• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • SPECTRA banner
  • Curtiss-Wright banner

BATTLESPACE Updates

   +44 (0)77689 54766
   

  • Home
  • Features
  • News Updates
  • Defence Engage
  • Company Directory
  • About
  • Contact

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

June 13, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

———————————————————————————————————————————————————————————————————————————————————————————————————————————————-

13 Jun 24. Spectra Group announces pre-production trials success of their next generation tactical radio system GENSS at Eurosatory 2024. Following the initial concept launch in January 2024, Spectra Group, a specialist provider of secure voice, data and satellite communications systems introduces their next generation tactical radio GENSS to European markets by announcing pre-production trials success.  Spectra Group will be discussing their new tactical radio system GENSS (pronounced genesis /jĕn′ĭ-sĭs), their award winning satcom SlingShot and the highly popular Troposcatter Family of Systems at Eurosatory in Paris from 17-21 June 2024 (Hall 5a Stand B156).

GENSS builds on the foundations created by their award-winning SlingShot system, embodying Spectra Group’s vision of producing ultimate radio systems that capitalize on technological advances, adapt to the evolving demands of military operations and simplify the user experience.  It has been designed and developed through a collaborative effort of tactical communication experts, seasoned military specialists and top-tier U.K. scientists and engineers.  GENSS is a significant advancement in the field of tactical radio communications, due to its modular core framework and software-defined flexibility, heralding a new era in communication technology.

Since January, Spectra Group have continued development of the GENSS platform at pace using initial working prototypes to prove key concepts.  At Eurosatory, Spectra Group are announcing the success of key concept capability prototype trials.  This month they have completed ‘over the air’ Beyond Line of Sight (BLOS) testing which has proved critical initial operating concept capabilities for the key planned modes of operation.  GENSS to SlingShot – standard UHF line of sight radios were connected to both SlingShot and GENSS devices and worked perfectly together, proving backward compatibility to maintain ultimate flexibility and interoperability.  LTAC TACSAT communications were achieved for GENSS as a stand-alone radio, transmitting simultaneous voice and data traffic over the same net.  Finally, Data Rebroadcast/Backhaul was proved, successfully establishing two ATAK Data MANET networks using a GENSS Bridge, connected through the Inmarsat L-TAC (satellite) BLOS service, thus delivering high data rate transmissions over strategic distances.

These trials validate the GENSS concept of delivering a single tactical radio capable of meeting the extensive secure data, voice, and application demands of modern military users.  GENSS is a modular, hardware-agnostic radio system designed and now proven to be exceptionally agile, providing ultimate interoperability through straightforward software reprogramming.  This allows it to adapt quickly and easily to diverse user needs.  Capable of operating across HF, VHF, UHF and satellite bands from 29Mhz to 6 GHz, GENSS overcomes BLOS barriers and supports Communications on the Move (COTM). It delivers a robust and agile solution for voice and high-bandwidth data transmission across all domains and platforms, whether on land, sea, or in the air.

Simon Davies, Chief Executive at Spectra Group, states, “GENSS represents the pinnacle of our development efforts, transforming complex communication needs into simple, effective solutions.  My vision has been to craft the ultimate radio system — user-friendly, light, modular and supremely flexible to adapt to the evolving demands of military operations and technological advances and GENSS is proving to deliver exactly that.  We are thrilled to introduce such a transformative tool to the European market at Eurosatory.”

 

14 Jun 24.  Thales and Google Cloud have signed a new partnership to deploy a global SOC (Security Operation Centre) platform and provide Thales customers with advanced cybersecurity incident detection and response capabilities.

  • These new-generation services combine Thales’s expertise in cyber detection and response with Google Cloud’s widely acclaimed intel-driven, AI-powered SecOps capabilities.
  • Under the new agreement, Thales and Google Cloud are combining their knowledge of the cyberthreat environment to offer a single platform, which is already operational in France, and will be available to international customers later this year, to round out Thales’s existing SOC offering.

Thales has teamed up with Google Cloud to expand its capacity to detect and respond to cyberattacks on the information systems of businesses and organisations.

Under the terms of this new partnership, Thales is developing a global SOC (Security Operation Centre) platform based on Google Cloud cybersecurity technologies and expertise, including Google Security Operations,VirusTotal and Mandiant Threat Intelligence, all powered by generative AI. It will leverage the existing network of eleven Thales SOCs, which are based on cloud or hybrid technologies and can be connected to on-premise environments. The agreement will benefit Thales’ customers by combining both partners’ expertise in cyberthreat analysis and drawing on the latest developments in AI technologies.

The new-generation SOC will provide organisations with enhanced protection against the most sophisticated cyberthreats:

  • Uncompromising system supervision: cost-effective data processing at Google cCloud speed and scale via an open platform to expand the scope of security monitoring;
  • Accurate, reliable cyberattack detection: advanced multi-source data analytics backed by the cyberthreat intelligence capabilities of two market leaders (Thales Cyber Threat Intelligence in Europe and Asia Pacific and Google’s Mandiant and VirusTotal threat intelligence resources);
  • Fast, efficient incident response: use of AI to quickly determine the impact of an attack and reduce incident response time to enable business continuity;
  • Permanent surveillance: 24/7 surveillance of IT and OT systems to guarantee immediate breach detection.

Pierre-Yves Jolivet, Vice President, Cyber Digital Solutions, Thales: “Thales is delighted to announce this partnership with Google Cloud, which will combine the latest cyber technologies and threat intelligence capabilities to provide customers with one of the most advanced suites of SOC services available in the market. In a world that is increasingly exposed to cyberattacks, this partnership will take Thales’s cyberthreat detection capabilities to the next level and provide faster, more efficient incident response solutions to ensure the resilience of its customers’ information systems.”

Sunil Potti, Vice President Cloud Security, Google Cloud: “This new extensive partnership with Thales is a confirmation of the relevance of our cloud security offering, combining our SecOps technology and threat analysis capacities, all supercharged with generative AI. Cybersecurity is not an individual sport and we are pleased to team up with Thales to further empower organisations around the world to better detect, investigate and respond to persistent threats.”

Thales and cybersecurity

As a global leader in cybersecurity, Thales is involved at every level of the cyber value chain: identification, protection, detection, response and recovery. Thales’s offering is focused on three families of cybersecurity products and services:

  1. Global security products around the CipherTrust data security platform, the SafeNet trusted Identity and Access Management (IAM) as-a-service solution, and the Group’s broader cloud protection and licensing offerings. Imperva’s products are part of this family.
  2. Sovereign protection products including encryptors and sensors to protect governmental and institutional critical information systems.
  3. A complete suite of cybersecurity services including threat and risk evaluation, training and simulation, detection and response, and integration projects. The Group’s 11 SOCs around the world provide 24/7 availability and include a number of SOCs with PRIS and PDIS certification by the French cybersecurity agency (ANSSI).

Thales has significantly increased its strategic focus on cybersecurity in recent years, expanding its geographic footprint and portfolio of products and capabilities through organic as well as external growth, including the acquisition of Imperva in 2023.

 

12 Jun 24. Global: Chinese-led operations will raise security risks facing Western government, defence entities. On 10 June, the Dutch authorities reported that an existing Chinese-led cyber espionage operation that was discovered in February was more extensive than they initially reported. In February, the Dutch authorities disclosed that Chinese threat actors exploited a vulnerability in Fortinet appliances (CVE-2022-42475) to install a backdoor, ‘COATHANGER’, onto Dutch Ministry of Defence systems. The backdoor is able to establish permanent persistence even when rebooted or given firmware updates. The report stated that Chinese threat actors gained access to over 20,000 vulnerable FortiGate systems in Western government and defence organisations between 2022 and 2023. They reportedly exploited the vulnerability for at least two months prior to Fortinet disclosing the zero-day, infecting 14,000 devices in that time. As a result, it is likely that the threat actors still have access to several systems due to COATHANGER’s ability to evade detection. As such, we assess that long-term espionage and security risks stemming from Chinese-backed operations will persist for Western government and defence entities in the long term. (Source: Sibylline)

 

11 Jun 24. Asia-Pacific: New backdoor points to elevated security, financial risks facing firms across region. Earlier on 11 June, the cyber security company Trend Micro reported that several Chinese threat actors are using a new remote access trojan (RAT), ‘NoodleRAT’, in cyber espionage and criminal operations. NoodleRAT is suspected to have been active since at least 2018; it also reportedly has Windows and Linux versions. This indicates the malware’s versatility and the threat actors’ ability to target multiple operating systems (which ultimately enlarges their potential victim pool). The malware shares similarities with other Chinese-made malware, including ‘Gh0stRAT’, which points to the likelihood that NoodleRAT is shared or offered for sale among Chinese-speaking threat groups. It exploits vulnerable public-facing applications for initial access, underscoring the security risks that misconfigured internet-facing applications can pose to firms. The RAT has been used as part of espionage operations in India, Japan, Malaysia, Taiwan and Thailand. NoodleRAT has also been employed in cryptocurrency theft operations, elevating the security and financial risks facing firms across the Asia-Pacific region. (Source: Sibylline)

 

10 Jun 24. Zambia-region: Cyber fraud convictions highlight organised cyber crime activity, exposure risks. On 7 June, a Zambian court convicted 22 Chinese nationals of operating an online fraud and money laundering syndicate. The syndicate was dismantled in April and operated call centres and numerous social media channels to defraud victims and make unauthorised withdrawals from thousands of SIM and bank accounts throughout Sub-Saharan Africa. Although petty cyber crime is extremely common in Zambia, the arrests highlight increasingly sophisticated cyber security threats from organised criminal groups with links to foreign entities. Although authorities will likely continue efforts to prosecute organised cyber criminal activity, low telecommunications infrastructure resilience throughout the region will likely undermine broader efforts to improve cyber security protections. As such, firms will continue to face elevated exposure to criminal activity, particularly entities relying on online banking and mobile money transfer services. Increasing organised cyber criminal activity will also increase threats of exposure to money laundering, elevating compliance concerns for firms in the financial sector. (Source: Sibylline)

 

07 Jun 24. NIST seeks innovators for UAS wireless data challenge. The United States National Institute of Standards and Technology (NIST) is seeking innovators for its First Responder Uncrewed Aerial Systems (UAS) Wireless Data Gatherer Challenge, also known as UAS 6.0.

As a first responder, the need to investigate accidents, as well as prepare for and adapt during a rescue, requires collecting various types of data about the potentially dangerous environment. In radio-complex outdoor environments, where communications infrastructure may be non-existent, UAS’ ability to collect information, via visual inspection and radio communication, from devices in the field, could be imperative to gaining situational awareness and deploying critical resources.

NIST is looking for applicable expertise across and beyond the UAS ecosystem who can contribute invaluable knowledge and ingenuity in artificial intelligence (AI), radio communications and mapping, Internet of Things (IoT), cybersecurity, and more.

Interested parties are invited to complete a research paper on relevant component technologies by July 26. A panel of SMEs and judges will review all eligible papers from which judges will select winners to receive prize awards. Prizes for this stage include cash prizes and those selected are encouraged to enter the second stage where capabilities will be measured with a view to progressing to scenario testing.

NIST says the challenge results will support the public safety community and its partners to improve real-time situational awareness and save lives while operating in potentially dangerous radio-complex outdoor environments without fixed communications infrastructure or satellite communications. (Source: www.unmannedairspace.info)

 

07 Jun 24. Global: Exploitation of existing vulnerabilities underscores security risks facing businesses. On 5 June, the security company Akamai reported that Chinese threat actors have been exploiting two patched vulnerabilities (CVE-2018-20062 and CVE-2019-9082) in the open-source application ‘ThinkPHP’ since April. The threat actors have exploited CVE-2018-20062 and CVE-2019-9082 to perform remote code execution on targeted systems. They have deployed the web shell ‘Dama’, which allows the actors to continue accessing infected systems remotely. Subsequently, they can perform port scanning, access existing databases and escalate privileges. This suggests that the operation is possibly an espionage-focused campaign. Patches for both vulnerabilities were released in late 2018 and early 2019, highlighting the long-term security risks emerging from lax patch-management policies. Additionally, we assess that this operation further emphasises the growing adoption of web shells to allow threat actors advanced control over victims’ systems. The threat actors reportedly deployed Dama against a wide range of targets, underscoring the ongoing security risks facing global organisations in the short-to-medium term. (Source: Sibylline)

 

07 Jun 24. Cyber Update Key points.

  • New malware targeting Brazilian bank users has underscored the elevated security and reputational risks facing financial institutions (see Sibylline Cyber Daily Analytical Update – 3 June 2024).
  • A new multi-pronged disinformation campaign has elevated the security, disinformation, disruption and reputational risks stemming from Russian state-sponsored actors ahead of the Paris 2024 Olympic Games (see Sibylline Cyber Daily Analytical Update – 4 June 2024).
  • A new phishing kit targeting customers from over 54 Europe-based financial institutions has heightened the security and reputational risks facing business operations (see Sibylline Cyber Daily Analytical Update – 5 June 2024 and our Technical analysis below).
  • A long-term multi-pronged campaign has underscored the espionage risks stemming from Chinese state-sponsored actors (see Sibylline Cyber Daily Analytical Update – 6 June 2024 and our Technical analysis below).
  • The exploitation by Chinese threat actors of existing vulnerabilities has underscored the security risks facing global businesses.

Technical analysis of weekly stories

A new phishing kit, ‘V3B’, is being sold to cyber criminals on the messaging platform Telegram as a phishing-as-service (PhaaS) model. V3B contains a sophisticated JavaScript that is typically distributed via social engineering techniques. The script distinguishes itself through its advanced features, including its ability to emulate local login and authentication techniques. The threat actors were able to create fraudulent QR codes, enabling them to access a victim’s account automatically in a QR code login jacking (QRLJacking) attack. Additionally, they demonstrated their knowledge of modern authentication methods by using a live chat function to interact with victims in real time and steal one-time passwords (OTPs) and other information to bypass authentication on local platforms such as PhotoTAN and SmartID. The kit also includes professionally translated pages in several European languages, highlighting its highly tailored nature. Notably, the kit also comprises multiple code obfuscation techniques and an advanced anti-bot system to prevent detection by security tools and to achieve prolonged persistence. V3B’s ability to emulate modern technologies combined with its various obfuscation and persistence techniques further underscores cyber criminal groups’ developing tactics, techniques and procedures (TTPs).

Several Chinese state-sponsored groups targeted an unnamed government agency in Southeast Asia in a long-term espionage campaign known as ‘Crimson Palace’. The campaign comprises three clusters of activity: ‘Cluster Alpha’, ‘Cluster Bravo’ and ‘Cluster Charlie’. The operations were primarily active between March and December 2023, though it is likely that the groups first obtained access in early 2022. Cluster Alpha focused on reconnaissance activities, including mapping server subnets and enumerating administrator accounts. The TTPs used in this phase of the operation also resemble those used by known Chinese-sponsored threat groups such as ‘BackdoorDiplomacy’, ‘REF5961’, ‘Worok’ and ‘TA428’. Cluster Bravo used legitimate accounts for lateral movement and deployed the malware ‘EthernalGh0st’ to maintain communication with actor-controlled servers and to exfiltrate credentials. Cluster Charlie notably attempted to collect and exfiltrate large volumes of sensitive information including documents concerning military, cyber security and economic interests in the South China Sea. It then deployed ‘PocoProxy’ to establish persistence and ‘HUI Loader’ to maintain control over the compromised system. While Cluster Bravo was likely associated with the group ‘Unfading Sea Haze’, Cluster Charlie is likely attributable to ‘APT41’.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Conduct cyber hygiene awareness courses for users to enable them to recognise and report phishing and other types of social engineering attempts.
  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network.
  • Enforce strict security policies including regular software and password updates to mitigate and prevent infections via leaked or stolen password credentials.
  • Ensure adequate security detection measures are in place, particularly behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.

Our cyber word(s) of the week: QR code login jacking (QRLJacking) attack

(Source: Sibylline)

———————————————————————————————————————————————————————————————————————————————————————————————————————————————

Spectra Group (UK) Ltd

 

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

 

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

————————————————————————————————————————————————————————————————————————————————————————————————————————————————-

Primary Sidebar

Advertisers

  • Pythia
  • Teledyne
  • Exensor
  • Visit the Oxley website
  • Blighter
  • SPECTRA
  • Britbots logo
  • Faun Trackway
  • Systematic
  • CISION logo
  • ProTEK logo
  • ProTEK logo
  • ssafa logo
  • IEE
  • EXFOR logo
  • sibylline logo
  • Team Thunder logo
  • Comtech logo
  • GoExporting logo
  • ECHODYNE logo
  • Supercat logo
  • Galvion logo
  • Leonardo DRS logo
  • MTC logo
  • IDC logo
  • DSEI logo
  • DVD2024 logo
  • SDSC logo
  • TELEDYNE FLIR logo
  • VeteranUK logo
  • Matrix Space logo
  • ST Engineering logo
  • EWS logo
  • sentinel photonics logo
  • capua logo
  • Curtiss-Wright logo
  • Brave1 logo
  • Drone Evolution logo
  • AEI Systems logo
  • EOS logo
  • NMSUK logo
  • Openworks logo
  • Sandown Park logo
Hilux UKDSE AARTOS ST Engineering Future Artillery

Contact Us

BATTLESPACE Publications
41 St Georges Drive
London SW1V 4DG

+44 (0)77689 54766

BATTLESPACE Technologies

An international defence electronics news service providing our readers with up to date developments in the defence electronics industry.

Recent News

  • Protek Selected By Dutch Armed Forces

    May 2, 2026
    Read more
  • PARLIAMENTARY QUESTIONS

    May 1, 2026
    Read more
  • MANAGEMENT ON THE MOVE

    May 1, 2026
    Read more

Copyright BATTLESPACE Publications © 2002–2026.

This website uses cookies to improve your experience. If you continue to use the website, we'll assume you're ok with this.   Read More  Accept
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT