# Kinematic Threat Brief

**LRRK Watch / Open-Source Intelligence** — Five current signals across systems that sense, move, and act.

| Field | Value |
| --- | --- |
| Collection cutoff | 31 August 2010 |
| Platform | Quiet Systems |
| Data label | Open-source intelligence // LRRK analytic product |
| Handling | Public-source material. Image rights require separate verification before publication. |

## Executive read

### BLUF

August split the unmanned problem into two trust failures: a Navy Fire Scout lost its control link and drifted toward Washington’s restricted airspace, and Symantec publicly described Stuxnet as able to inject and hide code on a PLC — Sense-to-Act on industrial machinery, not just on office PCs.

### Key judgments

1. **[Assessment — high confidence]** On 2 August 2010 an MQ-8B Fire Scout lost communications on a test flight from Webster Field and entered National Capital Region restricted airspace before operators regained the link.
2. **[Assessment — high confidence]** Microsoft issued MS10-046 on 2 August for the Windows Shell shortcut vulnerability used in Stuxnet’s USB propagation, and Symantec’s 6 August reporting described PLC injection and hiding — a public shift from “WinCC malware” to industrial Act.
3. **[Inference — moderate confidence]** The Fire Scout incident will become the domestic political exhibit for why FAA will not treat lost-link UAS as routine NAS users.

### Analytic labels

- **Fact** — verified reporting or primary record
- **Assessment** — analytic judgment
- **Inference** — reasoned but not directly observed
- **Uncertainty** — unresolved information gap

### Source grades

- **A1** — authoritative primary record / directly confirmed
- **B1–B2** — generally reliable and corroborated
- **C3** — useful but requires caution

## 01. Fire Scout lost-link over the National Capital Region

*Event / publication dates: 2 August 2010 incident; CNN report 25 August 2010*

**Verified record — [Fact — B1]** CNN reported that a U.S. Navy spokesman said an MQ-8B Fire Scout took off from Webster Field at the Patuxent River test facilities on 2 August, lost communications during a pre-programmed flight, traveled about 23 miles, and entered National Capitol Region restricted airspace, never getting closer than 40 miles to Washington. Operators lost control for about 20 minutes; NORAD and the FAA were notified; the link was reestablished and the aircraft returned. Northrop Grumman is the manufacturer. Fetched: https://www.cnn.com/2010/US/08/25/runaway.helicopter/index.html

**Threat landscape.** Lost-link is a Control Fabric failure: the Move continues after Sense/C2 drops. The physical consequence this time was airspace violation, not a crash. The political consequence is capital-region air defense and FAA caution.

**Intelligence assessment.** [Assessment — high confidence] The 2 August lost-link and NCR entry occurred as the Navy described. [Inference — moderate confidence] Automatic return-to-base logic did not behave as operators expected (CNN does not quote the software-glitch detail; that remains Uncertainty pending other primaries). [Uncertainty] CNN does not state injuries or damage; it also does not publish a software root-cause.

**Opportunity.** A Navy preliminary investigation notice in August would have settled whether the fail-safe was software, link, or procedure.

**LRRK relevance.** Control Fabric / Watch / Kestrel. Passport: Webster Field, MQ-8B, ~20-minute lost-link, NCR restricted airspace, NORAD/FAA notified.

**Confidence.** High on the Navy-described facts in CNN; low on root cause.

## 02. Microsoft patches the shortcut vulnerability (MS10-046)

*Event / publication dates: 2 August 2010*

**Verified record — [Fact — A1]** Symantec’s W32.Stuxnet Dossier timeline states that on 2 August 2010 Microsoft issued MS10-046, patching the Windows Shell shortcut vulnerability. Fetched: https://www.cs.unh.edu/~it666/reading_list/ZeroDay/w32_stuxnet_dossier.pdf

**Threat landscape.** The USB last-hop Move used by Stuxnet is now a named, patched Windows defect. Patching does not remediate already-compromised ICS hosts or stolen certificates.

**Intelligence assessment.** [Assessment — high confidence] MS10-046 is the August platform-security response to the July .lnk story. [Inference — moderate confidence] Unpatched engineering laptops and air-gapped machines that rarely receive updates remain the residual Move path. [Uncertainty] August patch-adoption rates in industrial networks are not public.

**Opportunity.** A Siemens/Microsoft joint note on WinCC-plus-MS10-046 would have been the ICS-specific remediation primary.

**LRRK relevance.** Lab / Passport. Record the patch ID and date; do not document exploit construction.

**Confidence.** High on the patch date as recorded by Symantec’s contemporaneous-month timeline.

## 03. Symantec: Stuxnet can inject and hide code on a PLC

*Event / publication dates: 6 August 2010*

**Verified record — [Fact — A1]** The same Symantec dossier timeline states: “August 6, 2010 Symantec reports how Stuxnet can inject and hide code on a PLC affecting industrial control systems.” The dossier’s executive summary, written after further work, states the ultimate goal is to sabotage a facility by reprogramming PLCs to operate as the attackers intend, most likely outside specified boundaries, and that Stuxnet hides modified code on PLCs — “essentially a rootkit for PLCs.” This brief records the 6 August public shift to PLC Act and does not describe how the injection is performed. Fetched: https://www.cs.unh.edu/~it666/reading_list/ZeroDay/w32_stuxnet_dossier.pdf

**Threat landscape.** This is the first month the public Sense-Move-Act chain reaches the controller that moves physical plant. Trust failure: the operator’s view of the PLC can be a lie.

**Intelligence assessment.** [Assessment — high confidence] By 6 August, a major vendor has said Stuxnet’s interesting Act is on the PLC, not only the Windows host. [Inference — moderate confidence] A specific industrial process is being fingerprinted; Symantec still says “likely in Iran, such as a gas pipeline or power plant” in the later dossier framing — target identity is not a July/August certainty. [Uncertainty] Public August sources fetched here do not prove Natanz.

**Opportunity.** An asset-owner or IAEA note of unexplained centrifuge or turbine behavior would have been the physical-effect primary; none is fetched for August.

**LRRK relevance.** Sense-Move-Act / Lab / Kestrel. Watch now files Stuxnet as cyber-to-physical Act on controllers, still un-located.

**Confidence.** High on the 6 August PLC-injection public claim; moderate on target geography.

## 04. IAEA still counting centrifuges — the physical ledger Stuxnet has not yet been publicly tied to

*Event / publication dates: GOV/2010/46 later gives a 28 August 2010 FEP snapshot*

**Verified record — [Fact — A1]** GOV/2010/46 states that on 28 August 2010 Iran was feeding natural UF6 into 17 cascades of Unit A24 and 6 cascades of Unit A26 at the Fuel Enrichment Plant, with additional cascades installed but not fed, all IR-1 machines, 164 per cascade. A footnote states that of 8,856 centrifuges installed at FEP, 3,772 were being fed with UF6. Fetched: https://www.iaea.org/sites/default/files/documents/gov2010-46.pdf

**Threat landscape.** The public physical picture on 28 August is a large installed base and a smaller fed set. That pattern has many possible explanations (maintenance, shortage, unreliability). Malware is not an IAEA finding in this report.

**Intelligence assessment.** [Assessment — high confidence] The 28 August counts are IAEA Facts. [Inference — low confidence in August] One must not infer Stuxnet as the cause of the installed-versus-fed gap from this report alone. [Uncertainty] Why 5,084 installed machines were not being fed is not explained as sabotage.

**Opportunity.** An IAEA sentence on unusual replacement rates would have been the physical-anomaly indicator; GOV/2010/46 does not provide one labeled as malware.

**LRRK relevance.** Watch. Keep the 28 August table as the pre-September physical baseline.

**Confidence.** High on the numbers as IAEA-reported; high that cause is unstated.

## 05. Domestic UAS integration debate now has a lost-link exhibit

*Event / publication dates: 2 August Fire Scout; continuing FAA COA regime*

**Verified record — [Fact — B1]** The Fire Scout lost-link occurred in the same national airspace system the FAA manages by COA and restricted airspace, not by an open civil sUAS rule. Fetched: https://www.cnn.com/2010/US/08/25/runaway.helicopter/index.html ; https://irp.fas.org/congress/2010_hr/uas.html

**Threat landscape.** Trust in lost-link behavior is now a capital-region air-defense issue, not only a test-range issue.

**Intelligence assessment.** [Assessment — moderate confidence] August’s Fire Scout story will be cited in September airspace hearings. [Inference — moderate confidence] Grounding or software holds on Fire Scout are likely (not confirmed in the CNN piece). [Uncertainty] Fleet-wide grounding is not stated by CNN.

**Opportunity.** An FAA or NORAD August press note on the NCR incursion would have been the civil-military primary.

**LRRK relevance.** Control Fabric. Tie lost-link to NAS access politics.

**Confidence.** High on the incident; moderate on policy effect.

## Forward indicators

Ranked watchlist as of the collection cutoff (what a 2001–2011 Watch desk would have monitored next).

1. Symantec or Siemens paper that names a process (frequency, pressure, centrifuge) rather than “a PLC.”
2. IAEA September report — compare with the 28 August snapshot.
3. Fire Scout grounding, software fix, and next flight.
4. Additional stolen code-signing certificates.
5. Next WikiLeaks military-document release.

> **Collection integrity.** Fire Scout from CNN’s 25 August report of the Navy spokesman. Stuxnet August dates from Symantec’s dossier timeline (MS10-046, 6 August PLC report). IAEA 28 August counts from GOV/2010/46 (published September; the observation date is 28 August). No exploit recipe. No claim that IAEA attributed centrifuge status to Stuxnet. NYT Fire Scout story was not separately fetched.

*LRRK — security assurance for systems that sense, move, and act.*

<p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C1</span></p>
