Wednesday, July 1, 2009

GCHQ Takes Lead on UK Gov IT Security Training

Via ZDNet UK -

In the past, all government IT security training has been the charge of the Cabinet Office, through the office of the Central Sponsor for Information Assurance (CSIA). However, GCHQ said on Tuesday that its National Technical Authority for Information Assurance arm, known as CESG, will take on the role of co-ordinating the training effort.

"CESG will develop the content for information assurance education and training, and will approve service providers for its delivery, in consultation with the CSIA," GCHQ told ZDNet UK in an email exchange.

However, the Cabinet Office will continue to have strategic oversight of the training, the agency added.

The information assurance training covers such areas as data protection, security good practice and how to harden IT systems. As its scope covers both government agencies and their industry partners, the task is "substantial", GCHQ said.

To deal with the amount of training needed, CESG will certify training programmes offered by the security industry so public-sector bodies and their business partners can use these.

"CESG is looking to quality-assure training and education programmes through industry partners and in collaboration with government departments," GCHQ said. "To meet the volume, we anticipate that all forms of training will be used, from traditional training in classrooms to e-learning packages, workshops and seminars."

Training materials will in part be gathered by harvesting 'good practice' from the public sector, via workshops involving government agencies. One of these workshops has already taken place, on 14 May, GCHQ said. "Twelve different government departments were represented [at the workshop], including the Department for Work and Pensions, the Home Office, HM Revenue & Customs, and the National Policing Improvements Agency," the agency said.

The agency also intends to feed information security knowledge from private-sector sources into the training. However, CESG will not take on any training role for the private sector, GCHQ said.

"[Information assurance] professionalism across the private sector is addressed by the Institute of Information Security Professionals," said GCHQ. "[Information assurance] and information security good practice for the private sector is handled by the department for Business, Innovation and Skills. CESG supports government customers and those private-sector organisations delivering information services to those customers."

The expansion in CESG's role comes at a time when GCHQ is taking on more responsibilities in general. As part of the government's Cyber Security Strategy, a Cyber Security Operations Centre is being set up in Cheltenham to co-ordinate UK systems infrastructure defence and attack capabilities.

Suspect North Korean Ship Changes Course Under US Scrutiny

Via GlobalSecurity.org -

A North Korean cargo ship being closely tailed by the United States Navy appears to be changing course, and may be returning to North Korea. The ship has come to be seen as an initial test of new United Nations restrictions on Pyongyang.

U.S. officials say the Kang Nam, a North Korean cargo ship, is apparently abandoning the course it has been on for a week toward Southeast Asia, and may now be headed back home.

The ship, which intelligence officials describe as having a history of transporting North Korean weapons for sale, was believed to have been headed toward Burma. A U.S. Navy destroyer group began tracking the ship about a week ago under suspicion it may be carrying items banned under a recently passed United Nations Security Council Resolution.

The ship was expected to refuel in Singapore, where the government had promised what it called "appropriate action" under the U.N. resolution. Park Seung-jae, an analyst with the Asia Strategy Institute in Seoul, says that may have helped change Pyongyang's mind about the voyage.

"When they (North Korea) go through Singapore, they cannot ignore inspection from Singapore. Also, on the other hand, it may be very difficult for them to throw out weapons or nuclear equipment on the sea," said Park.

Park says if the ship does return to the North, it will bolster the impression that international sanctions against Pyongyang are effective. He says the United States and its partners will need to maintain close scrutiny of the North's shipping.

"North Korean ships in Myanmar and Iran will be the first priority to watch," he said.

Weapons sales are an important source of hard currency for North Korea, one of the most economically isolated and impoverished nations in the world. Washington also fears Pyongyang may attempt to cash in on its nuclear programs by selling equipment, technology, or even fissile material to nations or groups hostile to the United States.

U.N. Security Council Resolution 1874, passed in response to North Korea's nuclear test in May, authorizes member states to inspect the North's ships in their ports or territory.

North Korea has said on several recent occasions it would view any attempt to stop and inspect its ships by the United States or South Korea as an act of war, and retaliate accordingly. Pyongyang's official Rodong Sinmun newspaper extended that threat to Japan Wednesday, saying "responsibility for all consequences" of military action would rest will Tokyo if it attempted an inspection.

Month of Twitter Bugs (MoTB) Begins

Aviv Raff has launched the Month of Twitter Bugs (MoTB).

-------------------------------

MoTB #01: Multiple vulnerabilities in bit.ly service

http://www.twitpwn.com/

-------------------------------

Luckily, all of the vulnerabilities released in MoTB #01 has been patched, but tomorrow is another day. =)

Cigarette and Tobacco Smuggling Finances Terrorism Worldwide

Via SecurityManagement.com -

A new report from the Center for Public Integrity, an investigative journalism outfit, details how terrorists and insurgencies the world over have smuggled cigarettes to finance their organizations and their missions.

CPI's investigation concentrates on seven groups which range from Marxist insurgencies to jihadist terrorists and from republican terrorists to profit-driven Congolese rebels.

After crackdowns on fundraising following the 9/11 attacks, terrorist groups worldwide have increasingly turned to criminal rackets, officials say. And smuggling cigarettes — either untaxed or counterfeit — has proved a particularly lucrative, low-risk way to fund operations.

Hezbollah, the Taliban, and al-Qaeda are involved in smuggling cigarettes; so are the Real Irish Republican Army (Real IRA) and the Kurdistan Workers’ Party (PKK). Terrorist financing through cigarette smuggling is “huge,” says Louise Shelley, a transnational crime expert at George Mason University and an adviser to the World Economic Forum on illicit trade. “Worldwide — it’s no exaggeration… No one thinks cigarette smuggling is too serious, so law enforcement doesn’t spend resources to go after it.”

“Cigarettes are easy to smuggle, easy to buy, and they have a pretty good return on the investment,” adds David Cid, a former FBI counterterrorism agent and deputy director of the Memorial Institute for the Prevention of Terrorism in Oklahoma City. “Drug dogs don’t alert on your car if it’s full of Camels.” And, he notes, “The other advantage is you don’t go to jail for 50 years.”

Trafficking stolen and counterfeit cigarettes has unwittingly become a lucrative venture for terrorist and militant organizations because of the hefty taxation on tobacco,
such as in the state of New York. According to CPI, it costs $100,000 to produce 10 million cigarettes in China, which can reap revenues as high as $2 million in the United States. When you consider the relative cheapness of terrorist operations, 9-11 only cost Al Qaeda about $500,000 to pull off, profit margins like these are enormously attractive to terrorists and militant groups.

But stopping the nexus between cigarette smuggling and terrorist financing is possible, reports CPI.

“You need to ensure that the products are being sold through legitimate channels through legitimate distributors — that they’re not committing willful blindness,” Larry Johnson, a terrorism and criminal finance investigator for BERG Associates, told CPI. “The contraband is fairly easy to deal with because it’s in the power of the distributors and producers to control the process. This is actually one of those few problems that is fixable.”

For more on the report and the relationship between terrorism financing and tobacco smuggling, see this article from the Agence France Presse.

For a short film on how taxes created an explosion in black market cigarettes in New York, watch the below from the CPI.

http://www.youtube.com/watch?v=5e9ZBcSexyw

Tuesday, June 30, 2009

South Korea: North is Enriching Uranium

Via VOA News -

South Korea's defense minister says North Korea appears to be pushing forward with a uranium enrichment program, raising fears that it may use the material to make atomic weapons.

Addressing a hearing of lawmakers Tuesday, Lee Sang-hee said it is clear that North Korea is moving forward with the program. He added that such a program is far easier to hide than the North's current plutonium-based program.

North Korea has ample supplies of natural uranium, and it could conduct an enrichment program in underground or undisclosed facilities, away from the view of U.S. spy satellites.

Earlier this month, after the United Nations placed more sanctions on North Korea for carrying out its second nuclear test in May, Pyongyang said it would start enriching uranium.

----------------------------

Today, The United States on Tuesday added two more companies to its lists of firms facing sanctions for allegedly aiding North Korea's nuclear and missile programs. One company is in North Korea and the other is described as a North Korean front-company based in Iran.

StopBadware.org, Sunbelt Software Partner to Fight Badware

Via StopBadWare.org -

StopBadware.org, the collaborative initiative to combat viruses, spyware, and other bad software, announced today that Sunbelt Software, developer of the VIPRE anti-malware product line, will participate in the effort as a data partner. Sunbelt Software joins Google in contributing data to the project, which is based at Harvard University’s Berkman Center for Internet & Society. The initiative is funded by Google, PayPal, Mozilla, AOL, and Trend Micro.

[...]

StopBadware.org collects the URLs of these badware websites, whether malicious or compromised, from its data partners. It uses the information to support and encourage site owners and web hosting companies in cleaning up and protecting their sites. The initiative also conducts analysis of infection trends, offers independent reviews of its partners’ findings, and operates a community website, BadwareBusters.org, that provides help to people who have been victims—or wish to avoid becoming victims—of badware.

“We are thrilled that a well-respected anti-malware company like Sunbelt Software has come on board as a data partner,” said Maxim Weinstein, manager of StopBadware.org. “The new data offers us a different view of the badware website landscape and will help us to extend our reach and to provide richer analysis.”

Sunbelt Software’s director of malware research, Eric Howes, has been an advisor to StopBadware.org since early in its development, but the data partnership represents the first time the company has established an official relationship with the project.

“Sunbelt Software has always encouraged a collaborative approach to addressing the malware problem,” said Eric Howes. “We are pleased to formalize our ongoing relationship with StopBadware and support the important work it does in educating the public and the industry.”

Sunbelt will provide research data via ThreatTrack™, a comprehensive array of malicious url and malware data feeds. The data in these feeds is derived from multiple sources including: research from Sunbelt Labs; ThreatNet™, Sunbelt’sVIPRE user community that anonymously sends information on potential threats to Sunbelt Labs; and Sunbelt CWSandbox, the leading automated malware behavior analysis tool for fast and autonomous analysis of large volumes of malware samples.

This morning, StopBadware.org launched a new, richer report interface—integrating the new Sunbelt Software data—to its searchable Badware Website Clearinghouse. The new reports allow security researchers, law enforcement, site owners, and other interested parties to see a site’s current and past badware activity, along with basic information about the site. Future enhancements are expected to provide insight into the concentration of badware sites on particular networks.

Pirate Bay Site Sold, Going to Legal Business Model

Via BBC -

Global Gaming Factory (GGF) has paid 60m kronor (£4.7m) to take over the site from its founders.

Once it has taken control, GGF said it would start paying copyright fees for the movies, music and games linked to via the site.

In April, The Pirate Bay owners were found guilty of promoting copyright infringement, fined 30m kronor and were sentenced to one year in jail.

The four men behind the site, Frederik Neij, Gottfrid Svartholm Warg, Carl Lundstrom and Peter Sunde, said they planned to appeal against the sentence.

The Pirate Bay is one of the most well-known file-sharing sites on the web. Many people use it to find copyrighted material such as TV shows, games and music tracks. The Pirate Bay does not host any of the pirated material itself.

"We feel that we can't take The Pirate Bay any further," Mr Sunde told the Swedish news agency TT. "We're in a bit of a frozen situation where there's not much happening and there are neither people nor money to develop things."

Half the money GGF will pay for the site will be in cash and the remainder in shares in the company.

"We would like to introduce models which entail that content providers and copyright owners get paid for content that is downloaded via the site" said Hans Pandeya, head of GGF in a statement.

"Content creators and providers need to control their content and get paid for it," he said.

GGF has not released details of how it will charge for the content downloaded via the site. The Pirate Bay will be handed over to GGF in August.

It is not clear how the deal affects the Video Bay - a video-sharing site set up by the people behind The Pirate Bay.

GGF specialises in software that helps run and maintain PCs used in cyber cafes and gaming centres.

-----------------------

Check out TorrentFreak for updates...as it could be days (or even longer) before we know what is really going to happen.

China Puts Indefinite Delay on 'Green Dam' Mandate

Via InformationWeek -

China has postponed its requirement that all PCs sold in the country include Web filtering software known as Green Dam.

According to a post on the Web site of the state-controlled news agency Xinhua, China's Ministry of Industry and Information Technology (MIIT) said late Tuesday that the pre-installation requirement would be delayed because computer makers wanted more time for such a massive undertaking.

Although Mindtouch CEO Aaron Fulkerson does a good job listing the major points that his company's namesake product (available as a service too) touches on in this reviewcam, it's also one of those products that's difficult to describe. Three guys, three pints of beer, and random truths about green tech, Web video, telepresence, and avatars InformationWeek's Mitch Wagner demonstrates how to "get good" at Twitter.

Although Mindtouch CEO Aaron Fulkerson does a good job listing the major points that his company's namesake product (available as a service too) touches on in this reviewcam, it's also one of those products that's difficult to describe.

The MIIT had set July 1 as a deadline and some computer manufacturers have already begun complying with the order. Sony has started shipping PCs with Green Dam, accompanied by disclaimer about the risks posed by the software. Acer has reportedly expresses its intent to comply.

No new deadline was disclosed, leaving open the possibility that China might decide to abandon the filtering requirement.

The MIIT said that it would continue to provide Green Dam as a free download for users who wanted it, and would install the software on computers in schools and public Internet cafes. It intends to "keep on soliciting opinions to perfect the pre-installation plan," the Xinhua News Agency said.

Exploiting MS Advisory 971778 - QuickTime DirectShow Vulnerability

Via Tipping Point DVLabs (Aaron Portnoy) -

On May 28th, 2009 Microsoft released MS Security Advisory 971778 titled Vulnerability in Microsoft DirectShow Could Allow Remote Code Execution. This vulnerability should be considered high-risk as it allows for remote code execution through a browser using the Windows Media Player ActiveX control. In this blog post I provide a brief walk through of details of this issue and touch upon how it can be exploited in a reliable fashion.

This vulnerability manifests itself within the quartz.dll module located within the \Windows\System32 directory. This DLL is part of Microsoft's DirectShow multimedia framework and is responsible for parsing various media formats and handing data off to appropriate installable compressors and decompressors. Frequently, vulnerabilities in media formats exist within these installable compressors (see TPTI-09-01 and TPTI-09-02 for recent examples), however, in this case the problematic code is located within quartz itself. It should be noted that Quicktime does NOT need to be installed for this issue to be exposed.

--------------------------

Check out the full post by Aaron to get all the juicy 0-day details...

ATM Vendor Halts Researcher’s Talk on Vulnerability

Via Wired.com -

An ATM vendor has succeeded in getting a security talk pulled from the upcoming Black Hat conference after a researcher announced he would demonstrate a vulnerability in the system.

Barnaby Jack, a researcher with Juniper Networks, was to present a demonstration showing how he could “jackpot” a popular ATM brand by exploiting a vulnerability in its software.

Jack was scheduled to present his talk at the upcoming Black Hat security conference being held in Las Vegas at the end of this month.

But on Monday evening, his employer released a statement saying it was canceling the talk due to the vendor’s intervention.

“Juniper believes that Jack’s research is important to be presented in a public forum in order to advance the state of security,” the statement read. “However, the affected ATM vendor has expressed to us concern about publicly disclosing the research findings before its constituents were fully protected. Considering the scope and possible exposure of this issue on other vendors, Juniper decided to postpone Jack’s presentation until all affected vendors have sufficiently addressed the issues found in his research.”

In the description of his talk on the conference web site, Jack wrote that, “The most prevalent attacks on Automated Teller Machines typically involve the use of card skimmers, or the physical theft of the machines themselves. Rarely do we see any targeted attacks on the underlying software. This presentation will retrace the steps I took to interface with, analyze, and find a vulnerability in a line of popular new model ATM’s. The presentation will explore both local and remote attack vectors, and finish with a live demonstration of an attack on an unmodified, stock ATM.”

Jack did not disclose the ATM brand or discuss whether the vulnerability was found in the ATM’s own software or in its underlying operating system. Diebold ATMs, one of the most popular brands, runs on a Windows operating system, as do some other brands of ATMs.

Diebold did not respond to a call for comment.

Earlier this year, Diebold released an urgent alert (.pdf) announcing that Russian hackers had installed malicious software on several of its Opteva model ATMs in Russia and Ukraine. A security researcher at SophosLabs uncovered three examples of Trojan horse programs designed to infect the ATMs and wrote a brief analysis of them. Last month another security research lab, Trustwave’s SpiderLabs, provided more in-depth analysis of malware used to attack 20 ATMs in Russia and Ukraine of various brands.

According to SpiderLabs, the attack required an insider, such as an ATM technician or anyone else with a key to the machine, to place the malware on the ATM. Once that was done, attackers could insert a control card into the machine’s card reader to trigger the malware and give them control of the machine through a custom interface and the ATM’s keypad.

The malware captured account numbers and PINs from the machine’s transaction application and then delivered it to the thief on a receipt printed from the machine in an encrypted format or to a storage device inserted in the card reader. A thief could also instruct the machine to eject whatever cash is inside the machine. A fully loaded ATM can hold up to $600,000.

It’s unclear if the talk Jack was scheduled to give addresses the same vulnerability and malware or a new kind of attack.

--------------------------

Weak sauce. This event shall now be known as ATMGATE!

But this move is not totally unexpected...after having beers with one of my friends @ Juniper several weeks ago...it sounded like the ATM vendor was starting to give the cold legal shoulder to Juniper....thus this being the outcome was not totally unforeseen.

Monday, June 29, 2009

Social Network Phishing Attacks Up More Than 240%

Via Dark Reading -

Social networks are increasingly becoming a favorite method of attack for phishers as they look for more efficient ways to reach potential victims, according to a newly released report.

Overall, phishing attacks rose 36 percent in the first quarter of this year compared to the same period in 2008, according to a sampling of banking brands used in MarkMonitor's Brandjacking Index report for January through April 2009. And more than 500 organizations worldwide were phished in the first quarter of this year, up 14 percent from the fourth quarter of last year, according to MarkMonitor.

Phishing attacks on social networking sites increased more than 240 percent compared to the same time last year, just behind attacks on payment services, which jumped a whopping 285 percent versus the first quarter of '08. "They exploit the trust one user has with another [on a social network]. There's a tendency to open up something from one of your 'friends' on these sites," says Frederick Felman, chief marketing officer at MarkMonitor. "This is the biggest innovation in phishing attacks since RockPHISH, and it's more social than technical exploitation. RockPHISH was an infrastructure play, but this is using someone else's infrastructure to spread the badness."

Blind Hacker Sentenced to 11 Years in Prison

Via Wired.com -

A legally blind Massachusetts phone hacker was sentenced Friday to over 11 years in federal prison, following his guilty plea on computer intrusion and witness intimidation charges earlier this year.

Matthew Weigman, 19, was sentenced in Dallas by U.S. District Judge Barbara M.G. Lynn, according to the U.S. Attorney’s Office there. There is no parole in the federal system, and little time off for good behavior, so the 135 month term will likely keep Weigman behind bars until 2018.

Known in the telephone party-line scene as “Li’l Hacker,” Weigman is widely considered one of the best phone hackers alive. Relying on an ironclad memory and detailed knowledge of the phone system, the teenager is known for using social engineering to manipulate phone company workers and others into divulging confidential information, and into entering commands into computers and telephone switching equipment on his behalf.

The FBI had been chasing Weigman since he was 15 years old, at times courting him as an informant. He was finally arrested last May, less than two months after celebrating his 18th birthday.

Pakistan Places Bounties on Senior Taliban Leaders

Via The Long War Journal -

The Pakistani government has put out bounties for the capture or death of Pakistani Taliban leader Baitullah Mehsud and 10 of his senior commanders operating in the lawless tribal agencies. Three senior Taliban leaders in North and South Waziristan were noticeably excluded, indicating that the government does not intend to take on these warlords.

The government announced the bounties in an advertisement in Pakistani newspapers.

Baitullah Mehsud, the leader of the Tehrik-e-Taliban, or the Movement of the Taliban in Pakistan, topped the list at an estimated price tag of $615,000.

Faqir Mohammed, the leader of the Taliban in Bajaur, came in second at $181,000.

Hakeemullah Mehsud and Qari Hussain Mehsud of South Waziristan, Omar Khalid and Qari Shakeel of Mohmand, and Commander Tariq Afridi of Darra Adam Khel each command a $123,000 bounty.

Qari Zia Rahman and Waliur Rahman of Bajaur, Fazal Saeed Utezai of Kurram, and Mufti Ilyas of Darra Adam Khel rounded out the list at $61,500 each.

The bounties for Baitullah and his deputies come a month after the government issued bounties for Swat Taliban leader Mullah Fazlullah, his deputy Shah Doran, spokesman and military commander Muslim Khan, and 18 other leaders from the region. So far, those bounties have not led to the arrest or capture of the leaders.

Both Fazlullah and Shah Doran are rumored to have been killed, but the reports have not been confirmed. The government has arrested Falzullah's family.

Siraj Haqqani, Hafiz Gul Bahadar, and Mullah Nazir are absent from the wanted list.

---------------------

Check out the CT blog's great Swat Analysis series of blogs for more information.

Sunday, June 28, 2009

Crash Course in Nuclear Safety & Iran's Nuclear Program

http://www.voanews.com/english/iran_nuclear_safety.cfm

VOA News has built a series of 5 videos, each with a different theme.

Very informative stuff.

Saturday, June 27, 2009

Invisibility Cloak Could Hide Buildings from Quakes

Via NewScientist.com -

Borrowing from the physics of invisibility cloaks could make it possible to hide buildings from the devastating effects of earthquakes, say physicists in France and the UK.

The "earthquake cloak" idea comes from the team led by Stefan Enoch at the Fresnel Institute in Marseille, France. They were the first to show that the physics of invisibility cloaks could have other applications – designing a cloak that could render objects "invisible" to destructive storm waves or tsunamis.

The seismic waves of an earthquake fall into two main groups: body waves that propagate through the Earth, and surface waves that travel only across the surface.

Although Enoch's team have calculated that controlling body waves would be too complex, controlling surface waves is within the ability of conventional engineering, they say. Fortunately, it is surface waves that are more destructive, says team member Sebastien Guenneau at the University of Liverpool in the UK.

The new theoretical cloak comprises a number of large, concentric rings made of plastic fixed to the Earth's surface. The stiffness and elasticity of the rings must be precisely controlled to ensure that any surface waves pass smoothly into the material, rather than reflecting or scattering at the material's surface.

When waves travel through the cloak they are compressed into tiny fluctuations in pressure and density that travel along the fastest path available. By tuning the cloak's properties, that path can be made to be an arc that directs surface waves away from an area inside the cloak. When the waves exit the cloak, they return to their previous, larger size.

[...]

"The outer rings remain nearly still, but the pair of rings tuned to the frequency of the wave move like crazy, bending up and down and twisting," says Guenneau. "For each small frequency range, there's one pair of rings that does most of the work." The team has simulated cloaks containing as many as 100 rings, says Guenneau, although fewer would be needed to protect against the most common kinds of earthquake surface waves.

When it comes to installing them into buildings, they could be built into the foundations, Guenneau suggests. It should be possible to make concrete structures with the right properties. To protect a building 10 metres across, each ring would have to be about 1 to 10 metres in diameter and 10 centimetres thick.

The concentric ring design can also be scaled down, and could offer a way to control vibration in cars or other machinery, he adds.

Police Chief & 91 Officers Detained in Pachuca, Mexico

Via Yahoo! News (AFP) -

A police chief and 91 officers were detained in a sweep on a city in central Mexico suspected of sheltering one of the country's most violent drug gangs, federal police said.

The police chief of Pachuca, capital of Hidalgo state, and the police officers were suspected of offering protection to the Zetas, the armed wing of the powerful Gulf drug cartel, federal police intelligence coordinator Luis Cardenas told reporters.

The Zetas carried out kidnappings and extortion in liaison with local police around Pachuca, some 120 kilometers (75 miles) from Mexico City, Cardenas said.

The original Zetas were elite Mexican Special Forces soldiers trained to find and detain drug lords. A group of deserters formed the group when they instead went to work for the drug lords in the late 1990s.

In recent weeks, a dozen army soldiers and police officers have been arrested in at least four Mexican districts for allegedly harboring organized crime, especially drug trafficking.

More than 10,000 people have died in suspected drug violence since President Felipe Calderon launched a nationwide military crackdown on the nation's powerful cartels two and a half years ago.

FBI: Al-Kini Group Behind Bombing Incidents in Pakistan

Via Dawn.com (Pakistan) -

The US Federal Bureau of Investigation (FBI) has informed Pakistan that Al-Qaeda's network known as ‘Al-Kini group’ was behind a series of bombing incidents in the country, including last year's deadly suicide attack on Islamabad's Marriot hotel.

In its latest communication to Pakistan's Federal Investigating Agency (FIA), the FBI has described the Al-Kini Group to be not only involved in the Marriot bombing, but its various terror cells were also involved in a suicide attack that had killed an army surgeon general, Lt. Gen Mushtaq Baig, in Rawalpindi and the bomb attack on a police station in Sargodha.

Usama al-Kini, also known as Azmarai, was Al-Qaeda's Pakistan chief until he was killed in one of the drone attacks in North Waziristan last year.

Its not clear who heads the Al-Qaeda network in Pakistan, but FBI's correspondence suggest terror-cells of those loyal to Al-Kini were still operating as a separate group, and carrying out attacks within Pakistan.

Perhaps the deadliest of the known attacks by the group was a dumper-truck bomb that caused mass destruction at Islamabad's Marriot hotel in September last year, killing 53 people and injuring dozens of others.

According to the FBI three US nationals were among those killed in the attack.

A highly informed source said the FBI has asked the FIA and Islamabad Capital Territory police to share their investigations they had carried out so far which may help them in apprehending three people described as absconders, including a person identified as Ibrar-ud-Din Syed.

A joint investigation team (JIT) headed by former director general FIA Tariq Pervez had carried out an investigation into the Marriot Hotel bombing and compiled a report.

Dr Muhammad Usman, a resident of Hayat Abad Peshawar, Rana Illyas Ahmed a resident of Sumanderi Faisalabad and Muhammad Hameed Afzal a resident of Toba Tek Sing were arrested by Pakistani security agencies for involvement in the Marriot Hotel bombing and are being tried in the ATC.

The source said in line with the FBI's request, the director general FIA has sought permission from the federal government to share their investigation with the US agency for the apprehension of individual involved in the bombing as three Americans had been killing in the terrorist attack on the hotel.

The Pakistan's federal investigating agency have also been requested to allow the FBI to carry out some forensic tests in their laboratories on left over pieces of the explosive laden vehicle, frame parts, the engine and its shrapnel which were seized by the Pakistani agencies.

The FBI believes that the relevant forensic testing on residue samples, found from the scene of the terrorist attack, would help the Pakistani authorities in their investigation.

The source said information collected from one of the arrested members of al-Kini group, Omar Farouk, revealed that the group had financed two terrorist attacks in Pakistan in 2007, including the attack on Sarghoda police station in 2007.

The FBI has stepped up its efforts to collect further information in close liaison with the FIA and other security agencies in Pakistan to tighten the noose around the Al-Kini network, which many believe had remained the most effective al-Qaeda wing within Pakistan.

Pentagon Creates U.S. Cyber Command, Will Work with NSA

Via The Register UK (June 24th) -

The long wrangle among the US military about who gets to be in charge of cyber warfare and who gets all the resulting pork appears to have been settled. Questions remain, however, regarding the level of America's readiness to take offensive military cyber action against enemies presumably overseas.

Reuters reports that the main decisions on the US military cyber command were announced yesterday at the Pentagon. Defense Secretary Robert Gates signed an order to create the new organisation, intended to be based at Fort Meade outside Washington and subordinated to the head of the US National Security Agency (NSA), widely believed to be the most powerful crypto, intercept and eavesdropping agency in the world.

The news wire quotes Department of Defense (DoD) spokesman Bryan Whitman, responding to questions about "offensive" as opposed to "defensive" cyber warfare by the US forces, as remaining noncommital.

"This command is going to focus on the protection and operation of DoD's networks," he said. "This command is going to do what is necessary to be able to do that."

The Pentagon has previously stated on many occasions that its networks and those of the US government in general are nowadays constantly subject to cyber attacks, most of which appear to emanate from abroad. China is the foreign country most often mentioned in this context, but Deputy SecDef William Lynn has recently stated that "more than 100" foreign intelligence organisations have tried to penetrate the US military's cyber grid on various occasions.

"There is simply no exaggerating our military dependence on our information networks: the command and control of our forces, the intelligence and logistics on which they depend, the weapons technologies we develop and field – they all depend on our computer systems and networks,” said Lynn earlier this month. “Indeed, our 21st century military simply cannot function without them.”

[...]

As for the matter of the US taking the cyber offensive (as opposed to defensive) this would seem to be a foregone conclusion. The very meaning of the word "Defence" in modern English has now changed to mean "activities formerly carried out by ministries or offices of War - including attack and offence as required". It's a universally acknowledged military truism that defence of one's own territory is often best conducted on someone else's.

If that wasn't enough, it should also be noted that the US military is at present engaged in building a cyber firing range - in effect a Matrix-esque virtual world - in which to test the effects of cyber weapons.

The new command's subordination to the NSA makes sense - the NSA is already hugely expert in crypto and other useful subjects. Not everyone remembers that it is a military organisation, but unlike the CIA it is indeed "a Combat Support Agency of the Department of Defense".

The cyber command is due to kick off in October, and reportedly will be fully up and running a year later.

Algeria: Taking the Pulse of AQIM

Via Stratfor (Security Weekly) -

Late in the evening of June 17, 2009, militants affiliated with al Qaeda in the Islamic Maghreb (AQIM) detonated two improvised explosive devices (IEDs) against a convoy near Bordj Bou Arreridj, Algeria, which is located in a mountainous area east of Algiers that has traditionally been an Islamist militant stronghold. The convoy consisted of Algerian paramilitary police vehicles escorting a group of Chinese workers to a site where they were building a new highway to connect Bordj Bou Arreridj with Algiers. After disabling the convoy using IEDs, the militants then raked the trapped vehicles with small-arms fire. When the ambush was over, 18 policemen and one Chinese worker had been killed. Another six gendarmes and two Chinese workers were wounded in the attack.

[...]

By design, AQIM incorporated the GSPC with elements of Morocco’s Islamic Combatant Group, Libya’s Islamic Fighting Group, several Tunisian groups, most notably the Tunisian Combatant Group, and jihadists in Mali, Niger and Mauritania. However, in practice, the vast majority of the group’s infrastructure came from the GSPC, and attacks since the founding of AQIM in 2006 have reflected this. Indeed, in spite of the many high-profile Libyan and Moroccan militants who serve as part of the al Qaeda core leadership, Libya and Morocco have been extremely calm since the emergence of AQIM, and the group has remained an Algeria-based phenomenon.

[...]

The attacks in Mauritania have shown rudimentary tactics with poor planning, and the militants associated with AQIM in Mauritania simply have not displayed the ability to mount a large-scale, coordinated attack. The group’s activities in Mali and Niger are also mainly constrained to low-level attacks against government or military outposts and foreign mining sites and personnel in the northern stretches of those countries. AQIM also conducts training and engages in smuggling and kidnappings for ransom in this deserted region.

This means that, in the end, in spite of all the hype associated with the AQIM name, the group is essentially a rebranded GSPC and not some sort of revolutionary new organization. It has adapted its target set to include foreign interests, and it did add suicide bombing to its repertoire, but aside from that there has been very little movement toward AQIM’s becoming a truly regional threat.

[...]

Perhaps the AQIM militants got lucky or the Algerian gendarmes targeted in the attack made a fatal mistake. However, the increased death toll could also have been a result of superior IED design, or superior planning by the operational leader of the ambush. Such a shift could indicate that an experienced operational commander or bombmaker has come to AQIM from someplace like Iraq or Pakistan. It will be very important to watch the next few AQIM attacks to see if the June 17 attack was indeed just an anomaly or if it was the beginning of a new and deadly trend.

Friday, June 26, 2009

NRO: 2006 Satellite Failure Remains a Mystery

Via FAS Secrecy Blog -

In February 2008, the U.S. fired a missile at an inoperable U.S. intelligence satellite that had failed shortly after launch in December 2006. The satellite was destroyed reportedly in order to prevent an intact reentry of its toxic hydrazine fuel tank. But do we know why or how it failed in the first place?

“No,” the director of the National Reconnaissance Office told Congress last year, in newly disclosed responses (pdf) to questions for the record (p.89).

“After an exhaustive formal failure investigation, and three different independent review team investigations, the cause of the failure and what failed was not determined,” said Scott Large, then-director of the NRO. “Our exhaustive analysis of the spacecraft design and test program did not identify the root cause of the failure,” Mr. Large said. His remarks appeared in the record of a March 5, 2008 hearing before the House Armed Services Committee that was published this month.

“The era of Acquisition Reform is over,” Mr. Large also told Congress. “It has left the NRO in a fragile state with a poor history of performance.”

On June 12, Secretary of Defense Robert Gates, with concurrence of the DNI, appointed retired Air Force Gen. Bruce Carlson as the 17th director of the National Reconnaissance Office.