Sponsored by Spectra Group
——————————————————————————————————————————————————————————————————————————————————————————————————————————————
09 May 24. General Atomics Aeronautical Systems, Inc. (GA-ASI) is working with the U.S. Special Operations Command (USSOCOM) to develop a new Airborne Battlespace Awareness and Defense (ABAD) capability. The new ABAD pod is being developed for the GA-ASI-supplied MQ-9A Block 5 Medium-Altitude, Long-Endurance Tactical (MALET) Extended Range Remotely Piloted Aircraft (RPA) being operated by the U.S. Air Force Special Operations Command (AFSOC). ABAD will provide detection and protection against Radio Frequency (RF) and Infrared (IR) threats.
“Threat awareness and survivability are critical for MQ-9A to operate in contested environments,” said GA-ASI President David R. Alexander. “ABAD will enable the tracking of RF and IR missile threats, enable defensive measures, and real-time threat awareness for MQ-9A.”
The first phase of contract work evaluated suitable RF Electronic Warfare (EW) and IR countermeasures systems. This led to the down selection of a next-generation software-defined radio-based EW system from BAE Systems and the AN/AAQ-45 Distributed Aperture Infrared Countermeasure System (DAIRCM) from Leonardo DRS.
“BAE Systems’ advancements in small form factor EW technologies will provide affordable multifunction capabilities for the MQ-9A, enabling it to operate in previously inaccessible airspace,” said Joshua Niedzwiecki, vice president and general manager of Electronic Combat Solutions at BAE Systems.
“Leonardo DRS is delighted to team with GA-ASI to provide our industry-leading and proven AN/AAQ-45 DAIRCM aircraft protection system to enhance MQ-9A survivability in support of this mission for USSOCOM,” said DRS Vice President of the DAIRCM Program, David Snodgrass.
Work is underway on an engineering and test effort to mature the capability as a podded payload capable of operation on the MQ-9A aircraft in 2025.
09 May 24. Kromek, the designer and manufacturer of radiological and biological detectors, based in Sedgefield Co. Durham, today launches its new generation RayMon detector. This is a high-performance handheld spectrometer with a set of interchangeable probes: CZT, NaI and Alpha Beta. It is ideal for protecting critical national infrastructure such as nuclear power stations or military installations and for security screening, civil defence, homeland security or peace keeping/peace support operations. It is portable, easy to deploy and can undertake previously-lab-based spectral analysis directly in the field with speed and precision.
The new generation RayMon has a built-in library of 94 radionuclides, to which custom nuclides can be added. Key information such as dose rate and counts per second can be viewed on the Dose Screen in real-time. In Search Mode, the clear visual graphs indicate when count rate is increasing or decreasing, directing the user to the location of the source. All reports and data files on the RayMon can either be exported onto a USB or shared via email.
Enhancing the RayMon’s capabilities are three additional probes: a high resolution CZT probe, a high sensitivity NaI (sodium iodide) smart probe and an Alpha Beta smart probe.
The CZT probe provides precise identification of radionuclides, even when faced with mixed or shielded sources. With its small form factor, operation at room temperature without the need for cooling, and direct conversion, the CZT Probe is a cost-effective and user-friendly alternative to HPGe detectors. Its small form factor alleviates the difficulty of taking measurements in hard-to-reach areas.
The NaI probe is designed for collecting count data in low-dose environments. The high sensitivity and efficiency of the 2” x 2” Sodium Iodide (NaI) crystal ensures even the weakest sources can be detected. Taking measurements in narrow areas is facilitated by the incorporation of silicon photomultiplier technology into Probe, giving the device its small form factor. The probe also includes a high dose sensor to ensure that measurements continue to be taken when the NaI probe becomes saturated with counts.
The Alpha Beta probe transfers Alpha or Beta count data onto the RayMon screen but can also store detector and calibration information itself. Its small size and lightweight build means the device can be used comfortably in one hand, with the RayMon in the other, for extended amounts of time.
Ahead of the launch of the new generation RayMon, Craig Duff, Kromek’s Commercial Director of Radiation and Nuclear Products, said: “The new generation RayMon is the most advanced detector designed specifically for the protection of critical national infrastructure. It is a product of the innovation of our in-house scientists and engineers who are able to respond quickly to meet new customer requirements.”
The new generation RayMon will make its public debut next week, alongside the full suite of Kromek’s handheld detectors, at the Society for Radiological Protection’s annual conference in Eastbourne between 14-16 May.
09 May 24. Iran’s Avtobazas. Last month, Armada published an article about what maybe an Iranian version of Russia’s 1RL257E Krasukha-4 ground-based Electronic Warfare (EW) system.
Information has since surfaced on social media disclosing that Tehran recently deployed Russian-supplied IL222M Avtobaza-M ground-based signals intelligence systems. Reports state that Iran may have received its first 1L222M examples in 2011. The kit was rumoured to have been involved in the Islamic Republic’s downing of a Lockheed Martin RQ-170 Sentinel Uninhabited Aerial Vehicle (UAV). The Central Intelligence Agency UAV was brought down in Iranian territory on 4th December 2011.
