Sponsored by Spectra Group
———————————————————————————————————————————————————————————————————————————————————————————————————————————————-
23 Dec 24. UK MoD says ‘no plans to cancel’ Morpheus communications project despite delays. The UK Ministry of Defence (MoD) told Janes on 20 December there are no plans to cancel the Morpheus project design to deliver a modernised army communication and information system (CIS). In a 4 December parliamentary response, Minister for Defence Procurement Maria Eagle said, “Morpheus is a project within the Land Environment Tactical Communication and Information Systems (LETacCIS) programme and is currently delayed. Work to reset the project remains ongoing, and an Independent Project Review, led by the Cabinet Office’s Infrastructure and Projects Authority (IPA), will take place in early 2025 and inform next steps.” Eagle added on 11 December that “as of 5 December 2024 total expenditure for the Morpheus project is GBP828m (USD1bn)”. In response to a Janes request for clarification on the meaning of “reset the project”, the MoD told Janes on 20 December that “the ongoing work with the IPA is focused on how best to deliver the benefits of the projects in the most timely and efficient manner for defence”. For the IPA, “it’s more about providing recommendations on the best way to deliver [the Morpheus project]”, an MoD press officer told Janes on 18 December, adding that all requirements and objectives for the project remain valid. In April 2017 General Dynamics UK (GDUK) won an MoD contract, known as Evolve to Open Transition Partner (EvO TP), which sought to transition the army’s existing tactical communications system, Bowman, with an open-modular modernisation. (Source: Janes)
02 Jan 25. Global: New software vulnerability heightens disruption, operational risks to industrial systems. On 30 December, international news outlets reported that threat actors are exploiting a newly identified software vulnerability (CVE-2024-12856) to deploy the ‘Mirai’ botnet. The vulnerability affects Four-Faith routers (versions F3x24 and F3x36) and exposes hardcoded default credentials. Unnamed threat actors first obtained access to the vulnerable devices via brute force techniques, before then exploiting CVE-2024-12856 to inject code remotely so as to conduct malicious activity. While CVE-2024-12856 can only be exploited by authenticated users, it allows threat actors to obtain post-authentication administrative-level privileges. We assess this highlights the possible impact of exploiting said vulnerability on infected systems. Mirai is typically used to conduct large-scale distributed denial-of-service (DDoS) attacks against Internet-of-Things (IoT) devices. Additionally, Four-Faith routers are often used within operational technology (OT) environments to monitor and control industrial processes. We assess this will raise the operational disruption risks in the short term, as patches and remediation guidelines are still in development. (Source: Sibylline)
31 Dec 24. On 30 December, international news outlets reported that an unnamed Chinese state-sponsored advanced persistent threat (APT) group infiltrated systems in the US Treasury Department. It reportedly accessed employee workstations and unclassified documents via a third-party vendor. The breach was first detected on 2 December, while the Treasury Department was notified on 8 December.
SIGNIFICANCE
- The threat group stole an application programming interface (API) key (a unique identifier used to authenticate users and programmes) to gain access to the third party remote management vendor’s systems (‘BeyondTrust’). It subsequently exploited two zero-day vulnerabilities (CVE-2024-12356 and CVE-2024-12686) to hijack instances used by the Treasury Department and remotely steal sensitive information. We assess this underscores the elevated security risks facing government agencies emanating from the software supply chain.
- The full impact of the compromise is yet to be determined as investigations by the Treasury Department, the Cyber Security and Infrastructure Security Agency (CISA) and the FBI are ongoing. The classification of the compromised documents and the seniority of the targeted workstations also remain unclear.
- This incident follows several reports that emerged in November regarding a large-scale cyber espionage campaign conducted by the Chinese state-sponsored group ‘Salt Typhoon’ against several high-profile US telecommunications providers. We assess this points to the scale and resources of Chinese state-sponsored cyber espionage and information-theft outfits amid escalating geopolitical tensions.
FORECAST
We assess there is a realistic possibility that the scale and impact of this campaign will expand in the coming weeks as investigations continue. The threat group was able to compromise multiple customer accounts (including the Treasury Department) as part of the breach. Following the detection, the vendor shut down all compromised accounts, revoking the affected API key to prevent additional compromises. While there is currently no evidence that the threat actors retain access to the agency’s systems, there is a realistic possibility that they have created new user accounts and changed credentials while maintaining access to the compromised systems.
We assess that the impact and scale of this campaign will possibly expand as details continue to emerge in the coming weeks. Notably, the vendor also provides cyber security and remote management services for other government agencies, tech firms, healthcare entities and energy/utility providers. As investigations are ongoing, there is a realistic possibility that additional reports of data breaches will emerge due to the highly sensitive nature of the data contained within the aforementioned sectors. Should this be the case, stolen data will possibly be used in follow-on cyber attacks, heightening the security and social engineering risks facing affected sectors in the short term.
Chinese state-sponsored groups are likely to conduct additional cyber operations in the short term, exacerbating espionage and information-theft risks facing US government and critical national infrastructure (CNI) sectors. In October, Salt Typhoon reportedly compromised several high-profile US broadband providers (including AT&T, Lumen Technologies and Verizon) in a cyber espionage operation. The breach resulted in the exfiltration of customer call records as well as conversations of US government officials and sensitive information pertaining to law enforcement-authorised wiretapping. In November, it transpired that the same group attempted to steal sensitive data from the telecommunications provider T-Mobile, likely as part of the same cyber espionage campaign. In August, another Chinese state-sponsored group, ‘Volt Typhoon’, reportedly exploited a zero-day vulnerability (CVE-2024-39717) for several months to target US-based internet and managed services providers, as well as the IT sector more broadly. These reports point to the consistency of Chinese state-sponsored cyber operations against US government and CNI sectors; we assess that additional attacks are likely in the short term. (Source: Sibylline)
————————————————————————————————————————————————————————————————————————————————————————————————————————————————
Spectra Group (UK) Ltd
Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.
Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.
With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.
Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.
In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.
Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.
Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.
————————————————————————————————————————————————————————————————————————————————————————————————————————————————-

