber Daily Analytical Update – 11 September 2024 and our Technical analysis below).
  • A new cyber operation manipulating search engine results will elevate the financial and reputational risks from Chinese cyber criminal groups (see Sibylline Cyber Daily Analytical Update – 12 September 2024).
  • The continuation of phishing operations targeting software developers will sustain elevated espionage risks stemming from the North Korean state-sponsored group ‘Lazarus.’

Technical analysis of weekly stories

A new Chinese-speaking group (TIDRONE) is targeting military-related industries in Taiwan in an ongoing cyber espionage operation. Although TIDRONE started targeting Taiwanese organisations in March, it is suspected that the group likely infiltrated targeted organisations via the software supply chain at an earlier stage. TIDRONE typically uses enterprise resource planning (ERP) systems and remote desktop software to deploy malware (including ‘CXCLNT’ and ‘CLNTEND’) on compromised systems. This enables the group to collect sensitive information, escalate privileges and evade security mechanisms. Notably, the infected organisations use the same ERP vendor, suggesting that TIDRONE has possibly infiltrated victims via supply chain attacks. The group has used several versions of malware loaders throughout this operation, with the latest variant merging two payloads into a single encrypted payload. This highlights the rapid evolution of TIDRONE’s tactics, techniques and procedures (TTPs), as well as its sophistication (due to the new loader’s anti-detection capabilities). The payload code enables CXCLNT and CLNTEND to be deployed in various file formats, further pointing to the actor’s sophistication and adaptability. Additionally, the payloads are stored in the system’s memory as an additional detection evasion mechanism.

The Quad7 botnet is exploiting software vulnerabilities to obtain access to global network edge devices in an ongoing cyber operation. The botnet comprises five device clusters, and includes compromised internet-facing ports for multiple small office/home office (SOHO) devices, virtual private network (VPN) appliances and wireless routers. Although the full scope of this campaign is unclear at present, actors are exploiting Quad7 to conduct brute force attacks on Microsoft365 accounts, as well as internet-exposed services such as VPNs, telnet and secure shell (SSH) protocols. Notably, Quad7 adopted the KCP protocol to communicate with actor-controlled infrastructure to achieve better latency and stealth due to the protocol’s encryption mechanisms. This is indicative of the adaptability of Quad7’s TTPs, as well as its gravitation towards more sophisticated tools. Additionally, the threat actors used a new backdoor (‘UPDTAE’) to control infected devices remotely while avoiding detection from internet scans. We assess there is a realistic possibility that Quad7 is currently in a testing phase due to the increasing number of infected devices in each cluster and the threat actors’ use of new TTPs.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network.
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
  • Ensure adequate security monitoring and detection capabilities, particularly for all external-facing services, devices and ports.
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.
  • Employ complex passwords for edge devices and staff accounts to mitigate against brute force and other password-focused cyber attacks.

Our cyber word(s) of the week: Brute force attack. (Source: Sibylline)

 

13 Sep 24. Global: Phishing operations will sustain espionage risks from North Korean state-sponsored groups. On 10 September, the software company ReversingLabs disclosed that the North Korean state-sponsored group ‘Lazarus’ is targeting software developers in an ongoing cyber campaign. Lazarus sends phishing messages to potential victims on the platform LinkedIn, impersonating staff from a financial institution. The actors then trick victims into clicking on a malicious link purporting to be a coding skills test for a job interview. Notably, the actors create urgency to ensure that the malware is executed by stating that the test can only be completed within a limited timeframe. Malicious code subsequently deploys various backdoor and information-stealing malware, likely to collect sensitive data and maintain prolonged presence on compromised systems. This operation is likely a continuation of a previous Lazarus campaign which has targeted software developers since August 2023. We assess that this campaign sustains espionage risks for global developers. (Source: Sibylline)

 

13 Sept 24. DOD Hosts International Exchange on Shaping Cybersecurity Workforce.

A senior Defense Department official hosted government officials, academics and entrepreneurs from Indonesia for a discussion on how the Pentagon is aligning its cyber workforce strategy to meet the demands of a rapidly evolving domain.

Patrick Johnson, director of the DOD Chief Information Officer’s Workforce Innovation Directorate, provided an in-depth overview of the Pentagon’s cyber workforce framework and vision for recruiting and retaining top talent to meet the demands of the future.

The exchange was held as part of the State Department’s International Visitor Leadership Program, or IVLP, which aims to develop lasting relationships between emerging foreign leaders and their counterparts in the United States. Next week, representatives from DOD CIO will host a group from Japan who are in the U.S. to discuss ways to enhance cybersecurity in Japan.

“In the cyber arena, the human being is the weapon system,” Johnson said, underscoring the critical importance of securing the global networks that permeate daily life in both the public and private sectors.

He said the nation’s defenders must increasingly account for both the kinetic and nonkinetic effects that shape the modern battlefield. He noted, for example, that a nefarious cyber actor could single-handedly take down the world’s most advanced fighter aircraft without firing a single shot.

In 2023, DOD published its strategy to align the department’s efforts to identify, recruit, develop and retain a data-literate and technology-adept cyber workforce to ensure the U.S. maintains its warfighting edge.

The department has also laid out its framework to shape the cyber workforce through personnel qualification, academic outreach and professional development; and it has implemented the Cyber Excepted Service, which taps into enhanced recruitment and retention authorities.

But the challenges presented by the rapidly changing cyber domain are not unique to DOD, as this week’s discussion highlighted.

The exchange provided an opportunity for the participants to discuss shared challenges that span the public and private sectors in both the U.S. and Indonesia.

The participants discussed common bureaucratic hurdles in in both countries that challenge public sector recruiters, who often battle lengthy hiring processes and higher salaries offered by private employers.

They also discussed the changing metrics used to gauge candidate qualifications for cyber jobs.

Al Akbar Rahmadillah, founder of Sobat Cyber Indonesia, highlighted the imperative to tap into practical qualifications gained through informal, hands-on training.

That sentiment is not unique to Indonesia’s private sector. Johnson said DOD is increasingly looking to leverage performance-based qualifications, rather than formal education.

Participants also mentioned the impact of competition stemming from Indonesia’s large population of young professionals has on recruiting cyber talent.

That back-and-forth exchange is precisely the level of dialogue the IVLP is designed to foster.

Since 1940, the IVLP has hosted more than 225,000 participants for exchanges focused on topics ranging from young people and women’s leadership to promoting cybersecurity and combatting transnational crime.

Alfian Linux, chief executive officer of Xtend Indonesia, a private sector technology firm, said his experience participating has been invaluable.

“Everyone knows that the giant companies and the technology before has come from the United States.,” he said, adding that he hopes the IVLP discussions will open doors for Indonesian firms to work effectively alongside U.S. firms.

But Johnson, who has hosted an IVLP cohort from Iraq as part of the program, said the U.S. also benefits immensely from the exchange.

“In the cyber domain, the talent shortage is global,” he said, adding that every country has information technology infrastructure that must be defended.

Johnson said it is incumbent on countries to learn from one another to overcome pressing challenges.

“I think we need to take it seriously take that opportunity to talk to smart people from outside our own little sphere,” he said. “The world has a lot to offer.” (Source: U.S. DoD)

 

13 Sept 24. Land Forces 2024: L3Harris to establish Australian radio support facility. L3Harris Technologies is set to open its first regional support centre (RSC) outside the United States as it gears up to provide maintenance, repair, and overhaul (MRO) services for tactical communication devices in operation by Australian, international, and US forces across the Indo-Pacific.

Speaking to Janes on 12 September at the Land Forces 2024 exhibition in Melbourne, Australia, company executives confirmed the RSC will be located at the company’s existing Integration and Sustainment Centre at Pinkenba near Brisbane airport in the first quarter of 2025.

Initially, the RSC will support Australian and New Zealand defence forces, negating any requirement to ship unserviceable radios back to L3Harris’s facility in Rochester, New York, where MRO traditionally takes place.

Instead, radios will be shipped directly to the Brisbane facility for repair, reducing the amount of time it takes to fix and return a radio from six months to just one month, the company said.

According to L3Harris Australia’s managing director Andrew Rushbrook, the company is also looking to expand the RSC’s remit to include MRO of L3Harris radios used by international customers across the wider Indo-Pacific region. These include Japan, Mongolia, the Philippines, and Taiwan, he said.

A third phase will also see the RSC providing MRO services for US forces deployed across the Indo-Pacific. In August L3Harris conducted a ‘fly-in/fly-out proof of principle’ with the US Marine Corps (USMC) to repair four of the USMC AN/PRC-117G manpack radios.

The Marine Rotational Force-Darwin at Robertson Barracks, Northern Territory, took part in the proof of principle to confirm “advantages of in-region equipment repairs”, according to the USMC. (Source: Janes)

————————————————————————————————————————

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

 

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

————————————————————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

September 13, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

———————————————————————————————————————————————————————————————————————————————————————————————————————————

11 Sept 24. Comtech Launches New Digital Common Ground Modem Product Line for DoD and Coalition Customers. U.S. sovereign designed DCG modems enable warfighters and military assets to easily roam across commercial and purpose-built networks.

Comtech (NASDAQ: CMTL) (“the Company”), a global technology leader, today announced the launch of the Company’s new Digital Common Ground (“DCG”) portfolio of modems. Comtech’s DCG product line is designed to enable the U.S. Department of Defense (“DoD”) and coalition partners to move to digitized, hybrid satellite network architectures, which will bring forward a new era of secure, resilient, interoperable, and ubiquitous connectivity across all domains.

Built on the proven success of Comtech’s extensive satellite communications (“SATCOM”) modem portfolio, the Company’s DCG modems are designed and built at Comtech’s headquarters in Chandler, AZ and support commercial and government satellite operations on a single common platform that can be reconfigured rapidly to address changing operational needs. Comtech’s DCG portfolio is also designed to evolve over time to incorporate new capabilities and keep pace with the upgrade cycle of new innovative satellite constellations-significantly reducing overall lifecycle costs for customers while also delivering industry leading performance and efficiency.

“As a leading provider of U.S. sovereign developed and manufactured communications solutions, Comtech’s software defined DCG product line provides the building blocks needed to enable the trusted, all-digital communications systems of the future,” said John Ratigan, Interim CEO of Comtech. “DCG represents a transition away from stovepipes and siloed communication systems toward an open-standard and truly flexible architecture. Comtech’s DCG product line reduces total cost of ownership for satellite operators while also enabling an all-digital, software defined infrastructure that can rapidly adapt at the speed of relevance.”

Customer Value and Operational Benefits:

  • Digital Transformation: Comtech’s DCG product line is designed to align with digital transformation and modernization initiatives to support the evolution of SATCOM infrastructures across commercial and government markets-enabling significantly enhanced flexibility, interoperability, and ease of operation while also reducing cost and removing complexity of operations.
  • Security: Comtech incorporates modern cybersecurity design principles at every level across its DCG product line-ranging from a trusted supply chain to a thoughtful software upgrade lifecycle, including in-field updates. The DCG product line also offers secure over-the-air communications through multi-stream Federal Information Protection Standards 140-3 Level 2 certified Transmission Security.
  • Superior Performance: Comtech’s DCG product line offers customers industry leading performance compared to other products available in the market today-offering multi-gigabit throughput at launch.
  • Enhanced Situational Awareness: The data-centric infrastructure of the DCG product line enables enhanced data exchange and facilitates a shared understanding of the battlespace, crucial for informed decision-making.
  • Multi-Orbit Capability & Improved Interoperability: Comtech’s DCG portfolio is one of the first product lines on the market today offering robust access to multi-orbit capabilities across commercial and purpose-built networks. The DCG product line is also one of the first to be Digital Intermediate Frequency Interoperability (“DIFI”) compliant-adhering to DoD and coalition communications standards to enable seamless information flow between services, a key tenet of Combined Joint All Domain Command and Control (“CJADC2”).
  • Waveform Flexibility: The DCG product line currently supports a variety of critical waveforms including DVB-S2X, DSSS, EBEM, and other protected waveforms. With a software defined core, Comtech’s DCG product line can easily add waveforms and integrate new capabilities tailored to specific mission needs.

Availability: Comtech is currently accepting orders for its DCG product line. For more information, please visit our webpage: https://comtech.com/capability/dcgmodems/

 

11 Sept 24. BIS Proposes Reporting Requirements for the Development of Advanced Artificial Intelligence Models and Computing Clusters – (89 Fed. Reg. 73612) – The U.S. Department of Commerce’s Bureau of Industry and Security (BIS) has proposed a rule that would amend its Industrial Base Surveys—Data Collections regulations by establishing reporting requirements for the development of advanced artificial intelligence (AI) models and computing clusters under the Executive order of October 30, 2023, “Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence.” Section 4.2(a)(i) of Executive Order 14110 of October 30, 2023, “Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence” (E.O. 14110), directs the Secretary of Commerce to require companies developing, or demonstrating an intent to develop, potential dual-use foundation AI models to provide certain information to the Federal Government on an ongoing basis. Additionally, section 4.2(a)(ii) of E.O. 14110 directs the Secretary of Commerce to require companies, individuals, or other organizations or entities that acquire, develop, or possess a potential large-scale computing cluster to report any such acquisition, development, or possession, including the existence and location of these clusters and the amount of total computing power available in each cluster. As defined under E.O. 14110, a “dual-use foundation model” is “trained on broad data; generally uses self-supervision; contains at least tens of bns of parameters; is applicable across a wide range of contexts; and that exhibits, or could be easily modified to exhibit, high levels of performance at tasks that pose a serious risk to security, national economic security, national public health or safety, or any combination of those matters.” The reporting requirements proposed in this regulation are intended to apply to dual-use foundation models that meet technical conditions issued by the Department. The Department expects to update the technical conditions, based on technological advancements, as necessary and appropriate, as directed by section 4.2(b) of E.O. 14110. Interested persons have until October 11, 2024, to submit comments. (Source: glstrade.com)

 

10 Sep 24. Viasat Receives Government Certification of IFF Test Set and IFF Certification Tools.

  • Viasat’s VRG-1000 and VRG certification tools can reduce IFF certification testing times from weeks to hours

Viasat, Inc. (NASDAQ: VSAT), a global leader in satellite communications, today announced that its Viasat Radio Frequency Generator (VRG)-1000 solution has been recertified by the Department of Defense AIMS program office.

Initially certified in 2017, the VRG-1000 has expanded its capabilities and is the only AIMS certified real-time, Identify Friend or Foe (IFF) RF environment generator.

The Viasat VRG-1000 is a commercial IFF testing capability that is highly specialized for testing military and commercial IFF systems. IFF systems are used in nearly all aircraft worldwide for reliable navigation and aircraft identification.

The VRG-1000 is unique in its ability to model complex flight environments at RF, making it easier for IFF manufacturers or integrators to test the effectiveness of their systems. The VRG-1000 provides certification tools for transponders, interrogators and passive receivers. Viasat’s evolved solution can significantly simplify the process for complex testing, which would previously require the use of multiple test sets to complete a single test. The Viasat solution will accelerate the supported test times from weeks to hours, including the VRG-1000 certification tool that performs complex Automatic Overload Control (AOC) transponder certification tests in less than one hour.

The VRG-1000 enables testing in a realistic, highly dense environment which other IFF test sets can’t replicate. The Viasat solution is designed to support a density of 400 targets on a single system, and over 2000 targets with multiple systems. The VRG-1000 IFF test set can also generate RF for up to 50 tightly synchronized interrogators to create complex, non-overlapping interrogations for testing transponder density and corner cases.

“With the increasing complexity of the RF signal environment, the need for more advanced, realistic testing capabilities has never been more important as older IFF testing capabilities can no longer support new AIMS certification requirements,” said David Schmolke, Vice President of Mission Connections and Cybersecurity, Viasat Government. “Viasat’s VRG-1000 IFF test set allows the user to perform comprehensive and complex flight-testing during development and our certification tools enable IFF certification testing in a fraction of the time previously required, resulting in improved product time-to-market with lower development and test costs for our customers.” (Source: ASD Network)

 

11 Sep 24. Global: Exploitation of vulnerable edge devices points to elevated risks stemming from botnet.  On 9 September, the security company Sekoia reported that the ‘Quad7’ botnet is exploiting software vulnerabilities to target global devices in an ongoing cyber operation. The botnet comprises five device clusters and includes compromised internet-facing ports for multiple small office/home office (SOHO) devices, virtual private network (VPN) appliances and wireless routers. Threat actors are exploiting Quad7 to conduct brute force attacks, primarily against Microsoft 365 services, hijacking corporate user accounts to obtain administrative privileges on compromised systems. Notably, the threat actors also use a new backdoor to control infected services remotely while avoiding detection by internet scans. Network edge devices play a significant role in botnet infrastructure as they facilitate widespread attacks while obscuring threat actors’ operations and protracting the length of attacks. We assess that Quad7 is possibly in a testing phase due to the increasing number of infected devices; this points to elevated security risks facing global organisations in the long term. (Source: Sibylline)

 

11 Sep 24. Anduril & Oracle Partner to Deliver AI-Powered Defense Solutions from the Datacenter to the Tactical Edge. Anduril and Oracle are partnering to bring Anduril’s Lattice, an open and extensible software platform for command and control (C2),to Oracle Cloud Infrastructure (OCI) and OCI Roving Edge Infrastructure globally. Anduril will also pair its Menace hardware systems with OCI to enhance operations in connected and disconnected mobile command and control environments. Together, Oracle and Anduril will provide secure mission capabilities across the globe from the datacenter to the tactical edge, and at all classification levels. Anduril will deploy Lattice on Oracle Cloud Isolated and National Security Regions, which are Oracle’s air-gapped cloud infrastructure for mission-critical, classified defense, and intelligence workloads. Lattice will also be available in Oracle Cloud Regions, Oracle EU Sovereign Cloud, and Oracle Government Clouds in Australia, the United Kingdom, and the United States.

“Anduril’s partnership with Oracle will provide more global capabilities for our customers,” said Tom Keane, senior vice president, Anduril. “Oracle Cloud provides the global infrastructure, price performance, and data sovereignty that mission customers need to deploy scalable, autonomous, and force-multiplying technology to the far edge.”

Deploying Lattice across Oracle’s distributed cloud will enable warfighters real-time understanding, automated decision advantage, dynamic machine tasking, and human-on-the-loop automation. Anduril has also integrated OCI Roving Edge Infrastructure into the Menace family of expeditionary hardware C4 solutions. Running across Oracle’s distributed cloud, Menace will enable warfighters to deploy, manage, and operate mission applications in disrupted, disconnected, intermittent and low-bandwidth (DDIL) environments.

“Public sector and defense customers operate in the real world, where deployable hardware interacts with humans and creates effects in the most complex environments imaginable,” said Rand Waldron, vice president, Oracle. “Anduril’s Lattice on Oracle Cloud ties together those physical systems with the world’s best cloud services, data management, and AI infrastructure— on a hyperscale global network, across an airgap or in the field.”

Oracle is the only hyperscaler capable of delivering AI and a full suite of 150+ cloud services across dedicated, public, sovereign, and hybrid cloud environments, anywhere in the world including air-gapped infrastructure on classified networks. With OCI’s sovereign and government cloud offerings, customers can meet regulatory, security, and performance requirements while getting the full benefits of the cloud and AI. Anduril supports operations with the US Department of Defense, the US Department of Homeland Security, the Australian Defence Force, the UK Ministry of Defence, and other partners around the world. Powered by Lattice, Anduril solutions provide integrated, persistent awareness, security, and command and control at the tactical edge across land, sea, and air. (Source: ASD Network)

 

11 Sept 24. Strategic AI investment in APAC is booming. AI investment in APAC countries has boomed, with major tech companies making huge strategic investments. Singapore’s Minister of Defence Dr Ng (right) calling on ROK Minister of National Defense Mr Kim (left) at the REAIM 2024 Summit on 9 September. Image courtesy of Singapore’s Ministry of Defence. ©2024 Government of Singapore.

The two-day Responsible Artificial Intelligence in the Military domain (REAIM 2024) summit concluded in Seoul on 10 September 2024, drawing global attention to the growing significance of AI in military applications.

Co-hosted by South Korea, Kenya, the Netherlands, Singapore, and the UK, the event highlighted the crucial need for responsible AI deployment in defence.

With AI’s rapid evolution, the military sector stands at the forefront of technological transformation. While AI has the potential to accelerate decision-making and impact collateral damage, there are serious risks of poor judgment due to biased data or lack of oversight. This motivates much of the international dialogue convened at REAIM 2024..

In parallel, Asia-Pacific (APAC) is fast becoming a global leader in AI investments, particularly in defence and cloud technology, according to a GlobalData report. APAC’s position as a ‘powerhouse’ reflects its role in accelerating AI adoption, particularly for military use. Countries like Singapore, Indonesia, and Thailand are investing strategically to foster AI-driven economies.

Tech giants are a significant driving force behind this investment wave. Microsoft, Amazon, Google, and NVIDIA have each announced large-scale investments in APAC, aimed at expanding cloud infrastructure and AI capabilities. These moves signal a broader realignment of the global tech landscape, with military applications becoming an integral aspect.

Microsoft has committed bns to boost AI and cloud infrastructure in Southeast Asia and Japan. Its investments include a $2.2bn initiative in Malaysia, aiming to establish an AI Centre of Excellence and enhance cybersecurity. In Indonesia, $1.7bn will be allocated to data centres and AI training, which aligns with the military’s growing reliance on AI for predictive analytics.

Amazon’s AWS has similarly announced substantial investments in APAC, amounting to $12.7bn in India by 2030. It also plans to develop a new infrastructure region in Taiwan by 2025. These investments will support advancements in generative AI, which could have military applications in training and bridging skill-gaps.

Google, not to be outdone, has increased its total investment in Singapore to $6.7bn with the completion of its fourth data centre. The company’s focus on hyperscale data infrastructure aims to enhance AI service delivery, a move that could strengthen military communications and operational efficiency in the region.

NVIDIA is also playing a pivotal role, partnering with Japan’s digital infrastructure providers and receiving a $740m boost from Japan’s Ministry of Economy, Trade, and Industry. This collaboration will foster generative AI development, which could support a range of military activities from simulation to real-time battlefield analytics. NVIDIA’s further $200m investment in Indonesia to build an AI Centre reinforces the military’s interest in AI for mission-critical functions.

Tejal Hartalkar, a Senior Analyst at GlobalData, commented, “The influx of AI and cloud investments in APAC signals more than a temporary boom. It is a significant realignment that could position the region at the forefront of AI innovation.”

“Countries like Singapore, Malaysia, Indonesia, and Thailand are leveraging strategic investments to build AI-driven economies. The substantial backing from big techs aimed at accelerating cloud and AI adoption in APAC is a testament to the region’s capability to attract and execute large-scale technology projects,” continued Hartalkar.

Despite the opportunities, APAC still faces challenges. Disparities in AI readiness, inconsistent internet connectivity, and varying regulatory frameworks across the region hinder uniform growth. Nevertheless, countries are committed to overcoming these hurdles, ensuring that AI and cloud technology can serve both civilian and military purposes effectively.

 

10 Sept 24. Leonardo DRS Delivers Critical C5I Capabilities for New Australian Army Combat Vehicles. Leonardo DRS, Inc. (NASDAQ: DRS) announced today that it has delivered, ahead of schedule, critical C5I capabilities for the Australian Army’s Heavy Armoured Capability Systems. The delivery provides the new vehicles with the latest situational awareness technology allowing the Australian Army to keep ahead of new and emerging threats in the region.

Through the U.S. Government Foreign Military Sales program, Leonardo DRS was selected to provide its next-generation ruggedized C5I Battle Management System (BMS) hardware for the new M1A2Sepv3 Main Battle Tanks; M1A2Sepv3 and M88A2 Recovery Vehicles; M1074 Joint Assault Bridge platforms, and M1150 Assault Breacher Vehicles.

The Leonardo DRS BMS technology delivered to the Australian Army is designed for the service’s unique requirements and is built around the same combat proven C5I hardware in use with the U.S. Army, U.S. Marine Corps, and U.K.’s ground combat vehicles. It is also designed to easily integrate networked communications with United States and coalition partners.

Leonardo DRS is one of the largest world-wide suppliers of rugged platform computers and display systems and has been providing these advanced systems to the Australian Army for more than 20 years. In total, the company has delivered more than 200,000 systems internationally, built to survive harsh environments and rigorous military standards.

“We are very proud to support our close allies in the Australian Land forces by delivering our newest generation of proven C5I Battle Management System capability ahead of schedule,” said Bill Guyan, senior vice president and general manager of the Leonardo DRS Land Electronics business unit. “In today’s complex threat environment, it is paramount to ensure these critical capabilities are ready to be fielded as soon as possible,” he said.

Network computing and integration is a key strategic focus for the DRS as it continues to be the leading provider of advanced C5 technologies with the U.S. military and allied militaries around the world. The combat-proven, ruggedized systems enable increased data and communications needed for targeting, situational awareness and Battle Management Systems in multi-domain battlefield operations. The company is investing in the future of C5 through the development of the next-generation of tactical computing systems, AI processing solutions and advanced C5ISR/EW Modular Open Suite of Standards/ Sensor Open System Architecture aligned mounted systems – all aimed at enabling future network and platform processing to improve sensor fusion, situational awareness, and reduce the cognitive burden for commanders and crews. (Source: BUSINESS WIRE)

 

10 Sept 24. Goldilock has today been announced as one of the ten companies selected to join the second phase of the Defense Innovation Accelerator for the North Atlantic (DIANA). The ten innovators were part of 44 companies chosen in 2023 to join the first acceleration cohort of the newly formed DIANA, an organisation set up by NATO Allies to tackle the complex security challenges with disruptive dual-use technologies.

As part of Phase II, Goldilock will receive additional funding of up to €300,000 as well as tailored programming, investor networking, and adoption opportunities. The approved funding will support Goldilock in obtaining technology certifications in CNI and defence settings, developing scalable versions of its technology for wider deployments, and establishing software tools for planning, deploying and operating large multi-site deployments.

Of the 44 participants accepted into Phase I, Goldilock emerges as the only CNI-focused cyber company selected to progress to Phase II. The remaining nine innovators come from seven nations, specialising in a range of technology sectors from quantum sensing to renewable energy to ultra cold matter.

This new achievement fuels Goldilock’s momentum as its unique solution, FireBreak, continues to gain recognition within the defence sector and the cybersecurity industry, empowering organisations to detect and neutralise sophisticated cyber attacks before they inflict lasting damage. With active participation in various incubation and acceleration programmes, including the UK’s National Cyber Security Centre’s joint NCSC For Startups programme with Plexal, and the UK Ministry of Defence’s Defence and Security Accelerator, this latest advancement has further solidified the government-trusted and CNI-backed company’s position as a leading innovator in advanced threat protection.

“Cyber attacks are growing more sophisticated year after year, and as demonstrated by recent incidents, not even the largest, most cyber-aware organisations are 100% protected. It’s clear something’s not working, and now more than ever, companies need to adapt their cybersecurity strategy,” said Tony Hasek, CEO and Co-Founder of Goldilock. “To keep these threats at bay, our stand-out hardware-based approach moves away from traditional methods and empowers users to physically disconnect their online systems in an instant. Without an internet connection, cyber attackers lose all their power, stopping them in their tracks and allowing organisation owners and managers to regain complete control.”

To move into Phase II, innovators had to demonstrate progress in their commercial and defence market potential, the technical viability and novelty of their solutions, and their investment readiness. Review panels compromised technical defence and innovation experts.

“We’re proud to announce the ten innovative companies moving into Phase II,” said Professor Deeph Chana, Managing Director of DIANA. “To solve complex security resilience problems, we need an ecosystem of creative, collaborative innovators willing to bring their talent and expertise to bear. These ten innovators, and indeed all of our first cohort, are paving the way for a strong pipeline of innovation for Allied nations to adopt.”

Phase I of the acceleration programme is a six-month ‘boot camp’ that increases participants’ exposure to defence markets and needs, commercial and investment guidance, and demo and testing opportunities. Innovators receive €100,000 as a main grant and are paired with one of DIANA’s network of accelerators across the Alliance. As such, NATO plans to design a bespoke program for Goldilock to scale, providing further validation in a wider set of the 32 countries and in dual-use scenarios.

Continuing this successful relationship, Goldilock is currently exploring collaboration opportunities with NATO Cyber Security Centre as well as cooperation with several of the NATO DIANA industries.

About Goldilock:

Goldilock FireBreak is a physical cybersecurity solution that saves manpower, time, money, and nerves. Based on Goldilock’s patented DPNS, it allows users to issue an authenticated remote non-IP command to instantly and physically isolate and ring-fence systems within seconds, from, and to, anywhere on Earth – without using the internet. The asset is then completely safe and un-hackable because it is truly physically disconnected from the network – exactly as a firebreak creates a physical gap over which fire cannot spread.

The “Non-IP”, or non-internet-protocol enabled command, is significant, because the method of control is completely taken away from the potential attack vector – the internet itself. Furthermore, the Goldilock FireBreak is triggered port by port, so disconnection and isolation can be very granular – right down to the network segment or endpoint.

About DIANA:

DIANA is the Defence Innovation Accelerator for the North Atlantic, a NATO organisation with a mission to locate and accelerate dual-use innovation across the Alliance. DIANA provides technology developers with the resources, networks and expertise to address critical defence and security challenges, to create a more peaceful and resilient future. Learn more at www.diana.nato.int.

 

11 Sept 24. Quantum Bridge Accepted into Canadian Federal Procurement Program. Quantum Bridge, a company offering a range of advanced quantum-safe data-security solutions, today announces that it has been accepted into a fast-track government procurement program. This follows extensive testing by the Canadian Government of the company’s Symmetric-Key Distribution System (SDS). This first of its kind solution now incorporates both Distributed Symmetric Key Establishment (DSKE) technology and multiple Post-Quantum Cryptography (PQC) algorithms including the Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM). The latter being recently established by the U.S. National Institute of Standards and Technology as one of three new standards for quantum-safe encryption.

By combining DSKE and Post-Quantum Cryptography such as ML-KEM in a single encryption solution, Quantum Bridge has developed a truly unbreakable method for protecting data and communications from ‘harvest-now and decrypt later’ attacks. Many recognized cryptographic authorities have recommended the use of symmetric keys in combination with PQC to protect sensitive information. The Quantum Bridge solution now allows the integration of this combination of technologies into existing communications infrastructure.

As the maturity of quantum computing continues to accelerate in the coming years, this type of encryption will become necessary not only to protect classified information, but also sensitive personal data such as financial information and medical records. For this reason, stakeholders ranging from governments to banks, telecom companies and hospitals are interested in this technology.

“Acceptance into Innovative Solutions Canada’s Pathway to Commercialization program is an important milestone for Quantum Bridge and provides us the opportunity to sell our innovations directly to the Government of Canada,” said Mattia Montagna, CEO at Quantum Bridge. “It also confirms that this solution is ready for use today. It is available now for forward-thinking government and corporate interests which are actively looking to absolutely ensure that their sensitive information and customer data are completely safe.”

Innovative Solutions Canada’s ‘Pathway to Commercialization’ is a program which provides small and medium-sized businesses the opportunity to explore commercial sales with the Government of Canada. To qualify, companies must successfully complete a period of testing with a department of the government of Canada. Upon completion of testing, it must be determined that the technology is at Technology Readiness Level 9. Quantum Bridge has successfully completed this testing with Defence Research and Development Canada, and has now been accepted into this phase of this Innovative Solutions Canada program.

DSKE encryption is proprietary to Quantum Bridge. This technology is highly scalable in a network setting, has no distance limit, and provides information-theoretic security via novel protocols for data sharing. This has been demonstrated in both network security and mobile applications. Further information on these or other data security innovations from Quantum Bridge is available on the company’s website at quantumbridge.io.

 

 

09 Sep 24. Taiwan: Cyber operation targeting military-related sectors points to raised espionage risks for firms. On 6 September, the cyber security company Trend Micro reported on an ongoing cyber espionage operation that has been targeting drone manufacturers and other military-related industries in Taiwan since March. The group behind the campaign (‘TIDRONE’) is a previously undocumented threat actor with suspected ties to other Chinese-speaking groups. The exact method with which it obtains initial access to targets is unclear. However, victims appear to have used the same enterprise resource planning software, underscoring that this is possibly a supply chain-focused operation. Notably, TIDRONE has consistently updated its arsenal during the operation, employing various anti-analysis and defence evasion techniques such as disabling security products. We therefore assess that the group is moderately sophisticated. While the most recent campaign has specifically targeted Taiwan, telemetry from the cyber security company VirusTotal indicates that TIDRONE has targeted other countries (such as Canada and South Korea) in previous years, elevating the cyber espionage risks facing military-related sectors globally in the long term. (Source: Sibylline)

 

09 Sept 24. As part of the collaborative framework and the positive relationship between Italy and Saudi Arabia, ELT Group signed a Memorandum Of Understanding (MoU) with the Ministry of Investment of the Kingdom of Saudi Arabia (MISA) and the General Authority for Military Industries (GAMI) in the Kingdom of Saudi Arabia (KSA).

Signed in the presence of the President and CEO Enzo Benigni, HE Eng. Khalid bin Abdulaziz Al-Falih Saudi Minister of Investment, Mohammed bin Saleh Al-Athel, Deputy Governor of the Saudi General Authority for Military Industries, Lorenzo Benigni the  Senior VP Institutional Relations and Paolo Izzo our Senior VP Global Sales, the Mou addresses the achievements of ELT Group to align its presence in the Kingdom with KSA’s Vision 2030, aiming at exploring collaboration opportunities in the aerospace and defence sectors, including training and development of a domestic supply chain in Saudi Arabia.

ELT Group has a long established history and strong relationship with the Country, marked recently by the establishment of a Saudi-law company, Elettronica for Industries LLC, focused on localizing logistic support and, more extensively, the entire value chain.

Through this MOU ELT Group wants to underline its role as a key Partner to the Kingdom of Saudi Arabia, due to its 70 years of experience in managing the electromagnetic spectrum and developing electronic defence systems in the naval, air, land, cyber, and space domains.

 

06 Sept 24. AI Security Center Keeps DOD at Cusp of Rapidly Emerging Technology. The director of the National Security Agency said the agency’s new Artificial Intelligence Security Center is paying dividends in the Defense Department’s efforts to stay at the cutting edge of the rapidly advancing technology.

Air Force Gen. Timothy D. Haugh, who also serves as the commander of U.S. Cyber Command, said the security center has become vital as the agency continues to seek ways to leverage, adapt to and protect against AI technology.

“One area that we see as really being able to provide value is focusing on the security of that technology — thinking about it through both the lens of the protection of intellectual property but also how we think about defending those models to ensure that they’re being used properly,” Haugh said during an event yesterday at the Billington Cybersecurity Summit in Washington.

Haugh’s predecessor, Army Gen. Paul M. Nakasone announced the creation of the center last year, consolidating the agency’s various artificial intelligence, security-related activities.

It serves as NSA’s focal point for developing best practices, evaluation methodology and risk frameworks with the aim of promoting the secure adoption of new AI capabilities across the national security enterprise and the defense industrial base.

Haugh said NSA also plays a critical role in shaping the government’s efforts to better understand the risk of AI in the hands of adversaries and defending against those risks.

U.S. officials have emphasized the increasing role AI is having in shaping the national security landscape, and they’ve taken steps to shape the future of the emerging technology.

Last year, DOD released its strategy to accelerate the adoption of advanced AI capabilities to ensure U.S. warfighters maintain decision superiority on the battlefield for years to come.

The Pentagon’s 2023 Data, Analytics and Artificial Intelligence Adoption Strategy builds upon years of DOD leadership in the development of AI and further solidifies the United States’ competitive advantage in fielding the emerging technology, defense officials said in releasing the blueprint.

In unveiling the strategy, Deputy Defense Secretary Kathleen Hicks also emphasized the Pentagon’s commitment to safety and responsibility while forging the AI frontier.  The U.S. has also introduced a political declaration on the responsible military use of artificial intelligence, which further seeks to codify norms for the responsible use of the technology.

Haugh said the agency also remains at the forefront in shaping DOD’s use of the technology, with a keen focus on responsibility.

He added that NSA brings a unique perspective from within the U.S. government to responsibly shape the future of AI.   (Source: U.S. DoD)

 

06 Sept 24. Cyber Update Key points.

  • The North Korean-nexus group ‘Citrine Sleet’ is exploiting a zero-day vulnerability to target financial and cryptocurrency organisations, raising financial risks (see Sibylline Cyber Daily Analytical Update – 2 September 2024 and our Technical analysis below).
  • A new ransomware operation is targeting VMware ESXi servers, elevating financial and disruption risks for global organisations (see Sibylline Cyber Daily Analytical Update – 3 September 2024 and our Technical analysis below).
  • A new highly sophisticated backdoor points to elevated security risks from the Chinese-nexus group ‘Earth Lusca’ (see Sibylline Cyber Daily Analytical Update – 4 September 2024).
  • The seizure of several websites used in a Russian-linked influence operation highlights increased disinformation risks to US voters (see Sibylline Cyber Daily Analytical Update – 5 September 2024).
  • A long-term campaign by Chinese-speaking cyber actors, ‘Tropic Trooper’ will raise security risks to Middle Eastern government entities associated with human rights investigations (see Sibylline Cyber Daily Analytical Update – 6 September 2024).

Technical analysis of weekly stories

The North Korean-nexus group ‘Citrine Sleet’ exploited a zero-day vulnerability (CVE-2024-7971) to target financial and cryptocurrency organisations. Citrine Sleet likely used social engineering tactics to direct users to a malicious actor-controlled domain, enabling them to exploit CVE-2024-7971 and remotely execute code on compromised systems. The actors then deployed a Windows sandbox escape payload to evade detection from the system’s security mechanisms. Simultaneously, the group also loaded the FudModule rootkit, directly storing it in the system’s memory to facilitate obfuscation. The FudModule establishes administrator-to-kernel access, allowing for direct kernel object manipulation (DKOM) which facilitates the disruption of the compromised system’s core configurations. Additionally, the rootkit provides the group with prolonged access and control over compromised Windows operating systems, highlighting the high sophistication of the group’s tactics. Notably, the most recent version of FudModule extends kernel tampering privileges to standard users as well as admins, underscoring the likely continuous development of this malware.

A new ransomware-as-a-service (RaaS) operation, ‘Cicada3301’, has targeted global VMware ESXi servers since June. Cicada3301 first infiltrated targeted systems using stolen credentials to gain unauthorised access to its target’s ScreenConnect account, highlighting the persistent security risks stemming from the software supply chain. There is a possibility that Cicada3301’s infrastructure may be affiliated with the known ‘Brutus’ botnet, which likely forms part of a wider intrusion campaign. Upon obtaining initial access, the actors then deploy ransomware, encrypting a system’s files and downloading a ransom note. The group also exfiltrates sensitive data from compromised ESXi hosts prior to encryption to conduct double extortion attacks. Furthermore, the ransomware contains several layers of encryption and a sleep parameter to delay the execution of the encryptor, highlighting the actors’ sophistication and their ability to evade detection. Cicada3301 also deletes a host’s data snapshots before deploying the encryptor to hinder post-execution data recovery, further pointing to the actors’ experience and knowledge. Notably, the malware’s code and execution mechanisms resemble those of the defunct ransomware group ‘ALPHV’ which reportedly halted operations in March. These similarities, combined with the actors’ clear knowledge, sophistication and their potential connection to the Brutus botnet, indicate a possible overlap between the groups.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network.
  • Routinely check for newly created user accounts and other abnormal files and audit existing user accounts, often rotating credentials.
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
  • Ensure adequate security monitoring and detection capabilities, particularly for all external-facing services, devices and ports.
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.

Our cyber word(s) of the week: Kernel  (Source: Sibylline)

———————————————————————————————————————————————————————————————————————————————————————————————————————————–

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

 

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

——————————————————————————————————————————————————————————————————————————————————————————————————————————–

  • « Go to Previous Page
  • Page 1
  • Page 2
  • Page 3
  • Page 4
  • Page 5
  • Page 6
  • Go to Next Page »

Primary Sidebar

Advertisers

  • Pythia
  • Teledyne
  • Exensor
  • Visit the Oxley website
  • Blighter
  • SPECTRA
  • Britbots logo
  • Faun Trackway
  • Systematic
  • CISION logo
  • ProTEK logo
  • ProTEK logo
  • ssafa logo
  • IEE
  • EXFOR logo
  • sibylline logo
  • Team Thunder logo
  • Comtech logo
  • GoExporting logo
  • ECHODYNE logo
  • Supercat logo
  • Galvion logo
  • Leonardo DRS logo
  • MTC logo
  • IDC logo
  • DSEI logo
  • DVD2024 logo
  • SDSC logo
  • TELEDYNE FLIR logo
  • VeteranUK logo
  • Matrix Space logo
  • ST Engineering logo
  • EWS logo
  • sentinel photonics logo
  • capua logo
  • Curtiss-Wright logo
  • Brave1 logo
  • Drone Evolution logo
  • AEI Systems logo
  • EOS logo
  • NMSUK logo
  • Openworks logo
  • Sandown Park logo
Hilux UKDSE AARTOS ST Engineering Future Artillery

Contact Us

BATTLESPACE Publications
41 St Georges Drive
London SW1V 4DG

+44 (0)77689 54766

BATTLESPACE Technologies

An international defence electronics news service providing our readers with up to date developments in the defence electronics industry.

Recent News

  • Protek Selected By Dutch Armed Forces

    May 2, 2026
    Read more
  • PARLIAMENTARY QUESTIONS

    May 1, 2026
    Read more
  • MANAGEMENT ON THE MOVE

    May 1, 2026
    Read more

Copyright BATTLESPACE Publications © 2002–2026.

This website uses cookies to improve your experience. If you continue to use the website, we'll assume you're ok with this.   Read More  Accept
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT