• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • SPECTRA banner
  • Curtiss-Wright banner

BATTLESPACE Updates

   +44 (0)77689 54766
   

  • Home
  • Features
  • News Updates
  • Defence Engage
  • Company Directory
  • About
  • Contact

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

May 3, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

————————————————————————————————————————————————————————————————————————————————————————————————————————————-

02 May 24. Spectra Group launches GENSS a revolutionary tactical radio communications system to the US Defense market at SOF 2024. Following the initial announcement in January 2024, Spectra Group are springboarding the GENSS system into the US market at SOF 24.  Spectra Group, a specialist provider of secure voice, data and satellite communications systems, is showcasing its next generation of tactical radio communications GENSS (pronounced genesis) at SOF Week 2024 and will be displaying GENSS and the highly popular SlingShot from 6-10 May 2024 in booth #1805 at the Tampa Convention Centre.

GENSS builds on the foundations created by their award-winning SlingShot system, embodying Spectra Group’s vision of producing the ultimate radio systems that capitalize on technological advances, adapt to the evolving demands of military operations and simplify the user experience.  It has been designed and developed through a collaborative effort of tactical communication experts, seasoned military specialists and top-tier U.K. scientists and engineers.  GENSS is a significant advancement in the field of tactical radio communications, due to its modular core framework and software-defined flexibility, heralding a new era in communication technology.

This modular, agnostic hardware radio system is designed to be agile and provide the ultimate interoperability through straightforward software reprogramming to adapt quickly and easily to meet the diverse needs of its users.  Capable of operating across HF, VHF, UHF, and satellite bands, GENSS is engineered to conquer Beyond Line-of-Sight (BLOS) barriers and support Communications on the Move (COTM), delivering a robust and agile solution for voice and high-bandwidth data transmission across all domains — land, sea, and air.  GENSS boasts high-capacity, network sensing capabilities and has increased data rates over 25kHz LTAC channels, scaling up to 90kBps.  It has adaptive modulation waveforms, which automatically adjust through network sensing techniques, to meet the tactical situation (on the move and in combat vs at the halt scenarios).  Also, through novel engineering techniques, voice and low data rate solutions can be applied in the contested communications space to minimise detection.

This revolutionary radio solution can stand alone or be integrated into any existing radio infrastructure and works seamlessly with SlingShot; unleashing superior interoperability and flexibility to meet the demands of today and the future.  By integrating multi-mission and multi-mode functionalities, combined with its modular design and open architecture, it delivers unparalleled adaptability for robust battlefield connectivity.  Secure by design and integrating the latest most advanced technological hardware means GENSS not only delivers maximum performance while minimizing its size, weight and power, but also delivers a future-proofed capability.  In addition, it is simple to operate and configure, with an easy-to-programme user interface, resulting in an overall reduced training burden.

Simon Davies, Chief Executive at Spectra Group, said: “For years, my vision has been to craft the ultimate radio system — user-friendly, light, modular and supremely flexible to adapt to the evolving demands of military operations and technological advances. After years of dedicated development, GENSS is the fruition of that vision and builds on the foundations set by our award-winning SlingShot system. Designed by soldiers, for soldiers, GENSS is not just a game-changer for military applications but possesses vast potential for integration into broader communication networks, unlocking endless possibilities.”

 

02 May 24. Department of Defense Issues Class Deviation on Cybersecurity Standards for Covered Contractor Information Systems. The Office of the Under Secretary of Defense for Acquisition and Sustainment, in collaboration with the Office of the Chief Information Officer, today issued a Defense Federal Acquisition Regulation Supplement (DFARS) class deviation relating to the cybersecurity standards required for covered contractor information systems.  The intent of this class deviation is to provide industry time for a more deliberate transition upon the forthcoming release of the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations,” revision.  This class deviation will also afford the Department of Defense time to best align any of the necessary supporting mechanisms.  Specifically, this class deviation provides an alternative clause that will require contractors, who are subject to DFARS clause 252.204-7012, to comply with NIST SP 800-171 Revision 2, instead of the version of NIST SP 800-171 in effect at the time the solicitation is issued. The class deviation is available on the Defense Pricing and Contracting public website at https://www.acq.osd.mil/dpap/policy/policyvault/USA000814-24-DPC.pdf. (Source: U.S. DoD)

 

03 May 24. Statement by the North Atlantic Council concerning malicious cyber activities against Germany and Czechia. We stand in solidarity with Germany following the malicious cyber campaign against a political party, in this case the Social Democratic Party of Germany, and with Czechia following the malicious cyber activities against its institutions. Allies recognize that Germany and Czechia have attributed the responsibility of the malicious cyber activities in their respective countries to the threat actor APT28 sponsored by the Russian Federation, specifically the Russian General Staff Main Intelligence Directorate (GRU). Allies also note with concern that the same threat actor targeted other national governmental entities, critical infrastructure operators and other entities across the Alliance, including in Lithuania, Poland, Slovakia and Sweden.

We strongly condemn malicious cyber activities intended to undermine our democratic institutions, national security and free society.

The malicious cyber activities targeting Germany and Czechia underscore that cyberspace is contested at all times. Cyber threat actors persistently seek to destabilize the Alliance.

We remain committed to countering the substantial, continuous and increasing cyber threat, including to our democratic systems and our critical infrastructure. We are determined to employ the necessary capabilities in order to deter, defend against and counter the full spectrum of cyber threats to support each other, including by considering coordinated responses.

We promote a free, open, peaceful and secure cyberspace. We call on all States, including Russia, to respect their international obligations and commitments to uphold international law and act within the framework for responsible state behavior in cyberspace as affirmed by all members of the United Nations. (Source: NATO)

 

03 May 24. United Kingdom joins partners in condemnation of malicious cyber activity by Russian Intelligence Services  : UK government statement.

The United Kingdom has joined with its international partners to condemn malicious cyber activity by the Russian Intelligence Services.

A UK government spokesperson said: “The United Kingdom stands with the European Union, Germany, Czechia and other allies in strongly condemning malicious cyber activity by Russian Intelligence Services. Today’s statements from our allies demonstrate the scale, persistence, and seriousness of unacceptable Russian behaviours in cyberspace. Recent activity by Russian GRU cyber group APT28, including the targeting of the German Social Democratic Party executive, is the latest in a known pattern of behaviour by the Russian Intelligence Services to undermine democratic processes across the globe.

On 7 December 2023, the UK exposed a series of attempts by the Russian Intelligence Services to target high-profile UK individuals and entities through cyber operations. At the same time, we sanctioned two Russian nationals responsible for political interference. With multiple elections around the world in 2024, raising awareness of the threat to the UK and our international partners remains vitally important for our collective resilience.

Today, as part of a broad coalition of allies, we are making clear to the Russian state that we will continue to identify, expose, and respond to such unacceptable activity.

Background

  • APT28 are capable cyber actors who have been active since at least 2004. They are known by industry nicknames including Strontium, Sofacy Group, Pawn Storm, Fancy Bear, and Sednit.
  • The UK has previously exposed APT28 as part of the GRU, the Russian military intelligence service, including:
  • In 2018, the UK and the Netherlands exposed an attempted attack against the Organisation for the Prohibition of Chemical Weapons (OPCW) by APT28, aimed at disrupting independent analysis of chemicals weaponised by the GRU in the UK.
  • In 2020, the UK announced sanctions against APT28 and two individual GRU officers for their reckless cyber-attacks on Germany’s Parliament in 2015, which affected email accounts belonging to German MPs and the German Vice Chancellor.
  • In 2023, the UK and US technical communities released a joint advisory to provide details of tactics, techniques and procedures associated with APT28’s exploitation of Cisco routers in 2021.
  • The UK Government also supports Germany’s assessment that APT28 exploited critical security vulnerabilities in Microsoft Outlook directed against email accounts of the German Social Democratic Party.

(Source: https://www.gov.uk/)

 

02 May 24. Good Cyber Hygiene Can Impede Adversary Meddling in U.S. Infrastructure. Good cyber hygiene, which includes things like regularly changing passwords or applying software security patches, plays an outsized role in preventing America’s adversaries from hacking into and crippling U.S. infrastructure systems, such as power, water or gas.

On Capitol Hill today, Director of National Intelligence Avril D. Haines told members of the Senate Armed Services Committee that in many cases where it’s been evident that U.S. adversaries have demonstrated an ability to hack into U.S. infrastructure systems, good cyber hygiene would have prevented it.

“This year, cyber actors are attacking U.S. industrial control systems, which are typically used to automate industrial processes, at record levels,” Haines said.

Critical infrastructure sectors — including water, wastewater, food, agriculture, defense, energy and transportation —rely on these kinds of systems, she said.

“Although the likelihood of any single attack having a widespread effect on interrupting critical services remains low, the increased number of attacks and the actors’ willingness to access and manipulate these control systems increases the collective odds that at least one could have a more significant impact,” Haines said.

The owners and maintainers of these systems play a role in their vulnerability to cyberattack by American adversaries, Haines told lawmakers.

“In virtually all the attacks we’ve seen against U.S. critical infrastructure, cyber actors took advantage of default or weak passwords; unpatched, known vulnerabilities; and poorly secured network connections to launch relatively simple attacks,” she said. “And for this reason, it is crucial that all of us — particularly critical infrastructure owners and operators — improve our cybersecurity practices to reduce our vulnerability to such efforts.”

According to Haines, the number of ransomware attacks globally went up by as much as 74% in the last year.

Air Force Lt. Gen. Jeffrey A. Kruse, director of the Defense Intelligence Agency, told senators that the need to protect DIA networks from cyberattacks by a wide range of actors, including foreign intelligence entities and insider threats, remains a primary concern for DIA.

“This includes not only the sophisticated capabilities of state actors, such as Russia and China, but also rogue cyber actors loosely aligned to governments,” he said. “In addition to … the growing threat to critical infrastructure in local governments, this threat directly endangers our defense industrial capabilities, our hard-won technological and military advantages, our allies and partners, and our future defense operations. We must partner, invest and integrate in new ways to secure what we value and safeguard: the assured resiliency of our networks, the data and the people.” (Source: U.S. DoD)

 

02 May 24. Ukraine comms struggles spur European hunger for L3Harris radios. The urgent need for secure communications in the Russia-Ukraine war is drumming up new levels of interest in L3Harris Technologies equipment among European militaries, according to the defense contractor.

More than 30,000 of the company’s radios and accessories have been shipped to the front lines, with much of the gear tied to handheld communication and coordination aboard vehicles. The U.S. has highlighted secure data-sharing devices in its pledges to Ukraine, at this point totaling approximately $44bn.

Samir Mehta, the president of communications systems at L3Harris, on May 1 told reporters in Washington the company is seeing “unprecedented demand among our NATO partners and allies for secure, resilient, tactical communications.” Close to $1bn of business is on the books.

“I think one only needs to look at a map to understand exactly what is driving that demand,” said Mehta, who spent the previous week meeting with officials in the Czech Republic and Poland, among other locations. “If you can’t communicate, you can fight but you can’t win.”

Reliable, low-profile means of relaying battlefield information have become a linchpin for fighting in Eastern Europe, where drones saturate the skies and sensors cue onto even the smallest electronic signal.

U.S. defense leaders have long warned of the risks of using unencrypted or rudimentary tools, citing the ease at which they can be traced, targeted and shot.

“If they’re not armed with the right equipment, the enemy will use transmissions, scanning the electromagnetic spectrum, to be able to find, locate and kill you any time you try to communicate,” Mehta said. “Every time that you take your non-high-assurance communication device out, whether it be a cell phone, whether it be Starlink, and use it to communicate, you are sending an emission that allows the Russians to find out exactly where you are.”

Indiscriminate cell phone use has been blamed for casualties on both sides of the war. Russian forces likely bombarded a Ukrainian base housing foreign fighters after detecting devices with British country codes, the London-based Telegraph reported. Dozens were killed in the strike.

“They’ve had too many unfortunate incidents where that happened,” Mehta said, “which is why they’ve adopted our technology and our radios as their primary communication device.”

L3Harris is the ninth largest contractor in world when ranked by defense-related revenue, reaping nearly $14bn in 2022, according to Defense News Top 100 analysis.

The U.S. Army tapped the company years ago for its combat net radio endeavor worth up to $6bn. An initial order was valued at $20m. (Source: C4ISR & Networks)

 

02 May 24. E4shield listed by The European Commission’s Joint Research Centre (JRC) among innovative technologies for defence against airborne pathogens. E4shield, the technology conceived, developed and patented by ELT Group that uses electromagnetic waves to inactivate respiratory viruses in the air, has been included and positively evaluated in the JRC – HERA technology foresight study. The European Commission’s Joint Research Centre (JRC) provides scientific support to the European Union in defining future guidelines/regulations with the aim of improving quality of life, for example by supporting the development and implementation of innovative technologies. The report ‘Suppressing Indoor Pathogen Transmission: A Technology Foresign study’ includes e4shield as one of the innovative technologies to be considered in the EU’s future to ensure an increase in indoor air quality.

Also according to this study, the airborne route is considered one of the most common modes of transmission of respiratory viruses. This is particularly relevant in indoor environments, where most respiratory infections occur. Controlling the transmission of airborne pathogens has become a major public health challenge to prevent the spread of infectious diseases, ensuring the safety and health of individuals and communities. Two groups of technologies have been identified to meet this challenge:

– For the detection of pathogens in the air

– For decontamination of air and surfaces

Experts from various fields, from universities to research and technology organisations, but also private companies and business associations, participated in this study in order to gain a multi-stakeholder perspective on the possible future development of innovative solutions.

The e4shield technology is currently used in devices distributed by e4life worldwide. The goal of e4life, a newco born out of the joint venture between ELT Group and Lendlease, is to expand the application of e4shield technology to other respiratory viruses (both human and animal) and to achieve the ambitious goal of also being effective against other microorganisms (e.g. bacteria).

 

01 May 24. L3Harris lobbying DoD to create ‘resilience’ standard for communications.

“Right now, you and I can go to a Cabela’s, we can buy a radio, we can go to a trade show, put it out on a table, and we can say it’s a form of resilient communication, because there’s no standard,” Samir Mehta said. “It’s time that we have a standard.”

L3Harris is actively lobbying leaders in the Pentagon and Congress to create a definition of what “resilient communications” means, as the defense giant seeks to fend off a growing interest for commercial communications providers from the military.

Speaking to reporters Wednesday, Samir Mehta, L3Harris’s president of communication systems, said the company was “talking to OSD leadership. We’re talking to service leadership. We’re talking to PMAs, we’re talking to PEOs. We’re carrying this message to all levels and all echelons.”

That message, at its core, is asking leadership to quite literally “define resilience” in a fundamental way that provides a standard across the military. Without spelling out exactly what the company wants that to look like, Mehta leaned heavily throughout his comments on the idea of high security waveforms that can’t be intercepted or jammed as easily as commercial capabilities.

“Right now, you and I can go to a Cabela’s, we can buy a radio, we can go to a trade show, put it out on a table, and we can say it’s a form of resilient communication, because there’s no standard,” Mehta said. “It’s time that we have a standard.”

The Pentagon’s Chief Information Officer is a main point of contact, Mehta said, adding that L3Harris is also talking to Congress on this issue. He didn’t rule out pushing for language to be included in the upcoming fiscal 2025 National Defense Authorization Act.

Mehta compared the push to the kind of standardization for encryption that has come out of the National Security Agency, noting, “Is it complicated? Probably will take some time and effort. Is it unobtanium? No, we’ve done this, we’ve proven the ability to do this in other areas.

The Defense Department is hardly alone among world militaries in looking to the commercial sector to see whether cheaper options are available. And Mehta was quick to note that there are plenty of good use cases for those unsecured comm links, such as the ability to connect servicemembers in the field to their families back home.

But “The concerning trend we see is that the budget pressures have caused some leaders in DoD, and a lot of our customers, to turn to [commercial comms] as a means of military communications,” Mehta said. “And some of these commercial providers provide a little bit of, I’ll call it the easy button. And so for us, it’s important to remind [DoD that] the easy button isn’t always the best button, especially if you’re taking missions and planning to potentially fight — hopefully not — but potentially fight in a highly contested environment versus a near peer adversary.”

The clearest example is the SpaceX Starlink terminal, which had much ballyhooed success in Ukraine — but which has also raised concerns, in part because of founder Elon Musk’s unpredictable nature and business dealings with China.

Relying on traditional defense firms means the Pentagon is “not entirely subject to the whims of one commercial owner of the company, or shareholder of the company, who happened to wake up in Beijing 48 hours ago to try to sell more Tesla’s and more EVs,” Mehta said. “So the question that we’re posing to our military leadership is, who do you trust?”

Despite the concerns about the Pentagon’s leanings towards the commercial sector, Mehta expressed confidence that his business is in healthy shape, citing a “record backlog” for the Harris-branded radio unit, to the point the company is transforming its Rochester, New York, production facility from split civil-military production to pure defense. That transformation should be done by the end of the year, with Mehta saying it should result in 5,000-7,000 more radios produced each year over the 2024 total of 70,000.

Driving that is “unprecedented demand” from Europe, he added, saying the company is now poised to book “close to a billion dollars in business from our European partners and allies.” (Source: Breaking Defense.com)

 

30 Apr 24. Volt Typhoon hacks likely to inspire copycats, CNMF’s Mahlock says. The Volt Typhoon hacks that targeted U.S. critical infrastructure won’t be the last of their kind, according to a Marine Corps cyber leader.

The Chinese intrusion affected organizations spanning the communications, utilities, education and government sectors including in Guam, a key foothold for American forces in the Indo-Pacific. The incident was disclosed in May 2023, with Microsoft describing the years-long operation as hard to detect and malicious.

The attack is likely to inspire copycats, said Maj. Gen. Lorna Mahlock, the commander of the Cyber National Mission Force. The CNMF, part of Cyber Command, deploys around the world to unearth malware and fortify digital defenses.

“I think we’re seeing Volt Typhoon activity continuing to persist. That’s in open source. We’re also seeing other actors using the tactics, techniques and procedures,” Mahlock said April 30 at the Modern Day Marine defense conference in Washington. “The greatest form of flattery is to copy.”

U.S. officials have long considered China a serious cyber hazard, with the International Institute for Strategic Studies think tank placing it in the second tier of its cyber powerhouse rankings alongside Russia. The Pentagon’s 2023 cyber strategy warned both Beijing and Moscow are prepared to unleash cyberattacks on critical infrastructure and defense networks should war break out.

The groundwork is being laid today. Volt Typhoon relied on so-called living-off-the-land techniques to lurk around vital systems and go largely unnoticed.

Attacks on critical infrastructure — food and water delivery, health care services, defense contracting and more — could jeopardize U.S. military response across the world as well as a sense of stateside calm. A ransomware attack on Colonial Pipeline in 2021 resulted in a run on fuel across the Southeast and aggravated concerns about energy security.

“Open-source reporting talks about this actor, out of China, who has access to our critical infrastructure and some of our key capabilities. Why? Not just for foreign intelligence-collection,” Mahlock said.

“We’ve seen this actor, China, grow in scope, scale and sophistication,” she added. “We’ve also seen that they’re undeterred.” (Source: C4ISR & Networks)

 

30 Apr 24.  Horizon3.ai Unveils Rapid Response Service for Cyber Resilience. Horizon3.ai, a pioneer in autonomous security solutions, today announced the launch of its Rapid Response service, now part of the NodeZero™ platform. This one-of-a-kind capability marks a significant advancement in autonomous penetration testing solutions by addressing a critical gap in measuring the real-world impact of exploitable vulnerabilities within the software many organizations have come to rely on. Now, organizations can gain a clear understanding of their ‘likelihood of exploitability’ for the most critical vulnerabilities being announced.

As organizations continue to contend with both zero-day and N-day vulnerabilities, the window of time between the public disclosure of a vulnerability and threat actors exploiting them in the wild is steadily shrinking. Knowing this predicament, organizations spend vast amounts of time, money, and resources patching the software they use after hearing of a vendor vulnerability announcement. Yet, how often are organizations expending considerable effort not knowing if a vulnerability is actually exploitable or not? The answer to that is, “quite often.”

So far in 2024, the U.S. National Vulnerability Database (NVD) has tracked 12,296 new vulnerabilities in publicly released software. A common challenge for organizations is determining whether any software they are using that is identified as vulnerable is actually exploitable within their specific environments, a judgment often contingent on how the software is deployed. Since organizations often lack a proven method to assess the ‘exploitability’ of software, they may find themselves updating software that does not require immediate patching. NodeZero addresses this issue with its Rapid Response service, which is specifically tailored to manage many of the most critical vulnerabilities more effectively. The following outlines the workings of the Rapid Response service.

As Horizon3.ai’s attack team conducts original research and uncovers new vulnerabilities, they also keep an eye on public vulnerability disclosures. They assess the exploitability of these vulnerabilities, considering factors such as the ease of exploitation, their severity, and the prevalence of the vulnerable software. Following their assessment, they develop proof of concept (POC) exploits, integrate them into NodeZero as new attack content, and notify customers about these emerging vulnerabilities. With NodeZero, customers can probe their systems using this new attack content to gain immediate insights into their level of exploitability. Furthermore, Horizon3.ai alerts customers if known vulnerable software is present in their production environments and warns them about NodeZero being able to exploit these weaknesses.

The Rapid Response service doesn’t just focus on vulnerabilities; it zeroes in on the exploitability of known issues in production environments. As part of this service, organizations receive proactive measures to keep abreast of cyberattacks. The vulnerabilities that flow through this program typically revolve around publicly accessible assets since they are the most likely targets for exploitation.

Recognizing the critical role of response time to emerging exploits in the wild, Horizon3.ai’s Rapid Response service is designed to provide organizations with a proactive defense mechanism to stay ahead of evolving cyberattacks as they’re discovered or trending in the wild. The fundamentals of this type of rapid response effort are concentrated on enabling organizations to preemptively mitigate nascent vulnerabilities before threat actors target them.

“In the swiftly evolving arena of cybersecurity, where threats emerge and proliferate with alarming speed, the essence of a robust defensive posture lies in responding rapidly. We enable organizations to move faster by prioritizing critical vulnerabilities that have the most potential impact on their organization,” says Snehal Antani, CEO and Co-founder of Horizon3.ai. “Our Rapid Response service is engineered to provide a preemptive shield, arming cybersecurity teams with the necessary knowledge, insights, and tools they need to protect their vital infrastructure.”

By leveraging Horizon3.ai’s expertise in using ‘offense to inform defense,’ and leaning into NodeZero’s autonomous capabilities, customers can schedule and/or immediately launch NodeZero using a single exploit-check to gain early detection of exploitability from an attacker’s perspective. Once finished, NodeZero prioritizes the most critical and exploitable vulnerabilities that must be patched because they have been deemed completely exploitable by the NodeZero platform.

Horizon3.ai’s Rapid Response service is a groundbreaking step forward in the field of cybersecurity, offering organizations an unprecedented level of preparedness against cyber threats. With its cutting-edge technology and proactive strategy, Horizon3.ai is redefining the landscape of cyber defense, providing a critical service that ensures organizations are not only aware of their vulnerabilities but are also equipped to address exploitability with unmatched speed and efficiency. This service, seamlessly integrated into the NodeZero platform, solidifies Horizon3.ai’s position as a leader in autonomous security solutions, empowering organizations to fortify their defenses against the unpredictable nature of cyber threats.

About Horizon3.ai

The NodeZero™ platform empowers organizations to continuously find, fix, and verify exploitable attack surfaces. It is the flagship product of Horizon3.ai, founded in 2019 by former industry and U.S. National Security veterans. Our mission is to help organizations see their networks through the eyes of the attacker and proactively fix problems that truly matter, improve the effectiveness of their security initiatives, and ensure that they are prepared to respond to real cyberattacks. (Source: BUSINESS WIRE)

 

30 Apr 24. Securonix Ushers in a New Era of AI-Reinforced CyberOps with the Launch of Securonix EON.

In an era where cybersecurity challenges are escalating at an unprecedented pace, Securonix today unveiled Securonix EON, a groundbreaking suite of AI-Reinforced capabilities to transform CyberOps in the face of new AI-powered threats. This launch builds on Securonix’s AI legacy, marking a significant leap forward in securing and preparing organizations to respond to the dynamic cybersecurity threat landscape against a backdrop of converging challenges facing security teams.

With the anticipated escalation of AI-powered attacks and adversaries, organizations already face the hurdles of ever-expanding attack surfaces, new regulatory and compliance pressures, and resource constraints. Securonix EON responds to these challenges by using Amazon Bedrock to provide a powerful, unified analyst experience with advanced AI-Reinforced capabilities. Amazon Bedrock is a fully managed service from Amazon Web Services (AWS) that offers a choice of high-performing foundation models—like Claude 3—from leading AI companies via a single API, along with a broad set of capabilities organizations need to build generative AI applications with security, privacy, and responsible AI. As part of the first phase of innovation, Securonix EON will include the following AI-Reinforced capabilities: Insider Threat Psycholinguistics, Adaptive Threat Modeling, and InvestigateRX.

“Cybercriminals are increasingly weaponizing AI, and we’re meeting that challenge head-on,” said Securonix CEO Nayaki Nayyar. “As the world faces advanced AI-powered threats on top of the myriad of other challenges confronting security teams, we are releasing Securonix EON to help our customers stay ahead of the escalating threat curve. Securonix EON is not just a suite of capabilities, it’s a comprehensive strategy to combat cyber threats ushering in a new era of AI-Reinforced CyberOps.”

Securonix has chosen Amazon Bedrock to underpin many of its advanced new capabilities, allowing organizations to use best-of-breed AI to make precise security decisions more quickly, and effectively counter the rise in sophisticated AI-powered threats. Amazon Bedrock is a strong fit for Securonix’s large enterprise customers who require AI systems that are compliant with several security and privacy standards, including HIPAA, GDPR, and others.

“By combining Amazon Bedrock and Anthropic’s Claude 3 with Securonix’s cutting-edge AI-Reinforced CyberOps advancements, customers will be able to detect and defend against adversaries with greater speed, precision, and efficacy than ever before,” continued Nayyar. “These are the first of our AI-Reinforced Securonix EON capabilities, with continued innovation to come that will further advance the cybersecurity market.”

The cornerstone of Securonix’s innovative approach rests on three core pillars: First, reinforce the platform with AI so human intervention happens at the most critical moments, while AI handles the manual, repetitive tasks. Second, apply a cybersecurity mesh architecture to seamlessly and agnostically integrate any security tool, clouds, and data lakes. Third, deliver a frictionless experience with reduced noise, an intuitive user interface, and targeted threat intelligence that frees analysts from the tedious task of manual log analysis and endless alert triage, allowing them to focus on high-level investigations and strategic decision-making. From these principles, Securonix EON extends the capabilities of the company’s industry-leading Unified Defense SIEM.

Key features of Securonix EON include:

  • Insider Threat Psycholinguistics: Utilizing the science of deciphering psychology from language powered by Amazon Bedrock, Securonix provides entity and activity-based risk scoring to uplevel insider threat hunting capabilities. This industry-first feature enables users to accurately and efficiently discern the intent behind a user’s language and behavior, identifying potential malicious activity. Key categories analyzed include financial crimes, obfuscation, and more.
  • Adaptive Threat Modeling: Leveraging machine learning to develop adaptive threat models and dynamic threat chaining of violations with anomaly detections, Securonix enhances investigations by enabling analysts and CyberOps teams to identify never-before-seen attack chains in near real-time. With more speed, accuracy, and efficiency, this capability builds the full picture of an attack to prevent destructive phases.
  • InvestigateRX: Converting retrieved targeted and objective content into a coherent and context-aware summary, analysts are empowered to make swift decisions and save approximately 15 minutes per incident. Securonix customers no longer need to search for data from various sources because the information is delivered directly to the analyst.

“Effectiveness, efficiency, and scale are the three words that drive our business. And in today’s world, the linear model of adding people as customers and data grows is unsustainable,” said Scott McCrady, CEO at SolCyber Managed Security Services. “That’s why we are thrilled about Securonix working with AWS to utilize Amazon Bedrock within its newly introduced suite of AI capabilities. Our goal is to have the best analysts in the world, and putting the best tools in their hands, allowing them to defend against present and emerging threats while also allowing them to be more efficient is the holy grail of security ops. We couldn’t be more excited about what this is unlocking for our operations and our customers.”

Securonix will be showcasing new AI-Reinforced Securonix EON capabilities at the RSA Conference, May 6 – 9, 2024 in San Francisco, at booth #1127 in South Hall. For more information or to meet with Securonix at the conference, please visit: https://www.securonix.com/rsa-conference-2024.

About Securonix

Securonix is pushing forward in its mission to secure the world by staying ahead of cyber threats. Securonix Unified Defense SIEM provides organizations with the first and only AI-Reinforced threat detection, investigation and response (TDIR) solution built with a cybersecurity mesh architecture on a highly scalable data cloud. The innovative cloud-native solution delivers a frictionless CyberOps experience and enables organizations to scale up their security operations and keep up with evolving threats. For more information, visit www.securonix.com

(Source: BUSINESS WIRE)

 

01 May 24. Global: Sophisticated tactics by Chinese state actors point to heightened security, disruption risks. On 29 April, the cyber security firm Infoblox reported that a Chinese state-sponsored group, ‘Muddling Meerkat’, is targeting global internet infrastructure. The group has been active since 2019. It crafts special requests to bypass restrictions imposed by the Great Firewall of China (GFW), which blocks users’ access to unauthorised websites. However, the group is able to mimic legitimate traffic. This allows it to circumvent the firewall and to conduct malicious operations globally. The group’s activity also suggests that it is possibly conducting reconnaissance operations to pre-position itself within adversarial infrastructure for espionage and disruption operations. Muddling Meerkat’s unique capabilities underscore Chinese state-sponsored actors’ high sophistication. The Chinese state-sponsored group ‘Volt Typhoon’ has also conducted pre-positioning operations against US infrastructure since 2019, pointing to heightened security and disruption risks facing global organisations. (Source: Sibylline)

 

30 Apr 24. Kongsberg contracted to develop remote control communications terminal. Kongsberg Defence & Aerospace will develop the THOR RCT (tRCT) for the Norwegian Defence Materiel Agency (NDMA) under a NOK255m (US$23m) contract as part of the country’s Mime programme.

The terminal will be designed for use with radio variants, but also equipped with interfaces to allow standalone  crypto solutions for other communications systems like satellites, 5G ands fixed infrastructure.

The development will be linked to the delivery of the THOR radio system and a contract for serial production of tRCT will be expected to follow. Norway’s Mime programme has included other THOR systems and will modernise tactical management systems for the land, sea and air domains.

In June 2023, the NDMA awarded a NOK320 m contract to Kongsberg to develop tactical radio equipment for the Norwegian Armed and low-volume production of THOR Vehicle Radio Module (VRM) will constitute the first phase of this agreement. It is believed a handheld THOR version has also been in development.

Mime will be built around a strategic agreement signed between NDMA and Kongsberg, with the company taking responsibility for service and system integration, which also includes application support and architecture.

Details have not been provided on tRCT or the handheld radio but Shephard Defence Insight described THOR VRM as a dual-band software-defined radio designed for tactical mobile platforms which operates between 30-1525Mhz. It provides two independent VHF/UHF channels that may be operated simultaneously for voice and data communication. (Source: Google/Shephard)

 

30 Apr 24. Global: Uptick in cyber attacks via stolen third-party credentials demonstrates elevated security risks. On 29 April, the software company Okta warned of a spike in cyber attacks against its customers between 19 April and 26 April. The company stated that unknown threat actors used stolen data from previous third-party breaches to compromise user accounts. Threat actors also employed residential proxies to reroute traffic and maintain anonymity. However, Okta claimed that only a small percentage of attacks were successful, as customers using the company’s ‘log and enforce’ mode were protected against proxy requests. These attacks follow a warning by the technology company Cisco in mid-April about an increase in brute-force attacks against their customers using stolen third-party data and anonymising services. As such, we assess additional attacks targeting user accounts are likely in the short term. Threat actors can easily purchase stolen third-party credentials on the dark web to conduct further malicious campaigns, highlighting elevated security risks to global organisations stemming from third parties. (Source: Sibylline)

 

29 Apr 24. BigBear.ai Achieves ‘Awardable’ Status on DoD’s Tradewinds Procurement Platform with 5 AI Solutions. BigBear.ai (NYSE: BBAI) today announced that it has been designated as an “Awardable” vendor for the Chief Digital and Artificial Intelligence Office’s (CDAO) Tradewinds Solutions Marketplace. Five of the company’s products, including Sensor, Data and AI Orchestration (ConductorOS), Time-Series Forecasting (VANE), Contested Logistics Planning (AURORA), Maritime Domain Awareness (Arcas), and Publicly Available Data Curation (Observe) have been added to the Marketplace.

The DoD’s Tradewinds program acts as a central hub to streamline the adoption of cutting-edge artificial intelligence (AI) capabilities. This program serves as a uniquely efficient contracting vehicle, bridging the procurement gap between the DoD and industry partners like BigBear.ai. With these solutions now available on the Tradewinds marketplace, they are considered post-competition, and DoD users are now able to satisfy standard competition requirements in government contracting.

BigBear.ai’s solutions now available on Tradewinds include:

  • ConductorOS: BigBear.ai’s data and AI orchestration platform, ConductorOS operationalizes AI at the edge to accelerate decision-making for the operator, while supporting the integration of 3rd party AI/ML models. ConductorOS offers a truly open architecture to enable interoperability across disparate sensors, data, and artificial intelligence models across nearly all domains, with near-zero latency and optimized for low/no bandwidth environments.
  • VANE: BigBear.ai’s ‘Virtual Anticipation Network’ contriving clarity from “dirty data” in multi-domain environments for military and government applications; processing bns of data points to predict and anticipate adversarial actions in complex environments with near accuracy.
  • Arcas: BigBear.ai’s computer vision, predictive analytics, and event alerting solution, Arcas conflates ms of data points to provide situational awareness, enabling AI/ML-powered predictive forecasting.
  • AURORA: BigBear.ai’s solution enables military planners to rapidly extract contested logistics and operations data, develop and assess Courses of Action, immediately understand the impact on force structure and readiness, and simulate, visualize, and plan sustainment operations.
  • Observe: A data collection and curation platform that transforms vast amounts of publicly available data into actionable intelligence, enabling unique global situational analysis needs.

“We are focused on delivering operations-ready capabilities in multiple critical use cases at the edge, and we will continue to pursue pathways for more accessible government funding,” commented Mandy Long, CEO of BigBear.ai. “Our designation as an ‘Awardable’ vendor on Tradewinds is an example of how we are continuing to stay nimble as the government acquisition landscape evolves.” (Source: BUSINESS WIRE)

 

26 Apr 24. Cyber Update Key points.

  • A cyber attack on a French hospital underscores the elevated security and financial risks facing the healthcare industry A new campaign targeting Western organisations elevates security and cyber espionage risks from Russian state-sponsored actors A new information-stealing campaign underscores security and financial risks from cyber criminals
  • The exploitation of zero-day vulnerabilities highlights security and espionage risks from state-sponsored groups via the software supply chain (see Sibylline Cyber Daily Analytical Update – 25 April 2024 and our Technical analysis below).
  • A cyber attack on US water and wastewater facilities signals elevated disruption risks from pro-Russian hacktivists (see Sibylline Cyber Daily Analytical Update – 26 April 2024).

Technical analysis of weekly stories

The financially motivated group ‘CoralRaider’ is targeting global organisations in a new information-stealing campaign. The campaign starts with a malicious download of a Windows .LNK file, distributed via phishing emails or masquerading as a film file download. The malicious file then fetches the information-stealer (info-stealer) malware from a content delivery network (CDN) cache, enabling the group to avoid request delays and evade network defence mechanisms. The group primarily deployed three popular info-stealers (‘CryptoBot’, ‘LummaC2’ and ‘Rhadamathys’), customising some of their features to achieve better obfuscation. Notably, the newer version of CryptoBot also targets password manager databases as well as authenticator information to steal cryptocurrency wallet credentials. Researchers suspect that the group is likely of Vietnamese origin due to its extensive use of the Vietnamese language, and frequent targeting of organisations based in South East Asia. Additionally, the group has also compromised organisations in Africa, Europe, the Middle East, North America and Latin America. Although the three info-stealers are popular malware-as-a-service (MaaS) tools, CoralRaider’s unique customisation points to the continuous development and sophistication of their tactics, techniques, and procedures (TTPs).

A new state-sponsored group, ‘UAT4356’, exploited two zero-day vulnerabilities (CVE-2024-20353 and CVE-2024-20359) in a cyber espionage campaign named ‘ArcaneDoor’ which targeted global government organisations. While it remains unclear how the group first infiltrated targeted networks, it deployed two backdoors (‘Line Dancer’ and ‘Line Runner’) to achieve persistence, evade detection and exfiltrate data. Line Dancer is specifically deployed to establish direct communication with targeted systems, bypassing authentication requirements and obtaining the ability to remotely execute code. Line Runner exploits the two zero-day vulnerabilities to allow the threat actors to maintain access to the compromised system regardless of upgrades and reboots. The threat actors combined the backdoors to initially stage information via Line Dancer and then exfiltrate it via Line Runner. This campaign further underscores the heightened exploitation of zero-day vulnerabilities, particularly in perimeter network devices like firewalls. These devices handle incoming and outgoing communication as they sit on the edge of a network, thus providing optimal positioning for espionage operations.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Enforce strict security policies such as regular software and password updates, as well as adequate network segmentation, to prevent lateral movement following an infection
  • Ensure sensitive information is stored securely in appropriate password management services, avoiding the use of plain text
  • Monitor devices and networks for suspicious activity
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network
  • Ensure adequate security detection measures are in place, particularly behaviour-based end-point detection and response (EDR) solutions

Our cyber word of the week: Endpoint Detection and Response (EDR)

(Source: Sibylline)

—————————————————————————————————————————————————————————————————————————————————————————————————————————————

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

 

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

—————————————————————————————————————————————————————————————————————————————————————————————————————————————

Primary Sidebar

Advertisers

  • Pythia
  • Teledyne
  • Exensor
  • Visit the Oxley website
  • Blighter
  • SPECTRA
  • Britbots logo
  • Faun Trackway
  • Systematic
  • CISION logo
  • ProTEK logo
  • ProTEK logo
  • ssafa logo
  • IEE
  • EXFOR logo
  • sibylline logo
  • Team Thunder logo
  • Comtech logo
  • GoExporting logo
  • ECHODYNE logo
  • Supercat logo
  • Galvion logo
  • Leonardo DRS logo
  • MTC logo
  • IDC logo
  • DSEI logo
  • DVD2024 logo
  • SDSC logo
  • TELEDYNE FLIR logo
  • VeteranUK logo
  • Matrix Space logo
  • ST Engineering logo
  • EWS logo
  • sentinel photonics logo
  • capua logo
  • Curtiss-Wright logo
  • Brave1 logo
  • Drone Evolution logo
  • AEI Systems logo
  • EOS logo
  • NMSUK logo
  • Openworks logo
  • Sandown Park logo
Hilux UKDSE AARTOS ST Engineering Future Artillery

Contact Us

BATTLESPACE Publications
41 St Georges Drive
London SW1V 4DG

+44 (0)77689 54766

BATTLESPACE Technologies

An international defence electronics news service providing our readers with up to date developments in the defence electronics industry.

Recent News

  • Protek Selected By Dutch Armed Forces

    May 2, 2026
    Read more
  • PARLIAMENTARY QUESTIONS

    May 1, 2026
    Read more
  • MANAGEMENT ON THE MOVE

    May 1, 2026
    Read more

Copyright BATTLESPACE Publications © 2002–2026.

This website uses cookies to improve your experience. If you continue to use the website, we'll assume you're ok with this.   Read More  Accept
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT