Sponsored by Spectra Group
———————————————————————————————————————————————————————————————————————————————————————————————————————————-
30 May 24. SAIC Employees Embrace Generative AI with the Launch of Tenjin GPT. Science Applications International Corp. (NASDAQ: SAIC) today announced the launch of Tenjin GPT, a new internal, generative Artificial Intelligence (AI) resource available to employees that harnesses cutting-edge AI capabilities to automate and optimize business processes.
“Tenjin GPT is just one example of how SAIC is pushing the limits of technological innovation to provide employees with real-time insights and data analysis, as well as enhancing creativity and collaboration across our enterprise,” said Nathan Rogers, senior vice president and chief information officer at SAIC. “SAIC is accelerating the adoption and use of AI while also adhering to ethical AI governance values enforced by SAIC’s AI Council.”
Tenjin GPT, the latest feature of SAIC’s data science platform Tenjin, leverages the power of OpenAI’s GPT, which is the latest advancement in natural language processing. This state-of-the-art AI model enables users to develop highly sophisticated applications, automate repetitive tasks, streamline processes and gain valuable insights from vast amounts of data.
“By embracing generative AI technologies, SAIC is empowering our employees to upskill and improve productivity, while also reducing mundane tasks,” said Andy Henson, senior vice president of Digital Innovation at SAIC. “We help our customers harness data and AI to meet their mission needs every day, so it’s only natural for our employees to embrace this technology.”
Currently Tenjin GPT is being used internally at SAIC for summarizations of information, code generation, translation, research, content generation, and more, but it can also be integrated into customers’ existing infrastructure. Powered through Microsoft’s Azure AI, the robust framework ensures seamless integration and scalability. Additionally, Tenjin GPT aligns with SAIC’s and Microsoft Azure’s strong commitment to securing sensitive data, which is especially crucial for government teams. (Source: BUSINESS WIRE)
28 May 24. New Rapidly Deployable Hand Carried Internet Solutions.
Tekniam’s Remote Universal Communication System (RUCS) is a fast deploying, easy to hand carry device weighing 5lbs that throws a powerful broadband internet signal 3 miles.
Tekniam’s new Remote Universal Communication System (RUCS) is a fast deploying, easy to hand carry device weighing only 5lbs (2.27kgs) that throws a powerful broadband internet signal 3 miles (4.8km) with very low power draw.
The signal can be relayed between units up to 35 miles (56.3km) with up to a gig of throughput at a time.
This technology delivers what has become one of the single most important strategic advantages of modern warfare. Bandwidth.
The world is at a major inflection point in history where new network technology is dramatically shifting the balance of military power from offense to defense.
According to Tekniam, fighting this type of modern warfare requires bandwidth that the company’s RUCS delivers for the full spectrum of military capabilities.
RUCS is being used for military applications talking to drone swarms. The video feeds or sensory data the drones send back is then processed for analysis for target selection connecting unmanned reconnaissance with the shooters.
For special operations communications, the RUCS was designed to be lightweight and have high throughput up to a gig at a time. The RUCS is able to deliver a large amount of power with a low power draw.
Tekniam’s RUCS delivers bandwidth to the battlefield in a way that is dramatically shifting the balance of military power from offense to defense. A low cost, easily hand carried device that formerly required heavy equipment towed on a trailer with a generator and gasoline to achieve only a fraction of the network power of Tekniam’s new RUCS. (Source: https://www.defenseadvancement.com/)
30 May 24. Mobile Battlefield Capabilities Demonstrated for Canadian Armed Forces. The field exercise, HERMES FORGE, showcased the speed, resilience, and reliability of Ultra Intelligence & Communications (Ultra I&C) mobile command post solutions. Ultra Intelligence & Communications (Ultra I&C) has demonstrated its capabilities across multiple tactical bearers during a field exercise with the Canadian Armed Forces.
The exercise, HERMES FORGE, is designed to assess the modernization progress of its tactical network architecture.
As the proliferation of UAVs and the prevalence of long-range precision fires threaten traditional command post operations, the Canadian military has engaged select industry partners, including Ultra I&C, to develop resilient communications solutions that will meet new mobility requirements. After two years of collaboration with the Canadian Armed Forces, this culminating exercise showcased the speed, resilience, and reliability of Ultra I&C’s mobile command post solutions.
Faith Rhodes, Vice President of programs for Ultra I&C’s Communications division, said; “Ultra I&C’s participation in HERMES FORGE allowed us to showcase our technologies currently deployed within NATO countries.
“By validating these technologies during the exercise, we underscored our role as the proven partner to provide interoperable capabilities in the field in Europe and truly enable expeditionary missions with our coalition partners.”
Keith Blanchet, vice president of business development for Ultra I&Cs’ Communications division, added; “Ultra I&C has a unique expertise and advantage fielding SATCOM, LOS, and troposcatter communication bearers in an integrated fashion that provides the diversity of communications options our soldiers need to be successful.
“This enables network resilience and eases the burden of having to understand and operate disparate systems and tools, making it easy to set up and operate.”
Central to the successful demonstration was Ultra I&C’s latest generation of quick deploy vehicular-mast-mounted line-of-sight systems, critical for on-the-move-missions. In Dispersed Command Posts (DCPs), Ultra I&C’s small SWaP Orion X510 was shown to be interoperable with the existing X500 Upper Tactical Network backhaul waveforms as well as with the existing Trellisware waveform (TSM). The new Orion X630 radio was deployed on a Vertical Height Antenna system to allow highly mobile DCPs to reach back to a rear headquartered Orion X500 radio, while simultaneously extending the range of the Brigade TSM network. The deployment of Ultra I&C’s extra-light VSAT SATCOM terminal was also evaluated as an alternative bearer to Orion LOS for maintaining robust communications between rear HQ and DCPs at the tactical edge.
The initial soldier touchpoints and user engagement that took place during the HERMES FORGE exercise will inform the Canadian Armed Forces’ consideration to leverage Ultra I&C’s solutions for deployment into Latvia to enhance on-the-move mission tactical
(Source: https://www.defenseadvancement.com/)
29 May 24. FCAS AI-Backbone is operational. The Future Combat Air System AI Backbone has become operational, with 50 pilots and ten organisations using the system. The AI-backbone of the Future Combat Air System (FCAS) has been made operational, with more than 50 pilots from ten organisations now using the cross-sectional platform, according to a release from Rohde-Scwarzh, one half of the HIS consortium developing the technology, on 29 May 2024.
The AI-backbone was provided by Helsing and Schönhofer Sales and Engineering (a subsidiary of Rohde & Schwarz) just nine months after the contract start in 2023.
According to the release from Rohde-Schwartz, the AI-Backbone offers improvements over the current standards, by introducing standardised procedures across organisations in the military sector and reducing fragmented processes with numerous interfaces.
This centralised platform is also intended to ensure data security and sovereignty for every user and increase flexibility and efficiency across the MiLOps workflow.
“The use of AI will be critical to FCAS air superiority. AI accelerates the evaluation of sensor data, the planning of missions and the use of effectors,” explains Frank Schrudde, managing director of Schönhofer Sales and Engineering. “As an innovative, long-standing partner of the Bundeswehr, we bring vigour to the research landscape. We are proud to have brought the agility of a medium-sized company to the project in collaboration with our partners. We were able to deploy the first demonstrator in an extremely short time of nine months.”
“With the first release, an important milestone in the implementation of the AI-backbone has been reached,” says Stephanie Lingemann, program director and head of the air domain at Helsing. “We are proud to have advanced the AI-backbone from the initial idea to implementation. The development of AI is now being supported in the ongoing phase of the national R&T projects and a decisive cross-sectional contribution is being made to enabling the NGWS.”
The next stage of development will be part of the second release, expected in November 2024. Rhode-Schwarz intend this update to enable standardised, collaborative AI workflows in highly sensitive environments, and to add additional capability components. (Source: airforce-technology.com)
29 May 24. Global: Custom ransomware will sustain elevated security, financial risks from North Korean actors. On 28 May, the technology company Microsoft revealed that the North Korean group ‘Moonstone Sleet’ (formerly tracked as ‘Storm-17’) has started deploying ransomware against software development companies and the defence sector. The group typically uses known tactics associated with North Korean actors and has been deploying new custom ransomware (‘FakePenny’) since April. This points to the group’s involvement in financially motivated operations alongside espionage campaigns. Additionally, the group has created several fake technology companies to trick victims into downloading malicious payloads, highlighting a shift in its tactics, techniques and procedures (TTPs) and the expansion of its operations. North Korean groups often conduct financially motivated attacks alongside espionage operations to finance Pyongyang’s missile and weapons programmes amid international economic sanctions. As such, we assess that the evolution of Moonstone Sleet’s TTPs will sustain elevated security and financial risks for the technology and defence sectors. (Source: Sibylline)
23 May 24. Cyber Update Key points.
- The resumption of the ‘Grandoreiro’ malware operation points to elevated financial and reputational risks facing the financial sector (see Sibylline Cyber Daily Analytical Update – 20 May 2024).
- Destructive operations conducted by Iranian state-sponsored actors have elevated the operational and security risks facing Israel-based organisations (see Sibylline Cyber Daily Analytical Update – 21 May 2024 and our Technical analysis below).
- A sophisticated crypto-mining campaign is disabling security protections, elevating cryptocurrency-theft and security risks for firms (see Sibylline Cyber Daily Analytical Update – 22 May 2024 and our Technical analysis below).
- A new suspected Chinese-affiliated group, ‘Unfading Sea Haze’, is targeting countries in the South China Sea region, underscoring elevated security and espionage risks therein (see Sibylline Cyber Daily Analytical Update – 23 May 2024).
- The recent surge in hacktivist attacks targeting the upcoming Indian general election has elevated information-theft, disruption and disinformation risks (see Sibylline Cyber Daily Analytical Update – 24 May 2024).
Technical analysis of weekly stories
The Iranian state-sponsored group ‘Void Manticore’ has targeted Israel-based organisations in several destructive attacks since October 2023. The group notably co-operates with another Iranian-sponsored threat group, ‘Scarred Manticore’, which provides Void Manticore with initial access to targeted systems. Void Manticore’s arsenal includes a highly sophisticated version of the ‘BiBi’ wiper, which has the ability to delete key functions from a system’s partition memory. This allows the group to inhibit data restoration, thereby amplifying the impact of its attacks. Additionally, the group often manually deletes data via legitimate utilities such as Windows Explorer, further highlighting its focus on quick and highly impactful and destructive attacks. The co-operation between Void Manticore and Scarred Manticore has also revealed a high degree of co-ordination, which points to the operation’s longevity ( as well as a consistent level of planning). Void Manticore has claimed attacks on over 40 Israeli organisations under the guise of the online hacktivist group ‘Karma’; its use of online personas underscores the multi-pronged nature of this campaign, which weaponises political tensions while also wiping data and causing operational disruption.
A new highly sophisticated crypto-mining campaign, ‘REF4578’, has compromised servers in China, Germany, Hong Kong, Japan, the Netherlands, South Africa, Sweden and the US to garner illicit profit. Although the initial attack vector remains unclear, the campaign starts with the deployment of a PowerShell script hidden in a PNG image; this establishes communication with actor-controlled servers and retrieves additional executables, including the malware ‘GhostEngine’. Notably, this payload has the ability to deactivate security processes, such as Microsoft Defender Antivirus and endpoint detection and response (EDR) tools, to achieve prolonged detection evasion. Additionally, the initial script downloads a dynamic link library (DLL) service to create system persistence; it also downloads any updates from the actor-controlled infrastructure. GhostEngine finally deploys the ‘XMRig’ crypto-mining malware, potentially allowing threat actors to garner illicit profit. This campaign contains highly complex anti-detection and persistence mechanisms, highlighting the high sophistication and continuous development of actors’ tactics, techniques and procedures (TTPs).
Some non-exhaustive recommendations to mitigate against these threats include:
- Apply patches to software vulnerabilities as soon as they are released to prevent exploitation.
- Enforce strict and timely patch management policies and ensure adequate software configuration.
- Monitor devices and networks for suspicious activity.
- Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network.
- Ensure adequate security detection measures are in place, particularly behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
(Source: Sibylline)
—————————————————————————————————————————————————————————————————————————————————————————————————————————————
Spectra Group (UK) Ltd
Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.
Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.
With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.
Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.
In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.
Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.
Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.
—————————————————————————————————————————————————————————————————————————————————————————————————————————————–

