• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • SPECTRA banner
  • Curtiss-Wright banner

BATTLESPACE Updates

   +44 (0)77689 54766
   

  • Home
  • Features
  • News Updates
  • Defence Engage
  • Company Directory
  • About
  • Contact

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY

March 8, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

————————————————————————

07 Mar 24. Global: New malware campaign highlights growing security risks posed by third-party cloud services. Earlier on 7 March, the cloud security company Cado Security warned that a new malware campaign (‘Spinning YARN’) is affecting misconfigured cloud services in Linux systems. The campaign has primarily targeted the software platform ‘Docker’. Threat actors first employ malicious programmes to identify and infect misconfigured services; they then create a new instance within the victim’s infrastructure to establish communication with actor-controlled servers, before deploying malicious files. The campaign subsequently deploys crypto-mining software to garner illicit profit. The increasing reliance on third-party cloud services to scale up companies’ operations will place greater pressure on firms’ IT teams to protect wider and more complex attack surfaces. Threat actors looking to garner illicit profit are exploiting weaknesses in these services, elevating the financial and operational risks facing firms. The recent campaign underscores the heightened security risks misconfigured and inadequately secured third-party cloud services pose to companies.(Source: Sibylline)

 

06 Mar 24. Dependency Syndrome. Social media continues to be a mine of information on how Russia evades sanctions to acquire EW technologies that support her continued occupation of Ukrainian territory.

Late February brought the revelation that Keysight Technologies products are ending up in Russian hands. As an American company, Keysight Technologies is subject to US government restrictions regarding Russia. These restrictions forbid a wide array of technology exports to Russia and full details of the restrictions can be found here. There are no suggestions that the company is willingly supplying its products to Russia. As has happened with other US technology companies, Russia illicitly buys these products through intermediaries.

The customer

Dogged investigation by @Tataigami_UA published both on Twitter (called X by almost no one) and their own Substack page has revealed how Keysight’s products have ended up in Russian hands. The first link in the chain is a Russian company called the Special Technology Centre (STC) which is the customer. Based in St. Petersburg, northern Russia, one of STC’s products is the Orlan-10 Uninhabited Aerial Vehicle (UAV). The Orlan-10 forms a key part of the Russian Army’s Leer-3 electronic warfare system. STC is acquiring Keysight’s products despite being sanctioned by the Office of Foreign Assets Control (OFAC). The OFAC administers and enforces economic and trade sanctions and is part of the US Department of the Treasury.

The intermediaries

How does STC acquire these products? @Tataigami_UA suggests they are sourced through intermediary companies. This process helps to obscure STC as the final recipient and hence avoid restrictions and sanctions. Three Russian companies chiefly Radioline, headquartered in Moscow, and Dipaul and RITM, both based in St. Petersburg, have offered to supply STC with Keysight’s products. The investigation cited Mikhail Mulminov, thought to be a citizen of St. Petersburg, as key to the operation. Mr. Mulminov worked as Keysight’s regional representative in the past, according to @Tataigami_UA. Another Russian company involved in the acquisition is Protech. Not much is known about this enterprise although evidence suggests it is also based in St. Petersburg.

The Russian companies purchasing on behalf of STC are probably doing so through third parties. In this case, it appears Keysight has been unlucky. A glance at the company’s website reveals that systems can be brought off-the-shelf with relative ease. Are products being purchased by companies in third countries not under US sanctions then sold overtly or covertly to the companies in Russia? It is impossible to say for certain and Keysight did not respond to Armada’s requests for information.

Tightening the noose

Nonetheless, this recent revelation underscores that Russian companies in the Electronic Warfare (EW) sector continue to source sophisticated electronics indirectly from Western suppliers with comparative ease. It is difficult combat this trade lest it affect companies in third countries making legitimate acquisitions. That Russian companies procure Western electronics for their EW systems shows how dependent they are on them. Clearly, the products they are acquiring are ones they cannot produce or procure equivalents of at home. Countries supporting Ukraine need to continue doubling down on their efforts to choke Russia’s dependence on advanced electronics.(Source: Armada)

 

06 Mar 24. Blowin’ up my phone. There are several mechanisms by which cellphones can be detected, located and tracked on the battlefield. These methods include detecting and tracking the phone’s signal or hacking into the network it uses. A new report highlights the challenges of tracking cellphones on the battlefield using the ongoing war in Ukraine as a case study.

