Category: Europe

  • MIL-OSI Global: The gas crisis is not over yet

    Source: The Conversation – UK – By Michael Bradshaw, Professor of Global Energy, Warwick Business School, University of Warwick

    Oleksandr Filatov/Shutterstock

    Policy and luck have bought Europe a reprieve from the heights gas prices reached between the winters of 2022 and 2023, but prices are climbing again and the global gas market remains precariously balanced.

    Rising tensions in the Middle East could upend it. If conflict spills into the Persian Gulf, it could disrupt shipments of liquefied natural gas (LNG) from Qatar that equal 20% of global exports.

    We believe this winter will be the final act of the gas crisis. Here’s what we should expect.

    Dangerously underprepared

    The case for Britain to rapidly phase out natural gas in heating and power generation is overwhelming. It would unburden household bills of expensive gas imports and leave the country less vulnerable to energy supply crunches, while also cutting carbon emissions. Doing so will take time: as of today, the UK relies on gas for 37% of all energy consumption.

    British households in particular are perilously exposed to gas prices. Directly, because four-fifths of households use gas for space heating. Indirectly, because in the UK, electricity prices are set by the price of gas-fired generation. After a decade of failed home insulation and energy-efficiency policies, the UK still has some of the draughtiest homes in Europe. It simply takes more energy to heat British homes, which lose heat three times faster than European neighbours.

    Since the beginning of the recent crisis, the UK government has done little to change these facts. The end of the winter fuel payment to pensioners adds fresh concern. The Energy Crisis Commission recently found that the UK remains “dangerously underprepared” for a repeat of the gas price explosion of 2022-23.

    All told, the UK cannot be oblivious to developments in the global gas market.

    A crisis in the making

    Resurgent gas demand after the lifting of COVID restrictions led to a quadrupling of UK gas prices in 2021. Following Russia’s invasion of Ukraine in February 2022, Vladimir Putin throttled pipeline gas exports to Europe.

    Europe turned to its greatest source of flexible gas supply: seaborne LNG. A price war for cargoes followed. The spending power of European economies pulled shipments away from low-income countries in Asia, such as Pakistan and Bangladesh, which caused crippling blackouts and a pivot to coal-fired generation.

    Energy bills for an average household in the UK hit £4,279 in January 2023. The government protected consumers from the very worst at a cost of £51 billion in 2022-23, but the average household lost 8% of its budget to energy costs in 2022, rising to 18% for the poorest tenth of households. Roughly 2 million households on pre-payment meters were being cut off from their energy supply at least once a month at the height of the crisis.

    Clement winters, moderate gas demand in Asia and successful measures to curb European gas demand saw UK gas prices fall from mid-2023. But they are still relatively high – at 48% above the average in the three years before Russia’s invasion of Ukraine.

    One more winter

    Could things get worse? Back in 2022, experts spoke of a “three-winter crisis” because significant new LNG export capacity (primarily in the US and Qatar) wasn’t expected until 2025. That has held true, and supply and demand in the global LNG market remains taut.

    Several disturbances could destabilise this balance. The International Energy Agency expects that over 2024, global growth in gas demand will exceed the rate of growth in new LNG supply. Attacks on commercial vessels in the Red Sea by the Houthi militia in Yemen, in response to Israel’s invasion of Gaza, have rerouted LNG shipping routes. Cargoes that would have passed through the Suez Canal must now take the longer route around the Cape of Good Hope.

    At the end of 2024, a major five-year agreement governing the transit of Russian gas through Ukraine will expire, and there is no prospect of renewal. Russian gas supplies to Europe will fall by around 5% of the EU’s total gas imports, or 65% of all gas imports into Austria, Hungary and Slovakia.

    While Europe has been saved by mild winters over the last two years, this luck could break in 2024-25 according to some forecasts. Temperature – and the demand it creates for heating – will probably decide winter gas prices in Europe.

    Geopolitical blowback

    How might the worst-case scenario of conflict in the Persian Gulf happen?

    LNG is shipped by sea on large tankers.
    Wojciech Wrzesien/Shutterstock

    Israel’s escalating military assaults on Hezbollah since September 17 have coincided with a 17% rise in UK gas prices. After Iran’s missile and drone strikes against Israel on October 1, European gas prices hit a new high for the year. This saw three LNG tankers destined for Asia change course mid-journey and head for Europe.

    Israel has vowed retribution for the Iranian strike. Having obliterated Gaza and decapitated Hezbollah’s leadership, and with resolute material support from the US, Israel may now see Iran as vulnerable.

    A severe response by Israel, targeting Iran’s nuclear facilities or oil infrastructure, would further up the ante. Wishing to avoid direct conflict, Iran could decide to target not Israel, but the flow of oil and gas through the Strait of Hormuz on which its western backers depend. Qatari LNG shipments through the strait account for 20% of global supply on their own.

    Any interruption would also block Iran’s oil exports, afflict Iran’s friends as much as its foes, and kill Iran’s current reconciliation with the Gulf states. It is unlikely, but one would hope that the warning signs in the global gas market would remind western decision-makers that the conflict in the Middle East can continue to blow back on them.



    Don’t have time to read about climate change as much as you’d like?

    Get our award-winning weekly roundup in your inbox instead. Every Wednesday, The Conversation’s environment editor writes Imagine, a short email that goes a little deeper into just one climate issue. Join the 40,000+ readers who’ve subscribed so far.


    Michael Bradshaw receives funding from the UK Energy Research Centre (UKERC) that is funded by the Engineering and Physical Sciences Research Council (EPSRC) and the Economic and Social Research Council (ESRC), part of UK Research and Innovation (UKRI). He also advises the government, thinktanks and companies on energy matters.

    Louis Fletcher receives funding from the UK Energy Research Centre (UKERC), which is funded by the Engineering and Physical Sciences Research Council (EPSRC) and the Economic and Social Research Council (ESRC), part of UK Research and Innovation (UKRI).

    ref. The gas crisis is not over yet – https://theconversation.com/the-gas-crisis-is-not-over-yet-241538

    MIL OSI – Global Reports

  • MIL-OSI Security: District Election Officer appointed to oversee election day complaints in the Southern District of Georgia

    Source: Federal Bureau of Investigation (FBI) State Crime Alerts (b)

    SAVANNAH, Ga.: Southern District of Georgia U.S. Attorney Jill E. Steinberg announced today that she has appointed a District Election Officer (DEO) to lead the efforts of the office in connection with the Justice Department’s nationwide Election Day Program for the upcoming Nov. 5, 2024, general election.

    The DEO is responsible for overseeing the district’s handling of election day complaints of voting rights concerns, threats of violence to election officials or staff, and election fraud, in consultation with Justice Department Headquarters in Washington.

    U.S. Attorney Steinberg said, “Every citizen must be able to vote without interference or discrimination and to have that vote counted in a fair and free election. Similarly, election officials and staff must be able to serve without being subject to unlawful threats of violence. The Department of Justice will always work tirelessly to protect the integrity of the election process.”

    The Department of Justice has an important role in deterring and combatting discrimination and intimidation at the polls, threats of violence directed at election officials and poll workers, and election fraud. The Department will address these violations wherever they occur. The Department’s longstanding Election Day Program furthers these goals and also seeks to ensure public confidence in the electoral process by providing local points of contact within the Department for the public to report possible federal election law violations.

    Federal law protects against such crimes as threatening violence against election officials or staff, intimidating or bribing voters, buying and selling votes, impersonating voters, altering vote tallies, stuffing ballot boxes, and marking ballots for voters against their wishes or without their input.  It also contains special protections for the rights of voters, and provides that they can vote free from interference, including intimidation, and other acts designed to prevent or discourage people from voting or voting for the candidate of their choice.  The Voting Rights Act protects the right of voters to mark their own ballot or to be assisted by a person of their choice (where voters need assistance because of disability or inability to read or write in English).   

    U.S. Attorney Steinberg stated that, “The franchise is the cornerstone of American democracy. We all must ensure that those who are entitled to the franchise can exercise it if they choose, and that those who seek to corrupt it are brought to justice. In order to respond to complaints of voting rights concerns and election fraud during the upcoming election, and to ensure that such complaints are directed to the appropriate authorities, the DEO will be on duty in this District while the polls are open. The DEO can be reached by the public at the following telephone number, 912-201-2560, or by email at USAGAS.Election@usdoj.gov.”

    In addition, the FBI will have special agents available in each field office and resident agency throughout the country to receive allegations of election fraud and other election abuses on election day.  The local FBI field office can be reached by the public at 770-216-3000.

    Complaints about possible violations of the federal voting rights laws can be made directly to the Civil Rights Division in Washington, DC by complaint form at https://civilrights.justice.gov/ or by phone at 800-253-3931.

    U.S. Attorney Steinberg said, “Ensuring free and fair elections depends in large part on the assistance of the American electorate. It is important that those who have specific information about voting rights concerns or election fraud make that information available to the Department of Justice.”

    Please note, however, in the case of a crime of violence or intimidation, please call 911 immediately and before contacting federal authorities. State and local police have primary jurisdiction over polling places, and almost always have faster reaction capacity in an emergency. 

    MIL Security OSI

  • MIL-OSI USA: Senate Study Committee on Access to Affordable Childcare to Hold Second Meeting

    Source: US State of Georgia

    ATLANTA (October 22, 2024) — On Wednesday, October 30th, 2024, at 11:00 a.m., the Senate Study Committee on Access to Affordable Childcare, chaired by Sen. Brian Strickland (R–McDonough), will hold its second hearing.

    EVENT DETAILS:                      

    • Date: Wednesday, October 30, 2024
    • Time: 11:00 a.m.
    • Location: The Shaquille O’Neal Boys & Girls Club of Henry County, 166 Holly Smith Dr, McDonough, GA 30253
    • This event is open to the public and will be live-streamed on the Georgia General Assembly website here.

    ABOUT THE MEETING:         

    Members will recommend measures to increase access to affordable child care in Georgia. This committee was created pursuant to Senate Resolution 471 during the 2024 Legislative Session. You can find more information about this study committee here.

    MEDIA OPPORTUNITIES:

    We kindly request that members of the media confirm their attendance in advance by contacting Jantz Womack at SenatePressInquiries@senate.ga.gov

    # # # #

    Sen. Brian Strickland serves as the Chairman of the Senate Committee on Judiciary. He represents the 17th Senate District, which includes all of Morgan and portions of Henry, Newton and Walton County. Sen. Strickland may be reached by phone at 404.463.6598 or by email at Brian.Strickland@senate.ga.gov.

    MIL OSI USA News

  • MIL-OSI USA: United States Announces Significant New Military Assistance for Ukraine

    Source: United States Department of State (3)

    Antony J. Blinken, Secretary of State

    The United States is providing another significant package of urgently needed weapons and equipment to our Ukrainian partners as they defend against Russia’s ongoing attacks. This additional assistance, provided under previously exercised Presidential Drawdown Authority from Department of Defense stocks, is valued at $400 million.  It includes Munitions for HIMARS; 155mm and 105mm artillery ammunition; Mortars; M113 armored vehicle; Tube-launched, Optically tracked, Wire-guided (TOW) missiles; Javelin missiles; AT-4 rockets; Satellite communications support; Ammunition for crew-served weapons; Small arms, grenades, and training equipment; Demolitions equipment and munitions; and Spare parts, ancillary equipment, services, training, and transportation.

    The United States is committed to supporting Ukraine with the equipment it needs to strengthen its position on the battlefield, defend against the Kremlin’s brutal aggression, and secure a just and lasting peace.  As President Biden has made clear, the United States and the international coalition we have assembled will continue to stand with Ukraine.

    MIL OSI USA News

  • MIL-OSI USA: Under Secretary Zeya’s Meetings in Kyiv, Ukraine

    Source: United States Department of State (3)

    Office of the Spokesperson

    Under Secretary of State for Civilian Security, Democracy, and Human Rights Uzra Zeya traveled to Kyiv, Ukraine, on October 18, 2024.

    While in Kyiv, Under Secretary Zeya underscored unwavering U.S. solidarity to Deputy Prime Minister for European and Euro-Atlantic Integration and Minister of Justice Olha Stefanishyna, Minister of Veterans Affairs Natalia Kalmykova, leadership of the National Anti-Corruption Bureau of Ukraine and Specialized Anti-Corruption Prosecutor’s Office, Chief Justice of the High Anti-Corruption Court of Ukraine, Deputy Minister of Internal Affairs Oleksiy Sergeyev, and First Deputy Chief of the National Police Maksym Tsutskeridze.  She also met with investigative journalists, humanitarian workers, veterans, and internally displaced persons, including youth. Throughout her engagements, she emphasized the United States’ steadfast commitment to helping Ukraine prevail; strengthening its democratic resilience; securing its Euro-Atlantic future; holding Russia accountable for its atrocities and advancing comprehensive justice for the Ukrainian people; and sustaining U.S. humanitarian assistance for the most vulnerable.

    In addition, the Under Secretary spoke at the National Anti-Corruption Bureau of Ukraine’s 10th anniversary ceremony, commending Ukraine’s tremendous anti-corruption gains and resolve to build upon them, amid Russia’s ongoing war of aggression.

    During her trip, Under Secretary Zeya announced three new initiatives to help the Ukrainian people win the war and win the future:

    • The State Department Bureau of International Narcotics and Law Enforcement Affairs launched a $5 million grant, in partnership with the Institute for War & Peace Reporting, to increase governmental transparency and accountability by supporting civil society organizations and investigative journalists making essential contributions in the fight against corruption. It will also seek to enhance collaboration between civil society and Ukraine’s independent anti-corruption institutions.
    • The State Department Office of Global Criminal Justice awarded $2 million to the International Organization for Migration to support reparative justice for Ukrainians. The initiative will help government policy makers and civil society develop domestic reparations mechanisms for direct compensation and support to victims and survivors of Russia’s crimes, laying the groundwork for Ukrainians to unlock justice at the earliest opportunity.
    • The State Department Bureau of Conflict and Stabilization Operations awarded $2 million to UN Women for a new partnership to advance Women, Peace, and Security (WPS) in Ukraine. With this funding, UN Women will support Ukraine’s institutions to implement the National Action Plan on WPS and advance women’s leadership, ownership, and participation in conflict response and recovery at all levels.

    Upon departing Kyiv, Under Secretary Zeya stated, “Today I was profoundly moved to meet dedicated Ukrainian government partners determined to strengthen their nation’s democratic resilience, anti-corruption champions advancing a more prosperous, democratic future, and Ukrainian veterans and non-governmental leaders helping their fellow citizens regain dignity, justice and safety in the face of Russia’s ongoing brutal aggression. Vladimir Putin underestimated the strength and tenacity of Ukraine and its people to resist this naked aggression, and the resolve of the United States, Europe, and international partners to support them.  Today Ukraine remains proud, strong, and free, and the United States will continue to do everything in our power to keep it so.”

    For further information, please follow @UnderSecStateJ on X and @UnderSecStateJ on LinkedIn. 

    MIL OSI USA News

  • MIL-OSI USA: Joint Statement of German Foreign Minister Annalena Baerbock and U.S. Secretary of State Antony Blinken on Yahya Sinwar

    Source: United States Department of State (3)

    Office of the Spokesperson

    The following is the Joint Statement of German Foreign Minister Annalena Baerbock and U.S. Secretary of State Antony Blinken after their meeting in Berlin, October 18, 2024:

    Yahya Sinwar was a brutal murderer and terrorist who was bent on eradicating Israel and its people. As vicious mastermind of the October 7 terror attacks, he brought death to thousands of people and immeasurable suffering across an entire region. Sinwar stood in the way of a ceasefire in Gaza. His death can create a momentum to end the conflict. All hostages must be released. At the same time, humanitarian aid must be surged to the civilians in Gaza in need. Germany and the United States, together with partners, won‘t spare any effort on this path.

    MIL OSI USA News

  • MIL-OSI USA: Targeting Russian Attack Drone Production Used in War Against Ukraine

    Source: United States Department of State (3)

    Matthew Miller, Department Spokesperson

    The United States is today imposing sanctions on three entities and one individual involved in the development and production of Russia’s Garpiya series long-range attack unmanned aerial vehicle (UAV), which has been deployed in Russia’s brutal war against Ukraine.  The Garpiya, designed and produced in the People’s Republic of China (PRC) in collaboration with Russian defense firms, has been used to destroy critical infrastructure and has resulted in mass casualties.

    These sanctions targets were involved in the development and production of military equipment for a U.S.-sanctioned Russian defense firm for use by the Russian military in Ukraine.  While the United States previously imposed sanctions on PRC entities providing critical inputs to Russia’s military-industrial base, these are the first U.S. sanctions imposed on PRC entities directly developing and producing complete weapons systems in partnership with Russian firms.

    Today’s action is part of our continued effort to disrupt attempts by PRC-based and Russia-based entities and individuals to support Russia’s acquisition of advanced weapons technology and components.  We will continue to impose costs on those who provide support to Russia’s military-industrial base.

    The Department of the Treasury sanctions actions were taken pursuant to Executive Order  (“E.O.”) 14024  “Blocking Property With Respect To Specified Harmful Foreign Activities of the Government of the Russian Federation.”  For more information on these actions, please see the Department of the Treasury’s press release .

    MIL OSI USA News

  • MIL-OSI USA: Under Secretary Zeya Travels to Ukraine, Poland, and the United Kingdom

    Source: United States Department of State (3)

    Office of the Spokesperson

    Under Secretary of State for Civilian Security, Democracy, and Human Rights Uzra Zeya will travel to Ukraine, Poland, and the United Kingdom from October 18-22, 2024.

    In Ukraine, Under Secretary Zeya will reaffirm steadfast U.S. commitment to robust civilian security and humanitarian support, and strengthening Ukraine’s democratic resilience in the face of Russia’s continued brutal aggression.  In her engagements with government, humanitarian, and civil society leaders, she will emphasize continued partnership on anti-corruption and rule of law reforms, a strong civil society and independent media, and advancing victim- and survivor-centered justice and accountability for Ukrainians.

    In Poland, the Under Secretary will meet with vulnerable Ukrainian refugees forced to flee Russia’s war against Ukraine and with valued humanitarian partners who provide direct support to them.  She will also visit a coordination center for Ukraine-bound support.

    In the United Kingdom, Under Secretary Zeya will further U.S.-U.K. cooperation on pressing global challenges.  She will meet with senior government officials, civil society, and members of Parliament to strengthen partnerships on humanitarian cooperation and human rights, including protections for survivors of trafficking in persons and LGBTQI+ individuals.

    For further information, please follow @UnderSecStateJ on X and @UnderSecStateJ on LinkedIn.

    MIL OSI USA News

  • MIL-OSI Security: Murder investigation launched and victim named following the death of a teenager in Islington

    Source: United Kingdom London Metropolitan Police

    A murder investigation has been launched and the victim named after a teenage boy was found with a fatal injury in Islington.

    Police were called by London Ambulance Service [LAS] at 00:12hrs on Tuesday, 22 October to reports of a possible collision at Courtauld Road.

    Officers and LAS attended and 16-year-old Deonte Mowatt-Slater was found with a serious injury.

    Medics fought to save Deonte but, despite their efforts, he sadly died at the scene.

    A murder investigation has been launched led by Detective Chief Inspector Neil John. He said: “We are in the very early stages of our investigation. At this point it is unclear exactly where Deonte was when he suffered his injury. He was found injured on Courtauld Road along with his motorcycle.

    “We are working hard to establish the sequence of events that led to this tragic loss of a young life.

    “I am keen to hear from anyone who witnessed, or has footage of, any part of this incident.

    A number of crime scenes remain in place while we continue with our enquiries, and I would like to thank local residents in advance for their patience.

    Today a family has received the worst possible news – if you have information about this incident please do the right thing and get in touch.”

    Deonte’s family have been notified and they are being supported by specialist officers.

    A post-mortem examination will be scheduled in due course.

    There have been no arrests.

    Anyone with information or footage/dash-cam relating to this incident should call the Incident Room on 020 8358 0100, call 101 or post on X @MetCC quoting 95/22OCT.

    Information can also be submitted at our Operation BIdwarm Public Information Portal.

    To remain 100 per cent anonymous call the independent charity Crimestoppers on 0800 555 111 or visit crimestoppers-uk.org.

    MIL Security OSI

  • MIL-OSI USA: NASA Reveals Prototype Telescope for Gravitational Wave Observatory

    Source: NASA

    2 min read

    NASA has revealed the first look at a full-scale prototype for six telescopes that will enable, in the next decade, the space-based detection of gravitational waves — ripples in space-time caused by merging black holes and other cosmic sources.

    On May 20, the full-scale Engineering Development Unit Telescope for the LISA (Laser Interferometer Space Antenna) mission, still in its shipping frame, was moved within a clean room at NASA’s Goddard Space Flight Center in Greenbelt, Maryland.
    NASA/Dennis Henry

    The LISA (Laser Interferometer Space Antenna) mission is led by ESA (European Space Agency) in partnership with NASA to detect gravitational waves by using lasers to measure precise distances — down to picometers, or trillionths of a meter — between a trio of spacecraft distributed in a vast configuration larger than the Sun. Each side of the triangular array will measure nearly 1.6 million miles, or 2.5 million kilometers.

    “Twin telescopes aboard each spacecraft will both transmit and receive infrared laser beams to track their companions, and NASA is supplying all six of them to the LISA mission,” said Ryan DeRosa, a researcher at NASA’s Goddard Space Flight Center in Greenbelt, Maryland. “The prototype, called the Engineering Development Unit Telescope, will guide us as we work toward building the flight hardware.”

    The prototype LISA telescope undergoes post-delivery inspection in a darkened NASA Goddard clean room on May 20. The entire telescope is made from an amber-colored glass-ceramic that resists changes in shape over a wide temperature range, and the mirror’s surface is coated in gold.
    NASA/Dennis Henry

    The Engineering Development Unit Telescope, which was manufactured and assembled by L3Harris Technologies in Rochester, New York, arrived at Goddard in May. The primary mirror is coated in gold to better reflect the infrared lasers and to reduce heat loss from a surface exposed to cold space since the telescope will operate best when close to room temperature.

    The prototype is made entirely from an amber-colored glass-ceramic called Zerodur, manufactured by Schott in Mainz, Germany. The material is widely used for telescope mirrors and other applications requiring high precision because its shape changes very little over a wide range of temperatures.

    The LISA mission is slated to launch in the mid-2030s.
    Download additional images from NASA’s Scientific Visualization Studio

    By Francis ReddyNASA’s Goddard Space Flight Center, Greenbelt, Md.Media Contact:Claire Andreoli301-286-1940claire.andreoli@nasa.govNASA’s Goddard Space Flight Center, Greenbelt, Md.

    MIL OSI USA News

  • MIL-OSI United Kingdom: Defence Secretary oral statement on war in Ukraine – 22 October 2024

    Source: United Kingdom – Executive Government & Departments

    Defence Secretary John Healey, provided an update to the House of Commons on the war in Ukraine.

    Mr Speaker, I have just returned from three days of intense defence diplomacy.

    First, at the NATO Defence Ministers meeting in Brussels where we welcomed President Zelenskyy and then, at the G7 Defence Ministers meeting in Naples where we had important updates from the battlefield, agreed this is a critical point in the conflict and stressed the need to step up and speed up support for Ukraine.

    The G7 joint declaration strongly condemned Putin’s illegal invasion and reinforced our unwavering support for Ukraine. It also rightly stated:

    “Russia’s aggression against Ukraine is posing a threat to international security, the purposes and principles of the United Nations, and the rules-based international order.”

    This is what’s at stake for us all. And if President Putin prevails in Ukraine, he will not stop at Ukraine. And if big nations redraw international boundaries by force, the sovereignty and security of all nations is undermined.

    That’s why the UK support, alongside allies, is so important. Military, economic, industrial, diplomatic.

    But I can tell the House, Mr Speaker, I have returned to the UK knowing that NATO is united for Ukraine. The G7 is united for Ukraine. Just as the UK is united for Ukraine.

    And our job now is to turn these talks into action, which is exactly what we are doing as a government. So, the Chancellor and I are today are announcing that the UK will provide an additional £2.26bn to Ukraine

    This is new money, new money which will be delivered under the Extraordinary Revenue Acceleration Loans to Ukraine scheme. That’s part of the $50 billion loan package from G7 countries to support Ukraine’s military, budget, and reconstruction needs.

    Loans, Mr Speaker, which will be repaid using the profits generated from immobilised Russian sovereign assets. Profits on frozen Russian money, supporting Ukraine’s fight against Putin. Turning the proceeds of Putin’s corrupt regime against that regime and putting it in the hands of Ukrainians.

    And Mr Speaker, I want to be clear: Today’s new money is additional to the £3bn a year of military support this Government has committed to Ukraine each year for as long as it takes.

    In addition to the £3.5bn Defence Industrial Support Treaty which I signed with Defence Minister Umerov in July, money that will be used by Ukraine to procure military equipment from British companies, boosting our British jobs and our British industry. And extra to the additional artillery, air defences, ammunition, and missiles we have announced in the first four months of this new Government.

    Ukraine is a first order priority for me as Defence Secretary, it’s a first order priority for this Government. We will continue to step up support.  We will continue to lead. We will stand with Ukraine as long as it takes.

    Mr Speaker, today is now day 973 since Putin launched his full scale, illegal invasion of Ukraine. 973 days during which Ukrainians have been fighting with great courage – civilians and military alike. And there have been important battlefield developments in recent weeks. When I last updated the House, Ukrainian forces were one month into their remarkable offensive in Kursk.

    Three months on, they continue to hold Russian territory and Ukraine’s strategic surprise has put Putin under pressure, forcing the diversion of some Russian troops and equipment.

    And despite the increase in brutal Russian counter attacks and aerial bombardments, they have so far failed to dislodge that Ukrainian incursion. And it’s not just in Kursk where Ukraine is fighting back.

    Ukrainian forces have launched long range attacks into Russian territory on military targets which are directly supporting Putin’s illegal invasion.

    In September, Ukraine used long range drones to attack four ammunition storage facilities. These strikes successfully destroyed thousands of tonnes of ammunition. 

    Both the defensive thrust into Kursk, and the strategic defensive strikes into Russia, have had an impact on the battlefield.

    Russia’s advance towards Pokrovsk in the East – Putin’s main line of effort – has been slowed. Russian losses continue to rise. Since the start of the conflict, Russia has likely suffered 675,000 casualties.

    In September, the average casualty rate each date of Russians on the battlefield of Ukraine was 1271 – a record high and two and a half times the level this time last year.

    And on equipment, Mr Speaker, they have now lost 3,400 tanks, 8,500 armoured vehicles and 26 Russian vessels in the Black Sea fleet have been destroyed or damaged.

    But despite the incredible resilience Ukrainian forces have shown, they remain under great pressure from Russian forces across multiple fronts, and Russian troops continue to advance and continue to attack Ukraine infrastructure. Targeting the important port of Odessa and striking energy infrastructure.

    So as we head into winter, Mr Speaker, Ukraine’s energy generation capacity has been reduced by up to two thirds of that of pre-war levels. Russian industry remains on a war footing. Russian artillery is outfiring Ukraine by at least 3 to 1, and Russia is also conscripting this year an additional 400,000 troops.

    Defence will now account for 32%, one third of the total government budget in Russia next year.

    And, Mr Speaker, in a concerning new development, it is now highly likely that the transfer and deployment of hundreds of combat troops from North Korea to Russia has begun. North Korean soldiers supporting Russia’s war of aggression on European soil – it is as shocking as it is desperate.

    North Korea already sends significant munitions and arms to Russia in direct violation of multiple UN resolutions. And this developing military cooperation between Russia and DPRK has serious security implications for Europe and the Indo-Pacific.

    It represents a wider growing alliance of aggression which NATO and the G7 nations must confront.

    Mr Speaker, despite this dangerous development, Ukraine remains determined to fight on their frontline in the East and holding the territory in Kursk. President Zelensky will also continue to seek support for his Victory Plan, and we want to see this Plan succeed. We stand ready to work closely with the Ukrainians and with allies to make it succeed.

    Mr Speaker, as we approach 1000 days of this war, this conflict is now at a really critical moment. And that’s why the UK continues to step up support for Ukraine.

    Ukrainians are fighting to regain their sovereign territory, but they are also fighting to protect the peace, the democracy and the security for the rest of us in Europe.

    Updates to this page

    Published 22 October 2024

    MIL OSI United Kingdom

  • MIL-OSI Security: NATO continues to strengthen 30 years of scientific cooperation with Bulgaria

    Source: NATO

    On Tuesday (22 October 2024), a team from the NATO Science for Peace and Security (SPS) Programme was in Sofia to further strengthen scientific cooperation with Bulgaria.

    Representatives from the SPS Programme and Bulgarian government officials highlighted the value of three decades of cooperation – which began during Bulgaria’s partnership with NATO and has continued in the 20 years since the country joined the Alliance. Through this scientific cooperation, researchers have developed novel materials to absorb sound, modelled pollution risks in the Black Sea, created software to enhance cyber defences, and more. The NATO team highlighted that they will soon launch a new call for proposals, enabling further research and innovation.

    The Information day organised by the NATO SPS Programme is one of a number of events to mark Bulgaria’s 20th anniversary as a member of NATO. Scientists at the event were joined by members of the diplomatic community, as well as officials from Bulgaria’s Ministry of Defence, Ministry of Foreign Affairs, and Ministry of Education and Science.
     

    MIL Security OSI

  • MIL-OSI USA: Justice Department Launches Voter Assistance Resources for People Impacted by Recent Hurricanes and Severe Weather Damage

    Source: US State of Vermont

    The Justice Department’s Civil Rights Division launched a webpage today compiling information to help voters in states impacted by recent hurricanes Helene and Milton to have access to the ballot. The hurricanes have displaced several thousands of people from their residences; disrupted vital services; closed schools, businesses and other places; slowed postal delivery; and destroyed important personal possessions, including photos and identification documents.

    In these online resources, the department focuses on the six states that were directly affected by recent hurricanes: Florida, Georgia, North Carolina, South Carolina, Tennessee and Virginia. The site identifies and provides links to various state changes made to accommodate voters who have been displaced, lost their identification documents, have had polling sites moved or who are unsure where or how they can vote. It also provides contact information so that voters can reach local voting officials who can provide the most specific and up-to-date guidance.

    The Justice Department is also committed to ensuring every eligible voter can cast their ballot free from discrimination and intimidation. Federal laws protect against voter intimidation, coercion and interference at every stage of the voting process. For additional information about voting and elections, including filing federal voting rights violations or threats against election workers, visit http://www.justice.gov/voting. Contact the Civil Rights Division’s Voting Section through the internet reporting portal at http://www.civilrights.justice.gov or by calling 1-800-253-3931.

    MIL OSI USA News

  • MIL-OSI USA: Kamlager-Dove, Kim, Coons, and Tillis to Introduce Bicameral Legislation to Promote Protection of International Digital Freedom

    Source: United States House of Representatives – Congresswoman Sydney Kamlager California (37th District)

    WASHINGTON, D.C. – Today, Congresswomen Sydney Kamlager-Dove (CA-37) and Young Kim (CA-40), alongside Senators Chris Coons (DE) and Thom Tillis (NC), announced plans to introduce the bicameral Advancing Digital Freedom Act of 2024, which would equip the U.S. State Department with the authorities to elevate digital freedom as a cornerstone of U.S. foreign policy and support its critical role in advancing democratic governance around the world.

    “Digital technology has both benefits and drawbacks when it comes to advancing democracy,” said Congresswoman Kamlager-Dove. “It can enable citizens to access information, share ideas, and organize while simultaneously allowing for authoritarian regimes to spread propaganda, enhance surveillance, and stifle free speech. We must ensure that digital technologies are used to strengthen democracy, not dismantle it. It is crucial for the United States to develop a comprehensive strategy to safeguard digital freedom worldwide and work with partners to implement this plan. Promoting human rights and democracy at home and abroad must remain a bipartisan issue, and I am proud to advance these priorities with a bipartisan, bicameral group of congressional colleagues.”

    “The Unholy Alliance, including the People’s Republic of China, Russia, Iran, and North Korea, relies on abusive surveillance technologies to restrict access to information and the outside world and to maintain their grip on power,” said Congresswoman Young Kim, Chair of the House Foreign Affairs Subcommittee on the Indo-Pacific. “To remain a global human rights leader, the United States cannot stand idly by as these authoritarian regimes use digital technologies and platforms to suppress innocent civilians, religious minorities, and political dissenters. I am proud to join Representative Kamlager-Dove and Senators Coons and Tillis to lead this bipartisan, bicameral effort to protect the right to international digital freedom. I’ll keep fighting to ensure the United States promotes global human rights and protects freedom-loving people around the world.”

    “As a global leader of human rights, the United States must deter authoritarian and illiberal states that are using advanced technologies to threaten human rights alongside our own national security,” said Senator Coons. “Protecting digital freedom abroad is a cornerstone of American foreign policy for the modern age, and that is why we must cooperate with like-minded countries to develop and deploy emerging technology in a manner that respects democracy and rule of law. As Co-Chair of the Senate Human Rights Caucus, I’m confident that this bill will help protect digital freedoms and counter global misinformation and disinformation in partnership with our allies.”

    “With increasing cyber threats and attacks on the horizon than ever before, working with our allies to counter them is all the more important,” said Senator Tillis. “Protecting and promoting digital freedom across the globe must be a priority, which is why I look forward to introducing this bipartisan legislation to ensure the Department of State continues to prioritize this as a cornerstone of U.S. foreign policy.”

    The right to freedom of expression has become a fault line between pro-democracy groups and authoritarian governments. Digital platforms, including social media, have been crucial tools for movements such as the Mahsa Amini protests in Iran or the Umbrella Movement in Hong Kong. However, autocratic governments have attempted to stifle these efforts by cracking down on digital freedom. Russia and China deploy digital tools to identify and silence dissidents, Iran routinely blocks access to thousands of websites conveying political content, and North Korea and Venezuela coordinate disinformation campaigns to undermine citizens’ access to credible information. To address such threats to digital freedom, the Advancing Digital Freedom Act would strengthen the United States’ role in leading efforts to ensure technology is used to uphold human rights, democratic values, and the rule of law.

    Specifically, the bill would:

    • Elevate digital freedom as a foremost foreign policy priority of the United States;
    • Empower the Coordinator for Digital Freedom in the State Department’s Bureau of Cyberspace and Digital Policy to lead global efforts to protect digital freedom, counter disinformation and misinformation, and advance democratic governance in the digital space;
    • Encourage the State Department to engage with foreign governments, nongovernmental organizations, and other actors to coordinate efforts to defend digital freedom against digital authoritarianism; and
    • Require the Bureau of Cyberspace and Digital Policy to submit an annual report to the Senate Foreign Relations Committee and the House Foreign Affairs Committee on the state of global digital freedom, including analysis of emerging and concerning trends impacting digital freedom.                                                                                                              

    The text of the bill is available here.

    ###

    MIL OSI USA News

  • MIL-OSI: NNIT A/S: NNIT adjusts 2024 financial outlook

    Source: GlobeNewswire (MIL-OSI)

    NNIT adjusts the 2024 financial outlook and now expects organic revenue growth to be around 6-7% (previously around 10%) and the Group operating profit margin to reach 6-7% before special items (previously 8-9%) on the back of unsatisfactory performance in Q3. An uplift in Q4 is expected based on improved transparency and a solid backlog for the remainder of the year following recent important contract wins.

    Based on preliminary and unaudited financial figures, NNIT generated Q3 2024 Group revenue of DKK 445 million (2023: DKK 453 million) and Group operating profit of DKK 17 million before special items (2023: DKK 26 million) corresponding to organic growth of -1.6% (2023: 11.1%) and a Group operating profit margin of 3.9% before special items (2023: 5.8%) in the quarter. For the first nine months of 2024, Group revenue was DKK 1,382 million (2023: DKK 1,290 million) with Group operating profit of DKK 73 million before special items (2023: DKK 72 million) for organic growth of 5.6% (2023: 11.3%) and a Group operating profit margin of 5.3% before special items (2023: 5.6%).

    The outlook adjustment follows an unexpected revenue decline in Region Europe and Region US in Q3, which was impacted by a moderate market slowdown resulting in projects being postponed or put on hold, combined with prolonged challenges in the data migration business. As one of several levers to accelerate profitability in the second half of 2024, NNIT recalibrated capacity in both Europe and the US in Q3, and additional adjustments are made to align internal capacity with market demand. NNIT is executing as planned on the remaining initiatives already taken to accelerate profitability, which include securing important wins in the US and Europe, leveraging the full effect of the turnaround in Asia, completing crucial internal projects and benefiting from a lower cost run-rate after relocation of offices. These key levers are contributing positively to profitability in 2024 and beyond.

    NNIT will publish the Q3 2024 trading statement on November 5, 2024 as planned.

    Contact for further information
    Carsten Ringius
    EVP & CFO
    Tel: +45 3077 8888
    carr@nnit.com

    Media relations
    Tina Joanne Hindsbo
    Media Relations Manager
    Tel: +45 3077 9578
    tnjh@nnit.com

    NNIT is a leading provider of IT solutions to life sciences internationally, and to the public and enterprise sectors in Denmark

    We focus on high complexity industries and thrive in environments where regulatory demands and complexity are high.

    We advise and build sustainable digital solutions that work for the patients, citizens, employees, end users or customers.

    We strive to build unmatched excellence in the industries we serve, and we use our domain expertise to represent a business first approach – strongly supported by a selection of partner technologies, but always driven by business needs rather than technology.

    NNIT consists of group company NNIT A/S and subsidiaries SCALES, Excellis Health Solutions and SL Controls. Together, these companies employ more than 1,700 people in Europe, Asia and USA.

    Read more at http://www.nnit.com

    Attachment

    The MIL Network

  • MIL-OSI Security: Former CEO of Abercrombie & Fitch and Two Other Individuals Charged with Sex Trafficking and Interstate Prostitution

    Source: United States Department of Justice (Human Trafficking)

    Defendants Allegedly Arranged for Dozens of Men to Travel to New York and Hotels Around the World for Sex Events

    A 16-count indictment was unsealed today in federal court in Central Islip charging former Abercrombie & Fitch Co. (Abercrombie) Chief Executive Officer Michael Jeffries, along with Matthew Smith and James Jacobson, with sex trafficking and engaging in interstate prostitution.  The indictment alleges that between December 2008 and March 2015, Jeffries, Smith and Jacobson used a combination of force, fraud and coercion to traffic men while operating a prostitution enterprise.  All three defendants were arrested this morning. Jeffries and Smith are scheduled to make their initial appearances this afternoon in federal court in the Southern District of Florida, and Jacobson is scheduled to make his initial appearance this afternoon in federal court in St. Paul, Minnesota. They will be arraigned in the Eastern District of New York at a later date.

    Breon Peace, United States Attorney for the Eastern District of New York, James E. Dennehy, Assistant Director in Charge, New York Field Office (FBI) and Thomas G. Donlon, Interim Commissioner, New York City Police Department (NYPD), announced the arrests and charges.

    “As alleged in the indictment, former CEO of Abercrombie Michael Jeffries, his partner Matthew Smith and their recruiter James Jacobson used their money and influence to prey on vulnerable men for their own sexual gratification,” stated United States Attorney Peace.  “Today’s arrests show that my Office and our law enforcement partners will not rest until anyone who engages in sex trafficking or interstate prostitution, regardless of their wealth or power, is brought to justice.”

    Mr. Peace expressed his thanks to the FBI Miami Field Office, West Palm Beach Resident Agency; the FBI Milwaukee Field Office, Eau Clair Resident Agency; the Barron County, Wisconsin, Sheriff’s Office; and the United States Attorney’s Offices for the Southern District of Florida and the District of Minnesota, for their assistance with the case.

    “Today’s indictment highlights the alleged abhorrent behavior of Michael Jeffries, Matthew Smith, and James Jacobson.  The defendants allegedly preyed on the hopes and dreams of their victims by exploiting, abusing, and silencing them to fulfill their own desires, with insidious secret intentions.  This case is yet another example of individuals using their wealth, power, or reputation to manipulate and control others for their personal gratification.   The FBI and our partners won’t allow these criminal acts to go unchecked, we remain committed to investigating and bringing these cases forward to prosecution,” stated FBI Assistant Director in Charge Dennehy.

    “Sex trafficking remains a pressing issue nationwide and New York City is no exception,” stated NYPD Interim Commissioner Donlon. “Through our continued partnership with the FBI and the U.S. Attorney for the Eastern District of New York, the NYPD is able to enhance our investigations and secure convictions. Importantly, our close collaboration also allows us to connect survivors of this abhorrent crime with the necessary support and services they deserve.”

    From approximately 1992 to 2014, Jeffries was the CEO of Abercrombie, a fashion clothing retailer that owned and operated retail stores around the world.  Smith was Jeffries’ life partner.  The indictment alleges that Jacobson was employed by Jeffries and Smith to recruit, interview and hire men to perform commercial sex acts for Jeffries and Smith.

    As set forth in the indictment, from approximately 2008 to 2015, Jeffries, Smith and Jacobson, together with others, operated an international sex trafficking and prostitution enterprise.  Jeffries and Smith not only relied on their financial resources and Jeffries’ power as the CEO of Abercrombie, but also on numerous others, including Jacobson and a network of employees, contractors and security professionals, to operate this venture, which was dedicated to fulfilling their sexual desires.

    As further alleged in the indictment, Jeffries and Smith paid for dozens of men to travel within the United States and internationally to various locations, including the Hamptons on Long Island, New York City and hotels in England, France, Italy, Morocco and Saint Barthélémy, for the purpose of engaging in commercial sex acts with Jeffries, Smith and others (the “Sex Events”). Jacobson allegedly traveled throughout the United States and internationally to recruit and interview men for the Sex Events.  During “tryouts” of potential candidates, Jacobson typically required that the candidates first engage in commercial sex acts with him.

    The indictment alleges that Jeffries, Smith and Jacobson used coercive, fraudulent and deceptive tactics in connection with their sex trafficking and prostitution venture. For example, among other things, Jeffries, Smith, Jacobson and others acting at their direction:

    • Employed a referral system and interview process that did not inform men of the details of the Sex Events before they attended, including the full extent and nature of the sexual activity that would be required of the men at the Sex Events;
    • Caused men to believe that attending the Sex Events could yield modeling opportunities with Abercrombie or otherwise benefit their careers;
    • Caused men to believe that not complying with requests for certain acts during the Sex Events could harm their careers;
    • Required men to relinquish their personal items, including clothing, wallets and cellular phones, and store them in an inaccessible location during the Sex Events;
    • Required men to sign non-disclosure agreements;
    • On more than one occasion when men did not or could not consent, Jeffries and Smith violated the bodily integrity of the men by subjecting them, or continuing to subject them, to invasive sexual and violent contact by body parts and other objects;
    • On more than one occasion, Jeffries and Smith directed others to inject, or personally injected, men with an erection-inducing substance for the purpose of causing the men to engage in sex acts the men were incapable or unwilling to engage in.

    Many of the victims, at least one of whom was as young as 19 years old, were financially vulnerable and aspired to become models in the fashion industry.  Some victims recruited by the defendants had previously worked at Abercrombie stores or had modeled for Abercrombie.

    If convicted of the sex trafficking charge, the defendants each face a maximum sentence of life imprisonment and a mandatory minimum sentence of 15 years’ imprisonment.  If convicted of the interstate prostitution charges, the defendants face a maximum sentence of 20 years’ imprisonment.

    The charges in the indictment are allegations, and the defendants are presumed innocent unless and until proven guilty.

    If you believe you are victim of a crime perpetrated by Michael Jeffries, Matthew Smith or James Jacobson, please contact the FBI at 1-800-CALL-FBI.

    The government’s case is being handled by the Office’s Civil Rights Section and the Criminal Section of the Office’s Long Island Division.  Assistant United States Attorneys Megan Farrell, Erin Reid and Philip Pilmar are in charge of the prosecution with the assistance of Bilingual Victim Witness Specialist Stephanie Marroquin and Fact Witness Services Unit Supervisor/Victim Witness Coordinator Huda Abouchaer.

    The Defendants:

    MICHAEL JEFFRIES
    Age: 80
    West Palm Beach, FL

    MATTHEW SMITH
    Age: 61
    West Palm Beach, FL

    JAMES JACOBSON
    Age:  71
    Rice Lake, WI

    E.D.N.Y. Docket No. 24-CR-423 (NJC)

    MIL Security OSI

  • MIL-OSI USA: Meloë Kacenelenbogen Eyes the Future of Air Quality, Climate Research

    Source: NASA

    A mentor of research scientist Meloë Kacenelenbogen once shared a sentiment from French author André Gide: “You cannot discover new oceans unless you have the courage to lose sight of the shore.” Kacenelenbogen pushes beyond her comfort zone to explore the unknown.
    Name: Meloë S. KacenelenbogenFormal Job Classification: Research scientistOrganization: Climate and Radiation Laboratory, Science Directorate (Code 613)

    What do you do and what is most interesting about your role here at Goddard?
    I study the impact of aerosols — suspended particles from, for example, wildfire smoke, desert dust, urban pollution, and volcanic eruptions — on air quality and the Earth’s climate. I use space, air, and ground-based observations, as well as models.
    Why did you become a scientist? What is your educational background?
    I never made a deliberate choice to become a scientist. I started with very little confidence as a child and then built up my confidence by achieving things I thought I could not do. I chose the hardest fields to work on along the way. Science looked hard and so did fluid mechanics, remote sensing, and atmospheric physics. I have failed many times, but I always learn something and move on. I do get scared and maybe even paralyzed for a day or two, but I never let fear or failure immobilize me for long.
    I was born in Maryland, but my family moved to France when I was young, so I am fluent in French. I have a bachelor’s and master’s degree in mechanical engineering, and physical methods in remote sensing from the Université Pierre et Marie Curie (Paris VI, Jussieu). In 2008, I got a Ph.D. in atmospheric physics for applying satellite remote sensing to air quality at the Université des Sciences et Technologies de Lille (USTL), France.
    What are some of your career highlights?
    After my Ph.D., I worked for the Atmospheric Lidar Group at the University of Maryland, Baltimore County (UMBC), on spaceborne and ground-based lidars. In 2009, I got a NASA Post-doctoral Program (NPP) fellowship at the agency’s Ames Research Center in California’s Silicon Valley, where I worked for 13 years on space-based, aircraft-based, and ground-based atmospheric aerosol vertical distribution and aerosol typing.
    In 2022, I came to work at the Climate and Radiation Lab at Goddard.
    What is most interesting about aerosols?
    Aerosols are very topical because they have a huge impact on the air we breathe and our Earth’s climate. The smaller the aerosol, the deeper it can get into our lungs. Among other sources, aerosols can come from cars, factories, or wildfires. We all know that wildfires are becoming bigger and more frequent. They are expected to happen even more frequently in the future due to climate change. Both when I was living in California and here in Maryland, I have experienced first-hand choking from the wildfire smoke. I will always remember how apocalyptic it felt back in the summer of 2020 in California when wildfire smoke was paired with COVID confinement, and the sky turned Mars-like orange.
    Please tell us about your involvement with the Atmosphere Observing System (AOS)?
    I am incredibly lucky to be able to contribute to the next generation of NASA’s satellites. I am working on AOS, which will observe aerosols, clouds, convention, and precipitation in the Earth’s atmosphere. I am part of the team that is helping design several instruments and algorithms.
    My role is to connect this spaceborne observing system to all our other space, ground, and air-based measurements at the time of launch. We are making a mesh of observations to address the science questions, run the algorithms, and validate the spaceborne measurements. I am constantly pushed to expand my horizon and my own knowledge.
    Why do you enjoy always challenging yourself intellectually?
    I started that way. I had no confidence, so I felt that the only way I could build my confidence was to try doing things that scared me. I may sometimes be a little scared, but I am never bored.
    What did you learn from your mentors?
    A few years ago, a mentor shared a quote from André Gide with me that encapsulates what we are talking about: “You cannot discover new oceans unless you have the courage to lose sight of the shore.” In other words, it is OK, maybe preferable, to be out of my comfort zone to explore the unknown as scary as it may be.
    Along the way, it has been extremely important for me to deliberately choose mentors. To me, a good mentor has earned the respect of all who have worked with them, is uplifting, reassuring, and gives me the invaluable guidance and support that I need. I deliberately try to surround myself with the right people. I have been very, very fortunate to find incredible people to encourage me.
    As a mentor, what do you advise?
    I tell them to deliberately choose their mentors. I also tell them that it is OK to be uncomfortable. Being uncomfortable is the nature of our field. To do great things, we often need to be uncomfortable.
    Why do you enjoy working on a team?
    I love working on teams, I love to feed off the positive energy of a team whether I lead it or am part of it. In my field, teamwork with a positive energy is incredibly satisfying. Everybody feeds off everybody’s energy, we go further, are stronger, and achieve more. This may not happen often, but when it does it makes it all worth it.
    What are the happiest moments in your career?
    I am always happiest when the team publishes a paper and all our efforts, are encapsulated in that one well-wrapped and satisfying peer-reviewed paper that is then accessible to everyone online. Every paper we publish feels, to me, the same as a Ph.D. in terms of the work, pain, energy, and then, finally, satisfaction involved.
    What do you hope to achieve in your career?
    I want to have been a major contributor to the mission by the time the AOS satellites launch.
    What do you do for fun?
    I do mixed martial arts. I love the ocean, diving, and sailing. I also love going to art galleries, especially to see impressionist paintings to reconnect with my Parisian past.

    Who is your favorite author?
    I love Zweig, Kafka, Dostoyevsky, Saint-Exupéry, and Kessel. The latter two wrote a lot about aviators in the early 1900s back in the days when it was new and very dangerous. Those pilots, like Mermoz, were my heroes growing up.
    Who would you like to thank?
    I would like to thank my family for being my rock.
    What are your guiding principles?
    To paraphrase Dostoevsky, everyone is responsible to all men for all men and for everything. I have a strong sense of purpose, pride, justice, and honor. This is how I try to live my life for better or for worse.
    By Elizabeth M. JarrellNASA’s Goddard Space Flight Center, Greenbelt, Md.

    Conversations With Goddard is a collection of Q&A profiles highlighting the breadth and depth of NASA’s Goddard Space Flight Center’s talented and diverse workforce. The Conversations have been published twice a month on average since May 2011. Read past editions on Goddard’s “Our People” webpage.

    MIL OSI USA News

  • MIL-OSI Security: Victim named in Farringdon murder investigation

    Source: United Kingdom London Metropolitan Police

    Met officers have named a man who died following a stabbing in Farringdon.

    Abdul-Latif Pouget, aged 20 from Camden, sadly died in hospital on the morning of 21 October after being stabbed.

    An investigation was launched after police were called to Back Hill, EC1 at 21:36hrs on Friday, 18 October, following reports of a moped colliding with a wall.

    While paramedics from the London Ambulance Service were treating Abdul-Latif, they found he also had stab injuries. He was taken to hospital but sadly died. His family are aware and being supported by specialist officers.

    Oguzcan Dereli, 26 (08.04.98) of Islington, was arrested on Sunday, 20 October and charged with murder the following day – he appeared at Highbury Corner Magistrates’ Court on Tuesday, 22 October and was remanded in custody to next appear at the Old Bailey on Thursday, 24 October.

    Anyone with information on this incident is asked to call 101 or ‘X’ @MetCC and quote reference CAD 8294/18Oct.

    Alternatively, you can also provide information anonymously to the independent charity Crimestoppers on 0800 555 111 or visit crimestoppers-uk.org.

    MIL Security OSI

  • MIL-OSI United Kingdom: Top comedian highlights the work of foster carers

    Source: City of York

    Published Tuesday, 22 October 2024

    A top stand-up comedian highlighted the life-changing work that foster carers do in a gig in York earlier this month (13 October).

    Kiri Pritchard McLean has spoken about her own experience as a foster carer for the first time during her current show, Peacock.

    Better known nationally as the Star of 8 out of 10 Cats Does Countdown, Have I Got News For You and QI, as well as hosting Live at the Apollo and fronting the Radio 4 panel show Best Medicine, Kiri hasn’t even told the children in her care that she’s a comedian.

    Cllr Bob Webb, the council’s Executive Member for Children and Young People, said:

    It’s fantastic to see such a well-known and loved comedian like Kiri highlighting the life changing work foster carers do.

    Fostering can be such a rewarding experience and we’d always welcome more foster carers in York to provide safe, loving homes for local children and young people. We welcome people from all backgrounds and we’d love to hear from anyone who thinks fostering might be for them.”

    A York foster carer who attended the performance, said:

    It’s great to see someone combining a high-profile role as a stand-up comedian with fostering, sharing their experiences with audiences across the country.

    “Fostering certainly has its challenges, but the rewards from helping children and young people are life changing.”

    For more information in fostering in York visit our fostering page, or call 01904 555678.

    MIL OSI United Kingdom

  • MIL-OSI United Kingdom: Jersey adopts legislation to implement Pillar 2 from 202522 October 2024 Ministers have welcomed the decision of the States Assembly to unanimously adopt legislation to implement a Pillar 2 Income Inclusion Rule and a multinational corporate income tax from 2025, fulfilling… Read more

    Source: Channel Islands – Jersey

    22 October 2024

    Ministers have welcomed the decision of the States Assembly to unanimously adopt legislation to implement a Pillar 2 Income Inclusion Rule and a multinational corporate income tax from 2025, fulfilling Jersey’s commitment to enact the OECD’s global minimum tax framework for large in-scope multinational groups. 

    For accounting periods starting on or after 1 January 2025, in-scope Jersey companies and branches of multinational groups will pay an effective rate of 15% on their Jersey profits under the new Multinational Corporate Income Tax (MCIT). Jersey’s MCIT applies the OECD Model Rules and takes account of certain instances of double taxation. 

    Jersey will also impose a top-up tax on low-taxed profits outside of the Island under the OECD’s Pillar 2 Income Inclusion Rule (IIR) but will not apply the Undertaxed Profits Rule (UTPR). 

    Jersey has a long-standing corporate income tax regime and Revenue Jersey is well resourced to deal with the roll out of Pillar 2. Over 95% of Jersey companies will be unaffected by this Pillar 2 legislation and will remain within the existing Jersey income tax regime. 

    Jersey’s Minister for Treasury & Resources, Deputy Elaine Millar, said: “The Government is committed to providing an internationally competitive business environment in Jersey and is working with industry and the Jersey Financial Services Commission in a tri-partite Ministerial Working Group. One of the outcomes will be a new Pillar 2-compliant Qualifying Refundable Tax Credit (QRTC) regime. This regime will be effective in incentivising business growth and deepening business ties with Jersey. 

    “Jersey is committed to providing taxpayers with the tax certainty they need and the highest standards of customer service. We will be keeping the Pillar 2 administrative burden in Jersey as low as possible, within the boundaries of the OECD global rules.”

    Jersey’s Minister for External Relations, Deputy Ian Gorst, added: “The passing of this legislation maintains Jersey’s reputation as a forward-thinking jurisdiction that is fully aligned with international tax initiatives developed by standard-setting bodies like the OECD. I am confident that Jersey is well positioned to implement this new Pillar 2 regime and maintain a globally competitive business environment for our taxpayer customers worldwide.” 

    Affected taxpayers and their advisers can also contact Revenue Jersey officers with any questions or requests by email at pillar2@gov.je​.​

    MIL OSI United Kingdom

  • MIL-OSI United Kingdom: Interim report on drugs “positive to see progress on saving lives and reducing harm” – Senator O’Hara

    Source: The Green Party in Northern Ireland

    Interim report on drugs “positive to see progress on saving lives and reducing harm” – Senator O’Hara

    Senator Mal O’Hara said “I am delighted to see this interim report. With an election due within weeks, this report gives a clear direction to any incoming Government on how to move to a health led approach which will save lives and reduce harm.
    Mal continued “The work of the joint committee is to respond to the 36 recommendations made by the Citizens Assembly. The Committee held engagements with stakeholders in June, July, September, and October of 2024 which provided evidence from a broad perspective of voices and sectors of Irish society. Arising from these engagements, the Committee made 59 recommendations in its interim report. Some of which include repealing the Misuse of Drugs Act 1997, introducing a regulatory model for certain drugs and decriminalisation in relation to possession of all substances for personal use. 
    These include:
    • the stigmatisation of drug use and the shaming of drug users are a source of significant harm.
    • the Committee recommends that steps are taken to introduce a regulatory model for certain drugs. The Committee recommends this should be considered with particular reference to Spain, Malta, and Germany in the development of an Irish not for profit regulated cannabis market.
    • that Government introduce a health-led approach to the use and misuse of substances.
    • the decriminalisation of the person in relation to the possession of all substances for personal use, in line with the recommendations of the Citizens’ Assembly – this highlights that the goal of drug policy should be to reduce harm and eliminate stigma, both, in large part, caused and exacerbated by the criminalisation of people who use drugs.
    • Section 3 of the Misuse of Drugs Act 1997 be repealed, to give effect to a comprehensive health led approach.
    • the decriminalisation of possession for personal use should apply equally to all illicit drugs.
    • people should be offered all supports and health resources that are required, but that no person should be criminalised for not availing of a supportive intervention.
    • the importance of there being a strong, constructive working relationship between the community, voluntary and statutory services, and An Garda Síochána, to support the provision of compassionate and person-centred interventions where required, underpinned by a robust Memorandum of Understanding.
    • local authorities and An Garda Síochana are supported and empowered in strongly discouraging and reducing consumption in public areas. This should be done in an appropriate and sensitive way which considers the complex inter-relationship between problematic use and extreme deprivation and homelessness.
    • that specific trauma and harm reduction training be provided to An Garda Síochána and local authorities, to inform their work with individuals and communities affected by drug misuse and addiction.
    • the development of clear guidelines for An Garda Síochána to operate within a decriminalised model
    Senator O’Hara finished “It is positive to see this progress on saving lives and reducing harm. It is disappointing that despite Northern Ireland having a higher drug death rate than the Republic, and drug deaths almost tripling in the last decade, that the Executive Parties sit on their hands while vulnerable people die.”
    ENDS 
    Press enquiries – Mal O’Hara on 07540790663 

    MIL OSI United Kingdom

  • MIL-OSI Russia: Mikhail Mishustin held a meeting with the State Secretary of the Union State Dmitry Mezentsev

    Translation. Region: Russian Federation –

    Source: Government of the Russian Federation – An important disclaimer is at the bottom of this article.

    Russian Prime Minister Mikhail Mishustin met with State Secretary of the Union State Dmitry Mezentsev.

    During the meeting, priority tasks for deepening Russian-Belarusian integration in the Union State were discussed in the context of preparations for the upcoming meeting of the Council of Ministers of the Union State.

    The draft agenda of the Union Council of Ministers includes current issues of practical cooperation between Russia and Belarus. Priority attention will be given to the implementation of the Main Directions for the Implementation of the Provisions of the Treaty on the Establishment of the Union State for 2024–2026, approved by the Supreme State Council of the Union State on January 6, 2024.

    It is also planned to discuss the promotion of joint projects in various areas in order to create favorable conditions for increasing trade and economic cooperation and improving the well-being of citizens of Russia and Belarus.

    Please note: This information is raw content directly from the source of the information. It is exactly what the source states and does not reflect the position of MIL-OSI or its clients.

    MIL OSI Russia News

  • MIL-OSI Canada: Media Accreditation for the Ministerial Conference on the Human Dimension of Ukraine’s Peace Formula

    Source: Government of Canada News

    The Honourable Mélanie Joly, Minister of Foreign Affairs, announced that Canada, together with co-organizers Norway and Ukraine, will host the Ministerial Conference on the Human Dimension of Ukraine’s 10-Point Peace Formula on October 30-31, 2024.

    October 22, 2024 – The Honourable Mélanie Joly, Minister of Foreign Affairs, announced that Canada, together with co-organizers Norway and Ukraine, will host the Ministerial Conference on the Human Dimension of Ukraine’s 10-Point Peace Formula on October 30-31, 2024.

    Media representatives who wish to cover the visit must obtain media accreditation.

    The media accreditation process is open to journalists (print, radio, television, news agencies and online media) who are on assignment with a bona fide media organization.

    Individuals performing journalistic functions who do not work for a media organization and are unable to provide a letter of assignment will have to provide proof of recent publications under the applicant’s by-line that can be readily found in the public realm and under a bona fide media organization.

    Government officials, representatives, or observers will not be accredited as media.

    To apply, please complete the form here and include all requested documentation. The registration code for media is: c&Dw8sbLRQ@M

    Only applications that include all requested information will be considered.

    The application period will close on October 29, 2024 at 15:30 PM ET. Once the application process is closed, there will be no further opportunity to apply for accreditation. Please note that accreditation does not guarantee access to all events during the visit.

    MIL OSI Canada News

  • MIL-OSI Economics: More new languages supported in Microsoft 365 Copilot

    Source: Microsoft

    Headline: More new languages supported in Microsoft 365 Copilot

    This month we rolled out support for an additional 12 languages in Microsoft 365 Copilot:  Bulgarian, Croatian, Estonia, Greek, Indonesian, Latvian, Lithuanian, Romanian, Serbian (Latin), Slovak, Slovenian, and Vietnamese. Microsoft 365 Copilot now supports a total of 42 languages. 

    There are a few noteworthy items in this latest set of languages we’re releasing. For example, very early in October, we have already introduced support for Welsh and Catalan, and it’s also important to note that the rollout of Indonesian and Serbian, which began in mid-October, will not reach all customers until early November. And finally, users working in Serbian language will see Teams meeting transcripts in Cyrillic, rather than Latin script. This is an issue we’re working to resolve.  We will provide customers with updates on progress towards providing Teams meeting transcripts for Serbian language in Latin script on an as-appropriate basis. Learn more about supported languages for Microsoft Copilot here.  

    We are always improving and refining Copilot’s language capabilities. We are also continuing to expand the list of supported languages, with plans to offer support for even more languages in the coming months.  

    MIL OSI Economics

  • MIL-OSI Europe: President Meloni’s telephone conversation with President Erdoğan

    Source: Government of Italy (English)

    22 Ottobre 2024

    The President of the Council of Ministers, Giorgia Meloni, had a telephone conversation today with the President of the Republic of Türkiye, Recep Tayyip Erdoğan. 

    The two leaders focused on the strength of bilateral relations, underlining the importance of continuing to work to further consolidate the steadily growing trend in trade. In this regard, President Meloni invited President Erdoğan to visit Italy in the first half of 2025 for a new session of the Italy- Türkiye intergovernmental summit.

    Their discussion also centred around the dramatic situation in the Middle East. Reaffirming Israel’s right to defend itself, the President of the Council of Ministers stressed the need to increase humanitarian aid to the civilian populations affected. The telephone conversation also highlighted the common commitment to call for a ceasefire in Gaza and in Lebanon. With regard to the latter, President Meloni underscored the crucial role played by UNIFIL and the need for the safety of this mission to be guaranteed at all times.

    At the end of their conversation, the two leaders also discussed the situation of Syrian refugees in the region and how to keep supporting Ukraine’s efforts for a just and lasting peace.

    MIL OSI Europe News

  • MIL-OSI USA: McCaul on State Department OIG Reports: “Persistent Refusal to Address Systemic Issues”

    Source: US House Committee on Foreign Affairs

    Media Contact 202-226-8467

    Austin, Texas – House Foreign Affairs Committee Chairman Michael McCaul issued the below statement following receipt of two reports from the State Department’s inspector general (IG), which further confirm the chairman’s investigative finding that U.S. Embassy Kabul abandoned and failed to secure significant amounts of sensitive security assets, including firearms and other lethal weapons, during the chaotic evacuation from Afghanistan. The IG reports also found the department has been unwilling and unable to learn from those mistakes. 

    “These reports by the State Department’s own inspector general confirm my investigation’s findings of willful blindness and dangerous negligence by key State Department officials at Embassy Kabul. They left valuable lethal assets available to the Taliban, who can use those same weapons in their oppression of the Afghan people, support for terrorist groups, and hostilities against the United States. In a world where Americans and our interests abroad are increasingly threatened by our adversaries, the State Department’s persistent refusal to address systemic issues is unacceptable. I will continue working to keep the United States safe and will not relent in pursuing the transparency and accountability Americans deserve.”

    Background:

    The State Department’s Inspector General recently released two reports: (1) Management Assistance Report: The Department Would Benefit From a Formal, Systematic Methodology To Capture and Utilize Lessons Learned Following Post Evacuations (U); and (2) Audit of the Disposition of Sensitive Security Assets at U.S. Embassies Kabul, Afghanistan, and Kyiv, Ukraine (SBU).

    According to the IG reports, U.S. Embassy Kabul abandoned 26% of its special protective equipment holdings and 63% of its total armored vehicle fleet in Afghanistan, with many of those abandoned assets intact for use by the Taliban.

    These findings are consistent with Chairman McCaul’s September 9 report, which — through public hearings, transcribed interviews, and document discovery — revealed how the State Department’s willful blindness to the deteriorating situation during the Afghanistan withdrawal resulted in a failure to plan for a Taliban takeover of the country and the deadly Abbey Gate ISIS-K terrorist attack killing 13 U.S. servicemembers and over 170 Afghan civilians.

    Click here to read the chairman’s full report.

    ###

    MIL OSI USA News

  • MIL-OSI United Kingdom: Collision of two passenger trains at Talerddig, Powys, Wales

    Source: United Kingdom – Executive Government & Departments

    The following press statement is issued by the RAIB about its investigation into the collision of two passenger trains at Talerddig, Powys, Wales

    At around 19:26 on the evening of 21 October 2024, the 18:31 Transport for Wales passenger service from Shrewsbury to Aberystwyth collided with another train on Network Rail’s Cambrian line, approximately 800 metres west of the passing loop located at Talerddig, Powys. Initial evidence suggests that collision occurred at a speed of approximately 24 km/h (15 mph). The second train involved was the 19:09 Machynlleth to Shrewsbury passenger service, also operated by Transport for Wales.

    One passenger tragically died and four other people were seriously injured. Eleven more people sustained injuries which required hospital treatment.

    RAIB was notified of the accident at 19:45 on the night of the accident and immediately dispatched a team of inspectors to examine the site and collect evidence.

    Additional RAIB staff and specialist equipment have arrived at the site of the accident throughout today and we continue to work in conjunction with the British Transport Police, the Office of Rail and Road and the railway companies involved to secure the necessary evidence to support our independent safety investigation. This will include examining the condition of the train and downloading its ‘black box’ data recorder, inspecting the track, analysing data from railway signalling and radio systems, and interviewing witnesses.

    The railway approaching Talerddig from each direction consists of a single track. To allow trains to pass each other a track loop is provided. These loops have points at each end and allow trains to enter a short length of track which lies alongside the single line.

    RAIB’s initial inspection of the track on approach to the point of collision found evidence that wheel/rail adhesion was relatively low, suggesting that the train may have entered into wheel slide when braking. This will be an area of ongoing investigation.

    Our investigation is in its very early stages and an additional update will be available in the coming days once RAIB has gathered and analysed further evidence.

    Updates to this page

    Published 22 October 2024

    MIL OSI United Kingdom

  • MIL-OSI Banking: Grandoreiro, the global trojan with grandiose ambitions

    Source: Securelist – Kaspersky

    Headline: Grandoreiro, the global trojan with grandiose ambitions

    Grandoreiro is a well-known Brazilian banking trojan — part of the Tetrade umbrella — that enables threat actors to perform fraudulent banking operations by using the victim’s computer to bypass the security measures of banking institutions. It’s been active since at least 2016 and is now one of the most widespread banking trojans globally.

    INTERPOL and law enforcement agencies across the globe are fighting against Grandoreiro, and Kaspersky is cooperating with them, sharing TTPs and IoCs. However, despite the disruption of some local operators of this trojan in 2021 and 2024, and the arrest of gang members in Spain, Brazil, and Argentina, they’re still active. We now know for sure that only part of this gang was arrested: the remaining operators behind Grandoreiro continue attacking users all over the world, further developing new malware and establishing new infrastructure.

    Every year we observe new Grandoreiro campaigns targeting financial entities, using new tricks in samples with low detection rates by security solutions. The group has evolved over the years, expanding the number of targets in every new campaign we tracked. In 2023, the banking trojan targeted 900 banks in 40 countries — in 2024, the newest versions of the trojan targeted 1,700 banks and 276 crypto wallets in 45 countries and territories, located on all continents of the world. Asia and Africa have finally joined the list of its targets, making it a truly global financial threat. In Spain alone, Grandoreiro has been responsible for fraudulent activities amounting to 3.5 million euros in profits, according to conservative estimates — several failed attempts could have yielded beyond 110 million euros for the criminal organization.

    In this article, we will detail how Grandoreiro operates, its evolution over time, and the new tricks adopted by the malware, such as the usage of 3 DGAs (domain generation algorithm) in its C2 communications, the adoption of ciphertext stealing encryption (CTS), and mouse behavior tracking, aiming to bypass anti-fraud solutions. This evolution culminates with the appearance of lighter, local versions, now focused on Mexico, positioning the group as a challenge for the financial sector, law enforcement agencies and security solutions worldwide.

    Grandoreiro: One malware, many operators, fragmented versions

    Grandoreiro is a banking trojan of Brazilian origin that has been active since at least 2016. Grandoreiro is written in the Delphi programming language, and there are many versions, indicating that different operators are involved in developing the malware.

    Since 2016, we have seen the threat actors behind Grandoreiro operations regularly improving their techniques to stay unmonitored and active for a longer time. In 2020, Grandoreiro started to expand its attacks in Latin America and later in Europe with great success, focusing its efforts on evading detection using modular installers.

    Grandoreiro generally operates as Malware-as-a-Service, although it’s slightly different from other banking trojan families. You won’t find an announcement on underground forums selling the Grandoreiro package — it seems that access to the source-code or builders of the trojan is very limited, only for trusted partners.

    After the arrests of some operators, Grandoreiro split its codebase into lighter versions, with fewer targets. These fragmented versions of the trojan are a reaction to the recent law enforcement operations. This discovery is supported by the existence of two distinct codebases in simultaneous campaigns: newer samples featuring updated code, and older samples which rely on the legacy codebase, now targeting only users in Mexico — customers of around 30 banks.

    2022 and 2023 campaigns

    Grandoreiro campaigns commonly start with a phishing email written in the target country language. For example, the emails distributed in most of Latin America are in Spanish. However, we also saw the use of Google Ads (malvertising) in some Grandoreiro campaigns to drive users to download the initial stage of infection.

    Phishing emails use different lures to make the victim interact with the message and download the malware. Some messages refer to a pending phone bill, others mimic a tax notification, and son. In early 2022 campaigns, the malicious email included an attached PDF. As soon as the PDF is opened, the victim is prompted with a blurred image except for a part containing “Visualizar Documento” (“View Document” in Spanish). When the victim clicks the button, they are redirected to a malicious web page which prompts them to download a ZIP file. Since May 2022, Grandoreiro campaigns include a malicious link inside the email body that redirects the victim to a website that then downloads a malicious ZIP archive on the victim’s machine. These ZIP archives commonly contain two files: a legitimate file and a Grandoreiro loader, which is responsible for downloading, extracting and executing the final Grandoreiro payload.

    The Grandoreiro loader is delivered in the form of a Windows Installer (MSI) file that extracts a dynamic link library (DLL) file and executes a function embedded in the DLL. The function will do nothing if the system language is English, but otherwise the final payload is downloaded. Most likely, this means that the analyzed versions didn’t target English-speaking countries. There have also been other cases where a VBS file is used instead of the DLL to execute the final payload.

    Grandoreiro recent infection flow

    As for the malware itself, in August 2022 campaigns, the final payload was an incredibly big 414 MB portable executable file disguised with a PNG extension (which is later renamed to EXE dynamically by the loader). It masked itself as an ASUS driver using the ASUS icon and was signed with an “ASUSTEK DRIVER ASSISTANTE” digital certificate.

    In 2023 campaigns, Grandoreiro used samples with rather low detection rates. Initially, we identified three samples related to these campaigns, compiled in June 2023. All of them were portable executables, 390 MB big, with the original name “ATISSDDRIVER.EXE” and internal name “ATIECLXX.EXE”. The main purpose of these samples is to monitor the victims’ visits to financial institution websites and steal their credentials. The malware also allows threat actors to remotely control the victim machines and perform fraudulent transactions within them.

    In the campaign involving the discussed samples, the malware tries to impersonate an AMD External Data SSD driver and is signed with an “Advice informations” digital certificate in order to appear legitimate and evade detection.

    Implant impersonating AMD driver

    Digital certificate used by Grandoreiro malware

    In both cases, the malware is an executable that registers itself to be launched with Windows. However, it is worth noting that in the majority of Grandoreiro attacks, a DLL sideloading technique is employed, using legitimate binaries that are digitally signed to run the malware.

    The considerable size of the executables can be explained by the fact that Grandoreiro utilizes a binary padding technique to inflate the size of the malicious files as a way to evade sandboxes. To achieve this, the attackers add multiple BMP images to the resource section of the binary. In the example below, the sample included several big images. The sizes of the highlighted images are around 83.1 MB, 78.8 MB, 75.7 and 37.6 MB. However, there are more of them in the binary, and together all the images add ~376 MB to the file.

    Binary padding used by Grandoreiro

    In both 2022 and 2023 campaigns, Grandoreiro used a well-known XOR-based string encryption algorithm that is shared with other Brazilian malware families. The difference is the encryption key. For Grandoreiro, some magic values were the following:

    Date Encryption key
    March 2022 F5454DNBVXCCEFD3EFMNBVDCMNXCEVXD3CMBKJHGFM
    March 2022 XD3CMBKJCEFD3EFMF5454NBVDNBVXCCMNXCEVDHGFM
    August 2022 BVCKLMBNUIOJKDOSOKOMOI5M4OKYMKLFODIO
    June 2023 B00X02039AVBJICXNBJOIKCVXMKOMASUJIERNJIQWNLKFMDOPVXCMUIJBNOXCKMVIOKXCJ
    UIHNSDIUJNRHUQWEBGYTVasuydhosgkjopdf

    The various checks and validations aimed at avoiding detection and complicating malware analysis were also changed in the 2022 and 2023 versions. In contrast with the older Grandoreiro campaigns, we found that some of the tasks that were previously executed by the final payload are now implemented in the first stage loader. These tasks include security checks, anti-debugging techniques, and more. This represents a significant change from previous campaigns.

    One of these tasks is the use of the geolocation service http://ip-api.com/json to gather the target’s IP address location data. In a campaign reported in May 2023 by Trustwave, this task is performed by a JScript code embedded in an MSI installer before the delivery of the final payload.

    There are numerous other checks that have been transferred into the loader, although some of them are still present in the banking trojan itself. Grandoreiro gathers host information such as operating system version, hostname, display monitor information, keyboard layout, current time and date, time zone, default language and mouse type. Then the malware retrieves the computer name and compares it against the following strings that correspond to known sandboxes:

    • WIN-VUA6POUV5UP;
    • Win-StephyPC3;
    • difusor;
    • DESTOP2457;
    • JOHN-PC.

    Computer name validation

    It also collects the username and verifies if it matches with the “John” or “WORK” strings. If any of these validations match, the malware stops its execution.

    Grandoreiro includes detection of tools commonly used by security analysts, such as regmon.exe, procmon.exe, Wireshark, and so on. The process list varies across the malware versions, and it was significantly expanded in 2024, so we’ll share the full list later in this post. The malware takes a snapshot of currently executing processes in the system using the CreateToolhelp32Snapshot() Windows API and goes through the process list using Process32FirstW() and Process32NextW(). If any of the analysis tools exists in the system, the malware execution is terminated.

    Grandoreiro also checks the directory in which it is being executed. If the execution paths are D:programming or D:script, it terminates itself.

    Another anti-debugging technique implemented in the trojan involves checking for the presence of a virtual environment by reading data from the I/O Port “0x5658h” (VX) and looking for the VMWare magic number 0x564D5868. The malware also uses the IsDebuggerPresent() function to determine whether the current process is being executed in the context of a debugger.

    Last but not least, Grandoreiro searches for anti-malware solutions such as AVAST, Bitdefender, Nod32, Kaspersky, McAfee, Windows Defender, Sophos, Virus Free, Adaware, Symantec, Tencent, Avira, ActiveScan and CrowdStrike. It also looks for banking security software, such as Topaz OFD and Trusteer.

    In terms of the core functionality, some Grandoreiro samples check whether the following programs are installed:

    • CHROME.EXE;
    • MSEDGE.EXE;
    • FIREFOX.EXE;
    • IEXPLORE.EXE;
    • OUTLOOK.EXE;
    • OPERA.EXE;
    • BRAVE.EXE;
    • CHROMIUM.EXE;
    • AVASTBROWSER.EXE;
    • VeraCrypt;
    • Nortonvpn;
    • Adobe;
    • OneDrive;
    • Dropbox.

    If any of these is present on the system, the malware stores their names to further monitor user activity in them.

    Grandoreiro also checks for crypto wallets installed on the infected machine. The malware includes a clipboard replacer for crypto wallets, monitoring the user’s clipboard activity and replacing the clipboard data with the threat actor keys.

    Clipboard replacer

    2024 campaigns

    During a certain period of time in February 2024, a few days after the announcement of the arrest of some of the gang’s operators in Brazil, we observed a significant increase in emails detected by spam traps. There was a notable prevalence of Grandoreiro-themed messages masquerading as Mexican CFDI communications. Mexican CFDI, short for “Comprobante Fiscal Digital por Internet” is an electronic invoicing system administered by the Mexican Tax Authority (SAT — Servicio de Administración Tributaria). It facilitates the creation, transmission, and storage of digital tax documents, mandatory for businesses in Mexico to record transactions for tax purposes.

    In our investigation, we have acquired 48 samples associated not only with this instance but also with various other campaigns.

    Notably, this new campaign added a new sandbox detection mechanism, namely a CAPTCHA before the execution of the main payload, as a way to avoid the automatic analysis used by some companies:

    Grandoreiro anti-sandbox CAPTCHA

    It is worth noting that in the 2024 Grandoreiro campaigns, the new sandbox evasion code has been implemented in the downloader. Although the main sample still has anti-sandbox functionality too, if a sandbox is detected, it is simply not downloaded. Besides that, the new version also added detection of many tools to its arsenal, aiming to avoid analysis. Here is whole list of analysis tools detected by the newest versions:

    regmon.exe hopper.exe nessusd.exe OmniPeek.exe
    procmon.exe jd-gui.exe PacketSled.exe netmon.exe
    filemon.exe canvas.exe prtg.exe colasoft.exe
    Wireshark.exe pebrowsepro.exe cain.exe netwitness.exe
    ProcessHacker.exe gdb.exe NetworkAnalyzerPro.exe netscanpro.exe
    PCHunter64.exe scylla.exe OmniPeek.exe packetanalyzer.exe
    PCHunter32.exe volatility.exe netmon.exe packettotal.exe
    JoeTrace.exe cffexplorer.exe colasoft.exe tshark.exe
    ollydbg.exe angr.exe netwitness.exe windump.exe
    ida.exe pestudio.exe netscanpro.exe PRTG Probe.exe
    x64dbg.exe die.exe packetanalyzer.exe NetFlowAnalyzer.exe
    cheatengine.exe ethereal.exe packettotal.exe SWJobEngineWorker2x64.exe
    ollyice.exe Capsa.exe tshark.exe NetPerfMonService.exe
    fiddler.exe tcpdump.exe windump.exe SolarWinds.DataProcessor.exe
    devenv.exe NetworkMiner.exe PRTG Probe.exe ettercap.exe
    radare2.exe smartsniff.exe NetFlowAnalyzer.exe apimonitor.exe
    ghidra.exe snort.exe SWJobEngineWorker2x64.exe apimonitor-x64.exe
    frida.exe pcap.exe NetPerfMonService.exe apimonitor-x32.exe
    binaryninja.exe SolarWinds.NetPerfMon.exe SolarWinds.DataProcessor.exe x32dbg.exe
    cutter.exe nmap.exe ettercap.exe x64dbg.exe
    scylla.exe apimonitor.exe PCHunter64.exe x96dbg.exe
    volatility.exe apimonitor-x64.exe PCHunter32.exe fakenet.exe
    cffexplorer.exe apimonitor-x32.exe JoeTrace.exe hexworkshop.exe
    angr.exe x32dbg.exe ollydbg.exe Dbgview.exe
    pestudio.exe x64dbg.exe ida.exe sysexp.exe
    die.exe x96dbg.exe x64dbg.exe vmtoolsd.exe
    ethereal.exe fakenet.exe cheatengine.exe dotPeek.exe
    Capsa.exe hexworkshop.exe ollyice.exe procexp64.exe
    tcpdump.exe Dbgview.exe fiddler.exe procexp64a.exe
    NetworkMiner.exe sysexp.exe devenv.exe procexp.exe
    smartsniff.exe vmtoolsd.exe radare2.exe cheatengine.exe
    snort.exe dotPeek.exe ghidra.exe ollyice.exe
    pcap.exe procexp64.exe frida.exe pebrowsepro.exe
    cain.exe procexp64a.exe binaryninja.exe gdb.exe
    nmap.exe procexp.exe cutter.exe Wireshark.exe
    nessusd.exe regmon.exe hopper.exe ProcessHacker.exe
    PacketSled.exe procmon.exe jd-gui.exe SolarWinds.NetPerfMon.exe
    prtg.exe filemon.exe canvas.exe NetworkAnalyzerPro.exe

    These are some RAT features that we found in this version:

    • Auto-update feature allows newer versions of the malware to be deployed to the victim’s machine;
    • Sandbox/AV detection, still present in the main module, which includes more tools than previous versions;
    • Keylogger feature;
    • Ability to select country for listing victims;
    • Banking security solutions detection;
    • Checking geolocation information to ensure it runs in the target country;
    • Monitoring Outlook emails for specific keywords;
    • Ability to use Outlook to send spam emails.

    In terms of static analysis protection, in 2024 versions, Grandoreiro has implemented enhanced encryption measures. Departing from its previous reliance on commonly shared encryption algorithms found in other malware, Grandoreiro has now adopted a multi-layered encryption approach. The decryption process in the newer versions is the following. Initially, the string undergoes deobfuscation through a simple replacement algorithm. Following this, Grandoreiro employs the encryption algorithm based on XOR and conditional subtraction typically utilized by Brazilian malware; however, it differs from them by incorporating a lengthy, 140759-byte string instead of smaller magic strings we saw in 2022 and 2023 samples. Subsequently, the decrypted string undergoes base64 decoding before being subjected to decryption via the AES-256 algorithm. Notably, the AES key and IV are encrypted within Grandoreiro’s code. Upon completion of all these steps, the decrypted string is successfully recovered.

    Grandoreiro AES key and IV

    In newer samples, Grandoreiro upgraded yet again the encryption algorithm using AES with CTS, or Ciphertext Stealing, a specialized encryption mode used when the plaintext is not a multiple of the block size, which in this case is the 128-bit (16-byte) block size used by AES. Unlike more common padding schemes, such as PKCS#7, where the final block is padded with extra bytes to ensure it fits a full block, CTS operates without padding. Instead, it manipulates the final partial block of data by encrypting the last full block and XORing its output with the partial block. This allows encryption of any arbitrary-length input without adding extra padding bytes, preserving the original size of the data.

    ECB Encryption Steps for CTS

    In the case of Grandoreiro, the malware’s encryption routine does not add standard padding to incomplete blocks of data. Their main goal is to complicate analysis: it takes time to figure out that CTS was used, and then more time to implement decryption in this mode, which makes the extraction and obfuscation of strings more complicated. This marks the first time this particular method has been observed in a malware sample.

    As the threat actors continue to evolve their techniques, changing the encryption in every iteration of the malware, the use of CTS in malware may signal a shift toward more advanced encryption practices.

    Local versions: old meets new

    In a recent campaign, our analysis has revealed the existence of an older variant of the malware that utilizes legacy encryption keys, outdated algorithms, and a simplified structure, but which runs in parallel to the campaign using the new code. This variant targets fewer banks — about 30 financial institutions, mainly from Mexico. This analysis clearly indicates that another developer, likely with access to older source code, is conducting new campaigns using the legacy version of the malware.

    How they steal your money

    Operators behind Grandoreiro are equipped with a wide variety of remote commands, including an option to lock the user screen and present a custom image (overlay) to ask the victim for extra information. These are usually OTPs (one-time passwords), transaction passwords or tokens received by SMS, sent by financial institutions.

    A new tactic that we have discovered in the most recent versions found in July 2024 and later suggests that the malware is capturing user input patterns, particularly mouse movements, to bypass machine learning-based security systems. Two specific strings found in the malware — “GRAVAR_POR_5S_VELOCIDADE_MOUSE_CLIENTE_MEDIA” (“Record for 5 seconds the client’s average mouse speed”) and “Medição iniciada, aguarde 5 segundos!” (“Measurement started, please wait 5 seconds!”) — indicate that Grandoreiro is monitoring and recording the user’s mouse activity over a short period. This behavior appears to be an attempt to mimic legitimate user interactions in order to evade detection by anti-fraud systems and security solutions that rely on behavioral analytics. Modern cybersecurity tools, especially those powered by machine learning algorithms, analyze user’s behavior to distinguish between human users and bots or automated malware scripts. By capturing and possibly replaying these natural mouse movement patterns, Grandoreiro could trick these systems into identifying the activity as legitimate, thus bypassing certain security controls.

    This discovery highlights the continuous evolution of malware like Grandoreiro, where attackers are increasingly incorporating tactics designed to counter modern security solutions that rely on behavioral biometrics and machine learning.

    To perform the cash-out in the victim’s account, Grandoreiro operators’ options are to transfer money to the account of local money mules, using transfer apps, buy cryptocurrency or gift cards, or even going to an ATM. Usually, they search for money mules in Telegram channels, paying $200 to $500 USD per day:

    Grandoreiro operator looking for money mules

    Infrastructure

    The newest Grandoreiro version uses 3 Domain Generation Algorithms (DGAs), generating valid domains for command and control (C2) communications. The algorithm uses the current daytime to select strings of predefined lists and concatenates them with a magic key to create the final domain.

    By dynamically generating unique domain names based on various input data, the algorithm complicates traditional domain-based blocking strategies. This adaptability allows the malicious actors to maintain persistent command-and-control communications, even when specific domains are identified and blacklisted, requiring security solutions to base their protection not on a fixed list of domains, but on an algorithm for generating them.

    Since early 2022, Grandoreiro leverages a known Delphi component shared among different malware families named RealThinClient SDK to remotely access victim machines and perform fraudulent actions. This SDK is a flexible and modular framework for building reliable and scalable Windows HTTP/HTTPS applications with Delphi. By using RealThinClient SDK, the program can handle thousands of active connections in an efficient multithreaded manner.

    Grandoreiro C2 Communication

    Operator tool

    Grandoreiro’s Operator is the tool that allows the cybercriminal to remotely access and control the victim’s machine. It’s a Delphi-based software that lists its victims whenever they start browsing a targeted financial institution website.

    Grandoreiro’s Operator tool

    Once the cybercriminal chooses a victim to operate on, they will be presented with the following screen, seen in the image below, which allows many commands to be executed and visualizes the victim’s desktop.

    Grandoreiro’s Operator commands

    Cloud VPS

    One overlooked feature of the Grandoreiro malware is what is called “Cloud VPS” by the attackers — it allows cybercriminals to set up a gateway computer between the victim’s machine and the malware operator, thus hiding the cybercriminal’s real IP address.

    This is also used by them to make investigation harder, as the first thing noted is the gateway’s IP address. When requesting a seizure, an investigator just finds the gateway module. Meanwhile, the criminal has already set up a new gateway somewhere else and new victims connect to the new one through its DGA.

    Grandoreiro Cloud VPS

    Victims and targets

    The Grandoreiro banking trojan is primed to steal the credentials accounts for 1,700 financial institutions, located in 45 countries and territories. After decrypting the strings of the malware, we can see the targeted banks listed separated by countries/territories. This doesn’t mean that Grandoreiro will target a specific bank from the list; it means it is ready to steal credentials and act, if there is a local partner or money mule who can operationalize and complete the action. The banks targeted by Grandoreiro are located in Algeria, Angola, Antigua and Barbuda, Argentina, Australia, Bahamas, Barbados, Belgium, Belize, Brazil, Canada, Cayman Islands, Chile, Colombia, Costa Rica, Dominican Republic, Ecuador, Ethiopia, France, Ghana, Haiti, Honduras, India, Ivory Coast, Kenya, Malta, Mexico, Mozambique, New Zealand, Nigeria, Panama, Paraguay, Peru, Philippines, Poland, Portugal, South Africa, Spain, Switzerland, Tanzania, Uganda, United Kingdom, Uruguay, USA, and Venezuela. It’s important to note that the list of targeted banks and institutions tend to slightly change from one version to another.

    From January to October 2024, our solutions blocked more than 150,000 infections impacting more than 30,000 users worldwide, a clear sign the group is still very active. According to our telemetry, the countries most affected by Grandoreiro infections are Mexico, Brazil, Spain, and Argentina, among many others.

    Conclusion

    We understand how difficult it is to eradicate a malware family, but it is possible to impede their operation with the cooperation of law enforcement agencies and the private sector — modern financial cybercrime can and must be fought.

    Brazilian banking trojans are already an international threat; they’re filling the gaps left by Eastern European gangs who have migrated into ransomware. We know that in some countries, internet banking is declining on desktops, forcing Grandoreiro to target companies and government entities who are still using operating in that way.

    The threat actors behind the Grandoreiro banking malware are continuously evolving their tactics and malware to successfully carry out attacks against their targets and evade security solutions. Kaspersky continues to cooperate with INTERPOL and other agencies around the world to fight the Grandoreiro threat among internet banking users.

    This threat is detected by Kaspersky products as HEUR:Trojan-Banker.Win32.Grandoreiro, Trojan-Downloader.OLE2.Grandoreiro, Trojan.PDF.Grandoreiro and Trojan-Downloader.Win32.Grandoreiro.

    For more information, please contact: crimewareintel@kaspersky.com

    Indicators of Compromise

    Host based
    f0243296c6988a3bce24f95035ab4885
    dd2ea25752751c8fb44da2b23daf24a4
    555856076fad10b2c0c155161fb9384b
    49355fd0d152862e9c8e3ca3bbc55eb0
    43eec7f0fecf58c71a9446f56def0240
    150de04cb34fdc5fd131e342fe4df638
    b979d79be32d99824ee31a43deccdb18

    MIL OSI Global Banks

  • MIL-OSI Russia: Financial news: 10/22/2024, 16:37 (Moscow time) the values of the upper limit of the price corridor and the range of market risk assessment for security RU000A107936 (RZhD 1P-29R) were changed.

    Translation. Region: Russian Federation –

    Source: Moscow Exchange – Moscow Exchange –

    10/22/2024

    16:37

    In accordance with the Methodology for determining the risk parameters of the stock market and deposit market of Moscow Exchange PJSC by NCO NCC (JSC), on 10/22/2024, 16:37 (Moscow time), the values of the upper limit of the price corridor (up to 121.15) and the range of market risk assessment (up to 1326.75 rubles, equivalent to a rate of 21.25%) of the security RU000A107936 (RZhD 1P-29R) were changed.

    Please note: This information is raw content directly from the source of the information. It is exactly what the source states and does not reflect the position of MIL-OSI or its clients.

    Please note; This information is raw content directly from the information source. It is accurate to what the source is stating and does not reflect the position of MIL-OSI or its clients.

    https://www.moex.com/n74198

    MIL OSI Russia News

  • MIL-OSI Russia: Financial news: On holding auctions on October 23, 2024 to place OFZ issues No. 26245RMFS and No. 29025MFS

    Translation. Region: Russian Federation –

    Source: Moscow Exchange – Moscow Exchange –

    For bidders

    We inform you that, based on the letter of the Bank of Russia and in accordance with Part I. General Part and Part II. Stock Market Section of the Rules for Conducting Trading on the Stock Market, Deposit Market and Credit Market of Moscow Exchange PJSC, the order establishes the form, time, term and procedure for holding auctions for the placement and trading of the following federal loan bonds:

    1.

    Name of the Issuer Ministry of Finance of the Russian Federation
    Name of security federal loan bonds with constant coupon income
    State registration number of the issue 26245RMFS from 08.05.2024
    Date of the auction October 23, 2024
    Information about the placement (trading mode, placement form) The placement of Bonds will be carried out in the Trading Mode “Placement: Auction” by holding an Auction to determine the placement price. BoardId: PACT (Settlements: Ruble)
    Trade code SO26245RMFS9
    ISIN code PO000A108EG6
    Calculation code B01
    Additional conditions of placement The share of non-competitive bids in relation to the total volume of bids submitted by the Bidder may not exceed 90%.
    Trading time Trading hours: bid collection period: 14:30 – 15:00; bid execution period: 15:30 – 18:00.

    2.

    Name of the Issuer Ministry of Finance of the Russian Federation
    Name of security variable coupon federal loan bonds
    State registration number of the issue 29025RMFS from 09/29/2023
    Date of the auction October 23, 2024
    Information about the placement (trading mode, placement form) The placement of Bonds will be carried out in the Trading Mode “Placement: Auction” by holding an Auction to determine the placement price. BoardId: PACT (Settlements: Ruble)
    Trade code SU29025RMFS2
    ISIN code PO000A106Z61
    Calculation code B01
    Additional conditions of placement The share of non-competitive bids in relation to the total volume of bids submitted by the Bidder may not exceed 90%.
    Trading time Trading hours: bid collection period: 12:00 – 12:30; bid execution period: 13:00 – 18:00.

    Contact information for media 7 (495) 363-3232PR@moex.com

    Please note: This information is raw content directly from the source of the information. It is exactly what the source states and does not reflect the position of MIL-OSI or its clients.

    Please note; This information is raw content directly from the information source. It is accurate to what the source is stating and does not reflect the position of MIL-OSI or its clients.

    https://www.moex.com/n74197

    MIL OSI Russia News