• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • SPECTRA banner
  • Curtiss-Wright banner

BATTLESPACE Updates

   +44 (0)77689 54766
   

  • Home
  • Features
  • News Updates
  • Defence Engage
  • Company Directory
  • About
  • Contact

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

March 22, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

————————————————————————

21 Mar 24. Ultra Intelligence & Communications celebrates opening of its new Cyber Centre of Excellence in Maidenhead, U.K. Ultra Intelligence & Communications, also known as Ultra I&C, celebrated the official opening of its flagship facility in Maidenhead, U.K., marking a major milestone in the company’s ongoing expansion and development.  Ultra I&C’s Cyber Centre of Excellence represents a significant achievement in advancing expertise in cybersecurity and manufacturing, providing the company and its customers a new base for 250 engineers, made possible by a £30M investment in the new facility. The 56,000 square foot engineering, integration and testing facility will serve as a hub for cyber technology development and the company’s U.K. STEM program, supporting local schools and placements from the CyberFirst program, aimed at identifying and nurturing a diverse group of talented individuals interested in pursuing a career in cybersecurity.

“Ultra I&C’s Maidenhead Cyber Centre of Excellence will support job growth in the engineering sector, which is critically needed to protect our national security,” said Richard Dingley, president of Ultra I&C’s cyber business. “Opening this location solidifies our long-term commitment to developing the skills and capabilities required to ensure the U.K. and our partners are protected and prosperous in the future.”

The opening ceremony brought together industry, local and national government and key clients such as the U.K. MOD, to mark the growth and expansion of the company in the U.K. Former U.K. Prime Minister, Rt Hon. Theresa May MP spoke at the opening ceremony, noting: “Ultra I&C’s Maidenhead facility represents a significant investment in the community to build skills, develop more careers in STEM and support the U.K.’s ability to respond to, and combat, the threats of the future.”

Ultra I&C leaders demonstrated their solutions to support the secure communications on the likes of the Typhoon aircraft, post-quantum security capabilities and satellite communications.

 

22 Mar 24. Silvus Technologies eyes on-the-move capability for StreamCaster radio. California-based mobile networking company Silvus Technologies is working with US Army officials to provide mobile ad hoc network (MANET) radio capability to ground units on the move, a critical requirement to the service’s evolving command post architecture under the Integrated Tactical Network (ITN). The on-the-move (OTM) capability being developed by the company’s StreamCaster MANET radio got a fiscal shot in the arm from the army in January, when service leaders inked a USD3.5m deal with Silvus to expedite “expanded deployment” of the radio to support service units employing the ITN. Specifically, the MANET radios procured by the army’s Program Executive Office Command, Control, and Communications-Tactical (PEO C3T) under the January contract will be used for operational testing and validation scheduled for fiscal year (FY) 2025, according to a company statement. StreamCaster MANET radios have already been deployed to infantry brigade combat teams (IBCTs) as part of the Capability Set 21 (CS21) iteration of the ITN, and then out to Stryker BCTs as part of Capability Set 23 (CS23). (Source: Janes)

 

21 Mar 24. Global: New campaign signals heightened cyber espionage risks facing public, private organisations. On 20 March, the cyber security firm Rapid7 identified a new campaign by the North Korea-affiliated threat group ‘Kimsuky’. The campaign primarily targets government agencies and think tanks based in the Asia-Pacific region and Europe. While the initial attack vectors used in the latest campaign are unknown, the group typically uses phishing and social engineering. Following initial access, a compiled HTML help (CHM) file containing malicious code is downloaded onto the victim’s system; the file then installs an infostealer to gather strategic information. CHM files are known for being difficult to identify as they are often used as legitimate files on Windows systems, underscoring the threat group’s sophistication and understanding of modern security tools. Like other non-Western countries, North Korea has ramped up its cyber espionage operations to improve its security and economic posture. Consequently, the latest activity points to the heightened cyber espionage risks facing public and private organisations in the short-to-medium term. (Source: Sibylline)

 

20 Mar 24. MOD admits it has too many secret cloud capabilities and is seeking commercial help. The MOD wants to find a single commercial cloud provider to help users securely access classified data (Picture: MOD)

The MOD is looking for a commercial company to provide a single “secret cloud” to deal with accessing classified data, admitting it has too many secret cloud capabilities.

Defence Procurement Minister James Cartlidge said the MOD was “ramping up” its engagement with industry at a secret level, working together to develop artificial intelligence (AI) capabilities.

The comments were made when MPs on the Defence Select Committee questioned MOD officials on the use of AI and discussed the sharing of secret-level data with companies providing or developing projects using the technology.

Mr Cartlidge told the committee: “We are ramping up engagement at ‘secret’ with industry.

“So we recently held a general industry day, this is for the defence sector. We’ve had some more specific ones. Yesterday Strategic Command held one with companies who are involved in electronic warfare.”

Committee member John Speller pressed officials on data-sharing with industry and said: “A lot of the companies have told us that secure cloud computing is needed to enable AI to be able to deal with classified data.

“When will they have access to this and is there possibly scope for government to have an overall umbrella contract into which they could have access in order to undertake that work.”

Paul Lincoln, the second permanent secretary at the MOD, responded: “We set out in the AI strategy that we would have secret cloud within defence, we have had secret on premises on cloud since early 2023 installed and operational.

“We are moving now to a convergence.

“The minister said we have got too many secret cloud capabilities to a single convergence at the moment, and we are looking for a commercial cloud provider to bring on board for that.”

Officials told the committee they recognised the importance of working with industry to develop future AI capabilities. (Source: forces.net)

 

19 Mar 24. Global: New campaign signals sustained espionage risks for Western government, technology firms. On 18 March, the cyber security company Trend Micro unveiled the discovery of a new cyber espionage campaign targeting government organisations. The China-affiliated group, ‘Earth Krahang’, has successfully breached 70 organisations since early 2022. The campaign uses spear phishing techniques and software vulnerabilities as initial access vectors. The group then executes backdoors to gather information from compromised systems. Additionally, the campaign uses brute force techniques to compromise Outlook accounts and collect additional targets’ email addresses to infiltrate secondary organisations. The threat group also builds custom virtual private network (VPN) software on infected systems to facilitate lateral movement, further underscoring the sophistication of its tactics, techniques and procedures (TTPs). China-affiliated threat groups routinely conduct cyber espionage campaigns to further Beijing’s strategic and political ambitions; they primarily target government and technology organisations in the West. As such, we assess that future such campaigns are highly likely as China seeks to strengthen its economic and security posture. (Source: Sibylline)

 

18 Mar 24. DoD Revises Eligibility Criteria for Its Voluntary Defense Industrial Base Cybersecurity Program – (89 Fed. Reg. 17741) – The U.S. Department of Defense’s Office of the DoD Chief Information Officer has published revisions to the eligibility criteria for the voluntary Defense Industrial Base (DIB) Cybersecurity (CS) Program. These revisions will allow all defense contractors who own or operate an unclassified information system that processes, stores, or transmits covered defense information to benefit from bilateral information sharing. DoD is also finalizing changes to definitions and some technical corrections for readability. The proposed rule was published at 88 Fed. Reg. 27832-27839 (May 3, 2023). In May 2012, DoD published an interim final rule establishing the voluntary DIB CS Program and the bilateral information-sharing model still used today. The 2012 rule established a voluntary cyber threat information sharing program for cleared defense contractors (CDC) with the ability to safeguard classified information, estimated at 2,650 in 2012. Under the rule, CDC is defined as a private entity granted clearance by DoD to access, receive, or store classified information for the purpose of bidding for a contract or conducting activities in support of any program of DoD. With this rule, the Department is expanding eligibility requirements to allow greater program participation and increase the benefits of bilateral information sharing, which helps protect DoD-controlled unclassified information from cyberattack, as well as to better align the voluntary DIB CS Program with DoD’s mandatory cyber incident reporting requirements. This rule is effective on April 11, 2024. (Source: glstrade.com)

 

18 Mar 24. Global: New vulnerability highlights financial, security risks stemming from outdated software. On 15 March, the cyber security company Cyble reported that the ransomware group ‘ShadowSyndicate’ attempted to exploit a newly identified Python vulnerability (CVE-2024-23334). The affected Python tool (AIOHTTP, version 3.9.1) is widely used by IT teams to build sophisticated web applications. This vulnerability enables unauthenticated threat actors to bypass data protection, granting them access to sensitive files that should not be accessible via the internet. Financially motivated threat groups are subsequently able to steal credentials and to execute malicious files on infected systems to garner illicit profit. Although ShadowSyndicate uses scanning tools to identify vulnerable servers, there is a realistic possibility that this vulnerability can be exploited by other actors. Outdated software often presents an effective attack vector for threat actors seeking to compromise a network, underscoring the financial and security risks posed by legacy software. Python has since released a fix to address the vulnerability. (Source: Sibylline)

 

18 Mar 24. ASD-Microsoft initiative bolsters Australia’s cyber defence.

The Australian Signals Directorate (ASD) and Microsoft will strengthen Australia’s cyber defences by connecting ASD’s Cyber Threat Intelligence Sharing (CTIS) platform with Microsoft’s Sentinel platform, creating a global cyber threat intelligence system.

This connection allows Microsoft’s Australian customers who also partner in ASD’s CTIS platform to share cyber threat information at the speed and scale required to mitigate against growing threats in cyberspace.

“This initiative is a significant step forward in bolstering our cyber defences,” said Deputy Prime Minister and Minister for Defence Richard Marles. “The best cyber defences are founded on genuine partnerships between and across the public and private sectors. It is collaborative partnerships like these that foster innovation and deliver practical outcomes for Australia’s cyber resilience.”

The integration of these platforms will enable deeper collaboration between ASD’s CTIS program and Microsoft Sentinel customers in Australia, who benefit from Microsoft’s analysis of 65 trillion signals of global threat intelligence every day.

“This initiative builds on our recently announced investment into improving our nation’s cyber defences, under the Microsoft-Australian Signals Directorate’s Cyber Shield (MACS),” according to Steven Worrall, managing director of Microsoft Australia and New Zealand.

This outcome is a key element of the Microsoft-ASD Cyber Shield initiative as part of Microsoft’s $5 bn investment in Australia announced by the Albanese Government in October 2023.

This initiative is another example of the importance of the partnership between the public and private sectors in countering collective cyber threats. It also continues to deliver on the Government’s commitment to enhance cyber threat visibility and harden the nation’s cyber defences. (Source: https://www.ex2.com.au/news/)

 

15 Mar 24. The financially motivated threat group ‘Magnet Goblin’ exploited known Ivanti software vulnerabilities (CVE-2023-46805 and CVE-2023-21887) to compromise Linux systems with a new version of the ‘NerbianRAT’ malware. The first vulnerability (CVE-2023-46805) enables threat actors to bypass authentication processes on a compromised system. The second vulnerability (CVE-2023-21887) can be exploited to execute malicious code remotely. The malware first collects information on the compromised system to establish command-and-control (C2) mechanisms and ensure communication with actor-controlled infrastructure. Subsequently, threat actors are able to execute code remotely on the infected machine to garner illicit profit. The actors used a credential stealer and tunnelling tools during their attacks, further demonstrating the sophistication of their tactics, techniques and procedures (TTPs). Unlike its Windows counterpart, the NerbianRAT Linux version lacks defence evasion mechanisms. However, its level of complexity and other capabilities ensure prolonged persistence in a compromised network. A new campaign exploited a patched vulnerability (CVE-2024-21412) in the Microsoft Defender antivirus software to infect systems with the ‘DarkGate’ malware. The campaign starts with a phishing email containing a PDF file with malicious links. These links leverage a legitimate Google advert platform to exploit the vulnerability, redirecting users to download a malicious file (disguised as a legitimate software installer) from an actor-controlled server. Following its installation, the malware can deploy additional malicious files, facilitate remote access and perform keylogging. The vulnerability was actively exploited by unknown threat groups prior to a patch being released. This campaign highlights organisations’ susceptibility to supply chain attacks as threat actors increasingly leverage vulnerabilities in trusted third-party applications. In particular, threat actors demonstrated that they can incorporate the use of multiple legitimate tools in one campaign to bolster success rates.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Apply patches to software vulnerabilities as soon as they are released to prevent exploitation
  • Monitor devices and networks for suspicious activity
  • Conduct cyber hygiene awareness courses for users to enable them to recognise and report phishing and other types of social engineering attempts
  • Create network segmentation to limit potential damage from infections
  • Add available Indicators-of-Compromise (IoCs) to the organisation’s security detection systems to detect potentially malicious samples on the network
  • Ensure adequate security detection measures are in place, particularly behaviour-based end-point detection and response (EDR) solutions

Our cyber word(s) of the week: Structured Query Language (SQL) Injection (Source: Sibylline)

 

15 Mar 24. Global: New software vulnerability points to espionage, information-theft risks via supply chain. On 13 March, the cyber security company Fortinet disclosed a new vulnerability (CVE-2023-48788) in its Enterprise Management Server (EMS) software (versions 7.0 to 7.2). There is currently no indication that the vulnerability was actively exploited prior to the release of its fixed version. The vulnerability can be leveraged via a structured query language (SQL) injection to manipulate the application’s backend, enabling threat actors to access sensitive information and escalate their privileges within the infected system. Previously, a suspected Chinese state-sponsored group exploited a vulnerability in Fortinet’s VPN software to deploy the ‘COATHANGER’ remote access trojan (RAT), with which it infiltrated the Dutch Ministry of Defence (MoD) in February. State-sponsored threat groups are increasingly exploiting vulnerabilities in the software supply chain for cyber espionage campaigns, accentuating the growing espionage and information-theft risks facing organisations. Consequently, we assess that the future exploitation of this vulnerability is possible amid current political tensions, further emphasising the need for strict patch management policies.  (Source: Sibylline)

————————————————————————-

 

Spectra Group (UK) Ltd

 

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

 

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

————————————————————————-

Primary Sidebar

Advertisers

  • Pythia
  • Teledyne
  • Exensor
  • Visit the Oxley website
  • Blighter
  • SPECTRA
  • Britbots logo
  • Faun Trackway
  • Systematic
  • CISION logo
  • ProTEK logo
  • ProTEK logo
  • ssafa logo
  • IEE
  • EXFOR logo
  • sibylline logo
  • Team Thunder logo
  • Comtech logo
  • GoExporting logo
  • ECHODYNE logo
  • Supercat logo
  • Galvion logo
  • Leonardo DRS logo
  • MTC logo
  • IDC logo
  • DSEI logo
  • DVD2024 logo
  • SDSC logo
  • TELEDYNE FLIR logo
  • VeteranUK logo
  • Matrix Space logo
  • ST Engineering logo
  • EWS logo
  • sentinel photonics logo
  • capua logo
  • Curtiss-Wright logo
  • Brave1 logo
  • Drone Evolution logo
  • AEI Systems logo
  • EOS logo
  • NMSUK logo
  • Openworks logo
  • Sandown Park logo
Hilux UKDSE AARTOS ST Engineering Future Artillery

Contact Us

BATTLESPACE Publications
41 St Georges Drive
London SW1V 4DG

+44 (0)77689 54766

BATTLESPACE Technologies

An international defence electronics news service providing our readers with up to date developments in the defence electronics industry.

Recent News

  • Protek Selected By Dutch Armed Forces

    May 2, 2026
    Read more
  • PARLIAMENTARY QUESTIONS

    May 1, 2026
    Read more
  • MANAGEMENT ON THE MOVE

    May 1, 2026
    Read more

Copyright BATTLESPACE Publications © 2002–2026.

This website uses cookies to improve your experience. If you continue to use the website, we'll assume you're ok with this.   Read More  Accept
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT