Back to news

August 29, 2024 | International, C4ISR, Security

Vietnamese Human Rights Group Targeted in Multi-Year Cyberattack by APT32

Vietnamese human rights group targeted by APT32 hackers in multi-year campaign. Malware used to compromise systems and steal data.

On the same subject

  • NATO advances in its new operational domain: cyberspace

    July 6, 2018 | International, C4ISR

    NATO advances in its new operational domain: cyberspace

    By: Sorin Ducaru As NATO prepares for its annual summit, to be held July 11-12 in Brussels, media attention has been focused on whether member states will boost their defense spending and readiness across the traditional operational domains of land, air and sea. This reflects a needed focus on important, but frankly longstanding alliance priorities. What many NATO-watchers are missing, however, is NATO's full embrace of its newest operational domain: cyberspace. Just two years ago, at the Warsaw Summit, allied nations recognized cyberspace as a new “operational domain in which NATO must defend itself as effectively as it does in the air, on land and at sea.” Since the Warsaw Summit, NATO has developed an ambitious roadmap to implement the cyber operational domain approach, with profound implications along lines of effort, such as: training, capability development, organizational construct, operational planning, training, exercises and strategic communications. Work in these areas is conducted with the aim to augment the cyber resilience and achieve mission success, in a cyber environment that is increasingly contested by adversaries. This is in line with the alliance's cyber pledge to prioritize investment in cyber skills and capabilities. Furthermore, the recognition of cyberspace as an operational domain opens the way for the integration of voluntary sovereign national cyber contributions into NATO operations and missions. Keeping in line with the other operational domains, NATO itself will not acquire offensive capabilities, but will rely on the contributions of its member nations. Already, the United Kingdom has led the efforts. In a Chatham House address last year, Sir Michael Fallon, former U.K. defense secretary, announced publicly that “the United Kingdom is ready to become one of the first NATO members to publicly offer such support to NATO operations as and when required.” At the NATO defense ministers' meeting last November, allies agreed on a framework of political and legal principles to guide the integration of voluntary cyber contributions from member nations. The framework ensures that any allied engagement in cyberspace will abide by NATO's defensive mandate, political oversight and compliance with international law. This is also in line with allies' support for the development of norms and confidence building measures, for security and stability in cyberspace. This year, allies' defense ministers agreed to establish a Cyber Operations Centre as part of the new NATO command structure, the first cyber-dedicated entity within NATO's command structure. This is the first step toward integrating cyber capabilities into NATO planning and operations, but specific considerations should be kept in mind. In the physical domains of land, air and sea, operational planning refers to of the physical forces or capabilities provided. In the cyber domain, integration will focus on the effects generated by the voluntary national cyber contributions, rather than the capabilities themselves, given that most cyber tools are unique and discrete. Within NATO, there has been a growing emphasis on developing the “digital IQ” of the allied military. In Portugal, a NATO Cyber and Communication-Information Systems Academy is being set-up, while cyber resilience is now featured in coordinated training curricula in every NATO member state. Cyber has been also streamlined across all NATO exercises. The NATO Cyber Center of Excellence in Estonia organizes two annual cyber-dedicated exercises. The first, “Cyber Coalition,” is testing the alliances readiness and response procedures and policies in situations of wide-reaching, persistent cyberattacks. The second exercise, under the Locked Shields banner, tests the skills of cyber experts in red-team/blue-team war games scenarios. This year, NATO's blue team won the exercises, signaling the growing interest of member nations to strengthen NATO's new operational domain. “All crises today have a cyber dimension,” noted Secretary General Jens Stoltenberg earlier this month. Soon after in London, Stoltenberg hinted that the July NATO summit will “take decisions on integrating national cyber capabilities into NATO operations.” This reflects a game-changing approach in terms of mainstreaming cyber across strategy and tactics, training and exercises, as well as military planning in all operational domains. This is consistent with the recent U.S. Department of Defense strategy, which aims to “invest in cyber defense, resilience and the continued integration of cyber capabilities into the full spectrum of military operations.” It is no secret that, in cyberspace, we are under attack as we speak. As the threat landscape expands, so does NATO's commitment to the new cyber operational domain. Ambassador Sorin Ducaru is a senior fellow at the Hudson Institute. Between September 2013 and November 2017, he was NATO assistant secretary general and chair of NATO's Cyber Defense Committee and Cyber Defense Management Board, having a leading role in NATO's cyber policy development and implementation. He is also a special advisor of the Global Commission on the Stability of Cyberspace.

  • Robust cryptographic policies will help save military software systems

    November 15, 2022 | International, C4ISR

    Robust cryptographic policies will help save military software systems

    How can we build resilient software systems out of unreliable parts?

  • Drones are now a permanent part of the LAPD’s arsenal

    September 20, 2019 | International, Aerospace, Security

    Drones are now a permanent part of the LAPD’s arsenal

    By CINDY CHANG Drones became a permanent part of the Los Angeles Police Department's crime-fighting arsenal Tuesday, despite opposition from privacy advocates who fear the remote-controlled aircraft will be used to spy on people. In a yearlong trial, the LAPD's SWAT team deployed drones four times, mostly when suspects were barricaded and the device provided a bird's eye view of the property's nooks and crannies. On Tuesday, the five-member civilian Police Commission unanimously approved new regulations that enshrine the drones' use in specific situations, including active shooters, barricaded suspects and search warrants. The drones will not be equipped with weapons or facial recognition software, according to the regulations, which are similar to those governing the trial program. In July, at Chief Michel Moore's recommendation, the use of drones was expanded beyond SWAT to include the bomb squad in neutralizing explosives and sweeping large public events for radioactive devices. Drones “provide invaluable information to decision makers while decreasing the risk to human life,” Moore wrote in a July 3 report, noting that everyone is safer when the devices check out a dangerous situation instead of officers going in blind. The LAPD joins about 600 other law enforcement agencies around the country that use drones, according to a 2018 report by Bard College's Center For the Study of the Drone. The new regulations will ensure that the drones are not “being used in a flippant manner,” Asst. Chief Horace Frank, who runs the department's counter-terrorism and special operations bureau, told the Police Commission on Tuesday. The LAPD's drone regulations are more restrictive than those of many other agencies, Frank said. Each drone deployment must be approved by a commander and a deputy chief, and the Police Commission will receive an annual report. Asked by Commissioner Eileen Decker whether drones can help de-escalate volatile situations, Frank cited a June 15 incident when a drone flew near a man who had barricaded himself in a trucking yard. “The minute we deployed the device at the entrance to the trailer and he saw it, he gave up,” Frank said. Activists said the LAPD and Police Commission have disregarded citizens who expressed reservations about the drones in community meetings and online surveys. One activist, Michael Novick, predicted that the LAPD would expand drone usage and infringe on civil liberties. “We're witnessing the exact definition of mission creep,” Novick said. “Now you're upgrading. You approved a temporary pilot project. You're going to normalize it with this step. ... The next step will be they'll come back and say, ‘We actually need the ability to have facial recognition.'” The LAPD's drone fleet will remain at four strong, Frank said. But the DJI Spark devices used in the pilot program will be replaced by DJI Mavics, which have better indoor flying capabilities, extended flight time and lights for navigating in the dark. The models are similar to those used by hobbyists. The Police Commission accepted a $6,645 donation from the Los Angeles Police Foundation to purchase the Mavics, as well as a donation of drone flight tracking software from Measure Aerial Intelligence. As the commission approved the drone regulations and donations, the audience broke into chants of “Shame! Shame!” Moore said he is mindful of “concerns of Big Brother and invasion of privacy and civil liberties.” “We're committed to striking the right balance that ... protects all of our community — their rights of privacy but also their public safety and their right to exist without threats of dangers that this tool can be used in some instances to mitigate,” he told reporters after the meeting.

All news