Arguably the first ‘smartphone’ war, the ongoing conflict in Ukraine has underscored the important role these devices continue to play in this war, and that they will play in the future. At the military level, smartphones can be a useful tactical communications alternative to military transceivers. Smartphones let people stay in touch or use the internet when conventional telecommunications may be damaged or unavailable. These devices have been invaluable for collecting and sharing evidence of Russian-perpetrated atrocities. Worryingly, smartphones are also effective conduits for the torrents of Russian propaganda, disinformation and outright lies Vladimir Putin’s regime spews into the ether.

A report published in February by ENEA takes a detailed look at the questions surrounding the use of cellphones on, and near, the battlefield. In January 2023 the Russian military blamed cellphone signals from Russian troops for helping the Ukrainian Army locate a target in Makiivka in southeast Ukraine. Reports say scores of Russian troops were killed when a college they were using was hit on 31st December 2022. Russian troops are banned from using their cellphones within range of Ukrainian weapons. As ENEA’s report makes clear, whether these signals were responsible for the geolocation of the Russian troops is debatable.

Are you gonna reach my telephone?

ENEA’s study says that cellphone signals can be located through passive radio frequency sensing and then triangulated to determine their point of origin. This method relies on the cellphone actively transmitting. Active direction finding is a more complex approach involving a tracking station. The station will communicate with the phone making it generate a signal as a response. Once this signal is generated it can be geolocated. This approach also lets Communications Intelligence (COMINT) cadres retrieve details from the targeted phone such as its SIM (Subscriber Mobile Identity) card number. The Russian Army’s Leer-3 COMINT system is thought to use the active direction finding method. Location retrieval over radio networks is a third method flagged in ENEA’s paper. A location tracker will send radio measurement commands to any cellphones being tracked. Usually, this is done innocently by networks to ascertain link quality and improve performance. Through mathematics the local retrieval over radio networks approach can determine a cellphone’s location.

Hacking presents another means to locate a phone. Network enabled tracking extracts location information for phones attached to any specific mobile network. Specifically, the Signalling System-7 (SS7) protocol, which governs traffic routing and billing, is exploited. It is possible to locate and track subscribers on a network by gaining access to SS7 protocols. Likewise, mobile operator telecom hacking can compromise network nodes which are then exploited for subscriber location information. It is also possible to insert malware into cellphones which is then used to track the device as chronicled in this Armada article.

Shoulda left my phone at home!

What does all this mean for cellphone use on the battlefield or more generally in the theatre of operations? “Regarding mobile phones … the surprise has been the increased use of them, and commercial communications in general, by military forces,” says Cathal McDaid, ENEA’s chief technology officer and one of the report authors. “(E)missions control of mobile devices should be as effective as possible, so if mobile devices are used, as seems increasingly common, then they should be used sparingly and with safeguards.”

Cellphone networks are now centres-of-gravity in contemporary and future warfare as targets that can be exploited to determine troop locations, hamper communications and disrupt morale. Alongside geolocation, electronic attacks against cellular networks could deprive militaries of alternative tactical communications. Exploiting cellular networks to spread false, misleading or demoralising traffic can have a powerful psychological impact.

Reflecting this importance cellular networks in Ukraine “have been secured and made more resilient by both parties, this improved connectivity has been present up to the edge and in many cases on the battlefield.” The flipside of this, says Mr. McDaid, “is ample opportunity to identify active and transmitting mobile devices.”

The effect the war in Ukraine is having on cellular networks, and vice versa, has an impact far beyond the theatre of operations. So-called fifth generation (5G) cellular protocols are being embraced by militaries to enhance communications both on and off the battlefield. NATO (North Atlantic Treaty Organisation) members and allied nations would do well to digest the lessons of ENEA’s report. Civilians in these nations should also take note. The cellular networks we all rely on are valuable targets in peace as well as war. Understanding network, and hence our own, vulnerabilities, makes sense.

Wise words: The translation of advice given to Ukrainian troops regarding cellphone use at, or near, the tactical edge. The ongoing conflict in Ukrainian is arguably the world’s first ‘smartphone war’, highlighting the importance of emissions control. (Source: Armada)

 

06 Mar 24. March Spectrum SitRep. The graphical user interface of Patria’s ARIS-E electronic support measure is shown in this image. The company has just concluded agreements to supply its ARIS ELINT system to two NATO members.

Armada’s monthly round-up of all the latest electronic warfare news in the product, programme and operational domains.

New ARIS Acquisitions

In early February, Patria announced it had signed agreements to supply the company’s ARIS Electronic Intelligence (ELINT) system to two undisclosed North Atlantic Treaty Organisation (NATO) members. ARIS is produced in two versions, the ARIS and ARIS-E. The key difference is that the ARIS is designed for ELINT gathering while ARIS-E adds Electronic Support Measure (ESM) functions. The company’s literature says that ARIS covers a waveband of 270 megahertz/MHz to 18 gigahertz/GHz. Optional increases for ARIS include extensions of 20MHz to six gigahertz, and 18GHz to 40GHz. ARIS-E works across a two gigahertz to 18GHz waveband. Options exist to extend this waveband downwards to 800MHz and upwards to 40GHz. Although the company cannot disclose when these ARIS deliveries will take place, it did tell Armada that the product is usually deployed in fixed, transportable and mobile ground configurations. That said, ARIS can also equip naval and airborne platforms. “ARIS relies on high-gain, directional antennas … whereas ARIS-E relies on interferometer antenna units providing automatic direction finding, 360-degree field-of-view (with multiple antenna units) and ultra-wide instantaneous frequency bandwidth,” the company said in a statement. Both ARIS and ARIS-E geolocate emitters-of-interest using line-of-bearing, angle-of-arrival and triangulation techniques; the latter with two or more sensors. Whereas ARIS “focuses on intelligence use cases … ARIS-E focuses on surveillance use cases.” As well as supporting ELINT collection and analysis of radar signals, both systems can intercept communications signals “when they fall into the supporting frequency ranges.”

This year’s Full Spectrum Air Defence conference takes place at London’s Hilton London Syon Park Hotel in west London. The event is an excellent opportunity to sample the latest research and perspectives on a host of subjects, and network with colleagues.

Air Defence Week – Call for Papers

This year, IQPC will once again run its Air Defence Week event in London between 24th and 27th June. The event takes place in the delightful setting of Syon Park in the west of the city. Syon Park is the home of Syon House which was built in 1552. The house has a rich history. It was where Catherine Howard, the fifth wife of the England’s King Henry VIII (1491 – 1547), was imprisoned. Lady Jane Grey, the ‘nine days queen’, lived at the house before her short reign in July 1553. More recently, in 1609, Syon Park was the venue for the first ever use of the telescope. This year’s conference comprises three events under one roof at the Hilton London Syon Park hotel. These include Directed Energy Systems (24th June), Full Spectrum Air Defence (25th to 26th June) and Military Radar (27th June). As with previous events, delegates can expect to hear the latest research and operational perspectives on a host of subjects. The conferences also present great networking opportunities. IQPC is keen to hear from potential speakers, and proposals for presentations are most welcome. Please do feel free to contact the conference producer, Lucy Breuning () for more information. (Source: Armada)

 

05 Mar 24. RoK: Ongoing campaign points to growing espionage risks facing defence, technology firms. On 4 March, the South Korean National Intelligence Services (NIS) disclosed that North Korean actors have conducted several cyber espionage campaigns against defence and technology firms since late 2023. At least two South Korea-based semiconductor companies were targeted in these operations. The threat actors stole sensitive data – including product design drawings and facility site photos – possibly to spur North Korea’s own production of semiconductors. The campaigns started with the threat actors exploiting vulnerabilities in internet-exposed assets to obtain initial access to corporate networks. The threat actors then used ‘living off the land’ techniques, thus exploiting native and legitimate software to evade detection within the victim’s network. North Korea has recently boosted its participation in cyber espionage campaigns to bypass economic sanctions and to continue advancing its satellite and missile programmes. Various non-Western states have employed cyber operations more widely against defence and technology sectors to bolster their economic and security postures. Subsequently, we assess that this underscores the growing espionage threats posed by these actors to defence and technology firms both in South Korea and across the globe. (Source: Sibylline)

 

04 Mar 24. Thales collaborative cloud solution certified to European Restricted level.

  • In 2021, TrustNest R-Cloud became the first cloud solution certified for use with information classified as Restricted Distribution in France, and is now available for European projects with the new European Restricted certification approved by ANSSI, the French national cybersecurity agency.
  • The TrustNest R-Suite applications marketplace hosted on this cloud since 2023 will now be authorised to offer European Restricted services to help companies collaborate more easily on European projects involving sensitive data.

As companies purse their digital transformation, remote collaboration in the cloud has come to play a key role in project management and is easy to set up with the cloud solutions available to the general public. But until now, the use of these public cloud solutions was not authorised for strategic projects handling sensitive data. Thales developed its R-Cloud platform to meet this requirement. With the new solution, partners on projects handling information classified as Restricted Distribution (RD) in France – and now European Restricted in Europe – can use collaborative tools that were previously unable to provide the necessary security assurances. The TrustNest R-Suite marketplace brings users all the benefits of the collaborative cloud without compromising on security.

ANSSI’s approval of European Restricted certification – the first time a single cloud has been certified for use by several clients – marks a significant milestone in that it sets the official seal of approval on the use of TrustNest R-Cloud on major European projects involving France and all the other EU Member States.

TrustNest R-Cloud has offered a Restricted Distribution collaboration solution to French companies of all sizes since January 2022, and the certified TrustNest R-Suite of as-a-service applications was added in 2023. Today, Thales is making these applications available for use on major European programmes that require European Restricted certification, to provide videoconferencing and team chat services, support co-development of sensitive software and hardware by teams located in different countries, supervise projects and manage resources using Software-as-a-Service (SaaS) applications.

This latest certification consolidates the position of TrustNest R-Suite as the preferred collaborative software suite for major French and European strategic programmes.

About TrustNest R-Cloud

TrustNest R-Cloud is the first collaborative cloud solution with both French Restricted Distribution and European Restricted certifications. Entirely operated by Thales, it is interconnected with the sensitive networks of multiple partners. Under French regulations, it meets the requirements of Ministerial Instruction No. 901 for protection of systems handing Restricted Distribution information in France, and General Interministerial Instruction No. 2102 for protection of systems handing European Restricted information. TrustNest R-Cloud brings organisations all the benefits of a cloud infrastructure, including elasticity, scalability and updatability. TrustNest R-Suite brings together all the SaaS applications hosted on this cloud, providing authorised companies access to an innovative suite of as-a-service applications to collaborate more easily and deliver sensitive projects more quickly.

As a trusted partner, Thales offers users of public, private, defence and restricted clouds highly secure, easy-to-deploy solutions that are tailored to the nature of the organisations involved, the level of protection required and their specific service needs.

Find out more about TrustNest R-Suite here: TrustNest R-Cloud (thalesgroup.com)

 

04 Mar 24. US: New multi-pronged campaign accentuates phishing risks facing organisations. On 2 March, the software company Lookout reported that it discovered a new phishing kit called ‘CryptoChameleon’. The campaign primarily targets US-based cryptocurrency users and employees of the Federal Communications Commission (FCC). It typically attempts to deceive them into disclosing sensitive information. The campaign begins with an email, SMS or voice call wherein the threat actor impersonates customer support to direct the victim to a malicious login site. Subsequently, the victim is asked to complete a CAPTCHA challenge designed to boost the site’s legitimacy and to avoid automated security detection tools. Cyber security experts have noted the high-level of sophistication associated with this multi-pronged campaign. It underscores that threat actors are becoming more skilled at evading detection via advanced tactics, techniques and procedures (TTPs), pointing to the increased security and information theft risks facing firms. (Source: Sibylline)

 

01 Mar 24. US-Europe: Government entities face heightened operational risks following FBI-led takedown. On 28 February, the cloud security company Zscaler reported that the well-known ‘LockBit’ ransomware group restarted operations following an FBI-led takedown operation in late February. Law enforcement seized the group’s infrastructure to access information on its affiliates as well as to retrieve victims’ stolen data. However, shortly after the seizure, Zscaler identified a series of LockBit ransomware attacks using new ransom notes, signalling that the group is once again operational. The new ransom notes leverage Tor software (a free and open-source medium used to access the dark web; it allows users to conceal their identity and communications, thereby remaining undetected). The group further stated on its new website that it would target government entities in retaliation, underscoring the elevated security and operational risks facing government organisations, particularly those that participated in the takedown campaign. In light of these new attacks from LockBit’s freshly established infrastructure, we assess that government entities are likely to be targeted in ransomware operations in the short term. (Source: Sibylline)

 

29 Feb 24. Poland signs $2.5bn deal for US air-defense software hub. The Polish Ministry of National Defence has signed a $2.5bn deal with the U.S. government to acquire the Integrated Battle Command System, or IBCS, to synchronize the nation’s air- and missile-defense weapons under development.

Deliveries are scheduled for the years 2024 to 2031. Poland intends to use the system to operate its Patriot missile launchers, which are part of the Wisla medium-range, air-defense program, and the Narew short-range equivalent, which relies on MBDA’s Common Anti-Air Modular Missile, or CAMM.

The acquired systems will be used for six Wisla batteries and 23 Narew batteries, the country’s defense ministry said in a statement

Władysław Kosiniak-Kamysz, Poland’s deputy prime minister and national defense minister, signed the contract during an official ceremony on Feb. 29. “We will be the second country, after the United States, to have this system, an integrated command system,” he said.

Kosiniak-Kamysz was sworn in on Dec. 13 as a new Cabinet replaced the ousted government of the right-wing Law and Justice party.

Poland’s Oct. 15, 2023, parliamentary election, which paved the way for a change in government, prompted U.S. manufacturer Northrop Grumman to host an event with top executives in Warsaw in November to advertise the program during the transition.

With the purchase now secured, it appears that the new defense leadership here will stick to the previous government’s procurement schedule for the key components of the Wisla and Narew programs. (Source: Defense News Early Bird/Defense News)

 

01 Mar 24. JFHQ-DODIN Officially Launches its New Cyber Operational Readiness Assessment Program. Following a successful nine-month pilot, Joint Force Headquarters — Department of Defense Information Network is officially launching its Cyber Operational Readiness Assessment program today.

Over the past four years, JFHQ-DODIN has made significant changes to the Defense Department Command Cyber Readiness Inspection program, transforming mindsets from an inspection compliance to an operational readiness underpinning mission assurance. To enunciate this significant shift, the program has been renamed to the Cyber Operational Readiness Assessment.

According to Air Force Lt. Gen. Robert Skinner, commander of JFHQ-DODIN, CORA is one of the most critical components of the DOD’s cyber security strategy and lays a strong cornerstone to support the command’s goal of continuous holistic assessments. The new processes help strengthen the posture and resiliency of the DODIN by supporting the network’s Areas of Operation commanders and directors in efforts to harden their information systems, reduce the attack surface of their cyber terrain and enhance a more proactive defense. These are the foundational cybersecurity principles measured by the CORA program.

“CORA is a vital aspect of continually understanding our cyber readiness through fusing many risk factors including access control, detecting anomalies, adjusting to adversary threat information and executing cyber orders,” Skinner said. “Ultimately, the assessment provides commanders and directors a more precise understanding of their high-priority cyber terrain and their overall cyber security and defensive posture enabling greater command and control and enhancing decision making.”

John Porter, JFHQ-DODIN’s acting director of DODIN Readiness and Security Inspections directorate, said “CORA represents a consolidated look at threat, vulnerability and impact designed to give DAO commanders and directors relevant information for making decisions about cyber terrain, forces and other resources.”

“CORA prioritizes MITRE ATT&CK mitigations to minimize adversarial risk to the DODINs through JFHQ-DODIN’s risk-based metrics. The command created risk-based metrics after analyzing MITRE ATT&CK tactics, techniques, and procedures for initial access, persistence, privilege escalation, lateral movement and exfiltration,” Porter said.

MITRE ATT&CK is a knowledge base of adversarial TTPs utilized by cyber defenders world-wide to protect and defend information systems and networks and hunt malicious actors.

Porter said, “the JFHQ-DODIN CORA team developed key indicators of risk from the risk-based metrics to ensure alignment with JFHQ-DODIN cybersecurity priorities and to direct focus onto the most critical areas of remediation.”

This, in turn, allows organizations to focus their mitigation efforts on risk and exposure to common adversarial TTPs. He added, “focusing on these essential remediation points allows DOD Components to concentrate limited resources and staffing on correcting high-risk areas.” JFHQ-DODIN risk-based metrics and CORA key indicators of risk are adjusted as the MITRE ATT&CK TTPs and mitigations priorities shift, enabling the CORA program to keep pace with the rapidly changing cyber domain.

In addition to the key indicators of risk, Porter said “CORA is hyper-focused on securing the boundary.” The boundary consists of network perimeter devices, public and DOD facing assets servicing the public or external DOD components and any information systems with a direct interface to an external information system. The boundary reviews measure the cyber-hardening risk of information systems exposed to the public internet and the possibility that the malicious activity could spread to other DOD Components if an information system is compromised.

The CORA has become a more agile process encouraging and enabling adjustments in strides. The assessment can be adjusted as new orders, policies or directives are issued, add new assessed technology if Security Technical Implementation Guides exist, and adjust key risk indicators as the threat landscape changes.

The program will help ensure a strong cybersecurity foundation for all DOD networks. It will help DAO commanders and directors better understand the status of their high-priority terrain and their overall cyber security readiness and defensive posture and provide them with relevant information for making decisions about terrain, forces and other resources. At the same time, it will provide the U.S. Cyber Command and JFHQ-DODIN commanders a greater understanding of level of risk to the DODIN. CORA is crucial for validating current, future, and emerging technologies that will help the DOD continuously monitor and assess terrain to assess and mitigate risk across the DODIN. (Source: U.S. DoD)

 

01 Mar 24. Cyber Update. Key points.

  • A Russian PSYOP campaign targeting Ukrainian speakers points to elevated phishing and disinformation risks for Western organisations (see Sibylline Cyber Daily Analytical Update – 26 February 2024).
  • The evolving TTPs of a Russian threat actor include exploiting cloud-based environments, highlighting elevated supply chain risks facing organisations (see Sibylline Cyber Daily Analytical Update – 27 February 2024 and our Technical analysis below).
  • The active exploitation of new software vulnerabilities by the ransomware groups ‘Black Basta’ and ‘Bl00dy’ underscores the elevated supply chain risks facing firms (see Sibylline Cyber Daily Analytical Update – 28 February 2024).
  • New PDF vulnerabilities allow threat actors to execute malicious code, pointing to elevated phishing and social engineering risks (see Sibylline Cyber Daily Analytical Update – 29 February 2024 and our Technical analysis below).
  • The ‘Lockbit’ ransomware group resumed operations despite being disrupted by an FBI-led seizure of its infrastructure (see Sibylline Cyber Daily Analytical Update – 1 March 2024).

Technical analysis of weekly stories

The well-known ransomware groups Black Basta and Bl00dy exploited two new vulnerabilities (CVE-2024-1709 and CVE-2024-1708) in the popular remote desktop application ScreenConnect. The most critical vulnerability (CVE-2024-1709) allowed both groups to gain access to their victims’ systems and to escalate their privileges by exposing the backend of the application. The backend remained accessible, enabling the actors to override all user permissions and to create new accounts. This then allowed the actors to grant themselves permissions within the victim’s system without administrative approval while deleting other users. Black Basta exploited this vulnerability to infiltrate its victim’s system and deploy post-exploitation tools; it then performed reconnaissance and privilege escalation before deploying the ransomware. Similarly, Bl00dy leveraged this vulnerability to propagate in the target network and deploy ‘Conti’ and ‘LockBit’ ransomware files.

The Russian state-sponsored threat group APT29 is now using more refined techniques to compromise victims via their cloud infrastructure. The group has shifted its tactics, techniques and procedures (TTPs) to target companies’ cloud-based environments in an effort to increase its attack vectors. The newly employed techniques include password- and authentication-related attacks to infiltrate the victim’s system. Most notably, the threat actors targeted service accounts with brute-force and password spraying attacks, attempting to force their way into a user’s account by repeatedly trying to guess their password. They also adopted ‘Multifactor Authentication (MFA) Bombing’ techniques to trick victims into confirming their identifies by flooding them with authentication requests. After gaining access to the target system, the actors register their own device as a new device on the cloud instance. This then enables them to deploy sophisticated tools, such as ‘MagicWeb’, in order to carry out espionage activities.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Apply patches to software vulnerabilities as soon as they are released to prevent exploitation
  • Monitor devices and networks for suspicious activity
  • Create an accurate inventory of all serviced and dormant accounts and enforce regular auditing
  • Add available Indicators-of-Compromise (IoCs) to the organisation’s security detection systems to detect potentially malicious samples on the network
  • Ensure adequate security detection measures are in place, particularly behaviour-based end-point detection and response (EDR) solutions

Word(s) of the week

Our cyber word(s) of the week: Buffer overflow attack  (Source: Sibylline)

————————————————————————-

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

 

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

————————————————————————-

Primary Sidebar

Advertisers

  • Pythia
  • Teledyne
  • Exensor
  • Visit the Oxley website
  • Blighter
  • SPECTRA
  • Britbots logo
  • Faun Trackway
  • Systematic
  • CISION logo
  • ProTEK logo
  • ProTEK logo
  • ssafa logo
  • IEE
  • EXFOR logo
  • sibylline logo
  • Team Thunder logo
  • Comtech logo
  • GoExporting logo
  • ECHODYNE logo
  • Supercat logo
  • Galvion logo
  • Leonardo DRS logo
  • MTC logo
  • IDC logo
  • DSEI logo
  • DVD2024 logo
  • SDSC logo
  • TELEDYNE FLIR logo
  • VeteranUK logo
  • Matrix Space logo
  • ST Engineering logo
  • EWS logo
  • sentinel photonics logo
  • capua logo
  • Curtiss-Wright logo
  • Brave1 logo
  • Drone Evolution logo
  • AEI Systems logo
  • EOS logo
  • NMSUK logo
  • Openworks logo
  • Sandown Park logo
Hilux UKDSE AARTOS ST Engineering Future Artillery

Contact Us

BATTLESPACE Publications
41 St Georges Drive
London SW1V 4DG

+44 (0)77689 54766

BATTLESPACE Technologies

An international defence electronics news service providing our readers with up to date developments in the defence electronics industry.

Recent News

  • Protek Selected By Dutch Armed Forces

    May 2, 2026
    Read more
  • PARLIAMENTARY QUESTIONS

    May 1, 2026
    Read more
  • MANAGEMENT ON THE MOVE

    May 1, 2026
    Read more

Copyright BATTLESPACE Publications © 2002–2026.

This website uses cookies to improve your experience. If you continue to use the website, we'll assume you're ok with this.   Read More  Accept
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT