• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • SPECTRA banner
  • Curtiss-Wright banner

BATTLESPACE Updates

   +44 (0)77689 54766
   

  • Home
  • Features
  • News Updates
  • Defence Engage
  • Company Directory
  • About
  • Contact

C2, Tactical Comms, AI, Cyber, EW, Cloud Computing & Homeland Security

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

May 3, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

————————————————————————————————————————————————————————————————————————————————————————————————————————————-

02 May 24. Spectra Group launches GENSS a revolutionary tactical radio communications system to the US Defense market at SOF 2024. Following the initial announcement in January 2024, Spectra Group are springboarding the GENSS system into the US market at SOF 24.  Spectra Group, a specialist provider of secure voice, data and satellite communications systems, is showcasing its next generation of tactical radio communications GENSS (pronounced genesis) at SOF Week 2024 and will be displaying GENSS and the highly popular SlingShot from 6-10 May 2024 in booth #1805 at the Tampa Convention Centre.

GENSS builds on the foundations created by their award-winning SlingShot system, embodying Spectra Group’s vision of producing the ultimate radio systems that capitalize on technological advances, adapt to the evolving demands of military operations and simplify the user experience.  It has been designed and developed through a collaborative effort of tactical communication experts, seasoned military specialists and top-tier U.K. scientists and engineers.  GENSS is a significant advancement in the field of tactical radio communications, due to its modular core framework and software-defined flexibility, heralding a new era in communication technology.

This modular, agnostic hardware radio system is designed to be agile and provide the ultimate interoperability through straightforward software reprogramming to adapt quickly and easily to meet the diverse needs of its users.  Capable of operating across HF, VHF, UHF, and satellite bands, GENSS is engineered to conquer Beyond Line-of-Sight (BLOS) barriers and support Communications on the Move (COTM), delivering a robust and agile solution for voice and high-bandwidth data transmission across all domains — land, sea, and air.  GENSS boasts high-capacity, network sensing capabilities and has increased data rates over 25kHz LTAC channels, scaling up to 90kBps.  It has adaptive modulation waveforms, which automatically adjust through network sensing techniques, to meet the tactical situation (on the move and in combat vs at the halt scenarios).  Also, through novel engineering techniques, voice and low data rate solutions can be applied in the contested communications space to minimise detection.

This revolutionary radio solution can stand alone or be integrated into any existing radio infrastructure and works seamlessly with SlingShot; unleashing superior interoperability and flexibility to meet the demands of today and the future.  By integrating multi-mission and multi-mode functionalities, combined with its modular design and open architecture, it delivers unparalleled adaptability for robust battlefield connectivity.  Secure by design and integrating the latest most advanced technological hardware means GENSS not only delivers maximum performance while minimizing its size, weight and power, but also delivers a future-proofed capability.  In addition, it is simple to operate and configure, with an easy-to-programme user interface, resulting in an overall reduced training burden.

Simon Davies, Chief Executive at Spectra Group, said: “For years, my vision has been to craft the ultimate radio system — user-friendly, light, modular and supremely flexible to adapt to the evolving demands of military operations and technological advances. After years of dedicated development, GENSS is the fruition of that vision and builds on the foundations set by our award-winning SlingShot system. Designed by soldiers, for soldiers, GENSS is not just a game-changer for military applications but possesses vast potential for integration into broader communication networks, unlocking endless possibilities.”

 

02 May 24. Department of Defense Issues Class Deviation on Cybersecurity Standards for Covered Contractor Information Systems. The Office of the Under Secretary of Defense for Acquisition and Sustainment, in collaboration with the Office of the Chief Information Officer, today issued a Defense Federal Acquisition Regulation Supplement (DFARS) class deviation relating to the cybersecurity standards required for covered contractor information systems.  The intent of this class deviation is to provide industry time for a more deliberate transition upon the forthcoming release of the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations,” revision.  This class deviation will also afford the Department of Defense time to best align any of the necessary supporting mechanisms.  Specifically, this class deviation provides an alternative clause that will require contractors, who are subject to DFARS clause 252.204-7012, to comply with NIST SP 800-171 Revision 2, instead of the version of NIST SP 800-171 in effect at the time the solicitation is issued. The class deviation is available on the Defense Pricing and Contracting public website at https://www.acq.osd.mil/dpap/policy/policyvault/USA000814-24-DPC.pdf. (Source: U.S. DoD)

 

03 May 24. Statement by the North Atlantic Council concerning malicious cyber activities against Germany and Czechia. We stand in solidarity with Germany following the malicious cyber campaign against a political party, in this case the Social Democratic Party of Germany, and with Czechia following the malicious cyber activities against its institutions. Allies recognize that Germany and Czechia have attributed the responsibility of the malicious cyber activities in their respective countries to the threat actor APT28 sponsored by the Russian Federation, specifically the Russian General Staff Main Intelligence Directorate (GRU). Allies also note with concern that the same threat actor targeted other national governmental entities, critical infrastructure operators and other entities across the Alliance, including in Lithuania, Poland, Slovakia and Sweden.

We strongly condemn malicious cyber activities intended to undermine our democratic institutions, national security and free society.

The malicious cyber activities targeting Germany and Czechia underscore that cyberspace is contested at all times. Cyber threat actors persistently seek to destabilize the Alliance.

We remain committed to countering the substantial, continuous and increasing cyber threat, including to our democratic systems and our critical infrastructure. We are determined to employ the necessary capabilities in order to deter, defend against and counter the full spectrum of cyber threats to support each other, including by considering coordinated responses.

We promote a free, open, peaceful and secure cyberspace. We call on all States, including Russia, to respect their international obligations and commitments to uphold international law and act within the framework for responsible state behavior in cyberspace as affirmed by all members of the United Nations. (Source: NATO)

 

03 May 24. United Kingdom joins partners in condemnation of malicious cyber activity by Russian Intelligence Services  : UK government statement.

The United Kingdom has joined with its international partners to condemn malicious cyber activity by the Russian Intelligence Services.

A UK government spokesperson said: “The United Kingdom stands with the European Union, Germany, Czechia and other allies in strongly condemning malicious cyber activity by Russian Intelligence Services. Today’s statements from our allies demonstrate the scale, persistence, and seriousness of unacceptable Russian behaviours in cyberspace. Recent activity by Russian GRU cyber group APT28, including the targeting of the German Social Democratic Party executive, is the latest in a known pattern of behaviour by the Russian Intelligence Services to undermine democratic processes across the globe.

On 7 December 2023, the UK exposed a series of attempts by the Russian Intelligence Services to target high-profile UK individuals and entities through cyber operations. At the same time, we sanctioned two Russian nationals responsible for political interference. With multiple elections around the world in 2024, raising awareness of the threat to the UK and our international partners remains vitally important for our collective resilience.

Today, as part of a broad coalition of allies, we are making clear to the Russian state that we will continue to identify, expose, and respond to such unacceptable activity.

Background

  • APT28 are capable cyber actors who have been active since at least 2004. They are known by industry nicknames including Strontium, Sofacy Group, Pawn Storm, Fancy Bear, and Sednit.
  • The UK has previously exposed APT28 as part of the GRU, the Russian military intelligence service, including:
  • In 2018, the UK and the Netherlands exposed an attempted attack against the Organisation for the Prohibition of Chemical Weapons (OPCW) by APT28, aimed at disrupting independent analysis of chemicals weaponised by the GRU in the UK.
  • In 2020, the UK announced sanctions against APT28 and two individual GRU officers for their reckless cyber-attacks on Germany’s Parliament in 2015, which affected email accounts belonging to German MPs and the German Vice Chancellor.
  • In 2023, the UK and US technical communities released a joint advisory to provide details of tactics, techniques and procedures associated with APT28’s exploitation of Cisco routers in 2021.
  • The UK Government also supports Germany’s assessment that APT28 exploited critical security vulnerabilities in Microsoft Outlook directed against email accounts of the German Social Democratic Party.

(Source: https://www.gov.uk/)

 

02 May 24. Good Cyber Hygiene Can Impede Adversary Meddling in U.S. Infrastructure. Good cyber hygiene, which includes things like regularly changing passwords or applying software security patches, plays an outsized role in preventing America’s adversaries from hacking into and crippling U.S. infrastructure systems, such as power, water or gas.

On Capitol Hill today, Director of National Intelligence Avril D. Haines told members of the Senate Armed Services Committee that in many cases where it’s been evident that U.S. adversaries have demonstrated an ability to hack into U.S. infrastructure systems, good cyber hygiene would have prevented it.

“This year, cyber actors are attacking U.S. industrial control systems, which are typically used to automate industrial processes, at record levels,” Haines said.

Critical infrastructure sectors — including water, wastewater, food, agriculture, defense, energy and transportation —rely on these kinds of systems, she said.

“Although the likelihood of any single attack having a widespread effect on interrupting critical services remains low, the increased number of attacks and the actors’ willingness to access and manipulate these control systems increases the collective odds that at least one could have a more significant impact,” Haines said.

The owners and maintainers of these systems play a role in their vulnerability to cyberattack by American adversaries, Haines told lawmakers.

“In virtually all the attacks we’ve seen against U.S. critical infrastructure, cyber actors took advantage of default or weak passwords; unpatched, known vulnerabilities; and poorly secured network connections to launch relatively simple attacks,” she said. “And for this reason, it is crucial that all of us — particularly critical infrastructure owners and operators — improve our cybersecurity practices to reduce our vulnerability to such efforts.”

According to Haines, the number of ransomware attacks globally went up by as much as 74% in the last year.

Air Force Lt. Gen. Jeffrey A. Kruse, director of the Defense Intelligence Agency, told senators that the need to protect DIA networks from cyberattacks by a wide range of actors, including foreign intelligence entities and insider threats, remains a primary concern for DIA.

“This includes not only the sophisticated capabilities of state actors, such as Russia and China, but also rogue cyber actors loosely aligned to governments,” he said. “In addition to … the growing threat to critical infrastructure in local governments, this threat directly endangers our defense industrial capabilities, our hard-won technological and military advantages, our allies and partners, and our future defense operations. We must partner, invest and integrate in new ways to secure what we value and safeguard: the assured resiliency of our networks, the data and the people.” (Source: U.S. DoD)

 

02 May 24. Ukraine comms struggles spur European hunger for L3Harris radios. The urgent need for secure communications in the Russia-Ukraine war is drumming up new levels of interest in L3Harris Technologies equipment among European militaries, according to the defense contractor.

More than 30,000 of the company’s radios and accessories have been shipped to the front lines, with much of the gear tied to handheld communication and coordination aboard vehicles. The U.S. has highlighted secure data-sharing devices in its pledges to Ukraine, at this point totaling approximately $44bn.

Samir Mehta, the president of communications systems at L3Harris, on May 1 told reporters in Washington the company is seeing “unprecedented demand among our NATO partners and allies for secure, resilient, tactical communications.” Close to $1bn of business is on the books.

“I think one only needs to look at a map to understand exactly what is driving that demand,” said Mehta, who spent the previous week meeting with officials in the Czech Republic and Poland, among other locations. “If you can’t communicate, you can fight but you can’t win.”

Reliable, low-profile means of relaying battlefield information have become a linchpin for fighting in Eastern Europe, where drones saturate the skies and sensors cue onto even the smallest electronic signal.

U.S. defense leaders have long warned of the risks of using unencrypted or rudimentary tools, citing the ease at which they can be traced, targeted and shot.

“If they’re not armed with the right equipment, the enemy will use transmissions, scanning the electromagnetic spectrum, to be able to find, locate and kill you any time you try to communicate,” Mehta said. “Every time that you take your non-high-assurance communication device out, whether it be a cell phone, whether it be Starlink, and use it to communicate, you are sending an emission that allows the Russians to find out exactly where you are.”

Indiscriminate cell phone use has been blamed for casualties on both sides of the war. Russian forces likely bombarded a Ukrainian base housing foreign fighters after detecting devices with British country codes, the London-based Telegraph reported. Dozens were killed in the strike.

“They’ve had too many unfortunate incidents where that happened,” Mehta said, “which is why they’ve adopted our technology and our radios as their primary communication device.”

L3Harris is the ninth largest contractor in world when ranked by defense-related revenue, reaping nearly $14bn in 2022, according to Defense News Top 100 analysis.

The U.S. Army tapped the company years ago for its combat net radio endeavor worth up to $6bn. An initial order was valued at $20m. (Source: C4ISR & Networks)

 

02 May 24. E4shield listed by The European Commission’s Joint Research Centre (JRC) among innovative technologies for defence against airborne pathogens. E4shield, the technology conceived, developed and patented by ELT Group that uses electromagnetic waves to inactivate respiratory viruses in the air, has been included and positively evaluated in the JRC – HERA technology foresight study. The European Commission’s Joint Research Centre (JRC) provides scientific support to the European Union in defining future guidelines/regulations with the aim of improving quality of life, for example by supporting the development and implementation of innovative technologies. The report ‘Suppressing Indoor Pathogen Transmission: A Technology Foresign study’ includes e4shield as one of the innovative technologies to be considered in the EU’s future to ensure an increase in indoor air quality.

Also according to this study, the airborne route is considered one of the most common modes of transmission of respiratory viruses. This is particularly relevant in indoor environments, where most respiratory infections occur. Controlling the transmission of airborne pathogens has become a major public health challenge to prevent the spread of infectious diseases, ensuring the safety and health of individuals and communities. Two groups of technologies have been identified to meet this challenge:

– For the detection of pathogens in the air

– For decontamination of air and surfaces

Experts from various fields, from universities to research and technology organisations, but also private companies and business associations, participated in this study in order to gain a multi-stakeholder perspective on the possible future development of innovative solutions.

The e4shield technology is currently used in devices distributed by e4life worldwide. The goal of e4life, a newco born out of the joint venture between ELT Group and Lendlease, is to expand the application of e4shield technology to other respiratory viruses (both human and animal) and to achieve the ambitious goal of also being effective against other microorganisms (e.g. bacteria).

 

01 May 24. L3Harris lobbying DoD to create ‘resilience’ standard for communications.

“Right now, you and I can go to a Cabela’s, we can buy a radio, we can go to a trade show, put it out on a table, and we can say it’s a form of resilient communication, because there’s no standard,” Samir Mehta said. “It’s time that we have a standard.”

L3Harris is actively lobbying leaders in the Pentagon and Congress to create a definition of what “resilient communications” means, as the defense giant seeks to fend off a growing interest for commercial communications providers from the military.

Speaking to reporters Wednesday, Samir Mehta, L3Harris’s president of communication systems, said the company was “talking to OSD leadership. We’re talking to service leadership. We’re talking to PMAs, we’re talking to PEOs. We’re carrying this message to all levels and all echelons.”

That message, at its core, is asking leadership to quite literally “define resilience” in a fundamental way that provides a standard across the military. Without spelling out exactly what the company wants that to look like, Mehta leaned heavily throughout his comments on the idea of high security waveforms that can’t be intercepted or jammed as easily as commercial capabilities.

“Right now, you and I can go to a Cabela’s, we can buy a radio, we can go to a trade show, put it out on a table, and we can say it’s a form of resilient communication, because there’s no standard,” Mehta said. “It’s time that we have a standard.”

The Pentagon’s Chief Information Officer is a main point of contact, Mehta said, adding that L3Harris is also talking to Congress on this issue. He didn’t rule out pushing for language to be included in the upcoming fiscal 2025 National Defense Authorization Act.

Mehta compared the push to the kind of standardization for encryption that has come out of the National Security Agency, noting, “Is it complicated? Probably will take some time and effort. Is it unobtanium? No, we’ve done this, we’ve proven the ability to do this in other areas.

The Defense Department is hardly alone among world militaries in looking to the commercial sector to see whether cheaper options are available. And Mehta was quick to note that there are plenty of good use cases for those unsecured comm links, such as the ability to connect servicemembers in the field to their families back home.

But “The concerning trend we see is that the budget pressures have caused some leaders in DoD, and a lot of our customers, to turn to [commercial comms] as a means of military communications,” Mehta said. “And some of these commercial providers provide a little bit of, I’ll call it the easy button. And so for us, it’s important to remind [DoD that] the easy button isn’t always the best button, especially if you’re taking missions and planning to potentially fight — hopefully not — but potentially fight in a highly contested environment versus a near peer adversary.”

The clearest example is the SpaceX Starlink terminal, which had much ballyhooed success in Ukraine — but which has also raised concerns, in part because of founder Elon Musk’s unpredictable nature and business dealings with China.

Relying on traditional defense firms means the Pentagon is “not entirely subject to the whims of one commercial owner of the company, or shareholder of the company, who happened to wake up in Beijing 48 hours ago to try to sell more Tesla’s and more EVs,” Mehta said. “So the question that we’re posing to our military leadership is, who do you trust?”

Despite the concerns about the Pentagon’s leanings towards the commercial sector, Mehta expressed confidence that his business is in healthy shape, citing a “record backlog” for the Harris-branded radio unit, to the point the company is transforming its Rochester, New York, production facility from split civil-military production to pure defense. That transformation should be done by the end of the year, with Mehta saying it should result in 5,000-7,000 more radios produced each year over the 2024 total of 70,000.

Driving that is “unprecedented demand” from Europe, he added, saying the company is now poised to book “close to a billion dollars in business from our European partners and allies.” (Source: Breaking Defense.com)

 

30 Apr 24. Volt Typhoon hacks likely to inspire copycats, CNMF’s Mahlock says. The Volt Typhoon hacks that targeted U.S. critical infrastructure won’t be the last of their kind, according to a Marine Corps cyber leader.

The Chinese intrusion affected organizations spanning the communications, utilities, education and government sectors including in Guam, a key foothold for American forces in the Indo-Pacific. The incident was disclosed in May 2023, with Microsoft describing the years-long operation as hard to detect and malicious.

The attack is likely to inspire copycats, said Maj. Gen. Lorna Mahlock, the commander of the Cyber National Mission Force. The CNMF, part of Cyber Command, deploys around the world to unearth malware and fortify digital defenses.

“I think we’re seeing Volt Typhoon activity continuing to persist. That’s in open source. We’re also seeing other actors using the tactics, techniques and procedures,” Mahlock said April 30 at the Modern Day Marine defense conference in Washington. “The greatest form of flattery is to copy.”

U.S. officials have long considered China a serious cyber hazard, with the International Institute for Strategic Studies think tank placing it in the second tier of its cyber powerhouse rankings alongside Russia. The Pentagon’s 2023 cyber strategy warned both Beijing and Moscow are prepared to unleash cyberattacks on critical infrastructure and defense networks should war break out.

The groundwork is being laid today. Volt Typhoon relied on so-called living-off-the-land techniques to lurk around vital systems and go largely unnoticed.

Attacks on critical infrastructure — food and water delivery, health care services, defense contracting and more — could jeopardize U.S. military response across the world as well as a sense of stateside calm. A ransomware attack on Colonial Pipeline in 2021 resulted in a run on fuel across the Southeast and aggravated concerns about energy security.

“Open-source reporting talks about this actor, out of China, who has access to our critical infrastructure and some of our key capabilities. Why? Not just for foreign intelligence-collection,” Mahlock said.

“We’ve seen this actor, China, grow in scope, scale and sophistication,” she added. “We’ve also seen that they’re undeterred.” (Source: C4ISR & Networks)

 

30 Apr 24.  Horizon3.ai Unveils Rapid Response Service for Cyber Resilience. Horizon3.ai, a pioneer in autonomous security solutions, today announced the launch of its Rapid Response service, now part of the NodeZero™ platform. This one-of-a-kind capability marks a significant advancement in autonomous penetration testing solutions by addressing a critical gap in measuring the real-world impact of exploitable vulnerabilities within the software many organizations have come to rely on. Now, organizations can gain a clear understanding of their ‘likelihood of exploitability’ for the most critical vulnerabilities being announced.

As organizations continue to contend with both zero-day and N-day vulnerabilities, the window of time between the public disclosure of a vulnerability and threat actors exploiting them in the wild is steadily shrinking. Knowing this predicament, organizations spend vast amounts of time, money, and resources patching the software they use after hearing of a vendor vulnerability announcement. Yet, how often are organizations expending considerable effort not knowing if a vulnerability is actually exploitable or not? The answer to that is, “quite often.”

So far in 2024, the U.S. National Vulnerability Database (NVD) has tracked 12,296 new vulnerabilities in publicly released software. A common challenge for organizations is determining whether any software they are using that is identified as vulnerable is actually exploitable within their specific environments, a judgment often contingent on how the software is deployed. Since organizations often lack a proven method to assess the ‘exploitability’ of software, they may find themselves updating software that does not require immediate patching. NodeZero addresses this issue with its Rapid Response service, which is specifically tailored to manage many of the most critical vulnerabilities more effectively. The following outlines the workings of the Rapid Response service.

As Horizon3.ai’s attack team conducts original research and uncovers new vulnerabilities, they also keep an eye on public vulnerability disclosures. They assess the exploitability of these vulnerabilities, considering factors such as the ease of exploitation, their severity, and the prevalence of the vulnerable software. Following their assessment, they develop proof of concept (POC) exploits, integrate them into NodeZero as new attack content, and notify customers about these emerging vulnerabilities. With NodeZero, customers can probe their systems using this new attack content to gain immediate insights into their level of exploitability. Furthermore, Horizon3.ai alerts customers if known vulnerable software is present in their production environments and warns them about NodeZero being able to exploit these weaknesses.

The Rapid Response service doesn’t just focus on vulnerabilities; it zeroes in on the exploitability of known issues in production environments. As part of this service, organizations receive proactive measures to keep abreast of cyberattacks. The vulnerabilities that flow through this program typically revolve around publicly accessible assets since they are the most likely targets for exploitation.

Recognizing the critical role of response time to emerging exploits in the wild, Horizon3.ai’s Rapid Response service is designed to provide organizations with a proactive defense mechanism to stay ahead of evolving cyberattacks as they’re discovered or trending in the wild. The fundamentals of this type of rapid response effort are concentrated on enabling organizations to preemptively mitigate nascent vulnerabilities before threat actors target them.

“In the swiftly evolving arena of cybersecurity, where threats emerge and proliferate with alarming speed, the essence of a robust defensive posture lies in responding rapidly. We enable organizations to move faster by prioritizing critical vulnerabilities that have the most potential impact on their organization,” says Snehal Antani, CEO and Co-founder of Horizon3.ai. “Our Rapid Response service is engineered to provide a preemptive shield, arming cybersecurity teams with the necessary knowledge, insights, and tools they need to protect their vital infrastructure.”

By leveraging Horizon3.ai’s expertise in using ‘offense to inform defense,’ and leaning into NodeZero’s autonomous capabilities, customers can schedule and/or immediately launch NodeZero using a single exploit-check to gain early detection of exploitability from an attacker’s perspective. Once finished, NodeZero prioritizes the most critical and exploitable vulnerabilities that must be patched because they have been deemed completely exploitable by the NodeZero platform.

Horizon3.ai’s Rapid Response service is a groundbreaking step forward in the field of cybersecurity, offering organizations an unprecedented level of preparedness against cyber threats. With its cutting-edge technology and proactive strategy, Horizon3.ai is redefining the landscape of cyber defense, providing a critical service that ensures organizations are not only aware of their vulnerabilities but are also equipped to address exploitability with unmatched speed and efficiency. This service, seamlessly integrated into the NodeZero platform, solidifies Horizon3.ai’s position as a leader in autonomous security solutions, empowering organizations to fortify their defenses against the unpredictable nature of cyber threats.

About Horizon3.ai

The NodeZero™ platform empowers organizations to continuously find, fix, and verify exploitable attack surfaces. It is the flagship product of Horizon3.ai, founded in 2019 by former industry and U.S. National Security veterans. Our mission is to help organizations see their networks through the eyes of the attacker and proactively fix problems that truly matter, improve the effectiveness of their security initiatives, and ensure that they are prepared to respond to real cyberattacks. (Source: BUSINESS WIRE)

 

30 Apr 24. Securonix Ushers in a New Era of AI-Reinforced CyberOps with the Launch of Securonix EON.

In an era where cybersecurity challenges are escalating at an unprecedented pace, Securonix today unveiled Securonix EON, a groundbreaking suite of AI-Reinforced capabilities to transform CyberOps in the face of new AI-powered threats. This launch builds on Securonix’s AI legacy, marking a significant leap forward in securing and preparing organizations to respond to the dynamic cybersecurity threat landscape against a backdrop of converging challenges facing security teams.

With the anticipated escalation of AI-powered attacks and adversaries, organizations already face the hurdles of ever-expanding attack surfaces, new regulatory and compliance pressures, and resource constraints. Securonix EON responds to these challenges by using Amazon Bedrock to provide a powerful, unified analyst experience with advanced AI-Reinforced capabilities. Amazon Bedrock is a fully managed service from Amazon Web Services (AWS) that offers a choice of high-performing foundation models—like Claude 3—from leading AI companies via a single API, along with a broad set of capabilities organizations need to build generative AI applications with security, privacy, and responsible AI. As part of the first phase of innovation, Securonix EON will include the following AI-Reinforced capabilities: Insider Threat Psycholinguistics, Adaptive Threat Modeling, and InvestigateRX.

“Cybercriminals are increasingly weaponizing AI, and we’re meeting that challenge head-on,” said Securonix CEO Nayaki Nayyar. “As the world faces advanced AI-powered threats on top of the myriad of other challenges confronting security teams, we are releasing Securonix EON to help our customers stay ahead of the escalating threat curve. Securonix EON is not just a suite of capabilities, it’s a comprehensive strategy to combat cyber threats ushering in a new era of AI-Reinforced CyberOps.”

Securonix has chosen Amazon Bedrock to underpin many of its advanced new capabilities, allowing organizations to use best-of-breed AI to make precise security decisions more quickly, and effectively counter the rise in sophisticated AI-powered threats. Amazon Bedrock is a strong fit for Securonix’s large enterprise customers who require AI systems that are compliant with several security and privacy standards, including HIPAA, GDPR, and others.

“By combining Amazon Bedrock and Anthropic’s Claude 3 with Securonix’s cutting-edge AI-Reinforced CyberOps advancements, customers will be able to detect and defend against adversaries with greater speed, precision, and efficacy than ever before,” continued Nayyar. “These are the first of our AI-Reinforced Securonix EON capabilities, with continued innovation to come that will further advance the cybersecurity market.”

The cornerstone of Securonix’s innovative approach rests on three core pillars: First, reinforce the platform with AI so human intervention happens at the most critical moments, while AI handles the manual, repetitive tasks. Second, apply a cybersecurity mesh architecture to seamlessly and agnostically integrate any security tool, clouds, and data lakes. Third, deliver a frictionless experience with reduced noise, an intuitive user interface, and targeted threat intelligence that frees analysts from the tedious task of manual log analysis and endless alert triage, allowing them to focus on high-level investigations and strategic decision-making. From these principles, Securonix EON extends the capabilities of the company’s industry-leading Unified Defense SIEM.

Key features of Securonix EON include:

  • Insider Threat Psycholinguistics: Utilizing the science of deciphering psychology from language powered by Amazon Bedrock, Securonix provides entity and activity-based risk scoring to uplevel insider threat hunting capabilities. This industry-first feature enables users to accurately and efficiently discern the intent behind a user’s language and behavior, identifying potential malicious activity. Key categories analyzed include financial crimes, obfuscation, and more.
  • Adaptive Threat Modeling: Leveraging machine learning to develop adaptive threat models and dynamic threat chaining of violations with anomaly detections, Securonix enhances investigations by enabling analysts and CyberOps teams to identify never-before-seen attack chains in near real-time. With more speed, accuracy, and efficiency, this capability builds the full picture of an attack to prevent destructive phases.
  • InvestigateRX: Converting retrieved targeted and objective content into a coherent and context-aware summary, analysts are empowered to make swift decisions and save approximately 15 minutes per incident. Securonix customers no longer need to search for data from various sources because the information is delivered directly to the analyst.

“Effectiveness, efficiency, and scale are the three words that drive our business. And in today’s world, the linear model of adding people as customers and data grows is unsustainable,” said Scott McCrady, CEO at SolCyber Managed Security Services. “That’s why we are thrilled about Securonix working with AWS to utilize Amazon Bedrock within its newly introduced suite of AI capabilities. Our goal is to have the best analysts in the world, and putting the best tools in their hands, allowing them to defend against present and emerging threats while also allowing them to be more efficient is the holy grail of security ops. We couldn’t be more excited about what this is unlocking for our operations and our customers.”

Securonix will be showcasing new AI-Reinforced Securonix EON capabilities at the RSA Conference, May 6 – 9, 2024 in San Francisco, at booth #1127 in South Hall. For more information or to meet with Securonix at the conference, please visit: https://www.securonix.com/rsa-conference-2024.

About Securonix

Securonix is pushing forward in its mission to secure the world by staying ahead of cyber threats. Securonix Unified Defense SIEM provides organizations with the first and only AI-Reinforced threat detection, investigation and response (TDIR) solution built with a cybersecurity mesh architecture on a highly scalable data cloud. The innovative cloud-native solution delivers a frictionless CyberOps experience and enables organizations to scale up their security operations and keep up with evolving threats. For more information, visit www.securonix.com

(Source: BUSINESS WIRE)

 

01 May 24. Global: Sophisticated tactics by Chinese state actors point to heightened security, disruption risks. On 29 April, the cyber security firm Infoblox reported that a Chinese state-sponsored group, ‘Muddling Meerkat’, is targeting global internet infrastructure. The group has been active since 2019. It crafts special requests to bypass restrictions imposed by the Great Firewall of China (GFW), which blocks users’ access to unauthorised websites. However, the group is able to mimic legitimate traffic. This allows it to circumvent the firewall and to conduct malicious operations globally. The group’s activity also suggests that it is possibly conducting reconnaissance operations to pre-position itself within adversarial infrastructure for espionage and disruption operations. Muddling Meerkat’s unique capabilities underscore Chinese state-sponsored actors’ high sophistication. The Chinese state-sponsored group ‘Volt Typhoon’ has also conducted pre-positioning operations against US infrastructure since 2019, pointing to heightened security and disruption risks facing global organisations. (Source: Sibylline)

 

30 Apr 24. Kongsberg contracted to develop remote control communications terminal. Kongsberg Defence & Aerospace will develop the THOR RCT (tRCT) for the Norwegian Defence Materiel Agency (NDMA) under a NOK255m (US$23m) contract as part of the country’s Mime programme.

The terminal will be designed for use with radio variants, but also equipped with interfaces to allow standalone  crypto solutions for other communications systems like satellites, 5G ands fixed infrastructure.

The development will be linked to the delivery of the THOR radio system and a contract for serial production of tRCT will be expected to follow. Norway’s Mime programme has included other THOR systems and will modernise tactical management systems for the land, sea and air domains.

In June 2023, the NDMA awarded a NOK320 m contract to Kongsberg to develop tactical radio equipment for the Norwegian Armed and low-volume production of THOR Vehicle Radio Module (VRM) will constitute the first phase of this agreement. It is believed a handheld THOR version has also been in development.

Mime will be built around a strategic agreement signed between NDMA and Kongsberg, with the company taking responsibility for service and system integration, which also includes application support and architecture.

Details have not been provided on tRCT or the handheld radio but Shephard Defence Insight described THOR VRM as a dual-band software-defined radio designed for tactical mobile platforms which operates between 30-1525Mhz. It provides two independent VHF/UHF channels that may be operated simultaneously for voice and data communication. (Source: Google/Shephard)

 

30 Apr 24. Global: Uptick in cyber attacks via stolen third-party credentials demonstrates elevated security risks. On 29 April, the software company Okta warned of a spike in cyber attacks against its customers between 19 April and 26 April. The company stated that unknown threat actors used stolen data from previous third-party breaches to compromise user accounts. Threat actors also employed residential proxies to reroute traffic and maintain anonymity. However, Okta claimed that only a small percentage of attacks were successful, as customers using the company’s ‘log and enforce’ mode were protected against proxy requests. These attacks follow a warning by the technology company Cisco in mid-April about an increase in brute-force attacks against their customers using stolen third-party data and anonymising services. As such, we assess additional attacks targeting user accounts are likely in the short term. Threat actors can easily purchase stolen third-party credentials on the dark web to conduct further malicious campaigns, highlighting elevated security risks to global organisations stemming from third parties. (Source: Sibylline)

 

29 Apr 24. BigBear.ai Achieves ‘Awardable’ Status on DoD’s Tradewinds Procurement Platform with 5 AI Solutions. BigBear.ai (NYSE: BBAI) today announced that it has been designated as an “Awardable” vendor for the Chief Digital and Artificial Intelligence Office’s (CDAO) Tradewinds Solutions Marketplace. Five of the company’s products, including Sensor, Data and AI Orchestration (ConductorOS), Time-Series Forecasting (VANE), Contested Logistics Planning (AURORA), Maritime Domain Awareness (Arcas), and Publicly Available Data Curation (Observe) have been added to the Marketplace.

The DoD’s Tradewinds program acts as a central hub to streamline the adoption of cutting-edge artificial intelligence (AI) capabilities. This program serves as a uniquely efficient contracting vehicle, bridging the procurement gap between the DoD and industry partners like BigBear.ai. With these solutions now available on the Tradewinds marketplace, they are considered post-competition, and DoD users are now able to satisfy standard competition requirements in government contracting.

BigBear.ai’s solutions now available on Tradewinds include:

  • ConductorOS: BigBear.ai’s data and AI orchestration platform, ConductorOS operationalizes AI at the edge to accelerate decision-making for the operator, while supporting the integration of 3rd party AI/ML models. ConductorOS offers a truly open architecture to enable interoperability across disparate sensors, data, and artificial intelligence models across nearly all domains, with near-zero latency and optimized for low/no bandwidth environments.
  • VANE: BigBear.ai’s ‘Virtual Anticipation Network’ contriving clarity from “dirty data” in multi-domain environments for military and government applications; processing bns of data points to predict and anticipate adversarial actions in complex environments with near accuracy.
  • Arcas: BigBear.ai’s computer vision, predictive analytics, and event alerting solution, Arcas conflates ms of data points to provide situational awareness, enabling AI/ML-powered predictive forecasting.
  • AURORA: BigBear.ai’s solution enables military planners to rapidly extract contested logistics and operations data, develop and assess Courses of Action, immediately understand the impact on force structure and readiness, and simulate, visualize, and plan sustainment operations.
  • Observe: A data collection and curation platform that transforms vast amounts of publicly available data into actionable intelligence, enabling unique global situational analysis needs.

“We are focused on delivering operations-ready capabilities in multiple critical use cases at the edge, and we will continue to pursue pathways for more accessible government funding,” commented Mandy Long, CEO of BigBear.ai. “Our designation as an ‘Awardable’ vendor on Tradewinds is an example of how we are continuing to stay nimble as the government acquisition landscape evolves.” (Source: BUSINESS WIRE)

 

26 Apr 24. Cyber Update Key points.

  • A cyber attack on a French hospital underscores the elevated security and financial risks facing the healthcare industry A new campaign targeting Western organisations elevates security and cyber espionage risks from Russian state-sponsored actors A new information-stealing campaign underscores security and financial risks from cyber criminals
  • The exploitation of zero-day vulnerabilities highlights security and espionage risks from state-sponsored groups via the software supply chain (see Sibylline Cyber Daily Analytical Update – 25 April 2024 and our Technical analysis below).
  • A cyber attack on US water and wastewater facilities signals elevated disruption risks from pro-Russian hacktivists (see Sibylline Cyber Daily Analytical Update – 26 April 2024).

Technical analysis of weekly stories

The financially motivated group ‘CoralRaider’ is targeting global organisations in a new information-stealing campaign. The campaign starts with a malicious download of a Windows .LNK file, distributed via phishing emails or masquerading as a film file download. The malicious file then fetches the information-stealer (info-stealer) malware from a content delivery network (CDN) cache, enabling the group to avoid request delays and evade network defence mechanisms. The group primarily deployed three popular info-stealers (‘CryptoBot’, ‘LummaC2’ and ‘Rhadamathys’), customising some of their features to achieve better obfuscation. Notably, the newer version of CryptoBot also targets password manager databases as well as authenticator information to steal cryptocurrency wallet credentials. Researchers suspect that the group is likely of Vietnamese origin due to its extensive use of the Vietnamese language, and frequent targeting of organisations based in South East Asia. Additionally, the group has also compromised organisations in Africa, Europe, the Middle East, North America and Latin America. Although the three info-stealers are popular malware-as-a-service (MaaS) tools, CoralRaider’s unique customisation points to the continuous development and sophistication of their tactics, techniques, and procedures (TTPs).

A new state-sponsored group, ‘UAT4356’, exploited two zero-day vulnerabilities (CVE-2024-20353 and CVE-2024-20359) in a cyber espionage campaign named ‘ArcaneDoor’ which targeted global government organisations. While it remains unclear how the group first infiltrated targeted networks, it deployed two backdoors (‘Line Dancer’ and ‘Line Runner’) to achieve persistence, evade detection and exfiltrate data. Line Dancer is specifically deployed to establish direct communication with targeted systems, bypassing authentication requirements and obtaining the ability to remotely execute code. Line Runner exploits the two zero-day vulnerabilities to allow the threat actors to maintain access to the compromised system regardless of upgrades and reboots. The threat actors combined the backdoors to initially stage information via Line Dancer and then exfiltrate it via Line Runner. This campaign further underscores the heightened exploitation of zero-day vulnerabilities, particularly in perimeter network devices like firewalls. These devices handle incoming and outgoing communication as they sit on the edge of a network, thus providing optimal positioning for espionage operations.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Enforce strict security policies such as regular software and password updates, as well as adequate network segmentation, to prevent lateral movement following an infection
  • Ensure sensitive information is stored securely in appropriate password management services, avoiding the use of plain text
  • Monitor devices and networks for suspicious activity
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network
  • Ensure adequate security detection measures are in place, particularly behaviour-based end-point detection and response (EDR) solutions

Our cyber word of the week: Endpoint Detection and Response (EDR)

(Source: Sibylline)

—————————————————————————————————————————————————————————————————————————————————————————————————————————————

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

 

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

—————————————————————————————————————————————————————————————————————————————————————————————————————————————

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

April 26, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

———————————————————————————————————————————————————————————————————————————————————————————————————————————————–

25 Apr 24. Global: Exploitation of zero-day vulnerabilities points to state-sponsored risks via supply chain. On 24 April, the technology company Cisco Talos warned that a new state-sponsored group, ‘UAT4356’, actively exploited two zero-day vulnerabilities (CVE-2024-20353 and CVE-2024-20359) as part of a cyber espionage campaign (‘ArcaneDoor’). The campaign targets government entities. While its initial attack vector is unknown, the group exploited the two vulnerabilities through their Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) firewalls. It then deployed two backdoors, ‘Line Dancer’ and ‘Line Runner’. The backdoors enabled the group to execute code remotely, as well as to move laterally, conduct reconnaissance and exfiltrate data. The sophisticated tactics, techniques, and procedures (TTPs) point to the group’s likely state affiliation. State-sponsored groups often exploit zero-day vulnerabilities in the software supply chain to conduct espionage campaigns, as they facilitate access and persistence. The revelation underscores the sustained security and espionage risks facing global government entities which stem from the software supply chain. (Source: Sibylline)

 

24 Apr 24. Lockheed Martin Australia, Defence sign $500m head contract for AIR 6500. Defence Industry Minister Pat Conroy has announced the signing of a $500m contract between Lockheed Martin Australia and the Department of Defence to build Australia’s future Joint Air Battle Management System under project – AIR 6500 Phase 1.

This milestone contract paves the way for Lockheed Martin to begin delivering the next stage of Australia’s Joint Air Battle Management System, as part of AIR 6500, expected to generate at least 230 jobs directly related to its operation, along with many more during construction.

In addition to these 230 jobs across Adelaide, Canberra and Williamtown outside of Newcastle, Defence Industry Minister Pat Conroy highlighted that the project will also create 300 indirect jobs in Australia’s air and missile defence supply chain and provide opportunities for Australian industry to benefit from a global $83bn export market.

Minister Conroy said, “This $500m contract continues the work by the Albanese government on next-generation air missile defence. This is an investment in our national security but also an investment in a future made in Australia which will support local businesses and create hundreds of jobs and support many more.”

AIR 6500 will deliver four advanced air-defence radars, manufactured by Canberra-based CEA Technologies, with the first delivery expected later this year.

Erika Marshall, vice-president, C4ISR, Lockheed Martin Rotary and Mission Systems, expanded on the comments made by Minister Conroy, saying, “We are honoured to be the Australian Defence Force’s strategic partner and lead the delivery of AIR 6500-1. At the core of this 21st century security, joint all-domain system is Australian industry.”

Ahead of the AIR 6500-1 contract signing, Lockheed Martin Australia developed an Operator Evaluation System for the Joint Air Battle Management System. This was delivered ahead of schedule and on budget. Using this system, Defence’s air battle managers can access a secure test environment to provide feedback on AIR 6500-1’s design and functionality. This feedback will inform future development activities.

Lockheed Martin will partner with a range of Australian defence industry businesses, including Boeing Defence Australia, C4i, Leidos Australia, Lucid Consulting Australia, Raytheon Australia, Shoal Group, and Silentium Defence to deliver this critical capability to the Australian Defence Force.

Minister Conroy said, “The Albanese government is actively creating opportunities for Australian industry, through the entire supply chain of small-and-medium enterprises, as we deliver these critical defence capabilities.”

Lockheed Martin Australia and New Zealand’s chief executive, Warren McDonald, commended Defence and Lockheed Martin Australia’s AIR 6500 Team on achieving this historic strategic partnership.

“AIR 6500-1 will give Australia and our allies a greater level of connectivity and interoperability to counter current and future air and missile threats. In a contested and fast-moving environment, AIR 6500-1 will give decisionmakers more time to consider and respond to a situation – time in these circumstances is a precious commodity,” McDonald explained. (Source: Defence Connect)

 

23 Apr 24. Iraq to equip F-16s with AIDEWS EW suite. Iraq is to equip its Lockheed Martin F-16 Fighting Falcon combat aircraft with the L3Harris AN/ALQ-211 Advanced Integrated Defensive Electronic Warfare Suite (AIDEWS) electronic warfare (EW) system, the US Department of Defense (DoD) disclosed on 22 April. The DoD requires the retrofit of the AIDEWS system into 34 Iraqi Air Force (IqAF) F-16C/D Block 52M aircraft located at Martyr Brigadier General Ali Flaih Air Base (Ali Flaih AB [AFAB], previously known as Balad Air Base), a solicitation posted on the SAM.gov US government procurement website said. The DoD solicitation provided no contract value or timeline details. The AIDEWS comes in both an AN/ALQ-211(V)4 integrated and an AN/ALQ-211(V)9 podded configuration, with the newer Block 52 and above aircraft of operators such as the IqAF having the internal space needed for integration, while older block aircraft do not and therefore, require the podded system. The IqAF fields 24 single-seat F-16C and 10 twin-seat F-16D aircraft, deliveries of which commenced in 2014. (Source: Janes)

 

24 Apr 24. uAvionix Partners with Viasat to Deliver Seamless Global Communication Service for Uncrewed Aerial Vehicles. Viasat, Inc., a global satellite communications company, has announced  collaboration with uAvionix, a pioneer in the development of certified avionics for crewed and uncrewed aviation. uAvionix will join Viasat’s Velaris Partner Network.

Following a strategic alliance agreement between the companies to develop products and services for the uncrewed aerial vehicle (UAV) market, uAvionix has begun integrating Viasat’s Velaris module into its compact muLTElink airborne radio system. Powered by Viasat’s global L-band network, Velaris provides secure, resilient, L-band, communications for commercial UAVs. Velaris enables real-time monitoring for Beyond Visual Line of Sight (BVLOS) UAV operations, with seamless integration into commercial airspace.

uAvionix’s system combines C-band, LTE, ISM and Viasat L-band, and carefully monitors and manages each data link using a DO-377A Link Executive Manager (LEM) while automatically registering aircraft with uAvionix’s SkyLine Cloud Managed BVLOS service.

SkyLine is the first cloud-based command and control network that combines fleet management, network health monitoring, detect & avoid, and seamless make-before-break roaming between multiple radio networks and ground stations and is purpose built to enable Beyond Visual Line of Sight (BVLOS) safety cases.

During system integration testing in 2023, uAvionix configured and integrated a Velaris development terminal with its SkyLine system and established a “very stable streaming connection” in a matter of just days.

Cyriel Kronenburg, VP Aviation Networks at uAvionix said: “uAvionix successfully flew with Velaris connectivity in northern Montana. Notably, where the LTE radio had good performance on the ground before take-off, and the SkyLink C-band ISM radios had good performance while in our area of operations, the satcom let us close the gap by providing phenomenal performance with a very stable streaming connection while enroute from the airport to our deployed SkyStations. It’s a huge testament to the ease of use of satcom and how supportive the Viasat team has been.”

Joel Klooster, SVP, Flight Safety and AAM at Viasat, said: “uAvionix is a highly respected and innovative avionics and software company. This partnership formalizes a number of initiatives and programs the two companies are collaborating on, and we look forward to future projects. uAvionix has a proven track record of developing cutting-edge technology for the aviation industry, and our combined expertise will lead to even more advancements in the field.” (Source: UAS VISION)

 

23 Apr 24. AeroVironment (AV) has introduced its Autonomy Retrofit Kit (ARK) and AVACORE software demonstrating the company’s commitment to advancing autonomy and machine learning capabilities to increase effectiveness of autonomous systems and reduce operator burdens. ARK and AVACORE bring AV’s accelerated autonomy to fielded assets such as Puma™ 3 AE and Puma™ LE, in addition to future autonomous systems.

ARK is a quick-connect payload introducing a new suite of intelligent mission capabilities for Group 1+ unmanned aircraft systems (UAS). Providing edge computing for mission-critical applications, ARK enables operators to task a single or multi-vehicle team with mission objectives for fully autonomous execution while operating in communications-contested environments. ARK also intelligently integrates with distributed groups of dismounted units in a Mobile Ad Hoc Network (MANET) using the Android Team Awareness Kit (ATAK).

AVACORE is AV’s autonomy software providing an open framework for unmanned systems. It features a modular set of interfaces such as autopilots, radios and sensors, and supports rapid integration with new platforms and applications. ARK also comes preinstalled with SPOTR-Edge, AV’s computer vision software, for onboard detection, classification, localization, and tracking of operationally relevant objects including people, vehicles, aircraft, and maritime vessels, day or night.

“ARK and AVACORE provide enhanced capabilities and critical advantages to warfighters on complex battlefields,” said AV’s Senior Vice President of MacCready Works, Jeff Rodrian. “This payload combines AV’s unparalleled autonomy and field-proven computer vision SPOTR-Edge to accelerate awareness and mission success.”

Though the combination of autonomy and computer vision, ARK and AVACORE allow operators to select a wide variety of single or multi-agent capabilities including multi-region search, track and follow and more. The introduction of these systems builds upon AV’s proven and trusted family of autonomous systems, bringing a scalable, adaptable AI toolset to fielded and new assets for safer, smarter mission capabilities.

“AVACORE features an intuitive behavior tree approach allowing flexibility for rapid development and adoption of new autonomous missions,” continued Rodrian. “This results in smarter systems with reduced cognitive load for warfighters.” (Source: BUSINESS WIRE)

 

24 Apr 24. PPM Systems Enables A 5x Increase in Detection Range. One infrastructure, all capabilities: discover evergreen RF over fibre architecture solutions. PPM Systems are increasing observational antenna radius by solving signal distribution limitations*. Enabling the next step in capability performance across multiple domains, PPM Systems have integrated operationally and commercially proven RF over fibre products together to form complete RF over fibre architecture solutions. For delegates attending the Combined Naval Event in May, these solutions will be available to explore on stand E04.Leveraging the benefits of COTS products and developing them for defence applications, PPM Systems uses extensive domain knowledge to form complete RF over fibre architecture solutions for the maritime ESM (Electronic Support Measures), EW (Electronic Warfare), CEMA (Cyber and Electromagnetic Activities) and C-UAS / C- USV (Counter Unmanned Aerial Systems / Common Unmanned Surface Vehicle) domains. The industry leading knowledge within PPM Systems ensures seamless signal transmission even in demanding maritime and land environments, whilst providing exceptional signal quality and performance alongside antenna positioning freedom. The solutions are, and continue to be, developed in alignment with open standards such as Open VPX, with PPM Systems poised to enable EW capabilities through ruggedised and dynamically reconfigurable signal distribution – a step change in capability for customers.Helping to ensure countries develop their maritime capabilities, ensure freedom of navigation is not threatened and, when necessary, sea control and denial are achieved, the Navy Leaders Combined Navy Event is a must-attend, especially as the maritime environment is emerging as a key priority for NATO and its partners. The intent is for a wide cross-section of attendees from international navies, defence industry and academia to explore how to align in common purpose to ensure naval capabilities match to the strategic, operational and technological opportunities and demands of the future.

The event will be held at the Farnborough International Exhibition Centre on 21st – 23rd May, where over 1500 attendees will be able to explore these RF over fibre architecture solutions that deliver ‘Any Signal, Anywhere’. Providing an easy post-design integration option with lossless and secure signal transport, these solutions are ideal for routing into SCIF environments, and for cost effective improvement of maritime ESM capabilities. Don’t miss the largest annual naval event in Europe – register to attend the Combined Naval Event at navyleaders.com today. *10m coax based antenna at 18 GHz would have 18% of the observational radius of the optically enabled Antenna CCU

 

23 Apr 24. China dissolves Strategic Support Force, focused on cyber and space. China has disbanded and replaced its Strategic Support Force, a pivotal component of the People’s Liberation Army’s modernization efforts. The Strategic Support Force, or SSF, was created on Dec. 31, 2015. It existed for a little more than eight years.

After China dissolved the SSF on April 19, it established an Information Support Force, with President Xi Jinping present at its investiture ceremony in Beijing the same day.

Its first commander is Lt. Gen. Bi Yi, a former deputy commander of the SSF. The Information Support Force is directly subordinate to the Central Military Commission, the top political party organ that oversees China’s armed forces.

Senior Col. Wu Qian, a Defense Ministry spokesperson, said the change is part of “building a strong military, and a strategic step to establish a new system of services and arms and improve the modern military force structure.”

He added that the Information Support Force underpins “coordinated development and application of network information systems.” This suggests it is responsible for command and control, information security, and intelligence dissemination.

He also said the move would have “profound and far-reaching significance” on PLA modernization. However, Brendan Mulvaney, the director of the U.S. Air Force’s China Aerospace Studies Institute, told Defense News it’s unlikely to be “as big of a shift as the 2015-2016 reforms,” which overhauled the PLA.

The military considers the information domain as important as the four traditional air, land, sea and space domains.

The PLA now has three nascent arms — the Information Support Force, Cyberspace Force and Aerospace Force. It appears the latter two were existing SSF departments that China renamed.

After the shakeup, the PLA’s new organization features four services and four arms: the existing PLA Army, Navy, Air Force and Rocket Force services, while the three previously mentioned arms sit alongside a fourth, the incumbent Joint Logistics Support Force.

The Cyberspace Force will subsume the responsibilities of the SSF’s former Network Systems Department, whose mandate was offensive and defensive cyber operations.

Indeed, the Defense Ministry described the Cyberspace Force’s role as “reinforcing national cyber border defense, promptly detecting and countering network intrusions and maintaining national cyber sovereignty and information security”.

The Aerospace Force will take on the charge of the SSF’s Space Systems Department, meaning it will supervise space operations and space launches. Wu said the force will “strengthen the capacity to safely enter, exit and openly use space.”

The ministry said that “as circumstances and tasks evolve, we will continue to refine the modern military force structure.”

Xi has repeatedly urged the PLA to do two things: modernize its readiness structure for high-tech combat, and to loyally follow party diktats.

He has now ordered the Information Support Force to “resolutely obey the party’s command and make sure it stays absolutely loyal, pure and reliable.” (Source: Defense News)

 

22 Apr 24. New Research Shows Accelerating AI Adoption is Critical to Public and Private Sector Resilience Against Evolving Cyber Threats.

Eighty percent of cybersecurity decision makers say accelerating artificial intelligence adoption is critical to their organization’s resilience against evolving threats, but only 31 percent say their organization is using AI today, according to a new study from MeriTalk, government IT’s top digital platform, and RSA Conference, the world’s leading information security conferences and expositions.

The study – which compiles qualitative data from five in-depth interviews with senior cybersecurity leaders, as well as quantitative data from 100 Federal and 100 private sector cybersecurity decision-makers, examines early cyber AI wins and asks cyber professionals how they want to work with AI going forward. While 86 percent feel human-AI collaboration will become the cornerstone of effective cybersecurity strategies, just one in five fully trust AI to automate cybersecurity decisions. When it comes to their ideal division of responsibilities, cyber leaders want humans to keep majority ownership of more nuanced efforts like strategic planning, innovation, and governance; while AI takes the lead on data-heavy efforts like cyber risk assessments and threat detection and response.

While most organizations view their current AI governance as adequate, critical policy gaps exist. Less than half have documented policies for decision-making models or formal ethical or program testing guidelines, and just 40 percent report policies specific to critical infrastructure. Additionally, just 30 percent feel their organization is well prepared to combat AI-driven cybersecurity threats. The challenges having the biggest impact on AI adoption are fears of increased attacks on new AI models, data, or services, a lack of a skilled workforce to implement, and data quality, integrity, or availability challenges.

“AI technologies, like machine learning (ML) and natural language processing (NLP), are not new to cybersecurity, but their applications are quickly evolving from optional enhancements to strategic necessities,” said Nicole Burdette, principal, MeriTalk. “We are already seeing AI users improve vulnerability detection and accelerate incident response times. The challenge for the next 6-12 months will be putting the right guardrails in place so organizations can maximize AI adoption and benefits while minimizing additional risk.”

“The impact of AI across our industry is seismic, and we’re clearly in the early days of understanding and adapting to the impact on teams and tools,” said Britta Glade, Vice President, Content & Curation, RSA Conference. “As evidenced in this research, the days and months ahead will be critical, and organizations must clearly and purposefully evaluate and define the boundaries and guardrails for how AI will be infused into workstreams and processes.”

When asked to envision the future of human-AI collaboration, cyber professionals relayed a mix of optimism and caution. While many see immense potential for innovation, efficiency, and improved security, concerns around safety, ethics, and responsible development remain.

To optimize AI’s cyber impact, the report recommends organizations:

  • Start with increased human communication and collaboration
  • Emphasize a culture of continuous learning
  • Evaluate AI use cases by tech maturity, mission value, and risk
  • Build in AI security from inception
  • Be realistic about expectations
  • Focus on thorough testing and evaluations
  • Embrace change

The Art of Human and AI Teaming in Cybersecurity report is underwritten by Fortinet Federal and Maximus. The report has a margin of error of ±6.93 percent at a 95 percent confidence level. To review the full findings, visit: https://meritalk.com/study/art-of-human-and-ai-team-cybersecurity/?campaign=pr

About MeriTalk

The voice of tomorrow’s government today, MeriTalk is government IT’s top digital platform. Our award-winning editorial team and world-class events and research staff produces unmatched news, analysis, and insight. The goal: more efficient, responsive, and citizen-centric government. MeriTalk connects with an audience of 160,000 Federal community contacts. For more information, visit www.meritalk.com or follow us on X, @MeriTalk. MeriTalk is a 300Brand organization.

About RSA Conference

RSA Conference™ is the premier series of global events and year-round learning for the cybersecurity community. RSAC is where the security industry converges to discuss current and future concerns and have access to the experts, unbiased content, and ideas that help enable individuals and companies advance their cybersecurity posture and build stronger and smarter teams. Both in-person and online, RSAC brings the cybersecurity industry together and empowers the collective “we” to stand against cyberthreats around the world. RSAC is the ultimate marketplace for the latest technologies and hands-on educational opportunities that help industry professionals discover how to make their companies more secure while showcasing the most enterprising, influential, and thought-provoking thinkers and leaders in cybersecurity today. For the most up-to-date news pertaining to the cybersecurity industry visit www.rsaconference.com. Where the world talks security. (Source: BUSINESS WIRE)

 

22 Apr 24. The British Army Land ISTAR team have just returned from Project Convergence Capstone 4 in the USA where, more than 600 British Army soldiers participated in a major war-fighting experiment alongside personnel from several other countries, including the US Army, Defence Australia, New Zealand Defence Force, Canadian Army | Armée canadienne, Armée de Terre, and Japan Ground Self-Defense Force. As well as integrating ZODIAC with multiple platform sensors – for instance, Watchkeeper, Puma and the latest UAV platform from Lockheed Martin’s Tiquila project (Indago) – using ZODIAC, the team collaborated with our Five Eyes partners for a more streamlined, heightened shared intelligence picture. Battlefield digitalisation under the ZODIAC programme ensures the British Army is at the forefront of digital development and integration of the sense-decide-effect chain. This supports the realisation of the Land Operating Concept and the modernisation of the UK’s warfighting capability. (Source: British Army)

 

22 Apr 24. Oracle Cloud Secret Impact Level 6 Regions for U.S. Department of Defense. Oracle today announced the accreditation of three cloud regions for the U.S. Department of Defense (DoD) with Defense Information Systems Agency (DISA) Impact Level 6 (IL6) authorization to host Secret classified workloads. Oracle Cloud Infrastructure is now available at all DoD classification levels, providing defense customers support for their full technology portfolio and more capability to fulfill their mission.

DoD customers operate many fragmented information systems on modern and legacy infrastructure, making it difficult to collect, analyze, secure, scale, and act on critical data to make real-time decisions. The DoD needs the best technology to succeed in an increasingly contested environment. As adversaries advance their capabilities, the DoD needs data, AI, and compute platforms that give our warfighters the technical overmatch they deserve.

“America’s warfighters must have the world’s preeminent technology and our taxpayers insist that technology is delivered at competitive costs. Oracle is bringing both to the Department of Defense’s Secret networks.” says Rand Waldron, vice president, Oracle. “Technology no longer sits outside the mission; technology is a part of the mission. In austere locations with limited communication, and in massive secure data centers, Oracle is bringing our best capabilities to serve the men and women that defend the U.S. and our Allies.”

Oracle’s air-gapped classified regions solve many of the DoD’s challenges with the latest innovations from the public cloud, competitive pricing, powerful analytics, and enhanced security. Oracle Cloud classified regions come with our Everything Everywhere® commitment to offer the same Oracle Cloud services that are available in the Oracle public cloud. This commitment ensures DoD technologists get leading edge cloud services and hardware to accelerate their work. These Oracle services provide customers higher performance, lower cost capabilities with consistent pricing across all classification levels.

Oracle Modern Data Platform simplifies the end-to-end data lifecycle to deliver critical insights faster. With Oracle’s comprehensive analytics and AI portfolio, users can leverage high-performance computing (HPC) to bring powerful, cost-effective computing capabilities to solve complex problems.

Oracle Cloud Infrastructure security is simple, prescriptive, and always-on. Our zero trust approach to cloud security helps customers implement a DISA Zero-Trust Reference Architecture. Oracle Cloud classified regions are supported and managed from secure, dedicated, cloud network operation centers, which are only accessed, monitored, and staffed by U.S. government-cleared personnel.

Join Oracle experts, partners, and thought leaders to learn about the latest technology trends and news at Oracle Federal Forum on Thursday, April 25 in Washington, D.C.

About Oracle

Oracle offers integrated suites of applications plus secure, autonomous infrastructure in the Oracle Cloud. For more information about Oracle (NYSE: ORCL), please visit us at oracle.com.

Trademarks

Oracle, Java, MySQL and NetSuite are registered trademarks of Oracle Corporation. NetSuite was the first cloud company—ushering in the new era of cloud computing. (Source: PR Newswire)

 

22 Apr 24. Micro-Ant, a leader in bespoke antenna design and manufacturing, has announced that its Airborne High Gain Antenna (HGA) passed a key test from Iridium Communications Inc. Achieving this milestone allows for the HGA’s use with Value-Added Manufacturer (VAM) developed Iridium Certus® 700 aviation terminals.

The Micro-Ant HGA is an electronically steered antenna with two simultaneous beams. The testing demonstrates that the antenna successfully tracks the Iridium® satellite constellation and switches satellites effectively, maintaining strong network signals at low elevation angles. Micro-Ant’s beam handover technology provides reliable satcom voice and data connectivity during flight maneuvers such as banking.

Micro-Ant’s airborne HGA Iridium antennas need to accurately track Iridium satellites from a moving aircraft and switch from one satellite to another as the satellites are moving across the sky. The key test passed by Micro-Ant, called monotonic testing, simulates these movements, and evaluates the antenna’s ability to maintain a lock on a satellite while adjusting the azimuth and elevation angles of the antenna.

Micro-Ant is now able to work with Iridium VAMs on system level and airworthiness certification efforts to put the aircraft antenna into service by the end of 2024.

“Exciting progress is being made by Micro-Ant, and we look forward to them supporting Iridium’s partners and bringing new state-of-the-art aviation products to the market,” said John Peterson, Executive Director, Aviation, Iridium. “Iridium Certus aviation solutions are setting a new standard for cockpit communications performance, and Micro-Ant’s new cost-effective, low-profile antenna will further reinforce the value these new solutions bring.”

Micro-Ant is part of the Iridium partner ecosystem, a collective of partners, enabling leading global technology companies to leverage Iridium’s unique network to manufacture, develop, market, and support innovative applications for a variety of different markets and industries.

This antenna will continue to support growing the Iridium Certus satcom ecosystem, which utilizes the Iridium constellation of 66 Low-Earth Orbit (LEO) satellites. The Iridium network is outfitted to provide critical communications including supporting the increasing demand for connectivity for the aviation industry from commercial passenger aircraft, business jets, rotorcraft, and unmanned aircraft.

Micro-Ant currently provides similar beam steering antennas for the Iridium Certus maritime vessel community. These highly efficient multi-patch antennas contain no moving parts and are robust enough for any all-weather conditions at sea.

About Micro-Ant

Founded in 2003, Micro-Ant designs, develops, and manufactures custom antennas for land, maritime, IoT, and aerospace applications operating within the Microwave Frequency Spectrum including UHF, L, S, C, X, Ku and Ka-bands.

Micro-Ant develops strategic antennas for various applications, including 2-way SATCOM, COTM, aircraft, SDARS, DVB, and GPS. Products include phased arrays, patch antennas, parabolic and flat panel antennas, and low-profile active antennas. Micro-Ant operates several world-class manufacturing facilities, headquartered in Jacksonville, Florida. (Source: PR Newswire)

 

22 Apr 24. Orion Technology Group Integrates Doodle Labs Datalinks into X BLUE NANO Drones. Orion Technology Group, a manufacturer of advanced artificial intelligence UxVs and mission software, has announced the integration of Doodle Labs’ cutting-edge Mesh Rider Radios into its full line of AIM BLUE drones, including its newest X2 BLUE NANO, a cargo pocket-sized nUAS with indoor and outdoor autonomous navigation capabilities.

Orion’s Artificial Intelligence Mission (AIM) system includes three AI aerial platforms with payloads up to 10kg. The smallest, the X BLUE NANOs, fills the need for a person-portable, body-worn UAS platform that is fully autonomous, easily carried and can provide GPS-denied ISR (intelligence, surveillance and reconnaissance) indoors and outdoors for tactical military and public safety teams. The company’s nano line includes five different airframe options, modular motors and prop guards and a multitude of swappable payloads, including cameras, thermal and LIDAR scanners.

Integrating Doodle Labs’ low-SWaP (size, weight and power) Mesh Rider Radio as an available on-board datalink across the entire line provides resilient connectivity and enables advanced performance in contested and disconnected spaces without compromising even the nano drones’ tiny profiles. The X2, the lightest frame in the modular suite of drones can be configured under 249 grams, or just over half a pound.

Doodle Labs’ radios are themselves incredibly small – the 2×2 MIMO mini Mesh Rider Radio weighs just 34 grams, while the 1×1 SISO nano version is only 26 grams – but do not skimp on performance. The company’s mini Mesh Rider Radio delivers up to 80Mbps of throughput and has been field-verified to transmit full HD video at 20+ kilometers.

Development of Doodle Labs’ Mesh Rider Radio was sponsored in part by the US Department of Defense’s Defense Innovation Unit (DIU), is on the Blue UAS Cleared components list and is NDAA-compliant. Orion’s full line of X BLUE NANO drones is also NDAA-compliant.

Doodle Labs will showcase the X2 BLUE NANO alongside its full Mesh Rider Radio lineup at its booth at Xponential 2024, one of the world’s largest drone and robotics trade shows, April 23-25 in San Diego.

“We’re always excited to learn about the new and innovative ways our customers leverage the Mesh Rider Radio, so we’re looking forward to showcasing such a unique nano-drone on our booth at Xponential,” said Doodle Labs Co-CEO Amol Parikh. “There’s a real demand for flexible, compact, high-performance UAV platforms within the DoD, law enforcement and other agencies with tactical teams. We’re happy our high-bandwidth, low-latency radios are such a perfect fit for these newest models from Orion.”

“Our nanos, tethered and even our 10kg payload AI drones were designed to be NDAA compliant and meet specific client requirements including ATAK control, modularity and being AI swarm capable out of the box. The Mesh Rider Radios met all the requirements for a high-performance, cost-effective radio that could meet the extreme SWaP needs of the latest X BLUE NANOs,” said Orion’s CEO Seth Spiller. (Source: UAS VISION)

 

22 Apr 24. US Army launches new kit to enhance multinational communication. The new mission partner kit (MPK) will support secure, multilingual communication between US and allied forces during multinational exercises. The US Army has unveiled an MPK designed to streamline communication across different languages during multinational military exercises.  This kit was showcased during the Saber Strike 24 exercise, part of the DEFENDER-Europe 24 series, where precise coordination between forces is crucial.

The MPK, a central element of the Extending the Network initiative, comprises three main applications, as reported by SPC Andrew Clark.

It includes Wickr for end-to-end encrypted messaging, Instant Connect Enterprise (ICE) for voice interoperability, and a Tactical Assault Kit (TAK) compatible with various operating systems such as Windows, Apple and Android devices.

Additionally, the kit includes a Radio Integrated Communications Suite (RICS) to enhance connectivity.

Wickr provides a secure platform for sharing data and coordinating with tactical mission data platforms in the field, according to US Army 1st lieutenant Joshua Chang of the 2nd Cavalry Regiment.

The RICS kit, paired with the ICE application, enables conversion of FM wavelength into internet protocol data, reducing equipment needs and extending communication networks.

Chang explains the practicality of the system, where a German soldier can speak in their language and US forces can receive the translated message in English.

The TAK component is essential for real-time tracking of friend and foe positions, allowing for dynamic collaboration and updates on the battlefield.

Chang added: “Extending the Network allows our mission partners to communicate with us. The MPK allows us to quickly, safely and securely provide our mission partners with voice, chat, collaboration and location-sharing capabilities.”

The MPK also integrates with the US Army 2nd Cavalry Regiment’s tactical network end-user devices, enhancing situational awareness for all members.

This technological advancement represents a step forward in military communication, offering strategic benefits and fostering cooperation with allied nations.

A cyber warfare officer supporting 2CR said: “The concept behind MPK from the interoperability perspective is to simplify access for our tactical forces, whether it is a foreign partner or ourselves.

“Because what we have done is we have simplified and increased access. By simplifying it, we have introduced applications that are familiar to the users.” (Source: army-technology.com)

 

23 Apr 24. The new R&S SMB100B analog microwave signal generator from Rohde & Schwarz offers an outstanding, market-leading performance for analog signal generation up to 40 GHz in the midrange class. Thanks to its easy operation and comprehensive functionality, the versatile R&S SMB100B is now the first choice for all applications requiring clean analog signals or high output power from 8 kHz to 40 GHz. Typical applications include testing radar receivers, semiconductor components, upconverters, downconverters or amplifiers. The high output power and low phase noise make it ideal as a source for simulating interferers for blocking tests.

The R&S SMB100B microwave signal generator features a signal purity which combines very low single sideband (SSB) phase noise, excellent non-harmonics suppression, and low wideband noise for all carrier frequencies. For users seeking even better close-in phase noise and frequency stability, and less temperature-based variation in performance, in addition to the standard OXCO reference oscillator, a higher performance version is available for all frequency ranges. In addition to the conventional 10 MHz reference frequency, users can choose optionally 1 MHz to 100 MHz as well as 1 GHz reference frequency signals. Optional high output power of measured 25 dBm at 20 GHz and 19.5 dBm at 40 GHz is activated by keycode, so users can install it at any time. Considering the microwave frequency range covered by the instrument, the R&S SMB100B microwave signal generator is light (10.7 kg) and compact, fitting in a 19” rack and only two rack units in height.

The level accuracy of the output directly from an R&S SMB100B itself is excellent. With each increase in the frequency of the required signal, the challenge of obtaining the correct level input to a device increases: The R&S SMB100B supports two additional features to compensate for path losses and variations in the signal caused by setups with additional test fixtures, cables or amplifiers. These features help to provide the wanted power level at the reference plane i.e. at the input of the device under test. One of them, the user correction function (UCOR), compensates if the frequency response of the setup is known and stable. However, there are still unknown factors especially if the setup includes additional active devices such as an amplifier. Then the frequency response of the setup with an external additional amplifier can vary over level or temperature. Closed-loop power control can compensate for all these variations by continuously measuring the input level to the DUT i.e. at the wanted reference plane with a suitable R&S NRP power sensor feeding its measured level back to the generator to adjust the output power accordingly. More details about this use case can be found in the application note 1GP141.

The R&S SMB100B is user-friendly in every detail. Users can create their own customized menus, so that the parameters they most use are always available. They can generate code to automate measurements first made manually with the SCPI macro recorder while the measurements are set up and run, then use the code generator to export the instructions in languages such as MATLAB®. Thanks to R&S Legacy Pro, the R&S SMB100B (and other Rohde & Schwarz test equipment) can be used to emulate other instruments such as R&S SMB100A or competitor instruments directly, as a drop-in replacement using the existing code.

The new R&S SMB100B microwave signal generator up to 40 GHz is now available from Rohde & Schwarz and expands the R&S SMB100B analog signal generator family with its established RF models up to 6 GHz. For more information on visit: https://www.rohde-schwarz.com/product/smb100b

 

19 Apr 24. Cyber Update Key points.

  • A new campaign targeting firewalls highlights sustained security and information theft risks stemming from zero-day vulnerabilities (see Sibylline Cyber Daily Analytical Update – 15 April 2024).
  • A new malware campaign has targeted Russian critical infrastructure, highlighting national security threats posed by state-aligned actors (see Sibylline Cyber Daily Analytical Update – 16 April 2024).
  • A new vulnerability has exposed cloud services’ sensitive data, underscoring the security and financial risks stemming from the software supply chain (see Sibylline Cyber Daily Analytical Update – 17 April 2024 and our Technical analysis below).
  • A new backdoor targeting Eastern European organisations points to elevated Russian-backed cyber espionage threats and disruption risks (see Sibylline Cyber Daily Analytical Update – 18 April 2024 and our Technical analysis below).
  • A ransomware operation targeting the UN highlights the financial and reputational risks facing international humanitarian organisations.

Technical analysis of weekly stories

A new vulnerability, ‘LeakyCLI’, was identified in Amazon’s and Google’s respective cloud services. The vulnerability stems from a tool used to streamline software development. Both platforms use command-line interfaces (CLIs) to manage and interact with their cloud platforms, as well as continuous integration and continuous deployment (CI/CD) environments to automate software releases. Configuration and environment data is usually recorded in a system’s build logs when both programmes complete their development processes and present the output to the end user. However, this information is often stored in plain text due to a configuration automation; this possibly results in the exposure of sensitive data to threat actors, including passwords. Although no incidents have been reported at the time of writing, threat actors are able to exploit these exposed credentials to move laterally and to escalate their privileges within compromised networks. Third-party cloud services often widen an organisation’s attack surface; they rely on shared security practices between vendors and customers, thereby presenting a significant security challenge for organisations.

The Russian state-sponsored group ‘Sandworm’ targeted organisations in Ukraine and other Eastern European countries with a new backdoor, ‘Kapeka’. The backdoor is designed to provide threat actors with intelligence-gathering capabilities as well as long-term access and prolonged obfuscation on victims’ systems. Although it is unclear how the malware is initially distributed, a malicious payload containing a dropper downloads the backdoor onto a victim’s system. Kapeka then collects information about the compromised system, forwarding it to actor-controlled command and control (C2) infrastructure. The backdoor also masks itself as a legitimate file to evade detection; it also supports the execution of custom payloads to enable threat actors to deploy additional malicious files. The malware’s multiple obfuscation techniques and multi-pronged nature highlight the potential expansion of Sandworm’s arsenal, as well as the growing sophistication of its tactics, techniques and procedures (TTPs). Kapeka was likely used to aid in the deployment of the ‘Prestige’ ransomware in late 2022, which disrupted Ukraine’s and Poland’s transport and logistics sectors.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Enforce strict security policies such as regular software and password updates, as well as adequate network segmentation, to prevent lateral movement following an infection
  • Ensure sensitive information is stored securely in appropriate password management services, avoiding the use of plain text
  • Monitor devices and networks for suspicious activity
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network
  • Ensure adequate security detection measures are in place, particularly behaviour-based end-point detection and response (EDR) solutions

Our cyber word of the week: Obfuscation (Source: Sibylline)

———————————————————————————————————————————————————————————————————————————————————————————————————————————————-

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

————————————————————————————————————————————————————————————————————————————————————————————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

April 19, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

————————————————————————

18 Apr 24. Epiq Solutions Partners with CyNtell to Provide Wireless Device Detection Systems for the DoD. Epiq Solutions (Epiq), a leading provider of software-defined radios and advanced wireless sensing systems, and CyNtelligent Solutions (CyNtell), a leading Federal cybersecurity services provider and certified 8(a) and HUBZone small business have established a partnership to provide complete solutions for wireless device detection in DoD sensitive areas.

The demand for device detection and mitigation has grown tremendously with the proliferation of low-profile wireless devices in everything from televisions to power tools to running shoes.  Coupled with the ubiquity of personal smartphones and smart devices, enforcing the DoD’s no-wireless policy in secure spaces, Sensitive Compartmented Information Facilities (SCIF), and Special Access Program Facilities (SAPF) have never been more of a challenge.

Wireless devices in secure spaces are seen as a threat to the sensitive information contained there and increasingly a potential cyber attack vector for adversaries.  As recently as July, the Secretary of Defense authored a memo reinforcing the no wireless policy in SCIFs and SAPFs and providing guidance to program for and use electronic detection systems to ensure compliance.

The partnership between Epiq and CyNtell provides Federal customers with systems to detect, decode, and locate wireless devices in secure spaces and integrate this capability into cyber operations. The combination provides a turnkey experience for customers that includes site planning, installation, integration, training, and support and maintenance services.

“We’re delighted to partner with CyNtell, a cybersecurity team specializing in delivering wireless systems that make a difference to the DoD,” said Gary Schluckbier, Epiq’s Vice President of Product. “The combination of our teams’ technology and expertise will provide the DoD with an end-to-end solution that will help ensure policy compliance and manage risk exposure to the growing wireless threat.”

“With years of experience deploying and supporting wireless intrusion device systems, our team understands the budgeting, deployment, and management challenges the DoD faces in implementing such systems,” said Claude Williams, CyNtell’s CEO. “Epiq’s Flying Fox product is field-proven in large and small installations, and we’re excited to amplify the availability of this technology to the DoD. We are laser-focused on the success of Flying Fox with the primary objective of extending the sales and support capabilities of Epiq and existing partners.”

For more information about the wireless device detection offering, please visit epiqsolutions.com/products/integrated-systems/flying-fox.

About Epiq Solutions

Epiq Solutions develops cutting-edge software-defined radio products and processing solutions to enable spectrum dominance for maritime, land, air, and space domains. With more than 14 years serving government and commercial enterprise customers and 20K+ devices fielded to date, Epiq Solutions is a trusted partner with a proven heritage of delivering open architecture products in radically small form factors where time-to-market, cost, and performance are critical for mission success. For more information, visit epiqsolutions.com.

About CyNtelligent Solutions

CyNtelligent Solutions, LLC (CyNtell) was established in 2016 to provide professional services to the Federal government, specifically DoD. CyNtell provides exceptionally rated professional and educational services and support as a prime and subcontractor. Our staff is highly experienced with proven expertise evidenced through achieved industry credentials like CISSP, CSA+, CASP, CEH, CHFI, EDRP, ECIH. CyNtell is an SBA 8(a) and HUBZone certified small business and GSA contract holder. Connect with CyNtell at cyntell.com (Source: PR Newswire)

 

17 Apr 24. Global: New vulnerability exposes sensitive data, highlights security, financial, social risks to firms. On 16 April, the cloud security company Orca Security reported a new vulnerability, ‘LeakyCLI’, affecting Amazon and Google cloud services. The vulnerability stems from command-line interfaces (CLIs) which are used by both cloud providers to manage and interact with their cloud platforms. CLIs notably bypass normal security mechanisms used to conceal sensitive configuration and environment information. This potentially provides threat actors with access to sensitive credentials, including usernames and passwords. Cyber criminals typically use sensitive account credentials in social engineering attacks to move laterally through compromised environments and conduct further malicious activity. This underscores elevated security, financial and social engineering risks to global firms, as cyber criminal actors increasingly exploit software weaknesses as part of their operations to garner illicit profit. Third-party cloud services present significant security challenges for IT teams, as they rely on shared security practices. The software supply chain consequently faces heightened security risks. (Source: Sibylline)

 

16 Apr 24. Silvus and Kagwerks marry radios, chest rigs for battle communications. Silvus Technologies and Kagwerks collaborated on equipment they said will streamline battlefield communications.  Defense contractors Silvus Technologies and Kagwerks unveiled a combination of their products they said will reduce the burden of gear on troops while also streamlining battlefield communications. The companies on April 16 rolled out their Dismounted Operator’s Combat Kit StreamCaster line of products, which marries a mobile ad-hoc network radio, a ruggedized tablet and a rig that can be worn on the chest for easy access. Jimi Henderson, a Silvus vice president, described the kit as a “strategic fusion” of the companies’ expertise.

“This collaboration elevates tactical communications, delivering unparalleled connectivity and situational awareness to empower our force in the most demanding environment,” he said in a statement to C4ISRNET.

The U.S. Department of Defense is putting a premium on connectivity and data-sharing as it prepares for potential large-scale fighting across Europe and the Indo-Pacific.

A key piece of that puzzle is the radios troops carry, that are fitted to manned and unmanned vehicles, and how they perform amid electronic harassment. The digital tubes through which information flows will be jeopardized in a fight with Russia or China, defense officials say.

Silvus has for years worked with the military, including the Army and its Program Executive Office for Command, Control and Communications-Tactical. PEO C3T develops, deploys and supports networking gear across the service. The California-based company in January announced a $3.5 m deal with the executive office for StreamCaster radios and expanded operational testing.

“Silvus is delivering on the Army’s integrated tactical network objectives of high bandwidth mesh networking connectivity across multi-domain environments,” Henderson said in a statement at the time. The ITN, as it’s known, aims to simplify and upgrade communication tools used by soldiers.

Working with PEO C3T and the Network Cross-Functional Team, Henderson said, “enables Silvus to continually optimize our tactical communications capabilities to help the Army advance toward their unified network modernization goals.” (Source: Defense News Early Bird/C4ISR & Networks)

 

17 Apr 24. Goldilock, the British cybersecurity startup behind a unique physical network isolation solution, has partnered with CR14, a cyber defence organisation established by the Estonian ministry of defence and host of NATO’s operative Cyber Defence Centre of Excellence (CCDCOE), to conduct testing activities with the aim of increasing the resilience of critical national infrastructure (CNI). Testing will occur under the banner of NATO’s Defence Innovation Accelerator for the North Atlantic (DIANA), a programme designed to equip governments and businesses of member countries with the skills and knowledge to navigate the world of deep tech and dual-use innovation and to which Goldilock was the only cybersecurity firm selected to become a member.

The convergence of OT and IT in CNI networks makes them complex to defend, while they remain a prime target for state-sponsored cyber-attacks. The partnership between Goldilock and CR14 will demonstrate the benefit of being able to instantly disconnect and physically segment CNI networks such as those governing energy grids and gas and water utilities. Testing will be supported through NATO DIANA’s Test, Evaluation, Validation and Verification (TEVV) grant programme to tackle problems with CNI security architecture.

“Our testing partnership with CR14 will demonstrate exactly how CNI organisations can ensure assets remain secure and take back control,” said Tony Hasek, CEO and Co-Founder of Goldilock. “The global cyber threat landscape continues to grow, and as critical national infrastructure remains the focus of brazen cybercriminals – especially state-sponsored actors – no organisation operating in this sector is safe. It’s crucial, therefore, that organisations in NATO-member countries question whether their OT or IT systems and digital assets need to be constantly online. The new default should be disconnection, with connection and disconnection able to occur on-demand, which is precisely what Goldilock’s patented hardware solution delivers.”

The testing will take place in two phases, starting with a tabletop exercise that will bring together cybersecurity and CNI experts to determine It will also examine operational aspects such as personnel and skills requirements and optimal procedures for employment of Goldilock’s cybersecurity technology to ensure the strongest possible integrated cyber defence and safe operation of CNI systems. Building on these findings, the second phase will involve a ‘real-life’ scenario test. Using CR14’s power grid simulation, this stage will measure key performance parameters and assess the technology’s usability in a practical setting. CR14 and Goldilock will then present the results of the testing jointly in a simulation exercise at both the NATO DIANA Demo Day and also the Latitude59 Conference in May, where CR14 will bring their energy grid wall.

Peter Lenk, Technical Lead at Goldilock commented: “CR14’s wide range of cyber expertise, makes this partnership an incredibly effective one. Its ability to simulate sophisticated cyber-attacks and a physical emulation of a power grid will also demonstrate the true potential Goldilock’s kill-switch delivers in this sector. Recent attacks on UK critical national infrastructure, such as that on Southern Water earlier this year, have demonstrated the huge impact cyber incidents can have on society. Disconnecting CNI from the internet is key to keeping it safe and it allows industry managers to step outside of the cybersecurity arms race and hands them back control of system safety.”

“Goldilock’s hardware-based cyber solution is the perfect pairing to our cyber-physical approach to testing and then reinforcing the security of critical infrastructure,” said Silver Andre, CEO of CR14. “The results of this collaboration could be a game-changer across NATO member countries. Imagine power grids and water treatment plants impervious to cyberattacks – that’s the future we’re working towards here.”

 

16 Apr 24. Pacific Defense, a leading provider of Modular Open Systems Approach (MOSA) products and mission solutions, will continue in its role as the C5ISR Modular Open Suite of Standards (CMOSS) systems engineering, integration, and deployment lead for Palantir’s TITAN Prototype Maturation Phase (PMP) Team. Palantir USG, Inc. was recently awarded a prime agreement for the development and delivery of the Tactical Intelligence Targeting Access Node (TITAN) ground station system, the Army’s next-generation deep-sensing capability enabled by artificial intelligence and machine learning (AI/ML). Pacific Defense’s scope entails analysis, design, integration, and test of CMOSS-aligned mission capability to reduce TITAN system size, weight, and power (SWAP) footprint while also providing a modular, open architecture for rapid insertion of next-generation capabilities throughout the life cycle of the TITAN system. MOSA technical standards like CMOSS and The Open Group’s Sensor Open Systems Architecture™ (SOSA) were expressly created to transform the way weapon systems are designed and supported. These standards unlock a system’s technical baseline allowing customers to openly source and insert best-in-breed capabilities at greatly reduced cost and schedule.

“Pacific Defense is purpose-built to drive the MOSA movement in the US Department of Defense and has been a leading partner of the US Army in creating and delivering CMOSS capabilities,” said Travis Slocumb, CEO of Pacific Defense. “Pacific Defense’s culture is built on open collaboration with its partners and customers and is proud to continue its partnership with Palantir on the TITAN program.”

Palantir’s agreement covers the development of 10 TITAN prototypes, including five Advanced and five Basic variants, as well as the integration of new critical technologies and the transition to fielding. Pacific Defense will design and integrate CMOSS systems TITAN Systems Integration Lab (SIL) and Advanced and Basic variants for deployment and test in the Prototype Maturation program. (Source: BUSINESS WIRE)

 

16 Apr 24. Smiths Detection, a global leader in threat detection and security screening technologies, today announces that it has launched the SDX 10060 XDi, a ground-breaking X-ray scanner powered by diffraction technology. X-ray Diffraction (XRD) is a powerful inspection technology offering highly accurate material discrimination and substance identification based on an object’s molecular structure. XRD is particularly suited to detecting constantly evolving compounds in powder, liquid or solid forms, such as ‘homemade’ explosives or narcotics, even for materials with similar densities.

Multi-level baggage and material handling operations and express forwarders are under pressure to screen huge volumes quickly and efficiently. The SDX 10060 XDi can transform this process by automating the resolution of potential explosive alarms, in turn improving both security and efficiency.

Due to its exceptional sensitivity, XRD technology can also be very effectively deployed to support customs agencies in screening for a range of contraband items including narcotics, helping to mitigate ever-growing threats to society.

Jerome de Chassey, President of Smiths Detection, commented: “We are immensely excited to announce the launch of the SDX 10060 XDi which marks a new era in security screening. Every minute of every day our threat detection and security screening technology helps to protect people and infrastructure, and this new development highlights our commitment to making the world a safer place. X-ray Diffraction will future-proof operations for a large variety of sectors, and we are proud to play a pivotal role in shaping the landscape of future threat detection.”

The SDX 10060 XDi can integrate seamlessly with existing material and baggage handling systems and is designed to meet ECAC Standard 3.1/3.2 and TSA 7.2 plus future regulations. Certification is underway.

 

16 Apr 24. Thales, the cybersecurity leader that protects critical applications, APIs, and data, anywhere at scale, today announced the release of the 2024 Imperva Bad Bot Report, a global analysis of automated bot traffic across the internet. Nearly half (49.6%) of all internet traffic came from bots in 2023—a 2% increase over the previous year, and the highest level Imperva has reported since it began monitoring automated traffic in 2013.

For the fifth consecutive year, the proportion of web traffic associated with bad bots grew to 32% in 2023, up from 30.2% in 2022, while traffic from human users decreased to 50.4%. Automated traffic is costing organizations bns (USD) annually due to attacks on websites, APIs, and applications.

“Bots are one of the most pervasive and growing threats facing every industry,” says Nanhi Singh, General Manager, Application Security at Imperva, a Thales company. “From simple web scraping to malicious account takeover, spam, and denial of service, bots negatively impact an organization’s bottom line by degrading online services and requiring more investment in infrastructure and customer support. Organizations must proactively address the threat of bad bots as attackers sharpen their focus on API-related abuses that can lead to account compromise or data exfiltration.”

Key trends identified in the 2024 Imperva Bad Bot Report include:

  • Global average of bad bot traffic reached 32%: Ireland (71%), Germany (67.5%), and Mexico (42.8%), saw the highest levels of bad bot traffic in 2023. The US also saw a slightly higher ratio of bad bot traffic at 35.4% compared to 2022 (32.1%).
  • Growing use of generative AI connected to the rise in simple bots: Rapid adoption of generative AI and large language models (LLMs) resulted in the volume of simple bots increasing to 39.6% in 2023, up from 33.4% in 2022. The technology uses web scraping bots and automated crawlers to feed training models, while enabling nontechnical users to write automated scripts for their own use.
  • Account takeover is a persistent business risk: Account takeover (ATO) attacks increased 10% in 2023, compared to the same period in the prior year. Notably, 44% of all ATO attacks targeted API endpoints, compared to 35% in 2022. Of all login attempts across the internet, 11% were associated with account takeover. The industries that saw the highest volume of ATO attacks in 2023 were Financial Services (36.8%), Travel (11.5%), and Business Services (8%).
  • APIs are a popular vector for attack: Automated threats caused a significant 30% of API attacks in 2023. Among them, 17% were bad bots exploiting business logic vulnerabilities—a flaw within the API’s design and implementation that allows attackers to manipulate legitimate functionality and gain access to sensitive data or user accounts. Cybercriminals use automated bots to find and exploit APIs, which act as a direct pathway to sensitive data, making them a prime target for business logic abuse.
  • Every industry has a bot problem: For a second consecutive year, Gaming (57.2%) saw the largest proportion of bad bot traffic. Meanwhile, Retail (24.4%), Travel (20.7%), and Financial Services (15.7%) experienced the highest volume of bot attacks. The proportion of advanced bad bots, those that closely mimic human behavior and evade defenses, was highest on Law & Government (75.8%), Entertainment (70.8%), and Financial Services (67.1%) websites.
  • Bad bot traffic originating from residential ISPs grows to 25.8%: Early bad bot evasion techniques relied on masquerading as a user agent (browser) commonly used by legitimate human users. Bad bots masquerading as mobile user agents accounted for 44.8% of all bad bot traffic in the past year, up from 28.1% just five years ago. Sophisticated actors combine mobile user agents with the use of residential or mobile ISPs. Residential proxies allow bot operators to evade detection by making it appear as if the origin of the traffic is a legitimate, ISP-assigned residential IP address.

“Automated bots will soon surpass the proportion of internet traffic coming from humans, changing the way that organizations approach building and protecting their websites and applications,” continued Singh. “As more AI-enabled tools are introduced, bots will become omnipresent. Organizations must invest in bot management and API security tools to manage the threat from malicious, automated traffic.”

Additional Information:

  • Download a copy of the 2024 Imperva Bad Bot Report for additional insights.
  • See how Imperva Advanced Bot Protection, API Security, and Client-Side Protection can protect websites, mobile applications, and APIs from automated attacks and fraud without affecting the flow of business-critical traffic.
  • Read the Imperva Blog for the latest product and solution news, and threat intelligence from Imperva Threat Research.

 

15 Apr 24. Hensoldt to consider Eurofighter EK Step 2 options after buyout of ESG. Hensoldt is considering how to proceed with its plans to offer a new airborne electronic attack (AEA) capability to Germany, following its recent acquisition of Elektroniksystem- und Logistik-GmbH (ESG). A company representative told Janes on 12 April that having previously proposed a joint solution with Rafael Advanced Defense Systems for Step 2 of the Eurofighter Elektronischer Kampf (EK) electronic combat, Hensoldt is considering its position as it waits on the Luftwaffe’s requirements and in light of its procurement of ESG on 2 April.

“We consider Eurofighter EK Step 2 as an important capability enhancement, which is still on the [Luftwaffe’s] agenda. However, requirements and details of implementation are still under consideration [by the customer]. Therefore, we are monitoring closely the developments before drawing conclusions with regard to our further positioning,” the representative said. (Source: Janes)

 

14 Apr 24. ShadowDragon™ Releases The OSINT Platform, Horizon®. ShadowDragon™, a provider of ethical open-source intelligence (OSINT) software, unique datasets and APIs, is pleased to announce significant enhancements to its flagship Open-Source Intelligence Investigative platform Horizon®. These updates represent a milestone in the evolution of investigative technology, offering capabilities to streamline investigative processes and uncover valuable insights.

The OSINT Platform encompasses an all-in-one solution for investigations with unparalleled access to publicly available information, including geolocation data, platform monitoring, breach data and the ability to integrate external data streams. This allows for a modern approach to link analysis in one comprehensive toolkit. Horizon® offers access to more than 225 data collection sources, more than 1500 pivot points, and advanced, customizable link analysis capabilities.

Horizon® is accessible with any internet connection and allows users to access critical data and conduct investigations from any device, providing unprecedented flexibility and mobility. Mapping advancements, plotting capability, visual geofencing, and geoestimation allow for different starting points that pinpoint precise locations and uncover valuable insights. Horizon® offers unmatched ease of integration, creating tailored data streams able to solve for any problem set. Horizon® will also enable analysts the ability to work on the go from a tablet, phone, or desktop/laptop.

Horizon®, coupled with ShadowDragon’s SocialNet ® offers a powerful OSINT toolkit that includes more than 225 data collection sources to use for correlating publicly available data, integrated brand monitoring, breach data inquiries, social media information and link analysis capabilities to empower users with a holistic approach to investigations. Users benefit from advanced link analysis capabilities, allowing them to connect the dots and uncover actionable intelligence with ease.

CEO Daniel Clemens said, “Our customers have asked for a unified platform for many years. We are answering their requests with Horizon®, enabling customers to use our platform and data with their existing tools, easily import and export data, while enabling greater focus for complex analysis of data. The Horizon® Platform allows publicly available data to tell the story for the analyst. I am very delighted at what our team has produced and thankful to how our tools help protect many on a global scale.”

“You guys are doing incredible things with SocialNet® and Horizon®. Looking back as a user of Horizon’s early release, it has been the coolest privilege to experience the last three years of innovation, watching the platform evolve and morph with every incremental update, and knowing there are always more tweaks still in the works.” – Law Enforcement Customer.

These updates underscore ShadowDragon’s commitment to innovation and excellence in the field of investigative technology. By continuously enhancing its OSINT suite with new features, data collection sources and capabilities, ShadowDragon aims to empower investigators with the tools they need to stay ahead of emerging threats and make informed decisions.

Nico Dekens, ShadowDragon Director of Intelligence, said, “This is as close as one can get to having a silver bullet solution that helps solve investigative and analytical needs. This means that no matter what OSINT expertise you have, ShadowDragon’s technology will speed up your investigation through an initiative platform. But it is not limited to just the platform and tools, the seasoned team will train you on usage and will support you in getting the most out of your investigative needs. The newly released features and capabilities will make your work future proof and will speed up ANY investigation significantly.”

For more information about the ShadowDragon™ suite of OSINT tools and capabilities, such as SocialNet®, OIMonitor®, MalNet®, and Horizon®, click here.

About ShadowDragon

ShadowDragon™ provides comprehensive, cyber investigative resources and training for use by private companies, intelligence gathering professionals, law enforcement, and government. The U.S.-based company delivers open source intelligence (OSINT) from over 225 networks including social media platforms, chat rooms, forums, historical datasets, and the dark web. The company monitors malware history, data breach dumps, and other areas for active cyber threats. These data collection and analytic tools help defend against malicious acts in the digital and physical world. For more information, visit www.shadowdragon.io. Visit the ShadowDragon Trust Center for details about the company’s approach to “OSINT for Good”. (Source: BUSINESS WIRE)

 

12 Apr 24. Global: Increased adoption of deepfakes by cyber criminals points to risks facing private sector. On 10 April, the password management platform LastPass revealed that one of its employees was targeted in a deepfake campaign. The employee received several phone calls in which artificial intelligence (AI)-generated audio impersonated the company’s CEO. The threat actors used the messaging platform WhatsApp to target the employee, leveraging known social engineering techniques (such as instilling a sense of urgency) to trick the employee into acting quickly. Although the attack was unsuccessful, as the employee immediately recognised the social engineering attempt, it highlights the increased adoption of AI and deepfake technologies by cyber criminals. In February, a Hong Kong-based finance worker transferred USD 25 m to threat actors who were using deepfake technology to impersonate the CEO of the employee’s firm, further underscoring the growing sophistication and availability of deepfake technologies. We assess that this trend will elevate financial and reputational risks facing the private sector in the long term. (Source: Sibylline)

 

15 Apr 24. New campaign highlights sustained security, information-theft risks from zero-day vulnerabilities. On 12 April, the security company Palo Alto Networks disclosed a new zero-day vulnerability (CVE-2024-3400) in their PAN-OS firewall (versions 10.2, 11.0, and 11.1) which was actively exploited in an information-theft campaign. The suspected state-sponsored group ‘UTA0218’ exploited this vulnerability to obtain unauthorised access to vulnerable systems and install a backdoor called ‘Upstyle’. This enabled the group to execute additional commands, move laterally and steal sensitive data from the compromised system including Windows event logs, login information and browser and configuration data. Notably, the group used several anti-detection tools to remain hidden and to establish prolonged persistence, underscoring the sophistication of the exploit. Although it is unclear which country ‘UTA0218’ might be affiliated with, the group’s advanced tactics, techniques and procedures (TTPs), capabilities and choice of targets suggest that it’s likely state-backed. State-sponsored actors frequently leverage zero-day vulnerabilities for initial access, highlighting sustained security and information theft risks via the software supply chain. (Source: Sibylline)

———————————————————————————————————————————————————————————————————————————————————————————————————————————————-

Spectra Group (UK) Ltd

 

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

———————————————————————————————————————————————————————————————————————————————————————————————————————————————–

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

April 12, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

————————————————————————

11 Apr 24. DOD Employs Proactive Measures to Counter Cyber Threats. By pursuing integrated deterrence, including cyber, the Defense Department continues to be ready to fight and win the nation’s wars, said Ashley Manning, who testified yesterday before the House Subcommittee on Cyber, Information Technologies and Innovation regarding the fiscal year 2025 budget request for cyber.

Manning is performing the duties of assistant secretary of defense for cyber policy.

Cyber challenges, she said, include:

  • China’s targeting of U.S. networks in prolonged campaigns of espionage and pre-positioning its cyber forces for future operations.
  • Russia’s use of cyberspace to target critical infrastructure networks, enable its malign influence operations and disrupt defensive military operations against Ukraine.
  • Iran’s use of cyberspace to create disruptions against Israel.
  • For-profit cybercriminals who target a wide array of vulnerable sectors, conducting ransomware attacks that impact the daily lives of Americans.

In response, the department is implementing its 2023 DOD Cyber Strategy, investing in a talented workforce and capabilities and presenting options to the secretary of defense regarding ways to increase cyber readiness, she said.

This is being done in close partnership with U.S. Cyber Command, Manning added.

During his testimony, Air Force Gen. Timothy D. Haugh, commander of U.S. Cyber Command, echoed much of what Manning said.

China poses the greatest challenge, he said, due to its “advanced cyber capabilities, state-sponsored cyber operations around the globe, and a strategic focus on leveraging cyberspace for military, economic and political purposes.”

Also, Haugh pointed out that Russia’s cyber campaigns prioritize sensitive U.S. government and military infrastructure and information and spread disinformation campaigns to influence public opinion and undermine the democratic processes.

“I am confident Cyber Command is well postured to meet the ever-evolving challenges we face today, creating advantages for the department and the nation,” he said, citing his team’s work at “network hardening, threat hunting and information sharing to foil potential cyberattacks before they can materialize.” (Source: U.S. DoD)

 

08 Apr 24. BLOS Troposcatter Communications System Demonstrated. Meeting U.S. Army range requirements, Ultra Intelligence & Communications Archer troposcatter communications system successfully maintained a communications link beyond 185km Ultra Intelligence & Communications has launched its Archer.family of troposcatter communication system to the global defense market. The launch follows a recent demonstration where the beyond-line-of-sight (BLOS) platform successfully maintained a communications link beyond 185 kilometers. With the demo, the system met U.S. Army range requirements, providing a resilient, redundant layer of secure communications.

“Offering the Archer family of troposcatter systems to our global defense partners is a testament to our ability to invest, innovate and deliver on crucial capabilities, when our customers need it most,” said Chris Bishop, chief growth officer of Ultra Intelligence & Communications. “We pride ourselves on building solid, trusted, long-term customer partnerships – combining decades of functional and technical experience with an innate ability to innovate and deliver revolutionary advancements at speed and scale.”

“Troposcatter bridges the gap when satellite communications aren’t accessible due to jamming, location or other factors, making it a cost-effective way to move beyond line-of-sight relays,” said Faith Rhodes, vice president of programs for Ultra I&C’s Communications business. “This resilient layer of communications is becoming more important as we prepare for the potentiality of a day without SATCOM.”

Ultra I&C’s troposcatter technology is tested to be resilient in diverse operational environments, withstanding interference and jamming to deliver key communication links over vast distances where fixed communications face limitations.

The Archer family of systems allows for quick deployment and self-alignment of antennas, ensuring connectivity at mission speed.

(Source: https://www.defenseadvancement.com/)

 

11 Apr 24. Germany: New campaign underscores adoption of AI tools, heightened information security risks. On 10 April, the cyber security company Proofpoint reported that the financially motivated threat group ‘TA547’ targeted several German organisations with the ‘Rhadamanthys’ information stealer. The campaign uses invoice-related phishing emails to trick potential victims into engaging with a malicious ZIP file. Once opened, the malicious file triggers the download of the Rhadamanthys malware through a large language model (LLM)-generated PowerShell script. This campaign marks the group’s first adoption of LLM tools, underscoring the growing sophistication of its tactics, techniques and procedures (TTPs), including through the use of Artificial Intelligence (AI)-generated code. AI enables cyber criminal groups of varying capabilities to refine their techniques and to conduct more complex attacks, bolstering their success rates. Rhadamanthys was recently used in February 2024 in an information-stealing campaign targeting the oil and gas sector. We assess that the increased deployment and development of this malware will exacerbate the security and information-theft threats posed by financially motivated actors. (Source: Sibylline)

 

11 Apr 24. Armageddon days are here again. The US Space Force is shelling out up to $8bn on its Evolved Strategic Satellite Communications System (ESS). ESS is expected to supplement, and eventually replace, the existing Advanced Extremely High Frequency (AEHF) Satellite Communications (SATCOM) system. The AEHF is a key component of the United States’ Nuclear Command, Control and Communications (NC3) network. NC3 employs a myriad of communications links to move nuclear weapons command and control traffic. These links would carry any orders from the president to US strategic forces to use nuclear weapons.

Reports in February said that an ESS draft solicitation is expected to be published by the end of 2024. The three satellites expected to form the ESS space component could be launched in 2025. The advent of the Evolved Strategic SATCOM System is a welcome enhancement to the NC3 enterprise. As of January 2024, the Bulletin of the Atomic Scientists’ famous Doomsday Clock was at 90 seconds to midnight. Avoiding Armageddon depends on adversaries believing their opponent’s deterrent would not fail. Maintaining robust, survivable and capable strategic communications systems is intrinsic to the concept of a credible nuclear deterrent. US nuclear-armed NATO allies France and the United Kingdom must follow Washington’s lead in ensuring their nuclear communications systems are fit for purpose both now, and in the future. (Source: Armada)

 

09 Apr 24. Link Rays. The United States Space Development Agency’s embrace of Link-16 connectivity is gathering momentum greatly improving the tactical datalink’s geographical footprint.

Link-16 is a North Atlantic Treaty Organisation (NATO) and allied Tactical Datalink (TDL) protocol which mainly supports air operations. The TDL uses frequencies of 960 megahertz/MHz to 1.215 gigahertz/GHz to handle secure tactical voice and data traffic. Link-16 was developed in the 1970s and introduced from the 1980s onward. For most of its history, Link-16 has been a terrestrial tactical datalink, but this is changing.

Viasat and Blue Canyon collaborated on the development of the XVI spacecraft to demonstrate the feasibility of moving Link-16 traffic across satellites. The XVI cubesat was launched in 2023 and placed in a Low Earth Orbit (LEO). According to the US National Aeronautics and Space Administration, cubesats are classified as having a twelve cubic metre volume. LEO orbits do not exceed 1,080 nautical miles/nm (2,000 kilometres/km) altitude. As a TDL using Ultra High Frequency (UHF) wavebands, Link-16’s range is restricted to line-of-sight. Placing Link-16 terminals on a satellite permits a significant range increase: A LEO satellite at a 1,080nm altitude could have a potential intercontinental range of 3,146nm (5,826km).

Enlarging the footprint

“The geographic footprint of the battlespace for which Link-16 was designed has increased ten-fold,” the US Space Development Agency told Armada. Tomorrow’s wars are expected to be fought across vast theatres, such as in the far east and southeast Asian regions. It is in these areas where the People’s Republic of China and the US could come to blows during any future conflict. “Link-16 from space allows quicker reaction times for warfighters over a large area … In order for US forces to react to rapid and changing adversarial threats, the timeline of these reactions must be faster than ever before.” A key motivation for evolving Link-16 provision from space is the challenge presented by time-sensitive, beyond line-of-sight targets. Such threats are exemplified by hypersonic surface-to-surface missiles. Hypersonic weapons travel at velocities exceeding 3,333 knots (6,174 kilometres-per-hour). The Russian Air and Space Force’s Kh-47M2 Kinzhal (NATO reporting name AS-24 Killjoy) has a reported top speed of 6,666 knots (12,348km/h). The missile’s range is said to be circa 1,080nm which could be covered in nine minutes and 43 seconds.

SDA efforts

The SDA has picked up the baton and is helping to advance space-based Link-16 capabilities. On 14th February, the SDA launched 27 Tranche-0 Proliferated Warfighter Space Architecture satellites. Seven of the spacecraft include TDL payloads. York Space Systems, Lockheed Martin, SpaceX and L3Harris have all been involved in developing these Tranche-0 satellites. The Proliferated Warfighter Space Architecture “has successfully demonstrated the first ever Link-16 network entry through space to a ground connection located within a Five Eyes partner nation from low earth orbit,” the SDA told Armada. The Five Eyes nations comprise Australia, Canada, New Zealand, the United Kingdom and the United States. “This demonstration represents a capability never before possible for our warfighters.”

Link-16 connectivity testing is expected to continue throughout 2024: “Signal characterisation tests” are ongoing noted the SDA with “network loading and entry tests” then occurring. These evaluations will “be followed by adding additional Link-16 participants to provide empirical data on network loading, participant interactions and the tests required to lead up to certifications.” Crucially, the Link-16 terminals equipping the Tranche-0 satellites are fully compatible with Link-16 radios used throughout NATO and allied nations: “No modifications (to these radios) are required for interoperability,” said the SDA. (Source: Armada)

 

10 Apr 24. Proving the Design. The US Army’s new RT-2129 Combat Net Radio recently completed a significant testing programme at the Electronic Proving Ground, Fort Huachuca, Arizona.

The US Army’s Combat Net Radio takes an important step towards service entry as the system begins its first article testing phase.

The US Army’s Programme Executive Office for Tactical Command, Control and Communications (PEO C3T) announced in March that the Combat Net Radio (CNR) has entered its first article testing phase. Thales is providing the Very High Frequency (VHF: 30 megahertz/MHz to 512MHz) CNR. Designated as the RT-2129, the company won the ten-year contract to provide the radio in May 2022. The RT-2129 is based on Thales’s AN/PRC-148 Joint Tactical Radio System Enhanced Multiband Inter/Intra Team Radio. The AN/PRC-148 is a multiband (30MHz to 512MHz), multi-channel system intended for squad/team leaders. In contrast, the RT-2129 is a single-channel transceiver for subordinates. Thales’s contract could be worth up to $6bn and could see the delivery of circa 7,000 RT-2129 radios. The RT-2129 replaces the erstwhile L3Harris RT-1523 Single Channel Ground and Airborne Radio System (SINCGARS) VHF transceiver.

Waveforms

Thales’ official literature says the CNR carries the SINCGARS waveform along with the HAVEQUICK-I/II 400MHz to 500MHz frequency-hopping waveform. Beyond SINCGARS and HAVEQUICK-I/II the radio accommodates the Integrated Waveform for satellite communications and Project-25 (APCO-25). The APCO-25 waveform is used throughout the US first responder community. CNR transceivers have a similar shape and size to the RT-1523 series. This will ease the retrofit of these new radios into legacy vehicles equipped with RT-1523s. As the new radios includes the SINCGARS waveform this will ensure interoperability with older transceivers. Given the timelines for CNR introduction, new and legacy radios will need to run side-by-side for some time.

Testing Times

According to the PEO C3T, the Combat Net Radio completed a “vendor-led excursion” at the Electronic Proving Ground (EPG) at Fort Huachuca, Arizona in February. With the completion of the vendor-led excursion, the RT-2129 now moves into first article testing. Lieutenant Colonel Brandon Motte, the PEO C3T’s waveforms product manager, told Armada that “the first article testing phase consists of environmental tests, lab-based tests and field-based tests.” Some of these environmental tests will occur at the vendor’s facilities and will be observed by the Defence Contract Management Agency (DCMA). The DCMA supervises and manages US defence contracts. These environmental tests will include ballistic, shock and temperature testing, Lt. Col. Motte explained. Government-led laboratory testing will occur in government-owned facilities and will entail “preliminary testing of the (radio’s) software, hardware, and functions of the equipment.” Field testing will occur at several army sites, including the EPG, and will see “additional performance testing while in an operational environment.”

Lt. Col. Motte said that the first article testing phase is expected to take between four and six weeks in June and July. Additional testing will follow in the form of an Operational User Assessment (OUA). The OUA is due to take place at the US Army’s Manoeuvre Battle Lab at Fort Moore, Georgia. “The purpose of the OUA is to gather soldier feedback on the new CNR variant” and will take place in October 2024. The first US Army units are expected to receive the CNR by the end of the year. (Source: Armada)

 

11 Apr 24. Seeking Guidance. In early March, the Ukrainian media announced that Russian forces are using an enhanced version of the Kometa GNSS receiver in the Ukrainian theatre.

The militarnyi website reported on 9th March that Russian air-to-surface ordnance equipped with the UMPK precision guidance kit are using a new variant of the Kometa system. UMPK kits are like the Boeing Joint Direct Attack Munition (JDAM) guidance system in use with US and allied militaries. Like JDAM, the UMPK kits adorn standard ‘dumb’ ordnance to improve precision. The guidance kits rely on Global Navigation Satellite System (GNSS) Position, Navigation and Timing (PNT) signals to improve precision. Russian sources say UPMK uses PNT signals transmitted by that country’s GLONASS GNSS constellation. GLONASS transmits PNT signals on frequencies of 1.201 gigahertz/GHz to 1.605GHz. Nonetheless, UMPK kits can probably use any GNSS signals transmitted on frequencies between 1.1GHz and 1.6GHz.

UPMK detects PNT signals with the target’s position being correlated with the bomb’s location as it flies. The guidance kit sends commands to a fin assembly mounted on the rear of the weapon. The fins move to correct the course of the weapon as it approaches the target. While UMPK helps to improve precision it can risk making a freefall weapon thus equipped vulnerable to jamming. GNSS PNT signals tend to be very weak by the time they have travelled from the satellites transmitting them to Earth. As previous articles have stated, the signals may be as weak as -127 decibels-per-milliwatt/dBm at the end of their journey. Comparatively weak jamming signals aimed at a UMPK kit maybe drown out the PNT signals used for guidance.

Kometa

Russian language technical papers discussing the baseline Kometa system, which the UMPK relies on, say the system provides ‘noise immunity’ to GNSS PNT jamming. Noise immunity levels of between 32 decibels/dB to 108dB are reportedly achievable with Kometa. It appears that Kometa detects abnormally high-power transmissions mimicking PNT signals using three radio receivers. These receivers detect and compare the spatial separation between the incoming PNT transmission and the more powerful jamming signal. Processing screens out the jamming based on its power levels and angle-of-arrival vis-à-vis the PNT signals. Weighing circa one kilogram (2.2 pounds), Kometa was designed to equip space-constrained platforms. Such attributes make it unsurprising that the apparatus has been employed in the UMPK equipment.

Kometa-M

The Ukrainian media reports in early March said Kometa has now been augmented with eight receivers with the new configuration known as Kometa-M. The addition of five PNT receivers is no doubt intended to improve the resistance of UMPK kits to jamming. By adding additional receivers, Kometa-M may be able to defeat more than three jamming sources. Additional radio receivers may improve the system’s discrimination between real and fake PNT transmissions. It is noteworthy that Kometa-M is also being used with Russian land forces tactical uninhabited aerial vehicles.

The enhancement of the baseline Kometa design shows that Ukrainian electronic warfare directed against Russian GNSS-dependent military systems is effective. It also shows that Russian electronic engineers can rapidly develop solutions to electromagnetically vulnerable systems. Expect similar innovations by both sides as the war continues. (Source: Armada)

 

10 Apr 24. April Radio Roundup. R-187 handheld V/UHF radios are in service with the Russian Army, but have they been deployed in sufficient numbers to support the invasion?

New Millimetric Wave Module

Peraso unveiled its new PRM2136 millimetric wave module to support secure tactical communications in March. A company data sheet said that the PRM2136 uses a 57 gigahertz/GHz to 60 gigahertz/GHz waveband providing 2.16GHz of channel bandwidth. The latter helps the system avoid interference from other signals. Directional beamforming is provided using a phased array antenna which steers signals in azimuth and elevation. Automatic Encryption Standard 128 (AES-128) data encryption is also supported. Peraso told Armada that the PRM2136 “has a USB 3.0 interface” adding that “it can connect directly to a host device, or with an Etherwave adapter, which enables smart power management when connected to Android devices such as smartphones and tablets.” The company said that data rates of between 400 megabits-per-second and 1.7 gigabits-per-second are achievable with the PRM2136. Development of the module is complete. It is “in mass production (and) has been adopted for consumer products and is in development for tactical applications.”

Peraso’s new PRM2136 millimetric wave module provides secure communications which can achieve data rates of up to 1.7 gigabits-per-second.

Satcom Direct Secures Blanking Agreement

Satcom Direct’s government subsidiary concluded an aeronautical blanking agreement with the US Department of Defence (DOD) for global Satellite Communications (SATCOM) connectivity in March. The news was announced via a company press release. The five-year agreement will provide the DOD with voice and data connectivity for US military and government aircraft. The contract is worth $240 m. Specifically, the agreement allows those users to access several SATCOM services offered by Viasat. Satcom Direct told Armada that the SATCOM service it offers “can be accessed through existing equipment (furnishing aircraft) as well as Satcom Direct’s growing portfolio of hardware.” The satellite communications services users can access will flow through Satcom Direct’s facilities in Melbourne, Florida. (Source: Armada)

 

10 Apr 24. Secretive US cyber force deployed 22 times to aid foreign governments. U.S. cyber specialists toiled in more than a dozen countries last year as part of a push to fortify networks and expose tools used by hackers, according to the leader of Cyber Command and the National Security Agency.

The so-called hunt-forward missions, conducted by CYBERCOM’s elite Cyber National Mission Force, or CNMF, totaled 22 deployments, with some happening simultaneously across the world, Air Force Gen. Timothy Haugh said in testimony submitted to the Senate Armed Services Committee on April 10.

“Enhancing the security of government, private sector and critical infrastructure systems grows ever more imperative,” said Haugh, who took the helm at CYBERCOM and NSA in February. “Foreign adversaries continuously update how they operate, and frequently work through American-owned networks and devices.”

Hunt-forward missions are executed at the invitation of a foreign government and are not always disclosed. They’re part of CYBERCOM’s persistent engagement strategy — a means of being in constant contact with adversaries and ensuring proactive, not reactive, moves are made.

Haugh’s disclosure offers a rare look at the CNMF workload, which is often nebulous, as some countries prefer to keep quiet the digital cooperation.

The mission force has in the past worked with Ukraine, ahead of Russia’s invasion; Albania, on the heels of Iranian cyberattacks; and Latvia, where malware was unearthed. Other previous deployments included Estonia, Croatia, Lithuania, Montenegro and North Macedonia.

The Defense Department sought $14.5 bn for cyber activities in fiscal 2025. The figure is about $1 bn more than the Biden administration’s previous ask. It is also up from FY23, when it sought $11.2 bn.

“We work every day against capable and determined cyber actors, many of them serving adversary military and intelligence services,” Haugh said. “Our operational experience reinforces the importance of campaigning globally in and through cyberspace across the conditions of competition, crisis and armed conflict.” (Source: C4ISR & Networks)

 

10 Apr 24. Global: Patched zero-day vulnerabilities underscore threats posed by financially motivated actors. On 9 April, the software company Microsoft revealed that two zero-day vulnerabilities (CVE-2024-26234 and CVE-2024-29988) were actively exploited by threat actors prior to the release of patches. One vulnerability (CVE-2024-26234) was exploited to inject a malicious file into targeted systems; this allowed the threat actors to install a backdoor and remotely access sensitive data. The second vulnerability (CVE-2024-29988) was exploited in conjunction with a SmartScreen software vulnerability discovered in February 2024; this enabled the threat actors to bypass security checks, as well as to access the compromised system remotely and to deploy additional malicious code. The financially motivated group ‘Water Hydra’ exploited both vulnerabilities in December 2023 to target Forex trading forums and Telegram channels for illicit profit. The incident highlights the growing sophistication of cyber criminals’ tactics, techniques and procedures (TTPs), which now include the exploitation of zero-day vulnerabilities. The increased use of zero-day vulnerabilities in criminal operations further underscores the elevated security and financial threats posed by cyber criminal actors. (Source: Sibylline)

 

10 Apr 24. Thales and Intel enable advanced protection for the Google Cloud ecosystem.

  • Enables persistent protection of the most sensitive enterprise workloads in the cloud through customer-controlled data security, not observable by non-authorized parties
  • Protects against malicious actors accessing code and data at rest, in transit and while in use

Thales, the leading global technology and security provider, today announced a collaboration leveraging its CipherTrust Data Security Platform (CDSP) to support End-To-End Data Protection (E2EDP) on Google Cloud, using Confidential Computing (CC) from Google Cloud and trusted cloud independent attestation provided by Intel Trust Authority (ITA).

The effort is a step forward in data security, giving enterprises additional controls to protect their data at rest, in transit, and in use.

“As more enterprises migrate their data and workloads to the cloud, there is an increasing demand to safeguard the privacy and integrity of the data, especially those sensitive workloads that include intellectual property, AI models and valuable personal information. This collaboration enables enterprises to protect and control their data at rest, in transit and in use with fully verifiable attestation. Our close collaboration with Google Cloud and Intel increases our customers’ trust in their cloud migration,” said Todd Moore, Vice President of Data Security Products at Thales.

A majority of the 2023 Thales Cloud Security Study respondents reported having a significant amount of sensitive data stored and in use in the cloud. Consequently, safeguarding sensitive data and associated workloads when stored or in use, is an increasing priority, especially for highly regulated industries such as financial services and healthcare. Thales’s collaboration with Intel and Google Cloud provides certifiable controls for enterprises to fully protect their data end-to-end.

Purnam Sheth, Vice President and General Manager: Trust and Security Products, SATG at Intel: “Creating this groundbreaking, seamless data security platform in Google Cloud meets customers’ complex requirements for data protection, controlled access and security, and adherence to compliance for data at rest, in transit and in use. Foundational Intel® Trust Domain Extensions Confidential Compute and Intel® Trust Authority gives enterprises assurance of the integrity of their workloads and guards at all stages of data management. This valuable collaboration between Thales, Google Cloud and Intel makes this possible.”

This security platform is based on the principle of separation of duties, where the customer remains in control of the encryption keys and their location. This approach enhances trust by holding each stakeholder responsible for their respective roles and reduces the ability for a malicious actor to access code and data at rest, in transit and while being executed.

Customers can migrate existing workloads with sensitive data or create new workloads needing zero trust, confidential computing and Confidential AI to this security platform in Google Cloud to broaden data security, attestation and set the right authorizations. With end-to-end data protection, multiple parties can securely collaborate on various use cases, such as Confidential AI datasets and models as needed while preserving privacy, confidentiality, and compliance with privacy regulations.

The Thales CipherTrust Data Security Platform uses Intel Trust Authority as a zero-trust, independent attestation service for advanced security and scalable confidential computing. Consistent attestation to Trusted Execution Environments (TEE) that are based on Intel Trust Domain Extensions. This single, consistent attestation process provides assurance to any relying party that the TEE and any data and workloads running within it have not been compromised.

Brian Roddy, VP, Product Management, Google Cloud: “Google Cloud is committed to providing our customers secure, private and reliable environments for their workloads, and our Confidential Computing portfolio plays a critical role in this effort. Offering our customers solutions like Thales’ encryption key management expertise, combined with Intel’s Trust Authority attestation, enables the choice of even stronger privacy controls.

The collaboration comes as Thales is recognized for its achievements in the Google Cloud ecosystem. For the second year in a row, Thales has received the 2024 Google Cloud Technology Partner of the Year Award for Security – Data Protection. ​

 

10 Apr 24.  Comtech (NASDAQ: CMTL) (the “Company”), a global technology leader, in partnership with the Arizona Department of Administrations (“ADOA”), today announced the successful completion of a statewide transition to Comtech’s Next Generation 911 (“NG911”) services. Arizona’s new statewide NG911 infrastructure is designed to significantly enhance the ability of first responders and public safety answering points (“PSAPs”) to respond faster to emergencies and provide more comprehensive and reliable 911 services to Arizona residents.

In less than two years, Comtech and the ADOA successfully migrated the state’s legacy 911 system to the new infrastructure. The Arizona NG911 program modernizes the state’s emergency response capabilities and enhances the efficiency, effectiveness and reliability of 911 services, while enabling new capabilities such as geospatial location routing and improved redundancy, as well as the implementation of a new Emergency Service IP Network (“ESiNET”).

“We are honored to partner with the State of Arizona to deploy one of the nation’s most robust NG911 infrastructures,” said John Ratigan, Interim CEO of Comtech. “With this statewide deployment, Arizona residents benefit from a much higher rate of call reliability and new multi-media and location services, which can save critical time during emergencies. Comtech has worked closely with the ADOA and state leaders to integrate multiple legacy networks to create a new unified NG911 infrastructure, and we are confident this transition helps ensure residents get the help they need when seconds matter most.”

“The efficiency of this deployment can serve as a model for the rest of the United States, and we are pleased to work with Comtech to roll out these lifesaving NG911 services to better protect Arizona residents,” said Travis Jensen, Program Administrator of the ADOA 911 Program. “We look forward to continuing our partnership and bringing new capabilities to residents as they become available.”

The Arizona NG911 statewide transition involved upgrading and integrating a wide range of 911 technologies, including call handling, dispatch, mapping and database systems. It also required implementing new protocols and standards to ensure interoperability and compatibility with other systems and networks.

As one of the most trusted providers of public safety technologies, Comtech is continuing to expand its NG911 offerings for governments and emergency response providers around the world. The Company’s NG911 systems are designed to adapt and continuously evolve over time to meet the needs of emerging use cases as well as future applications.

 

08 Apr 24. Frontier Technology Inc. Announces SaaS and Perpetual Licensing Options for Its Proven Cortex Military Data Integration Platform.

FTI Cortex integrates complex and disparate systems, applications and data types, and enables powerful analysis, visualizations and predictive modeling for DoD customers. Frontier Technology Inc. (FTI), a leading provider of deep data expertise and mission-tailored services and solutions to the United States Department of Defense (DoD) and Intelligence Community, today announced SaaS and perpetual licensing options for its Cortex data integration platform. Previously, FTI Cortex was only available as part of the company’s technology-enabled services offerings.

FTI Cortex is a powerful, proven cloud-based platform that leverages AI/ML to enable DoD users to quickly gain the insights they need from their data to make the fastest, best decisions possible for their missions.

Cortex is designed to break down silos that often limit the potential of DoD data. It integrates complex and disparate systems, applications and data types, and enables powerful analysis, visualizations and predictive modeling that empowers users to dive deep into their data, providing a clear path to the insights they need. With a selection of native visualizations that allow users to quickly identify key relationships between data sources, Cortex offers rapid analysis capabilities right out of the box.

Cortex isn’t disruptive to current customer environments, and works with virtually all systems, data types, and virtually all commercial and open source applications including Grafana, Tableau, PowerBI and Qlik.

Schedule a demonstration or request more information: 

The FTI Difference: Speed to Solution, Cost, Compatibility, Ease of Use – Customers continue to own their own data

The FTI Cortex platform can be operational in weeks or months, versus years, at a fraction of the cost of alternatives. Cortex is easy to use, yet serves a wide range of users, from those with basic skills to highly technical professionals. It is scalable to the enterprise and FTI customers continue to own their own data.

“The U.S. Department of Defense and Intelligence Community need to make critical decisions fast, but often spend too much of their time analyzing overwhelming volumes of data from disparate sources that don’t talk to each other,” said Jose Hidalgo, President, Frontier Technology Inc. “FTI Cortex addresses that challenge with automated data integration, normalization and standardization that empowers real-time analysis, visualization and predictive modeling to enable our warfighters to make the fastest and best mission-critical decisions possible.”

FTI Cortex is Now Available via SaaS and Perpetual Licensing

Delivery via SaaS

FTI Cortex is now available via a Software as a Service (SaaS) model. Subscription pricing allows fast and predictable adaptation to changing customer demands, ensuring new capabilities, data ingestion and integration requirements, and scalability can be delivered as fast as they are needed. Additionally, Cortex’s throughput-based approach is designed to meet a wide range of needs, from maintaining current systems to deploying enterprise-scale solutions across multiple Program Executive Offices (PEOs) or large-scale operations. Cortex is highly flexible, enabling tailored support for a diverse range of requirements, from straightforward updates to complex, cloud-based installations for extensive user communities. The demand signal from the customer defines the volume of data and how quickly it must be ingested.

Perpetual Licensing Option

FTI’s new perpetual licensing model for on-premise implementations is designed for both new and existing customers seeking both affordability and predictability. This approach also provides an opportunity to secure continuous support, regular capability enhancements, critical security updates, and the latest ATO and environmental certifications, keeping your operations not just running, but running securely. Designed and built with flexibility at the forefront, our licensing model ensures customers can leverage the full power of Cortex at an affordable price point. Customers can choose to license Cortex independently or in combination with our expert technical services, ensuring seamless integration and maintenance across various environments.

“FTI is adjusting our business to meet the DoD leadership vision of procuring ongoing continued developments vs continuous logistical sustainment costs.”, said Lincoln Hudson, COO, Frontier Technology Inc. “FTI’s new SaaS and License purchase models give our customers in the DoD a range of flexible new options for accessing the powerful integration capabilities of Cortex for untangling the volume, complexity and velocity of their data, and unlocking its true potential for better decision-making.”

FTI’s Full Capabilities

FTI offers a broad, integrated and seamless data analytic ecosystem, with capabilities including data integration, data analytics, modeling and defensive/resilient cyber technologies and services to enable the U.S. DoD, Intelligence Community and Federal Government to make the best decisions possible for their missions.

FTI’s extensive library of IP and technologies leverage more than $200M of U.S. Government and FTI R&D investment.

FTI’s data analytics solutions and services are built around the Cortex Integration Platform which leverages artificial intelligence/machine learning (AI/ML) to deliver a wide range of analytic and visualization capabilities for acquisition and operational decision support across DevSecOps, enterprise architecture analysis, enhanced data visualizations, model-based systems engineering, digital transformation and system performance analysis.

FTI’s modeling solutions and services help our customers better track, visualize, simulate and analyze trends and underlying mission drivers across wargaming, logistics analysis and visualization, system performance modeling, synthetic systems and data generation support.

FTI’s defensive/resilient cyber solutions offer a portfolio of advanced technologies and services to help maintain and optimize cyber defense, including mission cyber risk analysis, supply chain Illumination, blue and gray space analysis, penetration testing, RF analysis, and cyber-enhanced threat intelligence analysis.

About FTI

FTI provides deep data expertise, technology and services that enhance the ability of the DoD, Intelligence Community and other agencies of the Federal Government to make the best decisions possible. Drawing on nearly four decades of innovation, FTI’s extensive portfolio of intellectual property and operational technologies has been augmented by more than $200 m of U.S. government and FTI R&D investment, and solutions can often be mission-ready in a matter of weeks at a fraction of the cost of alternatives. Headquartered in Beavercreek, Ohio, FTI operates in 34 states, works at all levels of classification, and offers seven facilities of varying clearance levels nationwide. More at www.ftidefense.com. (Source: BUSINESS WIRE)

 

05 Apr 24. US Army picks Akamai for prototype battlefield zero trust project: T-ICAM. The civilian internet firm will build prototype software for Tactical Identity Credential & Access Management, a critical step in bringing “zero trust” cybersecurity to battlefield networks. The Army picked cloud and edge-computing giant Akamai to develop prototype cybersecurity software for its combat units, the service announced today. The project, known as T-ICAM, or Tactical Identity Credential & Access Management, aims to bring modern “zero trust” cybersecurity techniques to the networks used by Army forces in the field. Combat units will field test early prototypes later this year and provide feedback for rapid upgrades, the service said, with a larger rollout in 2025.

Akamai isn’t a traditional defense contractor and this isn’t a traditional acquisition program, the Army pointedly noted in its release about the April 4 award. Instead, using the streamlined Software Acquisition Pathway and a flexible Other Transaction Authority contract, the Army aims to leverage Akamai’s quarter-century of experience accelerating internet connections for civilian consumers and Fortune 500 businesses.

The Army’s portion of the Pentagon’s all-encompassing approach to information age command-and-control, CJADC2, requires major upgrades to already extensive tactical networks. But that creates an ever-greater challenge to keep all those devices and wireless links secure — especially if a soldier’s digital radio, militarized smartphone, or tablet full of battle plans is captured, stolen, lost, or hacked.

Traditional cybersecurity deals with such threats, in essence, through perimeter defense. Users log in with a unique ID and password and, in more secure systems, must also physically insert an ID card into a reader, such as the military’s much-hated CAC, the Common Access Card. Once a user logs in, however, they typically have access to everything on the network — a potential bonanza for both turncoat insiders and outside hackers able to steal or fake credentials.

To stop such threats, modern “zero trust” cybersecurity assumes the perimeter is going to be breached and keeps track of users’ activity once they’re logged on, granting each individual user access only to what they personally need for their particular role. For example, it might require additional checks to access important data or use AI to detect anomalous behavior by seemingly legitimate users. This monitoring, however, only works if the cybersecurity software knows which user is doing what and what they’re actually authorized to do — a process known as Identity, Credential, & Access Management.

“ICAM provides critical insight to the Army on exactly who and what is operating on the tactical network and what data they are accessing,” said Lt. Col. Keith Jordan, the Army’s product manager for tactical cyber & network operations, in the service’s release. “This unprecedented level of insight and visibility has never existed on the tactical network.”

That’s because ICAM is much easier to implement in the Pentagon or on a military base than on handheld digital radios and other ruggedized devices that a soldier has to take to the field, which must endure not only a physical beating but bad network connections caused by enemy jamming, hacking, or simple physical interference.

So the Army looked first at ICAM for its “enterprise” (on base and back-office) systems, then moved on to study vulnerabilities in its tactical (battlefield) networks, explained Col. Michael Smith, the service’s zero-trust director, in an August interview with Federal News Network.

“We’re really in the beginning stages of just piloting with some tactical formations,” Smith said then. “[It’s] a nascent effort … to get away from Common Access Cards in a tactical space, and use something that’s more simpler and faster for soldiers in specific roles to use.”

Now, seven months later, the Army has announced this contract to prototype Tactical ICAM software, awarded to Akamai, a company with little military experience but a lengthy track record on civilian networks. The goal, the press release says, is “to demonstrate the technical and operational feasibility of extending commercial ICAM capabilities — including Army Enterprise (E)-ICAM capabilities such as authoritative identity directories — to tactical units in denied, disconnected, intermittent, and limited bandwidth (DDIL) operational environments.”

“We have to assume that malicious cyber-attacks and degraded network environments will be a constant threat in future Large Scale Combat Operations,” said Mark Kitz, the Army’s Pogram Executive Officer for tactical command, control, & communications (PEO-C3T), in the service’s release. “Tactical-ICAM will enhance our defenses by more securely and effectively providing network and specific data access only to authorized users, devices, applications and services, even in the harshest operational environments.” (Source: Breaking Defense.com)

 

05 Apr 24. Netherlands seeks systems integrator for Foxtrot programme. The Netherlands Ministry of Defence (MoD) is looking for a systems integrator to assist with running the Foxtrot tactical digitisation programme, Janes learnt. Foxtrot is a major digitisation modernisation programme that aims to support the Netherlands Armed Forces transition to an information-driven, integrated force. Key to this is the replacement of legacy communication systems and the enhancement of its battlefield management systems. According to industry sources who spoke to Janes at the SAE Group’s Future Soldier Technology conference held between 11 and 13 March, L3Harris Technologies is one of the companies bidding to be the systems integrator. (Source: Janes)

 

05 Apr 24. Cyber Update Key points.

  • A newly discovered vulnerability in Linux software points to information-theft risks via the software supply chain (see Sibylline Cyber Daily Analytical Update – 2 April 2024 and our Technical analysis below).
  • An emergent malware distribution campaign signals growing security and financial threats posed by financially-motivated threat groups (see Sibylline Cyber Daily Analytical Update – 3 April 2024 and our Technical analysis below).
  • New ransomware operation targeting VMware software highlights sustained security, financial and reputational risks from vulnerable software (see Sibylline Cyber Daily Analytical Update – 4 April 2024).
  • US-based entities face elevated security and disinformation risks from Chinese state actors as they increase the use of AI-generated media in election interference campaigns.

A new backdoor was discovered in the Linux open-source software, ‘liblzma’, commonly used by developers to compress and decompress release files. The malware affects servers hosting publicly-accessible Secure Shell (SSH) authentication processes, loading versions xz-5.6.0 or xz-5.6.1. A malicious script is initially executed after the compromised payload is downloaded from its repository. The script then looks for a specific set of conditions upon inspecting incoming SSH connection requests. This then loads additional malicious payloads which grant unauthenticated threat actors the ability to remotely execute code on the targeted system. Although the intent behind the deployment of this backdoor remains unknown, remote access is typically used to steal sensitive data, install malware, disrupt critical operations and/or launch further attacks. Most notably, the malicious payload is partially hidden in release test files, allowing for greater stealth and prolonged obfuscation. Consequently, the discovery of this new backdoor emphasises threat actors’ perseverance alongside the growing sophistication of their tactics, techniques and procedures (TTPs).

The financially-motivated threat group, ‘Water Curupira’, recently started distributing the ‘Pikabot’ trojan in a new campaign. The campaign starts with a phishing email containing either malicious zip files or a server message block (SMB) file-sharing link. The link exploits a bug which allows the threat actors to hijack existing email threads, thereby enhancing legitimacy. The malware then inserts itself in the targeted system, subsequently enabling the threat actors to collect sensitive data and remotely execute additional malicious code. Water Curupira typically exploits access to infected systems to deploy ‘Black Basta’ ransomware and garner illicit profit. Additionally, Pikabot checks for debugging and sandbox environments so as to remain undetected. Water Curupira uses a wide variety of file formats (such as Excel and JavaScript) to more effectively trick victims into engaging with the malicious files, while simultaneously evading automated detection tools. The group’s ability to bolster success rates and achieve prolonged persistence points to its knowledge of modern IT systems and growing sophistication of their TTPs.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Enforce strict security policies including regular software and password updates, as well as adequate network segmentation to prevent lateral movement following an infection.
  • Monitor devices and networks for suspicious activity.
  • Conduct cyber hygiene awareness and vigilance courses to enable users to recognise and report phishing and other types of social engineering attempts.
  • Add available Indicators-of-Compromise (IoCs) to the organisation’s security detection systems to detect potentially malicious samples on the network.
  • Ensure adequate security detection measures are in place, particularly behaviour-based end-point detection and response (EDR) solutions.
  • Store regular data backups in external and secure locations to ensure data can be restored quickly and effectively in the event of a compromise.

Our cyber word(s) of the week: Wiper (Malware) (Source: Sibylline)

 

05 Apr 24. Finnish Ministry of Defence Decided on a Partnership Agreement with Bittium Wireless Ltd, a Subsidiary of Bittium Corporation. The Finnish Minister of Defence, Mr. Antti Häkkänen has authorized the Finnish Defence Forces to sign a partnership agreement with Bittium Wireless Ltd, a subsidiary of Bittium Corporation, for the years 2025–2036. The aim is to sign the agreement during the year 2024.

The basis for the partnership is the maintaining and development of defense readiness for the purposes of normal and emergency circumstances. The partnership agreement secures the availability, performance and usability of Bittium-supplied products and services critical for the Finnish Defence Forces in all conditions. The partnership agreement creates mechanisms for planning joint operation in emergency circumstances, which enables Bittium to plan and provide product manufacturing, servicing, repair, maintenance, and development related functions.

The partnership agreement covers command and control systems used by all branches of the Defence Forces, including Bittium’s tactical communications system and related products (Bittium Tactical Wireless IP Network™, Bittium Tough SDR™, Bittium Tough VoIP™). The aim of the agreement is that the partnership will become a fixed part of the comprehensive national defense.

“When realized, the partnership agreement will enable systematic planning and execution of cooperation in a cost-efficient manner that benefits both parties. Partnership with the Finnish Defence Forces would add the credibility as reliable partner also in the international markets”, says Johan Westermarck, CEO of Bittium Corporation.

The monetary value of the agreement will depend on the yearly armament needs and funding of the Finnish Defence Forces.

————————————————————————-

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

 

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

April 5, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

————————————————————————

04 Apr 24. Raytheon increases tech readiness of CADRE for US Navy Next Gen Jammer. The objective is to advance its ‘Controlled, Advanced, Distributed Radio Frequency Effects’ from TRL three to TRL six for NGJ integration. Raytheon, a US defence prime and RTX subsidiary, will develop its ‘Controlled, Advanced, Distributed Radio Frequency Effects’ (CADRE) enough to integrate them with the US Navy’s Next Generation Jammer (NGJ). The US Department of Defense allocated $40.59m to the supplier on 3 April 2024, to advance CADRE from technology readiness level (TRL) three to TRL six. The work will be divided into three phases: System Design and Risk Reduction; Detailed Design, Integration and Verification; and Ground Test and Flight Demonstration. These phases aim to achieve measurable progress toward the long-term Future Naval Capabilities objective of multi-aircraft flight demonstration. Work will be performed in McKinney, Texas, and the base effort is expected to be completed in November 2025. NGJ is the next step in Airborne Electronic Attack (AEA). It is needed to meet emerging electronic warfare (EW) threats. The system will augment, and ultimately replace, the legacy ALQ-99 Tactical Jamming System that is currently used on the Navy’s EA-18G Growler Electronic Attack aircraft. Using the latest digital software and Active Electronically Scanned Array (AESA) technologies, NGJ provides enhanced AESA capabilities to disrupt, deny, and degrade enemy air defence and ground communication systems. It brings increased power and jamming capability at longer ranges. Additionally, the system allows for rapid hardware and software updates to counter improving and evolving threat capabilities. A little over a year ago, the DoD awarded Raytheon a $650m contract for the production of 15 low-rate initial production Lot III NGJ mid-band ship sets, 11 of which were to be used by the US Navy and four for the Royal Australian Navy. At the time, a GlobalData Defence Analyst commented that these sets will be “more powerful, have open-source systems for software and hardware upgrades, and use AESA technology themselves sometimes. Details on jamming tech like this can be sparse but consider it a likely upgrade in most or all ways.” Now, Raytheon will enhance the NGJ further with CADRE capabilities in its evolution to continually outmatch emerging EW capabilities. The global EW market, valued at $13.9bn in 2023, is projected to grow at a compound annual growth rate of 4.6% over the next decade. GlobalData anticipates the market will reach $21.8bn by 2033 and cumulatively value $194.2bn over the forecast period. (Source: naval-technology.com)

 

02 Apr 24. Cobra Shows its Fangs. Iran’s Cobra-V8 EW system has strong similarities with Russia’s IRL257E Krasukha-4 jammer as can be seen from the antenna arrangement on the top of the vehicle. Iran claims to have new jamming capabilities in the form of the Cobra-V8, but is this simply a re-badged Russian Krasukha-4 electronic attack system, and how capable might it be? Is the Islamic Republic of Iran’s Cobra-V8 Electronic Warfare (EW) system an indigenised version of Russia’s 1RL257E Krasukha-4 EW platform? It certainly looks that way. News came to light on social media in mid-March that Cobra-V8 systems had supported a recent Iranian military exercise. At first blush, Iran’s equipment bears a strong resemblance to its Russian counterpart. This is arguably most visible in the antenna ensemble atop the container on the rear of the vehicle. On the 1RL257E two circular antennas are positioned either side of two large horizontal plates. These plates presumably prevent the sidelobes spreading out around the main jamming beam interfering with beams from the other antennas. A closer look at the antennas assembly reveals that they point inwards. This configuration may help ensure that jamming beams are focused on the target. Whether Iran has purchased the 1RL257E directly from Russia or manufactures it under licence is unknown. The fact that the system is designated as the Cobra-V8 seems to suggest local or licenced manufacture.

Targets

Information in the public domain says that that 1RL257E attacks airborne emitters using frequencies of eight gigahertz/GHz to 18GHz. This waveband would be sufficient for the 1RL257E to target airborne X-band (8.5GHz to 10.68GHz) radars and Satellite Communications (SATCOM). Airborne Ku-band (13.4GHz to 14GHz/15.7GHz to 17.7GHz) radars and SATCOM (14GHz uplink/10.9-12.75GHz downlink) could also be targeted. Public information continues that Krasukha-4 can engage airborne targets at between one degree and 60 degrees’ elevation across a 360-degree radius.

The 1RL257E is advertised as being capable of attacking airborne emitters at up to 162 nautical miles/nm (300 kilometres/km) range. According to Russian language documents seen by Armada, Krasukha-4 can transmit up to 64 decibels/dB of jamming energy. The system may have an antenna gain of 96.5dB based on the circa one metre (3.3 feet) diameter of the circular antennas. Gain is basically a measurement of how much energy an antenna can focus onto a target, much like how a magnifying glass can focus sunlight.

Performance

For this discussion, we will assume that the 1RL257’s target is a combat aircraft with a ten square metre Radar Cross Section (RCS). RCS is a measurement of how large, or small, a target appears to a radar. Let us assume the Krasukha-4 is transmitting a jamming signal on a frequency of 8.2GHz. The signal is travelling across its full advertised range of 162nm against a target with a seven square metre RCS.

According to our own rough back-of-the-envelope calculations, the jamming signal would leave the 1RL257E with 64dB of strength. Nonetheless, it would lose 77.4dB of strength during its journey. Thus, the jamming signal would have a strength of -13.4dB when it reaches the target. This is not the whole story as the jamming signal must move through the atmosphere which also causes it to lose energy, in this case up to 160.3dB. Taken on its own, the jamming signal may now have a strength of -96.3dB when it reaches the target. We must also add the 77.4dB signal loss, meaning that the jamming signal may have a combined strength of -173.7dB. Decibels are a tricky thing to explain, but a basic rule says that the closer the figure is to zero the stronger the signal. It is possible that at such ranges jamming signals this weak may not be able to ‘wash out’ the signal strength of the radar or SATCOM system they are trying to attack.

Iran’s deployment of the Cobra-V8 is a cause for concern and something that allied powers, who may have to face the country’s military in any future conflict, should take seriously. Nonetheless, the capabilities of such systems can sometimes be exaggerated for propaganda purposes. (Source: Armada)

 

03 Apr 24. April Spectrum SitRep.

Kvertus is supplying the company’s AD Counter FPV jamming system to the Ukrainian military to provide protection against tactical FPV UAVs.

Armada’s monthly round-up of all the latest electronic warfare news in the product, programme and operational domains.

New CUAV Systems for Ukrainian Military

In early March Kvertus announced it was equipping the Ukrainian Army’s 3rd Assault Brigade with new electronic warfare systems. Specifically, the force is being supplied with the company’s AD Counter FPV jamming equipment. The AD Counter FPV jams radio signals across a waveband of 850 megahertz/MHz to 940MHz; frequencies commonly used by First Person View Uninhabited Aerial Vehicles (FPV UAV). Signals on these frequencies are employed to connect the aircraft to its pilot. The company said that the AD Counter FPV can achieve jamming ranges of up to 0.2 nautical miles (300 metres). The system is available in static and backpack configurations, and can be installed on vehicles. The company told Armada that the AD Counter FPV “can prove useful when employed during assault attacks, when shorter distances between the enemy’s drones and their pilot allows the disruption of radio communications between the aircraft and its control station.” Currently, these systems are only being supplied to the Ukrainian armed forces to ensure that the ongoing threat presented by Russian tactical UAVs can be countered.

Ready Mercury

Mercury Systems has won a $243.7m contract to supply Digital Radio Frequency Memory (DRFM) subsystems to the US Navy. According to a press release announcing the news the DRFMs are to support AN/ULQ-21(V) electronic attack systems. Details of the AN/ULQ-21(V)’s manufacturer do not appear in the public domain. It is thought the system is used to simulate hostile jamming waveforms. The DRFMs will be installed on AN/ULQ-21(V) systems employed by the Naval Air Warfare Centre Weapons Division. Specifically, they are expected to be used by training aircraft flown by the US military. Mercury Systems told Armada that DRFM deliveries will commence in circa August 2025. The company expects to complete the work by February 2029.

New RWRs for US Army Apaches

On 11th March Northrop Grumman revealed it had been awarded a contract to produce AN/APR-39E(V)2 Radar Warning Receivers (RWRs) for the US Army. James Conroy, Northrop Grumman’s vice president for navigation, targeting and survivability, told Armada that “the AN/APR-39E(V)2 is the next step in the evolution of the AN/APR-39, the radar warning receiver and suite controller that has been protecting aircraft for decades.” The AN/APR-39E(V)2 is fully digital and “uses Northrop Grumman’s ultra-wideband architecture that provides greater instantaneous bandwidth, higher sensitivity, and improved digital signal processing algorithms to handle advanced threats.” Mr. Conroy continued that deliveries of these RWRs are scheduled to take place in 2026. These systems will equip US Army Boeing AH-64E Guardian attack helicopters. The exact number of AN/APR-39E(V)2s to equip these aircraft will be determined by the force. Nonetheless, Mr. Conroy stated that “the army has more than 2,000 fixed- and rotary-wing aircraft which the AN/APR-39E(V) was designed to support.”

(Source: Armada)

 

03 Apr 24. DOD Cyber Officials Detail Progress on Zero Trust Framework Roadmap. The Defense Department is on track to implement its zero trust cybersecurity framework by the end of fiscal year 2027, senior Pentagon information technology officials said this week.

David McKeown, who serves as the DOD’s deputy chief information officer, underscored the significant progress the department has made in implementing what he said will be a transformational change in how the department approaches cybersecurity.

“Zero trust integration offers the most robust and reliable approach to cybersecurity, ensuring that our systems are resilient against evolving threats, while safeguarding our nation’s interests,” McKeown said today during his keynote address as part of a virtual two-day Zero Trust Symposium hosted by the Defense Acquisition University.

“It is not just a program, or a new application, zero trust is an evolution of our entire security landscape,” he said. “By embracing it, we not only protect our data, but we strengthen our defenses and preserve our way of life.”

Once implemented, the zero trust framework will move the DOD beyond traditional network security methods with capabilities designed to reduce exposure to cyberattacks, enable risk management and data sharing and quickly contain and remediate adversary activities.

The department released its strategy for achieving its vision for a zero trust architecture in 2022. The strategy outlines four high-level goals including cultural adoption, security and defense of DOD information systems, technology acceleration and zero trust enablement.

Since unveiling the strategy, McKeown, who also serves as the department’s senior information security officer, said his office has remained laser focused on making it a reality.

“As the DOD’s lead for zero trust, we have made great progress,” he said, detailing the department’s efforts to align resources and capabilities at the component level, review implementation plans submitted by DOD agencies and work with industry to build solutions.

John Sherman, DOD’s chief information officer, said implementing the framework has been an “absolute top priority.”

“If you look at our funding, and if you look at our cyber investments we’re making and the time we’re spending, zero trust is first and foremost among what we’re doing,” Sherman said yesterday, the first day of the symposium.

He said what once seemed unachievable just a few years ago is now becoming a reality.

“We are looking really good, on track, to get target-level zero trust in place by the end of fiscal 2027,” he said.

Both officials underscored the importance of implementing the framework as adversaries continue to improve their offensive cyber capabilities.

“Our protection and detection methodologies absolutely need to change in order to defend against today’s adversaries,” McKeown said. “Because of this, zero trust is my top cybersecurity initiative. I absolutely believe zero trust will greatly improve our ability to defend our networks against sophisticated attacks.” (Source: U.S. DoD)

 

03 Apr 24. Global: New malware distribution campaign points to threats posed by financially motivated groups. On 2 April, the software company Mcafee unveiled the discovery of a new ‘Pikabot’ campaign. Pikabot is a trojan attributed to ‘Water Curupira’, a financially motivated threat group. It is typically distributed via thread-jacking phishing emails, wherein threat actors hijack existing email threads to trick a user into downloading a malicious file. This file then enables the threat actors to execute code remotely on the infected system. This allows them to deploy the ‘Black Basta’ ransomware and to garner illicit profit. However, the new campaign distinguishes itself from previous iterations as a result of the wider variety of file formats and links used for distribution; these significantly bolster the group’s success rates. This highlights the sophistication of Water Curupira’s tactics, techniques and procedures (TTPs), as well as its knowledge of modern IT systems. Additionally, the recent rise in Pikabot distribution via multi-stage operations further underscores the growing security and financial threats posed by financially motivated groups. (Source: Sibylline)

 

02 Apr 24. Palantir to Deliver EMBM-J DS Prototype to the DISA. Palantir Technologies Inc. (NYSE: PLTR) today announced that it was selected by the Defense Information Systems Agency (DISA) to deliver an Electromagnetic Battle Management – Joint Decision Support (EMBM-J DS) Prototype. This effort will provide the Department of Defense with a cutting-edge software capability to support Joint Electromagnetic Spectrum Operations (JEMSO). The award of prototype Other Transaction Authority (OTA) Agreement is worth $9.8 m over twelve months. Palantir will work closely with the DISA PEO Spectrum as well as USSTRATCOM, the operational sponsor, and Combatant Commands to enable enhanced mission analysis, course of action (COA) and scheme of maneuver development, COA analysis and scoring, wargaming, and product production. This Impact Level 6, web-based EMBM-J DS prototype will also integrate with Service tools and processes for Electromagnetic Battle Management, maximizing interoperability and coordination across the joint force.

“The next iteration of the program addresses the need for a decision support capability by providing joint force commanders with a first-of-its-kind planning tool that can automate key operational electromagnetic spectrum planning processes,” said Donny Williams, PEO Spectrum chief of spectrum information systems.

“We are excited to continue our work with DISA PEO Spectrum and deliver our technology to accelerate the Department of Defense’s achievement of spectrum dominance,” said Dr. Miriam Marwick, SVP of Emerging Technologies at Palantir USG. “Through our extensive work with the operational community, we have learned a great deal about the impact of electromagnetic spectrum on recent conflicts and are working diligently to apply these lessons to meet the challenges of contested battlespaces.”

“DISA should be commended for their leadership in enabling warfighter decision-making in future battlefields,” said Akash Jain, President of Palantir USG. “We are proud to have been selected through DISA’s competitive procurement process and look forward to rapidly delivering a minimum viable capability to integrate EMBM-J DS into all aspects of mission planning.”

EMBM-J DS represents the next phase of Palantir’s ongoing investment in spectrum operations capabilities and will support joint planning efforts through JEMSO planning processes. The capability is being designed to integrate with service-provided Electromagnetic Battle Management tools and processes, maximizing interoperability between combatant command and Joint Task Force JEMSOCs and their counterparts at the component level.

“The ability to ingest component-level courses of action and schemes of maneuver into an overall joint plan and evaluate the associated electromagnetic spectrum opportunities and risks will be a significant technological leap forward for EMS operational planners,” said Betsy Park, EMBM-J program manager. “EMBM-J will play a critical role in ensuring that our forces are able to achieve EMS superiority across every warfighting domain.” (Source: ASD Network)

 

02 Apr 24. BAE Systems’ Eagle Passive Active Warning Survivability System for F-15 aircraft completes operational testing. The U.S. Air Force recently completed Initial Operational Test & Evaluation (IOT&E) of the Eagle Passive Active Warning Survivability System (EPAWSS), validating the game-changing capabilities BAE Systems’ advanced system brings to the F-15. EPAWSS provides critical electronic warfare (EW) capabilities for the F-15E Strike Eagle and F-15EX Eagle II aircraft.

“EPAWSS was designed for upgradeability and rapid capability insertion,” said Amy Nesbitt, EPAWSS program manager at BAE Systems. “We’re using agile software development to provide iterative upgrades to fielded EW systems—allowing our customers to defeat future electromagnetic threats.”

EPAWSS provides instantaneous full-spectrum EW capabilities—including radar warning, geolocation, situational awareness, and self-protection. The system enables freedom of maneuver and deeper penetration into battlespaces protected by modern integrated air defense systems.

“EPAWSS is a leap in technology, improving the lethality and combat capabilities of the F-15E and F-15EX in contested, degraded environments against advanced threats,” said Maj Bryant “Jager” Baum, EPAWSS Test Director for the Air Force Operational Test & Evaluation Center (AFOTEC). “EPAWSS has set the baseline for EW within the fighter community.”

BAE Systems supported AFOTEC in executing EPAWSS IOT&E and is now in the process of producing and fielding one of the world’s most advanced EW systems, improving the F-15’s ability to conduct combat missions. The company is working closely with Boeing and the U.S. Air Force to enhance the system’s discriminating EW capabilities, including the use of cognitive EW as demonstrated during the Northern Edge 2023 (NE23) large force exercise test event.

“Our close collaboration with the U.S. Air Force allows us to mature EPAWSS cognitive processing capabilities,” said Chip Mosle, program director at BAE Systems. “By incrementally testing and fielding cognitive EW solutions to proven systems such as EPAWSS, we are enabling tactical spectrum overmatch against advanced threats that are unpredictable, evolving, and adaptable.”

The NE23 event tested EPAWSS’ ability to rapidly respond to previously unencountered electromagnetic threats. The tests challenged the system’s ability to process in-mission sensor data, create exquisite techniques, and optimize waveforms in real time. Furthermore, the NE23 environment challenged the system to execute the tasks in a dense, unpredictable electromagnetic spectrum at a theater-exercise level. BAE Systems executes the EPAWSS program at its facilities in Nashua, New Hampshire and Austin, Texas, actively producing EPAWSS hardware in support of F-15EX new-aircraft production and F-15E aircraft fleet modifications. For additional information about EPAWSS, visit http://www.baesystems.com/epawss. (Source: News Now/PR Newswire)

 

02 Apr 24. Global: New vulnerability points to sustained information-theft risks via software supply chain. On 1 April, security researchers at Microsoft discovered a new vulnerability affecting the Linux open-source software ‘liblzma’ (versions 5.6.0 and 5.6.1). The vulnerability comprises a backdoor hidden in the liblzma source code, which is often used in authentication processes (such as Secure Shell, SSH). The backdoor intercepts legitimate SSH connections, effectively authenticating unauthorised threat actors on the system. Subsequently, threat actors can remotely execute malicious code on a compromised machine, enabling them to steal sensitive data, install malware, disrupt critical operations and/or launch further attacks. The software supply chain often presents a significant security challenge for organisations, especially as these organisations are increasingly reliant on third-party services and struggle to protect the growing attack surface adequately. Chinese-affiliated actors recently exploited vulnerabilities in third-party virtual private network (VPN) software to steal sensitive information from the Dutch Ministry of Defence (MoD). Consequently, we assess that this highlights the sustained information-theft risks stemming from third-party software, especially as supply chain attacks become an increasingly productive attack vector. (Source: Sibylline)

————————————————————————-

Spectra Group (UK) Ltd

 

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

 

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

March 28, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

————————————————————————

29 Mar 24. Palantir to Deliver Electromagnetic Battle Management – Joint Decision Support (EMBM-J DS) Prototype to the Defense Information Systems Agency (DISA). Palantir Technologies Inc. (NYSE: PLTR) today announced that it was selected by the Defense Information Systems Agency (DISA) to deliver an Electromagnetic Battle Management – Joint Decision Support (EMBM-J DS) Prototype. This effort will provide the Department of Defense with a cutting-edge software capability to support Joint Electromagnetic Spectrum Operations (JEMSO). The award of prototype Other Transaction Authority (OTA) Agreement is worth $9.8 million over twelve months.

Palantir will work closely with the DISA PEO Spectrum as well as USSTRATCOM, the operational sponsor, and Combatant Commands to enable enhanced mission analysis, course of action (COA) and scheme of maneuver development, COA analysis and scoring, wargaming, and product production. This Impact Level 6, web-based EMBM-J DS prototype will also integrate with Service tools and processes for Electromagnetic Battle Management, maximizing interoperability and coordination across the joint force.

“The next iteration of the program addresses the need for a decision support capability by providing joint force commanders with a first-of-its-kind planning tool that can automate key operational electromagnetic spectrum planning processes,” said Donny Williams, PEO Spectrum chief of spectrum information systems.

“We are excited to continue our work with DISA PEO Spectrum and deliver our technology to accelerate the Department of Defense’s achievement of spectrum dominance,” said Dr. Miriam Marwick, SVP of Emerging Technologies at Palantir USG. “Through our extensive work with the operational community, we have learned a great deal about the impact of electromagnetic spectrum on recent conflicts and are working diligently to apply these lessons to meet the challenges of contested battlespaces.”

“DISA should be commended for their leadership in enabling warfighter decision-making in future battlefields,” said Akash Jain, President of Palantir USG. “We are proud to have been selected through DISA’s competitive procurement process and look forward to rapidly delivering a minimum viable capability to integrate EMBM-J DS into all aspects of mission planning.”

EMBM-J DS represents the next phase of Palantir’s ongoing investment in spectrum operations capabilities and will support joint planning efforts through JEMSO planning processes. The capability is being designed to integrate with service-provided Electromagnetic Battle Management tools and processes, maximizing interoperability between combatant command and Joint Task Force JEMSOCs and their counterparts at the component level.

“The ability to ingest component-level courses of action and schemes of maneuver into an overall joint plan and evaluate the associated electromagnetic spectrum opportunities and risks will be a significant technological leap forward for EMS operational planners,” said Betsy Park, EMBM-J program manager. “EMBM-J will play a critical role in ensuring that our forces are able to achieve EMS superiority across every warfighting domain.” (Source: BUSINESS WIRE)

 

29 Mar 24. Establishment of the Office of the Assistant Secretary of Defense for Cyber Policy. As directed in the National Defense Authorization Act for Fiscal Year 2023, the Department of Defense established the Assistant Secretary of Defense for Cyber Policy (ASD(CP)) and the Office of the Assistant Secretary of Defense for Cyber Policy (OASD(CP)) on March 20, 2024.

The ASD(CP) will be the senior official responsible for overall supervision of DoD policy for cyber operations.  The ASD(CP) will be under the authority, direction, and control of the Under Secretary of Defense for Policy (USD(P)).  In addition, ASD(CP) serves concurrently as the Principal Cyber Advisor (PCA) and, in that role, acts as principal advisor the Secretary of Defense on military cyber forces and activities.  The Deputy Assistant Secretary of Defense for Cyber Policy (DASD(CP)) and Deputy Principal Cyber Advisor (DPCA) report through the ASD(CP).

“In standing up this office, the Department is giving cyber the focus and attention that Congress intended,” said Acting Undersecretary of Defense for Policy Sasha Baker.

The Secretary of Defense has designated Ms. Ashley Manning, a career member of the Senior Executive Service, as the official performing the duties of the ASD(CP) until such time as an individual is nominated by the President, confirmed by the Senate, and appointed to the position. The President has nominated Michael Sulmeyer, who is currently serving as the Principal Cyber Advisor to the Secretary of the Army, to be the Assistant Secretary of Defense for Cyber Policy.

The ASD(CP) is responsible to the Secretary of Defense, Deputy Secretary of Defense, and USD(P) for all matters related to cyber-related activities that support or enable DoD missions in, through, and from cyberspace, including but not limited to:

  • Developing, coordinating, assessing, and overseeing the implementation of DoD cyberspace policy and strategy, and ensuring these efforts are aligned with overarching national security objectives.
  • Overseeing and certifying the department’s Cyberspace Operations Budget, Additionally, providing fiscal and budgetary oversight to USCYBERCOMs $3B annual execution with their ‘Enhanced Budget Control’ (Budget Authority, as recently approved by the FY24 DoD Appropriations Act)
  • Monitoring programs and activities associated with implementation of cyberspace workforce development, recruitment, and retention.
  • Overseeing integration of cyberspace operations and capabilities into operations and contingency plans.
  • Developing DoD cyberspace policy guidance on private sector outreach, engagement, and agreements.
  • Leading the DoD implementation of national-level cyberspace policies.
  • Leading the development, implementation, and oversight of cyberspace-related activities for security cooperation.
  • Exercising authority, direction, and control over the official designated as Deputy PCA with respect to that official’s Deputy PCA duties.  (Source: U.S. DoD)

 

25 Mar 24. Silvus Technologies developing StreamCaster variant for small UAS. Mobile networking company Silvus Technologies is developing a pared down variant of its StreamCaster mobile ad hoc network (MANET) radio, specifically designed to provide networked radio communications capability for small unmanned aircraft systems (UASs).

Company officials are preparing to release “our next generation” of the small UAS-specific StreamCaster variant later this year, Silvus Technologies vice-president of sales Jimi Henderson said.

“We’ve seen that as a key and demand signal in the market and we’re working to help address that gap” with the new variant, he told Janes . Henderson declined to comment on specifics of the new MANET radio variant.

However, he indicated that the new platform would likely feature a significantly smaller form factor, compared with the StreamCaster Lite 4200, which is currently the company’s smallest offering in the StreamCaster family of systems. (Source: Janes)

 

28 Mar 24. DOD Releases Strategy to Bolster Cybersecurity Across Industrial Base. The Pentagon today released its first strategy aimed at enhancing cybersecurity across defense industry stakeholders.

The Defense Industrial Base Cybersecurity Strategy plots a course for increased focus and collaboration between the Defense Department and the U.S. defense industrial base on cybersecurity initiatives amid what officials say are persistent cyberthreats.

“Our adversaries understand the strategic value of targeting the DIB,” said David McKeown, DOD’s deputy chief information officer for cybersecurity. “Private sector DIB contractors are at risk for malicious cyber activities by adversaries and nonstate actors alike,” he said. “Working in conjunction with the DIB, we can better ensure the safety of critical information and unauthorized disclosure of that information.”

McKeown, who also serves as DOD’s senior information security officer, was joined by Stacy Bostjanick, DOD’s chief of defense industrial base cybersecurity, in unveiling the strategy at the Pentagon.

“We need to get on top of this extremely complex challenge,” Bostjanick said. “This is a well contemplated, multifaceted, agile and nuanced response to the constant and evolving challenge securing the DIB against malicious cyber activity.”

The strategy lays out DOD’s vision over the next three years for a secure, resilient and technologically superior U.S. defense industrial base to ensure the United States’ warfighting edge.

It outlines four goals aligned with that vision:

Strengthening DOD’s governance structure for U.S. defense industrial base cybersecurity;

Enhancing the cybersecurity posture of the U.S. defense industrial base;

Preserving the resiliency of critical defense industrial base capabilities in a cyber-contested environment; and

Improving cybersecurity collaboration between DOD and the U.S. defense industrial base.

Central to the goal of strengthening DOD’s cybersecurity governance structure are efforts to bolster interagency collaboration and develop regulations that will further govern the cybersecurity responsibilities of contractors and subcontractors.

In terms of enhancing the DIB’s cybersecurity posture, the strategy outlines steps to evaluate compliance with departmental cybersecurity requirements and evaluate the effectiveness of regulations and requirements. It also outlines steps to improve cyber-related threat and intelligence information with industry partners, identify vulnerabilities and recover from malicious cyber activity.

The strategy also directs the department to prioritize cyber resiliency among critical defense production capabilities and establish policies that reflect a focus on cybersecurity for key suppliers.

That focus aligns with broader department guidance, including the 2022 National Defense Strategy and the 2023 National Cybersecurity Strategy.

The newly released document also responds to a requirement to develop a comprehensive plan to ensure the reliability and integrity of production nodes for critical weapons systems outlined in the 2023 strategy.

The cybersecurity strategy also marks a continuation of the department’s efforts to ensure the defense industrial base meets the demands of a challenging national security landscape.

Earlier this year, the Pentagon released the National Defense Industrial Strategy, which lays out long-term priorities that will guide DOD’s actions to create a modern, resilient defense industrial ecosystem designed to deter U.S. adversaries and meet the production demands posed by evolving threats.

The NDIS focuses on four key areas critical to building a modernized defense industrial ecosystem over the next three to five years. Those areas are resilient supply chains, workforce readiness, flexible acquisition and economic deterrence.

The newly released cybersecurity strategy further builds upon that collaboration between DOD and its industry partners.

“We have identified opportunities to bolster cybersecurity of our DIB partners, which will improve our overall cybersecurity of the U.S.,” said Deputy Defense Secretary Kathleen Hicks in a statement accompanying the release of the strategy. “As our adversaries continuously seek information about U.S. capabilities, the department, in coordination with the DIB, must remain resilient against these attacks and succeed through teamwork to defend the nation.” (Source: U.S. DoD)

 

28 Mar 24. Israel announces that Oron intelligence aircraft is operational. The Oron intelligence-gathering aircraft is carrying out missions in support of Operation ‘Iron Swords’ against Hamas in the Gaza Strip, the Israel Ministry of Defense (MoD) announced on 26 March.

“The aircraft became operational quickly for use in Operation ‘Iron Swords’ and has already recorded hundreds of operational flight hours and close to 100 sorties,” the MoD said in a statement.

Developed by the MoD’s Directorate of Defense Research and Development (DDR&D), Israel Aerospace Industries (IAI), and the Israeli Air Force (IAF), the Oron is a Gulfstream G550 business jet equipped with an advanced active electronically scanned array (AESA) radar produced by IAI subsidiary Elta, as well as electro-optical and signals intelligence (SIGINT) sensors and advanced data-processing systems.

“What makes Oron unique is its ability to perform a wide range of intelligence missions in the same sortie and to transmit in real time to all relevant entities,” the MoD’s statement said. It added that the aircraft can collect a larger volume of information than any other Israeli platform.

The aircraft was unveiled on 4 April 2021, when it landed at Nevatim Air Base to be fitted with its mission systems in Israel. The MoD announced in August 2023 that Oron had begun flight tests, describing it as the most advanced aircraft of its kind.

Lieutenant Colonel Yoed, head of the DDR&D’s Missionized Aircraft Branch, said he called 122 ‘Nachson’ Squadron and industry partners to get Oron operational as soon as details of Hamas’ 7 October 2023 attack on Israel emerged. (Source: Google/Janes)

 

28 Mar 24. New Multi-Network Support Capability for Radio Operators.

goTenna’s new EdgeRelay offers permanent extended network coverage for off-grid missions, offering environmental ruggedization and external charging options to extend onboard powerBy Abi Wylie / 25 Mar 2024

goTenna has unveiled a new multi-network, endurance-focused support capability for goTenna’s Pro X2 radio operators — the goTenna EdgeRelay™.

This ad hoc infrastructure solution supports up to two separate mesh networks, with the system extending goTenna networks and offering environmental ruggedization, external charging options to extend onboard power, and varied mounting support to ensure sustained operational coverage without expensive and cumbersome installations.

Customers can mount the goTenna EdgeRelay in remote and austere environments to ensure seamless connectivity of goTenna edge networks. Tested at over 100 miles point-to-point line-of-sight in real-world scenarios, EdgeRelays can be connected together to create several hundred square miles of coverage.

With solar and direct power options, along with a dependable internal battery, the goTenna EdgeRelay aims to provide continuous operation as a dedicated infrastructure relay. This ruggedized and self-sustaining solution provides labor and personnel cost savings to the end user.

Using an EdgeRelay greatly reduces the time it takes to deploy, recharge, fix, and maintain ad-hoc communications in an austere or comms-denied environment.

The goTenna EdgeRelay system supports two separate mesh networks on each device, allowing operators to support different mission configurations, and is already enhancing missions for multiple U.S. government organizations. Additional software features in the relay introduce advanced capabilities for remote diagnostic checks on network statistics and health.

A companion relay manager app and updated TAK plug-in allow operators to remotely monitor the health and status of deployed relays across the mesh network, eliminating the need to physically revisit deployed relays.

Ari Schuler, goTenna CEO, said; “One of goTenna’s greatest strengths is being able to stand up a communication network where there is no infrastructure whatsoever.

“The EdgeRelay extends that capability by enabling our customers to create robust fixed or itinerant goTenna mesh networks that operators can automatically connect to, offering more flexibility to those who are responding to natural disasters, supporting an austere forward operating base or operating in other difficult mission environments.”

(Source: https://www.defenseadvancement.com/)

 

28 Mar 24. DoD Releases Defense Industrial Base Cybersecurity Strategy. Today, the Department of Defense (DoD) released its Defense Industrial Base (DIB) Cybersecurity (CS) Strategy, an actionable approach to maturing a more resilient Joint Force and Defense cybersecurity ecosystem.  Spanning Fiscal Year 2024 – 2027, the DoD DIB CS Strategy provides a path forward for the Department’s internal and industry-facing cybersecurity activities.

The Strategy’s vision, mission, goals, and objectives support the directives and priorities of the National Defense Strategy, 2023 National Cybersecurity Strategy, and 2023 DoD Cyber Strategy.  By sharpening the Department’s focus on collaboration with industry partners, the Strategy’s four goals and key objectives will guide DoD’s efforts to defend the nation and maintain our technology advantage:

  1. Strengthen the DoD governance structure for DIB Cybersecurity
  2. Enhance the Cybersecurity posture of DIB contractors
  3. Preserve the resiliency of critical DIB capabilities in a cyber-contested environment
  4. Improve collaboration with DIB.

The Department is working together with the DIB, harnessing the expertise of Industry, academic institutions and research and development organizations to achieve the goals and objectives in this strategy.

“We have identified opportunities to bolster cybersecurity of our DIB partners, which will improve our overall cybersecurity of the US,” said Deputy Secretary of Defense Hicks.  “As our adversaries continuously seek information about U.S. capabilities, the Department, in coordination with the DIB, must remain resilient against these attacks and succeed through teamwork to defend the Nation.”

You can read a copy of the strategy here: https://media.defense.gov/2024/Mar/28/2003424523/-1/-1/1/DOD_DOB_CS_STRATEGY_DSD_SIGNED_20240325.PDF(Source: U.S. DoD)

 

28 Mar 24. Thales, Europe’s leading high-tech company in the civil and defence fields, has announced the creation of cortAIx, which brings together the company’s AI capabilities in research, sensors and systems.

  • cortAIx is the AI accelerator that will equip armed forces, aircraft manufacturers and all critical infrastructure operators with highly secure solutions to provide them with more efficient data analysis and decision support, whilst taking into account specific constraints such as cybersecurity, embeddability and frugality that are related to critical environments.
  • With over 600 AI experts, around 100 doctoral students in AI and a top-tier network of industry, start-up and academic partners, Thales has been a major player in trusted, transparent, explainable and ethical AI for the past decade. The company is Europe’s top patent applicant in the field of AI for critical applications, and has incorporated AI into over a hundred of its products and services.

The defence sector is undergoing major changes related to the proliferation of data on the battlefield. And it is taking advantage of new usage in the civilian world, such as personal assistants, video analysis and noise reduction.

On the back of the investments it has made in the field of AI, Thales has been incorporating AI into its critical systems for the last ten years, in order to enable its customers to gain an edge and to become more resilient in the face of a deluge of data, threats and information.

Thales Chairman and CEO Patrice Caine, said: “Our company, which is a European leader in the fields of civil and defence high-tech, is able to draw on its mastery of AI and on the assets that are its strength: its technological expertise, its knowledge of critical domains – defence and aerospace, space, cybersecurity, digital identity – and its management of constrained environments. Thales is already developing embeddable, frugal, trusted, explainable and secure end-to-end solutions, and today it is moving to the next level by acquiring major AI capabilities, that meet the security and sovereignty needs of our customers.”

cortAIx, the trusted AI accelerator for research, sensors and systems

On the occasion of today’s fourth edition of the Thales Media Day, structured around AI, Thales is introducing cortAIx, the AI accelerator designed to expand the integration of AI technology into all of the company’s sectors of activity (defence, space, aerospace, cybersecurity and digital identity). cortAIx brings together:

  • cortAIx Lab – the most powerful integrated lab for critical AI in Europe, based in Saclay, at the heart of the European innovation ecosystem.
  • cortAIx Factory – Thales’s AI technology factory, designed to speed up the classification and industrialisation of AI development tools and use cases for system data. Thales already equips its systems with AI, and continues to identify new use cases to increase performance, such as, for instance, mission planning, air traffic management, and steering drones and robots. AI enables situations to be analysed and processed quicker and systems to be used more intuitively, in order to speed up decision-making and reduce operators’ mental workload.
  • cortAIx Sensors – this represents all the AI capabilities in the field of sensors within the company’s defence businesses. The Thales sensors (sonar, radar, radio and optronics) that incorporate AI offer hugely increased capabilities – both more precise and more efficient – in terms of sighting and identifying threats and targets, and they meet frugality requirements in terms of size, weight, power, as well as being resilient in extreme environments.

This trusted AI serves its end-users, who remain the final decision-makers at all times.

Cybersecure AI

In the face of the security threats of AI, Thales, which is a pioneer in the field, has developed specific assessment methods at its Toulouse-based CESTI laboratory (Centre d’Évaluation de la Sécurité des Technologies de l’Information – Centre for the Assessment of the Security of Information Technology), which is certified by ANSSI (the French Agency for Information System Security). It draws on the expertise of more than 5,800 cybersecurity experts across the company to provide tailor-made solutions for the vulnerabilities that have been detected.

Trusted AI in Thales’s critical systems

Sonar, radar, equipment on board maritime patrol aircraft and fighter jets… Thales’ solutions use the best sensor and system technologies, which cover the whole range of intelligence needs in the land, aerospace and space domains. Trusted AI, which is incorporated into these sensor technologies, lightens operators’ workloads and speeds up the detection, identification and classification of objects of interest and target scenes:

  1. The Talios pod is designed for air reconnaissance and targeting missions, and is to be found on board Dassault Aviation’s Rafale fighter jet. Until now, the images collected by the pod were analysed on the ground, but thanks to the Thales Neural Processor, the optronics images captured in flight will be analysed in real time, and 100 times quicker, by embedded AI.
  2. With its Friendly Hacking unit, Thales provides its development teams with the ability – hitherto unseen in the industry – to submit their AI-based solutions to a cyber crash-test, with the aim of strengthening considerably the cybersecurity of systems that implement AI.
  3. AI on board maritime patrol aircraft’s AirMaster surveillance radars enables ever-greater quantities of data to be analysed, and targets to be classified in a few tenths of a second.
  4. Thales’ air defence radars perform remarkably well in detection at very low altitude. AI will provide significant help to operators in identifying small targets.
  5. AI in air traffic control systems will enable the optimisation of the sequencing of aircraft on the approach paths to airports, thus contributing to a reduction in their carbon footprint.
  6. AI will make the coordination of multi-drone and multi-robot systems easier. The controlled and secure autonomy of these systems will significantly reduce pressure on operators.
  7. Using an innovative human-machine interface coupled with AI, helicopter pilots will be able to not only prepare tactical missions much quicker, but also to change them in flight, which had until now been impossible. Pilots will remain in charge of the choice of trajectory depending on the mission objective, whilst minimising their cognitive workload.
  8. AI in radios for armed forces improves sound quality in noisy environments. It has been designed to be embdedded in a miniature chip that ensures that the autonomy of equipped devices is maintained.

 

27 Mar 24. Global: Unveiled Cyber campaigns affirm heightened risks from Chinese state-sponsored groups. On 25 March, the UK and US announced sanctions targeting two Chinese companies and individuals for their involvement in cyber espionage operations. Both governments claimed that these entities have been targeting several private and public organisations since 2020 and 2021 on behalf of ‘APT31’, a state-sponsored group affiliated with the Chinese Ministry of State Security (MSS). The compromised organisations included US 5G providers and members of the steel and energy sectors as well as the UK’s Government Communications Headquarters (GCHQ) and legislature. The announcement was followed by similar reports from Canada, Finland and New Zealand. The longevity and persistence of these campaigns affirm that cyber espionage forms an integral part of China’s strategic intelligence gathering. It is highly likely that China is seeking to bolster its economic and security posture by stealing trade secrets and compromising political organisations through cyber campaigns. Consequently, this event illustrates heightened espionage risks to Western private and public organisations from Chinese state-sponsored groups. (Source: Sibylline)

 

26 Mar 24. Finland to host NATO tech centers, revamp cybersecurity strategy. One of NATO’s newest members plans to build and jointly operate two research centers and an accelerator facility for the alliance as part of a program dubbed DIANA.

The move comes as Finland also seeks to ramp up its defense strategy and capacity to deal with escalating cyberthreats.

The NATO research centers, which are to focus on new technologies, will be based in the Finnish town of Espoo, while the accelerator unit will be run from a new facility in Oulu, Finland’s leading cyber technology hub.

The Espoo site will collaborate with VTT, Finland’s largest technical research center and the axis for quantum computer development in Finland. The location will also test cyber-secure communications in addition to quantum and space technologies.

The test facility in Oulu, which will operate in cooperation with the University of Oulu, will test 6G network technologies.

Finnish Defence Minister Antti Häkkänen said the accelerator and test centers will create business opportunities for domestic technology companies as well as help lift Finland’s profile among the 32 other fellow NATO member states. Finland joined NATO in April 2023.

“Finland’s leading position, especially in the development of new-generation communication technologies and quantum technologies, is likely to attract operators and experts to Finland. Our status as a global frontrunner of dual-use communication technologies will render Finland more attractive to international financiers and strengthen our technological input as a NATO member,” Häkkänen said in a statement.

NATO launched the DIANA program — or Defence Innovation Accelerator for the North Atlantic — in 2021 with the mission of identifying challenges for the defense sector. A core part of the program’s mission is to find technologically innovative solutions through partnerships with tech firms inside and outside of the defense industry.

Cyberspace switch

Meanwhile, under a new joint initiative, the Defence Ministry and the Ministry of Transport and Communications are tasked with revamping Finland’s national cybersecurity strategy. The initiative aims to provide the government with an operating model better suited to protect critical military and civilian assets and infrastructure.

Bolstering cyber resilience and improving defensive capabilities were among the chief national security priorities of Prime Minister Petteri Orpo’s coalition government that took power after parliamentary elections in June 2023.

The urgency behind updating the national cybersecurity strategy became evident during the third quarter of 2023 when Finnish security and intelligence service SUPO warned of a sharp rise in cyberattacks emanating from Russia. Those attacks reportedly targeted state agencies, the Finnish Defence Forces, and their critical IT networks and infrastructure.

In February, SUPO issued an alert that Russia was trying to recruit and train migrants seeking political and economic asylum in Finland as spies. The agency also warned that “hostile forces” in Russia were behind an increase in cyberespionage activities against Finland.

As a result of the heightened security threat — and with Russia allegedly bussing thousands of migrants to Finnish crossing points — Finland closed its 832-mile border with Russia on Feb. 20. The government plans to keep the border closed until April 14 at the earliest.

RELATED

Baltic states to bolster border security with Russia, Belarus

Finish government websites experienced a distributed denial-of-service attack in April 2022 amid an address to Parliament by Ukrainian President Volodymyr Zelenskyy. Russia launched a full-scale invasion of Ukraine in February 2022.

The Finnish government’s drive to strengthen national security is backed by an increase in the cyber defense budget. Finland will spend $350m on cybersecurity in 2024, corresponding to a 35% increase over 2023. A large part of the additional funding will be used to drive projects and programs that counter artificial intelligence-based cyberthreats.

The budget will support new cybersecurity measures slated for implementation by the military and SUPO in 2024. The increase in the cyber budget is partly influenced by findings and recommendations in a report on AI-enabled cyberattacks, which was delivered to the government in 2022.

The report was created by a group that included the national communications agency Traficom, the National Emergency Supply Agency, and the Helsinki-based cybersecurity firm WithSecure.

The national cybersecurity strategy, once finalized and implemented, will conform with the European Union’s updated directive on measures meant to achieve a high common level of cybersecurity across the bloc, said Rauli Paananen, director Finland’s National Cyber Security Unit.

“Under its plan, the government wants to revamp Finland’s cybersecurity strategy in a way that makes it more able to respond to the changed operating environment and the increasing risk to national security that is posed by threats from the cyber domain,” Paananen said.

The unit ran a major national cybersecurity exercise over five days in mid-February. The KYHA drill included cybersecurity experts in Finnish municipalities as well as state and private sector operators of critical infrastructure.

“Organizations need to develop cyber defense capabilities and resilience, just as Finland needs to develop cyber resilience as a country. Exercises like KYHA strengthen Finland’s cyber resilience, which is also what the cyber security strategy update aims for. The goal of the strategy is to be well prepared as a society,” Paananen said. (Source: C4ISR & Networks)

 

27 Mar 24. Rackspace Technology® (NASDAQ: RXT), a leading end-to-end hybrid, multicloud and AI technology solutions company, has announced the launch of Rackspace UK Sovereign Services as part of its next generation product set. The offering provides end-to-end, digitally sovereign cloud services for the UK public sector and other regulated industries.

Sovereign cloud services keep data, support, and infrastructure within the borders of a national state. This is normally a requirement for government agencies, healthcare providers, law enforcement organisations and other regulated industries in the private sector such as pharma and financial services. Providing a solution to these sectors assures regulatory compliance and allows a reduction in an organisation’s security risk, especially important considering the increase in global cyberthreats.

Rackspace UK Sovereign Services prioritises customer data security aligned with the recommendations of the UK National Cyber Security Centre & NHS England amongst other UK regulatory bodies. Rackspace UK Sovereign Services is changing the game by providing a platform that has dedicated compute and storage ‘Pods’ for each customer sector, each Pod is isolated from any other with full segregation of compute and storage services between customers. This approach ensures a cost-effective hosting solution for customers, while providing the high levels of data security they require. The platform is designed for secure workloads accredited for UK Official (to a handling guidance of Official-Sensitive) or NHS England Class V risk data.

Through Rackspace Technology’s extensive partnership with BT, it also provides secure, and fully sovereign, communication services into our secure data centres, adding further value to the service to customers.

“Digital independence and sovereignty within the UK have become key requirements of public sector and many other regulated industries with only a small number of providers to choose from. This truly digital Sovereign offering allows for the UK public sector to achieve cost savings and compliance all through a single provider, without compromising on security or performance,” said Rick Martire, General Manager for Sovereign Services, UK at Rackspace Technology.

Rackspace UK Sovereign Services key features include:

  • ITIL based service delivery, with incident, change & problem management.
  • Fully managed end-to-end solution with a pre-built blueprint, anti-malware protection, vulnerability scanning, performance monitoring and system patching included as standard.
  • Separated multi-tenant PODs for UK healthcare, government, police and regulated industries to ensure compute and disk workloads are never mixed on the same physical servers or disks.
  • Offering multiple levels of configuration for customers that require secure cost-effective multi-tenancy or dedicated compute / storage ranging up to a fully isolated compute, network and storage stack for higher security workloads.
  • Highly available platforms across multiple data centres capable of delivering in-built Disaster Recovery as a service.
  • Platforms and support team isolated from the Rackspace Technology global network to ensure no access is possible to sovereign platforms.
  • Costed on a monthly usage-based model, ensuring migrations in or out of the environment can still be achieved with ease.
  • Evergreen IT to ensure platforms are refreshed without a large CAPEX investment from Sovereign Customers.

About Rackspace Technology

Rackspace Technology is a leading end-to-end, hybrid, multicloud, and AI solutions company. We design, build, and operate our customers’ cloud environments across all major technology platforms, irrespective of technology stack or deployment model. We partner with our customers at every stage of their cloud journey, enabling them to modernize applications, build new products and adopt innovative technologies.

 

26 Mar 24. Royal Navy warships to be boosted with new cutting-edge launchers.

UK security will be bolstered through a new contract worth £135m that will equip the Royal Navy with new decoy launchers to counter missile and drone threats.

£135m contract for cutting-edge launchers for Royal Navy warships

  • Decoy Launchers provide increased protection for vessels against missile and drone threats, including in the Red Sea
  • New contract will sustain up to 150 jobs in the South West to help grow the economy.

UK security will be bolstered through a new contract worth £135m that will equip the Royal Navy with new decoy launchers to counter missile and drone threats, ensuring the long-term availability and resilience of warships.

Following the signing of the new contract, Trainable Decoy Launcher technology will increase the protection of Royal Navy ships and sailors, further strengthening the Navy’s ability to defend Britain’s interests across the world, including the Red Sea.

It comes as new missile and drone technology creates greater threats to the UK’s fleet and the latest decoy launchers will help counter this, providing optimised manoeuvrability that provides the capability to defend warships without the need to alter course.

The innovative new system, which uses high-end technology, will be manufactured in Systems Engineering & Assessment Ltd (SEA) site in North Devon and Chess’s facilities in Sussex, sustaining up to 150 jobs to help grow the economy. Both SEA and Chess are part of the UK-based Cohort plc group.

Minister for Defence Procurement, James Cartlidge said: “In a time of global instability, it is vital we protect the Royal Navy in the best possible way to ensure national security.  With recent attacks towards HMS Diamond and HMS Richmond in the Red Sea, it’s crucial our sailors have the latest technology to best defend themselves and the fleet.  “

The new Trainable Decoy Launcher technology is an improvement on speed and agility and highlights more excellent work from UK companies in backing UK defence.

The contract for the Trainable Decoy Launcher will see Type 26 and Type 31 frigates and Type 45 destroyers fitted with a new trainable countermeasure launcher system.

Trainable Decoy Launchers use an improved decoy launcher technology and enables a decoy to be rapidly deployed against modern missile threats, without the need to manoeuvre the vessel itself. The launcher fires a range of countermeasures, which includes chaff, flares and ‘corner reflector’ rounds to target hostile missiles.

The contract, procured by Defence Equipment & Support (DE&S), was awarded to SEA and will see a fully UK-designed and built solution. SEA have partnered with Chess Dynamics and Frazer-Nash Consultancy (FNC) to deliver the product.

Richard Flitton, Managing Director of SEA said: “Being awarded a contract of this nature demonstrates the Royal Navy’s trust in SEA which is based on our proven track record of delivering, upgrading, and sustaining high-end maritime capabilities over many years. The knowledge and maritime domain expertise within our UK-based team has enabled our long-standing partnership with the Royal Navy, and we’re delighted that this will allow us to support the UK’s defensive capabilities against modern and complex naval threats.”

DE&S CEO, Andy Start said: “This contract is an excellent example of how dedicated DE&S teams work with our partners in industry and across defence to deliver innovative and agile equipment to our Armed Forces that can be upgraded to keep pace with ever-evolving threats.”

(Source: https://www.gov.uk/)

 

25 Mar 24. Pentagon inks dozens of cloud contract orders, more in the pipeline. The U.S. Department of Defense said it lined up at least 100 task orders tied to its multibn-dollar Joint Warfighting Cloud Capability contract.

More than 47 orders have already been awarded to contractors, and over 50 are “in the pipeline right now,” according to Defense Department Chief Information Officer John Sherman. The figures are up sharply from August, when officials said they were working with more than 13.

“In today’s environment … it is critical more than ever that we provide DOD personnel with secure and resilient software when and where they need it,” Sherman told the House’s Cyber, Information Technology and Innovation panel March 22. Exactly how many orders have been completed thus far was unclear.

The Defense Department in December 2022 tapped Amazon, Google, Microsoft and Oracle to supply digital services for the JWCC, itself the successor to the failed Joint Enterprise Defense Infrastructure venture, or JEDI. The JWCC is valued up to $9 bn over several years. The four companies compete for each order dished out, with each only guaranteed $100,000.

The cloud capability contract is considered the backbone of the Defense Department’s connect-everything-everywhere campaign dubbed Combined Joint All-Domain Command and Control. The CJADC2 concept envisions troops and their databases seamlessly linked across land, air, sea, space and cyber, and spanning unclassified, classified and top secret designations.

“When I testified last year, the department was just beginning the enterprise cloud journey,” Sherman told lawmakers. “I’m happy to report significant and successful progress.”

Cloud is increasingly seen as a means to get the right data to the right people at the right time — a pillar of CJADC2. Sherman last year advised defense agencies, military services and other offices to prioritize JWCC, especially when inking deals involving the nation’s most sensitive information.

The guidance helps streamline cloud contracting and reduces “contract sprawl” across the Defense Department, Sherman said.

His directions for JWCC employment included carve outs for the National Reconnaissance Office, National Geospatial-Intelligence Agency, Defense Intelligence Agency and the National Security Agency. They rely on the intelligence community’s Commercial Cloud Enterprise, or C2E, which was awarded in 2020. It features the same vendors as JWCC, plus IBM. (Source: Defense News)

 

25 Mar 24. MITRE Opens New AI Assurance and Discovery Lab. While artificial intelligence (AI) can transform government operations, decision makers need confidence that AI-enabled systems will operate effectively with acceptable levels of risk before adopting them. MITRE was joined by Sen. Mark Warner, Rep. Donald Beyer, and Rep. Gerry Connolly as it opened its AI Assurance and Discovery Lab today with the mission to discover and mitigate critical risks in AI-enabled systems that need to operate in increasingly complex, uncertain, and high-stakes environments.

“Government use of AI will have consequential impacts on the nation and world, in areas such as efficient transportation, effective healthcare, and strengthened national security,” said Charles Clancy, MITRE senior vice president and chief technology officer. “However, in adopting these systems, we also need to mitigate risks. Providing an independent assessment of the security, safety, and efficacy of AI systems will play a critical role toward helping government and business realize the transformational power of AI in benefits processing, intelligence analysis, autonomous vehicles, and more. This lab will demonstrate a repeatable engineering approach and infrastructure that could serve as a blueprint for a national network of AI assurance facilities.”

MITRE defines AI assurance as a process for discovering, assessing, and managing risk throughout the lifecycle of an AI-enabled system so that it operates effectively to the benefit of its stakeholders and end users. The new AI Assurance and Discovery Lab will evaluate AI-enabled systems intended for use in consequential applications including national security, healthcare, and transportation. Government agencies can also use the lab to inform requirements development for new AI-enabled systems, create and evaluate proposed risk mitigation plans, and develop long-term AI assurance strategies for their organizations.

The lab, which is based at MITRE’s McLean, Virginia headquarters, features configurable space for risk discovery in simulated environments, AI red teaming, large language model evaluation, human-in-the-loop experimentation, and assurance plan development. The lab’s physical space can be tailored and instrumented for specific mission scenarios and workflows.

“For federal agencies and private companies, this new lab delivers an objective, independent analysis to complement and validate their own testing and evaluation of AI-enabled systems, helping establish confidence for end users,” said Cedric Sims, MITRE senior vice president. “Ensuring that AI provides transformational benefits for our government sponsors is a top priority as we solve problems for a safer world.”

MITRE’s team of scientists and engineers includes expertise in computational sciences, linguistics, robotics, human cognitive science, systems neuroscience, and government mission domains. Federal agencies, and soon private companies, can bring AI-enabled systems to the lab to explore potential risks including whether they perform effectively, consistently, and safely in real-world contexts. MITRE will also use the lab to evaluate factors such as whether systems are secure and free from harmful bias, and allow users to control how their information is used.

Members of Virginia’s U.S. Congressional Delegation Join MITRE at AI Lab Opening

“The opening of MITRE’s AI Assurance and Discovery Lab is an exciting development in the most fertile frontier of technological progress—extracting maximum value from AI while mitigating some of its risks,” said Sen. Mark Warner. “We need to have an all-hands-on-deck approach to studying and unleashing the potential of AI, and I look forward to seeing the discoveries and progress the lab will be able to make in this critical field.”

“The emergence and evolution of new technologies like AI have led us to the brink of an exciting future,” said Rep. Gerry Connolly. “As we seek to embrace AI safely and with the proper guardrails in place, ventures like MITRE’s AI Assurance and Discovery Lab will be invaluable to our efforts across government. I am thrilled to be part of this grand opening, and I can’t wait to see what’s in store for the lab and its goal of advancing AI for the public good.”

“As federal agencies leverage the utility of AI to help fulfill their missions, I’m thrilled to see Northern Virginia continue to lead the way on tech innovation,” said Rep. Don Beyer. “The grand opening of MITRE’s AI Assurance and Discovery Lab, which will support the secure implementation of advanced AI systems in federal agencies, is another step forward for our region’s leadership in research and applied sciences.” (Source: BUSINESS WIRE)

 

25 Mar 24. Cohort company SEA awarded £135m maritime countermeasures contract. Cohort, the Independent Technology Group announces that its subsidiary Systems Engineering and Assessment Ltd (SEA) has been awarded a £135m contract by the UK Ministry of Defence (MOD) to provide a Trainable Decoy Launcher to improve Royal Navy surface ships’ defensive capabilities.

SEA’s Ancilia system, a highly modular and flexible maritime countermeasures solution, has been selected by the MOD to provide Electronic Warfare Countermeasures Increment 1a (EWCM 1a) to the Royal Navy. Ancilia delivers effective and rapid protection against modern anti-ship threats such as ballistic missiles as well as other sophisticated systems and tactics. It will be installed across a range of the Royal Navy’s surface ships. Its design builds on SEA’s deep knowledge of existing systems in service with the Royal Navy. Built on technology developed collaboratively by Cohort subsidiaries SEA and Chess Dynamics, the Ancilia system offers a world-leading solution to a growing threat using the best available engineering solution from within the UK supply chain.

The Ancilia technology is a step-change from traditional fixed solutions, as its trainable nature removes the need to manoeuvre the vessel to counter incoming threats. Its relatively small size and weight enables rapid installation on a wide range of maritime platforms, and its capability to configure the firing of multiple decoy types in varying positions provides the Royal Navy with a truly flexible countermeasures solution.

Andy Thomis, Cohort Chief Executive said of the win: “We are delighted that Cohort’s Ancilia system has been selected to provide this vitally important capability. It represents a strong vote of confidence in our operating businesses SEA and Chess, and in the Group as a whole. The conflict in Ukraine, and investment by some countries in advanced missile technology, has underlined the importance of defence against sophisticated anti-ship threats. Ancilia has generated considerable interest from overseas customers, and this contract award will boost its visibility still further. We estimate that our addressable market for systems of this kind in the coming years is at least £250m. The win will sustain employment for 150 professional and skilled staff in North Devon, and further success in export markets will generate new employment opportunities and economic benefits in the region and in the UK more widely.”

Richard Flitton, SEA Managing Director said:  “The knowledge and maritime domain expertise within our UK-based team has enabled us to build a true and long-standing partnership with the Royal Navy. We’re delighted that this win will allow us to support the UK’s defensive capabilities against modern and complex naval threats, while bringing employment and economic benefits to North Devon.”

This is comfortably Cohort’s largest single order ever and will take its orderbook to over £500m.

 

26 Mar 24. Kromek receives $2.1m security screening order. Kromek Group plc (AIM: KMK), a leading developer of radiation and bio-detection technology solutions for the advanced imaging and CBRN detection segments, is pleased to announce that it has received a $2.1m order from an existing US-based OEM customer that is an emerging leader and global company in the homeland security marketplace.

The order is for the supply of key detector components for incorporation into the customers’ advanced security screening system for the detection of explosives. Delivery will commence in the current year and complete in the first half of FY 2025. The Group has been supplying this customer since 2017 when it was awarded a five-year delivery contract, following the completion of an R&D phase to design components to meet the customer’s requirements, and it expects to enter another long-term delivery contract.

Arnab Basu, CEO of Kromek, said: “We are pleased to have received this latest order from a long-standing customer in the security screening market. It demonstrates the strength of our advanced imaging business where, after an initial design phase, we continue to receive orders for years to come. It also adds to the growing pipeline for FY 2025, which we expect to be a year of further growth. In addition, with the global aviation market now recovering, we expect another long-term delivery contract in due course, which will provide enhanced visibility into 2025 and beyond. We look forward to updating the market on our progress.”

 

22 Mar 24. USAF to add 5 new Compass Call electronic-attack planes in 2025. The Air Force plans to add five EA-37B Compass Call electronic-attack aircraft to its arsenal in the coming fiscal year, as it swaps out the aging EC-130H fleet for a smaller, modern set of airborne jammers.

The service noted their arrival in budget documents released March 11. The first of 10 EA-37Bs was delivered to the Air Force last year for testing — two years later than anticipated — before heading to its eventual home at Davis-Monthan Air Force Base, Arizona. Delivery of the first mission-ready jet is expected sometime in 2024.

It’s unclear to what extent the first five aircraft will be used in testing or if they will enter regular operations as they come online. Air Combat Command, which manages the fleet, declined to provide more details about the jets.

Compass Call is designed to jam enemy signals, including communications, radar and navigations systems, and can suppress enemy air defenses by blocking the connection between weapons systems and command-and-control networks. The aircraft also carries hardware and software that give airmen the ability to hack into wireless devices, defuse roadside bombs and more.

Its new airframe — a Gulfstream G550 business jet outfitted with advanced electronic attack equipment by an L3Harris-BAE Systems team — will also be able to soar higher than 40,000 feet and fly at nearly 600 mph, nearly twice as high and as fast as the legacy EC-130H.

The 43rd Electronic Combat Squadron at Davis-Monthan will be the first to transition to the new Compass Call, which began flying in the 1980s. As it prepares to replace old with new, the squadron logged its final flight in an EC-130H on Feb. 15.

“Throughout its storied existence, the squadron’s adaptability and commitment to evolving military technologies shine through, having operated 11 different aircraft types across six continents,” 43rd ECS Commander Lt. Col. Tray Wood said in a statement. “The final EC-130H flight marks the end of an era and signals the beginning of a new chapter with the forthcoming EA-37B transition.”

The 41st and 42nd Electronic Combat Squadrons, also based at Davis-Monthan, are still flying the legacy platform. The 41st is the only remaining operational squadron flying the EC-130H; the 42nd is a training squadron.

The new EA-37B, which was redesignated from EC-37B late last year, comes as the Air Force looks to replace many of its decades-old aircraft with more-capable versions that may have a better shot at surviving in future conflicts against advanced adversaries like China.

The service said in November it had retired nine of its 14 old Compass Calls so far. Air Force budget documents show that the service plans to send one more EC-130H to its aircraft “Boneyard” this year. The budget also includes an additional $15 m for operating and maintaining the Compass Call program, driven by fielding the new aircraft and storing the retiring planes.

A mainstay in U.S. Central Command during the war on terror, the EC-130H carries a 13-person crew, including two pilots, a navigator, a flight engineer, a mission crew commander and supervisor, a signals analyst and multiple cryptologic language analysts. The Air Force contends that though its new Compass Call airframe is smaller, advances in equipment will allow it to consolidate jobs onboard and cut the crew to nine members.

The 41st Electronic Combat Squadron spent 20 years overseas with the Compass Call, becoming the longest continuously deployed Air Force unit in Afghanistan at nearly 14,800 sorties over 90,000 flying hours before returning home in 2021. (Source: Defense News Early Bird/Army Times)

 

22 Mar 24. Cyber Update Key points.

  • A new Python tool vulnerability allows threat actors to bypass data protection, highlighting the financial and security risks stemming from outdated software.
  • A new Chinese-affiliated campaign points to sustained espionage risks facing Western government and technology (See Sibylline Cyber Daily Technical analysis below).
  • The recent rise in cyber attacks targeting operational technology (OT), primarily US water and wastewater facilities, points to elevated operational threats posed by state-sponsored actors
  • A new North Korea state-sponsored campaign signals the heightened espionage risks facing public and private organisations see Technical analysis below).
  • A new strain of wiper malware possibly disrupted Ukrainian telecommunication networks, pointing to the elevated destruction and disruption threats posed by Russian threat actors (see Sibylline Cyber Daily Analytical Update – 22 March 2024).

Technical analysis of weekly stories

The Chinese state-sponsored group ‘Earth Krahang’ has targeted multiple government organisations in a cyber espionage campaign since early 2022. The campaign starts with the exploitation of vulnerabilities or spear phishing emails to gain initial access to a targeted system. Subsequently, two backdoors, ‘RESHELL’ and ‘XDealer’, are downloaded onto the victim’s system to collect strategic information by capturing screenshots, logging keystrokes and intercepting data. Additionally, the group uses Python scripts and other brute force techniques to hijack corporate Outlook accounts. It then uses these legitimate accounts to infiltrate secondary organisations via phishing emails, highlighting the stealthy and multipronged nature of the campaign. The threat actors can also achieve persistence and facilitate lateral movement by building virtual private network (VPN) software on compromised servers. This further points to the growing sophistication of state-sponsored actors’ tactics, techniques and procedures (TTPs).

The North Korean state-sponsored threat group ‘Kimsuky’ is leveraging legitimate Windows files to deploy information-stealing malware in a new campaign. The campaign primarily targets government organisations and think tanks based in the Asia-Pacific region and Europe to collect strategic information. Although the initial attack vectors are unknown, the group typically uses phishing and social engineering to gain access to its victims’ systems. The threat actors trick victims into downloading a malicious Compiled HTML Help (CHM) file. CHM files are frequently found on Windows systems in the form of legitimate help files; as such they enable threat actors to bypass defence systems and to prolong detection evasion. The threat actors then establish a command-and-control (C2) mechanism and harvest additional information on a victim’s system to maintain persistence. Stolen data is then forwarded to the actor-controlled infrastructure, subsequently deleting any trace from the victim’s machine (so as to remain undetected). This campaign highlights threat actors’ knowledge of modern security mechanisms, and displays their innovation in exploiting legitimate tools to evade detection and achieve persistence on a compromised system.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Enforce strict security policies including regular software and password updates, as well as adequate network segmentation to prevent lateral movement following an infection
  • Monitor devices and networks for suspicious activity
  • Conduct cyber hygiene awareness courses for users to enable them to recognise and report phishing and other types of social engineering attempts
  • Add available Indicators-of-Compromise (IoCs) to the organisation’s security detection systems to detect potentially malicious samples on the network
  • Ensure adequate security detection measures are in place, particularly behaviour-based end-point detection and response (EDR) solutions

Our cyber word(s) of the week: Wiper (Malware) (Source: Sibylline)

————————————————————————-

Spectra Group (UK) Ltd

 

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

 

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

March 22, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

————————————————————————

21 Mar 24. Ultra Intelligence & Communications celebrates opening of its new Cyber Centre of Excellence in Maidenhead, U.K. Ultra Intelligence & Communications, also known as Ultra I&C, celebrated the official opening of its flagship facility in Maidenhead, U.K., marking a major milestone in the company’s ongoing expansion and development.  Ultra I&C’s Cyber Centre of Excellence represents a significant achievement in advancing expertise in cybersecurity and manufacturing, providing the company and its customers a new base for 250 engineers, made possible by a £30M investment in the new facility. The 56,000 square foot engineering, integration and testing facility will serve as a hub for cyber technology development and the company’s U.K. STEM program, supporting local schools and placements from the CyberFirst program, aimed at identifying and nurturing a diverse group of talented individuals interested in pursuing a career in cybersecurity.

“Ultra I&C’s Maidenhead Cyber Centre of Excellence will support job growth in the engineering sector, which is critically needed to protect our national security,” said Richard Dingley, president of Ultra I&C’s cyber business. “Opening this location solidifies our long-term commitment to developing the skills and capabilities required to ensure the U.K. and our partners are protected and prosperous in the future.”

The opening ceremony brought together industry, local and national government and key clients such as the U.K. MOD, to mark the growth and expansion of the company in the U.K. Former U.K. Prime Minister, Rt Hon. Theresa May MP spoke at the opening ceremony, noting: “Ultra I&C’s Maidenhead facility represents a significant investment in the community to build skills, develop more careers in STEM and support the U.K.’s ability to respond to, and combat, the threats of the future.”

Ultra I&C leaders demonstrated their solutions to support the secure communications on the likes of the Typhoon aircraft, post-quantum security capabilities and satellite communications.

 

22 Mar 24. Silvus Technologies eyes on-the-move capability for StreamCaster radio. California-based mobile networking company Silvus Technologies is working with US Army officials to provide mobile ad hoc network (MANET) radio capability to ground units on the move, a critical requirement to the service’s evolving command post architecture under the Integrated Tactical Network (ITN). The on-the-move (OTM) capability being developed by the company’s StreamCaster MANET radio got a fiscal shot in the arm from the army in January, when service leaders inked a USD3.5m deal with Silvus to expedite “expanded deployment” of the radio to support service units employing the ITN. Specifically, the MANET radios procured by the army’s Program Executive Office Command, Control, and Communications-Tactical (PEO C3T) under the January contract will be used for operational testing and validation scheduled for fiscal year (FY) 2025, according to a company statement. StreamCaster MANET radios have already been deployed to infantry brigade combat teams (IBCTs) as part of the Capability Set 21 (CS21) iteration of the ITN, and then out to Stryker BCTs as part of Capability Set 23 (CS23). (Source: Janes)

 

21 Mar 24. Global: New campaign signals heightened cyber espionage risks facing public, private organisations. On 20 March, the cyber security firm Rapid7 identified a new campaign by the North Korea-affiliated threat group ‘Kimsuky’. The campaign primarily targets government agencies and think tanks based in the Asia-Pacific region and Europe. While the initial attack vectors used in the latest campaign are unknown, the group typically uses phishing and social engineering. Following initial access, a compiled HTML help (CHM) file containing malicious code is downloaded onto the victim’s system; the file then installs an infostealer to gather strategic information. CHM files are known for being difficult to identify as they are often used as legitimate files on Windows systems, underscoring the threat group’s sophistication and understanding of modern security tools. Like other non-Western countries, North Korea has ramped up its cyber espionage operations to improve its security and economic posture. Consequently, the latest activity points to the heightened cyber espionage risks facing public and private organisations in the short-to-medium term. (Source: Sibylline)

 

20 Mar 24. MOD admits it has too many secret cloud capabilities and is seeking commercial help. The MOD wants to find a single commercial cloud provider to help users securely access classified data (Picture: MOD)

The MOD is looking for a commercial company to provide a single “secret cloud” to deal with accessing classified data, admitting it has too many secret cloud capabilities.

Defence Procurement Minister James Cartlidge said the MOD was “ramping up” its engagement with industry at a secret level, working together to develop artificial intelligence (AI) capabilities.

The comments were made when MPs on the Defence Select Committee questioned MOD officials on the use of AI and discussed the sharing of secret-level data with companies providing or developing projects using the technology.

Mr Cartlidge told the committee: “We are ramping up engagement at ‘secret’ with industry.

“So we recently held a general industry day, this is for the defence sector. We’ve had some more specific ones. Yesterday Strategic Command held one with companies who are involved in electronic warfare.”

Committee member John Speller pressed officials on data-sharing with industry and said: “A lot of the companies have told us that secure cloud computing is needed to enable AI to be able to deal with classified data.

“When will they have access to this and is there possibly scope for government to have an overall umbrella contract into which they could have access in order to undertake that work.”

Paul Lincoln, the second permanent secretary at the MOD, responded: “We set out in the AI strategy that we would have secret cloud within defence, we have had secret on premises on cloud since early 2023 installed and operational.

“We are moving now to a convergence.

“The minister said we have got too many secret cloud capabilities to a single convergence at the moment, and we are looking for a commercial cloud provider to bring on board for that.”

Officials told the committee they recognised the importance of working with industry to develop future AI capabilities. (Source: forces.net)

 

19 Mar 24. Global: New campaign signals sustained espionage risks for Western government, technology firms. On 18 March, the cyber security company Trend Micro unveiled the discovery of a new cyber espionage campaign targeting government organisations. The China-affiliated group, ‘Earth Krahang’, has successfully breached 70 organisations since early 2022. The campaign uses spear phishing techniques and software vulnerabilities as initial access vectors. The group then executes backdoors to gather information from compromised systems. Additionally, the campaign uses brute force techniques to compromise Outlook accounts and collect additional targets’ email addresses to infiltrate secondary organisations. The threat group also builds custom virtual private network (VPN) software on infected systems to facilitate lateral movement, further underscoring the sophistication of its tactics, techniques and procedures (TTPs). China-affiliated threat groups routinely conduct cyber espionage campaigns to further Beijing’s strategic and political ambitions; they primarily target government and technology organisations in the West. As such, we assess that future such campaigns are highly likely as China seeks to strengthen its economic and security posture. (Source: Sibylline)

 

18 Mar 24. DoD Revises Eligibility Criteria for Its Voluntary Defense Industrial Base Cybersecurity Program – (89 Fed. Reg. 17741) – The U.S. Department of Defense’s Office of the DoD Chief Information Officer has published revisions to the eligibility criteria for the voluntary Defense Industrial Base (DIB) Cybersecurity (CS) Program. These revisions will allow all defense contractors who own or operate an unclassified information system that processes, stores, or transmits covered defense information to benefit from bilateral information sharing. DoD is also finalizing changes to definitions and some technical corrections for readability. The proposed rule was published at 88 Fed. Reg. 27832-27839 (May 3, 2023). In May 2012, DoD published an interim final rule establishing the voluntary DIB CS Program and the bilateral information-sharing model still used today. The 2012 rule established a voluntary cyber threat information sharing program for cleared defense contractors (CDC) with the ability to safeguard classified information, estimated at 2,650 in 2012. Under the rule, CDC is defined as a private entity granted clearance by DoD to access, receive, or store classified information for the purpose of bidding for a contract or conducting activities in support of any program of DoD. With this rule, the Department is expanding eligibility requirements to allow greater program participation and increase the benefits of bilateral information sharing, which helps protect DoD-controlled unclassified information from cyberattack, as well as to better align the voluntary DIB CS Program with DoD’s mandatory cyber incident reporting requirements. This rule is effective on April 11, 2024. (Source: glstrade.com)

 

18 Mar 24. Global: New vulnerability highlights financial, security risks stemming from outdated software. On 15 March, the cyber security company Cyble reported that the ransomware group ‘ShadowSyndicate’ attempted to exploit a newly identified Python vulnerability (CVE-2024-23334). The affected Python tool (AIOHTTP, version 3.9.1) is widely used by IT teams to build sophisticated web applications. This vulnerability enables unauthenticated threat actors to bypass data protection, granting them access to sensitive files that should not be accessible via the internet. Financially motivated threat groups are subsequently able to steal credentials and to execute malicious files on infected systems to garner illicit profit. Although ShadowSyndicate uses scanning tools to identify vulnerable servers, there is a realistic possibility that this vulnerability can be exploited by other actors. Outdated software often presents an effective attack vector for threat actors seeking to compromise a network, underscoring the financial and security risks posed by legacy software. Python has since released a fix to address the vulnerability. (Source: Sibylline)

 

18 Mar 24. ASD-Microsoft initiative bolsters Australia’s cyber defence.

The Australian Signals Directorate (ASD) and Microsoft will strengthen Australia’s cyber defences by connecting ASD’s Cyber Threat Intelligence Sharing (CTIS) platform with Microsoft’s Sentinel platform, creating a global cyber threat intelligence system.

This connection allows Microsoft’s Australian customers who also partner in ASD’s CTIS platform to share cyber threat information at the speed and scale required to mitigate against growing threats in cyberspace.

“This initiative is a significant step forward in bolstering our cyber defences,” said Deputy Prime Minister and Minister for Defence Richard Marles. “The best cyber defences are founded on genuine partnerships between and across the public and private sectors. It is collaborative partnerships like these that foster innovation and deliver practical outcomes for Australia’s cyber resilience.”

The integration of these platforms will enable deeper collaboration between ASD’s CTIS program and Microsoft Sentinel customers in Australia, who benefit from Microsoft’s analysis of 65 trillion signals of global threat intelligence every day.

“This initiative builds on our recently announced investment into improving our nation’s cyber defences, under the Microsoft-Australian Signals Directorate’s Cyber Shield (MACS),” according to Steven Worrall, managing director of Microsoft Australia and New Zealand.

This outcome is a key element of the Microsoft-ASD Cyber Shield initiative as part of Microsoft’s $5 bn investment in Australia announced by the Albanese Government in October 2023.

This initiative is another example of the importance of the partnership between the public and private sectors in countering collective cyber threats. It also continues to deliver on the Government’s commitment to enhance cyber threat visibility and harden the nation’s cyber defences. (Source: https://www.ex2.com.au/news/)

 

15 Mar 24. The financially motivated threat group ‘Magnet Goblin’ exploited known Ivanti software vulnerabilities (CVE-2023-46805 and CVE-2023-21887) to compromise Linux systems with a new version of the ‘NerbianRAT’ malware. The first vulnerability (CVE-2023-46805) enables threat actors to bypass authentication processes on a compromised system. The second vulnerability (CVE-2023-21887) can be exploited to execute malicious code remotely. The malware first collects information on the compromised system to establish command-and-control (C2) mechanisms and ensure communication with actor-controlled infrastructure. Subsequently, threat actors are able to execute code remotely on the infected machine to garner illicit profit. The actors used a credential stealer and tunnelling tools during their attacks, further demonstrating the sophistication of their tactics, techniques and procedures (TTPs). Unlike its Windows counterpart, the NerbianRAT Linux version lacks defence evasion mechanisms. However, its level of complexity and other capabilities ensure prolonged persistence in a compromised network. A new campaign exploited a patched vulnerability (CVE-2024-21412) in the Microsoft Defender antivirus software to infect systems with the ‘DarkGate’ malware. The campaign starts with a phishing email containing a PDF file with malicious links. These links leverage a legitimate Google advert platform to exploit the vulnerability, redirecting users to download a malicious file (disguised as a legitimate software installer) from an actor-controlled server. Following its installation, the malware can deploy additional malicious files, facilitate remote access and perform keylogging. The vulnerability was actively exploited by unknown threat groups prior to a patch being released. This campaign highlights organisations’ susceptibility to supply chain attacks as threat actors increasingly leverage vulnerabilities in trusted third-party applications. In particular, threat actors demonstrated that they can incorporate the use of multiple legitimate tools in one campaign to bolster success rates.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Apply patches to software vulnerabilities as soon as they are released to prevent exploitation
  • Monitor devices and networks for suspicious activity
  • Conduct cyber hygiene awareness courses for users to enable them to recognise and report phishing and other types of social engineering attempts
  • Create network segmentation to limit potential damage from infections
  • Add available Indicators-of-Compromise (IoCs) to the organisation’s security detection systems to detect potentially malicious samples on the network
  • Ensure adequate security detection measures are in place, particularly behaviour-based end-point detection and response (EDR) solutions

Our cyber word(s) of the week: Structured Query Language (SQL) Injection (Source: Sibylline)

 

15 Mar 24. Global: New software vulnerability points to espionage, information-theft risks via supply chain. On 13 March, the cyber security company Fortinet disclosed a new vulnerability (CVE-2023-48788) in its Enterprise Management Server (EMS) software (versions 7.0 to 7.2). There is currently no indication that the vulnerability was actively exploited prior to the release of its fixed version. The vulnerability can be leveraged via a structured query language (SQL) injection to manipulate the application’s backend, enabling threat actors to access sensitive information and escalate their privileges within the infected system. Previously, a suspected Chinese state-sponsored group exploited a vulnerability in Fortinet’s VPN software to deploy the ‘COATHANGER’ remote access trojan (RAT), with which it infiltrated the Dutch Ministry of Defence (MoD) in February. State-sponsored threat groups are increasingly exploiting vulnerabilities in the software supply chain for cyber espionage campaigns, accentuating the growing espionage and information-theft risks facing organisations. Consequently, we assess that the future exploitation of this vulnerability is possible amid current political tensions, further emphasising the need for strict patch management policies.  (Source: Sibylline)

————————————————————————-

 

Spectra Group (UK) Ltd

 

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

 

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

March 15, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

————————————————————————

14 Mar 24. Thales eyes UK Personal Role Radio replacement programme. Thales is planning to pitch its SquadNet radio for the UK armed forces’ next-generation Personal Role Radio (PRR) replacement programme due to be announced in 2025, Janes learnt at SAE Group’s Future Soldier Technology conference held from 11 to 13 March. According to John Dix, Thales UK sales manager for land communications, SquadNet is a suitable replacement to PRR because of its small form factor, making it a cost-effective solution tailored for dismounted soldiers. The system being replaced is the Leonardo H4855 PRR, which has been in service with the army for more than 20 years. The PRR is a small, lightweight system designed for short-range communications suitable up to platoon level. The system has a 500 m operating range, weighs 1.5 kg, offers a 20 hour battery life, and has a 38.4 Kbps data rate. (Source: Janes)

 

14 Mar 24. ELT Group and the Qatar Armed Forces signed a Letter of Intention (LOI) to cooperate on strategic projects in the field of EMSO. During the last Doha International Maritime Defence Exhibition and Conference (DIMDEX 2024), ELT Group and the Qatar Armed Forces have signed a LOI stating their common will to cooperate on strategic projects in the field of Electromagnetic Spectrum Operations and in particular on the development of an EW and Intelligence Centre. The LOI was signed in the presence of the Commander of the Qatar Emiri Air Force, Major General Jassim Al-Mannai and the CEO and COO of ELT Group, Domitilla Benigni.  This is a confirmation of a solid friendship and long term cooperation between the Group and the Qatar Air Force. ELT Group has been present in Qatar since 2017 with the opening of its commercial office, providing support within many national programs thanks to its portfolio of capabilities in the EMSO domain.

 

11 Mar 24. Bowman’s life to be extended … again!

The UK’s Bowman tactical communications and command and control system is to be upgraded once more because of the collapse of the EVO project. This latest initiative could extend the life of the Bowman architecture to at least 2031 and possibly to 2035.

The UK MOD’s long-running saga to replace the communications element of the Bowman tactical radio and C2 system used by British land forces enters a new chapter.

In February, Armada reported the cancellation of a major component of the United Kingdom’s Project Morpheus military communications system. Specifically, the Evolve to Open (EVO) stage of the programme was axed. EVO used the latest version of the Bowman tactical radio and Command and Control (C2) system as its baseline, known as Bowman Combat Infrastructure-5.6 (BCIP-5.6). The EVO initiative was being led by General Dynamics’ UK subsidiary. At the heart of EVO was a plan to evolve BCIP-5.6 into an open, modular design. The rationale was to ensure the Bowman radio infrastructure could easily and safely accept new hardware, software and capabilities as and when they become available. The MOD said this approach would “enable (it) to integrate and deploy new capabilities selected from across (i)ndustry in a faster and more cost-effective manner.”

Question time

On 14th December James Cartlidge, the UK’s minister for defence procurement, conceded the long-running problems the EVO project has suffered and that Armada reported on in the past. “We have been open that progress on the Morpheus project has fallen short of what was expected,” Mr. Cartlidge told the British parliament. Sources close to the programme told Armada that the MOD and General Dynamics were at an impasse over EVO’s expectations and deliverables. Although EVO is dead, General Dynamics will sustain Bowman to ensure it continues to support UK military commitments.

In early February, the Financial Times reported that Bowman’s life will now be extended to 2035 at the latest. The news was divulged in a response from Mr. Cartlidge to a written parliamentary question tabled by the opposition shadow secretary of state for defence. Mr. Cartlidge revealed that Bowman will be upgraded once more via an initiative called BCIP-5.7 which was originally commissioned in 2023. In another response to Mr. Healey, Mr. Cartlidge said that BCIP-5.7 is “still in development and subject to approvals.” The precise scope of BCIP-5.7 is unclear. That said, it appears that this might be a relatively straightforward extension of the Bowan radio infrastructure as opposed to the more ambitious EVO initiative.

Bye bye GD?

One thing that does seem certain is that General Dynamics’ role is likely to be confined solely to sustaining Bowman. An MOD source close to Morpheus told Armada that the company is unlikely to be allowed to bid for any future work involving Bowman. Nonetheless, they could be involved as a subcontractor to whichever company is selected for BCIP-5.7.

Despite the EVO setback and the need for BCIP-5.7 the Ministry of Defence’s wider Project Morpheus overhaul of UK land forces communications continues: “Bowman (provides) secure communications on the battlefield,” an MOD spokesperson told Armada. “Having received several upgrades, Bowman will be updated again, ensuring the army continues to operate a secure and capable communications system until Morpheus delivers.”

All eyes are now on whether and when BCIP-5.7 can be delivered and the likely effect of both this, and the EVO cancellation, on Morpheus as a whole. The pressure is on following another cliffhanger in the UK’s long-running tactical communications soap opera. (Source: Armada)

 

11 Mar 24. Clear Channels. Lt. Gen. Sir Jim Hockehull gave RUSI’s inaugural Profession of Arms Series lecture on 15th February where he cited loss rates for Ukrainian UAVs of around 10,000 per month.

An innovative approach to radio communications promises to enhance the survivability of Ukrainian uninhabited aircraft in a conflict increasingly characterised by the widespread use of UAVs.

Lieutenant General Sir Jim Hockenhull, commander of the UK’s Strategic Command, gave a speech at the inaugural Royal United Service’s Institute’s (RUSI) Profession of Arms Series lecture on 15th February. Gen. Hockenhull discussed threats, challenges and opportunities in the cyber and electromagnetic domains. A full transcript of his speech can be found here.

Gen Hockenhull highlighted research performed by RUSI in mid-2023 which noted that Ukraine was losing around 10,000 Uninhabited Aerial Vehicles (UAV) per month in its ongoing war with Russia. The US involvement in the Vietnam War was associated with development of the helicopter as a military platform. The Ukraine War is increasingly associated with the UAV’s coming of age as a tactical capability.

These uninhabited aircraft are proving their worth for both sides as valuable Intelligence, Surveillance and Reconnaissance (ISR) platforms. UAVs deliver ordnance against hostile assets like troops, weapons, vehicles, sensors and bases. Explosive-laden kamikaze UAVs crash themselves into targets.

RF Reliance

Such is the UAV threat in Ukraine that both sides have worked hard to develop and deploy Counter Uninhabited Aerial Vehicle (CUAV) capabilities focused on kinetic and electronic attack. The latter directs jamming against the Radio Frequency (RF) links these aircraft depend on. UAVs use radio links to connect the aircraft to its pilot, and to share ISR data and information on the aircraft’s health. Global Navigation Satellite System (GNSS) receivers aid navigation with satellite-transmitted PNT (Position, Navigation and Timing) signals.

Jamming works to disrupt these RF links. Civilian-standard UAVs typically, but not exclusively, use frequencies of 2.4 gigahertz/GHz and 5.8GHz to connect the aircraft to its pilot. Frequencies of 1.1GHz to 1.6GHz are used for GNSS PNT signals. Russian land forces have deployed scores of Electronic Warfare (EW) systems at the tactical and operational level to attack and jam frequencies used by UAVs. Details of these systems can be found here. If a UAV loses its RF links it may either automatically return to its point-of-origin, or land in situ.

Given the jamming threat, it is little surprise that Ukraine is taking strenuous efforts to avoid the threat posed by Russian EW systems. Armada has learned that around 90 percent of all tactical Electronic Warfare (EW) in the Ukrainian theatre is targeting UAVs. Encrypting UAV RF links can help as the aircraft will ignore all signals not matching the encryption keys. Using inertial navigation systems, which do not need RF, are another option. Sometimes, Ukrainian troops will deliberately fly their UAVs using the same frequencies as those used by Russian uninhabited aircraft. This means that the Russians will jam their own UAVs if they try to electronically attack the Ukrainian aircraft. Another tactic is to launch around 20 UAVs, all of which are using different frequencies. This forces the Russians to divide their EW force to detect and target each frequency in the hope that insufficient electronic warfare assets exist in the UAVs locale. The logic is that at least one or two of the aircraft will complete their mission.

Local Innovation

Innovation is moving at breakneck speed in Ukraine, accelerated by the necessities of war, and ultimately the country’s survival. Colibri Defence Dynamics shared with Armada that it has developed an innovative radio system that could help Ukrainian UAVs outflank Russian jamming. While radio frequency hopping offers some resilience it is limited says Jack De Santis, the company’s founder. The problem with frequency hopping is that it usually occurs across a relatively narrow band: “The Russians simply jam the entire band.” Anecdotal evidence from Ukraine recently shared with your correspondent said that any RF system transmitting 500 hops-per-second is easily jammed by Russian EW cadres.

Mr. De Santis and his innovators have taken a different approach developing an RF system which can equip a UAV, but which provides several communications channels across a very wide bandwidth. Understandably, Mr. De Santis declines to share the bandwidth this system works across. He did mention that all the RF processing is enclosed in a single printed circuit board which can easily outfit a UAV. Each UAV thus equipped will have scores of channels it can use simultaneously for its RF links. “The Russians cannot jam all these links at the same time,” he argues.

The wider the jamming bandwidth an EW system must attack, the less power it can direct against each frequency and the shorter the range this jamming becomes, progressively reducing its effectiveness. An alternative is to try to deploy yet more tactical CUAV systems but this is easier said than done: “The more EW systems the Russians deploy at the front the easier it is for the Ukrainians to find them.” Moreover, these systems are expensive, complex to produce, require trained personnel and are lucrative targets. All factors restricting how many CUAV systems Russian land forces can deploy at any one time. “The Russians, or any other EW force for that matter, are unable to jam every frequency known to humankind at once, no matter how much they spread their power.”

Russian CUAV systems at the front may be able to jam or spoof some of a UAV’s links but not all of them. Let us suppose that the RF channel one of the UAVs is using to share ISR data is suddenly jammed. Software immediately moves the ISR feed to an unjammed channel. Suppose false PNT information is received on another channel. The software discards this information as it does not match the PNT data received on the GNSS link. Mr. De Santis and his team call their approach channel parallelisation.

Ukraine is moving innovation forward in the electromagnetic sector at breakneck speed as the conflict’s UAV dimension illustrates. This is helped in no small measure by an efficient ‘lessons learned’ approach. Mr. De Santis and other innovators can quickly understand what is happening in the spectrum and react accordingly. (Source: Armada)

 

11 Mar 24. Check the Manual. Russian land forces are highly reliant on so-called FPV UAVs to gather ISR data, deliver weapons and perform kamikaze attacks. A recent Russian Army manual gives important clues as to how these aircraft are deployed on the battlefield.

Armada has obtained a Russian language military manual providing guidance on tactical first person view uninhabited aerial vehicle employment by Russia’s land forces.

The manual provides a treasure trove of details regarding the electromagnetic aspects of Russian tactical First Person View Uninhabited Aerial Vehicle (FPV UAV) use in the ongoing war in Ukraine. Mass UAV usage at the tactical edge is becoming a hallmark of the ongoing war in Ukraine.

The manual is a very recent publication having been drafted and published by the General Staff of the Armed Forces of the Russian Federation this year. The introduction makes clear that the manual provides guidelines for tactical commanders and FPV UAV operators. The manual stresses that its provisions “should be applied creatively, in accordance with the conditions of the situation.”

Aircraft Types

Russian land forces FPV UAVs are to be deployed to target enemy personnel, unprotected, lightly armoured and fully armoured vehicles. The aircraft provide intelligence, surveillance and reconnaissance support, and assist tactical command and control. Standard FPV UAVs deployed by Russian forces include Boomerang, Starling, XL-10, Kofer, Piranha-7, Lirian, IBX-10, Limba-7, TVH-1, IBX-2 and NBX-3. The latter aircraft, the manual notes, uses artificial intelligence in its software.

The manual recommends that a thorough analysis of the “radio-electronic situation is carried out by spectrum analysers” to determine whether enemy forces are already performing electronic attack prior to a sortie. The survey will help UAV operators decide the frequencies they will use to connect to and from the aircraft.  To improve the survivability of the unit launching the drone, the manual recommends using decoy antennas. High points, tall buildings, telegraph poles and elevated objects should be employed to site actual, and decoy, antennas. These antennas can be dotted around the location of the UAV’s operator to transmit fake radio signals. The hope is that enemy communications intelligence cadres are frustrated in trying to find the actual antenna hosting the Radio Frequency (RF) link between the pilot and the aircraft.

Frequencies

Prior to the sortie UAV pilots are to notify local Russian EW units of their intention to fly, and the frequencies they wish to use, to avoid the latter inadvertently jamming the UAV’s RF links. This seems to imply that FPV UAVs Russian land forces are using cannot operate independently of Russian jamming in their locale. The manual continues that land forces typically use frequencies of 390 megahertz/MHz to 490MHz, 850MHz to 960MHz, and 1.2 gigahertz/GHz and 2.4GHz for aircraft control. Frequencies of 2.4GHz and 5.8GHz are employed for downloading video

The manual recommends that troops continue to share their experiences of using FPV UAVs with the armed forces so that these can be folded into future editions of the manuals. It even lists two email addresses for the Department for Summarising Combat Experience;  and .

The Russian and Ukrainian armies are reliant on FPV UAVs at the tactical level. The manual provides insights into how these aircraft are deployed and their electromagnetic characteristics. Understanding such information will help those devising countermeasures, electronic or otherwise, against Russian uninhabited aerial vehicles. (Source: Armada)

 

11 Mar 24. March Radio Roundup. L3Harris performed tests of its DPAAS phased array satellite communications system in Alaska in October 2023. The company told Armada DPAAS is currently at Technology Readiness Level-7 denoting that a prototype has been demonstrated in an operational environment.

Armada’s monthly roundup of all the latest news in the military communications product, programme and operational domains.

DPAAS Evolves

L3Harris announced in early February that it had demonstrated a digital phased array antenna system for satellite communications. The demonstration took place in Fairbanks, Alaska in October 2023 and involved the company’s Digital Beamforming Phased-Array Antenna System (DPAAS). During the three-month long initiative, DPAAS handled circa 300 satellite contacts daily, including eight simultaneous contacts. The company told Armada, via a written statement, that DPAAS established contacts with over 90 satellites. These included international meteorology satellites and US spacecraft. Defence applications for DPAAS “may include any mission requiring satellite command and control and/or downlink telemetry and mission data reception from many simultaneous satellites,” the statement said. Work continues to reduce the overall size, weight, power and cost of DPAAS. These objectives should be met by the end of this year. Production and delivery schedules are then “dependent on customer budgets and mission schedules.”

New Radios Support ACE Concept

The United States Air Force’s (USAF) Air Mobility Command (AMC) is receiving Persistent Systems’ MPU5 tactical radios, the company announced in late January. Under the terms of the $5.1 m contract Persistent Systems will supply over 280 MPU5s, along with ten Integrated Sector Antennas. The latter allows MPU5 coverage to be extended over a large area. These systems will be deployed by the AMC’s 621st and 821st Contingency Response Groups (CRGs) to support the USAF’s Agile Combat Employment (ACE) initiative. The ACE concept focuses on the air force rapidly deploying and securing foreign airstrips in host countries. The Persistent Systems press release disclosed that the USAF currently uses legacy handheld radios which cannot share video or imagery in a similar fashion to the MPU5. The Integrated Sector Antenna is typically “pole- or tower-mounted,” the company told Armada in a written statement: “It utilises various antenna polarities to maximise throughput to the MPU5s within its coverage range.” Meanwhile, “the high-bandwidth, easy-to-use, ad hoc nature of the MPU5s and Integrated Sector Antennas allow the CRGs to command and control US Air Force operations in austere and remote locations, as well as with partner nation forces.”

New Terminals

The US Department of Defence has emerged as the first customer for Ovzon’s new T7 Satellite Communications (SATCOM) terminal. According to the company’s official literature, the terminal transmits data at speeds of up to ten megabits-per-second/mbps. Data is received at speeds of 60mbps. A waveband of 12.76 gigahertz/GHz to 13.25GHz is used for transmission. Signals are received on frequencies of 10.70GHz to 11.45GHz. The T7 weighs 2.8 kilograms (6.2 pounds). Ovzon told Armada in a written statement that “pound-to-pound, megabits-by-megabits the Ovzon T7 is the smallest, lightest and highest-performing mobile satellite terminal on the market.” The terminal can be used for communications across the company’s Ovzon-3 satellite and work with Ovzon’s legacy SATCOM networks. The terminal’s on-board processor enables “operations in GNSS (Global Navigation Satellite System) denied environments, (permits) obfuscated traffic patterns to prevent enemy interception, (has) a very low signal-to-noise ration mode for operations requiring low probability of interception and (provides) detection and full mesh networking supporting ultra-small terminals in scenarios where ground-based teleports are unavailable.” (Source: Armada)

 

13 Mar 24. Red Cell Partners Launches Eyris to Revolutionize Data Protection and Cybersecurity. Eyris offers a suite of blockchain technologies to boost digital security for DoD, Armed Services, and private sector

Red Cell Partners (Red Cell), an incubation firm building rapidly scalable, technology-led companies that are bringing advancements to market in national security, cyber, and healthcare, has announced $3 m in pre-seed funding for Eyris, a digital infrastructure platform created to provide cybersecurity, secure communications, and data protection.

Eyris offers a suite of blockchain technologies that provide advanced security solutions and mitigation from ransomware for the Department of Defense (DoD), Intelligence Community, and the private sector. Since Eyris is cloud- and encryption-agnostic, it can work with various cloud providers and encryption methods, tailoring its solutions to customer needs.

Eyris, which emerged out of stealth in 2023, was co-founded by Kevin Keaton, a U.S. Army veteran and former Chief of Innovation for the National Security Agency (NSA). With 34 years of experience in the national security industry, Keaton understands the urgent need for a proven, secure technology to fortify enterprise IT environments and mitigate risk.

“Resilient and secure technological infrastructure is critical for the security of the United States as well as public and commercial entities worldwide,” Keaton said. “At Eyris, we are committed to delivering that infrastructure so we can provide an unmatched level of data protection that makes it harder for cybercriminals to inflict harm and easier for entities to safely operate and overcome attacks.”

Eyris is the first company to publicly launch under Red Cell’s newly formed Cyber Practice, which was established to drive innovation and strengthen cybersecurity and resiliency for government and commercial clients. The practice is led by George Barnes, the former Deputy Director of the NSA, and colleague of Keaton.

“Cybercrime presents a rampant and persistent threat to an ever-broadening span of victims, from private citizens to industries of all types and sizes,” said Grant Verstandig, Red Cell Founder, Chairman, and CEO, and Co-Founder of Eyris. “In 2023 alone, the FBI reported that it received more than 800,000 cybercrime-related complaints. It also revealed that victims experienced more than $12.5 bn in potential losses, a staggering figure that far surpasses the $6.9 bn in losses reported in 2021.

“That’s why we need a company like Eyris, which was purpose-built to secure infrastructure and data by utilizing state-of-the-art blockchain technology that easily interfaces with existing applications,” Verstandig added. “Eyris’s Number One goal is to deploy data protection technologies that thwart cyberattacks so that enterprises worldwide are more secure, resilient, and in control.”

The funding from Red Cell allows Eyris to start a pilot program with the DoD and extend its services to other federal agencies in the near future. Eyris’ technology seamlessly integrates with existing applications such as Outlook and Slack, making communications more resilient and secure.

“Through our tamper-resistant blockchain, encrypted copies of data and sensitive information will remain safe,” said Keaton. “We bring revolutionary advancements in cybersecurity, data protection, and resiliency to national defense and beyond.”

About Red Cell Partners:

Red Cell Partners is an incubation firm building and investing in rapidly scalable technology-led companies that are bringing revolutionary advancements to market in three distinct practice areas: healthcare, cyber, and national security. United by a shared sense of duty and deep belief in the power of innovation, Red Cell is developing powerful tools and solutions to address our Nation’s most pressing problems. Visit us at redcellpartners.com and follow us on social media (LinkedIn, Twitter, Instagram).

About Eyris:

Eyris is harnessing the power of blockchain technology to deliver unmatched cybersecurity and data protection for public and commercial entities worldwide. In addition to providing foundational data and communications security, Eyris is deploying technology that is applicable in countless use cases across the public and private (finance, cybersecurity, logistics, healthcare) sectors. Learn more at eyris.tech and follow us on social media (LinkedIn). (Source: BUSINESS WIRE)

 

13 Mar 24. Everfox Partners with Microsoft to Advance Cloud Solutions for National Security. Global high-assurance cybersecurity leader, Everfox, formerly Forcepoint Federal, and Microsoft announced a strategic partnership agreement whereby Microsoft will integrate Everfox’s cross domain technology into Azure’s cloud service offerings.

Everfox’s portfolio of accredited, defense-grade cross domain solutions is built to meet the most stringent security requirements of data access and transfer. Through partnership with Microsoft, warfighters and the intelligence community will be able to access the information they need at the scale and velocity that the mission requires.

“Everfox is committed to supporting the missions of our customers who must maintain decision dominance in a world of increasing nation-state and non-nation-state driven attacks,” said Sean Berg, CEO of Everfox. “By partnering with Microsoft, our combined innovation and industry expertise will realize expanded capabilities from cloud to tactical edge.”

“This partnership with Everfox will enable us to continue evolving our cloud solutions and delivering the accredited, secure collaboration capabilities critical to our government customers,” said Zach Kramer, Vice President, Mission Engineering at Microsoft. “When the power of Microsoft Azure is combined with Everfox’s defense-grade cybersecurity solutions, we enable improved security and a real-time experience for our government users and coalition partners worldwide.”

As a result of this new agreement, Everfox and Microsoft will work together to develop innovative new cloud products to ensure that federal employees, from warfighters to the intelligence community, from sensor to shooter, or from home base to military base, can access the information they need at the scale and velocity the mission requires. Consequently, Everfox and Microsoft will be able to deliver enhanced value creation for the consumer by prioritizing an on-demand cloud service with built-in cybersecurity features. (Source: BUSINESS WIRE)

 

11 Mar 24. UK MoD withholds spending approval on DSA programme.

The risk that comes with the programme down the line has impacted the next stage of radio procurement.

The UK Armed Forces’ Dismounted Situational Awareness (DSA) soldier solution will continue to experience delays, prompted by the Ministry of Defence’s (MoD) avoidance of any risk in its decision-making.

While the Armed Forces have the sufficient funding required to procure the radios they need for the next level of procurement, the MoD is unwilling to give its approval as they do not want to commit until the risks have subsided.

Already set back by a six-to-nine-month delay, DSA, a project that began in July 2021, was originally anticipated to last for two years with an option to extend the programme for another six months. The combined contract valuation option was not to exceed £9m ($11.5m).

Delivery uncertainty took a turn for the worse as the Minister for Defence Procurement, James Cartlidge, introduced new acquisition reforms at the end of February 2024 that placed importance on the exportability of the MoD’s new systems and a greater emphasis on spiral development.

“Delivering new equipment and technology more quickly is key to the overall reforms, and the concept of ‘spiral’ development will be at the forefront as new programmes are initiated,” the MoD observed.

“Rather than striving for perfection before delivering to the frontline, capabilities at 60-80% of their full potential will be provided to the user, allowing early application, and subsequent improvements to reach their full potential.”

However, the problem with DSA is that the Government is unsure how successfully it will be able to spirally develop these new radios for the long-term. Ironically, this curbs the MoD’s plans for delivering a faster acquisition process.

UK extends Bowman radio system

Currently the UK Armed Forces use the Bowman combat radio, a system supplied by General Dynamics UK since it was originally awarded a contract for the communications system since 2001. However, a planned update to sustain the in-service Bowman system is currently underway as future systems in development face delays.

“The update will deliver new hardware and software ensuring troops on the frontline continue to have a secure communications system.”

As the Bowman 5.7 project is still in development and subject to approvals the procurement strategy is yet to be confirmed.

Concerns over Morpheus

Another MoD tactical communications network programme – a £3.2bn programme known as ‘Morpheus’ – was said to be at risk of delays in May 2023.

A UK Public Accounts Committee (PAC) report “expressed series doubts” about whether the MoD Equipment Plan was affordable, or agile and responsive enough to react to a changing threat environment brought about by Russia’s invasion of Ukraine.

Given National Audit Office’s assessment of the MoD Equipment Plan for 2023-33 in December 2023 identified a deficit just shy of £17bn – the MoD’s largest shortfall in the history of the Equipment Plan – this is a legitimate concern.

There was a “significant risk” that the UK could not provide Nato with an operational Army division, with programmes such as the Ajax armoured vehicle and Morpheus communications system “beset by problems and delays”. (Source: army-technology.com)

 

14 Mar 24. Stronger together: International cyber partnerships. Leading cyber is a core priority, part of this is sharing our expertise with and learning from international partners so we can better protect global security.

In an increasingly uncertain world, new threats and technologies are constantly emerging. It is vital that we hone and adapt our cyber capabilities to compete with and deter our adversaries. Strong international relationships are pivotal to this success.

One of these partnerships is with the German Cyber and Information Domain Service (CIDS) which signed a bilateral arrangement with Strategic Command in July 2022. Recent staff talks, which were held at our Development, Concept and Doctrine Centre in Shrivenham, took our cooperation to the next level.

Major General James Roddis, Director Strategy, co-chaired the talks alongside Brigadier General Dietmar Mosmann, his counterpart from CIDS. Discussions focused on how best to develop our cyber people, joint training and exercising, support to multi-domain operations, and provide enhanced collaboration around information activities. These are areas where the UK and Germany can combine forces extremely effectively to drive change in our own institutions but more importantly into the NATO alliance.

While UK’s cyber and information relationship with Germany plays an important part in transforming NATO, whether this be on cyber, digitalisation or multi-domain operations, our alliances and partnerships extend far beyond NATO and have a global reach, including with Japan, Singapore and of course our close Five Eyes partners.

Key bilateral events with Australia have enabled us to further share best practice, with General Jim Hockenhull discussing our efforts to learn from the Australian Defence Strategic Review with Chief of the Defence Force General Angus Campbell.

Recent conversations with Japan’s Cyber Defense Command shared more about our role at the forefront of digital capabilities, following on from General Hockenhull’s visit to Tokyo last year and the signing of the Cyber Partnership agreement and the landmark Hiroshima Accord.

Having a strong digital defence will be crucial over the coming years. Rapidly evolving technology, the proliferation of AI, and our adversaries’ intent on unconventional ways of disruption mean the knowledge and capabilities shared through our international relationships will continue to be vital.

Read more on the cooperation agreement between the UK and Germany here: Cyber Co-operation with Germany Strengthens – GOV.UK (www.gov.uk).

Our relationship with the Japanese Cyber Defense Command is discussed in more detail here: https://www.gov.uk/government/news/strategic-command-shares-cyber-expertise-with-japan (Source: https://www.gov.uk/)

 

11 Mar 24. US: Microsoft breach signals heightened espionage, information theft risks for US-based tech firms. On 8 March, Microsoft revealed that the Russian-affiliated threat group ‘Midnight Blizzard’ accessed some of the company’s source code and proprietary information. The stolen information pertains to the core programming instructions behind Microsoft’s software. The group used information gathered during an earlier phase of this attack to obtain elevated privileges in the system. The attack started in January following the compromise of an inactive test account that granted threat actors prolonged access to Microsoft’s network. The confidentiality of the compromised information and the length of the campaign underscore the ongoing development and perseverance of state-sponsored threat actors. Technological advancement has become a primary objective for cyber espionage operations, with countries seeking to gain a competitive advantage amid rising global tensions. Subsequently, we assess that US-based technology companies are highly likely to be targeted in espionage and information theft operations in the short-to-medium term, primarily by non-Western state-sponsored groups. (Source: Sibylline)

 

08 Mar 24. US Army needs more industry input before pivot to ‘radio as a service.’ The U.S. Army is looking for additional input from industry about its nascent radio-as-a-service initiative, a move away from the traditional method of acquiring and maintaining communications gear.

The service has hundreds of thousands of radios, too many to quickly and cost-effectively modernize given looming security deadlines and cat-and-mouse competition with Russia and China, world powers with sophisticated signals intelligence capabilities. An as-a-service model may provide the military with the latest radios and support networks while driving down costs and promoting hardware and software flexibility.

At least one related request for information was published last year. It garnered more than a dozen responses, ranging from enthusiasm to rejection, officials said at the time.

The input was helpful to the Army, and that sort of dialogue with defense suppliers will continue, Undersecretary Gabe Camarillo told reporters March 7, 2024, on the sidelines of the McAleese defense conference in Washington.

“We were going to send an RFI out, we were going to enter into a very formal and elaborate conversation with industry about the economics of that buying model and get feedback,” Camarillo said. “I think we’ll continue to partner with industry on multiple RFIs, multiple discussions in different fora.”

Exploratory pilots could help iron out kinks, Camarillo said. Radio as a service could resemble a subscription offered by some makers of consumer products; it could also mirror other deals in which companies furnish goods and expertise on a rolling basis, keep them up to date and handle quality control.

Updated connectivity has for years been a priority for the Army, alongside demands for improved long-range precision fires, air and missile defense and aviation. Secure, reliable networking is a tenet of the Pentagon’s Combined Joint All-Domain Command and Control concept, which envisions insights seamlessly relayed across land, air, sea, space and cyber.

Army Chief of Staff Gen. Randy George at the same conference Thursday said the service must recognize the demands of today without losing sight of the potential leaps ahead of tomorrow.

“We have to get our soldiers the right technology, when it is relevant, with the ability to upgrade and adapt to the threat. If we don’t, then we are putting our men and women in the dirt unprepared to fight and win,” George said. “This isn’t just about product innovation, it’s about process innovation.”

The chief of staff previously said soldiers “need to shoot, move and communicate,” and that “technology should facilitate those fundamentals, not encumber them.” (Source: Defense News Early Bird/Defense News)

 

08 Mar 24. RFIDKNOW Unveils Innovative and Affordable FlexAntenna.

Technology pioneer RFIDKNOW has released its ground-breaking industrial RFID portal, designed to be scalable, robust and easy to deploy. The RFIDKNOW FlexAntenna completely transforms traditional RFID portal reading systems, by blending technology innovation with practicality. The result is a reader portal that is easy to ship, handle and install, with exceptional read performance. Demand for visibility into supply chains is driving the need for affordable, modular RFID reader portals in warehouses and distribution centers. Many existing RFID antenna solutions can be a challenge to ship and install at busy dock doors and conveyors. Ability to rapidly deploy industrial RFID systems without heavy equipment is crucial for large-scale deployments.

RFIDKNOW is uniquely positioned to offer a solution to RFID functionality and affordability. Its leadership has decades of experience advising companies on a wide variety of RAIN RFID projects. “It became clear that existing RFID portals were not cost effective, convenient, or accurate enough to meet industry needs,” says Joe Hoerl, the company’s principal consultant. “RFIDKNOW decided to take action and developed FlexAntenna.”

Developed in cooperation with industry-leading antenna design firm Innovoi, Ltd., the patent-pending FlexAntenna’s modular multilinear antennas represent a completely new engineering approach to RFID tag reading and portal manufacturing. With focused beams this innovative new technology captures RFID tag reads from all orientations for best-in-class performance.

The FlexAntenna is optimized for ease of transportation and installation. In addition to being modular, compact and lightweight to reduce shipping costs, FlexAntenna boasts a robust aluminum enclosure that withstands the rigors of industrial environments. Deployments are seamless, since the FlexAntenna can be fitted with leading RFID readers and associated software systems, right out of the box.

“RFIDKNOW’s FlexAntenna has not only proven its technical capabilities but also stands out in practicality. Its flexible design ensures ease of shipping, allowing for reduced logistics challenges, but has also surpassed the performance of other RFID portals,” says Danny Kwoka, RMS Omega Technologies’ business development manager. “After several series of rigorous tests, the FlexAntenna consistently outperforms its counterparts, showcasing its superior tag reading capabilities. RMS Omega Technologies is excited to announce its partnership with RFIDKNOW as a solutions integration partner.”

The FlexAntenna is manufactured in the USA and available at scale, today. RFIDKNOW provides custom branding.

About RFIDKNOW: RFIDKNOW is a high-tech antenna manufacturer and services consulting firm that leverages its years of wireless experience and successes to help solution providers plan, conduct trials, select technologies, and implement industrial RFID and short-range wireless IoT solutions best suited for each application. RFIDKNOW’s business is underpinned by our strong system integrator partner ecosystem along with advanced manufacturing methods, R&D, and a range of highly qualified team members. (Source: BUSINESS WIRE)

 

08 Mar 24. Cyber Update Key points.

  • New multi-pronged phishing campaign underscores threat actors’ evolving tactics, techniques and procedures (TTPs), accentuating security and information theft risks to cryptocurrency users (see Sibylline Cyber Daily Analytical Update – 4 March 2024 and our Technical analysis below).
  • North Korean threat actors targeted at least two South Korea-based semiconductor companies, highlighting elevated cyber espionage risks facing defence and technology firms (see Sibylline Cyber Daily Analytical Update – 5 March 2024).
  • The active exploitation of two new zero-day vulnerabilities in Apple’s iOS platform signals heightened espionage risks facing Western entities (see Sibylline Cyber Daily Analytical Update – 6 March 2024).
  • New malware campaign highlights the growing security risks third-party cloud services pose to companies (see Sibylline Cyber Daily Analytical Update – 7 March 2024 and our Technical analysis below).
  • Remote access trojan (RAT) campaign points to growing espionage and security risks for firms via online meeting platforms (see Sibylline Cyber Daily Analytical Update – 8 March 2024).

Technical analysis of weekly stories

A new multi-pronged phishing kit, ‘CryptoChameleon’, targeted US-based cryptocurrency users and employees of the Federal Communications Commission (FCC). The campaign uses fake copies of legitimate single sign-on (SSO) pages to coerce users into disclosing their credentials and ultimately steal sensitive information. Potential victims are initially contacted via SMS, email or voice call by threat actors impersonating customer support. The user is then directed to a malicious site where they are prompted to complete a CAPTCHA challenge; this new tactic evades automated security detection tools while simultaneously enhancing the site’s authenticity. Subsequently, the victim is asked to input their credentials and complete Multifactor Authentication (MFA) via a sophisticated command and control (C2) method. This can include personalising SMS-based MFA where the victim is sent a message containing the last digits of their phone number. This new kit distinguishes itself from previous iterations due to its high level of sophistication. The threat actors demonstrated their awareness of modern security controls, leveraging them to bolster legitimacy. Additionally, the URLs, login pages and C2 methods employed all display high levels of complexity, further underscoring actors’ maturing TTPs.

A new malware campaign, ‘Spinning YARN’, is affecting misconfigured cloud services in Linux systems. The campaign primarily targeted the software platform, Docker. Threat actors initially employ malicious programs to identify and infect the misconfigured services. This allows them to create and control a new instance within the victim’s infrastructure, enabling them to establish consistent communication with the actor-controlled infrastructure. Subsequently, the actors execute an additional script that delivers a cryptominer to garner illicit profit. Notably, the campaign involves the use of two rootkits to conceal the malicious processes alongside utilising Secure Shell (SSH) credentials to maintain access to the compromised system. This malware emerged as part of a broader trend of developing TTPs, exploiting inadequate security policies and misconfigurations in third-party cloud services.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity
  • Enforce strict security policies including regular software and password updates
  • Conduct cyber hygiene awareness courses for users to enable them to recognise and report phishing and other types of social engineering attempts
  • Create network segmentation to limit potential damage from infections
  • Add available Indicators-of-Compromise (IoCs) to the organisation’s security detection systems to detect potentially malicious samples on the network
  • Ensure adequate security detection measures are in place, particularly behaviour-based end-point detection and response (EDR) solutions

Our cyber word of the week: Rootkit

Definition: A collection of software tools used to gain unauthorised access and control of a computer system without being detected.

Example:‘Notably, the campaign also involves the use of two rootkits to conceal the malicious processes…‘ (see Technical Analysis).

Frequency of TTPs during this monitoring period: LOW frequency, MODERATE frequency, HIGH frequency

The MITRE ATT&CK framework is a globally accessible documented collection of information detailing the malicious behaviours of cyber threat actors; it is used as the foundation for organising the processes which threat actors execute during cyber operations. It provides an encyclopaedic reference for organisations, highlighting the tactics, techniques and procedures (TTPs) cyber actors employ in campaigns, while also providing suggestions for detecting and mitigating against specific TTPs to bolster organisations’ security mechanisms. The framework organises a threat actor’s entire operational lifecycle from reconnaissance to exfiltration and impact. (Source: Sibylline)

 

14 Mar 24. Global: Malware campaign points to security risks emanating from trusted third-party software. On 13 March, Zero Day Initiative (an international software vulnerability programme) reported the discovery of a malware campaign that exploits a patched vulnerability (CVE-2024-21412) in Microsoft Defender (antivirus software). The campaign starts with a phishing email coercing victims into opening a PDF file containing malicious links. These links then redirect the victim to actor-controlled web servers, leveraging the vulnerability to bypass Microsoft Defender’s routine security checks. Following initial access, the threat actors then deploy the ‘DarkGate’ malware, which enables them to evade detection and steal data from the compromised system. The abuse of legitimate third-party software often bolsters success rates for attackers as it exploits established (and trusted) applications while widening an organisation’s attack surface. Threat actors are increasingly exploiting vulnerabilities in the software supply chain to infiltrate corporate systems, highlighting the sustained security risks facing firms. Microsoft has since released a patch addressing this vulnerability, further stressing the importance of strict patch management and security policies. (Source: Sibylline)

 

14 Mar 24. France: DDoS attacks amplify disruption risks to government, public sectors in short-to-medium term. On 11 March, international news outlets reported that several French government institutions were targeted in multiple distributed denial-of-service (DDoS) attacks between 9 and 10 March. The threat actors targeted several government websites, rendering services temporarily unavailable. While the French government quickly restored these services, it reported that the attacks displayed unprecedented intensity. Additionally, the hacktivist group ‘Anonymous Sudan’ claimed the attacks on Telegram, though this has not been officially confirmed. The upcoming 2024 Paris Olympic Games and European Parliament (EP) elections are likely to present attractive targets for threat actors, increasing the likelihood of attacks and underscoring the disruption risks posed by state-sponsored and hacktivist groups. As geopolitical tensions remain strained across multiple regions, we assess that politically motivated threat actors will seek to influence elections and disrupt perceived adversarial entities by compromising high-profile events. Consequently, we assess that similar attacks targeting European officials and political bodies are highly likely in the short-to-medium term. (Source: Sibylline)

————————————————————————-

 

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

 

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY

March 8, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

————————————————————————

07 Mar 24. Global: New malware campaign highlights growing security risks posed by third-party cloud services. Earlier on 7 March, the cloud security company Cado Security warned that a new malware campaign (‘Spinning YARN’) is affecting misconfigured cloud services in Linux systems. The campaign has primarily targeted the software platform ‘Docker’. Threat actors first employ malicious programmes to identify and infect misconfigured services; they then create a new instance within the victim’s infrastructure to establish communication with actor-controlled servers, before deploying malicious files. The campaign subsequently deploys crypto-mining software to garner illicit profit. The increasing reliance on third-party cloud services to scale up companies’ operations will place greater pressure on firms’ IT teams to protect wider and more complex attack surfaces. Threat actors looking to garner illicit profit are exploiting weaknesses in these services, elevating the financial and operational risks facing firms. The recent campaign underscores the heightened security risks misconfigured and inadequately secured third-party cloud services pose to companies.(Source: Sibylline)

 

06 Mar 24. Dependency Syndrome. Social media continues to be a mine of information on how Russia evades sanctions to acquire EW technologies that support her continued occupation of Ukrainian territory.

Late February brought the revelation that Keysight Technologies products are ending up in Russian hands. As an American company, Keysight Technologies is subject to US government restrictions regarding Russia. These restrictions forbid a wide array of technology exports to Russia and full details of the restrictions can be found here. There are no suggestions that the company is willingly supplying its products to Russia. As has happened with other US technology companies, Russia illicitly buys these products through intermediaries.

The customer

Dogged investigation by @Tataigami_UA published both on Twitter (called X by almost no one) and their own Substack page has revealed how Keysight’s products have ended up in Russian hands. The first link in the chain is a Russian company called the Special Technology Centre (STC) which is the customer. Based in St. Petersburg, northern Russia, one of STC’s products is the Orlan-10 Uninhabited Aerial Vehicle (UAV). The Orlan-10 forms a key part of the Russian Army’s Leer-3 electronic warfare system. STC is acquiring Keysight’s products despite being sanctioned by the Office of Foreign Assets Control (OFAC). The OFAC administers and enforces economic and trade sanctions and is part of the US Department of the Treasury.

The intermediaries

How does STC acquire these products? @Tataigami_UA suggests they are sourced through intermediary companies. This process helps to obscure STC as the final recipient and hence avoid restrictions and sanctions. Three Russian companies chiefly Radioline, headquartered in Moscow, and Dipaul and RITM, both based in St. Petersburg, have offered to supply STC with Keysight’s products. The investigation cited Mikhail Mulminov, thought to be a citizen of St. Petersburg, as key to the operation. Mr. Mulminov worked as Keysight’s regional representative in the past, according to @Tataigami_UA. Another Russian company involved in the acquisition is Protech. Not much is known about this enterprise although evidence suggests it is also based in St. Petersburg.

The Russian companies purchasing on behalf of STC are probably doing so through third parties. In this case, it appears Keysight has been unlucky. A glance at the company’s website reveals that systems can be brought off-the-shelf with relative ease. Are products being purchased by companies in third countries not under US sanctions then sold overtly or covertly to the companies in Russia? It is impossible to say for certain and Keysight did not respond to Armada’s requests for information.

Tightening the noose

Nonetheless, this recent revelation underscores that Russian companies in the Electronic Warfare (EW) sector continue to source sophisticated electronics indirectly from Western suppliers with comparative ease. It is difficult combat this trade lest it affect companies in third countries making legitimate acquisitions. That Russian companies procure Western electronics for their EW systems shows how dependent they are on them. Clearly, the products they are acquiring are ones they cannot produce or procure equivalents of at home. Countries supporting Ukraine need to continue doubling down on their efforts to choke Russia’s dependence on advanced electronics.(Source: Armada)

 

06 Mar 24. Blowin’ up my phone. There are several mechanisms by which cellphones can be detected, located and tracked on the battlefield. These methods include detecting and tracking the phone’s signal or hacking into the network it uses. A new report highlights the challenges of tracking cellphones on the battlefield using the ongoing war in Ukraine as a case study.

Arguably the first ‘smartphone’ war, the ongoing conflict in Ukraine has underscored the important role these devices continue to play in this war, and that they will play in the future. At the military level, smartphones can be a useful tactical communications alternative to military transceivers. Smartphones let people stay in touch or use the internet when conventional telecommunications may be damaged or unavailable. These devices have been invaluable for collecting and sharing evidence of Russian-perpetrated atrocities. Worryingly, smartphones are also effective conduits for the torrents of Russian propaganda, disinformation and outright lies Vladimir Putin’s regime spews into the ether.

A report published in February by ENEA takes a detailed look at the questions surrounding the use of cellphones on, and near, the battlefield. In January 2023 the Russian military blamed cellphone signals from Russian troops for helping the Ukrainian Army locate a target in Makiivka in southeast Ukraine. Reports say scores of Russian troops were killed when a college they were using was hit on 31st December 2022. Russian troops are banned from using their cellphones within range of Ukrainian weapons. As ENEA’s report makes clear, whether these signals were responsible for the geolocation of the Russian troops is debatable.

Are you gonna reach my telephone?

ENEA’s study says that cellphone signals can be located through passive radio frequency sensing and then triangulated to determine their point of origin. This method relies on the cellphone actively transmitting. Active direction finding is a more complex approach involving a tracking station. The station will communicate with the phone making it generate a signal as a response. Once this signal is generated it can be geolocated. This approach also lets Communications Intelligence (COMINT) cadres retrieve details from the targeted phone such as its SIM (Subscriber Mobile Identity) card number. The Russian Army’s Leer-3 COMINT system is thought to use the active direction finding method. Location retrieval over radio networks is a third method flagged in ENEA’s paper. A location tracker will send radio measurement commands to any cellphones being tracked. Usually, this is done innocently by networks to ascertain link quality and improve performance. Through mathematics the local retrieval over radio networks approach can determine a cellphone’s location.

Hacking presents another means to locate a phone. Network enabled tracking extracts location information for phones attached to any specific mobile network. Specifically, the Signalling System-7 (SS7) protocol, which governs traffic routing and billing, is exploited. It is possible to locate and track subscribers on a network by gaining access to SS7 protocols. Likewise, mobile operator telecom hacking can compromise network nodes which are then exploited for subscriber location information. It is also possible to insert malware into cellphones which is then used to track the device as chronicled in this Armada article.

Shoulda left my phone at home!

What does all this mean for cellphone use on the battlefield or more generally in the theatre of operations? “Regarding mobile phones … the surprise has been the increased use of them, and commercial communications in general, by military forces,” says Cathal McDaid, ENEA’s chief technology officer and one of the report authors. “(E)missions control of mobile devices should be as effective as possible, so if mobile devices are used, as seems increasingly common, then they should be used sparingly and with safeguards.”

Cellphone networks are now centres-of-gravity in contemporary and future warfare as targets that can be exploited to determine troop locations, hamper communications and disrupt morale. Alongside geolocation, electronic attacks against cellular networks could deprive militaries of alternative tactical communications. Exploiting cellular networks to spread false, misleading or demoralising traffic can have a powerful psychological impact.

Reflecting this importance cellular networks in Ukraine “have been secured and made more resilient by both parties, this improved connectivity has been present up to the edge and in many cases on the battlefield.” The flipside of this, says Mr. McDaid, “is ample opportunity to identify active and transmitting mobile devices.”

The effect the war in Ukraine is having on cellular networks, and vice versa, has an impact far beyond the theatre of operations. So-called fifth generation (5G) cellular protocols are being embraced by militaries to enhance communications both on and off the battlefield. NATO (North Atlantic Treaty Organisation) members and allied nations would do well to digest the lessons of ENEA’s report. Civilians in these nations should also take note. The cellular networks we all rely on are valuable targets in peace as well as war. Understanding network, and hence our own, vulnerabilities, makes sense.

Wise words: The translation of advice given to Ukrainian troops regarding cellphone use at, or near, the tactical edge. The ongoing conflict in Ukrainian is arguably the world’s first ‘smartphone war’, highlighting the importance of emissions control. (Source: Armada)

 

06 Mar 24. March Spectrum SitRep. The graphical user interface of Patria’s ARIS-E electronic support measure is shown in this image. The company has just concluded agreements to supply its ARIS ELINT system to two NATO members.

Armada’s monthly round-up of all the latest electronic warfare news in the product, programme and operational domains.

New ARIS Acquisitions

In early February, Patria announced it had signed agreements to supply the company’s ARIS Electronic Intelligence (ELINT) system to two undisclosed North Atlantic Treaty Organisation (NATO) members. ARIS is produced in two versions, the ARIS and ARIS-E. The key difference is that the ARIS is designed for ELINT gathering while ARIS-E adds Electronic Support Measure (ESM) functions. The company’s literature says that ARIS covers a waveband of 270 megahertz/MHz to 18 gigahertz/GHz. Optional increases for ARIS include extensions of 20MHz to six gigahertz, and 18GHz to 40GHz. ARIS-E works across a two gigahertz to 18GHz waveband. Options exist to extend this waveband downwards to 800MHz and upwards to 40GHz. Although the company cannot disclose when these ARIS deliveries will take place, it did tell Armada that the product is usually deployed in fixed, transportable and mobile ground configurations. That said, ARIS can also equip naval and airborne platforms. “ARIS relies on high-gain, directional antennas … whereas ARIS-E relies on interferometer antenna units providing automatic direction finding, 360-degree field-of-view (with multiple antenna units) and ultra-wide instantaneous frequency bandwidth,” the company said in a statement. Both ARIS and ARIS-E geolocate emitters-of-interest using line-of-bearing, angle-of-arrival and triangulation techniques; the latter with two or more sensors. Whereas ARIS “focuses on intelligence use cases … ARIS-E focuses on surveillance use cases.” As well as supporting ELINT collection and analysis of radar signals, both systems can intercept communications signals “when they fall into the supporting frequency ranges.”

This year’s Full Spectrum Air Defence conference takes place at London’s Hilton London Syon Park Hotel in west London. The event is an excellent opportunity to sample the latest research and perspectives on a host of subjects, and network with colleagues.

Air Defence Week – Call for Papers

This year, IQPC will once again run its Air Defence Week event in London between 24th and 27th June. The event takes place in the delightful setting of Syon Park in the west of the city. Syon Park is the home of Syon House which was built in 1552. The house has a rich history. It was where Catherine Howard, the fifth wife of the England’s King Henry VIII (1491 – 1547), was imprisoned. Lady Jane Grey, the ‘nine days queen’, lived at the house before her short reign in July 1553. More recently, in 1609, Syon Park was the venue for the first ever use of the telescope. This year’s conference comprises three events under one roof at the Hilton London Syon Park hotel. These include Directed Energy Systems (24th June), Full Spectrum Air Defence (25th to 26th June) and Military Radar (27th June). As with previous events, delegates can expect to hear the latest research and operational perspectives on a host of subjects. The conferences also present great networking opportunities. IQPC is keen to hear from potential speakers, and proposals for presentations are most welcome. Please do feel free to contact the conference producer, Lucy Breuning () for more information. (Source: Armada)

 

05 Mar 24. RoK: Ongoing campaign points to growing espionage risks facing defence, technology firms. On 4 March, the South Korean National Intelligence Services (NIS) disclosed that North Korean actors have conducted several cyber espionage campaigns against defence and technology firms since late 2023. At least two South Korea-based semiconductor companies were targeted in these operations. The threat actors stole sensitive data – including product design drawings and facility site photos – possibly to spur North Korea’s own production of semiconductors. The campaigns started with the threat actors exploiting vulnerabilities in internet-exposed assets to obtain initial access to corporate networks. The threat actors then used ‘living off the land’ techniques, thus exploiting native and legitimate software to evade detection within the victim’s network. North Korea has recently boosted its participation in cyber espionage campaigns to bypass economic sanctions and to continue advancing its satellite and missile programmes. Various non-Western states have employed cyber operations more widely against defence and technology sectors to bolster their economic and security postures. Subsequently, we assess that this underscores the growing espionage threats posed by these actors to defence and technology firms both in South Korea and across the globe. (Source: Sibylline)

 

04 Mar 24. Thales collaborative cloud solution certified to European Restricted level.

  • In 2021, TrustNest R-Cloud became the first cloud solution certified for use with information classified as Restricted Distribution in France, and is now available for European projects with the new European Restricted certification approved by ANSSI, the French national cybersecurity agency.
  • The TrustNest R-Suite applications marketplace hosted on this cloud since 2023 will now be authorised to offer European Restricted services to help companies collaborate more easily on European projects involving sensitive data.

As companies purse their digital transformation, remote collaboration in the cloud has come to play a key role in project management and is easy to set up with the cloud solutions available to the general public. But until now, the use of these public cloud solutions was not authorised for strategic projects handling sensitive data. Thales developed its R-Cloud platform to meet this requirement. With the new solution, partners on projects handling information classified as Restricted Distribution (RD) in France – and now European Restricted in Europe – can use collaborative tools that were previously unable to provide the necessary security assurances. The TrustNest R-Suite marketplace brings users all the benefits of the collaborative cloud without compromising on security.

ANSSI’s approval of European Restricted certification – the first time a single cloud has been certified for use by several clients – marks a significant milestone in that it sets the official seal of approval on the use of TrustNest R-Cloud on major European projects involving France and all the other EU Member States.

TrustNest R-Cloud has offered a Restricted Distribution collaboration solution to French companies of all sizes since January 2022, and the certified TrustNest R-Suite of as-a-service applications was added in 2023. Today, Thales is making these applications available for use on major European programmes that require European Restricted certification, to provide videoconferencing and team chat services, support co-development of sensitive software and hardware by teams located in different countries, supervise projects and manage resources using Software-as-a-Service (SaaS) applications.

This latest certification consolidates the position of TrustNest R-Suite as the preferred collaborative software suite for major French and European strategic programmes.

About TrustNest R-Cloud

TrustNest R-Cloud is the first collaborative cloud solution with both French Restricted Distribution and European Restricted certifications. Entirely operated by Thales, it is interconnected with the sensitive networks of multiple partners. Under French regulations, it meets the requirements of Ministerial Instruction No. 901 for protection of systems handing Restricted Distribution information in France, and General Interministerial Instruction No. 2102 for protection of systems handing European Restricted information. TrustNest R-Cloud brings organisations all the benefits of a cloud infrastructure, including elasticity, scalability and updatability. TrustNest R-Suite brings together all the SaaS applications hosted on this cloud, providing authorised companies access to an innovative suite of as-a-service applications to collaborate more easily and deliver sensitive projects more quickly.

As a trusted partner, Thales offers users of public, private, defence and restricted clouds highly secure, easy-to-deploy solutions that are tailored to the nature of the organisations involved, the level of protection required and their specific service needs.

Find out more about TrustNest R-Suite here: TrustNest R-Cloud (thalesgroup.com)

 

04 Mar 24. US: New multi-pronged campaign accentuates phishing risks facing organisations. On 2 March, the software company Lookout reported that it discovered a new phishing kit called ‘CryptoChameleon’. The campaign primarily targets US-based cryptocurrency users and employees of the Federal Communications Commission (FCC). It typically attempts to deceive them into disclosing sensitive information. The campaign begins with an email, SMS or voice call wherein the threat actor impersonates customer support to direct the victim to a malicious login site. Subsequently, the victim is asked to complete a CAPTCHA challenge designed to boost the site’s legitimacy and to avoid automated security detection tools. Cyber security experts have noted the high-level of sophistication associated with this multi-pronged campaign. It underscores that threat actors are becoming more skilled at evading detection via advanced tactics, techniques and procedures (TTPs), pointing to the increased security and information theft risks facing firms. (Source: Sibylline)

 

01 Mar 24. US-Europe: Government entities face heightened operational risks following FBI-led takedown. On 28 February, the cloud security company Zscaler reported that the well-known ‘LockBit’ ransomware group restarted operations following an FBI-led takedown operation in late February. Law enforcement seized the group’s infrastructure to access information on its affiliates as well as to retrieve victims’ stolen data. However, shortly after the seizure, Zscaler identified a series of LockBit ransomware attacks using new ransom notes, signalling that the group is once again operational. The new ransom notes leverage Tor software (a free and open-source medium used to access the dark web; it allows users to conceal their identity and communications, thereby remaining undetected). The group further stated on its new website that it would target government entities in retaliation, underscoring the elevated security and operational risks facing government organisations, particularly those that participated in the takedown campaign. In light of these new attacks from LockBit’s freshly established infrastructure, we assess that government entities are likely to be targeted in ransomware operations in the short term. (Source: Sibylline)

 

29 Feb 24. Poland signs $2.5bn deal for US air-defense software hub. The Polish Ministry of National Defence has signed a $2.5bn deal with the U.S. government to acquire the Integrated Battle Command System, or IBCS, to synchronize the nation’s air- and missile-defense weapons under development.

Deliveries are scheduled for the years 2024 to 2031. Poland intends to use the system to operate its Patriot missile launchers, which are part of the Wisla medium-range, air-defense program, and the Narew short-range equivalent, which relies on MBDA’s Common Anti-Air Modular Missile, or CAMM.

The acquired systems will be used for six Wisla batteries and 23 Narew batteries, the country’s defense ministry said in a statement

Władysław Kosiniak-Kamysz, Poland’s deputy prime minister and national defense minister, signed the contract during an official ceremony on Feb. 29. “We will be the second country, after the United States, to have this system, an integrated command system,” he said.

Kosiniak-Kamysz was sworn in on Dec. 13 as a new Cabinet replaced the ousted government of the right-wing Law and Justice party.

Poland’s Oct. 15, 2023, parliamentary election, which paved the way for a change in government, prompted U.S. manufacturer Northrop Grumman to host an event with top executives in Warsaw in November to advertise the program during the transition.

With the purchase now secured, it appears that the new defense leadership here will stick to the previous government’s procurement schedule for the key components of the Wisla and Narew programs. (Source: Defense News Early Bird/Defense News)

 

01 Mar 24. JFHQ-DODIN Officially Launches its New Cyber Operational Readiness Assessment Program. Following a successful nine-month pilot, Joint Force Headquarters — Department of Defense Information Network is officially launching its Cyber Operational Readiness Assessment program today.

Over the past four years, JFHQ-DODIN has made significant changes to the Defense Department Command Cyber Readiness Inspection program, transforming mindsets from an inspection compliance to an operational readiness underpinning mission assurance. To enunciate this significant shift, the program has been renamed to the Cyber Operational Readiness Assessment.

According to Air Force Lt. Gen. Robert Skinner, commander of JFHQ-DODIN, CORA is one of the most critical components of the DOD’s cyber security strategy and lays a strong cornerstone to support the command’s goal of continuous holistic assessments. The new processes help strengthen the posture and resiliency of the DODIN by supporting the network’s Areas of Operation commanders and directors in efforts to harden their information systems, reduce the attack surface of their cyber terrain and enhance a more proactive defense. These are the foundational cybersecurity principles measured by the CORA program.

“CORA is a vital aspect of continually understanding our cyber readiness through fusing many risk factors including access control, detecting anomalies, adjusting to adversary threat information and executing cyber orders,” Skinner said. “Ultimately, the assessment provides commanders and directors a more precise understanding of their high-priority cyber terrain and their overall cyber security and defensive posture enabling greater command and control and enhancing decision making.”

John Porter, JFHQ-DODIN’s acting director of DODIN Readiness and Security Inspections directorate, said “CORA represents a consolidated look at threat, vulnerability and impact designed to give DAO commanders and directors relevant information for making decisions about cyber terrain, forces and other resources.”

“CORA prioritizes MITRE ATT&CK mitigations to minimize adversarial risk to the DODINs through JFHQ-DODIN’s risk-based metrics. The command created risk-based metrics after analyzing MITRE ATT&CK tactics, techniques, and procedures for initial access, persistence, privilege escalation, lateral movement and exfiltration,” Porter said.

MITRE ATT&CK is a knowledge base of adversarial TTPs utilized by cyber defenders world-wide to protect and defend information systems and networks and hunt malicious actors.

Porter said, “the JFHQ-DODIN CORA team developed key indicators of risk from the risk-based metrics to ensure alignment with JFHQ-DODIN cybersecurity priorities and to direct focus onto the most critical areas of remediation.”

This, in turn, allows organizations to focus their mitigation efforts on risk and exposure to common adversarial TTPs. He added, “focusing on these essential remediation points allows DOD Components to concentrate limited resources and staffing on correcting high-risk areas.” JFHQ-DODIN risk-based metrics and CORA key indicators of risk are adjusted as the MITRE ATT&CK TTPs and mitigations priorities shift, enabling the CORA program to keep pace with the rapidly changing cyber domain.

In addition to the key indicators of risk, Porter said “CORA is hyper-focused on securing the boundary.” The boundary consists of network perimeter devices, public and DOD facing assets servicing the public or external DOD components and any information systems with a direct interface to an external information system. The boundary reviews measure the cyber-hardening risk of information systems exposed to the public internet and the possibility that the malicious activity could spread to other DOD Components if an information system is compromised.

The CORA has become a more agile process encouraging and enabling adjustments in strides. The assessment can be adjusted as new orders, policies or directives are issued, add new assessed technology if Security Technical Implementation Guides exist, and adjust key risk indicators as the threat landscape changes.

The program will help ensure a strong cybersecurity foundation for all DOD networks. It will help DAO commanders and directors better understand the status of their high-priority terrain and their overall cyber security readiness and defensive posture and provide them with relevant information for making decisions about terrain, forces and other resources. At the same time, it will provide the U.S. Cyber Command and JFHQ-DODIN commanders a greater understanding of level of risk to the DODIN. CORA is crucial for validating current, future, and emerging technologies that will help the DOD continuously monitor and assess terrain to assess and mitigate risk across the DODIN. (Source: U.S. DoD)

 

01 Mar 24. Cyber Update. Key points.

  • A Russian PSYOP campaign targeting Ukrainian speakers points to elevated phishing and disinformation risks for Western organisations (see Sibylline Cyber Daily Analytical Update – 26 February 2024).
  • The evolving TTPs of a Russian threat actor include exploiting cloud-based environments, highlighting elevated supply chain risks facing organisations (see Sibylline Cyber Daily Analytical Update – 27 February 2024 and our Technical analysis below).
  • The active exploitation of new software vulnerabilities by the ransomware groups ‘Black Basta’ and ‘Bl00dy’ underscores the elevated supply chain risks facing firms (see Sibylline Cyber Daily Analytical Update – 28 February 2024).
  • New PDF vulnerabilities allow threat actors to execute malicious code, pointing to elevated phishing and social engineering risks (see Sibylline Cyber Daily Analytical Update – 29 February 2024 and our Technical analysis below).
  • The ‘Lockbit’ ransomware group resumed operations despite being disrupted by an FBI-led seizure of its infrastructure (see Sibylline Cyber Daily Analytical Update – 1 March 2024).

Technical analysis of weekly stories

The well-known ransomware groups Black Basta and Bl00dy exploited two new vulnerabilities (CVE-2024-1709 and CVE-2024-1708) in the popular remote desktop application ScreenConnect. The most critical vulnerability (CVE-2024-1709) allowed both groups to gain access to their victims’ systems and to escalate their privileges by exposing the backend of the application. The backend remained accessible, enabling the actors to override all user permissions and to create new accounts. This then allowed the actors to grant themselves permissions within the victim’s system without administrative approval while deleting other users. Black Basta exploited this vulnerability to infiltrate its victim’s system and deploy post-exploitation tools; it then performed reconnaissance and privilege escalation before deploying the ransomware. Similarly, Bl00dy leveraged this vulnerability to propagate in the target network and deploy ‘Conti’ and ‘LockBit’ ransomware files.

The Russian state-sponsored threat group APT29 is now using more refined techniques to compromise victims via their cloud infrastructure. The group has shifted its tactics, techniques and procedures (TTPs) to target companies’ cloud-based environments in an effort to increase its attack vectors. The newly employed techniques include password- and authentication-related attacks to infiltrate the victim’s system. Most notably, the threat actors targeted service accounts with brute-force and password spraying attacks, attempting to force their way into a user’s account by repeatedly trying to guess their password. They also adopted ‘Multifactor Authentication (MFA) Bombing’ techniques to trick victims into confirming their identifies by flooding them with authentication requests. After gaining access to the target system, the actors register their own device as a new device on the cloud instance. This then enables them to deploy sophisticated tools, such as ‘MagicWeb’, in order to carry out espionage activities.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Apply patches to software vulnerabilities as soon as they are released to prevent exploitation
  • Monitor devices and networks for suspicious activity
  • Create an accurate inventory of all serviced and dormant accounts and enforce regular auditing
  • Add available Indicators-of-Compromise (IoCs) to the organisation’s security detection systems to detect potentially malicious samples on the network
  • Ensure adequate security detection measures are in place, particularly behaviour-based end-point detection and response (EDR) solutions

Word(s) of the week

Our cyber word(s) of the week: Buffer overflow attack  (Source: Sibylline)

————————————————————————-

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

 

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

————————————————————————-

  • « Go to Previous Page
  • Page 1
  • Interim pages omitted …
  • Page 4
  • Page 5
  • Page 6

Primary Sidebar

Advertisers

  • Pythia
  • Teledyne
  • Exensor
  • Visit the Oxley website
  • Blighter
  • SPECTRA
  • Britbots logo
  • Faun Trackway
  • Systematic
  • CISION logo
  • ProTEK logo
  • ProTEK logo
  • ssafa logo
  • IEE
  • EXFOR logo
  • sibylline logo
  • Team Thunder logo
  • Comtech logo
  • GoExporting logo
  • ECHODYNE logo
  • Supercat logo
  • Galvion logo
  • Leonardo DRS logo
  • MTC logo
  • IDC logo
  • DSEI logo
  • DVD2024 logo
  • SDSC logo
  • TELEDYNE FLIR logo
  • VeteranUK logo
  • Matrix Space logo
  • ST Engineering logo
  • EWS logo
  • sentinel photonics logo
  • capua logo
  • Curtiss-Wright logo
  • Brave1 logo
  • Drone Evolution logo
  • AEI Systems logo
  • EOS logo
  • NMSUK logo
  • Openworks logo
  • Sandown Park logo
Hilux UKDSE AARTOS ST Engineering Future Artillery

Contact Us

BATTLESPACE Publications
41 St Georges Drive
London SW1V 4DG

+44 (0)77689 54766

BATTLESPACE Technologies

An international defence electronics news service providing our readers with up to date developments in the defence electronics industry.

Recent News

  • Protek Selected By Dutch Armed Forces

    May 2, 2026
    Read more
  • PARLIAMENTARY QUESTIONS

    May 1, 2026
    Read more
  • MANAGEMENT ON THE MOVE

    May 1, 2026
    Read more

Copyright BATTLESPACE Publications © 2002–2026.

This website uses cookies to improve your experience. If you continue to use the website, we'll assume you're ok with this.   Read More  Accept
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT