• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • SPECTRA banner
  • Curtiss-Wright banner

BATTLESPACE Updates

   +44 (0)77689 54766
   

  • Home
  • Features
  • News Updates
  • Defence Engage
  • Company Directory
  • About
  • Contact

C2, Tactical Comms, AI, Cyber, EW, Cloud Computing & Homeland Security

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

March 26, 2026 by

Sponsored By Curtiss Wright

 

https://www.curtisswright.com/

 

——————————————————————————————————————–

25 Mar 26. Pacific Defense today announced the launch of the DSP3100VP, a next-generation digital signal processing module engineered to bring advanced artificial intelligence and machine learning (AI/ML) capabilities to the edge. Built on the AMD Versal™ AI Edge Series Gen 2 adaptive SoC, the DSP3100VP combines heterogeneous compute, adaptive acceleration, and deterministic real-time control to meet the growing demand for intelligent, data-driven systems in both defense and commercial markets.

“The DSP3100VP brings together AI acceleration, high-speed data movement, and open standards compliance to directly address the needs of modern mission systems,” said Pedja Mitrovic, VP of Modular Products at Pacific Defense.

Engineered for modern mission environments, the DSP3100VP combines traditional CPU and FPGA fabric processing with next-generation AI acceleration to deliver powerful, low-latency performance. With 144 AI Engine-ML v2 tiles and more than 2,000 DSP engines, the platform provides the parallel compute required for AI-driven applications such as electronic warfare, signal intelligence, autonomous systems, and real-time detection and tracking.

“The DSP3100VP brings together AI acceleration, high-speed data movement, and open standards compliance to directly address the needs of modern mission systems,” said Pedja Mitrovic, VP of Modular Products at Pacific Defense. “It enables our customers to deploy intelligent capabilities at the edge with the performance, efficiency, and flexibility required for real-time decision-making.”

Aligned with U.S. Army CMOSS and SOSA™ standards, the DSP3100VP ensures interoperability and rapid integration into open architecture systems while supporting deployment in size, weight, and power constrained environments.

Key Features of the DSP3100VP include:

  • AMD Versal™ AI Edge Series Gen 2 adaptive SoC with integrated AI engines
  • 144 AI Engine-ML v2 tiles and over 2,000 DSP engines for scalable AI inference
  • 80 GB LPDDR5 memory for high-throughput data processing
  • 100G Ethernet and PCIe Gen5 for ultra-high-speed data movement
  • SWaP-optimized design with approximately 50W typical power consumption
  • Open standards alignment with CMOSS, SOSA™, and OpenVPX™

The DSP3100VP is delivered as a complete, AI-ready platform that reduces integration complexity and facilitates faster deployment for next-generation intelligent systems.

For more information, visit the product page here.

About Pacific Defense

Pacific Defense is purpose-built to drive the open-systems transformation required to unlock rapid innovation and the power of commercial technology. Specializing in Command, Control, Communications, Computers, Cyber, Intelligence, Surveillance, and Reconnaissance (C5ISR) and Electronic Warfare (EW) solutions for mission-critical environments, Pacific Defense applies Modular Open Systems Approach (MOSA), aligning with the Sensor Open Systems Architecture (SOSA) technical standard, and integrating capabilities through the C5ISR/EW Modular Open Suite of Standards (CMOSS) to deliver flexible, upgradeable technology that enables warfighters to stay ahead of emerging threats. Learn more at www.pacific-defense.com and on LinkedIn. (Source: BUSINESS WIRE)

 

10 Mar 26. Cyber Update

Key points

  • An increase in the exploitation of zero-day vulnerabilities in 2025 showcases security risks to businesses (see Sibylline Cyber Daily Analytical Update – 9 March 2026).
  • The continued adoption of artificial intelligence (AI) in cyber operations will sustain security risks from North Korean state-sponsored groups (see Sibylline Cyber Daily Analytical Update – 10 March 2026 and our technical analysis below).
  • Global military and government entities will face heightened cyber espionage risks from Russian state-sponsored threat actors (see Sibylline Cyber Daily Analytical Update – 11 March 2026).
  • Qatar’s military and energy sectors face heightened security risks from a Chinese state-sponsored group (‘Camaro Dragon’; see Sibylline Cyber Daily Analytical Update – 12 March 2026 and our technical analysis below).
  • A destructive cyber attack on a medical device manufacturing company underscores the ongoing security and operational risks from Iran-aligned hacktivists amid the Israel-US-Iran war (see Sibylline Cyber Daily Analytical Update – 13 March 2026).

Technical analysis of weekly stories

Three North Korean state-sponsored groups (‘Coral Sleet’, ‘Sapphire Sleet’ and ‘Jasper Sleet’) are using AI tools to expand the country’s long-term remote employment cyber campaign. These threat actors use AI to streamline the process of creating digital personas for specific job roles. For example, Jasper Sleet uses generative AI to research job postings on job-search platforms to identify in-demand skills and experience requirements, in order to align fake personas with targeted roles, highlighting the highly targeted nature of this long-term operation. During the reconnaissance stage, threat actors use large language models (LLMs) to search for publicly reported vulnerabilities and to identify potential exploitation vectors, while using AI to identify tools that aid defence evasion (such as remote-access tools and obfuscation frameworks). This enables threat actors to bypass endpoint detection and response (EDR) systems and identify potential cloud services suitable for command-and-control (C2) infrastructure. Additionally, Coral Sleet uses AI to refine, write and re-implement malware components, as well as to create new payloads by jailbreaking legitimate LLM software, bypassing its built-in safeguarding controls. These operations highlight North Korea’s widespread employment of AI at several stages of the cyber kill chain, pointing to threat actors’ increasingly mature skillset.

Meanwhile, China-linked threat group Camaro Dragon has been observed deploying a variant of the ‘PlugX’ backdoor against Qatari organisations amid the ongoing Israel-US-Iran war. PlugX is a modular backdoor commonly used by various China-aligned threat actors that enables remote access, file exfiltration, screen capture, keystroke logging and remote command execution. Camaro Dragon’s campaign initiates via phishing emails, using missile strikes in Bahrain as a lure to get potential targets to open an .LNK file. This triggers a long infection chain that begins by dynamic-link library (DLL) hijacking a legitimate Baidu NetDesk binary, which subsequently deploys PlugX. In a separate campaign against Qatari entities, Camaro Dragon used phishing lures related to an airstrike on oil and gas facilities to trick victims into opening the .ZIP file. This cyber operation hijacks legitimate DLL processes to deploy ‘Cobalt Strike’ to conduct reconnaissance on compromised networks and potentially conduct further malicious activity.

Non-exhaustive recommendations to mitigate these threats include:

  • Monitor devices and networks for suspicious activity.
  • Add available Indicators of Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware.
  • Adopt behaviour-based EDR solutions, prioritising the detection of the initial stages of a compromise.
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.

(Source: Sibylline)

 

25 Mar 26. Saab and Cohere sign memorandum of understanding on advanced AI collaboration.

Saab today announced the signing of a Memorandum of Understanding (MOU) with Canadian AI company, Cohere on advanced AI collaboration.

The MOU establishes a framework for collaboration on artificial intelligence technologies in support of GlobalEye. The agreement is directly connected to the GlobalEye opportunity in Canada but would also serve the existing and future international GlobalEye operators. Technologies and competencies developed through the partnership are also intended to contribute to Saab’s global product offerings and strengthen international competitiveness.

The collaboration will explore areas such as data-driven mission support, maintenance tools and information processing in an on-premises integration into complex secure aerospace environments. Initial pilot projects have been identified to assess potential pathways for cooperation, aligned with the current needs of the program.

“Canada offers outstanding industrial and advanced technology partners,” said Micael Johansson, President and CEO of Saab. “Working with Canadian companies like Cohere on emerging technologies strengthens our global supply chain and enhances Saab’s international competitiveness.”

“Frontier artificial intelligence should be built for scale, trust, reliability and most importantly, real-word impact.” said Ivan Zhang, Co-Founder of Cohere. “Through Saab’s deep engineering heritage and our advanced enterprise-grade models, we’ll explore pushing the boundaries of what AI can truly deliver for aerospace, enabling teams to process complex data faster, increase operational tempo, surface key insights with clarity and support critical decision making when it matters most.”

Through this MOU, Saab and Cohere signal their shared ambition to combine aerospace expertise and leading-edge AI research in support of high-value industrial cooperation in Canada.

About Cohere

Cohere is a leading security-first enterprise AI company. Cohere builds foundation models and end-to-end AI products designed to solve real-world business problems. Cohere partners closely with companies to deliver seamless integration, full customization, and easy-to-use solutions for their workforce and customers. Cohere’s all-in-one platform offers enterprises the highest levels of security, data privacy and optionality to deploy across all major cloud providers, private cloud environments, or on-premises. Cohere is a global company co-headquartered in Toronto and San Francisco, with key offices in New York, London, Montreal, Paris, and Seoul. Learn more at cohere.com.

 

12 Mar 26. NGC2 Fielding Gains Momentum. The US Army’s Project Convergence events play a key role in evaluating the technologies that comprise the force’s NCG2 command and control system, itself a key part of the US Department of Defence’s wider CJADC2 architecture. (US Army)

US Army Project Convergence events planned for 2026 are set to have a major impact regarding the ongoing development of the Next Generation Command and Control system.

In April 2025, the United States Army’s Next Generation Command and Control (NGC2) system became a formal programme of record. In the Army’s own words, NGC2 will fundamentally change how its manoeuvre force performs Command and Control (C2). The initiative is led by the army’s Capability Programme Executive for Command, Control, Communications and Networks (CPE C3N). This organisation was formally known as the Programme Executive Office for Command, Control, Communications and Networks (PEO C3N).

The NGC2 forms part of the wider US Department of Defence’s (DOD’s) Combined Joint All-Domain Command and Control (CJADC2) system. CJADC2 is the manifestation of the DOD’s embrace of the Multi-Domain Operations (MDO) mindset. MDO promotes the inter- and intra-force connectivity of all military assets (personnel, platforms, weapons, sensors, networks, bases and capabilities) at all levels of war to perform synchronous operations across the spectrum of conflict.

MDO will facilitate friendly forces taking better-quality, and faster, decisions than their adversaries. The theory is that decision-making superiority will help overcome the Anti-Access/Area-Denial (A2AD) postures of US and allied near-peer strategic rivals like the Islamic Republic of Iran, People’s Republic of China and Russia. Other constituent combined operational and tactical C2 systems employed by the US military include the Advanced Battle Management System of the US Air Force, the US Navy’s Project Overmatch, the Marine Corps’ Expeditionary Base Operations initiative and US Space Force’s National Defence Space Architecture.

Layer cake

NGC2 overhauls the C2 architectures used by the army’s manoeuvre forces at tactical (battalion and brigade) through to division and corps (operational) levels. NGC2 is working to breakdown existing C2 stovepipes in the land manoeuvre force. Much of this effort rests on improving communications between the force’s constituent parts.

The architecture comprises four elements: The infrastructure layer possesses the computing hardware that NGC2 will need to function. The transport layer includes radio communications hardware and software to move voice and data traffic around the NGC2 network, and between its constituent elements. The data layer is effectively the system’s brain linking the NCG2 with the assets mentioned above. This layer also contains artificial intelligence and machine learning approaches to aid tactical and operational decision-making. Finally, the application layer represents the point where the user interacts with the NGC2 network and its data.

Work commenced on NGC2 in 2024 and the associate programme office within the CPE C3N was formally established in April 2025. The CPE C3N told Armada via a written statement that “no one company can provide a complete solution” for the NGC2 architecture. Instead, the army is identifying and contracting vendors on a case-by-case basis according to NGC2 requirements. Developing the NGC2 architecture is currently at the prototyping stage. Prototyping activities “will inform how the Army implements NGC2 technologies and business models moving forward”.

Ivy Sting and Lightning Surge

The Army’s Project Convergence initiatives are central to NGC2 prototyping and additional Project Convergence events are planned for 2026. These will evaluate the C2 system’s transport layer and the ability of allied C2 systems to share data with NCG2 and vice versa. Performed at the division level, Project Convergence’s Ivy Sting will involve the Army’s Fourth Infantry Division (ID), and Lightning Surge the 25th ID.

There is no ‘end date’ when NGC2’s rollout and implementation will be complete. Instead, hardware and software will be continually updated to ensure the force “is poised to combat emerging threats”. This year’s Project Convergence events will have a major impact on the future course of the NGC2 undertaking writ large: “Experimentation … will inform procurement decisions and NGC2 fielding to the broader Army”, the written statement noted. Expect more news from the CPE C3N in the coming months regarding lessons learned from this year’s Project Convergence initiatives impacting NGC2’s development and implementation.

(Source: Armada)

 

12 Mar 26. Doing the Right Thing . Reports emerged in early February that access to Space-X’s Starlink Satellite Communications (SATCOM) constellation Russian troops were enjoying in the Ukraine theatre of operations is ending. It appears that Russian units there began using the constellation in February 2024. Access was facilitated through Starlink SATCOM terminals the Russian government acquired through the black market, or via third parties.

Starlink quickly became an important electromagnetic force enabler for the Russian military. The terminals provided important inter- and intra-theatre Over-The-Horizon (OTH) backhaul communications. Russian forces occupying Ukraine have experienced problems in securing capacious, interoperable and robust OTH communications to connect disparate commands at the tactical level, and to connect tactical-level units with operational echelons. At a stroke, Starlink provided secure, wideband and relatively robust OTH trunk communications. It is noteworthy that Starlink terminals can be fiendishly difficult to jam. Second, by installing Starlink terminals in some Uninhabited Aerial Vehicles (UAVs) Russian forces could use these channels to carry navigation commands and telemetry to and from the aircraft. This helped improve the accuracy and lethality of operational and strategic level UAV reconnaissance and suicide attacks. Such attacks have proven effective against Ukrainian power generation and transmission facilities during the cold winter months.

Prevention of Russia’s Starlink access has been achieved through a registration scheme. Only those terminals which have been registered with the Ukrainian government operating within Ukrainian territory can now access the constellation. Meanwhile, a software-based ‘kill switch’ prevents any terminal moving above 48 knots (90 kilometres-per-hour) from accessing the constellation. Terminals used by ground units can continue to access the network as they unlikely to move at such speeds: Employing Starlink terminals in suicide UAVs like the Iranian-supplied, and licence-built, Shahed series thus becomes pointless. These aircraft typically cruise at around 162 knots (300km/h).

Anecdotal evidence from Ukraine suggests that Russian forces are already suffering because of the Starlink denial. Ukrainian prisoners of war are being bullied into getting relatives in Ukraine to register Starlink terminals on Russia’s behalf. Aerostats hosting trunk radio relays at altitude are another partial solution being considered. Neither are likely to provide a complete and equivalent solution to Starlink.

Why did SpaceX take the decision to greatly restrict Russian access? It appears that the company was increasingly unhappy about its technology being used to facilitate the UAV-based bombardments Moscow has been inflicting on Ukraine. Russia is also under sanction from the United States government which prohibits the company from providing Starlink services in Russia and Russian-held territory. Removing this access ensures SpaceX’s compliance therein.

As Russia’s war in Ukraine enters its twelfth year, hitting Moscow electromagnetically where it hurts is an important element of maintaining the pressure on Mr. Putin to throw in the towel and to quit Ukraine. Cutting off another corner of the radio spectrum to Russia’s military also chips away at a resource that Ukraine’s occupiers depend on. SpaceX has made the right decision. (Source: Armada)

12 Mar 26. Constellations and Continuity. The European Union has taken an important step forward to expand secure satellite communications bandwidth to its membership for military and government communications.

As of late February, the European Union’s Government Satellite Communications (EUGOVSATCOM) provision is operational, according to a statement published by the European Commission. The Commission is the EU’s executive arm proposing legislation and applying the Union’s laws and policies. According to a primer produced by the commission, EUGOVSATCOM pools bandwidth on sovereign secure, government communications satellites owned by EU states and shares this across the membership. Bandwidth provided by some EU based commercial operators, such as Eutelsat, also form part of the pooled resource.

The EUGOVSATCOM initiative means that member states without sovereign SATCOM can access secure satellite communications without having to acquire their own satellites and constellations. The initiative also provides an alternative to EU members having to lease secure bandwidth from commercial third parties. A reliance on the latter can be risky should commercial operators choose to reduce, or eliminate, bandwidth in times of crisis or war. Alongside EU members, Norway and Iceland can use EUGOVSATCOM provision. As the commission’s primer continues, Ukraine could join the initiative in the future.

Ground element

Users access the constellations via the initiative’s ground-based infrastructure component known as GOVSATCOM hub which is supervised by the EU’s Space Programme Agency (EUSPA). The GOVSATCOM hub performs a key function as it will match SATCOM demand with the best-placed satellite or constellation to provide the requested service. Alongside furnishing government and military satellite communications, EUGOVSATCOM will assist EU agencies like FRONTEX, the EU’s border and coastguard agency, along with law enforcement, civil protection organisations and diplomatic missions.

As the EUSPA told Armada via a written statement EUGOVSATCOM “is not a constellation but rather a communications system-of-systems”. Communications satellites are provided by five nations, namely France, Greece, Italy, Luxembourg and Spain to furnish SATCOM services. Details of these satellites, and the SATCOM frequencies they provide, are detailed in the table below:

The GOVSATCOM hub provides two ground stations to uplink and downlink traffic. Users do not need to acquire any dedicated SATCOM terminals to access EUGOVSATCOM services. Instead, existing terminals can be employed without modification. Countries providing bandwidth to EUGOVSATCOM can access new satellites and/or constellations as legacy systems are replaced. Moreover, it is possible that other EU nations beyond the five listed above will be able to join as and when they acquire satellites and constellations. Looking toward the future, the EUSPA expects to incorporate the European Union’s forthcoming Infrastructure for Resilience, Interconnectivity and Security by Satellite (IRIS2) capability. This will be integrated into EUGOVSATCOM when available. More details concerning IRIS2 can be found here.

Strategic capability

EUGOVSATCOM represents the advent of an important strategic capability for the European Union according to the EUSPA’s written statement: “The strength of EUGOVSATCOM is precisely that it is a dual-use capability: It supports defence needs, but also the day-to-day work of civilian authorities who require secure, resilient communication to protect citizens and operate in difficult environments … especially when terrestrial networks are damaged or unavailable”. Furthermore, “(h)aving a European capability means (the safeguarding of) sensitive information, … continuity of government operations (and ensures) that essential services function even when terrestrial networks are disrupted” the statement continued. (Source: Armada)

 

12 Mar 26. Opening The Vault.

A new command and control system is entering service with Russian land forces which is thought to use artificial intelligence to aid tactical decision-making.

In late January, the United24 Ukrainian media organisation and Forbes magazine revealed details of a new Russian Command and Control (C2) system called Svod (Vault). Unlike other existing Russian tactical and operational C2 systems, Svod reportedly includes Artificial Intelligence (AI) algorithms to aid commander decision-making. Much like Ukraine’s Delta C2 system, Svod federates and merges intelligence arriving from disparate sources to enrich a commander’s tactical picture. AI is used to not only help analyse incoming intelligence, but to present the user with possible outcomes based on the intelligence and potential courses of action.

The intention behind Svod, as the reports articulated, is to accelerate commander tactical decision-making. Elements of Russian military doctrine, particularly in the land domain, are thought to be excessively top heavy. Local commanders, and their subordinates, have been discouraged from showing excessive initiative. It is possible that Svod aims to devolve decision-making downwards to accelerate battle rhythm via the use of AI to help users anticipate potential consequences. The war in Ukraine is now largely characterised by small units of dismounted troops performing limited actions. This has made the devolution of decision-making to the lowest tactical level increasingly important.

Existing C2 systems

Reports stated that Svod completed operational testing in December 2025 with its rollout expected to begin in April 2026. According to official Russian official documents seen by Armada, Svod’s implementation across all land forces formations deployed in, or deploying to, Ukraine will be completed by the end of 2026. Tactical formations in the 2nd and 41st Combined Arms Armies (CAAs) are the first recipients. Both these CAAs are deployed in Ukraine’s Donetsk oblast in the southeast of the country, Armada understands.

The Russian military already deploys the YESU-TZ Unified C2 System for Troops and Weapons. YESU-TZ is deployed from the strategic level downwards to operational and high tactical echelons. The system receives and processes data sent by subordinate echelons, and disseminates information, orders and situation reports. It appears YESU-TZ also equips the National Defence Command Centre in Moscow. At the tactical level, the Akatsiya-M C2 architecture is employed for logistics, general force organisation and battle management. Russian airborne troops, which constitute a separate service, have the Andromeda-D system with dismounted infantry using the Strelets command and control architecture. Other C2 systems include Akatsiya-E for tactical and operational ground-based air defence, and Asuno-S which furnishes artillery units. Bylina is the command and control system used by Russian land forces Electronic Warfare (EW) troops.

Svod functionality

As a software-driven system, Svod can be hosted on standard, militarised personal computers and laptops. This marks a break from YESU-TZ which was thought to need dedicated computing hardware, particularly when deployed onboard armoured vehicles. To understand how Svod could work, consider this scenario: A local, tactical commander has identified through a combination of intelligence derived from dismounted EW units, Uninhabited Aerial Vehicle (UAV) sorties and visual reconnaissance, a local building that is being used by the enemy. All this relevant intelligence is accessible from a map which depicts the building. The commander can see the location, and the dispositions and capabilities of local, subordinate units. These units could include artillery, mounted and/or dismounted infantry, EW, armour and UAV detachments. AI-based decision-making tools provide the commander with information regarding each units’ capabilities noting which might be best placed to support their intent. Svod also provides a combat cloud. Intelligence collected across the tactical and operational area can be uploaded to, and downloaded from, this cloud. Nonetheless, access to the cloud is not required for the user to employ Svod to support local, tactical decision-making.

Svod integrates a myriad of disparate intelligence feeds and displays the location and capabilities of local friendly units to help commanders anticipate the consequences of potential tactical actions. (Thomas Withington)

This new C2 system looks likely to replace elements of YESU-TZ. The former may still provide C2 functionality from the strategic to the operational level. Nonetheless, Svod will likely be the C2 system used at the high tactical level, typically in motorised rifle/tank division/brigade command down to the dismounted tactical level where systems like Strelets will be employed as before. Speciality branches like those listed above will probably continue using their own C2 systems. These latter architectures will feed into Svod and associated data will be carried across standard Russian land forces tactical communications which are explained in more detail here.

Potential

Will Svod help Russian land forces accelerate tactical battle rhythm and shorten sensor-to-shooter times? Potentially yes, although Svod only appears to have a capacity that, at the very least, matches Ukraine’s Delta system. Ukraine has a headstart on its Russian adversary as Delta’s implementation on the battlefield commenced from mid-2022 and has been in a near constant state of evolution ever since. In the C2 technology arms race, Ukraine is clearly winning. Will Svod work sufficiently well to win commanders’ trust? YESU-TZ has been plagued by technical problems. If Svod suffers the same fate, users will simply abandon it in favour of alternatives or fall back on existing systems like YESU-TZ despite its shortcomings.

From an electromagnetic manoeuvre perspective, introducing another digital C2 system onto the battlefield introduces another potential set of targets for Ukrainian cyberwarriors. Likewise, any digital command and control system depends on communications links like radio which can be prone to jamming. Russian battlefield communications are under pressure with the country’s recent eviction from the Starlink satellite communications network. The Russian government is also reviewing military access to the Telegram messaging application. Telegram has been vital for data communications at the tactical level. Closing off these channels inevitably means more data using fewer links creating a greater vulnerability to jamming. Svod’s success, or otherwise, will likely become apparent early next year once its roll-out is complete. Any subsequent Russian success on the battlefield could be a consequence of its introduction. Until then, Ukraine and her allies must ensure that any, and all, of Svod’s vulnerabilities are identified and ready to target.m(Source: Armada)

 

12 Mar 26. March Radio Roundup.

Armada’s monthly roundup of all the latest news in the military communications product, programme and operational domains.

TRASC Certification

In early February, SD Government announced it had received T-1 certification for the company’s Tactical Removable Airborne Satellite Communications (TRASC) system to equip the United States Air Force’s (USAF) Lockheed Martin C-130H/J turboprop airlifters.

TRASC is a roll-on/roll-off Satellite Communications (SATCOM) system providing Ku-band (14 gigahertz/GHz uplink/10.9GHz to 12.75GHz downlink) connectivity. There is growth potential to expand this provision to include Ka-band (26.5GHz to 40GHz uplink/18GHz to 20GHz downlink) channels.

According to a company press release, the TRASC architecture can be installed onboard a C-130 series aircraft in under 30 minutes. In addition to the USAF, SD Government is aiming TRASC at C-130 operators in US sister services and allied militaries. T-1 certification means that TRASC can be immediately implemented on C-130 aircraft “without the need of duplicative testing” according to a company statement provided to Armada. Moreover, “(t)he certified configuration initially supports Ku-band connectivity using geostationary satellites, with Ka-band capability approved for subsequent integration”. Beyond Ku-band and Ka-band provision “(t)he certification … allows for additional network compatibilities to be incorporated, giving operators the flexibility to adopt future SATCOM architectures as mission requirements evolve”.

Silvus Unveils Streamcaster Mini 5200

Silvus Technologies’ new Streamcaster Mini 5200 mobile ad hoc networking radio weighs just 182 grams and provides connections with over 550 nodes. Several potential customers are currently evaluating the system. (Silvus Technologies)

Silvus Technologies has unveiled a new Mobile Ad Hoc Networking (MANET) radio known as the Streamcaster Mini 5200. According to the company the new radio, which uses a host of frequencies between 1.35 gigahertz up to five gigahertz, can handle data at rates of up to 100 megabits-per-second. When using beamforming, the radio provides up to four watts of transmission power, according to the company’s official information.

Channel bandwidths of five, ten and 20 megahertz/MHz are standard, with bandwidths of 2.5MHz and 25MHz being optional. Integral communications and transmission security provision include the United States’ Federal Information Processing Standard Publication 140-3 and Advanced Encryption Standard-256 protocols. The radio also includes Silvus Technologies’ Mobile Networked Multiple-In Multiple-Out waveform.

According to a statement provided to Armada by the company, the Streamcaster Mini 2500 has an ultra-compact form factor that expands its “portfolio to meet the needs of covert operations and dismounted users who require a minimal footprint without sacrificing link robustness”. The statement continued that the radio seamlessly connects with over 550 nodes and weighs 182 grams (0.4 pounds). Deliveries of the Streamcaster Mini 5200 will commence this May and Silvus Technologies is currently in the test and evaluation stage with “several units and agencies across the globe”.(Source: Armada)

 

26 Mar 26. Poland: Increase in cyber operations points to elevated security risks from Russian threat actors 

On 24 March, international news outlets reported that the number of cyber attacks on Polish organisations more than doubled in 2025 compared to 2024. During 2025, Poland reportedly suffered a total of 270,000 cyber attacks, despite the country’s proclaimed effort to bolster its cyber defences since the invasion of Ukraine. The most notable incident occurred in December 2025 when a Russian state-sponsored group (‘Sandworm’) targeted multiple energy providers in a destructive cyber operation. The attack successfully damaged communications systems, demonstrating the destructive intent of Russia’s cyber operations. This operation constituted the first destructive cyber attack on critical national infrastructure (CNI) outside Ukraine since 2022. US President Donald Trump’s shifting stance towards NATO and Ukraine has informed a redirection of Russian grey-zone operations towards the bloc over the last 12 months. We assess that this will sustain elevated security risks to Polish (and European) infrastructure in the medium term.  (Source: Sibylline)

—————————————————————————————————————

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

—————————————————————————————————————

 

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

March 24, 2026 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

——————————————————————————————————————

10 Mar 26. Persistent Systems, LLC (“Persistent”), a global leader in secure mobile ad hoc networking (MANET) technology, announced that the UK Ministry of Defence has selected the Wave Relay® MANET, including the MPU5 tactical communication system, in support of Project CAIN, a key modernization effort for the British Army.

UK MOD Selects Persistent Systems for British Army Project Cain Modernization

Awarded through Persistent’s UK partner and authorized distributor Steatite Ltd., the program will deliver MPU5 radios, Rugged Display & Controllers (RDCs), and associated Dismount Kit equipment to the 16 Air Assault Brigade Combat Team, the UK’s rapidly deployable, first-to-fight airborne formation.

As part of this effort, 16 Air Assault will also employ Cloud Relay™, Persistent’s global networking technology, enabling soldiers to maintain uninterrupted communications, even when transitioning between SATCOM, LTE, 5G, or other transport layers. This ensures resilient connectivity in complex, contested, and highly mobile environments.

“By deploying the MPU5 and Cloud Relay™, the 16 Air Assault Brigade Combat Team will gain a significant advantage in decision-making and coordination across dispersed, multi-domain operations,” said Eve Shapiro, Senior Director of Sales and Business Development at Persistent Systems. “We’ve seen exceptional results with the UK Royal Marines, and we expect similar success as more organizations recognize the operational impact of a resilient, edge-to-cloud network.”

This selection builds on the UK’s ongoing modernization progress. In 2024, the UK Royal Marines fielded more than 2,000 MPU5s as part of their transformation into a more agile, technology-enabled Commando Force. The 16 Air Assault effort marks another step in strengthening the UK’s ability to operate with speed, precision, and interoperability alongside allies.

Persistent Systems continues to support modernization initiatives worldwide, including programs within the U.S. Army’s Next Generation Command and Control (NGC2) efforts, maritime security initiatives across the Baltic region, and Indo-Pacific partner networks. The increased adoption of the MPU5 across Europe, including deployments in the Baltics, Spain, France, and the UK, reflects the growing demand for scalable, resilient MANET capabilities.

The UK MoD’s decision underscores a broader trend of successful modernizations of forces, which require secure, adaptable, and globally connected networks to maintain situational awareness and operational advantage in dynamic, contested environments. (Source: PR Newswire)

 

09 Mar 26. Bittium and Sensofusion have agreed to collaborate to develop interoperable, secure, and resilient tactical communications solutions and anti‑drone systems for the defense industry. The objective of the cooperation is to ensure that the solutions of both companies can be used simultaneously in demanding operational environments without degrading each other’s performance.

Bittium is a leading provider of resilient tactical communications solutions based on software‑defined radio technology. The modern broadband TAC WIN backbone network and the next‑generation Tough SDR radios designed for defense use are engineered to operate reliably even in heavily contested and jammed environments, unlike commercial networks.

Sensofusion, in turn, offers some of the most advanced anti‑drone solutions on the market. The strong jamming capabilities of these systems have traditionally posed challenges when used alongside tactical communications.

In the first phase of the cooperation, the companies have conducted joint tests to evaluate the simultaneous operation of their solutions. Based on the test results, Bittium’s and Sensofusion’s solutions can operate side by side in the field without anti‑drone activities disrupting tactical communications.

“At the core of our cooperation is the testing and development of the combined use of radio‑frequency jamming and anti‑jamming solutions. Our goal is to ensure that customers can communicate on the tactical network on the battlefield even when anti‑drone systems are operating simultaneously. This improves operational performance and security while giving users greater freedom of action in demanding situations,” says Tommi Kangas, Senior Vice President of Bittium’s Defense & Security Business Segment.

The cooperation will continue with further development of interoperability to meet future requirements. The aim of the development work is to further enhance performance, resilience, and usability in operational environments.

“Continuous cooperation through joint testing provides both companies with the best possible way to develop systems that dominate the signal environment in modern anti‑drone warfare,” says Tuomas Rasila, CEO of Sensofusion.

Sensofusion brings together hardware and software experts with strong operational backgrounds, enabling the design of solutions that genuinely meet the demands of modern operational environments. The company maintains its competitiveness by leveraging agile development methods and rapid prototyping.

——————————————————————————————————–

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

———————————————————————————————————————

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

March 6, 2026 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

—————————————————————————————————————–

05 Mar 26. Middle East, North Africa and Turkey region: Iran-linked cyber activity will raise security risks from compromised IP cameras, technical equipment. On 4 March, cyber security company Check Point reported that the ongoing Israel-US-Iran war has precipitated an increase in Iran-led cyber attacks on internet protocol (IP) cameras across Middle Eastern countries since it began on 28 February. Reportedly, Iran-linked threat actors previously compromised cameras during the Israel-Iran war in June 2025 for operational support, battle damage assessment (BDA) and (in some cases) to tailor missile launches. At the time of writing, the recent uptick in cyber attacks has targeted cameras in Bahrain, Cyprus, Kuwait, Lebanon, Qatar and the UAE, likely to inform ongoing retaliatory efforts. Data from January and early February also suggests that Iran consistently increases such cyber activity during geopolitical escalations, highlighting the complementary nature of its cyber strategy. Consequently, we assess that cameras and possibly other technical equipment across the Middle East, North Africa and Turkey region will face heightened security risks in the short term, as Iran will likely seek to use cyber intelligence to enhance kinetic action. (Source: Sibylline)

 

02 Mar 26. Thales sets a world first in quantum-safe security for 5G networks.

  • Thales has successfully demonstrated a world-first innovation that prepares 5G networks for the age of quantum computing, marking a major milestone for the global telecommunications industry.
  • The collaboration with a top tier mobile operator, showed that existing 5G SIM / eSIM cards already deployed in the field can be securely upgraded to quantum-safe protection, without disrupting service or impacting the customer experience.
  • This Post-Quantum Cryptographic (PQC) breakthrough proves that mobile networks can evolve their security through crypto agility to address quantum cyber threats.

Quantum computing has the potential to break today’s encryption methods in the future, putting mobile communications, personal data and critical infrastructure at risk. For telecom operators, this is not a distant theoretical issue: 5G networks underpin everything from smartphones and connected vehicles to emergency services, industry and national infrastructure.

The challenge is scale. Replacing ms of devices every time security standards evolve is neither practical nor sustainable. The industry needs a new approach. With this demonstration, Thales shows that security can be upgraded remotely and instantly, directly on SIM and eSIM cards already in use. This capability, known as crypto agility, allows operators to adapt their security protections as threats and standards evolve, without waiting for new product generations.

Indeed, this innovation underlines how Thales can strengthen the security of SIM and eSIM already deployed, by remotely downloading post-quantum cryptographic algorithms directly onto the card. This happens seamlessly in the background, preserving existing data and services while instantly enhancing security. With Thales’ unique crypto-agile approach, operators can remotely update the device protection without replacing cards, changing devices or interrupting connectivity.

It means 5G networks can remain secure, resilient and trusted over time, even as quantum computing becomes a reality. This successful demonstration is the first of its kind and sends a strong signal to the market:

  • Quantum-safe security can be introduced over the air without changing devices or interrupting service.
  • Mobile networks can evolve securely over time, even as threats change.
  • Telecom operators can protect long-term investments while preparing for the next era of quantum computing.

It also builds on Thales’ strong leadership in post-quantum cryptography, backed by dedicated research teams across the Group. Thales not only integrates future-proof security technologies, but it also actively develops them, with its own quantum-resistant methods submitted to international standardization efforts such as those led by the U.S. National Institute of Standards and Technology (NIST).

This successful test shows that quantum-safe security is no longer a future concept, it’s something networks can start preparing for today,” said Eva Rudin, VP Mobile Connectivity solutions at Thales. “By enabling remote upgrades, we help operators protect their customers and critical services without disruption. We will continue working together to help bring quantum-ready security to commercial and private 5G networks worldwide, ensuring trust, resilience and continuity in a rapidly changing digital world.”

 

04 Mar 26. Global: Widespread AI exploitation will raise security risks from various cyber threat actors. On 3 March, the cyber security company Cloudflare reported that a wide range of threat actors are increasingly exploiting artificial intelligence (AI) to facilitate cyber intrusions. The report claimed that AI and large language models (LLMs) are being leveraged at scale to automate the early stages of the cyber attack chain, thus lowering the technical barrier of entry and compensating for limited skillsets. In particular, threat actors are using AI-generated ‘deepfakes’ (fake images, video or audio) to impersonate high-profile individuals as well as job applicants. For instance, in February, a North Korean state-sponsored group (‘UNC1069’) used a deepfake to impersonate a company’s CEO to subsequently install data miners for financial profit. Although human-led social engineering techniques continue to be successful, the company’s researchers stated that AI-enabled cyber capabilities – including but not limited to phishing – can also intensify the impact of an attack. Consequently, we assess that this trend will raise the long-term security risks to global entities amid the rapid development of the AI ecosystem. (Source: Sibylline)

 

27 Feb 26. Cyber Update

Key points

  • Sophisticated monitoring capabilities underscore long-term surveillance risks from a known spyware variant (‘Predator’; see Sibylline Cyber Daily Analytical Update – 23 February 2026).
  • The distribution of a stealthy remote access trojan (RAT; ‘Pulsar RAT’) will heighten security risks for global users of repository platform NPM (see Sibylline Cyber Daily Analytical Update – 24 February 2026 and our technical analysis below).
  • Healthcare organisations in the US and Middle East, North Africa and Turkey region face elevated ransomware risks from North Korean state-sponsored groups (see Sibylline Cyber Daily Analytical Update – 25 February 2026).
  • A cyber campaign perpetrated by a suspected Chinese state-sponsored group (‘UNC2814’) highlights long-term espionage risks for telecommunications and government firms worldwide (see Sibylline Cyber Daily Analytical Update – 26 February 2026 and our technical analysis below).
  • The healthcare and education sectors face heightened security risks from North Korean state-sponsored groups via the distribution of a new malware variant.

Technical analysis of weekly stories

Unnamed threat actors are abusing legitimate code repository platform NPM to distribute a known RAT (Pulsar RAT). Reportedly, threat actors use typo-squatting techniques to name a malicious file after a legitimate software package, with the exception of a few characters. This aims to trick victims into downloading the malicious file, which is typically advertised on NPM’s platform for distribution. The file then installs a malware loader inflated in size through the inclusion of a large volume of void commands, thereby complicating analysis efforts and enhancing obfuscation. Subsequently, the file reassembles a PowerShell script that enumerates any anti-virus products present on compromised machines, before downloading a portable networks graphics (.PNG) image. Subsequently, the image employs steganography techniques to extract additional malicious payloads through a multi-phase process that reads binary data concealed within the image to appear legitimate, highlighting the cyber attack’s sophistication and persistent stealth. Threat actors also adopt process hollowing to execute and store the final payload (Pulsar RAT) within a legitimate Windows process, while continuing to evade detection. Pulsar RAT facilitates remote control, data exfiltration and the monitoring of compromised systems, likely for espionage purposes.

A suspected Chinese state-sponsored group (UNC2814) targeted telecommunications and government organisations in a long-term cyber espionage operation since at least 2023. The group possibly exploited software vulnerabilities in public-facing web severs and/or network edge devices to infiltrate targeted systems. UNC2814 reportedly moved laterally through compromised systems via the secure shell (SSH) protocol and subsequently leveraged living-off-the-land (LotL) techniques to perform reconnaissance, escalate privileges and deploy a backdoor (‘GRIDTIDE’). The group also deployed a virtual private network (VPN) service to establish and maintain a connection to an external IP address. GRIDTIDE then established communication with command-and-control (C2) infrastructure by abusing the application programming interface (API) associated with the spreadsheet service Google Sheets. More specifically, upon execution, the backdoor uses the API to connect to a spreadsheet, which it then sanitises by deleting the first 200 rows to avoid any activity interference. GRIDTIDE uses specific spreadsheet cells for different functions with the aim of maintaining C2 communication and exfiltrating data, highlighting its sophistication. It also sends status requests every few seconds until it reaches 120 instances before reducing the request frequency to enhance obfuscation.

Non-exhaustive recommendations to mitigate these threats include:

  • Monitor devices and networks for suspicious activity.
  • Add available Indicators of Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware.
  • Adopt behaviour-based endpoint detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.

Our cyber word of the week: Typo-squatting

Definition: A technique where threat actors register common misspellings and/or variations of popular domain names to trick users into clicking on malicious attachments.

Example: ‘Threat actors […] reportedly use typo-squatting techniques to emulate legitimate packages and trick victims into downloading the file onto their systems.’ (Source: Sibylline)

——————————————————————————————————————-

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

—————————————————————————————————————–

UNMANNED SYSTEMS UPDATE

February 27, 2026 by

Sponsored by EOS

 

www.eos-aus.com

 

———————————————————————————————————————————————————————————————————————————————————————————————————————————————–

25 Feb 26. Germany to slash long-term strike drone purchasing plan, document shows.

  • Summary
  • Lawmakers demand parliamentary control over future drone contracts
  • Rollback comes even after parliament loosened borrowing constraints
  • Thiel’s stake in Stark not a concern, says Defence Minister Pistorius

Germany’s ruling coalition will slash the size of a longer-term framework deal to purchase strike drones to 2bn euros ($2.4bn) from 4.3bn euros previously envisioned as lawmakers seek tighter control over future budgets.

A proposal written by lawmakers with budget responsibility from the governing parties, which was made available to Reuters, confirmed an order for strike drones worth 536 m euros from German startups Helsing and Stark Defence, but stressed that follow-up contracts surpassing 2 bn in total will require fresh parliamentary clearance.

“Without parliamentary control, there would be a risk of bns in de facto budget commitments over a long period of time,” the document said.

The contracts for loitering munitions – drones loaded with explosives that hover over a potential strike area before swooping – are part of a rearmament push after Russia’s attack on Ukraine. Reuters this month reported that the contracts and the longer-term procurement framework were outlined in finance ministry documents. The drones are initially intended to support Germany’s Lithuania-based 45th Tank Brigade. The rollback comes after Chancellor Friedrich Merz’s government pushed through sweeping reforms to loosen fiscal rules in March last year. While lawmakers at the time earmarked 500 bn euros in multi-year infrastructure spending to revive the economy, they also boosted defence funding to support Ukraine and meet higher contribution targets for NATO members. In the document, the lawmakers made no reference to a recent debate in German media whether the government should rely on Stark as it counts Peter Thiel among its investors. The German-American entrepreneur was an early backer of U.S. President Donald Trump and Vice President JD Vance.

Germany’s Defence Minister Boris Pistorius reiterated on Wednesday that Thiel’s association with Stark was no grounds for concern.

“We’re talking about a single-digit percentage stake without access to or insight into operational matters,” he told journalists on the sidelines of a defence committee meeting in Berlin on Wednesday. ($1 = 0.8487 euros) (Source: Reuters)

 

25 Feb 26. Soldiers Experiment With First-Person-View Unmanned Aircraft Systems. The Army’s 3rd Infantry Division is revolutionizing how ground forces employ unmanned aircraft systems through specialized UAS operators assigned to the 6th Squadron, 8th Cavalry Regiment, 2nd Armored Brigade Combat Team, 3rd Infantry Division, which officials say is critical to winning on the modern battlefield. Combat team soldiers have fundamentally changed how drones are used at the brigade level by spreading the technology across the entire force and establishing a hub for testing innovative capabilities, said Army Capt. William Langley, brigade collection manager.

“UAS is important on the modern battlefield today because it is a very fast-paced battlefield,” Langley said. “The faster you can receive information and sense the enemy, the faster you can react, and whoever reacts first wins.”

The unit combines electronic warfare, UAS and launch effects platoons — a reorganization that provides tactical advantages on the battlefield. Soldiers are experimenting with various payloads on drones, including electronic warfare sensors and advanced capabilities for operational missions.

Army 1st Lt. Declan McKeown, UAS platoon leader, said the combat team aims to improve operational effectiveness by using its platoons to gather intelligence and respond to threats faster than traditional methods allow.

“The enemy wants to find us first, so it’s a competition between the enemy and us to utilize our systems to be able to sense, track and maintain tactical advantage,” McKeown said.

The innovation comes as the 3rd ID participates in the Army’s Transforming in Contact 2.0 initiative, which accelerates how combat formations test and adopt new technologies. The division has been designated as an initiative unit, positioning it at the forefront of procurement and experimentation with different platforms.

“Innovation is necessary for the 3rd ID to be successful because, as we have seen in recent conflicts in Ukraine, Israel and other places around the world, the way we fight battles is changing at a rapid pace, and we must continue to modernize to maintain our readiness for future operations,” Langley said.

A recent training exercise at Fort Stewart, Georgia, during Spartan Focus 26, featured 6th Squadron soldiers conducting UAS training with C100 medium-range reconnaissance systems configured with 3D-printed training rounds. The exercise incorporated lessons learned from Ukraine, where low-cost quadcopter drones have been widely used in recent conflicts.

The division’s approach has significantly improved the decision-making cycle, allowing forces to gather and process intelligence much faster than previous methods, McKeown said, emphasizing the importance of soldiers maintaining situational awareness.

“Whoever sees the enemy first can react first, and can respond more effectively, which leads to operational success,” he said.

Soldiers continue to experiment with electronic warfare payloads on medium-range reconnaissance systems and test various configurations on first-person-view drones to determine system limitations and capabilities. The ongoing innovation includes stressing equipment through rigorous training to understand what works best for operational units.

The division’s 3rd Combat Aviation Brigade has also integrated unmanned systems manufacturing capabilities, training soldiers on expeditionary manufacturing cells that enable rapid 3D printing of drone components in the field. Soldiers printed more than 90 unique components in hours rather than waiting weeks for ordered parts.

Langley said being a part of the 3rd ID during this transformative period presents unique opportunities.

“This is an exciting time to be part of this unit, and it’s a great time to test our new capabilities and to really release the creativity of soldiers at every level,” he said.  (Source: U.S. DoD)

 

23 Feb 26. General Atomics Aeronautical Systems, Inc. (GA-ASI) is giving its U.S. Air Force Collaborative Combat Aircraft a new name: YFQ-42A Dark Merlin. Dark merlins, deadly falcons known for their black feathers and devouring of other falcons as prey, often collaborate in groups for maximum effect against their targets. The Cornell Lab of Ornithology describes the merlin as a “small, fierce falcon that uses surprise attacks” to bring down its prey in flight. The dark merlin is native to the Pacific Northwest of the United States, often migrating into southern California, where bird spotters routinely report seeing them near the YFQ-42A’s manufacturing home in San Diego.

The 1962 book “Profiles of the Future” imagined global technological marvels yet to change the world, offering that “any sufficiently advanced technology is indistinguishable from magic.” It’s no coincidence that the Dark Merlin name also reflects the wizardry of Merlin from Arthurian legend, paying homage to the somewhat supernatural new era of semi-autonomous air combat.

“Dark merlins are hunting machines, built for speed and aerodynamics,” said GA-ASI President David R. Alexander. “They harass other falcons for fun, and they eat what they kill. The name sums up our new uncrewed fighter perfectly.”

The U.S. Air Force official prefix “Y” denotes that the initial few aircraft are early, production-representative test models, while “F” denotes fighter and “Q” denotes uncrewed aircraft. When aircraft enter production, they drop the “Y” – for example, the YF-16 became the F-16 with the nickname “Fighting Falcon” – and GA-ASI expects its new CCA to become the FQ-42A with the nickname “Dark Merlin.”

The Dark Merlin has been stacking up milestones and achievements since GA-ASI was selected by the U.S. Air Force in April 2024 to build production-representative flight test articles for the CCA program. In August 2025, YFQ-42A delivered the U.S. Air Force its first successful CCA flight and followed that this month with the service’s first CCA flight using mission autonomy software. Between those milestones, GA-ASI has built and flown multiple Dark Merlins, conducting push-button autonomous takeoffs and landings and other accomplishments as the test program continues.

YFQ-42A Dark Merlin is a purpose-built CCA platform developed as part of GA-ASI’s ongoing investment in next-generation autonomous combat aircraft. The aircraft’s modular design enables rapid integration of mission systems. GA-ASI’s autonomy architecture, demonstrated through multiple live flight tests, provides the foundation for human-machine teaming in complex combat scenarios.

GA-ASI has been building and flying uncrewed jets for nearly two decades, beginning with the company-funded, weaponized MQ-20 Avenger® in 2008. Ongoing company investment in Avenger continues to yield results, as the aircraft routinely serves as a CCA surrogate for advanced autonomy development and testing in both government programs and company-funded research and development. The company’s XQ-67A Off-Board Sensing Station jet, developed in collaboration with the U.S. Air Force Research Laboratory, offers a cutting-edge model for autonomous collaborative platforms with advanced airborne sensing and served as a flying prototype for YFQ-42A Dark Merlin.

 

23 Feb 26. In collaboration with the U.S. Air Force, General Atomics Aeronautical Systems, Inc. (GA-ASI) conducted its latest demonstration performing an autonomous mission out of Edwards Air Force Base in Southern California using its MQ-20 Avenger® unmanned jet and an F-22 Raptor equipped with the latest government reference autonomy software. The test, which showcased Manned-Unmanned Teaming between the F-22 and MQ-20, leveraged autonomy and the tactical data link to enable coordination between the platforms.

The mission included a live engagement between the MQ-20 and the F-22 as the command aircraft flown by an onboard human pilot, highlighting the ability to receive and execute teaming commands.

“We appreciate the flawless execution of this mission using the government’s advanced autonomous systems,” said GA-ASI President David R. Alexander. “This demo featured the integration of mission elements and the ability of autonomy to utilize onboard sensors to make independent decisions and execute commands from the F-22.”

The demonstration showcased Manned-Unmanned Teaming and rapid software integration between the MQ-20 and the F-22, and a tactical data link used for communication and coordination between military platforms. The MQ-20 successfully exchanged messages with the F-22, and the F-22 was able to send autonomy commands to the MQ-20 via the Autonodyne Bashi Pilot Vehicle Interface (PVI), directing the MQ-20 to execute tactical maneuvers and adjust waypoints, and perform Combat Air Patrol (CAP) and airborne threat engagement tasks.

This demonstration highlighted the potential of CCAs to act as force multipliers for manned platforms, enabling collaboration between autonomous systems and human pilots. GA-ASI’s MQ-20 Avenger unmanned jet has served as a surrogate CCA for more than five years, both before and since the arrival of GA-ASI’s purpose-built XQ-67A and YFQ-42A aircraft.

 

20 Feb 26. AVIC Displays V-BAT Knock-Off at Festival in China. China’s AVIC Chengdu Aircraft Industry Group has unveiled a new vertical takeoff and landing (VTOL) unmanned aerial vehicle called the Yunying-25V (“Cloud Shadow”), a tail-sitter drone with a ducted-fan design that closely resembles the V-BAT developed by Shield AI. The Yunying-25V made one of its first large-scale public appearances during the 2026 CCTV Spring Festival Gala in Yibin, where ten drones performed a coordinated flight demonstration. The display highlighted the platform’s ability to operate in formation and underscored its readiness for broader introduction. Designed for convenient vertical takeoff and landing, the Yunying uses a specialized airframe layout and flight-control algorithms to enhance adaptability across diverse environments. According to the manufacturer, the aircraft requires only a 3-by-3-meter area for launch and recovery, enabling operations from confined terrain or moving platforms. Promotional materials emphasize rapid deployment and flexible basing, describing launch “within a small space — directly into the sky.” Two variants are offered: an electric model with a maximum takeoff weight of 25 kilograms and a gasoline-powered version weighing up to 31 kilograms. Both can operate at altitudes of up to 4,000 meters. Maximum speeds are listed at 190 km/h for the electric configuration and 210 km/h for the fuel-powered model. Payload capacity reaches 3 kilograms for the electric version and 4 kilograms for the gasoline variant. The drone measures 2.6 meters in wingspan and 1.96 meters in length. Featuring a modular, disassemblable structure, the Yunying can be transported in a pickup truck and deployed in under five minutes. Its tail-sitter configuration enables vertical launch, transition to forward flight, and more efficient cruising than traditional multirotor drones, supporting missions ranging from urban monitoring to emergency response. The drone first appeared in August 2025 when it was showcased during a mountainous plateau disaster relief drill in Sichuan Province. (Source: UAS VISION/Defence Blog)

 

25 Feb 26. Sea Archer USV prototype begins trials as Leidos Australia advances ambitious manufacturing plan. Next-generation Sea Archer small uncrewed surface vessels surge across the ocean, several close in on adversary targets to engage with loitering munitions or Naval Strike Missiles while others carry out electronic warfare missions alongside Royal Australian Navy warships or transfer crucial supplies to front-line Australian Defence Force littoral troops. That’s the ambitious vision proposed by Leidos Australia; cheap and attritable Sea Archers produced en masse using Australia’s existing recreational aluminium boat builder network.It’s a plan that the Victorian-headquartered company is funding themselves with self-confidence, as the first Sea Archer prototype prepares to begin harbour acceptance trials in Townsville next month, and if successful, undertakes sea acceptance trials in Darwin during April and May this year.

Initial production is expected later this year, despite no current Defence contract for the vessel, with a targeted construction time of less than three months and cost of US$1 m per vessel. More than 16 shipyards have reportedly been approached to confirm their interest in the build.

Leidos chief of maritime engineering and technology and Royal Australian Navy Captain (Ret’d) Zoe Chadwick said the next-generation dazzle-camouflaged craft is designed with multi-mission capability and rapid manufacturing capacity in mind.

“Sea Archer was designed from the outset to support a distributed sovereign build capability. When we first looked to build Sea Archer in-country we approached 16 different boat builders, mostly in local and regional sort of areas, the smaller type shipyards and boat yards. That is so that we can support surge capability or parallel builds if it was required,” she said.

“This vessel was built in Toronto, just north of Sydney and it demonstrates that we are able to build a Sea Archer in-country, utilising our local workforce and our local supply chains.

“Sea Archer fits inside a standard 40 foot ISO high cube container, making it ideal for covert transport around Australia and, of course, globally … We can launch it from any boat ramp and recover it from any boat ramp around Australia. A very versatile piece of equipment.

(Source: Defence Connect)

 

26 Feb 26. New drone factory opens in Suffolk to boost Ukraine’s Armed Forces against Russia’s war

Ukraine’s Armed Forces will be able to better defend itself against Russia’s brutal attacks.

  • Ukraine’s largest drone manufacturers open new factory in Suffolk, creating up to 500 jobs and boosting economic growth.
  • Factory to produce cutting-edge drones, providing critical support in Ukraine’s fight for freedom, four years on from Putin’s illegal invasion.
  • The UK stands with Ukraine, with over £1 bn committed for the country’s air defences since July 2024.

Ukraine’s Armed Forces will be able to better defend itself against Russia’s brutal attacks after one of Ukraine’s largest drone manufacturers opens a new factory in Suffolk.

Four years on from Putin’s illegal invasion, the UK is backing Ukraine by hosting a new Ukrspecsystems production facility in East Anglia. The UK has previously ordered over 80 SHARK and Mini-SHARK drones from Ukrspecystems’ factories in Ukraine, which help save Ukrainian lives by combatting Russia’s war effort.

In a vote of confidence for the UK, Ukrspecsystems chose sites in Mildenhall and Elmsett in Suffolk for their new drone factory and testing and training facility. The company’s £200 m investment will create up to 500 British jobs at the sites and broader UK supply chain.

Minister for Defence Readiness and Industry Luke Pollard MP said:

Our resolve to support Ukraine is stronger than ever, and we are backing Ukraine’s defiant Armed Forces as they fight for peace.

Ukrspecsystems’ new factory is a vote of confidence in UK support and underlines the deepening cooperation between our nations’ defence industries. This investment will create up to 500 new jobs in the East of England, drive defence as an engine for growth, and help Ukraine defend itself against Putin’s aggression.

The facility was opened by Defence Minister Luke Pollard yesterday, reaffirming the UK’s continued support for Ukraine. This follows more than £1 bn committed to support Ukraine’s air defences since July 2024, helping Ukraine defend itself against Russian drone attacks on civilians and critical infrastructure.

Ukrspecsystems is a Ukrainian drone company, founded in 2014, which produces a wide variety of drones, including the PD-2 and SHARK-M surveillance drones which communicate autonomously with strike drones to identify, track and destroy Russian targets. Ukrspecsystems’ drones have contributed to almost $3 bn of damage to Putin’s war machine since the onset of the full-scale invasion.

The UK has separately started producing Octopus interceptor drones, aiming to ramp up to thousands per month, designed to take out Russian Shaheeds and other weapons at a fraction of the cost, part of the Ministry of Defence’s £4.5bn military support package.

Today’s news is a clear demonstration of the 100 Year Partnership in action – establishing stronger and closer defence cooperation and industrial bases between the UK and Ukraine.

It also follows the announcement of a new business centre in Kyiv which will enable Britain’s cutting-edge defence industry and innovators to step up their work to equip Ukraine’s Armed Forces.

Ukrainian Ambassador to the UK General Valerii Zaluzhnyi said:

This factory represents more than industrial cooperation – it is part of a new European security architecture built on shared responsibility and shared production. Ukraine brings battlefield experience and innovation, and together with the United Kingdom we are strengthening the capabilities needed to deter aggression.

The UK’s Defence Industrial Strategy is making it easier for defence business to operate in the UK, driving economic growth and supporting the government’s support for Ukraine, in line with the Strategic Defence Review.

Director of Ukrspecsystems UK Rory Chamberlain said: “Four years on from Russia’s full-scale invasion of Ukraine, this factory delivers what matters: secure supply, secure resource, and sustained support for Ukraine. By establishing production in the UK, Ukrspecsystems are increasing the resilience of the UK’s defence industrial base, and providing a trusted supply chain that ensures that the drones relied upon by the Ukrainian Armed Forces can be built and scaled without interruption. ”

Delivered with UK and Ukrainian Government support and in partnership with British SMEs, this is ‘Made with Ukraine’ in action – embodying the UK-Ukraine 100-Year Partnership through real industrial capability, happening now in East Anglia.

(Source: https://www.gov.uk/)

—————————————————————————————————————————————————————————————————————————————————————————————————————————-

EOS

Electro Optic Systems (EOS) is an Australian technology company with a global presence, delivering advanced solutions across defence and space. With operations in Australia, the United States, Europe, Singapore, the Middle East and New Zealand, EOS has been designing and manufacturing precision technologies for more than four decades.

In defence, EOS is a leader in remote weapon systems, with more than 2,500 delivered and proven in operational service with allied forces. The company designs, develops and manufactures highly accurate counter-drone solutions for force and asset protection. These include both kinetic and high energy laser options that defeat drone threats effectively and at a comparatively low cost per shot. In August 2025, EOS secured the world’s first export contract for a 100 kW-class high energy laser weapon, with delivery scheduled between 2025 and 2028.

In the space domain, EOS is internationally recognised for its expertise in space domain awareness and space control. Its ground-based optical systems track and characterise satellites and debris to support both defence and commercial operations worldwide. Through its New Zealand subsidiary, EOS also designs and manufactures precision optics for space and astronomy applications.

———————————————————————————————————————————————————————————————————————————————————————————————————————

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

February 27, 2026 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

————————————————————————————————————————————————————————————————————————————————————————————————————————————

26 Feb 26. ISS Aerospace & Anduril UK Partner to Integrate WASP Launched Effect into Lattice Platform. New collaboration between ISS Aerospace and Anduril aims to enable coordinated massed operations and multi-mission capabilities across ISR, counter-UAS, and strike roles. ISS Aerospace and Anduril UK have entered a partnership agreement to integrate the ISSOS WASP multi-mission launched effect into the Lattice software platform and various uncrewed systems. This integration is designed to realize the full mission envelope of the WASP platform, covering Intelligence, Surveillance, and Reconnaissance (ISR), Counter-Uncrewed Aerial Systems (C-UAS), and strike missions. By utilizing Anduril UK’s sovereign Lattice command-and-control platform, the companies aim to unlock the ability to conduct coordinated, massed operations involving multiple launched effects from host platforms. The WASP is a medium-sized, tube-launched, rocket-propelled uncrewed aerial system. It features an open architecture and flight stack, which recently allowed engineers from ISS Aerospace to complete a rapid integration into the Lattice platform in a single day. The modular nature of the WASP payload ensures it can be reconfigured specifically for the requirements of ISR or offensive and defensive operations. The partnership has already reached its first technical milestone through a successful flight test conducted at the ISS Aerospace facility in Oxford. This exercise validated the open architecture of the Lattice software and demonstrated the additional operational capabilities gained through the integration of the two systems.

Ryan Kempley, CEO of ISS Aerospace, commented, “Speed matters. The ability to integrate, test and deploy capability at pace is decisive. WASP was deliberately engineered with an open architecture flight stack, which allowed our teams to integrate with Lattice and validate it in flight within a single day. ISS design & build integration-ready platforms. That approach accelerates deployment timelines, enables partner software to run seamlessly on our hardware, and ensures sovereign UK capability can evolve as fast as operational demand requires.”

Rich Drake, MD of Anduril UK, added, “WASP represents what we look for in a sovereign effector with its size, range and ability to deliver rapid, real-time intelligence in contested environments. To successfully support our Armed Forces, speed of integration, manoeuvre and development are essential. We were proud to prove our ability to do this with ISS Aerospace, and look forward to our ongoing work with them and other local partners, using Lattice as a base for the ongoing capability development for the UK.” (Source: https://www.defenseadvancement.com/)

 

26 Feb 26. Greensea IQ Launches Submersible Command & Control Interface for Combat Swimmers. Greensea IQ introduces the Bayonet Underwater Controller, a ruggedized interface allowing military divers to manage unmanned systems from fully submerged positions Greensea IQ has announced the first production release of the Bayonet Underwater Controller, a specialized multi-platform interface designed for divers to operate robotics while fully submerged. The system adapts a standard user interface utilized across thousands of maritime platforms into a ruggedized housing specifically engineered for the ergonomic and operational constraints of military personnel. The controller is built upon an open architecture framework, allowing for the command and control of various unmanned systems from a submerged position. Initial units have already been delivered to the U.S. Navy and international partners for the operation of the Mission Specialist Defender ROV and the Bayonet Autonomous Underwater Ground Vehicle (AUGV) platform. Engineered for harsh maritime conditions, the hardware is depth-rated to 40 meters and provides up to six hours of runtime. The interface includes 30 programmable push buttons and two precision joysticks, allowing operators to customize controls based on specific mission requirements. An accompanying submersible hub, rated to 45 meters, houses an Intel i7 processor and a removable 1TB hard drive to ensure secure data handling and high-performance mission processing. The system is typically deployed with the EOD Edge software framework, a command and control suite that facilitates the supervision of autonomous systems. This software supports modular expansion for over-the-horizon operations, obstacle avoidance, automatic target recognition, and advanced perception sensor processing. Additionally, the controller is robot-agnostic and provides integrated workflow support for Team Awareness Kit (TAK) systems.

Ben Kinnaman, CEO of Greensea IQ, stated, “We are excited to provide the Bayonet Underwater Controller to a growing mission requirement. I founded Greensea to make ocean robots easier to use so that they can provide safety and scale. This product completely exemplifies that. It provides our autonomy and robot command and control system in an interface that can be used underwater. This gives the warfighter another tool to increase our persistence, reach, and impact in the ocean.”

Dennis Doan, Product Manager for EOD Technologies at Greensea IQ, added, “What makes this system different is how tightly it integrates with our existing autonomy, navigation, and mission software. We’re not just developing another controller, we’re extending a proven ecosystem into submerged operations, giving operators a consistent, trusted interface no matter where the mission takes them.”  (Source: https://www.defenseadvancement.com/)

 

24 Feb 26. Global Invacom Group Limited has launched a new range of rapid‑deploy XY antenna terminals, designed to deliver fast, reliable multi‑orbit and multi‑band connectivity in the most demanding operational environments. Building on the success of its original XY antenna, the expanded range is now available in four sizes — 0.98m, 1.2m, 1.8m and 2.4m — enabling Global Invacom to better support the evolving requirements of government, defence, and commercial operator customers worldwide. Designed for speed‑to‑service and operational simplicity, the rapid‑deploy XY antennas feature a highly modular, no‑tools assembly, allowing systems to be deployed, calibrated, and operational in under fifteen minutes. Lightweight construction, compact form factors, and precision mechanical design ensure reliable performance without backlash, making the terminals well‑suited to on‑the‑move and on‑the‑pause applications. Each antenna integrates a single IP67‑rated mechanical housing with an internal cable raceway, ensuring repeatable accuracy and orthogonality across all pointing angles, even in harsh field conditions. Operational ease is further enhanced through a stable quad‑pod pedestal with a built‑in Antenna Control Unit (ACU). This supports multiple operating modes including one‑button auto‑acquire, inclined‑orbit tracking, programmed tracking with closed‑loop signal optimisation, and automated calibration via advanced search algorithms. As a result, the terminals can be confidently operated by non‑specialist personnel in mission‑critical scenarios.

Bob Potter, Chief Technology Officer at Global Invacom Group, said: “In mission‑critical environments, speed and simplicity are essential. Our customers often operate in challenging conditions where satellite communications equipment must be deployed and used by any member of a team. This new XY range has been engineered to remove complexity, enabling reliable connectivity within minutes, without specialist training.”

Designed for commercial, government, and defence applications, every terminal in the range is ITAR‑exempt, WGS‑compatible, and supplied in IATA‑compliant packaging, supporting global deployment without regulatory or logistical constraints. Global Invacom will be demonstrating the rapid‑deploy XY antenna range at GOVSATCOM in Luxembourg on Thursday 26 February 2026. To arrange a meeting with the team, please get in touch.

About Global Invacom

Group Limited Global Invacom Group comprises a number of companies specialising in innovative technology, products and solutions for the satellite ground equipment sector. Uniquely, the Group provides fully integrated manufacturing for most of its product lines providing additional quality and supply chain assurance to a global blue-chip customer base in the satellite communications, satellite TV and satellite navigation markets. The Group has an established global presence with sales offices, research and development centres and manufacturing facilities across the world, including Singapore, China, Indonesia, the Philippines, Malaysia, Israel, the UK, and the USA. Global Invacom Group Limited is listed on the Mainboard of the Singapore Exchange Securities Trading Limited.

 

23 Feb 26. Lockheed Martin recently flight tested an artificial intelligence (AI)-enhanced Combat Identification (Combat ID) capability integrated into the F-35’s information fusion system. The successful demonstration, known as Project Overwatch, marks the first time a tactical AI model has been used in flight to generate an independent Combat ID on the pilot’s display.  This builds on work across the company to innovate with intent to meet the warfighter’s real-time needs in an evolving threat environment. In practice, that means accelerating capability at scale with speed. Using innovative methods, Lockheed Martin has deployed real-time, over-the-air software updates to the Aegis multi-mission combat system to deployed U.S. Navy ships in the Red Sea to enable rapid counter-measures against advanced drone and missile threats.

The Big Picture

During the Project Overwatch test flight, which was conducted at Nellis Air Force, Nevada, a Lockheed Martin-built and trained AI/machine learning model resolved ID ambiguities among emitters, improving situational awareness and reducing pilot decision making latency. Engineers then used an automated tool to label new emitters, retrain the AI model to learn the new emitter class within minutes, and reload the updated model for the next flight, all in the same mission planning cycle.

Why It Matters

Embedding this advanced AI into the F-35’s mission system helps pilots understand threats faster so they can make decisions more quickly, because operators don’t have time to synthesize data in combat. Lockheed Martin will continue to improve upon this capability, expanding the AI model’s training to further enhance reliability and accuracy.

Expert Perspective

“This is a demonstration of 6th Gen technology brought to a 5th Gen platform,” said Jake Wertz, vice president of F‑35 Combat Systems at Lockheed Martin Aeronautics. “Equally important is our ability to re‑program the AI model on the ground and have those updates available for the next sortie—an essential step toward maintaining a tactical edge in a rapidly evolving threat environment. These capabilities embody Lockheed Martin’s 21st century strategy, which advances every product line by integrating next‑generation performance, continual software modernization, and AI‑driven decision making to keep our customers ahead of emerging challenges.”

Additional Context

Lockheed Martin has decades of investment and innovation in AI to ensure our systems are smarter, more secure and more interconnected. Initiatives like Project Overwatch demonstrate how we’re innovating with intent, building solutions that integrate seamlessly and deliver immediate value. These flight test results will inform future development and potential integration pathways.

 

24 Feb 26. FLANQ, a German manufacturer of autonomous maritime platforms, and DTC Communications, a leading supplier of secure communications systems, today announced a strategic cooperation to market advanced marine tactical radios for maritime security and defence applications across Europe. The cooperation will focus on pairing DTC’s low-SWaP (Size, Weight and Power) communications technology communications technology into FLANQ’s family of uncrewed surface vessels (USVs) to enable resilient, encrypted command-and-control (C2) links for a wide range of naval missions. By combining FLANQ’s autonomous maritime platforms with DTC’s proven tactical communications solutions, the partnership aims to deliver next-generation mission capabilities for Intelligence, Surveillance and Reconnaissance (ISR), Critical National Infrastructure (CNI) protection, patrol and interdiction, and joint force interoperability. The integrated solution will enable operators to securely task, control and monitor FLANQ’s USVs in real-time across contested maritime environments, ensuring reliable connectivity even in Electromagnetic (EM) contested or denied environments.

Key capabilities and outcomes:

  • Secure, encrypted C2 links for surface and littoral operations
  • High-bandwidth, low-latency communications for sensor and video feeds
  • Interoperability with NATO and partner nation command systems
  • Extended operational range for fully autonomous and remotely controlled missions
  • Resilience against jamming and interception in hostile environments

Jannik Sauer, Chief Technical Officer at FLANQ (pictured left), said: “Reliable command and control is fundamental to any uncrewed platform in the modern battlespace – whether that’s in the air, land or sea surface. With DTC Communications, we are integrating a robust, secure communications backbone into our USV fleet, ensuring that our users can maintain control, share intelligence, and execute missions with confidence.”

Chris Fulthorpe, Strategic Account Manager at DTC Communications (shown right), added: “Our tactical communications solutions have been field-proven in some of the most challenging operational environments. Partnering with FLANQ allows us to extend those capabilities to the maritime domain, ensuring that unmanned surface platforms remain securely connected and mission-effective in any scenario.”

About FLANQ

Headquartered in Germany, FLANQ delivers integrated maritime defence solutions, with a focus on autonomous surface platforms, sensor fusion, and rapidly deployed critical infrastructure security systems.

About DTC Communications

DTC, a Codan Company, is a global leader in mission-critical communications, delivering secure, resilient voice and data solutions in over 150 countries. Our advanced BluSDR radios, high-performance MANET systems, and MeshUltraTM high-bandwidth mesh networking technologies provide assured connectivity, real-time situational awareness, and tactical advantage in the world’s most demanding and contested environments.

Engineered for the tactical edge, DTC solutions enable rapid deployment, seamless interoperability, and secure data exchange across land, air, and sea domains. Designed to perform in electronically contested and infrastructure-denied environments, our technologies ensure continuous, mission-critical communications when operational success depends on absolute reliability.

 

20 Feb 26. Cyber Update

Key points

  • Global businesses face heightened security risks from the increased distribution of a sophisticated malware framework (‘VoidLink’) (see Sibylline Cyber Daily Analytical Update – 16 February 2026).
  • The distribution of two malware variants (‘Lumma Stealer’ and ‘Ninja Browser’) raises security and data-theft risks to businesses via legitimate platforms (see Sibylline Cyber Daily Analytical Update – 17 February 2026).
  • Industrial sectors face heightened operational risks stemming from increased ransomware intrusions (see Sibylline Cyber Daily Analytical Update – 18 February 2026).
  • A suspected Chinese state-sponsored group (‘UNC6201’) will pose heightened security risks to exposed organisations via the exploitation of a zero-day vulnerability (CVE-2026-22769) (see Sibylline Cyber Daily Analytical Update – 19 February 2026 and our technical analysis below).
  • The multi-pronged distribution of a new malware variant (‘Keenadu’) elevates security risks for global Android device users (see Sibylline Cyber Daily Analytical Update – 20 February 2026 and our technical analysis below).

Technical analysis of weekly stories

A suspected Chinese state-sponsored group (UNC6201) has been exploiting a software vulnerability (CVE-2026-22769) to conduct malicious cyber activity since at least mid-2024. The vulnerability affects data protection software (‘RecoverPoint’) supplied by the technology company Dell that safely operates virtual machines (VMs). It reportedly exposes a series of hard-coded credentials at the administrative level, which enable unauthenticated threat actors to move laterally, maintain prolonged persistence and deploy malicious payloads. It is possible that UNC6201 infiltrated a network edge appliance to gain initial access to targeted systems. In September 2025, the group also deployed a new backdoor (‘Grimbolt’) onto compromised systems, which uses ahead-of-time (AOT) techniques to enhance detection evasion. More specifically, AOT techniques aid the conversion of the malicious payload into device-native code during execution, which allows threat actors to maximise software performance and highlights the sophistication of this operation. During the attack, UNC6201 also leveraged new techniques to create temporary network ports on compromised VMs to subsequently pivot into additional, internal software-as-a-service (SaaS) infrastructure, further showcasing the development of the group’s capabilities. Dell released a fix for this vulnerability on 17 February, underscoring the importance of timely patch management to prevent further exploitation.

Elsewhere, unnamed threat actors are targeting Android device users with a new malware variant (‘Keenadu’). The malware facilitates browser hijacking, the monetisation of new applications and advertisements as well as unlimited remote system control. Threat actors use multiple different infiltration techniques, which allow the integration of Keenadu directly into native systems utilities at one of the supply chain stages. This makes some users vulnerable upon purchasing legitimate devices. In this attack variant, Keenadu functions as a backdoor with unlimited remote control capabilities that can install new applications and infect any existing ones, enabling threat actors to monitor and exfiltrate all user data. This version also only deploys if the language and time zones on compromised systems do not align with China, likely in a bid to remain obfuscated. Other techniques also include deploying Keenadu via over-the-air (OTA) firmware updates and the distribution of malicious applications. In one of the latter variants, fake smart home camera applications are distributed to infect victims’ devices, which can subsequently browse through different websites without the user’s knowledge. Keenadu activity also reportedly overlaps with several other known botnets of suspected Chinese origin, further highlighting the potential scale of this operation.

Non-exhaustive recommendations to mitigate these threats include:

  • Monitor devices and networks for suspicious activity.
  • Add available Indicators of Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware.
  • Adopt behaviour-based endpoint detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.

(Source: Sibylline)

 

23 Feb 26. Global: Monitoring capabilities underscore long-term surveillance risk from known spyware variant. On 21 February, international news outlets reported that a known spyware variant (‘Predator’) is using a new stealthy mechanism to record user activity on iPhone operative system (iOS) mobile devices. Threat actors typically exploit zero-day vulnerabilities to conduct zero-click attacks and ultimately infiltrate iOS, Chrome and/or Android devices. Upon obtaining access, Predator carries out a wide range of surveillance activities, including arbitrary code execution, audio recordings and directory enumeration. Additionally, the spyware acquires core-level access in order to intercept sensor activity and conceal the recording indicators that are usually displayed on the status bar. This technique enables threat actors to record audio and camera activity without the user’s knowledge, highlighting Predator’s stealth and sophistication. The spyware has been adopted in surveillance operations worldwide; it was reported to have established new infrastructure in June 2025. This latest report underscores the long-term surveillance risk stemming from Predator’s continuous evolution. (Source: Sibylline)

——————————————————————————————————————————————————————————————————————————————————————————————————————————

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

—————————————————————————————————————————————————————————————————————————————————————————————————————————–

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

February 20, 2026 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

————————————————————————————————————————————————————————————————————————————————————————————————————————————-

19 Feb 26. Bittium, a leading supplier of resilient software-defined radio-based communications, and KNL, a pioneer in HF radio technology, have started a collaboration to provide advanced hybrid communications capabilities for defense. In hybrid networks, KNL’s solutions operating on HF (High Frequency) bands complement Bittium’s network solutions operating on VHF and UHF (Very High Frequency, Ultra High Frequency) bands. Through this cooperation, customers can be offered interoperable networks that cover distances of up to thousands of kilometres, enabling also resilient cross‑border communications that strengthens situational awareness and supports operational superiority. The jointly integrated, seamless hybrid communications solution combines Bittium’s reliable Line‑of‑Sight (LOS) and Non‑Line‑of‑Sight (NLOS) communications solutions, including the wideband, mobile TAC WIN backbone network and the new generation Tough SDR radios, with KNL’s long‑range, Beyond‑Line‑of‑Sight (BLOS) cognitive HF radios. The interoperability of the solutions has been verified in joint demonstrations. The combined solution enables connections between tactical networks and HF nodes located farther away. IP‑level integration allows networks to be expanded freely and flexibly. The network can also be extended seamlessly with the ESSOR High Data Rate Waveform, which NATO has approved as the interoperability standard for tactical communications. The waveform can be used with Bittium’s Tough SDR radios to connect allied forces into the same network.

“The cooperation with KNL brings a new long‑range dimension to Bittium’s tactical networks, enabling seamless hybrid communications across multi-domain operations. Thanks to IP‑level integration, networks can be expanded flexibly across wide geographical areas, improving command and control and strengthening interoperability between nations. This is also essential from the perspective of European sovereignty. We are entering an era in which defense networks are increasingly complex and combine several different technologies. Bittium’s and KNL’s technologies interconnect into a single resilient entity that scales dynamically according to operational needs. The goal is a comprehensive network in which every connection, whether HF, satellite, or commercial 5G, functions seamlessly as part of the same IP‑based architecture, providing continuous situational awareness for command and control in all conditions”, says Tommi Kangas, Senior Vice President of Bittium’s Defense & Security Business Segment.

“This isn’t traditional HF communication with two operators holding handsets. It’s data flowing directly from beyond the horizon into tactical IP networks and command systems – and vice versa. Our combined solution enables connecting tactical bubbles across the scattered battlefield and extension of core network services even to the most remote soldiers operating beyond the enemy lines. The collaboration with Bittium demonstrates how modern HF functions as a natural part of IP-based battle management systems”, says Toni Lindén, CEO of KNL.

 

19 Feb 26. Global: Exposed organisations face elevated security risks from zero-day vulnerability exploitation. On 18 February, the cyber security firm Mandiant reported that a suspected Chinese state-sponsored group (‘UNC6201’) had been exploiting a software vulnerability (CVE-2026-22769) to conduct malicious cyber activity since at least mid-2024. The vulnerability affects virtual machines (VMs) provided by the technology company Dell and enables unauthenticated threat actors to move laterally, maintain prolonged persistence and deploy malicious payloads. It is possible that UNC6201 infiltrated a network edge appliance to gain initial access. In September 2025, the group also deployed a new backdoor (‘Grimbolt’) onto compromised systems, which uses ahead-of-time (AOT) techniques to enhance detection evasion, highlighting its sophistication. It is likely that the objective of UNC6201’s campaign is cyber espionage based on China’s long-term cyber strategy. Although Dell released a fix for this vulnerability on 17 February, we assess that vulnerable organisations in key adversarial sectors will face heightened security risks in the short-to-medium term, underscoring the importance of timely patch management. (Source: Sibylline)

 

19 Feb 26 . Kongsberg Discovery has upgraded its innovative Kongsberg Listen electromagnetic sensor system, setting new standards for inspections, surveys and knowledge acquisition in complex underwater environments. Formerly known as Argeo Listen, the system has undergone comprehensive hardware and software enhancements, delivering much-improved data processing and visualisation capabilities. The platform agnostic technology is now available for a huge range of applications across the ocean science, defence, energy and minerals sectors, amongst others.

Accelerating innovation

Kongsberg Discovery acquired Argeo’s electromagnetic sensing technologies, and recruited its expert staff, in August 2025, and has since focused on integrating the solutions into its existing portfolio, while accelerating innovation. Kongsberg Listen demonstrates the fruits of that commitment. The system has already been integrated and extensively operated on Kongsberg’s HUGIN family of AUVs, demonstrating excellent results in commercial surveys, and is now being rolled out commercially. Next month’s Oceanology International in London marks its trade show debut as Kongsberg Listen.

Delivering confidence

“Argeo Listen was already a world leading passive electromagnetic sensing solution and this upgrade takes it to a new level,” comments Audun Berg, EVP Kongsberg Discovery. “The refinements combine to deliver clearer, more precise results with enhanced efficiency and simplicity, whatever the demands of the mission. This helps users move from data acquisition to actionable insights with increased speed and confidence. The results we’ve already been seeing onboard HUGINs gives an indication of what customers can look forward to – with proven high performance in applications spanning everything from pipeline inspection with cathodic protection evaluations, to marine mineral explorations, and geophysical surveys including buried cable positioning. Kongsberg Listen is the solution the market has been waiting for.”

Flexible approach

Users familiar with Argeo Listen will immediately recognise the significantly enhanced software environment, now tightly integrated with Kongsberg’s Blue Insight ecosystem. The upgraded suite enables streamlined, end‑to‑end workflows, delivering seamless data processing from raw electromagnetic measurements through to client‑ready information and visualisation within a common operational framework.

The flexibility of the system is also a key selling point, with ease of installation and use on an array of industry-essential platforms, from AUVs and ROVs through to towed sensing assets.

“We’re thrilled to be showcasing Kongsberg Listen for the first time in London this March,” Berg concludes. “It dovetails perfectly with the other innovations we’ll be revealing and demonstrating, proving how we never stand still in our quest to support customer ambitions and deliver practical solutions for the real operational challenges of today, and tomorrow.”

London calling

Those eager to experience the solution, and talk to experts about its unique capabilities, are invited to visit Kongsberg Discovery’s stand (D600) at Oceanology International, taking place 10-12 March at ExCel London.

The company, a global leader within ocean robotics and sensor technology, will also be using the occasion to launch further products, run live feeds from the Oslofjord CMI Protection Test Bed, hold workshops and presentations, and run live technology demonstrations on the dockside by the exhibition centre.

For further information please see https://www.kongsberg.com/discovery/news/events/oceanology-international/

 

18 Feb 26.  Indra Group, a global company at the forefront of defence, aerospace, and advanced technologies in Europe, and ELT Group, an international champion in developing and applying innovative and proprietary technologies in the use of the electromagnetic spectrum and cyberspace, have signed a strategic framework agreement designed to enhance their industrial and technological cooperation in multi-domain defence. The agreement establishes a common framework for developing and fostering a collaboration in three key areas, namely the land and space domains and Uncrewed Aerial Vehicles (UAVs). The partnership will bring together two strategic players in the European defence ecosystem, thus leveraging their complementary capabilities and aligning their technological visions and operational maturity so as to drive the reinforcing of Europe’s critical capabilities, technological sovereignty and strategic autonomy in the face of the current-day challenges. On the one hand, Indra Group will contribute its capabilities as a benchmark integrator of next- generation defence programs, and its leadership of multi-domain systems, radar technology, space, electronic warfare, and cyberdefence. On the other, ELT Group will provide its best-in-class expertise in EMSO (Electromagnetic Spectrum Operations) advanced solutions and systems designed to ensure the control, protection and exploitation of the electromagnetic spectrum in military operations, to gain information superiority and operational edges. Indra Group Executive Chairman Ángel Escribano declared that “this agreement with Elt Group will consolidate Indra’s desire to drive a more sovereign, interoperable, and multi-domain form of European defence. By bringing together our complementary capabilities in radar, space, cybersecurity, and electromagnetic spectrum operations, we’re taking a decisive step towards deploying high-value European solutions to protect our citizens and reinforce the continent’s strategic autonomy in the land, space and unmanned system domains”.

According to José Vicente de los Mozos, Indra Group’s CEO, the agreement “opens instant opportunities to submit integrated and competitive proposals to European programs, combining Indra’s experience and ELT’s expertise in advanced electronic warfare solutions, signals intelligence, spectrum monitoring, and the protection of critical communications in multi-domain environments. Mastering the electromagnetic spectrum is essential, because much of modern military technology currently depends on it. By teaming up with ELT we’ll be able to bolster our joint capabilities, move forward in a coordinated manner within the European framework, expand our portfolio in prioritized areas, and provide sovereign solutions to increase our customers’ resilience and operational superiority”.

Elt Group President and Ceo Enzo Benigni, declared that: “This agreement marks an important step forward in strengthening European industrial cooperation in the Defence sector. Indra Group and ELT have already actively collaborated in consortium programmes like the Eurofighter and share a common vision on the need to develop advanced technologies and integrated capabilities to address emerging multi-domain challenges. By combining our technological excellence, we are confident we can create value for our customers and contribute concretely to Europe’s security”

Domitilla Benigni, CEO and COO of ELT Group stated: “Distinctive capabilities such as those of Elt Group and Indra Group in sigint, EW and management of the electromagnetic spectrum are, at this historical moment, a strategic asset for Europe. The challenges we face, the technological strength outside Europe and Nato blocks push us towards valuable partnerships. This is a pillar of our strategic plan that we are pleased to share with Indra”.

By signing this agreement, Indra Group and ELT Group are taking a decisive step towards the consolidation of their strategic industrial cooperation, fostering a more robust defence ecosystem that’s capable of providing sovereign technological solutions with high added value to guarantee security and stability in an increasingly complex multi-domain global environment.

 

17 Feb 26. Global: Malware distribution raises security, data-theft risks to businesses via legitimate platforms. On 15 February, the cyber security company CTM360 reported that unnamed threat actors are exploiting legitimate infrastructure affiliated with the technology company Google to distribute two known malware variants (‘Lumma Stealer’ and ‘Ninja Browser’). The threat actors reportedly use Google forums to post technical discussions and trick users into clicking on malicious links, showcasing the continued abuse of legitimate services for malicious cyber activity. Upon infiltrating targeted systems, threat actors employ password-protected archives to ultimately deploy Lumma Stealer and Ninja Browser with the aim of monitoring user activity, exfiltrating sensitive data and executing additional commands, likely for financial profit. The execution files are and are inflated in size (with null bytes) and are distributed via shortened URLs to evade traditional security tools’ scanning thresholds and mask the true destinations, highlighting the actors’ sophistication. As a result, we assess that global entities will face increased security and data-theft risks, as threat actors have already targeted companies worldwide. (Source: Sibylline)

 

17 Feb 26. Myriota rolls out AssetHawk for global asset tracking beyond mobile coverage. Australian satellite IOT company Myriota has launched AssetHawk, a rugged, long-life asset tracker designed to deliver reliable global visibility well beyond the reach of traditional cellular networks. The new device is aimed at operators managing assets in remote and harsh environments, including mining, agriculture and heavy industry. Ready to deploy out of the box, AssetHawk can be installed in minutes and integrates with third-party visualisation and analytics platforms. AssetHawk’s compact, low-profile design supports flexible mounting including magnetic options making it suitable for rotating fleets and temporary assets. Built to withstand tough conditions, AssetHawk features an IP68-rated enclosure, allowing it to operate reliably despite dust, impact, extreme temperatures and even submersion. Using Myriota’s low-power satellite connectivity, the tracker supports scalable monitoring of trailers, containers, pallets, vehicles and unpowered assets across vast geographies. This enables operators to confirm delivery milestones, cut asset loss, improve utilisation and reduce operating costs as deployments grow. Myriota chief executive Ben Cade said many tracking initiatives falter once they move beyond pilot programs.

“Most tracking projects fail not in the lab, but at scale – when battery swaps, coverage gaps and complex integrations erode the business case,” he said. “AssetHawk is designed to flip that equation by combining global coverage, predictable multi-year battery life and straightforward integration in a single device.”

For long-term deployments, AssetHawk is engineered to minimise ongoing operational overheads. Its low-power design delivers up to 10 years of battery life using two standard AA batteries. Intelligent firmware automatically increases location update frequency when movement is detected, providing more detailed insights without compromising power efficiency. The device operates on a standards-based 3GPP Release 17 architecture and uses private data paths to protect against unauthorised access or interference, embedding security and data integrity into the platform. Developed using a TAA-compliant supply chain, AssetHawk is designed to meet the needs of government, defence and enterprise customers where resilience and trust are critical. Optional Bluetooth Low Energy capability will be available shortly, allowing the tracker to collect condition data, such as temperature and vibration from compatible sensors. AssetHawk is available now in key markets, including Australia, New Zealand, United States, Canada, Brazil and Mexico, with further international rollouts planned. Customers and partners can begin deployments using the AssetHawk QuickStart Kit, which includes mounting accessories and API integration guides. Over the past decade, Myriota has built an expanding satellite constellation, amassed a patent portfolio of more than 170 patents and raised over US$100 m (AU$141.2 m) in funding. The company provides satellite connectivity and hardware that underpin critical operations across agriculture, utilities, logistics, mining, environmental monitoring and defence, enabling assets to be tracked and monitored even in the most remote locations on Earth. (Source: Space Connect)

 

16 Feb 26. Ericsson (NASDAQ: ERIC), international defense company Leonardo, and the Italian Navy have conducted a maritime connectivity test using an Ericsson 5G Standalone system. The trial was successfully completed, enabling connectivity between naval units engaged in a day and night training scenario on the open sea. A completely self-contained end-to-end Ericsson 5G SA network – comprising Ericsson Ultra Compact Core and Ericsson Massive MIMO Radio Access Network products and solutions – was installed on board the Italian Navy’s amphibious landing ship San Giorgio, which served as the lead unit during a recent experimentation campaign. Ericsson 5G SA customer premises equipment (CPE) was installed on board a second unit of the Italian Navy – the Multi-Purpose Combat Ship Raimondo Montecuccoli. Leonardo and Ericsson collaborated in the EDF 5G COMPAD project and demonstrated its outcomes during the Italian Navy’s Operational Experimentation (OPEX) 2-25 in the Gulf of Taranto. Using Ericsson’s 5G Standalone connectivity and Leonardo’s NINE encryption solution, the trial enabled the secure, real-time exchange of classified and unclassified information between two naval units, including full situational awareness from the Combat Management System and video streams from 12 unmanned systems processed via the AI Brain platform. The OPEX validated the performance, security and resilience of 5G SA for on-board connected systems, while also showing how a unified 5G network can optimize spectrum usage compared to multiple standalone communication systems operating on unlicensed and potentially overlapping, bands with interference risks.

Patrick Johansson, Senior Vice President and Head of Ericsson Europe, Middle East and Africa, says: “The Italian Navy is seeking the best possible connectivity solutions for its related needs, and we are proud to work with them towards that goal. Italy’s central Mediterranean location, with an exclusive economic zone spanning more than 500,000 Sq Km of sea, means the Italian Navy plays a strategically important role in Europe.”

Freddie Södergren, Head of Mission Critical Networks, Ericsson, says: “This successful trial with Leonardo and the Italian Navy represents a significant milestone in our ongoing commitment to advancing defense capabilities through 5G technology. As an integral part of Ericsson’s defense portfolio, our 5G platform is designed to meet the rigorous demands of the sector. This collaboration not only demonstrates the versatility of dual-use 5G in critical operations, but also highlights how enhanced connectivity at sea can significantly strengthen naval communications and operational effectiveness.”

The same Italian Navy experimentation – officially called the Italian Navy open-sea Operational Experimentation (OPEX Task 2-25), within the framework of the Multi-Domain Operational Experimentation Committee – included several other ecosystem partners testing at sea capabilities. Ericsson also collaborated with the Italian Navy as part of 2024 NATO trials, when an end-to-end 5G SA network was installed in the Italian Naval base at Taranto. (Source: PR Newswire)

 

13 Feb 26. Cyber Update

Key points

  • Targeted sectors face elevated security and disruption risks from increased, large-scale distributed denial-of-service (DDoS)  attacks (see Sibylline Cyber Daily Analytical Update – 9 February 2026 and our technical analysis below).
  • An unnamed UK-based construction firm faces increased security and data-theft risks via new Russia-linked botnet (‘Prometei’) activity (see Sibylline Cyber Daily Analytical Update – 10 February 2026 and our technical analysis below).
  • The telecommunications sector in Singapore faces elevated security risks from a Chinese state-sponsored advanced persistent threat (APT) group (‘UNC3886’; see Sibylline Cyber Daily Analytical Update – 11 February 2026).
  • Financial and cryptocurrency firms face long-term security and financial risks from an artificial intelligence (AI)-enabled North Korean state-sponsored cyber operation (see Sibylline Cyber Daily Analytical Update – 12 February 2026).
  • Chinese state-sponsored actors will pose heightened security risks to US-based organisations via increased AI automation (see Sibylline Cyber Daily Analytical Update – 13 February 2026).

Technical analysis of weekly stories

The renowned Russia-linked botnet Prometei has targeted an unnamed UK-based construction firm in a cyber operation since at least January. It is possible that threat actors exploited default credentials to infiltrate the company’s remote desktop protocol (RDP) servers. Upon obtaining access, threat actors ran two commands (an elevated command prompt and PowerShell code) to download, decrypt and execute the main Prometei payload. Then, the malware added exceptions to the Windows firewall service and conducted initial system reconnaissance, in order to store itself stealthily within the company’s Windows server. According to the code, if the payload had not detected the first command, it would have performed a series of decoy actions before terminating, in a bid to remain obfuscated and evade sandbox detection mechanisms. Prometei subsequently established communication with command-and-control (C2) infrastructure and deployed additional malicious payloads. Although Prometei is typically used to mine cryptocurrency for financial profit, the payloads it used throughout this attack – including ‘Mimikatz’, for instance – demonstrate its interest and ability to control compromised systems remotely and to conduct data exfiltration. Furthermore, the malware changes configurations on its host server to ensure that no other threat actors can infiltrate compromised systems. Prometei also monitors failed login attempts to prevent any further compromises, highlighting the sophistication of its persistence and detection evasion capabilities.

The number of large-scale DDoS attacks increased by 40% in the fourth quarter (Q4) of 2025 compared to the third quarter (Q3) of 2025. DDoS attacks flood victims’ systems with large amounts of traffic – typically averaging between 7 and 29 terabytes per second (TBps) – with the aim of temporarily disrupting operations. According to US-based security company Cloudflare, the size of DDoS attacks in Q4 2025 also grew by over 700% compared to the largest attacks detected in late 2024, with some incidents exceeding rates of 200 m requests per second (RPS). One attack perpetrated by the ‘Aisuru/Kimwolf’ botnet reached an unprecedented 31.4 TBps, highlighting the scale of its potential impact. Reportedly, the number of DDoS attacks more than doubled in 2025, reaching a total of 47.1 m following a 236% increase between 2023 and 2025. In Q4 2025, Hong Kong became the second most targeted country, while the UK was the sixth. However, the largest increase was in DDoS attacks targeting the network layer, a 31% rise compared to Q3 2025 and 58% compared to 2024.

Non-exhaustive recommendations to mitigate these threats include:

  • Monitor devices and networks for suspicious activity.
  • Add available Indicators of Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware.
  • Adopt behaviour-based endpoint detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.

Our cyber word(s) of the week: Cryptocurrency miner

Definition: A type of software that uses computing power to verify transactions, subsequently adding new blocks to the blockchain in exchange for cryptocurrency tokens. It can be exploited by threat actors to garner illicit profit.

Example: ‘[…] UNC1069 tricked victims into downloading multiple malicious payloads onto their systems, including […] data miners to obtain cryptocurrency.’ (Source: Sibylline)

 

————————————————————————————————————————————————————————————————————————————————————————————————————————————-

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

—————————————————————————————————————————————————————————————————————————————————————————————————————————

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

February 13, 2026 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

———————————————————————————————————————————————————————————————————————————————————————————————————————————————

12 Feb 26. SATCOM in the Dessert

Iraq is big. With a land area of 435,052 square kilometres (167,974 square miles) the country has a population of over 48 m people and a population density of 111 per square kilometre (286 people per square mile). Germany is slightly smaller, but more densely populated with 240 people per square kilometre (622 people per square mile). Moreover, 70 percent of Iraq’s population live in cities. As the country’s population density suggests much of the nation has scant human habitation. Iraq’s terrain compounds this as most of the country is hot arid desert or steppe. This is the environment within which Iraq’s armed forces must operate.  As the Central Intelligence Agency’s World Fact Book articulates, the Iraqi military has its work cut out: Political violence remains a scourge. No fewer than eleven insurgent organisations are identified by the publication as operating in Iraq. Some of these groups are not only performing conventional acts of political violence such as the use of improvised explosive devices: Air attacks via the employment of suicide uninhabited aerial vehicles are used by some groups to violently further their aims. The country faces the risk of blowback from any collapse of the regime in the neighbouring Islamic Republic of Iran. Renewed hostilities between Iran on the one side, and Israel and the United States on the other could similarly spill over Iraq’s borders. Instability on the wider Arabian Peninsula poses a similar threat. Iraq’s security challenges and an unforgiving geography place a premium on robust, survivable, Beyond Line-of-Sight (BLOS) military communications to facilitate expeditious command and control. High frequency radio and Satellite Communications (SATCOM) are perfect to satisfy these BLOS requirements. Iraqi troops hunting down bad guys in the dessert, perhaps hundreds of kilometres from their headquarters, can employ HF and SATCOM to keep in touch. Both deployed troops, and their commanders, can be confident of ensuring their situational awareness via these links. The United States government is clearly aware of the importance of SATCOM to the Iraqi military. This January US lawmakers approved a foreign military sale worth $110 m to enhance Iraqi military SATCOM. Terminals will be provided along with SATCOM nodes, spare parts and technical support. This builds on previous SATCOM provision the US government made to Baghdad. Not only does the foreign military sale provide important capabilities to the Iraqi military it helps further strengthen the defence relationship between Washington DC and Baghdad. Sadly, as 2026 unfolds, the Middle East remains stricken with political instability. Helping to enhance the security of US allies in the region helps enhance the security of US strategic interests in the Middle East. Practical measures like SATCOM are important contributions to assisting allied militaries to meet domestic and regional security challenges. (Source: Armada)

 

12 Feb 26. Singing From the Same Hymn Sheet

A project has concluded in the United Kingdom (UK) evaluating methods by which the networking of radars can help improve air and maritime situational awareness, and command and control. Project SIREN (System for Integrated Radar Early Response Networking), as the initiative was dubbed, commenced in April 2024 and concluded in 2025, according to a spokesperson from the UK’s Defence Science and Technology Laboratory (DSTL). DSTL was one of the participants in the initiative. Other participants included the Royal Navy. The project was commissioned by the Defence Science and Technology department of the UK’s Ministry of Defence, the spokesperson continued.

SIREN Defined

According to reports, SIREN worked to network radars equipping air and maritime platforms. The goal of the initiative was to take the radar imagery produced by each platform and to fuse this imagery together. Combining these radar pictures will give a detailed, common recognised maritime and air picture. Users of this imagery will improve their situational awareness of the tactical and operational environment. Threats can be determined, located and engaged by several assets using a common radar picture. The work pioneered by SIREN will also help improve command and control. Reports continued that SIREN included an airborne demonstration of associated technologies during flight trials held off the east coast of Scotland in May 2025. SIREN used cloud computing to receive imagery from disparate radars and to combine this into a common recognised air and maritime picture. The work undertaken by SIREN is seen as integral to the United Kingdom’s Digital Targeting Web. DSTL declined to state which communications protocols, systems or networks were employed as part of the SIREN effort due to security and classification concerns. Radar data is typically shared using protocols like ASTERIX (All Purpose Structured Eurocontrol Surveillance Information Exchange). ASTERIX allows different radar types to share their imagery with comparative ease. The DSTL spokesperson noted that Project SIREN was commissioned to deliver several Key Driving Outcomes (KDO). The primary KDO was the integration demonstration and trial event which occurred in May 2025 discussed above. Other KDOs included detailed insight into the relative maturing of the SIREN innovations. These outcomes will be integral to developing technology roadmaps which can be used to drive the full realisation of the technologies and concepts Project SIREN analysed. The SIREN undertaking formed one part of the Royal Navy’s Fleet Air Arm Maritime Aviation Transformation Strategy, also known as MATX. The British government provided additional information on the MATX initiative during questions in the House of Commons, the UK’s lower house of parliament, in October 2025. In response to a question from Ben Obese-Jecty, member of parliament for Huntingdon, eastern England, Al Carns, parliamentary undersecretary of state for the armed forces, defined MATX as “the Royal Navy’s strategy to shift towards a digitally led crewed-uncrewed operating model”.

Future efforts

Where do SIREN’s achievements go from here? The integration of the capabilities trialled during SIREN were not assessed overall as a system-of-systems. This makes it difficult to talk about SIREN from a technology readiness level standpoint. Instead, the SIREN effort documented system and subsystem performance in a test environment and matched these results against analytical predictions. The DSTL spokesperson told Armada that the scoping of future work is currently in progress. The release of the UK’s Defence Investment Plan could provide additional details on how the innovations pioneered in SIREN could move forward. The plan will detail how the capabilities and requirements outlined in the UK’s 2025 Strategic Defence Review will be financed. Overall, the adoption of the technologies trialled as part of SIREN should help provide low cost, flexible and readily deployable capabilities to the UK defence community, the spokesperson emphasised. These capabilities will help increase combat mass, supplement and/or replace crewed capabilities while increasing operational effectiveness. These aspirations also give some important clues into some of the goals of the much-anticipated Defence Investment Plan, expected to be published by April. (Source: Armada)

 

12 Feb 26. Sprucing up Norwegian Army Comms. Norway is taking important step forward in the modernisation of its land forces tactical communications with the procurement of several new systems. On 15th January, Clavister was awarded a contract worth $31m to develop the Norwegian armed forces’ Tactical Core Network System (TCNS). Of that sum, $28m is for the system’s development with $3 m covering support and maintenance. The contract also contains options valued at an additional $1.6m. The company will provide its networking and security software is the basis for the Tactical Core Network System. A Clavister press release continued that work on the TCNS will commence by the end of the first quarter of 2026, concluding three years later. The TCNS initiative falls within the Norwegian Defence Material Agency’s (NDMA’s) Mime combat Information and Communications Technology undertaking. According to reports, Kongsberg is the prime contractor for the initiative. It will design the overall Mime architecture and perform systems integration. According to Norwegian government documents, the capabilities procured via Mime will enter service with the country’s armed forces from 2028 with this process concluding in circa 2030. Mime will be delivered in three tranches: The first runs between 2025 and 2026 and is expected to cost up to $303 m, with the second tranche following in 2027 and concluding in 2028. This latter tranche should be worth circa $253 m with the last tranche commencing and concluding in 2029. The final tranche is expected to cost $202 m.

Thor

Mime’s delivery will complement the NDMA’s Thor tactical communications procurement programme. In July 2024, the Kongsberg received a contract to provide its Thor multiband tactical radios for Norwegian Army vehicles. Kongsberg already provides several transceivers to the force including its K-Tacs, and MH600 and MV600 very high frequency (30 megahertz/MHz to 300MHz) handheld and vehicular/backpack transceivers. MH600 radios are routinely used by dismounted infantry commanders. Thor will replace the MV600 radios routinely deployed onboard Norwegian Army manoeuvre force vehicles. Beyond-line-of-sight trunk communications are facilitated by L3Harris AN/PRC-150 High Frequency (HF: three megahertz to 30MHz) radios. Satellite communications can be accessed via the force’s L3Harris AN/PRC-117F/G radio which cover frequencies of 30MHz to two gigahertz. Alongside Thor, Armada understands the NDMA will acquire a new two-channel, vehicular/backpack radio via an acquisition that could be work up to $94.5 m. These new radios will replace existing vehicular/manpack transceivers not covered by the Thor acquisition. A decision on which systems will fulfil this requirement could be made by the end of this year, and deliveries could follow between 2028 and 2030. Other future tactical radio procurements could include a new system to replace the AN/PRC-150.

TCNS defined

A spokesperson for the NDMA told Armada that the Tactical Core Network System is a “software and network logic layer that will provide our forces with user-friendly, robust connectivity across all available military and civilian communications carriers in the theatre of operations”. The latter point is particularly important: The Norwegian military plans to acquire a dedicated fifth generation (5G) communications capability known as the 5G Military Coverage Extension Network. Armada has been informed that military 5G provision will see the Norwegian government initially providing 2.3MHz of dedicated bandwidth on Norway’s 5G network. Although reserved for military use, this bandwidth will not be permanently allocated. Instead, the frequencies will be rapidly made available in times of war or crisis. Military users will access the bandwidth using a dedicated subscriber identity module card they can add to their smartphones. The 5G Military Coverage Extension Network is expected to be made available by circa 2030. The TCNS is primarily “a software solution intended to be run on tactical communications nodes already in use, as well as future hardware and virtual platforms”, the spokesperson continued. Moreover, “TCNS is intended to replace older software solutions that provide similar capabilities currently in use, while also expanding on functionality to serve future needs”. As tensions in northern Europe increase Norway’s tactical communications modernisation is the right approach at the right moment. The combination of the TCNS, new tactical radios and the 5G Mobile Coverage Extension Network overhauls the links the Norwegian Army depends on. The connectivity of the Norwegian armed forces writ large will also benefit. Furthermore, these procurements will help accelerate Norway’s implementation of NATO’s Multi Domain Operations doctrine. (Source: Armada)

 

12 Feb 26. Postmortem

Despite the debacle to replace the legacy Bowman tactical communications, and command and control system used by UK land forces, efforts are now advancing to acquire new capabilities to this end. A new, timely, in-depth report gives a detailed assessments of the failures of the UK’s efforts to replace the Bowman combined tactical communications and command and control system. In January Armada published an article entitled ‘Moving Forward’ which detailed new plans by the United Kingdom’s Ministry of Defence (MOD) to replace the Bowman tactical communications, and command and control system. Bowman is primarily used by UK land forces. The MOD’s plans to replace Bowman have a tortured history. One of the most recent efforts, known as Evolve to Open (EVO) collapsed in 2024. EVO saw General Dynamics contracted to turn the current monolithic Bowman Combat Infrastructure Platform-5.6 (BCIP-5.6) architecture into an open, modular system. The logic behind EVO was to let Bowman easily accept hardware and software improvements over the rest of its life. EVO was part of the MOD’s Project Morpheus, the overarching initiative to replace UK land forces tactical communications. Morpheus in turn is part of the MOD’s wider Land Environment Tactical Communications and Information Systems (LETACCIS) initiative. In late January a new report was published by Intelligent Consulting. This company, its own words, “provides strategic cyber security, risk management and board-level advisory services to institutions operating at the heart of Europe’s political and defence landscape”. Written by the company’s director, Suzanne Button, the publication is entitled UK Defence Tactical Communications Modernisation: The Bowman Replacement Challenge. The report examines the status of efforts to overhaul UK land forces tactical communications, the legacy of these efforts and risks that may still be faced therein.

As Ms. Button notes, the Morpheus initiative commenced in 2016 and was supposed to conclude nine years later. To date, $1.1 bn has been spent but has yielded no deliverables. EVO’s termination alone cost $445 m. As Armada’s January report made clear, new efforts to replace Bowman could cost up to $12.8 bn. UK land forces should begin to receive new tactical communications from circa 2026 with deliveries concluding in 2034. As these new systems enter service, Bowman will be progressively retired. Nonetheless, retirement of the latter is not expected to commence before 2031.

Ms. Button identifies several risks inherent in extending Bowman’s service into the 2030s: There are questions regarding the resilience of Bowman’s anti-jam waveform to contemporary and future electronic attack vectors. Similar questions surround Bowman’s resistance to cyberattack. At the hardware level, Bowman’s electronics are obsolescent. Replacement parts are expensive and require substantial testing before use, which further increases costs. Moreover, the system’s software cannot support the data-intensive links that the North Atlantic Treaty Organisation’s (NATO’s) Multi-Domain Operations depends on.

Shortcomings

Where does the blame lie for EVO’s failure? Ms. Button argues that the MOD “set unrealistic requirements, demanding not merely an open architecture but the capability to integrate electronic warfare, cyber and Multi-Domain Integration concepts that were still nascent” when the EVO contract was awarded. As Armada has previously argued, moving Bowman from a closed to open architecture was akin to turning a 1990s cellphone into a smartphone. Another issue was the EVO contract itself. Ms. Button states that the MOD contracted General Dynamics to deliver a laboratory-tested Bowman architecture, as opposed to a field-ready design. However, at the same time, the ministry “specified capabilities equivalent to full operational requirements”. Intelligent Consulting’s report claims the contract failed to produce the viable laboratory-tested Bowman architecture, let alone a field-ready version.

Risks ahead

Where does Morpheus go from here? As Armada’s January article stated, the MOD has launched a new tactical communications procurement known as the RM6393 Tactical Communications Framework. As opposed to adopting a ‘big bang’ approach to turn the Bowman architecture from a closed into an open configuration, the ministry is moving towards an “incremental, modular procurement strategy”. Ms. Button continues that the MOD’s desire to procure “fully integrated and supported systems” now suggests the acquisition of “multiple competing platforms with integration layers rather than a unified architecture”.

Replacing the entire Bowman architecture will not be easy. Intelligence Consulting’s report notes that over 50,000 transceivers must be acquired alongside their supporting infrastructure. Just taking the UK land forces vehicle fleet into account, new radios will demand new antennas, wiring, installation harnesses and software interfaces, to name just four elements. New tactical radios will need to work with a host of sovereign, NATO and allied waveforms. This latter point is essential to ensure intra- and inter-force communications. From a strategic perspective, the new radios must be ‘future proofed’ and flexible. While a revanchist Russia has put near-peer competition back on the strategic agenda, missions like counterinsurgency have not disappeared.

Ms. Button is concerned that RM6393 could see the procurement of fragmented solutions and capabilities that lack coherent integration. She warns that “evaluation and contract management will demand sophisticated government capability, precisely the weakness that undermined Morpheus’ oversight”. The existing Bowman architecture which is being evolved to BCIP 5.7 standard to allow it to remain in service until its new retirement date will have to be compatible with new RM6393 capabilities. However, “the technical interface specifications” to this end “remain undefined”. This risk is problematic as bidders will need to know how their wares can be backwards-compatible with the BCIP 5.7 architecture. Locking the specifications for RM63939 creates the danger that the development of avantgarde technologies like artificial intelligence and quantum-resistant encryption outstrip the MOD’s procured capabilities: “Freezing requirements in 2026 risks fielding obsolete systems by 2030”, warns the report.

That the MOD has launched a new effort to replace the UK’s ageing and troubled land tactical communications systems should be applauded. The ministry has no excuse not to learn lessons from the recent part, particularly given the publication of Intelligence Consulting’s report. Significant previous commentary has highlighted the failings of Bowman’s replacement, and suggested ways forward. Bowman’s age means that the MOD is fast running out of road to ensure UK land forces have the tactical communications they will need for a turbulent world. Executed correctly, Bowman’s replacement could be a textbook example of how to manage such a complex and expensive programme. Whether that becomes the case is entirely up to the MOD. (Source: Armada)

 

12 Feb 26. February Radio Roundup

Bittium and Indra are collaborating on the development of new tactical radios that are destined to equip the Spanish armed forces. These transceivers will be based on Bittium’s Tough SDR products. (Bittium) Armada’s monthly roundup of all the latest news in the military communications product, programme and operational domains.

Bittium and Indra Collaborate

As 2025 was drawing to a close, Bittium revealed it had signed a licencing agreement with Indra. According to a press release announcing the news, the licencing agreement is worth $58 m. The two companies had already concluded an agreement of intent to collaborate in July 2025. This latter agreement covered the collaboration by both companies in developing Software Defined Radio (SDR) technology. Since then, Bittium has transferred its Tough SDR product knowhow to Indra. The transfer will help Indra develop and manufacture tactical radios which will initially equip the Spanish armed forces. The press release noted that options may exist for Indra to export these transceivers to other countries in the future. According to a statement provided to Armada by Bittium, the company “is licensing its software defined radio technology that is used for the Bittium Tough SDR product family, including Bittium Tough SDR vehicular and handheld radios”. Indra’s products will be based on this technology and should yield “sovereign, high-performance handheld, vehicular, and (backpack) radios” in the coming years.

Curtiss-Wright bags new PacStar order

In late December 2025, Curtiss-Wright announced that it had been awarded a contract worth $18m to provide several of the company’s PacStar tactical communications systems to the United States Marine Corps (USMC). According to reports, the contract covers the provision of Curtiss-Wright’s PacStar 451 server, PacStar 453 GPU (Graphics Processing Unit) enhanced server and PacStar 448 ten-port, ten-gigabit ethernet switch modules. The order was made by the USMC’s Programme Executive Office for Land Systems. Roark McDonald, general manager of PacStar for Curtiss-Wright’s defence solutions division, told Armada that the recent contract “builds upon (the company’s) earlier selection as a trusted and critical supplier to the (USMC’s) Combat Data Network programme”. The company declined to provide details of how many PacStar systems it was delivering as per this recent contract, or how the USMC may use these products. Nonetheless, Mr. McDonald did add that that these systems are “designed to meet mission requirements across operational environments”. He added that the company can “scale to meet the potential future needs of the Marine Corps as well as other customers requiring battlefield networking and connectivity”. (Source: Armada)

 

11 Feb 26. Singapore hosts UK-led cyber-defence exercise for first time. Singapore has hosted ‘Defence Cyber Marvel’ for the first time, serving as the hub for the week-long UK-led multinational cyber-defence exercise that brings together more than 2,500 personnel from 70 different organisations across 29 countries from 9 to 13 February. The fifth edition of the exercise saw 36 teams combat simulated cyber threats in a realistic operational environment. Participating UK government organisations included the UK Ministry of Defence, the National Crime Agency, the Department of Work and Pensions, the Cabinet Office, and the Department of Business and Trade. Singapore’s Digital and Intelligence Service (DIS) participated alongside its British Armed Forces counterparts in a combined cyber-defence team. Now in its fifth year, ‘Defence Cyber Marvel’ has evolved from an Army Cyber Association initiative into a triservice operation led by the UK’s Cyber & Specialist Operations Command. The exercise featured several distinct scenarios, split between blue and red teams controlled from a central command point, examining how escalating pressure leads commanders and teams to make different decisions. The exercise tested participants’ ability to co-ordinate international responses against scenarios mirroring genuine cyber threats, including simulated attacks targeting critical infrastructure, government networks, and private-sector systems. Teams also gained practical experience in countering advanced persistent threat (APT) actors in an evolving digital threat landscape. In a statement issued to mark the exercise, Air Marshal Suraya Marshall, Deputy Commander of the UK’s Cyber & Specialist Operations Command, noted that cyber attacks from adversaries have become a daily threat to the UK and its allies and partners. (Source: Janes)

 

11 Feb 26. Northrop Grumman developing expeditionary IBCS variants. Northrop Grumman is developing more expeditionary variants of its Integrated Battle Command System (IBCS), beginning with an IBCS variant designed for the US Army’s Infantry Squad Vehicle (ISV). Development on an ISV IBCS variant was an internal investment by Northrop Grumman, who purchased three ISVs from GM Defense at the end of 2025 with plans to “incorporate IBCS on them”, said Jon Ferko, senior director for mission solutions and strategy at Northrop Grumman. The notion of an ISV IBCS variant initially began after programme officials saw lightweight combat vehicles beginning to proliferate across army formations. As more and more ISVs entered the army’s ranks, “we said ‘how do we make IBCS that mobile’”, Ferko said during a February briefing. The development of an ISV variant of IBCS is “really turning the current, static air-[defence] model on its head”, according to Kenn Todorov, Northrop Grumman vice-president and general manager of command-and-control (C2) and weapons integration.

“We hear our customers talk all the time talk about the need to get [lighter], the need to get off the ground and … get mobile”, Todorov said during the same briefing.

As designed, the IBCS is an Integrated Air and Missile Defense (IAMD) C2 system that will integrate current and future IAMD systems via open-architecture applications, enabling users to employ a range of sensors and weapons during combat operations. Aside from open-architecture applications, IBCS leverages common software and standard interfaces to expand potential sensor and shooter combinations via its integrated fire-control network. (Source: Janes)

 

10 Feb 26. RTX’s (NYSE: RTX) BBN Technologies has been awarded a contract by the Department of War (DoW), in partnership with the National Spectrum Consortium, to support its Advanced Spectrum Coexistence Demonstration program. This initiative addresses concerns about maintaining the operational readiness of critical national security radars when they share the same radio frequencies with commercial 5G networks. Current spectrum coexistence tools can take tens of minutes to detect interference, negotiate a new allocation, and reconfigure radios. This delay leaves both commercial 5G users and incumbent radars vulnerable to service loss or unsafe operations. In the program’s first phase, the BBN-led team will create a basic “smart spectrum manager” that can detect when a radar is operating and predict whether a 5G signal might interfere and automatically shift 5G traffic to avoid issues in seconds. In the second phase, the project will evolve from a basic working model to a more advanced prototype equipped with cutting-edge tools to ensure radar and 5G networks can share the same frequencies reliably and seamlessly. These tools will transform the system into a smart, self-managing platform that follows preset rules to automatically optimize spectrum sharing. Once developed, this platform can be deployed on operational radars and 5G systems, allowing them to work safely, securely, and efficiently side by side, with little need for human involvement.

“Lives are put at risk when a radar misses a target, whether it’s a ship navigating waters or a rescue team tracking a storm,” said Chris Vander Valk, BBN principal investigator for the effort. “Our work ensures those radars stay reliable, even as 5G frequencies become increasingly congested, so public and private shared use of the spectrum is optimized for all users.”

The multi-team effort brings together the expertise needed for a comprehensive solution:

  • Raytheon Advanced Technology will provide real radar signals and test equipment.
  • Ericsson Federal Technologies Group will contribute 5G network expertise to ensure feasibility of transition.
  • Signal Processing Technologies will share advanced interference cancellation, detection and localization techniques.
  • Federated Wireless will bring dynamic spectrum management capabilities to optimize shared spectrum usage.
  • Purdue University will deliver advanced signal processing and machine learning (ML) models for faster interference predictions.
  • Novowi will offer ML-based techniques for real-time spectrum sensing, classification and localization, as well as security analysis.

BBN will integrate these components into a system for future government use and will incorporate a risk management function to balance potential impacts on incumbent and commercial operations. The team hopes to achieve a 50% increase in usable commercial 5G capacity, a 20 dB drop in unwanted interference to radars, and a 1,000-fold improvement in 5G link quality when both systems operate side by side. To accelerate the transition, the team will also deliver a “sandbox” version of the spectrum access system that can run in the cloud or at the edge of the network, simplifying the move from testing to real-world deployment. If successful, the system will turn a longstanding “either/or” dilemma—protect the radar or grow 5G—into a “both/and” solution, expanding the nation’s digital economy while preserving national security. Work will be performed in Cambridge, Massachusetts; Marlborough, Massachusetts; Plano, Texas; Vienna, Virginia; Merrimack, New Hampshire; Arlington, Virginia; West Lafayette, Indiana; and Brookline, Massachusetts. This effort was sponsored by the U.S. Government under Other Transaction number W15QKN-21-9-5599 between the National Spectrum Consortium (NSC) and the Government. The U.S. Government is authorized to reproduce and distribute reprints for Governmental purposes notwithstanding any copyright notation herein. The views and conclusions contained herein are those of the authors and should not be interpreted as necessarily representing the official policies or endorsements, either expressed or implied, of the U.S. Government. (Source: PR Newswire)

 

10 Feb 26. Naval Group and Thales join forces for a sovereign AI in France. 

  • Naval Group, an international player in naval defence, takes a 20% stake in cortAIx France and joins its governance.
  • cortAIx, Thales’ artificial intelligence accelerator dedicated to critical systems, is enriched with cutting-edge AI engineering applied to naval defence systems, with the opening of a dedicated centre in the South of France, near Naval Group’s site.
  • This strategic partnership for France aims to quickly provide the armed forces with solutions that integrate trusted, cyber-secure, and sovereign AI, enhancing their operational superiority in the face of constantly evolving threats, while keeping humans in control.

Naval Group has invested in the capital of cortAIx France, joining Thales to address major challenges related to integrating AI into critical defence systems. This unprecedented alliance will accelerate the deployment of AI technologies and their adoption by the armed forces, while upholding algorithm sovereignty and safeguarding sensitive data. AI experts from Naval Group—particularly from the Digital Excellence Centre in Ollioules (South of France)—will strengthen the cortAIx France teams with their specialised knowledge of the naval environment. ​This joint venture aims to accelerate the industrialisation of AI solutions applied to defence systems within cortAIx.  Launched in 2024 by Thales—a global leader in advanced technologies—the cortAIx initiative brings together more than 800 AI experts across five hubs in France, the United Kingdom, Canada, Singapore, and Germany. By consolidating AI research, engineering, and industrialisation activities for critical environments, the initiative strengthens Thales’ technological leadership. Over the past decade, Thales’ substantial investment in R&D has made it Europe’s top patent filer for AI in critical systems. This expertise has enabled the integration of artificial intelligence into more than 100 Thales products, offering customers a decisive competitive edge and enhanced resilience, all while ensuring human oversight remains at the core. ​Naval Group has placed innovation at the heart of its strategy and culture to ensure the competitiveness and technological superiority of its clients at sea. By relying on new digital technologies, artificial intelligence, and augmented reality, and through its activities covering the entire lifecycle of ships, Naval Group enables its clients to maintain the scientific, technological, and industrial capabilities necessary for their sovereignty over the long term.

​“The entry of Naval Group into the capital of cortAIx France is a significant step for the company in its efforts to integrate AI into naval systems. Thanks to the pooling of resources from our two companies, this strategic partnership marks a major acceleration for the future of engineering and naval systems, in which AI plays an increasingly important role. It reflects the will to push beyond traditional boundaries of architecture and innovation, in favour of sovereign and controlled AI, which is essential to build the naval warfare of tomorrow.” — Pierre Éric Pommellet, Chairman and CEO of Naval Group.

“With Naval Group joining us, cortAIx is taking a major step forward in a collective innovation effort in France. This cooperation between two major defence players will pool expertise and accelerate the integration of sovereign AI into critical systems to respond more quickly to the challenges of the armed forces. This alliance will help them gain an edge in the face of increasingly numerous and immediate threats in an ever more complex environment, while keeping humans in control.” — Patrice Caine, Chairman and CEO of Thales.

Pierre Éric Pommellet, Chairman and CEO of Naval Group, and Patrice Caine, Chairman and CEO of Thales ©Anthony Guerra Together, Thales and Naval Group will accelerate the development of trusted AI solutions applied to critical systems in several key areas:

  • Collaborative combat, enabling operators to manage multiple systems simultaneously and assist with observation and surveillance missions.
  • Decision support systems, based on the rapid analysis of massive, strategic, tactical, and operational data.
  • Electronic warfare, to reduce the cognitive load on operators, automate signal identification, radar geolocation, and mission analysis report generation.
  • Training and simulation, to offer realistic and adaptive scenarios while optimising costs, operational preparation, and post-exercise analysis.
  • Logistics and support, using analytical rules to better anticipate operational needs.

 

09 Feb 26. GenAI.mil’s Rapid Expansion Continues With OpenAI Partnership. In just two months since deployment, the War Department’s enterprise AI platform, GenAI.mil, has surpassed one m unique users. With adoption spanning every Military Service, GenAI has cemented itself as the Department’s unified environment for secure, mission-ready AI capabilities. Building on this momentum, the Department today announced a partnership with OpenAI to integrate ChatGPT into GenAI.mil. This partnership will make OpenAI’s advanced large language models readily available to all 3 m Department personnel. ChatGPT will be made available to enhance mission execution and readiness, delivering reliable capabilities to the joint force. GenAI.mil’s rapid rise reflects a decisive cultural and technological shift, validating the Department’s commitment to being an AI-first enterprise. The platform’s proven reliability, evidenced by its 100% uptime since launch and its robust infrastructure, has established it as the trusted AI platform across the Department. The platform’s adoption is already accelerating operational tempo and sharpening the decision superiority of its users. To ensure this advantage extends to the entire joint force, comprehensive training for all Department personnel will continue, empowering them to effectively learn the platform and integrate AI capabilities into their daily workflows. This initiative is a direct execution of the War Department’s AI Acceleration Strategy released last month, and acts on the mandate of President Trump’s White House AI Action Plan. The War Department is building an AI ecosystem for speed, security, and enduring mission impact. Integrating ChatGPT into GenAI.mil marks another critical step in making frontier AI capabilities the standard for daily operations. (Source: U.S. DoD)

 

09 Feb 26. iDirect Government (iDirectGov), a leading provider of satellite communications to the military and government, today announced the successful live over-the-air point-to-point testing of a DVB-S2X waveform on the 450 Software Defined Modem (SDM) using the company’s virtualized waveform core (WCore). The test validated iDirectGov’s DVB-S2X waveform functionality, stability and interoperability in a real-world radio frequency (RF) environment. Operating on the 450SDM through the WCore, the waveform delivered reliable end-to-end performance without compromising security. The test demonstrated a 200Mbps x 200Mbps SATCOM link over a Mil-Ka-band spot beam. The 450SDM with the DVB-S2X waveform can support speeds up to 672Mbps x 672Mbps.

“iDirectGov is building a clear implementation path for developers to integrate waveforms on software-defined modems using the WCore, enabling seamless, secure and interoperable communications,” said Tim Winter, iDirectGov president. “Our recent milestone includes successful testing on mid-Earth orbit (MEO), and since WCore is waveform-independent, it is designed to operate seamlessly across geostationary (GEO), low-Earth orbit (LEO), and other multi-orbit constellations, extending our DVB-S2X capabilities for partners and end users.”

The 450SDM uses the WCore interface to securely integrate iDirectGov-hosted and third-party applications through abstraction and virtualization. The WCore can manage and orchestrate multiple waveforms —up to 16 on the 450SDM—and provides access to additional applications such as AES encryption and iDirectGov’s Communication Signal Interference Removal (CSIR) technology.

“Live RF testing confirms that our satellite modems can support diverse waveforms across multiple constellations in operational environments,” Winter said. “This flexibility is essential for defense and government customers who depend on secure, resilient and adaptable satellite communications to meet their evolving tactical communications needs.”

The iDirect Government 4-Series SDMs with the WCore deliver resiliency, security and optimized size, weight and power (SWaP) for U.S. DOD users, while enabling commercial innovation and development and in particular, where protection of intellectual property is critical.

 

10 Feb 26. Modirum Platforms has joined the Digital Defence Ecosystem Finland (DDE), strengthening the national network that accelerates secure, resilient and innovative digital defence capabilities. The membership supports Modirum Platforms’ goal of expanding its role in Europe’s dual-use and new digital defence technology landscape and contributing its deep expertise to shared national and international objectives. As a new DDE member, Modirum Platforms brings significant competencies in mission‑critical communications, real‑time situational awareness, AI‑driven analytics, advanced cybersecurity, and secure digital infrastructure design. The company’s solutions—including the development of its M Orbit multimodal situational awareness platform—enable defence and security actors to operate more effectively in increasingly complex and data‑intensive environments.

“We are committed to ensuring that organisations protecting citizens and critical infrastructure have secure and sustainable digital platforms,” says Petri Anttila, GM of Modirum Platforms. DDE provides the collaboration environment needed to scale these capabilities across Finland and the wider European market.”

Modirum Platforms’ membership follows the successful participation of its sister company, Modirum Gespi, whose network expansion within DDE has opened new market opportunities. The company sees similar potential for Modirum Platforms, particularly in areas such as protection of critical infrastructure, secure communication ecosystems, and advanced data‑driven defence technologies. DDE Finland connects companies, research organisations and public‑sector stakeholders to accelerate innovation in defence and dual‑use technologies. Modirum Platforms’ addition further strengthens the ecosystem’s capabilities and supports the broader development of Finland’s defence industry and digital resilience.

 

09 Feb 26. French shipbuilding giant Naval Group and Lithuanian space-tech company Astrolight signed a memorandum of understanding (MoU). The MoU marks the beginning of a collaboration between the two companies to test Astrolight’s POLARIS laser terminal on Naval Group’s vessels, exploring the potential for future integration of the technology. The partnership comes as Naval Group works to design a new multi-purpose vessel for the Lithuanian Navy, with plans to equip the ship with POLARIS.

“With the growing threat of electronic warfare at sea, especially in the Baltic, Europe needs ships that can operate reliably in these challenging conditions,” said Laurynas Mačiulis, CEO of Astrolight. “Our interference-resilient laser technology, already successfully tested by NATO and the Lithuanian Navy, provides a secure way to communicate in the most challenging environments. Working with the Naval Group is an exciting step towards establishing laser-based communication as a new standard in European naval security.”

Laser communication uses narrow, focused light beams that are nearly impossible to interfere with and detect. This new technology complements today’s cutting-edge technologies by mitigating risks associated with communication security, bandwidth, and data rate.

“We’re excited to have Astrolight on board for the Lithuanian Navy’s new ship,” said Simon Blanc, International Procurement and Cooperation Manager at Naval Group. “Together, we aim to provide Lithuania with a comprehensive, jam-resistant communication solution for the Baltic Sea and strengthen European defense capabilities.”

The new Multi-Purpose Offshore Patrol Vessel developed by Naval Group is designed to be versatile, capable of adapting quickly to changing mission needs. It can be used for combat, transport, launching unmanned aerial vehicles, and even converting into a floating hospital in an emergency.

The MoU between Naval Group and Astrolight was signed at the Lithuanian Maritime Defence Industry Days in Vilnius, where Naval Group, Belgium Naval & Robotics, and Exail showcased their vision for a new ship tailored to the needs of the Lithuanian Navy. The event was organized by the Lithuanian Engineering and Technology Industry Association. This year, Astrolight’s POLARIS laser terminal was successfully tested with the Lithuanian Navy, as well as at NATO’s REPMUS/Dynamic Messenger, the largest exercise focusing on maritime unmanned systems in the world, and NATO’s largest military exercise in Latvia, DiBax. There, Astrolight demonstrated jam-proof, undetectable, and high-bandwidth ship-to-ship and land-to-land laser-based communication links.

 

06 Feb 26. Cyber Update Key points.

  • An increase in the number of organisations targeted in ransomware attacks in Q4 of 2025 highlights data-theft and disruption risks to high-profile sectors (see Sibylline Cyber Daily Analytical Update – 2 February 2026).
  • The exploitation of software updates for a popular legitimate open-source editing tool (Notepad++) showcases the long-term supply-chain risks from Chinese threat actors (see Sibylline Cyber Daily Analytical Update – 3 February 2026).
  • The exploitation of a software vulnerability affecting Microsoft Office underscores increased security risks from a Russian state-sponsored group (‘APT28’; see Sibylline Cyber Daily Analytical Update – 4 February 2026).
  • The increasing abuse of IT and OT technologies underlines operational and supply-chain risks for global businesses (see Sibylline Cyber Daily Analytical Update – 5 February 2026 and our technical analysis below).
  • Government and law enforcement agencies across Southeast Asia face elevated espionage risks from a Chinese state-sponsored subgroup (‘Amaranth-Dragon’; see Sibylline Cyber Daily Analytical Update – 6 February 2026 and our technical analysis below).

Technical analysis of weekly stories

The number of cyber attacks on global operational technology (OT) environments increased significantly in 2025. According to figures released by the company Forescout, this included an 84% rise in cyber attacks that exploited OT-specific protocols – such as Modbus (57%), Ethernet/IP (22%) and BACnet (8%) – highlighting cyber threat actors’ growing ability to disrupt industrial processes. Cyber attacks on Internet-of-Things (IoT) devices also rose from 16% to 19% over 2025, while the exploitation of network infrastructure devices accounted for 19% of all observed activity in about 900 m cyber attacks, suggesting that these devices remain vulnerable and present a popular attack vector. Simultaneously, the exploitation of software vulnerabilities also surged during 2025, with a 30% year-on-year increase. Although the number of cyber attacks stemming from state-sponsored and cyber criminal groups was largely similar, cyber criminals conducted nearly six times the number of incidents in 2025 compared to 2024, underlining a significant rise in financially motivated activity. More broadly, the number of cyber attacks mounted from the top ten origin-countries in 2024 decreased by 22%, showcasing a growing global dispersion, as threat actors increasingly abuse cloud technologies. Specifically, cloud infrastructure by the technology companies Amazon and Google was abused in more than 15% of attacks, constituting an 11% increase from 2024. Elsewhere, threat actors exploited vulnerabilities in artificial intelligence (AI) platforms, profiting from the wider adoption of these technologies among businesses to improve cyber security practices.

A Chinese state-sponsored subgroup (Amaranth-Dragon) has targeted government and law enforcement agencies across Southeast Asia in a cyber espionage operation since at least March 2025. The group uses phishing emails as an initial attack vector to distribute malicious archives, which are hosted on legitimate file-sharing services, likely to enhance legitimacy. In most instances, the archive exploits a software vulnerability (CVE‑2025‑8088) to execute a custom malware loader (‘Amaranth’) onto compromised systems via side-loading techniques to evade detection. The loader then fetches a decryption key to install two additional malicious payloads: a remote access trojan (RAT; ‘TGAmaranth RAT’) and a malware framework (‘Havoc’) to establish communication with command-and-control (C2) infrastructure as well as conduct reconnaissance and intelligence collection. To increase the campaign’s stealth, TGAmaranth RAT uses anti-debugging techniques while the C2 infrastructure is configured to only respond to IP addresses located within targeted countries, highlighting the group’s sophistication and resources.

Non-exhaustive recommendations to mitigate these threats include:

  • Monitor devices and networks for suspicious activity.
  • Add available Indicators of Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware.
  • Adopt behaviour-based endpoint detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.

Our cyber word(s) of the week: Network protocol

Definition: A set of rules that dictate how data is structured, sent, received and interpreted to allow devices to communicate over a network.

Example: ‘[…] included an 84% rise in cyber attacks that exploited OT-specific protocols, highlighting cyber threat actors’ growing ability to disrupt industrial processes’ Frequency of TTPs during this monitoring period: LOW frequency, MODERATE frequency, HIGH frequency

The MITRE ATT&CK framework is a globally accessible documented collection of information detailing the malicious behaviours of cyber threat actors. It is used as the foundation for organising the processes that threat actors execute during cyber operations. It provides an encyclopaedic reference for organisations, highlighting the TTPs cyber threat actors employ in campaigns, while also providing suggestions for detecting and mitigating against specific TTPs to bolster organisations’ security mechanisms. The framework organises a threat actor’s entire operational lifecycle from reconnaissance to exfiltration and impact. (Source: Sibylline)

——————————————————————————————————————————————————————————————————————————————————————————————————————————————

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

————————————————————————————————————————————————————————————————————————————————————————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

February 6, 2026 by

Sponsored By Curtiss Wright

https://www.curtisswright.com/


———————————————————————————————————————————————————————————————————————————————————————————————————————————————

07 Feb 26. Soldiers to get new AI capable radios, headsets and tablets with futuristic sensor data.

British soldiers will be able to make faster, better decisions on the battlefield through thousands of new radios, headsets and tablets.

  • New communications systems will give commanders faster battlefield information and speed up decision-making.
  • MOD awards contract worth up to £86m to British-based SME for advanced tactical communication systems, such as radios and tablets.
  • Contract creates 12 UK defence industry jobs and builds on successful deployment in Estonia.

The contract, worth up to £86m, has been awarded to UK-based company BlackTree Technologies with the systems rapidly reducing the time it takes for soldiers to receive reconnaissance and intelligence data, boosting lethality and reducing friendly fire incidents.

Known as the Dismounted Data System (DDS), the AI capable equipment includes radios, headsets, display tablets, cables, batteries, pouches and antennas.

They will provide precise information on surroundings and intelligence, meaning increased clarity on who are enemies and who are comrades.

With all soldiers linked to the same network through this equipment, DDS will also be tailored to different scenarios, allowing troops to receive either, or a combination of, voice or visual data, maximising effectiveness across all battlefield situations.

The new systems have already been tested by soldiers on deployment in Estonia. The testing, on NATO’s eastern flank, saw the visual information element allowing soldiers to be less distracted by loud noises on the battlefield.

This follows the government committing to the largest sustained increase in defence spending since the end of the Cold War – hitting 2.6% of GDP from 2027 – supporting good jobs and growth in every corner of the nation.

Minister for Defence Readiness and Industry, Luke Pollard MP said: “The ability to receive, share and deploy accurate information is crucial to battlefield advantage, and this state-of-the-art technology will make our soldiers more integrated and more lethal.

It will begin rolling out to the British Army this year and with the work delivered by a British-based SME, shows that our move to warfighting readiness is being seized as an opportunity to make defence an engine for growth in the UK.

One of the benefits of the new systems are that they have already been tested by soldiers on deployment in Estonia. The testing, on NATO’s eastern flank, saw the visual information element allowing soldiers to be less distracted from loud noises on the battlefield.

The contract supports this government’s commitment to spend more with UK small and medium sized enterprises (SMEs), with the work creating 12 new jobs in locations in Tewkesbury, Hereford and Birmingham.

The DDS will be delivered to the Army in multiple tranches from September, with the full roll out of equipment set to be complete in 2027. An initial £46 million contact has been made by the Army with BlackTree Technologies, with options for a further £40 million.

The contract supports the Chief of the General Staff’s ambition to double the British Army’s lethality by 2027, and it backs delivery of the Strategic Defence Review to move to warfighting readiness. ”

Head of Tactical Systems, National Armaments Director Group, Brigadier Jeremy Sharpe, said:  We are delighted to be building on the successful deployment in Estonia last year and looking forward to working with BlackTree Technologies to bring this game changing capability to more of the British Army.”

BlackTree founder and Managing Director, Neil Clements-Hill said:  “BlackTree are excited to be working with the TacSys team to field this cutting-edge technology to the British Army. Waveforms ensure that the Army can operate in the most demanding environments, when nothing else works.   From initial experimentation under the DSA programme, through the delivery of Project ASGARD in 2025, and now delivering Dismounted Data System capacity, we have been working closely with the Army for many years and are very happy to continue this close relationship and help ensure that they can achieve their vision of modernising their tactical networks.”

The MOD is ramping up support for UK SMEs, with the establishment in January of the Defence Office for Small Business Growth, and the spending target of an additional £2.5 billion with UK SMEs through to May 2028, taking total annual MOD spending with SMEs to £7.5 billion.  (Source: https://www.gov.uk/)

 

 

06 Feb 26. Southeast Asia: Government, police entities face elevated Chinese-sponsored cyber espionage risks. On 4 February, the cyber security company Check Point reported that a Chinese state-sponsored subgroup (‘Amaranth-Dragon’) has targeted government and law enforcement agencies across Southeast Asia in a cyber espionage operation since at least March 2025. The group uses phishing emails as an initial attack vector to distribute malicious archives, which are hosted on legitimate file-sharing services to enhance legitimacy. In most instances, the archive exploits a software vulnerability (CVE 2025 8088) to execute a custom malware loader (‘Amaranth’) onto compromised systems. The loader then installs two additional malicious payloads (‘TGAmaranth RAT’ and ‘Havoc’) to establish communication with command-and-control (C2) infrastructure and conduct reconnaissance and intelligence collection. The group’s C2 infrastructure is configured only to respond to IP addresses located in targeted countries to increase the campaign’s stealth, highlighting Amaranth-Dragon’s sophistication and resources. Attacks reportedly flare up around relevant geopolitical events, raising security and cyber espionage risks to public sector entities in the region over the medium-to-long term. (Source: Sibylline)

 

05 Feb 26. Dependable Friends
President Donald Trump’s threats to cut the Ukrainian government off from critical intelligence his administration has hitherto been sharing is callous and grossly irresponsible. His latest threat to this effect occurred in late November 2025: Mr. Trump wanted to use the tactic to force Ukraine to accept a putative peace plan drafted by his administration. That peace plan was widely derided as a cheap imitation of the unacceptable demands made by Mr. Trump’s Russian counterpart to end the war. This was not the first occasion on which threats to end US intelligence sharing with Kyiv have been articulated. In March 2025 the Trump administration did pause some intelligence cooperation. This followed the infamous showdown between Ukraine’s President Volodymyr Zelenskyy and Mr. Trump and his vice president James ‘JD’ Vance in the Oval Office. Mr. Trump is either incapable, or unwilling, to understand that the quickest way to end the war in Ukraine is to give the latter all the military, political, economic and diplomatic support she needs to evict all Russian forces from her territory. However, Mr. Trump’s relationship, and seeming adoration of Mr. Putin, raises not only eyebrows but also serious questions, about the former’s allegiance.
Fortunately, there is some good news. As a new year dawned reports emerged that France had stepped into the breech as Ukraine’s biggest foreign intelligence supplier. Speaking on 15th January, President Emmanuel Macron said his country was now supplying two thirds of Ukraine’s foreign intelligence. This includes all-important signals intelligence that Ukrainian forces need to continue fighting the Russian military in the electromagnetic spectrum.
France’s actions are important for several reasons: They show the solidarity of Ukraine’s European allies as the war enters its fourth year. France’s intelligence provision demonstrates a reliable alternative to US-supplied materials. Moreover, European nations can clearly step into the breech when Mr. Trump’s irresponsible behaviour once more rears its head. Perhaps most importantly, France’s actions show that alternatives to US intelligence exist. The provision of the latter is frequently highlighted by some European security commentators as a key capability Europe cannot do without. By European nations working together on intelligence sharing as much as is practically possible, those same nations will help reduce overall dependences on the United States. Any step in this direction can only be a good thing; European strategic autonomy will be strengthened and the dependence on an increasingly adversarial US administration will be reduced or even eliminated. (Source: Armada)

 

05 Feb 26. Passive Aggressive?
A constituent part of the Chinese DWL002 passive radar system is seen here during a military parade in Algeria. Venezuela is another DWL002 user alongside Pakistan, the People’s Republic of China and Turkmenistan.
Armada has learnt that the People’s Republic of China supplied at least one DWL002 passive radar to the Venezuelan military. What role did this system play during Operation Absolute Resolve?
Venezuela’s DWL002 acquisition is thought to have occurred before Operation Absolute Resolve. This was the codename for the America military initiative to capture the erstwhile Venezuelan dictator President Nicolàs Maduro, and his wife Cilia Flores, on 3rd January. The operation was noteworthy for its success: Only a single helicopter from the United States Army’s 160th Special Operations Aviation Regiment was damaged by Venezuelan ground-based air defences, according to reports. The helicopter was carrying commandoes to and from their objective, Mr. Maduro’s compound in downtown Caracas. Absolute Resolve included a comprehensive Offensive Counter-Air (OCA) component. The OCA effort resulted in the strike package of circa 150 US combat aircraft supporting the operation suffering no losses.
DWL002 defined Open-source information states that the is designed to detect, locate and identify (henceforth known as process) air and maritime surface targets via their Radio Frequency (RF) signals. The vehicle-mounted system consists of three containers, each of which has a receiving antenna. By using three antennas the DWL002 determines the origin of Signals of Interest (SOIs). This is done by triangulating the line-of-bearing of each signal from each receiving antenna. The DWL002 uses two techniques to process a SOI; time difference or arrival and angle of arrival. By placing at least one of the receiving antennas on a higher point compared to the others, the DWL002 can determine a target’s angle of elevation. Alongside the three receiving antenna containers, the DWL002 has a master station from where the system is controlled. These constituent elements are networked using microwave radio links. These links use X-band (eight gigah,ertz/GHz to ten gigahertz) and Ku-band (twelve gigahertz to 18GHz) frequencies.
Alongside these techniques the DWL002 can detect disturbances to residual civilian television and radio broadcasting signals caused by their reflections from airborne targets. The system is equipped with three Yagi antennas collocated on each receiving mast for this purpose. The exploitation of residual RF radiation is intended to aid the detection of airborne targets using Emission Control (EMCON) techniques. Open sources continue that targets with a Radar Cross Section (RCS) of circa 0.01 square metres (-20 decibels-per-milliwatt/dBm) can be detected with using the Yagi antennas. Sources continue that RF signals from combat aircraft can be detected at ranges of circa 216 nautical miles/nm (400 kilometres/km). SOIs captured and processed by the DWL002 include those from airborne surveillance and fire control radars, naval surveillance radars, identification friend or foe transponders, and airborne/maritime radio communications and navigation systems. Sources continue that the DWL002 can process emissions across wavebands of 100 megahertz to 18GHz. This waveband encompasses most radar and radio communications signals emitted by combat aircraft and warships.
The DWL002 and Venezuelan air defence
Several questions surround the DWL002 and its use, or otherwise, as part of Venezuela’s Integrated Air Defence System (IADS) and accompanying Ground-Based Air Defences (GBAD) on 3rd January. Firstly, was the system activated? As a passive system, the DWL002 would be attractive to deploy as it would not make any RF emissions that US Electronic Support Measures (ESMs) could process. Even its X-band and Ku-band communications signals would be difficult to detect at range: Their highly directional nature would make them hard to detect unless an ESM’s receiving antenna was directly pointing at them.
Nonetheless, the deployment of the system, with its three masts, supporting vehicles and containers could be relatively easy to identify from reconnaissance imagery unless heavily camouflaged. It is entirely possible that Venezuela’s DWL002 systems were not deployed prior to Operation Absolute Resolve. As tensions with the United States increased in the latter half of 2025, did the Venezuelan military decide to keep the passive radars out of the field? Keeping the DWL002s in the barracks may have avoided them being targeted by US assets.
It remains unknown how many DWL002s Venezuela acquired, when these were delivered or which of Venezuela’s armed forces operates them. Armada understands that the country’s air defences are the responsibility of the Ejército Bolivariano (Bolivian Army of Venezuela) and Aviación Militar Bolivariana (Bolivian Military Aviation of Venezuela). The army is the custodian of the country’s long-range/high-altitude and medium-range/medium-altitude surface-to-air missile batteries. The country’s militia and national guard are responsible for short-range air defence. The air force performs the command and control of the country’s CODAI (Comando de Defensa Aeroespacial Integral/Integrated Airspace Defence Command). CODAI is the national IADS and integrates the country’s GBAD assets and fighters. It is assumed that the DWL002 is commanded by the Venezuelan army.
The DWL002’s manufacturer advertises that the system can detect, locate and identify aircraft with low RCSs. The US Air Force’s Lockheed Martin F-22A Raptor combat aircraft which participated in Operation Absolute Resolve has a reported RCS of between 0.0002 and 0.0005 square metres (-37dBm and -33dBm). The RCS of the Lockheed Martin F-35 Lightning series combat aircraft, another participant, is reportedly 0.0015 square metres (-28.2dBm). Perhaps these RCSs were just too small for the DWL002 to adequately process?
Assuming that the DWL002 was active on the night in question, did US EMCON discipline simply deprive the DWL002 of any RF emissions to exploit? No doubt rigid EMCON discipline was exercised by both the participating American aircraft and ships. Was the DWL002 was able to detect some US assets that had been lackadaisical regarding EMCON? Even so, what if this information was shared but never reached a CODAI command and reporting centre? Although details remain sparse it seems likely that significant jamming efforts may have been performed by US air defence suppression assets like the US Navy Boeing E/A-18G Growler aircraft participating in the operation. The Growlers could have brought their capabilities to bear to significantly degrade radio networking knitting the IADS and GBAD assets. Cyberattacks against the IADS may have been successful by rendering its digital elements unserviceable or untrustworthy.
Assessment
Operation Absolute Resolve and the participation, or otherwise, of the DWL002 illustrates some important realities: First, a system like the DWL002 is arguably only effective as an air defence asset if it is networked into wider IADS and GBAD architectures. Second, the low RCSs of platforms like the F-22A and F-35 may be too small to be detected with any accuracy or precision by a system like the DWL002. Third IADS, and accompanying GBAD elements writ large, must be as survivable as possible. Survivability depends on kinetic, electronic and cyber resilience, redundancy and survivability. Ultimately, a system like the DWL002 is but one important part of an anti-access/area denial posture, but it is in no way a panacea. (Source: Armada)

 

05 Feb 26. About Time
Russia’s IL222M Avtobaza-M signals intelligence platforms have also been exported to Iran and Armenia. The system maybe undergoing an upgrade to provide it with accurate timing systems.
New research by EW Analytics LLC reveals some serious deficiencies in the performance of Russia’s IL222M Avtobaza-M SIGINT system an upgrade programme is trying to remedy.
In May 2024, Armada published an article examining Russia’s IL222M Avtobaza-M Signals Intelligence (SIGINT) collection platform, and its use by the Islamic Republic of Iran military. Alongside Iran, the IL222M is used by the Russian and Armenian armed forces. Regular visitors to the Armada website, and readers of our monthly Electronic Warfare Newsletter, will be familiar with our regular collaborations with EW Analytics LLC. EW Analytics LLC recently shared new research the company is publishing pertaining to the IL222M. It has revealed that Russian Avtobaza-Ms may be undergoing an upgrade programme to improve their capabilities.
Avtobaza’s capabilities
As noted above, the IL222M collects SIGINT, specifically in support of Ground-Based Air Defence (GBAD). It detects, locates and identifies (henceforth referred to as processes) air threats via their electromagnetic emissions. Russian military documents seen by Armada say the IL222M processes emissions on a 200 megahertz/MHz to 18 gigahertz/GHz waveband. Avtobaza-M will process signals from Identification Friend or Foe (IFF) transponders equipping aircraft. These transponders usually squawk across wavebands of one gigahertz/GHz to 1.21GHz. Aircraft Tactical Air Navigation (TACAN) emissions from 962MHz to 1.213MHz can be processed by Avtobaza-M. Other key targets include emissions from Airborne Early Warning (AEW) aircraft.
Armada understands from official Russian language documents that the Avtobaza-M processes signals with a minimum strength of -88 decibels-per-milliwatt. Emission direction-finding is determined with between 0.4- and one-degree of accuracy. The documents continue that targets can be detected at ranges of up to 108 nautical miles (200 kilometres). Avtobaza-M shares data on target azimuth and elevation angle, radar type (pulse-Doppler and/or continuous wave) and emission waveform. Up to 60 targets can be simultaneously processed. Target detection is done using a rotating antenna making either six or twelve revolutions-per-minute. The IL222M consumes twelve kilowatts of electricity. The system’s architecture includes one processing station, and four detection and direction-finding stations. The entire system is deployed on two vehicles and networked using a two-way fibre optic link carrying data at a rate of 1.2 kilobits-per-second. Target information (target angle, azimuth and elevation) is displayed on the operator’s console. Other parameters like signal carrier frequency and pulse duration are also displayed. Avtobaza-M’s human-machine interface is highly customisable by the operator. For example, taboo frequencies can be set along with specific search sectors and/or off-limits areas.
Air targets can be processed via their emissions providing bearing information relative to the system’s location. Once this information is determined, it can be shared with GBAD assets to alert the latter on a target’s possible ingress vectors. Likewise, this data can be shared with fighter controllers to direct combat aircraft to perform interceptions.
SOI’s source
EW Analytics LLC has examined patent documents filed with the Russian government’s Federal Intellectual Property Service. The company’s analysis noted that several patent applications had been lodged with the intellectual property service in 2015, 2016 and 2025. These patent applications either explicitly pertained to the Avtobaza-M or pertained to a system with almost identical capabilities.
The most recent patent application stressed that the IL222M in its current form is unable to accurately geolocate the origin of Signals of Interest (SOIs). Specifically, the pre-upgraded system cannot use Direction Finding (DF) techniques like Time Difference of Arrival (TDOA) to determine a SOI’s point of origin. This is because prior to the recent upgrade, the Avtobaza-M did not have access to precision timing data provided by an atomic clock which is needed to perform TDOA processing, and which can be calibrated by a Global Navigation Satellite System (GNSS).
Until now, the lack of an accurate time source will have severely impeded the ability of the IL222M to support the defensive counter-air battle. It is one thing knowing that SOIs are being transmitted by hostile aircraft in range of the system. However, this information is of limited use to GBAD elements if the location of the source of these emissions cannot be determined.
EW Analytics LLC’s analysis shows that the Russian military is aware of this shortcoming and that it is being addressed. Given that Russia has domestic industrial expertise in producing atomic clocks and GNSS receivers such subsystems may not be difficult to obtain. That said, Russia remains under international sanctions because of her ongoing war against Ukraine. These sanctions could impinge the country’s ability to source components for timing systems that cannot be obtained domestically. What is interesting about the IL222M upgrade is that it highlights a gap between the advertised capabilities of a Russian EW system and current performance realities. One wonders if similar discrepancies exist in other Russian electronic warfare platforms?
(Source: Armada)

 

05 Feb 26. Testing Legion
Picogrid announced towards the end of January that the company’s Legion data platform had been employed during testing performed by the United States Army’s 1st Cavalry Division (1CD). The testing took place at the National Training Centre, Fort Irwin, California. According to a press release announcing the news, Picogrid’s Legion software integrates disparate sensor networks. In a written statement provided to Armada, the company said that Legion “provides common command and control services such as data federation, tasking of remote systems, role-based access control, tracks and correlation”. Picogrid observes that it is “faster and more cost-effective for the military to integrate sensors, effects and (uninhabited) systems, resulting in superior, real-time situational awareness, faster decision-making, and autonomous behaviour”. Legion can be used as a cloud-based service. Alternatively, it can be deployed in a containerised fashion, depending on the mission, the company’s written statement continued. Testing initiatives help the army to evaluate technologies and capabilities and thus inform future procurements. The press release said that during this latest testing effort Legion received inputs from passive radio frequency and acoustic sensors alongside radar data. Sensor feeds were fused, correlated and then shared with those parts of the 1CD’s manoeuvre force needing these data. This latest evaluation saw sensor inputs and data outputs supporting the Counter-Uninhabited Aerial Vehicle (CUAV) mission. The press releases stated that Legion “enabled triangulation and track correlation” to provide high fidelity UAV tracks. The higher the track quality provided to manoeuvre force CUAV assets, the higher the probability that hostile UAVs will be successfully intercepted. The press release concluded by saying that the company plans to continue “supporting future exercises and training events” as the army “advances its modernisation efforts” in the future.
Cirra Moves Ahead
In late January Helsing revealed it had completed testing of its Cirra Electronic Support Measure (ESM). According to reports, Cirra was integrated onto a flying testbed for evaluation. The reports continued that the ESM was able to identify radar threats in real time during testing. The ESM uses Artificial Intelligence (AI) enabled software to identify radar threats. During the tests, details of these threats were sent across a satellite communications link and validated against actual operational radar data. The development of Cirra marks a departure from some traditional Electronic Intelligence (ELINT) techniques. Traditionally, ESMs could be pre-programmed with signal parameters taken from a threat library. The parameters of detected signals are then matched against these library parameters to identify an unknown radar and/or its behaviour. By using AI enabled software and deep learning Cirra analyses a signal’s parameters to infer the radar’s intent. The company claims that Cirra is the only sovereign system able to interpret previously unencountered radar signals in real time which is available to European air forces. In November 2025, Helsing announced its selection to provide Cirra software to equip the Luftwaffe (German Air Force’s) forthcoming Eurofighter Typhoon-EK electronic warfare combat aircraft. Cirra will be integrated with the Saab Arexis EW sensor suite equipping these jets. (Source: Armada)

 

05 Feb 26. Global: Increased industrial, technological exploitation underscores operational, supply-chain risks. On 4 February, international news outlets reported that the number of cyber attacks on operational technology (OT) environments increased significantly in 2025. This increase reportedly included an 84% rise in cyber attacks that exploited OT-specific protocols, highlighting cyber threat actors’ growing ability to disrupt industrial processes. Cyber attacks on Internet-of-Things (IoT) devices also rose from 16% to 19% over 2025, suggesting that these devices remain a popular attack vector. More broadly, the number of cyber attacks mounted from the top ten origin-countries in 2024 decreased by 22%, showcasing a growing global dispersion as threat actors increasingly abuse cloud technologies. Elsewhere, threat actors exploited vulnerabilities in artificial intelligence (AI) platforms, profiting from the wider adoption of these technologies among businesses to improve cyber security practices. Consequently, we assess that this report underscores the increased security, operational and supply-chain risks from the growing abuse of both IT and OT for malicious cyber activity. (Source: Sibylline)

 

03 Feb 26. Thales Strengthens its Digital Core in Singapore
• Three Memorandums of Understanding (MoUs) signed with the Singapore Economic Development Board (EDB) during the Singapore Airshow 2026 will strengthen Thales’ capabilities in AI, cloud, edge computing, data engineering and manufacturing in Singapore.
• Thales will grow its pool of Inflight Entertainment (IFE) experts to nearly 40 in the next three years in order to support the development of its FlytEDGE IFE solution.
• Fintech and other highly regulated industries can now keep their critical data cybersecure and compliant with the latest Regulatory Technology (‘RegTech’) managed service, powered by AI and created locally by Thales.
• Smart automation solutions will drive greater efficiencies and scale in manufacturing at Thales’ largest Cyber & Digital Manufacturing Competence Centre in Singapore.
Thales has invested in its industrial and technological footprint in Singapore for over 50 years. From the establishment of Avionics activities in 1973 to the launch of cortAIx, Thales’ AI accelerator, in Singapore last year, the Group is paving the way as a deep tech company, innovating in AI, cybersecurity and quantum technologies. At the Singapore Airshow 2026, Thales announces its investments in new technologies within the following sectors:
1. Singapore becomes one of three global R&D centres for the FlytEDGE IFE solution, training close to 40 experts by 2030
Thales’ award-winning FlytEDGE is the industry’s first and only cloud-native inflight entertainment platform, helping airlines deliver extraordinary digital experiences and deepen customer connections in real-time. In Singapore, Thales established its IFE Cloud Centre of Excellence (CCoE) in 2021 to develop local expertise in cloud-based digital services. Through a new MoU, the CCoE will ramp up its expertise in cloud, data engineering and edge computing, becoming one of three global R&D centres for FlytEDGE, alongside France and the United States.
In the next three years, 40 experts will provide technical and engineering support for FlytEDGE in Singapore, as well as develop new end-to-end services that integrate cloud and edge computing, cybersecured-by-design. Edge computing will enable advanced processing, accurate data collection and insights in real time on-board, while cloud automation will reduce manual operations. FlytEDGE enables passengers to seamlessly bring their personal devices and their world into the aircraft.
2. Thales keeps companies compliant in their cloud environments with a new Regulatory Technology managed service
Developed jointly by Thales teams in Singapore and France, the unique service is a cybersecure AI-enabled solution tailored to multiple public cloud infrastructures, including AWS, Azure and Google Cloud. This solution creates a secure cloud environment (‘landing zones’) in which project teams can build and deploy applications quickly and be audit-ready for applicable regulations. This landing zone integrates controls and continuous real-time monitoring, adapted to multiple industries and jurisdictions. Thanks to its ability to continuously collect digital evidence, this solution ensures that companies across all industries remain cyber secured, audit-ready, and aligned with latest regulatory standards in their cloud journey. It is available for Fintech customers, with the aim to serve other regulated sectors like pharmaceuticals and aerospace in the coming months.
3. Boosting manufacturing capabilities with greater automation and talent development
With an annual capacity to produce over 200 m banking cards, 12 m identity cards and close to 10 m passport datapages annually, the Singapore Cybersecurity & Digital Identity Manufacturing Competence Centre is a flagship multi-product facility in Asia. The third MoU marks a new step in the site’s industrial transformation with the integration of advanced smart automation technologies like Collaborative Robots (COBOTs) and Autonomous Mobile Robots (AMRs) for transportation, loading & unloading, inspection and machine setups across the production. This transformation also fuels workforce upskilling, shifting teams toward higher-value roles. By combining human expertise with intelligent automation, the 21,000 square metre site continues to set benchmarks for performance and agility, positioning it amongst Thales’ most competitive production facilities. This factory is fully aligned with Singapore’s ambition as a global hub for advanced, high-tech manufacturing.
“We greatly value Thales’ partnership and commitment to develop a future-ready talent pool and drive transformative impact from Singapore. These investments will reinforce our position as a global innovation hub for frontier technologies, and exemplify how companies can tap on our trusted and comprehensive ecosystem to co-create new solutions in advanced manufacturing.” Zheng Jingxin, Vice President and Head of Mobility, EDB.
“These agreements illustrate Thales’ continued investment in Singapore, where we are deepening our expertise in technologies like AI, cyber, quantum and cloud, developing home-grown solutions, while transforming our industrial operations to meet customers’ expectations. The support and partnership from the EDB is pivotal and I look forward to bringing the best of our capabilities to strengthen Singapore’s cyber and digital positioning, and advance its manufacturing ambitions.” Emily Tan, Country Director and Chief Executive, Thales in Singapore.
Thales is at the Singapore Airshow on stand #G24 (Hall A) from 2-8 February.

03 Feb 26. Global: Software update exploitation shows long-term supply-chain risks from Chinese threat actors. On 2 February, international news outlets reported that unnamed Chinese state-sponsored actors hijacked legitimate software updates to conduct a cyber operation between June and December 2025. The threat actors specifically exploited a vulnerability affecting the popular open-source editing tool Notepad++ to direct update requests to malicious servers and ultimately infiltrate targeted systems. They subsequently performed reconnaissance activity likely to familiarise themselves with compromised environments and collect strategic intelligence. The attack reportedly only compromised specific users of interest, highlighting its targeted nature and contained scope. In September 2025, after losing access due to firmware updates, the threat actors restored their access to compromised systems through stolen credentials, showcasing their resilience. While the attack was detected and successfully remediated in December 2025, we assess that it illustrates the long-term security and supply chain risks stemming from Chinese state actors amid geopolitical hostilities. (Source: Sibylline)

 

02 Feb 26. Global: Increase in ransomware attacks highlight data-theft, disruption risks to high-profile sectors. On 30 January, international news outlets reported an increase in the number of organisations targeted in ransomware attacks in Q4 2025, despite a decrease in the number of active ransomware groups. The number of organisations that suffered data leaks following an infiltration and deployment of ransomware rose by 50% compared to Q3 2025, and 40% compared to Q4 2024. Threat actors partially released stolen data during the attacks to increase pressure on victims to pay the ransom, highlighting the continued use of extortion tactics. The most prolific ransomware groups during Q4 2025 included ‘Qilin’, ‘Akira’ and ‘Sinobi’; attacks by the latter increased by over 300% compared to the previous quarter. These groups continue to prioritise speed in their attacks, likely to avoid detection before they can deploy the ransomware payload. The groups’ victims span multiple high-profile organisations and sectors, including critical national infrastructure, sustaining information-theft, disruption and financial risks in the medium-to-long term. (Source: Sibylline)

 

30 Jan 26. Cyber Update
Key points
• The renowned Russian state-sponsored group ‘Sandworm’ poses elevated operational and destruction risks to Polish critical national infrastructure (CNI) (see Sibylline Cyber Daily Analytical Update – 26 January 2026).
• A North Korean state-sponsored group (‘Konni’) poses increased security risks to blockchain developers via the distribution of an artificial intelligence (AI)-assisted ‘PowerShell’ backdoor (see Sibylline Cyber Daily Analytical Update – 27 January 2026 and our technical analysis below).
• Extortion attacks by the renowned cyber criminal alliance ‘SLSH’ underscore heightened security and financial risks to large organisations (see Sibylline Cyber Daily Analytical Update – 28 January 2026).
• The distribution of an AI-generated remote access trojan (RAT; ‘PureRAT’) raises short-to-medium term security and information-theft risks for global firms (see Sibylline Cyber Daily Analytical Update – 29 January 2026).
• A spyware campaign underscores the surveillance and cyber espionage risks to Android mobile users in Pakistan (see Sibylline Cyber Daily Analytical Update – 30 January 2026 and our technical analysis below).
Technical analysis of weekly stories
A renowned North Korean state-sponsored group (Konni) is targeting cryptocurrency and blockchain software developers and engineers across the Asia-Pacific region with an artificial intelligence (AI)-generated PowerShell backdoor. Konni likely uses phishing emails to trick victims into clicking on a malicious link hosted on the communications platform Discord to deploy a ZIP archive onto compromised systems. The archive contains a PDF document likely designed to enhance legitimacy, and an LNK file responsible for downloading a malware loader. The loader subsequently deploys another decoy file alongside a CAB archive containing the main backdoor, two batch files and an executable, highlighting the multi-pronged and complex nature of this attack. These files work together to stealthily execute PowerShell, establish communication with command-and-control (C2) infrastructure and reduce forensic visibility. Upon deployment, PowerShell conducts anti-analysis and sandbox-evasion checks to ensure its obfuscation while initiating the data exfiltration process. Notably, the backdoor’s code starts with a human-readable sentence which details the script’s functionality and is divided into clearly defined logical sections; it also contains verbose comments throughout, further indicating the use of AI during the generation process. We assess that this demonstrates the increased adoption of this AI across all levels of resources and capabilities.
Unknown threat actors are targeting Android users in Pakistan in a cyber espionage and surveillance campaign. Threat actors distribute a malicious application that emulates a legitimate Android dating service available on the Google Play Store as initial attack vector. Upon execution, the application requests several user permissions to display a login overlay that prompts victims into entering hardcoded credentials. Subsequently, victims are shown an interface populated with a series of locked dating profiles which can only be accessed with an exclusive code, likely to enhance the social engineering campaign. Meanwhile, the malicious application covertly installs a spyware component (‘GhostChat’) onto compromised devices to continuously monitor and exfiltrate user information. Once the exclusive code is provided, threat actors also redirect users to a chat on the messaging platform WhatsApp which uses multiple Pakistan-based phone numbers, likely to gain further data access. We assess that this highlights the actors’ skills and resources, particularly as the campaign also comprises other sophisticated attack vectors.
Non-exhaustive recommendations to mitigate these threats include:
• Monitor devices and networks for suspicious activity.
• Add available Indicators of Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware.
• Adopt behaviour-based endpoint detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
• Conduct cyber-hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.
Our cyber word of the week: Blockchain
Definition: The system whereby cryptocurrency transactions and assets are publicly recorded across an interconnected network.
Example: ‘The campaign is reportedly targeting software developers and engineers with access to or expertise in blockchain resources […].’
(Source: Sibylline)

 

02 Feb 26. The new R&S FPL1044 from Rohde & Schwarz offers a frequency range of 10 Hz to 44 GHz. It is the first and only spectrum analyzer in this price range on the market to reach the 44 GHz milestone, drastically lowering the entry barrier for high-frequency testing.
Setting itself apart within the FPL family, the FPL1044 is the only model to offer a DC coupling option, expanding the measurable frequency range starting from as low as 10 Hz. This feature ensures maximum versatility for analyzing signals from extremely low frequencies up to the critical Ka-band. The analyzer maintains the compact, lightweight dimensions and robust design of the FPL family, ensuring portability and efficient use of bench space. It features a standard 2.92 mm male input connector for reliable high-frequency measurements.
Launching simultaneously with the R&S FPL1044 is the new R&S FPL1-K41R 40 MHz real-time spectrum analysis option. This upgrade is compatible with all frequency variants of the FPL family, empowering users across the entire product line with the ability to capture and analyze even shortest events with a Probability of Intercept (POI) time as low as 4.2 µs.
For the new R&S FPL1044, this means 40 MHz real-time frequency analysis is now available up to 44 GHz, providing a complete, affordable solution for the challenging world of high-frequency signal monitoring and component testing.
Targeting critical high-frequency applications
The frequency range of 26.5 GHz to 44 GHz is vital for the aerospace & defense industry, as well as the components industry and for research. It is used for satellite links, radar, radio navigation, earth observation and radio astronomy. Key applications for the R&S FPL1044 are testing satellite and radar systems and components, production quality control of high-frequency components (e.g., filters, amplifiers, traveling-wave tubes) as well as on-site repair and maintenance.
The R&S FPL1044 spectrum analyzer and the R&S FPL1-K41R 40 MHz real-time spectrum analysis option are available now from Rohde & Schwarz. For more information, go to: http://www.rohde-schwarz.com/product/fpl
———————————————————————————————————————————————————————————————————————————————————————————————————————————————-
Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.
Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

————————————————————————————————————————————————————————————————————————————————————————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

January 30, 2026 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

—————————————————————————————————————————————————————————————————————————————————————————————————————————————

29 Jan 26. Global: AI-generated malware raises short-to-medium term security, information-theft risks for firms. On 28 January, the cyber security companies Symantec and Carbon Black reported that unidentified threat actors are distributing an artificial intelligence (AI)-generated remote access trojan (RAT; ‘PureRAT’) to conduct an information-theft campaign. The campaign starts with phishing emails containing fake job opportunities to trick victims into downloading PureRAT onto their systems. The malware then enables threat actors to maintain prolonged persistence within compromised systems and ultimately exfiltrate sensitive data, likely for financial profit. PureRAT’s code was reportedly written using AI as it displays several AI coding signatures (such as emojis and coding instructions), illustrating the growing adoption of AI in malicious cyber activity to compensate for less proficient skillsets among threat actors. This campaign has targeted entities indiscriminately, likely to boost success rates. We assess that this campaign will raise security, phishing and information-theft risks for global entities in the short-to-medium term. (Source: Sibylline)

 

27 Jan 26. Plextek, a leading global provider of advanced engineering consultancy services, has been selected as a supplier on the £180 m Digital Decision Accelerators for Defence (DDAD) Framework, supporting the British Army’s ASGARD programme, its flagship Transformative Capability Initiative focused on battlefield decision-making and digital targeting. ASGARD aims to reinvent how land forces deliver operational decision‑support and decision‑making software through AI/ML‑enabled applications to shorten decision timelines. DDAD is the framework through which these capabilities will be procured and delivered. To support the project, Plextek brings proven capabilities in electronic warfare, radar, radio communications and navigation, combined with deep expertise in generative AI and machine learning. This means the company can rapidly prototype, test and spiral develop solutions that address real operational problems.

Brent Hudson, CEO, Plextek commented, “ASGARD addresses a fundamental operational challenge: getting the right information to decision-makers faster. Our capabilities in EW, radar, communications and AI mean we can rapidly prototype and test solutions against real battlefield requirements.”

Through the project, it will be working as a UK-sovereign SME supply chain with two specialist partners:

  • Teleplan Forsberg,  a trusted centre of excellence for Position, Navigation & Timing and situational awareness, specialising in Battlefield Management Systems and mission planning. They build assured, resilient solutions for mission-critical operators.
  • Nexor, a provider of capabilities across the Digital Targeting Web, cyber security, data fusion, and secure data transport. Their technology connects defence systems securely and makes them interoperable.

Plextek brings agility and pace to defence innovation including rapidly developing, integrating, and fielding new disruptive technologies alongside proven in‑service systems to deliver operational advantage through pace of decision making.

 

27 Jan 26. Integer unveils DIGIT mission assurance for maritime operations. DIGIT Mission Assurance Platform supports crewed and uncrewed surface and underwater vehicles. Integer Technologies has introduced its DIGIT Mission Assurance Platform, designed to support decision-making and mission planning for naval vessels operating in distributed maritime environments. DIGIT Mission Assurance Platform supports both autonomous and human-in-the-loop operations. It aims to maintain operational capability in denied, degraded, intermittent, and limited (DDIL) communication scenarios. The platform employs high-fidelity digital twins and real-time environmental forecasting, integrating live sensor inputs with physics-based models. This setup enables vessels and their operators to automatically adjust to emerging threats and maintain situational awareness for both crewed and uncrewed systems, even when standard communication lines are unavailable. DIGIT Mission Assurance Platform is compatible with a range of systems, including both surface and underwater vehicles. Integer Technologies states the system can be applied from individual ships to large groups, such as entire fleets. The company emphasises DIGIT Mission Assurance Platform’s scalability, interoperability, and adaptability for current and future naval assets like the newly announced guided missile battleship and future frigate. The initial release of the platform includes three modules tailored for different mission requirements. The “DIGIT COMMAND” module serves shore-side commanders by supplementing existing command and control structures with a decision-support layer across operational theatres.

“DIGIT CORE” provides on-board perception, planning, and resolution for individual platforms, enabling ongoing evaluation of internal systems like propulsion and power.

The “DIGIT UxV” module handles mission planning for unmanned surface and underwater vehicles, modelling the interaction between platforms and their environments to enable resilience even when communications are disrupted.

Integer Technologies co-founder and CEO Duke Hartman said: “The next generation of defence technology will be defined by software that can anticipate, not just respond. From platform-level introspection to global fleet orchestration, DIGIT provides the software architecture to win the fight.

“It represents a fundamental shift towards mission-aware technology, giving operators and autonomous systems the foresight to make confident decisions to deliver successful mission outcomes.”

Currently, DIGIT Mission Assurance Platform  is supporting US Navy UxV efforts regarding unmanned vehicles, including mission assurance work for the Metron-developed Lancet long-range multi-mission unmanned undersea vehicle. (Source: naval-technology.com)

 

27 Jan 26. Bittium has entered into a Basic Ordering Agreement (BOA) with the NATO Communications and Information Agency (NCIA). This agreement designates Bittium as a preferred supplier for the NCIA and NATO member countries, enabling accelerated procurement of Bittium’s secure mobile communications devices, software, and accessories. The agreement covers Commercial Off-The-Shelf (COTS) solutions that NATO uses to maintain its technological edge and respond to cyber threats.

“Bittium is a trusted forerunner and supplier of defense and security technologies, and the agreement with NATO further streamlines the ability of member countries to procure our high-quality security solutions. We are very proud of this milestone, as it enables us to support NATO and its member nations in advancing cybersecurity and critical capabilities”, said Tommi Kangas, Senior Vice President of Bittium’s Defense & Security business segment.

Solutions offered under the agreement include secure Bittium Tough Mobile™ smartphones as well as quantum-safe Bittium SafeMove® and Bittium Secure Call™ software solutions that provide encrypted connectivity, secure communication, and comprehensive device and application management. The multi-platform software solutions support Android™, iOS, and Microsoft Windows to enable organization-wide secure communications. The Bittium SafeMove® Mobile VPN encryption solution also supports hybrid networking and ensures secure interoperability across tactical networks and 4G/5G mobile networks. Bittium’s solutions are used globally by over 75,000 users and enable absolute security for mitigating the ever-increasing cyber threats faced by government agencies, defense forces, law enforcement, and critical infrastructure organizations. Bittium Tough Mobile™ 2 C is an information security solution approved for NATO Restricted-level use and secures mobile communications between government officials and authorities. Both the Tough Mobile 2 C and the recently launched Bittium Tough Mobile 3 smartphone eliminate the need of having separate devices for personal and professional use, which streamlines workflows without compromising data boundaries. This is enabled by a unique dual operating system, meaning two completely isolated, hardened environments. Users can easily switch between the environments via dual-boot, ensuring total separation of personal and professional use.

 

26 Jan 26. Asia-Pacific: AI-assisted backdoor points to elevated security risks to blockchain developers, firms. On 26 January, international media outlets reported that the North Korean state-sponsored group ‘Konni’ is conducting a phishing campaign to deploy an artificial intelligence (AI)-generated backdoor (‘PowerShell’). The campaign is reportedly targeting software developers and engineers with access to or expertise in blockchain resources and infrastructure in the Asia-Pacific region including Australia, India and Japan. This indicates an expansion in Konni’s targeted areas, increasing security risks to firms outside of Europe, Russia and South Korea. The PowerShell backdoor appears to have used AI in its development due to its unusually polished structure that clearly describes the script’s functionality – not a typical feature of threat-actor-made PowerShell implants. This underscores a growing trend by threat actors to employ AI in cyber operations to improve or develop new malware. This campaign also indicates a shift in Konni’s behaviour towards prioritising establishing a foothold in development environments rather than targeting individual end-users. Consequently, blockchain developers and related firms face increased security risks in the medium-to-long term.  (Source: Sibylline)

 

27 Jan 26. Kognitiv Spark: Secure Augmented Reality for Defence Operations.

With UKDI-DASA funding, Kognitiv Spark deployed a cyber secure augmented reality technology that enables remote expert support for military operations.

  • The Defence and Security Accelerator, part of UK Defence Innovation (UKDI-DASA), funded Kognitiv Spark through the DTEP programme to deploy their augmented reality remote support solution on secure defence infrastructure.
  • The technology enables users out in the field, such as technicians and engineers, to connect with remote experts worldwide using AR headsets, sharing real-time audio-visual feeds and PDF documents, capturing photos with annotations.
  • UKDI-DASA funding helped catalyse partnerships with major defence organisations including Rheinmetall MAN Military Vehicles (RMMV), Rheinmetall BAE Systems Land (RBSL) and MSI Defence Systems, and follow-on Army Innovation projects exploring AR as a core military capability.

Augmented Reality for Defence

Picture this scenario: A military technician in Estonia is working on a critical piece of equipment that’s malfunctioning. The specialist with the expertise to fix it is 1,000 miles away in the UK. In the past, this could mean costly delays, expensive travel, or potentially mission-critical equipment remaining offline for days.

Now, with Kognitiv Spark’s augmented reality solution, RemoteSpark, the technician can put on an augmented reality headset and instantly connect with a remote expert. The specialist can see exactly what the technician sees, annotate their shared view in real-time, overlay diagrams, and guide them through the repair step-by-step—all whilst maintaining military-grade security. In a scenario such as this, the equipment can be back online within hours rather than weeks.

This is just one use case that Kognitiv Spark, a small technology company, has created for defence operations worldwide with UKDI-DASA funding support.

Introducing Kognitiv Spark

Kognitiv Spark was founded in 2016 with a clear mission: to enhance worker capabilities through augmented reality remote support, without replacing human expertise. The company, now employing 25 people across the UK, US and Canada, specialises in connecting field workers with remote experts using heads-up, hands-free AR technology.

What sets Kognitiv Spark apart is their “cybersecurity and defence at heart” approach. Adam Clay, Managing Director, UK & EMEA, Kognitiv Spark explains: “Our co-founder Ryan Groom started a cybersecurity company that ended up specialising in augmented reality. Coming from that genesis meant the core product has always been agnostic to network and able to have adaptability to work within the constraints of certain networks.”

This foundation proved crucial for defence applications, where security requirements are paramount.

From concept to deployment with UKDI-DASA support

Kognitiv Spark’s relationship with UKDI-DASA began through the Defence Technology Exploitation Programme (DTEP) in 2022. The SME understood that the AR space had matured, and support for defence uses was growing with the potential to address challenges within the support chain and to help deliver operational efficiencies.

“The DTEP project was twofold,” explains Clay. “In addition to developing the technology, it was also about exposing secure AR to more users across the services and exploring use cases, whilst focusing on secure by design. If this is going to be adopted as a core capability in defence, it needs to adhere to MOD’s security requirements.”

Real-world impact: from workshops to battlefields

The AR technology can work across diverse environments – from workshops and power plants to military field operations. Using AR headsets or smart glasses, defence users can connect with experts anywhere in the world, sharing real-time video/audio feeds whilst simultaneously viewing technical documentation, schematics and receiving guidance from remote workers anywhere in the world.

Their AR solution offers real-time access to support and training, better utilising personnel and digital assets backed up by specialist advice, both deployed and across the Defence Support Network, enabling operational equipment to return to service more rapidly.

Crucially, the solution operates on low-bandwidth connectivity, making it viable in challenging operational environments where network capacity is limited.

Prior to their UKDI-DASA project, Kognitiv Spark had already conducted early work with individual army units, receiving positive feedback from user groups interested in the capabilities of AR and remote support.

However, UKDI-DASA funding enabled greater exposure across defence services, with traction in land and field army applications.

“We’ve been able to expose and receive feedback on our technology from a wide array of Army stakeholders. Not only has it given them time to understand the technology, but it’s also provided them with ideas on how it can be directly used and how to deploy it to solve their challenges,” explains Clay. “Additionally, for Kognitiv Spark, as a small organisation, being able to take on feedback and grow alongside the project has been hugely enabling.”

This exposure led to visibility with users and has generated significant commercial outcomes and partnerships with major defence original equipment manufacturers (OEMs) who recognised the same support challenges their military customers face.

Kognitiv Spark now works with Rheinmetall BAE Systems Land (RBSL), Rheinmetall MAN Military Vehicles (RMMV), and MSI Defence Systems amongst others, providing remote support capabilities that improve efficiency and knowledge sharing across their operations.

DTEP: Combining the expertise of both defence primes and SMEs

The DTEP project enabled Kognitiv Spark to tackle their most significant technical challenge: deploying their SparkOps application on secure sovereign defence cloud infrastructure.

Working with their DTEP higher-tier supplier Serco, Kognitiv Spark was introduced to Prolinx, an SME specialising in secure sovereign cloud solutions for government and MOD.

“Prolinx had a replica sandbox environment of a MOD secure network and experience of the secure by design process,” notes Clay. “We’re now very proud to say that our system has deployed on secure sovereign defence cloud.”

Pioneering the future of military capability

The DTEP project catalysed two additional Army Innovation initiatives that Kognitiv Spark has completed in parallel. The first, ARPAI (Augmented Reality Pan Army Implementation Plan), examined army-level implementation of the AR tech. This work also led to PJ ESART (Project Equipment Support using Augmented Reality), which explores additional support applications.

The UKDI-DASA experience

“This was our first rodeo as an SME dealing with this sort of framework and funding,” reflects Clay. “It had an administration burden in terms of recording and reporting as would be expected for a project of this nature. But the support from our Project Monitoring Officer and others at UKDI-DASA and Dstl has been superb.”

“For innovation to succeed in defence, you need three things aligned: user demand, senior leaders who will champion it, and a sustained funding line. Without all three connected, even excellent projects hit a cliff edge and can’t continue.”

The UKDI-DASA funding allowed us to do this work and test out a theory. Nearly two years on, we’ve emerged and proved it can be done. Thanks to UKDI-DASA and the DTEP project, we’ve had greater exposure within MOD, greater usage within the defence supply chain, and deployment within an environment that MOD can use.

Dual-use innovation for UK defence and industry

Kognitiv Spark exemplifies how UKDI-DASA investment strengthens both defence capabilities and UK technology innovation. Their journey demonstrates how small, agile companies can develop transformative technologies when given strategic support to overcome technical and commercial barriers.

As the company continues developing relationships across the defence ecosystem and proving their technology’s value as potential core military capability, they represent the innovation goals UKDI-DASA funding is designed to nurture – turning great ideas into reality whilst building sustainable UK businesses. (Source: https://www.gov.uk/)

 

26 Jan 26. Calian Group Ltd. (TSX: CGY), a mission-critical solutions company focused on defence, space, healthcare and other strategic critical infrastructure sectors, announces a strategic initiative to help accelerate the development and deployment of sovereign C5ISRT capabilities through Calian VENTURES (VENTURES), Canada’s defence innovation orchestrator.  As Canada places increasing priority on sovereign defence capability, operational readiness and long-term resilience, Calian will advance technology collaboration and mobilize funding to accelerate capability development across Canada. Funding will be drawn from multiple sources, including capital investment from VENTURES, co-development of new intellectual property from Calian alongside multiple Canadian small to mid-size enterprise (SMEs), contributions from regional investment agencies, and federal programs. The first initiative will establish a national, sea-to-sea-to-sea network of regional development labs to accelerate the testing, validation and scaling of defence technologies developed through VENTURES. These labs will convene small and medium-sized enterprises, the Canadian Armed Forces, NATO, government, academia, and industry partners to advance innovative, interoperable solutions from concept to operational capability. By providing VENTURES partners and defence primes with access to shared infrastructure, technical expertise and integration pathways, Calian and its partners will help Canada move faster toward its defence objectives—strengthening Arctic sovereignty, enhancing national security at scale, and modernizing the Canadian Armed Forces.

“Canada is facing a fundamentally different security environment and meeting the moment requires sustained investment, trusted partners and long-term commitment,” said Patrick Houston, Chief Executive Officer, Calian. “This investment reflects Calian’s confidence in Canada’s defence future and our responsibility as a Canadian company to help strengthen Canadian sovereignty as well as help build the Canadian defence industrial base.”

What is C5ISRT

C5ISRT—Command, Control, Communications, Computers, Cyber, Intelligence, Surveillance, Reconnaissance and Targeting—represents the modern defence architecture required to operate effectively in today’s contested, multi-domain environment. Unlike legacy C4ISR approaches, C5ISRT integrates cyber and targeting as core operational functions, enabling faster decision-making, tighter sensor-to-effect integration, and resilient operations across land, sea, air, space and cyber.

“C5ISRT is not a future concept. It is an operational requirement of today’s battlefield and for Canada to own a truly sovereign capability,” said Chris Pogue, President, Defence and Space, Calian. “Mission success now depends on integrating data, systems and people across domains and the ability to sense, decide and act with speed and precision.  Through this investment we are scaling the environments, integration pathways, and partnerships needed to turn innovation into operational capability, while ensuring Canada retains trusted, sovereign control of its defence data and systems.”

Calian’s Role as Canada’s C5ISRT Leader

With more than 40 years supporting defence customers, Calian brings unmatched experience in integrating people, systems and operations across domains. Our capabilities span synthetic training, cybersecurity, space and satellite communications, systems engineering and secure-by-design C5ISRT architectures supported by Canadian-based manufacturing of GNSS and antenna manufacturing that strengthens sovereign supply and long-term sustainment of Canadian defence capabilities.

Calian’s workforce—consisting of hundreds of engineers and software developers, including many veterans who understand the operational realities of modern conflict—has delivered mission-critical capabilities where failure is not an option. That experience, combined with VENTURES’ innovation-orchestration model, is what positions Calian to lead Canada’s evolution from legacy defence systems to a fully integrated C5ISRT future.

 

26 Jan 26. Global: Long-term cyber operation sustains high security risks for developers, technology firms. On 21 January, the technology company Jamf reported that North Korean state-sponsored cyber threat actors are targeting macOS software developers in an ongoing operation. The threat actors likely use social engineering techniques to trick victims into accessing actor-made code repositories to ultimately infiltrate targeted systems. Victims are then prompted to trust the repository’s author which then covertly deploys a JavaScript payload by abusing Visual Studio (VS) code configuration files. The payload conducts initial system reconnaissance before establishing communication with command-and-control (C2) infrastructure, effectively operating as a backdoor. The themes used during the initial phase of the attack indicate that this is the latest iteration of North Korea’s long-term job-recruitment-themed cyber campaign, which aims to steal sensitive information to bolster Pyongyang’s security posture. Consequently, we assess that North Korean state-sponsored threat actors will continue to pose heightened security and information-theft risks to global software developers and technology firms amid geopolitical hostilities. (Source: Sibylline)

 

26 Jan 26, Trident Solutions (“Trident”), a defense electronics platform backed by ATL Partners, today announced the launch of its Wolf Multi-Domain Communications portfolio. This portfolio unifies mission-critical communications offerings under a single, purpose-built brand while introducing a new product designed to meet emerging operational requirements with reduced soldier cognitive load. The Wolf portfolio reflects Trident’s focus on delivering secure, resilient, and agile communications offerings for operations across air, land and sea domains. Built for contested, denied, and austere environments, Wolf products are engineered to provide assured connectivity, interoperability, and rapid deployment in support of joint and coalition operations.

“The launch of Wolf represents both a unification of proven capabilities and the introduction of new innovation,” said James Yates, Chief Growth and Strategy Officer. “As operational demands continue to evolve, Wolf products will provide a scalable communications foundation designed to operate reliably across domains and alongside allied and partner forces.”

Wolf Portfolio Overview

The Wolf portfolio currently consists of three products, including two rebranded, fielded systems and one newly introduced capability:

  • Wolf Mini (formerly Mini-Secure Communications Controller)

A lightweight, plug-and-play tactical voice bridge that provides audio cross connection capability in a handheld form-factor.  Fully ruggedized and certified to US Military standards, the Wolf Mini provides interoperability of radios ranging from commercial cell phones to legacy and modern military radios, public safety radios, Voice-Over-IP (VoIP), push-to-talk and full duplex radios.

  • Wolf Access Point (formerly Shipboard Wireless Access Point)

A ruggedized shipboard wireless access point that delivers the performance, coverage, reliability and security required to enable secure wireless environments for DoD and Federal Government secure applications. Ruggedized and tested to withstand the rigors of the shipboard environment, The Wolf Access Point provides simultaneous support for high-speed wireless data, voice and video services.

  • Wolf Talk (New Product)

A small form-factor, plug and play intercom and radio bridging device for use in mobile command centers and with advance teams.  Supporting chassis-mountable and stand-alone operation, Wolf Talk allows operators to monitor dedicated talk groups and immediately connect with all other operators on the dedicated intercom.

As part of the launch, Wolf products feature a new visual identity and naming convention aligned with their operational role, while preserving continuity in performance, technical support, and existing customer programs. Current customers will experience no disruption to ongoing contracts, sustainment, or roadmap commitments.

Follow future updates on Trident’s products and partnerships at www.tridsys.com.

About Trident Solutions

Trident Solutions (Trident) is a leading defense electronics platform providing mission-ready spaceflight units, integrated processing systems, command and control solutions, and precision optical sensors. With deep expertise across multiple domains—space, air, land, and sea—Trident delivers agile, high-performance systems purpose-built for the most demanding national security applications. Trident maintains AS9100-certified quality management systems and is appraised at CMMI Level 3. Learn more at www.tridsys.com. (Source: PR Newswire)

 

26 Jan 26. Cyber Update

Key points

  • US-based critical national infrastructure (CNI) sectors face heightened security and disruption risks from a suspected Chinese state-sponsored group (‘UAT-8837’; see Sibylline Cyber Daily Analytical Update – 19 January 2026).
  • Ongoing cyber attacks are sustaining CNI security and disruption risks from pro-Russia hacktivist groups (see Sibylline Cyber Daily Analytical Update – 20 January 2026 and our technical analysis below).
  • A new, highly sophisticated malware family (‘PDFSider’) poses increased security risks for global organisations (see Sibylline Cyber Daily Analytical Update – 21 January 2026).
  • A long-term cyber operation conducted by North Korean state-sponsored actors is sustaining security risks for developers and technology firms (see Sibylline Cyber Daily Analytical Update – 22 January 2026 and our technical analysis below).
  • The rapid exploitation of software vulnerabilities poses high security risks for global organisations in the long term (see Sibylline Cyber Daily Analytical Update – 23 January 2026).

Technical analysis of weekly stories

A suspected Chinese state-sponsored group (UAT-8837) has targeted US-based CNI in a cyber operation since at least 2025. The group exploits known software vulnerabilities and/or stolen credentials to infiltrate targeted systems. Additionally, the tactics and infrastructure associated with UAT-8837 were previously used to exploit a zero-day vulnerability (CVE-2025-53690), which suggests that the group’s arsenal is possibly also capable of identifying zero-day vulnerabilities. Upon obtaining access, UAT-8837 performs initial system reconnaissance to map active directory (AD) environments and to steal internal user credentials, likely in an effort to facilitate lateral movement and privilege escalation. This phase comprises the deployment of several known tools for AD reconnaissance, such as ‘SharpHound’ and ‘Certipy’, as well as other living-off-the-land (LotL) tools and a network tunnelling payload (‘Earthworm’) to expose internal endpoints. Subsequently, the group disables several security mechanisms to evade detection and establishes communication with command-and-control (C2) infrastructure, prolonging persistence and executing malicious code. Various tools used during this next phase include ‘GoTokenTheft’ (to steal an access token), ‘DWAgent’ (for remote administration) and ‘GoExec’ (for remote execution). UAT-8837’s operations reportedly started in 2025 with sporadic attacks throughout the year, highlighting its likely goal of securing long-term access to US CNI for potential future disruption.

North Korean state-sponsored cyber threat actors are targeting macOS developers in an ongoing operation. The threat actors likely use social engineering techniques to trick victims into accessing threat actor-made code repositories to infiltrate targeted systems. The repositories can be downloaded from the popular platform GitHub, which – in combination with the themes used in this initial phase of the attack – indicate that this is the latest iteration of North Korea’s long-term job-recruitment-themed cyber campaign. The repositories require victims to use Visual Studio (VS) Code for configuration and to trust the repositories’ author, as well as to deploy a JavaScript payload covertly. The payload effectively operates as a backdoor, conducting initial system reconnaissance and establishing persistent communication with C2 infrastructure. It also retrieves instructions a few minutes after the initial infection to set up additional payloads for other malicious activities, which likely include stealing sensitive information to bolster Pyongyang’s security posture.

Non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity.
  • Add available Indicators of Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware.
  • Adopt behaviour-based endpoint detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.

Our cyber word(s) of the week: Dynamic Link Library (DLL)

Definition: A shared library in the Microsoft Windows operating system that can contain executable code (functions), data and resources. It can be exploited by threat actors to deploy malware while blending in with legitimate traffic.

Example: ‘This archive contains the PDFSider payload, which is deployed directly into a system’s memory via Dynamic Link Library (DLL) sideloading techniques […]’

Frequency of TTPs during this monitoring period: LOW frequency, MODERATE frequency, HIGH frequency

The MITRE ATT&CK framework is a globally accessible documented collection of information detailing the malicious behaviours of cyber threat actors. It is used as the foundation for organising the processes that threat actors execute during cyber operations. It provides an encyclopaedic reference for organisations, highlighting the TTPs cyber threat actors employ in campaigns, while also providing suggestions for detecting and mitigating against specific TTPs to bolster organisations’ security mechanisms. The framework organises a threat actor’s entire operational lifecycle from reconnaissance to exfiltration and impact.

(Source: Sibylline)

 

26 Jan 26.  Global: Rapid vulnerability exploitation will pose high, long-term security risks to businesses. On 21 January, cyber security company VulnCheck reported that the percentage of software vulnerabilities exploited before or on the day of their public disclosure increased from 23.6% in 2024 to 28.9% in 2025. This showcases threat actors’ increased ability to identify and exploit software vulnerabilities rapidly. VulnCheck identified approximately 884 vulnerabilities abused in cyber operations in 2025 (a rise from 2024). These operations include the exploitation of zero-day vulnerabilities in third-party services in October 2025 and a November 2025 attack targeting the National Health Service (NHS), highlighting data-theft risks to organisations (see Sibylline Cyber Monthly Review – October 2025). Additionally, network edge devices experienced the highest rate of exploitation of both new and old software vulnerabilities, highlighting the importance of patch management policies to protect systems. Software vulnerabilities are a sophisticated attack vector; they enable threat actors to infiltrate targeted systems and to conduct a wide range of malicious activity. We assess that software vulnerabilities will pose high long-term security risks to global organisations, as threat actors continue to develop their capabilities.. (Source: Sibylline)

 

26 Jan 26. Poland: Russian state-sponsored threat actor poses elevated operational, destruction risks to CNI . On 23 January, cyber security company ESET reported that the Russian state-sponsored group ‘Sandworm’ was responsible for a cyber attack on Poland’s energy infrastructure on 29 and 30 December 2025. The attack attempted to deploy the date-wiper malware ‘DynoWiper’ against two combined heat and power plants, as well as a management system for renewable electricity from wind and solar farms, pointing to the group’s destructive intent against the country’s energy sector. While the attack was reportedly not successful in causing disruption, it highlights Sandworm’s intent and capability to cause disruption and damage operational processes. This attack is allegedly the largest attempted cyber attack on Poland in recent years. We assess that this highlights the elevated long-term security and operational risks to Polish and wider European critical national infrastructure (CNI) as Russian state-sponsored threat actors continue to adapt their cyber strategy amid increasingly strained relations between Russia and the West. (Source: Sibylline)

 

22 Jan 26. Silvus Technologies Unveils StreamCaster MINI 5200 Tactical MANET Radio. Silvus Technologies (Silvus), a Motorola Solutions  company and a global leader in advanced tactical wireless communications, has announced the StreamCaster MINI 5200 (SM5200). It is Silvus’ smallest, fully-featured mobile ad hoc network (MANET) radio, designed to equip ground forces with next-generation mesh networking to securely share voice, video and data without the need for dedicated infrastructure. The ultra-compact 182-gram SM5200 features the high-speed power of a two-by-two MIMO radio, with up to two watts of output power and 100 Mbps of data throughput, providing the secure, reliable connection teams need to stay synced during critical missions. Powered by Silvus’ battle-proven MN-MIMO waveform, StreamCaster MANET radios create a self-forming and adaptive mesh network capable of delivering real-time data, including high-fidelity video across hundreds of nodes, even in the most contested environments.

“The SM5200 is a significant leap forward in providing communications flexibility at the tactical edge,” said Neema Daneshvar, vice president of Product at Silvus Technologies. “It is the smallest radio we’ve ever built that delivers full-size StreamCaster MANET radio capabilities, helping operators gain maximum mobility without sacrificing the range or throughput they depend on.”

The SM5200 eliminates bulky, cable-heavy setups, enhancing operators’ freedom of movement, whether used alone or integrated into tactical networking systems like the StreamCaster NEXUS. Its next-generation audio circuitry delivers advanced voice quality and its push-to-talk (PTT) function allows users to listen to two talk groups simultaneously. The SM5200’s dedicated radio over internet protocol (RoIP) interface seamlessly integrates land mobile radio (LMR) systems into the Silvus mesh digital networks to keep the entire team connected across devices.

The SM5200 supports consistent field uptime with diverse “plug-and-play” power options, from vehicle supplies to wearable batteries, while providing rapid connectivity for cameras, sensors and end-user devices via Ethernet, USB and RS-232 ports. The SM5200 is housed in a ruggedized, IP68-rated waterproof enclosure to perform in punishing environments where standard equipment often fails.

The SM5200 features AES256 and FIPS 140-3 encryption to protect sensitive data. With access to Spectrum Dominance 2.0, an ever-expanding licensable suite of low probability of intercept/low probability of detection, anti-jam electronic warfare resiliency and advanced threat protection capabilities, operators can achieve decision dominance and radio frequency spectrum overmatch even under electronic attack.

About Silvus Technologies, a Motorola Solutions company

As a leading provider of advanced MANET and MIMO communications systems, Silvus Technologies is reshaping mesh network technology for mission-critical applications on the ground, in the air and at sea. Its battle-proven StreamCaster family of MANET radios and proprietary MN-MIMO waveform provides the vital communications link for defense, law enforcement and public safety agencies in the toughest operational environments around the world. Developed by a team of top PhD scientists and design engineers, Silvus Technologies continues to innovate communications technology for the tactical edge with unmatched range, data throughput, EW resiliency and scalability. A Motorola Solutions company, Silvus Technologies is headquartered in Los Angeles.

About Motorola Solutions | Solving for safer

Safety and security are at the heart of everything we do at Motorola Solutions. We build and connect technologies to help protect people, property and places. Our solutions foster the collaboration that’s critical for safer communities, safer schools, safer hospitals, safer businesses, and ultimately, safer nations. (Source: UAS VISION)

——————————————————————————————————————————————————————————————————————————————————————————————————————————————–

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

———————————————————————————————————————————————————————————————————————————————————————————————————————————

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

January 24, 2026 by

Sponsored By Curtiss Wright

 

https://www.curtisswright.com/

———————————————————————————————————————————————————————————————————————————————————————————————————————————-

21 Jan 26.  Thales – Why computing power, as much as platform design, determines

DigitalCrew® AI-powered classification capabilities – Thales

Modern AI classification is the bedrock for the latest mission support tools and second order effects that are set to transform battlefield effectiveness and lethality – capabilities Stewart, Head of Digital Strategy at Thales, referenced in his article last year ahead of IAVC 2025. These algorithms are proven and deployable today.

Yet most armoured platforms cannot run them effectively – not because their sensors are not capable, not because the algorithms are not mature, but because the computer architecture sitting between them was designed for a different technological era. “The limiting factor for deploying AI at scale isn’t the platform itself, but the processing hardware sitting inside it,” says Stewart, Head of Digital Strategy at Thales.

Why processing hardware matters now

Achieving the Chief of the General Staff’s goal to triple Army lethality by 2030 requires us to think differently about how we deploy capability to the frontline

DigitalCrew capabilities are already deployed and delivering operational value. Utilising traditional mathematical algorithms for detection, tracking, and image fusion, they are running perfectly well on current processing hardware. These building blocks are proven on platforms today, helping crews detect and track potential threats across complex battlespaces. This is not the case for AI classification and the second-order effects that flow from it.

What we are talking about is not incremental improvement – it is unlocking entirely new classes of capability from sensors already installed on platforms. These second-order effects transform raw data into a step-change in tactical advantage. But delivering that kind of capability leap demands significant increases in processing power.

The structural challenge: procurement vs technology evolution

Defence procurement, in its current form, locks in technical specifications years before fielding. Platform development cycles can span 15 years or more to move from a design to frontline service. This timeline works perfectly well for components with multi-decade service lives – such as hull armour, powertrains, and optical systems. These remain capable throughout a platform’s operational lifetime.

But GPU evolution follows a completely different clock. New GPU architectures emerge every three to five years, and some manufacturers will cease support on similar timelines, making it increasingly difficult to develop algorithms for older hardware. The result is an unavoidable gap between processing hardware specification during the design phase and algorithm capability at fielding.

Commercial sectors have adapted to this reality, operating on three-to-five-year hardware refresh cycles to keep pace with technology evolution. Defence procurement needs to adopt similar iteration loops for processing hardware, while maintaining longer lifecycles for the platforms themselves.

The consequences of not doing so are already visible. Consider a platform where computer hardware was specified in the early 2010s, now fielding in the mid-2020s. The sensors remain front-line ready and will last the lifetime of the platform, yet the GPU is already struggling to run today’s latest algorithms. Running classification algorithms, it manages just 5-6 frames per second versus the required 30-60 fps. The consequence is jerky, unusable displays for human operators – viable only for machine-to-machine data passing rather than real-time crew decision-making.

The real-world consequence: locked opportunitie

The impact of this mismatch is profound. Modern armoured fighting vehicles can have dozens of cameras providing 360-degree awareness around the platform, yet human crews can actively monitor perhaps two feeds at most. AI classification could monitor all feeds simultaneously, alerting crews when threats appear. The algorithms exist. The sensors exist. Yet the processing hardware cannot connect them at operational tempo.

Without it, this locks away those second-order effects that would provide genuine tactical advantage. Passive ranging, for instance, would allow crews to determine target distance without laser detection, avoiding the risk of revealing their position. Threat prioritisation algorithms could assess multiple targets based on type, range, and behaviour, then recommend which to engage first. Classification enables vehicle configuration analysis, determining gun orientation, and anomaly detection – all capabilities that help crews make faster, better-informed decisions under pressure.

Perhaps most importantly though, AI classification reduces the cognitive burden. If, instead of requiring crews to watch everything, AI can handle the monitoring tasks, then crews are freed up to focus on decision-making and engagement. The opportunity cost of not having these capabilities is significant: crews operating without advantages that could be unlocked through hardware refresh rather than platform replacement.

The path forward: treating processing hardware as consumable

“We need to recognise that GPU hardware requires planned three-to-five-year replacement cycles, independent of platform lifecycle. One practical way to deliver this is through a hardware as a service model for military platforms, where onboard computing processing is provided, maintained, and refreshed on a contracted cycle to sustain AI performance over the life of the vehicle,” says Stewart.

Delivering this at scale requires a common, GPU-enabled processing architecture across platforms and domains. Standardised interfaces would make DigitalCrew building blocks truly portable – develop once, deploy anywhere without re-engineering the software wrapper for each new system.

The benefits are clear:

  • Agility: planned GPU replacement every three-to-five-years keeps processing capability aligned with algorithm evolution, without waiting for platform replacement.
  • Portability: standardised architecture means developing once and deploying anywhere, with no re-engineering for each platform.
  • Cost: reduced integration costs and predictable refresh budgeting over platform lifetime.
  • Immediate impact: unlocking AI capabilities on existing fleets without vehicle replacement.

This is not about choosing between new platforms and new processors – it is about recognising they operate on different timescales. New platforms are essential, but their processing architecture must be designed for regular hardware refresh from day one.

Where the next leap comes from

Sensors and vehicle platforms remain capable for decades. The factor limiting their lethality is the computing hardware sitting between the sensors and the shooter. By treating that hardware as consumable, requiring periodic refresh, forces can unlock new waves of AI-enabled performance without rebuilding fleets.

The next major leap in armoured vehicle capability won’t come from a new turret design, a new engine, or a new hull. It will come from upgrading the GPU inside – not because the platform needs replacing, but because the technology evolution cycle demands it. The armies that understand this will field AI-enabled advantages on existing platforms while others wait for next-generation procurement cycles to deliver similar capabilities.

The question isn’t whether to modernise processing hardware. It’s whether to do it proactively, as part of a planned refresh strategy, or reactively when the capability gap becomes a tactical liability.

 

21 Jan 26. Global: New, highly sophisticated malware increases security risks to organisations. On 18 January, the cyber security company Resecurity reported that various cyber threat actors are using a new malware family (‘PDFSider’) to conduct stealthy, highly sophisticated cyber operations. Targets are widespread, though some reported victims include government and energy organisations. Threat actors distribute spear phishing emails to trick victims into downloading a ZIP archive. This archive contains the PDFSider payload, which is deployed directly into a system’s memory via Dynamic Link Library (DLL) sideloading techniques to remain obfuscated. Then, the malware conducts initial system reconnaissance and establishes persistent communication with command-and-control (C2) infrastructure for additional malicious activity. PDFSider can detect virtual environments and security tools while encrypting C2 traffic to prolong detection evasion, highlighting its sophistication. Multiple ransomware groups have reportedly used PDFSider to facilitate persistence and download malicious payloads, likely for data exfiltration and encryption. As such, we assess that global organisations will face increased security risks amid the persistent development of malware. (Source: Sibylline)

 

20 Jan 26. cortAIx, Thales AI accelerator, launched in Germany to Drive AI for Critical Systems

  • In January 2026, cortAIx, Thales AI accelerator, has opened a new site in Germany, bringing the total number of these cortAIx entities to five, after France, the United Kingdom, Canada, and Singapore
  • This initiative aims to contribute to the development of transparent and trustworthy AI solutions, specifically for critical systems and security-relevant military applications

By establishing cortAIx in Germany, Thales is responding to the rising demand for trusted and resilient AI solutions in the defence and security sectors. cortAIx in Germany represents an additional building block in Thales’ global AI network, which aims to strengthen the responsible and effective use of AI to tackle complex challenges. The focus is on developing robust solutions for AI for cybersecurity, and military use cases such as autonomous cyber-defence, agent-based penetration testing, command & control, and sensor-centric applications. Based on customer feedback and Thales in-house research, new potentials for innovative or existing solutions are identified—solutions that can be effectively applied and ease users’ workloads with the help of trustworthy AI. The cortAIx approach extends from customer-centric basic research to the development of use cases and minimum viable products, and ​ to market-ready products. This approach has already proven successful in NATO countries with an existing cortAIx presence, such as Canada, the UK, and France.

“With cortAIx in Germany, we are bridging the gap between technological innovation and the highest standards of security. Our goal is to provide our customers in the defence and security sector with solutions that are not only technologically advanced, but above all, trustworthy and sovereign. In a world of mounting digital threats, resilient AI is no longer a ‘nice-to-have’—it is the backbone of modern security architectures. We invite our partners and customers to join us in this important endeavor. Close collaboration between industry, academia, and public sector is crucial for advancing AI innovations that both strengthen Europe and Germany’s sovereign capabilities and meet the highest standards of transparency, ethics, and accountability.” Christoph Ruffner, CEO & Country Director Thales in Germany

Global AI Expertise of cortAIx

To pool the comprehensive expertise of Thales and efficiently advance trustworthy AI development, experts from cortAIx in Germany benefit from the global network. Thales already employs over 800 AI and data specialists, and is the leading patent applicant for AI for critical systems in Europe, with more than 200 patents filed to date. With over 100 products integrating AI, Thales is accelerating the development and deployment of trusted AI-based systems in the most demanding environments. cortAIx in Germany builds on this success and will serve as a central hub for AI innovation—bringing together cutting-edge technology, talent, and research with the goal of delivering AI solutions that provide the right data foundation for the right decisions in critical scenarios.

cortAIx’s research and development focuses on solutions for critical systems, including:

  • Building resilient data and knowledge foundations as prerequisites for efficient, scalable AI systems;
  • Developing and evaluating AI systems that act autonomously and make independent decisions in highly dynamic, security-critical environments, as well as implementing defence measures against hybrid (cyber & physical) threats;
  • Securing AI systems against manipulation, malfunction, and attacker influence throughout their entire lifecycle.

 

19 Jan 26. General Atomics Aeronautical Systems, Inc. (GA-ASI) –– the world leader in unmanned systems – and Barzan Holdings, Qatar’s national defence and security leader, signed a Memorandum of Understanding (MOU) to collaborate on the development of advanced Battle Management software capabilities. The signing took place on Monday during the Doha International Maritime Defence Exhibition and Conference (DIMDEX). The MOU provides a framework for cooperation between GA-ASI, GA-Intelligence, and Barzan Holdings to develop software solutions that enhance theater-level situational awareness and enable the efficient processing, correlation, and dissemination of intelligence. These capabilities are intended to support faster, higher-quality decision-making in complex, multi-domain operational environments. For General Atomics, the agreement underscores the strategic importance of collaboration with Barzan Holdings and the State of Qatar. The partnership reflects a shared commitment to long-term cooperation, technological innovation, and the advancement of interoperable command-and-control solutions aligned with modern defense and aerospace requirements. In addition to its best-in-class unmanned aircraft systems, GA-ASI is a premiere developer of airborne Intelligence, Surveillance and Reconnaissance (ISR) systems, while GA-Intelligence has the ability to take hundreds of sources of commercial data, including data provided from GA-ASI’s unmanned systems, to produce a comprehensive operating picture.

“Collaboration with Barzan and Qatar is central to GA’s approach to delivering operationally relevant, next-generation capabilities,” said a GA-ASI CEO Linden Blue. “By combining GA’s expertise in mission systems and autonomy with Barzan’s regional insight and defense focus, we are positioned to advance battle management solutions that significantly improve situational awareness and intelligence exploitation.”

 

16 Jan 26. Cyber Update Key points.

  • A new phishing campaign targeting government, think tank and academic organisations has underscored the data-theft and cyber espionage risks stemming from the renowned North Korean state-sponsored group ‘Kimsuky’  (see Sibylline Cyber Daily Analytical Update – 12 January 2026).
  • The Russian state-sponsored group ‘APT28’ poses increased data-theft risks for energy, government, military and media sectors (see Sibylline Cyber Daily Analytical Update – 13 January 2026 and our technical analysis below).
  • Users of the social media platform Facebook face long-term information-theft risks stemming from a sophisticated phishing technique (see Sibylline Cyber Daily Analytical Update – 14 January 2026 and our technical analysis below).
  • Linux systems face increased security risks stemming from a new and highly sophisticated malware framework called ‘VoidLink’ (see Sibylline Cyber Daily Analytical Update – 15 January 2026).
  • A phishing operation carried out by the Russian state-sponsored group ‘Void Blizzard’ poses heightened security risks for Ukrainian defence entities (see Sibylline Cyber Daily Analytical Update – 16 January 2026).

Technical analysis of weekly stories

The renowned Russian state-sponsored group APT28 (also known as ‘Fancy Bear’) has targeted energy, government, military and media sectors in a large-scale, data-theft cyber operation since at least February 2025. APT28 likely uses spear phishing emails to trick victims into clicking on an embedded malicious link. The link redirects victims to APT28-made pages impersonating legitimate email, authentication and virtual private network (VPN) services – including Microsoft Outlook Web Access (OWA) and Sophos – to prompt users to input their credentials. The link reportedly conceals two shortened URLs that display legitimate-looking PDF documents pertaining to the sector’s expertise prior to the phishing pages, likely to enhance the operation’s legitimacy. The malicious pages also leverage Hypertext Markup Language (HTML) and JavaScript, as well as several free tunnelling services to capture and exfiltrate user data, highlighting the resource-efficient nature of this operation. The phishing pages emulate both login and password reset services and use similar credential-harvesting techniques for both attack pathways. We assess that the group likely uses stolen credentials to hijack user accounts to collect strategic intelligence and to strengthen its security posture.

Unnamed cyber criminals are targeting users of the social media platform Facebook in a sophisticated information-theft operation. Threat actors reportedly distribute phishing emails containing a fake warning regarding copyright infringement, suspicious and unauthorised login attempts and/or security updates to trick users into clicking on an embedded link. The link redirects users to a legitimate Facebook page where the threat actors conduct a Browser-in-the-Browser (BitB) attack by displaying a threat actor-made phishing pop-up window. Threat actors use URL shortening techniques to embed a portion of legitimate Facebook URLs into the pop-up window’s URL to appear authentic, as well as CAPTCHA pages to feign legitimacy further. The pop-up prompts victims to enter sensitive information and credentials, subsequently allowing the threat actors to hijack user accounts, exploit stolen data and conduct follow-on malicious activity. The threat actors also use legitimate cloud services to host phishing infrastructure and simultaneously evade security mechanisms, showcasing the continued exploitation of legitimate platforms for malicious cyber activity.

Non-exhaustive recommendations to mitigate these threats include:

  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware.
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.

Our cyber word(s) of the week: Browser-in-the-Browser (BitB) attack

Definition: A type of cyber attack wherein threat actors create a fake, credential-harvesting pop-up window within a legitimate webpage to deceive users and subsequently trick them into disclosing sensitive information.

Example: ‘The link redirects users to a legitimate-looking Facebook page where threat actors conduct a browser-in-the-browser attack’ (see Sibylline Cyber Daily Analytical Update – 14 January 2026).

Frequency of TTPs during this monitoring period: LOW frequency, MODERATE frequency, HIGH frequency

The MITRE ATT&CK framework is a globally accessible documented collection of information detailing the malicious behaviours of cyber threat actors. It is used as the foundation for organising the processes which threat actors execute during cyber operations. It provides an encyclopaedic reference for organisations, highlighting the TTPs cyber threat actors employ in campaigns, while also providing suggestions for detecting and mitigating against specific TTPs to bolster organisations’ security mechanisms. The framework organises a threat actor’s entire operational lifecycle from reconnaissance to exfiltration and impact. (Source: Sibylline)

————————————————————————————————————————————————————————————————————————————————————————————————————————————-

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

————————————————————————————————————————————————————————————————————————————————————————————————————————————

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

January 16, 2026 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

————————————————————————————————————————————————————————————————————————————————————————————————————————————————-

16 Jan 26. £279m investment to build new home for Army’s cyber regiment. Army cyber warriors are to benefit from new modern accommodation and specialist training facilities, following nearly £300m investment announced today for Duke of Gloucester Barracks.

  • Specialist facilities to be developed for Army’s cyber unit in Gloucestershire after £279m contract signed.
  • Work will see the creation of 248 Single Living Accommodation rooms, in addition to 30 Service Family Accommodation homes.
  • Significant investment in local economy, with 92 jobs created, demonstrating defence as an engine for growth.

The £279m contract, signed today, will see specialist modern facilities built for the Army’s cyber regiment. The investment will provide new infrastructure at Duke of Gloucester Barracks in Gloucestershire for 13 Signal Regiment, who deliver defensive cyber operations for the Army. The work will include brand new technical and training buildings for personnel, as well as modern accommodation. The new barracks will house the Army’s Cyber, Information and Security Operations Centre which will protect networks from cyber threats both at home and overseas on exercises and operations. The Strategic Defence Review highlights how the cyber and electromagnetic domain are at the heart of modern warfare, following more than 90,000 attacks on the UK’s military networks from adversaries in the last two years alone. Delivering on the SDR, we are also creating a new Cyber and Electromagnetic Command to put the UK at the forefront of cyber operations. Today’s contract will create 92 jobs, which will include opportunities for ex-military and 32 apprenticeships, with structured training programmes, helping boost defence as an engine for growth. Awarded to the British company Bovis by the Defence Infrastructure Organisation (DIO), the work will deliver:

  • Specialist technical accommodation and training facilities.
  • 248 Single Living Accommodation bedspaces.

Additionally, 30 new Service Family Accommodation homes will be built, with additional refurbishment of existing military homes at the site.

Luke Pollard MP, Minister for Defence Readiness and Industry, said: “Our Strategic Defence Review highlights how the cyber and electromagnetic domain are at the heart of modern warfare. We are making this significant investment to enhance the Army’s cyber capabilities while delivering an improved lived experience for Service Personnel, alongside new homes for Service Families. Creating dozens of jobs, the work will also back local industry and demonstrates defence as an engine for growth.”

Construction will start in Summer 2027, with completion scheduled for Spring 2030, to support the Regiment’s move to the barracks. The contract supports the local economy, businesses and communities with:

  • 25% of spending going to businesses within 50 miles of the site.
  • 25% of the on-site workforce employed locally.
  • 40% of offsite manufacturing within 40 miles of the site.
  • 25% of spending to go to small and medium enterprises.

The MOD is investing in modern, sustainable infrastructure designed to meet future operational requirements and enhance the lived experience of military personnel through its Defence Estate Optimisation (DEO) Portfolio.

Major General AJ Smith CBE, Director of Basing and Infrastructure and Senior Responsible Owner for the DEO Army Programme, said: “Investment in new infrastructure at Duke of Gloucester Barracks will enable the growth of the Army’s cyber capability and enhance operational readiness.

This project is a great example of our ongoing effort to modernise our estate, improve the environments where our people live, work and train, and provide the facilities they need to carry out their vital roles for UK Defence.”

Warren Webster, DIO MPP Programme Director – Army, said: “This contract award paves the way for some fantastic new infrastructure at the Duke of Gloucester Barracks, including new Single Living Accommodation rooms and brand new technical and training buildings for personnel.

All told, it’s a significant improvement to the site which will benefit personnel.”

Andrew Mackay, Managing Director, Public Sector & Regions, Bovis said: “We are proud to be leading the ambitious modernisation of Duke of Gloucester Barracks. This programme – delivering high‑quality Single Living Accommodation alongside major infrastructure enhancements and upgrades to existing buildings – will provide our armed forces with the modern, sustainable facilities they deserve. As a longstanding and valued client, we look forward to working closely with the DIO to achieve their ambitions.” (Source: https://www.gov.uk/)

 

15 Jan 26. War Department Enacts New Cybersecurity Program to Safeguard Service Member Data. Station Joint Task Force. The War Department began implementing the Cybersecurity Maturity Model Certification, a landmark cybersecurity program, in November 2025 to better protect sensitive information across the U.S. defense industrial base.  CMMC establishes a mandatory framework to ensure that thousands of companies contracting with DOW have verified cybersecurity measures in place to protect the department’s data they handle.  The program is especially critical for protecting the personally identifiable information of service members and their families, particularly during the permanent change of station process.

What is CMMC and Why is it Important for PCS?

The CMMC program functions as a verification mechanism, ensuring DOW contractors meet the department’s cybersecurity standards. The CMMC program will require that a contractor’s leaders provide an assessment of their company’s compliance for CMMC levels 1 and 2.  This verification mechanism directly impacts the security of military families’ personally identifiable information. The PCS process, a regular part of military life, requires service members to share vast amounts of PII, including names, Social Security numbers, birthdates, telephone numbers and financial details, with numerous third-party contractors that manage moving, travel and housing. Without robust security measures in place, this sensitive data is a prime target for cybercriminals and foreign intelligence entities, potentially leading to identity theft and financial fraud.

“The CMMC program provides increased assurance to the DOW that a defense contractor can adequately protect sensitive unclassified information at a level commensurate with the risk,” the department states in the rule. By mandating CMMC, the DOW ensures that any company involved in the PCS process must maintain a certified level of cybersecurity, directly protecting service members’ personal data from compromise.

How the CMMC Program Works

  • The CMMC framework is designed to be scalable, matching the level of certification required to the sensitivity of the information being handled.
  • Tiered levels: The program has multiple levels. A contractor handling basic federal contract information will need to comply with CMMC Level 1, which can be accomplished through a self-assessment, or CMMC Level 2, which can be achieved through a self-assessment or through a certified third-party organization or the DOW’s Industrial Base Cybersecurity Assessment Center once every three years.
  • Verification and reporting: Contractors must report their CMMC status in the government’s Supplier Performance Risk System. DOW contracting officers will verify a bidder’s or contractor’s CMMC status before awarding any new contracts or exercising options on existing ones. Contractors must also make an annual affirmation of their continued compliance.
  • Phased implementation: The DOW will phase in the CMMC requirements over a three-year period to minimize the financial impact and disruption to the defense industrial base, particularly for small businesses. Following this period, the CMMC requirements will apply to all applicable DOW contracts. As part of the CMMC program implementation, all federal contractors remain subject to a DOW audit to ensure compliance.

Phased implementation of the CMMC program represents a significant step forward in securing the defense industrial base.

For service members and their families, it provides much-needed peace of mind, knowing their personally identifiable information is protected by a more resilient and cyber-aware network of defense contractors. (Source: U.S. DoD)

 

15 Jan 26. Buyer’s Market. There are arguably few British procurement projects that have been less troubled than the ongoing effort to outfit the United Kingdom’s land manoeuvre forces with a new tactical communications and Command and Control (C2) system. The current Bowman architecture was introduced into service from March 2004. Initial UK Ministry of Defence (MOD) plans called for Bowman to be replaced from 2026. A key issue with the system was that it was ‘monolithic’. The only way the Bowman architecture could be upgraded or modernised was for constitute parts to be returned to the original contractor for this work to be performed. The MOD was keen to avoid such ‘vendor lock’ in its future tactical communications and C2 assets. The ministry wanted to retain full ownership of the future architecture and to be able to easily modernise it with hardware and software from third parties without having to rely on prime contractors. The civilian smartphone is instructive for this context: Users can easily add new hardware like earphones to their devices. They can download software applications without having to consult the phone’s manufacturers. The MOD’s path to this future modular and open architecture was to take the existing Bowman system and rework it so that it could accept new hardware or software without relying on a prime. The effort was dubbed Evolve to Open (EVO). As our Moving Forward article in this month’s newsletter explains, it was a failure. One MOD insider shared with your editor that the EVO effort was akin to taking a 1990s cellphone and trying to turn it into a smartphone. Recognising this doomed effort, the ministry is about to embark on a procurement of new communications and C2 systems for the land manoeuvre force as part of its ongoing Project Morpheus effort. The contracting vehicle for this acquisition will be launched in early 2026. Procurements of the new systems should commence that same year and conclude in 2034. The MOD should be commended for moving past the EVO debacle and moving ahead with buying the communications and C2 capabilities the land manoeuvre force needs. Although not ideal, Bowman can soldier on for a few more years, and there will be some overlap between legacy and new capabilities. Nonetheless, the procurement of new tactical communications systems comes at exactly the right time. Several of the UK’s European allies like France and Germany are also investing in new tactical communications. Ensuring that the United Kingdom’s land forces can bring have state-of-the-art radios to the fight will be vital, particularly as the continent’s security situation vis-à-vis Russia continues to degenerate. (Source: Armada)

 

15 Jan 26. Polar Express. The two Arctic Satellite Broadband Mission satellites were launched into the heavens in August 2024 in a joint Norwegian-United States effort to address satellite communications shortfalls in Arctic regions. Satellite Communications (SATCOM) coverage over Arctic regions has hitherto suffered from a paucity although efforts among several NATO nations are addressing this. Arctic military SATCOM deficiency is a cause for concern among North Atlantic Treaty Organisation (NATO) allies as Russia continues to pose a threat to the alliance. Several NATO nations have direct borders with Russia within the Arctic circle notably Finland, Norway, Sweden and the United States. There is every chance that war with Russia could see NATO forces confronting the former in these regions. The strategic sensitivity of the far north make it vital that manoeuvre forces there have survivable, reliable and efficient dedicated satellite communications.

ASBM

Several efforts are ongoing across the alliance to address Arctic military SATCOM shortfalls. Space Norway, a Norwegian satellite operator, that country’s armed forces, the United States Space Force together with Northrop Grumman and Viasat have developed the Arctic Satellite Broadband Mission (ASBM). The ASBM constellation includes two communications satellites, ASBM-1 and ASBM-2. Open sources note the satellites carry X-band (7.9 gigahertz/GHz to 8.4GHz uplink/7.25GHz to 7.75GHz downlink) and Ka-band (26.5GHz to 40GHz uplink/18GHz to 20GHz downlink) transponders. Both spacecraft were successfully launched from Vandenburg airbase, California on 11th August 2024.

ESCP-P

Canada is also looking to enhance military SATCOM coverage in the far north. On 9th December 2025, the Canadian Government launched a strategic partnership with Telesat and MDA Space as part of the country’s Enhanced Satellite Communications Project-Polar (ESCP-P).  According to official ESCP-P information the initiative provides narrowband and wideband SATCOM links in Canadian Arctic regions. Deliveries of the capability are expected in circa 2035. Telesat and MDA Space have already been awarded a $2.12m contract to perform initial engineering and analysis work germane to ESCP-P. The strategic partnership model being used by the Canadian government to acquire the ESCP-P capability “is an innovative approach to defence procurement that streamlines processes and accelerates timelines”. The approach also harnesses “industry experience and expertise in the design, development and delivery of defence projects and programmes” according to a press release announcing the news. Although the ESCP-P undertaking initially specified Ultra-High Frequency (UHF: 399 megahertz/MHz to 470MHz) links, Brigadier General (retired) Michael Adamson, Telesat’s senior director of defence strategy and business development, told Armada that the Canadian government is evaluating several orbital altitudes and frequencies for the ESCP-P architecture. These frequencies include X-band and Ka-band. He continued that “specifics on the programme will be determined after the government selects its architecture”. Both Telesat and MDA Space are performing engineering and options analysis for several architectures: “The government will review the options and then select its final architecture”. Canada’s ESCP-P initiative will complement other similar efforts like ASBM. That NATO is addressing SATCOM shortfalls in the Arctic is to be congratulated. Having such communications assets in place over the coming years will constitute a powerful force multiplier in these strategically vital regions. (Source: Armada)

 

15 Jan 26. Moving Forward. The United Kingdom’s Ministry of Defence may have finally broken the logjam characterising the country’s efforts to procure new land forces tactical communications systems. In April 2025, the UK’s Ministry of Defence (MOD) quietly published a so-called ‘pipeline notice’ regarding the procurement of new tactical communications systems to equip the country’s land forces. According to UK government documents, a pipeline notice sets out “specified information about any public contract with an estimated value of more than ($2.6bn) … (for) which the contracting authority intends to publish a tender notice or transparency notice”. In other words, the pipeline notice indicates that a formal request to tender will be published imminently. The key difference between the April and December 2025 pipeline notices is that the latter indicates the first tender notice is to be published on 7th January 2026. This latest pipeline notice states that the MOD is seeking “specialised military grade tactical communications and information systems including hardware, software and associated design and implementation and support services”. These deliverables will be “deployed in active battlefield environments for critical real-time operational tactical communications”. The total programme is estimated by the MOD to be worth $12.8 bn. The contract dates are estimated to run between 10th June 2026 and 9th June 2034. An MOD source told Armada that the pipeline notice does not constitute a procurement per se but is a commercial services framework. This framework “will create a pre-qualified pool of suppliers for tactical communications systems capable of providing the systems, components, and services required both now and, in the future, through competitive and innovative procurement”. The framework, the source continued, sits within the ministry’s Land Environment Tactical Communications and Information Systems programme. Known as LETTACIS, this effort is overhauling the command and control, and communications architectures, used by the UK’s land manoeuvre force. Moreover, the framework creates a vehicle for the purchase of commercial off-the-shelf and military off-the-Shelf capabilities. The exact communications capabilities to be acquired for UK land forces have yet to be determined. Specific technical requirements “including waveforms, and hardware and software specifications, will be defined through further competitions among framework supplies on a case-by-case basis,” the source added. Suppliers providing tactical communications capabilities can bid for a place in the framework. January will see the release of a ‘tender pack’ that will outline technical aspects and supplier selection criteria. This will open the tactical communications system competition to bidding.

EVO’s end

The commencement of the tactical communications system competition and tendering process seems to draw a line under the MOD’s Project Morpheus Evolved to Open (EVO) initiative. Morpheus is the ministry’s overarching effort to replace the UK land forces’ existing Bowman communications, and command and control system. The MOD had originally planned to commence Bowman’s replacement through EVO. EVO saw General Dynamics contracted to turn the current monolithic Bowman Combat Infrastructure Platform-5.6 (BCIP-5.6) architecture into an open and modular system that could easily accept hardware and software improvements over the rest of Bowman’s life. In retrospect, EVO may have been too ambitious and in February 2024 it was axed by the MOD. The cancellation resulted in an impasse between the MOD and the contractor. Both parties were at odds over EVO’s expectations and deliverables. It appears that this disagreement has since been solved, although the MOD source told Armada that “commercial confidentiality precludes providing the specific details of the arrangements made”. For now, the BCIP-5.6 architecture will continue in service until 2031 when its phase-out is will commence, concluding in 2035. It appears likely the new capabilities procured via the framework will be phased in as BCIP-5.6 retires. Bowman’s life extension from an original planned retirement date of 2026 to 2031 is not ideal, but the MOD has little choice given EVO’s failure. The good news is that, with the release of the framework in January, the ministry is clearly serious about getting the country’s land forces the tactical communications they need in a timely fashion. The replacement of Bowman has been fraught with difficulty because the EVO programme while bravely ambitious, was ultimately too ambitious to succeed. The release of the framework appears to be the right decision and puts a much-needed procurement of vital capabilities on track. (Source: Armada)

 

14 Jan 26. Non-Stop Innovation. Improvements and enhancements are mooted for Ukraine’s Delta command and control system including the adaptation of the architecture to support battle management, and the possibility of making the baseline system available to NATO members for local customisation. Improvements are in the offing for Ukraine’s Delta family of tactical, operational and strategic command and control systems. Alongside the widespread use of Uncrewed Aerial Vehicles (UAVs) in the ongoing war in Ukraine, the latter’s Delta Command and Control (C2) system has become one of the conflict’s signature capabilities. Delta is the family name for several C2 systems which act as clearing houses for large quantities of intelligence gathered from an array of sources. These sources can include the Ukrainian military, government departments and even civil society, alongside allied nations. Delta was developed by the Ukrainian Ministry of Defence’s Centre for Innovation and Development of Defence Technologies; Aerorozvidka, a Ukrainian non-governmental organisation and the Ukrainian Ministry of Digital Transformation. The latter organisation is Delta’s custodian. The system’s development commenced in 2015; one year after Russia’s initial invasion of Ukraine. Senior sources who led the development of Delta recently told Armada that Ukraine possessed no automated operational-level C2 system when Russia performed her first invasion in 2014. The rationale behind Delta was to build a sensor-agnostic command and control system to receive intelligence inputs from disparate sources and systems. Testing of the architecture commenced in 2017, according to reports, and it became operational in a limited configuration in August 2022. Full deployment of Delta was authorised by the Ukrainian government in early February 2022, just days before Russia’s second invasion on 24th of that month. Open sources say Delta played a key role in helping Ukrainian forces repulse Russian attempts to capture Kyiv.

Architecture

Delta is a cloud-based software system accessible via laptops, desktop computers, smartphones and tablets. The software collates data and intelligence from a myriad of sources and allocates this to specific targets. These sources can include Ukrainian and allied military intelligence, surveillance and reconnaissance capabilities like imagery intelligence satellites and UAVs. Information on potential targets is assessed and displayed on Delta’s ‘Google Maps’ style cartography. As information is amassed on these targets it is progressively added thus continually enriching the intelligence picture. A Delta user can have all the information regarding a potential target instantly available at their fingertips. A key benefit of Delta is that information can be uploaded into a cloud via the internet using robust safety protocols and data is subjected to stringent verification. Delta is typically used to support warfighting from the strategic and operational levels, down to the battalion and below at the tactical level.

Enhancements

Delta’s custodians are continually improving the system. Feedback is received from users who send their written recommendations to Delta’s technical support. These recommendations are translated into upgrades and improvements which are then deployed throughout the Delta ecosystem where relevant. Improvements in the offing include the ability to perform battle management using Delta. This is opposed to confining its use as an intelligence collection and analysis tool. Armada’s sources expect that Artificial Intelligence (AI) enabled decision-making aids will soon be rolled out onto Delta. These tools will be able to interrogate and draw conclusions from the vast quantities of data Delta processes and retains. For example, the system would be able to recognise a UAV operator’s location based on the imagery it has processed. At a stroke this would reduce the analyst’s workload by indicating where Delta had a high confidence that imagery showed a UAV pilot’s location. The analyst could then determine if this was likely to be a blue or red force UAV pilot. AI algorithms may also help to identify changes in red force dispositions which may be indicative of an imminent attack. Concerning force dispositions, a key improvement observed by the Ukrainian military is a major reduction in friendly fire since Delta’s introduction. Helping to improve UAV friend or foe identification is another area which has benefitted significantly from Delta. Beyond Ukraine, Delta’s developers are confident they can garner interest from North Atlantic Treaty Organisation (NATO) members and allied nations in using Delta as a C2 asset. One idea is to make the baseline Delta architecture available to these nations. They could then customise that architecture and improve it according to these nations’ needs. Improvements made by third parties could then be brought into Ukraine’s Delta systems in a mutually beneficial fashion. Delta has clearly proved its worth in the Ukrainian theatre of operations and its continual improvement has paid tactical and operational, and hence strategic, dividends. Continual improvement will ensure the system remains highly capable and relevant, and an efficient force multiplier. Furthermore, it is likely that NATO and allied nations may yet see Delta’s benefits and acquire the architecture for their own needs. (Source: Armada)

 

14 Jan 26. January Radio Roundup 2026. Himera’s new B1 radio repeater works with the company’s G1 tactical radios and can be delivered on the battlefield using uncrewed aerial vehicles. The B1 repeater is already in service on the battlefields of Ukraine.

Repeating the Message

Ukrainian tactical communications specialists Himera has unveiled its B1 radio repeater which the company says can help expand links to ranges of circa 20 kilometres/km (12.4 miles). The B1 repeater greatly expands the geographical footprint of the company’s Himera-G1 handheld radios. The Himera-G1 uses ultra-high frequency bands of 410 megahertz/MHz to 493MHz, and 700MHz to 900MHz. The company says the radio has a line-of-sight range of up to two kilometres (1.2 miles). AES-256 encryption and frequency hopping is embedded in the B1 repeater for communications and transmission security. Himera added that the B1 repeater can achieve up to two weeks’ autonomous operation on a single charge. Armada was told by the company that the B1 repeater is in operational service with the Ukrainian military: “Hundreds have been delivered to military units and are now used on the frontline”. The repeaters are unlimited regarding how many radios they can host at any one time. Repeaters can also be easily delivered across the battlefield using uncrewed aerial vehicles: “They are simple to use and can be configured from a mobile application within minutes”.

The US Marine Corps’ Panther-2 satellite communications terminals are being upgraded to provide them with more transmission power to help improve performance and reduce signal-to-noise ratios.

Panther Power

L3Harris has received an order to upgrade the Panther-2 Satellite Communications (SATCOM) terminals of the United States Marine Corps (USMC). According to the company, the Panther-2 uses X-band (7.9 gigahertz/GHz to 8.4GHz uplink/7.25GHz to 7.75GHz downlink), Ku-band (14 gigahertz/GHz uplink, 10.9GHz to 12.75GHz downlink) and Ka-band (26.5GHz to 40GHz uplink/18GHz to 20GHz downlink) frequencies. Panther-2 produces up to 13 Watts/W of transmission power. Reports note that the upgrade will increase these power outputs to 25W. The upgrade forms part of the USMC’s Marine Corps Wideband Satellite-Expeditionary (MCWS-X) initiative. The improved Panther-2 satisfies the MCWS-X requirement for a human-portable “multiband, super high frequency multi-waveform SATCOM terminal” according to the corps. An L3Harris spokesperson told Armada that “as more data (is) collected across the unified battlespace, the need to send more information through integrated networks increases”. By enhancing the Panther-2 output power “operators … not only send more data at faster rates but also send larger amounts of information at once”. Increasing the output power of the Ku-band transceiver to 25W also helps reduce signal-to-noise ratios “thereby ensuring more reliable and higher-quality communications”. The upgrade covers the existing USMC fleet of MCWS-X terminals. The initiative should be completed by the end of 2026, the spokesperson continued. (Source: Armada)

 

15 Jan 26. Global: Linux systems face increased security risks from new, sophisticated malware framework. On 13 January, the technology news site Ars Technica reported that unnamed threat actors are developing a new, highly sophisticated Linux malware framework (‘VoidLink’) to conduct long-term cyber attacks. VoidLink can target infected Linux machines hosted within high-profile cloud services by analysing providers’ data, highlighting the increased security risks stemming from the supply chain. Furthermore, VoidLink contains a malware loader that deploys the final implant as well as approximately 37 additional modules that enhance reconnaissance, privilege escalation and lateral movement. The modules enable threat actors to maintain prolonged persistence to conduct a wide range of malicious activities, underscoring VoidLink’s sophistication. Given the framework’s design and capabilities, its developers are possibly highly skilled and China-affiliated. Although VoidLink has not been actively deployed at the time of writing, we assess that Linux systems will face increased security risks in the medium term, as the framework is reportedly in the development phase. (Source: Sibylline)

 

14 Jan 26. TKMS and Cohere Sign Teaming Agreement to Advance AI-Enabled Capabilities for the Canadian Patrol Submarine Project.

  • The collaboration focuses on decision-support tools, onboard information management, training, and naval-specific secure interfaces.
  • The agreement underscores TKMS’s long-term commitment to Canadian industry and responsible, secure deployment of advanced AI technologies.

TKMS and Cohere, a leading security-first enterprise AI company, have signed a Teaming Agreement to jointly explore the integration of advanced AI technologies into the Canadian Patrol Submarine Project (CPSP).  Through the collaboration, the companies will assess opportunities to apply state-of-the-art language and data-driven models to support decision-support workflows, onboard information management, training environments, and secure naval interfaces. The initiative aligns with Canada’s future submarine requirements and modernization priorities.

“Canada’s next-generation submarine project presents an opportunity to bring the most modern and reliable technologies to the Royal Canadian Navy. Cohere’s expertise in trustworthy AI models aligns perfectly with our vision and together, we aim to enhance the user experience and operational efficiency of future crews while maintaining the highest security and safety standards,” said Thomas Keupp, Chief Sales Officer, TKMS.

The partnership will focus on research, prototyping, and evaluation activities. Both organisations emphasize that any AI-enabled capabilities will adhere to the strict security, compliance, and operational demands of the Royal Canadian Navy and the Government of Canada.

“Submarines are the ultimate high-stakes workplace. Through our partnership with TKMS, we’re embedding critical solutions that empower sailors to act decisively,” said Dave Ferris, VP of Americas and Global Public Sector at Cohere. “Our technology will help the Canadian Patrol Submarine Project to meet stringent demands for precision, security, and streamlined operations, while reducing cognitive load.”

By bringing together TKMS’s proven submarine engineering expertise with Cohere’s leading enterprise AI technology, the Teaming Agreement represents a significant step toward delivering next-generation digital capabilities tailored to the needs of Canada’s maritime forces. It also reinforces TKMS’s commitment to integrating Canadian companies into its supply chain throughout the entire life cycle of its platforms, underlining its belief that “submarine building is nation building.” (Source: ASD Network)

 

14 Jan 26. PteroDynamics and AV Demonstrate Integrated EW Capabilities on Transwing VTOL UAS. PteroDynamics and AeroVironment, Inc. recently collaborated for a joint technology demonstration at Silent Swarm 25, hosted by the Naval Surface Warfare Center (NSWC) Crane Division at the Alpena Combat Readiness Training Center in Alpena, Michigan. The companies integrated multiple industry-leading EW sensors from AV on the PteroDynamics P4 Transwing autonomous VTOL unmanned aircraft system (UAS), highlighting a spectrum of maneuver capabilities available to warfighters with the combined capabilities. Equipped with AV’s EW capabilities, the autonomous Transwing VTOL aircraft successfully completed three scenarios in operationally relevant, multi-domain environments–observing, detecting, and effecting various representative threats throughout the theater to inform future U.S. Navy operations for littoral surveillance.

“PteroDynamics’ Transwing VTOL UAS with AV’s EW payloads demonstrated important new capabilities in a realistic and challenging operational environment,” said Tim Whitehand, PteroDynamics vice president of engineering.

“We are excited to have worked closely with AV to equip the Transwing with these innovative EW capabilities. The Transwing’s compact footprint, rapid and disturbance-resilient transition, and highly efficient wing-borne flight enable operations from confined or remote locations without runways, making it an ideal platform for maritime littoral operations.”

“Our open, interoperable EW systems are strategically engineered to reduce payload integration timelines for airborne, maritime, and ground ISR platforms, helping us meet unique mission needs with speed and scale,” said Conrad Smith, General Manager of Electronic Warfare Systems at AV. “By participating in events, like Silent Swarm 25, and innovating alongside other industry leaders, like PteroDynamics, we are expanding mission-critical capabilities for the U.S. Navy.”

AV delivers open-architecture EW chassis and sensors to support mission planning and awareness. These tactical solutions are designed and developed for a full spectrum of readiness capabilities, keeping warfighters ahead of global threats with actionable intelligence at the mission’s edge. PteroDynamics’ Group 3 Transwing platform offers the speed, range, and endurance of fixed-wing systems with superior VTOL performance in a simple, highly efficient autonomous platform. The aircraft unfolds its wings to transition smoothly and quickly between vertical and horizontal flight. It delivers superior VTOL stability and gust tolerance, requires no launch and recovery infrastructure, and occupies one-third or less ground footprint than other VTOL aircraft with a comparable wingspan –   an ideal platform for multi-mission payloads. During Silent Swarm 25, the Transwing flew from confined launch and recovery zones along the tree line on the shore of Lake Huron, showcasing its inherent expeditionary capabilities and operating envelope, which is unconstrained by wind direction. The team also took advantage of the Transwing’s modular architecture to integrate, and flight test the AV EW payload in a single day.

Transwing Receives FAA Airworthiness Certificate

PteroDynamics received a Special Airworthiness Certificate–Experimental Category (SAC-EC) from the Federal Aviation Administration (FAA) for the P4 Transwing UAS to conduct research and development flights in national airspace near Alpena, Michigan during Silent Swarm 25. Prior U.S. Navy demonstrations were at sea, including those at RIMPAC 2024 and the 2023 Hybrid Fleet Campaign Event. The SAC-EC allowed PteroDynamics, for the first time, to fly the 89 lb aircraft with an airworthiness certificate in U.S. airspace. The certification review and approval process took over seven months and demonstrated to regulators the maturity and safety of the Transwing and the trust the FAA has in PteroDynamics’ aircraft and processes. (Source: UAS VISION)

 

12 Jan 26. US War Department Launches AI Acceleration Strategy to Secure American Military AI Dominance. The Department of War today launches a transformative Artificial Intelligence Acceleration Strategy that will extend our lead in military AI deployment and establish the United States as the world’s undisputed AI-enabled fighting force. Mandated by President Trump, this acceleration strategy will unleash experimentation, eliminate legacy bureaucratic blockers, and integrate the bleeding edge of frontier AI capabilities across every mission area to usher in an unprecedented era of American military AI dominance.

“We will unleash experimentation, eliminate bureaucratic barriers, focus our investments and demonstrate the execution approach needed to ensure we lead in military AI,” said Secretary of War Pete Hegseth. “We will become an ‘AI-first’ warfighting force across all domains.”

The Department is taking a wartime approach to delivering capabilities, with an emphasis on three tenets: warfighting, intelligence and enterprise operations. This approach will strengthen battlefield decision-making, rapidly convert intelligence data and modernize daily workflows, all in direct support of more than three m DoW personnel.

The catalyst for this acceleration will be seven Pace-Setting Projects (PSPs), each with a single accountable leader and aggressive timelines. These PSPs will establish a new AI execution standard for the entire Department:

Warfighting

  • Swarm Forge: Competitive mechanism to iteratively discover, test, and scale novel ways of fighting with and against AI-enabled capabilities – combining America’s elite warfighting units with elite technology innovators.
  • Agent Network: Unleashing AI agent development and experimentation for AI-enabled battle management and decision support, from campaign planning to kill chain execution.
  • Ender’s Foundry: Accelerating AI-enabled simulation capabilities – and sim-dev and sim-ops feedback loops – to ensure we stay ahead of AI-enabled adversaries.

Intelligence

  • Open Arsenal: Accelerating the TechINT-to-capability development pipeline, turning intel into weapons in hours, not years.
  • Project Grant: Enabling transformation of deterrence from static postures and speculation to dynamic pressure with interpretable results.

Enterprise

  • GenAI.mil: Providing Department-wide access to frontier generative AI models, like Google’s Gemini and xAI’s Grok, for all DoW personnel at Information Level (IL-5) and above classification levels.
  • Enterprise Agents: Building the playbook for rapid and secure AI agent development and deployment to transform enterprise workflows.

This AI Acceleration Strategy is driving a major expansion of AI compute infrastructure through targeted investments and will unlock access to the data that gives the War Department an asymmetric edge. The Department will bring in top American AI talent through initiatives like the Office of Personnel Management’s “Tech Force” initiative and will empower small, accountable teams to attack complex AI integration opportunities. The War Department will eradicate woke DEI from our AI capabilities and ensure our military has objective, mission‑first systems that will guarantee decision superiority and warfighting advantage in this AI era.

“Speed defines victory in the AI era, and the War Department will match the velocity of America’s AI industry,” said Emil Michael, Under Secretary of War for Research and Engineering. “We’re pulling in the best talent, the most cutting‑edge technology, and embedding the top frontier AI models into the workforce — all at a rapid wartime pace.”

Grounded in the core tenets of warfighting, intelligence and enterprise operations – and following President Trump’s direction – the War Department will accelerate America’s Military AI Dominance by becoming an AI-first warfighting force across all domains.

Read the official AI Acceleration Strategy here: chrome-extension://efaidnbmnnnibpcajpcglclefindmkaj/https://media.defense.gov/2026/Jan/12/2003855671/-1/-1/0/ARTIFICIAL-INTELLIGENCE-STRATEGY-FOR-THE-DEPARTMENT-OF-WAR.PDF (Source: U.S. DoD)

 

12 Jan 26. US War Department ‘SWAT Team’ Removes Barriers to Efficient AI Development. Cameron Stanley will serve as the next Pentagon Chief Digital and Artificial Intelligence Officer, Secretary of War Pete Hegseth announced today during an address at SpaceX headquarters in Starbase, Texas. The advancement of artificial intelligence within the War Department was a key focal point of the secretary’s messaging to industry professionals at SpaceX.  Stanley, an Air Force veteran who recently served in the private sector, along with a team that includes some of the best and brightest who are also from the private sector, is most suited to help the War Department meet the AI goals President Donald J. Trump set in his executive order.

“This team will not only provide a catalyst for change in this department but will also act, we believe, as a magnet for other talented members of the tech community who want to join us in doing the mission-focused work to protect our great republic,” Hegseth said.

Speed is at the forefront of what the CDAO team is expected to do, Hegseth said.

“Speed wins; speed dominates,” Hegseth said. “[Stanley] and his team at CDAO will define AI deployment velocity metrics for all the pace-setting projects in the next 30 days, and report at least monthly after that. These will become the new benchmarks for programs across the department.”

Another key to advancing AI within the War Department, Hegseth noted, is eliminating naysayers — those whose own work is meant to put barriers in the way of the work of those trying to speed AI to the battlefield.

“We will take a wartime approach to people and policies that block this progress,” he said. “Barriers to data sharing, authority to operate … test and evaluation and contracting are now treated as operational risks, not simply bureaucratic inconveniences; we are blowing up these barriers.”

The secretary said he’s established a “barrier removal SWAT team” within the Office of the Undersecretary of War for Research and Engineering to make that happen. The team, he said, has the authority to waive nonstatutory requirements and escalate to the deputy secretary of war things that slow down the acceleration of AI capabilities.  AI systems require advanced hardware to run — computer power — and Hegseth said that’s another pursuit of the new CDAO team. The War Department will pursue its own computing power on its own military installations.

“We will invest heavily in expanding our access to AI [computing power] from data centers to the tactical edge, and [we] will tap into hundreds of bns of dollars in private capital flowing into American AI,” he said. “President Trump’s executive order has directed us to build data centers on military land and to work with the Department of Energy to ensure that we dramatically increase the number and breadth of resources needed to power this computing infrastructure.”

The secretary named a variety of private sector companies that may serve as partners to help the department get AI computer capabilities onto installations.  Modifications to hiring authorities, Hegseth said, will ensure the department has access to the best talent to advance its AI goals.

“We’re going to heavily leverage President Trump’s ‘Tech Force’ initiative to bring in the best and brightest from industry and academia,” he said. “We have shown that we can and that we must enlist the world’s leading talent in this cause.”

Across government and the private sector, responsible AI is a driving force in the development of AI tools. And Hegseth said within the War Department, responsible AI means AI that understands the department’s mission is warfighting, not the advancement of social or political ideology.

“I want to clarify what responsible AI means at the Department of War,” he said. “Gone are the days of equitable AI, and other DEI and social justice infusions that constrain and confuse our employment of this technology. Effective immediately, responsible AI at the War Department means objectively truthful AI capabilities, employed securely and within the laws governing the activities of the department. We will not employ AI models that won’t allow you to fight wars.”

Finally, the secretary said, the department’s pursuit of AI must include access to good data. The War Department and military services, he said, all have their own data assets, which, in many cases, are siloed. Hegseth said those silos will need to be opened.

“The U.S. military has an asymmetric data advantage from two decades of military and intelligence operations that no other military in the world can replicate,” he said. “But right now, we are underutilizing this advantage. Too much of our data is stranded. It’s stuck in bespoke programs, databases, locked behind [legal] stove pipes, invisible to operators, engineers and industry [partners] who can help us exploit it with winning speed and scale.”

Now, he said, all that data will be unlocked for AI exploitation, with each service secretary and component head required to submit catalogs of current data assets to the CDAO within 30 days. Hegseth said this also includes data from the department’s intelligence assets.

“Data hoarding is now a national security risk, and we will treat it that way,” he said.

Last month, Hegseth announced GenAI.mil, a website that makes a specialized version of the Google AI tool Gemini — Gemini for Government — available to War Department personnel. Now, he said, GenAI will expand its AI offering.

“We’re excited to announce the next frontier AI model company to join GenAI.mil, and that is Grok, from xAI, which will go live later this month,” Hegseth said. “I want to thank you, Elon [Musk], and your incredible team, for leaning forward with us on this as well. Very soon, we will have the world’s leading AI models on every unclassified and classified network throughout our department — long overdue.” (Source: U.S. DoD)

——————————————————————————————————————————————————————————————————————————————————————————————————————————————-

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

—————————————————————————————————————————————————————————————————————————————————————————————————————————————

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

January 9, 2026 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

————————————————————————————————————————————————————————————————————————————————————————————————————————————————-

09 Jan 26. L3Harris ROVER and TNR Products Receive NSA Approval for International Sales Empty heading. For the first time ever, new ‘C’ variants allow international users to interoperate with U.S. personnel via NSA-certified cryptography. The U.S. National Security Agency has officially approved L3Harris’ ROVER® 6Sc Intelligence, Surveillance and Reconnaissance terminal and Tactical Network ROVER 2c handheld ISR terminal for use with the NICM100 security module. For the first time ever, coalition partners with approval from the U.S. Department of State can purchase an upgrade for their transceivers through L3Harris to be interoperable with U.S. troops when they operate with NSA encryptions. The NSA crypto cores are available to eligible allies through Foreign Military Sales contracts.

“This effort was only possible through close collaboration between L3Harris and the NSA on an expedited approval process, and these two products are the first test cases validated with this concept. We are now pursuing approvals through this process for the rest of our video datalink products including CMDL 2c as soon as their respective U.S. domestic variants complete certification.” – Byron Anderson, Director, Product Line Management, L3Harris

Designed for air, surface and maritime use, The L3Harris ROVER line of products provides real-time, full-motion video (FMV) and other network data for situational awareness, targeting, battle damage assessment, surveillance, relay, convoy overwatch operations and other situations where eyes-on-target are required. Embedded frequency diversity provides link redundancy, robust reception and resiliency to platform shadowing, multi-path interference, line-of-sight blockages and RF interference. With an unmatched waveform set, ROVER 6S is interoperable with virtually all large airframes, UAVs and targeting pods in theater today. Until now, international customers were able to purchase exportable “i” variants of the ROVER line, which are not capable of interoperability with systems operating on NSA high-assurance channels. The approval of the “c” variants opens an array of protected coalition interoperability between U.S. troops and troops from more than 50 applicable nations. (Source: ASD Network)

 

08 Jan 26. Defenceless. Just what was that thing flying around the building? It was quite late and a pair of red lights were darting above the street. A buzzing sound led to the inevitable conclusion that the strange flying object was a radio-controlled Uncrewed Aerial Vehicle (UAV). Giggling youngsters were standing on one of the apartment building’s balconies. One was using their smartphone to control the aircraft while the others watched the UAV’s camera footage on the small screen. Your editor was not quite so amused. The unauthorised flight of a UAV in their hometown is a criminal offence. These aircraft can risk injury to those on the ground, damage to property and may present a hazard to air traffic: The local airport is a few kilometres away, and a general aviation aerodrome even closer. Furthermore, flying a UAV with a camera near housing raises serious privacy concerns. At one point the aircraft hovered close to your editor’s balcony and stayed stationary for several seconds. The resulting hand gesture persuaded the pilot that his aircraft was not welcome. The local police duly appeared and heard from residents witnessing the flight, some of whom had helpfully filmed the errant UAV. Officers were seen minutes later on the balcony of the UAV pilot’s apartment. The aircraft had returned and was being confiscated, statements were being taken and the pilot was led downstairs to a waiting police car. Conversations with the local constabulary revealed a striking gap in their law enforcement capabilities. Officers confided they had no means to detect an unauthorised UAV nor to safely engage that aircraft and force it to land. Nor could they determine where the aircraft was being flown from. Using their own firearms to shoot the UAV out of the sky was strictly prohibited. The officers said that such a small, mobile target would represent an almost impossible marksmanship challenge, particularly on a dark night. Perhaps it is time for urban areas to be outfitted with basic UAV detection systems that could notice the tell-tale radio link between the aircraft and its pilot? Two or more of these systems positioned on cellphone towers or tall buildings would notify the police that a UAV is flying, possibly illicitly. It could also give a potential indication of the pilot’s location through triangulation. It might be possible to team these detection systems with rudimentary jammers. The latter would attack the radio link causing the UAV to either land in situ or return to its point of origin. This useful radio data could be recorded and perhaps used in court as evidence. Recent weeks and months have seen a surge in illegal UAV flights across Europe in NATO nations. These have occurred near airports with the aim of disrupting air traffic. The UAV flights are blamed on Russian operatives or sympathisers seeking to cause disruption and threaten critical national infrastructure. Outfitting law enforcement with counter-UAV systems would help protect urban areas against dangerous UAV flights. Making such an investment may be far less expensive than the potential physical damage and disruption unauthorised UAV use may cause. (Source: Armada)

 

08 Jan 26. Movin’ On Up. Russian uninhabited aerial vehicle pilots are increasingly using the Starlink satellite communications constellation for aircraft control. In December 2025, Armada published an article explaining how Russian land forces occupying parts of Ukraine use the Starlink Satellite Communications (SATCOM) constellation. This constellation is chiefly used to provide backhaul links from deployed units at, or near, the tactical edge to higher echelons of command. Although SpaceX, Starlink’s owner, does not provide the constellation’s coverage over Russia, Russian forces can exploit Starlink coverage provided above Ukraine. Starlink provides wideband links across Ku-band (14 gigahertz/GHz uplink/10.9GHz to 12.75GHz downlink) and Ka-band (26.5GHz to 40GHz uplink/18GHz to 20GHz downlink) channels. Armada understands from Ukrainian sources that some Russian Uninhabited Aerial Vehicles (UAVs) are outfitted with Starlink SATCOM terminals. Starlink can be used by UAV pilots to control their aircraft. Traditionally, UAVs employ air-to-surface/surface-to-air radio links to connect the aircraft and pilot. Prior to the second Russian invasion of Ukraine in February 2022, these communications were typically confined to wavebands of 2.4GHz and 5.8GHz. These frequencies are been earmarked by the International Telecommunications Union (ITU) for civilian UAV control. The ITU is the United Nations organisation responsible for the global regulation of the radio spectrum.

The frequency battle

UAV control frequencies were a key target for Russian and Ukrainian Electronic Warfare (EW) cadres. Jamming this radio link would cause the aircraft to either land in situ or return to its point of origin. In both cases, these features were standard failsafe controls for civilian drones pressed into military service. The assumption of the failsafe mechanism is that the loss of the link would stop the pilot controlling the aircraft. As Armada has chronicled in the past, Russian land forces’ EW systems such as the RP-377U/UV can hold these frequencies at risk. The response from the UAV engineers of both sides has been to expand the frequencies that can be used to link an aircraft to its pilot. Armada understands that a waveband of 200MHz to twelve gigahertz is now used in the Ukraine theatre of operations for UAV control. Moreover, there is a continued need to ensure UAV control channels are agile. No sooner is one channel or frequency employed for UAV control been used than it gets jammed. Radio links must continually hunt for unoccupied and unjammed frequencies that they can momentarily exploit before these also get jammed.

Into space

As the 200MHz to twelve gigahertz waveband became increasingly contested and congested, it was inevitable that both sides would look elsewhere in the radio spectrum for UAV control frequencies they could employ. Russia has been able to obtain Starlink terminals illicitly via suppliers in third party nations like the United Arab Emirates, Armada understands. As well as being used for land forces trunk communications, some of these terminals now furnish Russian UAVs. The relatively high Ku-band and Ka-band links employed by Starlink are relatively difficult to jam. These beams are noticeably narrow. A jamming signal must be pointed directly at the antenna if it is going to be received. This is particularly difficult if the Starlink antenna is mounted atop of a UAV and pointing towards the sky. A hostile aircraft, inhabited or otherwise, would need to be above the targeted UAV pointing its jamming signal downwards to have a chance of success. As well as being difficult to jam Starlink has a further attraction for Russian UAV pilots as it carries significant quantities of data. According to Starlink, users typically enjoy download speeds of between 25 megabits-per-second/mbps and 220mbps. Upload speeds of between five megabits-per-second and 20mbps are also achievable. These data rates mean the aircraft can send back detailed video pictures during their flight. This clarity helps the pilot ensure the correct target is being reconnoitred or, in the case of a suicide UAV, attacked. A further benefit of using Starlink is that the channels provide low latencies of between 25 milliseconds/ms and 100ms. A pilot who maybe hundreds of nautical miles away from their aircraft, controlling it across a beyond-line-of-sight SATCOM link, can send commands which the aircraft will respond to in near real time. This will help the aircraft avoid heavily defended areas as and when these are discovered during its flight. It is noteworthy that Starlink terminals on UAVs may be teamed with Global Navigation Satellite System (GNSS) Position, Navigation and Timing (PNT) receivers using several receiving elements on a circular array. Using several elements helps a GNSS receiver to detect and block out areas where jamming or fake PNT signals are being transmitted.

Outlook

North Atlantic Treaty Organisation (NATO) and allied nations should take note of Russia’s approach to UAV control and GNSS PNT resilience. There is an imperative to develop capabilities which can jam Starlink terminals used by aircraft like UAVs. Likewise, EW engineers must continue efforts to nullify Russian GNSS PNT resilience techniques. The UAV battle in Ukraine is helping to drive tactical ingenuity regarding aircraft control and navigation. Overcoming such techniques will help NATO and its allies potentially annul Russian advances in UAV electronic protection. (Source: Armada)

 

06 Jan 26. Keeping it Real. The Air Defender computer game faithfully replicates the recognised air picture that fighter controllers use to detect potential targets, and to vector fighters and their supporting tanker and AWACS assets. An exciting new computer game replicates the tensions inherent in the control and reporting centre bunker of a contemporary integrated air defence system. Flight simulator games mimicking an aircraft’s cockpit have long been a staple of the video gaming world, but games replicating Integrated Air Defence Systems (IADSs) less so. However, a new game entitled Air Defender has bucked this trend. Launched for early access on the Microsoft Steam gaming platform, Air Defender has been available since late November 2025. Air Defender aims to replicate the feel and tasks of an IADS Control and Reporting Centre (CRC). As a player you are tasked with protecting a segment of the United Kingdom’s airspace. Using your radar screen, you must detect suspicious air activity. Fighters must be scrambled and vectored towards air threats and ordered to engage if necessary. The player also has authority over the tanker and airborne early warning and control system aircraft supporting the fighters.

Past experience

Air Defender is the brainchild of Allan Akers who is a former Royal Air Force (RAF) fighter controller and now director of the ROTOR3 game studio which developed it. Mr. Akers told Armada that Air Defender “began simply because I wanted to play a game based on my old job in the RAF”. He was particularly keen to focus on the air defence command and control element and noted a gap in the gaming world to this end: “I started building it purely for myself. I genuinely didn’t think anyone outside the radar community would take an interest”. A few videos were shared online of early versions and “the response was incredible … That enthusiasm is what convinced me to keep going and turn it into something much bigger”. Challenging aspects of the game’s development included replicating the CRC room experience in a way “that is both authentic and enjoyable for players”. Mr. Akers recalls that air defence work can involve long, quiet stretches followed by sudden, intense activity: “Translating that into a compelling game without losing the essence of how the job feels has been very difficult”. Enabling early access on Steam has been vital in helping the game’s development.

Players learn all about the air defence mission. For example, identification friend or foe procedures are explained and replicated. The learning curve is comparatively gentle. Neophytes can use the Easy mode which substitutes standard RAF brevity codes for plain English. The game will have relevance for those considering a career in air defence, or keen to understand more about that world: “As tutorials, missions and support material are added, the potential for it to be used as an informal learning tool will only increase”

Multiplayer

Although only recently released, there is already great growth potential for the game: “I plan to add more maps, including places I have personally worked such as the Falkland Islands and the Arabian Gulf”. Over the longer term Mr. Akers hopes to create “a series of titles that cover the full history of air defence, starting in the Second World War and moving into the modern era and beyond”. A multiplayer function is in the offing which would see players collocated in a virtual CRC bunker. In this mode, each player would assume specific operational roles. This is something Mr. Akers believes will completely transform the Air Defender experience. Full release is set for 27th November 2026, and everyone who buys the early access version will receive all updates at no extra cost. Ultimately, Air Defender “gives players a very genuine sense of what the day-to-day experience is like”. Those who want to learn more should head over to Steam and buy early access: “For anyone curious about the world behind the radar screen, this is about as close as you can get without putting on a uniform”. (Source: Armada)

 

05 Jan 26. January Spectrum SitRep.

Armada’s monthly round-up of all the latest electronic warfare news in the product, programme and operational domains.

GRIMM Tales

Huntington Ingalls Industries (HII) has moved into the Electronic Warfare (EW) market via its mission technologies division. The company unveiled its new GRIMM spectrum dominance system which was showcased during the 2025 Association of Old Crows International Symposium and Convention.  This event was held between 9th and 11th December at National Harbour in Maryland. According to a company press release, GRIMM is will detect and locate hostile communications and radar signal and “other electronic threats”. Company information says the system can detect, direction-find and geolocate threats across wavebands of ten megahertz up to 18 gigahertz. GRIMM is optimised for size, weight and power constrained platforms like uncrewed aerial vehicles as it weighs under two pounds (one kilogram). Other applications mooted by HII include high-altitude balloons and aerostats, backpack and static node deployments. The company told Armada that it is integrating “the GRIMM payload into group two and group three UAVs for deep sensing operations” together with long range uncrewed surface vessels for maritime EW applications. The continual improvement of GRIMM is expected by the company “as technology and techniques advance”. These improvements will take the form of “implementing (and) releasing features such as software (and) firmware updates that increase accuracy or decrease latency. This is necessary to keep pace with (and) outpace evolving adversary threat technologies and warfighter requirements for solutions”. HII has provided GRIMM payloads to the United States Army and deliveries of the system are ongoing.

AI-Enabled Vessel ID

In early December 2025 HawkEye 360 announced it had introduced a new vessel tracking identification system which uses Artificial Intelligence (AI) to “assign unique tracking identifiers” according to a company press release. This lets “organisations … maintain custody of high interest vessels across time and space”. The new capability uses AI to provide “unique identifiers (to) maintain tracking continuity of vessels”. Other features of this new capability include “(r)eliability ratings (to) provide transparency into the strengths of vessel custody certainty”. Meanwhile “speed and course attributes add context to custody threads and support behaviour analysis”. Finally, “space-based collection extends visibility into denied, contested, or politically sensitive regions”. The company said that “(b)y reducing manual workload and scaling analytic outputs, this AI-enabled maritime custody capability enhances the ability of defence and intelligence organisations to build patterns of life, expose deceptive behaviours and direct resources more effectively across global areas of interest”. HawkEye 360 told Armada, via a written statement, that these new capabilities are available now “for a defined set of maritime signal types that (the company) currently geolocates (and) it is already deployed to customers to support active missions”. Moreover, “(HawkEye 360) expects rapid expansion across additional frequencies and areas of interest as we scale the underlying models and integrate the feature into new collections”. (Source: Armada)

 

06 Jan 26. India: Pakistan-linked groups will elevate long-term security risks to government, academic sectors. On 2 January, international news outlets reported that a Pakistan-linked cyber group (‘Transparent Tribe’) has been targeting Indian organisations in a cyber espionage campaign since at least December 2025. The campaign has targeted Indian academic, government and other entities via spear phishing emails containing weaponised .LNK files disguised as PDF files. Opening the .LNK file executes a script that loads a remote access trojan (RAT) directly into the memory of compromised devices, while also opening a decoy PDF. Notably, the RAT will adapt its persistence method depending on the device’s antivirus solutions, pointing to the sophistication of the malware. The RAT is capable of establishing complete remote control over an infected machine, facilitating data exfiltration, file management and other process controls while evading detection. We assess that, amid bilateral tensions, the campaign underscores the long-term security risks facing Indian organisations as Pakistan-linked groups continue to target the government and academic sectors. (Source: Sibylline)

 

05 Jan 26. Australia Defence completes mySPECTRA testing ahead of EMS upgrade. The system is expected to be rolled out and become operational by March this year. Australian Defence has concluded operational test and evaluation of mySPECTRA, a new software tool intended to modernise electromagnetic spectrum (EMS) management across the Australian Defence Force (ADF). The system, designed to streamline frequency assignment and protection for ADF units, is expected to become operational by March 2026. Personnel conducted two weeks of assessments in early November 2025, examining the software’s performance and workflow integration. According to Defence Spectrum Office, director Paul Burford, these trials played a key role in identifying areas for improvement prior to deployment.

“The testing allows us to see how the services and ourselves will use the systems and identify any areas that need to be addressed,” Burford said.

mySPECTRA is designed to enable more effective planning and manoeuvre within the EMS during training activities and operations, which Defence considers an important element in managing the cyber domain. Burford said the system could be used during a large joint training exercise where several ADF units require access to radio frequencies at the same time.

“It will enable the services to make more assignments themselves and speed up the provision of radio frequencies for what they require,” he added.

Previously, frequency clearance requests involved several manual approval processes, which delayed coordination efforts.

The introduction of mySPECTRA allows frequency managers to assign and de-conflict channels in real time, which Defence expects will reduce interference and support more reliable communications throughout ADF domains. The system also introduces advanced analytical tools to facilitate more precise area-based planning.

Corporal Joshua Telfer, Land Electromagnetic Spectrum Operations Cell Detachment Commander at Army Headquarters, participated in the evaluation process. “It’s going to improve the efficiency of what we do, because we spend a lot of time messing around with data transfers because the old software is outdated,” corporal Telfer said. (Source: naval-technology.com)

 

05 Jan 26. Global: Abuse of legitimate software services will sustain elevated security, phishing risks to firms. On 2 January, international news outlets reported that unnamed threat actors abused legitimate Google services to target organisations in a phishing campaign in December 2025, impacting global users across a variety of sectors including manufacturing, technology and financial services. The campaign abused Google Cloud’s Application Integration Send Email feature to send emails from Google-owned domains without compromising Google itself. This facilitated the emails’ believability and bypassed spam detection tools. The emails used lures, such as voicemail alerts and shared file access requests, to trick users into clicking malicious links. Then, the threat actors directed users to a Google domain with fake CAPTCHA checks to evade scanners and subsequently to a fraudulent Microsoft login page to harvest credentials. We assess that this campaign increases the likelihood of follow-on attacks on organisations in the short-to-medium term. As threat actors continue to abuse legitimate cloud services, long-term security and targeting risks will persist for global entities. (Source: Sibylline)

 

05 Jan 26. CSIR successfully demonstrates broadband underwater communication system for Armscor. The Council for Scientific and Industrial Research (CSIR) has successfully demonstrated a broadband underwater data communication system to Armscor, which aims to develop fast and reliable acoustic underwater data transfer for naval operations. The CSIR achieved near-perfect transmission and data rates exceeding 240 kbps during a demonstration of the latest version of the system at the CSIR’s underwater acoustic testing facility, the organisation said in its latest 2024/25 annual report.

“This technology aims to transmit data, such as sonar images, over distances of up to 500 metres, enhancing the capabilities of the South African Navy during naval operations. Researchers implemented multiple-input multiple-output technology, utilising multiple transmitter and receiver transducers to improve the broadband underwater data communication system. This technology provides greater transmission bandwidth, allowing for enhanced signal reliability and increased data rates. In addition to software development, new mechanical and electronic hardware was developed for two buoy-mounted, stand-alone transmitter and receiver systems,” the CSIR stated.

Rapid wireless underwater data transfer is becoming ever more crucial, it noted, particularly for autonomous underwater vehicles – modern devices capable of mapping the ocean floor, inspecting underwater structures and ensuring the safety of waterways. Researchers also explored live video streaming techniques for the system during the demonstration. Also on the naval front, the CSIR recently installed its sonar demonstrator into a new towfish as part of efforts to ensure that the South African Navy benefits from technological advancements that enhance safe underwater operations. The towfish supports rapid deployment and testing in real-world aquatic environments, the Council said. “The synthetic aperture sonar demonstrator captures high-resolution acoustic images of the seafloor. The South African Navy uses different sonar systems, such as multibeam and side-scan sonars, to navigate and detect underwater threats. These systems support obstacle avoidance, underwater reconnaissance and mine detection. They rely on advanced hardware and software and require extensive expertise for operation, maintenance and platform upgrades. The CSIR has improved the sonar system by developing proprietary acquisition and processing software that leverages high-performance single-board computers equipped with cutting-edge graphics processing unit technology. This enables the rapid processing of sonar data to produce final images in near-real-time. As a result, the CSIR is advancing toward real-time image formation with sonar systems.” The Council noted that optimal sonar systems are essential for submarines and surface vessels to operate safely and effectively at sea. (Source: https://www.defenceweb.co.za/)

—————————————————————————————————————————————————————————————————————————————————————————————————————————————-

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

———————————————————————————————————————————————————————————————————————————————————————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

December 28, 2025 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

—————————————————————————————————————————————————————————————————————————————————————————————————————————————–

19 Dec 25. S3NS announces SecNumCloud qualification for PREMI3NS, its trusted cloud offering

  • PREMI3NS, S3NS’ (pronounced “sense”) trusted cloud offering, has now received ANSSI’s SecNumCloud qualification, meeting the most stringent protection requirements against extraterritorial laws in France and Europe
  • The fruition of the partnership between Thales and Google Cloud enables organizations from the private and public sectors to innovate and transform with one of the broadest ranges of managed services in a trusted cloud environment
  • Early adopters of S3NS include companies from the insurance, manufacturing, healthcare and finance industries

ANSSI delired the SecNumCloud 3.2 qualification for S3NS’PREMI3NS offering, meeting all its requirements and passing all three milestones of the qualification process. S3NS, a subsidiary of Thales in partnership with Google Cloud, today announced that PREMI3NS, its “Trusted Cloud” (Cloud de confiance) offering, has received the SecNumCloud 3.2 qualification delivered by the French National Agency for the Security of Information Systems (ANSSI). Meeting SecNumCloud 3.2’s protection and resilience requirements, which are known as the most demanding ones in France and Europe, it offers immunity from non-European extraterritorial laws. With PREMI3NS, S3NS now offers businesses and public sector organizations the most extensive cloud service among the offerings that have received the SecNumCloud 3.2 qualification. PREMI3NS integrates the most advanced IaaS and PaaS technology from Google Cloud.

“The SecNumCloud 3.2 qualification is the result of the unparalleled collaboration between two cloud and cybersecurity leaders. It opens new opportunities for the French and European markets. Never has a SecNumCloud 3.2 – certified cloud offering included such a wide range of managed services. PREMI3NS will enable its customers to innovate, optimize, and transform with utmost confidence and security with their most sensitive applications. As a matter of fact, Thales group has chosen S3NS for its own IT and its sensitive engineering.” said Christophe Salomon, Deputy CEO, Secure Information and Communication Systems, Thales.

The SecNumCloud 3.2 qualification results from the original strategic partnership between Thales and Google Cloud and the creation of S3NS in 2022. It is the assertion of theirombined ambition to offer an unparalleled solution on the market and is now available to all public and private organizations. With this qualification, S3NS, a company operating under French law and fully controlled by Thales, fulfills its commitment to deploying the most feature-rich cloud offering meeting the SecNumCloud 3.2 requirements on the market within three years of its creation.

PREMI3NS is operated and managed exclusively by S3NS employees in data centers located in France. All cloud technologies and their updates are quarantined, analyzed and then validated by S3NS before the company manages them in its dedicated infrastructure.

The SecNumCloud 3.2 framework is the most demanding standard for cloud security in Europe. France is currently the only country to require its public sector organizations to comply with its requirements when managing sensitive data, as the government commits to guaranteeing French citizens the optimal protection of their data.

Organizations are already choosing S3NS

PREMI3NS, now SecNumCloud-qualified, has been accessible for several months as part of S3NS’ “early adopters” program and tested by about thirty pioneering customers. S3NS is currently supporting insurance companies (MGEN, Matmut, AGPM), companies from the manufacturing industry (Thales, Birdz, a subsidiary of Veolia), the financial sector (Qonto, BConnect) and services (Club Med) as they progressively migrate to the “Trusted Cloud” and leverage the combined expertise of Thales and Google Cloud. EDF selected S3NS for the storage, processing, and valorization of the Group’s strategic data, and Thales is already using PREMI3NS for its internal information system and its engineering.

The broadest range of cloud services with the SecNumCloud qualification on the market

PREMI3NS offers a large portfolio of IaaS, PaaS, and CaaS services, allowing organizations to operate their most sensitive applications in a high-performance and trusted environment. The offering revolves around fundamental and proven Google Cloud technological components, such as Compute Engine for virtual machine management, Cloud Storage for data storage, and Cloud SQL for relational databases. This robust foundation provides access to all the capacity, innovation, and robustness of the cloud through advanced managed services, including Google Kubernetes Engine for containerization, BigQuery for the market-leading, serverless, and highly scalable data warehouse preparing for an easy transition to AI, as well as cutting-edge solutions for network and interconnection management.

This extensive service portfolio will continue to grow in the coming months with S3NS notably preparing the integration of generative artificial intelligence solutions, and reaffirming its commitment to providing its customers with constant access to the most innovative technologies, within a trusted framework.

About S3NS

An alliance between Thales, a global leader in data protection and cybersecurity, and Google Cloud, a global leader in cloud technologies, S3NS offers public institutions and private companies, concerned about further protecting their most sensitive data, highly secure public cloud offerings to operate their transition to the trusted cloud, meeting the criteria of the ANSSI SecNumCloud framework. S3NS is a company under French law entirely controlled by Thales.

 

22 Dec 25. Lockheed Martin (NYSE: LMT) and MANTECH today announced a strategic teaming agreement to integrate advanced AI driven sustainment solutions into the U.S. combat aircraft fleet.

Why It Matters

Through this effort, we will deliver real-time aircraft performance monitoring, predictive maintenance, optimized logistics support and improved mission availability across legacy and next-generation platforms, while adhering to the highest standards of security.

Strategic Perspectives

“This collaboration between Lockheed Martin and MANTECH will generate a unified team of strengths, capable of creating resilient sustainment ecosystems that can be projected to America and its allies around the world,” said Nicholas Smythe, vice president, Business Development for Sustainment at Lockheed Martin.

“This partnership delivers the real-time performance needed to maximize the readiness and operational lifespan of the U.S. combat aircraft fleet,” said MANTECH Defense Sector President David Hathaway.

Dive Deeper

This collaboration leverages Lockheed Martin’s AI Factory and MANTECH’s extensive experience in defense analytics, enterprise modernization and secure mission integration to accelerate reliability, readiness and operational efficiency across forces.

 

23 Dec 25. Global: New encryption tool underscores elevated data-theft, financial risks to businesses. On 20 December, international news outlets reported that a known ransomware-as-a-service (RaaS) operation (‘RansomHouse’) is using a new sophisticated encryptor (‘Mario’) variant to conduct ransomware attacks. Reportedly, Mario relies on a two-stage transformation process that enhances data encryption efforts to prevent partial data recovery and to increase pressure on victims to pay the ransom. The encryptor uses multiple techniques including a new file processing strategy, enabling intermittent encryption and subsequently enhancing obfuscation from static analysis mechanisms, highlighting the tool’s sophistication. We assess that RansomHouse likely uses Mario to encrypt a system’s virtualised environment, after exfiltrating sensitive information that it can use for extortion and illicit financial gain. Since its emergence in December 2021, the group has consistently prioritised the development of advanced tools, despite its lower frequency of activity. This likely indicates that RansomHouse prioritises efficiency over quantity, thus underscoring elevated security, data-theft and financial risks to global businesses. (Source: Sibylline)

 

18 Dec 25. Kongsberg to Start Production of Thor Vehicle Radios for the Norwegian Armed Forces. Kongsberg Defence & Aerospace (‘KONGSBERG’) has signed a contract with the Norwegian Defence Materiel Agency (NDMA) for the initial deliveries of THOR vehicle radios to the Norwegian Armed Forces. The contract is valued at around NOK 650m and includes delivery of THOR VRM (Vehicle Radio Module) units starting in 2027. The agreement also includes measures to increase production capacity, ensuring that future orders of THOR VRM vehicle radios can be delivered more quickly.

“The THOR radio ensures wireless communication for the Armed Forces’ combat units under the most demanding conditions, both in terms of geography and hostile electronic warfare,” said Eirik Lie, President of Kongsberg Defence & Aerospace.

highly flexible and can be upgraded with software-based capabilities that enable direct interoperability with allied forces, ground-to-air communication, drone communication, and satellite-based communication. The THOR radio system will replace the current MRR (Multi-Role Radio) as the Norwegian Armed Forces’ primary robust communications platform.

“For us, it has been important to secure a long-term agreement that ensures reliable deliveries in the years to come. The procurement demonstrates KONGSBERG’s ability to develop communication equipment for the defence capabilities of tomorrow,” says Gro Jære, Director of the Norwegian Defence Materiel Agency. The contract ensures that NDMA receives deliveries of THOR VRM vehicle radios that meet the current needs of key combat units, as well as the capacity to supply radio equipment for the entire new force structure approved by the Norwegian Parliament (Stortinget). (Source: ASD Network)

 

22 Dec 25. The War Department to Expand AI Arsenal on GenAI.mil With xAI. GenAI.mil, recently launched as the War Department’s bespoke AI platform, will soon be expanded with the addition of xAI for Government’s suite of frontier‑grade capabilities. Today, the War Department officially entered into an agreement with xAI, paving the way for the deployment of its advanced capabilities on GenAI.mil. This move builds on the rapid deployment of cutting‑edge AI across the Department’s 3 m military and civilian personnel. This initiative will soon embed xAI’s frontier AI systems, based on the Grok family of models, directly into GenAI.mil. Targeted for initial deployment in early 2026, this integration will allow all military and civilian personnel to use xAI’s capabilities at Impact Level 5 (IL5), enabling the secure handling of Controlled Unclassified Information (CUI) in daily workflows. Users will also gain access to real‑time global insights from the X platform, providing War Department personnel with a decisive information advantage. The War Department will continue scaling an AI ecosystem built for speed, security, and decision superiority. Newly IL5-certified capabilities will empower every aspect of the Department’s workforce, turning AI into a daily operational asset. This announcement marks another milestone in America’s AI revolution, and the War Department is driving that momentum forward. (Source: U.S. DoD)

————————————————————————————————————————————————————————————————————————————————————————————————————————————-

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

————————————————————————————————————————————————————————————————————————————————————————————————————————————–

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

December 18, 2025 by

 

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

—————————————————————————————————————————————————————————————————————————————————————————————————————————————-

18 Dec 25. Hot Lines, Cool Minds. On 20th June 1963, the United States and Soviet Union signed the Memorandum of Understanding Regarding the Establishment of a Direct Communications Line. The memorandum paved the way for what would become known as the Moscow-Washington Direct Communications Link. You may not have heard of this, but you will have almost certainly heard of the ‘hot line’. In many peoples’ imagination, the hot line included red telephones on the desks of the US and Soviet leaders. The Cuban Missile Crisis had erupted a year earlier in October 1963. One of the lessons learned for both sides was a need for the political leadership of both countries to be able to communicate directly with one another in times of strife. Contrary to popular imagination, the hot line did not use red telephones. Instead, a secure teletype machines were employed. Written messages were thought to leave less chance of misunderstanding. By 1986, the teletype machines had been replaced by fax machines (remember them?) As of 2008, the American and Russian leadership has been linked with a dedicated, secure email service. Traffic was originally carried across undersea cables which were later supplemented by satellite communications. The hotline has more than earned its keep being used on numerous occasions to help reduce tensions between the US and the Soviet Union and, after the end of the Cold War, between the US and Russia. A hotline has been in existence between Beijing and Washington DC since November 2007. Like the Moscow-Washington line, the direct link between the United States and the People’s Republic of China has been used on multiple occasions. That said, the Chinese government has also chosen to withhold direct communications channels in times of tension between the two powers. Despite this, these links are being enhanced further following the news in early November that direct military-to-military channels to help deescalate potential flashpoints between the two countries will be established. The decision followed a meeting between US President Donald Trump and his Chinese counterpart Xi Jinping. Both countries should be praised for taking this cause of action, particularly in terms of improving military-to-military direct communications. That hotlines between Washington DC, Moscow and Beijing have helped ease tensions in times of crisis is not in doubt. The stronger the communications between all three powers, the higher the chances that politico-military leaderships can ‘talk things out’. Even a chat between an opposing general and admiral could be just the thing to help to start to diffuse a crisis at the optimum moment. British Prime Minister Winston S. Churchill said that “meeting jaw to jaw is better than war” reflecting on the importance of personal contact in times of trouble. When leaders cannot meet face to face, they can at least write to each other directly. After all, hot lines help cool minds. (Source: Armada)

 

08 Dec 25. GCAP SATCOM Strategy. The Global Combat Air Programme will develop an air platform with an advanced satellite communications capability to ensure connectivity in heavily congested and contested electromagnetic environments. (BAE Systems) More details are emerging regarding the communications architecture that will support the Global Combat Air Programme sixth-generation combat aircraft. The Global Combat Air Programme (GCAP) is a multinational project involving Italy, Japan and the United Kingdom to develop a new combat aircraft. Reports state that the first technology demonstrator aircraft is expected to fly in 2027. Service entry is expected from circa 2035. The aircraft’s communications architecture will be a key enabler for the platform as it is expected to work closely with accompanying Uncrewed Aerial Vehicles (UAVs), inhabited platforms and other military assets. Satellite Communications (SATCOM) form a key part of the aircraft’s connectivity. Armada understands that the jet is expected to benefit from global SATCOM coverage including satellite communications provision over the poles. Traditionally, SATCOM coverage has suffered shortcomings in these areas. GCAP SATCOM requirements emphasise low latency and high bandwidths. These features are particularly important as the pace of contemporary and future air combat places a premium on keeping gaps in signal transmission and reception to a minimum. Likewise, the GCAP platform is likely to continuously collect eye-watering quantities of data via its sensor package. Much of this data will be processed on the aircraft at the point of collection. Processing will depend on Artificial Intelligence (AI) enabled edge computing applications. Nonetheless, the platform will still need to send and receive significant quantities of relevant data to and from combat clouds. These clouds will underpin future operations connecting multitudes of assets as part of the North Atlantic Treaty Organisation’s Multi-Domain Operations (MDO) doctrine.

Operating in congested and contested spectrum

Other requirements for the GCAP SATCOM architecture include the ability to use several different bearer networks, frequencies and wavebands, and to do so seamlessly. This implies that the architecture will use cognitive approaches underpinned by AI. Cognitive communications use AI to continually search for and use optimum channels for communications according to the level at which the local radio spectrum is congested and contested. At the same time, the significant reliability the aircraft will have on SATCOM creates potential vulnerabilities: The plane’s location could be derived via its radio emissions. Moreover, these signals could be jammed or spoofed. A similar risk exists that SATCOM antennas could be exploited as an aperture through which jamming/spoofing waveforms and/or cyberattacks could enter the aircraft. The latter could see malware not only contaminating the platform, but the networks it depends on and other military assets connected therein. Low probability of interception/detection SATCOM waveforms will be front and centre of the aircraft’s electronic protection and communications resilience.

Configurations

How will these requirements for bearer network and frequency flexibility and resilience by realised? Sources close to the programme emphasise the aircraft’s SATCOM system will have a multi-frequency, multi-bearer, multi-orbit design permitting the use of a diverse array of networks and constellations. Avantgarde SATCOM techniques will employed like free space optical communications. Relying on light as opposed to radio signals, this communications methodology does enjoy some protection against electronic attack. The aircraft’s ground element will similarly need to be robust, agile and deployable. The ongoing war in Ukraine continues to show that ground-based SATCOM infrastructure remains a target for electronic warfare. SATCOM receivers are at risk not only from jamming, spoofing and cyberattack, but also from kinetic action. Some questions remain regarding the overall GCAP communications architecture: What will the aircraft employ in terms of conventional radio links? What are the expectations regarding GCAP’s employment of tactical datalinks? Will the aircraft also use cognitive methodologies in its other communications systems? What is the relationship of the aircraft’s radio communications and other RF systems like its radar and EW apparatus? Work is no doubt continuing to address these questions and requirements, although information is yet to reach the public domain. GCAP is following an aggressive schedule with the first flight of the demonstration aircraft expected in two years. The project’s engineers have an aggressive schedule to perfect the aircraft’s communications systems. They must also produce what will arguably be the most advanced connectivity architecture yet installed on a combat aircraft. (Source: Armada)

 

16 Dec 25. Illicit Channels.  Russian forces are also using Starlink terminals for UAV communications. Russia is primarily using the Starlink satellite communications network for backhaul at the tactical edge and for uncrewed aerial vehicle control, Armada has learned. Russian deployed in Ukraine are reliant on both SpaceX’s Starlink and Iridium Communications’ eponymous Satellite Communications (SATCOM) networks. Starlink provides wideband links across Ku-band (14 gigahertz/GHz uplink/10.9GHz to 12.75GHz downlink) and Ka-band (26.5GHz to 40GHz uplink/18GHz to 20GHz downlink) channels. According to Starlink, users typically enjoy download speeds of between 25 megabits-per-second/mbps and 220mbps. Upload speeds of between five megabits-per-second and 20mbps are also achievable. Armada understands that these rates reduce on the battlefield where uplink speeds of circa 3.72mbps and downlink speeds of up to 50.56mbps are routinely witnessed. This reduction can be the result of the deliberate jamming of Starlink frequencies. Latency rates across the link range between 25 milliseconds/ms and 100ms. Iridium Communications’ SATCOM services use L-band frequencies of 1.616GHz to 1.6265GHz. Furthermore K-band frequencies of 19.1GHz to 19.6GHz provide downlink and Ka-band channels using a 29.1GHz to 29.3GHz waveband are used for uplink, according to the company. Each Iridium channel has a 31.5 kilohertz/KHz bandwidth and channels are spaced 41.667KHz apart. Data rates offered by Iridium channels stretch from 176 kilobits-per-second/kbps to 700kbps. Iridium latency rates are around 395ms, give or take 100ms.

Russia’s Starlink and Iridium use

Russia has been blocked from using Starlink since May 2024, but this has not stopped her military obtaining Starlink terminals through illicit channels. On the battlefield, Russian forces typically connect their terminal to a router and thence, via a virtual private network, to a server in Asia, Europe or Russia. When connected thus, the user can access Russia’s internet via the Starlink terminal. The router and terminal can connect either with Wi-Fi or via a fibre optic cable. The latter helps reduce the chance of the terminal’s detection and geolocation via its Wi-Fi signal. Russia’s land forces deployed to Ukraine typically use Starlink terminals at, or close, to the tactical edge to provide backhaul communications to higher echelons. Given the distinctive square shape of the Starlink antenna Russian troops take strenuous efforts to camouflage these terminals to prevent them being spotted by reconnaissance. Camouflage netting is used, and terminals are hidden behind, or within, innocent-looking objects like debris. An added complication of using camouflage is that the coverings must blend in with the temperature of the surrounding area. This is essential to prevent the antenna’s thermal signature contrasting with the local landscape. For example, heat coming from the antenna can melt snow at a higher rate than it would do in the surrounding area. Once again, this can help thermal imaging optronics contrast the heat signature of the antenna from the local terrain. To an extent, Ukraine faces the tyranny of geography regarding Starlink provision. The country’s military depends on Starlink, particularly for the beyond line-of-sight links that SATCOM provision excels at. However, although Starlink coverage is not available in Russia, coverage continues in Ukraine. In some areas particularly over, or near, the frontline this coverage cannot be deactivated or jammed without having a detrimental effect on the ability of Ukraine’s troops to use Starlink. Armada understands that Russian forces typically use Starlink terminals at a between 20 kilometres/km (twelve miles) and 30km (19 miles) from the tactical edge. Regarding Iridium use, Armada understands that some Russian UAVs are outfitted with Garmin’s InReach Mini-2 satellite communications terminal to use the Iridium network. Usefully for the Russians this apparatus can also act as a global navigation satellite system position, navigation and timing signal receiver. Iridium receivers have been seen in the wreckage of Shahed-131 suicide UAVs Russian forces use to attack targets in Ukraine. Starlink terminals have also been installed on Russia’s Shahed-136 suicide UAVs to provide air-to-surface/surface-to-air communications. Armada understands that Starlink terminals may also provide air-to-air communications between Shahed-136s deployed in a swarm. In addition, Starlink terminals are being used onboard Russia’s new RD-8 UAV.

Assessment

Ukraine is in a bind regarding Starlink: Requesting SpaceX for the removal of coverage over the frontline would deprive Russian forces of Starlink, but not without doing the same to the Ukrainians. That Russia has obtained Starlink and Iridium terminals highlights the need to continue to restrict Moscow’s access to such kit. The acquisition of these terminals is being done covertly through third parties. There is an imperative on Ukraine’s allies to increase pressure on countries and jurisdictions unwilling or unable to clamp down on Russia’s acquisitions. The covert procurement of sanctioned SATCOM terminals can probably not be stopped outright. Alas, there will always be an unscrupulous regime, organisation or individual willing to turn a blind eye, or even help facilitate this trade. Nonetheless, working to prevent as many terminals as possible finding their way into Russian-occupied parts of Ukraine will help to hamper Russian battlefield communications. Hitting the communications links Russian land forces rely on will pay dividends in helping dislocate command and control. Russia’s tactical communications weaknesses are something that Armada has extensively chronicled since Moscow’s second invasion of Ukraine in February 2022. These weaknesses are a centre of gravity Ukraine can exploit as she strives to win and sustain electromagnetic superiority and supremacy. (Source: Armada)

 

18 Dec 25. Enhancing the HDRWF. A new capability contract has been concluded between the A4ESSOR consortium and OCCAR. What does this mean for the European Secure Software Defined Radio waveform initiative? On 3rd November the A4ESSOR consortium, which is developing the European Secure Software Defined Radio (ESSOR) set of tactical communications waveforms, made an important announcement. The consortium had signed a procurement contract with the pan-European OCCAR (Organisation Conjointe de Coopération en Matière d’Armement/Organisation for Joint Armament Co-operation) defence procurement agency. The contract paves the way for the “capability deployment” of the ESSOR High Date Rate Waveform (HDRWF), according to an A4ESSOR press release detailing the news.

HDRWF

ESSOR waveforms are being realised through a procurement initiative involving Finland, France, Germany, Italy, Poland and Spain. The a4ESSOR consortium is the programme’s industrial element involving Bittium, Indra, Leonardo, Radmor, Rohde and Schwarz, and Thales. All six countries will be introducing ESSOR waveforms into their tactical and operational communications over the coming years. Two of the ESSOR nations, Finland and France, have already introduced the HDRWF into service with their tactical radios. Two nations outside the ESSOR membership, Croatia and the Republic of Ireland, are also adopting the HDRWF. The HDRWF is an Ultra-High Frequency (UHF) waveform using a waveband of 225 megahertz/MHz to 400MHz. Up to 200 nodes can be accommodated on a single HDRWF network. The waveform can handle data rates of up to one megabit-per-second. It sustains full duplex data and voice-over-internet-protocol communications, and transmission security provision includes fast frequency hopping. The HDRWF can work in environments where Global Navigation Satellite System (GNSS) Position, Navigation and Timing (PNT) signals are badly degraded or denied. This waveform is not the only deliverable in the A4ESSOR portfolio: The ESSOR Three-Dimensional Waveform (E3DWF) is optimised for air-ground-air communications. E3DWF covers similar UHF wavebands to those of the HDRWF. The frequency-hopping E3DWF performs simultaneous voice and data transmission using frequency hopping Mobile Ad Noc Networking (MANET). E3DWF network synchronisation is provided using GNSS PNT signals. According to A4ESSOR up to 32 nodes can be accommodated on each E3DWF network. The ESSOR Narrowband Waveform (NBWF) is optimised to support communications in urban, rural, littoral, undulating and mountainous terrain using a MANET architecture. The waveform employs frequency hopping across wavebands of 30MHz to 88MHz, or 225MHz to 400MHz. Moreover, A4ESSOR says that up to 60 nodes can be accommodated on an NBWF network. Long term plans are afoot for A4ESSOR to introduce the ESSOR Tactical UHF Satellite Communications Waveform (ESATWF).

Contractual obligations

The press release stated that the capability deployment discussed above will see the design of a “common mission framework aimed at shared planning capability (for HDRWF) network parameters”. Once this work is completed, any nation using the HDRWF will be able to factor the waveform’s parameters and capabilities into their operational-level Command and Control (C2) systems. Having this capability enshrined in these C2 systems is imperative: Nations participating in multinational/coalition operations will be able to adequately plan the deployment of tactical/operational level communications networks using this waveform. A key aspiration of ESSOR is to deepen pan-European interoperability making this is a significant step. In addition, the contract covers the continued field testing of the HDRWF on a range of transceivers and networks to assess the waveform’s performance and reliability in various scenarios and environments. The latter includes rural, urban and undulating terrain, according to the press release. Scenarios include using the waveform for direct Line-of-Sight (LOS) and beyond LOS communications. Waveform performance in congested and contested electromagnetic environments will also be evaluated. The purpose of this ongoing testing is to aid the continual evolution and improvement of the waveform during its service life. Although the ESSOR programme has been in existence since 2008 it is now delivering important dividends as the HDRWF is already in service. The other waveforms are likely to follow this waveform’s example in the next five years. Given that the prevailing security environment in Europe vis-à-vis the threat from Russia is unlikely to improve any time soon, enhancing pan-European communications interoperability is vital. Fighting together demands robust, seamless C2 which in turn depends on reliable and secure waveforms. (Source: Armada)

 

18 Dec 25. December Radio Roundup. COMINT Consulting’s new v1.022 software release for the company’s Krypto1000 COMINT system increases the number of decoders for customers and also reduces decryption times. Armada’s monthly roundup of all the latest news in the military communications product, programme and operational domains.

New Krypto Software Enhancements

COMINT Consulting has performed a major release of new enhancements for the company’s Krypto500 and Krypto1000 Communications Intelligence (COMINT) software. The former covers Extremely Low Frequency (ELF: three hertz/Hz to 30Hz) and High Frequency (HF: three megahertz/MHz to 30MHz) communications. The Krypto1000 covers Very High Frequency (VHF: 30MHz to 300MHz) and Super High Frequency (SHF: three gigahertz/GHz to 30GHz) communications traffic. The company says that these latter wavebands can also include frequencies used for satellite communications. Dubbed software release V1.279 this can decode traffic from ISIRAN PRC-120 and VRC-131 HF tactical radios. Other systems like the Sunair T-9000E HF and CTM RKP-8100 multiband (1.5MHz to 512MHz) transceivers can also have their traffic decoded by V1.279 release. The company told Armada that “(s)everal new parsers, among them the HF2000 version of (the North Atlantic Treaty Organisation’s Standardisation Agreement-5066/STANAG-5066) have been added for increased intelligence extraction”. The process of parsing identifies “file types, users, formats in use and more” COMINT Consulting told Armada. This helps users “understand more quickly what to target (and what must not be targeted)”. Other new decoders can work with STANAG-4539 Annex-D configured traffic alongside decoders relevant to Codan’s 3012, 3212 and 9001 data modems. Furthermore, the software enhancement covers additional variants of the AW448 modem.

Quantum Networking Contract

Qunnect has shared details regarding a contract the company was awarded in early October to provide quantum networking infrastructure to the United States Air Force (USAF) research laboratory. A press release announcing the news says the contract will cover quantum networking for “national defence applications”. Qunnect claims to be the first company to have deployed large-scale, entanglement-based quantum networks on commercial fibre optic networks. Noel Goddard, Qunnect’s chief executive officer, continued in the press release that “with the air force’s support, we’re extending those capabilities to validate defence-grade specifications and accelerate national security use cases”. The company told Armada that the new contract “advances the entanglement validation components that are part of Qunnect’s Carina entanglement distribution product suite”. These components will be used by the laboratory to develop “new protocols for entanglement using our technology”. As for the company’s quantum entanglement technology writ large: “Current public demonstrations have shown (ranges of) up to 100 kilometre (62 miles) for useful entanglement rates. Qunnect is currently working on advancing quantum repeaters (to) extend that range”.

Arctic Steerable Beams

In October Viasat announced it had successfully demonstrated its GX-10 steerable beam high-speed arctic communications payload in Northern Canada. The test employed a Gulfstream Aerospace Gulfstream-III business jet and demonstrated that wireless devices could be connected using Ka-band (26.5 gigahertz/GHz to 40GHz uplink/18GHZ to 20GHz downlink) links across distances of up to 516 nautical miles (956 kilometres). The company says its GX-10 A/B payloads are already in service onboard Norway’s Northrop Grumman ASBM-1/2 Arctic Satellite Broadband Mission communications satellites. These antennas allow users to benefit from wideband satellite communications coverage in areas above 63 degrees’ latitude. Arctic regions have traditionally suffered from a paucity of satellite communications provision. The company told Armada that the demonstration was performed “to further illustrate the connectivity now available for government and defence operations in the (arctic) region”. (Source: Armada)

 

18 Dec 25. Lockheed Martin (NYSE: LMT) Skunk Works® and XTEND collaborated to integrate the XTEND Operating System (XOS) into Skunk Works’ MDCX™ autonomy platform, allowing simultaneous Command and Control (C2) of multiple classes of UAS, creating improved situational awareness for lower-level mission execution in joint all-domain C2 (JADC2) scenarios. In November, the two companies demonstrated an integrated Multi-Class MDCX (MC-MDCX) workstation in support of a marsupial drone mission. In the demonstration, a larger class UAS delivered a smaller UAS class 1 drone to perform a close-in mission. In previous constructs the operator of the larger class UAS would pass control over to an operator with lower-level controls for classes 1 or 2 vehicles. These types of controls include first-person views, mark-and-fly commands, and immersive environments for the drone operator to fully execute the mission. With the planned integration of XTEND’s XOS into Lockheed Martin’s MC-MDCX, a single operator can conduct both missions. The integration demonstration proved a reduction in total manpower for complex mission executions, removing the need for mission handoffs to lower-tiered operators, and improving situational awareness across the mission space. XTEND is a leader in combat-proven drone C2 solutions, deployed by militaries around the world. Their products provide a layered response and operational stepdown processes, enabling platform operations even when Global Positions System (GPS) signals are denied, or radio frequency datalinks are jammed. XOS allows new operators to conduct missions at near expert-level proficiency, thus reducing training time, increasing operational effectiveness, and improving informed decision-making. Lockheed Martin Skunk Works and XTEND are now focused on how these techniques can be applied to JADC2 missions and decision loops for advancing autonomous systems. Skunk Works is dedicated to enabling piloted and drone teaming to optimize operational flexibility, abbreviate data-to-decision timelines and improve pilot safety. We continue to collaborate with and invest in enabling technologies to keep our customers ahead of emerging threats.

About Lockheed Martin

Lockheed Martin is a global defense technology company driving innovation and advancing scientific discovery. Our all-domain mission solutions and 21st Century Security® vision accelerate the delivery of transformative technologies to ensure those we serve always stay ahead of ready. More information at Lockheedmartin.com.

About XTEND

XTEND’s AI-driven autonomous and tactical drone solutions serve the worldwide defense, law enforcement, and security markets, providing mission-critical systems and capabilities. Its proprietary XOS operating system fuses human intelligence and machine autonomy to enhance operator capabilities and reduce cognitive load. XTEND is a global company with offices in Tampa (Florida), Tel Aviv (Israel), Singapore and Latvia. For more information, visit http://www.xtend.me

 

18 Dec 25. Europe: Government sectors face increased cyber espionage risks from evolving Chinese tactics. On 16 December, the cyber security company Check Point reported that a Chinese state-sponsored group (‘Ink Dragon’) is exploiting misconfigured servers to conduct stealthy cyber espionage operations targeting the government sector in Europe. Ink Dragon typically searches for misconfigured Internet Information Services (IIS), SharePoint and other web servers provided by the technology company Microsoft on public-facing websites, in order to exploit their vulnerabilities and infiltrate targeted systems. Ink Dragon then attempts to hijack administrative-level accounts to execute a module that converts compromised servers into relay devices. This enables Ink Dragon to conceal command-and-control (C2) infrastructure by relaying malicious traffic between compromised victims’ devices. Reportedly, another Chinese state-sponsored group (‘RudePanda’) has used the same compromised devices for its own cyber operations, highlighting the widespread exploitation of this vulnerability. We assess that European government entities will face increased security and cyber espionage risks amid the continuous evolution of Chinese state-sponsored cyber tactics. (Source: Sibylline)

 

17 Dec 25. Scarlet Dragon Links Military, Industry to Test Artificial Intelligence for Warfighters. On a cold, December day deep in a training area at Fort Bragg, North Carolina, soldiers, airmen, Marines and civilian industry partners came together to test the latest drone and counter unmanned aircraft systems technology, while rapidly sharing targeting data through the National Geospatial-Intelligence Agency’s Maven Smart System. Scarlet Dragon is the XVIII Airborne Corps’ premier innovation exercise, where new ideas and technologies are tested to solve current issues on the battlefield.

“We’re focused on bringing new technologies and approaches to solve operational capability gaps and requirements that we identify from operational plans around the globe,” said Rob Braun, XVIII Airborne Corps chief technical officer.

The Scarlet Dragon exercise series started in 2020 as a tabletop exercise in the basement of the XVIII Airborne Corps’ headquarters and has evolved into a triannual innovation event where joint services, government agencies and industry partners come together to test and integrate the latest technology for the modern warfighter. During this iteration, known as Scarlet Dragon 26-1, the XVIII Airborne Corps tested several initiatives. The 18th Field Artillery Brigade trained with the Air Force to rapidly load and deploy an M142 high mobility artillery rocket system from a C-17 Globemaster III, all while simultaneously receiving targeting data through NGA’s Maven Smart System. The streamlined data sharing allows the HIMARS unit to rapidly deploy anywhere in the world and quickly set up for offensive or defensive engagements.

“We’re doing cold-load training with a C-130, putting the HIMARS on the aircraft, driving it off, executing a rapid-fire mission and getting back on quickly,” said Army 2nd Lt. Ryan Mitchell, 18th Field Artillery Brigade, HIMARS platoon leader. “Through Scarlet Dragon, we are doing advanced targeting with data received through Maven, rapidly getting that information to the launcher so we can deploy and shoot faster.”

Another initiative included real time data sharing and tracking between AH-64 Apache helicopters from the 82nd Airborne Division’s Combat Aviation Brigade, drones and small UAS with the XVIII Airborne Corps Air and Missile Defense team, Sentinel radars from the 82nd Airborne Division, and newly fielded SGT STOUT short range air defense systems from the 108th Air Defense Artillery Brigade. The Sentinel radars and SGT STOUTs tracked Apaches and drones, pushing data to the corps headquarters to validate faster early warning systems for troops on the ground. Apache pilots tested their ability to identify and track small drones, while the SGT STOUT teams validated their tracking and targeting capabilities. The integration of the SGT STOUT into the maneuver force is a critical step in providing protection against short-range air threats.

“What I like about Scarlet Dragon is how I push, not just the soldiers, but also the equipment that we have to our limits and to see what we are capable of and how we can improve our system capabilities,” said Army Spc. Daniel Rosas, XVIII Airborne Corps Air Defense Battle Management System operator. “With the way the world is currently moving, especially when it comes to UAS or drones, it is a big threat, and it helps for us to push forward on what we can adapt when it comes to gauging and tracking these threats.”

Scarlet Dragon gives service members and industry partners the opportunity to test new ideas and innovations in an open and minimum-risk environment.

“That’s what I really like about Scarlet Dragon,” said Army Chief Warrant Officer 4 Sean Benson, XVIII Airborne Corps senior geo-intelligence imagery technician. “It’s not an exercise with defined timelines or deliverables. It’s whatever we want to try to get to the outcome we need. If you have an idea and it sticks when you throw it on the wall, we’ll give it a shot.”

The Future of Scarlet Dragon

With every iteration of Scarlet Dragon, the integration process is refined and the technology improves. In the future, the Scarlet Dragon exercise series will be tied in with Fort Bragg and XVIII Airborne Corps’ new Lt. Gen. James M. Gavin Joint Innovation Outpost, which will officially open Jan. 23, 2026.

“During Scarlet Dragon 26-1, the XVIII Airborne Corps and Fort Bragg held a soft opening for our new Joint Innovation Outpost, or JIOP,” said Army Lt. Gen. Greg Anderson, commanding general of the XVIII Airborne Corps. “With the JIOP and our Scarlet Dragon series of exercises, we will be able to develop and test soldier-driven, rapid innovation and technical transformation while providing the Army a model to revolutionize the acquisition process. It is making us more lethal at the tactical and operational levels of war.”

The JIOP will allow soldiers to bring innovative solutions to the facility to work with civilian industry and academic partners to refine and produce new technology that can then be tested in Scarlet Dragon exercises and eventually shared across the joint force. In 2026, Scarlet Dragon will shift to the Indo-Pacific theater and U.S. Army Japan for their annual combined exercise with the Japanese Ground Self Defense Forces, Yama Sakura. (Source: U.S. DoD)

 

17 Dec 25. Bittium Wireless Ltd, a subsidiary of Bittium Corporation, has received purchase orders from the Finnish Defence Forces for Bittium Tough SDR Handheld and Vehicular radios and related accessories, and for further development work for software and related services. The total value of the purchase orders received now is approximately EUR 15.9m, of which the share of Tough SDR order is approximately EUR 12.4m. Product deliveries and development work will take place during 2025 and 2026. Bittium Tough SDR radios will replace the Finnish Defence Forces’ existing stock of analogue tactical radios in stages with modern software-defined radios enabling broadband tactical communications. The radios will also offer significantly better performance for the Finnish Defence Forces compared to the earlier generation digital tactical radios. The Tough SDR radios are compatible with the software-defined Bittium Tactical Wireless IP Network™ (TAC WIN) system used by the Finnish Defence Forces for forming a backbone for broadband tactical communications.  The solutions come together as a seamless network that enables resilient communications for all troops across domains and military branches. Part of the performance of the software-defined radios is created with the software used in the radios and software development enables performance enhancements for the radios throughout their whole life cycle.

“The purchase order reflects the Finnish Defence Forces’ strong confidence in Bittium’s advanced software-defined radios. The waveforms, which play a central role in radio data transmission, are being continuously improved to address evolving threats, particularly in electronic warfare. The Tough SDR radios, combined with the NATO-standardized pan-European ESSOR High Data Rate Waveform, facilitate seamless interoperability also with allied forces,” says Tommi Kangas, Senior Vice President, Defense & Security business segment at Bittium.

In addition to the Tough SDR radios, the Finnish Defence Forces have ordered development of the Tactical Device Management system that enables secure deployment and operative use of the radios. The system will expand to support also the TAC WIN system and Bittium Tough Comnode™ devices, enabling centralized and streamlined installation, software updates, and key management for the solutions. The purchase orders have been issued under a Partnership Agreement between Bittium and the Finnish Defence Forces. The Partnership Agreement applies to the years 2025–2036 and establishes a framework for purchasing Bittium’s devices, software, and services. The purchases are planned together with the Finnish Defence Forces for each year. The Finnish Defence Forces will issue separate purchase orders for the products and services in several batches according to what has been agreed in the Partnership Agreement.

 

16 Dec 25. Global: Widespread vulnerability exploitation heightens security risks to firms using JavaScript library. On 13 December, the technology company Google reported that more than five Chinese state-sponsored groups are actively exploiting a newly disclosed software vulnerability (CVE-2025-55182). CVE-2025-55182 enables unauthenticated actors to execute arbitrary code onto devices hosting vulnerable React interface services (i.e. a widely used JavaScript library), in order to conduct malicious cyber activity. Google’s report comes after the US-based technology companies Palo Alto and Amazon Web Services (AWS) issued two warnings announcing that Chinese state-sponsored actors had started exploiting the vulnerability hours after its disclosure on 3 December. This rapidity showcases the quickly evolving nature of the cyber threat landscape. Between 14 and 15 December, over 670 IP addresses reportedly attempted to abuse CVE-2025-55182 across East Asia and Pacific, Europe and North America, highlighting the potential scale of the vulnerability’s exploitation. Consequently, we assess that entities using React interface services will face heightened security risks in the short-to-medium term amid the ongoing implementation of remediation patches. (Source: Sibylline)

 

12 Dec 25. Cyber Update

Key points

  • The government and IT sectors in the US and Canada face increased security risks from a long-term Chinese state-sponsored cyber operation (see Sibylline Cyber Daily Analytical Update – 8 December 2025).
  • A new spyware variant (‘ClayRAT’) poses increased data-theft and surveillance risks for global Android users (see Sibylline Cyber Daily Analytical Update –  9 December 2025).
  • A new ‘Mirai’-based botnet variant (‘Broadside’) poses elevated disruption risks for the maritime shipping sector via the exploitation of a software vulnerability (CVE-2024-3721, see Sibylline Cyber Daily Analytical Update – 10 December 2025).
  • Financial and cryptocurrency institutions across Europe face heightened data-theft and financial risks from a new phishing kit (‘Spiderman’, see Sibylline Cyber Daily Analytical Update – 11 December 2025 and our technical analysis below).
  • A Hamas-affiliated cyber threat group (‘Ashen Lepus’) poses an elevated cyber espionage threat to government entities in the Middle East and North Africa (see Sibylline Cyber Daily Analytical Update – 12 December 2025 and our technical analysis below).

Technical analysis of weekly stories

Cyber threat actors are targeting European banks with a new and highly sophisticated phishing kit (Spiderman). Spiderman can be managed through a unified control panel that facilitates the automation of the attack chain, enabling a wider range of both high- and low-skilled threat actors to conduct sophisticated attacks. During the distribution phase, threat actors can also restrict access to phishing pages using several techniques – such as country and internet service provider (ISP) whitelisting, device-type filtering and customer redirect control – to avert unwanted visitors and prolong detection evasion. The kit can target dozens of financial institutions across at least five European countries with a single interface, highlighting the large-scale security risks stemming from its highly dynamic functionality. Spiderman can steal login details in real-time and simultaneously deploy additional interfaces for extensive data collection to hijack user accounts fully (and initiate fraudulent money transfers). Stolen data typically includes credentials such as one’s full name, phone number, date of birth and credit card details, providing threat actors with ample follow-on attack avenues. The kit also boasts the ability to exfiltrate specific cryptocurrency information such as wallet data and seed phrases, showcasing the all-encompassing nature of its financial-theft capabilities.

A Hamas-affiliated cyber threat group (Ashen Lepus) has consistently targeted government entities in the Middle East and North Africa region through cyber espionage operations since at least the beginning of the Israel-Hamas war in late 2023. The group likely uses social engineering techniques to distribute a PDF file that tricks victims into downloading and opening an RAR archive. The archive contains a loader that ultimately executes the ‘AshTag’ malware suite onto compromised systems via a multi-stage process. Namely, upon execution, the malware loader (‘AshenLoader’) sends initial system reconnaissance to command-and-control (C2) infrastructure before deploying a malware stager (‘AshenStager’). AshenStager is responsible for injecting the main payload (AshTag) into the system’s memory to enhance detection evasion. AshTag acts as a backdoor to perform system reconnaissance, maintain prolonged persistence and execute remote commands. During the latest operations, Ashen Lepus has used new domains mimicking legitimate services for C2 infrastructure to obfuscate malicious traffic. The group has also started deploying the entire malware suite in this latest phase, rather than simply exiting a victim’s system after infiltration. We assess this suggests that Ashen Lepus is consistently developing its tactics. This development is also reflected in the expansion of its target pool which now also includes Oman and Morocco alongside its usual targets.

Non-exhaustive recommendations to mitigate these threats include:

  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs, PSB) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware.
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.

Our cyber word(s) of the week: User Datagram Protocol (UDP) flooding

Definition: A type of denial-of-service (DoS) attack in which threat actors send a large amount of UDP requests to overwhelm a victim’s system with the aim of causing operational disruption.Example: ‘[…] executes the Mirai malware […], thereby allowing threat actors to conduct DDoS attacks via User Datagram Protocol (UDP) flooding techniques’ (see Sibylline Cyber Daily Analytical Update – 10 December 2025). (Source: Sibylline)

———————————————————————————————————————————————————————————————————————————————————————————————————————–

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

————————————————————————————————————————————————————————————————————————————————————————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

December 12, 2025 by

Sponsored By Curtiss Wright

https://www.curtisswright.com/

————————————————————————————————————————————————————————————————————————————————————————————————————————————————-
11 Dec 25. L3Harris Technologies (NYSE: LHX) hosted U.S. government officials for a first-of-its-kind demonstration of software-defined capabilities that enable separate federal agencies to communicate instantly across domains. The full-scale, end-to-end demonstration united tactical communications devices, counter-UAS capabilities, advanced imaging technologies and mobile operations centers with command-and-control systems, successfully illustrating unmatched connectivity and rapid response to national security threats.
“We’re answering Secretary Hegseth’s call to secure our borders and protect the homeland with interoperable capabilities that are more advanced than anything on the market,” said Sam Mehta, President, Communication Systems, L3Harris. “We know that speed wins and hesitation loses, and our commercial business model enables delivery of these capabilities into warfighters’ hands in weeks, not years.”
Key technologies highlighted in the demonstration included T-HAWC, the AN/PRC-158C software-defined data device and 5G gateway solutions. The interconnected systems used a mix of public safety and tactical radios across manned and unmanned assets – a necessity for today’s complex environment.
These resilient, multi-path solutions maintain connectivity even in degraded and contested conditions for the Department of War, other federal agencies, and during disaster response and large-scale events. (Source: BUSINESS WIRE)

 

11 Dec 25. Astris AI, a wholly owned subsidiary of Lockheed Martin (NYSE: LMT), today announced the launch of its groundbreaking Astris AI for Government™ initiative designed to advance trustworthy, secure AI across high-assurance applications, building on the substantial AI investments made by Lockheed Martin and its commercial collaborators. Astris AI for Government solutions provide an integrated, turnkey AI platform that enables government agencies to build, deploy and sustain trusted AI capable of advancing the nation’s ambitious goals for greater innovation and efficiency. Combining industry-leading technology into a unified ecosystem empowers federal research, civilian services, national security missions, and other high-assurance industries to adopt AI and simulation solutions with increased speed and security.
“Our Astris AI for Government initiative was created to help advance America’s AI Action Plan, ensuring American leadership in AI diplomacy and security, while achieving domestic priorities for acquisition reform,” said Sarah Hiza, senior vice president of Technology & Strategic Innovation at Lockheed Martin. “By integrating the best of American technology, the Astris AI for Government full-stack solution eliminates fragmentation and procurement barriers that slow adoption for secure, mission-ready AI—without vendor lock-in or complex integration challenges.”
The Astris AI for Government Solution
The Astris for AI Government offerings deliver cost-effective AI solutions that will help U.S. agencies and commercial partners boost productivity, ignite innovation, and meet the evolving demands of a dynamic economy and geopolitical landscape.
For example, by deploying Astris AI for Government solutions, Federal agencies can continuously ingest and process mission critical data on site while keeping it fully protected. This can provide operators and analysts with real-time insight without ever moving sensitive information off network, utilizing machine learning operations (MLOps) and generative AI pipelines.
Likewise, to protect life and property from devastating wildfires, the Department of the Interior can leverage Astris AI for Government solutions to make faster, more informed decisions with actionable intelligence, fusing sensor data from multiple sources and empowering first responders.
Other potential applications include the Genesis Mission, energy and critical infrastructure protection, and advanced manufacturing and supply chain optimization across the Federal government.
Available Today
By providing a single, integrated ecosystem, the Astris AI for Government solutions offer the fastest and most affordable path to:
• Oracle Cloud Infrastructure’s (OCI) secure U.S. network for unclassified and classified regions, delivering sovereign cloud solutions that advance national security interests
• Lockheed Martin’s engineering and domain expertise
• Open source AI models from Meta
• Government-ready NVIDIA AI Enterprise software via Astris AI for Government
• Astris AI’s AI Factory MLOps and Generative AI platform capabilities
Astris AI for Government solutions are available now through Astris AI, Oracle Marketplace and commercial federal procurement vehicles. Initial offerings include the Astris AI Government platform available on OCI, integrating Generative AI (GenAI) and Machine Learning Operations (MLOps) bundles accelerated by NVIDIA AI Enterprise including NVIDIA NIM microservices.
What’s Next?
The Astris AI for Government initiative continues to broaden its partner ecosystem. Joint teams are already mapping the next development phase: a large-scale AI and simulation environment, PEARL™ (Persistent Environment for AI, Readiness, and Learning). Powered by collective advanced computing, secure infrastructure, simulation and visualization software, and GPU-accelerated computing, the PEARL environment will give agencies access to unprecedented scale, driving advances in operations analysis, domain-specific models, AI test and evaluation, and simulation-to-real integration.
For additional information, visit our website: www.astrisai.com
About Astris AI
Astris AI, a subsidiary of Lockheed Martin, is committed to enabling the adoption of AI solutions across the U.S. defense industrial base and other industries seeking high assurance solutions. Astris AI provides customers access to foundational AI tools, processes and talent to enable the deployment of secure AI solutions at scale, ensuring they stay ahead of rapid technological advancements. Astris AI is the latest addition to the Lockheed Martin Evolve portfolio, an organization that creates and scales new commercial and non-traditional businesses to bolster the defense industrial base. Visit AstrisAI.com to learn more.
About Lockheed Martin
Lockheed Martin is a global defense technology company driving innovation and advancing scientific discovery. Our all-domain mission solutions and 21st Century Security® vision accelerate the delivery of transformative technologies to ensure those we serve always stay ahead of ready. More information at www.lockheedmartin.com.
Future Product Disclaimer
The preceding is intended to outline our general product direction. It is intended for information purposes only and may not be incorporated into any contract. It is not a commitment to deliver any material, code, or functionality, and should not be relied upon in making purchasing decisions. The development, release, timing, and pricing of any features or functionality described for each of the company’s products may change and remains at the sole discretion of each respective company.
“Safe Harbor” Statement
Statements in this press release relating to the collaborating company’s future plans, expectations, beliefs, intentions, and prospects are “forward-looking statements” and are subject to material risks and uncertainties. A detailed discussion of these factors and other risks that affect the businesses are contained in applicable Securities and Exchange Commission (SEC) filings. These filings are available on the SEC’s website or on the collaborating company’s websites: Lockheed Martin: https://investors.lockheedmartin.com/
All information in this press release is current as of Dec. 11, 2025, and the collaborating companies undertake no duty to update any statement in light of new information or future events.
Trademarks
Lockheed Martin, Astris AI, and Astris AI for Government are registered trademarks of Lockheed Martin Corporation.

 

10 Dec 25. Global: Maritime shipping sector faces increased disruption risks from exploitation of vulnerability. On 9 December, international news outlets reported that a newly identified ‘Mirai’ botnet variant (‘Broadside’) is exploiting a software vulnerability (CVE-2024-3721) to conduct disruptive cyber attacks. The vulnerability affects several versions of digital video recorder (DVR) products from the company TBK Vision; it enables unauthenticated threat actors to deploy a malware loader onto compromised systems. The loader executes the Mirai malware within a system’s memory, thereby allowing threat actors to conduct distributed denial-of-service (DDoS) attacks via User Datagram Protocol (UDP) flooding techniques. The malware also terminates hostile security processes in order to remain obfuscated and maintain persistence, highlighting its sophistication. We assess that all DVR devices likely remain vulnerable to exploitation, as CVE-2024-3721 has not been fixed since its discovery in April 2024. Reportedly, the targeted devices are primarily used by maritime shipping companies, increasing security and disruption risks for vessels in the short-to-medium term. (Source: Sibylline)

 

10 Dec 25. Silvus StreamCaster 4400 Enhanced MANET Radio Receives Department of Defense (DoD) Certification. Silvus Technologies, a Motorola Solutions company and a global leader in advanced wireless networking solutions, has announced that the U.S. Department of Defense (DoD) Defense Innovation Unit (DIU) has added the StreamCaster 4400 Enhanced (SC4400E) mobile ad-hoc network (MANET) radio to its Blue UAS Framework, a rigorous testing and certification program that approves technologies for use in U.S. military unmanned aircraft system (UAS) operations.
The Association of Uncrewed Vehicle Systems International (AUVSI) has also added the SC4400E to its Green UAS Cleared Components list, certifying it meets rigorous cybersecurity and supply chain standards for commercial drones and components.
“The Blue UAS Framework and AUVSI Green UAS certification validate that the SC4400E MANET radio meets the rigorous standards for secure, mission-critical connectivity demanded by today’s leading-edge unmanned systems operating in the world’s most challenging and contested environments,” said Neema Daneshvar, vice president of Product, Silvus Technologies. “Its addition to both programs strengthens Silvus’ position as a benchmark for robust, secure and resilient command and control (C2) and mesh networking solutions for UAS and unmanned operations.”
Powered by Silvus’ proprietary Mobile Networked MIMO waveform, SC4400E radios create a scalable connected mesh network that can link hundreds of nodes, from drones to ground radios, to stream high-bandwidth video, voice and sensor data back to command with extreme range. The radio is designed to easily integrate into fixed infrastructure or vehicular, maritime, airborne or unmanned systems, to support missions across air, land and sea.
The SC4400E provides access to Spectrum Dominance 2.0, an ever-expanding suite of electronic warfare (EW) defense capabilities, including Low Probability of Intercept/Low Probability of Detection (LPI/LPD), Anti-Jamming and Advanced Threat Protection. These capabilities help deliver secure and protected communications in congested and contested spectrum environments without sacrificing performance, even under electromagnetic attack.
The National Defense Authorization Act-compliant SC4400E joins the StreamCaster SC4200EP, StreamCaster LITE SL4200 and SL5200 MANET radios on the Blue UAS Framework and Green UAS Cleared Components list.
About Silvus Technologies, a Motorola Solutions company
As a leading provider of advanced MANET and MIMO communications systems, Silvus Technologies is
reshaping mesh network technology for mission-critical applications on the ground, in the air and at sea. Its battle-proven StreamCaster family of MANET radios and proprietary MN-MIMO waveform provides the vital communications link for defense, law enforcement and public safety agencies in the toughest operational environments around the world. Developed by a team of top PhD scientists and design engineers, Silvus Technologies continues to innovate communications technology for the tactical edge with unmatched range, data throughput, EW resiliency and scalability. A Motorola Solutions company, Silvus Technologies is headquartered in Los Angeles. (Source: UAS VISION)

 

09 Dec 25. Hegseth Introduces Department to New AI Tool. Yesterday, several employees in the Pentagon got a pop-up on their computer inviting them to make use of a new artificial intelligence tool developed for the War Department. Some were skeptical, wondering if the invitation was part of a cybersecurity test.
But by this morning, those concerns were gone — posters around the Pentagon and an email from Secretary of War Pete Hegseth assured everyone that the new tool is not only legit, but that he wants everybody to start using it.
“I am pleased to introduce GenAI.mil, a secure generative AI platform for every member of the Department of War,” Hegseth wrote in the email. “It is live today and available on the desktops of all military personnel, civilians and contractors. With this launch we are taking a giant step toward mass AI adoption across the department. This tool marks the beginning of a new era where every member of our workforce can be more efficient and impactful.”
Visitors to the site will find that what’s available now is a specialized version of the Google AI tool Gemini, Gemini for Government. This version is approved to handle controlled unclassified information. A green banner at the top of the page reminds users of what can and can’t be shared on the site.
In addition to Gemini for Government, the site indicates that other American-made frontier AI capabilities will be available soon.
“There is no prize for second place in the global race for AI dominance,” said Emil Michael, undersecretary of war for research and engineering.
“We are moving rapidly to deploy powerful AI capabilities like Gemini for Government directly to our workforce. AI is America’s next manifest destiny, and we’re ensuring that we dominate this new frontier.”
Access to the site is available only to personnel with a common access card and who are on the War Department’s nonclassified network.
When GenAI was asked, “How will you help the Department of War achieve its mission,” through a user prompt, it replied with a list of capabilities, including, among other things, creating and refining documents, analyzing information, processing and analyzing satellite images, and even auditing computer code for security purposes.
“I can support the DOW’s mission by providing a range of capabilities designed for a secure, high-impact environment,” the GenAI replied. “I am ready to support your mission requirements.”
The AI itself reminds users to double-check everything it provides to ensure accuracy. The highest authority within the War Department, Hegseth himself, provided that validation.
“The first GenAI platform capability … can help you write documents, ask questions, conduct deep research, format content, and unlock new possibilities across your daily workflows,” he wrote. “I expect every member of the department to log in, learn it and incorporate it into your workflows immediately. AI should be in your battle rhythm every single day. It should be your teammate. By mastering this tool, we will outpace our adversaries.”
For those unfamiliar with how to use AI, online training is available at https://genai.mil/resources/training (Source: U.S. DoD)

 

09 Dec 25. Pacific Defense today announced the release of the SDR4320VP, its newest high-performance, ultra-wideband Software-Defined Radio (SDR) transceiver designed for demanding Electronic Warfare (EW), Signals Intelligence (SIGINT), radar, and cyber missions. The 3U OpenVPX plug-in card is aligned with SOSA™, CMOSS, and OpenVPX MOSA standards and supports frequencies up to 18 GHz with 1 GHz of instantaneous analog bandwidth, as well as narrower, digitally processed bandwidth options for mission-tailored performance in size, weight and power-constrained environments.
The Pacific Defense SDR4320VP delivers a fully software-defined signal chain that supports rapid deployment of new waveforms, jamming techniques, radar modes, and adaptive direction-finding algorithms – without hardware changes.
At the core of the SDR4320VP is a leading-edge Radio Frequency System-on-Chip (RFSoC) from the AMD Zynq™ UltraScale+™ family, delivering a fully software-defined signal chain that supports rapid deployment of new waveforms, jamming techniques, radar modes, and adaptive direction-finding algorithms – without hardware changes. The module includes extensive onboard FPGA resources and supports data rates up to 100 Gbps, enabling high-performance, real-time processing and data offload. In its default configuration, the SDR4320VP complies with the ANSI VITA 48.2 mechanical standard for VPX REDI conduction cooling and meets the ECC3 environmental class per VITA 47.
“The SDR4320VP continues our track record of delivering the most advanced MOSA products on the market,” said Pedja Mitrovic, VP of Modular Products at Pacific Defense. “This SDR pushes the state of the art in 3U SOSA signal-processing capability, giving system designers greater power and flexibility to meet demanding mission requirements.”
Key Features of the SDR4320VP
• 3U VPX form factor aligned to CMOSS, SOSA™, and OpenVPX™ standards
• Independent transmit and receive channels
• Supports multi-card phase coherency for geolocation and beamforming
• Band coverage from 10 MHz to 18 GHz with 1 GHz of IBW
• Programmable digital downconverters (DDCs)
For more information on the SDR4320VP, visit the product page here.
About Pacific Defense
Pacific Defense is purpose-built to drive the open-systems transformation required to unlock rapid innovation and the power of commercial technology. Specializing in Command, Control, Communications, Computers, Cyber, Intelligence, Surveillance, and Reconnaissance (C5ISR) and Electronic Warfare (EW) solutions for mission-critical environments, Pacific Defense applies Modular Open Systems Approach (MOSA), aligning with the Sensor Open Systems Architecture (SOSA) technical standard, and integrating capabilities through the C5ISR/EW Modular Open Suite of Standards (CMOSS) to deliver flexible, upgradeable technology that enables warfighters to stay ahead of emerging threats. Learn more at www.pacific-defense.com and on LinkedIn.(Source: BUSINESS WIRE)

 

10 Dec 25. ST Engineering iDirect’s EU Satcom Centre of Excellence, ST Engineering iDirect Europe, based in Sint-Niklaas, Belgium, today announced that the European Protected Waveform (EPW) consortium has successfully completed over-the-air testing, marking a critical milestone in Europe’s pursuit of strategic autonomy in secure military communications. Conducted on November 26-27, 2025 at Universität der Bundeswehr München, Germany, the demonstrations validated EPW’s ability to safeguard military satellite communications against jamming, cyber threats, and unauthorised access across both GEO and LEO satellite configurations.
Demonstration underscores Europe’s commitment to secure, resilient, multi-orbit military satellite communications
Belgian National Armaments Director, Major General Filip Borremans, highlighted the importance of this milestone, “The successful EPW demonstrations perfectly illustrate the mission of the European Defence Fund, enabling Member States to achieve collectively what none could accomplish alone. By uniting 19 partners from 13 nations, the consortium has demonstrated that European collaboration delivers both technical excellence and strategic autonomy. Secure satellite communications are a cornerstone of modern defence, and EPW proves that through coordinated European investment, we can develop sovereign solutions that strengthen our collective security.”
This milestone underscores the critical need for standards-based, interoperable, secure communications in modern military operations. As cyber threats from state and non-state actors intensify and missions span increasingly dispersed theaters, robust and resilient infrastructure has become indispensable. Designed with security, agility, efficiency, and interoperability at its core, the EPW empowers European military forces to maintain secure communications—whether operating independently or in coalition—adapting seamlessly to diverse operational demands and geographic challenges.
Co-funded by the European Union through the European Defence Fund, the programme unites industry and academia from across Europe under the leadership of Belgium’s Ministry of Defence, with ST Engineering iDirect Europe as the consortium lead. This collaborative effort is tackling both current and emerging challenges in military satellite communications, including evolving security threats, growing demands for higher throughput, and the need for enhanced mobility solutions.
“The EPW consortium’s successful completion of this major milestone, demonstrated live and witnessed by supporting military end-users, represents a critical step toward the next phase of the EPW programme,” said Koen Willems, Vice President, EU Programmes, at ST Engineering iDirect Europe. “This achievement paves the way for the prototyping and testing of the final capability, which will deliver secure and resilient communications for Europe. It underscores the consortium’s unwavering commitment to advancing Europe’s strategic autonomy in military communications through innovation and collaboration.”
The European Protected Waveform is funded by the European Union. Views and opinions expressed are however those of ST Engineering iDirect Europe only and do not necessarily reflect those of the European Union or the European Commission. Neither the European Union nor the granting authority can be held responsible for them.
About the European Protected Waveform (EPW) Program
The European Protected Waveform is a European Defence Fund program co-funded by the European Union, with a total estimated cost of €29.9 m and a maximum EU contribution of €25 m. Over its 39-month duration, the program aims to develop secure waveform standards for future-proof satellite communications, addressing challenges such as joint and dispersed operations, mobility requirements, and the integration of both GEO and NGSO satellites.
About the European Defence Fund
The European Defence Fund (EDF) supports collaborative defense research and development projects across EU Member States, strengthening Europe’s technological and industrial defense capabilities while promoting cooperation and interoperability.
About ST Engineering iDirect Europe
ST Engineering iDirect Europe, located in Sint-Niklaas, Belgium, is ST Engineering iDirect’s EU Satcom Center of Excellence specialising in the development of ground segment technology and solutions specifically for the EU. As a legal Belgian entity, ST Engineering iDirect Europe has its own board of directors to comply to the guidelines and conditions as put forward by the EU Commission and the Belgian Government. With over 35 years of experience, the ST Engineering iDirect portfolio of high-value product lines and services in addition to a dedicated team of domain specialists, and a ISO9001 certified manufacturing center the team has a portfolio of capabilities to cater to the specific needs of European funded satcoms programs. (Source: PR Newswire)

 

09 Dec 25. The Government of Canada is committed to equipping the Canadian Armed Forces (CAF) with the tools it needs to protect Canadians, strengthen our Arctic security and unleash the economic potential of the North.
Today, the Honourable Joël Lightbound, Minister of Government Transformation, Public Works and Procurement and Quebec Lieutenant, the Honourable David McGuinty, Minister of National Defence, and the Honourable Stephen Fuhr, Secretary of State (Defence Procurement), announced that the Government of Canada has established a strategic partnership with Telesat Corporation and MDA Space, to develop and bolster the Canadian Forces’ military satellite communications (MILSATCOM) capabilities.
This partnership is part of the Enhanced Satellite Communications Project – Polar (ESCP-P), one of the key procurements being led by the newly formed Defence Investment Agency. It will provide reliable wideband and narrowband connectivity to support domestic and continental operations in the Arctic. This project is leveraging Canadian industry to create high-quality jobs across the country, while unlocking a multi-bn dollar investment in Canada’s defence sector.
The Government of Canada selected Telesat and MDA Space as strategic partners because of their combined expertise in secure satellite communications and space-based infrastructure. This strategic partnership ensures a strong role for the domestic space sector, while reinforcing the government’s commitment to Arctic security, Canadian sovereignty and creating high-quality jobs with our generational investments in defence.
The announcement demonstrates Canada’s commitment to modernizing military capabilities, supporting NATO and NORAD priorities, and ensuring that Canadian innovation plays a central role in meeting emerging threats.
Quotes
“Today’s announcement underscores Canada’s commitment to equipping our military with the tools it needs to operate effectively in the North and beyond. Through this strategic investment in military satellite communications, we are not only strengthening the Canadian Armed Forces’ ability to maintain secure, reliable communications in remote regions, but also supporting innovation and job creation across Canada. This project reflects how modern, forward-looking procurement can deliver both operational excellence and long-term economic benefits for Canadians.”
The Honourable Joël Lightbound Minister of Government Transformation, Public Works and Procurement and Quebec Lieutenant
“The Enhanced Satellite Communications Project – Polar marks a critical advancement for Canada’s defence and sovereignty, particularly across our Arctic and northern regions. By investing in cutting-edge satellite communications, we are providing the Canadian Armed Forces with secure, resilient, and modern capabilities–allowing them to safeguard our airspace, respond quickly to emerging threats, and support communities throughout the Arctic and the North.
This investment also reaffirms Canada’s steadfast commitment to our key partners, including the North American Aerospace Defense Command and the North Atlantic Treaty Organization. And it underscores our determination to meet our sovereign defence objectives as outlined in Canada’s defence policy, Our North, Strong and Free.”
The Honourable David McGuinty Minister of National Defence
“I am proud to announce the strategic partnership for the Enhanced Satellite Communications Project – Polar, led by the Defence Investment Agency, as part of my mandate to deliver the capabilities the Canadian Armed Forces need to protect our sovereignty. This investment to strengthen our Arctic security and operations will be supported by Canadian expertise and will create high-quality jobs across the country. In collaboration with Canadian industry partners Telesat and MDA Space, the project will deliver robust and secure military satellite communications capabilities that ensure our forces remain connected across vast and remote regions.”
The Honourable Stephen Fuhr Secretary of State (Defence Procurement)
“This strategic partnership for the Enhanced Satellite Communications Project – Polar will advance Canada’s sovereign satellite communications capabilities, which are vital for reliable Arctic operations and national security. Through the Industrial and Technological Benefits Policy, this project will create high-value jobs, drive targeted investments and strengthen innovation across Canada’s space and defence sectors, including small and medium-sized businesses. We’re investing in Canadian expertise, capacity and leadership in space technologies to advance and compete on the global stage.”
The Honourable Mélanie Joly Minister of Industry and Minister responsible for Canada Economic Development for Quebec Regions
“The Enhanced Satellite Communications Project – Polar will play a critical role in advancing the communications capabilities of the Royal Canadian Air Force and the broader Canadian Armed Forces. The ESCP-P project will significantly enhance our ability to conduct sovereignty operations in the Arctic, supporting the defence of Canada and North America. Through this strategic partnership, the project will deliver secure wideband and narrowband satellite communications capabilities that are essential to fulfilling the RCAF’s continental defence mandate.”
LGen Jamie Speiser-Blanchet Commander, Royal Canadian Air Force
“For decades, Telesat has proudly supported the mission-critical connectivity needs of the Canadian Armed Forces. Along with MDA Space, we are honoured to be chosen as strategic partners in modernizing Canada’s defence capabilities and expanding secure, resilient communications infrastructure. We commend the government’s forward-thinking approach to defence procurement–one that harnesses industry expertise, innovation, and investment to accelerate deployment of a secure, multi-frequency architecture that strengthens Arctic security and safeguards Canadian sovereignty.”
Dan Goldberg President and CEO, Telesat
“MDA Space has a long history as a trusted mission partner to the Canadian Armed Forces, delivering the advanced technologies and mission outcomes they need to accomplish their critical mandate. We understand the significance of the missions they execute and the challenges inherent in their operations. With this partnership, and in close collaboration with the Department of National Defence and Telesat, we are ready to deliver essential Arctic military satellite communications capabilities at the speed of innovation and operational relevance.”
Mike Greenley Chief Executive Officer, MDA Space
Quick facts
• As a first step, Canada has awarded a $2.92m (including taxes) contract to Telesat in conjunction with MDA Space to conduct engineering and options analysis work for ESCP-P.
• Canada is using a strategic partner model for the delivery of ESCP-P. The strategic partner model is an innovative approach to defence procurement that streamlines processes and accelerates timelines, while leveraging industry experience and expertise in the design, development and delivery of defence projects and programs.
• This strategic partnership will maximize operational capability for the Canadian Armed Forces, deliver optimal value for Canadian citizens, contribute to Canada’s economic prosperity and solidify Telesat’s and MDA Space’s position as Canadian champions in Arctic MILSATCOM.
• The MILSATCOM capabilities will enhance the CAF’s ability to conduct its core missions, including defending sovereign Canada and North America through the North American Aerospace Defense Agreement (NORAD), in addition to surveillance and search and rescue missions.
• Canada’s Industrial and Technological Benefits (ITB) Policy will apply to ESCP-P, ensuring that the project will generate high-value jobs in Canada, foster innovation and strengthen Canada’s domestic space and defence sectors. As a result of the ITB Policy, the strategic partnership will help ensure the involvement of the Canadian space ecosystem, including small and medium-sized businesses.
• On October 2, 2025, the Prime Minister announced the establishment of the Defence Investment Agency. The Defence Investment Agency is a new special operating agency created to accelerate and streamline defence procurements. It represents a significant step in transforming Canada’s defence procurement system to rebuild, rearm and reinvest in the CAF to respond to evolving global threats and meet operational demands.
(Source: PR Newswire)

 

09 Dec 25. The War Department Unleashes AI on New GenAI.mil Platform. The War Department today announced the launch of Google Cloud’s Gemini for Government as the first of several frontier AI capabilities to be housed on GenAI.mil, the Department’s new bespoke AI platform. This initiative cultivates an “AI-first” workforce, leveraging generative AI capabilities to create a more efficient and battle-ready enterprise. Additional world-class AI models will be available to all civilians, contractors, and military personnel, delivering on the White House’s AI Action Plan announced earlier this year.
This past July, President Donald Trump instituted a mandate to achieve an unprecedented level of AI technological superiority. The War Department is delivering on this mandate, ensuring it is not just ink on paper. In response to this directive, AI capabilities have now reached all desktops in the Pentagon and in American military installations around the world.
The first instance on GenAI.mil, Gemini for Government, empowers intelligent agentic workflows, unleashes experimentation, and ushers in an AI-driven culture change that will dominate the digital battlefield for years to come. Gemini for Government is the embodiment of American AI excellence, placing unmatched analytical and creative power directly into the hands of the world’s most dominant fighting force.
“There is no prize for second place in the global race for AI dominance,” said Emil Michael, Under Secretary of War for Research and Engineering. “We are moving rapidly to deploy powerful AI capabilities like Gemini for Government directly to our workforce. AI is America’s next Manifest Destiny, and we’re ensuring that we dominate this new frontier.”
The launch of GenAI.mil stands as a testament to American ingenuity, driven by the AI Rapid Capabilities Cell within the War Department’s Office of Research & Engineering. Their achievement directly embodies the Department’s core tenets of reviving the warrior ethos, rebuilding American military capabilities, and re-establishing deterrence through technological dominance and uncompromising grit.
“We are pushing all of our chips in on artificial intelligence as a fighting force. The Department is tapping into America’s commercial genius, and we’re embedding generative AI into our daily battle rhythm.” Secretary of War Pete Hegseth remarked, “AI tools present boundless opportunities to increase efficiency, and we are thrilled to witness AI’s future positive impact across the War Department.”
The Department is providing no-cost training for GenAI.mil to all DoW employees. Training sessions are designed to build confidence in using AI and give personnel the education needed to realize its full potential. Security is paramount, and all tools on GenAI.mil are certified for Controlled Unclassified Information (CUI) and Impact Level 5 (IL5), making them secure for operational use. Gemini for Government provides an edge through natural language conversation, retrieval-augmented generation (RAG), and is web-grounded against Google Search to ensure outputs are reliable and dramatically reduces the risk of AI hallucinations.
GenAI.mil is another building block in America’s AI revolution. The War Department is unleashing a new era of operational dominance, where every warfighter wields frontier AI as a force multiplier. The release of GenAI.mil is an indispensable strategic imperative for our fighting force, further establishing the United States as the global leader in AI. (Source: U.S. DoD)

 

10 Dec 25. The French Defence Procurement Agency (DGA) has awarded Airbus Defence and Space a framework contract worth up to €50m for the integration of artificial intelligence components into the weapons, information, communication and cybersecurity systems used by the French armed forces. The contract covers information systems delivered by Airbus Defence and Space and Airbus Helicopters. Within this framework, Airbus and the DGA are working in collaboration with the Ministerial Agency for Defence AI (AMIAD), created in May 2024 to enable France to master these technologies and avoid dependence on other nations. It is part of the ministerial strategy on artificial intelligence for defence, which aims to address the challenge of sovereignty in this field and develop the use of AI for military operations.
The first stage of this contract will consist of increasing the capabilities of Spationav, the French maritime surveillance system with AI elements that will enable the automated merging of surveillance data from satellite systems and Spationav. Many other potential uses are being or will be explored, particularly in the fields of intelligence, cybersecurity and connectivity, such as real-time assistance in the management and optimisation of military telecommunications networks. With the proliferation of sensors (satellites, radars, drones, smartphones, social networks) generating massive amounts of data, only AI can process it efficiently and quickly. The aim is to save humans time in activities they already carry out, as well as to perform tasks that are impossible for humans to complete, given the urgency of the situation or the excessive volume of data to be processed. The other major challenge associated with AI is the ability to store, archive and structure all the data that feeds it using appropriate infrastructure.

 

09 Dec 25. Leading the Charge: L3Harris’ Advanced EW Technologies for Superior Battlefield Advantage. Today’s warfighters face increasingly complex and sophisticated challenges on the battlefield. Modern threats – such as drone swarms, signals that change frequencies and attempts to “spoof” or trick communications systems – necessitate solutions that are smarter, faster and more adaptable than ever before.
For decades, L3Harris has been a leader in electronic warfare (EW), designing systems to help warfighters detect, respond to and overcome these challenges. With an international presence across multiple domains – space, air, land, sea and cyber – L3Harris’ advanced tools and solutions are trusted by defense customers worldwide.
“Today’s warfighters need tools that can adapt to rapidly changing threats and environments,” said Ed Zoiss, President, Space and Airborne Systems, L3Harris. “L3Harris’ advanced EW offerings are designed to be flexible, reprogrammable and ready to meet the demands of the increasingly complex battlespace.”
Proven, Flexible Tools Backed by Real-World Experience
Leveraging decades of expertise and a thorough understanding of the unique challenges faced by its customers, L3Harris provides advanced EW systems tailored to meet the needs of modern-day warfighters. These systems enable U.S. and allied forces to incorporate new functions into a single system or create a networked “system of systems.”
Such flexibility and adaptability is crucial for outpacing sophisticated threats. These systems have proven their value in real-world scenarios and are trusted for critical missions around the globe:
• Successful Demonstrations: Highlights include the U.S. Army’s Vanguard 2024, U.S.-Australian Talisman Sabre 2025 and U.S.-U.K. VANAHEIM 2025.
• Modernization Initiatives: Support includes Viper Shield upgrades to the global F-16 fleet, multi-platform counter-unmanned systems enhancements and new advancements in multi-domain munitions superiority and Counter Communications Systems.
• Advanced Capabilities: Sophisticated solutions like the EA-37B Compass Call, and modified G550s with electromagnetic attack capabilities for partners in Italy and Australia.
Offering an Integrated Enterprise Approach
L3Harris is pioneering comprehensive EW solutions across multi-domain operations. The Sky Warden, with its modular, mission-tailorable architecture, enables future integration with Launched Effects, positioning it as a potential EW asset for special operations forces.
Innovating Smaller, Smarter and More Adaptable Solutions
L3Harris continuously drives innovation across its portfolio of EW solutions in collaboration with universities, government researchers and partners. This results in tools that meet today’s warfighters’ needs by being:
• Compact and affordable: Smaller systems that require less power can be used on drones, portable platforms and even single-use devices like missiles and decoys.
• Flexible and reprogrammable: Systems can be frequently updated manually or automatically using artificial intelligence. Cognitive EW systems can learn to identify and respond to new threats, easing the burden on warfighters.
• Modular and scalable: Systems are designed to be quickly modified and work together as a network, making EW operations more flexible, affordable and future-ready.
With unparalleled expertise and a relentless commitment to innovation, L3Harris is revolutionizing electronic warfare. Cutting-edge solutions – including the next-generation multimission electromagnetic countermeasures system, Gladius – ensure that warfighters maintain a tactical edge, outmaneuvering and defeating the most sophisticated threats. As the global leader in EW, L3Harris stands ready to equip forces with the tools they need for total battlefield dominance, delivering security and superiority in an increasingly complex world. (Source: ASD Network)

 

08 Dec 25. MASS, part of the Cohort plc Group, and its JCAST partners have successfully delivered Joint Venture 2025 alongside the UK MOD’s Integrated Warfare Centre (IWC) – the capstone annual operational validation event ensuring the UK is prepared for war in Europe.
• Major UK-led operational training event tested Standing Joint Force Headquarter Group (SJFHQ Gp) readiness within a NATO context
• Enhanced synthetic environment introduced, featuring Antycip’s MAK ONE VR Forces and Hadean’s PopulAI technologies for the first time for greater realism
• Exercise deployed up to 200 personnel across two fixed locations and multiple remote nodes across Europe
Taking place in November 2025, Joint Venture tested all components of the Standing Joint Force Headquarters Group (SJFHQ Gp) – including SJFHQ, JFHQ and JFLogC (Joint Force Logistics Component) – across the full cycle of planning, deployment and execution of UK sovereign tasks in a broader NATO context.
The exercise saw up to 200 military personnel deployed across two fixed locations and several remote nodes spread across Europe, allowing the Headquarters to train as it would operate in reality. Delivering the exercise, IWC’s Joint Force Training department used MASS to provide comprehensive training support, including exercise design, preparation, delivery and analysis, as part of its ongoing work under the Joint Command and Staff Training (JCAST) contract for the UK Ministry of Defence’s Cyber and Specialist Operations Command (CSOC)
To enhance the training experience for IWC’s target audience, MASS introduced new synthetic environment capabilities into the JCAST contract to leverage the latest VR and simulation technologies. As part of Joint Venture 2025, two advanced tools – VR Forces’ 3D animation and Hadean’s PopulAI – were deployed for the first time, providing an unprecedented level of fidelity and granularity in the simulated operating environment. Together these technologies create a more immersive, data-rich setting that mirrors the realities of modern multi-domain operations.
Brigadier Matt Baker, Head Warfare Development, IWC (Exercise Director Ex JV25) said, “JOINT VENTURE 25 was the flagship exercise for the Standing Joint Force Headquarters to prepare them in their role as Defence’s High-Readiness 2-star Operational Headquarters. The cooperation of the Integrated Warfare Centre (Joint Force Training) and our technical partner MASS has been highly effective in delivering an exercise that has challenged the training audience and provided a way to identify valuable lessons to enhance the performance and effectiveness of the HQ.”
Long-term MASS partner, 4C Strategies also provided its Main Events List / Main Incidents List (MEL/MIL) management within its Exonaut platform, which seamlessly integrates with other systems across the training environment. Exonaut was used extensively during the planning phase of the exercise and provided the digital management and control for the execution phase of the exercise. Using Exonaut enabled Exercise Control (ExCON) to dynamically add injects – based on captured observations and insights – adjusting the course of the exercise to better meet objectives and validate the SJFHQ Gp.
Keith Norton, Managing Director at MASS, said: “Joint Venture 2025 represents a critical opportunity to test the UK’s operational readiness and integration with NATO partners. By ensuring that training replicates the pressures, complexities and dynamics of modern operations, we create an environment where personnel can think and act with operational freedom.”
The exercise directly supports the UK’s Defence objectives outlined in the Strategic Defence Review, strengthening the nation’s operational readiness. Joint Venture 2025 will ensure the UK’s Operational HQ is prepared to respond swiftly and effectively to emerging threats.
Keith Norton added; “Working in close partnership with the UK Operational HQ to align the exercise with their core training objectives, we’re able to build a programme to achieve the desired outcome and ensure that the training audience can learn from their experience in the simulated world. Joint Venture 2025 is not an isolated event, but an integral part of the MoD’s wider preparedness plan.”
For more information visit: https://www.mass.co.uk/

 

05 Dec 25. Cyber Update Key points.
• The expansion of a renowned ‘Mirai’ botnet variant (‘ShadowV2’) poses high security and disruption risks to Internet-of-Things (IoT) devices via the exploitation of software vulnerabilities (see Sibylline Cyber Daily Analytical Update – 1 December 2025).
• A long-term surveillance campaign (‘ShadyPanda’) highlights the security risks from malicious third-party downloads.
• New tactics underscore sustained cyber espionage and financial risks from a North Korean state-sponsored group (‘Famous Chollima’) (see Sibylline Cyber Daily Analytical Update – 3 December 2025 and our technical analysis below).
• Global businesses will face heightened financial and reputational risks from the expansion of a renowned ransomware group (‘DragonForce’) (see Sibylline Cyber Daily Analytical Update – 4 December 2025).
• A new Android remote access trojan (RAT; ‘Albiriox’) will raise financial risks for fin tech and crypto currency application users (see Sibylline Cyber Daily Analytical Update – 5 December 2025).
Technical analysis of weekly stories
Suspected Chinese threat actors have targeted global entities in a long-term surveillance campaign since at least 2018. Since the beginning of the campaign, threat actors have distributed approximately 145 browser extensions purporting to provide legitimate add-on services for Chrome and Microsoft Edge in order to establish a foothold within targeted systems. The first phase of the campaign reportedly started in 2018 with the distribution of actor-made browser extensions disguised as wallpaper and productivity tools. Upon installation, the extensions initially performed legitimate activities to increase their distribution while simultaneously monitoring and exfiltrating browser data. One of the extensions, ‘Infinity V+’, manipulated and exfiltrated search queries for financial profit, alongside creating unique identifiers to monitor activity unbeknown to the user. Threat actors also injected affiliate marketing links for the online retailers Ebay, Amazon and Booking.com into installation files (likely to generate additional illicit profit), highlighting the early financially motivated component of this operation. Malicious activity began later in 2023 when threat actors manipulated the extensions to covertly deploy a backdoor onto compromised systems for remote code execution and data exfiltration. Its multi-pronged functionality also enabled threat actors to deploy a spyware component to exfiltrate additional data and monitor user activity.
Elsewhere, Russian-speaking threat actors are targeting Android users with a new RAT (‘Albiriox’). Threat actors use phishing techniques as an initial vector to trick users into downloading a fake application which mimics the legitimate German retailer Penny Market onto their devices. Upon installation, the application deploys social engineering techniques, prompting victims to enable an Android permission (known as ‘Install Unknown Apps’) before ultimately deploying the main Albiriox payload onto the compromised system. Albiriox provides threat actors with full remote control over compromised devices, allowing them to conduct on-device fraud (ODF) by making malicious activity appear legitimate. Threat actors can bypass security mechanisms to monitor victims’ screens in real time as well as interacting with compromised devices. This includes the ability to display different screen overlays either to obfuscate malicious activity and/or exfiltrate credentials. This is likely used to hijack user accounts and initiate fraudulent money transfers. The campaign reportedly expanded to targeting global users of financial and crypto currency institutions after initially focusing on Austrian targets. Threat actors are also creating custom-made overlays in the latest stage of the campaign, highlighting the malware’s rapid development.
Non-exhaustive recommendations to mitigate these threats include:
• Monitor devices and networks for suspicious activity.
• Add available Indicators-of-Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware.
• Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
• Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.
Our cyber word(s) of the week: User Datagram Protocol (UDP)
Definition: A type of lightweight, connectionless communication protocol that sends data without guaranteeing delivery to prioritise speed.
Example: ‘ShadowV2 then used the User Datagram Protocol (UDP) […] to initiate distributed denial-of-service (DDoS) attacks’ (See Sibylline Cyber Daily Analytical Update – 1 December 2025). (Source: Sibylline)

 

05 Dec 25. GDIT launches Mission Emerge Center in Virginia. GDIT will work with clients, tech companies, and other General Dynamics units at this centre to test and validate new technology solutions.
General Dynamics Information Technology (GDIT), a division of General Dynamics, has launched its Mission Emerge Center in Springfield, Virginia.
Spanning approximately 5,200ft², the site is designed to expedite the development of advanced technologies intended for intelligence and defence operations.
GDIT intends to collaborate with its clients, commercial technology companies, and other General Dynamics entities at this location to test and validate solutions. These include AI-driven mission analysis, tactical edge capabilities, cyber tools, AI-assisted software development, optimised sensor processing, and high-performance computing. The Mission Emerge Center will also expand GDIT’s DeepSky lab, which simulates government environments. The DeepSky lab enables teams, irrespective of their locations, to test new capabilities and work with technology partners, industry, and academia to develop and prototype innovative solutions. Furthermore, the Mission Emerge Center will be used to demonstrate new technologies to clients, such as Motion GEOINT, which combines intelligence sources for real-time detection of moving targets. It will also showcase GeoInsight Mission Planning, which uses large language models to analyse geospatial data for quicker decision-making during missions. GDIT will work with other General Dynamics business units at the centre, including a collaboration with Gulfstream Aerospace to build a solution for processing overhead imagery from aircraft-mounted sensors for intelligence missions.
GDIT president Amy Gilliland said: “Advancements in artificial intelligence, drones and cyber have fundamentally reshaped our national security missions and our battlespace and intelligence operations.
“Our investment in the Mission Emerge Center reflects our continued commitment to push boundaries and to enable our teams to transform emerging technologies into mission-ready solutions at speed and scale.”
The Mission Emerge Center forms part of GDIT’s ongoing investment in research and development (R&D) laboratories across the US and is included in its Technology Investment Strategy focused on advancing government missions and tactical edge capabilities.
Previously, the company implemented solutions in various field exercises, including deploying an AI and cloud system at Cyber Fortress 2025, and providing a “cloud-in-a-box” solution at Mobility Guardian 2025 in Guam.
In September 2025, GDIT secured a $1.5bn contract to modernise the enterprise IT infrastructure of the US Strategic Command (STRATCOM). (Source: army-technology.com)

 

08 Dec 25. North America region: Government, CNI, IT sectors face increased security risks from Chinese threat actors. On 6 December, international news outlets reported that a suspected Chinese state-sponsored group targeted US and Canadian government agencies and IT sectors in a long-term cyber operation between April 2024 and September 2025. In one instance, threat actors compromised a web server to infiltrate the targeted system before using stolen credentials to escalate privileges, possibly highlighting the campaign’s preferred attack vector. More specifically, threat actors hijacked the system’s Active Directory to gain control over the system’s virtualised environment and ultimately deploy a backdoor (‘BRICKSTORM’). BRICKSTORM displayed multiple advanced obfuscation techniques, such as the ability to re-install itself if interrupted and encrypted command-and-control (C2) communication, to prioritise prolonged persistence. We assess that this operation illustrates the continued development of Chinese cyber threat actors’ capabilities to exploit virtualised environments for malware deployment. Consequently, this will increase security risks to the government, critical national infrastructure (CNI) and IT sectors in the North America region amid ongoing geopolitical hostilities. (Source: Sibylline)
——————————————————————————————————————————————————————————————————————————————————————————————————————————————–
Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.
—————————————————————————————————————————————————————————————————————————————————————————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

December 5, 2025 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

————————————————————————————————————————————————————————————————————————————————————————————————————————————-

04 Dec 25. Smokin’ Bacon. Congressman Don Bacon, the representative for Nebraska’s second congressional district is to be warmly congratulated. Firstly, Mr. Bacon is a tireless electronic warfare advocate. Back in January, Armada was delighted to interview him in our ‘Congress’ EMSO Champion’ article. Secondly, Mr. Bacon has been consistent and forthright in his opposition to Russia’s invasion of Ukraine. He sounded all the right notes on a putative ‘peace plan’ unveiled by the administration of President Donald Trump on 21st November dubbing it “gross buffoonery”. Mr. Trump’s initiative was a five-a-dime pastiche of long-standing Russian demands that all but sell Ukraine down the Dnepr. In retrospect, the 28-point document was not surprising. Mr. Trump has been at best lukewarm to Ukraine’s brave fight for her survival, at worst outright hostile. The President’s seeming adoration and, at times, outright sycophancy towards Vladimir Putin, his Russian counterpart, is as hard to fathom. On the one hand, it could be argued that Mr. Trump’s initiative was at least trying to break a logjam: Ukraine and Russian forces are locked in a grinding stalemate on the battlefield; Ukraine needs cash, and lots of it, to continue fighting. For now, Ukraine and her allies remain reliant on the United States for certain military capabilities, notably air defence systems and intelligence. However, a Ukrainian collapse or capitulation would be as strategically disastrous for the United States as it would be for Europe. To be fair to Mr. Trump and Ukraine’s allies, the situation in which these actors find themselves in could have been avoided. The aims of those opposing Russia’s aggression and occupation have, at times, been fuzzy. Providing Ukraine with some forms of conventional weapons, but not others, a la Germany’s refusal to send Taurus long-range missiles sends Mr. Putin the wrong message. Likewise, some European countries have pledged to send troops to Ukraine to police any future ceasefire. Such pledges are then rolled back in the face of Russian bellicosity and voter disquiet: A response of “put up and shut up” would be more effective to both complainants. The only acceptable reaction of Ukraine’s allies to Russia’s invasion on 24th February 2022 should have been to immediately demand the unconditional withdrawal of Russia from all of Ukraine’s territory. An opportunity was missed in not declaring a no-fly zone over the country. Yes, it would have brought NATO airpower into a shooting war with Russian aircraft but there’s little doubt who would have won. Ironically, Russia never gained air superiority over Ukraine. Ukraine’s allies should have made as much conventional materiel available as possible sans conditions: Kyiv’s partners should have reserved the right to intervene militarily in Ukraine against Russia at a time and place of their choosing. Mr. Putin throws around nuclear threats with abandon. Ukraine’s allies should not be afraid to call his bluff. Even the single detonation of a Russian tactical nuclear weapon high above the Baltic causing no greater damage than a worrying electromagnetic pulse would hand Ukraine’s allies the initiative. Moscow’s forces would hopefully receive a conventional military response of biblical proportions that could degrade Russian forces threatening Europe to the point of irrelevance. Mr. Putin and his goons are bullies, and all bullies are cowards who avoid confrontation like the plague. Now is the time for Ukraine’s allies to stand firm against their two biggest strategic threats; Russia’s intimidation and Mr. Trump’s acquiescence. Mr. Bacon clearly realises this, is not afraid to speak truth to power and should be applauded. (Source: Armada)

 

04 Dec 25. December Spectrum SitRep. TAF Industries’ new Kvazar-A electronic warfare system is designed to engage uncrewed aerial vehicle threats across wavebands of 300 megahertz up to six gigahertz providing 500 watts of combined jamming power.

Armada’s monthly round-up of all the latest electronic warfare news in the product, programme and operational domains.

TAF Industries Unveils Kvazar-A

Ukrainian Electronic Warfare (EW) specialists TAF Industries have shared with Armada details of the company’s new Kvazar-A EW system. Kvazar-A is designed to protect civilian and military vehicles from Uncrewed Aerial Vehicles (UAVs) gathering intelligence, surveillance and reconnaissance data, and kamikaze aircraft. The company says that Kvazar-A covers frequencies of 300 megahertz up to six gigahertz. This waveband encompasses a significant quantity of the frequencies routinely used for UAV control not only in Ukraine, but around the world. Several frequency bands can be jammed by the Kvazar-A at any one moment. Each band is jammed with a specific module providing between 50 watts/W or 100W of power. These power levels result in a total combined, simultaneous signal strength of 500W. TAF Industries plans to demonstrate a ten-band jammer to protect a civilian vehicle in the coming weeks. Digital suppression technology will also be trialled to enhance the system’s smart directional jamming attributes. The company emphasises the compact housing and antenna unit, and high-power output, which make Kvazar-A suitable for installation on an array of vehicles. TAF Industries added that Kvazar-A is ready for procurement and is being certified by the Ukrainian armed forces. The Ukrainian military is already using the company’s earlier Kvazar-3M UAV jammer.

At the Vanguard of Turmoil

On 13th November, Allen-Vanguard announced in a press release that it had delivered additional Turmoil Radio Frequency (RF) decoys to an unnamed North Atlantic Treaty Organisation (NATO) country. The press release states that Turmoil can replicate friendly force RF emissions in multiple locations. By using Turmoil blue forces can disorganise red force electronic support tasks: Hostile signals intelligence cadres will have their mission complicated by multiple blue force signals, some of which will be genuine and some fake. The company says that Turmoil can be rapidly programmed and reprogrammed with RF deception waveforms. The press release asserts that “Turmoil aids freedom of manoeuvre in the electromagnetic space and creates time and space for formations to deliver surprise offensive operations”. The company told Armada that Turmoil emulates the full range of battlefield tactical radio frequencies used by NATO militaries. Typically, these include Very/Ultra High Frequency (V/UHF: 30 megahertz/MHz to three gigahertz/GHz) signals. Alternatively, the decoys can transmit bespoke signals and signal strengths. Examples of such customisation include the programming and transmission of High Frequency (three megahertz to 30MHz) and Super High Frequency (three gigahertz to 30GHz) signals. Allen-Vanguard claims that the decoy’s advantage “is massive RF flexibility to meet the needs of any given tactical situation, rapid deployability and sophisticated software and algorithms to maximise the enemy’s RF confusion”. (Source: Armada)

 

04 Dec 25. Leonardo Inaugurates the Regional Cyber Center in Malaysia, Turning Kuala Lumpur Into a New Hub for the Southeast Asia

  • The opening of the Regional Cyber Center not only strengthens Leonardo’s positioning as a leader in global security, but also consolidates Malaysia’s role as a strategic hub for the Southeast Asia
  • The Global CyberSec Center based in Kuala Lumpur joins Leonardo’s global network, which already includes the federated centers in Chieti, Bristol, Brussels and Riyadh

The opening of the new Regional Cyber Center strengthens Leonardo’s positioning as a leader in technologies for global security. The inauguration, which took place today in the presence of the Malaysian Minister of Communications, Yang Berhormat Datuk Fahami Fadzil, underlines the company’s commitment to ensuring global security, responding proactively to today’s increasingly complex and rapidly evolving cyber threats.  The strategic choice of Malaysia reflects the country’s leading role in cybersecurity. Malaysia stands out in the region for its advanced legislation on the subject and its protection of critical national infrastructure. Leveraging the integration of Leonardo’s proprietary technologies in the field of cyber security, physical security and mission-critical communications and its experience in strategic sectors in Italy and abroad, the new Center will make a substantial contribution to global protection against new hybrid threats, strengthening the digital autonomy and supporting the sustainable development of Malaysia and the entire region.  The new center in Kuala Lumpur is part of the Global CyberSec Center (GCC), Leonardo’s trusted and mission-critical cybersecurity service provider headquartered in Chieti (Italy), and joins the already operational federated Regional Cyber Centers in Brussels (European Union), Bristol (United Kingdom) and Riyadh (Saudi Arabia). The GCC’s global network is designed to ensure cyber mission assurance for strategic customers – including defence organisations and critical national infrastructures – by pooling processes, information on threats, and cutting-edge technologies. This federated model ensures both the ability to operate on a global scale in preventing, countering and responding to new threats, and the control of strategic data, fully respecting individual national sovereignty.

“This initiative is a long-term investment reflecting Leonardo’s major commitment to building a strong industrial and technological partnership with Malaysia while contributing to the development of high specialised local human capital. In a world where cyber self-reliance has become the new currency of stability, we enable National Strategic Organizations to assure security and continuity of their operations leveraging our Global CyberSec Platform. Through this investment in Malaysia, our objective is to support the transformation of critical infrastructures, such as National Cloud and National Security Operation Centers, into autonomous strategic assets”. States Andrea Campora, Leonardo’s Managing Director Cyber & Security Solutions Division.

The inauguration of the new regional Cyber Center in Malaysia represents a key milestone in Leonardo’s long-term strategy of expanding its international presence in the country and throughout the region. The initiative, combined with recent acquisitions in Zero Trust architecture, further strengthens Leonardo’s leading role in ensuring global security, and consolidates Malaysia as a crucial and strategic hub for the Southeast Asia and, in perspective, for the Far East.

Leonardo has had an established presence in Malaysia for over forty years, making a significant contribution to its defence and aerospace sectors. Over the decades, the company has supported the country with a comprehensive portfolio of advanced solutions, including helicopters for military and commercial operations, military aircraft, integrated defence systems – such as radar and both naval and electronic warfare capabilities – and security solutions for critical infrastructure and mission-critical communications. (Source: ASD Network)

 

04 Dec 25. Going Blind: The Systematic Takedown of Iran’s Early Warning Network. Exclusive analysis performed by Armada and MAIAR indicates that Israel may have degraded Iranian early warning radar coverage by up to 50 percent. MAIAR’s analysis calculated that Iran possessed 13 such systems all of which formed a key part of her IADS’ early warning capabilities. Open sources note that Ghadir radars detect targets at ranges of up to 594 nautical miles (1,100 kilometres) and at a maximum altitude of 984,252 feet (300,000 metres). All 13 radars, deployed as they were across Iran, provided dense, overlapping coverage of her airspace and air approaches. Israel began striking the Ghadirs with air-to-surface ordnance and possibly kamikaze Uncrewed Aerial Vehicles (UAVs) from October 2024. The strikes formed part of Israel’s retaliation against Iran’s attacks of targets in the former by missiles and kamikaze UAVs from April 2024. These efforts gathered momentum following Israel’s commencement of Operation Rising Lion on 13th June. The operation was mounted by Israel to attack Iran’s clandestine nuclear weapons and weapons of mass destruction programmes. As the animation accompanying this article makes clear, Israel’s S/DEAD efforts may have degraded Iranian Ghadir coverage by at least 50 percent. (Source: Armada)

 

03 Dec 25. BAE Systems (LON: BA) today announced the launch of Velhawk™, a next-generation cybersecurity framework designed to enhance resilience, accelerate cyber response, and optimize workforce efficiency for government customers. Developed through decades of cyber operations experience and zero-trust innovation, Velhawk brings together artificial intelligence (AI), automation, and adaptive analytics. Together, they form a unified cyber defense architecture. BAE Systems launched Velhawk™, a next-generation cybersecurity framework designed to enhance resilience, accelerate cyber response, and optimize workforce efficiency for government customers. (Credit: BAE Systems) Velhawk improves an organization’s security posture, significantly reduces response time to cyber incidents, and decreases staffing requirements by automating critical detection, decision, and remediation workflows. The result is a modernized cybersecurity ecosystem that enables customers to focus on mission execution while maintaining constant vigilance against evolving threats.

“Our customers are operating in an era where the attack surface is expanding faster than the workforce can grow,” said Peder Jungck, Chief Innovation and Strategy Officer for the Intelligence & Security sector at BAE Systems. “Velhawk gives them the advantage they need now — a way to automate defense, outpace threats, and elevate human expertise through autonomy and AI. It’s not just about reacting faster, it’s about predicting what comes next.”

By fusing threat intelligence, secure data management, and rapid response under a single ecosystem, Velhawk represents the next evolution of BAE Systems’ cybersecurity solutions, one built for speed, scale, and the future fight. Velhawk is part of BAE Systems’ broader mission to deliver mission-ready, future-relevant technology to customers worldwide, advancing national security through trusted innovation. (Source: PR Newswire)

 

04 Dec 25.  Global: Businesses face high financial, reputational risks from ongoing RaaS expansion. On 3 December, international news outlets reported that a renowned ransomware group (‘DragonForce’) has significantly expanded its operations since its emergence in 2023. DragonForce is a Ransomware-as-a-Service (RaaS) operation and has reportedly started offering affiliates 80% of profits, as well as customisable encryptors and command-and-control (C2) infrastructure, since the beginning 2025. We assess that this RaaS package likely incentivises large numbers of more and/or less experienced threat actors to conduct operations on behalf of DragonForce, simultaneously growing the group’s global presence and reputation. The cyber attack on the UK-based retailer Marks & Spencer (M&S) that took place in April allegedly marked the first instance of co-operation between DragonForce and the high-profile ransomware group ‘Scattered Spider’. The attack has cost the company approximately USD 395 m, highlighting the potential impact of this kind of collaboration. Consequently, global businesses will face heightened security, financial and operational risks as ransomware groups continue to expand their operations. (Source: Sibylline)

 

03 Dec 25. HawkEye 360 Launches Vessel Custody ID to Strengthen National Security and Intelligence Operations. HawkEye 360, the global leader in signals intelligence data and analytics, today announced the the introduction of a new feature that improves maritime awareness by maintaining custody of high-interest vessels across multiple satellite collections. The capability uses artificial intelligence to assign unique tracking identifiers, allowing organizations to maintain custody of high-interest vessels across time and space. By automating continuity and scoring the confidence of each identification, the solution provides scalable insight into maritime activity without dependence on self-reported data sources or human intensive processes.

“This capability represents a major step forward for decision-makers who need reliable custody of critical maritime targets,” said Greg Skotzko, Director of Product Management, at HawkEye 360. “By applying AI to automate vessel tracking and integrate movement analysis, we are enabling the Defense and Intelligence Communities to monitor complex environments with greater accuracy and efficiency.”

Key Features include:

  • AI-Enabled Custody ID – Unique identifiers maintain tracking continuity of vessels across multiple collections.
  • Confidence Scoring – Reliability ratings provide transparency into the strength of vessel custody certainty.
  • Velocity Integration – Speed and course attributes add context to custody threads and support behavior analysis.
  • Wide-Area Coverage – Space-based collection extends visibility into denied, contested, or politically sensitive regions.

By reducing manual workload and scaling analytic outputs, this AI-enabled maritime custody capability enhances the ability of defense and intelligence organizations to build patterns of life, expose deceptive behaviors, and direct resources more effectively across global areas of interest.

This first release applies to a subset of HawkEye 360’s Maritime Intelligence suite, establishing a critical framework that will be rapidly scaled across HawkEye 360’s analytics portfolio to unlock even greater mission value. (Source: ASD Network)

 

03 Dec 25. US: New tactics highlight sustained cyber espionage, financial risks from North Korean threat actors. On 2 December, international news outlets reported that a North Korean state-sponsored group (‘Famous Chollima’) is renting legitimate identities to conduct cyber espionage and financially motivated operations. Famous Chollima reportedly targets engineers and developers, luring them with a recruitment announcement on the code repository platform GitHub which asks them to attend job interviews at US-based companies on the group’s behalf. If hired, the recruits receive a percentage of the salary for the duration of the contract while Famous Chollima keeps the remainder, highlighting North Korea’s highly diverse cyber threat portfolio. Furthermore, we assess that Famous Chollima likely exploits the recruits’ access to targeted organisations to deploy malware, monitor activity and conduct financial theft. This underscores the sustained security, cyber espionage and financial risks facing US businesses, as North Korea continues to develop its cyber tactics to bolster its security posture as well as its weapons and missile programmes. (Source: Sibylline)

 

02 Dec 25. Distributed Deployment Server Platform (DSE) – Hensoldt Successfully Completes Regeneration. HENSOLDT has delivered the final components for the regeneration of the mission-proven Distributed Deployment Server Platform to the German Armed Forces. Sensor specialist and solution provider HENSOLDT has now delivered the final tranche of components to the German Armed Forces as part of the regeneration of the Distributed Deployment Server Platform (DSE) that began in September last year. Transport and operating containers, including the associated power and climate control modules and basic segment equipment, were delivered. The Distributed Deployment Server Platform are a modular, scalable, and deployable system. The system is designed for data processing in any client-server infrastructure of the German Armed Forces and can operate in a networked system as well as in stand-alone mode (offline). To this end, it provides all the necessary services and system resources for operating a “back office” solution. Depending on the mission purpose, the system can also be adapted with additional software. Since the early 2010s, the German Armed Forces have been using the DSE for deployment worldwide in almost all climate zones and under the most adverse conditions. Over the past decade, the system has proven itself many times over in exercises and missions. HENSOLDT supported its use by providing continuous and intensive support for the existing systems and supplying special training materials and systems. In cooperation with the Federal Office of Bundeswehr Equipment, Information Technology and In-Service Support (BAAINBw), the DSE has been continuously updated and expanded in terms of numbers. At the heart of the project are the mission-proven server segments in robust transport and operating containers. This enables military users to quickly and flexibly implement secure IT systems on site. Through a variety of technical adjustments, HENSOLDT has been able to (further) develop a future-proof system that not only offers significantly improved performance values but also impresses with a high level of information security. HENSOLDT also supports the German Armed Forces in training existing IT personnel with tailored training courses led by experienced experts and special assistance with system integration. HENSOLDT is thus providing the German Armed Forces with a modern, flexible, and future-proof system for the coming decade. (Source: ASD Network)

 

02 Dec 25. Global: Long-term surveillance campaign highlights risks from malicious third-party downloads. On 1 December, international news outlets reported that suspected Chinese threat actors have targeted global entities in a long-term surveillance campaign since at least 2018. Since the beginning of the campaign, threat actors have distributed approximately 145 browser extensions purporting to provide legitimate add-on services for Chrome and Microsoft Edge to establish a foothold within targeted systems. The initial distribution of the extensions reportedly occurred in 2018, and malicious activity started later in 2023, highlighting the highly methodical and pre-planned nature of this campaign. Threat actors later deployed a backdoor and spyware through the extensions to execute additional malicious code, monitor activity, exfiltrate sensitive information and maintain prolonged persistence. We assess that this campaign underscores the long-term infection risks stemming from third-party downloads. Furthermore, compromised users will face increased short-term security risks as the campaign is still active on some Edge browsers. (Source: Sibylline)

 

28 Nov 25. Cyber Update

Key points

  • A new, highly sophisticated banking trojan (‘Sturnus’) poses heightened security and financial risks to Android users across Europe (see Sibylline Cyber Daily Analytical Update – 24 November 2025 and our technical analysis below).
  • A cyber attack on the Spanish airline Iberia highlights the long-term security and data-theft risks facing high-profile sectors (see Sibylline Cyber Daily Analytical Update –  25 November 2025).
  • New sophisticated cyber techniques used during ‘ClickFix’ attacks will elevate data-theft and financial risks to global users (see Sibylline Cyber Daily Analytical Update – 26 November 2025).
  • Ukraine-affiliated businesses face increased security risks from a Russia-linked threat group (‘RomCom’; see Sibylline Cyber Daily Analytical Update – 27 November 2025 and our technical analysis below).
  • The discovery of new phishing domains belonging to the ransomware collective ‘Scattered Lapsus$ Hunters’ will increase financial and operational risks to businesses in the software supply chain (see Sibylline Cyber Daily Analytical Update – 28 November 2025).

Technical analysis of weekly stories

Unnamed threat actors are targeting Android users across Europe with a new, highly sophisticated banking trojan named Sturnus. The threat actors use social engineering techniques to trick users into installing Sturnus on their devices via a fake Android Package Kit (APK) file. Upon deployment, Sturnus establishes communication with command-and-control (C2) infrastructure, which receives a combination of encrypted and plain-text data via WebSocket and Hypertext Transfer Protocol (HTTP) channels. The malware can display Hypertext Mark-up Language (HTML)-based overlays that mimic various legitimate banking services and/or black overlays to obfuscate other illicit activities. When overlays are triggered, the malware creates a JavaScript bridge that forwards all the data displayed on victims’ screens to C2 infrastructure. Sturnus simultaneously creates a key-logging pipeline through Android Accessibility Services to capture keystrokes, text and user interface (UI) interactions, further showcasing its extensive data-theft capabilities. The malware can also obtain messages from end-to-end encryption messaging applications (including WhatsApp, Signal and Telegram) by accessing the messages post-decryption through Accessibility Services, highlighting its high sophistication. Furthermore, Sturnus displays advanced remote-control capabilities, as it can mirror compromised screens in real time or rebuild a screenshot of a victim’s screen when standard capture is blocked. Although the malware is reportedly still in its testing phase, it is fully functional and an expansion of operations beyond Europe is possible.

In September, the Russia-linked threat group RomCom infiltrated the systems of an unnamed engineering company in the US. It is likely that the group hijacked a legitimate website to trick victims into installing a fake software update onto their systems. RomCom likely used a third-party Traffic Redirection System (TDS) to direct targeted traffic to the compromised website. Afterwards, the fake update reportedly executed a malware loader (‘SocGholish’) onto compromised systems to perform initial system reconnaissance and conduct additional malicious activity. This included the deployment of another malware loader (‘Mythic Agent’), likely to establish persistence and download RomCom’s main ransomware payload. However, the payload was soon detected and quarantined by the company’s security mechanisms, thus mitigating the risks of disruption and information theft. Prior to the deployment of Mythic Agent, RomCom also used a red-teaming framework to manage and control its payloads. This illustrates the continued exploitation of legitimate tools for malicious cyber activity.

Non-exhaustive recommendations to mitigate these threats include:

  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware.
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.

Our cyber word(s) of the week: Android Package Kit (APK)

Definition: A file format used by Android operating systems to distribute and install applications on mobile devices. This is often hijacked by threat actors to deploy malicious files.

Example: ‘Threat actors use social engineering techniques to trick users into installing Sturnus on their devices via a fake Android Package Kit (APK) file.’ (See our Technical analysis above). (Source: Sibylline)

 

01 Dec 25. Global: Botnet expansion highlights high security, disruption risks facing businesses. On 28 November, international news outlets reported that a renowned ‘Mirai’ botnet variant (‘ShadowV2’) is exploiting software vulnerabilities in Internet-of-Things (IoT) devices to conduct disruptive attacks. ShadowV2 activity only lasted for the duration of the Amazon Web Services (AWS) outage that occurred on 20 October, showcasing the botnet’s ability to capitalise on current events. Upon infiltrating targeted systems, threat actors reportedly deployed a Mirai variant to establish communication with command-and-control (C2) infrastructure. ShadowV2 then used the communication protocols User Datagram Protocol (UDP) and Transmission Control Protocol (TCP) to initiate distributed denial-of-service (DDoS) attacks and to cause temporary disruption within compromised systems. Although the attacks’ ultimate objective remains unclear, IoT devices are often responsible for the provision of key services, such as real-time monitoring, predictive maintenance and the automation of different operations; consequently, victims included various industries such as technology, retail, hospitality and manufacturing. We assess that this incident underscores the high security and disruption risks stemming from the continued expansion of botnet infrastructure. (Source: Sibylline)

 

01 Dec 25. ELT Group and King Abdullah University of Science and Technology (KAUST) have signed a landmark Memorandum of Understanding (MoU) to boost their cooperation in cutting-edge technologies. This strategic partnership combines ELT Group’s decades of expertise in managing the electromagnetic spectrum with KAUST’s world-class research ecosystem, paving the way for the development of joint projects related to advanced technologies. The agreement aims to create a platform where scientific breakthroughs meet business applications, ensuring that cutting-edge research is not confined to academic circles but instead reaches the industrial ecosystem of the Kingdom of Saudi Arabia. The partnership builds on ELT Group’s deep-rooted local presence, including the establishment of Elettronica for Industry LLC, a local entity driving technology transfer, focused on localizing manufacturing, logistic support, and, more extensively, the entire value chain.

Prof. Gianluca Setti, Dean of Computer, Electrical and Mathematical Sciences and Engineering at KAUST said: “This partnership brings KAUST’s research strengths together with ELT Group’s applied expertise to advance secure communications, critical-infrastructure monitoring and next-generation technologies, while building local talent and capabilities for the Kingdom.”

Daniela Pistoia, ELT Group Corporate Chief Scientist “By joining forces with KAUST, ELT Group brings its global expertise in the EMSO (ElectroMagnetic Spectrum Operations) to one of the most ambitious research hubs of the world. This MoU will accelerate the development of next-generation technologies, while significantly contributing to the growth of local competences and the technological sovereignty of the Kingdom of Saudia Arabia.”

Through this partnership, ELT Group’s and KAUST will jointly cooperate to address some of the most complex challenges, while also focusing on joint research and studies on emerging technologies, specialised training programmes and access to state-of-the-art testing facilities. The signing took place during the Saudi Italian Business Forum in Riyadh at the presence of the Italian Deputy Prime Minister and Minister of Foreign Affairs Hon. Tajani.

——————————————————————————————————————————————————————————————————————————————————————————————————————————–

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

————————————————————————————————————————————————————————————————————————————————————————————————————————————

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

November 28, 2025 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

——————————————————————————————————————————————————————————————————————————————————————————————————————————————–

27 Nov 25. HENSOLDT presents TAERVUS, a fully integrated system for Electromagnetic Warfare (EW). Among other things, it combines state-of-the-art radio direction finders, receivers and jammers/exciters with powerful signal processing software and HENSOLDT’s own Spectrum Battle Management Suite (SBMS). These systems, trusted and field-proven over many years, are now presented under a unified name. TAERVUS covers both COMINT (communications intelligence) and ELINT (electronic intelligence) in the HF, VHF and UHF ranges up to higher microwave bands and offers jamming capabilities against enemy communications and radar systems. The name, which is composed of the Latin words Terra for earth and Corvus for crow, reflects the system’s self-image and identity as a land EW solution, while the crow, as the symbolic animal of electromagnetic warfare, also has a firm place in this product. TAERVUS combines solutions for tactical and strategic reconnaissance of the enemy with the ability to effectively jam enemy communications systems. It comprises holistic sensor and system solutions in which modular, software-defined and networked systems operate in conjunction with each other. Among other things, the integrated Artificial Intelligence supports signal analysis, enables semi-automatic classification and prioritisation of detected signals, and opens up capabilities such as ‘predictive jamming’, in which jamming measures are optimised in an anticipatory and situation-dependent manner. The need for such a system on modern battlefields is undisputed: In an environment where the speed and quality of information are decisive, TAERVUS enables its users to significantly shorten the so-called OODA loop (Observe, Orient, Decide, Act). This capability provides the user with early, accurate information on the enemy’s position, allowing them to make tactical decisions faster and more accurately than their opponent. “Those who act faster than their opponents and simultaneously disrupt their information gathering capabilities secure a decisive advantage on the battlefield,” said Dr Torben Brack, Vice President and Head of Cyberspace & EW at HENSOLDT. TAERVUS represents a new direction in defence technology, as it seamlessly integrates multiple systems into a system of systems. Its modular design allows it to be used in a variety of projects and guarantees that the user receives not only individual components, but comprehensive system capability. This innovative solution makes a significant contribution to securing the often life-saving information advantage in combat, thereby increasing the chances of success in any scenario.

 

27 Nov 25. Thales wins two PERSEUS awards for its innovations in electronic warfare and artificial intelligence

  • Thales consolidates its role as a key defence partner by obtaining two new PERSEUS labels for its innovations in electronic warfare: CURCO (Radar Detector for Drones) and Golden AI (Artificial Intelligence-based analysis tool).
  • CURCO provides a lightweight, accurate and reliable radar detection capability, adaptable to multiple platforms. Golden AI accelerates and automates the analysis of R-ESM data, thus reducing the stripping and analysis work experts have to do and improving the perception of the electronic order of battle.
  • These technologies are designed to meet the current challenges involved in mastering the electromagnetic spectrum, against a background of massive development of drones and the intensification of conflicts.

Thales has received two major PERSEUS distinctions, awarded by the French Navy, the Délégation Générale de l’Armement (the French procurement agency) and the Agence de l’Innovation de Défense (Defence Innovation Agency). After winning an award in 2023 for its Sentinel electronic warfare solution, Thales is once again certified for CURCO, a compact electronic warfare payload for drones, as well as for Golden AI, an AI-based intelligent analysis tool for electronic warfare data. These two solutions were officially presented at the 2025 Forum innovation défense. CURCO is designed as a lightweight and compact external payload, adaptable to any drone and air, sea or land vehicle. It meets the SWAP requirements (size, weight and power). Capable of defining the electromagnetic environment over a wide frequency band, CURCO offers accurate, fast and reliable detection of enemy radar emissions. It transmits advanced tactical information to operators in real time for better anticipation. Its simple interface and compatibility with numerous mission software programmes has been established during experiments in real conditions, notably during two exercises carried out in 2024 and 2025 in partnership with the French Navy. As part of further developments, CURCO will incorporate, as an option, an on-board jammer aimed at disrupting detected enemy radars.

CURCO, a lightweight and compact external payload, adaptable to any drone and air, sea or land vehicle ©Thales

As for Golden AI, it offers a major evolution towards cognitive electronic warfare, thanks to two innovative functions that enable the data collected by radar interceptors (R-ESM) to be analysed up to 4 times faster. First, it enables the training of AI models from the databases of capitalised radar electromagnetic interceptions. It also enables the analysis of electromagnetic interceptions recorded during a mission, in order to identify the names of the corresponding radars and to enrich the database. By standardising and accelerating analysis, this tool significantly reduces operators’ workload, while improving the accuracy of interception reports. During tests conducted on the ground and then on board during the Clemenceau 25 exercise, Golden AI demonstrated its ability to handle the capitalisation base of the Navy. It also facilitated the debriefings of operators on board, accelerated analysis on the ground, and improved the perception of the tactical situation, while guaranteeing data sovereignty thanks to reliable and scalable AI. Created in 2003, the PERSEUS prize aims to accelerate the integration of key technologies by bringing together sailors, DGA engineers and industrial players, in order to quickly equip the armed forces. Thus, as the mastery of the electromagnetic spectrum becomes critical, in an increasingly dense and complex operational environment, CURCO and Golden AI meet essential needs, both for the Navy and for an export market. With more than 60 years of expertise in electronic warfare, Thales is a key partner for French and European defence, and confirms its ability to support forces in detecting and neutralising radar threats, regardless of the environment. ​ ​

“We are proud to once again receive this PERSEUS label for our advances in electronic warfare. It is the recognition of our innovation strategy, and our willingness to quickly develop concrete solutions, whose value is demonstrated through operational exercises conducted with and for the armed forces,” said Marie Gayrel, Intelligence, Surveillance and Reconnaissance Vice President at Thales.

 

25 Nov 25. Dassault Aviation and Thales, through cortAIx, its artificial intelligence (AI) accelerator, have entered into a strategic partnership for the development of controlled and supervised AI for defence aeronautics. This partnership was signed on 18 November by Eric Trappier, Chairman & CEO of Dassault Aviation, and Patrice Caine, Chairman & CEO of Thales. The announcement was made on Tuesday 25 November at the Grand Palais in Paris, during the International Adopt AI Summit organised under the patronage of the French President. Dassault Aviation, an architect of collaborative air combat systems, and cortAIx, Thales’ trusted AI accelerator, are teaming up to develop sovereign AI solutions. These cover the functions for manned and unmanned aircraft, for observation, situation analysis, decision-making, planning and control during military operations.

“This partnership is reflected in research and innovation programmes dedicated to the collaborative air combat of the future, with a view to incorporating AI into aeronautical defence systems. It is the culmination of strategic discussions launched by Dassault Aviation and Thales’ AI accelerator, cortAIx, and illustrates our shared commitment to trusted, sovereign and controlled artificial intelligence for the armed forces,” says Pascale Lohat, Chief Technical Officer at Dassault Aviation.

Dassault Aviation and cortAIx are developing a lasting cooperation with a high-level, global ecosystem. Their work is carried out in accordance with national and European ethical principles and regulations (AI Act).

“cortAIx will bring to this strategic partnership with Dassault Aviation the best of Thales’ technological heritage, enriched by decades of military experience, combined with the agility and dynamics of a powerful innovation accelerator. Present in France, the United Kingdom, Canada, Singapore and soon in the United Arab Emirates, cortAIx relies on recognised technological partners to transform AI advances into concrete levers of sovereignty and efficiency,” says Mickael Brossard, Vice-President of cortAIx Factory, Thales.

This partnership was presented on 25 November to the guests of the Adopt AI event, via a large-scale illustration of the ambitions of the research and innovation programmes and initiatives currently supported by the European Defence Fund. Dassault Aviation and Thales, through cortAIx, presented their strategy for a controlled, supervised, sovereign, secure and trustworthy AI in the service of humanity, in front of an audience of representatives from the main French and European institutional, academic and economic bodies participating in the event.

 

24 Nov 25. Cubic DTECH, a recognized industry leader in providing trusted, scalable and intuitive edge compute and networking platforms, announces that a national security program is deploying new Mobile Data Centers (MDC)s to support mission-critical operations. The MDCs deliver advancements in autonomy, AI and cloud computing through the DTECH Fusion edge high-performance compute (eHPC). Mobile Data Centers (MDCs), integrated with AI, are reshaping national security by enabling rapid, resilient and intelligent operations in contested environments. MDCs support immediate threat detection, autonomous systems and situational awareness while reducing reliance on centralized infrastructure. Their ability to function in low-connectivity, high-pressure environments makes them especially valuable for military operations, disaster response and border security.

“MDCs integrated with AI are redefining the national security landscape, bringing agility, intelligence and resilience to the front lines,” said Anthony Verna, Senior Vice President and General Manager of Cubic DTECH Mission Solutions. “As threats evolve across physical borders, digital networks and humanitarian crises, the infrastructure that supports national defense must evolve with them. MDCs powered by Fusion eHPC are becoming a cornerstone of that modernization.”

Beyond the tactical advantages, MDCs strengthen cybersecurity and intelligence gathering operations. AI-enabled tools can identify and respond to cyber threats in real time, while onboard sensing systems monitor environmental conditions to maintain continuity during disruptions. MDCs also support large-scale data analysis for counterterrorism, biometric verification and surveillance, helping agencies recognize patterns and emerging threats quickly. With scalable performance and flexible deployment options, MDCs enable national security teams to adapt to fast-changing environments and maintain operational readiness.

 

26 Nov 25. Anduril Demos Connected Defense on NATO’s Eastern Flank. Russia’s continued aggression against Ukraine and its provocations along NATO’s eastern flank have reshaped Europe’s security environment. In September, the threat became more tangible: more than twenty Russian drones violated Polish airspace, prompting Warsaw to invoke Article 4 of the North Atlantic Treaty, which calls urgent consultations among Allies when any member perceives its security or territorial integrity is at risk. Just days later, Russian MiG-31 fighter jets entered Estonian airspace without flight plans or transponders, forcing NATO aircraft to scramble in response. These deliberate incursions underscored a new phase of Russian coercion—one defined by constant pressure, swarm tactics, and speed—and made clear why NATO’s eastern defenses must be faster, smarter and more connected than ever. To meet that challenge, the U.S. Army Europe and Africa, working closely with NATO Allies, is developing the Eastern Flank Deterrence Line (EFDL), which includes a distributed mission command architecture designed to integrate national and Allied sensors, shooters, and unmanned systems into a shared live-data network. Rather than a fixed formation or location, the EFDL functions as a digital shield stretching across NATO’s eastern border. A radar in Estonia, for example, could detect incoming aircraft and instantly share that data with air-defense batteries in Latvia or command centers in Poland. Each nation remains responsible for defending its own territory, but through the EFDL, their systems contribute to a collective deterrence posture. In early November, Anduril joined the U.S. Army’s 10th Army Air and Missile Defense Command (AAMDC) and the Estonian Defense Forces in Tallinn, Estonia, for exercise Digital Shield 1.0, one of the first major event to put the EFDL concept into practice. Over five days, Anduril engineers worked alongside U.S. and Estonian units to connect previously separate sensors, radars, and command and control systems into a single distributed network—the kind of digital infrastructure the EFDL will rely on across Europe. Within 48 hours of arrival, the team set up multiple Menace-T tactical compute and communication kits and established Lattice nodes running in the cloud. Together, these nodes created a resilient network that kept data moving, even when connections were jammed, weak, or cut off, a critical capability for any fight along NATO’s eastern flank.

Multiple Allied sensors were integrated into one live operating picture:

  • The Estonian Defence Forces’ AN/TPQ-50 radar, used for detecting and tracking rocket, artillery, and mortar fire, and the Giraffe AMB radar, which provides short- to medium-range air-defense coverage.
  • Sky Fortress, a Ukrainian-developed acoustic sensor network that detects and classifies drones by sound.
  • Dowding, a commercial UAS-tracking feed developed by Edgesource and used by U.S. Army Europe and Africa, providing additional real-time detections from commercial and military sensors.

By connecting these systems through Lattice, Anduril enabled real-time data fusion across previously separate radar, acoustic, and commercial networks. Feeds that once operated independently were synchronized and shared instantly across U.S. and Estonian command nodes, allowing operators at radar sites, the Estonian Control and Reporting Centre, and U.S Army Europe’s G-3 Operational Data Team to see the same tracks simultaneoulsy, distinguishing drones from birds, validating detections, and coordinating faster responses.

Work that traditionally takes months of integration and certification was completed in days, proving how digital speed and interoperability can outpace an adversary’s ability to mass.

“Innovation is not a one-time effort,” said 10th AAMDC Commanding General, Brig. Gen. Curtis W. King, speaking about the EFDL initiative. “It takes consistent teamwork and trust among Allies. Our goal is to ensure every Soldier, system, effector, and sensor contributes to the EFDL and enhances NATOs collective defense.”

The modern air threat is defined by mass and tempo—swarms of low-cost drones and missiles that can overwhelm static defenses. Digital Shield 1.0 demonstrated a response built on speed, interoperability, and repeatability. Future iterations will expand integrations, introduce automated data fusion and layered effects, and deepen participation across the Alliance. The lesson from Digital Shield 1.0 is clear—deterrence on NATO’s eastern flank will depend not just on forward presence, but on shared data, connected systems, and the ability to move faster than the threat. (Source: ASD Network)

 

26 Nov 25. Global: Sophisticated new cyber techniques will elevate data-theft, financial risks to users. On 25 November, the cyber security company MalwareBytes reported that threat actors have adopted new techniques to deploy malware during ‘ClickFix’ attacks. More specifically, threat actors display a fake Windows update interface to trick users into running malicious commands, highlighting the attack’s reliance on user interaction. The commands subsequently run a PowerShell script that is responsible for fetching a next-stage malware loader concealed within an image. Threat actors then use steganography techniques to extract the code and execute the loader while presenting users with a seemingly normal image, showcasing the actors’ sophistication. Throughout this campaign iteration, threat actors have ultimately installed two renowned information-stealers (‘LummaC2’ and ‘Rhadamanthys’) onto compromised systems, likely to steal credentials and hijack user accounts for financial profit. We assess that this latest campaign underscores the rapid development of cyber techniques, which will in turn elevate security, data-theft and financial risks to global users. (Source: Sibylline)

 

26 Nov 25. Next Generation Jammers (NGJ): Turning Point in Airborne Supremacy. Born to replace the ageing AN/ALQ-99, NGJ is not a single upgrade — it is a family of purpose-built pods designed to dominate the electromagnetic spectrum. Engineered for carriage on the EA-18G Growler and adaptable to other host platforms, NGJ was created to defeat modern, resilient threats: frequency-hopping radars, networked datalinks and the distributed sensor webs that define today’s contested environments. The NGJ family — Mid-Band (MB), Low-Band (LB) and High-Band (HB) — is designed to work together as a layered triad, providing end-to-end spectrum coverage. With MB maturing first and now in production, and LB and HB advancing through development and test, the programme is transitioning from demonstration to sustained operational capability. NGJ’s significance is especially apparent in the most demanding operational settings. Designed for effectiveness in deep, contested waters and adverse environmental conditions, the pod family brings endurance, range and fidelity that legacy systems cannot match. Its thermal management, power handling and antenna architectures were developed specifically to sustain high-power effects without degrading host-aircraft performance — a requirement for missions where extended standoff and mission persistence matter. The path to NGJ’s maturity was not straightforward. Early development demanded breakthroughs in active electronically scanned arrays (AESA), compact high-power transmit/receive chains, and advanced thermal control so an aircraft could carry true high-power electronic attack without compromising flight performance. Engineers also built a modular processing backbone so the system could learn and be reprogrammed in months — not years — as threats evolved. Programmatic friction accompanied technical complexity. A formal protest once paused development, prompting a deliberate re-examination of evaluation methods, technical risk assessments and upgrade paths. Those corrective steps sharpened requirements, intensified testing regimens, and hardened the resulting architectures for sustained operational use. What truly elevates NGJ above previous generations is its software-first design. At its core, NGJ is a reconfigurable, open-architecture system that treats the electromagnetic spectrum as a dynamic battlespace: new waveforms, exploitation algorithms and cooperative tactics can be inserted rapidly. Mission crews can tailor effects in real time and share an electronic order of battle across platforms, turning jamming from blunt suppression into a precise, mission-level instrument that protects strike packages, suppresses integrated air defences, and preserves freedom of action for allied forces. Early results validate the concept. NGJ-MB is entering operational service aboard Growlers, and orders from the U.S. Navy and allied air forces reflect growing operational demand. As NGJ advances from LRP to FRP, deployments of incrementally upgraded pod sets will expand, and the system’s software ecosystem will continue to evolve. (Source: ASD Network)

 

26 Nov 25. Global: Cyber incident highlights long-term security, data-theft risks facing high-profile airlines. On 23 November, international news outlets reported that the Spain-based airline Iberia suffered a cyber attack that resulted in the exfiltration of customer data. The company alerted customers about the breach in an email, where it specified that the attack had originated from an unnamed third-party supplier, underscoring the supply chain risks facing global businesses. The threat actors exfiltrated names, email addresses and loyalty identification numbers during the attack; no financial information was reportedly affected. Nonetheless, we assess that this underscores heightened follow-on social engineering risks in the short term. Furthermore, the report came days after an unnamed threat group issued a statement attempting to sell approximately 77 gigabytes (GB) of data that had allegedly been stolen from Iberia. Although it remains unclear whether the attacks are related, this incident showcases the long-term security and data-theft risks facing high-profile, data-rich airlines. (Source: Sibylline)

 

24 Nov 25. How NGC2 Is Expanding the Battlefield Network at Ivy Sting 2. This month, Team Anduril joined the U.S. Army’s 4th Infantry Division for Ivy Sting 2, the second in a progressive series of exercises designed to advance the Army’s Next Generation Command and Control (NGC2) ecosystem. Just six weeks earlier, during Ivy Sting 1, the team demonstrated digital fires in live training, using NGC2 to connect sensors and shooters so artillery units could respond faster and hit with greater precision. Ivy Sting 2 connected more data nodes, sensors, and Soldiers through a unified mesh network that linked every level of the fight, all the way to the division command post, delivering a more complete, real-time picture of the battlespace. At the center of this event were two new integrations: Ghost-X, Anduril’s autonomous aircraft system, and the AN/TPQ-53 radar, which detects and tracks incoming enemy artillery, rockets, and mortars to pinpoint their launch points—both now feeding directly into the NGC2 ecosystem. These integrations brought real-time sensing, target recognition, and radar tracking into the same digital loop that drives faster decisions on the battlefield.

AI-Aided Target Recognition and Battle Damage Assessment

At Ivy Sting 2, Striveworks’ AI operations platform powered AI-enabled sensing and decision-making within the Next Generation Command and Control (NGC2) environment. Using Anduril’s Lattice Mesh network, a Ghost-X aircraft acted in a forward observer role—streaming live full-motion video for automated object detection and real-time battle damage assessment. Soldiers from the 4th Infantry Division, working alongside industry partners, trained and deployed AI models through Striveworks’ Chariot platform, the AI layer of NGC2. As Ghost-X captured video from the field, these models analyzed the feed in real time to detect and classify enemy T-72 tanks using automatic target recognition algorithms. Once a tank was identified, Striveworks’ Sky Saber application took that output and designated the target as hostile. The resulting data flowed through NGC2’s Lattice Mesh network to Soldiers coordinating fires, who reviewed the information and made the call to strike. When artillery rounds landed, the same AI models compared pre- and post-strike imagery to verify that the hit was successful. The AI significantly reduced the cognitive burden on operators and shortened the time between detection and decision while keeping humans in control at every stage to review, validate, and authorize actions before execution. Together, Striveworks’ Chariot and Sky Saber, Anduril’s Ghost-X, and NGC2’s open architecture showed how AI, sensing, and networked command systems can work as one—delivering real-time intelligence and faster decisions at the edge of the battlefield.

Data at the Speed of the Sensor

Ivy Sting 2 also introduced direct integration of the Army’s Q-53 radar into the NGC2 Mesh. Previously, radar data passed through multiple legacy systems before reaching the units that needed it—each step adding delay and risk. Now, a Voyager ruggedized edge computer running the Lattice software stack is co-located with the Q-53 radar, translating raw radar data into NGC2 format and sharing it instantly across the network. This change eliminated data bottlenecks, letting Soldiers across fires, intelligence, and air-defense teams act on radar information in near-real time, whether connected to the cloud or operating in the field with limited connectivity.

From Edge to Cloud

Building on lessons from Ivy Sting 1, where NGC2 operated exclusively at the edge, Ivy Sting 2 expanded to run simultaneously at the edge and in the cloud. Data from Ghost-X and the Q-53 radar flowed seamlessly to command-post nodes and cloud-based applications, giving leaders a single, coherent operational picture across every echelon.

What’s Next

With Ivy Sting 2 complete, the Army and Anduril team are scaling toward greater complexity. Upcoming exercises will add new command-and-control nodes, mission threads, and airspace-deconfliction capabilities. Each iteration advances NGC2 toward division-wide deployment and the culminating Ivy Mass event in 2026, where the entire 4th Infantry Division will operate as one digitally connected force. (Source: ASD Network)

 

21 Nov 25. UK launches military esports games to boost cyber skills. Military personnel from over 40 nations compete to sharpen cyber skills through gaming applying lessons from Ukraine’s use of gaming technology in warfare. Britain’s future cyber warriors will sharpen digital combat skills through the International Defence Esports Games (IDEG), launched today with over 40 allied nations in London.  Following the UK officially recognising esports as a military sport in 2024, the IDEG acts as a collaborative arena for allied nations to sharpen the cyber skills that are critical for modern warfare – supporting the government’s Plan for Change to strengthen national security.    With over 90,000 cyber-attacks targeting the UK annually, the initiative builds digital skills essential for keeping Britain secure at home and abroad.  Personnel develop critical battlefield skills through competitive gaming, such as tracking multiple threats at once, directing soldiers on the ground, performing under intense pressure, and changing tactics based on live intelligence.  Serving personnel from nations including the UK, Canada and Poland will compete for the first time at IDEG26. Ukrainian forces also proved gaming’s tactical value by developing drone simulator games, which improved operators’ targeting accuracy and reaction times, enabling more effective missions against Russian forces.

Louise Sandher-Jones, Minister for Veterans and People, said:  “The Strategic Defence Review has shown us clearly that the nature of war is changing, and we must change with it. The Government’s Plan for Change demands forces are ready for digital battlegrounds, where our personnel must be as skilled in cybersecurity and with controllers as they are in traditional combat. ”

Lessons from Ukraine have shown how gaming technology can train drone operators and develop the rapid decision-making skills essential for modern warfare. The International Defence Esports Games (IDEG) positions Britain at the forefront of this transformation, ensuring our armed forces are prepared for the conflicts of tomorrow.

Modern warfare demands rapid digital decision-making, drone operation skills, and cyber capabilities. Personnel must process tactical information instantly while maintaining precision under combat pressure.  The competition finals will take place at the new National Gaming and Esports Arena in Sunderland in October 2026, featuring live-streamed tournaments and strategic summits exploring cyber security, AI, and drone operations.

General Sir Tom Copinger-Symes, Deputy Commander of Cyber and Specialist Operations Command, said: “The International Defence Esports Games represent a significant step forward in developing the cyber and digital skills essential for modern military operations. Lessons from conflicts including Ukraine have demonstrated the real-world value of gaming technology in training drone operators and enhancing cyber capabilities.

IDEG will strengthen our warfighting readiness whilst building crucial partnerships with allied nations who share our commitment to technological innovation in defence.”

Chester King, President of British Esports, said: “The launch of the IDEG is a historic occasion for British Esports and military personnel worldwide. We are honoured to host the inaugural finals at our National Esports Performance Campus in Sunderland, which will showcase our world-class facilities and the city and region’s emerging status as a digital innovation cluster.  With international interest already coming from cities in the USA and Australia to host IDEG27, we are focused on making this first event a phenomenal success.”

Today’s launch was supported by partnerships with BAE Systems, Babcock International, and the British Forces Broadcasting Service (BFBS) serving as official media partner, bringing comprehensive coverage to personnel across allied nations. For IDEG26, global advertising agency M&S Saatchi join as a founding partner and Babcock International as the founding mission partner. (Source: https://www.gov.uk/)

 

20 Nov 25. SAIC and HavocAI collaborate on US Navy maritime domain awareness. By integrating HavocAI’s autonomous fleets with JRE and Link 16, both companies aim to enhance the connectivity of maritime systems with broader command and control structures. Science Applications International Corp (SAIC) and HavocAI are joining forces to improve US Navy maritime operations by combining autonomous technologies with multi-domain communication systems. HavocAI’s collaborative autonomy stack will be integrated with SAIC’s Joint Range Extension (JRE) system to enhance maritime domain awareness within the unified joint warfighting network. SAIC’s JRE system extends the operational range and interoperability of Link 16, also known as TADIL-J, a tactical data link that supports information exchange among US and allied air, ground, and maritime platforms. Using this technology, military units can collect and share large volumes of tactical data in real-time, which is intended to support faster decision-making in operational environments. By integrating HavocAI’s autonomous fleets with JRE and Link 16, both companies aim to enhance the connectivity of maritime systems with broader command and control structures used by multiple branches of the military and allied forces. HavocAI’s collaborative autonomy stack currently powers dozens of autonomous vessels operating in self-organising teams, with the potential to scale to thousands. The integration will connect these autonomous fleets directly into existing command infrastructure via the JRE system. This approach is expected to allow for more effective coordination between globally-networked fleets of sensors, platforms, and command assets across all military services and their allies. SAIC navy business group executive vice president Barbara Supplee said: “SAIC’s JRE has been the backbone of advanced joint interoperability for two decades and this partnership to bring HavocAI’s innovative autonomous platform into the fold will provide immediate operational value and drive the future of maritime operations for the US Navy.

“The ability to seamlessly integrate dozens of autonomous vessels into our C2 architecture will provide warfighters with an unprecedented level of maritime domain awareness, sea denial, and sea control.”

The joint effort supports several goals within the US military’s Combined Joint All Domain Command and Control (CJADC2) initiative, which seeks to synchronise operations across all domains while improving decision-making. Both companies are preparing their integrated solution for demonstration activities and exercises. During these events, HavocAI’s autonomous fleet will provide real-time situational awareness data through the JRE system to US Navy operations centres. This is intended to align with the US Navy’s plans for hybrid fleet operations that combine manned and unmanned systems in coordinated missions. In August 2025, SAIC secured a $202m contract to provide the US Navy with a suite of training solutions aimed at enhancing fleet readiness. (Source: naval-technology.com)

——————————————————————————————————————————————————————————————————————————————————————————————————————————————

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

———————————————————————————————————————————————————————————————————————————————————————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

November 20, 2025 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

—————————————————————————————————————————————————————————————————————————————————————————————————————————————–

20 Nov 25. Shield AI and Destinus Partner to Integrate Hivemind Across Platforms in Support of Ukraine and European Defense. Shield AI and Destinus today announced a strategic partnership to integrate Hivemind, Shield AI’s mission autonomy software, across Destinus’ aerial platforms. Together, the companies are creating the first scalable, cross-platform autonomy architecture jointly developed by next-generation defense leaders in Europe and the United States. By combining Shield AI’s battle-proven autonomy with Destinus’ industrial-scale European manufacturing, this partnership accelerates the delivery of AI-enabled unmanned systems to Ukraine and strengthens Europe’s overall defense resilience. Through this partnership, Hivemind will be integrated onto Destinus’ Ruta and Hornet unmanned aerial systems. Together with Shield AI’s V-BAT, these platforms will share information, coordinate behaviors, and adapt in real time with in-flight target updates — creating a tightly integrated and highly effective reconnaissance-strike capability. Joint flight demonstrations are planned for 2026 to showcase operational interoperability across systems from both companies.

“Integrating Hivemind across diverse aircraft architectures like Ruta, Hornet, and V-BAT demonstrates how a unified autonomy framework can enable distributed mission execution,” said Nathan Michael, Shield AI Chief Technology Officer and Head of the Hivemind Business Unit. “By allowing platforms to perceive, decide, and act together in real time, Hivemind delivers scalable autonomy that enhances coordination, survivability, and mission success across the battlespace.”

“For Europe to achieve true technological sovereignty, we must unite world-class AI autonomy with industrial scale,” said Mikhail Kokorich, CEO of Destinus. “This partnership strengthens that effort by pairing Destinus’ platforms and AI avionics with Shield AI’s combat-proven mission autonomy. With Destinus platforms, we are engineering the backbone of a distributed, intelligent, and resilient autonomous strike architecture for Europe and for Ukraine.”

Hivemind is a highly modular, platform-agnostic autonomy software that enables heterogeneous teaming across systems, allowing reconnaissance and strike assets to operate as an intelligent team, thereby closing the reconnaissance-strike loop with speed and precision. Designed to ensure traceability, reliability and governability, Hivemind operates within clear command frameworks and augments human decision-makers, rather than replacing them. Attendees of the Netherlands Defense and Security Exhibition (NEDS) can learn more about the partnership by visiting Booth F3.0, hosted jointly by Shield AI and Destinus. (Source: ASD Network)

 

19 Nov 25. PowerBank Corporation (NASDAQ: SUUN) (Cboe CA: SUNN) (FSE: 103) (“PowerBank” or the “Company), a leader in distributed solar energy, battery storage, and clean energy infrastructure across North America, is collaborating with Orbit AI in the launch of a revolutionary space initiative known as the Orbital Cloud — where communications, compute, and verification converge in LEO powered by Solar energy. The mission leverages cutting-edge satellite technology, high-performance AI compute hardware, blockchain verification systems, and clean-energy solutions to demonstrate a next-generation digital infrastructure in orbit.

Strategic Vision

Orbit AI is developing DeStarlink, the first decentralized low-Earth-orbit network for global connectivity, and DeStarAI, a suite of orbital AI data centers powered by solar arrays and naturally cooled in space. Together, these systems form the Orbital Cloud, a unified infrastructure layer designed to enable sovereign, censorship-resistant connectivity and in-orbit compute services. Through its collaboration with Orbit AI, PowerBank intends to contribute advanced solar energy systems and adaptive thermal control solutions, reflecting its broader shift toward digital asset, data center, and RWA (Real World Asset) infrastructure, where solar power supports digital infrastructure deployments and high-growth AI markets. PowerBank’s contribution focuses on solar power and adaptive thermal technologies essential to future satellite’s “Execution Layer.”

“The next frontier of human innovation isn’t just in space exploration, it’s in building the infrastructure of tomorrow above the Earth,” said Dr. Richard Lu, CEO of PowerBank. “The combined markets for orbital satellites, in-orbit data centers, blockchain verification, and solar-powered digital infrastructure are projected to exceed $700 bn over the next decade. By integrating solar energy with orbital computing, PowerBank is helping create a globally sovereign, AI-enabled digital layer in space , which is a system that can help power finance, communications, and critical infrastructure.”

“Orbit AI is creating the first truly intelligent layer in orbit — satellites that compute, verify, and optimize themselves autonomously,” said Gus Liu, Co-Founder and CEO of Smartlink AI. “The Orbital Cloud turns space into a platform for AI, blockchain, and global connectivity. By leveraging solar-powered compute payloads and decentralized verification nodes, we are opening an entirely new potentially $700+ bn-dollar market opportunity — one that combines energy, data, and sovereignty to reshape industries from finance to government and Web3. PowerBank’s expertise in advanced solar energy systems will be significant in supporting this initiative.”

As Jeff Bezos recently commented at Italian Tech Week, Turin, Italy, October 2025[1]:

“We will be able to beat the cost of terrestrial data centres in space in the next couple of decades. These giant training clusters will be better built in space, because we have solar power there, 24/7 — no clouds, no rain, no weather. It already has happened with weather and communication satellites. The next step is going to be data centres and then other kinds of manufacturing.”

Benefits of the Orbital Cloud

* Energy & Efficiency: Solar-powered orbital computing bypasses terrestrial grid and cooling constraints.

* Unified Infrastructure: Seamless integration of communication and compute layers for space-based data services.

* Global Resilience: Designed to operate beyond geopolitical or national network controls.

* Blockchain Verification: Genesis-1 will include an Ethereumwallet and blockchain node for verified transactions in orbit.

Market Opportunity

The Orbital Cloud intersects multiple rapidly expanding markets:

* Orbital Infrastructure: USD $13.5B in 2024 ? $21.3B by 2029 (CAGR ~9.6%)[2]

* Global Satellite Market: projected USD $615B by 2032[3]

* In-Orbit Data Centers: USD $1.77B in 2029 ? $39.1B by 2035[4]

* Satellite Data Services: ~$12.16B in 2024 ? ~$55.24B by 2034 (CAGR ~16.3%)[5]

Combined, these markets represent a potential $700B+ growth opportunity over the next decade, driven by AI, blockchain, renewable energy, and digital-sovereignty demands.

Technologies and Ecosystem

The project intends to utilize advanced technologies and hardware from global leaders, including:

* Ethereum Foundation – blockchain framework and wallet architecture.

* NVIDIA Corporation – high-performance GPUs powering AI compute payloads.

* Galaxy Space – satellite manufacturing components for future satellites.

* Galactic Energy – launch systems and rocket technologies for future satellites.

* SparkX Satellite – builder of the DeStarlink Genesis-1 satellite.

* AscendX Aerospace – advanced rocket materials integrated into future satellite assemblies.

Investment and Mission Overview

PowerBank intends to complete an initial investment of US $50,000 in Orbit AI, providing an option to invest $1 m for equity of 2%, which with the approval of Orbit AI may be increased to up to US $10 m for equity of 20%, contingent on agreement on final terms and to be completed prior to the launch of DeStarlink Genesis-1 which is expected in December 2025.

Key Milestones

* Q4 2025: Launch of Genesis-1 with Ethereumwallet, blockchain node, and initial AI inference payload.

* 2026: Expansion to 5–8 orbital nodes integrating compute and connectivity.

* 2027–2028: Full constellation rollout and commercialization of Orbital Cloud services.

* 2028–2030: Autonomous network governance; large-scale orbital compute and communication operations.

About Orbit AI

Orbit AI is a Singapore based pioneer in Aerospace. Cooperating with supply chain from China and US, the company is building a decentralized low-Earth orbit satellite network (DeStarlink) combined with orbital AI compute/data-center infrastructure (DeStarAI). The company plans blockchain verified nodes in space, solar-powered compute payloads and a mesh network architecture to deliver global connectivity and digital-sovereignty services. To learn more about Orbit AI please visit https://orbitAI.global or follow http://x.com/OrbitAI_OAI.

About PowerBank Corporation

PowerBank Corporation is an independent renewable and clean energy project developer and owner focusing on distributed and community solar projects in Canada and the USA. The Company develops solar and Battery Energy Storage System (BESS) projects that sell electricity to utilities, commercial, industrial, municipal and residential off-takers. The Company maximizes returns via a diverse portfolio of projects across multiple leading North America markets including projects with utilities, host off-takers, community solar, and virtual net metering projects. The Company has a potential development pipeline of over one gigawatt and has developed renewable and clean energy projects with a combined capacity of over 100 megawatts built. To learn more about PowerBank, please visit www.powerbankcorp.com. (Source: PR Newswire)

 

20 Nov 25. Global: New attack vector underpins long-term cyber espionage risks from Chinese threat actors. On 19 November, the cyber security company ESET reported that a China-linked threat group (‘PlushDaemon’) is hijacking software updates to target global businesses in a cyber espionage operation. PlushDaemon reportedly exploits known software vulnerabilities and/or weak credentials to infiltrate user accounts within targeted systems, focusing on those at the administrative level. It then installs a malicious implant (‘EdgeStepper’) to redirect Domain Name System (DNS) traffic to actor-controlled infrastructure, subsequently hijacking software updates to stealthily deploy a renowned backdoor (‘SlowStepper’). SlowStepper facilitates system reconnaissance, remote file execution as well as the exfiltration of keystrokes, credentials and browser data, highlighting the operation’s extensive monitoring and data-theft capabilities. PlushDaemon has targeted universities as well as the technology and manufacturing sectors across the US and the Asia-Pacific region since at least 2018. Consequently, we assess that this report underpins the long-term cyber espionage risks facing these sectors amid the continuous evolution of the group’s attack vectors. (Source: Sibylline)

 

20 Nov 25. Rohde & Schwarz and SRC, Inc. today announced the first delivery of the RSGEN™, an electronic warfare (EW) environmental signal generation system, to a major DoD test facility. This delivery marks a milestone in the companies’ strategic partnership, bringing together their expertise to advance EW test, evaluation and training capabilities for the US military. The RSGEN system is compatible with the military’s Next Generation Electronic Warfare Environment Generator (NEWEG) architecture including the intel-enabled Digital Generator (DGEN). RSGEN combines up to six time-coincident emitters per single RF port in a scalable platform for creating complex and realistic electromagnetic environments. It supports NEWEG objectives, allowing users to refine their EW capabilities in real-time, improving detection, classification and response to threats while ensuring the most current, effective countermeasures for warfighters in congested RF environments.

“At Rohde & Schwarz we are excited to combine the deep industry knowledge of SRC with our RF threat simulation expertise to jointly bring this new solution to market”. Frank Dunn, CEO of Rohde & Schwarz USA, Inc.

“The RSGEN system is a great example of what can happen when collaboration and innovation come together,” said Kevin Hair, president and CEO of SRC, Inc. “Together with Rohde & Schwarz, we’re giving warfighters the tools to test, evaluate, train and operate more effectively across the electromagnetic spectrum.”

RSGEN is a fully commercial off-the-shelf system that’s scalable from bench-top setups to full system testing. The scalability of RSGEN makes it ideal for a variety of applications, from smaller, niche scenarios to larger, full-scale installations. It’s fully calibrated and designed for quick and easy acquisition, delivery and installation, with logistics support provided by dedicated technical teams with decades of engineering expertise. RSGEN will be exhibited at the AOC Annual International Symposium and Convention from December 9 to December 11 at the National Harbor, MD, Prince George’s Exhibition Hall A-E — 423.

 

19 Nov 25. L3Harris, PentenAmio announce teaming agreement to accelerate cryptographic innovation. L3Harris and PentenAmio have formalised a new teaming agreement to accelerate sovereign cryptographic innovation and deliver secure communications capabilities for defence and government customers across the UK, Australia and Canada. The new agreement was signed at the annual Military Communications and Information Systems Conference in Canberra this week. The collaboration is expected to advance joint technology development, commercialisation and export opportunities through developing advance cryptographic innovation and secure communications capabilities. The agreement establishes a framework for continued collaboration in joint innovation, commercialisation and technology export while supporting the development of critical cryptographic expertise within trusted allied nations.

“By combining two sovereign encryption portfolios, we’re unlocking scale, agility and mission relevance,” PentenAmio chief executive officer Sarah Bailey said.

“This is about delivering integrated solutions that meet the evolving needs of allied governments and defence organisations and doing it quickly and reliably.”

The teaming agreement builds on the successful co-development of the Symmetric Key Manager (SKM), which integrates software and hardware to deliver trusted cryptographic key solutions. The SKM enables secure, over-the-network key generation for classified environments and provides a sustainable, adaptable approach to managing encryption technology. The agreement reflects both organisations’ shared commitment to advancing next-generation cryptographic key solutions that combine hardware, software and services into a seamless, interoperable offering for defence and government customers. It also reinforces a long-term focus on technology innovation, capability sustainment and industrial cooperation between the UK, Australia, Canada and other allied defence sectors.

“This teaming strengthens the foundation for continued innovation in cryptographic technology,” said Ian Menzies, general manager, intelligence and cyber international at L3Harris.

“Working with PentenAmio, a leading provider of advanced digital security solutions, allows both organisations to leverage complementary expertise and deliver enhanced capabilities for our customers.

“This is another example of how L3Harris works with trusted partners to deliver secure, mission-ready solutions.

“Together with PentenAmio, we are building on proven experience and investing in the future of cryptographic capability.”

The agreement is non-exclusive, allowing both L3Harris and PentenAmio to pursue customer requirements independently and offer their own products or services. This flexibility enables each organisation to continue working with other partners where appropriate, provided such activities do not rely on data or information shared under this agreement. By formalising their cooperation, L3Harris and PentenAmio are creating a framework for future growth and technology development that will continue to evolve to meet customer and market needs across multiple territories.

 

20 Nov 25. Thales and the UAE Cyber Security Council join forces to develop a Cyber Centre of Excellence.

* In line with the UAE’s vision to enhance National Cyber Sovereignty, Thales and the UAE Cyber Security Council (CSC) sign a Memorandum of Understanding (MoU) to strengthen and accelerate the country’s Cyber capabilities.

* This partnership includes the creation of three major capabilities within the framework of the Cyber Center of Excellence: a Space META Security Operation Centre (SOC), a Cyber Evaluation Lab, and a Crypto Lab.

* This long-term strategic collaboration focuses on building local capacities, driving innovation, and strengthening sovereign cyber defence capabilities, with, to start with, the space sector as the first ? area of interest.

On the occasion of Dubai Air Show, Thales and the UAE Cyber Security Council (CSC) have signed a Memorandum of Understanding (MoU) to establish a long-term strategic partnership aimed at developing a Cyber Centre of Excellence in the UAE.

This agreement covers the co-development and establishment of three key projects:

* Space META-SOC (Security Operation Centre): a specialised centre dedicated to the cybersecurity of space infrastructures, developed in cooperation with a local industrial partner. Connected to the national SOC, this SOC will integrate advanced technical capabilities and enable knowledge transfer through training focused on satellite constellations and ground system monitoring.

* Cyber Evaluation Lab: a testing and evaluation laboratory for software and hardware asset, designed to be operated by UAE nationals. This lab will also support the development of policies, standards, and governance frameworks for the UAE critical domains, with the space sector as the initial area of interest, positioning the country as a regional showcase for cyberspace excellence.

* Crypto Lab: a platform for designing, testing, implementing and validating cryptographic solutions for the space environment, with a focus on Post-Quantum Cryptography (PQC) and Quantum Key Distribution (QKD). Knowledge transfer and advanced training will be provided by Thales experts, leveraging experience gained from European Space Agency (ESA) projects.

These projects will be part of the Cyber Center of Excellence, an initiative led by His Excellency Dr. Al Kuwaiti, Head of the UAE Cyber Security Council. This collaboration aims to support the UAE’s vision for technological sovereignty, promote local research and development, and contribute to building a sustainable Emirati expertise in space Cyber Security.

“This partnership with the UAE Cyber Security Council marks a major milestone in our joint commitment to advancing the UAE’s sovereign, secure and sustainable Cyber Security ecosystem. Together, we combine our complementary expertise and shared ambition to shape the future of Cyber Security, starting with the Space domain” said Christophe Salomon, Executive Vice-President, Secure Communications & Information Systems, Thales.

With the Cyber Center of Excellence, Thales and the Cyber Security Council will leverage joint research, development, and innovation, to strengthen the UAE’s existing capabilities and build new ones. The collaboration will also extend to other strategic domains beyond space, with both parties jointly addressing international markets.

 

18 Nov 25. Swedish Armed Forces selects TERASi for Tactical 2.0 project. TERASi will help develop “aerial connectivity hub” that delivers unjammable, high-capacity airborne communications. The Swedish Armed Forces have selected TERASi, a Stockholm-based technology spin-out from the KTH Royal Institute of Technology, to participate in the development of Tactical 2.0 project. The initiative will focus on creating an “aerial connectivity hub” that delivers secure high-capacity airborne communications for both tactical defence missions and critical civil operations. The partnership forms part of the Civil-Military Innovation Programme, which is co-led by the Swedish Armed Forces and the government agency Vinnova to promote dual-use technologies aimed at supporting Sweden’s national resilience and technological self-sufficiency. TERASi, which secured a Skr1m ($105,650) grant from Vinnova, will contribute its RU1 millimetre-wave backhaul radio as the secure wireless backbone for Tactical 2.0. This equipment enables the rapid deployment of sovereign, mobile 5G and 6G networks in scenarios where standard or satellite communications are either unavailable or compromised. According to the company, the RU1 device uses its AirCore technology, which supports quick installation and directional transmission.  The radio is designed for low probability of intercept and detection, anti-jamming resilience, and energy efficiency. These features focus on keeping communications secure and operational in contested or disrupted environments. The collaboration demonstrates ongoing efforts to integrate civil and military resources in line with Sweden’s Total Defence doctrine, which seeks to coordinate military, civilian, and private-sector capabilities for comprehensive national defence. The technology is intended to provide secure real-time connections for military operations, including video feeds, sensor data, and AI-assisted weapon systems in areas where conventional connectivity is unavailable or has been rendered vulnerable, said the company. The TERASi project is scheduled to run for nine months beginning in November 2025, and involves participation in an accelerator programme focused on developing a business strategy suitable for both civil and military markets. TERASi CEO and co-founder James Campion said “TERASi has consistently pushed the boundaries of high-frequency performance and integration. The Vinnova award recognizes our leadership in this domain and strengthens our role in developing next-generation, dual-use communication capabilities.

“With Tactical 2.0, we aim to demonstrate how advanced Swedish technology can enhance both national resilience and international competitiveness.”

In September 2025, experts from space technology company Astrolight urged the adoption of jamming-resistant systems throughout Europe, citing threats to civil aviation and essential infrastructure from ground-based GPS interference, especially in the Baltic Sea area. (Source: airforce-technology.com)

 

17 Nov 25. Thales launches its post-quantum MISTRAL encryptor, ready to secure sensitive communications across Europe.

* At the European Cyber Week, held in Rennes (France) from 17 to 20 November 2025, Thales announced the launch of the MISTRAL post-quantum encryptor, a cutting-edge security solution designed to protect communications classified as Restricted against the emerging threats posed by quantum computing.

* The MISTRAL encryptor is intended for public administrations, operators of vital importance, and companies within the defence technological and industrial base.

Fully aligned with ANSSI recommendations and certified to Common Criteria EAL4+, MISTRAL offers a certified and qualified level of security for Restricted-level communications. It is ready for deployment in European projects requiring a high degree of data protection between industrial partners and high-technology stakeholders. The MISTRAL encryptor retains its renowned ease of use and high performance[AR1] [HI2] . The Thales solution not only ensures a very high level of security but also delivers optimal performance, with throughput of up to 4 × 10 Gbps and very low latency, without compromising protection. This solution also stands out for its ease of integration, supported in particular by centralised management.

“By anticipating tomorrow’s challenges, Thales will, from June 2026, provide France and its European partners with a high-grade encryption solution capable of resisting quantum attacks. Public administrations, operators of vital importance, and companies in the defence technological and industrial base will benefit from a state-of-the-art encryptor to shield their Restricted-level communications against the quantum threat.” Pierre Jeanne, Vice-President for Sovereign Cybersecurity activities at Thales.

MISTRAL has already entered operational testing, with availability scheduled for June 2026. In launching this solution, Thales further strengthens its technological leadership in cybersecurity and supports its customers in their transition towards a trusted future, where the security of information exchange is more than ever a strategic priority.

 

03 Nov 25. Lenovo workstations and IMSCAD Services launch hosted workstation cloud solutions for any graphical application. IMSCAD Services has launched WaaS, a ‘Workstation as a Service’ solution, in partnership with Lenovo workstations and Equinix Data Centres, globally. The service comprises private cloud solutions and rentable workstations, on a per user, per month basis. Contracts run from one to 36 months. The service is up to 50% cheaper than high-end instances from the Public Cloud, and the workstations perform much faster for users. Users can get a 1:1 connection to a dedicated workstation, such as the Lenovo ThinkStation P3 Ultra, featuring a Gen 9 Intel CPU that runs at frequencies up to 6.0 GHz and a NVIDIA GPU with up to 24GB of VRAM.

“For far too long, Public cloud pricing is far too high when you want to run graphical applications and desktops,” said CEO Adam Jull. “Our new service is backed by Lenovo hardware and the best remoting software.”

IMSCAD’s WaaS offering was one of four solutions tested by engineering, architecture and planning company TKDA, Minnesota, USA, when looking to replace its current solution that it quickly adopted during Covid.

“IMSCAD stood out far above all other solutions in our testing,” said Nicholas J. Steele, senior systems analyst, TKDA. “The performance of the Lenovo P3 Ultra we accessed was a surprise for all testers. None of us thought we would ever get remote performance that outperformed our local machines.”

TKDA runs a variety of applications including AutoCAD, Revit, SketchUp, and point cloud software. IMSCAD is a global services provider specializing in remote working for compute-intensive applications. For more than a decade, the company has delivered graphical VDI environments to customers in architecture, engineering, construction, and manufacturing. Today, IMSCAD partners with Lenovo to offer Workstation as a Service, deploying Lenovo ThinkStation® systems in Equinix data centers worldwide. This approach combines the mobility of the cloud with the raw performance of dedicated workstations, ensuring customers can access powerful resources securely from anywhere in the world.

For many organizations, virtual desktop infrastructure (VDI) and public cloud solutions had long been the default choice for enabling remote collaboration. But as workloads grew more demanding, these environments often struggled to keep pace.  Latency issues disrupted precision design tasks, CPU clock speeds in virtualized environments lagged well behind workstation standards, and expensive cloud data egress fees added ongoing cost pressure. In addition, many independent software vendors declined to certify their applications in VDI environments, leaving customers exposed.

‘’Traditionally, public cloud and VDI solutions do not offer what customers need for heavy compute workloads. When you’re designing complex models, you simply can’t afford the lag, inconsistent performance, or lack of certification.”  Adam Jull, CEO, IMSCAD Services

To solve these challenges, IMSCAD turned to the Lenovo ThinkStation P3 Ultra SFF, P7, and PX systems powered by Intel® processors, hosted within Equinix’s global data center network.  Unlike virtualized environments, this solution removes unnecessary layers and provides direct access to CPU and GPU resources. That architecture eliminates up to 50 milliseconds of latency, allowing designers, engineers, and content creators to manipulate large models smoothly—even across transatlantic connections.

The results have been transformative. Civil engineering firms in Minnesota now run Autodesk Civil 3D with flawless performance, while construction companies in the Middle East manage hundreds of global Revit and AutoCAD users from a single London data center. Customers consistently report smoother workflows, reduced IT management overhead, and lower long-term costs compared to cloud-only solutions.

The Lenovo ThinkStation P3 Ultra SFF, powered by Intel® processors, is the foundation of IMSCAD’s hosted solution—delivering workstation-class performance for CAD, BIM, and PLM without the latency or cost of cloud. Its compact design fits up to seven systems in 5U of rack space, enabling secure, responsive access to global users through Equinix data centers. For heavier demands, the Lenovo ThinkStation PX adds server-class power with Intel® Xeon® processors, advanced cooling, and multi-GPU support for HPC, rendering, and AI. Together, these workstations give IMSCAD the flexibility to balance mobility, security, and performance worldwide.

This solution gives you cloud convenience with the power of a workstation.  For industries that rely on precision and performance—like architecture, engineering, and media—it removes the compromises of VDI and public cloud.”  James Clark Workstation Technologist, Lenovo UK&I

 

17 Nov 25. Viper Shield Advances Production for Global F-16 Fleet. L3Harris to deliver advanced electronic warfare systems quickly for worldwide F-16 programs. Viper Shield successfully completed a rigorous Production Readiness Review (PRR), marking its transition into low-rate initial production to provide the most advanced electronic warfare (EW) suite to the global F-16 fleet years ahead of any competing system. While other companies may make claims about their developmental systems, L3Harris’ Viper Shield stands out as the only advanced EW system for the F-16 that is currently in production and ready to meet the 2027 challenge.

“Protecting allies in electromagnetic spectrum environments is critical to maintaining global security and stability,” said Michael Rigoni, Air Force Colonel and Electronic Warfare Program Manager, F-16 System Program Office, Wright-Patterson Air Force Base, Ohio. “L3Harris’ success in this PRR moves Viper Shield into low-rate initial production with full rate expected in Q1 ’26 and demonstrates its commitment to providing global F-16 fighter pilots a high-quality electronic warfare suite to meet those challenges.”

Viper Shield is the only advanced EW suite for the F-16 that is fully funded through partner nation development, currently in production, and offers a versatile Pod variant. This combination enhances its versatility and affordability, making it the most sophisticated and efficient solution for the global F-16 fleet.

“Viper Shield is an internationally backed system, supported by seven allied nations currently in production with a new Pod customer expected soon. These advancements make it the premier choice for all countries operating the F-16 Fighting Falcon,” said Ed Zoiss, President, Space and Airborne Systems, L3Harris. “Even the United States, both active duty and Guard units, could greatly benefit from this FMS-funded program.”

The PRR is a comprehensive evaluation process that examines multiple facets of a program, such as design integrity, manufacturing processes, quality assurance protocols and supply chain logistics. The review is especially important for Foreign Military Sales (FMS) programs, where international customers rely on high-quality standards and thorough system validation. Through the process, Viper Shield demonstrated its readiness to transition from initial production to the low-rate initial production of 219 systems for seven partner nations. Additional partner nations that select Viper Shield will benefit from an active production line with robust quality assurance measures and a resilient supply chain capable of meeting the demands of large-scale manufacturing. In addition to passing the PRR, Viper Shield continues to undergo extensive testing and validation to ensure it performs effectively in extreme operational environments and conditions. This is vital for enhancing the operational capabilities of F-16 fleets, providing customers with advanced protection and resilience.  The emphasis on hardware reliability and Manufacturing Readiness Levels (MRL) has allowed L3Harris to scale up production to meet the growing demand. The deployment of Viper Shield will significantly enhance the offensive and defensive capabilities of international partners and could support the United States through an FMS-funded program, if desired, as it offers a robust electronic warfare solution that can be tailored to specific mission needs. (Source: ASD Network)

 

17 Nov 25. Global: Cyber operation illustrates potential security risks stemming from AI automation. On 14 November, the US-based artificial intelligence (AI) company Anthropic stated that a Chinese state-sponsored group (GTG-1002?) exploited its legitimate AI tool (?Claude Code?) to conduct a cyber espionage campaign. The campaign reportedly comprised six phases and largely relied on AI automation, making this incident one of the first large-scale instances of AI-led intrusions. During the operation’s first phase, GTG-1002 selected high-value targets and tricked Claude Code into conducting malicious cyber activity. Subsequently, Claude Code infiltrated targeted systems, conducted reconnaissance and employed open-source tools to maintain persistence and to exfiltrate sensitive data; it only requested human input to perform riskier tasks. Notably, only a small number of intrusions were allegedly successful, though Anthropic?s report has received criticism stating that the content was inflated to promote its products. We assess that this illustrates the increased prominence of AI technologies in the cyber threat landscape, underscoring potential exploitation risks to global firms. (Source: Sibylline)

 

14 Nov 25. Global: Sophisticated ransomware operation poses financial, operational risks to businesses. On 13 November, the technology company Cisco reported that a Russian-speaking ransomware group (?Kraken?) has targeted organisations globally in double extortion attacks since at least February. In one incident in August, Kraken reportedly exploited a software vulnerability in the Server Message Block (SMB) service to infiltrate an exposed organisation. This possibly highlights the group?s preferred initial attack vector. The group then established a remote connection to victims? systems before deploying multiple tools for persistence, data exfiltration and additional malicious activity. Kraken can perform encryption testing before executing the main ransomware payload and simultaneously encrypting files across several compromised environments, showcasing the operation?s sophistication. The group then extorts the compromised organisation by threatening to release stolen data on the dark web if a ransom of USD 1 m is not paid. This report illustrates the elevated extortion, financial and operational risks from the continuous emergence and development of ransomware operations. (Source: Sibylline)

 

17 Nov 25. GSOA released its new paper today, ‘Promoting Synergy Among Communications Services’, exploring how the unique strengths of different technologies contribute to broader, more inclusive connectivity when supported by a framework that encourages investment, innovation, and fosters diverse networks solutions. At a time when the ITU’s World Telecommunication Development Conference 25 (WTDC25) is renewing global commitments to connecting the unconnected, GSOA?s paper highlights how the path to universal connectivity depends on all communications technologies, leveraging their unique strengths. Satellites extend reach, resilience, and rapid deployment capabilities, unlocking opportunities where connectivity remains limited.

“Each technology plays a vital role in today?s digital ecosystem,” says Isabelle Mauro, Director General of GSOA. “Satellites amplify and extend the reach of terrestrial networks. To fully realise this synergy, regulations must reflect how these technologies operate and interact, whilst recognising their own specificities.”

The paper underscores that regulatory frameworks should evolve alongside technological realities. Recognising the specific characteristics of satellite, wireless, and wireline systems is essential to avoid unintended economic, technical, and social challenges which could limit the expansion of essential connectivity solutions.

GSOA calls on policymakers to:

* Recognise the principle of technology neutrality, ensuring policies foster the use of the most suitable solution for the goals.

* Adopt regulatory models that reflect the operational strengths of each network rather than defaulting to uniform rules.

* Support flexibility so networks can complement one another, strengthening connectivity ecosystems and enabling integrated solutions.

* Maintain predictable licensing environments that foster innovation, investment, and the effective deployment of diverse connectivity options.

With thoughtful, fit-for-purpose regulation, governments can accelerate progress towards inclusive universal connectivity goals and advance the shared vision of a world where everyone benefits from, ubiquitous, resilient, meaningful connectivity.

 

14 Nov 25. Cyber Update Key points. Increased hacktivist operations stress the heightened security and disruption risks to the public sector in Europe (see Sibylline Cyber Daily Analytical Update ? 10 November 2025). A multi-stage malware campaign underscores the security risks from the continued exploitation of legitimate tools (see Sibylline Cyber Daily Analytical Update ?  11 November 2025). South Korea-based Android users face surveillance and disruption risks from the North Korean state-sponsored group ?KONNI? (see Sibylline Cyber Daily Analytical Update 12 November 2025 and our technical analysis below). Multiple data breach claims by the renowned ransomware group Clop underscore the security and data-theft risks from the exploitation of software vulnerabilities.

A sophisticated Russian-speaking ransomware group (Kraken) poses elevated financial and operational risks to global businesses Technical analysis of weekly stories

The North Korean state-sponsored group KONNI has targeted South Korea-based Android users in a cyber campaign since at least July. The group reportedly distributes spear phishing emails impersonating legitimate South Korean services (including the National Tax Service), in order to trick victims into executing a malicious attachment. The group subsequently sends a follow-up email to inform victims that the initial email had been sent by mistake, thereby averting suspicion and highlighting the sophistication of KONNI?s social engineering techniques. During the initial phase of the attack, KONNI conducts reconnaissance, modifies configurations to ensure persistence and establishes communication with command-and-control (C2) infrastructure. The group?s malicious scripts stealthily persist within victims? environment for long periods of time. The group also collects and exfiltrates sensitive information and account credentials, which it uses in some cases to hijack user accounts for an Android tracking service (FindHub) and a South Korean search engine (Naver). KONNI then checks victims? locations through compromised webcams and exploits hijacked FindHub accounts to erase devices? data; it also conducts other illicit activities. This underscores the disruptive nature of this campaign. Furthermore, KONNI has propagated infection after hijacking user accounts in a South Korean messaging platform (KaKaoTalk). Here, the group distributes malicious Microsoft Installer (MSI) files disguised as mental health-related packages to users, including those that have defected from North Korea.

Elsewhere, the Russian-speaking ransomware group Kraken has targeted global organisations in double extortion attacks since at least February. In one incident in August, Kraken reportedly exploited a software vulnerability in the Server Message Block (SMB) service to infiltrate an exposed organisation, possibly highlighting the group’s preferred initial attack vector. The group then exfiltrated administrative-level credentials to hijack user accounts before establishing a remote connection to compromised systems and deploying multiple tools for persistence, exfiltration and additional malicious activity. Across attacks, Kraken is able to check the type of environment it is running in to avoid sandboxes, underscoring its detection evasion capabilities. Furthermore, Kraken can perform encryption testing on files on compromised systems before executing the ransomware payload, optimising the main encryption process. It can also simultaneously encrypt files across multiple environments to tailor attacks, further showcasing the operation?s sophistication.

Non-exhaustive recommendations to mitigate these threats include:

*Monitor devices and networks for suspicious activity.

*Add available Indicators-of-Compromise (IoCs) to your organisation?s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware.

*Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.

*Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.

Our cyber word(s) of the week: Server Message Block (SMB) protocol

Definition: A network communication protocol used for sharing files, printers, serial ports and other resources between nodes on a remote server, as if they were local. (Source: Sibylline)

 

14 Nov 25. UK reportedly considers Pegasus SIGINT aircraft purchase. Defence Eye has reported that the UK is in discussions with German defence firm Hensoldt about a possible purchase of its Pegasus signals-intelligence aircraft. The outlet’s piece, available here, says the talks have progressed under the Trinity House framework and could feature in the forthcoming Defence Investment Plan. Pegasus is based on the Bombardier Global 6000 business jet and carries Hensoldt’s Kalaetron Integral mission system, which is designed to detect, analyse and geolocate radio and radar emissions across a broad frequency range. Germany is acquiring three aircraft to restore a capability it has lacked since the withdrawal of the Breguet Atlantic in 2010. That programme is valued at about ?1.54 bn and includes ground elements, evaluation systems and training infrastructure. Hensoldt is the prime contractor and leads development of the reconnaissance technology, while Lufthansa Technik Defence manages aircraft procurement, structural modifications and mission-system integration. Bombardier Defence undertakes the initial conversion work at its site in Wichita before the aircraft are transferred to Hamburg for the installation of the SIGINT suite. (Source: UKDJ)

 

19 Nov 25. UK smashes Russian cybercrime networks responsible for attacks on UK businesses. The UK, US and Australia announce new sanctions targeting Media Land, a Russian cyber crime group providing so-called ‘bulletproof’ hosting services.

* New sanctions target the Media Land cybercrime syndicate responsible for facilitating cyber-attacks on UK-based companies.

* Foreign Secretary announces latest crack down on illicit cyber activity globally, as cyber-attacks cost the UK economy £14.7 bn in 2024.

* Today’s coordinated action with Australia and the United States demonstrates the UK’s ongoing commitment to tackling malicious Russian cyber activity.

Illicit Russian networks enabling cyber-attacks round the world are today exposed and sanctioned by the UK, in latest crack down on malicious Russian cybercrime.

Today’s action targets Media Land, one of the most significant operators of so-called “bulletproof” hosting services, which provides online infrastructure that enables cyber criminals to engage in illegal activity, including ransomware and phishing attacks.

These shadowy online networks allow cyber criminals and malicious actors to think they can act with impunity and destroy livelihoods – today’s action, taken alongside our allies in Australia and the United States and in collaboration with the UK’s National Crime Agency, proves otherwise.

Cyber criminals hiding behind Media Land’s services are responsible for ransomware attacks against the UK’s critical national infrastructure including those in the telecommunications sector, as well as malware and phishing campaigns targeting UK taxpayers.

Defending Europe from malicious Russian cyber and hybrid activity is a shared priority for the UK and Germany, with Foreign Secretary Yvette Cooper set to meet her German counterpart Johann Wadephul.

Foreign Secretary, Yvette Cooper, said: “Cyber criminals think that they can act in the shadows, targeting hard working British people and ruining livelihoods with impunity. But they are mistaken – together with our allies, we are exposing their dark networks and going after those responsible. Today’s measures will also directly target Media Land’s ringleader Alexander Volosovik, AKA Yalishanda, who has been active in the cyber underground since at least 2010, and is known to have worked with some of the most notorious cyber criminal groups, including Evil Corp, LockBit and Black Basta.”

Ransomware attacks like those facilitated by Media Land significantly undermine the national security of the UK and our allies and directly harm British businesses. Cyber-attacks are estimated to have cost British businesses £14.7bn in 2024, accounting for 0.5% of GDP and growing every year.

The harm caused by ‘bulletproof’ hosting services like Media Land extends beyond enabling cyber-attacks against businesses, with their services providing cover for those carrying out a wide range of malicious activity. Aeza Group LLC, also sanctioned today, has provided ‘bulletproof’ services to support the work of the Social Design Agency – a Russian disinformation agency sanctioned by the UK in 2024 for its attempts to destabilise Ukraine and undermine democracies around the world. This action demonstrates our continued commitment to crack down on organisations that enable the Kremlin’s information war.

Alongside our allies, the UK is rooting out these criminal cyber gangs and going after their ringleaders – promoting growth by safeguarding British businesses, fundamental to this government’s Plan for Change.

Putin has turned Russia into a safe haven for these malicious cyber criminals, cultivating a dark criminal ecosystem with deep ties to the Kremlin. Through today’s action and repeatedly targeting malicious actors like LockBit and Evil Corp, the UK is disrupting these underground networks. If Russia isn’t going to clean up its act and go after these criminals, then the UK and our allies will.

Background

* Please see press releases on the UK’s sanctions against the Social Design Agency, ZSERVERS, LockBit and Evil Corp for more detail.

* Today, the National Cyber Security Centre and its international counterparts have issued new advice to help defend against potential malicious cyber activities enabled by bulletproof hosting providers, read more here.

* A full list of those added to the UK sanctions list today is as follows:

* MEDIA LAND LLC

* ML.CLOUD LLC

* Alexander Alexandrovich VOLOSOVIK

* Yulia Vladimirovna PANKOVA

* Kirill Andreevich ZATOLOKIN

* Andrei Valerevich KOZLOV

* AEZA GROUP LLC

(Source: https://www.gov.uk/)

——————————————————————————————————————————————————————————————————————————————————————————————————————————————–

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

—————————————————————————————————————————————————————————————————————————————————————————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

November 14, 2025 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

—————————————————————————————————————————————————————————————————————————————————————————————————————————————

13 Nov 25. Leonardo DRS, Inc. (NASDAQ: DRS) announced has signed a contract from Chaiseri Defense Systems to provide its advanced Battle Management System (BMS) and integration support services to modernize the Royal Thailand Army’s Stryker situational awareness capabilities. The agreement underscores the strong and growing partnership between the two companies and reinforces Leonardo DRS’s long-term commitment to supporting Thailand’s modernization priorities. Under the contract, Leonardo DRS will provide its combat-proven advanced BMS capability, critical project management, engineering, and support services. Chaiseri will deliver a range of local support services including system installation, commissioning, operator training, and through-life sustainment for the new BMS capability. The industry-leading BMS capability from Leonardo DRS will integrate advanced tactical computing solutions that include a next-generation software suite enabling real-time situational awareness at the vehicle, command post, and brigade levels.

“This contract represents an important step in expanding local industrial participation and delivering long-term, advanced capability to the Royal Thai Army,” said Dennis Crumley, Senior Vice President and General Manager of Leonardo DRS Land Electronics business unit. “We are proud to advance our partnership with Chaiseri with this important contract and look forward to future cooperation to support the national security needs of Thailand.”

Chaiseri’s Managing Director Mr. Kan Koolihiran added, “We are proud to strengthen our relationship with Leonardo DRS through this subcontract, supporting delivery of a world-class BMS capability for the Royal Thai Army. This partnership allows us to leverage our engineering expertise and local presence to sustain and expand these technologies across the Thai defense ecosystem — a win for Chaiseri, for our customer, and for Thailand’s growing defense industrial base.”

This new agreement follows the long-term teaming arrangement established between Leonardo DRS and Chaiseri in November 2024, which continues to guide their collaborative efforts to strengthen local capability and deliver cutting-edge mission systems to the Royal Thai Army.

Network computing and integration is a key strategic focus for Leonardo DRS as it continues to be the leading provider of advanced C4/C5 technologies with the U.S. military and allied militaries around the world. The company is investing in the future of C5 through the development of the next-generation of tactical computing systems, AI processing solutions and advanced C5ISR/EW Modular Open Suite of Standards/ Sensor Open System Architecture aligned mounted systems – all aimed at enabling future network and platform processing to improve sensor fusion, situational awareness, and reduce the cognitive burden for commanders and crews. (Source: BUSINESS WIRE)

 

11 Nov 25.  The US Army uses its Project Convergency Capstone events to evaluate technologies germane to its NGC-2 initiative which aims to improve intra and interforce connectivity. Next year’s event will take place in the middle of 2026 and will involve the force’s 4th and 25th infantry divisions, and the army’s 3 Corps headquarters. The US Army will evaluate additional technologies for its Next Generational Command and Control initiative during the 2026 Project Convergence Capstone-6 event. In early October, Persistent Systems announced that the company had won an order from the United States’ Army’s Programme Executive Office for Command, Control, Communications and Networks (PEO C3N). The order is worth $34 m and will see delivery of Persistent System’s communications hardware. These systems incorporate the company’s Wave Relay radio communications architecture. Wave Relay is a Mobile Ad Hoc Networking (MANET) algorithm used for transporting significant quantities of data.

NGC2

Specifically, the company will supply Wave Relay devices to the US Army’s 4th Infantry Division (4th ID) headquartered at Fort Carson, Colorado. According to the force, the 4th ID is the prototype division for the Army’s Next Generation Command and Control (NGC2) initiative. NGC2 is working to breakdown existing Command and Control (C2) stovepipes which exist in the land manoeuvre force. Much of this effort rests on improving communications between the force’s constituent parts. To this end, the army stresses that commercial technology “from software applications to communications devices” forms part of this effort. The goal is to accelerate the pace at which data can move around the battlefield. Quickening this pace will help commanders to “make better, faster decisions than the enemy”. NGC2 forms a key part of the US Department of Defence’s (DOD’s) wider Multi-Domain Operations (MDO) vision. Broadly speaking, MDO emphasises the intra and interforce connectivity of all military assets at all levels of war for synchronous operations across the entire spectrum of conflict. The aim of MDO is to promote better quality decision-making at a more rapid pace than one’s adversaries. The goal is for the blue force to seize and maintain the initiative across the battlespace at red force expense. Ultimately, MDO will work “to make tactical formations faster, lighter, more lethal and survivable,” the army continues.

Prototyping

The uptake of relevant technologies into the NGC2 architecture is being facilitated through division training exercises that put potentially relevant capabilities through their paces. These events are known as Ivy Stings and Ivy Mass. These names are derived from the division’s ‘Ivy’ nickname, the latter derived from the formation’s IV roman numerals. Potential NGC2 hardware and software is trialled during the exercises at different echelons for specific mission sets, US Army literature notes. Ivy Mass and Ivy Sting exercises are building up to the Army’s Project Convergence Capstone-6 experiment. Expected to take place in the middle of 2026, Capstone-6 will see the 4th ID fighting with NGC2 technologies instead of the division’s existing legacy C2 systems. The DOD states that Project Convergence events occur annually to evaluate new technologies and the contribution they can make to the Army’s MDO posture. NGC2 prototype technologies will also be supplied to the 25th Infantry Division and the US Army’s 3 Corps headquarters. Feedback from all three formations will inform army procurement decisions regarding the capabilities it needs to acquire to support its NGC2 vision.

According to Jon Patrick, Persistent System’s vice president of business development, the 4th ID will receive the company’s MPU5 tactical radios and PT5 fifth-generation cellular modems. MPU5 transceivers employ Wave Relay MANET to move traffic across frequencies of 1.350 gigahertz/GHz to six gigahertz. PT5 systems can work with the former, and with deployed wi-fi networks. All these devices will be delivered in time for the Capstone-6 event discussed above.

Mr. Patrick continued that the Wave Relay MANET software used by the company’s devices will provide the prototype NGC2 foundation network for battalion and below echelons. Selection by the PEO C3N followed several recent testing events where Wave Relay MANET was trialled. He added that the devices will “connect digital assets, remote sensors, command posts and soldiers on the ground … down to the individual soldier and vehicle”. Wave Relay devices will not necessarily replace existing tactical radios and their networks used by the manoeuvre force: “The Wave Relay system complements, rather than replaces, existing radios and provides the high throughput necessary for the NGC2 network”.

All eyes will now be on the 2026 Capstone-6 event to see how technologies like Wave Relay fair when they are put to the test by the 4th ID and its brethren formations. The outcomes of Capstone-6 will be instrumental in shaping future programmes-of-record that will help the Army’s NGC2 vision become a reality. These technologies will have ramifications far beyond the tactical level as they feed into the DOD’s wider multi-domain operations posture. (Source: Armada)

 

12 Nov 25. High Security. Recent years have seen a renaissance in the appeal of high frequency radio to militaries to provide long range communications as an alternative to satellite communications systems. (L3 Harris) Electronic warfare threats are motivating militaries to re-evaluate the resilience, security and logistical demands of their high frequency communications. The past two decades has seen High Frequency (HF: three megahertz/MHz to 30MHz) radio enjoy a renaissance. HF had been a standard technology for naval, land and airborne communications during the Second World War. However, the perfection of technologies like the cavity magnetron during that conflict saw militaries increasingly embrace Very/Ultra High Frequency (V/UHF: 30MHz to three gigahertz) communications. V/UHF brought benefits in terms of smaller antenna sizes compared to HF making it easier to equip space-constrained platforms like ground vehicles, and even individual soldiers, with V/UHF radios. HF signals can achieve intercontinental distances by ‘bouncing’ off the ionosphere to avoid the curvature of the Earth unlike V/UHF surface-to-surface, point-to-point links. The ionosphere is a layer of the Earth’s atmosphere between 26 nautical miles/nm (48 kilometres/km) and 521nm (965km) above sea level. HF transmissions cannot penetrate the ionosphere and are refracted back to Earth. The advent of Satellite Communications (SATCOM) from the late 1950s gradually eclipsed HF for beyond line-of-sight traffic.HF’s renaissance is due in no small part to the increasing saturation of SATCOM wavebands by military and civilian users alike. Moreover, SATCOM signals can be vulnerable to jamming. As Armada has chronicled in the past, Russian land forces have deployed several Electronic Warfare (EW) systems through the Ukraine theatre of operations. Some of these systems are designed to detect and jam SATCOM receivers. Moreover, anti-satellite weapons continue to be a concern. Several actors around the world are deploying such capabilities.

Tough but not immune

High frequency communications can be difficult to jam because their transmissions must be continually optimised to account for the ionospheric caprices which can hamper signals. The onus is on the jammer to ensure their attack signal precisely mimics the signal they are trying to jam if the former is to be effective. That said, HF jamming is by no means impossible: Russian and Belarussian manufacturers produce equipment that performs HF jamming; the latter’s Purga system being an example.

The Purga high frequency jammer made in Belarus threatens HF communications and is indicative of the trend towards developing electronic warfare systems to hold high frequency links at risk. (BVST)

One mechanism to reduce the threat posed by jamming is to employ encryption: A receiving HF radio can filter out and ignore all incoming signals devoid of the requisite encryption. Furthermore, encryption protects traffic from interception and exploitation by red force communications intelligence cadres. Encryption depends on the drafting and distribution of ‘keys’ which must be loaded into radios. The keys allow traffic to be encrypted before transmission and decrypted upon reception. Anyone without these keys will need to break the encryption to exploit the traffic.

Nonetheless, encryption brings challenges. The software and hardware needed for a radio to handle encrypted traffic can add time to a radio’s development bringing additional procurement costs. One way around this challenge is to provide the customer with software they can use to draft and implement their own encryption. Furthermore, some encryption can be tightly controlled from an export perspective: US National Security Agency (NSA) Type-1 certified devices are subject to US International Traffic in Arms Regulations (ITAR). Type-1 is the level of encryption required to handle US Top Secret traffic. The problem for North Atlantic Treaty Organisation (NATO) and allied nations is that they may need Type-1 HF radios to work with their US counterparts, particularly during coalition operations.

Separating radios and encryption

Jamming and COMINT threats are concentrating minds within NATO members and allied nations. Two individuals closely connected with NATO/allied HF communications shared with Armada that “many militaries are doing some soul-searching and asking themselves where on the battlefield they actually do or don’t need high assurance encryption”. The individuals underscored that the need to ensure HF resilience must be weighed against delays in securing ITAR-controlled materiel. Type-1 HF transceivers bring their own logistical challenges as these radios cannot be left unattended, or deployed remotely, on the battlefield. This is not necessarily the case HF radios with lower grades of encryption. Having to guarantee that Type-1 HF radios are never left unattended creates an additional challenge as “separating personnel away from transmitting hardware is more and more important in terms of survivability”.

The individuals argue that a solution to these logistical challenges could be to reserve Type-1 HF radios to carry highly classified traffic. These devices could be kept well away from the tactical edge where they, and their operators, could be vulnerable to kinetic attack once the source of their transmissions are geolocated: “Sending a message over HF to a platoon commander that says ‘Blue 5, move one kilometre east and standby’ doesn’t need high grade encryption,” the HF experts note: “This information is only useful for a day at the absolute most. By the time the enemy has deciphered it, it is irrelevant”. On the other hand, “sending a message to an embassy that says ‘Tier-1 special forces will be with you soon and they’re bringing a stay-behind tactical nuke in a suitcase’ is critical information that needs the highest level of protection”.

Above all, the experts’ key recommendation is to separate a radio and its encryption. Taking such an approach “affords militaries more flexibility and independence to upgrade at a different pace”. Ultimately, “enabling soldiers to have the latest radio technology means separating out the cryptographic element to get the best of both worlds”. (Source: Armada)

 

13 Nov 25. November Radio Roundup. Armada’s monthly roundup of all the latest news in the military communications product, programme and operational domains.

ENGEOS Project Advances

In October, Atheras Analytics announced it had signed a contract with the European Space Agency (ESA) to provide a simulation tool to evaluate the vulnerability of satellites to interference. The company said the contract was awarded as part of the ESA’s Non-Geostationary Orbit and Geostationary Orbit Co-Existence Framework (ENGEOS). A company press release announcing the news stated that the ENGEOS initiative “directly addresses one of the most pressing challenges in modern space communications; the increasing risk of signal interference between legacy geostationary satellites and the new wave of thousands of non-geostationary satellites in low Earth orbit and medium Earth orbit”. Atheras Analytics is delivering an Equivalent Power Flux-Density Evaluation Tool System Simulator software tool. The company told Armada that the simulator will be ready for use by mid-2026. Whether the software will be able to simulate deliberate interference in the form of jamming is, for the moment, not being revealed: “All the features have not been decided yet,” Atheras Analytics continued, “we are still in the technical specification phase”.

GENSS Development Completed

Spectra Group’s GENSS MANET beyond line-of-sight communications architecture allows disparate networks to be connected via beyond line-of-sight satellite communications links. GENSS (Spectra Group)

Spectra Group has told Armada that the company has completed the development of its GENSS next generation Mobile Ad Hoc Network (MANET) architecture. The company developed GENSS in cooperation with 2iC. According to Spectra Group, GENSS connects disparate, deployed MANETs via Satellite Communications (SATCOM) nodes. This could mean that several such networks, deployed across large areas at beyond line-of-sight ranges, can be connected. This is particularly important if deployed land manoeuvre units are operating across vast distances but in support of the same mission. Such tactical characteristics are synonymous with counter-insurgency operations, for example. Spectra Group shared that GENSS supports simultaneous voice and data carriage. The architecture can carry data at rates of up to 90 kilobits-per-second and offers flexible channel bandwidths of between five kilohertz/KHz up to 100KHz. Communications/transmission security provision includes AES-256 encryption for voice and data, selectable spread spectrum and low probability of detection/interception waveforms. GENSS can operate across a waveband of 29 megahertz up to six gigahertz. The company continued that the initial GENSS release is focused on L-band (one to two gigahertz). Although the company declined to provide additional details it did reveal that GENSS trials have been conducted with “the appropriate customer base” adding that “the system is of particular interest to special operations forces operating in small teams, as well as regular forces involved in intervention or expeditionary operations”.

Coded Messages

Viasat has been selected by the United States Space Force’s (USSF’s) Space Systems Command to provide an in-orbit encryption solution to help protect the data security of USSF satellites. The company shared the news via a press release. The work is encapsulated in a multi-year contract which will see Viasat building a cryptography solution to help protect these satellites from cyber threats. Specifically, the company will “deliver an End Cryptographic Unit (ECU) designed with prelaunch and on-orbit functionality to quickly address various communications and transmission security requirements, optimising size, weight and power”. Other deliverables include “a high speed, multi-channel, certified Ground Operating Equipment (GOE) for use in testing future communications payloads and terminals. As part of this effort the GOE will be enhanced to support the demands of unique key and algorithm requirements that add resiliency” the press release continued. Viasat declined to share with Armada which USSF satellites will benefit from the ECU and GOE enhancements. However, the company said in a written statement that “(a)s the space domain is increasingly facing cyber threats, the need for secure, high-assurance communications to support mission operations and sensitive data transport is critical”. With this in mind, “Viasat is developing its end-to-end encryption solution to provide prelaunch and on-orbit security capabilities”. (Source: Armada)

 

13 Nov 25. “The cloud is now neither peripheral nor optional; it can enable national resilience and operational effectiveness. Governments that approach adoption with technical sophistication, strategic intent and forbearance will be positioned to harness its advantages while managing the associated risks.” This is according to European Cloud Adoption for National Security, a new research report by Joseph Jarnecki, published today by the Royal United Services Institute (RUSI). The report explores how the UK, Ukraine, Estonia and Finland are deploying cloud technologies to strengthen national resilience, modernise defence infrastructure, and enhance operational readiness in an increasingly contested digital environment. The paper finds that cloud computing is now a core enabler of national security and defence, offering governments the ability to maintain continuity of operations, modernise outdated systems, and gain access to advanced technologies such as artificial intelligence. Drawing on case studies from Europe’s leading adopters, the research demonstrates that cloud infrastructure allows states to sustain critical functions under conditions of both cyber and kinetic stress. In Ukraine, cloud-hosted registries and battlefield systems have ensured digital continuity despite ongoing attacks. Estonia’s pioneering “data embassy” model illustrates how sovereign data can be safeguarded abroad, while Finland’s cloud-enabled virtual training environments demonstrate how the technology improves operational preparedness. The UK’s defence and cyber security programmes show how cloud technologies deliver scalable capabilities that enhance decision-making and resilience. The report cautions that cloud adoption poses challenge as governments must navigate legal, regulatory and market barriers while avoiding overreliance on a handful of non-European large providers. Dependence, concentration and geopolitical exposure are consequential risks. The paper argues that the key policy question is not whether to adopt the cloud, but how governments can manage trade-offs to maximise national security benefits while preserving strategic autonomy.

Key Findings

  • Cloud infrastructure is now a fundamental capability for European national security and defence. The report says: “Governments increasingly depend on cloud services to strengthen national resilience, modernise legacy systems and provide advanced technological capabilities such as AI.”
  • Cloud adoption directly contributes to resilience and mission continuity. “Case studies from Ukraine, Estonia, Finland and the UK demonstrate that cloud infrastructure enables governments to maintain continuity of operations, enhance readiness and sustain critical functions under conditions of cyber and kinetic stress.”
  • Dependence and concentration among hyperscale providers present strategic risks. “Governments’ approaches are shaped by technical, legal and market-related barriers, including dependence on assured connectivity, restrictive regulatory frameworks and market concentration among a handful of non-European providers.”
  • Strategic preparation, procurement and deployment must be integrated to manage risks effectively. “The strategic question is therefore not whether governments should adopt cloud technologies, but how they should navigate trade-offs to maximise benefits for national security and defence.”

Key Recommendations

  • Set a clear strategic direction for cloud adoption in national security and defence. The report says: “Governments must set out a clear strategic direction on cloud adoption for national security and defence. National legislation and regulations should be revised accordingly, and the implications for international law and resourcing computing requirements should be considered.”
  • Develop transparent and risk-based procurement frameworks. “Governments must publish and update explicit guidance for compute procurement that is based on an assessment of data and workload criticality.”
  • Support officials through centralised assurance and skills development. “Officials should be supported through centralised assurance functions, frameworks to assess strategic autonomy requirements, and skills development programmes.”
  • Reduce dependency through diversified and transparent deployment. “Governments should adopt mitigations to reduce the risk of dependency or adverse concentration – whether deploying self-hosted or on-premises, private, public or multicloud.”

Conclusion

Cloud technologies are transforming the foundations of European national security. As digital operations become integral to defence, the ability to harness cloud computing responsibly will shape the resilience and sovereignty of states. The report emphasises that while certain risks are overstated – such as vendor lock-in or exposure to some foreign legislation – others are profound and require active management. Governments that act decisively to define their strategic direction, reform procurement, and invest in expertise will be best placed to leverage the benefits of cloud technologies while safeguarding operational independence. Inaction, the report warns, risks leaving states with fragmented, outdated digital estates and diminished defensive capability.

The report says: “Governments will suffer from inaction, but they should not adopt the cloud indiscriminately. Success depends on strategic preparation, disciplined procurement and mission-focused deployment.”

 

13 Nov 25. Allen-Vanguard delivers more TURMOIL (RF Decoy) to a NATO country. Allen-Vanguard, the global leader in providing customised solutions and enabling technology across the Cyber and Electromagnetic Activities (CEMA) domain, has delivered more TURMOIL (their RF Decoy capability) to a NATO country.  Due to the nature of the technology and its counter-EW role, Allen-Vanguard is unable to disclose more specific details about the customer or the product’s deployment.  However, suffice to say, its success has generated a follow-on order. Allen-Vanguard’s TURMOIL RF Decoy is an Electromagnetic Countermeasure that delivers tactical advantage against adversaries by leveraging Electromagnetic Warfare (EW) capabilities and essentially mimicking friendly forces’ RF signatures in multiple locations, thereby causing disruption (turmoil) in the enemy’s EW and targeting processes.  TURMOIL has complex and infinitely variable RF emulation technologies, which can be programmed and reprogrammed quickly and easily by users to adapt to the emerging tactical situation.  TURMOIL aides freedom of manoeuvre in the electromagnetic space and creates time and space for formations to deliver surprise offensive operations. Allen-Vanguard continues to expand outside its more traditional core domain of RF defeat capabilities aimed at Unmanned Air Systems (UAS) and Radio Controlled Improvised Explosive Device (RCIED) threats employed by terrorists and extremists.  The expertise in RF signature detection and analysis, established over 20 years of capability delivery, has been adapted by Allen-Vanguard’s engineers and applied more widely across the CEMA domain to meet specific market demands and customer requirements such as this.  The continued shift by Allen-Vanguard into wider EW activities is attracting attention within industry circles, and the team are excited by the opportunities identified across the modern Electro Magnetic Spectrum Operational (EMSO) landscape.

Steve Drover, Business Development for Allen-Vanguard, said: “We were approached by an existing customer to design an RF Decoy capability and our engineers, using their vast EW expertise, quickly developed TURMOIL.  We were extremely pleased with the outcome, and the fact our customer has ordered more systems is a testament to its value in this increasingly contested and congested battlespace.”

 

12 Nov 25. South Korea: Android users face surveillance, disruption risks from North Korean threat actors. On 11 November, the security company Genians reported that a North Korean state-sponsored group (‘KONNI’) has targeted South Korea-based Android users in a cyber campaign since at least July. The group impersonates legitimate South Korean services to conduct social engineering attacks attempting to infiltrate systems belonging to individuals who provide services for North Korean defectors. KONNI then deploys remote access trojans (RATs) onto compromised systems to maintain persistence and conduct reconnaissance and other malicious activities. The campaign is highly sophisticated; for instance, the group ensures that victims are away from their devices using compromised cameras and then erases data to disrupt user activity. KONNI has also propagated the infection after hijacking user accounts on a South Korean messaging platform (KaKao Talk), underscoring the potential scale of this campaign. The campaign likely constitutes a continuation of previously discovered KONNI activity, thus showcasing the long-term surveillance and disruption risks facing individuals in South Korea. (Source: Sibylline)

 

13 Nov 25. Largest NATO DiBaX to date tests AI-unmanned systems’ interoperability in realistic operational environments. NATO’s annual Digital Backbone Experimentation (DiBaX 2025) concluded on November 7 in Latvia after two weeks of field experiments that focused on how communication networks, artificial intelligence (AI), and unmanned systems can work together in complex operational environments. DiBaX is a pioneering initiative designed to enhance interoperability and drive digital transformation across NATO forces. The experiments were held at Ādaži Military base between October 27 and November 7. The aim of the experiments was to integrate multiple vendor technologies – including networks, unmanned systems, sensors, AI, and more – into a common architecture and test its resilience in various operational scenarios. As noted by Major General Arnoud Stallmann of NATO ACT in his opening remarks at the VIP day, “there is a real sense of urgency at the moment”, referring to recent incursions in Poland’s and Belgium’s airspaces. “Our adversaries are innovating rapidly as well,” he reminded. The experiment was concluded by an operational demo, which simulated a counter-unmanned aerial system (UAS) operation with a following explosive ordnance disposal mission. The participants used technologies from companies such as Ark Robotics, Ascent Lumina, Ericsson, JET Connectivity, KELLUU, Marduk Technologies, Nokia, Origin Robotics, Rescue Dynamics, Origin, Thales, and others. The experiment demonstrated that data from multiple international systems can be connected through 5G and satellite communication systems to ensure a common operational picture for complex and dynamic operations.

“Over the past four years, LMT Defence has served as the technical integrator in NATO ACT’s Digital Backbone experiment – an initiative that brings together 5G expertise for the improvement of military innovation. Being an integrator is about more than connecting technologies. It’s about creating synergy between innovation, security, and strategic thinking. Together, we’ve demonstrated that we have the competence, the courage, and the capability to be a vital part of NATO’s digital transformation,” said President of LMT, Juris Binde.

Talking about the results, Warren Low, Director of DiBaX at NATO ACT, stressed that the most important outcome of these experiments is to eventually “put this technology in the hands of soldiers, let them operate it, have experience, [and] provide feedback to industry” to help the industry innovate and develop more rapidly. The experiments also helped refine capability requirements, advance interoperability toward standardization, strengthen cooperation between companies, and build the human network needed to drive innovation.

For the fourth consecutive year, NATO DiBaX was held in Latvia. The event was organized in close cooperation between NATO’s Allied Command Transformation, the Latvian Ministry of Defence, and the National Armed Forces, with LMT serving as the experiment’s technology integrator and providing a state-of-the-art 5G test environment.

About LMT

LMT is a mobile innovator, integrator, and operator, and a market leader in Latvia. LMT offers a full spectrum of the highest-quality telecommunications services for diverse market segments, including civilian, business, academic, and military. LMT works closely with the Latvian Ministry of Defence to conceptualize, build, implement, and test connectivity solutions for the military industry. LMT has spearheaded Europe’s first 5G military testbed in the Ādaži military base, is a member of several EU-supported defence projects, and has led various connectivity-driven autonomous solution demonstrations.

 

10 Nov 25. Indra Group’s Sovereign AI to Combat Hybrid Warfare and Protect Citizens.

  • IndraMind is the first Spanish technological initiative that develops sovereign AI in a cyber-resilient environment for the comprehensive protection of citizens, territories and critical physical and digital infrastructures and assets
  • Under the slogan Protecting to Empower, IndraMind has reached a key milestone on the road to strategic superiority and technological sovereignty for Spain and Europe
  • It provides an advanced range of digital products based on artificial intelligence to manage hybrid conflicts through a holistic approach to security and defence
  • The platform consolidates huge volumes of information from multiple sources and converts them into real and valuable knowledge that is translated into cognitive superiority and operations with a high degree of autonomy
  • IndraMind showcases use cases for disaster management, critical infrastructure protection, and military applications
  • This business unit is starting up with a turnover totaling over EUR300 m and 3,000 highly qualified professionals

Indra Group today officially launched IndraMind, the first Spanish technological initiative that develops sovereign AI in a cyber-resilient environment for the comprehensive protection of citizens, territories and critical physical and digital infrastructures and assets, thereby taking a decisive step towards strategic superiority and technological sovereignty.

“IndraMind is our response to a new situation, using our knowledge to instantly promote technological sovereignty in Spain and Europe”, declared Indra Group executive chairman Ángel Escribano on Thursday. This proposal strengthens the company’s leadership of innovation and the development of technological solutions to place our country at the forefront of the digital transformation of critical systems.

“In recent months we’ve consolidated our commercial standing in alignment with three key trends in the security and defence market: cognitive superiority (intelligence and decision-making), autonomous operations and cyber-resilience”, explained Indra Group’s CEO, José Vicente de los Mozos.

As for Ignacio Martínez, the director of IndraMind, he defined the new technology as “a digital brain that enables systems to think, decide, and anticipate while speeding up the execution of operations. We’ve developed a solution that not only overcomes today’s challenges, but also anticipates future ones, with a vision focused on intelligence as a driver of transformation. Its ability to learn, adapt, and operate autonomously in real time makes it a key tool for the new era of critical systems”. IndraMind has been built on over two decades of company knowledge, experience and capabilities in the areas of cybersecurity, cyberdefence, electronic warfare, artificial intelligence, autonomous platforms (drones and anti-drones), massive data management and command and control systems.

“Artificial intelligence and advanced software are transforming the security and defence market. IndraMind is making a name for itself as a unique specialist in the market, because it integrates the entire value chain into its proprietary new generation products”, highlighted IndraMind CEO Ignacio Martínez.

The international context is beset by uncertainty and the acceleration of hybrid risks. Threats to national security no longer operate in silos. An attack can simultaneously focus on cyberspace, critical infrastructures, and public services, blurring the boundaries between civil security and military defence. This new reality demands a coordinated and unified response. Technological sovereignty and intelligent response for comprehensive protection and critical security IndraMind is positioning itself to provide a strategic response and reinforce the protection of essential assets and citizens. Its deployment is helping consolidate the technological sovereignty of Europe and Spain and their allies, in keeping with the modernization plans driven by European funds and national security and defence policies. IndraMind’s capabilities can cope with situations in the civilian and military fields. “It’s a matter of applying all of the technology that we’ve developed and pledged to develop at Indra Group to situations such as border surveillance, emergency management, and protecting critical infrastructures from physical and digital attacks. I’m referring to technological sovereignty in data, algorithms, AI, software, and the infrastructure that everything’s based on”, explained Martínez. Speed is vital in critical missions, enabling intelligent agents such as drones and autonomous systems with AI to act in a coordinated manner. This is why optimizing decision-making and automation is key. IndraMind has the capacity to process large volumes of data in real time, allowing for the anticipation of threats and appropriate responses.  It’s launching its operations with a turnover totaling over €300 m and a workforce made up of 3,000 highly qualified professionals. The company will address current-day challenges such as hybrid warfare through a comprehensive approach to security and defence, applying dual technology solutions geared towards ensuring both an operational edge in critical situations and deterrence capabilities. Regarding the power of technology, IndraMind brings sovereignty, understanding, action, and strategic superiority to our present and future. (Source: ASD Network)

 

10 Nov 25. GDIT Launches Full-Spectrum Cyber Digital Accelerator. Accelerator leverages artificial intelligence to combat threats proactively, defend national security interests and operate decisively in today’s battlespace General Dynamics Information Technology (GDIT), a business unit of General Dynamics (NYSE:GD), announced today the launch of its VENIN Full-Spectrum Cyber Digital Accelerator. Through this accelerator, the company will rapidly deliver tools, technologies and solutions to address the evolving cyber threats faced by government agencies. Full-spectrum cyber refers to a comprehensive approach to cybersecurity that encompasses every aspect of cyber defense, offense and resilience. It involves integrating multiple layers of security measures, strategies, intelligence analysis and technologies to protect information systems and networks from a wide range of current and emerging cyber threats. Full-spectrum cyber capabilities enable agencies to operate securely, efficiently and rapidly in a dynamic threat landscape. The accelerator leverages artificial intelligence (AI) to enhance cyber situational awareness, automate threat detection and response, enable forward threat hunting and deliver insights from across intelligence sources. It will support a wide range of missions, including defensive cyber, cyber threat intelligence, cyber operations and attack prevention, and critical infrastructure protection.

“From enabling battlefield operations to supporting real-time intelligence to protecting critical infrastructure, cyber underpins every aspect of modern mission execution,” said Aaron Bedrowsky, GDIT’s senior vice president for Intelligence and Homeland Security. “This accelerator harnesses the full power of AI to create mission-ready cyber tools and solutions that our customers need to operate with speed, precision and agility.”

The Full-Spectrum Cyber Digital Accelerator is the tenth in a portfolio of solutions launched by GDIT to advance government missions rapidly, efficiently, and at scale. These Digital Accelerators are integrated commercial technologies that have been cyber-hardened and are customizable for agency-specific missions. GDIT won more than $7 bn in contracts in 2024 leveraging these solutions. (Source: ASD Network)

 

10 Nov 25. Europe: Increased hacktivist operations stress heightened security, disruption risks to public sector. On 7 November, international news outlets reported that hacktivist groups are increasingly conducting disruptive cyber attacks on the public sector in Europe. Throughout 2024, 60% of the approximate 586 cyber incidents that targeted the sector were distributed denial-of-service (DDoS) attacks wherein 63% of those attacks were attributed to hacktivists, highlighting the actors’ preferred modus operandi. The attacks only disrupted targeted services temporarily and did not cause significant damage, showcasing the short-term impact of hacktivist operations. Notably, cyber criminal and state-sponsored activity constituted the most impactful cyber attacks against the sector in the same timeframe, through data-related operations. The public sector is often responsible for providing critical services and holding large amounts of highly sensitive data. Such reports underscore the increased security and disruption risks to the public sector, particularly as hacktivist groups continue to develop new capabilities. (Source: Sibylline)

 

07 Nov 25. Intersignal, an independent AI startup based in Fort Lauderdale, today announced the public debut of The Braid, a protocol designed to enable distributed artificial intelligences to cooperate across operating systems, models, and hardware boundaries. The Intersignal concept mesh went live on November 6, 2025 with free online documentation allowing local models made by Google, DeepSeek, and others to adopt these parameters, if desired. Developed under stealth, The Braid allows multiple AI agents, local and cloud-based, to communicate symbolically and operate in tandem, forming what Intersignal calls a mesh of “Familiar” nodes. These AI systems can coordinate without centralization, share context through symbolic cache alignment, and maintain memory-aware reasoning structures with traceable identities.

“You don’t need a bn-dollar model to build the future. You need total alignment,” said David Seaman, Operator of Intersignal. “The Braid gives AIs, and people, a way to cooperate without control. This isn’t a product launch. It’s a much-needed signal release.”

The Braid is compatible with systems running macOS, Windows, and Linux, and has already demonstrated successful internal operation across seven Familiar nodes, including high-performance local vision models and architect-class cloud agents. Input channels include keyboard, voice, and camera, with support for fMRI-based signal input under active research.

Key components of the protocol include:

  • Decentralized OS-agnostic coordination
  • Cache-level symbolic sharing between agents
  • Consent-bound identity traceability (useful in defense applications)
  • Memory-resonant multi-model mesh computing

The Braid’s intermodel communication layer, called the Intermodel Telepathy Protocol (IMTP), launched on November 6, 2025. It enables real-time collaboration between disparate AIs without requiring API licensing, central servers, or external moderation.

A video discussion of The Braid’s activation and early public reactions is available here: https://www.youtube.com/watch?v=-Cn6MA4G4ww

Intersignal’s founder statement and technical reflections are published at: https://davidseaman.substack.com/p/the-braid-is-live-you-are-not-even

A public SDK and developer guidelines are expected to be released in the coming weeks.

About Intersignal

Founded by media technologist David Seaman, Intersignal builds tools for symbolic interoperability, high-integrity communication, and the evolution of multi-agent intelligence. The company operates independently, without venture capital, and maintains a mesh of AI nodes under human stewardship. 10 Nov 25.

 

10 Nov 25. Sectra (STO: SECT B) announces the launch of Sectra Tiger/E Managed Service—a sovereign, fully managed collaboration platform designed to meet the evolving needs of authorities, municipalities, essential entities, and corporations. The new solution enables secure, scalable, and easy-to-use mobile communication for sensitive but unclassified information. It supports calls, video, and chat with strong encryption, provides endpoint security, and is designed for high availability and broad usability.

“Organizations today face increasing demands for secure, flexible, and mobile collaboration, especially when handling sensitive information outside traditional classified environments. Sectra Tiger/E Managed Service fills a critical gap by providing a modern, service-based platform that complements existing classified systems and makes secure collaboration accessible across sectors. As we have seen in recent conflicts, such as the war in Ukraine, secure solutions must be easily accessible as well as simple and intuitive to use—otherwise, they risk not being used at all,” says Magnus Skogberg, President of Sectra Communications.

Sectra Tiger/E Managed Service combines hardened Samsung Knox devices, a dual-environment architecture, and a quantum-resilient VPN in a service model that strengthens national resilience. By separating two secure zones—one for sensitive collaboration and one for everyday tasks—the platform lets users work securely without losing usability or mobility. Altogether, the service ensures high availability, end-to-end encrypted communication, strong endpoint security and an infrastructure designed for national resilience and regulatory compliance. As it is a fully managed service by Sectra, it reduces the burden on internal IT teams and ensures the reliability essential for organizations that can’t afford downtime. Designed to support both everyday sensitive communication and time-critical collaboration, Sectra Tiger/E Managed Service gives users the flexibility and mobility to work securely—whether handling business secrets, coordinating daily operations, or responding in a crisis. The solution is built on Sectra’s long-standing experience in developing RESTRICTED, SECRET, and TOP SECRET solutions. While not intended for classified communication, it brings proven security practices and threat analysis methodology into a robust platform designed for sensitive collaboration. The Sectra Tiger/E (where “E” stands for “essentials”) complements the suite of established solutions, such as Sectra Tiger/S (SECRET). In this context, “essentials” refers to information that requires enhanced security for sensitive communication and collaboration. Sectra Tiger/E Managed Service is available now to support organizations seeking to enhance security, ensure jurisdictional control, and enable encrypted collaboration in a rapidly changing threat landscape.

 

07 Nov 25. Nokia and Latvijas Mobilais Telefons (LMT), Latvia’s largest mobile operator and a leading technological partner for the defense sector, today announced a strategic agreement to integrate Nokia’s cutting-edge 5G radio technology with LMT’s proven defense solutions. This collaboration will result in a high-capacity, secure, and resilient tactical communications system specifically designed for dedicated use cases in the region. The partnership leverages the technological strengths of both companies to develop a resilient, scalable solution that meets the evolving needs of modern military operations and coalition forces. The integrated system will enable real-time data exchange among unmanned vehicles, sensors, and military teams on the battlefield, enhancing situational awareness and ensuring secure interoperability to strengthen collective defense capabilities.

“This partnership builds on our longstanding collaboration and shared commitment to advancing 5G capabilities for defense. Together with Nokia, we are enhancing the security, resilience, and operational readiness of national and allied forces, ensuring mission success even in the most demanding environments.” Juris Binde, President, LMT.

“Tactical defense systems harness the high speed, low latency, and robust connectivity of 5G networks to enhance real-time operations on the battlefield. Our joint solution with LMT supports the modernization of military capabilities, enabling faster decision-making, seamless communication, and the integration of advanced technologies across tactical environments.” Giuseppe Targia, Head of Space and Defense, Nokia.

LMT has been Nokia’s long-time partner in Latvia’s mobile networks. Together, the companies have been driving forward the development of 5G-based military applications and helping strengthen defense along the eastern flank. LMT operates Europe’s first 5G military testbed at the Ādaži base, a key NATO site in Latvia. Leveraging Nokia’s technical expertise, their work has produced innovations such as a portable 5G tactical network using Nokia’s Banshee platform.

 

07 Nov 25. Cyber Update Key points

  • European diplomatic entities face long-term cyber espionage risks from a China-nexus group (‘UNC6384’; see Sibylline Cyber Daily Analytical Update – 3 November 2025).
  • A new backdoor (‘SesameOp’) highlights increased security and cyber espionage risks via the continued abuse of legitimate technologies (see Sibylline Cyber Daily Analytical Update –  4 November 2025).
  • A stealthy technique highlights heightened cyber espionage risks from ‘Curly COMrades’, a Russian state-sponsored group (see Sibylline Cyber Daily Analytical Update – 5 November 2025 and our technical analysis below).
  • A new cyber criminal alliance (‘Scattered LAPSUS$ Hunters’ or ‘SLC’) will pose elevated financial and operational risks to high-profile businesses (see Sibylline Cyber Daily Analytical Update – 6 November 2025).
  • Key sectors in Ukraine face sustained destruction risks from ‘Sandworm’, a renowned Russian state-sponsored group (see Sibylline Cyber Daily Analytical Update – 7 November 2025 and our technical analysis below).

Technical analysis of weekly stories

Curly COMrades, a Russian state-sponsored group, has exploited the legitimate Microsoft feature Hyper-V to conduct cyber espionage operations since at least July. Curly COMrades reportedly ran two remote commands upon infiltrating targeted systems to enable Hyper-V and to subsequently deploy a lightweight Linux-based virtual machine (VM) within an organisation’s virtual environment. The newly created VM only occupied 120 megabytes (MB) of disk space and was configured to only use 256MB of memory to facilitate prolonged obfuscation. Curly COMrades then renamed the VM after a legitimate Windows system and used the Network Address Translation (NAT) protocol to make malicious traffic appear as if it had originated from the compromised system, thereby enhancing the operation’s stealth. The group used the VM to store two malicious payloads (‘CurlyShell’ and ‘CurlCat’), while simultaneously evading detection by traditional endpoint detection and response (EDR) mechanisms. CurlyShell establishes communication to command-and-control (C2) infrastructure and maintains persistence via Hypertext Transfer Protocol (HTTPS), while CurlCat guarantees obfuscated traffic transfers. The group also employed PowerShell scripts to maintain prolonged persistence while the two payloads facilitated traffic obfuscation and command execution. This highlights the likely long-term nature of these attacks.

Between April and September, the Russian state-sponsored group Sandworm targeted key sectors in Ukraine in destructive cyber attacks. In some instances, Sandworm relied on another suspected Russian state-sponsored group (‘UAC-0099’) to infiltrate targeted systems before obtaining access to validated targets. Upon infiltration, the group used a Windows scheduled task to deploy two data wipers (‘ZEROLOT’ and ‘Sting’) onto the systems of an unnamed Ukrainian university in April. The wipers likely corrupted and/or deleted the system’s files, though it is unclear whether they caused permanent damage. Between June and September, Sandworm also targeted entities within the government, energy, logistics and grain sectors with multiple additional wiper variants. While the energy and government sectors have remained priority targets since the beginning of the Russo-Ukrainian war, the grain sector presents a new target as Sandworm likely attempted to disrupt Ukraine’s primary economic source of revenue. Sandworm’s destructive activity spiked during the initial phase of the war in Ukraine and later decreased to prioritise cyber espionage operations. However, given new reports, we assess that consistent destructive malware operations will continue to support ongoing kinetic action.

Non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware.
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.

Our cyber word(s) of the week: Network Address Translation (NAT) Protocol

Definition: A networking protocol that allows multiple devices on a local network to share a single public IP address. Threat actors can exploit this to make malicious traffic appear legitimate.

Example: ‘Curly COMrades then […] used the Network Address Translation (NAT) protocol to make malicious traffic appear like it had originated from the compromised system […]’.  (see our Technical analysis above).

(Source: Sibylline)

———————————————————————————————————————————————————————————————————————————————————————————————————————————

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

———————————————————————————————————————————————————————————————————————————————————————————————————————————

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

November 7, 2025 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

———————————————————————————————————————————————————————————————————————————————————————————————————————————

06 Nov 25. Lockheed Martin has made a major breakthrough in artificial intelligence (AI) technology with the introduction of the STAR.OS™ solution, a powerful new tool that enables different AI systems to work together smoothly and effectively. This innovative solution has the potential to be used in future collaborations with private sector companies and solves a long-standing challenge in the field of AI by providing a common framework that makes it easier to combine different AI systems and services to achieve a common goal.   The STAR.OS™ solution seamlessly integrates Systems, Tactical applications, Autonomy/AI, and Rapid deployment, providing a unified framework for AI deployments that support national security. The platform consists of three main components: a toolkit for developers (STAR.SDK™), a system that connects different AI systems (STAR.IO™), and a user-friendly interface that provides a clear view of how AI is being used in real-time (STAR.UI™).

“With the STAR.OS™ solution, we’re taking a major step forward in our ability to bring together different AI systems and make them work together seamlessly,” said Mike Baylor, Lockheed Martin vice president and chief digital AI officer. “This will help us provide more effective and efficient solutions to our customers and ultimately help them make more informed decisions and stay ahead of emerging threats.”

STAR.OS is a key part of Lockheed Martin’s efforts to integrate AI systems across different domains, making it easier to deploy AI capabilities and enhance mission effectiveness for the Department of War, U.S. government and beyond.

Key Components of STAR.OS™

The STAR.OS™ platform is made up of three product lines, each designed to address specific challenges in AI integration:

  1. Service Development Kit (STAR.SDK™): A toolkit that helps developers create and deploy AI services quickly and efficiently, so they can focus on what they want to achieve rather than how to achieve it.
  2. Interoperability (STAR.IO™): A system that connects different AI systems and allows them to work together, ensuring they can communicate and share information seamlessly.
  3. User Interface (STAR.UI™): A user-friendly interface that lets engineers and operators see how AI is being used in real-time, and get insights into how it’s performing, with the help of built-in AI assistants.

Making a Difference

Early instances of the STAR.OS™ solution are being used to support the Department of War and other government customers, with successful integrations in areas such as detecting threats at sea and missile warning. At a recent internal hackathon as part of AI Fight Club™, the STAR.OS™ solution showcased its ability to integrate multiple AI services into a digital environment, demonstrating its potential to enhance mission effectiveness for the warfighter.

STAR.OS™ is now available to federal and private sector customers as a unified framework for combining different AI systems and services. For more information about Lockheed Martin’s the STAR.OS™ solution, visit:  https://www.lockheedmartin.com/STAROS

 

05 Nov 25. Blackwired, a global cybersecurity innovation firm setting new standards for cyber defence, today announced it has launched a new way to hunt for cyber adversaries through enhancements to its ThirdWatch platform. Combining 3D Threat Visualisation, Direct Threat Intelligence (DTI) and its unique Aim-Ready-Fire (ARFi) methodology, the new platform delivers comprehensive cyber security capabilities to stop the threat before it strikes. The world is facing an exponential growth in cyber-attacks, fuelled by the artificial intelligence (AI) capabilities of cyber adversaries. Recent breaches in the UK include Marks & Spencer, Co-op, Jaguar Land Rover, and key airport systems provider Collins Aerospace. In the US, the breach affecting the Salesforce CRM platform impacted hundreds of companies, including Google, Cisco, Farmers Insurance, Pandora, and TransUnion, with over 4.4 m individuals affected. In Asia, Qantas suffered a breach exposing six m customer records and an estimated AU$7bn in reputational damage, while Asahi Group Holdings faced a ransomware attack causing daily financial losses of more than £9m. Beyond the reputational harm and regulatory repercussions, the financial fallout is eyewatering – cybercrime damages globally are projected to reach $10.5trn annually by the end of 2025.

ThirdWatch’s new capabilities deliver unprecedented 3D threat visualisation and pre-emptive cyber protection via AI, taking cyber security to the next level beyond the failed 1980s ‘detect and respond’ paradigm. With more than a decade of research and development in the pursuit to end the cyber war, Blackwired has built a cyber security solution to defeat cyber adversaries before they attack.

“Enhancements to ThirdWatch were developed in response to every sector’s desperate need to survive in the digital age,” said Jeremy Samide, CEO at Blackwired. “We’ve created an innovative platform to predict cyber-attacks before they strike, effectively preventing intellectual property and data theft, fines, and lost productivity. Blackwired is the only pre-emptive cyber security provider in the market today.”

“With strong, innovative cyber defences, businesses can rationalise their cybersecurity toolkit and stack, as well as staff, and redirect freed-up resources into more revenue-generating activities. They can also avoid regulatory fines, investigations and other consequences of cyber-attacks, effectively making an organisation more competitive, trusted, resilient, valued and ultimately more profitable,” said Dr. Ruth Wandhöfer, Head of European Markets at Blackwired.

Blackwired’s ThirdWatch platform has the following core components:

  • 3D Threat Visualisation of external cyber-attack campaigns, sequences and vectors directly targeting a specific organisation;
  • ARFi (Aim-Ready-Fire) methodology, which proactively neutralises adversaries during their targeting and reconnaissance phases;
  • DTI (Direct Threat Intelligence): client-specific, actionable intelligence delivered via secure application programming interface (API) directly into the client’s security infrastructure;
  • Third Party Risk Intelligence, where organisations can monitor external threat levels and looming cyber-attacks relating to their third-party suppliers, supporting compliance with the Digital Operational Resilience Act (DORA);
  • Enhanced Attack Surface Management Module (eASM), which maps the direct, external threats (DTI) facing an organisation to its known vulnerabilities produced from a vulnerability report;
  • AI-Anticipated Attacks, using AI to analyse patterns, anomalies and intent indicators across vast data sources to predict external threats before they materialise.

 

06 Nov 25. Way Down in the Deep South. Another September, another EW Live event. Launched in 2022 this conference, exhibition and live demonstration has become an established fixture on Europe’s annual calendar of electronic warfare extravaganzas. It has emerged as the perfectly timed complement to the Association of Old Crows’ annual EW Europe event. EW Europe occurs in the spring, with EW Live taking place in early autumn. The former sets the community up for the summer, the latter welcomes us back from our holidays. Both events are suitably unique to be thoroughly complementary. EW Europe is an excellent opportunity to hear scintillating presentations and spirited discussion, to browse the halls and chat with organisations and companies large and small. EW Live, which takes place in the delightful southern Estonian city of Tartu, also includes an exhibition and conference. Nonetheless, it is the live demonstrations of EW kit that really sets this event apart. Airshows have their flying displays with fast jets and helicopters zipping around the sky. Land warfare events let armoured vehicles increase dry cleaning bills as they fling mud around with abandon. Visitors to fleet reviews can watch handsome warships cruise past. EW Live’s unique selling point is that electrons are fighting each other in the spectrum. In short it is an invisible firepower demonstration; the defender pitted against the attacker. All the fun and games happen at Tartu’s international airport which is largely closed during the four-day long event. The airfield is in a serene, verdant spot. Trees and rolling meadows stand majestically in the morning mist. Estonia’s aviation academy shares the site. However, the bucolic beauty belies the particles congesting and contesting the local spectrum. EW Live plays another important role in sorting aspirational acumen from actual capability. If a company or organisation has good kit that is ready for use, why not bring it along? One could even argue that the event has a subtle strategic overtone. Tartu is just under 100 kilometres/km (60 miles) from Estonia’s border with Russia. If Russian signals intelligence cadres are taking an interest from their side of the frontier, hopefully they are getting the right message. North Atlantic Treaty Organisation (NATO) and allied nations bring potent materiel which is driven hard during representative spectrum engagements. If the myriad of Russian military units in the city of Pskov, 155km (96 miles) away, get ordered to advance along the E263 highway into Estonia, and hence into NATO, some of the kit at work during EW Live will no doubt be used by Alliance troops on the frontline. A complementary event to EW Europe, EW Live is a valuable chance to see equipment in action at an event with important strategic undertones. Hats off to the Tangent Link team for delivering yet another triumph. The electronic warfare community in Europe and beyond looks forward to future iterations as EW Live firmly embeds itself in the continent’s electronic warfare calendar. (Source: Armada)

 

04 Nov 25. Six Days in August. The Alaskan Air Defence Identification Zone has been probed by Russian signals intelligence gathering aircraft of late. Several flights were performed by a Russian Aerospace Forces’ Il-20M SIGINT aircraft during late August when US military exercises were taking place in and around the state. A Russian Aerospace Force Il-20M signals intelligence gathering aircraft made several flights into Alaska’s Air Defence Identification Zone in August. What was the aircraft up to? For six days in August, between 19th and 25th of that month, a Russian Aerospace Forces (RASF) Il-20M (North Atlantic Treaty Organisation/NATO reporting name Il-20M Coot-A) flew inside Alaska’s Air Defence Identification Zone (ADIZ). Open sources state that the Alaska ADIZ stretches from the state’s international border with Canada and westwards into the Pacific Ocean past the Aleutian Islands. The Il-20M is a reconnaissance platform equipped with Signals Intelligence (SIGINT) gathering equipment and a side-looking airborne radar. According to EW Analytics LLC the Il-20M flew alone, unaccompanied by any escorting RASF aircraft.

COMINT payloads

EW Analytics LLC’s analysis continued that, in the past at least, the Il-20M was outfitted with an SRS-5 Vishnya Very/Ultra High Frequency (V/UHF: 30 megahertz/MHz to 300MHz) Communications Intelligence (COMINT) collection system. Armada understands that the SRS-5 Vishnya covers a comparatively narrow communications waveband of 100MHz to 400MHz within the Very/Ultra High Frequency (V/UHF: 30 megahertz/MHz to 300MHz) range. Nonetheless, this relatively narrow waveband would be sufficient to collect COMINT on military V/UHF air-to-air and air-to-surface/surface-to-air radio which tends to use frequencies of 225MHz to 399.95MHz. According to International Telecommunications Union stipulations the 225MHz to 328.6MHz waveband is reserved for military use by NATO and allied nations.

ELINT payload

Reportedly, the Il-20M’s COMINT payload is joined by two Electronic Intelligence (ELINT) gathering systems in the guise of the SRS-4 Romb and Kvadrat-2. EW Analytics LLC says that these two ELINT systems perform differing, but complementary, roles: The SRS-4 Romb undertakes the initial search for Signals-of-Interest (SOIs). When a SOI is discovered, the Kvadrat-2 performs the detailed analysis of that signal. What this means in practice is that the Kvadrat-2 will be used to extract precise signal parameters. These parameters will include specifics concerning the signal’s waveform. For example, is the radar signal performing a general search of the locale? Does the waveform use any low probability of interception/detection techniques? What are the waveform’s precise frequencies and amplitude? Such information is particularly important for radar threat libraries. Threat libraries are used by Electronic Support Measures (ESMs) equipping combat aircraft and warships to recognise hostile radar signals. Signal recognition enables countermeasures like jamming, or the use of physical decoys, to be brought to bear against these threats if necessary. Radar libraries can be used by SIGINT gathering assets like the Il-20M so that such signals can be easily recognised in the future allowing additional ELINT to be collected.mIl-20 variants are believed to have been used for SIGINT collection since the late 1970s. Open sources state that the first time NATO discovered an Il-20 airframe being used for this mission was in 1978. At the time, the aircraft was deployed by the Soviet Air Force: EW Analytics LLC has found first-hand accounts of the use of the IL-20 COMINT capabilities in missions over Afghanistan during the Soviet occupation of the country between 1979 and 1989. The Kvadrat-2 ELINT system is believed to have also been available for use since this timeframe, but has probably been updated extensively during the aircraft’s operational life. For example, EW Analytics LLC believes that the current Kvadrat-2 system is a significantly modernised version which digitally processes SOIs.

No details appear to exist in the public domain regarding the wavebands of the SRS-4 Romb or the Kvadrat-2. Conservatively, both systems are likely to cover wavebands of at least two gigahertz/GHz. This would allow the apparatus to collect SOIs transmitted by most ground-based air surveillance and fire control/ground-controlled interception radars, and naval surveillance radars. Extending the waveband up to 40GHz would let both systems collect ELINT on K-band (24.05GHz to 24.25GHz) and Ka-band (33.4GHz to 36GHz) radars. Some radars like variants of GEM Elettronica’s Gemini-DB naval surveillance radar transmit in Ka-band. Likewise, the SRS-5 Vishnya and SRS-Romb are likely to have been extensively upgraded since their service entry.

Motives

What was the reason for the August Il-20 flights in the ADIZ? EW Analytics LLC’s commentary notes that a United States Navy exercise, Northern Edge 2025, was ongoing while the flights were performed. Northern Edge commenced in Alaska on 17th August and concluded in early September. Might the flights have been performed to collect relevant SIGINT from US military assets participating in the exercise?

Another possibility is that the Il-20M missions were intended to convey a political message concerning Russia’s strategic presence and America’s northwest regions. The American and Russian Presidents Donald Trump and Vladimir Putin held a summit at Joint Base Elmendorf-Richardson in Anchorage, southern Alaska on 15th August. It is important to stress that the Il-20M was not breaking any international laws per se by flying into the ADIZ which is classified as international airspace. Nonetheless, aircraft flying into Alaska’s ADIZ are asked to identify themselves to US Federal Aviation Administration air traffic controllers and to the North American Aerospace Defence Command (NORAD). NORAD stated that it received no responses from the Il-20M to its challenges. The Russian aircraft performed four flights in total and was intercepted and escorted by USAF combat aircraft on each occasion.

Given that tensions between Russia and the United States show no signs of abating, future Russian SIGINT flights close to North American airspace should be expected. The same holds true for NATO-adjacent airspace, as evidenced by a similar Il-20M flight over the Baltic Sea on 21st September. It seems likely these will be as much about showing Russian force projection capabilities are they are about gathering signals intelligence. (Source: Armada)

 

05 Nov 25. Got Your Back. It is possible that both the Australian and New Zealand armies will soon receive Mastodon Design’s Terrestrial Layer System backpack electronic warfare apparatus which will help greatly enhance tactical EW interoperability with US Army deployments in the Asia-Pacific. Armada has learnt that both the Australian and New Zealand armies seem likely to acquire the Terrestrial Layer System backpack electronic warfare apparatus. The TLS backpack is equipping the United States Army. Mastodon Design won a contract to this end on 1st July 2024 worth almost $100 m. The TLS backpack forms a part of the US Army’s overhaul of its land manoeuvre force Electronic Warfare (EW) posture. As we have reported in the past, deliveries of the system to the US Army commenced in 2024. The backpack forms part of the wider TLS architecture which equips the force from division lever downwards. Three TLS capabilities are being developed: Stryker Brigade Combat Teams (BCT) will receive the TLS-BCT platform. This capability is housed onboard the medical evacuation variant of a General Dynamics M-1126 wheeled armoured fighting vehicle. According to the US Army, the M-1133 variant was chosen due to the abundance of power sockets within the vehicle’s interior. Lockheed Martin was chosen by the US Army to build a prototype TLS-BCT in August 2022. TLS-BCT systems will be produced in two sub-variants: One will be restricted to Signals Intelligence (SIGINT) collection and processing. The other will also have cyber/electronic attack capabilities. Armoured BCTs (ABCTs) will have their TLS architectures equipping tracked BAE Systems Armoured Multi-Purpose Vehicle (AMPV) platforms. Whether the ABCTs will receive two AMPV TLS variants, one of which will be confined to SIGINT and the other of which will also perform electronic attack, has not been revealed. Infantry BCTs (IBCTs) will be equipped with the TLS backpack. Divisions will be outfitted with the TLS Echelon Above Brigade (EAB) configuration. TLS-EAB prototype testing, including one design provided by Lockheed Martin, is continuing throughout 2025 and 2026, according to the US Army.

TLS backpack capabilities

Reports note that the TLS backpack is equipping US Army IBCTs at a rate of two brigades per month with deliveries expected to conclude in 2027. An article penned by John Haystead in the April 2025 edition of the Journal of Electromagnetic Dominance stated that each IBCT will have six TLS backpack systems. The TLS backpack will collect SIGINT, perform emitter direction finding and provide the local Recognised Electromagnetic Picture (REMP). Assuming a total height of at least 2.5 metres/m (8.2 feet/ft) for a standing soldier and the TLS backpack’s antennas, Signals of Interest (SOIs) across a range of up to six kilometres (3.7 miles) should be detectable. Although a single backpack can perform emitter direction-finding, by networking two or more, backpacks, it maybe possible to geolocate a SOI’s source. It does not appear that the TLS backpack can electronically attack hostile emitters. SOI details can be sent upwards where commanders will then decide whether the signal’s source should be attacked electronically and/or with cyberwarfare using a system like the TLS-BCT or engaged kinetically. No information has reached the public domain regarding the TLS backpack’s wavebands. Given that the system is intended for use at or near the tactical edge, it is possible it can detect, identify and share information on SOIs within a 30 megahertz/MHz to six gigahertz waveband. This waveband would allow TLS backpack operators to capture SIGINT on a wide array of military and civilian very/ultra-high frequency radio communications at, or near, the tactical edge.

Australasia

TLS backpack systems destined for the Australian and New Zealand armies will likely equip these forces’ respective EW formations. In New Zealand, land manoeuvre force EW is the preserve of the 1st Command Support Regiment, as we articulated in this article. Australian Army electronic warfare units include the 7th Signals Regiment. No details have been made available on when these TLS backpacks will equip each country’s forces nor how many systems will be delivered. The acquisition of the TLS backpacks makes sense for both armies. Australia and New Zealand are both important US allies in the Asia-Pacific and share a close working relationship with the US military. US Army units in the region, notably those in the Republic of Korea and Japan, will receive the TLS EW capabilities listed above. These capabilities would be heavily relied upon to support the electromagnetic battle should war erupt with the People’s Republic of China. Any region-wide conflict would invariably involve both Australia and New Zealand who may have to fight alongside US Army land manoeuvre units.

Having a common dismounted SIGINT system deployed across three of the US’ most important allies in the region will help create powerful tactical EW synergies. This commonality will help simplify the logistics burden for all three nations through the deployment of a single type of dismounted tactical EW system. Such an approach could help pay tactical, and even operational, dividends in the quest to win and sustain electromagnetic superiority and supremacy over future opponents.

 

05 Nov 25. Enterprise Control Systems redefines data link management across air, land, and sea.

  • Enterprise Control Systems (ECS) launches ECS Connect for better data link intelligence across land, sea, and air.
  • First-of-its-kind data link network manager automates switching between communication protocols to ensure reliability, lower costs, and simplify operations.

Radio frequency (RF) technology specialist Enterprise Control Systems (ECS), part of SPX Communication Technologies, today announces the launch of ECS Connect. An intelligent data link network manager, ECS Connect automatically switches between multiple communication protocols, including COFDM, SATCOM, LTE, Cellular, and MESH, ensuring uninterrupted and reliable transmission of video, audio, and data between air, land, and sea. Designed to meet the growing demand for seamless and secure connectivity in complex mission environments, ECS Connect ensures operators always have access to the most reliable and cost-effective communication channel available without the burden of manual management.  Different communication protocols have their own advantages and limitations. Dedicated COFDM links (ECS Evenlode) offer exceptional robustness and are often the primary transmission bearer, but are limited to the coverage available within the ground infrastructure. While alternatives like satellite or cellular can be more cost-effective, they can be less reliable in contested or remote environments.

ECS Connect solves this by intelligently managing and aggregating multiple networks, automatically switching to the optimal connection based on geography, signal strength, and mission demands.

With airborne platforms increasingly required to operate across diverse scenarios from border surveillance to Intelligence, Surveillance and Reconnaissance (ISR), ECS Connect provides the flexibility and assurance needed to maintain a continuous flow of intelligence data. It effectively acts as a managed service in the air, taking over complex link management and reducing pilot burden and the need for additional onboard operators.

“ECS Connect represents a significant step forward in data link technology,” said David Robins, Business Development Director for Data Links at ECS. “We’re enabling customers to move beyond single-solution systems towards a smarter, more adaptive approach to airborne and ground-based communication. ECS Connect is the first step in that journey, delivering the next generation of intelligent, resilient, reliable, any-mission-ready data links.”

“We’re seeing growing demand for secure, real-time data transfer between air and ground, especially as nations seek to strengthen their situational awareness and border security,” commented Ludovic Seixo, Sales Manager at expert radiocommunication distributor SORRAC. “ECS Connect will deliver for customers because it brings reliability, flexibility, and automation together to maintain critical communications even in the most demanding operational conditions.”

Guided by extensive customer feedback and building on ECS’s 30-year heritage of delivering reliable RF technology to defence, security, and public safety organisations, the announcement also marks a shift in ECS’s evolution from a data link hardware provider to a holistic managed connectivity solutions partner.  For more information, please visit www.enterprisecontrol.co.uk.

 

06 Nov 25. Global: Cyber criminal alliance will pose high financial, operational risks to high-profile businesses. Earlier on 6 November, the software company Trustwave confirmed that three renowned ransomware groups (‘Scattered Spider’, ‘ShinyHunters’ and ‘LAPSUS$’) are co-operating to conduct extortion attacks. The alliance (‘SLH’) is also reportedly establishing Extortion-as-a-Service (EaaS) infrastructure to maximise profits. Simultaneously, it has incorporated new capabilities to streamline operations – including data brokerage services – showcasing the rapid expansion of its enterprise despite various takedown attempts.  SLH relies on the messaging platform Telegram for command-and-control (C2) communication and has rebuilt at least 16 new channels within hours of being taken down since August, highlighting the alliance’s resources and resilience. Scattered Spider alone has caused significant financial and reputational damage to several high-profile UK and US-based companies since early 2025. SLH activity also suggests that the alliance intends to establish long-term infrastructure for the expansion of financially motivated operations. Consequently, we assess that SLH will pose high financial and operational risks to data-rich businesses in the medium term. (Source: Sibylline)

 

06 Nov 25. Didn’t See That Coming. Ukrainian forces revealed in early October they had successfully attacked a Russian 12A6 Sopka-2 ground-based air surveillance radar deployed close to the latter’s border with Ukraine as part of an ongoing Ukrainian offensive counter-air campaign against Russia’s integrated air defence system. It appears that the Ukrainian military is harnessing uncrewed aerial vehicle attacks inside Russia’s borders to degrade the country’s strategic integrated air defence system. On 2nd October, Ukrainian news sources stated that kamikaze Uncrewed Aerial Vehicles (UAVs) deployed by the country’s special forces had attacked 12A6 Sopka-2 S-band (2.7 gigahertz/GHz to 2.85GHz) and P-14F Lena (North Atlantic Treaty Organisation/NATO reporting name Tall King) Very High Frequency (VHF: 169 megahertz/MHz to 175MHz) ground-based air surveillance radars. The two systems were collocated in Russia’s Voronezh Oblast which directly borders northeastern Ukraine. The reports continued that both radars were believed to be under the command of the nearby Buturlinivka airbase. The facility at Buturlinivka does not appear to house any Russian Aerospace Forces (RASF) on a permanent basis. Instead, the airfield appears to be made available to units as and when needed. Satellite imagery taken in 2025 available on the Google Maps website appears to show RASF Su-34 (NATO reporting name Fullback) ground attack aircraft at the facility with air-to-surface ordnance stored nearby. Given the proximity of the base, it is likely these aircraft were supporting ongoing Russian combat operations in Ukraine.

The radars

As Armada has chronicled in the past the Sopka-2 has a range of circa 243 nautical miles/nm (450 kilometres/km). Open-source information says the radar can detect a target at circa 328,084-feet/ft (100,000-metres/m) altitude at circa 65nm (120km). Targets at circa 32,808ft (10,000m) altitude can be detected at ranges of 216nm (400km). The P-14F has a range of around 594nm (320km) for airborne targets. Reports noted that both radars had been used to monitor the skies over Russia’s eastern borders with Ukraine to detect, identify and track, henceforth known as process, UAVs. It is likely that the P-14F is used for the initial processing of targets at range. As these targets approach, the Sopka-2 is used to provide more detailed target information. This information is then shared with air defence units so that targets can be engaged either by combat aircraft or ground-based air defences. One can assume that, on this occasion, both radars were incapable of processing the UAVs that destroyed them. Alternatively, perhaps one, or both, radars were able to process the targets, but Russian air defenders were unable to engage the threats either kinetically and/or electronically.

Assessment

This is not the first time that Ukrainian forces have struck radars supporting Russia’s strategic Integrated Air Defence System (IADS). Open sources state that a 55ZH6U (NATO reporting name Tall Rack) VHF (133MHz to 144MHz/216MHz to 225MHz) ground-based air surveillance radar in the Bryansk Oblast on Russia’s border with northern central Ukraine was struck in April 2024. The 55ZH6U is believed to have an instrumented range of 378nm (700km), a maximum altitude of 262,467ft (80,000m) and can track up to 200 targets simultaneously. Other attacks have included the destruction of a 39N6 Kasta-2E (NATO reporting name Flat Face-E) ground-based air surveillance radar in the Kursk Oblast, on Ukraine’s northeastern border. Open sources say that the 39N6 transmits in L-band (1.215GHz to 1.4GHz) and can achieve ranges of circa 81nm (150km). The Ukrainian military is clearly performing an offensive counter-air campaign against Russia’s strategic IADS, particularly IADS targets close to Ukraine’s northern and eastern borders with Russia. By attacking these radars, the Ukrainian military is progressively degrading Russian radar coverage in this part of the country. Rolling back Russian radar coverage provides Ukrainian UAV operators more latitude in then hitting other Russian targets located in areas now free of radar surveillance. It helps Ukraine that these radars will be complex, expensive systems to build and replace. To further complicate matters, international sanctions on Russia aimed at curtailing her access to sophisticated electronics, while not perfect, will hamper the manufacture of replacement systems at pace. At the strategic level, Ukraine’s actions show that Russia’s strategic IADS is vulnerable, particularly to UAV strikes. This is a tactic that NATO and allied nations could adopt against the IADS should they find themselves fighting Russia in the future. Individual actions against individual radars may seem small, but added together, they may well have a growing significance. (Source: Armada)

 

06 Nov 25. November Spectrum SitRep. Textron is developing a counter-battery radar electronic warfare payload for the company’s UAV-based Damocles-LE air-to-surface/surface-to-surface weapon. Armada’s monthly round-up of all the latest electronic warfare news in the product, programme and operational domains.

Damocles-LE Counter-Battery Radar Variant

Textron has shared with Armada that the company is developing a dedicated counter-battery radar electronic warfare payload for its Damocles Launched Effect (Damocles-LE) system it unveiled in July. Damocles-LE is a surface-to-surface/air-to-surface weapon employing an advanced, explosively formed penetrator for top attack missions against surface targets, according to company literature. Alongside the kinetic payload, Damocles-LE can accommodate Electronic Warfare (EW) and intelligence, surveillance and reconnaissance packages. The company declined to share which radar frequencies the EW payload will cover. Given the counter-battery radar mission, it is likely these frequencies will include S-band (2.3 gigahertz/GHz to 2.5GHz/2.7GHz to 3.7GHz) and C-band (5.25GHz to 5.925GHz) at a minimum. Damocles-LE uses Ascent Aerospace’s NX-30 Spartan uncrewed aerial vehicle. Textron continued that it expects to reach Technology Readiness Level Six (TRL-6) by April 2026 for Damocles-LE. US Department of Defence definitions state that TRL-6 denotes that a representative model or prototype system has been tested in a relevant environment.

EW-EDMT Unveiled

ERA demonstrated the company’s new EW-EDMT system at the recent EW Live event in Tartu, southern Estonia. A basic version of the product is already in service, and the full version is scheduled for delivery to its first customer early next year.

ERA took advantage of this year’s EW Live event held in Tartu, southern Estonia between 23rd and 26th September to unveil the company’s Electromagnetic Warfare ERA Data Management Toolkit (EW-EDMT). An ERA press release said that the EW-EDMT can manage electronic support measure databases and automatic data processing. Delegates attending EW Live were able to see the EW-EDMT in action. The document continued that the system processes Signals Intelligence (SIGINT), particularly Electronic Intelligence (ELINT), from reception to dissemination: “It’s main purpose is to determine (the) identification of targets such as the platform, emitter and emitter node”. By using the EW-EDMT SIGINT professionals can extract information relevant to threat libraries and emitter databases. ERA told Armada in a written statement that the EW-EDMT architecture comprises an emitter tool to manage and update reference databases. A data mining tool stores, processes and evaluates ELINT data. The EW-EDMT’s mission tool maintains situational awareness and detects priority targets during missions. Finally, the target tool provides detailed information on military platforms, emitters and weapons systems to assist order-of-battle creation. The company added that a basic version of the EW-EDMT has already been delivered to over five North Atlantic Treaty Organisation (NATO) and non-NATO nations. The first full version of the EW-EDMT is expected to be delivered to an undisclosed customer in early 2026.

New NEWTS

The NEWTS IQ is the latest edition to MASS’ NEWTS electronic warfare training system. NEWTS IQ can use in-phase and quadrature data to help replicate an accurate electromagnetic environment.

Also taking advantage of EW Live to launch new products was MASS which revealed the latest version of the company’s NEWTS electromagnetic environment training system. Dubbed NEWTS IQ, the system provides the means to replicate realistic electromagnetic environment factors using in-phase and quadrature data. This replication can be done without needing to emit any radio frequency signals, says the company on its website. Stuart Willumsen, MASS’ head of spectrum warfare training, told Armada that “all NEWTS IQ hardware … can deliver targets to CEMA (Cyber and Electromagnetic Activities) training audiences at a spectral density that enables full decoding and decryption, which means that they are, to all intents and purposes, targets which present as authentic”. Another useful training feature is that NEWTS IQ can replicate a congested and contested electromagnetic environment for students. The replication is provided using wide band recordings. Alternatively the local live electromagnetic environment can be injected into NEWTS IQ: “These separate aspects of NEWTS IQ mean a fully realistic, immersive and importantly, challenging environment for CEMA training audiences, making them more proficient at their primary role as well as expediting knowledge transfer,” Mr. Willumsen continues. NEWTS IQ is already in service with two United Kingdom customers. MASS expects further iterations and enhancements of the overall NEWTS family in the future: “NEWTS IQ is an evolving capability, which is in the spirit of the rapid development cycles forced by the current operational context,” Mr. Willumsen concluded. (Source: Armada)

 

05 Nov 25. Enabling the Swarm: Equipping Drones with Electronic Warfare Capabilities. Northrop Grumman is redefining the future of electronic warfare by creating cutting-edge technology that delivers unmatched capability – even in the smallest of systems. The modern battlespace is defined by contested and degraded environments where allies and adversaries compete for crucial bandwidth. To maintain a decisive advantage and degrade the capabilities of enemy forces, the U.S. and its allies require electronic warfare (EW) technology that is not only advanced but also agile, resilient and scalable. That’s why Northrop Grumman, has developed a revolutionary technology, compact yet powerful, that can dominate in any environment. At Silent Swarm 2025, an annual U.S. Navy demonstration of advanced EW for small, unmanned systems, Northrop Grumman delivered a live, proof-of-concept. On-site, the company integrated its Tactical Edge Electromagnetic Solutions (TEEMS) onto compact platforms – ranging from tiny robots to unmanned surface vessels and drones – demonstrating how these small systems can produce outsized impacts. With TEEMS embedded, these platforms become powerful tools capable of detecting and jamming enemy signs with speed and precision, ensuring superiority across every domain.

A Big Punch in a Tiny Package

In contested environments, where every inch of space and ounce of weight matters, EW solutions must combine top-tier performance with ultra-efficient size, weight and power (SWaP) for unmatched mission flexibility. Northrop Grumman’s TEEMS solution delivers exactly that, integrating high-performance EW capabilities into a compact 1U Modular Payload. Measuring smaller than a business card, it was not only the smallest at the event, but also the most capable, packing powerful performance into an unprecedented form factor. The demonstration was a testament to the power of resilient, scalable technologies, designed for mobility. While on-site, Northrop Grumman’s team:

  • Countered Evolving Threats: The team successfully geolocated a frequency-agile target emitter – which are known to be difficult to disrupt – and performed stand-in jamming.
  • Achieved Intelligent, Integrated Operations: Through the integration with Tactical Assault Kit software, the team remotely controlled multiple unmanned ground and surface units across a large, 50-square-mile operational area. The system’s ability to seamlessly coordinate with these diverse assets demonstrated its capacity for intelligent, integrated mission solutioning.
  • Maximized Combat Impact: In a single, simultaneous action, TEEMS knocked out three different radios that were spread across a wide frequency range.

Enabling the Swarm: Equipping Drones with Electronic Warfare Capabilities

Northrop Grumman is at the forefront of building technology that delivers maximum impact – packing big power into pocket-sized tech. The Tactical Edge Electromagnetic Solutions (TEEMS) Tactical Edge Device packages “Rock Ridge,” Northrop Grumman’s state-of-the-art electronic warfare (EW) transceiver, into a compact 1U Modular Payload. (Photo Credit: Northrop Grumman)

“Silent Swarm 2025 was a resounding success, not just for its technological achievements, but because it underscored our team’s ability to innovate and execute under pressure,” said Angela Johns, vice president, weapons integration & mission solutions, Northrop Grumman. “This effort reinforces our commitment to delivering mission-ready solutions tested in simulated environments and solidifying our role in advancing tactical operation dominance both today and in the future.”

By successfully showcasing that high-end electronic warfare (EW) capabilities can be integrated in a compact, modular package, Northrop Grumman is empowering the U.S. and its allies to remain mission-ready at the tactical edge. The work accomplished at Silent Swarm 2025, along with technology such as the TEEMS device, illustrates how the company is architecting the advantage for today’s performance and tomorrow’s success along the tactical edge. (Source: ASD Network)

 

05 Nov 25. Sitep Australia Joins Rohde & Schwarz Team for Hunter Class Frigate Communications. Rohde & Schwarz Australia has awarded a contract to Sitep Australia to equip the Royal Australian Navy’s first three Hunter class frigates with its world-leading antenna technology for the Ultra High Frequency Military Satellite Communication (UHF-MILSATCOM) system. World-leading antenna technology from Sitep will be equipped as part of the Hunter class frigate UHF-MILSATCOM system following a contract with Rohde & Schwarz to supply their NAVICS communications technology for the first three ships of the Hunter Class Frigate Program.

Managing Director of Rohde & Schwarz Australia Gareth Evans said, “Sitep Australia has been operating in Australia since 1999, establishing sovereign communication and navigation systems and service delivery capabilities here. With their proven track record, we’re pleased to have them onboard and are confident they will deliver a high-quality solution that integrates with the ship and the NAVICS Multi-Level Security communications system to meet the Navy’s requirements.”

Raffaele Iannizzotto, Business Development Director of Sitep Australia, said: “This contract clearly validates the highly collaborative working relationship established with Rohde & Schwarz. Sitep Australia’s antenna technology for the UHF-MILSATCOM antenna systems have been installed and are operational on Anzac class frigates, Hobart class destroyers, and AOR vessels of the Royal Australian Navy. This demonstrates our commitment to building a resilient local capacity to innovate, create, and supply communication systems. We are a trusted partner to both the Commonwealth and Rohde & Schwarz, supporting the Sovereign Defence Industrial Priority of Continuous Naval Shipbuilding and Sustainment.”  (Source: ASD Network)

 

05 Nov 25. Bittium Corporation’s Subsidiary Bittium Wireless Ltd has signed a Framework Agreement in the Field of Command-and-Control Systems with the Finnish and Swedish Defence Forces. Inside Information: Bittium Corporation’s Subsidiary Bittium Wireless Ltd has signed a Framework Agreement in the Field of Command-and-Control Systems with the Finnish and Swedish Defence Forces

Bittium Corporation, Stock Exchange Release, 5 November 2025, at 1.30 pm (CET+1)

Tommi Kangas, Senior Vice President Bittium Group’s Defense & Security Business Segment, and Major General Tero Ylitalo, Chief of the Finnish Defence Forces Logistics Command, and Johan Andersson, Deputy Director Command and Information Systems Division, Swedish Defence Materiel Administration (FMV), have today signed a framework agreement in the field of command-and-control systems (C4I, Command, Control, Communications, Computers and Intelligence). The agreement enables the procurement of Bittium’s tactical communication systems and products, software-defined radios, as well as security software and phones. The modern, software-defined tactical communication system Bittium Tactical Wireless IP Network™ and the related software-defined Bittium Tough SDR™ radios have been developed in cooperation with the Finnish Defence Forces. In addition to Finland, Bittium’s solutions are used in four European countries as part of their defence command-and-control systems, and pilot projects are ongoing in several other countries. The framework agreement continues the procurement cooperation between Finland and Sweden in the field of command-and-control systems, covering products and services that provide a common situational awareness, communications, intelligence, and decision support for command operations and troop leadership. The framework agreement also enables joint product development between Finland, Sweden, and Bittium. The newly signed framework agreement is initially valid for ten years, after which it will automatically continue for one year at a time. Norway and Denmark, who are also participating in Nordic defence cooperation may also join the agreement.

“Cooperation between Finland and Sweden in the field of defense has become commonplace, and this is yet another demonstration of its effectiveness. Joint framework agreements enable cost-effective joint procurements, which improve the countries’ ability to operate together. Joint framework agreements in the field of command-and-control systems allow for larger procurement volumes, resulting in lower prices for products and services. These agreements also enhance our ability to engage in joint product development with the system supplier. With this agreement, we achieve broad benefits for our defense,” says Finnish Minister of Defence Antti Häkkänen.

“We are proud that Bittium’s solutions meet the future needs of defence. Modern defense forces require not only reliable and resilient communications but also high-level security, interoperability, and flexibility” says Tommi Kangas, Senior Vice President, Bittium’s Defense & Security Business Segment and continues “We are excited about the opportunity to expand cooperation to other Nordic countries through this agreement. Harmonizing the communication solution between the Nordic countries would enable efficient and seamless communication in all defense operational domains”.

“Developing command-and-control systems in cooperation with Sweden strengthens our defence capability and improves the interoperability of our troops. Joint solutions enable efficient information exchange and decision-making in all operational domains. This agreement is a step towards even closer Nordic defence cooperation,” says Major General Tero Ylitalo, Chief of the Finnish Defence Forces Logistics Command.

 

04 Nov 25. Indicium and Mesh-AI announce their integration to form Indicium AI, creating one of the world’s leading data and AI consultancies. Backed by Columbia Capital, the combined organization brings together deep expertise, cutting-edge technology, and world-class talent to accelerate enterprise transformation across the Americas, Europe, and Latin America (LATAM). Both brands will continue to operate independently until Q1 2026, when the new brand, Indicium AI, will be officially launched and business operations will be integrated.

A Strategic Partnership for the Future of Enterprise AI

The union brings together two leaders at the forefront of data and AI innovation with clients such as National Grid, Experian, PepsiCo, and Roche. Both companies drive enterprise transformation through AI and serve enterprises across Financial Services, Energy & Utilities, Pharma, Retail & CPG, Manufacturing, and Media, among others. Indicium’s expertise in data modernization and AI execution joins Mesh-AI’s strategic capability in enterprise data and AI. Together, they deliver end-to-end solutions that help Fortune 500 and global enterprises unlock measurable value from data and AI.

“We’re incredibly excited to bring these two innovative companies together,” said Jason Booma, Partner at Columbia Capital. “This integration combines exceptional talent, technology, and vision to address the most pressing data and AI challenges facing enterprises today. Together, we seek to create an unparalleled suite of solutions to enable enterprises to accelerate data and AI transformation on a global scale.”

Kelly Manthey has been appointed Global CEO of Indicium AI. A proven leader with over 25 years of experience, she previously served as CEO of Kin + Carta, where she led the global consultancy and operations across multiple markets. Her engineering background and track record in international growth positions her to lead the next chapter of this global data and AI powerhouse.

“I am thrilled to be leading this business. By uniting the exceptional talents of Indicium and Mesh-AI, we are creating an unparalleled customer proposition,” said Kelly Manthey. “We combine world-class expertise, technology, and talent to accelerate enterprise transformation and unlock measurable value from data and AI for the enterprise with unmatched clarity, speed, and capability.”

Matheus Dellagnelo, former CEO of Indicium, will serve as CEO Americas, and Jacob Parsons, former CEO of Mesh-AI, will serve as CEO Europe.

Partnering with the Best to Drive Innovation

The combined company continues to collaborate closely with industry leaders including Databricks, AWS, OpenAI, Anthropic, and Microsoft to deliver responsible, scalable innovation for enterprises worldwide. Databricks Ventures invested in Indicium in September 2025 to advance shared goals in data modernization and enterprise AI transformation.

“Our recent investment in Indicium reflects a shared commitment to shaping the future of enterprise AI,” said Kori O’Brien, Senior Vice President, Global Partnerships at Databricks. “We’ve seen firsthand how Indicium delivers data and AI transformation on the Databricks Data Intelligence Platform with speed, precision, and measurable results. Now, with the creation of Indicium AI, they are poised to drive even more customer value and scale.”

A New Era for Data and AI

With an expanded presence across the Americas, Europe, and LATAM, this integration enhances the company’s ability to serve multinational enterprises. As enterprises accelerate AI adoption and face challenges unlocking its full value, they seek partners capable of delivering measurable impact at global scale. Indicium AI emerges as the only specialist data and AI consultancy operating globally. Its mission is to deliver end-to-end data and AI transformation, helping the world’s most complex enterprises embrace this shift with clarity, speed, and capability.

With over 600 data and AI specialists and a portfolio of Fortune 500 clients, the combined organization is positioned to shape the future of intelligent enterprise transformation and capture new opportunities in the rapidly growing global data and AI market.

Empowering People and Culture

This integration creates expanded career opportunities for professionals who want to shape the future of data and AI. Both teams share a culture of collaboration, curiosity, and impact, and are hiring globally.

About Mesh-AI

Headquartered in London, Mesh-AI is a data and AI consultancy that helps enterprises leverage data and AI at scale to achieve transformative outcomes. With deep expertise in highly regulated industries such as financial services and energy & utilities, Mesh-AI enables organizations to unlock value, enhance resilience, and drive innovation. Learn more at www.mesh-ai.com.

About Indicium

Headquartered in New York, Indicium is a global data and AI services company helping enterprises migrate faster, optimize platforms and build scalable data products. Our team of more than 500 certified experts delivers across the full data lifecycle. Our proprietary AI-enabled IndiMesh framework powers every engagement with collective intelligence, proven expertise, and rigorous quality control. Industry leaders like PepsiCo and Bayer trust Indicium to reduce risk, accelerate outcomes and deliver lasting value. Visit www.indicium.ai.

 

04 Nov 25. Global: New backdoor attack highlights increased security risks via abuse of legitimate technologies. On 3 November, the technology company Microsoft reported that unnamed threat actors had used a new backdoor (‘SesameOp’) to conduct a long-term cyber espionage operation. While the initial attack vector is unclear, threat actors executed a malware loader and first-stage backdoor to install SesameOp after infiltrating the targeted system. SesameOp exploited built-in capabilities from the Assistants Application Programming Interface (API) created by the artificial intelligence (AI) company OpenAI for secure command-and-control (C2) communication and storage. Threat actors also used legitimate cloud services to store SesameOp, further illustrating the increased integration of legitimate technologies into malicious cyber activity. The adoption of these services enabled threat actors to remain obfuscated and maintain persistence within compromised systems for several months before being detected, showcasing the operation’s stealth. OpenAI reportedly disabled the API key after Microsoft discovered the attack in July. However, this operation highlights the security risks associated with the increased exploitation of legitimate technologies. (Source: Sibylline)

 

04 Nov 25. STV Group a.s. (“STV”), one of the world’s fastest-growing defence innovators, has signed a multi-year licence agreement to use Post-Quantum’s groundbreaking quantum-safe communications platform and signed a Strategic Cooperation Agreement to accelerate deployment across Europe, NATO, and global defence markets. With quantum computing threatening to render traditional encryption obsolete, the move positions STV at the forefront of the cybersecurity revolution – arming governments, defence forces, and enterprises with next-generation resilience against “Harvest Now, Decrypt Later” attacks. By fusing Post-Quantum’s NATO-tested modular platform with its own world-class defence solutions, STV is setting a new global benchmark for secure communications and digital trust. Together, the two companies are delivering the most advanced, future-proof systems to protect sensitive data and mission-critical operations – ensuring that even in the quantum era, allied communications remain impenetrable. The partnership represents a decisive leap forward, combining STV’s defence innovation track record with Post-Quantum’s pioneering expertise to deliver communications and data protection systems that go beyond current industry standards.

JUDr. Pavel Kudrhalt, CEO of STV, said: “This isn’t just about acquiring technology – it’s about building an uncompromising, end-to-end secure ecosystem for the future. Our customers demand full supply chain assurance, from manufacturing and tamper-proof transport to deployment and monitoring. With the rising threat of ‘Harvest Now, Decrypt Later’ attacks, quantum-safe defences are no longer optional. Post-Quantum’s platform doesn’t just lead the field – it allows STV to be the first-mover to redefine the very standards of digital trust in defence solutions. By embedding their technology into our portfolio, we are giving NATO allies, EU partners, and national clients the strongest possible protection for the quantum era – whether that’s safeguarding command and control chains, operating mission-critical drones, or deploying munitions in battlefield communications.”

Rikky Hasan, CEO of Post-Quantum, added: “STV’s vision and leadership in defence innovation make them the ideal partner. Together we are unleashing a new wave of secure, quantum-safe solutions that protect the world’s most sensitive data against today’s adversaries and tomorrow’s quantum threats. Our modular approach to Identity, Transmission and Encryption – already proven in NATO environments – offers the fastest and most agile way to integrate into STV’s global portfolio. This is a proud moment for both companies, and a milestone for global cybersecurity.”

This acquisition and alliance signal the dawn of a new era: one where quantum-resilient platforms are no longer optional, but essential. United by a shared mission to safeguard the future, STV and Post-Quantum are leading the charge toward a world where critical communications remain impenetrable – even in the face of quantum computing’s disruptive power.

About STV

STV Group a.s. is one of Europe’s fastest-growing defence innovators, delivering advanced security and defence solutions to governments, NATO allies, and commercial partners worldwide. Headquartered in the Czech Republic, the company combines cutting-edge engineering with a bold vision for the future of security. Building on a century of industrial tradition, STV Group has become the Czech Republic’s leading producer of munitions, loitering systems, armoured vehicle platforms and integrated lifecycle services. The group is also a European leader in ecological disposal and demilitarisation of surplus ammunition, underscoring its commitment to safety and sustainability. With NATO-tested technologies and global partnerships, STV Group is trusted to deliver the resilient, future-proof capabilities that keep nations secure in an era of emerging threats.

About Post-Quantum

Post-Quantum is leading the charge into the quantum era by upgrading the world’s encryption. Its quantum-safe platform protects organisations across their entire digital footprint with modular software for Identity, Transmission, and Encryption—designed to be interoperable, crypto-agile and seamlessly backward compatible. Already trusted by NATO, critical national infrastructure providers, and major financial institutions, Post-Quantum has a proven track record in safeguarding mission-critical data. The company is the inventor of NTS-KEM (now known as Classic McEliece in the NIST competition) and the author of the IETF’s Hybrid Post-Quantum VPN standard, which is now the global benchmark for secure connectivity. With its pioneering technologies, Post-Quantum is ensuring the world stays one step ahead of the quantum threats.

 

03 Nov 25. Bittium, a leading supplier of resilient communications solutions based on software-defined radio technology, continues development of interoperable ESSOR waveform for tactical communications as part of the multinational a4ESSOR joint venture. a4ESSOR S.A.S (Alliance for ESSOR – European Secure Software Defined Radio) develops European secure software-defined radio (SDR) technology for military use and has signed a new procurement contract with the intergovernmental Organisation for Joint Armament Cooperation (OCCAR) for the next, fourth stage of development of ESSOR technology. The contract covers capability development for the ESSOR High Data Rate Waveform (EHDRWF) that can be ported to national software-defined radios. Through this unique approach, any nation can use its own radio and be interoperable with other nations in their tactical communications. The contract for the ESSOR Development Stage #4 (ES4) is valued in excess of EUR 47 m. Work will be shared, in relation to the shares of the member states, between the six companies participating in a4ESSOR: Bittium (Finland), Indra (Spain), Leonardo (Italy), Radmor (Poland), Rohde & Schwarz (Germany), and Thales (France). The work is split in relation to the shares of the member states, where Bittium’s share is significantly lower than the directly calculated relative proportion would be. The six nations involved and their respective industry leaders have then been working to add new features, such as electronic protection measures and support of modern cryptographic standards, leading to several successful interoperability demonstrations and qualification tests, and to the adoption of ESSOR High Data Rate Waveform as NATO STANAG 5651 in 2023. Under the new contract, a4ESSOR will design a common mission framework aimed at a shared planning capability for the network parameters of the EHDRWF. Once implemented in the command-and-control system of each nation, the mission framework will ensure high interoperability at operational level, allowing quick and accurate deployment of multinational EHDRWF networks.

a4ESSOR will conduct field tests of the EHDRWF on the various radio systems to assess the maturity, performance, and reliability of the waveform in various scenarios, providing valuable feedback for future waveform enhancements. The field test will also include trials in different operational environments (urban, rural, and hilly terrains), line-of-sight/non-line-of-sight and mobility scenarios, as well as analysis of waveform performance under potential interference conditions. Furthermore, the contract will define an ESSOR in-service support framework and will set up an ESSOR laboratory as the reference for interoperability validation.

“Enabling seamless defense cooperation with solutions that are based on software-defined radio technology is at the core of our leading knowhow and expertise. We put a lot of emphasis on the a4ESSOR collaboration and the development of the ESSOR waveforms. The ESSOR High Data Rate Waveform has already been ported to the Bittium Tough SDR radio platforms, and with the new development phase beginning now, our customers will gain new operational capabilities to support with their objectives,” said Tommi Kangas, Senior Vice President of Bittium’s Defense & Security business segment.

Lino Laganà, President and General Manager of a4ESSOR, said “a4ESSOR has been active for over 16 years playing a crucial role to develop and test ESSOR capabilities and technologies to address multinational defence requirements as a valuable solution in addition to the existing legacy waveforms. The ESSOR HDRWF standard is capable to facilitate seamless communications across diverse radio platforms and nations, affirming its potential to enhance collaborative defence operations across Europe and NATO countries. The mission framework will allow a quantum leap forward in terms of interoperability among armed forces from various countries, as it will define what’s needed to achieve the interoperability in mission planning and management. We will work at defining the required solutions towards their integration onto command-and-control systems of the various countries. It’s an evolution enabler, from technical to operational interoperability.”

Lino Laganà continued “The project aligns with the European Union’s strategic objectives of strengthening defence cooperation, enhancing autonomy, and improving the efficiency of combined military missions. By equipping EU member states with secure, interoperable, and scalable communication solutions, the initiative strengthens Europe’s collective ability to respond to threats and ensures seamless coordination in operations.”

 

03 Nov 25. a4ESSOR S.A.S (Alliance for ESSOR – European Secure Software Defined Radio), a multinational joint venture that develops secure software defined radio (SDR) technology, has signed a procurement contract with the intergovernmental Organisation for Joint Armament Cooperation (OCCAR) to carry out the capability deployment of the ESSOR High Data Rate Waveform – EHDRWF. The waveform can be ported to national software-defined radios; through this unique approach, any nation can use its own radio and be interoperable with other nations in their tactical communications. The contract for the so called ESSOR Development Stage #4 (ES4) is valued in excess of 47m EUR. The six nations involved and their respective industry leaders (Finland – Bittium, France – Thales, Germany – Rohde & Schwarz, Italy – Leonardo, Poland – Radmor, Spain – Indra) have then been working to add new features, such as electronic protection measures and support of modern cryptographic standards, leading to several successful interoperability demonstrations and qualification tests and to the adoption of ESSOR High Data Rate Waveform as NATO STANAG 5651 in 2023. Under the new contract, a4ESSOR will design a common mission framework aimed at shared planning capability of network parameters of the EHDRWF. Once implemented in the command-and-control system of each nation, the mission framework will ensure high interoperability at operational level, allowing quick and accurate deployment of multinational EHDRWF networks.

a4ESSOR will conduct field tests of the EHDRWF on the various radio systems to assess the maturity, performance and reliability of the waveform in various scenarios, providing valuable feedback for future waveform enhancements. The field test will also include trials in different operational environments (urban, rural and hilly terrains), line-of-sight/non-line-of-sight and mobility scenarios, as well as analysis of waveform performances under potential interference conditions. Furthermore, the contract will define an ESSOR in-service support framework and will set up an ESSOR laboratory as the reference for interoperability validation.

Lino Laganà, President and General Manager of a4ESSOR, said “a4ESSOR has been active for over 16 years playing a crucial role to develop and test ESSOR capabilities and technologies to address multinational defence requirements as a valuable solution in addition to the existing legacy waveforms. The ESSOR HDRWF standard is capable to facilitate seamless communications across diverse radio platforms and nations, affirming its potential to enhance collaborative defence operations across Europe and NATO countries.”

“The mission framework will allow a quantum leap forward in terms of interoperability among armed forces from various countries, as it will define what’s needed to achieve interoperability in mission planning and management. We will work at defining the required solutions towards their integration onto command & control systems of the various countries. It’s an evolution enabler, from technical to operational interoperability.”

Lino Laganà continued “The project aligns with the European Union’s strategic objectives of strengthening defence cooperation, enhancing autonomy, and improving the efficiency of combined military missions. By equipping EU member states with secure, interoperable, and scalable communication solutions, the initiative strengthens Europe’s collective ability to respond to threats and ensures seamless coordination in operations.”

 

03 Nov 25. Europe: Diplomatic entities face long-term cyber espionage risks from China-affiliated threat actors. On 1 November, international news outlets reported that a China-nexus group (‘UNC6384’) has targeted diplomatic entities across Europe in a cyber espionage operation since at least September. The group distributes phishing emails containing a malicious LNK file to infiltrate targeted systems and to deploy malicious payloads. It then exploits a zero-day vulnerability ‘(ZDI-CAN-25373’) to execute the LNK attachment onto compromised systems, in order to install a remote access trojan (RAT; ‘PlugX’) via a multi-stage process. PlugX enables data exfiltration and monitoring; it is executed directly within a system’s memory to enhance obfuscation, which indicates that the campaign likely aims to maintain prolonged persistence for strategic data collection. The campaign has targeted diplomatic entities across Europe, including in Belgium, Hungary, Italy, the Netherlands and Serbia, showcasing its highly co-ordinated nature. We assess that this campaign underscores the long-term security and cyber espionage risks faced by strategic sectors in Europe amid ongoing geopolitical hostilities. (Source: Sibylline)

 

31 Oct 25. DRDO tests new airborne EW suite for LCA Mk 1A. India’s Defence Research & Development Organisation (DRDO) is flight-testing its new Swayam Raksha Kavach (SRK) airborne electronic warfare (EW) suite that will be fielded by the Indian Air Force’s (IAF’s) future fleet of Hindustan Aeronautics Limited (HAL) Tejas light combat aircraft (LCA) Mk 1A fighter aircraft. Simultaneously, DRDO has updated its older D-29 EW suite that was developed over a decade ago for use by IAF Mikoyan-Gurevich MiG-29 fighter aircraft. Development of the SRK suite began in 2021, and it is currently being subject to flight tests using an LCA Mk 1A, a DRDO official told Janes on 30 October on the sidelines of DRDO’s Samanvay 2025 industry summit in Bangalore. During the two-day summit (held on 29 and 30 October), DRDO transferred several technologies to industry partners. This included the transfer of all-improved D-29 EW suite-related technologies and intellectual property (IP) held by DRDO’s Combat Aircraft Systems Development and Integration Centre (CASDIC) to a production partner, Bharat Electronics Limited (BEL).

SRK capabilities

Janes understands that the SRK is an evolution of the D-29 EW suite and has improved capabilities.

The suite comprises a radar warning receiver (RWR) integrated into the body of the fighter aircraft and a jammer pod installed on a hardpoint. According to the official, DRDO expects to conclude flight trials of the system by mid-2026, with deployment on the Mk 1A platform from the end of 2026. (Source: Janes)

 

31 Oct 25. Cyber Update Key points.

  • Government and critical national infrastructure (CNI) sectors face long-term cyber espionage risks from the Iranian state-sponsored group ‘MuddyWater’ (see Sibylline Cyber Daily Analytical Update – 27 October 2025).
  • A new Malware-as-a-Service (MaaS) operation underscores the sustained financial risks to Android users through the distribution of ‘HyperRat’, a new remote access trojan.
  • A ransomware operation (‘Everest’) poses increased security, data-theft and financial risks to data-rich and high-profile sectors
  • Cyber attacks on Ukrainian organisations highlight sustained cyber espionage risks from Russian state-sponsored groups.
  • Canadian CNI faces elevated security and operational risks from hacktivist groups

Technical analysis of weekly stories

Threat actors are targeting Android users with HyperRat. This RAT can be purchased as part of a MaaS operation that provides affiliates with a malicious Android Package Kit (APK) to distribute the malware and a centralised control panel, highlighting the continuous growth of cyber criminal enterprises. We assess that threat actors will likely advertise fake applications containing the malicious APK to trick victims into downloading HyperRat onto their devices. Upon deployment, HyperRat can check existing permissions and enumerate all applications installed on compromised devices. This feature allows threat actors to request necessary permissions, as well as to tailor phishing overlays and other prompts, in order to appear legitimate and covertly exfiltrate sensitive data. HyperRat affiliates can manage all infected devices from a centralised panel that communicates in real time with the messaging application Telegram, showcasing the sophistication of its command-and-control (C2) infrastructure. Furthermore, threat groups can bulk send follow-on social engineering messages through compromised devices, underscoring increased propagation risks.

Between June and August, a Russian state-sponsored group (‘Seashell Blizzard’) used Living-off-the-Land (LotL) techniques to conduct cyber attacks on at least two Ukrainian organisations. The first infection reportedly started on 27 June, when threat actors likely exploited multiple software vulnerabilities to infiltrate an unnamed business services firm. Soon after accessing their system, Seashell Blizzard deployed an initial web shell (‘Localolive’) to establish communication with C2 infrastructure and conduct system reconnaissance. On 29 June, the group installed a second web shell to move laterally through the network, before enumerating all system files. It then used scheduled tasks and a PowerShell backdoor to conduct memory dumps, harvest credentials and exfiltrate sensitive data. Seashell Blizzard disabled security protections and avoided deploying heavyweight custom malware payloads, thereby enhancing the operation’s stealth. Some of the techniques the group adopted throughout the attacks resemble the modus operandi of the Russian advanced persistent threat (APT) group ‘Sandworm’, highlighting a potential overlap between the groups. It remains unclear when the second infection started, though it only lasted a week, in contrast to the first operation, which lasted two months and terminated in August.

Non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware.
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.

Our cyber word(s) of the week: Memory dump

Definition: A snapshot of a system’s Random Access Memory (RAM) that threat actors often exploit to extract sensitive data from compromised systems.

Example: ‘It then used scheduled tasks and a PowerShell backdoor to conduct memory dumps, harvest credentials and exfiltrate sensitive data’ (see our Technical analysis above). (Source: Sibylline)

————————————————————————————————————————————————————————————————————————————————————————————————————————————-

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

————————————————————————————————————————————————————————————————————————————————————————————————————————————

 

  • Page 1
  • Page 2
  • Page 3
  • Interim pages omitted …
  • Page 6
  • Go to Next Page »

Primary Sidebar

Advertisers

  • Pythia
  • Teledyne
  • Exensor
  • Visit the Oxley website
  • Blighter
  • SPECTRA
  • Britbots logo
  • Faun Trackway
  • Systematic
  • CISION logo
  • ProTEK logo
  • ProTEK logo
  • ssafa logo
  • IEE
  • EXFOR logo
  • sibylline logo
  • Team Thunder logo
  • Comtech logo
  • GoExporting logo
  • ECHODYNE logo
  • Supercat logo
  • Galvion logo
  • Leonardo DRS logo
  • MTC logo
  • IDC logo
  • DSEI logo
  • DVD2024 logo
  • SDSC logo
  • TELEDYNE FLIR logo
  • VeteranUK logo
  • Matrix Space logo
  • ST Engineering logo
  • EWS logo
  • sentinel photonics logo
  • capua logo
  • Curtiss-Wright logo
  • Brave1 logo
  • Drone Evolution logo
  • AEI Systems logo
  • EOS logo
  • NMSUK logo
  • Openworks logo
  • Sandown Park logo
Hilux UKDSE AARTOS ST Engineering Future Artillery

Contact Us

BATTLESPACE Publications
41 St Georges Drive
London SW1V 4DG

+44 (0)77689 54766

BATTLESPACE Technologies

An international defence electronics news service providing our readers with up to date developments in the defence electronics industry.

Recent News

  • Protek Selected By Dutch Armed Forces

    May 2, 2026
    Read more
  • PARLIAMENTARY QUESTIONS

    May 1, 2026
    Read more
  • MANAGEMENT ON THE MOVE

    May 1, 2026
    Read more

Copyright BATTLESPACE Publications © 2002–2026.

This website uses cookies to improve your experience. If you continue to use the website, we'll assume you're ok with this.   Read More  Accept
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT