Back to news

April 9, 2024 | International, Security

Critical Flaws Leave 92,000 D-Link NAS Devices Vulnerable to Malware Attacks

Hackers are exploiting vulnerabilities (CVE-2024-3272 and CVE-2024-3273) in D-Link NAS devices. Up to 92,000 devices affected.

https://thehackernews.com/2024/04/critical-flaws-leave-92000-d-link-nas.html

On the same subject

  • Contract Awards by US Department of Defense - July 13, 2020

    July 14, 2020 | International, Aerospace, Naval, Land, C4ISR, Security

    Contract Awards by US Department of Defense - July 13, 2020

    AIR FORCE The Boeing Co., St. Louis, Missouri, has been awarded a $22,890,000,000 indefinite-delivery/indefinite-quantity contract (FA8634-20-D-2704). The first delivery order has been awarded as an undefinitized contract action with a total not-to-exceed value, including options, of $1,192,215,413. It is a cost-plus-fixed-fee, cost-plus-incentive-fee, fixed-price-incentive-fee, firm-fixed-price effort for the F-15EX system. This delivery order (FA8634-20-F-0022) provides for design, development, integration, manufacturing, test, verification, certification, delivery, sustainment and modification of F-15EX aircraft, as well as spares, support equipment, training materials, technical data and technical support. Work will be performed in St. Louis, Missouri; and at Eglin Air Force Base, Florida, and is expected to be completed Dec. 31, 2023. This award is the result of a sole-source acquisition. Fiscal 2020 research, development, test and evaluation funds in the amount of $248,224,746; and fiscal 2020 aircraft procurement funds in the amount of $53,000,000 are being obligated at the time of award. Air Force Life Cycle Management Center, Wright-Patterson AFB, Ohio, is the contracting activity. Filius Corp., Centreville, Virginia, has been awarded a $70,617,597 indefinite-delivery/indefinite-quantity, firm-fixed-price contract for the AN/TYQ-23A (V)1 Tactical Air Operations Module weapons system logistics support. The contractor will provide all labor, tools, equipment, technical data/manuals, materials, supplies, parts, original equipment manufacturer (OEM) service bulletins and services necessary to perform contractor logistics support on TYQ-23A (V)1 in accordance with OEM standards (commercial standards if third party is performing service/repair), including software/firmware upgrades. This support will also include emergency and preventative maintenance for any future technologies designed to be implemented in the TYQ-23A. Work will be performed in Centreville, Virginia, and is expected to be completed July 2025. This award is the result of a competitive acquisition with five offers received. Fiscal 2020 operations and maintenance funds in the amount of $2,300,000 are being obligated at the time of award. Air Force Life Cycle Management Center, Hill Air Force Base, Utah, is the contracting activity (FA8217-20-D-0005). Renco Corp., Manchester, Massachusetts, has been awarded a not-to-exceed $22,400,000 undefinitized contract action for capacity expansion of Nitrile beutadine rubber (NBR) gloves production for the Department of Health and Human Services in care of the Joint Acquisition Task Force. This contract provides for the procurement of raw NBR materials, dipping lines, storage tanks, storage equipment, roofing repairs, lighting, loading docks, water treatment, solar roofs and a remote facility to be determined at a later date in the south central part of the U.S. in order to bring an industrial base and to replenish the strategic national stockpile of Nitrile produced rubber gloves back to the U.S. Work will be performed in Colebrook, New Hampshire, and is expected to be completed July 14, 2021. This award is the result of a sole-source acquisition. Fiscal 2020 other procurement funds in the amount of $22,400,000 are being obligated at the time of award. Air Force Life Cycle Management Center, Robins Air Force Base, Georgia, is the contracting activity (FA8527-20-C-0005). NAVY Blue Rock Structures Inc.,* Pollocksville, North Carolina (N40085-16-D-6300); Daniels & Daniels Construction Co. Inc.,* Goldsboro, North Carolina (N40085-16-D-6301); Joyce & Associates Construction Inc.,* Newport, North Carolina (N40085-16-D-6302); Military & Federal Construction Co. Inc.,* Jacksonville, North Carolina (N40085-16-D-6303); Quadrant Construction Inc.,* Jacksonville, North Carolina (N40085-16-D-6304); and TE Davis Construction Co.,* Jacksonville, North Carolina (N40085-16-D-6305), are awarded a $90,000,000 firm-fixed-price modification to increase the maximum dollar value of indefinite-delivery/indefinite-quantity, multiple award construction contracts for general construction services within the Marine Corps Installations East area of responsibility. After award of this modification, the total maximum dollar value for all six contracts combined will be $339,000,000. Work will be performed at Navy and Marine Corps installations at various locations including, but not limited to, North Carolina (90%); Georgia (3%); South Carolina (3%); Virginia (3%); and other areas of the U.S. (1%). The work to be performed provides for general construction services including, but not limited to, new construction, demolition, repair, alteration and renovation (total/partial/interior/exterior) of buildings, systems and infrastructure, which may include civil, structural, mechanical, electrical and communication systems; installation of new or extensions to existing high voltage electrical distribution systems; extensions to the existing high pressure steam distribution systems, potable water distribution systems and sanitary sewer systems; additional storm water control systems; painting; removal of asbestos materials and lead paint; and incidental related work. Work is expected to be completed by December 2020. No funds will be obligated at the time of award; funds will be obligated on individual task orders as they are issued. Future task orders will be primarily funded by operations and maintenance (Marine Corps); and military construction funds (Marine Corps). The Naval Facilities Engineering Command Mid-Atlantic, Norfolk, Virginia, is the contracting activity. Huntington Ingalls Inc., Newport News, Virginia, is awarded a $35,346,618 cost-plus-fixed-fee, firm-fixed-price modification to a previously awarded contract (N00024-16-C-4316) to continue performance of the repair, maintenance, upgrades and modernization efforts on the USS Helena (SSN 725) dry-docking selected restricted availability (DSRA). Work will be performed in Newport News, Virginia. The contracted requirements include advance and new work efforts necessary to repair, and maintain full unrestricted operation of the submarine, as well as upgrades and modernization efforts required to ensure the submarine is operating at full technical capacity as defined in the availability work package during the Chief of Naval Operations scheduled availability. Work is expected to be completed by October 2020. Fiscal 2020 operations and maintenance (Navy) funding in the amount of $35,346,618 will be obligated at time of award and will expire at the end of the current fiscal year. In accordance with 10 U.S. Code 2304(c)(1), this contract was not competitively procure; only one responsible source and no other supplies or services will satisfy agency requirement. The Supervisor of Shipbuilding, Conversion and Repair, USN, Newport News, Virginia, is the contracting activity. L3 Technologies Inc., Camden, New Jersey, is awarded a $34,999,948 fixed-price-incentive-firm-target contract for the detail design and fabrication of a prototype Medium Unmanned Surface Vehicle (MUSV). This contract includes options for up to eight additional MUSVs, logistics packages, engineering support, technical data, and other direct costs, which, if exercised, will bring the cumulative value of this contract to $281,435,446. Work will be performed in Morgan City, Louisiana (72.7%); Arlington, Virginia (9.8%); Jeanerette, Louisiana (8.1%); New Orleans, Louisiana (6.6%); Worthington, Ohio (1.7%); Lafayette, Louisiana (0.9 %); and Gautier, Mississippi (0.2%), and is expected to be completed by December 2022. If all options are exercised, work will continue through June 2027. Fiscal 2019 and 2020 research, development, test and evaluation funding in the amount of $34,999,948 will be obligated at the time of award, and $29,779,038 will expire at the end of the current fiscal year. This contract was competitively procured via Federal Business Opportunities (now beta.SAM.gov), and five offers were received. The Naval Sea Systems Command, Washington, D.C., is the contracting activity (N00024-20-C-6312). Northrop Grumman Systems Corp., Linthicum, Maryland, is awarded an $11,300,000 not-to-exceed, cost-plus fixed-fee contract for the procurement of transitional development and sustaining engineering services for the Ground/Air Task-Oriented Radar (G/ATOR), to include software support activity transition, low/slow/small capability development and ground weapons locating radar improvements. The G/ATOR program is managed within the portfolio of Program Executive Officer Land Systems, Quantico, Virginia. Work will be performed in Linthicum, Maryland, and is expected to be completed by July 2021. Fiscal 2020 research, development, test and evaluation (Marine Corps) funds in the amount of $2,217,296; and fiscal 2020 operations and maintenance (Marine Corps) funds in the amount of $3,000,000 will be obligated at the time of award. Funds will not expire at the end of the current fiscal year. This contract was not competitively procured and was prepared in accordance with Federal Acquisition Regulation 6.302-1 and 10 U.S. Code 2304(c)(1). The Marine Corps Systems Command, Quantico, Virginia, is the contracting activity. General Dynamics Electric Boat, Groton, Connecticut, is awarded an $8,127,069 modification under previously awarded contract N00024-16-C-2111 to perform alterations during the USS South Dakota (SSN 790) post-delivery work period. Work will be performed in Groton, Connecticut. General Dynamics Electric Boat will perform planning and execution efforts on SSN 790, USS South Dakota. Work is expected to be completed by December 2020. No funding will be obligated at time of award. The Supervisor of Shipbuilding Conversion and Repair, Groton, Connecticut, is the contracting activity. General Dynamics Electric Boat, Groton, Connecticut, is awarded a $7,829,633 modification under previously awarded contract N00024-16-C-2111 to perform alterations during the USS South Dakota (SSN 790) post-delivery work period. Work will be performed in Groton, Connecticut. General Dynamics Electric Boat will perform planning and execution efforts on SSN 790, USS South Dakota. Work is expected to be completed by December 2020. No funding will be obligated at time of award. The Supervisor of Shipbuilding Conversion and Repair, Groton, Connecticut, is the contracting activity. General Dynamics Electric Boat Corp., Groton, Connecticut, is awarded a $7,765,664 cost-plus-fixed-fee modification to a previously awarded contract (N00024-09-C-2104) for planning and execution of USS Delaware (SSN 791) post delivery work period (PDWP). Work will be performed in Groton, Connecticut. Electric Boat Corp. will perform planning and execution efforts, including long lead time material procurement, in preparation to accomplish the maintenance, repair, alterations, testing, and other work on USS Delaware (SSN 791) during its scheduled PDWP. Work is expected to be completed by October 2020. Fiscal 2020 shipbuilding and conversion (Navy) funding in the amount of $7,765,664 will be obligated at the time of award and will not expire at the end of the current fiscal year. The Supervisor of Shipbuilding Conversion and Repair, Groton, Connecticut, is the contracting activity. DEFENSE LOGISTICS AGENCY Hikma Pharmaceuticals USA Inc., Eatontown, New Jersey, has been awarded a maximum $42,907,336 fixed-price with economic-price-adjustment, indefinite-delivery/indefinite-quantity contract for various pharmaceutical products. This was a competitive acquisition with one response received. This is a one-year base contract with nine one-year option periods. Location of performance is New Jersey, with a July 12, 2021, ordering period end date. Using customers are Army, Navy, Air Force, Marine Corps and federal civilian agencies. Type of appropriation is fiscal 2020 through 2021 Warstopper funds. The contracting activity is the Defense Logistics Agency Troop Support, Philadelphia, Pennsylvania (SPE2D0-20-D-0006). ARMY Mathy Construction Co., Onalaska, Wisconsin, was awarded an $8,870,763 modification (P00002) to contract W911SA-19-D-2018 for asphalt paving at Fort McCoy. Work will be performed at Fort McCoy, Wisconsin, with an estimated completion date of July 14, 2022. Bids were solicited via the internet with one received. The U.S. Army 419th Contracting Support Brigade, Fort McCoy, Wisconsin, is the contracting activity. Northrop Grumman Systems Corp., Herndon, Virginia, was awarded a $7,845,596 hybrid (cost-no-fee, firm-fixed-price) contract to provide U.S. Forces Korea with information technology, architecture and engineering, command and control networks and associated systems support services. Bids were solicited via the internet with five received. Work will be performed in Pyongtaek, South Korea, with an estimated completion date of July 31, 2025. The 411th Contracting Support Brigade, Camp Red Cloud, South Korea, is the contracting activity (W91QVN-20-F-0440). *Small Business https://www.defense.gov/Newsroom/Contracts/Contract/Article/2272447/source/GovDelivery/

  • How the Army will plan cyber and electronic warfare operations

    June 21, 2018 | International, C4ISR

    How the Army will plan cyber and electronic warfare operations

    Mark Pomerleau   With cyber playing a critical role in conflict going forward, the Army has begun to recognize the need to have organic cyber planners within a brigade's staff to offer commanders options related to cyber as well as electronic warfare. Cyber and Electromagnetic Activities, or CEMA cells, have been stood up in each brigade acting as planners to provide targeting options and capabilities to get at commander objectives just as an artillery planner would offer the commander choices related to their field for a pending operation. At the tactical level, these two disciplines – cyber and electronic warfare – have become intertwined. “When I talk to Army commanders and staffs, I try to make the point that I want you to worry less about whether it's a cyber or EW effect,” Lt. Col. Christopher Walls, deputy director for strategy and policy, at the Army's Cyber Directorate within the G-3/5/7, said at the C4ISRNET Conference in May. For example, Walls said for a river crossing mission, a commander might say he needs to buy a few hours to get a battalion across. The CEMA cell, in turn, would look across the capability sets in its portfolio and come up with a course of action. These cells potentially have the ability to allow the commander to target local internet service providers or local routers and prevent opposing forces from using them. The teams may also have an electronic warfare capability that can jam local area network protocols. Finally, these teams might know where mobile switching centers are by digitally geolocating them allowing physical strikes to take them out, Walls said. “I don't want the commander to worry about which of those three things, I just want him to talk to me in terms of desired objective and effects and then us, along with the staff, will determine which capability makes sense,” Walls said. “That's kind of the way we're thinking about the tactical fight.” The best choice comes down to understanding the commander's objectives and intent in order to offer the best solution. “What I would do is understand his intent, what effect he wants and what I'll do is submit that in a formal request and I'll let the higher echelons determine if they can provide that effect,” Capt. Daniel Oconer, brigade CEMA officer, told C4ISRNET during a recent visit to the National Training Center. “In general, all I really need to know for my planning processes is understand what the maneuver force wants to do,” he added. “How do tanks and Bradleys [move], how are the troops on the ground moving. Then, what is their mission? What is their objective? What is the commander's intent? Once I understand that I throw some CEMA flavor, so to say, onto it and then enable them to accomplish their mission.” Oconer is currently billeted as a 29 series electronic warfare officer. The Army will begin to transition these individuals into the cyber branch, or 17 series, so they will all eventually be cyber planners in the CEMA cell. “The way that we're transforming our electronic warfare professionals is they will become cyber operators. They will be the face inside our brigade combat teams and our maneuver formations for cyber operational planning,” Maj. Gen. John Morrison, commander of the Cyber Center of Excellence, said during a May speech. “They're complimentary. You cannot look at electronic warfare professionals and cyber operators in isolation.” https://www.c4isrnet.com/electronic-warfare/2018/06/20/how-the-army-will-plan-cyber-and-electronic-warfare-operations/

  • How U.S. Open Skies Exit Could Undermine Arms Control

    May 28, 2020 | International, Aerospace

    How U.S. Open Skies Exit Could Undermine Arms Control

    Tony Osborne Jen DiMascio May 28, 2020 The decision by the U.S. government to withdraw from the Open Skies Treaty signed two decades ago is creating ripples of discontent within the U.S. and in Europe. Washington announced on May 22 that it would end its obligations to the arms control treaty in six months, saying that it was “no longer in the United States' best interest to remain a party to this Treaty when Russia does not uphold its commitments,” in a statement put out by the Defense Department. The Open Skies Treaty permits its 34 signatories to conduct observation flights over each other's territory. Aircraft with four types of sensors—-optical panoramic and framing cameras, real-time video cameras, infrared line-scanners and sideways-looking synthetic aperture radar—may make observations anywhere over a country's national territory. Treaty rules say that the flight may only be restricted for reasons of flight safety, not for reasons of national security. NATO and European nations may share U.S. concerns about inconsistent flight restrictions imposed by Moscow but see a U.S. departure from the agreement, in place since 1992, as regrettable. According to the U.S. and NATO, Russia has imposed restrictions on the treaty, in particular those flying near Kaliningrad, Russia's enclave on the Baltic Sea, and near the country's border with Georgia. The Pentagon also says Moscow blocked the overflight of a major military exercise in September 2019, “preventing the exact transparency the treaty is meant to provide.” In an op-ed in The New York Times, Tim Morrison, a senior fellow at the Hudson Institute and a former member of this administration's National Security Council, added that Russia has been using its overflights to collect “military relevant intelligence on the other parties, like the means to target critical infrastructure.” NATO Secretary General Jens Stoltenberg, during the May 22 meeting of alliance members, called on the Russian government to return to compliance as soon as possible, noting that the U.S. could reconsider its position if Russia complied. European Open Skies Treaty member states—including Belgium, the Czech Republic, Finland, France, Germany, Italy, Luxembourg, Netherlands, Spain and Sweden—said they would continue to implement the treaty, saying it has a “clear added value” for conventional arms control architecture and cooperative security. Russia rejects the claims of flight restrictions and contends that the U.S. had limited Russia's own Open Skies flights over Hawaii and the Aleutian Islands. Senior Russian officials, including Dmitry Medvedev, deputy chairman of the Russian Security Council, denounced Washington's decision. Medvedev said the U.S. had taken another step down the “path of dismantling the international security architecture that took decades to lay down.” Moscow believes Washington's decision could also affect other arms control treaties, with negotiations on the next New Strategic Arms Reduction Treaty potentially at risk. In Washington, the leaders of the House Armed Services and Foreign Affairs committees (both Democrats) have written a letter to Defense Secretary Mark Esper and Secretary of State Mike Pompeo contending that withdrawal from the treaty is illegal. They say it violates the fiscal 2020 National Defense Authorization Act, which requires Esper and Pompeo to notify Congress 120 days before the intent to withdrawal is presented. “This notification must be based on your joint conclusion that withdrawal is in the best interests of the United States and that other states parties to the treaty have been consulted. To date, this requirement has not been fulfilled,” wrote Reps. Adam Smith (Wash.), the Armed Services chairman, and Eliot Engel (N.Y.), the Foreign Affairs chairman. President Donald Trump and his administration have support from Repub-licans who lead the Senate for their decision to exit the treaty. Sen. James Inhofe (R-Okla.), who chairs the Senate Armed Services Committee, asserts that the U.S. should withdraw if Russia is not complying with the agreement. “It will be critical for the Trump administration to continue working with our allies and partners, especially those in Eastern Europe, to ensure they have access to the intelligence they need to protect their security. That includes facilitating access to high-quality imagery.” The U.S. had planned to upgrade the two Boeing OC-135 aircraft delivered to the Air Force in 1996. Late last year, the U.S. issued a request for information saying it was considering awarding two contracts—one for the purchase of two commercial aircraft and another to modify the airframe and provide logistics support. But the Pentagon did not include funding for OC-135 upgrades in its fiscal 2020 budget request. And in March, Esper told Congress he was not prepared to authorize funding for those upgrades until a path forward is clear. Several signatories to the treaty have dedicated aircraft for the mission; others share or lease platforms from other nations for the task. Germany is the latest country to dedicate an aircraft for the mission, using an Airbus A319 converted by Lufthansa Technik. https://aviationweek.com/defense-space/budget-policy-operations/how-us-open-skies-exit-could-undermine-arms-control

All news