Avtobaza-M is designed to collect signals intelligence to support air defence by detecting, locating and identifying air threats via their electromagnetic emissions. Russian military documents seen by Armada say the IL222M detects and processes emissions on a 200 megahertz/MHz to 18 gigahertz/GHz waveband. Avtobaza-M will detect and process signals from Identification Friend or Foe (IFF) transponders equipping aircraft. These transponders usually squawk across wavebands of between one gigahertz/GHz to 1.21GHz. Aircraft Tactical Air Navigation (TACAN) emissions from 962MHz to 1.213MHz can be detected and processed by Avtobaza-M. Other key targets include emissions from Airborne Early Warning (AEW) aircraft. Specific targets include the Northrop Grumman AN/APY-1/2 S-band (2.3GHz to 2.5GHz/2.7GHz to 3.7GHz) and Lockheed Martin AN/APS-139 and AN/APS-145 very high frequency (400MHz to 450MHz) AEW radars equipping Boeing E-3 Sentry and Northrop Grumman E-2 Hawkeye series aircraft respectively.
The 1L222M detects signals with a minimum strength of -88 decibels-per-watt. Direction-finding of emitters of interest are determined with between 0.4- and one-degree of accuracy. The documents continue that targets can be determined at ranges of 81 nautical miles/nm (150 kilometres/km) to 108nm (200km). Avtobaza-M shares data on target azimuth and elevation angle, radar type (pulse-Doppler and/or continuous wave) and emission waveform. Up to 60 targets can be detected and processed by the system at any one time. Target detection is done using a rotating antenna making either six or twelve revolutions-per-minute. The IL222M consumes twelve kilowatts of electricity.
Architecture
The system’s architecture includes one information processing station, and four detection and direction-finding stations. The entire system is deployed on two vehicles, networking is facilitated with a two-way fibre optic link carrying data at a rate of 1.2 kilobits-per-second. Target information (target angle, azimuth and elevation) is displayed on the operator’s console. Other parameters like signal carrier frequency and pulse duration are also displayed. Avtobaza-M’s human-machine interface is highly customisable by the operator with particulars regarding taboo frequencies, and specific search sectors and/or off-limits areas easy to arrange. The system has a crew of four.
Concepts of operations
Air targets can be detected and processed via their emissions providing at bearing information relative to the system’s location. Once this information is determined, it can be shared with ground-based air defences to advice the latter on a target’s possible ingress vectors. Likewise, this data can be shared with fighter controllers to direct combat aircraft to perform interceptions. Given the IL222M’s range, one should consider it an ostensibly tactical and/or operational asset which supports battlefield air defence.
It is likely the Iranian military deploys the Avtobaza-M not only to support battlefield air defence but also to help protect strategic point targets. One key tactical consideration is that emissions control could hamper the system’s utility. Combat aircraft routinely go ‘electromagnetically dark’ when flying in contested airspace, although the 1L222M could help prosecute targets exhibiting lax radio discipline. Similarly, target coordinates derived by the equipment could assist the direction of electronic attack by systems like the Krasukha-4. The documents add that Avtobaza-M supports littoral operations by detecting line-of-sight emissions from naval surveillance radars.
On 13th April Iran mounted a large-scale attack on Israel involving circa 300 surface-to-surface ballistic and cruise missiles, and UAVs. According to the Israeli Ministry of Defence, 99 percent of these threats were engaged and destroyed by American, British, French, Israeli and Jordanian electronic and kinetic effects. This engagement was assisted with sensor and communications provision from these, and other unnamed, allied nations.
Systems like the 1L222M are important capabilities for Iran. As a force protection asset, they provide a means by which the Islamic Republic can protect key strategic targets from air-to-surface attack. Avtobaza-M can also be a useful force protection asset on the battlefield. Allied nations need to be cognisant of such capabilities and ensure that systems like 1L222M are high priority targets during any future showdown with the Islamic Republic. (Source: Armada)
09 May 24. May Spectrum SitRep.
Armada’s monthly round-up of all the latest electronic warfare news in the product, programme and operational domains.
New COMINT Consulting Capabilities
COMINT Consulting has shared with Armada what the company says is a first for the communications and signals intelligence market, specifically precision Linear Feedback Shift Register (LFSR) classification. LFSR is a complex mathematical procedure which in the communications and signals intelligence context allows the extraction of one or more polynomials. The company told Armada that these polynomials can be used to identify the encryption hardware and/or software maybe using. This process can be performed in real time. COMINT Consulting added that LFSR precision classification will be available with its Krypto500 analysis, classification and decoding software by the end of April. The Krypto500 software performs these tasks across wavebands of three kilohertz up to 30 megahertz.
Impressive Integrity
Shift5 announced the release of its new GPS Integrity Module on 23rd April. A company press release described the product as a “platform-agnostic solution applicable for military, aviation, rail, maritime, and space industries.” The module determines changes to navigational position “through multi-faceted anomaly detection methods.” The module helps alert users to GNSS (Global Navigation Satellite System) spoofing attacks as they occur. The GPS Integrity Module works by performing algorithmic position analysis to determine significant position deviations and “GPS (Global Positioning System) data validation to verify GPS information accuracy.” Should GNSS spoofing be determined, users are notified immediately. Egon Rinderer, Shift5’s chief technology officer, told Armada that GNSS jamming can be identified through advanced signal analysis, anomaly detection, cross-validation with alternative navigation sources, and geolocation analysis and timing verification. The GPS Integrity Module “utilises raw data generated by sensors and systems onboard platforms.” Mr. Rinderer added that Shift5 is currently deploying the GPS Integrity Module with an unnamed customer. (Source: Armada)
08 May 24. DSA 2024: Aselsan unveils radio relay system. Turkish company Aselsan has unveiled its latest radio relay system at the Defence Services Asia (DSA) 2024 exhibition held in Kuala Lumpur from 6 to 9 May.
The system, known as URAL, is an airborne software-defined radio relay operating in the very/ultra-high frequency (V/UHF) band.
URAL is designed for unmanned aerial vehicles (UAVs) and other airborne platforms for surveillance, reconnaissance, and mapping applications.
It utilises Aselsan’s advanced network waveform features to achieve the high throughput data rate.
The VHF and UHF bands are incorporated in a single unit to reduce the system’s size and weight to meet the low size, weight, and power (SWaP) requirement of UAVs. The company told Janes that older radio relays are available in single band only, either VHF or UHF frequency.
Aselsan’s representative did not disclose the modulation type, data rate, and the waveforms incorporated in the system at the time of publication.
(Source: Janes)
08 May 24. Today, General Atomics Aeronautical Systems, Inc. (GA-ASI) announced its partnership with Shift5 to integrate the company’s onboard cyber anomaly detection and predictive maintenance capabilities into the MQ-9A Reaper for the United States Special Operations Command (USSOCOM) and Air Force Special Operations Command (AFSOC). The GA-ASI and Shift5 partnership will assure AFSOC and SOCOM mission readiness and cyber survivability.
“GA-ASI has long maintained a focused commitment to unmanned combat operations and unmatched unmanned aircraft system (UAS) experience, exemplified through our MQ-9A Reaper,” said GA-ASI President David R. Alexander. “The next logical and immediate extension of our work in enabling the U.S. Air Force is empowering AFSOC and SOCOM with additional resiliency and survivability of the MQ-9A on the battlefield. Shift5 represents a new class of dual-use defense tech business that can successfully operate at speed and scale with us to make an immediate impact for the warfighter.”
The Shift5 Platform reveals critical operational and cybersecurity insights that enable operators to move from data to decisions quickly and confidently. The Shift5 Platform deploys on premises or in the cloud and supports streaming and air-gapped modes for offline and online capability.
“The battlefield of the future will include more remotely piloted, autonomous, and unmanned systems. Central to maintaining advantage in this operating environment is access to real-time data,” said Josh Lospinoso, CEO and co-founder of Shift5. “Our work with GA-ASI represents one of the most efficient and effective ways that AFSOC and SOCOM can gain access to critical operational and cybersecurity insights, democratize that data, and maintain decision dominance.”
Shift5 achieved its first cross-platform Authority to Operate (ATO) Certification from the U.S. Department of Defense (DoD) in April 2023, validating the resilience and security of the Shift5 Platform. Most recently, the company announced its contract with the U.S. Army to secure the High Mobility Artillery Rocket System (HIMARS) against cyber threats and provide readiness assessments to enable predictive maintenance. It also introduced the GPS Integrity Module, the first known cross-platform solution to automate detection and alerts to combat GPS spoofing risks.
08 May 24. US Army Successfully Demos GD’s Impact Mission Planning System.
- Software designed to reduce pilot workload, improve situational awareness and sensor-to-shooter timelines, and reduce fratricide
The U.S. Army recently evaluated the Integrated Mission Planning and Airspace Control Tools (IMPACT) from General Dynamics Mission Systems at the National Training Center at Ft. Irwin and Camp Pendleton, Calif. as part of Project Convergence-Capstone 4, which is an annual Joint and Coalition large-scale experiment where the military tests its cutting-edge technologies under field-like conditions. Elements of the III Corps and XVIII Airborne Corps employed IMPACT for integrated mission planning and airspace control.
The focus of the evaluation was the collection of feedback from hands-on soldier usage of the IMPACT software at the flight company level for mission planning. Soldiers successfully used IMPACT, along with its ATAK plugin for the PEO-Soldier Air Warrior Tablet, to plan and evaluate a rotary wing mission, load that mission data onto a data transfer device, and use the device to load the mission onto a UH-60M helicopter.
“This pilot effort was the result of years of teamwork between the Army and its industry partners,” said Rachel Oberc, General Dynamics Mission Systems vice president for RF Systems. “To see the payoff of this trailblazing technology tested under real-world scenarios is extraordinary.”
The team also gathered critical feedback on the software and plan to use it for improving the software prior to its scheduled fielding date in two years. Soldiers also used IMPACT in several PEO Aviation experiments to provide command post data to the aircraft in flight, enabling emergent airspace usage (Artillery, EW, and UAS re-tasking) to be pushed to the aircraft, thus enabling dynamic replanning of the mission route.
“IMPACT is a key enabling tool to facilitate Joint All Domain Command and Control for Army aviation in Multi Domain Operations,” said Col. Burr H. Miller, Product Manager, Aviation Mission Systems and Architecture in PEO Aviation. “It provides capabilities for both the command post and mobile/handheld computing environments and converges the current mission planning capabilities of AMPS with the airspace control capabilities of TAIS into one role-based solution.”
Additionally, IMPACT was used to manage the airspace control picture for the event, disseminating such information digitally to the command post (including CPCE, AFATDS, and DARPA’s experimental ASTARTE software), and coordinating all airspace control requests for the Army and coalition partners from France and the United Kingdom. IMPACT was used to inform ASTARTE’s microservices to accelerate weapon/target pairing by predictive analysis of airspace and aircraft in flight. IMPACT also demonstrated a prototype integration of ASTARTE microservices into a standalone capability enhancement for aviation commander mission planning.
By utilizing a browser-based, fully 3-D web application, IMPACT ensured that all participants on the network could access and use the airspace control and mission planning functions. IMPACT’s role-based access ensured that individuals could login from any computer using their credentials and access their mission functions, maintaining established user preferences like bookmarks, units of measurement, and display states of layers. IMPACT’s focus on services and data made sure that external systems could leverage the detailed information maintained by its operators.
“As we continue to add and mature IMPACT capabilities, the result will be an integrated enterprise solution for both the enduring and future Army aviation fleets,” said Miller. “We are excited with what IMPACT is bringing to the fight and judging by the great feedback and acceptance from the Soldier-operators, so are they.” (Source: ASD Network)
07 May 24. DOD Support to National Security Memorandum 22. On April 30, the White House released National Security Memorandum (NSM)-22 on Critical Infrastructure, to secure and enhance the resilience of the 16 critical infrastructure sectors that provide essential services to the American people, to include the energy, communications, transportation, water, and Defense Industrial Base (DIB) services that DoD relies on to operate.
We know that the People’s Republic of China and Russia are actively targeting U.S. critical infrastructure to be poised to disrupt our society and interfere with DoD’s operations in a crisis. Extreme weather also increasingly poses a risk to our mission. Proactive steps by government and industry partners, as outlined in this NSM, are essential to ensure that our critical infrastructure can withstand and operate through disruption, no matter the cause.
DoD will continue to invest in capabilities like the Critical Infrastructure Defense Analytic Center and in civilian-military collaboration with federal, state, local, tribal, and territorial levels of government to manage risk to the critical infrastructure that support DoD missions. As the Sector Risk Management Agency for the DIB, DoD will leverage major Secretary of Defense-level initiatives like the DOD DIB Cyber Strategy and the National Defense Industrial Base Strategy. DoD will continue to support robust information exchanges and collaboration with industry, and we will continue to assess and manage risk to the DIB. We will develop a sector-wide risk management program, leveraging and aligning DoD wide efforts. Finally, we will support and leverage Cybersecurity and Infrastructure Security Agency (CISA) led cross-sector risk management, in coordination with other federal agencies, to address challenges in areas where DoD cannot effectively act alone.
DoD thanks industry partners in the National Defense Information Sharing and Analysis Center (ND-ISAC), and in the Sector Coordinating Council (SCC) who are key partners for this NSM’s implementation, and all of the components across DoD who are coming together to support and enable this NSM’s success.
DoD encourages all DIB companies to join the ND-ISAC, the SCC, and the DoD DIB Cybersecurity programs to receive assistance and support, and to be a part of this important effort. (Source: U.S. DoD)
07 May 24. Red Hat Announces Podman AI Lab. Red Hat, Inc., the world’s leading provider of open source solutions, today announced Podman AI Lab, an extension for Podman Desktop that gives developers the ability to build, test and run generative artificial intelligence (GenAI)-powered applications in containers using an intuitive, graphical interface on their local workstation. This contributes to the democratization of GenAI, and gives developers the benefits of convenience, simplicity and cost efficiency of their local developer experience while maintaining ownership and control over sensitive data.
The recent surge of GenAI and open source large language models (LLMs) has ushered in a new era of computing that relies heavily on the use of AI-enabled applications, and organizations are moving quickly to establish expertise, processes and tools to remain relevant. Industry analyst firm IDC notes this shift, predicting “By 2026, 40% of net-new applications will be intelligent apps, where developers incorporate AI to enhance existing experiences and form new use cases.”1
As AI and data science move into mainstream application development, tools like Podman AI Lab can help fuel developer adoption of GenAI for building intelligent applications or enhancing their workflow using AI-augmented development capabilities. AI Lab features a recipe catalog with sample applications that give developers a jump start on some of the more common use cases for LLMs, including:
– Chatbots that simulate human conversation, using AI to comprehend user inquiries and offer suitable responses. These capabilities are often used to augment applications that provide self-service customer support or virtual personal assistance.
– Text summarizers, which provide versatile capabilities across many applications and industries, where they can deliver effective and efficient information management. Using this recipe, developers can build applications to assist with things like content creation and curation, research, news aggregation, social media monitoring, and language learning.
– Code generators, which empower developers to concentrate on higher-level design and problem-solving by automating repetitive tasks like project setup and API integration, or to produce code templates.
– Object detection helps identify and locate objects within digital images or video frames. It is a fundamental component in various applications, including autonomous vehicles, retail inventory management, precision agriculture, and sports broadcasting.
– Audio-to-text transcription involves the process of automatically transcribing spoken language into written text, facilitating documentation, accessibility, and analysis of audio content.
These examples provide an entry point for developers where they can review the source code to see how the application is built and learn best practices for integrating their code with an AI model.
For developers, containers have traditionally provided a flexible, efficient and consistent environment for building and testing applications on their desktops without worrying about conflicts or compatibility issues. Today, they are looking for the same simplicity and ease of use for AI models. Podman AI Lab helps meet this need by giving them the ability to provision local inference servers, making it easier to run a model locally, get an endpoint, and start writing code to wrap new capabilities around the model.
In addition, Podman AI Lab includes a playground environment that allows users to interact with models and observe their behavior. This can be used to test, experiment and develop prototypes and applications with the models. An intuitive user prompt helps in exploring the capabilities and accuracy of various models and aids in finding the best model and the best settings for the use case in the application.
As AI becomes more ubiquitous in the enterprise, Red Hat is leading the way in unlocking the potential for AI to drive innovation, efficiency and value through its portfolio of consistent, trusted and comprehensive AI platforms for the hybrid cloud.
Podman AI Lab builds on the strength of Podman Desktop, an open source project founded at Red Hat which now has more than one m downloads. It also offers tight integration with image mode for Red Hat Enterprise Linux, a new deployment method for the world’s leading enterprise Linux platform that delivers the operating system as a container image. This integration enables developers to more easily go from prototyping and working with models on their laptop to turning the new AI-infused application into a portable, bootable container that can easily be run anywhere across the hybrid cloud, from bare metal to a cloud instance, using Red Hat OpenShift.
The cloud is hybrid. So is AI.
For more than 30 years, open source technologies have paired rapid innovation with greatly reduced IT costs and lowered barriers to innovation. Red Hat has been leading this charge for nearly as long, from delivering open enterprise Linux platforms with RHEL in the early 2000s to driving containers and Kubernetes as the foundation for open hybrid cloud and cloud-native computing with Red Hat OpenShift.
This drive continues with Red Hat powering AI/ML strategies across the open hybrid cloud, enabling AI workloads to run where data lives, whether in the datacenter, multiple public clouds or at the edge. More than just the workloads, Red Hat’s vision for AI brings model training and tuning down this same path to better address limitations around data sovereignty, compliance and operational integrity. The consistency delivered by Red Hat’s platforms across these environments, no matter where they run, is crucial in keeping AI innovation flowing. (Source: BUSINESS WIRE)
07 May 24. MITRE to Establish New AI Experimentation and Prototyping Capability for U.S. Government Agencies/ MITRE is building a new capability intended to give its artificial intelligence (AI) researchers and developers access to a massive increase in computing power. The new capability, MITRE Federal AI Sandbox, will provide better experimentation of next generation AI-enabled applications for the federal government. The Federal AI Sandbox is expected to be operational by year’s end and will be powered by an NVIDIA DGX SuperPOD™ that enables accelerated infrastructure scale and performance for AI enterprise work and machine learning.
As U.S. government agencies seek to apply AI across their operations, few have adequate access to supercomputers and the deep expertise required to operate the technology and test potential applications on secure infrastructure.
“The recent executive order on AI encourages federal agencies to reduce barriers for AI adoptions, but agencies often lack the computing environment necessary for experimentation and prototyping,” says Charles Clancy, MITRE, senior vice president and chief technology officer. “Our new Federal AI Sandbox will help level the playing field, making the high-quality compute power needed to train and test custom AI solutions available to any agency.”
MITRE will apply the Federal AI Sandbox to its work for federal agencies in areas including national security, healthcare, transportation, and climate. Agencies can gain access to the benefits of the Federal AI Sandbox through existing contracts with any of the six federally funded research and development centers MITRE operates.
Sandbox capabilities offer computing power to train cutting edge AI applications for government use including large language models (LLMs) and other generative AI tools. It can also be used to train multimodal perception systems that can understand and process information from multiple types of data at once such as images, audio, text, radar, and environmental or medical sensors, and reinforcement learning decision aids that learn by trial and error to help humans make better decisions.
“MITRE’s purchase of a DGX SuperPOD to assist the federal government in its development of AI initiatives will turbocharge the U.S. federal government’s efforts to leverage the power of AI,” says Anthony Robbins, vice president of public sector, NVIDIA. “AI has enormous potential to improve government services for citizens and solve big challenges, like transportation and cyber security.”
The NVIDIA DGX SuperPOD powering the sandbox is capable of an exaFLOP of performance to train and deploy custom LLMs and other AI solutions at scale. (Source: BUSINESS WIRE)
07 May 24. Global: New campaign highlights security, information theft risks from North Korean groups. On 2 May, several US government agencies revealed that the North Korean state-sponsored group ‘Kimsuky’ is exploiting weak email domain-based message authentication (DMARC) settings in a new, likely ongoing spear phishing campaign. The campaign starts with tailored phishing emails designed to trick high-value targets into opening malicious links or attachments. The group conducts extensive research on potential targets, impersonating individuals from trusted organisations, such as higher education institutions and think tanks, to bolster success rates. Kimsuky specifically targets organisations with unsuitable DMARC configurations to bypass anti-spoofing protections and successfully reach victims’ inboxes. Kimsuky’s capacity for substantial pre-campaign reconnaissance demonstrates the sustained security, information theft and phishing risks facing global organisations. North Korea continues to rely on cyber operations to gather strategic intelligence from perceived adversarial countries as it seeks to bolster its military and economic posture. As such, we assess further campaigns are likely in the long term. (Source: Sibylline)
07 May 24. Roke, a leading UK-based prime contractor and innovator in science and engineering, has today launched Roke Intelligence – a new business unit dedicated to redefining global standards in commercially outsourced professional intelligence. By integrating the expertise and tradecraft of intelligence professionals with cutting-edge technology – including AI, machine learning, advanced sensor technology, and data analytics – Roke Intelligence will empower clients with actionable insights, more informed decision-making, and a vital competitive advantage in a dynamic global risk environment. Roke Intelligence provides clients with tailored and customised intelligence solutions, meeting their unique requirements and providing them with access to a comprehensive suite of open-source intelligence capabilities. This gives these organisations the most robust and market-leading toolkit for faster and more accurate decision-making. At the head of the Roke Intelligence suite of capabilities is Geollect, a geospatial intelligence solution that is at the forefront of the outsourced professional intelligence revolution. Combining human expertise with advanced AI, machine learning and sensor technology, Geollect uncovers hidden patterns of activity and provides clients with the intelligence advantage they need to make informed decisions.
By blending multiple layers of data into one place and visualising the results, Geollect transforms the way organisations think, communicate, and strategise. With instant access to accurate real-time information and pinpoint location certainty, Geollect users know where, know first and know more.
Geollect joined the Roke family in January 2023, when it was acquired by Chemring Group PLC as part of Roke’s strategy to facilitate IP-led growth.
Paul MacGregor, Managing Director at Roke, said: “Roke has played a key role in supporting UK Defence and Security for over 65 years. Our clients face increasing levels of risk and uncertainty in today’s world, and we are delighted to be able to offer them this new capability; combining the best of our technology and tradecraft with the deep insights derived from our acquisition of Geollect.
“Roke Intelligence provides our clients with instant access to an evergreen, cutting edge capability that would traditionally only have been available to global intelligence agencies.”
Roke Intelligence offers four core capabilities:
o Geollect, Roke’s transformational solution providing state-of-the-art geospatial analytics and situational awareness.
o Centri, which leads the way in visualising and transforming geospatial data into action, providing a full data-to-intelligence solution.
o Infosight, our information operations platform that provides detailed knowledge and situational awareness about events in a defined environment.
o Intelligence Services, harnessing industry-leading intelligence tradecraft expertise, fused with cutting-edge technology, to deliver simple answers to the most complex questions.
07 May 24. USAF solicits AI-enabled battlefield C2 capabilities. The US Air Force’s (USAF’s) main research and development (R&D) directorate is soliciting industry solutions to accelerate the air service’s integration of artificial intelligence (AI) capabilities into its command-and-control (C2) and battle management systems. Officials from the Air Force Research Laboratory (AFRL) issued a broad agency announcement (BAA) in March, seeking industry input on “development and application of AI to C2, new concepts and techniques for the battle management, and orchestration of AI at pace and scale”. AFRL officials at the organisation’s Rome Research Site in Rome, New York, are seeking proposals to also explore “how the use of AI by adversaries can be considered in the C2 planning and execution process and distributed and collaborative C2 to enable C2 anywhere and anyplace”, the 24 March BAA noted. (Source: Janes)
06 May 24. Airborne Technologies announced the successful implementation of the Smith Myers ARTEMIS Mobile Phone Detection, Location & Communication system, in partnership with their local partner LIMA Aviation LLC in the UAE. This cutting-edge project involved the installation of the system into nine AW139 search and rescue helicopters belonging to a UAE government customer, with the first installation already completed. This project represents the collaboration between the teams of Airborne Technologies, LIMA Aviation and Smith Myers aimed at delivering innovative and reliable airborne surveillance solutions to UAE government customer.
Olga Martyshchenko, CEO of Lima Aviation, said: “We are thrilled to partner with Airborne Technologies on this exciting project to bring the Smith Myers ARTEMIS system to our esteemed UAE government customer. This strategic partnership marks a significant milestone in our commitment to excellence and innovation, as we continue to deliver state-of-the-art solutions that redefine industry highest standards of quality, reliability, and performance. The successful integration of the ARTEMIS system, renowned for its unparalleled capabilities in mobile phone detection, location, and communication, underscores our collective dedication to delivering innovative and advanced aviation solutions and technologies tailored to meet the evolving needs of our customers. Together, we are leveraging the power of ARTEMIS to optimize and elevate the search and rescue operational performance and efficiency for our UAE government customer.”
06 May 24. Military Academy launches centre for artificial intelligence excellence.
The South African Military Academy overlooking Saldanha Bay in the Western Cape has formally launched the Defence Artificial Intelligence Research Unit (DAIRU) as a centre of Artificial Intelligence (AI) excellence.
Artificial Intelligence is viewed as a critical component of the Fourth Industrial Revolution, capable of fundamentally shaping geopolitics and the conduct of warfare. Nations need to adopt AI technologies swiftly and effectively, as integration determines success in future conflicts.
In his keynote address at the ceremony held on Friday 3 May, Mondli Gungubele, Minister of Communications and Digital Technologies, remarked that the initiative is not just symbolic; it represents a strategic move towards leveraging AI for national development and security. He emphasised the transformative power of AI and its potential to revolutionise various sectors.
Gungubele said that AI is being rapidly adopted globally and has the potential to surpass human abilities. Artificial Intelligence crosses a broad spectrum, from Narrow AI, which excels in specific tasks, to General AI, which can outperform humans in intellectual tasks, and the theoretical realm of Artificial Super Intelligence (ASI).
The integration of AI into defence and military operations was emphasised, acknowledging the global trend towards AI-powered military applications and the need for proactive governance in this sphere. The establishment of the DAIRU positions the country as a leader in harnessing emerging technologies for global competitiveness and safeguarding national interests, guests at the ceremony heard.
“AI, akin to electricity or fossil fuels, has the potential to redefine modern militaries and reshape the global balance of power,” the Minister said.
Lieutenant General Michael Ramantswana, South African National Defence Force (SANDF) Chief of Staff, noted that the inauguration of the DAIRU marked a significant milestone for South Africa, reflecting the nation’s commitment to leveraging AI for military advancement and broader socio-economic growth.
The initiative is not only about bolstering military prowess but also about positioning South Africa as a leader in AI innovation on the continent and globally, attendees at the launch were told.
From radar development in World War II to the advent of GPS and the internet, the military has consistently embraced emerging technologies to gain a strategic advantage. The South African National Defence Force’s investment in AI research and development through DAIRU reflects a proactive approach to staying abreast of technological advancements.
“We do not just want to be consumers of the technology,” Ramantswana said. “The SANDF should also strive to innovate new artificial intelligence solutions.”
Collaboration with industry and academia is deemed essential for the success of the DAIRU, Ramantswana emphasised, enabling the SANDF to leverage expertise, share resources and accelerate progress in AI implementation.
“But make no mistake – success will require dedication and commitment. We must dedicate sufficient resources to this initiative to ensure that the SANDF and defence sector remain at the forefront of technological innovation in Africa and beyond,” he added.
Dr Moses Khanyile (Director: DAIRU) underscored the opportune timing of the event, aligning with the drafting of the African Union’s formulation of a Continental AI Strategy.
“The uneasy peace that has been in existence between the superpowers for the last seven decades is directly attributable to the possession of nuclear weapons,” Khanyile noted. “However, the discovery of artificial intelligence technology has ignited a new global digital arms race.”
This has far-reaching implications if left unregulated and he emphasised the imperative for oversight.
“As things stand,” Khanyile told the assembled dignitaries, “there is no consensus on the rules of the game, how AI should be regulated, both as dual-use technology and as an asset to humanity.” This sentiment encapsulates the urgency and complexity surrounding AI governance.
The SANDF has already established a cyber command within the Defence Intelligence Division and the Space Command Section within the South African Air Force and these capabilities need continuous flows of highly skilled AI practitioners, such as those produced by the DAIRU.
This includes research and development on AI capacity, strengthening the country’s cyber resilience, improving maritime and border security, combating illicit trade and trafficking and boosting the SANDF’s operational efficiency on and off the battlefield.
In modern warfare, AI can assist human decision-making processes by rapidly processing vast amounts of data from diverse sources. Specific applications include AI-driven drones, targeting systems and image analysis, which have already demonstrated their value in military operations. AI can also be leveraged to counter disinformation, enhance cybersecurity, and predict/prevent cyber-attacks.
Institutions like the South African AI Institute and military academies are pivotal players in preparing national defence forces for digital warfare.
The DAIRU seeks to achieve these objectives by, amongst others, utilising resources within the government, Stellenbosch University (the Military Academy houses the Faculty of Military Science) and the private sector. The establishment of the Defence AI Research Unit exemplifies a commitment to spearhead AI applications in defence within the African context. (Source: https://www.defenceweb.co.za/)
03 May 24. Cyber Update Key points.
- A cyber attack on local election infrastructure points to ongoing security and disruption risks facing election personnel and infrastructure (see Sibylline Cyber Daily Analytical Update – 29 April 2024).
- An uptick in cyber attacks via stolen third-party credentials demonstrates elevated security risks from the software supply chain (see Sibylline Cyber Daily Analytical Update – 30 April 2024 and our Technical analysis below).
- Sophisticated tactics by Chinese state-sponsored actors underscore heightened security and disruption risks facing global organisations (see Sibylline Cyber Daily Analytical Update – 1 May 2024 and our Technical analysis below).
- New campaign targeting non-profits, among other sectors, highlights sustained security, espionage, phishing risks from Iranian state-sponsored actor, ‘APT42’ (see Sibylline Cyber Daily Analytical Update – 2 May 2024).
- Data breach exposing sensitive customer information exacerbates security and financial risks from third-party services (see Sibylline Cyber Daily Analytical Update – 3 May 2024).
Technical analysis of weekly stories
A newly identified Chinese state-sponsored group, ‘Muddling Meerkat’, has been targeting global organisations since 2019. The group distinguishes itself from other known Chinese state-sponsored groups due to their unique ability to craft special domain name system (DNS) requests. The Great Firewall of China (GFW) typically restricts internet access by responding to these types of requests with randomised IP addresses, thereby blocking unauthorised websites. However, the group can bypass these restrictions by sending special requests for open mail exchanger (MX) records which obtain a response even when no mail service is configured. As a result, the group is able to build a potential victim pool to compromise for future malicious activities. Although the motivations behind the group’s activities are unclear, the intermittence of requests and type of activity are possibly in line with slow drip attacks, a type of distributed denial-of-service (DDoS). Additionally, the group blends in with normal network activities by scattering requests and limiting the amount of activity normally captured by logging. This allowed the group to achieve prolonged obfuscation, pointing to their sophistication and in-depth knowledge of modern IT and DNS systems.
There was a significant spike in credential stuffing attacks targeting customers of the authentication platform Okta reported between 19- 26 April. Threat actors attempted to compromise customers’ accounts by using a list of usernames and passwords likely obtained from previous unrelated data breaches and/or phishing and malware campaigns. Notably, all the recent attacks originated from anonymised sources such as The Onion Router (TOR) and other residential proxy services; the former conceals a user’s IP address while the latter routes traffic via third-party devices, thereby enabling the threat actors to remain undetected. This latest wave of attacks is possibly related to a recent surge in brute-force attacks targeting varying devices such as virtual private network (VPN) and Secure Shell (SSH) services. The threat actors’ use of anonymisation tools to remain undetected further indicates the continuous adaptation of actors’ tactics, techniques and procedures (TTPs).
Some non-exhaustive recommendations to mitigate against these threats include:
- Identify and eliminate DNS open resolvers as well as external domains for active directory or DNS search domains.
- Enforce strict security policies including regular software and password updates to prevent infections via leaked password credentials.
- Conduct cyber hygiene awareness courses for users to enable them to recognise and report phishing and other types of social engineering attempts.
- Monitor devices and networks for suspicious activity.
- Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network.
- Ensure adequate security detection measures are in place, particularly behaviour-based end-point detection and response (EDR) solutions.
Our cyber word of the week: Slow Drip Attack. (Source: Sibylline)
06 May 24. Anduril touts Pulsar jammers that rapidly adapt to changing threats. Anduril Industries pulled back the curtain on its line of portable, rapidly reprogrammable electronic warfare tools that the U.S. military has been quietly using around the globe.
The defense tech company on May 6 made public its Pulsar products, which it said are capable of countering drones, geolocating forces and neutering improvised explosive devices. The equipment comes in variants for fixed use, mounting aboard ground vehicles, and integration on aircraft. A version that can be slung onto troops’ backs is also being eyed.
Electronic warfare represents a battle over the electromagnetic spectrum, which militaries rely on to communicate, discern friend from foe and guide munitions to targets. Pentagon investment in sophisticated EW atrophied in the years following the Cold War, but fighting in Eastern Europe and the Greater Middle East reignited interest.
“There’s a realization that the United States military is not where it needs to be, in terms of operating in this kind of high-EW threat environment, and then having the types of agile capabilities to defend our forces and fight back offensively,” Chris Brose, Anduril’s chief strategy officer, told reporters at a briefing.
“We’re not going to go talk about ideas that we have, share glossy renderings of what they might look like in the world, and then go seek to build them and deliver them years later,” he added. “We tend to do the opposite.”
The Pulsar line has been in development since 2020 and was funded internally. It is software-defined, meaning updates can be dished out quickly and constraints imposed by hardware are lessened, and leans on advanced computing to retool for novel threats.
A war with Russia in Europe or China in the Indo-Pacific, for example, might introduce previously unseen technologies and electronic signatures. The time it takes to counter them could mean the difference between victory and defeat.
“Each system can process the data where it is, and then many systems that are networked together can learn from each other, just using small metadata,” said Sam El-Akkad, the general manager of radio frequency and EW systems at Anduril. “If one system sees something new, all the other systems are trained to see that new thing and recognize it in the future.”
While Anduril declined to specify where Pulsar has been used, deployment was described as happening across “multiple continents.”
The company in 2022 mentioned the EW equipment after winning a nearly $1 bn counter-unmanned aerial systems contract from U.S. Special Operations Command. A memo obtained by Defense News that same year described it helping to “mitigate incoming threats.”
“Pulsar is not just a figment of our imagination,” El-Akkad said. “At a high level, we’re in production of these systems, so we’re pumping them out and they are being used.” (Source: C4ISR & Networks)
—————————————————————————————————————————————————————————————————————————————————————————————————————————————
Spectra Group (UK) Ltd
Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.
Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.
With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.
Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.
In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.
Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.
Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.
————————————————————————————————————————————————————————————————————————————————————————————————————————————-

