Blog

  • MIL-OSI Asia-Pac: Hospital Authority announces senior appointment (with photo)

    Source: Hong Kong Government special administrative region

    The following is issued on behalf of the Hospital Authority:

         The Hospital Authority (HA) spokesperson announced the following senior appointment today (September 23):
     
         Dr Ada Yu will be appointed as Hospital Chief Executive of Bradbury Hospice, Cheshire Home, Shatin, and Shatin Hospital with effect from October 1.
     
         Dr Yu is a specialist in emergency medicine by background. She is currently the Chief Manager (Planning and Commissioning) of the New Territories East Cluster (NTEC) overseeing all major hospital projects in the NTEC including the planning and commissioning of the Prince of Wales Hospital (PWH) Phase 2 Redevelopment Project, the North District Hospital Expansion Project and the North District Community Health Centre Project. As an experienced senior executive, Dr Yu steers the strategic planning of the NTEC and drives a wide spectrum of projects for enhancement of clinical services and improvement of patient experiences in the hospitals. In her concurrent role as the Co-ordinator of Clinical Services of the PWH, she formulates the cluster annual plan, drives innovative technology development and smart solutions in the NTEC, and co-ordinates the service collaboration between the HA and the Chinese University of Hong Kong Medical Centre.
     
         The HA Chairman, Mr Henry Fan, and the Chief Executive, Dr Tony Ko, congratulate Dr Yu on her new appointment and wish her every success in taking up the new role.
        

    MIL OSI Asia Pacific News

  • MIL-OSI Asia-Pac: CHP investigates case of invasive meningococcal infection

    Source: Hong Kong Government special administrative region

    CHP investigates case of invasive meningococcal infection
    CHP investigates case of invasive meningococcal infection
    *********************************************************

         The Centre for Health Protection (CHP) of the Department of Health is today (September 23) investigating a case of invasive meningococcal infection, a communicable disease transmitted by direct contact with droplets from carriers or infected persons.     The case involves a 50-year-old female with good past health, who presented with malaise, fever and a rash since September 18, and sought medical attention from a private doctor on September 19. She attended the Accident and Emergency Department of Tseung Kwan O Hospital on September 21 due to dizziness, headache, vomiting and a stiff neck and was admitted for treatment on the same day. Her cerebrospinal fluid sample tested positive for Neisseria meningitidis upon laboratory testing. Her clinical diagnosis was meningitis. The patient is now in stable condition.     Initial enquiries revealed that the patient had no travel history during the incubation period. Her household contacts remain asymptomatic. The CHP’s investigation is continuing.     “Meningococcal infection is caused by a bacterium known as meningococcus. It is mainly transmitted by direct contact through respiratory secretions, including droplets from the nose and throat, from infected persons. The incubation period varies from two to 10 days, and is commonly three or four days,” a spokesman for the CHP said.     The clinical pictures among the infected may vary. Severe illness may result when the bacteria invade the bloodstream (meningococcaemia) or the membranes that envelop the brain and spinal cord (meningococcal meningitis).     Meningococcaemia is characterised by a sudden onset of fever, an intense headache, purpura, shock and even death in severe cases. Meningococcal meningitis is characterised by high fever, severe headache and a stiff neck followed by drowsiness, vomiting, fear of bright light, or a rash. It can cause brain damage or even death. The brain damage may lead to intellectual impairment, mental retardation, hearing loss and electrolyte imbalance. Invasive meningococcal infection can be complicated by arthritis, inflammation of the heart muscle, inflammation of the posterior chamber of the eye or chest infection.     Meningococcal infection is a serious illness. Patients should be treated promptly with antibiotics.     To prevent meningococcal infection, members of the public are advised to take heed of the following measures: 

    Wash hands with liquid soap and water properly, especially when they are dirtied by respiratory secretions, e.g. after sneezing, and clean hands with alcohol-based handrub when they are not visibly soiled;
    Cover the nose and mouth while sneezing or coughing, hold the spit with a tissue, dispose of nasal and mouth discharge in a lidded rubbish bin, and wash hands immediately;
    Avoid crowded places;
    Avoid close contact with patients who have a fever or severe headache;
    Travellers to high-risk areas may consult doctors for meningococcal vaccination; and
    Travellers returning from high-risk areas should seek medical advice if they become ill, and should discuss their recent travel history with their doctor.

         ???The public may visit the CHP’s website for more information on meningococcal infection.

     
    Ends/Monday, September 23, 2024Issued at HKT 17:45

    NNNN

    MIL OSI Asia Pacific News

  • MIL-OSI Translation: AFRICA/DR CONGO – Religious confessions’ commitment to peace in South Kivu

    MIL OSI Translation. Region: Italy –

    Source: The Holy See in Italian

    CDJP Bukavu

    Kinshasa (Agenzia Fides) – The important interreligious meeting for peace held on September 21 in Bukavu, capital of South Kivu, one of the three provinces in the east of the Democratic Republic of Congo, which have been tormented for decades by violence committed by dozens of armed groups, ended on a note of hope. The meeting was held at the archbishopric of the city and saw the participation of representatives of various religious denominations of the entire ecclesiastical province of Bukavu (Catholics, Kimbanguists, Muslims, Orthodox Christians, revival churches, Anglicans, Protestants, Salvation Army, Union of Independent Churches), as well as those of the diocese of Cyangugu, in Rwanda. The participation of Rwandan representatives is particularly significant and important. The government of Rwanda is accused by the Congolese government of providing support to guerrilla groups operating in the DRC, in particular to the M23, active especially in North Kivu. Kigali, in turn, accuses Kinshasa of tolerating the presence on its territory of the Democratic Forces for the Liberation of Rwanda (FDLR) for decades, considered an emanation of the old Rwandan regime responsible for the genocide of 1994. The effort of dialogue of all religious confessions was praised by the governor of South Kivu, who stressed the importance of collaboration between civil authorities and religious faiths to establish an exemplary system of government. Joining his voice with that of religious leaders, the governor recalled that building peace and good governance requires the involvement of all, beyond political or spiritual differences. During the meeting, the other emergency that this area of the DRC is experiencing, the Mpox epidemic (the so-called “monkeypox”), was also addressed. Dr. Deogratias Cigwerhe, a specialist in the field, provided a detailed anamnesis of the disease, determining its origin, the methods of transmission and the preventive measures to be adopted to limit its spread. His speech made it possible to raise awareness among participants about the dangers posed by the disease and the importance of collective efforts to prevent it. (LM) (Agenzia Fides 23/9/2024)Share:

    EDITOR’S NOTE: This article is a translation. Apologies should the grammar and/or sentence structure not be perfect.

    MIL Translation OSI

  • MIL-OSI Translation: ASIA/SRI LANKA – President Dissanayake: The New Face of the Nation

    MIL OSI Translation. Region: Italy –

    Source: The Holy See in Italian

    Colombo (Agenzia Fides) — Anura Kumara Dissanayake is the new president of Sri Lanka, as announced yesterday by the Electoral Commission, after the vote on Saturday 21 September. A left-wing MP, Dissanayake received – as announced by the Electoral Commission – over 5.7 million votes, followed by candidate Sajith Premadasa with 4.5 million. During the election campaign, Dissanayake aimed to gain the favor of the working class and found polarization among young people and in the middle-lower social classes, while Sri Lanka is trying to recover after an economic and political crisis that brought the country to its knees and exacerbated widespread poverty. Two years ago, tens of thousands of Sri Lankans rebelled and forced the then President Rajapaksa to flee the country, “and since then there has been a great desire for change in society: this is the result, which I would not hesitate to define as historic”, comments Fr. Basil Rohan Fernando, a priest of the Archdiocese of Colombo and National Director of the Pontifical Mission Societies on the island. Fr. Fernando notes “a positive atmosphere in society: first of all, it should be noted that the electoral process was peaceful and transparent and then, in the aftermath of the vote, there were no clashes between opposing factions, as has often happened in the past”. Furthermore, he notes, “there is an atmosphere of great hope in society. The population wanted something new, they strongly wanted a change and so it was, the will of the people was expressed democratically”. If the international press calls Dissanayake “the “Marxist” president, Fr. Fernando notes: “The label should not cause alarm and is related to ideological positions of the past. The new president is well inserted in the democratic framework and his declared objective is to work for the poor and vulnerable, which is what the nation needs. It is believed that within a month the president will also call general elections for the renewal of Parliament and this will allow the nation to be given a totally new face, with the entry into active politics of educated and qualified young people, which will be a clear break with the old establishment, involved in corruption games”. On the Catholic community – about 1.5 million faithful out of 22 million inhabitants – the priest notes that in the “coastal belt, which includes Colombo, Chilaw and other places where most of the Sri Lankan Catholic population lives, support for Dassyake has been very high. This shows that there has also been consensus among the Catholic population. Generally I see the faithful satisfied and hopeful. The population expects a lot from the new president, “In particular, the Catholic Church does not forget the sensitive topic of the Easter attacks of 2019: “The hope is that even on that front, a serious episode of now five years ago, a wound in national history, we can sincerely and truly promote the justice that is still missing, with the recognition of those responsible and help to the victims”. (PA) (Agenzia Fides 23/9/2024) Share:

    EDITOR’S NOTE: This article is a translation. Apologies should the grammar and/or sentence structure not be perfect.

    MIL Translation OSI

  • MIL-OSI United Kingdom: Celebrating a Century of Love: Old Marylebone Town Hall marks 100 Years with 100 Weddings | Westminster City Council

    Source: City of Westminster

    We are just days away from celebrating the 100th anniversary of Old Marylebone Town Hall, an iconic venue renowned for hosting weddings of legendary figures like Ringo Starr, Sir Paul McCartney, and Liam Gallagher.

    In honour of this milestone, 100 lucky couples will soon tie the knot, enter into civil partnerships, or renew their vows at this historic location for just £100—a fraction of the usual cost. Each couple can bring up to 8 guests and even 2 pets to share their special day.

    The team at Old Marylebone Town Hall has been working tirelessly to prepare for this momentous occasion. On the 1st October 2024, from 8:00 AM to 10:30 PM, the venue will host a diverse range of couples, celebrating love in all its forms on one of the most important days of their lives.

    Pop star Cilla Black and her personal manager Bobby Willis after their wedding at Marylebone Town Hall 25 January 1969

    Many of the couples share a deep connection to Westminster—whether through living, working, or studying in the area. Many even began their relationships in Westminster.

    For others, the venue holds special significance, with parents who were married or children registered at Old Marylebone Town Hall, making it the perfect place to celebrate their own love stories. Many couples have expressed their excitement about being part of such a historic event, adding a unique layer of meaning to their special day.

    Here are some of the reasons behind why the couples chose to get married on this special day:

    I used to work around Marylebone and walk past the town hall every week. Watching the couples walk down the iconic stairs and enjoying their happiest day, I said to myself that one day I’d like to get married there too. And I can’t believe that it’s going to happen soon, I’m so excited! It’s a dream come true.”

    It sounds so fun and way more ‘us’ than a big wedding. I love that we won’t be the centre of attention and that 99 other couples will be celebrating the same day. And also save a fortune. We have hired an afternoon tea bus for after but the money we have saved is all going on a bucket list honeymoon to Mauritius!”

    Marylebone Town Hall has always been one of my favourite venues and we were contemplating about where to get married, having been engaged for a year or so. On October 24th last year, I was on my commute home reading the Evening Standard, and I saw the article about the centenary. I always associate the Old Town Hall with the Beatles and the 60s, and the photos caught my eye. Both my fiancé and I will be 64 when we get married so it seemed a perfect match. ‘When I’m 64’ won’t be our music choice, but it very nearly was!”

    Councillor Ryan Jude, Cabinet Member for Climate, Ecology and Culture says:

     We are thrilled to celebrate the 100th anniversary of Old Marylebone Town Hall, a venue that holds historical and cultural significance for Westminster. This milestone is not just a reflection of the building’s rich past, but also a celebration of the diverse couples who will be creating new memories here.

    I am excited to see so many people with personal ties to Westminster come together to mark this occasion. We look forward to continuing the tradition of love at this iconic venue for many more years to come.”

     Notes:

    • Media access is limited, and space for coverage is restricted.
    • Please complete this form, and we will follow up to confirm if we can accommodate your request. Only accredited media will be allowed on-site on the day.
    • For further media inquiries, please contact [email protected]

    MIL OSI United Kingdom

  • MIL-OSI United Kingdom: Over 100 get health checked at city’s cancer bus

    Source: City of Wolverhampton

    Organised by the local NHS in partnership with the City of Wolverhampton Council’s Public Health team, the cancer bus tour was an opportunity for local people to meet and talk with a range of clinicians about how to check for symptoms of cancer, the support services available and what to do if they’re concerned.

    Attendees were given information on the 3 main NHS cancer screening programmes of breast, bowel and cervical, including when people will be invited and what’s involved in the screening. Macmillan Cancer Support also attended and offered support for people living with and beyond cancer.

    Councillor Jasbir Jaspal, the City of Wolverhampton Council’s Cabinet Member for Adults and Wellbeing, said: “We were pleased to be able to work with the NHS in the Black Country to bring the bus to Queen Square, and delighted that over 200 people came along to either have a health check or find out more about cancer and the cancer screening process.”

    Dr Mona Sidhu, Medical Director of Primary Care for the NHS Black Country Integrated Care Board, added: “Early detection is the best form of defence against cancer and it’s vital that people know the signs and symptoms to look out for.

    “That’s why initiatives like the cancer bus tour are so important. They give us the opportunity to have one on one conversations with people who may not realise they are at risk, who may not recognise potential symptoms or may feel unable to act on them or are too fearful to.

    “It was fantastic to see so many people come forward so thank you to everyone who paid us a visit. And please remember, if you notice something that isn’t normal for you or isn’t going away, it’s important to speak to your GP. It probably won’t be cancer. But if it is, spotting it early can make a real difference.”

    To find out more about the cancer screening process, please watch the following videos:

    Breast    
    Bowel  
    Cervical   

    MIL OSI United Kingdom

  • MIL-OSI United Kingdom: More green fingers for work at Elemore Country Park

    Source: City of Sunderland

    A ‘not for profit’ community interest company that helps train older, vulnerable or adults with disabilities, is receiving a boost from the City Council.

    Bishopwearmouth Co-operative is based at the Bishopwearmouth Nursery in Chester Road. It has its own garden centre, tea rooms and offers gardening and landscaping services for the public.

    In 2023 it expanded to Elemore Country Park in Easington Lane with a garden centre and coffee shop.

    A key part of its work is how the company encourages and provides work and training opportunities in horticultural, floristry and other gardening services. All the opportunities are for older people, vulnerable adults, people who may have a learning disability, physical disability, or have mental health needs.

    Sunderland City Council’s decision-making Cabinet has now backed a £125,000 grant to help provide further training and work-based placements focused on Elemore Country Park. The funding was backed at the Cabinet meeting in City Hall on Thursday 19 September. It is to help towards providing six full-time placements for day and volunteering opportunities over the next two years.

    The City Council’s Deputy Leader and Cabinet Member for Health, Wellbeing and Community Services, Councillor Kelly Chequer welcomed the support.

    She said: “As a council we are completely committed to supporting everyone in our communities and to reducing inequalities. The Bishopwearmouth Co-operative company continues to do great work with vulnerable adults and helping them to move on to greater independence.”

    “Alongside this important work with people, the funding helps support the ongoing investment in Elemore and our communities in the Coalfield area as we bring more improvements to this great new and still improving country park.”

    Elemore is following in the footsteps of other similar and successfully reclaimed colliery sites in and around Sunderland such as Hetton Lyons Country Park, Herrington Country Park and Rainton Meadows Nature Reserve. They are all examples of how land once set over to the coal mining industry can become new ecosystems and community assets. This summer Elemore hosted its second Family Music Festival on Saturday 24 August.

    Bishopwearmouth Co-operative CIC, currently employs 30 staff and has provided over a hundred job, training and volunteer opportunities since it was founded.

    Managing Director Shaun Donnelly said: “This is brilliant news it will allow Bishopwearmouth to build on its volunteer and day opportunities for vulnerable adults. The grant from the council will allow us to provide day opportunities and training in catering and horticulture, we will also continue to assist the community by working within Elemore Country Park and organising events. 

    “In addition to the park’s schedule of events, our team will continue working with other partners in the park assisting with tree planting and maintenance.”

    MIL OSI United Kingdom

  • MIL-OSI Economics: How the Necro Trojan infiltrated Google Play, again

    Source: Securelist – Kaspersky

    Headline: How the Necro Trojan infiltrated Google Play, again

    Introduction

    We sometimes come across modified applications when analyzing suspicious files. These are created in response to user requests for more customization options within the app or for new features that the official versions don’t have. Unfortunately, it’s not uncommon for popular mods to contain malware. This often happens because they’re distributed on unofficial websites that don’t have any moderation. For example, last year we found popular WhatsApp mods infected with CanesSpy and distributed this way. Before that, we found ads for WhatsApp mods infected with the Triada Trojan dropper in the popular Snaptube application. However, even official app stores can be infiltrated by infected apps. In 2019, we discovered the Necro dropper hidden within CamScanner, a widely used document scanning and processing app available on Google Play. At the time of the malware discovery, this app had been downloaded to more than 100 million devices worldwide. Sadly, history has repeated itself, and this time the Trojan authors exploited both distribution vectors: the new version of the multi-stage Necro loader infected both apps in Google Play and modified versions of Spotify, Minecraft, and other popular applications in unofficial sources.

    Our conclusions in a nutshell:

    • The new version of the Necro Trojan has infected various popular applications, including game mods, with some of them being available on Google Play at the time of writing this report. The combined audience of the latter exceeds 11 million Android devices.
    • The new version of the Necro loader, like most payloads it loads, has begun to use obfuscation to evade detection.
    • The loader, embedded in some applications, used steganography techniques to hide payloads.
    • The downloaded payloads, among other things, could display ads in invisible windows and interact with them, download and execute arbitrary DEX files, install applications it downloaded, open arbitrary links in invisible WebView windows and execute any JavaScript code in those, run a tunnel through the victim’s device, and potentially subscribe to paid services.

    How Necro spreads

    Necro loader inside a Spotify mod

    In late August 2024, our attention was drawn to a Spotify mod called Spotify Plus, version 18.9.40.5. At the time of writing this, the mod could be downloaded from spotiplus[.]xyz and several related sites that linked to it. The original website claimed that the mod was certified, safe, and contained numerous additional features not found in the official app. We decided to verify the claims about the application’s safety by downloading the latest version from this website (acb7a06803e6de85986ac49e9c9f69f1) and analyzing it.

    Site containing the Spotify mod

    The mod implements a custom Application subclass that initializes an SDK named adsrun in its onCreate method. This SDK is intended for integrating several advertising modules into the application: among other things, it initializes a module named Coral SDK. Upon activation, Coral SDK transmits a POST request to a designated command-and-control server. This request contains encrypted JSON data, specifically detailing the compromised device and the application hosting the module. The encryption method employed is a substitution cipher, where the substitution values are generated using a standard Java pseudo-random number generator seeded with a predefined constant. See an example of data sent by the module below.

    The C2 server returns a JSON response with an error code, encrypted with the same method. A value of 0 indicates successful execution. In this case, the response from the C2 will also contain an array of one object with a link to download the image in PNG format and associated metadata: name, MD5, version, and so on. Intriguingly, the downloaded file is termed “shellP”, suggesting it might be a condensed form of “shellPlugin”.

    Next, the module verifies the integrity of the downloaded image by calculating its MD5 hash and comparing it to the value received from the server. A payload is hidden in this image using steganography, which the module must extract and execute in the next step.

    Coral SDK uses a very simple steganographic algorithm. If the MD5 check is successful, it extracts the contents of the PNG file — the pixel values in the ARGB channels — using standard Android tools. Then the getPixel method returns a value whose least significant byte contains the blue channel of the image, and processing begins in the code.

    Steganographic algorithm for payload extraction

    If we consider the blue channel of the image as a byte array of dimension 1, then the first four bytes of the image are the size of the encoded payload in Little Endian format (from the least significant byte to the most significant). Next, the payload of the specified size is recorded: this is a JAR file encoded with Base64, which is loaded after decoding via DexClassLoader. Coral SDK loads the sdk.fkgh.mvp.SdkEntry class in a JAR file using the native library libcoral.so. This library has been obfuscated using the OLLVM tool. The starting point, or entry point, for execution within the loaded class is the run method.

    Starting the payload

    Therefore, the security claims made about the application on the mod website can be considered false.

    Having searched for the loader in our telemetry, we found other apps infected with Necro, including those available in Google Play at the time of writing this report. Their combined audience numbered more than 11 million Android devices.

    Wuta Camera app in Google Play

    Our first find is the Wuta Camera app. Judging by its page in Google Play, it was downloaded at least 10 million times. According to our data, the Necro loader has been embedded in it starting from version 6.3.2.148. The latest version of the app at the time of collecting information, 6.3.6.148 (1cab7668817f6401eb094a6c8488a90c), which was available on Google Play, also had the Necro loader. We reported the presence of malicious code to Google Play, after which the loader was removed from the app in version 6.3.7.138.

    Malicious loader in Wuta Camera

    The second infected app we found was Max Browser.

    Max Browser app in Google Play

    This browser, according to Google Play, has been installed more than a million times and, starting with version 1.2.0, also contained the Necro loader. After we reported it, Google took down the infected app from their store.

    Necro Trojan within Max Browser

    WhatsApp mods with the Necro loader

    We also found WhatsApp mods containing the Necro loader (0898d1a6232699c7ee03dd5e58727ede) in unofficial sources. The infected application is distributed under the package name com.leapzip.animatedstickers.maker.android. Interestingly, there’s a legitimate app on Google Play with the exact same package name that isn’t a WhatsApp mod, but instead offers a collection of stickers for the messaging app.

    The loader contained within the ad module in these applications functions somewhat differently from the sample described above. For instance, the code isn’t obfuscated at all but is protected by the SecAPK code protector. Additionally, the application uses Google’s Firebase Remote Config cloud service as a C2, storing information about files that need to be downloaded and executed.

    Running the payload

    While examining this loader, we discovered an interesting quirk: the malicious code within it has an 84% or 90% chance of execution. Initially, a random number between 0 and 99 is generated. Subsequently, based on the application package name, a threshold for malware execution is selected: the generated number must exceed either 9 or 15 for the loader to launch. If the number meets this criterion, a corresponding flag inhibiting loader operation is set to false, and the malicious functionality is executed.

    The malicious functionality will be executed with a predetermined probability

    Intermediate payloads downloaded by this loader are not pre-encoded. The Trojan receives both the entry point information for the downloaded file and the download link from its C2 server. According to our data, one of the payloads (37404ff6ac229486a1de4b526dd9d9b6) bore resemblance to a loader found in a modified version of Spotify, albeit with minor variations.

    • The next-stage payload (shellPlugin) is loaded without the aid of native code.

      Loading shellPlugin

    • A different path is used for the POST request to the command-and-control server to retrieve shellPlugin information.
    • Instead of using the steganographic algorithm, shellPlugin is decoded with Base64.

    Other infected applications

    This is not an exhaustive list of our findings. In addition to Spotify and WhatsApp mods, as well as apps in Google Play, we found infected game mods, including the following:

    • Minecraft;
    • Stumble Guys;
    • Car Parking Multiplayer;
    • Melon Sandbox.

    Given that various apps from multiple sources, including official ones, were found to be infected, we believe that the developers used an untrusted solution for ad integration. This led to a malicious loader appearing in the apps. Our security solutions detect it with the following verdicts:

    • HEUR:Trojan-Downloader.AndroidOS.Necro.f;
    • HEUR:Trojan-Downloader.AndroidOS.Necro.h.

    The Necro lifecycle in the wild: how the payload works

    During our research, we managed to obtain several samples of payloads that the loader subsequently executes. This particular payload (fa217ca023cda4f063399107f20bd123) exhibits several interesting characteristics that allow us to classify it as belonging to the Necro family:

    • The loader obtains download information from the C2 domain bearsplay[.]com. According to our telemetry data, the domain has been contacted by Necro-family malware.
    • According to our data, the C2 domains that this file interacts with are also being used by the Necro and xHelper Trojans.
    • The functionality of this new payload is very similar to the previous version of Necro (402b91c6621b8093d44464fc006e706a). The code of the Trojans is also similar, but in this new payload, the attackers have used an obfuscator to make it harder for security solutions to detect and analyze.

      Code snippet from the payload

      Similar code snippet from an old version of Necro

    • The payload configuration structure is identical to that of older versions of Necro, including the one we previously discovered in the CamScanner app. The field names in the configuration match the corresponding fields in other Necro versions.

    Based on this, we assert that both the examined payload and the original loader belong to the Necro family, which is familiar to us.

    Payload structure

    Now let’s move on to analyzing the payload. The second stage of the launch process reads a JSON-formatted configuration embedded within the code. An example of the configuration is provided below.

    The rp switch might contain malicious services to be launched, but it was empty in the samples we analyzed.

    Code for launching the malicious service from the “rp” parameter

    The mp configuration switch holds parameters for the second-stage loader. It’s likely an abbreviation for “module parameters”.

    The malicious functionality of Necro is implemented in additional modules that are downloaded from the C2 server. The malware authors frequently refer to these as “plugins” in the code. The ps configuration field (likely an abbreviation for “plugin stop list”, meaning a list of prohibited plugins) is necessary to block these modules. The switches in this object are the names of plugins that are forbidden to load, and the values are alternative plugins that can be executed instead of the blocked ones if they were loaded. The download ban will be applied if the mp field has the PluginControl flag set to true. However, in the samples we were able to obtain, the restrictions did not apply. Additionally, the mp field may contain the PluginUpdateFeature flag, which controls plugin updates. If this flag is not present, plugins will be updated by default.

    The hs switch in the configuration stores a list of C2 addresses which the Trojan will talk to. Note that the malware logic does not require all addresses to match, although in the sample we examined, they were identical. The Trojan needs each address to perform the following tasks:

    • server is used to update the PluginServer server address. To do this, the Trojan first sends a POST request containing the ID of the malicious implant and the name of the application package it’s embedded into. After that, the server can send a new PluginServer address. If the address cannot be updated, the value from the configuration set in the code is used.

      Updating PluginServer

    • dataevent is used to store various events related to SDK activity.
    • default is not used at this stage.
    • PluginServer instructs the Trojan which plugins to download. Initially, a large amount of data is sent to this server. This includes information about the infected device (screen size, RAM, IMEI, IMSI, operating system version), information about the device’s environment (whether USB debugging mode and developer mode are enabled, if emulator artifacts are detected, etc.), details about the infected app, and so on.

      Sending collected data to PluginServer

    In response, the server sends a list of plugins to download. These are downloaded asynchronously. To do this, the malware registers a broadcast receiver, and a separate thread, which is started for the download, sends a broadcast message when a plugin is ready to be downloaded. The plugins are differentiated by their name, which is also provided by the server.

    Plugin encryption and loading

    The plugin loading code supports, among other things, the ability to decrypt plugins using various methods. Additionally, payloads can be extracted beforehand using the steganographic algorithm described above if a file with a .png extension was downloaded. The decryption method is specified in the file URL. The following options are available:

    • new/ enc: decryption with a substitution cipher similar to that used for C2 communication
    • ssd: plugin decryption using the DES algorithm
    • ori: unencrypted plugin

      Selecting a decryption procedure

    If no encryption method is specified, the plugin will be decrypted using a substitution cipher. The initial seed for this cipher will be the PMask parameter (short for plugin mask), which is defined in the mp object within the loader configuration. Once decoded, plugins can be loaded in various ways.

    Selecting a method to load the plugin

    • dex: this method loads the plugin using DexClassLoader. The loader provides it with the application and plugin context, and additional plugin information.

      Loading the plugin in dex mode

      Launching the plugin entry point

    • res: this method allows loading plugins with new resources. These resources can be used to download more plugins in the future.

      Loading new resources

    • apk: a method that allows sending information about a downloaded file to a service via the IPC Binder mechanism. The name of the service is specified in the bird_vm_msg_service property. While it’s not definitively known which services Necro used, we can speculate that this function is used to install arbitrary APK files on the victim’s device.

    Types of plugins

    To better understand the attackers’ goals, we decided to thoroughly examine the payloads downloaded by the Trojan and, after analyzing telemetry data, found several Necro modules.

    ed6c6924201bc779d45f35ccf2e463bb – Trojan.AndroidOS.Necro.g

    This is a Necro module named “NProxy”. Its purpose is to create a tunnel through the victim’s device. When launched, the module connects to a server defined in the code.

    Connecting to the server

    This server acts as a C2 server that the Trojan talks to via an unidentified protocol implemented over TCP sockets. The C2 sends commands, which the Trojan processes. After processing, the Trojan forwards traffic from one endpoint to another through the victim’s device.

    b3ba3749237793d2c06eaaf5263533f2 – Trojan.AndroidOS.Necro.i

    We named this plugin “island”. When launched, the plugin generates a pseudo-random number, which it uses as an interval (in milliseconds) between displays of intrusive ads.

    Trojan showing ads

    ccde06a19ef586e0124b120db9bf802e – Trojan.AndroidOS.Necro.d

    This plugin is named “web”, and it is one of the most popular Necro plugins, judging by our telemetry data. Its code contains a configuration similar in structure to the shellPlugin payload configuration in the previous stage. It’s interesting that the code for this plugin contains artifacts of older versions of Necro.

    nicro is one such artifact from older Necro versions found within the plugin’s configuration

    Depending on the value of the CheckAbnormal flag, the plugin checks for the presence of a debugger in the execution environment and if a phone is connected via USB using ADB. If either condition is met, the Trojan clears the Logcat log to hide traces of its activity. Additionally, the plugin verifies if it has the permission to display windows on top of other applications. After all these checks, it launches a malicious task that runs once every two hours. When the malware starts, it sends a POST request containing details about the infected device to the server server. This is done to get the address of another server, named main URL, which the Trojan will communicate with frequently. If there’s an error when getting this address, the malware will fall back to using a server named default.

    Data about the infected device sent to the C2

    The received main URL serves as the C2 server: it sends a list of pages to the Trojan, which the malware later opens in the background before processing the interactive elements contained on them. This functionality has a couple of interesting features. First, the Trojan code contains some artifacts that indicate it might be running with elevated privileges. However, Android processes with elevated privileges do not allow WebView by default. Privilege checks occur directly when creating an instance of the WebView factory: in privileged processes, it won’t be created. To circumvent this restriction, the Trojan creates an instance of the factory directly using reflection, thus bypassing all checks of the current process.

    Instantiating a WebView factory directly

    Secondly, the Trojan can download and run other executables, which are then used to replace links loaded with WebView. Combined with the functionality described above, this theoretically allows to do things like adding any additional information to the URL parameters of a replaced link, such as confirmation codes for paid subscriptions, as well as executing other arbitrary code when loading specific links.

    36ab434c54cce25d301f2a6f55241205 – Trojan-Downloader.AndroidOS.Necro.b

    This module is named “Happy SDK”. Its code partially combines the NProxy and web modules logic, as well as the functionality of the previous stage of the loader with a few minor differences:

    • The code lacks the Trojan configuration, and backup C2 servers are located by default in the corresponding methods.

      Server address for updating the module is specified in the method code by default

    • The code corresponding to the “web” plugin lacks the functionality to execute arbitrary code.
      Note that we have occasionally encountered this SDK under the name “Jar SDK”. Analysis has shown that Jar SDK is a new version of Happy SDK.

      Happy SDK artifacts in Jar SDK

    We believe this is a different variant of Necro where the developers have opted for a non-modular architecture in the malicious SDK. This suggests that Necro is highly adaptable and can download different iterations of itself, perhaps to introduce new features.

    874418d3d1a761875ebc0f60f9573746 – Trojan.AndroidOS.Necro.j

    We dubbed this plugin “Cube SDK”. It’s pretty simple and acts as a helper: its only job is to load other plugins to handle ads in the background.

    522d2e2adedc3eb11eb9c4b864ca0c7f – Trojan.AndroidOS.Necro.l

    This plugin, in addition to NProxy’s functionality, has an entry point for another plugin we’ve named “Tap”. Judging by its code, the latter is still under development: it contains a lot of unused functionality for interacting with ad pages. Tap downloads arbitrary JavaScript code and a WebView interface from the C2 server, which are responsible for viewing ads in the background. Among other things, the plugin includes com.leapzip.animatedstickers.maker.android as the package name of the infected app. This confirms that the WhatsApp mod loader described earlier, which uses Firebase Remote Config as a C2, also belongs to the Necro family.

    These are all the payloads we were able to find during our research. For simplicity, we’ve combined all the processes described above into a single diagram illustrating all stages of the Necro Trojan.

    Necro Trojan infection diagram

    It’s worth noting that the creators of Necro may regularly release new plugins and distribute them among infected devices, selectively or otherwise, for example, depending on the information about the infected application.

    Victims

    According to Google Play data, the infected applications could have been downloaded over 11 million times. However, the actual number of infected devices might be much higher, considering that the Trojan also infiltrated modified versions of popular apps distributed through unofficial sources.

    KSN data shows that our security solutions blocked over ten thousand Necro attacks worldwide between August 26th and September 15th. Russia, Brazil, and Vietnam experienced the highest number of attacks. The chart below illustrates the distribution of Necro attacks across countries and territories where users most frequently encountered the Trojan.

    Necro attacks by country and territory, August 26 through September 15, 2024 (download)

    Conclusion

    The Necro Trojan has once again managed to attack tens of thousands of devices worldwide. This new version is a multi-stage loader that used steganography to hide the second-stage payload, a very rare technique for mobile malware, as well as obfuscation to evade detection. The modular architecture gives the Trojan’s creators a wide range of options for both mass and targeted delivery of loader updates or new malicious modules depending on the infected application. To avoid being infected with this malware:

    • If you have any of the aforementioned Google Play apps installed and the versions are infected, update the app to a version where the malicious code has been removed, or delete it.
    • Download applications from official sources only. Applications installed from unofficial platforms may contain malicious functionality.
    • Use a reliable security solution to protect your device from attempts to install malware.

    Indicators of compromise

    Applications infected with the loader

    Loader C2 server
    oad1.bearsplay[.]com
    shellPlugin versions

    Second-stage payload
    37404ff6ac229486a1de4b526dd9d9b6

    Second-stage payload C2 server
    oad1.azhituo[.]com

    Plugins (third stage)

    Plugin C2 servers
    47.88.246[.]111
    174.129.61[.]221
    47.88.245[.]162
    47.88.190[.]200
    47.88.3[.]73
    hsa.govsred[.]buzz
    justbigso[.]com
    bear-ad.oss-us-west-1.aliyuncs[.]com

    MIL OSI Economics

  • MIL-OSI Video: Reminder to world leaders of the incredible potential of refugees – Youth at Summit of the Future

    Source: United Nations (Video News)

    Remarks by Monicah Malith, (Republic of South Sudan), refugee youth advocate at the Opening of the Summit of the Future.

    Malith reminded world leaders of the incredible potential of refugees when they are seen, heard, and empowered.

    She also reminded young people that “The future is ours to forge. Not theirs to cling to. Not theirs to pass down like spoils of war.”

    ————————–

    The Summit of the Future (22-23 September 2024) is a once-in-a-generation opportunity to enhance cooperation on critical challenges and address gaps in global governance, reaffirm existing commitments including to the Sustainable Development Goals and the United Nations Charter, and move towards a reinvigorated multilateral system that is better positioned to positively impact people’s lives.

    The Summit of the Future is a high-level event, bringing world leaders together to forge a new international consensus on how we deliver a better present and safeguard the future.

    Effective global cooperation is increasingly critical to our survival but difficult to achieve in an atmosphere of mistrust, using outdated structures that no longer reflect today’s political and economic realities.

    World leaders will convene at the United Nations to adopt the Pact for the Future, which will include a Global Digital Compact and a Declaration on Future Generations as annexes.

    Screenshot Credit:
    UN Photo/Loey Felipe

    Website: https://www.un.org/en/summit-of-the-future

    Programme: https://www.un.org/en/summit-of-the-future/programme

    https://www.youtube.com/watch?v=W4t692S9rBo

    MIL OSI Video

  • MIL-OSI Video: Summit of the Future Action Days | United Nations

    Source: United Nations (Video News)

    The Summit offers a once-in-a-generation opportunity for change.
    It will pave a way to a better tomorrow that we can only shape together.

    In support of this vision and objectives, The Summit of the Future Action Days will be convened by the Secretary-General of the United Nations on 20 and 21 September 2024 at United Nations Headquarters in New York to generate additional opportunities for the engagement of all actors.

    Bringing together representatives from Member States, civil society, private sector, academia, local and regional authorities, youth, and many more, the Action Days will provide an opportunity for broad engagement and inclusion. These stakeholders have all played a key role in shaping the Pact for the Future and its annexes, and will be critical to implementation.

    The Action Days will kick off with a dedicated, youth-led afternoon followed by a Saturday programme which will focus on three priority themes – digital and technology, peace and security, and sustainable development and financing. In addition to the three themes, there will also be a dedicated focus throughout the day on future generations. Expected participants include Heads of State, Ministers, senior UN officials and representatives from the private sector, civil society and other actors.

    More information: https://summitofthefutureun.org/action-days

    https://www.youtube.com/watch?v=nUTRLpJvmDc

    MIL OSI Video

  • MIL-OSI Video: Call for Climate Justice and Indigenous Wisdom – Youth Representative at the Summit of the Future

    Source: United Nations (Video News)

    Niria Alicía Garcia, a Xicana human rights advocate from the United States, climate justice organizer, educator and storyteller, said her generation’s hearts are breaking as it endures the impacts of climate disaster that could have been prevented.

    “Our mother earth is hurting, and she needs our help. Worldwide our waters and sacred places are being desecrated. Corporate greed and war are pushing life to the verge of extinction. Global governments and politics are void of spirituality, of morality and basic respect for life,” she said.

    Speaking about the Pact for the Future, she highlighted that while it mentions words like sustainable development nearly 300 times, words like children, Earth and future generations are mentioned less than 60 times.

    “Do Indigenous Peoples still not exist to you? Are we not the stewards of 80 per cent of the world’s biodiversity?” she emphasised.

    However, she concluded on a hopeful note, stating firmly, “make no mistake that we have the medicine that this world needs and that with the help of creation, we will turn the tide for good.”

    ——————————-

    The Summit of the Future (22-23 September 2024) is a once-in-a-generation opportunity to enhance cooperation on critical challenges and address gaps in global governance, reaffirm existing commitments including to the Sustainable Development Goals and the United Nations Charter, and move towards a reinvigorated multilateral system that is better positioned to positively impact people’s lives.

    The Summit of the Future is a high-level event, bringing world leaders together to forge a new international consensus on how we deliver a better present and safeguard the future.

    Effective global cooperation is increasingly critical to our survival but difficult to achieve in an atmosphere of mistrust, using outdated structures that no longer reflect today’s political and economic realities.

    World leaders will convene at the United Nations to adopt the Pact for the Future, which will include a Global Digital Compact and a Declaration on Future Generations as annexes.

    Screenshot credit:
    UN Photo/Loey Felipe

    Website: https://www.un.org/en/summit-of-the-future

    Programme: https://www.un.org/en/summit-of-the-future/programme

    https://www.youtube.com/watch?v=sgie5rC8x7Y

    MIL OSI Video

  • MIL-OSI Video: Buttigieg on the Alaska and Hawaiian Airlines merger

    Source: United States of America – Federal Government Departments (video statements)

    For the first time in the history of our Department’s airline merger review process, we have locked in consumer protections up front to ensure Alaska and Hawaiian Airlines passengers were treated fairly before the merger moved forward.

    https://www.youtube.com/watch?v=gzyph0grI14

    MIL OSI Video

  • MIL-OSI Video: Shaping local pathways for a more equitable, sustainable, & secure future for all – UN Deputy Chief

    Source: United Nations (Video News)

    Remarks by Ms. Amina J. Mohammed, Deputy Secretary-General, at Shaping local pathways for a more equitable, sustainable, and secure future for all – “Localizing the Pact for the Future” (Side Event, Action Day 2, Summit of the Future).

    https://www.youtube.com/watch?v=dygUW6AoXfc

    MIL OSI Video

  • MIL-OSI Video: Where is the next UNGA meeting & when is it? – #UNGA Explained | United Nations

    Source: United Nations (Video News)

    From today, UN Video presents a series of videos addressing the most frequently asked questions by the public, aimed at demystifying and explaining the General Assembly. These eight short clips are available, please share! We appreciate your warm reception of these materials! We would like to thank Julia Foxen and Heyi Zou for their contributions to these explainers.

    https://www.youtube.com/watch?v=EAPzJ8-j6TY

    MIL OSI Video

  • MIL-OSI Video: The Life of a UN Security Council Resolution

    Source: United Nations (Video News)

    How does a Security Council resolution get adopted? 
    The 15-member Council is charged with taking action, through resolutions and decisions, on any threats to international peace and security, but sometimes adopting a draft into a legally binding document for the UN’s 193 Member States faces multiple hurdles. 
     
    Utilizing material from the UN Audiovisual Library, this production showcases imagery shot over several decades.

    https://www.youtube.com/watch?v=HYUc8PAA7u8

    MIL OSI Video

  • MIL-OSI Video: “Future Ours” – Art Exhibition on the SDGs

    Source: United Nations (Video News)

    “Future Ours,” art exhibit for the occasion of the Summit of the Future opened at the UN Headquarters on 20 September.

    On the occasion of the Summit of the Future, the Permanent Mission of Denmark hosts the art exhibition “Future Ours” on the UN Plaza, opening on 20 September. Presented by Art 2030, a non-profit dedicated to harnessing the power of art for the SDGs, the large-scale public art project showcases the perspectives of twenty-one artists and collectives from around the world on how to address current and future global challenges. The exhibition explores how art can reweave a dialogue between social, economic, and ecological equity for the planetary community at large as it confronts passersby to the multifaceted crises impacting our world today and to alternative visions for change. Extending beyond the walls of the United Nations, the “Future Ours” posters are exhibited on hundreds of JCDecaux bus shelters throughout the five New York City boroughs.

    https://www.youtube.com/watch?v=FtyicZmbSC4

    MIL OSI Video

  • MIL-OSI Video: Times Square lights up for International Day of Peace

    Source: United Nations (Video News)

    On the eve of UN International Day of Peace (21 September) at midnight, multiple billboards across Times Square in New York lit up the night for peace. The activation, produced in collaboration with OUTFRONT Media and WHO in support of the UN’s Act Now campaign, shared messages of hope and ways to take action to build a peaceful world together. #OurCommonFuture #ActNow #PeaceDay

    https://www.youtube.com/watch?v=2YNcU1AU8fo

    MIL OSI Video

  • MIL-OSI Video: Overview of the National Cemetery Administration Pre-Eligibility and VA Burial Benefits 09.17.2024

    Source: United States of America – Federal Government Departments (video statements)

    This webinar provides a brief overview of the benefits and services provided by the VA’s National Cemetery Administration. This briefing is open to Veterans, their families, and the general public.

    The panelists for this training are:

    1. Jay Dalrymple, Director, National Cemetery Scheduling Office, Deputy Director, Field Programs, National Cemetery Administration, U. S. Department of Veterans Affairs
    2. Steve Ecker, Assistant Director, National Cemetery Scheduling Office, National Cemetery Administration, U. S. Department of Veterans Affairs

    https://www.youtube.com/watch?v=aiA8amwgPK4

    MIL OSI Video

  • MIL-OSI Security: NATO participates in the United Nations “Summit of the Future”

    Source: NATO

    NATO joined the United Nations “Summit of the Future” in New York on Sunday (22 September 2024), taking part in a session dedicated to the vital role of multilateralism for international peace and security.

    “NATO deeply values our cooperation with the United Nations. We share a commitment to international peace and security, and to upholding the rules-based international order,” said Dylan White, Head of the NATO Liaison Office to the United Nations. “We are here to engage with partners, listen to their perspectives, and continue deepening our cooperation in the face of serious security challenges.”

    The Summit of the Future brought together world leaders, international organizations, and other stakeholders to discuss the future of global governance, emerging global challenges, and strengthening multilateral cooperation.

    On Tuesday, NATO Secretary General Jens Stoltenberg will attend the opening session of the UN General Assembly’s high-level General Debate. He will also meet with a number of world leaders while in New York.

    MIL Security OSI

  • MIL-OSI Video: Voices of Peace: Visions for the future | United Nations | DPPA

    Source: United Nations (Video News)

    The video was broadcast on 21 September 2024 during the session on Intergenerational Dialogue for Peace at the UN Summit of the Future #ActionDays. It features the voices of young peacemakers from around the world who are making a difference through their work.

    #OurCommonFuture #PeacefulFuture

    https://www.youtube.com/watch?v=jHZ7Srk0WNI

    MIL OSI Video

  • MIL-OSI Video: Attacks in Lebanon and Syria – Security Council Briefing | United Nations

    Source: United Nations (Video News)

    Briefing an emergency Security Council meeting on Lebanon in the aftermath of deadly explosions of communication devices in the country, UN Under-Secretary-General Rosemary DiCarlo warns Member States of possible bigger conflagration and urges all actors to exercise maximum restraint to avert any further escalation. ‘They must abide by their obligations under international law concerning the protection of civilians’, she said.

    https://www.youtube.com/watch?v=sxoxXHC42Xw

    MIL OSI Video

  • MIL-OSI Video: Can anyone attend and watch the GA sessions?- #UNGA Explained | United Nations

    Source: United Nations (Video News)

    From today, UN Video presents a series of videos addressing the most frequently asked questions by the public, aimed at demystifying and explaining the General Assembly. These eight short clips are available, please share! We appreciate your warm reception of these materials! We would like to thank Julia Foxen and Heyi Zou for their contributions to these explainers.

    https://www.youtube.com/watch?v=2K9ULyZWWK4

    MIL OSI Video

  • MIL-OSI Video: Harnessing the benefits of AI | Summit of the Future | United Nations

    Source: United Nations (Video News)

    Artificial Intelligence is shaping our world in unprecedented ways, and its power, scalability, and potential for good is still evolving. But without effective guardrails, AI could become a major threat to our collective future.

    The Summit of the Future (22-23 September 2024) at the United Nations in New York is an is an opportunity for world leaders to agree on ways to harness AI for the benefit of humanity. Together, we can pave the way for #OurCommonFuture.

    Learn more: un.org/summit-of-the-future

    https://www.youtube.com/watch?v=VWabGQ8f3p0

    MIL OSI Video

  • MIL-OSI Video: International Day of Peace 2024 – UN Chief Message | United Nations

    Source: United Nations (Video News)

    Video message by António Guterres, Secretary-General of the United Nations, on the International Day of Peace (21 September 2024).

    “Everywhere we look, peace is under attack.
    From Gaza, to Sudan, to Ukraine and beyond we see:
    Civilians in the firing line;
    Homes blown apart;
    Traumatised, terrified populations who have lost everything – and sometimes everyone.
    This catalogue of human misery must stop.
    Our world needs peace.
    Peace is the ultimate prize for all humanity.
    And as this International Day of Peace reminds us – the solutions are in our hands.
    Cultivating a culture of peace means replacing division, disempowerment, and despair with justice, equality and hope for all.
    It means focusing on preventing conflict;
    Propelling the Sustainable Development Goals;
    Promoting human rights.
    And tackling all forms of discrimination and hate.
    This month’s Summit of the Future is a vital opportunity to advance these aims.
    Let’s seize it.
    Together, let’s lay the groundwork for peace.
    And let’s nurture a culture where equality, peace and justice thrive.
    Thank you”.

    Website: https://www.un.org/en/observances/international-day-peace

    https://www.youtube.com/watch?v=Ej9gtJBfQoo

    MIL OSI Video

  • MIL-OSI Video: Summit of the Future – Pre-Opening and Renée Fleming Performance | United Nations

    Source: United Nations (Video News)

    Immediately before the Summit of the Future opening segment, a short video will be played in the General Assembly Hall summarizing the Summit of the Future Action Days.

    Grammy winning singer Renée Fleming will then sing accompanied by a video produced by National Geographic. 

    ——————–

    The Summit of the Future (22-23 September 2024) is a once-in-a-generation opportunity to enhance cooperation on critical challenges and address gaps in global governance, reaffirm existing commitments including to the Sustainable Development Goals and the United Nations Charter, and move towards a reinvigorated multilateral system that is better positioned to positively impact people’s lives.

    https://www.youtube.com/watch?v=z11Td1KkYzE

    MIL OSI Video

  • MIL-OSI Video: Gaza, Lebanon, Summit of the Future & other topics – Daily Briefing (20 Sep 2024) | United Nations

    Source: United Nations (Video News)

    Noon Briefing by Stéphane Dujarric, Spokesperson for the Secretary-General.

    Highlights:
    – Summit of the Future Action Days
    – Lebanon
    – Occupied Palestinian Territory
    – Syria
    – Venezuela
    – Ukraine
    – Democratic Republic of the Congo
    – Somalia
    – Viet Nam
    – Haiti
    – International Day of Peace
    – World Cleanup Day

    Summit of the Future Action Days
    This afternoon, at 1pm, the Summit of the Future Action days will kick off with a youth-led event.
    Felipe Paullier, the Assistant Secretary-General for Youth Affairs, will lead the opening ceremony under the theme #Youthlead the future.
    At 2pm, the Secretary-General will take part in a dialogue with youth advocates. This will also take place in the General Assembly Hall and you will be able to watch the conversation live on UN Webtv.
    The action days, which are convened by the Secretary-General, will continue tomorrow. The Secretary-General will address Saturday’s opening session at 9 a.m, tomorrow.
    Tomorrow’s programme will focus on three priority themes – digital and technology, peace and security, and sustainable development and financing.
    There will also be a dedicated focus throughout the day on future generations.
    The action days bring together representatives from Member States, civil society, the private sector, academia, youth, and more. The full list of events and side events is available on the webpage of the Summit of the Future.

    Lebanon
    We are very concerned at the heightened escalation across the Blue Line, including the deadly strike we saw on Beirut today. We urge all parties to de-escalate immediately. All must exercise maximum restraint.
    We also urge the parties to immediately return to the cessation of hostilities and to fully implement Security Council resolution 1701.
    The region is on the brink of a catastrophe. All efforts should focus on finding a diplomatic solution.
    Our Special Coordinator for Lebanon, Jeannine Hennis-Plasschaert, has been insistently conveying these messages to her interlocutors in Lebanon and Israel.
    And this afternoon, the Under-Secretary-General for Political Affairs, Rosemary DiCarlo, and our High Commissioner for Human Rights, Volker Türk, will brief the Security Council in an open meeting on developments in Lebanon. They will convey similar messages. Those remarks will be shared with you.
    Meanwhile, on the peacekeeping front, our blue helmets at UNIFIL peacekeepers continue to implement their mandate in, obviously, extremely challenging conditions, working to help avert further escalation and return to a cessation of hostilities.
    The head of the UN peacekeeping mission there, Force Commander General Aroldo Lázaro, has been in constant communication with the Lebanese Armed Forces and the Israel Defense Forces to help avoid any miscalculations along the Blue Line and to support humanitarian access in southern Lebanon.

    Occupied Palestinian Territory
    Turning to the situation in Gaza, the Office for the Coordination of Humanitarian Affairs says that Palestinians already displaced in the Strip are at risk of having to move again as the rainy season approaches, which is expected to bring flooding and high tides.
    OCHA says that many of those displaced by hostilities in Gaza are sheltering along the Mediterranean coast, where Israeli-issued evacuation orders have instructed them to go. Several municipalities in Gaza have also warned of the risks, with some advising people sheltering in low-lying areas to leave and seek out safer places due to the danger of flooding. Displaced people in Khan Younis and Deir al Balah have been warned to move to higher ground and stay away from the shore, as high tides could cause their tents to drift, among other risks.
    UNRWA, for its part, warns that people in Gaza are sheltering in open spaces with no sewage network or rainwater drainage systems. The agency says that as reptiles, rodents and insects spread, its teams are spraying pesticides and removing waste to protect families from diseases.
    Meanwhile, OCHA also reports that water, sanitation and hygiene operations in northern Gaza have been forced to drastically reduce their operating hours to prevent shutdowns.
    Our partners working on the response say it continues to be extremely difficult to get fuel to the north, with deliveries often delayed or rejected at checkpoints.
    In addition to fuel shortages and the ongoing electricity outages that stall pumps, the current water crisis in Gaza has been worsened by damage to water infrastructure, the absence of safety to make repairs, and a lack of spare parts and chlorine.
    To address the critical lack of clean water in Gaza, UNICEF says it is providing 15 litres of water per person per day for nearly 900,000 people, ensuring that part of their water needs are met for a duration of three months.

    Full Highlights: https://www.un.org/sg/en/content/ossg/noon-briefing-highlight?date%5Bvalue%5D%5Bdate%5D=20%20September%202024

    https://www.youtube.com/watch?v=wyNKmTDNQTk

    MIL OSI Video

  • MIL-OSI USA: FACT SHEET: Taking Action to Support Auto Workers and Manufacturers, Including in  Michigan

    US Senate News:

    Source: The White House
    In Detroit, the White House will convene the Michigan Workforce Hub to announce new commitments to support the auto workforce and increase capital access for auto suppliers
    The American auto industry has driven the U.S. manufacturing base for generations, and the Biden-Harris Administration is ensuring that the future of the auto industry is made in America by American union workers. Today, National Economic Advisor Lael Brainard is traveling to Detroit, Michigan to convene the Michigan Workforce Hub and announce a suite of new actions to support automakers and auto workers, with an emphasis on historic auto communities in Michigan. The Michigan Workforce Hub is one of nine Investing in America Workforce Hubs launched by the Biden-Harris Administration to ensure all Americans can access the good jobs created by the Biden-Harris Investing in America agenda.
    Today’s announcement builds on the actions that Vice President Harris announced in May to support small- and medium-sized auto manufacturers with access to capital to expand or retool manufacturing facilities, new workforce training resources, and new technical assistance programs.
    “I believe in an economy where everyone has a chance to compete and a chance to succeed. Investing in the ambitions and aspirations of our people is the best way to grow the American economy and the middle class,” said Vice President Kamala Harris. “Yet for far too long, we have seen lack of investment in communities across America and profound obstacles to economic opportunity—including in communities with historic manufacturing expertise such as Detroit. Earlier this year, I was proud to announce new support for small- and medium-sized auto suppliers in Detroit. Today’s announcements build on those investments by making sure our auto supply chains stay here in America, strengthening our economy overall by investing in historically underserved communities, and keeping more auto jobs in Detroit.”
    $1 Billion in Financing for Small- And Medium-Sized Auto Suppliers
    Auto suppliers support the majority of auto manufacturing jobs, and small- and medium-sized suppliers employ more than 250,000 workers across the country—serving as economic engines in Michigan, Ohio, and other historic auto communities.
    Today, the Department of the Treasury is announcing a $9.1 million grant to launch the Michigan Auto Supplier Transition Program to help small and underserved automotive manufacturers and aftermarket suppliers secure financing to scale and shift to supplying the electric vehicle supply chain. Made possible by Treasury’s State Small Business Credit Initiative (SSBCI), the Michigan Auto Supplier Transition Program will provide financial, legal, accounting, and other support services to underserved and very small businesses, including helping these firms access the over $230 million in additional lending and equity investments made available to support Michigan businesses through the American Rescue Plan’s SSBCI program. The Michigan Economic Development Corporation will oversee the Auto Supplier Transition program in coordination with the Michigan Department of Labor and Economic Opportunity Community and Worker Economic Transition Office. Additionally, Monroe Capital is announcing a commitment to raise up to $1 billion for a new “Drive Forward” Fund to facilitate access to lower cost capital for small- and medium-sized auto manufacturers to refinance, grow, and diversify their businesses. The Drive Forward Fund builds on successful investment funds catalyzed by the Small Business Administration’s Small Business Investment Company program, which provides low-cost government-guaranteed leverage funding to lower the cost of capital for portfolio companies. The Drive Forward Fund will be advised by a council with experts from across the automotive industry to ensure that capital is directed to small and medium-sized auto suppliers with high-road labor practices and significant domestic manufacturing content. A focus will be placed on manufacturers that are well-positioned to lead in the future of the automotive industry and need additional capital and support to grow their manufacturing capacity, including companies making critical investments in the transition from internal combustion engine (ICE) production to electric vehicles (EV).
    These new announcements build on investments that the Biden-Harris Administration has already made in auto manufacturers, including in Michigan. For example, under the Domestic Manufacturing Conversion Grant Program, the Department of Energy announced a $500 million award to General Motors in Lansing and a $158 million award to ZF North America in Marysville to support the conversion of these legacy ICE facilities to EV production—retaining or creating over 1,000 combined jobs. Both of these facilities are UAW unionized. The Department of Energy also announced that the State of Michigan is eligible to receive over $18 million in funding to provide grants to small- and medium-sized auto suppliers converting their facilities to electric vehicle production. To protect these investments from unfair trade practices abroad, the President has taken strong and strategic action, including by raising tariffs to 100% on EVs and batteries from China.
    The Administration welcomes additional commitments and actions from stakeholders across industry to support automakers and auto workers.
    Michigan Workforce Hub Commitments
    In 2023, First Lady Jill Biden announced the Investing in America Workforce Initiative in five initial locations where the Biden-Harris Investing in America agenda is catalyzing historic investments in industries of the future. In April, President Biden announced Michigan as one of four new Workforce Hubs, designed to prepare Michigan workers for the good-paying and union jobs created by these historic investments, with a focus on the auto sector. Since the start of the Biden-Harris Administration, industry has announced $28 billion in private investment in clean energy and manufacturing in Michigan. The Hub is focused on four pillars: improving alignment between training programs and industry needs, standardizing training program guidelines for emerging occupations in the auto supply chain, promoting career readiness with a focus on underserved communities, and addressing structural barriers to employment.
    The Michigan Workforce Hub is coordinating across the Department of Labor, the Department of Energy, the Michigan Department of Labor and Economic Opportunity, community colleges, unions, employers, philanthropy, nonprofits, and others to deliver on President Biden’s announcement. Since the launch of the Hub, the Department of Labor has invested more than $5.4 million to modernize, expand, and diversify registered apprenticeship programs in Michigan across key industries, including manufacturing, and connect workers to good-paying jobs, and the Michigan Department of Labor and Economic Opportunity has continued to leverage $25 million in American Rescue Plan funding to expand apprenticeships in the state. The Detroit Regional Partnership is also continuing to implement its $52.2 million grant from the American Rescue Plan to invest in the Detroit area’s legacy automotive industry and unite 135 local coalition members around a common vision for a collaborative and equitable regional economy; the coalition is undertaking
    To institutionalize the work of the Michigan Workforce Hub, the Department of Energy is announcing the selection of a full-time Michigan Fellow, hosted by the Michigan AFL-CIO Workforce Development Institute. This Fellow is part of an inaugural cohort of ten fellows and host organizations funded by the Community Workforce Readiness Accelerator for Major Projects (RAMP) program—which is designed to address workforce gaps while ensuring that historic clean energy investments lift all communities, especially those historically left behind.
    Today, the Michigan Workforce Hub is announcing a suite of new federal, state, philanthropic, nonprofit, and private sector commitments:
    Building pipelines to careers for underserved communities:
    The Department of Labor and the Michigan Department of Labor and Economic Opportunity is announcing a new pilot program to train workers in Wayne County for over 140 high-quality jobs in the auto supply chain. The pilot will partner with local automotive employers to train workers while they earn a paycheck, addressing a major barrier to enrollment. As part of the pilot, the Southeast Michigan Community Alliance (SEMCA) will work with employers, including Roush, and provide supportive services to address transportation, childcare, and other needs to make it easier for Detroit-area residents from underserved communities to access both training and good-paying manufacturing jobs.
    The Michigan Department of Labor and Economic Opportunity has partnered with International Brotherhood of Electrical Workers (IBEW) and invested $4 million to support more than 500 Michigan workers to receive the Electric Vehicle Infrastructure Training Program credential in preparation for good-paying, union jobs installing EV chargers, including through the Bipartisan Infrastructure Law National Electric Vehicle Infrastructure program. Forty percent or more of the participants served will be from underserved targeted populations.
    Michigan Department of Labor and Economic Opportunity, AFL-CIO Workforce Development Institute, and International Brotherhood of Electrical Workers (IBEW) are launching an accelerated Commercial Driver’s License (CDL) to Registered Apprenticeship Program pilot to expedite preparation of RAP candidates who have completed CDL training. Through collaborative efforts with Labor partners and the IBEW, leveraging innovative Apprenticeship Readiness Programs, 15 participants from traditionally underrepresented groups will receive CDL training and participate in a registered apprenticeship resulting in a good-paying union job.
    Taskforce Movement is partnering with the Michigan Department of Labor & Economic Opportunity to create career pathways for transitioning service members and veterans into electronic vehicle, manufacturing, and cybersecurity jobs. Transitioning service members and veterans will leverage the skills and discipline honed during military service to build a more robust workforce while providing veterans with stable, high-quality careers.
    The Detroit Lions and Detroit Pistons will partner with Detroit Public Schools to launch new manufacturing career exposure programs for over 1,000 high school students, with a focus on supporting students from underrepresented and employment-distressed neighborhoods.
    Driving career readiness and standardizing training programs for good-paying jobs:
    The Department of Energy and over a dozen industry sponsors are providing $23.6 million in funding for the Battery Workforce Challenge to invest in equipment, technical support, mentorship, internships, and job placements and train up to 14,000 workers across the country for careers across the EV value chain—including technicians, electricians, skilled trades, and engineers. The program will invest more than $600,000 in colleges in Michigan to train over 300 Michiganders. Sponsors include Stellantis, Samsung SDI America, the American Battery Technology Company, AVL North America, Vector, and the Battery Innovation Center.
    The Department of Energy’s Battery Workforce Challenge Program, managed by Argonne National Laboratory, will create STEM talent pipelines in battery manufacturing hubs across the nation—the first being piloted in Michigan with the support of at least $400,000 in total, direct funding. Key partners in the Michigan pilot will include the Michigan Economic Development Corporation, high schools, vocational institutions, higher education, and industry. The Department of Energy will provide $200,000 in seed funding to Henry Ford Community College in Detroit to establish a state-of-the-art Battery/EV Technical Center. The Michigan Economic Development Corporation will also award $200,000 to the University of Michigan-Dearborn to establish an undergraduate-level training program as well as a summer boot camp to educate undergraduate students in EV battery technology and build a talent pipeline.
    The Department of Energy and Argonne will partner with New Energy New York to develop battery and EV training and educational content, “BattTech,” to be used in the Michigan pilot and the other Battery Workforce Hubs. BattTech will provide industry-aligned educational content and training in battery technology, EV development, safety, manufacturing, and recycling—ensuring participants are equipped with the skills required for roles across the battery and electric vehicle value chain.
    As part of the Battery Workforce Challenge, the Department of Energy will provide $250,000 to the Society of Manufacturing Engineers (SME) to pilot a battery manufacturing career pathway in high school career technical education courses in Michigan. The battery manufacturing career pathway will be integrated into the SME PRIME (Partnership Response In Manufacturing Education) program that currently is serves 110 schools and 10,000 students annually across 23 states. SME PRIME also intends to further expand its existing footprint in Michigan.
    The Department of Energy’s Battery Workforce Initiative and Michigan community colleges will launch discussions for a memorandum of understanding (MOU) to deploy industry-approved classroom and on-the-job training with battery manufacturers and their community college partners for high-demand occupations. This training program has also been certified by the Department of Labor as the guidelines for battery manufacturing machine operator apprenticeship.
     Supporting employers in building a skilled workforce and navigating resources:
    The Michigan Workforce Hub will provide new resources to employers to attract a skilled and diverse workforce for clean energy manufacturing jobs. The Department of Energy’s Battery Workforce Initiative will invest $200,000 to provide skills assessment and job task analysis to firms transitioning to EV component or clean goods production.
    Additionally, the Families and Workers Fund will partner with the Good Jobs Institute and Toyota Production System Support Center to deliver training and coaching to ten small and medium clean technology manufacturers to help them navigate workforce and operational challenges. The recruitment for the first cohort of manufacturers is now underway, and the program will formally launch in 2025.
    Leveraging American Rescue Plan funding, the Michigan Department of Labor and Economic Opportunity and SEMCA Michigan Works! will accelerate the adoption of apprenticeship programs in Michigan, particularly for small- and medium-sized auto manufacturers, by launching a Race to Talent with Registered Apprenticeship Michigan Event on September 25, which is designed to grow employer and industry awareness of the benefits of Registered Apprenticeships in the EV and mobility sector.
    With philanthropic support and in partnership with the Michigan Department of Labor and Economic Opportunity, NextStreet will create a digital hub to help connect small- and medium-sized suppliers in Michigan to resources to help with retooling, modernization, and economic transition.
    Supporting employers in building a skilled workforce and navigating resources:
    The Michigan Workforce Hub will provide new resources to employers to attract a skilled and diverse workforce for clean energy manufacturing jobs. The Department of Energy’s Battery Workforce Initiative will invest $200,000 to provide skills assessment and job task analysis to firms transitioning to EV component or clean goods production.
    Additionally, the Families and Workers Fund will partner with the Good Jobs Institute and Toyota Production System Support Center to deliver training and coaching to ten small and medium clean technology manufacturers to help them navigate workforce and operational challenges. The recruitment for the first cohort of manufacturers is now underway, and the program will formally launch in 2025.
    Leveraging American Rescue Plan funding, the Michigan Department of Labor and Economic Opportunity and SEMCA Michigan Works! will accelerate the adoption of apprenticeship programs in Michigan, particularly for small- and medium-sized auto manufacturers, by launching a Race to Talent with Registered Apprenticeship Michigan Event on September 25, which is designed to grow employer and industry awareness of the benefits of Registered Apprenticeships in the EV and mobility sector.
    With philanthropic support and in partnership with the Michigan Department of Labor and Economic Opportunity, NextStreet will create a digital hub to help connect small- and medium-sized suppliers in Michigan to resources to help with retooling, modernization, and economic transition.
    Building local capacity and promoting economic development:
    With the support of up to $250,000 in funding from the Department of Agriculture, the Federal Interagency Thriving Communities Network will team up with the State of Michigan, local officials, and economic development leaders to build capacity in the historic auto communities of Saginaw and Flint as well as rural communities in the Upper Peninsula. This initiative will work to close gaps related to workforce participation, infrastructure, and poverty—driving local economic comebacks. This work builds upon place-based capacity building efforts that the Network is providing to other parts of Michigan and across the country.
    The City of Lansing will increase representation of women in construction and skilled trades through the Leveraging Infrastructure Networks for Equity Initiative, a partnership between the Department of Labor’s Women’s Bureau and the non-profit Accelerator for America. This project has been renewed for second year with nearly $500,000 in funding to improve pathways for women to access the good jobs being created by historical investments in infrastructure.

    MIL OSI USA News

  • MIL-OSI Video: Seizing Dangerous Foods (Agriculture) – International Travel and Customs | CBP

    Source: United States of America – Federal Government Departments (video statements)

    Many agriculture products are prohibited entry into the United States from certain countries because they may carry plant pests and foreign animal diseases. All agriculture items must be declared and are subject to inspection by a CBP Agriculture Specialist at ports of entry to ensure they are free of plant pests and foreign animal diseases. Prohibited or restricted items may include meats, fresh fruits and vegetables, plants, seeds, soil and products made from animal or plant materials.

    Visitors to the U.S. are encouraged to declare all agriculture items they are bringing into the United States. A traveler who declares an item that is prohibited or restricted may abandon the item at the port; however undeclared items that are prohibited or restricted can result in a civil fine.

    Declaring Agricultural Items ➤
    https://www.cbp.gov/travel/international-visitors/agricultural-items

    Instagram ➤ https://instagram.com/CBPgov
    Facebook ➤ https://facebook.com/CBPgov
    Twitter ➤ https://twitter.com/CBP
    Official Website ➤ https://www.cbp.gov

    #cbp
    #agriculture
    #travel
    #customs
    #inspection

    https://www.youtube.com/watch?v=AGvyWEXgqKQ

    MIL OSI Video

  • MIL-OSI Video: Soyuz MS-25 Reentry and Landing with Tracy Dyson

    Source: United States of America – Federal Government Departments (video statements)

    Watch live as NASA astronaut Tracy Dyson and Roscosmos cosmonauts Nikolai Chub and Oleg Kononenko return home from the International Space Station. Their Soyuz MS-25 spacecraft will head for a parachute-assisted landing on the steppe of Kazakhstan at 8 a.m. EDT Monday, Sept. 23 (1200 UTC).
    Dyson will conclude her fourth spaceflight with the landing of the Soyuz. Dyson’s mission spanned 184 days, 2,944 orbits of the Earth, and a journey of 78 million miles. While on orbit, she conducted an array of experiments and technology demonstrations that contribute to advancements for humanity on Earth and NASA’s trajectory to the Moon and Mars.

    About the science highlights of her mission: https://www.nasa.gov/missions/station/iss-research/nasa-astronaut-tracy-c-dyson-scientific-mission-aboard-space-station/

    Credit: NASA

    #NASA #Space #Astronaut #SpaceStation #ISS

    https://www.youtube.com/watch?v=bXfPTDrh2ZY

    MIL OSI Video

  • MIL-OSI Video: Incident After-Action Review Observation Development

    Source: United States of America – Federal Government Departments (video statements)

    This video describes the development of incident after-action review observations. Observations summarize key topics and resulting recommended actions. The video considers why observations are important and how to write and validate them. Chapter two of the National Continuous Improvement Guidance (NCIG) provides more information on this topic. https://preptoolkit.fema.gov/web/cip-citap/ncig.

    https://www.youtube.com/watch?v=syB3oRxRf98

    MIL OSI Video