Sponsored by Spectra Group
————————————————————————
18 Apr 24. Epiq Solutions Partners with CyNtell to Provide Wireless Device Detection Systems for the DoD. Epiq Solutions (Epiq), a leading provider of software-defined radios and advanced wireless sensing systems, and CyNtelligent Solutions (CyNtell), a leading Federal cybersecurity services provider and certified 8(a) and HUBZone small business have established a partnership to provide complete solutions for wireless device detection in DoD sensitive areas.
The demand for device detection and mitigation has grown tremendously with the proliferation of low-profile wireless devices in everything from televisions to power tools to running shoes. Coupled with the ubiquity of personal smartphones and smart devices, enforcing the DoD’s no-wireless policy in secure spaces, Sensitive Compartmented Information Facilities (SCIF), and Special Access Program Facilities (SAPF) have never been more of a challenge.
Wireless devices in secure spaces are seen as a threat to the sensitive information contained there and increasingly a potential cyber attack vector for adversaries. As recently as July, the Secretary of Defense authored a memo reinforcing the no wireless policy in SCIFs and SAPFs and providing guidance to program for and use electronic detection systems to ensure compliance.
The partnership between Epiq and CyNtell provides Federal customers with systems to detect, decode, and locate wireless devices in secure spaces and integrate this capability into cyber operations. The combination provides a turnkey experience for customers that includes site planning, installation, integration, training, and support and maintenance services.
“We’re delighted to partner with CyNtell, a cybersecurity team specializing in delivering wireless systems that make a difference to the DoD,” said Gary Schluckbier, Epiq’s Vice President of Product. “The combination of our teams’ technology and expertise will provide the DoD with an end-to-end solution that will help ensure policy compliance and manage risk exposure to the growing wireless threat.”
“With years of experience deploying and supporting wireless intrusion device systems, our team understands the budgeting, deployment, and management challenges the DoD faces in implementing such systems,” said Claude Williams, CyNtell’s CEO. “Epiq’s Flying Fox product is field-proven in large and small installations, and we’re excited to amplify the availability of this technology to the DoD. We are laser-focused on the success of Flying Fox with the primary objective of extending the sales and support capabilities of Epiq and existing partners.”
For more information about the wireless device detection offering, please visit epiqsolutions.com/products/integrated-systems/flying-fox.
About Epiq Solutions
Epiq Solutions develops cutting-edge software-defined radio products and processing solutions to enable spectrum dominance for maritime, land, air, and space domains. With more than 14 years serving government and commercial enterprise customers and 20K+ devices fielded to date, Epiq Solutions is a trusted partner with a proven heritage of delivering open architecture products in radically small form factors where time-to-market, cost, and performance are critical for mission success. For more information, visit epiqsolutions.com.
About CyNtelligent Solutions
CyNtelligent Solutions, LLC (CyNtell) was established in 2016 to provide professional services to the Federal government, specifically DoD. CyNtell provides exceptionally rated professional and educational services and support as a prime and subcontractor. Our staff is highly experienced with proven expertise evidenced through achieved industry credentials like CISSP, CSA+, CASP, CEH, CHFI, EDRP, ECIH. CyNtell is an SBA 8(a) and HUBZone certified small business and GSA contract holder. Connect with CyNtell at cyntell.com (Source: PR Newswire)
17 Apr 24. Global: New vulnerability exposes sensitive data, highlights security, financial, social risks to firms. On 16 April, the cloud security company Orca Security reported a new vulnerability, ‘LeakyCLI’, affecting Amazon and Google cloud services. The vulnerability stems from command-line interfaces (CLIs) which are used by both cloud providers to manage and interact with their cloud platforms. CLIs notably bypass normal security mechanisms used to conceal sensitive configuration and environment information. This potentially provides threat actors with access to sensitive credentials, including usernames and passwords. Cyber criminals typically use sensitive account credentials in social engineering attacks to move laterally through compromised environments and conduct further malicious activity. This underscores elevated security, financial and social engineering risks to global firms, as cyber criminal actors increasingly exploit software weaknesses as part of their operations to garner illicit profit. Third-party cloud services present significant security challenges for IT teams, as they rely on shared security practices. The software supply chain consequently faces heightened security risks. (Source: Sibylline)
16 Apr 24. Silvus and Kagwerks marry radios, chest rigs for battle communications. Silvus Technologies and Kagwerks collaborated on equipment they said will streamline battlefield communications. Defense contractors Silvus Technologies and Kagwerks unveiled a combination of their products they said will reduce the burden of gear on troops while also streamlining battlefield communications. The companies on April 16 rolled out their Dismounted Operator’s Combat Kit StreamCaster line of products, which marries a mobile ad-hoc network radio, a ruggedized tablet and a rig that can be worn on the chest for easy access. Jimi Henderson, a Silvus vice president, described the kit as a “strategic fusion” of the companies’ expertise.
“This collaboration elevates tactical communications, delivering unparalleled connectivity and situational awareness to empower our force in the most demanding environment,” he said in a statement to C4ISRNET.
The U.S. Department of Defense is putting a premium on connectivity and data-sharing as it prepares for potential large-scale fighting across Europe and the Indo-Pacific.
A key piece of that puzzle is the radios troops carry, that are fitted to manned and unmanned vehicles, and how they perform amid electronic harassment. The digital tubes through which information flows will be jeopardized in a fight with Russia or China, defense officials say.
Silvus has for years worked with the military, including the Army and its Program Executive Office for Command, Control and Communications-Tactical. PEO C3T develops, deploys and supports networking gear across the service. The California-based company in January announced a $3.5 m deal with the executive office for StreamCaster radios and expanded operational testing.
“Silvus is delivering on the Army’s integrated tactical network objectives of high bandwidth mesh networking connectivity across multi-domain environments,” Henderson said in a statement at the time. The ITN, as it’s known, aims to simplify and upgrade communication tools used by soldiers.
Working with PEO C3T and the Network Cross-Functional Team, Henderson said, “enables Silvus to continually optimize our tactical communications capabilities to help the Army advance toward their unified network modernization goals.” (Source: Defense News Early Bird/C4ISR & Networks)
17 Apr 24. Goldilock, the British cybersecurity startup behind a unique physical network isolation solution, has partnered with CR14, a cyber defence organisation established by the Estonian ministry of defence and host of NATO’s operative Cyber Defence Centre of Excellence (CCDCOE), to conduct testing activities with the aim of increasing the resilience of critical national infrastructure (CNI). Testing will occur under the banner of NATO’s Defence Innovation Accelerator for the North Atlantic (DIANA), a programme designed to equip governments and businesses of member countries with the skills and knowledge to navigate the world of deep tech and dual-use innovation and to which Goldilock was the only cybersecurity firm selected to become a member.
The convergence of OT and IT in CNI networks makes them complex to defend, while they remain a prime target for state-sponsored cyber-attacks. The partnership between Goldilock and CR14 will demonstrate the benefit of being able to instantly disconnect and physically segment CNI networks such as those governing energy grids and gas and water utilities. Testing will be supported through NATO DIANA’s Test, Evaluation, Validation and Verification (TEVV) grant programme to tackle problems with CNI security architecture.
“Our testing partnership with CR14 will demonstrate exactly how CNI organisations can ensure assets remain secure and take back control,” said Tony Hasek, CEO and Co-Founder of Goldilock. “The global cyber threat landscape continues to grow, and as critical national infrastructure remains the focus of brazen cybercriminals – especially state-sponsored actors – no organisation operating in this sector is safe. It’s crucial, therefore, that organisations in NATO-member countries question whether their OT or IT systems and digital assets need to be constantly online. The new default should be disconnection, with connection and disconnection able to occur on-demand, which is precisely what Goldilock’s patented hardware solution delivers.”
The testing will take place in two phases, starting with a tabletop exercise that will bring together cybersecurity and CNI experts to determine It will also examine operational aspects such as personnel and skills requirements and optimal procedures for employment of Goldilock’s cybersecurity technology to ensure the strongest possible integrated cyber defence and safe operation of CNI systems. Building on these findings, the second phase will involve a ‘real-life’ scenario test. Using CR14’s power grid simulation, this stage will measure key performance parameters and assess the technology’s usability in a practical setting. CR14 and Goldilock will then present the results of the testing jointly in a simulation exercise at both the NATO DIANA Demo Day and also the Latitude59 Conference in May, where CR14 will bring their energy grid wall.
Peter Lenk, Technical Lead at Goldilock commented: “CR14’s wide range of cyber expertise, makes this partnership an incredibly effective one. Its ability to simulate sophisticated cyber-attacks and a physical emulation of a power grid will also demonstrate the true potential Goldilock’s kill-switch delivers in this sector. Recent attacks on UK critical national infrastructure, such as that on Southern Water earlier this year, have demonstrated the huge impact cyber incidents can have on society. Disconnecting CNI from the internet is key to keeping it safe and it allows industry managers to step outside of the cybersecurity arms race and hands them back control of system safety.”
“Goldilock’s hardware-based cyber solution is the perfect pairing to our cyber-physical approach to testing and then reinforcing the security of critical infrastructure,” said Silver Andre, CEO of CR14. “The results of this collaboration could be a game-changer across NATO member countries. Imagine power grids and water treatment plants impervious to cyberattacks – that’s the future we’re working towards here.”
16 Apr 24. Pacific Defense, a leading provider of Modular Open Systems Approach (MOSA) products and mission solutions, will continue in its role as the C5ISR Modular Open Suite of Standards (CMOSS) systems engineering, integration, and deployment lead for Palantir’s TITAN Prototype Maturation Phase (PMP) Team. Palantir USG, Inc. was recently awarded a prime agreement for the development and delivery of the Tactical Intelligence Targeting Access Node (TITAN) ground station system, the Army’s next-generation deep-sensing capability enabled by artificial intelligence and machine learning (AI/ML). Pacific Defense’s scope entails analysis, design, integration, and test of CMOSS-aligned mission capability to reduce TITAN system size, weight, and power (SWAP) footprint while also providing a modular, open architecture for rapid insertion of next-generation capabilities throughout the life cycle of the TITAN system. MOSA technical standards like CMOSS and The Open Group’s Sensor Open Systems Architecture™ (SOSA) were expressly created to transform the way weapon systems are designed and supported. These standards unlock a system’s technical baseline allowing customers to openly source and insert best-in-breed capabilities at greatly reduced cost and schedule.
“Pacific Defense is purpose-built to drive the MOSA movement in the US Department of Defense and has been a leading partner of the US Army in creating and delivering CMOSS capabilities,” said Travis Slocumb, CEO of Pacific Defense. “Pacific Defense’s culture is built on open collaboration with its partners and customers and is proud to continue its partnership with Palantir on the TITAN program.”
Palantir’s agreement covers the development of 10 TITAN prototypes, including five Advanced and five Basic variants, as well as the integration of new critical technologies and the transition to fielding. Pacific Defense will design and integrate CMOSS systems TITAN Systems Integration Lab (SIL) and Advanced and Basic variants for deployment and test in the Prototype Maturation program. (Source: BUSINESS WIRE)
16 Apr 24. Smiths Detection, a global leader in threat detection and security screening technologies, today announces that it has launched the SDX 10060 XDi, a ground-breaking X-ray scanner powered by diffraction technology. X-ray Diffraction (XRD) is a powerful inspection technology offering highly accurate material discrimination and substance identification based on an object’s molecular structure. XRD is particularly suited to detecting constantly evolving compounds in powder, liquid or solid forms, such as ‘homemade’ explosives or narcotics, even for materials with similar densities.
Multi-level baggage and material handling operations and express forwarders are under pressure to screen huge volumes quickly and efficiently. The SDX 10060 XDi can transform this process by automating the resolution of potential explosive alarms, in turn improving both security and efficiency.
Due to its exceptional sensitivity, XRD technology can also be very effectively deployed to support customs agencies in screening for a range of contraband items including narcotics, helping to mitigate ever-growing threats to society.
Jerome de Chassey, President of Smiths Detection, commented: “We are immensely excited to announce the launch of the SDX 10060 XDi which marks a new era in security screening. Every minute of every day our threat detection and security screening technology helps to protect people and infrastructure, and this new development highlights our commitment to making the world a safer place. X-ray Diffraction will future-proof operations for a large variety of sectors, and we are proud to play a pivotal role in shaping the landscape of future threat detection.”
The SDX 10060 XDi can integrate seamlessly with existing material and baggage handling systems and is designed to meet ECAC Standard 3.1/3.2 and TSA 7.2 plus future regulations. Certification is underway.
16 Apr 24. Thales, the cybersecurity leader that protects critical applications, APIs, and data, anywhere at scale, today announced the release of the 2024 Imperva Bad Bot Report, a global analysis of automated bot traffic across the internet. Nearly half (49.6%) of all internet traffic came from bots in 2023—a 2% increase over the previous year, and the highest level Imperva has reported since it began monitoring automated traffic in 2013.
For the fifth consecutive year, the proportion of web traffic associated with bad bots grew to 32% in 2023, up from 30.2% in 2022, while traffic from human users decreased to 50.4%. Automated traffic is costing organizations bns (USD) annually due to attacks on websites, APIs, and applications.
“Bots are one of the most pervasive and growing threats facing every industry,” says Nanhi Singh, General Manager, Application Security at Imperva, a Thales company. “From simple web scraping to malicious account takeover, spam, and denial of service, bots negatively impact an organization’s bottom line by degrading online services and requiring more investment in infrastructure and customer support. Organizations must proactively address the threat of bad bots as attackers sharpen their focus on API-related abuses that can lead to account compromise or data exfiltration.”
Key trends identified in the 2024 Imperva Bad Bot Report include:
- Global average of bad bot traffic reached 32%: Ireland (71%), Germany (67.5%), and Mexico (42.8%), saw the highest levels of bad bot traffic in 2023. The US also saw a slightly higher ratio of bad bot traffic at 35.4% compared to 2022 (32.1%).
- Growing use of generative AI connected to the rise in simple bots: Rapid adoption of generative AI and large language models (LLMs) resulted in the volume of simple bots increasing to 39.6% in 2023, up from 33.4% in 2022. The technology uses web scraping bots and automated crawlers to feed training models, while enabling nontechnical users to write automated scripts for their own use.
- Account takeover is a persistent business risk: Account takeover (ATO) attacks increased 10% in 2023, compared to the same period in the prior year. Notably, 44% of all ATO attacks targeted API endpoints, compared to 35% in 2022. Of all login attempts across the internet, 11% were associated with account takeover. The industries that saw the highest volume of ATO attacks in 2023 were Financial Services (36.8%), Travel (11.5%), and Business Services (8%).
- APIs are a popular vector for attack: Automated threats caused a significant 30% of API attacks in 2023. Among them, 17% were bad bots exploiting business logic vulnerabilities—a flaw within the API’s design and implementation that allows attackers to manipulate legitimate functionality and gain access to sensitive data or user accounts. Cybercriminals use automated bots to find and exploit APIs, which act as a direct pathway to sensitive data, making them a prime target for business logic abuse.
- Every industry has a bot problem: For a second consecutive year, Gaming (57.2%) saw the largest proportion of bad bot traffic. Meanwhile, Retail (24.4%), Travel (20.7%), and Financial Services (15.7%) experienced the highest volume of bot attacks. The proportion of advanced bad bots, those that closely mimic human behavior and evade defenses, was highest on Law & Government (75.8%), Entertainment (70.8%), and Financial Services (67.1%) websites.
- Bad bot traffic originating from residential ISPs grows to 25.8%: Early bad bot evasion techniques relied on masquerading as a user agent (browser) commonly used by legitimate human users. Bad bots masquerading as mobile user agents accounted for 44.8% of all bad bot traffic in the past year, up from 28.1% just five years ago. Sophisticated actors combine mobile user agents with the use of residential or mobile ISPs. Residential proxies allow bot operators to evade detection by making it appear as if the origin of the traffic is a legitimate, ISP-assigned residential IP address.
“Automated bots will soon surpass the proportion of internet traffic coming from humans, changing the way that organizations approach building and protecting their websites and applications,” continued Singh. “As more AI-enabled tools are introduced, bots will become omnipresent. Organizations must invest in bot management and API security tools to manage the threat from malicious, automated traffic.”
Additional Information:
- Download a copy of the 2024 Imperva Bad Bot Report for additional insights.
- See how Imperva Advanced Bot Protection, API Security, and Client-Side Protection can protect websites, mobile applications, and APIs from automated attacks and fraud without affecting the flow of business-critical traffic.
- Read the Imperva Blog for the latest product and solution news, and threat intelligence from Imperva Threat Research.
15 Apr 24. Hensoldt to consider Eurofighter EK Step 2 options after buyout of ESG. Hensoldt is considering how to proceed with its plans to offer a new airborne electronic attack (AEA) capability to Germany, following its recent acquisition of Elektroniksystem- und Logistik-GmbH (ESG). A company representative told Janes on 12 April that having previously proposed a joint solution with Rafael Advanced Defense Systems for Step 2 of the Eurofighter Elektronischer Kampf (EK) electronic combat, Hensoldt is considering its position as it waits on the Luftwaffe’s requirements and in light of its procurement of ESG on 2 April.
“We consider Eurofighter EK Step 2 as an important capability enhancement, which is still on the [Luftwaffe’s] agenda. However, requirements and details of implementation are still under consideration [by the customer]. Therefore, we are monitoring closely the developments before drawing conclusions with regard to our further positioning,” the representative said. (Source: Janes)
14 Apr 24. ShadowDragon™ Releases The OSINT Platform, Horizon®. ShadowDragon™, a provider of ethical open-source intelligence (OSINT) software, unique datasets and APIs, is pleased to announce significant enhancements to its flagship Open-Source Intelligence Investigative platform Horizon®. These updates represent a milestone in the evolution of investigative technology, offering capabilities to streamline investigative processes and uncover valuable insights.
The OSINT Platform encompasses an all-in-one solution for investigations with unparalleled access to publicly available information, including geolocation data, platform monitoring, breach data and the ability to integrate external data streams. This allows for a modern approach to link analysis in one comprehensive toolkit. Horizon® offers access to more than 225 data collection sources, more than 1500 pivot points, and advanced, customizable link analysis capabilities.
Horizon® is accessible with any internet connection and allows users to access critical data and conduct investigations from any device, providing unprecedented flexibility and mobility. Mapping advancements, plotting capability, visual geofencing, and geoestimation allow for different starting points that pinpoint precise locations and uncover valuable insights. Horizon® offers unmatched ease of integration, creating tailored data streams able to solve for any problem set. Horizon® will also enable analysts the ability to work on the go from a tablet, phone, or desktop/laptop.
Horizon®, coupled with ShadowDragon’s SocialNet ® offers a powerful OSINT toolkit that includes more than 225 data collection sources to use for correlating publicly available data, integrated brand monitoring, breach data inquiries, social media information and link analysis capabilities to empower users with a holistic approach to investigations. Users benefit from advanced link analysis capabilities, allowing them to connect the dots and uncover actionable intelligence with ease.
CEO Daniel Clemens said, “Our customers have asked for a unified platform for many years. We are answering their requests with Horizon®, enabling customers to use our platform and data with their existing tools, easily import and export data, while enabling greater focus for complex analysis of data. The Horizon® Platform allows publicly available data to tell the story for the analyst. I am very delighted at what our team has produced and thankful to how our tools help protect many on a global scale.”
“You guys are doing incredible things with SocialNet® and Horizon®. Looking back as a user of Horizon’s early release, it has been the coolest privilege to experience the last three years of innovation, watching the platform evolve and morph with every incremental update, and knowing there are always more tweaks still in the works.” – Law Enforcement Customer.
These updates underscore ShadowDragon’s commitment to innovation and excellence in the field of investigative technology. By continuously enhancing its OSINT suite with new features, data collection sources and capabilities, ShadowDragon aims to empower investigators with the tools they need to stay ahead of emerging threats and make informed decisions.
Nico Dekens, ShadowDragon Director of Intelligence, said, “This is as close as one can get to having a silver bullet solution that helps solve investigative and analytical needs. This means that no matter what OSINT expertise you have, ShadowDragon’s technology will speed up your investigation through an initiative platform. But it is not limited to just the platform and tools, the seasoned team will train you on usage and will support you in getting the most out of your investigative needs. The newly released features and capabilities will make your work future proof and will speed up ANY investigation significantly.”
For more information about the ShadowDragon™ suite of OSINT tools and capabilities, such as SocialNet®, OIMonitor®, MalNet®, and Horizon®, click here.
About ShadowDragon
ShadowDragon™ provides comprehensive, cyber investigative resources and training for use by private companies, intelligence gathering professionals, law enforcement, and government. The U.S.-based company delivers open source intelligence (OSINT) from over 225 networks including social media platforms, chat rooms, forums, historical datasets, and the dark web. The company monitors malware history, data breach dumps, and other areas for active cyber threats. These data collection and analytic tools help defend against malicious acts in the digital and physical world. For more information, visit www.shadowdragon.io. Visit the ShadowDragon Trust Center for details about the company’s approach to “OSINT for Good”. (Source: BUSINESS WIRE)
12 Apr 24. Global: Increased adoption of deepfakes by cyber criminals points to risks facing private sector. On 10 April, the password management platform LastPass revealed that one of its employees was targeted in a deepfake campaign. The employee received several phone calls in which artificial intelligence (AI)-generated audio impersonated the company’s CEO. The threat actors used the messaging platform WhatsApp to target the employee, leveraging known social engineering techniques (such as instilling a sense of urgency) to trick the employee into acting quickly. Although the attack was unsuccessful, as the employee immediately recognised the social engineering attempt, it highlights the increased adoption of AI and deepfake technologies by cyber criminals. In February, a Hong Kong-based finance worker transferred USD 25 m to threat actors who were using deepfake technology to impersonate the CEO of the employee’s firm, further underscoring the growing sophistication and availability of deepfake technologies. We assess that this trend will elevate financial and reputational risks facing the private sector in the long term. (Source: Sibylline)
15 Apr 24. New campaign highlights sustained security, information-theft risks from zero-day vulnerabilities. On 12 April, the security company Palo Alto Networks disclosed a new zero-day vulnerability (CVE-2024-3400) in their PAN-OS firewall (versions 10.2, 11.0, and 11.1) which was actively exploited in an information-theft campaign. The suspected state-sponsored group ‘UTA0218’ exploited this vulnerability to obtain unauthorised access to vulnerable systems and install a backdoor called ‘Upstyle’. This enabled the group to execute additional commands, move laterally and steal sensitive data from the compromised system including Windows event logs, login information and browser and configuration data. Notably, the group used several anti-detection tools to remain hidden and to establish prolonged persistence, underscoring the sophistication of the exploit. Although it is unclear which country ‘UTA0218’ might be affiliated with, the group’s advanced tactics, techniques and procedures (TTPs), capabilities and choice of targets suggest that it’s likely state-backed. State-sponsored actors frequently leverage zero-day vulnerabilities for initial access, highlighting sustained security and information theft risks via the software supply chain. (Source: Sibylline)
———————————————————————————————————————————————————————————————————————————————————————————————————————————————-
Spectra Group (UK) Ltd
Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.
Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.
With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.
Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.
In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.
Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.
Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.
———————————————————————————————————————————————————————————————————————————————————————————————————————————————–

