Sponsored by Spectra Group
————————————————————————————————————————————————————————————————————————————————————————————————————————————–
15 Aug 24. The members of the research and business consortium led by Bittium Wireless Ltd, a subsidiary of Bittium Corporation, have signed a framework agreement as part of the indirect industrial cooperation program related to the procurement of F-35 fighter jets with manufacturer Lockheed Martin. In the three-year project, the members of the consortium and Lockheed Martin will jointly develop methods and capabilities for cyber situational awareness. The other members of the Bittium-led consortium are VTT Technical Research Centre of Finland Ltd and Huld Oy, which offers technological solutions for the space industry, among other things. The agreement applies to the years 2024–2026 and its total value is approximately USD 3.8 m distributed among the consortium member companies in proportion to the amount of work done.
The goal of the project is to develop cyber capabilities for constantly changing defense and security. One example of this is developing the ability to observe and identify different phenomena, which affects cyber resilience of the tactical network and the creation of situational awareness. The project will be used to develop the survivability of Bittium’s Tactical Wireless IP Network™ (TAC WIN) and Bittium Tough SDR™ radios. The Finnish Defence Forces will also benefit from the cooperation, as the performance of the products they use will be improved with the help of new functionalities.
“The new development project continues the successfully started cooperation between the consortium and Lockheed Martin. This development project focusing on cyber security of tactical networks further strengthens the cyber resilience of our tactical communications systems to meet the demanding requirements of the battlefield,” says Tommi Kangas, Senior Vice President, Defense & Security Business Segment.
Through indirect industrial cooperation projects, Lockheed Martin builds industry partnerships with indigenous companies, which offer opportunities to develop and promote global cooperation far into the future.
14 Aug 24. Ultra Intelligence & Communications successfully participated in the NATO-led Coalition Warrior Interoperability Exploration, Experimentation, Examination Exercise (CWIX) in Bydgoszcz, Poland. The exercise provides bilateral technical testing and testing of fielded, developmental and experimental systems in the context of a coalition scenario.
As part of the Marine Corps Forces Europe and Africa (MARFOREUR) team, Ultra I&C deployed its ADSI® system in a joint coalition environment. The deployment demonstrated key accomplishments through tactical data link compliance, Curser on Target (CoT) integration, CoT to Joint Range Extension Applications Protocol (JREAP-C) translation, JREAP-C forwarding and digital warfighting platform demonstration.
“By rapidly configuring TDL interfaces to multiple nations on the fly, ADSI demonstrated how it enables seamless forwarding and interoperability across coalition C2 systems and helps pave the way to meet CJADC2 goals for the U.S. and its partners,” said Bradford Powell, president of Ultra I&C’s C2IE division. “We remain committed to enhancing mission effectiveness and operational efficiency across multi-domain operations.”
Ultra I&C will begin incorporating feedback from the exercise as it continues to participate in future exercises with the U.S. Marine Corps and partners, furthering its commitment to continuous improvement and partnership.
“The responsiveness and partnership demonstrated by Ultra I&C were instrumental in achieving the objectives of CWIX and was imperative to achieving new milestones compared to previous exercises,” said MSgt. Larry Morales, operations and plans chief with MARFOR Europe and Africa. “The team’s ability to adapt quickly to our evolving requirements and provide real-time solutions significantly contributed to the overall success of the exercise. This collaboration exemplifies the kind of industry partnership that enhances our coalition interoperability efforts.”
As a collaborative Cooperative Research and Development Agreement (CRADA) partner with U.S. Marine Corps Tactical Systems Support Activity (MCTSSA), Ultra I&C is integral to the efforts dedicated to perfecting interoperability between NATO members and partner nations.
“Deployment of Ultra Intelligence & Communications products enabled successful demonstrations of service, joint, and mission partner capabilities,” said Thomas Johnson, senior principal engineer, USMC MCTSSA. “Their participation enabled demonstration of significant advancements in our data transfer and interoperability capabilities with NATO partners, representing a substantial improvement in our operational effectiveness.”
ADSI, the premiere Command and Control (C2) gateway, ensures seamless interoperability and enhanced mission effectiveness with best-in-class datalink translation and the largest number of datalinks and interfaces available in a single library. Integrated in over 35 countries at 2,500 sites around the globe, ADSI’s flexible design provides a common operating picture to coalition C2 systems. (Source: PR Newswire)
14 Aug 24. Global: China-backed actor expands operations, heightening espionage risks to global firms. On 14 August, international media sites reported that China-backed cyber actor ‘Earth Baku’ expanded its activities outside the Indo-Pacific region to include Africa, Europe, and the Middle East in 2022. In the group’s more recent operations, Earth Baku exploited vulnerable public-facing applications (such as Microsoft IIS servers) as initial attack vectors to deliver malware. The actors use new loader malware and a new backdoor, pointing to the group’s evolution and growing maturity. The group targeted Georgia, Germany, Italy, Qatar, Romania and the UAE, focusing on the education, healthcare, government, media and communications, technology and telecommunications sectors. Consequently, we assess the presence of elevated security and espionage risks. As Earth Baku is linked to the Chinese government, operations will likely continue against global targets in the long term as Beijing seeks to bolster its security and economic posture. (Source: Sibylline)
13 Aug 24. Soteria and Panther Enter into Strategic Partnership to Defend Clients from Cyber Threats. Soteria’s dedicated cybersecurity expertise combined with Panther’s cloud-native security platform provide organizations worldwide with 24×7 cybersecurity coverage.
Soteria, a leading cybersecurity services company, today announced a strategic partnership for its Managed Detection and Response line of business, partnering with next generation Security Information Event Management (SIEM) provider Panther.
Panther is a cloud-native SIEM that accelerates threat detection, response, and investigations to make security teams smarter and faster than adversaries. Soteria customers can now leverage the next generation capabilities of the Panther platform while offloading time and resource intensive security tasks to the cybersecurity expertise of Soteria’s Detection and Response Team.
“Soteria Defense Managed Detection and Response services protect organizations across the globe. Together, Soteria and Panther provide an easy path for customers to use their security data to take decisive action and reduce their cyber risk, 24 hours a day. Panther allows us to deliver a Managed SIEM solution in a way that aligns with our security values, and we are very excited to bring this to market,” said Paul Ihme, Co-Founder & Managing Principal at Soteria. “This partnership levels up our capabilities and in turn, our ability to deliver our mission– providing safe passage for our clients so they can remain focused on delivering their missions.”
Soteria is dedicated to improving cybersecurity outcomes, preventing cyber incidents before they happen, and providing organizations with business-critical cybersecurity services. Soteria Defense MDR is a leading cybersecurity monitoring and response service that defends clients from cyber-attack, spanning endpoints, cloud platforms, identity providers, and more.
Panther’s next-generation, cloud native SIEM platform delivers code-driven detection and response at petabyte scale without the overhead or cost of traditional SIEMs. Detections-as-code lets security teams code, test, and deploy detection rules in Python, using CI/CD for streamlined collaboration and enhanced reliability. This approach to detection engineering aligns directly with the approach and philosophy Soteria has helped pioneer.
Now businesses can prioritize the areas that matter most for their mission, using Panther as a cost-effective basis of their security program, and Soteria’s Managed Detection and Response service for 24×7 coverage with real-time response to cyberthreats.
“Panther welcomes Soteria into the strategic partnership family, where our combined efforts will help customers globally adopt our partnered solutions,” said Andrew Dooley, Head of Partnerships at Panther.
“Since day one, Soteria’s services capabilities, detection-as-code approach, and exceptional cybersecurity focus stood out as an ideal fit for our clients. We could not be happier to partner with Soteria and bring our enhanced capabilities to the wider market. The result is increased security coverage, reduced cyber risk, and clients avoiding the budget-busting that generally takes place with legacy SIEMs. Paul and the team at Soteria are champions of detection-as-code, and their approach to MDR is ideal for Panther and our customers.”
Panther’s mission is to make security monitoring fast, flexible, and scalable for all security teams. They are leading the evolution of security operations, helping security teams overcome the challenges of detection and response at scale.
Learn more about Soteria Defense Managed SIEM at its page on the Soteria website.
About Soteria
Soteria’s leadership and security professionals have held leading positions in private industries, state governments, and federal intelligence communities, having defended thousands of client environments and shaping deep expertise in cybersecurity. With this combination of technical expertise and industry-specific insight, Soteria provides tailored cybersecurity services spanning pre-breach consulting, incident response, and managed security services.
(Source: BUSINESS WIRE)
13 Aug 24. The MCS Group Announces RelativityOne Government Offering to Expand eDiscovery Solutions. The MCS Group, Inc., a leader in outsourcing solutions including eDiscovery, records retrieval, and management services, today announced it is expanding its offerings with the addition of Relativity’s FedRAMP-authorized, cloud-based eDiscovery solution for government agencies, RelativityOne Government. With RelativityOne Government, The MCS Group will be able to offer all the tools needed to handle FOIA requests, litigation, and investigations – from legal hold through production.
The MCS Group will leverage its existing workflows and eDiscovery expertise on RelativityOne Government to assist government entities with managing growing data volumes, sources, and types, and provide them with access to the same cutting-edge solutions available to private entities. With the release of Relativity aiR, government clients will have access to state-of-the-art generative AI tools and customizable workflows designed to empower government experts and reduce overall legal spend in discovery preparation.
Beyond traditional eDiscovery, The MCS Group excels developing customized solutions using Relativity’s existing architecture to solve complex problems for its customers. These customized solutions create new efficiencies for clients, allowing them to work confidently knowing their data is hosted entirely within a FedRAMP-certified environment.
With the secure and powerful RelativityOne Government product, The MCS Group will be able to further leverage its eDiscovery expertise to provide more value and better results for its public sector clients. RelativityOne Government is FedRAMP-authorized software secure from the ground up with proactive threat intelligence and 24/7 monitoring.
“We are excited to expand into the Government space with our eDiscovery solutions,” said Stephen Ehrlich, CIO of The MCS Group. “Our ability to assist clients at all levels with their eDiscovery workflows, data management and technology will be of great benefit to government entities, especially within the secure confines of RelativityOne Government.”
“The MCS Group continues to demonstrate their dedication to serving the varying technological needs of their clients with the addition of the RelativityOne Government solution to their vast range of offerings,” said Laurie Usewicz, Chief Partner Officer at Relativity. “We look forward to further supporting government agencies and organizations alongside MCS Group by providing tools to meet users’ growing data challenges.”
RelativityOne Government is the only cloud-native eDiscovery platform built in Microsoft Azure Government, empowering users to work confidently knowing their data will never leave the Azure cloud. With responsible AI built in directly to RelativityOne Government, The MCS Group’s customers spend less time waiting and more time doing, with automated workflows eliminating the most repetitive tasks and reducing the chance of human error. In 2023, on average, RelativityOne Government customers saved approximately over 1,200 hours across automated workflows.
For more about The MCS Group’s work within the government sector, visit https://www.relativity.com/partners/themcsgroup/. To learn more about RelativityOne Government, a FedRAMP authorized SaaS solution that tackles the diverse challenges of litigation, investigations and FOIA requests for government agencies, visit https://relativity.com/data-solutions/government-agencies/.
About The MCS Group: Founded in 1979 in Philadelphia, Pennsylvania, The MCS Group is a privately held company certified by the Women’s Business Enterprise National Council (WBENC). Our mission is to deliver custom, efficient, and cost-effective legal support solutions. With over 100TB of data under management and an average of 20+ years of experience in eDiscovery, MCS offers a suite of eDiscovery tools and services that clients can rely on to solve difficult challenges and control costs. For more information, please visit www.themcsgroup.com.
About Relativity
Relativity makes software to help users organize data, discover the truth and act on it. Its SaaS product, RelativityOne, manages large volumes of data and quickly identifies key issues during litigation and internal investigations. Relativity has more than 300,000 users in approximately 40 countries serving thousands of organizations globally primarily in legal, financial services and government sectors, including the U.S. Department of Justice and 198 of the Am Law 200. Please contact Relativity at or visit www.relativity.com for more information. (Source: BUSINESS WIRE)
13 Aug 24. Pacific Defense Announces US Army CMFF Program Team. Defense, a leading provider of Modular Open Systems Approach (MOSA) products and mission solutions, announced their team to compete for the U.S. Army’s CMOSS Mounted Form Factor (CMFF) program. Led by Pacific Defense, the CMFF team includes state-of-the-art industry technology leaders Thales Defense & Security Inc., BAE, Regal Technology Partners, Palantir and STC, an Arcfield Company.
“Our company is purpose-built to drive the open-systems change the Army needs to take advantage of the commercial technology base and keep pace with the evolving threat,” said Travis Slocumb, CEO of Pacific Defense. “One hundred percent of what we do is modular, open system architecture. That, combined with this carefully curated team, will allow the Army to unlock mission systems’ technical baseline and enable rapid, recurring and affordable innovation.”
The Pacific Defense CMFF team’s layered standards will make it simpler, faster and much less expensive to rapidly introduce new capabilities and commercial technology. The standards will also reduce complex integration challenges, eliminate proprietary interfaces and enable greater competition and reuse. Pacific Defense’s CMFF team brings essential capabilities to address program requirements including ground and aviation platform design and integration, multi-waveform communications, Type 1 cryptographic implementation, model-based systems engineering (MBSE), and production at scale.
Pacific Defense is a leader in advancing integrated, open mission systems (C5ISR/EW Modular Open Suite of Standards and Sensor Open Systems Architecture) for U.S. customers and Five Eyes Alliance countries. The company has invested more than $100m in its MOSA product base – both hardware and software – and has extensive integration experience, including third-party content. (Source: BUSINESS WIRE)
13 Aug 24. Australia establishes Cyber Command. The Australian Defence Force (ADF) has established a new command focused on cyber within its Joint Capabilities Group (JCG).
This new command is expected to reinforce the ADF’s efforts to enhance its capabilities in cyberspace and the electromagnetic spectrum, the Australian Department of Defence (DoD) said on 9 August.
The cyber domain also plays a critical role in enabling forces to have an edge in cognitive and information warfare, the DoD added.
“Establishing a Cyber Command ensures [the DoD] meets the government’s direction to enhance our cyber capabilities and enable an integrated, focused force requirement,” Lieutenant General Susan Coyle, Chief of JCG, said.
The DoD said that with the establishment of Cyber Command, the Cyber Force Generation branch has evolved into Cyber Forces Group, a command entity. The ADF’s Joint Cyber Unit, Fleet Cyber Unit, 138 Signal Squadron, 462 Squadron, and 1st Joint Public Affairs Unit have been moved into Cyber Forces Group.
Transferring all cyber-warfare units into Cyber Command will help integrate soldiers skilled and trained in cyber warfare from all services of the ADF, along with public servants and personnel from industry partners, and enable a more centralised and co-ordinated management of this workforce, the DoD added.
The DoD said the Joint Survivability Tactics Validation Unit has also been transferred from the Royal Australian Air Force (RAAF) to the JCG’s Joint Capabilities Division to consolidate all operations associated with the cyber domain within the JCG.
The DoD also plans to create a Joint Data Network Unit in the future to support Cyber Command. (Source: Janes)
13 Aug 24. South Korea: Strategic military data will likely remain key target in espionage operations. On 11 August, South Korea’s government stated that North Korean threat actors had stolen critical information regarding South Korean military assets. The press release reported that cyber operations targeted technical data related to aerial reconnaissance planes. Any such operations are likely to have involved North Korean cyber actors exfiltrating sensitive data in a bid to compete with South Korea’s military arsenal. Similarly, data related to South Korea’s main battle tank was reportedly exported abroad illicitly after engineers from a South Korean parts manufacturer moved to a competing organisation, taking with them external storage drives containing sensitive information regarding the tank’s overpressure systems. Whether the reported exfiltration was the result of negligence or malicious intent, the incident highlights the security and operational risks associated with third-party vendors’ access to strategic data. As tensions in the Korean peninsula continue to fester, we assess that the military sector will remain a key target during espionage operations in the long term. (Source: Sibylline)
09 Aug 24. i2 increases investment in intelligence analysis software to strengthen agencies’ pursuit of ‘bad actors.’ Today, i2 Group said increasing demand for its intelligence analytics software among NATO forces and intelligence and law enforcement agencies was driving the company’s double-digit growth.
The global leader in visual data analysis today reported an annual 18% uptick in software license sales and 10% workforce growth as it launched a refreshed brand and new website to showcase its pioneering tech. The company said it was committed to supporting its customers and the wider market with continued investment in its products.
Acquired by Constellation Software subsidiary Harris Group from IBM in 2022, the UK and US-based company has since grown its client list, updating its product portfolio to meet the ever-evolving risks landscape for national and international organizations tackling the world’s ‘bad actors’.
Mission-critical tools such as the i2 Analyst’s Notebook are now helping more agencies and governments to analyze complex datasets, ‘join the dots’ and make data-driven decisions to combat terrorism, serious crime, espionage, insurgency, human trafficking and much more.
The World Economic Forum’s 2024 Global Risks Report identified interstate violence, illicit economic activity, terrorist attacks and cyber insecurity as key risks. The backdrop is behind the high demand for increasingly sophisticated software that can uncover hidden connections in disparate data ‘to stay two steps ahead’, said i2.
The company’s refreshed brand and new website reflect its unstinting commitment to delivering innovative solutions to the many global threats we now face, said i2 Executive Vice-President Jamie Caffrey.
Caffrey added: “We live in an increasingly volatile, uncertain and complicated world. Agencies need i2 solutions to make data-driven decisions about the biggest threats we now face. After a period of strong growth and development, we’re confident in our ability to deliver exactly what agencies need.”
For more information about i2, visit https://i2group.com.
About i2
i2 Group is the global leader in advanced visual analysis solutions, with a presence in more than 140 countries. Its innovations empower analysts and investigators to discover, create, and disseminate actionable intelligence to combat threats, such as serious crime, terrorism, war and fraud. These pioneering solutions are relied upon by thousands of organizations in global, international, national and local operations.
(Source: PR Newswire)
09 Aug 24. Global: Increased use of legitimate cloud services in cyber activity points to raised espionage risks. On 7 August, the cyber security company Symantec reported that the exploitation of legitimate cloud services in cyber operations has increased substantially since mid-July 2023. More threat actors are leveraging legitimate cloud services in attacks (including Microsoft OneDrive and Google Drive) to obfuscate malicious traffic. In July, Symantec observed three cyber espionage operations using legitimate services to host malware or actor-controlled command-and-control (C2) servers. For example, Microsoft Graph was employed by the state-backed group ‘Harvester’ to install a new backdoor against media organisations in South Asia in November 2023. Similarly, another backdoor was deployed against entities in Hong Kong, Taiwan and Vietnam in April using a C2 server hosted on Microsoft OneDrive. These incidents highlight threat actors’ growing exploitation of the trust associated with legitimate cloud service providers to feign legitimacy and obfuscate malicious activity to ensure successful operations. As such, we assess that this points to elevated espionage risks for global entities in the long term. (Source: Sibylline)
09 Aug 24. Cyber Update Key points.
- A cyber operation compromised an unnamed internet service provider (ISP), elevating espionage and supply chain risks from the Chinese state-sponsored group ‘Evasive Panda’.
- Cyber attacks on South Korea’s machinery and construction sectors have underscored the espionage risks stemming from North-Korean state-sponsored groups.
- A ransomware attack targeted the Grand Palais in Paris (France), sustaining operational risks to the Paris 2024 Olympic Games.
- A new worm compromising high-value targets in Russia will sustain information-theft and disruption risks for firms.
- The increased use of legitimate cloud services to obfuscate malicious traffic points to elevated espionage risks facing global entities.
Technical analysis of weekly stories
A new worm, ‘CMoon’, has compromised high-value targets in Russia as part of an information-theft campaign since early July. The unnamed threat actors replaced legitimate document links on a gas company website with a malicious executable to distribute CMoon to targeted entities. Upon initial infection, CMoon searches for the presence of native antivirus security tools, copying itself into a new folder and emulating the legitimate service. It then changes the creation date of the new folder to 22 May 2013 to prolong obfuscation on compromised systems. Notably, the worm ensures it runs on system startup, thereby establishing persistence and allowing itself space to operate without the need for user input. Subsequently, CMoon monitors connected USB drives alongside other removable media to steal information and simultaneously propagate the infection. The worm collects files from specific locations containing saved passwords, cookies, bookmarks, browsing history and data for auto filling forms such as credit card data. Additionally, CMoon communicates with actor-controlled infrastructure to download and execute additional malicious files, as well as to take screenshots, initiate distributed denial-of-service (DDoS) attacks, collect information about available resources and send stolen files to a remote server. We assess that the malware’s numerous obfuscation techniques and varied functionality underscore the sophistication of this operation.
The Chinese state-sponsored group ‘Evasive Panda’ compromised an unnamed ISP to infiltrate organisations in a cyber espionage operation in mid-2023. Although some details of the initial attack vector remain unknown, the threat actors reportedly conducted a domain name system (DNS) poisoning attack to intercept customers’ DNS requests. More specifically, the threat actors modified the content of requested HTTP pages to display a pop-up browser update alert. This then prompted users to update their browser, downloading malicious files onto the system. Alternatively, the threat actors exploited vulnerabilities in their victims’ automatic update mechanisms, injecting malware without requiring any user interaction (and consequently highlighting the threat actors’ sophistication). Subsequently, Evasive Panda deployed the ‘MACMA’ and ‘POCOSTICK’ payloads to steal information from targeted systems via device fingerprinting and keylogging, as well as audio and screen capture. Additionally, the group deployed a Google Chrome extension, ‘RELOADTEXT’, in some operations to exfiltrate browser cookies to an actor-controlled Google Drive account. We assess that the exploitation of a third-party vendor in the attack lifecycle further underscores the security and espionage risks presented via the software supply chain.
Some non-exhaustive recommendations to mitigate against these threats include:
- Monitor devices and networks for suspicious activity.
- Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network.
- Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
- Ensure adequate security monitoring and detection capabilities, particularly for all external-facing services and devices, including personal devices connected to corporate networks or applications.
Our cyber word(s) of the week: Domain name system (DNS) poisoning attack
(Source: Sibylline)
——————————————————————————————————————————————————————————————————————————————————————————————————————————————
Spectra Group (UK) Ltd
Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.
Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.
With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.
Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.
In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.
Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.
Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.
—————————————————————————————————————————————————————————————————————————————————————————————————————————————-

