Securing the Orbital Frontier: Northrop Grumman and Aeronix Target Data Throughput
A new strategic partnership aims to overhaul space-based encryption hardware to support the high-speed data demands of modern military satellite networks.
Israeli researchers unveil “SmartAttack,” a novel method leveraging smartwatches to siphon sensitive data from air-gapped computers via inaudible ultrasonic signals. This ingenious breach highlights a critical vulnerability in isolated systems, prompting calls for new security measures like device bans.

In the shadowy world of cyber espionage, where the stakes are measured in national security and critical infrastructure, the concept of an “air gap” has long stood as a sacrosanct barrier.
Imagine a digital fortress, physically isolated from the internet and external networks, designed to safeguard the most sensitive data – the blueprints for weapons platforms, the operational codes of nuclear power plants, the classified intelligence within government facilities.
This physical separation was once considered the ultimate defense against malware and data theft.
Yet, an unsettling reality continues to emerge: even this seemingly impenetrable wall is proving to be permeable, not by brute force, but by the ingenious, often insidious, manipulation of the mundane.
Enter ‘SmartAttack,’ the latest brainchild from Israeli university researchers led by Mordechai Guri, a name synonymous with pushing the boundaries of covert data exfiltration.
This new methodology leverages something as ubiquitous and seemingly innocuous as a smartwatch to siphon sensitive information from air-gapped systems.
It’s a plot twist straight out of a spy novel, transforming a fitness tracker or a convenient communication device into a clandestine tool for espionage.
The premise is disturbingly simple yet profoundly clever.
The first hurdle, as with any attack on an air-gapped system, is the initial infiltration.
This often relies on an insider threat – a disgruntled employee, a compromised individual, or a sophisticated supply chain attack that plants malware onto the isolated machine.
Once entrenched, the malicious software goes to work, not by sending data over conventional network channels, which are non-existent in an air-gapped environment, but by manipulating the physical characteristics of the hardware itself.
SmartAttack capitalizes on the often-overlooked built-in speaker of the air-gapped computer.
The malware instructs the speaker to emit ultrasonic signals, frequencies well beyond the range of human hearing.
These aren’t random noises; they are carefully modulated whispers of data.
Using a technique called Binary Frequency Shift Keying (B-FSK), the audio signals are tweaked – 18.5 kHz representing a binary “0” and 19.5 kHz denoting a “1.”
This inaudible data stream then floats through the air, a silent beacon of stolen secrets.
The receiver in this sophisticated relay is the microphone embedded within a nearby smartwatch.
Whether it’s a device purposefully equipped by a rogue operative or one unknowingly compromised by external forces, the smartwatch becomes the crucial link.
Its sound monitoring application, armed with signal processing capabilities, detects these subtle frequency shifts, demodulating the encoded signal back into intelligible binary data.
From there, the smartwatch, with its inherent Wi-Fi, Bluetooth, or cellular connectivity, can easily transmit the pilfered information to an external receiver, completing the exfiltration chain.
Guri’s previous work has consistently explored the outer limits of data leakage from isolated systems, demonstrating how information can be siphoned via the noise from LCD screens, RAM modulation, network card LEDs, USB drive RF signals, SATA cables, and even power supplies.
His research underscores a fundamental truth in cybersecurity: if a system consumes power or emits any form of physical signal, there’s a potential pathway for data exfiltration.
While many of these attack vectors are theoretical and incredibly difficult to execute in a real-world scenario, their significance lies in exposing vulnerabilities that, once identified, can be exploited by determined adversaries.
They force security professionals to consider the seemingly impossible.
However, SmartAttack, like its predecessors, is not without its practical limitations.
Smartwatch microphones, by design, are small and possess lower signal-to-noise ratios compared to their smartphone counterparts.
This makes the demodulation of weak ultrasonic signals a challenging endeavor, particularly at higher frequencies or lower signal intensities.
The precise orientation of the smartwatch on the wrist also plays a critical role, with optimal performance achieved when the watch has a clear “line-of-sight” to the computer’s speaker.
The transmission range is modest, typically between 6 and 9 meters (20-30 feet), and the data transfer rate is glacially slow, ranging from a paltry 5 bits per second (bps) to a maximum of 50 bps.
As the rate and distance increase, reliability plummets, making large-scale data theft a painstakingly slow process.
Despite these constraints, the implications are profound.
The very existence of such an attack vector demands a re-evaluation of security protocols in critical environments.
The most straightforward countermeasure, as suggested by the researchers, is a blanket prohibition on smartwatches in secure facilities.
This simple policy shift could effectively neutralize SmartAttack and similar acoustic covert channels.
Another robust defense involves the physical removal of built-in speakers from air-gapped machines, eliminating the very source of the ultrasonic signals.
Where these measures are not feasible, more complex solutions like ultrasonic jamming (emitting broadband noise to overwhelm the signal), software-based firewalls designed to detect anomalous speaker activity, and “audio-gapping” (physical barriers to sound transmission) could offer layers of protection.
SmartAttack serves as a stark reminder that the battle for digital security is a perpetual cat-and-mouse game.
As defenders erect higher walls, attackers find new ways to tunnel beneath them, often exploiting the very devices designed for convenience.
The air gap, once seen as an impregnable fortress, is increasingly revealed to be a perimeter with countless tiny, often invisible, pores.
It is a testament to human ingenuity – both in devising such attacks and in developing defenses – but also a sobering reflection on the persistent vulnerability of even our most critical digital assets.
The future of security will undoubtedly rely not just on firewalls and encryption, but on a vigilant awareness of every possible physical signal, no matter how faint or seemingly insignificant.
A new strategic partnership aims to overhaul space-based encryption hardware to support the high-speed data demands of modern military satellite networks.
Commercial data networks have become a critical vulnerability for military personnel as foreign adversaries exploit real-time bidding for intelligence.
Mohit Bansal’s approach to security engineering at Webflow rests on a deceptively simple reframe: treating fixed headcount not as a limitation to work around but as a firm design constraint that shapes every architectural decision, from how vulnerabilities get prioritized to how vendor risk gets automated away. His core discipline is pragmatic sequencing over theoretical perfection—getting 80 percent coverage on five critical risks rather than chasing 100 percent on two—paired with a relentless drive to automate repetitive data-gathering so a fixed team can spend its limited human judgment on the problems that actually require it.