• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • SPECTRA banner
  • Curtiss-Wright banner

BATTLESPACE Updates

   +44 (0)77689 54766
   

  • Home
  • Features
  • News Updates
  • Defence Engage
  • Company Directory
  • About
  • Contact

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

December 13, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

————————————————————————————————————————————————————————————————————————————————————————————————————————————–

12 Dec 24. Commercial Tech at Heart of Future Defense Spectrum Management. The electromagnetic spectrum is required for nearly every aspect of space-based communications, from satellite to satellite to satellites to soldiers on the ground. Ensuring the spectrum needed for that communication is protected for use by the U.S. and its allies, increasingly means adopting technology developed in the commercial sector.

Over the past few decades, the commercial sector has spent four times as much on research and development than the federal government, including in areas like spectrum management, said Air Force Maj. Gen. Steven J. Butow, the military deputy director of the Defense Innovation Unit, while speaking Wednesday at the Association of Old Crows International Symposium and Convention, just outside Washington.

“During the time that we were not investing in electronic warfare capabilities as a fighting force, the commercial sector was taking off, digitizing, adopting communications capabilities — 3G, 4G, 5G — scaling up,” Butow said. “You have companies like Qualcomm that were developing new methodologies to harness previously unusable parts of spectrum for economic advantage, and all kinds of different business models that we can learn from and then look at how we apply that today.”

Today’s warfighters, Butow said, have more commercial capabilities at their disposal than they did in the past, when everything was military issued.

“Now we have a plethora of different commercial capabilities that we can use throughout peacetime, contingency and even in war, and so do our allies,” he said.

“Commercial technology provides the best way for us to actually rapidly expand and integrate with our allies and partners.”

Working with the commercial sector to bring the best of what it has to offer into the Defense Department is part of what the DIU does, said Butow.

“The Defense Innovation Unit was created in 2015 by then Secretary of Defense Ash Carter, with the sole purpose of trying to bring the commercial technology sector back in, in a way that we could really benefit from a lot of innovation happening outside of the Department of Defense,” he said.

Today, Butow said, much of technology development in spectrum management and in capabilities related to electronic warfare are being developed in the private sector. Integrating that into the department is a challenge that DIU is solving.

“The DOD has the monopoly on wicked problems,” he said. “If you really want to solve a tough problem, we probably own it. And the best talent … in the commercial sector today, they really want to work on those kind of problem sets.”

Creating pathways for that to happen, he said, is what DIU does. In the last decade, he said, about 100 different organizations related to innovation have developed in the Defense Department, which do just that.

“Let’s create an opportunity for them to be able to work on our problems in a way that could be financially favorable to them,” he said. (Source: U.S. DoD)

 

11 Dec 24. CDAO and DIU Launch New Effort Focused on Accelerating DOD Adoption of AI Capabilities. Today, the Chief Digital and Artificial Intelligence Office (CDAO) in partnership with the Defense Innovation Unit (DIU) announced the formation of a new AI Rapid Capabilities Cell (AI RCC) focused on accelerating DoD adoption of next-generation artificial intelligence (AI) such as Generative AI (GenAI). The AI RCC will be managed by the CDAO and will be executed in partnership with DIU. The AI RCC will lead efforts to accelerate and scale the deployment of cutting-edge AI-enabled tools, to include Frontier models, across the Department of Defense.

This announcement comes as the CDAO sunsets Task Force Lima, the Department’s initiative focused on harnessing the power of GenAI. The AI RCC will build upon the findings, and focus on executing pilots in the primary use case areas identified by Task Force Lima. These areas are:

  • Warfighting: Command and Control (C2) and decision support, operational planning, logistics, weapons development and testing, uncrewed and autonomous systems, intelligence activities, information operations, and cyber operations
  • Enterprise management: financial systems, human resources, enterprise logistics and supply chain, health care information management, legal analysis and compliance, procurement processes, and software development and cyber security

The executive summary of Task Force Lima’s findings can be found on CDAO’s website.

“The US commercial sector is at the cutting edge when it comes to artificial intelligence, and digital solutions,” said Chief Digital and AI Officer Dr. Radha Plumb. “We need an all-hands-on-deck approach to accelerate development and deployment of these tools for the Department of Defense to responsibly harness the tremendous promise of AI in everything from financial management to logistics to operations planning to autonomous systems.”

“DIU’s role is bringing the very best commercial tech to bear to meet critical warfighter problems with the focus, speed, and scale required to meet the strategic imperative,” said Doug Beck, Director of DIU. “Our partnership with CDAO, and collaboration on the Rapid Capabilities Cell, will allow us to shape critical AI initiatives in a way that incorporates the standards, policy, and requirements from the beginning. The result will help us scale the tech faster and more reliably, and will also help change the way the Department thinks about software development and delivery tempo for the future.”

The AI RCC will initially be resourced with approximately $100M in FY 2024 and FY 2025 for pilot efforts that apply generative AI models to priority use cases, and investments in foundational AI infrastructure and tools. In partnership with other parts of the Department, industry, and academia, CDAO and DIU will take a rapid experimentation-based approach to the AI pilots, consistent with the CDAO and DIU’s Open DAGIR construct and use all available agile acquisition approaches.

Additional details about planned pilots, infrastructure investments, and other AI-focused efforts can be found in the linked fact sheet.

About the CDAO and DIU

CDAO is the Department of Defense’s (DoD) organization responsible for the acceleration of the department’s adoption of data, analytics, and artificial intelligence (AI). It has the mission of providing enterprise-level infrastructure and services, as well as scaling proven secure digital and AI-enabled solutions for enterprise and joint use cases. CDAO leverages relevant dual-use commercial technologies and novel operating models to enable all DoD organizations to quickly develop, test, integrate and deliver secure, data, analytic, and AI capabilities to achieve their missions.

DIU is the DoD’s organization responsible for leading the adoption of commercial technologies to solve warfighter problems for strategic impact at speed and scale, in support of the National Defense Strategy. It serves as the principal liaison between the DoD and the national security innovation base, and with its companies and investors, and coordinates and advises efforts within the DoD, and with interagency and international partners, on matters related to the development, procurement, and fielding of commercially derived technology. (Source: U.S. DoD)

 

12 Dec 24. Strategic Effect. The regime of Syria’s dictator Bashir al-Assad is no more. On 7th December 2024 Mr. Assad fled Damascus following a dramatic advance across much of Syria by the Hayat Tahrir al-Sham (HTS) Islamist political grouping. One day later Mr. Assad and his family were reportedly granted asylum in Russia.

Syria has been mired in civil war since 2011. A dramatic offensive led by forces opposed to the regime commenced on 27th November. Several Syrian cities fell in rapid succession to the opposition including Homs in the central, western part of the country and Aleppo in the north. Mr. Assad’s fate was sealed following fall of Damascus.

Unconfirmed local reports say that HTS’ advance was assisted by a concerted jamming effort directed against tactical radio networks and military communications used by forces loyal to the regime. Speculation focused on Turkish forces deployed in Syria directing electronic attacks against these communications. Turkish forces have been deployed in northern Syria since 2016. The Turkish military has supported elements of the anti-Assad opposition and fought Kurdish militias active there. As Armada has chronicled in the past, Turkish military Electronic Warfare (EW) assets have proven effective during Ankara’s involvement in the Syrian civil war.

Several conclusions can be drawn assuming these reports of Turkish EW prowess are correct: Firstly, Syrian forces loyal to the regime lacked Communications/Transmission Security (COMSEC/TRANSEC) protocols to resist electronic attack. Secondly, these forces may have been largely relying on civilian communications unable to withstand electronic attack. Thirdly, Mr. Assad’s Russian backers may not have provided the secure communications needed to guarantee electromagnetic resilience. Fourthly, any COMSEC/TRANSEC protocols and/or military communications used by regime forces may have been unable to withstand the severity of attacks.

Perhaps the most important lesson is that HTS cadres may have enjoyed electromagnetic superiority over the regime thanks to the jamming. Regime forces could not use the spectrum as they wished for communications, unlike HTS units. The inability of the regime to thus exploit the spectrum for communications cost them dearly by depriving them of a vital tactical and operational command and control conduit. This depravation may have had a strategic effect by discombobulating the regime’s forces, thus contributing to Mr. Assad’s downfall. (Source: Armada)

 

12 Dec 24. Belarussian Tactical Communications Enhancements. The Belarussian Army is receiving R-185 Epocha command and control vehicles which provide V/UHF and HF communications. These vehicles are likely deployed at the regimental and brigade level in Belarussian ground forces manoeuvre formations. The modernisation of the Belarussian Army’s tactical communications is continuing with recent deliveries of new R-185 Epocha command and control platforms. Ukraine’s militarnyi website reported in late November that the Belarussian Army has received a new batch of R-185 Epocha (Р-185 Эпоха) Command and Control (C2) systems. The R-185 ensemble is housed onboard a BTR-60MB2 eight-wheel drive armoured vehicle. The reports continued that work on the R-185 commenced in 2016. According to the Belarussian Ministry of Defence, the first R-185-equipped vehicles entered service in 2020. The R-185 communications fit includes R-181-50VU-2 (Р-181-50ВУ-2), R-181-50TU (Р-181-50ТУ) and R-181-100VK (Р-181-100ВК) tactical radios.

The radios

Official Belarussian government documents specify that the R-181-50VU-2 uses frequencies of Very/Ultra High Frequencies (V/UHF: 30 megahertz/MHz to 512MHz). The radio handle two simplex (one-way) channels, and one duplex (two-way) channel. The document continues that ranges of 30 kilometres/km (18.6 miles) are achievable when the radio is stationary, with ranges of 20km (12.4 miles) possible when the radio is mobile. Unclassified data is handled at rates of 19.2 kilobits-per-second/kbps. The R-181-50VU2 carries both fixed frequency and frequency-hopping traffic.

The R-181-50TU is a VHF (30MHz to 108MHz) transceiver. Providing up to 100 channels, the radio produces between five and 50 watts/W of transmission power. Communications/Transmission Security (COMSEC/TRANSEC) comprises a minimum frequency hopping rate of 200 hops-per-second/hps. The R-181-50TU can handle data at rates of between 9.6kbps and 19.2kbps. This radio has a range of 25km (15.5 miles) when mobile, and up to 50km (31.1 miles) with a mast when the vehicle is stationary.

The R-181-100VK is a High Frequency (HF: three megahertz to 30MHz) transceiver providing up to 100W of output power. It is likely that the R-181-100VK facilitates beyond line-of-sight backhaul to higher echelons. When mobile the R-181-100VK has a range of 75km (46.6 miles), and up to 350km (217.5 miles) with a mast when the vehicle is stationary. The R-185 has also been designed to communicate with aircraft. VHF ground-to-air/air-to-ground links of up to 65 nautical miles/nm (120km) can be established using the R-181-50TU. The Epocha’s R-181-100VK HF radio permits longer ground-to-air/air-to-ground links of up to 243nm (450km).

Assessment

How many R-185 systems have been delivered to the Belarussian Army remains unknown. It is likely that the army’s signals troops, which are a separate command, are the primary Epocha users. The Belarussian Army’s order-of-battle is organised around the brigade as its primary unit of manoeuvre. Mechanised brigades have organic mechanised infantry, armour, artillery and combat support regiments and battalions. It is possible that the R-185s provide intra-brigade communications, and communications with higher echelons of command. The Epocha programme does not appear to have concluded. Additional supplies of the system can be expected in the future. (Source: Armada)

 

12 Dec 24. Keeping Secrets. Link-16 is one of several tactical datalink protocols employed throughout NATO. The protocol is primarily used to support air operations, with Link-11/22 primarily supporting the maritime domain. Why capturing an airborne radio compatible with NATO’s Link-16 tactical datalink protocol may not hand Russian radio frequency engineers an intelligence coup.

In late November, Pravda cited a Turkish source which stated that Ukraine’s Ministry of Defence had requested access to North Atlantic Treaty Organisation (NATO) Link-16 connectivity. Link-16 is a secure, encrypted tactical voice and communications protocol. Primarily used to support air operations, Link-16 traffic includes target track data and other tactically relevant information. This traffic is carried via so-called ‘J-Series’ messages across frequencies of 960 megahertz to 1.215 gigahertz. NATO began to use Link-16 in the 1980s and the protocol has supported alliance air operations ever since.

The Pravda article speculated that furnishing the Ukrainian F-16s with Link-16 could allow these aircraft to plug into NATO Link-16 networks. Open-source websites like flightradar24 regularly show NATO aircraft flying in alliance airspace close to Ukraine’s borders. These planes can include Boeing RC-135V/W Rivet Joint Signals Intelligence (SIGINT) aircraft flown by the United States Air Force and the Royal Air Force. Regular flights are also made by alliance airborne early warning and control aircraft such as Boeing E-3 series jets or Royal Swedish Air Force Bombardier/Saab S106 GlobalEye platforms. These NATO planes can all carry Link-16 compatible radios. The article speculated that Ukrainian F-16s could now receive tactical information direct from NATO aircraft via Link-16 networks. Technically, this is possible. Whether it has occurred is beyond the scope of this article.

Does Russian have Link-16 technology?

Pravda’s boldest assertion was that “if Russia obtains … the Link-16 system, it may have an extremely negative impact on the combat capability of NATO aviation.” The article surmised that the Russian military may succeed in shooting down an F-16, or a Ukrainian F-16 pilot could be tempted to defect. A Link-16 compatible radio in the possession of Russian engineers might then give up its secrets. The article warns that “(i)f this equipment falls into the hands of Russian specialists, they will be able to access NATO codes and ciphers used in the system.”

It is difficult to believe that Russia does not already have knowledge of Link-16 technology. NATO nations have lost several combat aircraft over the years that were likely equipped with Link-16 compatible radios. Many of these aircraft have been downed by countries, or organisations, considered sympathetic to Russia. During NATO operations in the Balkans in the 1990s three alliance combat aircraft were shot down by the Bosnian Serb Army and/or the Yugoslav military.

Famously, a US Navy Lockheed Martin EP-3E Aries-II SIGINT aircraft was forced to land on Hainan Island off the southern coast of the People’s Republic of China on 1st April 2001. The EP-3E landed after a collision with a People’s Liberation Army (PLA) Navy Air Force Shenyang J-8 (NATO reporting name Finback) series combat aircraft. The EP-3E crew were released after ten days of internment on the island. The aircraft was disassembled and later returned to the US Navy on 3rd July 2001. Reports revealed that the PLA examining the EP-3E captured cryptographic keys used by the aircraft’s communications. It was speculated that some classified materials the EP-3E crew could not destroy were shared with Russia.

Robust encryption

Capturing a Link-16 compatible radio is unlikely to result in an intelligence coup rendering the protocol redundant overnight. Open sources say that Link-16 J-Series messages, and the signal carrying this traffic, are encrypted. To break into a Link-16 network both the message, and the signal, must be decrypted. Moreover, Link-16 networks use pseudo-random frequency-hopping. Each separate Link-16 network has its own distinct frequency-hopping scheme. Link-16 messages and traffic can only be encrypted or decrypted using the message and traffic encryption keys embedded in the radios at that time. Keys are regularly changed precisely to frustrate any attempts to gain unauthorised access to a Link-16 network. A Link-16 compatible radio could be captured, and its encryption keys discovered, but it is unlikely the keys will have any use. By the time the radio can be used to gain illicit access to Link-16 traffic, encryption keys will have changed. Even if Russian engineers do succeed in capturing a Link-16 radio, they may find it little more than dead circuitry as far as secure Link-16 traffic is concerned.(Source: Armada)

 

12 Dec 24. December Radio Roundup. Thales’ Naval Drakon communications system is the company’s latest offering in this market space. Naval Drakon is scheduled to equip the French Navy’s ‘Amiral Ronarc’h’ and the Royal Navy’s ‘Type-31/Inspiration’ classes of frigate.

Armada’s monthly roundup of all the latest news in the military communications product, programme and operational domains.

Naval Drakon Unveiled

Thales has showcased the latest evolution of the company’s naval communications product portfolio at this year’s Euronaval exhibition held in Paris between 4th and 7th November. Known as Naval Drakon, this new suite of naval communications hardware and software continues the company’s involvement with this sector as enshrined in the Aquilon family. Drakon is a suite of hardware and software that integrates and manages disparate communications links using High Frequency (HF: three megahertz/MHz to 30MHz), Very/Ultra High Frequency (V/UHF: 30MHz to three gigahertz) and Satellite Communications (SATCOM) wavebands. Thales officials told Armada during Euronaval that Drakon works with Thales’ hardware such the company’s transceivers, or with those of third parties. Naval Drakon is the maritime equivalent of the Drakon system the company has developed for land forces. The officials continued that the Drakon has been designed with the trend towards Joint Electromagnetic Spectrum Operations (JEMSO) in mind. The JEMSO philosophy converges ostensibly disparate disciplines such as radar, radio communications and Electronic Warfare (EW), among others. At the heart of JEMSO is the desire to perform electromagnetic spectrum operations in a managed, coordinated manner. The intention here is to reduce spectrum congestion, improve spectrum management and emissions control. JEMSO also stresses reducing risks of electromagnetic fratricide, while improving the efficacy of EW, communications and ISR (Intelligence, Surveillance and Reconnaissance). Officials said that Naval Drakon is scalable according to the size of vessel it equips. Moreover, the system is already in service onboard the Marine Nationale’s (French Navy’s) ‘Jacques Chevallier’ class replenishment vessels. Naval Drakon is also equipping the French Navy’s ‘Amiral Ronarc’h’ class frigates and the Royal Navy’s ‘Type-31/Inspiration’ class frigates. BAE Systems and Kongsberg are working together promoting their Integrated Combat Solution which can shared battlefield data and also control vehicle weapons, sensors and other subsystems.

ICS Gains Momentum

Last month it was revealed that BAE Systems and Kongsberg have entered into a teaming agreement regarding the Integrated Combat Solution (ICS). The former has shared more information with Armada regarding this arrangement. Kongsberg is developing the ICS and BAE Systems is integrating the architecture onto vehicles, according to a press release. The ICS is a battle management system which also lets vehicle crews control their subsystems. These subsystems could include a remote weapons station, and/or electronic warfare and self-protection apparatus from individual screens inside the platform. The ICS has been demonstrated onboard an Iveco/BAE Systems Amphibious Combat Vehicle and BAE Systems Armoured Multi-Purpose Vehicle. A written statement provided by BAE Systems revealed that the ICS is used by the militaries of Australia, Finland, Norway and Ukraine. The latter deploys the ICS as part of Kongsberg Cortex Typhon counter-uninhabited aerial vehicle system. The statement continued that the ICS “can be integrated on any battlefield platform that is equipped with a weapon system and on-board sensors.” In terms of bearer networks for ICS’ data, these can be carried across “multiple communication methods.”

New E-Lynx Arrival

October saw Elbit Systems launch a new member of its E-Lynx tactical radio family dubbed the E-Lynx SR. A press release announcing the news disclosed that this multi-channel system was launched at the International Dismounted Soldier Conference held in London between 29th and 30th October. Elbit says that the radio incorporates cognitive techniques and multiple-in/multiple-out architectures. Other features include simultaneous voice, internet protocol, blue force tracking and video traffic carriage. In addition, the radio can connect to fourth- and fifth-generation cellular networks. The company told Armada in a written statement that the transceiver uses frequencies of 225 megahertz/MHz to 2.9 gigahertz. Elbit continued that the E-Lynx SR contains the company’s new soldier waveform. This waveform is compatible with existing E-Lynx products. Customer-specified waveforms can also be hosted in the transceiver. Elbit’s statement added that it is pitching this radio as a capability for dismounted squad and platoon leaders. (Source: Armada)

 

12 Dec 24. China: Spyware operation highlights surveillance, information-theft risks stemming from authorities. On 11 December, the cyber security company Lookout reported that the Chinese authorities are using new spyware (‘EagleMsgSpy’) to target Android mobile users in China. The malware is installed after gaining physical access to victims’ unlocked devices. Law enforcement officers reportedly deploy EagleMsgSpy to collect extensive sensitive data from compromised devices, including call logs, messages, contacts’ information and GPS co-ordinates. Stolen data is then encrypted and sent to command-and-control (C2) infrastructure that can only be accessed by authenticated users, underscoring the sophistication and covert nature of this operation. Additionally, the spyware’s obfuscation and encryption techniques have evolved since it first became active in 2017, pointing to its continued development. Notably, EagleMsgSpy contains functions to distinguish between Android and iOS operating systems, suggesting that an unidentified iOS version of the spyware possibly exists. This discovery showcases the scale of China’s surveillance activities, elevating the surveillance and information-theft risks facing individuals in the medium-to-long term. (Source: Sibylline)

 

11 Dec 24. C3 AI (NYSE: AI), the Enterprise AI application software company, and Collins Aerospace, an RTX business, today announced expanded joint initiatives to develop and deliver AI solutions across the defense and intelligence space.

“As the defense and intelligence sectors confront increasingly complex challenges, the need for advanced, scalable AI solutions has never been more critical,” said Thomas M. Siebel, CEO, C3 AI. “Our strengthened partnership with Collins underscores our shared commitment to equipping federal agencies with the AI capabilities essential to maintaining strategic advantage, improving decision making, and enhancing mission readiness. Together, we are accelerating a transformative shift that will redefine how national security and defense are achieved in the modern era.”

These new initiatives aim to leverage AI for critical defense operations, advancing technology adoption in support of federal priorities. Specifically, C3 AI and Collins are deploying applications from the C3 AI Defense and Intelligence Suite, including C3 AI Readiness and C3 Generative AI for Defense and Intelligence.

“By combining our expertise in mission-critical systems with C3 AI’s advanced AI platform and applications, we are equipping federal agencies with the tools they need to act decisively, enhance situational awareness, and strengthen national security. This collaboration is about more than technology — it’s about driving a future-ready approach to defense,” said Ryan Bunge, vice president and general manager, C4I&A, Collins Aerospace. (Source: BUSINESS WIRE)

 

10 Dec 24. Global: Malware variant heightens security, operational risks to critical infrastructure. On 10 December, the cyber security company Check Point reported that the ‘Androxgh0st’ malware is being used by cyber criminal groups to target critical national infrastructure (CNI) systems. Threat actors have reportedly integrated Androxgh0st with the ‘Mozi’ botnet to strengthen the malware’s capabilities. This allows Androxgh0st to exploit software vulnerabilities for access to targeted systems as well as to achieve prolonged presence within compromised systems to exfiltrate sensitive data. We assess that cyber criminals likely sell stolen data on the dark web to garner illicit profit. Notably, these operations targeted Internet-of-Things (IoT) devices alongside web servers and encompassed distributed denial-of-service (DDoS) attacks. We assess this highlights increased operational risks to CNI systems as the sophistication of cyber criminal groups continues to grow. Androxgh0st impacted at least 5% of global organisations in November, thus elevating security, financial and disruption risks in the short-to-medium term amid a general uptick in cyber criminal attacks. (Source: Sibylline)

 

10 Dec 24. CrowdStrike (NASDAQ: CRWD) today announced a key government certification, achieving C5 compliance in Germany. The C5 (Cloud Computing Compliance Criteria Catalogue) certification, established by the German Federal Office for Information Security (BSI), ensures that cloud service providers meet rigorous security criteria required by public sector organizations to remain secure while delivering critical services. This achievement reinforces CrowdStrike’s dedication to supporting customers through government-led security standards.,This latest milestone is part of CrowdStrike’s ongoing global efforts to expand access and accelerate adoption of the AI-native CrowdStrike Falcon® Platform. Achieving C5 compliance underlines CrowdStrike’s commitment to government-led security standards and supports public sector organizations in Germany and beyond. Through a rigorous certification process, CrowdStrike reaffirms its technical capabilities, security expertise, and adherence to privacy and data security best practices – adding to an expansive list of international certifications and government recognition that CrowdStrike has achieved, including being recommended by the German Federal Office for Information Security (BSI) as a qualified Advanced Persistent Threat (APT) response service provider.

“Achieving C5 certification is an important milestone for CrowdStrike as we work with public sector customers in Germany to stop breaches,” said Michael Sentonas, president of CrowdStrike. “We have tremendous momentum in the region and are committed to providing organizations of all sizes, across sectors, with the world’s most advanced AI-native cybersecurity.”

CrowdStrike’s drive to meet global compliance standards continues to ensure its global customers are supported by the highest level of security. To learn more about its global compliance efforts, please visit the CrowdStrike Compliance and Certification Page.

About CrowdStrike

CrowdStrike (NASDAQ: CRWD), a global cybersecurity leader, has redefined modern security with the world’s most advanced cloud-native platform for protecting critical areas of enterprise risk – endpoints and cloud workloads, identity and data.

Powered by the CrowdStrike Security Cloud and world-class AI, the CrowdStrike Falcon® platform leverages real-time indicators of attack, threat intelligence, evolving adversary tradecraft and enriched telemetry from across the enterprise to deliver hyper-accurate detections, automated protection and remediation, elite threat hunting and prioritized observability of vulnerabilities.

Purpose-built in the cloud with a single lightweight-agent architecture, the Falcon platform delivers rapid and scalable deployment, superior protection and performance, reduced complexity and immediate time-to-value. (Source: BUSINESS WIRE)

 

10 Dec 24. Movius, the leading global provider of secure, AI-powered, purpose-driven communications software, announced it has been listed in the FedRAMP marketplace with a Department of Defense sponsored agency to provide mission-critical, secure communications solutions (https://marketplace.fedramp.gov/products/FR2335850270). Movius has already been awarded multiple Phase II Small Business Innovation Research (SBIR) contracts through AFWERX, Tactical Funding Increase (TACFI) award, and most recently a Phase III award to scale enhanced secure communication capabilities. Movius’s solutions will contribute directly to the Department of the Air Force’s (DAF) strategic need for resilient information sharing, secure decentralized and distributed communications, intelligence, surveillance and reconnaissance, assured communications, and situational awareness with Movius’s edge AI.

Movius’s MultiLine solution is a secure, scalable application that allows users to call and message through a secure business identity across any device, carrier, and connection type (Wi-Fi, Data, GSM, Satellite and Private). MultiLine supports built-in recording and call/message capture and storage for the entire workforce, enabling full surveillance, regulatory reporting, compliance management, and robust application security. The solution is also supported on legacy government cell phone programs.

Movius Decentralized Distributed Secure Communications solution enables decentralized, military grade communications globally, including in a denied and degraded network environment. With this solution there are no central server dependencies or risk of communications being blocked or thwarted. It includes the notion of self-sovereign identity.

“These awards are a culmination of over two years of focused partnership for groundbreaking innovation between the Air Force and the Movius team,” said Amit Modi, Chief Technology Officer at Movius. “Ultimately, the vision is simple—freedom to communicate securely and safely from anywhere at any time,” added Modi.

To learn more about MultiLine by Movius and the company’s full suite of AI-powered solutions, visit www.movius.ai. (Source: BUSINESS WIRE)

 

10 Dec 24. Enhancing UK Biosecurity: DASA Launches Microbial Forensics Competition. DASA and UKMFC seek novel technology options to enhance the UK’s Microbial Forensic capability.

  • DASA has launched a new Themed Competition: Future-proofing Biosecurity by Strengthening the UK’s Microbial Forensic Capability
  • This competition is funded by Dstl for the UK Ministry of Defence (MOD)
  • The total possible funding available for this competition is £1m (excluding VAT).
  • Competition closes midday on Tuesday 18th February 2025 (GMT)

On behalf of the Defence Science and Technology Laboratory(Dstl), the Defence and Security Accelerator (DASA) is pleased to launch a new Themed Competition called Future-proofing Biosecurity by Strengthening the UK’s Microbial Forensic Capability. The competition is being run in response to the 2023 UK Biological Security Strategy which aims to implement a UK-wide approach to biosecurity that will strengthen deterrence and resilience to a spectrum of biological threats.

Dstl is leading the creation of the United Kingdom Microbial Forensics Consortium (UKMFC) which is being developed in support of the Detect Pillar of the Biological Security Strategy. It will comprise a network of biosurveillance laboratories from all four nations of the UK, operating under a One Health doctrine. This competition seeks novel technology options or technical approaches that can directly support the UKMFC initiative.

Key dates and funding

The total possible funding available for this competition is £1m (excluding VAT). We are looking to fund a minimum of 4 and up to 10 projects, each up to a maximum value of £250,000. The deadline to submit a proposal is midday (GMT) on 18 February 2025. Submit via the DASA Online Submission Service.

Background

The aim of the competition is to strengthen UK capability in the field of Microbial Forensics. Novel technology options are required to function within the context of the UKMFC laboratory network; an appropriately resourced, high technological infrastructure, staffed by subject matter experts in biosurveillance. Innovations that either augment current approaches (e.g. increasing the speed and / or opportunity for anomaly detection through genomics) including novel uses of technology platforms or that provide completely new avenues for a Microbial Forensic investigation are of interest.

Any new capability should not increase the risks encountered in the day-to-day activities of a laboratory, or significantly increase the financial burden encountered by a laboratory (above normal investment patterns). There is no interest in technology development that would provide a solely mobile Microbial Forensic capability or enhance a laboratory’s ability to simply identify a pathogen.

Dstl provides expert scientific advice and deployable capabilities which directly support resolution of some of the most challenging national security incidents: those involving explosive, chemical or biological materials. Dstl hosts the UK’s only sovereign Chem-Bio capability used to analyse and understand the world’s most deadly pathogens and biological weapons.

What are the technology challenges we would like addressed?

There is particular interest in funding new research in the following areas:

  1. Computational tools that improve the opportunity to detect anomalies in genome sequencing data, including evidence of biological engineering.
  2. Technologies that allow the identification and / or computational analysis of other omic signatures for novel Microbial Forensic capabilities.

Ideally any new capability would be agnostic of the sector, sample type, and class or type of biological agent being analysed. However, technical approaches that are specific to certain types or classes of biological agent may be considered. We are also interested in proposals that develop or repurpose existing technologies used in other scientific disciplines.

We are looking for innovations that will form the basis of the next generation of Microbial Forensic capability, potentially enhancing our ability to use any branch of science under the omics banner in a Microbial Forensic investigation, and fundamentally improve our understanding of an encountered pathogen.

Supporting events

Thursday 9 January 2025

A dial-in webinar providing further detail on the problem space and a chance to ask questions in an open forum. If you would like to participate, please register on the Eventbrite page here.

Wednesday 15 and Tuesday 21 January 2025

There will also be one-to-one teleconference sessions on 15 and 21 January giving you the opportunity to ask specific questions to the competition team in a closed forum. Registration details for these sessions will be published the day after the dial in webinar session, i.e. on 10 January 2025. Booking will be on a first come first served basis.

Please attend the dial-in session on 9 January 2025 or reach out to your local Innovation Partner if you have more general questions on DASA the application process.

Submit a proposal

We want novel ideas to enhance the UK’s Microbial Forensic capability. Can you provide innovative solutions? If so, please read the full competition document and submit a proposal.

https://www.gov.uk/government/publications/future-proofing-biosecurity-by-strengthening-the-uks-microbial-forensics-capability (Source: https://www.gov.uk/)

 

04 Dec 24. The second UK-EU Cyber Dialogue takes place in London.

The second UK-EU Cyber Dialogue took place this week. Both sides agreed to hold the next UK-EU Cyber Dialogue in Brussels in 2025.

From left to right: Maciej Stadejek, Christiane Kirketerp de Viron, Rod Latham, and Andrew Whittaker

The second UK-EU Cyber Dialogue took place on Thursday 5 and Friday 6 December in London.

The meeting was co-chaired by Andrew Whittaker, Cyber Director in the UK Foreign, Commonwealth and Development Office (FCDO) and Rod Latham, Director, Cyber Security and Digital Identity in the Department of Science, Innovation and Technology (DSIT).

Held under the UK-EU Trade and Cooperation Agreement, the Cyber Dialogue welcomed Maciej Stadejek, Director, Security and Defence Policy, European External Action Service (EEAS) and Christiane Kirketerp de Viron, Acting Director, Digital Society, Trust and Cybersecurity, DG Communications Networks, Content & Technology (DG CNECT), European Commission as co-chairs from the European Union (EU).

Other representatives from the Commission and EU agencies (Europol, ENISA) also participated in the discussions.

The agenda included exchanges of views on our respective approaches to cyber resilience, secure technology and digital identity; deterrence strategies against cyber threats; countering cybercrime including ransomware; working with the multi-stakeholder community to uphold a free, open, secure and peaceful cyberspace; the Pall Mall Process to tackle the proliferation and irresponsible use of commercial cyber intrusion capabilities; cyber skills; and cyber capacity building.

The UK was represented by officials from the Foreign, Commonwealth and Development Office (FCDO), Department for Science, Innovation and Technology (DSIT), National Cyber Security Centre (NCSC), and Home Office.  Both sides agreed to hold the next UK-EU Cyber Dialogue in Brussels in 2025. (Source: https://www.gov.uk/)

 

06 Dec 24. Cyber Update Key points.

  • The distribution of the ‘SpyLoan’ malware via malicious mobile applications underscores elevated financial risks facing Android users (see Sibylline Cyber Daily Analytical Update – 2 December 2024).
  • Threat actors targeted Taiwan with the ‘SmokeLoader’ malware, heightening security and information-theft risks to firms (see Sibylline Cyber Daily Analytical Update – 3 December 2024).
  • Evolving phishing tactics will increase security risks from the North Korean state-sponsored group ‘Kimsuky.’
  • The Russian state-sponsored group ‘Turla’ hijacked the cyber infrastructure of another state-sponsored threat group for espionage operations, elevating espionage risks to government and military organisations in Afghanistan and India.
  • A new Malware-as-a-Service (MaaS) operation elevates security and financial risks to global Android mobile users and financial institution.

Technical analysis of weekly stories

The North Korean state-sponsored group Kimsuky adopted new phishing techniques in a cyber operation between May and October. The group used phishing emails to trick researchers, financial institutions and corporate officials into visiting fraudulent websites designed to steal user credentials. The emails impersonated government and financial institutions to enhance legitimacy and asked users to urgently review documents online. Kimsuky did not deploy any malware upon gaining access to targeted systems, highlighting a potential shift in the group’s tactics towards prioritising stealth, establishing a prolonged presence in targeted systems and detection evasion. Additionally, the actors consistently rotated infrastructure throughout the campaign, using Japanese domains in April, Korean services between May and September and finally shifting to Russian domains in October. This further emphasises the sophistication of Kimsuky’s detection evasion capabilities as it focuses on countering analysis and security mechanisms. We assess that the group likely stole credentials to hijack user accounts to exfiltrate sensitive information and initiate fraudulent money transfers.

A new MaaS operation has been targeting Android mobile users in a financially motivated campaign since at least June. The campaign has already compromised at least 77 banking institutions, cryptocurrency exchanges and national organisations primarily based in Europe and Latin America. The campaign starts by distributing a new remote access trojan (RAT), ‘DroidBot’, via malicious applications on the Google Play store, impersonating legitimate security and banking applications. Users are then asked to enable Android accessibility services, subsequently allowing threat actors to monitor and mimic user activity. Some of the malware’s most notable features include keylogging, overlaying and SMS interception to hijack one-time passwords (OTPs) and other authentication information. DroidBot also uses virtual network computing (VNC) modules to remotely monitor infected devices as well as execute additional commands including darkening mobile screens to obfuscate malicious activity. The RAT uses the Message Queuing Telemetry Transport (MQTT) protocol to communicate with command-and-control (C2) infrastructure. MQTT is not typically used in cyber operations or associated with malicious activity, thus helping threat actors prolong detection evasion. DroidBot’s MaaS operation currently boasts around 17 affiliates, pointing to the scale of this operation and the possibility of future operations using this RAT. The RAT also displayed some unfinished features, suggesting that it is likely facing ongoing development.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security-detection systems to detect potentially malicious samples on the network
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
  • Ensure adequate security monitoring and detection capabilities, particularly for all external-facing services and devices; this includes personal devices connected to corporate networks or applications
  • Adopt and review network authentication services including virtual private network (VPN) services and multi-factor authentication (MFA)
  • Avoid downloading applications from untrusted third-party websites and only use the official websites and application stores to install applications and tools on devices.

Our cyber word(s) of the week: Message Queuing Telemetry Transport (MQTT) protocol. (Source: Sibylline)

 

08 Dec 24. Cyber Command Chief Discusses Challenges of Getting Intel to Users. The United States has spent trillions of dollars on ensuring intelligence and the network that distributes that intelligence is the best on the planet, but more needs to be done, said Air Force Gen. Timothy D. Haugh, commander of U.S. Cyber Command, director, National Security Agency and chief, Central Security Service, in a discussion at the Reagan Defense Forum yesterday.

Intelligence is the lifeblood of defense strategy and a crucial aspect of deterrence. Haugh spoke during a panel hosted by New York Times reporter Julian Barnes. The panelists agreed that the United States does a good job of collecting intelligence and analyzing the intelligence but has shortcomings in ensuring that the people who need that information get it in a timely and effective form.

Competitors, of course, try to guard their intelligence and use all methods to find what the United States knows, Barnes stated to the general about Salt Typhoon — the Chinese government led hack aimed at North America and Southeast Asian targets. The hack — discovered by Microsoft — was not only aimed at companies, but high-level political figures.

Haugh said the hack — which some in the intelligence community called “mind-boggling” — is just one part of China’s global cyber program. “So that is an area that we have to continue to be able to educate our allies, our partners and the American people of what the intent is, whether it be coming at our critical infrastructure or intending to do collection through a large-scale series of operations against our telecommunications industry,” he said.

The National Security Agency is working with the Cybersecurity and Infrastructure Security Agency, the FBI and industry partners on the threat Salt Typhoon poses. The agency did send out cyber security advisories in 2022 “that laid out this exact series of things that we had observed overseas,” the general said. His agency does not collect data in the United States.

“Our question now is … how do we bring the partnership together with industry so that we can together enhance early warning,” he said. “How do we bring our strengths to bear that allow us to think collectively on how we defend U.S. infrastructure. I think that partnership with industry is the component.”

Haugh said the cooperation between his agency and tech industries has gotten better, but “how we do that in a timeline that gets us to outcomes that makes it more difficult for the .”

One way may be the use of the enduring security framework that exists with CISA and NSA. This may help harden the collective telecommunications infrastructure.

Haugh did get asked about how well the NSA is doing in getting intel to the shooters. “One of the roles of the National Security Agency is we’re a combat support agency,” he said. “We are responsible as an element of the Department of Defense to enable military commanders.”

The question about effectiveness really needs to be directed to commanders downrange. “I think the test today would be to the commanders of the various ships that are operating in the Red Sea — how are we doing in informing their threat and their response,” he said. “We’re proud of the work that we do as a community.”

Commanders operating under Houthi threats and threats from other Iranian-backed groups have an understanding of the environment and indications of warning, he said. They are able to put their ships in position to deal with these threats.

“The other component that we’re doing every day is in ensuring that European Command in its role today in support of Ukraine,” he said. “My role is to make sure that from within the Department of Defense and within the nation, we’ve got an ability to deliver signals intelligence in a unified architecture to ensure that we’re getting maximum value for both military commanders and our policy makers.” (Source: U.S. DoD)

————————————————————————————————————————————————————————————————————————————————————————————————————————————

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

———————————————————————————————————————————————————————————————————————————————————————————————————————————

Primary Sidebar

Advertisers

  • Pythia
  • Teledyne
  • Exensor
  • Visit the Oxley website
  • Blighter
  • SPECTRA
  • Britbots logo
  • Faun Trackway
  • Systematic
  • CISION logo
  • ProTEK logo
  • ProTEK logo
  • ssafa logo
  • IEE
  • EXFOR logo
  • sibylline logo
  • Team Thunder logo
  • Comtech logo
  • GoExporting logo
  • ECHODYNE logo
  • Supercat logo
  • Galvion logo
  • Leonardo DRS logo
  • MTC logo
  • IDC logo
  • DSEI logo
  • DVD2024 logo
  • SDSC logo
  • TELEDYNE FLIR logo
  • VeteranUK logo
  • Matrix Space logo
  • ST Engineering logo
  • EWS logo
  • sentinel photonics logo
  • capua logo
  • Curtiss-Wright logo
  • Brave1 logo
  • Drone Evolution logo
  • AEI Systems logo
  • EOS logo
  • NMSUK logo
  • Openworks logo
  • Sandown Park logo
Hilux UKDSE AARTOS ST Engineering Future Artillery

Contact Us

BATTLESPACE Publications
41 St Georges Drive
London SW1V 4DG

+44 (0)77689 54766

BATTLESPACE Technologies

An international defence electronics news service providing our readers with up to date developments in the defence electronics industry.

Recent News

  • Protek Selected By Dutch Armed Forces

    May 2, 2026
    Read more
  • PARLIAMENTARY QUESTIONS

    May 1, 2026
    Read more
  • MANAGEMENT ON THE MOVE

    May 1, 2026
    Read more

Copyright BATTLESPACE Publications © 2002–2026.

This website uses cookies to improve your experience. If you continue to use the website, we'll assume you're ok with this.   Read More  Accept
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT