• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • SPECTRA banner
  • Curtiss-Wright banner

BATTLESPACE Updates

   +44 (0)77689 54766
   

  • Home
  • Features
  • News Updates
  • Defence Engage
  • Company Directory
  • About
  • Contact

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

February 23, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

————————————————————————

21 Feb 24, Spectra Group invests in advanced 3D printing. Defence and security communication systems manufacturer, Spectr.a Group, has invested in Stratasys 3D printing technology to upgrade their product development and production processes. A global provider of tactical and strategic mission-critical communication systems, Spectra Group has revolutionised its product development process by investing in one of the UK’s first Stratasys Origin One 3D printers from SYS Systems – UK Stratasys Platinum Partner. The Stratasys Origin One 3D printer has enabled the mass production of Spectra’s critical communications systems for the high-pressure industries they serve, allowing them to develop, alter and manufacture prototypes and products in-house faster than ever before. This state-of-the-art 3D printer has given Spectra the capacity to proactively develop and produce critical communications technology that can withstand even the most strenuous conditions. Head of Research and Development at Spectra, Simon Perrett said: “The products we produce haven’t just got to look good, they have got to perform really well as well. For the military community, one minute you could be in 50-degree heat and in the next minute you could be in -25, -30, so the products have got to withstand those environmental changes, as well as taking a bit of a bashing.

“When I came into the company and looked at how much we were outsourcing, one of the things I looked at was cost for things like tooling, but I also looked at the flexibility that if we have an idea, how we can change it and how to change it quickly.”

The Stratasys Origin One is an advanced industrial 3D printer that enables companies like Spectra Group to manufacture high-quality parts without the cost of retooling, whilst maintaining minimal inventory by printing on-demand with exceptional accuracy, consistency and repeatability.

Since investing in a Stratasys Origin One, Spectra Group have revolutionised their in-house product development processes which has enabled them to increase the manufacturing of field-ready end-use products directly from their Herefordshire site.

Simon said: “Once we’re happy with a product, we don’t have to go and get any injection mould tooling or anything. We can literally produce a part, with a little bit of post-processing, insert all the parts we need to and then ship it out. That was the revolution we were after and now we have achieved it.”

Spectra Group have been producing vital communications systems for 20+ years and their continuous investment in new technology reflects their focus on innovation and advancement. The Stratasys Origin One 3D printer from SYS Systems has unlocked Spectra’s capacity to produce new and groundbreaking products at a record time-to-market.

Simon said: “We had a concept for a vehicle adapter to put onto our universal power controller and it was produced within five working days. So literally from a concept to a capability, which we are now selling and pushing out of the door, it’s unheard of. We constantly want to diversify and change things, and the Origin One gives us that capability. We couldn’t do without this printer now. And in terms of a partner for us, SYS Systems have been brilliant.” (Source: ADS)

 

20 Feb 24. Solution to Enable Uncrewed Vehicles to Operate in Hostile RF Environments.

DTC has combined MANET radio and Mesh-based technology with inertial navigation capabilities by Inertial Labs, to provide a unique solution for uncrewed systems operating in GNSS-contested environmentsBy DA Team / 20 Feb 2024

Leading provider of wireless IP mesh technology Domo Tactical Communications (DTC), and Inertial Labs, Inc., a leading developer of global navigation satellite system (GNSS)-independent navigation solutions, have partnered to develop a breakthrough integrated uncrewed systems solution to benefit UxV manufacturers and end users worldwide.

The new solution combines technologies from both companies to create a single navigation, command and control (C2), and intelligence, surveillance and reconnaissance (ISR) system.

DTC’s MANET Mesh with MeshUltraTM family waveforms deliver robust, high-bandwidth C2 and ISR links, enabling uncrewed vehicles to operate successfully in the most hostile RF environments.

Leveraging Inertial Labs’ inertial navigation system (INS) and DTC’s Mesh-based RF ranging capability, those same vehicles will also be able to operate even when space-based positioning systems are unavailable due to jamming, spoofing, or lack of sky view. The INS provides assured position, navigation, and timing (APNT), and alternative navigation (ALTNAV) solutions directly to the uncrewed vehicle.

“DTC is committed to ensuring connectivity in almost any environment or situation. This partnership with Inertial Labs offers a breakthrough combined solution for uncrewed systems,” said Rob Garth, Business Unit Director for Unmanned Systems at DTC. “The cohesive communications and positioning package will reduce customers’ time to market and increase their beyond-line-of-sight connectivity.”

“DTC is a trusted partner with a track record of delivering mission-critical Unmanned systems communication solutions,” said Jamie Marraccini, President and CEO of Inertial Labs.

“By combining our Inertial Navigation capability with DTC’s MANET radio and Mesh- based ranging, we are providing our current and future customers with an unparalleled solution set perfectly tailored for the most demanding of GNSS-contested environments.”

(Source: https://www.defenseadvancement.com/)

 

22 Feb 24. Global: New worm poses heightened exploitation risks for global firms via lateral movement. On 21 February, the security company Sysdig reported the existence of a new Secure Shell (SSH) worm. SSH worms are a type of malware capable of automatic self-replication; they are also able to hijack SSH credentials that are used to enable secure network connections, leveraging them to connect to another system. The new worm deviates from more traditional worms, as it contains new functionalities, including the ability to identify potential use-cases of stolen SSH credentials independently. This emphasises the evolving tactics, techniques and procedures (TTPs) employed by threat actors to obtain initial access to networks and to evade detection. Although the primary targets of the malware are unclear, threat actors are actively exploiting known confluence vulnerabilities before deploying the worm. Consequently, we assess that this TTP will possibly provide an access vector for the worm. Organisations in Georgia, Latvia, Moldova, Taiwan, Ukraine and the US have previously been victims of this vulnerability, highlighting the risk of further exploitation on a global scale. (Source: Sibylline)

 

22 Feb 24. Creomagic Ltd., a global leader in Wireless Communication Solutions to showcase CreoHub —an advanced personal radio device that acts as a fortress of connectivity engineered to support secure, immune, and intelligent communication for tactical units engaged in modern warfare and complex security operations. CreoHub unique capabilities address the critical challenges of spectrum scarcity, electronic warfare, and seamless integration of autonomous systems within tactical frameworks. Creomagic will showcase CreoHub at Enforce Tac, Nurnberg, Germany, 26-28 February 2024. In the rapidly evolving arenas of combat and security, the need for a resilient communication system to counter emerging threats has become increasingly crucial. CreoHub is a field-proven radio device for modern military operations ensuring uninterrupted, high-throughput wireless coverage for multidomain operations across land, air, and sea. CreoHub advanced radio capabilities establish secure and resilient networks ensuring robust connectivity even in the most contested and challenging environments.

“CreoHub encapsulates our vision for a seamless, secure, and intelligent communication ecosystem, specifically designed to meet the rigorous demands of tactical units,” remarks Alex Shapochnik, Creomagic Co-Founder and CEO. “It represents our relentless pursuit of innovation, providing tactical teams with a decisive edge in operational areas.”

Equipped with cutting-edge antennas technology, Cognitive-Radio methodologies, and powered by Artificial Intelligence, CreoHub secures a dominant position in the field by ensuring uninterrupted connectivity and high data transfer rates under any condition.

Its advanced waveform technology and adaptive networks are tailored to maintain operational continuity and resilience, proving indispensable for mission success.

Operational feedback from tactical experts underscores CreoHub’s critical role in transforming tactical communication landscapes, presenting a new era of mission efficiency and security.

 

21 Feb 24. Northrop ‘combat edge’ software connects troops without cloud. Northrop Grumman said it successfully tested software that can receive, share and tailor data on handheld devices used by U.S. troops without the need to link to a cloud server miles away from the battlefield.

Testing of the “combat edge software” involved Link 16 data, the Virginia-based company said in an announcement Feb. 21, and represented another step toward realizing the Pentagon’s Combined Joint All-Domain Command and Control vision.

The CJADC2 campaign aims to connect disparate databases and forces across land, air, sea, space and cyber, enabling the best-positioned and best-armed force to strike first. Future adversaries will attempt to disrupt those links. Northrop’s software accounts for that as well as what troops actually need in the field.

“We’ve come a long way. It is no longer just a question of, ‘Hey, it’s hard to get data somewhere,’” Kevin Berkowitz, Northrop’s vice president of secure processing and networks, told C4ISRNET in an interview. “It’s now about getting the right data somewhere and getting it there quickly, and in a way that’s meaningful for the end user.”

RELATED

“The broadscale data that comes from the cloud server, there’s a place for that, if you look at operations centers and others where they have large systems,” he said. “But we also realize that you have to get data to the end user, the soldier on the battlefield, that takes advantage of all that information that’s there, but isn’t always tied to or dependent on it. They don’t need that overarching infrastructure.”

The software is constructed to cooperate with different waveforms and networks — not just the Link 16 that was tinkered with — and plays well with existing equipment, including products Northrop furnishes.

Berkowitz said it has potential applications across the military, but noted the Air Force and Navy are providing “a lot of pull” initially. Both services operate across vast distances, on the move and in remote areas where connectivity is strained.

“By definition, this is really lightweight. You can put it on devices that take very little power from a physical-energy perspective, from a processing-power perspective,” Berkowitz said.

“The concept is not that we are going to go sell you a box to do ‘combat edge,’” he added. “We have customers that have existing needs.” (Source: Defense News Early Bird/Defense News)

 

21 Feb 24. Hicks Announces Delivery of Initial CJADC2 Capability. The Defense Department has delivered its initial iteration of the Combined Joint All-Domain Command and Control, or CJADC2, capability, Deputy Secretary of Defense Kathleen Hicks announced today.

The initial version represents a minimum viable capability combining software applications, data integration and cross-domain operational concepts designed to provide decision advantage to warfighters.

“The minimum viable capability for CJADC2 is real and ready now,” Hicks said during the keynote address at Advantage DOD 2024: Defense Data and AI Symposium, a three-day event hosted by the Pentagon’s Chief Digital and Artificial Intelligence Office in Washington.

CJADC2 is the department’s approach to developing both material and non-material solutions to deliver information and decision advantage to commanders.

The department aims to apply the CJADC2 approach across all warfighting domains to give warfighters the edge in deterring and, as necessary, defeating adversaries anywhere throughout the globe.

Hicks noted CDAO’s critical role in getting the initial iteration across the finish line, after being challenged last summer to deliver a minimum viable capability in a matter of mere months.

She said that due to security reasons she could not reveal where or what the initial capability announced today was specifically developed for.

“But what I can tell you it was no easy task, especially in six months,” she said. “But with a lot of hard work across many teams, pairing operators across multiple commands with engineers from DOD and industry, they delivered on time and on target.”

She said the first iteration has proven to be low latency and reliable, adding that it represents “the beauty of what software can do for hard power.”

“Delivery doesn’t take years or decades,” she said. “Our investments in data, AI and compute are empowering war fighters today.”

The department intends to build on the success, Hicks said, to deliver the capability at scale.

“Our goal is to be ahead of the curve, not chasing the curve,” she said. “CDAO will play a critical role in this next phase of our development, but so too will our operators and research, development and acquisition professionals throughout the Defense Department.”

Hicks said staying ahead of the curve requires sustained improvement in internal processes, investments in talent and effective partnerships with industry.

It also requires predictable and timely appropriations from Congress.

“We can’t do it without resources,” Hicks said. “One of our combatant commanders recently reached out to me noting that the advances that they’re relying on from CDAO are dead in the water without our fiscal year 2024 appropriations.

“We need Congress to come together and pass appropriations for 2024 ASAP,” she said. “It is long overdue, and the delay is devastating.”

The initial rollout represents a tangible outcome from DOD’s focus on adopting innovations that can deliver military value under Hicks and Secretary of Defense Lloyd J. Austin III.

That focus includes rapidly and responsibly investing, iterating and building “a more modernized, data-driven and AI-empowered military now,” Hicks said.

“There’s no debating the why, because these technologies give us an even better decision advantage than we already have today,” she said. “And that’s imperative given the pacing challenge we face from the People’s Republic of China in deterring and defending against aggression.”

Investments in AI, specifically, can greatly improve the speed, quality and accuracy with which commanders make decisions, giving them a decisive advantage in deterring conflict and winning a fight, Hicks said.

“Data and AI are necessary to empower our warfighters,” she said. “We have to capitalize on that.”

But she cautioned that the U.S. is not engaged in an AI arms race with other nations and will continue to lead in the responsible development of new technology.

“We need speed and safety,” she said. “We have to be responsible and rapid. We don’t have the luxury of choosing one or the other. It has to be both for the good of the nation, for the good of our mission and for the good of the world.” (Source: U.S. DoD)

 

21 Feb 24. Global: New vulnerabilities, discontinued software point to increased espionage threats to firms. On 20 February, the software company VMware released an urgent advisory prompting customers to remove their Enhanced Authentication Plug-in (EAP) from servers. This plug-in relies on an integration with Windows Authentication services to enable seamless user logins. It was deprecated by VMware in 2021 and contains two vulnerabilities (CVE-2024-22245 and CVE-2024-22250). These vulnerabilities expose users’ credentials to threat actors during authentication processes; some threat actors are able to hijack a legitimate EAP session to gain unauthorised access to a network. A critical vulnerability in VMware was actively exploited by a Chinese cyber espionage group in January, underscoring the elevated security risks facing firms. As global espionage campaigns against various countries’ defence and technology sectors ramp up, we assess that these vulnerabilities will likely be leveraged by global state-backed cyber groups. VMware urged customers to disable the service, highlighting the importance for organisations to remove deprecated products promptly. (Source: Sibylline)

 

21 Feb 24. Thales Enables A Secure Connected World. Thales actively contributes to making the world not just more connected, but also cyber-secured from the edge to the core – a testament to its unwavering dedication in building secure solutions for a connected world.

  • With more than 650 customers relying on Thales connectivity solutions every day, Thales enables a successful journey towards the digital era, as it simplifies IoT deployment with eSIM-based technology, maximizes 5G security, and anticipates post-quantum threats with cutting-edge encryption.
  • Thales remains committed to pioneering solutions that not only push the boundaries of innovation but also ensure a secure and resilient digital landscape for bns of people and devices relying on its technology worldwide.

Thales, a global leader in digital security, continues to advance its mission of securing data and identities for bns of people and objects in the connected world. Ranging from consumer devices to smart cars, Thales expertise supports the telecom industry on its road to 5G deployment with scalable, secure, and sustainable solutions. This year at the Mobile World Congress, Thales showcases its expertise around four major focuses:

Revolutionizing eSIM Management: In an accelerating digital world, the game is changing: subscribers want more flexible and bespoke experiences that meet their needs. The eSIM technology enables new use cases that reinvent how to engage customers and offer them new services by emphasizing optimal connectivity experience. Discover Thales solutions that help capture new business possibilities by attracting subscribers in new ways and developing connectivity offers.

Simplifying IoT Deployments: Massive IoT deployments need effective connectivity and cybersecurity management, which frequently result in manufacturing, logistical, and operational issues. Thales improves any IoT journey (from connected devices to connected cars) with an all-in-one solution that overcomes existing technology limits to ensure IoT deployments are simpler, safe and robust, while preserving flexibility of choice throughout the device’s lifespan.

Leading the Change in 5G Security: As the mobile industry embraces the transformative power of 5G, Thales stands at the forefront, ensuring that security is not compromised in the pursuit of connectivity. Thales leverages its extensive expertise to provide scalable and robust security solutions, contributing to the growth and adoption of 5G technologies globally. Whatever it addresses 5G private network or 5G non-terrestrial network, Thales’ security-by-design approach enables the technology to unleash wide range of new businesses.

Pioneering Post-Quantum Cryptography: Acknowledging the future challenges posed by quantum computing, Thales pioneers post-quantum cryptography. By staying ahead of the curve, Thales reinforces its commitment to long-term data security, developing solutions that are resilient against emerging quantum threats.

“As we showcase our latest innovations at the Mobile World Congress, we reaffirm our commitment to securing the evolving landscape of mobile and IoT connectivity. From fortifying 5G security to facilitating eSIM management and leading post-quantum cryptography, we are dedicated to bringing secure solutions for a connected world. Join us on this transformative journey as we set new benchmarks for the new use cases the industry brings, ensuring that every connection is not just seamless but secured against the challenges of our digital era” said Eva Rudin, VP Mobile Connectivity Solutions at Thales.

This year, the Software République’ s concept car will be demonstrated at the GSMA Pavilion, Hall 4, Booth F30. Feel free to stop by and learn how Thales is bringing security and convenience to Smart Mobility.

About Thales

Thales (Euronext Paris: HO) is a global leader in advanced technologies within three domains: Defence & Security, Aeronautics & Space, and Digital Identity & Security. It develops products and solutions that help make the world safer, greener and more inclusive.

The Group invests close to €4bn a year in Research & Development, particularly in key areas such as quantum technologies, Edge computing, 6G and cybersecurity.

Thales has 77,0001 employees in 68 countries. In 2022, the Group generated sales of €17.6bn.

 

19 Feb 24. Babcock unveiled as headline sponsor for code-breaking challenge. Babcock is delighted to be named as headline sponsor for the Army Benevolent Fund’s (ABF) flagship fundraising event, Operation Bletchley.

Each year people from across the world take part in the physical and mental challenge this event offers, raising vital funds to support soldiers, veterans and their immediate families. Operation Bletchley is one of the UK’s most innovative events, giving participants the opportunity to tackle the fiendish codes, explore the great outdoors and learn more about our incredible heroes from the Second World War.

Tom Newman, CEO of Babcock’s Land Sector, said: “Operation Bletchley is the second event we are sponsoring as part of our commitment to supporting the armed forces community through the valuable work of ABF.

“We have a long-standing relationship with the British Army, working closely with them to deliver critical equipment, support and essential technical training, as well as providing employment opportunities for service leavers and reservists. Supporting Operation Bletchley enables us to further strengthen our support by helping the next generation of the army family to develop the skills and attitudes of future soldiers and supporting STEM learning and wellbeing outcomes.”

As well as supporting ABF with Operation Bletchley, Babcock is also the headline sponsor for this year’s Cateran Yomp, a gruelling hike across the Scottish Highlands, which takes place in June.

Major General Tim Hyams CB, OBE, Chief Executive Officer, Army Benevolent Fund said:

“We are delighted to have the support of Babcock to help us grow our award-winning event programme, which exists to raise vital funds to support the Army Family. This demonstration of commitment to the Army’s National Charity helps us continue to deliver benevolence quickly and effectively to those in need.”

To find out more about ABF and Operation Bletchley visit: Army Benevolent Fund. To enter the Cateran Yompm, visit: The Cateran Yomp 2024 (armybenevolentfund.org)

 

17 Feb 24. Leonardo kicks off Space Cloud project for Italy’s armed forces. Italy’s state-owned Leonardo (LDOF.MI), opens new tab said on Monday that the Ministry of Defence had asked it to study the development of its military space cloud architecture project, the first in Europe.

The project, dubbed MILSCA, will provide Italy’s government and armed forces with a system of high-performing computing, cloud and artificial intelligence (AI) and storage capacity directly in space, the statement said.

During the two-year study, Leonardo will cooperate with Telespazio and Thales Alenia Space, two joint ventures between the Italian defence and aerospace group and France’s Thales (TCFP.PA), opens new tab.

It falls in line with Leonardo’s main goals for the years ahead to focus on the space industry – key for defence and security in the future – and setting up interconnected, multi-domained digitalised platforms, aimed at supporting its traditional products.

MILSCA will guarantee users access to strategic data such as communications, earth observation, and navigation data, anywhere and at any time.

It can grant higher speed and flexibility in the processing and sharing of information, with 100 Terabytes of data storage on Earth and in space aboard each satellite and a processing power of over 250 TFLOPS, or 250 thousand bn operations per second.

In the first phase of the study the architecture will be defined, while in the second phase a digital twin will be developed.

“In a multi-domain scenario, management, security, and rapid exchange of an ever-increasing amount of data, much of which is tactical, become strategic elements for the country’s defense. We will be the first in Europe to develop a Space Cloud project…,” Leonardo’s Chief Innovation Officer Simone Ungaro said in a statement. (Source: Reuters)

 

19 Feb 24. Global: Newly identified software vulnerabilities point to increased cyber espionage risks for firms. On 16 February, researchers discovered five remote code execution (RCE) vulnerabilities in the Access Rights Manager (ARM) solution of software developed by the company SolarWinds. ARM is a software solution designed to help organisations manage user access across their IT infrastructure. In all, three of these vulnerabilities (CVE-2023-40057, CVE-2024-2347 and CVE-2024-23476) were exposed to threat actors able and willing to compromise systems and to execute malicious code remotely. SolarWinds’ clientele exceeds 300,000 contracts worldwide; these include high-profile companies, such as Amazon and Google, as well as several government organisations. Notably, the company’s Orion IT administration function was compromised four years ago by a Russian threat group, APT29, which resulted in several US government agencies being breached. Although we do not assess that these vulnerabilities are currently being actively exploited, the recent spike in cyber espionage activities by Russian state-sponsored groups points to an increased likelihood of exploitation in the short term. SolarWinds has since released an update (Access Rights Manager 2023.2.3) in an attempt to fix these vulnerabilities. (Source: Sibylline)

 

16 Feb 24. US: Disruption of Russian hacking operation underscores risk of attacks facing critical infrastructure. On 15 February, the Department of Justice (DOJ) announced that the FBI and international US allies disrupted a Russian hacking operation that infiltrated more than 1,000 home and small-business internet routers in the US and around the world. The DOJ stated that Russian intelligence, in collaboration with cyber criminals, created a network of private computers infected with malicious software to spy on military and security organisations and private firms in the US. The announcement comes one day after the Biden administration alerted Congress that Russia is seeking to create a space-based nuclear weapon to target US satellites. In the short term, we assess that these efforts will aid the White House in convincing Republicans to fund Ukraine’s military operations by linking the Russia-Ukraine war to US national security. In the medium-to-long term, we assess that Russia-US bilateral relations will remain strained, a situation that will be sustained by Russian attempts to target critical US infrastructure and to carry out reconnaissance operations on the US energy sector. The heightened likelihood of a foreign-sponsored attack will raise energy security risks in the long term. We assess that firms in the military, technology and energy sectors will face an increased risk of cyber attacks in the long term. (Source: Sibylline)

 

16 Feb 24. Poland: New Russian backdoor signals heightened cyber espionage risks facing global businesses. On 15 February, researchers from the information security company Cisco Talos reported that a Russian advanced persistent threat (APT) group, ‘Turla’, conducted a cyber espionage campaign against various Polish NGOs. The group used a new version of their known custom backdoor, ‘TinyTurlaNG’, which is a ‘last chance’ backdoor that mainly operates on Windows systems. The term ’last chance’ means that the malware is left behind on an infected system to be used when all other unauthorised access avenues have failed. The new iteration introduces features such as the ability to execute instructions on the infected system remotely and also the ability to exfiltrate files that may be of interest to the threat actor. This points to an increase in efforts by Russia to supplement ongoing kinetic developments in Ukraine with cyber-related espionage operations. We assess that it is highly likely that similar campaigns will occur in the short-to-medium term against both private and public organisations. (Source: Sibylline)

 

16 Feb 24. Cyber Update Key points.

  • France suffered its largest ever cyber security breach following a data leak of customers’ information from two health insurance companies (see Sibylline Cyber Daily Analytical Update – 12 February 2024).
  • A bug in the split tunnelling feature of the Windows version of the virtual private network (VPN) software ExpressVPN exposed users’ browsing habits.
  • Election personnel and infrastructure in South Korea, the UK and the US will be the most likely targets for cyber threat actors in the upcoming elections (see Sibylline Cyber Daily Analytical Update – 14 February 2024).
  • Microsoft unveiled a zero-day vulnerability (CVE-2024-21410) in its Exchange server that had been actively exploited by threat actors (see Sibylline Cyber Daily Analytical Update – 15 February 2024).
  • The Russian advanced persistent threat (APT) group ‘Turla’ was observed conducting a cyber espionage campaign against various Polish NGOs Technical analysis of weekly stories.

The Russian advanced persistent threat (APT) group ‘Turla’ recently used a new version of its backdoor, ‘TinyTurlaNG’, which operates on Windows systems as a ‘last-chance’ backdoor. TinyTurlaNG allows a threat actor to maintain access to an infected system when all other avenues of unauthorised access have been detected or have failed. The backdoor was installed using a ‘svchost.exe’ file to emulate a legitimate Windows Time Service file. This allows the malware to run on the infected system. The malware hides in one of Microsoft’s authorised processes. Once installed, the malware runs through a list of pre-configured command-and-control (C2) servers every five seconds to establish a C2 connection to communicate with and execute additional commands on compromised devices. TinyTurlaNG can be used to upload, execute and exfiltrate files from an infected system. The simplicity in the coding style of this backdoor makes it difficult for anti-malware systems to detect the malware for prolonged periods of time.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity
  • Add available Indicators-of-Compromise (IoCs) to the organisation’s security detection systems to detect potentially malicious samples on the network
  • Ensure adequate security detection measures are in place, particularly behaviour-based end-point detection and response (EDR) solutions

A bug was identified in the split tunnelling feature of the Windows version (12.23.1-12.72.0) of the VPN software ExpressVPN. The bug inadvertently exposed users’ browsing habits to their internet service provider (ISP), potentially allowing for third-party monitoring. Split tunnelling is a widely used VPN feature that enables users to select what portion of their internet traffic is protected by the VPN’s secure connection, and what can access the internet directly. This determines how traffic is routed. Therefore, traffic requests secured by the VPN will be sent to the VPN’s own unmonitored server. The newly discovered flaw was, however, sending some of these secure requests to the user’s ISP servers, violating their privacy. While the content of the user’s browsing activity remained confidential, the user’s domain visitations were vulnerable to targeted advertising and/or further tracking.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Apply patches to software vulnerabilities as soon as they are released to prevent exploitation
  • Ensure adequate security detection measures are in place, particularly behaviour-based end-point detection and response (EDR) solutions

Word(s) of the week

Our cyber word(s) of the week: NTLM Relay Attack.

(Source: Sibylline)

————————————————————————-

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

————————————————————————-

Primary Sidebar

Advertisers

  • Pythia
  • Teledyne
  • Exensor
  • Visit the Oxley website
  • Blighter
  • SPECTRA
  • Britbots logo
  • Faun Trackway
  • Systematic
  • CISION logo
  • ProTEK logo
  • ProTEK logo
  • ssafa logo
  • IEE
  • EXFOR logo
  • sibylline logo
  • Team Thunder logo
  • Comtech logo
  • GoExporting logo
  • ECHODYNE logo
  • Supercat logo
  • Galvion logo
  • Leonardo DRS logo
  • MTC logo
  • IDC logo
  • DSEI logo
  • DVD2024 logo
  • SDSC logo
  • TELEDYNE FLIR logo
  • VeteranUK logo
  • Matrix Space logo
  • ST Engineering logo
  • EWS logo
  • sentinel photonics logo
  • capua logo
  • Curtiss-Wright logo
  • Brave1 logo
  • Drone Evolution logo
  • AEI Systems logo
  • EOS logo
  • NMSUK logo
  • Openworks logo
  • Sandown Park logo
Hilux UKDSE AARTOS ST Engineering Future Artillery

Contact Us

BATTLESPACE Publications
41 St Georges Drive
London SW1V 4DG

+44 (0)77689 54766

BATTLESPACE Technologies

An international defence electronics news service providing our readers with up to date developments in the defence electronics industry.

Recent News

  • Protek Selected By Dutch Armed Forces

    May 2, 2026
    Read more
  • PARLIAMENTARY QUESTIONS

    May 1, 2026
    Read more
  • MANAGEMENT ON THE MOVE

    May 1, 2026
    Read more

Copyright BATTLESPACE Publications © 2002–2026.

This website uses cookies to improve your experience. If you continue to use the website, we'll assume you're ok with this.   Read More  Accept
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT