LC-2 · Software Danger Reports
LrrK Kinematic Software Danger Report
Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
# LrrK Kinematic Software Danger Report **LRRK Watch / Software Assurance** — Monthly filing. | Field | Value | | --- | --- | | Collection cutoff | 19 August 2026 | | Platform | Quiet Systems | | Series | DKSR-M-2026-08 | | Status | short | | Data label | Open-source intelligence // LRRK analytic product | | Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. | ## Executive read ### BLUF A camera module on a Royal Navy K3 Scout USV sent heartbeat traffic toward a China IP. MoD confirmed an issue from a routine cyber assessment and said it found no evidence of MoD data leaving. The camera OEM is unpublished. ### Key judgments 1. **[Assessment — High confidence]** First widely reported naval-USV payload out-of-band case in this portfolio. 2. **[Assessment — High confidence]** NDAA-compliant label was not a firmware-behavior audit. 3. **[Uncertainty]** Camera OEM, exact IP, and whether location left the boat remain unpublished. ### Analytic labels - **Fact** — verified reporting or primary record - **Assessment** — analytic judgment - **Inference** — reasoned but not directly observed - **Uncertainty** — unresolved information gap ### Source grades - **A1** — authoritative primary record / directly confirmed - **B1–B2** — generally reliable and corroborated - **C3** — useful but requires caution ## 01. Kraken K3 Scout cameras: heartbeat to a China IP *Event / publication dates: Telegraph 9 August 2026 (as cited); BBC/MoD follow-up 10 August 2026. Collection cutoff 19 August 2026.* | Field | Value | | --- | --- | | Component | firmware | | Product | Kraken Technology Group K3 Scout USV; unnamed third-party EO/IR cameras | | CVE / advisory | no CVE | | Patch | partial / unpublished. Internet removed from cameras (secondary). MoD did not confirm or deny the cut. | | Exploit status | reported as an observed outbound channel, not a named software exploit | | Taxonomy | ATT&CK ICS T0862 · OWASP IoT I3 · I5 | **Verified record — [Fact — A1/B2] BBC 10 August 2026; TWZ; Defence Blog; Army Recognition citing Telegraph 9 August. MoD: issue found in a routine cyber vulnerability assessment; no evidence MoD data or systems accessed, compromised, or transmitted externally.** **Exposure.** Payload egress on a naval USV. Sense (camera) with an undeclared Control Fabric channel. **Intelligence assessment.** [Assessment — High confidence] Event and MoD quotes established. [Uncertainty] OEM, IP, location-exfil, connectivity cut. [Inference — Moderate confidence] “NDAA compliant” will keep being treated as a Passport it is not. **Opportunity.** Lab egress-deny on payload modules. Passport camera firmware behavior, not the sticker. Watch for a CVE or vendor name. **LRRK relevance.** Sense and Control Fabric. Kestrel identical camera modules. Live Watch item. **Confidence.** High on the event and MoD quotes. Low on OEM and location-exfil. ## Forward indicators 1. Camera OEM, firmware, and IP, or a CVE. 2. A second government USV/UUV payload-egress case with a named module. 3. Daily DKSR watch (weekdays 9:18 PT) picks up from this cutoff. > **Collection integrity.** Press plus MoD quotes. Camera OEM not used. No exploit steps. Month is partial (cutoff 19 August). *LRRK — security assurance for systems that sense, move, and act.* <p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>