Sponsored by Spectra Group
————————————————————————
08 Feb 24. Inside the top secret world of UK defence intelligence.
Forces News reporter Sian Grzeszczyk was invited into the secret world of UK defence intelligence. This is what she found.
“It’s the jewel in our crown. We call it the newsroom,” one defence official proudly told us.
I was among a small group of the UK’s defence correspondents and we were taking a closer look at the giant “floor plate” as they call it, a vast open plan windowless office with clusters of intelligence analysts busy at work.
We were in the Pathfinder building at RAF Wyton in Cambridgeshire, a site steeped in history, where the first sorties were flown just 90 minutes after WW2 was declared.
In 2024 it is a tri-service base and the Pathfinder building is the biggest defence intelligence centre in the UK.
After handing over our phones and laptops and agreeing not to name anyone we met to protect their identities, we were escorted through the main entrance, passing through the floor-to-ceiling security tube scanners and directed upstairs to what looked like a boring conference room.
Strangely we were told not to take a seat at the large conference table.
Some did, but they realised very quickly why we had been told to remain standing.
All of a sudden a button was pressed which revealed secret screens that transformed into large windows on a world hardly ever seen by anyone without top secret clearance.
Small red lights had been turned on across a series of pillars and walls down there. We were quick to ask what they were.
It was a warning to everyone hard at work that a bunch of journalists were not only in the building, but were watching them. Standard procedure when any visitors are around, we were told.
There was what looked like a real-time feed of a ship, but it was playing on a loop. The title of the video said the Port of Sudan.
Flags representing each of the single services were displayed, and outside the main building were the flags of the Five Eyes countries: the United States, Canada, Australia and New Zealand who also work alongside UK defence officials. These countries have shared intelligence since WW2.
We were told that any question on intelligence for defence comes here first. There was a mix of people wearing military uniforms and wearing plain clothes. Some 60% of staff here are military and 40% civilian.
Several hundred people work here. It is the biggest Five Eyes by design floorplate in the alliance.
There are day and night shifts where countries hand over to each other, enabling 24/7, 365 days a year intelligence cover.
Elsewhere we were taken to a hangar and beneath camo nets were shown a Russian Orlan 10 drone and a Shahed 131 Iranian drone used against the Ukrainians.
They revealed these are just two examples of weapons being analysed by defence experts in the UK to ascertain more about how they work. Both had been given to UK intelligence by the Ukrainians.
It is here at RAF Wyton that they collect, process and analyse intelligence.
For obvious reasons they are not an organisation that seeks the limelight, but their profile was elevated when they made the decision to start tweeting about the Russian invasion of Ukraine early in 2022.
The “newsroom” was a hive of activity in the run-up to Russia’s invasion.
For most of what they do success depends on maintaining the secrecy of their operations and capabilities. So why did they let us in?
They said they believe it is important to share what they can about who they are and how they go about their missions. The public, they feel, should have an appropriate understanding of this secret part of defence and what they do to help protect the nation.
They shared real-life examples of how they contribute to the UK’s national security. Many of those we met gave us examples of things they said they were proud of.
We met one operative whose work helped reveal an “arms for horses” deal done between Russia and North Korea which hit the headlines back in November 2022.
Thirty horses, specifically Orlov trotters, were sent via cargo train to North Korea after Pyongyang shipped Moscow artillery shells.
The operative spoke of his pride in working on the investigation and the significance of that intelligence that proved the intent of both nations in striking this deal.
A spotlight was shone on human intelligence, ie talking to people to gather a picture of what is happening and feeding it in to the wider picture after verifying its accuracy.
(Source: forces.net)
08 Feb 24. Global: Vulnerability in Linux system boot programme poses moderate security risks to global firms. On 7 February, a researcher at Microsoft’s Security Response Centre reported on a new remote code execution vulnerability (CVE-2023-40547) affecting all Linux distributions that support Secure Boot, including Debian, Red Hat, SUSE and Ubuntu. A piece of code known as Linux Shim is executed during the secure boot process that is responsible for an operating system’s security. The vulnerability grants threat actors the opportunity to inject malicious code during this boot process; it also gives them access to (and control over) the entire compromised system. Organisations with machines using HTTP boot or pre-boot execution environment (PXE) boot are most vulnerable to exploitation via this software bug. Consequently, we assess that there is a realistic possibility that organisations using these Linux instances will be targeted, highlighting the need for up-to-date patch management policies to reduce the likelihood of exploitation. A patch has since been released by Linux; users should therefore update their software to the latest version of Shim (v15.7). (Source: Sibylline)
07 Feb 24. Scepticism of AI remains despite disruptive impact – GlobalData survey.
Over three-quarters of survey respondents believe AI will be disruptive, but not everyone believes it deserves the hype.
Artificial Intelligence (AI) is viewed as the most disruptive technology among businesses, but some scepticism of the technology remains, according to a new GlobalData survey.
The Thematic Intelligence: Tech Sentiment Polls Q4 2023 survey, carried out across GlobalData’s network of B2B websites, found that 78% of respondents believe that AI will cause either “significant disruption” or “slight disruption” in the future, with 54% of respondents noting that they were already experiencing the impacts of the technology.
AI is followed by cybersecurity and robotics in terms of how disruptive businesses view the technologies as being, leaving augmented reality (AR) and the metaverse lagging.
Looking forward, 13% believe that AI will disrupt their industry in the next 12 months, while a further 14% feel the disruption will become evident within one to four years. Only 8% believe that AI will “never” cause disruption.
Scepticism about AI technologies
Despite the overall tone of confidence around AI, there is still lingering scepticism. 40% of respondents feel that “the technology is hyped”, although most could “see a use for it”. The results note that “there will likely be some scepticism surrounding AI’s capabilities until the full impact of generative AI on productivity is better understood.”
The hesitation is partly because of uncertainties to do with regulation, as well as concerns about reliability. While the technology has experienced rapid evolution and adoption, regulation has lagged, leaving businesses concerned about potential vulnerabilities and pitfalls.
Europe’s AI Act will represent the first significant move towards restriction and management, classifying, banning and limiting AI systems according to their risk level. The act will ban the real-time use of biometric analysis via sensitive characteristics in public spaces (with an exception for law enforcement) and will establish requirements for human oversight of computer models and actions.
Yet, despite the pending introduction of regulation, AI currently remains the wild west of the technology sector. In its Enterprise Predictions report for this year, GlobalData suggests that “2024 will see a high-profile case of a big corporation or government involved in a scandal as a direct result of deploying AI applications.” Specifically, it warns against “the potential for misinformation, toxicity, bias, copyright infringements and privacy breaches.”
Copyright concerns have already made it to the courtroom, with the New York Times recently suing OpenAI and Microsoft for copyright infringement, contending that its articles were used to train chatbots that now compete as a news outlet.
These concerns, along with consumer reluctance, have seen creative and artistic outlets positioned amongst the more reluctant adopters; however, with the AI market forecast to be worth $909bn by 2030, the technology looks set to transform businesses across even the most cautious of industries.
Confidence in other technologies
Aside from AI, the GlobalData survey also identifies cybersecurity and robotics as technology themes that respondents expect to be disruptive. 47% believe that cybersecurity is already causing “significant disruption”, a sentiment that 39% share for robotics.
Robotics is the technology that respondents are most optimistic will “live up to all its promises”, with 72% of respondents indicating as much. Cybersecurity is not far behind, with 71% of respondents believing that the hype around it is worthwhile. Cloud computing follows with 69%.
However, 46% do not consider the metaverse to be a disruptive technology. The results suggest that “a lack of tangible use cases and a limited understanding of the technology have contributed to the current metaverse winter.”
This is accompanied by general pessimism towards AR, which 25% of respondents feel will “never” disrupt their industry. The scepticism has likely been catalysed by the abandonment of AR projects by some major tech companies, including Google, which abandoned its project Iris in 2023. (Source: airforce-technology.com)
07 Feb 24. Following the Rule Book.
The United States has provided around 60 AGM-88B HARM missiles to the Ukrainian Air Force. This maybe nowhere near enough. Armada has performed exhaustive analysis of Suppression of Enemy Air Defence (SEAD) efforts in previous air campaigns in Iraq, the Balkans and Libya over the past three decades. Our studies are based on theatre size, campaign duration and deployed SEAD elements. We calculate Ukraine would need circa 2,400 anti-radar weapons to attrit Russian ground-based air defences in theatre to a point where they could no longer threaten Ukrainian air power.
Details are emerging of the Ukrainian Air Force’s air defence suppression doctrine as the country seeks to win and sustain air superiority and supremacy in her ongoing war against Russia’s occupation.
It is a reality of the ongoing war in Ukraine that neither the Russian nor the Ukrainian military has managed to win and sustaining air superiority. The US Department of Defence (DOD) defines air superiority as “that degree of control of the air by one force that permits the conduct of its operations at a given time and place without prohibitive interference from air and missile threats.” Air superiority is the essential pre-requisite to establishing air supremacy. Returning to DOD definitions, air supremacy is “that degree of control of the air wherein the opposing force is incapable of effective interference within the operational area using air and missile threats.”
Ongoing combat losses of Ukrainian and Russian aircraft illustrate that neither side has won, let alone sustained, control of the air. This is problematic for Ukraine as she continues to resist Russia’s aggression and works to expel Moscow’s forces from her territory. During the Second World War the celebrated British Field Marshal Bernhard Montgomery argued that “if we lose the war in the air, we lose the war and we lose it quickly.” Over 80 years later, his words still resonate. Ukraine cannot win her battle on the ground if she cannot control the air. Winning control of the air depends on attritting Russia’s fighter strength and destroying the Ground-Based Air Defences (GBAD) she has deployed to the Ukrainian theatre of operations. In short, Russian GBAD in Ukraine must be wiped out. Any new GBAD systems Russia deploys into theatre as replacements must meet a similar fate.
Achieving depends on Ukraine having the kinetic and electronic weaponry relevant to the SEAD battle. Kyiv’s allies have not been shy about providing artillery and precision-guided weapons. Examples of the latter include MBDA’s Storm Shadow/SCALP (Système de Croisière Autonome à Longue Portée–Emploi Général/Autonomous Cruise Missile System for General Employment) and Boeing’s Joint Direct Attack Munition precision guidance kit for unguided bombs. Likewise, Texas Instruments/Raytheon AGM-88B/C HARM (High-Speed Anti-Radiation Missiles) have been invaluable. AGM-88s have helped make life miserable for Russian ground-based air surveillance and fire control radar operators.
Doctrine
The Ukrainian Air Force (UAF), and armed forces more widely, have been fighting hard for air superiority and supremacy. Sources close to Ukraine’s SEAD battles shared with Armada the approaches adopted to date. Ensuring that UAF aircraft avoid areas where Russian GBAD is robust and concentrated is paramount. This prudence is vital to conserve UAF airframes. However, this tactic alone does little to reduce the ferocity of the defences Russia has arrayed against Ukrainian air power. Allied to GBAD avoidance tactics is discretion, primarily concealing UAF movements as much as possible. As the Ukrainian sources note, finding Russian radars places a premium on Electronic Intelligence (ELINT) gathering. Find the radar signal and you find the radar. To this end, “operational and strategic level (ELINT),” including that collected from space, is vital.
Avoidance tactics are merged with offensive actions against “hostile air defence facilities.” Ukrainian sources noted the importance of electronic warfare to the UAF’s endeavours. Detecting the radars supporting Russian GBAD is the vital first step in the kill chain. Regarding effects, the UAF has three choices; kinetic weapons like the AGM-88, electronic attack and possibly cyberattack. Details on the execution of all three tactics are understandably kept under wraps.
UAF SEAD doctrine places a premium on sanitising an area up to 15 kilometres (9.3 miles) deep from the tactical edge. Ensuring the electronic and kinetic attrition of Russian GBAD in these areas is key to assisting Ukrainian Close Air Support (CAS). Such tactics pose a dilemma for Russian land forces: They can pull back their GBAD units, particularly their Short-Range Air Defence (SHORAD) systems beyond this 15km limit. In doing so, they risk leaving Russian units at the tactical edge dangerously exposed to Ukrainian CAS. If the Russian leave their GBAD units there, they risk kinetic attack.
Learning from history
It is noteworthy that Ukrainian airpower places a premium on employing Uninhabited Aerial Vehicles (UAVs) to support the SEAD fight. This makes sense as SEAD is an inherently dangerous mission. The fewer aircrew that are put at risk, the better. The Israeli Air Force pioneered the use of UAVs to support SEAD. Witness the employment of such aircraft against Syrian GBAD during Israel’s 1982 Operation Peace for Galilee. Israel Aerospace Industries’ Harpy loitering anti-radar weapon distils lessons from that, and other, SEAD efforts. Fighting Russian GBAD at the tactical edge and beyond also depends on fires with GBAD units engaged by artillery.
Ukraine is learning SEAD lessons the hard way in the unforgiving crucible of war, but a crucible that is a great teacher. The UAF, and the Ukrainian military in general, have clearly sharpened their SEAD doctrine to a fine point. Nonetheless, doctrine is half the story. Ukraine needs the electronic and kinetic capabilities to finish the job and banish Russian GBAD from the theatre of operations. Likewise, she needs to dominate the electromagnetic spectrum, to achieve and hold spectrum superiority/supremacy. Only by doing this can Ukraine hope to win on the ground. Getting Kyiv enough of these tools is the challenge faced by Kyiv’s allies, a challenge they must not forsake if they are serious about Ukraine’s victory. (Source: Armada)
07 Feb 24. Strife on the Ocean Waves. AIS spoofing is a growing problem on the high seas. A new report by Global Fishing Watch discusses the extent of this problem and includes important recommendations for policy makers.
A new report highlights shortcomings in global maritime surveillance capabilities provided via the Automatic Identification System.
The International Maritime Organisation (IMO) mandates Automatic Identification System (AIS) transponders for all vessels displacing over 500 Gross Tonnage (GT). Vessels displacing over 300GT on international voyage are also obliged to use AIS alongside all passenger vessels. AIS transponders transmit details of a vessel’s identity, position, voyage and cargo. This information is sent across frequencies of 161.975 megahertz/MHz to 162.025MHz. AIS data can be overlaid onto a radar’s recognised maritime picture to populate this with vessel identification information. Usefully, AIS data can be shared across Ultra High Frequency (300MHz to three gigahertz) satellite links.
A recent study by Global Fishing Watch (GFW), a non-government organisation monitoring illegal activity on the high seas, highlighted how important AIS data has become in tracking suspect maritime activity. One revelation of GFW’s report concerns the lack of AIS data on certain vessel activities, notably fishing. IMO mandates “currently excludes fishing vessels unless the flag state decides to include fishing vessels in the (domestic AIS) requirement,” says David Kroodsma, GFW’s director of research and innovation. Unless the country where the vessel is registered requires AIS to be fitted, there is a chance it may not be.
The good news, according to GFW, is that the European Union and the United States now require some smaller-sized fishing vessels to transmit AIS when out of port. “Global Fishing Watch would like to see the rules requiring AIS on fishing vessels to be adopted more universally and to be harmonised so we can avoid a patchwork of different regulations governing the use of AIS on fishing vessels.”
“We see a lot of vessels between ten and 20 metres (33 and 66 feet/ft) in length, most of which are not required to broadcast their positions on AIS,” said Mr. Kroodsma. That said, some states may require these ships to transmit their position to government-owned vessel monitoring services. Another problem when tracking vessels with AIS is that the quality of the transmission in some regions may affect signal reception. For example, although AIS messages may be transmitted, they may not always be received by satellites because of poor coverage.
Motivations
Some vessels deliberately switch off their AIS transponders. Deactivation may have an innocent explanation. A ship traversing pirate-infested waters may not want to advertise her presence to would-be hijackers. Given that AIS data is freely available online, this is an understandable concern. Other vessels deactivating their AIS transmissions maybe doing so for nefarious reasons: “Previous research, published in Science Advances, has shown that fishing vessels more often turn off their AIS when close to a country’s Exclusive Economic Zone (EEZ),” notes Mr. Kroodsma. Deactivating AIS transponders when a vessel is near an EEZ may indicate that she plans to covertly enter the EEZ for illegal fishing.
Another of GFW’s findings relates to voyages by vessels not transmitting AIS but carrying energy products: “Large transport and energy vessels are mostly broadcasting,” says Mr. Kroodsma. Nonetheless, some smaller vessels are not. Again, this could have an innocent explanation given that satellite reception for AIS signals can be poor in some areas. However, some of these vessels maybe engaged in illegal activity such as illicit oil trafficking. For example, both the Islamic Republic of Iran and Russia are under international sanctions regarding their oil exports.
While a lack of AIS transmission can be a cause of concern, so can the transmission of deliberately false AIS data. The GFW research showed that “a very small faction of vessels broadcast false AIS data.” False AIS data indicates that a vessel may be doing something she should not. GFW’s study employed satellite data to determine if AIS information was false as AIS transmissions are designed to be received by satellites. GFW used radar imagery provided by the European Space Agency’s (ESA’s) Sentinel-1 spacecraft. Sentinel-1 is equipped with a Synthetic Aperture Radar (SAR). The radar can detect ships and AIS transmissions from vessels can be overlaid onto this. If a ship is in the middle of the South China Sea, but her AIS data is saying she is in the North Sea this discrepancy could indicate that AIS data is being deliberately falsified.
Recommendations
One of GFW’s recommendations is to extend the mandate for AIS to equip smaller fishing vessels below the IMO’s stipulations. “Requiring AIS on fishing vessels improves safety and transparency within the fishing sector,” says Mr. Kroodsma. GFW’s report has been instructive in exposing gaps in global AIS maritime surveillance coverage which risks leaving suspect activities on the high seas unchecked. It is now up to governments and supranational organisations like the IMO to decide what actions they will take to this end. (Source: Armada)
08 Feb 24. February Spectrum SitRep.
Armada’s monthly round-up of all the latest electronic warfare news in the product, programme and operational domains.
Calling all speakers!
The Royal Air Force Museum has announced its call for speakers for its 2024 lecture series. The museum is planning a series of lectures, covering the whole gamut of air power, to take place throughout the year. The lectures will be held online and throughout the United Kingdom. The museum has sites in London, Wolverhampton in the West Midlands and Lancaster in the north of England. Proposals for lectures are sought from postgraduate students, early-career and established researchers. The objective of the lectures is to share new research being undertaken in air power, aviation history and histories of air forces. This includes the Royal Air Force’s, and air power’s, use of the electromagnetic spectrum. Proposals in diverse, related fields and their relationship to the RAF and air power will also be considered. These fields can include, but are not restricted to, archaeology, law and ethics, museology, international relations and strategic studies. Papers relating to the future direction of air and space power are particularly welcome. The lectures enable those interested in these fields share knowledge and highlight interdisciplinary approaches and research methods. Those interested in responding to this call for papers should send a 300-word abstract outlining their idea along with a 200-word biography, both of which should be written in English. Abstracts and biographies should be sent to Dr. Megan Kelleher, the RAF Museum’s historian and academic access manager, at . The deadline for abstract and biography submissions is 1st March.
Two Into One
On 19th December, Raytheon announced it had won a contract worth $80m to produce a prototype Advanced Electronic Warfare (ADVEW) system. ADVEW will equip the United States Navy’s Boeing F/A-18E/F Super Hornet combat aircraft. The new EW system replaces two existing capabilities; L3Harris’ AN/ALQ-214 integrated countermeasures system and Raytheon’s AN/ALR-63(V)3 radar warning receiver. According to a press release announcing the news, ADVEW will consolidate the attributes of these two systems into a single architecture. At the same time, Raytheon says ADVEW will deliver improvements in performance vis-à-vis these legacy systems. The press release continued that ADVEW prototypes will be developed, tested and reviewed over a 36-month period. Raytheon told Armada in a written statement that ADVEW “will deliver a generational refresh to the (aircraft’s) electronic warfare capability.” The statement added that the company “continues to work closely with the government’s F/A-18E/F programme office to ensure we’re prepared to deliver the needed electronic warfare enhancements, on time and within budget, to the backbone of the US Navy’s carrier air wing.” The company declined to provide details of the initial and full operational capability dates for ADVEW. Raytheon also declined to say how many of the existing F/A-18E/F fleet would receive the new system referring these inquiries to the US Navy. (Source: Armada)
07 Feb 24. Netherlands: Chinese state actors pose sustained espionage risks to government research sector. On 6 February, the Dutch government revealed that an unnamed Chinese-linked threat group breached the Dutch Ministry of Defence in 2023. The group deployed a previously unknown remote access trojan (‘COATHANGER’) after obtaining initial access to the ministry’s network by exploiting an existing software vulnerability in FortiGate devices (CVE-2022-42475). COATHANGER persists through system reboots and firmware upgrades, which can result in prolonged infections on compromised devices. The group breached a network used for research and development (R and D) of unclassified projects, and also for collaboration with two third-party research institutes. There is a realistic possibility that the group attempted to steal intellectual property or other sensitive information, a common motivation for cyber espionage operations conducted by Chinese-backed threat actors against government research sectors. Consequently, moderate security risks will continue to impact the Dutch defence sector in the medium term. The effects of the attack were limited due to proper network segmentation, underscoring how adequate security protocols can minimise the spread and impact of a cyber attack. (Source: Sibylline)
07 Feb 24. BFBS collaborates with BT to deliver broadcast content via the Cloud to UK armed forces serving abroad. Military charity and media organisation, the British Forces Broadcasting Service (BFBS) has chosen BT to future-proof delivery of its content for UK armed forces serving overseas and at sea.
BFBS provides serving personnel and their families overseas with a variety of television and radio services via satellite, including a bespoke mix of current British TV, public service broadcasting and access to premium sports, series, and movies. From April, this content – which is curated at BFBS’s headquarters in the UK – will be encoded and multiplexed by BT’s Media and Broadcast unit, using its new virtualised platform hosted at BT Tower.
BFBS will join BT’s intelligent broadcast platform, Vena, for content contribution and distribution. BT will also provide uplink services from its earth station in Herefordshire to three of the satellites used by BFBS to reach its global audience.
Ben Chapman, CEO of BFBS, said: “Moving to BT’s Vena network and virtualised platform offers us the agility to flex and adjust to the evolving needs of our armed forces overseas. It also ensures a secure, robust, and future-proof method of delivering our media content.
“BFBS is already a trusted and reliable source of media for the military, and this partnership with BT strengthens the technology behind the distribution of our TV, radio, and data services. This is vital, as our channels increase wellbeing and morale for those deployed worldwide, not only in well-connected regions, but in remote and austere locations too.”
BFBS joins a growing number of broadcasters on the Vena platform that will process and simplify content production and distribution. The agreement also includes the provision of digital coding and multiplexing, essentially combining multiple content streams into one before distribution to armed forces personnel watching in multiple locations across the globe. All this will be under one umbrella service with full end-to-end, round-the-clock monitoring provided from its International Media Centre at BT Tower.
Faisal Mahomed, Director of BT Media and Broadcast & UK Portfolio Businesses said: “We’re excited to support BFBS with this transition to cloud-based broadcasting. It’s an organisation with a purpose that sits at the heart of BT’s ambitions to connect for good, and we will help them bring content every day to armed forces personnel and their families around the world – including those often serving in difficult or extreme locations.
“Our Vena platform was built to offer broadcasters the resilience and flexibility to serve audiences wherever they are, and this is a great example of its potential for the industry.
“BT has a long history of supporting the armed forces and this new partnership with BFBS is building on that heritage and using the power of technology to future-proof services for an organisation that entertains, informs, connects and champions the UK’s armed forces both domestically and across the globe.”
05 Feb 24. Ultra Intelligence & Communications hosted a technical demonstration for government and military customers in Sanford, Florida, where it successfully illustrated the capability of its sixth-generation Orion multi-mission, high-capacity tactical line-of-sight radios and our family of deployable SATCOM terminals to support large scale combat operations.
The demo marked several significant new milestones:
- Prototypes of the single-channel Orion X610 were showcased for the first time to a public audience, utilizing Ultra I&C’s high throughput mesh (HTM) waveform in an urban environment. This robust waveform, coupled with the small-form factor, multi-mission X610 demonstrated an unparalleled ability to provide on-the-move C2 and fires applications over higher bandwidth channels than any other Mobile Adhoc Networking (MANET) waveform in its class.
- The dual-channel Orion X630 demonstrated a new range milestone between two SWAP-constrained tethered drones, establishing and maintaining a high bandwidth point-to-point channel at nearly 30 kilometers, achieving approximately 30 Mbps. The X630 Orion has been optimized to be smaller, lighter, and more powerful than any other comparable multi-mission dual-channel radio on the market and can be used on air, land or maritime platforms from tethered unmanned systems to surface vehicles.
- The range-extending dual-channel Orion X650 demonstrated over-the-air interoperability with the currently fielded Orion X500 (GRC-262) and the X630, which was configured to crossband PLI and SA from disconnected nodes supported by an edge-tier waveform. The X650, with its true 4×4 MIMO, multi-mission, software-defined point-to-point, point-to-multipoint and mesh waveforms, meets and exceeds the U.S. Army’s need for increased range and spectrum agility while reducing SWAP and cost. It delivers enhanced features and functionality to operators while maintaining backward compatibility with all high-capacity line-of-sight radios fielded within the Army for the last 25 years.
- Ultra I&C’s GigaSat Ultralight VSAT (ULV), FA-100, and FA-180 SATCOM terminals were quickly set up and disassembled, demonstrating ease of use and adaptability for various missions. The modular designs of inter-terminal exchangeable components are built to withstand extreme weather and offer unmatched simultaneous dual-band transmit and receive waveguides.
“The success of today’s demonstration represents not just progress for military communications, but a connected future battlespace where command posts can be made more effective and survivable through more secure, mobile and flexible communication systems,” said Alain Cohen, Ultra I&C’s president of communications.
“Getting equipment into the hands of [our warfighers] to test allows us to get their ideas and an understanding of their mission set,” said one military officer in attendance. “Ultra I&C is providing us that Swiss army knife to get after expeditionary advanced base operations. The capabilities you have are incredible!”
On today’s battlefield, soldiers need to effectively engage the enemy, maneuver quickly to new missions and clearly communicate orders, intelligence, logistics and fires up and down the chain of command. The family of Orion high-capacity tactical radios enables the warfighter to receive and relay immense amounts of data, including full-motion video, to ensure a complete common operational picture during multi-domain operations.
About Ultra Intelligence & Communications
Ultra Intelligence & Communications, also known as Ultra I&C, has generations of experience fielding tactical communications, command and control and cyber security technologies for the most challenging defense applications. Ultra I&C connects the multi-domain battlespace and ensures secured information advantage in high-threat environments. These innovative solutions are an integral operational component for the U.S. Department of Defense, the UK Ministry of Defence, the Canadian Department of National Defence and many more defense organizations worldwide. For more information, visit www.ultra-ic.com. (Source: PR Newswire)
06 Feb 24. QuSecure Joins Post-Quantum Cryptography Alliance as Founding Member Furthering Technology to Address the Post-Quantum Cybersecurity Threat.
QuSecure™, Inc., a leader in post-quantum cryptography (PQC), today announced it has been named as a founding member of the Post-Quantum Cryptography Alliance (PQCA), an open and collaborative initiative to drive the advancement and adoption of post-quantum cryptography. As a result, QuSecure will lend its unique and demonstrated experience implementing PQC in both enterprises and government agencies to the PQCA’s efforts furthering technological advances to address the looming post-quantum cybersecurity threat.
As announced by the Linux Foundation today, the PQCA brings together industry leaders, researchers and developers to address cryptographic security challenges posed by quantum computing through the production of high-assurance software implementations of standardized algorithms, while supporting the continued development and standardization of new post-quantum algorithms.
“The PQC Alliance has the laudable goal of bringing together the brightest minds in security and cryptography to deliver open-source, high-assurance post-quantum cryptography,” said Joey Lupo, Product Security Architect at QuSecure. “QuSecure is excited to be a founding member of this effort and continue our mission to engineer a more secure post-quantum future for our customers and the world.”
The PQCA will engage in various technical projects to achieve its objectives, including the development of software for evaluating, prototyping, and deploying new post-quantum algorithms. By providing these software implementations, the foundation seeks to facilitate the practical adoption of post-quantum cryptography across different industries.
Rebecca Krauthamer, QuSecure Co-Founder and Chief Product Officer, added, “QuSecure is proud to be a founding member of the Linux Foundation’s Post-Quantum Cryptography Alliance working alongside the trailblazers of the industry. Our work with the alliance underscores our shared mission of enabling access to quantum-resilient resources where the threat is no longer theoretical but existential. We are excited to collaborate to advance technology ensuring a more secure and resilient digital future.”
QuSecure uniquely adds a real-world deployment element to the PQCA, having installed its PQC solution QuProtect in dozens of enterprises and federal network environments. This gives QuSecure a thorough understanding of what organizations are looking for when deploying PQC. For example, QuSecure has gained customer feedback on the value of cryptographic agility and key-strength agility due to seeing how customers use the QuProtect Orchestration Platform to change algorithms and key sizes. Also, QuSecure can report on the value of being able to install QuProtect in an enterprise without removing or changing existing cryptography. By leaving existing encryption in place, QuSecure has been able to rapidly deploy QuProtect in as little as four hours, which gives QuSecure a rapid learning capability wherein it can share some of the findings with PQCA.
QuSecure’s QuProtect software enables organizations to leverage quantum-resilient technology and is currently available to test and deploy, helping to prevent today’s cyberattacks while future-proofing networks and preparing for quantum cyberthreats. It provides quantum-resilient cryptography, anytime, anywhere and on any device including network, cloud, IoT (Internet of Things), edge devices, and satellite communications. Using QuProtect, organizations can implement PQC on the network without removing existing encryption so installation is fast and risk is minimal. QuProtect software uses an end-to-end quantum-security-as-a-service architecture that addresses the digital ecosystem’s most vulnerable aspects, uniquely combining zero-trust, next-generation post-quantum cryptography, crypto agility, quantum-strength keys, high availability, easy deployment, and active defense into a comprehensive and interoperable cybersecurity suite. The end-to-end approach is designed to protect the entire information lifecycle as data is communicated, used and stored.
About the Linux Foundation
The Linux Foundation is the world’s leading home for collaboration on open source software, hardware, standards, and data. Linux Foundation projects are critical to the world’s infrastructure including Linux, Kubernetes, Node.js, ONAP, PyTorch, RISC-V, SPDX, OpenSSF OpenChain, and more. The Linux Foundation focuses on leveraging best practices and addressing the needs of contributors, users, and solution providers to create sustainable models for open collaboration. For more information, please visit us at www.linuxfoundation.org. The Linux Foundation has registered trademarks and uses trademarks. For a list of trademarks of The Linux Foundation, please see its trademark usage page: www.linuxfoundation.org/trademark-usage. Linux is a registered trademark of Linus Torvalds.
About QuSecure
QuSecure is a leader in post-quantum cybersecurity with a mission to protect enterprise and government data from quantum and classical cybersecurity threats. Its quantum-safe solutions provide an easy transition path to quantum resiliency across any organization. The company’s QuProtect solution is the industry’s first PQC software-based platform uniquely designed to protect encrypted communications and data with quantum-resilience using a quantum secure channel. For more information visit www.qusecure.com. (Source: BUSINESS WIRE)
06 Feb 24. Global: OT environments face heightened threats posed by state-sponsored cyber actors. On 5 February, international news sources shared a report by the cyber security firm TXOne Networks on operational technology (OT) security threats in 2023. The report focuses on data obtained from over 400 organisations in the Asia-Pacific, Europe and North America regions. According to the survey, 46% of organisations reported being affected by an OT security incident, with 47% of those incidents being the result of ransomware campaigns. The most targeted sectors included government facilities, as well as manufacturing and healthcare entities, underscoring the heightened long-term operational risks facing these sectors. Despite many cyber attacks initially targeting information technology (IT) environments, OT environments were also impacted in 97% of cases. This highlights the second-order impacts facing these environments, even if they are not the initial target. This underscores the necessity for network segmentation and improved security protocols. As OT environments operate critical national infrastructure, we assess that there is a sustained operational threat posed by state-sponsored threat actors looking to carry out destructive attacks. (Source: Sibylline)
03 Feb 24. Cyber Command Flag Passed to Air Force General at Fort Meade Ceremony. Leaders from the Defense Department and intelligence community gathered at Fort Meade, Maryland, yesterday for the change of command ceremony of U.S. Cyber Command, as Army Gen. Paul M. Nakasone passed the flag to Air Force Gen. Timothy D. Haugh.
Haugh also became the director of the National Security Agency and the chief of the Central Security Service. The change of command took place in the Shannon Kent Conference Center at the command’s new headquarters. Kent was a Navy senior chief cryptanalyst killed in Syria in 2019.
Deputy Secretary of Defense Kathleen Hicks presided at the change of command, and the Director of National Intelligence Avril D. Haines presided as Haugh assumed the NSA/CSS directorship. Navy Adm. Christopher Grady, vice chairman of the Joint Chiefs of Staff, represented the Joint Staff at the event.
Cyber Command is a combatant command that is constantly at war, ensuring the U.S. military has secure communications. Enemies — from nation states to hackers — constantly attack the network as they seek to disrupt military operations worldwide. The command defends the network and nation through full-spectrum offensive and defensive operations. Cyber Command also works with other U.S. government agencies and with allies and partners worldwide.
The National Security Agency and Central Security Service lead the nation in cryptology and signals intelligence and also develops cybersecurity products and services.
The massive campus at Fort Meade is the headquarters for an organization that stretches across the globe and into space.
Nakasone took command in 2018 when Cyber Command was still new, having been established in 2010.
“People at Fort Meade are tackling some of the most important missions in the Department of Defense,” said Hicks in remarks at the ceremony. “Day and night, Cybercom keeps the watch in cyberspace.”
Every American benefits from the mission as the Internet is vital to U.S. democracy, America’s way of life, and the world’s economic well-being. “We rely on cyberspace to be free, open and secure; so every day, Cybercom works hard to ‘own the domain,'” she said.
The command evolves as the threats evolve, Hicks said, and the people of the command must adapt to outpace adversaries and ensure the safety and reliability of the digital world.
“In the 21st century security environment, you are the front lines,” Hicks said. “Our competitors are looking to degrade our military advantage — to threaten our infrastructure, our information systems, and our industrial base.”
China is the pacing challenge as the only strategic competitor with the will and, increasingly, the means to remake the international rules-based order that has prevented great power war since 1945. ” seeks to spread its brand of autocracy through digital means: like intrusive hardware and software, forcing tech to comply with political ideologies, stealing and trying to dominate the telecom and cybersecurity industries,” Hicks said.
Russia is also an acute threat, the deputy secretary said. “They’ve launched troubling influence campaigns meant to interfere in our elections and undermine our democracy, while their cyber criminals have launched damaging ransomware attacks,” she said. “Russia’s cyberattacks have tried to weaken Ukraine’s military and damage civilian infrastructure there. And their global online-propaganda campaigns try to justify their unprovoked aggression.”
Nakasone worked across an array of threats, which ranged from cyber operations to combating Islamic State terrorists, to position Cyber Command and the NSA for strategic competition with China and Russia.
“His transformational leadership has strengthened our national security, bolstered our deterrence and defended our democracy — including protecting U.S. elections from foreign attacks,” Hicks said. “Above all, he understands that cybersecurity is a team sport. That’s why he has coordinated closely across the interagency: recognizing that our cyber capabilities must be used alongside other instruments of national power.”
In-coming commander Haugh is well-versed in the organizations after having served at Nakasone’s deputy. He has had a long history in intelligence and cyber fields since he commissioned into the Air Force in 1991. “Tim, this command, these agencies, and their people are fortunate to have you lead them into their next era,” Hicks said. “We look forward to everything you will do here to strengthen these institutions and their teams and to make America even more secure.”
Nakasone and Haugh stressed the importance of the people of the command and agencies. Nakasone said that while technology is important, it is the people who make the difference. They are the innovators, and they are the reason the American people respect the organizations, he said.
“Our talent is unmatched in the world,” Haugh said in his remarks. “The National Security Agency and Cyber Command create advantages for the nation.”
The organizations will continue to create and use new technologies because “that is part of our enduring advantage,” the Air Force general said. He said the watchwords of his term will be “people, innovation and partnerships.”
Haines said the intelligence community, writ large, is a team sport and that Cyber Command and NSA are essential players. She said Nakasone provided the highest levels of government with the intelligence needed to make informed decisions. Haines also presented Nakasone with the George Washington Spymaster Award, the highest award in the intelligence community.
Nakasone leaves after six years in the positions. Grady praised the Army general for his leadership through the pandemic, for growing cyber operations in all domains of warfare, for the increasing agility of the command and for his outreach efforts to allies, partners and, increasingly, to private entities. (Source: U.S. DoD)
02 Feb 24. Pakistan: Malicious applications elevate espionage risks to users in diplomatic, government sectors. On 1 February, the security firm ESET reported an espionage campaign using malicious mobile applications to install a remote access trojan (RAT) on devices in Pakistan. The campaign used 12 malicious Android chat applications to run a RAT (‘VajraSpy’) onto targeted users. These applications are available for download on the Google Play Store. At least six were downloaded over 1,400 times, highlighting the ongoing risks to users as the applications are yet to be removed from the Google Play Store. The campaign likely used honey-pot romance scams to lure users into downloading the malicious applications, underscoring the targeted nature of the operation. The pro-India threat actor ‘Patchwork APT’ was attributed to the campaign, which was likely directed at high-value targets within Pakistan’s diplomatic and government sectors for cyber espionage to benefit India’s strategic interests in the region. Heightened tensions between India and Pakistan will likely sustain espionage operations against strategic sectors. Source: Sibylline)
02 Feb 24. Cyber Update Key points.
- Despite an observed decline in reported ransomware incidents during Q4 2023, ransomware groups continue to develop new tactics, techniques and procedures (TTPs) to sustain operations (see Sibylline Cyber Daily Analytical Update – 29 January 2024).
- As a result of information-stealing malware, over 1,500 compromised digital assets of global internet service registries have been observed for sale on the dark web (see Sibylline Cyber Daily Analytical Update – 30 January 2024).
- A Chinese threat actor, ‘UNC5221’, is exploiting unpatched Ivanti virtual private network (VPN) devices to drop loader malware (‘KrustyLoader’) in a multi-stage operation (see Sibylline Cyber Daily Analytical Update – 31 January 2024).
- The FBI seized hundreds of infected small home and office routers, removing a Chinese-controlled botnet and reducing potential cyber espionage risks posed by said botnet (see Sibylline Cyber Daily Analytical Update – 1 February 2024).
- A suspected pro-India actor, ‘Patchwork APT’, is targeting users in Pakistan with malicious mobile applications to install malware for espionage purposes (see Sibylline Cyber Daily Analytical Update – 2 February 2024 and our Technical analysis below).
Technical analysis of weekly stories
The ‘VajraSpy’ remote access trojan (RAT) is downloaded onto targeted users’ devices via trojanised mobile chat applications. The RAT is used to exfiltrate data for espionage purposes. Several of the 12 applications share the same code responsible for data exfiltration; the overlap of the malicious code indicates it is likely written by the same actor. VajraSpy’s malicious functionalities vary based on the application permissions, which determine the extent of the malicious activity the RAT can conduct on an infected device. Most malicious applications engage in normal chat functionalities to appear legitimate while simultaneously exfiltrating contacts, text messages, call logs, a device’s location, a list of installed applications and specific files. Four of the trojanised applications contained extended malicious capabilities in addition to the aforementioned functionalities. These capabilities can exploit built-in accessibility options to steal data from WhatsApp, WhatsApp Business and Signal; they can also record calls, log keystrokes, take pictures via a device’s camera and scan for wireless networks. It is possible that the varying malicious capabilities of the RAT are used against specific targets; higher-value targets are possibly selected with more sophisticated RATs so as to maximise data theft.
Some non-exhaustive recommendations to mitigate this threat include:
- Monitor devices and network for suspicious activity
- Add available Indicators-of-Compromise (IoCs) to the organisation’s security detection systems to detect potentially malicious samples on the network
- Ensure there are adequate security detection measures in place, including end-point detection and response (EDR) solutions (such as anti-virus software)
- Conduct cyber hygiene awareness courses for users to enable them to recognise and report phishing and social engineering attempts
- Only download mobile applications from trusted sites such as the Google Play and Apple stores
- Ensure applications are legitimate prior to downloadingFrequency of TTPs during this monitoring period: LOW frequency, MODERATE frequency, HIGH frequency
The MITRE ATT&CK framework is a globally accessible documented collection of information detailing the malicious behaviours of cyber threat actors; it is used as the foundation for organising the processes which threat actors execute during cyber operations. It provides an encyclopaedic reference for organisations, highlighting the tactics, techniques and procedures (TTPs) cyber actors employ in campaigns, while also providing suggestions for detecting and mitigating against specific TTPs to bolster organisations’ security mechanisms. The framework organises a threat actor’s entire operational lifecycle from reconnaissance to exfiltration and impact.
Word(s) of the week
Our cyber word(s) of the week: Post-exploitation framework
(Source: Sibylline)
————————————————————————-
Spectra Group (UK) Ltd
Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.
Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.
With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.
Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.
In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.
Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.
Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.
————————————————————————-

