Defence and Aerospace


  • Threats in space (or rather, on Earth): Internet-exposed GNSS receivers

    November 13, 2024

    Global Navigation Satellite Systems (GNSS) are collections, or constellations of satellite positioning systems. There are several GNSSs launched by different countries currently in operation: GPS (US), GLONASS (Russia), Galileo (EU), BeiDou Navigation Satellite System (BDS, China), Navigation with Indian Constellation (NavIC, India) and Quazi-Zenith Satellite System (QZSS, Japan). These systems are used for positioning, navigation ...

  • Pentagon leaker Jack Teixeira sentenced to 15 years in prison

    November 12, 2024

    Jack Teixeira, a member of the Massachusetts National Guard, has been jailed for 15 years for leaking classified documents about the war in Ukraine and other military secrets. A federal judge in Boston, United States, on Tuesday sentenced the 22-year-old after he pleaded guilty earlier this year to six counts of wilful retention and transmission of ...

  • Chinese threat actor Storm-0940 uses credentials from password spray attacks from a covert network

    October 31, 2024

    Since August 2023, Microsoft has observed intrusion activity targeting and successfully stealing credentials from multiple Microsoft customers that is enabled by highly evasive password spray attacks. Microsoft has linked the source of these password spray attacks to a network of compromised devices we track as CovertNetwork-1658, also known as xlogin and Quad7 (7777). Microsoft is publishing ...

  • Midnight Blizzard conducts large-scale spear-phishing campaign using RDP files

    October 29, 2024

    Since October 22, 2024, Microsoft Threat Intelligence has observed Russian threat actor Midnight Blizzard sending a series of highly targeted spear-phishing emails to individuals in government, academia, defense, non-governmental organizations, and other sectors. This activity is ongoing, and Microsoft will continue to investigate and provide updates as available. Based on our investigation of previous Midnight Blizzard ...

  • The Crypto Game of Lazarus APT: Investors vs. Zero-days

    October 23, 2024

    On May 13, 2024, Kaspersky consumer-grade product Kaspersky Total Security detected a new Manuscrypt infection on the personal computer of a person living in Russia. Since Lazarus rarely attacks individuals, this piqued Kaspersky researchers interest and they decided to take a closer look. The researchers discovered that prior to the detection of Manuscrypt, Kaspersky technologies also ...

  • Taiwan: Defense ministry confirms basic data leak

    October 21, 2024

    The Ministry of National Defense today confirmed a data leak of basic personal information about certain high-ranking officials in response to a report from Chinese-language media, but said it did not include any information about personal asset holdings. The China Times this morning published a report saying that personal data of people ranked colonel and above ...

  • U.S. Investigating Intelligence Leak About Israel’s Plans for Attacking Iran

    October 20, 2024

    The U.S. is investigating the leak of top-secret American documents that show Israel military preparations for an expected strike on Iran, U.S. officials said Sunday. The two leaked reports were prepared last week by the National Geospatial-Intelligence Agency, which analyzes imagery gathered by American reconnaissance satellites and other intelligence. Neither document indicates Israel’s potential targets, and ...

  • Beyond the Surface: the evolution and expansion of the SideWinder APT group

    October 15, 2024

    SideWinder, aka T-APT-04 or RattleSnake, is one of the most prolific APT groups that began its activities in 2012 and was first publicly mentioned by us in 2018. Over the years, the group has launched attacks against high-profile entities in South and Southeast Asia. Its primary targets have been military and government entities in Pakistan, ...

  • FBI: Update on SVR Cyber Operations and Vulnerability Exploitation

    October 10, 2024

    The Federal Bureau of Investigation (FBI) and pertners are releasing this joint Cybersecurity Advisory (CSA) to highlight the tactics, techniques, and procedures (TTPs) employed by the Russian Federation’s Foreign Intelligence Service (SVR) in recent cyber operations and provide network defenders with information to help counter SVR cyber threats. Since at least 2021, Russian SVR cyber actors ...

  • How Israel harnesses technology to advance its offensive in Middle East

    October 7, 2024

    In September, thousands of pagers exploded across Lebanon in what seemed to be a sophisticated attack planned months in advance by Israel, turning the spotlight on the country’s cyber capabilities and its use of artificial intelligence (AI) in warfare. Since October 7, 2023, Israel has shown no signs of slowing down its military rampage on multiple ...

  • Japan: JMSDF set to establish a new “Fleet Information Warfare” command

    September 9, 2024

    The move would strengthen the JMSDF’s response capabilities to integrated information warfare, especially in the cognitive dimension. Most notably, the new reorganization process will abolish the current Fleet Intelligence Command (艦隊情報群), the only specialized intelligence unit in the JMSDF. The move came as part of a major organizational restructuring of the JMSDF. As Naval News reported ...

  • TIDRONE Targets Military and Satellite Industries in Taiwan

    September 6, 2024

    Since the beginning of 2024, Trend Micro have been receiving incident response cases from Taiwan. Trend Micro researchers track this unidentified threat cluster as TIDRONE. Their research reveals that the threat actors have shown significant interest in military-related industry chains, particularly in the manufacturers of drones. Furthermore, telemetry from VirusTotal indicates that the targeted countries are ...

  • Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure

    September 5, 2024

    The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and National Security Agency (NSA) assess that cyber actors affiliated with the Russian General Staff Main Intelligence Directorate (GRU) 161st Specialist Training Center (Unit 29155) are responsible for computer network operations against global targets for the purposes of espionage, sabotage, and reputational harm ...

  • ACSC chief appointed new top cyber spy

    August 26, 2024

    Australian Cyber Security Centre chief Abigail Bradshaw has been named the new director-general of the Australian Signals Directorate, replacing outgoing chief Rachel Noble. Ms Bradshaw, a former Navy officer with deep expertise in cyber, national security, crisis management and incident response roles across government, will take up the top job on September 6. Prime Minister Anthony ...

  • Pentagon contractor Leidos hit by data breach Internal documents leaked on cybercrime forum

    July 25, 2024

    Hackers have reportedly leaked internal documents stolen from Leidos Holdings Inc., a company with a significant contract portfolio including the US Defense Department, Homeland Security, and NASA. A person with knowledge of the matter told Bloomberg News that the company believes the documents leaked by hackers were stolen during a previously disclosed breach at Diligent Corporation. ...

  • Allies agree new NATO Integrated Cyber Defence Centre

    July 10, 2024

    The NATO Integrated Cyber Defence Centre (NICC) will enhance the protection of NATO and Allied networks and the use of cyberspace as an operational domain. The Centre will inform NATO military commanders on possible threats and vulnerabilities in cyberspace, including privately-owned civilian critical infrastructures necessary to support military activities. The Centre will bring together civilian and ...

  • NATO releases revised AI strategy

    July 10, 2024

    On Wednesday (10 July 2024), NATO released its revised artificial intelligence (AI) strategy, which aims to accelerate the use of AI technologies within NATO in a safe and responsible way. AI or Artificial intelligence concept. It builds on one published in 2021 and takes account of recent advances in AI technologies, such as generative AI, and ...

  • Japan: MSDF chief may quit over widespread mishandling of secret info

    July 6, 2024

    Several Maritime Self-Defense Force vessels reportedly allowed unvetted personnel to handle top secret information related to national security, with the MSDF’s top uniformed officer signaling his intention to resign over the latest breach. Ryo Sakai, the MSDF’s chief of staff since 2022, is expected to quit his post and the Defense Ministry is considering disciplinary actions ...

  • The US Wants to Integrate the Commercial Space Industry With Its Military to Prevent Cyber Attacks

    June 29, 2024

    The US military recently launched a groundbreaking initiative to strengthen ties with the commercial space industry. The aim is to integrate commercial equipment into military space operations, including satellites and other hardware. This would enhance cybersecurity for military satellites. As space becomes more important to the world’s critical infrastructure, the risk increases that hostile nation-states will ...

  • Stopping Chinese cyberattacks is officially now the biggest priority for US security forces

    June 25, 2024

    The US Department of Homeland Security (DHS) has shuffled its priorities to place battling the “cyber and other threats posed by the People’s Republic of China” at the top of the list, at least until the end of 2025. China has been conducting numerous cyber attacks against US infrastructure, particularly focussing on internet-facing endpoints within water ...