• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • SPECTRA banner
  • Curtiss-Wright banner

BATTLESPACE Updates

   +44 (0)77689 54766
   

  • Home
  • Features
  • News Updates
  • Defence Engage
  • Company Directory
  • About
  • Contact

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

January 19, 2024 by

 

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

————————————————————————

19 Jan 24. Global: Politically-motivated influence operations elevate espionage risks to government entities. On 18 January, the Threat Analysis Group (TAG) at Google reported that a Russian threat group, ‘ColdRiver’, is using proprietary malware (‘Spica’) to conduct cyber espionage campaigns against Ukraine, NATO member states, academic institutions and NGOs. This campaign sends an encrypted PDF file to prompt the user to request a new file link, which installs Spica malware on the machine. The malware is capable of executing shell commands, stealing cookies from browsers, uploading and downloading files and exfiltrating documents. Although TAG discovered Spica in September 2023, it has likely been used since November 2022. This is the first instance of ColdRiver using proprietary malware, indicating the group’s developing sophistication. The group’s capacity to leak sensitive information in political influence operations will almost certainly drive heightened risks to governmental entities, particularly for the UK and US ahead of their 2024 elections. (Source: Sibylline)

 

18 Jan 24. Cyber Update Key points.

  • There was a reported 61,839% year-on-year (y/y) increase in HTTP-based distributed denial-of-service (DDoS) attacks targeting the environmental services industry in 2023 (see Sibylline Cyber Daily Analytical Update – 15 January 2024).
  • Two zero-day vulnerabilities in Ivanti software are being exploited by a variety of threat actors seeking to disrupt critical infrastructure operations (see Sibylline Cyber Daily Analytical Update – 16 January 2024).
  • The cyber security company CyberInt reported a 55.5% increase in ransomware attacks in 2023 compared to 2022 (see Sibylline Cyber Daily Analytical Update – 17 January 2024).
  • US government entities warned users about the ‘Androxgh0st’ malware being used by threat actors to exploit victim networks (see Sibylline Cyber Daily Analytical Update – 18 January 2024 and our Technical analysis below).
  • Finally, a Russian threat actor, ‘ColdRiver’, is using new malware to target NATO entities, among other sectors, in politically-motivated influence operations (see Sibylline Cyber Daily Analytical Update – 19 January 2024).

Technical analysis of weekly stories

The Androxgh0st malware is being used by threat actors to establish a botnet to identify potential victims and exploit target networks. It is a Python-based malware used to target environment files (.env) that contain sensitive credentials for high-profile applications including Amazon Web Services (AWS), Microsoft Office 365, SendGrid and Twilio. It is also capable of abusing Simple Mail Transfer Protocol (SMTP) to scan for and exploit exposed credentials and application programming interfaces (APIs). The malware searches for web servers by exploiting vulnerabilities in Apache HTTP server versions (2.4.49 or 2.4.50), as well as vulnerabilities in the Laravel web application framework and PHPUnit. Once an actor obtains stolen credentials via these methods, they will likely then use the information to access sensitive data and/or conduct further malicious operations.

Non-exhaustive recommendations to mitigate against this threat include:

  • Monitoring devices and networks for suspicious activity
  • Adding available Indicators-of-Compromise (IoCs) to the organisation’s security detection systems to detect potentially malicious samples on the network
  • Ensuring there are adequate security detection measures in place, including end-point detection and response (EDR) solutions (such as anti-virus software)
  • Conducting cyber hygiene awareness courses for users to enable them to recognise and report phishing attempts
  • Applying patches to existing software vulnerabilities as soon as they are released to prevent avoidable exploitation

Frequency of TTPs during this monitoring period: LOW frequency, MODERATE frequency, HIGH frequency

The MITRE ATT&CK framework is a globally accessible documented collection of information detailing the malicious behaviours of cyber threat actors; it is used as the foundation for organising the processes which threat actors execute during cyber operations. It provides an encyclopaedic reference for organisations, highlighting the tactics, techniques and procedures (TTPs) cyber actors employ in campaigns, while also providing suggestions for detecting and mitigating against specific TTPs to bolster organisations’ security mechanisms. The framework organises a threat actor’s entire operational lifecycle from reconnaissance to exfiltration and impact.

Word(s) of the week

Our cyber word(s) of the week: Lateral movement

(Source: Sibylline)

 

18 Jan 24. NuHarbor Security Releases New Report on SLED Leader Strategies to Bolster Cyber Defenses. State, local, and education (SLED) organizations are often mistakenly overlooked in the cybersecurity landscape, in spite of their critical role protecting the votes, services, and information of every citizen in the country. NuHarbor Security, trusted managed security provider to hundreds of clients in both the public and private sectors, has released the second annual edition of the unique SLED Cybersecurity Priorities Report (CPR), highlighting the latest trends among leaders and innovators in this crucial sector.

The research and report, led by Executive Director Curt Wood, former CIO of the Commonwealth of Massachusetts, share the stories of SLED IT leaders and describe new approaches and best practices to deliver actionable insights for individuals and agencies that serve constituents in every college, county, city, and state.

The 2023-2024 SLED Cybersecurity Priorities Report is the only report dedicated to the unique challenges and perspectives of the SLED community. The report features interviews with prominent CIOs, CISOs, security directors, technology executives, and cybersecurity experts from across the country. The report explores approaches to implementing Whole-of-State cybersecurity frameworks, retaining and developing cybersecurity talent, making decisions about cyber insurance, and more.

“The response to last year’s inaugural SLED CPR was positive and constructive, and we want to keep that conversation going,” said Justin Fimlaid, CEO and Founder of NuHarbor Security. “This latest edition signifies our continued commitment to working with, serving, and learning from SLED organizations.”

The report combines NuHarbor’s experience with data from Splunk, Zscaler, and Recorded Future to highlight the SLED sector’s unique challenges and potential solutions, such as:

  • 37% of states experienced a reduction in cybersecurity funding
  • 57% of leaders plan to offer or leverage Whole-of-State cybersecurity services
  • 71% of leaders cite hiring challenges in building security teams
  • 42% are considering self-insuring against attacks rather than purchasing cyber insurance

“Having focused discussions with SLED leaders is the only way to illuminate their unique challenges with both cybersecurity and cybersecurity solutions,” said Jack Danahy, Vice President of Strategy and Innovation at NuHarbor Security. “In both last year’s research and this year’s report, it’s clear that success is less about shiny new cybersecurity tools and more about thoughtful strategies that are appropriate for this community to adopt as they address these unique challenges.”

“We all thrive when we share our successes and our concerns, and the openness of our community separates it from the competitive commercial environments,” said Wood. “During my time in the public sector, I’ve seen these strategies advance because of idea sharing, and to produce this report as a means of continuing those conversations is a gratifying way to keep contributing to the SLED community.”

Download the full report to see complete findings and better understand the latest trends in the SLED community: https://www.nuharborsecurity.com/annual-sled-cpr

About NuHarbor Security

NuHarbor is an established national cybersecurity services firm, combining experience from a portfolio of hundreds of clients with the very best security technologies available. We deliver white glove, managed security programs that are the most comprehensive in the market from compliance to premium 24×7 security operations coverage. We make cybersecurity stronger and easier for our clients in state and local government, higher education, finance, healthcare, and insurance, helping them better understand and protect themselves. Learn more at nuharborsecurity.com. (Source: BUSINESS WIRE)

 

18 Jan 24. Huge boost for global security with almost £1bn government investment. The UK benefited from £830m in the 2022-23 financial year delivering programmes and peacekeeping in more than 90 countries to bolster global security.

The Conflict, Stability and Security Fund’s (CSSF) investment delivers projects in Ukraine, Africa, the Indo-Pacific and the Overseas Territories among other places. Last year it more than doubled spending on cyber security programmes, with £25.5m spent on the Global Cyber Programme, the Africa Joint Operations Against Cyber Crime and bolstering the cyber defences Georgia, Iraq and elsewhere.

The Cabinet Office-led CSSF tackles the greatest threats to UK national security emanating from overseas, especially conflict, transnational threats and hostile state activity. The 2022 to 2023 CSSF Annual Report reveals how and where it spent money to tackle these global security challenges, such as assistance to Ukraine following the illegal invasion by Russia and countering Russian disinformation on the invasion.

The CSSF also plays a key role in strengthening UK and international partners’ cyber security by strengthening their cyber defences and supporting their fight against cyber-crime. For example the CSSF has also funded programmes in the Indo-Pacific region, delivering cyber exercises in Malaysia, Indonesia, and Japan to help test their response to a major national cyber attack.

Through the CSSF, the UK established a Ukraine Cyber Programme, providing £7.3m from the beginning of the invasion to March 2022. Following the IRR, funding for this programme will be increased by up to £25m, including £16 m from UK funding, and potential for a further £9m contribution from international allies.

Ukraine was the biggest single-state recipient of CSSF-funded Official Development Assistance, receiving £41 m, an increase from £23.5m in the 2021 to 2022 financial year.

Cabinet Office Minister for the CSSF Baroness Neville-Rolfe said: “From the Balkans to Latin America, the Indo-Pacific and beyond, the UK’s Conflict, Stability and Security Fund plays a vital role in keeping people safe both at home and abroad. Improving the cyber security of our international partners is vital to the preservation of the rules-based international system and so detecting, disrupting and deterring cyber threats across the globe has been central to the CSSF’s work.”

Other significant areas of spending included projects in Eastern Europe and Central Asia which accounted for around 14% of CSSF funding (£119.28m) and projects in Sub-Saharan Africa which accounted for almost 12% of CSSF funding (£98.57m). In Sub-Saharan Africa the CSSF’s investment has tackled the threat of violent extremists by working with counter terror organisations.

The CSSF also manages the UK government’s funding of peacekeeping operations and deployments and manages the Rapid Response Mechanism with peacekeeping efforts accounting for more than a third (36%) of its spending (£301.8m).

In March 2023, as part of the Integrated Review Refresh, the Prime Minister announced the CSSF would transform into a new fund: the Integrated Security Fund (ISF) from April 2024. The CSSF’s transition into the ISF will link up our domestic and overseas security to strengthen our ability to export world-leading expertise to international partners so we can tackle global challenges such as smuggling, illicit finances and large-scale migration.

The Cabinet Office-led CSSF brings together several government departments, including the FCDO, Home Office and Ministry of Defence. The FCDO was the single biggest spender of CSSF funding the 2022 to 2023 financial year; it accounted for 81.7% of total spend (£678.27m).

(Source: https://www.gov.uk/)

 

18 Jan 24. Global: Malware used to identify victims elevates risk to multi-stage cyber attacks for organisations. On 16 January, the US’ FBI and Cybersecurity and Infrastructure Security Agency (CISA) released a joint advisory warning users of the ‘Androxgh0st’ malware that threat actors use to exploit networks. Androxgh0st is used to support malicious activity in infected networks by establishing a botnet to identify potential victims to steal high-value credentials from before exploiting three existing software vulnerabilities (CVE-2017-9841, CVE-2018-15133 and CVE-2021-41773). Threat actors are then able to execute remote code, resulting in data loss, escalation of unauthorised privileges, lateral movement and the deployment of additional malware. A variety of threat actors use Androxgh0st for cyber operations, underscoring the risk it poses to firms for potential multi-layered attacks that can have operational, security, financial and reputational impacts. As the malware exploits existing vulnerabilities that have patches available, organisations can reduce their risk of exploitation by applying the relevant updates. (Source: Sibylline)

 

18 Jan 24. Estonia’s SensusQ restructures military intelligence with real-world impact.

SensusQ’s technology has demonstrated its effectiveness in transforming information processing during active military use.

Having attended a demonstration at the Estonian Embassy, I delved into the world of SensusQ, an Estonian-based company focusing on military intelligence. Their flagship technology, Winning Minds, has proven itself in active military scenarios.

Estonian-based SensusQ’s Winning Minds technology proves its effectiveness, transforming information processing in critical situations.

In the era of information overload, SensusQ emerges as a player for military intelligence, providing a 30% efficiency over traditional methods. The platform, already deployed in Ukraine, promises quicker decision-making, enhanced security, and the prevention of intelligence failures.

In an age where data overwhelms traditional military intelligence methods, the misconceptions fuelled by Hollywood glamorising intelligence work are shattered by the reality of painstaking manual processes reminiscent of the 1990s. SensusQ’s Winning Minds technology aims to propel military intelligence into the 21st century, converting data into actionable insights.

Addressing military needs in Ukraine

SensusQ addresses the need for data conversion in high-pressure military environments. “Every step of the way that I’m showing here is saving, you know, 10-15% of time from each operation,” explains Erik Markus Kannike, CSO at SensusQ. Unlike fictional depictions, the reality involves crafting of reports using outdated tools.

While specifics on individual cases remain confidential, Estonian-based SensusQ’s tools actively contribute to enhancing military intelligence in Ukraine. “In Ukraine, we’re working with the Ukrainian border guards. They use our platform for various capabilities, from making sense of the world to strategic communications, providing valuable support without compromising sensitive information,” says Kannike.

Organisations safeguarding lives and the country benefit from the platform’s ability to streamline data processes, making a tangible difference in situations.

Setting SensusQ apart

“SensusQ’s technology is designed to transcend borders, contributing to military intelligence wherever it is crucial,” emphasises Kannike. The company prioritises strengthening NATO states and allies and conducting background checks to ensure ethical collaboration.

SensusQ tries to set itself apart with a unique approach, emphasising keeping sensitive data in end-users hands and integrating with existing military drills. “It’s an open API. If they have their own camera systems, it can be literally everything,” states Kannike, differentiating from competitors such as Palantir and Helsing.

“In this sector, there’s a certain challenge, and training data is quite hard to come by,” admits Kannike. However, Estonian-based SensusQ provides on-premises operations, ensuring sensitive data remains under the client’s control. This approach alleviates concerns about data security and access.

Estonia’s proactive defence modernisation

To bolster its defence capabilities, the Estonian Ministry of Defence has pursued modernisation programmes on a limited budget, collaborating with allies and focusing on IoT and unmanned systems technologies.

Notable examples include Cybernetica’s contributions to the European Cyber Situational Awareness platform and MilRem Robotics’ joint procurement contract for multi-role unmanned ground vehicles. As the European geopolitical security landscape evolves, Estonia’s proactive approach positions it as a dedicated partner in the European defence market.

Proven impact on military operations

“SensusQ is working on self-explainable and transparent AI, aligning with NATO standards,” reveals Kannike. The company carefully vets potential customers to ensure their intentions align with ethical standards, emphasising responsible data handling.

“Founded by military veterans with real-world experience in Iraq and Afghanistan, SensusQ brings a depth of knowledge and practical understanding to military needs,” shares Kannike. The platform aims to avert future conflicts and prevent intelligence failures, ultimately supporting global security and peace.

“SensusQ’s impact is not confined to theory,” notes Kannike; it’s actively utilised by the Estonian Defence League, providing practical solutions in real-world scenarios. The company collaborates closely with military units, attending major training exercises to refine and enhance its platform continually.

Estonia has unveiled a decade-long military strategy, surpassing NATO guidelines with a commitment to a $1.3bn (€1.2bn) defence budget by 2028, according to GlobalData’s intelligence on the Estonian defence market. This proactive response to regional threats, primarily from Russia, reflects Estonia’s dedication to fortifying sovereignty.

Collaborating with NATO, the EU, and Baltic partners, Estonia’s multifaceted approach underscores collective security amid shared regional challenges, aligning with a ten-year development plan. Despite challenges, strategic collaborations position Estonia for military strength and resilience. Estonian-based companies, such as SensusQ, are pushing the Estonian defence market further in the role that Estonia plays within geopolitical dynamics.

Looking ahead

SensusQ’s future plans involve scaling operations, delivering on a larger scale in Ukraine, expanding to Poland, and entering the US market,” outlines Kannike. The company envisions becoming the standard system in NATO and preventing tragic intelligence failures in allied countries.

It offers a fully functional product with on-premise operations to ensure reliability.

“For deep tech and sector-specific investors, SensusQ presents a unique opportunity,” says Kannike, “with diverse revenue streams, stable growth potential, and a team boasting expertise in both military and IT sectors.”

SensusQ emerges as an industry player in the military intelligence landscape, challenging outdated processes and offering tangible solutions for the challenges of the 21st century. With a focus on efficiency, security, and ethical use, SensusQ stands ready to try and shape the future of military intelligence. (Source: naval-technology.com)

 

17 Jan 24. Cigent Approved for Securing Government and Military Data, Added To NSA Commercial Solutions For Classified (CSfC) Components List. Cigent® Technology, Inc., the leader in embedded cybersecurity in storage devices, today announced that its pre-boot authentication software has been approved for inclusion on the National Security Agency Central Security Service (NSA/CSS) components list for the Commercial Solutions for Classified (CSfC) program.Cigent’s Pre-Boot Authentication (PBA), a key element in the Cigent Data Defense™ platform, is now available for use by agencies seeking the highest data security for classified Data at Rest stored in laptops, desktops, and other devices to avert compromise.

Cigent PBA brings a new level of security for endpoints containing classified data. The solution utilizes hardware-based full drive encryption (FDE). What makes this solution different, however, are the capabilities that enable Cigent PBA to lock down data ranges on the drive firmware itself, protecting the encrypted data at rest (DAR) from being accessed, cloned, wiped, or viewed, even by disk utilities or other methods.

Beyond the CSfC requirements, the Cigent Data Defense™ platform includes additional data security capabilities to protect classified data. These include creating up to 8 hidden drive partitions, complete erasure verification, nefarious insider threat logging, and automated threat response, all built directly into the drive. These capabilities are available from Cigent Ready partners whose secure SSD drives are also on the CSfC components list. As a result, government customers can now take advantage of these unique capabilities.

“The CSfC listing of Cigent’s PBA software is highly valued by our customers, who require CSfC data storage solutions to protect their sensitive information,” said Randal Barber, CEO of CDSG. “The Cigent PBA solution is an integral part of our own CSfC-listed DIGISTOR Citadel C Series secure SSDs that are sought after to prevent unauthorized access to mission-critical and other confidential data.”

The CSfC program enables agencies to utilize commercial products in specific configurations to protect classified data. Commercial products must undergo stringent evaluations and be selected for inclusion on the NSA’s approved components List. CSfC certification enables military and government agencies to procure and deploy the technology they need to secure their sensitive endpoint data.

“This CSfC approval by NSA/CSS enables government entities to achieve the highest levels of data security, enabling fundamental CSfC requirements and also Zero Trust storage access controls, complete erasure verification, nefarious insider threat detection, and protection against advanced attacks that go undetected by existing endpoint protections,” said Tom Ricoy, Chief Revenue Officer at Cigent. “We are very pleased to receive this certification and enable government entities to fully protect, hide, and destroy classified and sensitive data at the individual storage level.” (Source: BUSINESS WIRE)

 

17 Jan 24. Northrop Grumman Corporation (NYSE: NOC) continues to pioneer the latest mobile ground station technology for the frontline with its recently awarded Maritime Targeting Cell – Expeditionary (MTC-X) contract. This program supports the Department of Defense’s strategy for its Joint All-Domain Command and Control (JADC2) mission to conduct multi-domain operations by providing critical data to the frontline.

The MTC-X mobile prototype system will:

  • Deliver multi-domain data for forward-deployed units and individual warfighters far from established bases;
  • Fully integrate data from multiple assets into a single mobile system;
  • Reduce sensor-to-shooter timelines and maximize the effectiveness of long-range precision fires; and
  • Allow for rapid assembly for quick and agile maneuverability with ground forces.

Expert:

Pablo Pezzimenti, vice president, integrated national systems, Northrop Grumman: “We designed this innovative technology for warfighters in situations where mobility is crucial for mission execution. This platform provides the latest multi-domain data at their fingertips, allowing commanders to make the best decisions possible for any mission on land, air or sea.”

Details on MTC-X:

The MTC-X mobile prototype development is a modification to an existing Maritime Targeting Cell – Afloat (MTC-A) program’s Indefinite Duration, Indefinite Quantity (IDIQ) contract. The mobile prototype supports the U.S. Marine Corps Force Design 2030 by delivering information that enables critical decision-making for mission specific needs with resiliency.

 

17 Jan 24. Global: Emerging ransomware actors expand threat landscape, elevating financial risks for firms. The security company CyberInt reported this month that the number of ransomware victims increased by 55.5% in 2023. ‘Lockbit 3.0’ continues to threaten global businesses; it conducted 1,047 of 4,368 ransomware attacks in 2023. Although groups such as ‘ALPHV’, ‘Cl0p’ and Lockbit 3.0 will continue to threaten businesses in 2024, emerging ransomware groups will widen the attack landscape. Of these emerging groups, ‘3AM’, ‘Rhysida’ and the ‘Akira Group’ were noted as key threat actors impacting business continuity. While 3AM’s activity was limited in 2023, it was used as a back-up during an attack conducted by a Lockbit 3.0 affiliate after the group was blocked from a targeted network. This points to a possible increase in the use of ransomware as an effective alternative during affiliate ransomware-as-a-service (RaaS) operations. Similarly, Rhysida’s high-profile attacks in 2023 and the Akira Group’s connection to the defunct Conti ransomware group will elevate disruption and financial risks for businesses throughout 2024., (Source: Sibylline)

 

17 Jan 24. OpenAI removes ban on military use of AI tools for national security scenarios. The move follows OpenAI forming a team, in October 2023, to combat “catastrophic risks” arising from the development of AI models. OpenAI has deleted part of its terms and conditions which prohibited the use of its AI technology for military and warfare purposes. An OpenAI spokesperson told Verdict that while the company’s policy does not allow its tools to be used to harm people, develop weapons, for communications surveillance, or to injure others or destroy property, there are, however, national security use cases that align with its mission.

“For example, we are already working with DARPA to spur the creation of new cybersecurity tools to secure open source software that critical infrastructure and industry depend on,” said the spokesperson adding: “It was not clear whether these beneficial use cases would have been allowed under “military” in our previous policies. So the goal with our policy update is to provide clarity and the ability to have these discussions.”

The ChatGPT maker’s usage policy initially included a ban on any activity that included “weapons development” and “military warfare”.

However, the new update that went live on 10 January, did not include the ban on “military and warfare”.

OpenAI left the blanket ban on using the service “to harm yourself or others” with an example included of using AI to “develop or use weapons”.

“We’ve updated our usage policies to be more readable and added service-specific guidance,” OpenAI said in a blog post.

“We cannot predict all beneficial or abusive uses of our technology, so we proactively monitor for new abuse trends,” the blog post added.

Sarah Meyers, managing director of the AI Now Institute, told the Intercept that AI being used to target civilians in Gaza makes now a notable time for OpenAI to change their terms of service.

Fox Walker, analyst at research company GlobalData, told Verdict that the new guidelines “could very well lead to further proliferation of AI use in defence, security, and military contexts.”

“Whether it be the use of non-lethal technology, the development of military strategy, or simply the use of budgeting tools, there are many areas where AI can assist military leaders without causing harm to others or creating new weapons,” Walker said.

In October, OpenAI formed a new team to monitor, predict, and try to protect against “catastrophic risks” posed by AI such as nuclear threats and chemical weapons.

The team, named Preparedness, will also work to counter other dangers such as autonomous duplication and adaptation, cybersecurity, biological, and radioactive attacks, as well as targeted persuasion.

In 2022, OpenAI researchers co-authored a study which flagged the risks of using large language models for warfare.

An OpenAI spokesperson previously said: “We believe that frontier AI models, which will exceed the capabilities currently present in the most advanced existing models, have the potential to benefit all of humanity. But they also pose increasingly severe risks”

Research company GlobalData estimates the total AI market will be worth $383.3bn in 2030, implying a 21% compound annual growth rate between 2022 and 2030. (Source: army-technology.com)

 

17 Jan 24. UK Government strengthens UK-Japan partnership on cyber.

A new partnership between Japan and the UK will strengthen the UKs strategic approach to cyber. Today the two countries have agreed to a Memorandum of Cooperation to deepen public-private partnerships in cyber between the UK and Japan.

The Memorandum was signed during the course of a three-day visit to the UK from Japan’s Keidanren Cyber Security Committee, hosted by the National Cyber Advisory Board (NCAB).

Co-chaired by Deputy Prime Minster, Oliver Dowden, and Chief Information Officer at Lloyds Banking Group, Sharon Barber, NCAB was formed in 2022 to bring together leaders from academia and industry. The group aims to present alternative viewpoints and harness networks from across the cyber ecosystem, supporting delivery of the National Cyber Strategy.

Signing the Memorandum on behalf of the UK, Deputy Prime Minister and Chancellor of the Duchy of Lancaster, Oliver Dowden said,

Cyber is the new frontier. To ensure we remain at the forefront of cyber strategy we must continue to work with democratic partners who share our values”.

Japan is an important friend and ally, sharing our beliefs on areas such as rule of law, climate change and human rights. This latest partnership further strengthens our relationship with Japan following the signing of the Hiroshima Accord and promotes collaboration across the public and private sector, strengthening our economy and demonstrating the UK Government’s commitment to making long-term decisions to secure our future.

The Japanese delegation met with key figures from the public sector alongside industry experts including senior representatives from IBM and Sharon Barber, Chief Information Officer at Lloyds Banking Group, to discuss securing digital supply chains, engaging businesses on cyber resilience and best practice recruitment to increase cyber skills across both countries.

This builds on the UK and Japan’s work together to strengthen our shared values of democracy, rule of law and free and open trade. In May 2023 the UK and Japan signed the Hiroshima Accord committing to an enhanced Global Strategic Partnership on issues such as global security, resilience and climate change.

Signing on behalf of Japan, Dr. Nobuhiro Endo commented, “Based on this MoC, Keidanren is determined to further deepen and broaden bilateral cooperation between our public and private sectors. From the perspective of co-creating a data-driven society, we hope to continue to discuss safe and secure use of digital technologies including AI.”

Co-chair of NCAB, Sharon Barber commented, “Close collaboration between government and industry is at the heart of NCAB. The Memorandum of Cooperation between the UK and Japan is a significant further step on our journey and one which will help both nations further mature their private-public partnerships on cyber, and ultimately support the delivery of each nation’s cyber security strategy.” (Source: https://www.gov.uk/)

 

16 Jan 24. Global: Exploitation of zero-day vulnerabilities in software firm’s appliances drives operational, security risks. On 15 January, threat intelligence company Volexity reported that two zero-day vulnerabilities in Ivanti’s Connect Secure VPN and Policy Secure network access control appliances were undergoing mass exploitation by threat actors. These vulnerabilities, identified as CVE-2023-46805 and CVE-2024-21887, have reportedly been exploited since December 2023. Victims of the attacks include government actors and companies from the military, telecommunications, defence, technology, finance, consulting and aerospace sectors. The attacks aim to infiltrate and possibly disrupt critical infrastructure operations and sensitive sectors. The attackers use a GIFTEDVISITOR webshell variant, compromising over 1,700 Industrial Control System VPN appliances worldwide. The exposure of these vulnerabilities online has escalated the impact of the attacks, with multiple threat actors, including suspected Chinese state-backed groups, participating. As Ivanti has not yet released patches for these vulnerabilities, the number of companies impacted by these attacks will likely increase. (Source: Sibylline)

 

16 Jan 24. EU launches Nostradamus and prepares Europe for a quantum world.

  • Deutsche Telekom-led consortium responsible for building EU’s quantum communications testing infrastructure.
  • Partners are Thales and the AIT Austrian Institute of Technology
  • EU is strengthening the protection of its communications networks, data centers and critical infrastructure.
  • Quantum communications to form critical pillar of Europe’s security architecture.

Europe is giving the go-ahead for the next technological leap for secure digitalization. The European Commission has commissioned a consortium (“Nostradamus”) led by Deutsche Telekom to build the testing infrastructure for quantum key distribution (QKD). This will enable the evaluation of European manufacturers’ QKD devices. Partners in the consortium are Thales, global leader in advanced technologies, the AIT Austrian Institute of Technology, as well as experts from across industry and academia. This paves the way for the implementation of EuroQCI – a highly secure pan-European communication network based on quantum technology. The governments of all EU member states and their citizens stand to benefit from more secure critical infrastructure.

The goal is the development of European Quantum Communication Infrastructure (EuroQCI). It is intended to provide more security for data centers, communications networks and critical infrastructure such as hospitals and power plants – via fiber optics and satellite. Quantum physics provides additional protection against new threats for today’s communication networks. The use of quantum technology is a key pillar of the EU’s strategy for cyber security in the coming decades.

EU satellite transmission to rely on quantum technology

The future encrypted EU satellite network IRIS2 (Infrastructure for Resilience, Interconnectivity and Security by Satellite) also relies on EuroQCI. It is intended to provide governments with communication services and network critical infrastructure. In future, IRIS2 will also provide companies and organizations with fast satellite internet. After Galileo for navigation and Copernicus for earth observation, IRIS2 is the third pillar of the EU’s space infrastructure. The EU gave the green light for IRIS2 last year. The first services are due to be launched this year. Full operation is planned for 2027.

Daniela Theisinger, Managing Director of Deutsche Telekom Global Business Belgium, explains: “Nostradamus exemplifies Deutsche Telekom’s commitment to pushing the boundaries of digital security. This collaborative effort not only enhances European cybersecurity but also underscores the importance of strategic partnerships in advancing technological resilience.”

Joan Mazenc, Head of Thales ITSEF (IT Security Evaluation Facility), says: “Thales is particularly proud to contribute to the protection of the EU communications networks and infrastructure. As a leader in advanced technologies, the Group is determined to develop an attack laboratory aimed at responding to quantum threats. This laboratory will identify methods for evaluating ground-based quantum key devices, based on fiber optic technology.”

Helmut Leopold, Head of Center for Digital Safety & Security at AIT, explains: “In addition to the quantum technology know-how at the AIT Austrian Institute of Technology, a high level of expertise is required to test and verify new and innovative products, processes and tools. This demands a close collaboration between research and industry and a fundamental understanding of quantum encryption and IT security. We are proud to bring together world-leading expertise to pave the way for the market introduction of advanced security products to support Europe’s digital sovereignty.”

About Quantum Key Distribution

Quantum Key Distribution uses the principles of quantum mechanics to secure communication. The keys for decoding information are sent using single photons (quantum light particles). Any attempt to intercept these photons leaves traces in their physical state and can be used to indicate possible eavesdropping. This technology ensures fundamentally secure data exchange. QKD represents the pinnacle of cyber security.

About Thales

Thales (Euronext Paris: HO) is a global leader in advanced technologies within three domains: Defence & Security, Aeronautics & Space, and Digital Identity & Security. It develops products and solutions that help make the world safer, greener and more inclusive.

The Group invests close to €4bn a year in Research & Development, particularly in key areas such as quantum technologies, Edge computing, 6G and cybersecurity.

Thales has 77,000 employees in 68 countries. In 2022, the Group generated sales of €17.6bn.

About AIT Austrian Institute of Technology

Over the past decade, AIT has gained an excellent international reputation as a specialist in both terrestrial and satellite-based quantum cryptography and as a coordinator of major European projects, such as the project “OpenQKD” as well as a strong partner in several highly competitive European “Quantum Flagship” projects. Currently, the work of quantum researchers is focused in particular on the miniaturization of the devices required for quantum communication with the aims to develop quantum technologies for the mass market. Together with other European partners, AIT coordinates the EU-funded EuroQCI project QCI-CAT which aims to establish a quantum communication network within Austria. Further information: https://qci-cat.at/ and https://www.ait.ac.at/en/dss.

 

15 Jan 24. US Navy upgrading 5G network and asset tracking in Indo-Pacific. The US Navy is upgrading its 5G cellular network and asset tracking in the Indo-Pacific under a new $10m contract with American military contractor Booz Allen Hamilton.

The company will lead the contract to design, implement, test, and operate a private 5G cellular network and asset tracking solution in Guam under the two-year agreement, according to a public statement on 11 January.

The private 5G network will support mobile and fixed wireless access, with architecture capable of extending to future use cases. The network will service Pearl Harbor Naval Shipyard and Intermediate Maintenance Facility, Detachment Naval Base Guam.

“This project win further solidifies our position as a key 5G innovator and integrator,” according to Chris Christou, Booz Allen senior vice-president and 5G, cloud, and edge portfolio leader.

“Booz Allen’s experience delivering 5G solutions to the Navy uniquely positions the firm to bring new, innovative solutions to the complex challenges facing the Indo-Pacific region.

“Geographically dispersed landscapes like the Indo-Pacific require next-generation network solutions capable of achieving all domain command and control.

“We are confident in our solutions’ ability to overcome the obstacles that distributed, edge-like environments like Guam present.”

The US Navy and US Department of Defense expects the new upgrades to maximise mission success in the region by providing technology to improve communication, logistics, maintenance and secure operations. It’s also expected that the 5G network will further enable the United States, its partners, and allies to compete responsibly and defend interests in the region.

The technical approach for the project is expected to integrate lessons learned from ongoing Department of Defense 5G projects to ensure maximum efficiency and apply zero trust design principles to secure NBG’s 5G infrastructure. Booz Allen will leverage robust RFID asset tagging on equipment and inventory to better enhance and modernise US Navy logistics capabilities.

“Booz Allen is excited to be chosen as a strategic partner and solution provider to help design, implement, test, and operate a private 5G network at the Naval Base Guam,” according to Jandria Alexander, Booz Allen vice-president and cyber security and cross-market technology innovation business leader.

“The deployment of secure 5G capabilities in Guam is critical to national security and aligns with the Navy’s 5G strategy.

“Through the successful implementation of this effort, Guam Naval Base will be establishing a strong foundation that accelerates transformation efforts in telecommunications, asset tracking, and future initiatives and use cases.” (Source: Defence Connect)

 

15 Jan 24. Global: Intensified DDoS attacks will heighten data security, operational risks throughout 2024. In a report published earlier on 15 January, Cloudflare (a cloud cyber security firm) claimed that there was a 61,839% year-on-year (y/y) increase in HTTP-based distributed denial-of-service (DDoS) attacks targeting the environmental services industry. Additionally, Cloudflare noted a 1,126%, rise in DDoS attacks against Palestinian websites and a 3,370% surge in attacks targeting Taiwan amid its recent presidential election and escalating tensions with China. A report by Akamai (another cyber security firm) on 2023 DDoS Trends corroborates these findings, noting an increase in the frequency, duration and sophistication of attacks. The global DDoS threat will likely intensify throughout 2024, with sectors such as healthcare, finance and government facing the highest risks due to their storage of sensitive information. It is also likely that cyber threat actors will capitalise on rising geopolitical and environmental tensions to target organisations related to high-profile issues. (Source: Sibylline)

 

12 Jan 24. Global: State-backed actor expands attacks against government entities, driving data security risks. In an 11 January report, the cyber security firm SecurityScorecard highlighted that the Chinese state-sponsored advanced persistent threat (APT) group ‘Volt Typhoon’ has escalated its activities to target government entities in Australia, the UK and the US. The group typically exploits old vulnerabilities in Cisco routers. Over a 37-day period, Volt Typhoon likely compromised approximately 325 of 1,116 RV320/325 VPN routers. The APT’s tactics, techniques and procedures (TTPs) involve using these routers for covert data transfer and command-and-control communications. SecurityScorecard’s investigation revealed a shift in Volt Typhoon’s infrastructure and the deployment of a new shell file in the attacks. The analysis also identified additional IP addresses linked to Volt Typhoon’s activities, with connections from 27 IP addresses hosting 69 government sites across Australia, India, the UK and the US. This points to an expansion in the group’s targeting scope, as well as heightened data security risks facing organisations and government entities globally, particularly those in Western countries (the distribution of the compromised devices is heavily concentrated in these regions). (Source: Sibylline)

————————————————————————-

 

Spectra Group (UK) Ltd

 

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

 

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

————————————————————————-

Primary Sidebar

Advertisers

  • Pythia
  • Teledyne
  • Exensor
  • Visit the Oxley website
  • Blighter
  • SPECTRA
  • Britbots logo
  • Faun Trackway
  • Systematic
  • CISION logo
  • ProTEK logo
  • ProTEK logo
  • ssafa logo
  • IEE
  • EXFOR logo
  • sibylline logo
  • Team Thunder logo
  • Comtech logo
  • GoExporting logo
  • ECHODYNE logo
  • Supercat logo
  • Galvion logo
  • Leonardo DRS logo
  • MTC logo
  • IDC logo
  • DSEI logo
  • DVD2024 logo
  • SDSC logo
  • TELEDYNE FLIR logo
  • VeteranUK logo
  • Matrix Space logo
  • ST Engineering logo
  • EWS logo
  • sentinel photonics logo
  • capua logo
  • Curtiss-Wright logo
  • Brave1 logo
  • Drone Evolution logo
  • AEI Systems logo
  • EOS logo
  • NMSUK logo
  • Openworks logo
  • Sandown Park logo
Hilux UKDSE AARTOS ST Engineering Future Artillery

Contact Us

BATTLESPACE Publications
41 St Georges Drive
London SW1V 4DG

+44 (0)77689 54766

BATTLESPACE Technologies

An international defence electronics news service providing our readers with up to date developments in the defence electronics industry.

Recent News

  • Protek Selected By Dutch Armed Forces

    May 2, 2026
    Read more
  • PARLIAMENTARY QUESTIONS

    May 1, 2026
    Read more
  • MANAGEMENT ON THE MOVE

    May 1, 2026
    Read more

Copyright BATTLESPACE Publications © 2002–2026.

This website uses cookies to improve your experience. If you continue to use the website, we'll assume you're ok with this.   Read More  Accept
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT