Saturday, December 17, 2011

CFR - The World Next Week: December 15, 2011

http://www.cfr.org/us-strategy-and-politics/world-next-week-december-15-2011/p26810

CFR's Director of Studies James M. Lindsay and CFR.org Editor Robert McMahon preview major world events in the week ahead. In this week's podcast: the Arab Spring's one year anniversary is marked; the U.S. Senate must pass a funding bill or face a government shutdown; and the Mercosur summit convenes in Uruguay.

-------------------------------------------

Best Quote = "What's Basketball?...I had totally forgotten we had professional basketball in this country."

Friday, December 16, 2011

Adobe Kills Two Actively Exploited Bugs in Reader

Via The Register UK -

Adobe has released updates for its Reader and Acrobat applications that fix two vulnerabilities that attackers were exploiting to seize control of Windows-based machines.

Version 9.4.6 of the programs fix two memory-corruption bugs that Adobe says are “being actively exploited in limited, targeted attacks in the wild” against machines running Windows. The same bugs are present in Mac and Unix versions of the applications, but there are no reports of machines running them being exploited. The bugs are also present in Reader X for Windows, but a security sandbox, which Adobe added last year to minimize the damage that results from code flaws, prevents the attacks from working.

As a result, those versions will be updated next month, during a regularly scheduled patch release.

Adobe warned of the attacks earlier this month in an advisory that credited military contractor Lockheed Martin and the Defense Security Information Exchange. A day later, researchers from antivirus provider Symantec warned that email-born attacks exploiting the flaw to install the Backdoor.Sykipot were detected as early as November 1. The vulnerability in the U3D, or Universal 3D, file format is identified as CVE-2011-2462.

On Friday, Adobe said a second vulnerability – in an RPC, or remote procedure call, component – was also under attack. It's identified as CVE-2011-4369. Adobe representatives provided no other details of the vulnerability, except to say they are “only aware of one instance” of it being used.


-------------------------------------------

APSB11-30: Security Updates Available for Adobe Reader and Acrobat 9.x for Windows
http://www.adobe.com/support/security/bulletins/apsb11-30.html

Tuesday, December 13, 2011

Key US Lawmaker: Iran Did Not Shoot Down RQ-170 Drone

Via Google (AP) -

A key US lawmaker on Tuesday denied Iran's claims of having brought down a US drone, saying "technical" problems pulled the state-of-the-art unmanned aircraft from the sky and into Tehran's hands.

"I will say without hesitation that this is not something that anyone had anything to do with coming down with, other than a technical problem," said US House Intelligence Committee Chairman Mike Rogers, a Republican.

"There was a technical problem that was our problem, nobody else's problem. I think there's a lot of PR (public relations) going on," he said at The Foreign Policy Initiative think tank's 2011 forum.

[...]

Iran has vowed to reverse engineer the drone but has given contradictory accounts of how the aircraft went down on December 4. Tehran initially said it shot down the drone, but later claimed the Iranian military managed to hack into the plane's flight controls.

Rogers said "it's not a good day for the United States" anytime a hostile nation nabs a piece of high-tech intelligence hardward, but played down the potential impact of Tehran dismantling and analyzing the drone.

"The good news is: While they're spending time re-engineering, we will be spending time engineering, and that's the biggest difference," he said.

"They're very proud that they're going to re-engineer this, and I hope they spend five, six, seven, eight years doing that, that would be great, because we'll be long past that" level of technology, said Rogers.

US President Barack Obama acknowledged for the first time Monday that the drone was in Iranian hands, and said the United States has asked Tehran to return the sophisticated aircraft.

"We've asked for it back. We'll see how the Iranians respond," Obama said at a news conference with Iraqi Prime Minister Nuri al-Maliki.

[...]

Obama, however, shed no further light on the plane's mission or why it failed to return to a base in Afghanistan.

"These things are not infallible," said Rogers.

Higgs Boson: ‘Tantalizing Hints’ but No Direct Proof in Particle Search

Via New York Times -

Two teams of scientists sifting debris from high-energy proton collisions in the Large Hadron Collider at CERN, the European Center for Nuclear Research, said Tuesday that they had recorded “tantalizing hints” — but only hints — of a long-sought subatomic particle known as the Higgs boson, whose existence is a key to explaining why there is mass in the universe. It is likely to be another year, however, before they have enough data to say whether the elusive particle really exists, the scientists said.

The putative particle weighs in at about 125 billion electron volts, about 125 times heavier than a proton and 500,000 times heavier than an electron, according to one team of 3,000 physicists, known as Atlas, for the name of their particle detector. The other equally large team, known as C.M.S. — for their detector, the Compact Muon Solenoid — found bumps in their data corresponding to a mass of about 126 billion electron volts.

If the particle does exist at all, it must lie within the range of 115 to 127 billion electron volts, according to the combined measurements. “We cannot conclude anything at this stage,” said Fabiola Gianotti, the Atlas spokeswoman, adding, “Given the outstanding performance of the L.H.C. this year, we will not need to wait long for enough data and can look forward to resolving this puzzle in 2012.”

Over the last 20 years, suspicious bumps that might have been the Higgs have come and gone, and scientists cautioned that the same thing could happen again, but the fact that two rival teams using two different mammoth particle detectors had recorded similar results was considered to be good news. Physicists expect to have enough data to make the final call by the summer.

The Atlas result has a chance of less than one part in 5,000 of being due to a lucky background noise, which is impressive but far short of the standard for a “discovery,” which requires one in 3.5 million odds of being a random fluctuation. Showing off one striking bump in the data, Ms. Gianotti said, “If we are just being lucky, it will take a lot of data to kill it.”


-----------------------------------------------------------------------------

CERN Press Release
http://press.web.cern.ch/press/pressreleases/Releases2011/PR25.11E.html
The main conclusion is that the Standard Model Higgs boson, if it exists, is most likely to have a mass constrained to the range 116-130 GeV by the ATLAS experiment, and 115-127 GeV by CMS. Tantalising hints have been seen by both experiments in this mass region, but these are not yet strong enough to claim a discovery.

Higgs bosons, if they exist, are very short lived and can decay in many different ways. Discovery relies on observing the particles they decay into rather than the Higgs itself. Both ATLAS and CMS have analysed several decay channels, and the experiments see small excesses in the low mass region that has not yet been excluded.

Taken individually, none of these excesses is any more statistically significant than rolling a die and coming up with two sixes in a row. What is interesting is that there are multiple independent measurements pointing to the region of 124 to 126 GeV. It's far too early to say whether ATLAS and CMS have discovered the Higgs boson, but these updated results are generating a lot of interest in the particle physics community.

Monday, December 12, 2011

Mexico's Navy Captures Zetas Leader "El Lucky"

Via Reuters (Dec 12, 2011) -

Mexico's navy captured a leader of the Zetas drug cartel, Raul Fernandez, President Felipe Calderon said on Monday via his Twitter account.

Fernandez, who is also known as "El Lucky" (The Lucky One), had a bounty of 15 million pesos ($1.09 million) on his head, operated in the Gulf state of Veracruz as well as the central state of Puebla and Oaxaca state in the south, Calderon said.

The Zetas, formed at the end of the 1990s by deserters from elite army forces, are believed to have been behind some of the bloodiest crimes against civilians in recent years including the arson attack on a casino in northern Mexico that killed 52 people in August.

Since sending in the army five years ago to crack down on cartel activity, Calderon has made a point of targeting top leaders. With Fernandez's capture, Calderon said the government had accounted for 22 of Mexico's 37 most-wanted drug lords.


-------------------------------------------------

Raúl Lucio Fernandez-Lechuga (alias El Lucky) was a Mexican drug lord of the Los Zetas. He was captured on Monday 12th December 2011. The government of Mexico has listed Fernandez-Lechuga as one of its 37 most wanted drug lords and offers the equivalent of over $2 million USD for information leading to his capture.

A Never Before Seen Optical Trick Creates Ultra-Secure Cash

Via Fast Company (Technology) -

If all goes as planned, the world's supply of cash will soon be secured with a nano-scale optical defense that is as secure as it is visually impressive. Using arrays of holes no bigger than a virus, scientists at Toronto-based Nanotech Security have created an atoms-thick display that can be read by humans or machines and that shines with the brightness of a typical LED despite using nothing but reflected light.

The technology was inspired by the Blue Morpho butterfly, whose brilliant blue coloration comes not from pigment but the way that tiny holes in its scales reflect light. But the tech, called Nano-Optic Technology for Enhanced Security (NOtES), is different from the Morpho butterfly's wings, and pretty much all other bio-inspired reflective optical technologies, in that it is both extraordinarily thin and functions even in dim light.

NOtES exploits an obscure area of physics to accomplish its bright and sharp display, known as plasmonics. Light waves interact with the array of nano-scale holes on a NOtES display--which are typically 100-200 nanometers in diameter--in a way that creates what are called "surface plasmons." In the words of the company, this means light "[collects] on the films surface and creates higher than expected optical outputs by creating an electromagnetic field, called surface plasmonic resonance."

Exploit Kit Intelligence: Blackhole 1.2.1 & Java

Building on top of the reports by Brain Kerbs over at Krebs on Security....

Steven over at the XyliBox blog outlines the recent update to the Blackhole Exploit Kit.
BlackHole 1.2.1:
1. Added Java Rhino exploit [CVE-2011-3544], working silently on all browsers and OS, this increased success rate.
2. Java SMB, Java Skyline, Java Trust removed for no need (Java Rhino covers the whole range of vulnerable JRE from these exploits)
According to just the single instance of Blackhole outlined by Steven, the CVE-2011-3544 exploit was responsible for over 83% of the successful infections made by this specific kit. That is huge!

PDF exploits followed Java with just 11% of the successful hits. Very likely due to Adobe works to harden Adobe X against PDF exploitation.

------------------------------------------------------------------------

CVE-2011-3544: Oracle Java Applet Rhino Script Engine Remote Code Execution
http://schierlm.users.sourceforge.net/CVE-2011-3544.html

------------------------------------------------------------------------

Oracle Java SE Critical Patch Update Advisory - October 2011
http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.html
This Critical Patch Update contains 20 new security fixes for Oracle Java SE - including CVE-2011-3544.
Users are recommended to update to Java 6 Update 29 or Java 1 Update 1 to close the CVE-2011-3544 vulnerability.

Sunday, December 11, 2011

The Covert Intelligence War Against Iran

Via STRATFOR (Security Weekly) -

There has been a lot of talk in the press lately about a “cold war” being waged by the United States, Israel and other U.S. allies against Iran. Such a struggle is certainly taking place, but in order to place recent developments in perspective, it is important to recognize that the covert intelligence war against Iran (and the Iranian response to this war) is clearly not a new phenomenon.

Indeed, STRATFOR has been chronicling this struggle since early 2007. Our coverage has included analyses of events such as the defection to the West of Iranian officials with knowledge of Tehran’s nuclear program; the Iranian seizure of British servicemen in the Shatt al Arab Waterway; the assassination of Iranian nuclear scientists; the use of the Stuxnet worm to cripple Iranian uranium enrichment efforts; and Iranian efforts to arm its proxies and use them as a threat to counteract Western pressure. These proxies are most visible in Iraq and Lebanon, but they also exist in Yemen, Afghanistan, Syria, the Palestinian territories, Saudi Arabia and other Gulf states.

While the covert intelligence war has been under way for many years, the tempo of events that can readily be identified as part of it has been increasing over the past few months. It is important to note that many of these events are the result of hidden processes begun months or even years previously, so while visible events may indeed be increasing, the efforts responsible for many of them began to increase much earlier. What the activities of recent months do tell us is that the covert war between Iran and its enemies will not be diminishing anytime soon. If anything, with the current withdrawal of U.S. troops from Iraq and Iranian nuclear efforts continuing, we likely will see the results of additional covert operations — and evidence of the clandestine activity required to support those operations.

Read more: The Covert Intelligence War Against Iran | STRATFOR


---------------------------------------------------------------------

CFR - Crisis Guide: Iran
http://www.cfr.org/interactives/CG_Iran/index.html#/overview/

Of particular note is the "Analyzing The Options" section.

Saturday, December 10, 2011

This Week at War: Disposable Warfare

Via Foreign Policy (Small Wars) -

This week we learned that a stealthy RQ-170 Sentinel unmanned aerial vehicle (UAV) crashed 140 miles inside Iran with its wreckage recovered by Iranian security forces. Dubbed "the Beast of Kandahar" in 2009 after it appeared at a U.S. airbase there, the RQ-170 flew clandestine missions over Abbottabad, Pakistan, collecting intelligence prior to the May raid that killed Osama bin Laden. According to the Wall Street Journal, U.S. officials considered a covert mission to either recover or destroy the wreckage before Iranian forces were able to reach the crash site, before concluding that the drone's technology likely didn't warrant the risk of another intrusion into Iran.

Rather than slow the march toward the future of drone warfare, this incident only supports the expanded development and deployment of smarter and more capable drones. That means that U.S. officials and commanders will have to live with more such losses of sensitive drone hardware to adversaries.

[...]

The lesson learned from this incident is not to hold back on drone employment but rather to build better drones and to accept the risks that come with their use. Stealthier drones will soon be able to provide continuous observation of suspected targets, gathering information that was not previously available to policymakers, thus reducing some of the guesswork from decision-making. Drones will be able to fly very long missions beyond the physiological endurance of human aircrews. In expansive theaters like the Asia-Pacific region, this capability will reduce U.S. dependence on forward bases currently vulnerable to missile attack. Long-range UAVs on aircraft carriers will allow the Navy to conduct strike operations from much longer ranges and with greater safety to its ships. Finally, long-endurance drones will provide isolated infantry patrols with continuous scouting and fire support.

Next-generation drone development seems to be ahead of schedule. The Navy's combat UAV demonstrator project recently took 16 flights rather than the anticipated 49 flights to reach initial flight test milestones. This rapid advance in robotic aircraft is in stark contrast to the delays experienced by the F-35 Joint Strike Fighter, many caused by software problems in the F-35's manned cockpit. In explaining the Navy UAV's test success, the program manager, in a subtle dig at pilots, said, "we will not have to fly the platform as much as manned systems, which are less predictable."


-----------------------------------------------------

Several other stories on the RQ-170 crash and the possible consequences....

FP: Iran Has America's Super Spy Drone. So What?
http://www.foreignpolicy.com/articles/2011/12/09/iran_has_americas_super_spy_drone_so_what
That one of many drones dedicated to collecting intelligence over Iran has fallen into Iranian hands is also expected given the law of averages. Drones crash at rates higher than manned aircraft for any number of reasons, including due to human error, incorrect information, network interference, system failure, weather, or being shot down. As a former official warned: "It was never a matter of whether we were going to lose one but when."
US Air Force Times: Iran’s Captured RQ-170: How bad is the damage?
http://www.airforcetimes.com/news/2011/12/defense-iran-captured-rq-170-how-bad-120911/

Aviation Week: Downed UAV Technology Already Dated (Dec 5th)
http://www.aviationweek.com/aw/generic/story_channel.jsp?channel=defense&id=news/awx/2011/12/05/awx_12_05_2011_p0-401894.xml&headline=Downed%20UAV%20Technology%20Already%20Dated

Wednesday, December 7, 2011

Analyzing CVE-2011-2462 - Part One

Via 9bplus.com (Brandon Dixon) -

Before I went to bed last night I took a look at uploaded files to PDF X-RAY in hopes that Christmas would come early (CVE-2011-2462 in my reports) and was surprised when I came across a file with /U3D references. I snatched the file off the server, opened up my snapshots to the latest 9.4 build of Adobe and ran the file. Reader crashed, and a new document was successfully opened. That was enough to stay up, so analysis started and can be found below.

Read the full analysis by Brandon @ 9bplus.com

--------------------------------------

Mila Parkour also links to Brandon's analysis and adds additional information over at Contagio.

Al-Shabab Changes Name to 'Somali Islamic Emirate'

Via barigaafrika.com (Dec 7, 2011) -

A major conference to discuss the future of Al-Shabab which has been ongoing in Baydhabo, Bay Regions [south western Somalia] in the last five days has now been concluded after which a statement was issued.

The conference was attended by clerics from areas under Al-Shabab control as well as senior Al-Shabab officials among them Sheikh Hasan Dahir Aweys, Shaykh Muqtar Robow and other prominent figures of the extremists group.

Towards the end of the conference, religious clerics attending the conference addressed the gathering in which they all expressed their excitement in the participation of the conference dubbed "the future of Al-Shabab".

The statement issued at the end of the conference comprised of seven major points some of which the Somali public are already quite familiar with while others are new and are to effect major changes in Al-Shabab.

[...]

The name 'Movement for the Al-Shabab Mujahidin' is to be replaced with 'Somali Islamic Emirate'. It has been said that as from the time of the release of the statement, the official name for the men used to be known as Al-Shabab will be 'Somali Islamic Emirate'.

Some of the new points in the statement include the formation of a new organization for Somali religious scholars that is to be under Al-Shabab which has been renamed as Islamic Emirate. It is believed that the whole point of this conference was to change Al-Shabab's name given that the rest of the points in the statement are issues which have already been implemented in areas under the group's control.

Mexico: Gadhafi Son Tried to Enter Country Under False Name

Via Google News (AP) -

Mexico said Wednesday that a son of the late Libyan dictator Moammar Gadhafi and three relatives had plotted to sneak into Mexico under false names and take clandestine refuge at a posh Pacific coast resort.

The elaborate plan to bring al-Saadi Gadhafi to Mexico allegedly involved two Mexicans, a Canadian and a Danish suspect, all of whom have been detained, Interior Secretary Alejandro Poire said.

He did not reveal which relatives had planned to accompany Al-Saadi Gadhafi, who is known for his love of professional soccer and run-ins with police in Europe.

The plot was uncovered by Mexican intelligence agents in early September as al-Saadi was fleeing Libya shortly after his father's ouster. He never made it to Mexico, but did reach the Western African country of Niger, where he has been living.

The plotters allegedly jetted into Mexico, opened bank accounts and bought properties meant to be used as safe houses in several parts of the country, including one at a resort on Mexico's Pacific coast.

"The large economic resources which this criminal organization has, or had, allowed them to contract private flights," Poire told a news conference.

Poire said the leader of the plot was a Canadian woman he identified as Cynthia Vanier. He said she had been detained on Nov. 10 and is being held, along with three other suspects, under a form of house arrest on suspicion of using false documents, human smuggling and organized crime.

Poire said Vanier "was the direct contact with the Gadhafi family and the leader of the group, and presumably was the person in charge of the finances of the operation.

The plot also allegedly involved a Mexican woman who lived in the United States, who Poire said served as the liaison to obtain the falsified Mexican identity documents.

A Danish man was "the logistic liaison" for the plan, Poire said. He said the alleged conspirators also traveled to Kosovo "and several Middle Eastern countries."

"The activities of the criminal organization in our country included the falsification of official documents, the opening of bank accounts with false documents (and) the purchase of real estate that was intended, among other things, to serve as a residence for the Gadhafi family at a house located in the zone of the Bahia de Banderas," just north of the resort of Puerto Vallarta, Poire said.

The Mexican officials made no mention of Moammar Gadhafi himself being involved in the plan, and Poire did not say which relatives might have planned to accompany the son to Mexico. The elder Gadhafi was ousted from power in late August and was captured and killed in Libya on Oct. 20.

Symantec: Four-Fold Increase in the Number of Daily Targeted Attacks Since January

Via Symantec Intelligence Blog -

With targeted attacks and advanced persistent threats being very much in the news this year, we thought it would be a good time as the end of the year draws closer to begin our review of targeted attacks and look more closely at what has been described as “advanced persistent threats” or APTs for short. Terms such as APT have been overused and sometimes misused by the media, but APTs are a real threat to some companies and industries.

In November, one in 255 emails was malicious, but approximately one in 8,300 of those were highly targeted. This means that highly targeted attacks, which may be the precursor to an APT, account for approximately one in every two million emails, still a rare incident rate. Targeted malware in general has grown in volume and complexity in recent years, but as it is designed to steal company secrets, it can be very difficult for recipients to recognize, especially when the attacker employs compelling social engineering techniques, as we highlight in this report.

A persistent threat residing inside your company’s network may be the by-product of a successful targeted attack, rather than the targeted email itself containing an APT, it is likely to contain a downloader component for the actual APT. Hence, targeted attacks of this nature can lead to an APT being deployed on your network if you don’t have the right defenses in place.

[...]

Targeted attacks have been around for a number of years now, and when they first surfaced back in 2005, Symantec.cloud would identify and block approximately one such attack in a week. Over the course of the following year, this number rose to one or two per day and over the following years it rose still further to approximately 60 per day in 2010 and 80 per day by the end of the first quarter of 2011. By November 2011, the number of attacks blocked rose to approximately 94 per day, almost four times the number in January.

[...]

The types of organizations being targeted tended to be large, well-known multi-national organizations, and were often within particular industries, including the public sector, defense, energy and pharmaceutical. In more recent years the scope has widened to include almost any organization, including smaller and medium-sized businesses.

[...]

To find out more, the full report can be downloaded here (PDF).

------------------------------------------------------------------------------------

The number of targeted attacks outlined by Symantec are only representative of Symantec E-mail service customers and Symatec.cloud customers, however two general points can be taken from the data. Targeted attacks are happening on a daily basis and the sectors which experience targeted attackers continue to increase and widen.

Whitepaper - Advanced Persistent Threats: A Symantec Perspective
http://www.symantec.com/content/en/us/enterprise/white_papers/b-advanced_persistent_threats_WP_21215957.en-us.pdf

"An APT is always a targeted attack, but a targeted attack is not necessarily an APT."

Tuesday, December 6, 2011

New Adobe Reader Zeroday Used in Targeted Attacks

Via Adobe Secure Software Engineering Team (ASSET) Blog -

We have just posted Security Advisory APSA11-04 regarding a new vulnerability (CVE-2011-2462) that is currently being exploited in the wild in limited, targeted attacks against Adobe Reader 9.4.6 on Windows. Here is a summary of our approach to address this issue:

  • We are planning to release an out-of-cycle security update for Adobe Reader and Acrobat 9.x for Windows no later than the week of December 12, 2011.
  • Because Adobe Reader X Protected Mode and Adobe Acrobat X Protected View would prevent an exploit targeting this vulnerability from executing, we are planning to address this issue in Adobe Reader and Acrobat X for Windows with the next quarterly security update on January 10, 2012.
  • The risk to Macintosh and UNIX users is significantly lower. We are therefore planning to address this issue in Adobe Reader and Acrobat X and earlier versions for Macintosh as part of the next quarterly update on January 10, 2012. An update to address this issue in Adobe Reader 9.x for UNIX is planned for January 10, 2012.
The reason for addressing this issue quickly for Adobe Reader and Acrobat 9.4.6 for Windows is simple: This is the version and platform currently being targeted. All real-world attack activity, both in this instance and historically, is limited to Adobe Reader on Windows. We have not received any reports to date of malicious PDFs being used to exploit Adobe Reader or Acrobat for Macintosh or UNIX for this CVE (or any other CVE).

[...]

I’d like to take this moment to encourage any remaining users still running Adobe Reader or Acrobat 9.x (or worse, older unsupported versions) to PLEASE upgrade to Adobe Reader or Acrobat X. We put a tremendous amount of work into securing Adobe Reader and Acrobat X, and, to date, there has not been a single piece of malware identified that is effective against a version X install. Help us help you by running the latest version of the software!


------------------------------------------------------

http://www.adobe.com/support/security/advisories/apsa11-04.html

Acknowledgments
Adobe would like to thank Lockheed Martin CIRT and members of the Defense Security Information Exchange for reporting this issue and for working with Adobe to help protect our customers.

Downed RQ-170 Drone Was On CIA Mission

Via CNN's Security Clearance Blog -

A stealth US drone that crashed in Iran last week was part of a Central Intelligence Agency reconnaissance mission which involved both intelligence community and military personnel stationed in Afghanistan, two U.S. officials tell CNN. The officials said they did not believe the mission involved flying the drone directly over Iran because the reconnaissance capability of the RQ-170 drone allows it to gather information from inside Iran while remaining on the Afghanistan side of the border. The officials also for the first time acknowledged to CNN it was an RQ-170 drone that was lost.

When the drone crashed in Iran late last week, the U.S. briefly considered all potential options for retrieving the drone or bombing the wreckage, according to a third official. But those ideas were relatively quickly discarded as impractical, the official said. There was also satellite surveillance over the site which helped confirm the location of the wreckage before the Iranians retrieved it.

All of the officials have direct knowledge of the events, but spoke on the condition of anonymity because of sensitive intelligence matters. CIA officials have declined to comment.

Monday, December 5, 2011

Senior US Official: American RQ-170 Drone in Iranian Hands

Via MSNBC (Dec 5, 2011) -

Iran's military has recovered a super-secret American stealth drone after the unmanned vehicle flew out of control and crashed inside Iran, NBC News reported Monday, citing a senior U.S. official.

According to the official, the RQ-170 drone was flying inside Afghanistan along the Iranian border, when ground commanders "lost control" of the aircraft. It took a "hard turn" into Iran and ultimately crashed, the source said.

Iranian media reported on Sunday that their country's military had shot down a U.S. reconnaissance drone in eastern Iran, but a U.S. official said there was no indication the aircraft had been shot down.


--------------------------------------------------

Lockheed Martin RQ-170 Sentinel (aka Beast of Kandahar)
http://en.wikipedia.org/wiki/Lockheed_Martin_RQ-170_Sentinel
RQ-170 Sentinels have been deployed to Afghanistan, where one was sighted at Kandahar International Airport in late 2007. This sighting, and the Sentinel's secret status at the time, led Bill Sweetman to dub it the "Beast of Kandahar". The UAV being deployed to Afghanistan, despite the Taliban having no radar, has led to speculation that the aircraft is being used to spy on Pakistan or Iran.

On the night of 1/2 May 2011 at least one RQ-170 monitored the area while elements of the United States Naval Special Warfare Development Group launched an assault on the compound which resulted in bin Laden's death.

There have been a number of reports, which the New York Times describes as "unconfirmed", that RQ-170s have operated over Iran during 2011 to spy on the country's missile and nuclear programs.

Operation Northeast: Mexican Military Dismantles Clandestine Radio Networks

Via Valley Central (AP) -

The Mexican army says its troops have dismantled a telecommunications system set up by organized crime in four northern states.

A Defense Department statement Thursday says soldiers confiscated 167 antennas and 166 power supplies that gang members used to communicate among themselves and to monitor military movements.

The operation also netted more than 1,400 radios and 2,600 cellphones in the border states of Tamaulipas, Nuevo Leon and Coahuila and in the state of San Luis Potosi.

The army hasn't said which cartel was affected.

During the summer, Mexico's navy dismantled a communication system used by the Zetas cartel in the Gulf state of Veracruz.

The Zetas have a strong presence in all four of the states involved in the army's operation.


-----------------------------------------------------------------

Official Statement (Spanish)
http://www.sedena.gob.mx/index.php/sala-de-prensa/comunicados-de-prensa-de-los-mandos-territoriales/8104-1-de-diciembre-de-2011-monterrey-nl

Google Translated Version (English)
http://translate.google.com/translate?sl=auto&tl=en&js=n&prev=_t&hl=en&ie=UTF-8&layout=2&eotf=1&u=http%3A%2F%2Fwww.sedena.gob.mx%2Findex.php%2Fsala-de-prensa%2Fcomunicados-de-prensa-de-los-mandos-territoriales%2F8104-1-de-diciembre-de-2011-monterrey-nl&act=url

-----------------------------------------------------------------

By being able to maintain their communication capabilities isolated from public telecommunication infrastructure, such as mobile operators, the cartels are able to communicate between members and cells spread across their territory with minimal risk of interception or detection.

Pakistan: Anti-Terror Agreements With U.S. To Be Dropped

Via The Express Tribune (Pakistan) -

Pakistan has decided to scrap all existing anti-terror cooperation agreements with the United States in a development that may not only take the uneasy alliance between the two countries to the point of no return but also impede world efforts at bringing sustainable peace in Afghanistan.

The decision, which was taken after consultations at the top civil and military levels following the Nato airstrikes, is part of a review of political, diplomatic and military ties with the US, officials familiar with the development told The Express Tribune.

This, however, does not mean the government is seeking a complete breakdown in the relationship with the US. Rather, it is aiming to enter a fresh agreement that clearly states in writing Pakistan’s ‘red lines’ and firm assurance from Washington not to violate those in the future, added the officials, who spoke on condition of anonymity because of the sensitivity of the issue.

MITEI: With Changes, The [U.S. Power] Grid Can Take It

Via MIT News -

Over the next two decades, the U.S. electric grid will face unprecedented technological challenges stemming from the growth of distributed and intermittent new energy sources such as solar and wind power, as well as an expected influx of electric and hybrid vehicles that require frequent recharging. But a new MIT study concludes that — as long as some specific policy changes are made — the grid is most likely up to the challenge.

Study co-director Richard Schmalensee, the Howard W. Johnson Professor of Economics and Management at the MIT Sloan School of Management, says the two-year study came about “because a number of us were hearing two sorts of rhetoric” about the U.S. power grid: that it’s on the brink of widespread failure, or that simply installing some new technology could open up wonderful new opportunities.

[...]

The report was commissioned by the MIT Energy Initiative (MITEI) and carried out by a panel of 13 faculty members from MIT and one from Harvard University, along with 10 graduate students and an advisory panel of 19 leaders from academia, industry and government.

While the grid’s performance is adequate today, decisions made now will shape that grid over the next 20 years. The MIT report recommends a series of changes in the regulatory environment to facilitate and exploit technological innovation. Among the report’s specific recommended changes: To enable the grid of the future — one capable of handling intermittent renewables — the United States will need effective and enhanced federal authority over decisions on the routing of new interstate transmission lines. This is especially needed, the report says, in cases where power is produced by solar or wind farms located far from where that power is to be used, requiring long-distance transmission lines to be built across multiple regulatory jurisdictions.

[...]

The MITEI report recommends that the Federal Energy Regulatory Commission (FERC) either be given the authority to make decisions in such cases, or be designated as the “backstop” authority in cases where there are disputes.

The grid would also benefit from a restructuring of the way customers pay for its costs, the study found. Payment for electric distribution, like payment for generation, is currently calculated based on usage. But most of the costs involved are fixed; they don’t depend on usage. This gives utilities incentives to resist distributed generation, such as homeowners installing rooftop solar panels, and gives consumers excessive incentives to install such systems — and thereby to shift their share of fixed network costs to their neighbors. Fixed network costs, the reports says, should be recovered primarily through customer charges that don’t depend on electricity consumption.

In addition, while many utilities have begun to install “smart meters” for their customers, most of these are not yet being used to provide feedback to customers that could shift electricity usage to off-peak hours.

[...]

Another area that will require restructuring, the study concluded, is cybersecurity: The more thoroughly the grid is interconnected, and the more smart meters are added to gather data about usage patterns, the greater the risk of security breaches or cyberattacks on the system.

Thursday, December 1, 2011

STRATFOR Above the Tearline: Mexican Cartel Violence In Texas

http://www.stratfor.com/analysis/20111129-above-tearline-mexican-cartel-violence-texas

In this week’s Above the Tearline, we are going to look at an incident that appears to be a Mexican cartel-related murder in Texas.

Last Monday, in the Houston area, several undercover officers from a High Intensity Drug Trafficking Areas Task Force (known as a HIDTA) were following a tractor-trailer from south Texas transporting drugs in an undercover operation. Four suspects ambushed the truck, firing shoulder weapons, shooting and wounding a task force police officer and killing the driver, who media have identified as an undercover government informant.

Read more: Above the Tearline: Mexican Cartel Violence In Texas | STRATFOR