• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • SPECTRA banner
  • Curtiss-Wright banner

BATTLESPACE Updates

   +44 (0)77689 54766
   

  • Home
  • Features
  • News Updates
  • Defence Engage
  • Company Directory
  • About
  • Contact

C2, Tactical Comms, AI, Cyber, EW, Cloud Computing & Homeland Security

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

October 31, 2025 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

——————————————————————————————————————————————————————————————————————————————————————————————————————————————-

31 Oct 25. Sofant Technologies, backed by EMV Capital, the deep tech and life sciences VC investment group, has achieved a major industry milestone by successfully demonstrating a fully functioning Ka band transmit array using its proprietary RF MEMS beamforming IC. This world-first accomplishment, revealed at the recent Tech Tour Defence conference in Paris, has been achieved after overcoming a series of complex technical challenges, marking a pivotal moment in the advancement of wireless technology. Beamforming is essential for the high-frequency millimeter-wave (mmWave) bands used across a wide range of applications including SatCom 5G and future 6G networks. RF MEMS delivers the high-performance phase shifters and switches needed to steer these signals power efficiently. In satellite communications, where every gram of weight and milliwatt of power is critical, RF MEMS components significantly reduce the size, weight, and power (SWaP) of communication systems used in aerospace applications. In defence and radar, agile and powerful beamforming is critical for advanced radar and electronic warfare systems used in the military. With the rest of Sofant’s technology stack now ready to scale, the company is poised to launch commercial sales of its innovative solution in the second half of 2026.

David Wither, CEO of Sofant Technologies, said: “This is a defining moment for both Sofant and the wireless industry. Delivering the world’s first RF MEMS beamforming IC demonstrates our team’s technical leadership and relentless determination in tackling challenges others thought impossible. In parallel, our operations team has worked tirelessly to develop a manufacturing system that ensures we can scale up quickly and deliver this transformative technology to the market in high volume at low cost.”

Dr Ilian Iliev, CEO of EMV Capital, added: “Sofant’s team has demonstrated outstanding technical innovation in developing a world-first RF MEMS beamforming solution. Their ability to combine engineering excellence with a clear path to scalable, cost-efficient production is a testament to the strength of their vision and execution. We are proud to be supporting Sofant as it brings this transformative technology to global markets.”

Headquartered in Edinburgh, Scotland, Sofant Technologies is at the forefront of wireless innovation. Supported by leading investors including Scottish Enterprise, EMV Capital, Kelvin Capital, Caladan Capital, NSSIF, the UK Space Agency, and the European Space Agency, Sofant’s patented RF MEMS technology delivers up to 70% reduction in power consumption, offering the market the lowest size, weight, and cost solutions available.

 

30 Oct 25. AT&T and Thales collaborate to revolutionize IoT deployments with new eSIM solution.

  • AT&T and Thales introduce a next generation eSIM solution, powered by the latest GSMA IoT specification (SGP.32), giving enterprises a consolidated platform to remotely and securely manage IoT subscriptions, while preserving device integrity on a highly secure and reliable network.
  • Backed by Thales’ “secure by design” approach, this solution targets the highest level of cybersecurity for IoT devices and supports compliance with evolving global cybersecurity regulations.
  • Optimized for large-scale IoT deployments, the new eSIM management platform simplifies operations, reduces costs, and delivers advanced automation beyond SGP.32 standards to support diverse industries and device types.

With over 5.8 bn IoT cellular connections expected globally by 2030 (GSMA Intelligence) — powering everything from smart meters to wearable health trackers — the need for secure, scalable, and easy-to-manage connectivity is greater than ever. AT&T, a leader in connectivity and IoT solutions, and Thales, a global leader in advanced Cyber & Digital technologies, announce the launch of a new eSIM solution designed to help businesses remotely activate and manage IoT devices. This eSIM solution, powered by Thales Adaptive Connect (TAC), becomes a key part of AT&T’s global IoT solution, AT&T Virtual Profile Management for IoT, and can support many industries worldwide including automotive, smart cities, healthcare and utilities.

Compliant with the GSMA SGP.32 standard1, the new solution enables customers to ship connected devices anywhere in the world with one single, pre-integrated eSIM from Thales, then seamlessly activate the correct local connectivity profile remotely, eliminating the need for any physical access to it. This results in faster launches and simpler logistics for global IoT deployments. It also enables AT&T and its customers to easily manage connectivity policies, diagnostics, and subscription changes entirely over the air, through a single unified industry-certified interface.

This solution also adds advanced automation to simplify the remote eSIM management of large numbers of devices. It automates complex tasks, such as switching subscriptions or updating fleets rules, so enterprises can spend less time on logistics and operations, while bringing new products and services faster to market.

Thanks to these advanced features, Thales’ eSIM solution (TAC) gives companies the flexibility to localize within AT&T network partners or adjust devices’ subscriptions across large fleets without hardware changes, helping optimize costs, supply chains, coverage, and performance.

The service is now available for commercial use and supports customers worldwide.

“At AT&T, we deliver intelligent IoT solutions you can trust—highly secure, end-to-end, and built to scale,” said Cameron Coursey, VP of AT&T Connected Solutions. “Our state-of-the-art approach, paired with Thales’ solution, will help customers reduce friction and gain control of managing their own devices with reliable connectivity.”

“We are entering a new era for remote eSIM Provisioning, ready to power bns of IoT devices, and we are proud to collaborate with AT&T in delivering smarter and safer IoT connectivity around the world,” said Eva Rudin, EVP Mobile Connectivity Solutions at Thales. “With Thales Adaptive Connect, we’re ensuring that every connected device benefits from strong security, reliable service, and simplified management — from the first connection and throughout its lifetime.”

1 The GSMA SGP.32 standard the latest specification from the GSM Association for eSIM (embedded SIM) Remote SIM Provisioning (RSP), for the remote eSIM management of Internet of things (IoT) devices and other types of mobile device deployments.

 

29 Oct 25. Global: Ransomware operations pose increased security risks to data-rich, high-profile sectors. On 26 October, international news outlets reported that a ransomware group (‘Everest’) has targeted at least three high-profile organisations in data-leak and extortion operations. Earlier in October, the group reportedly infiltrated the systems of a recruitment platform used by the US-based telecommunications company AT&T in order to exfiltrate approximately 576,000 applicant records. On 21 October, Everest published some of this stolen data on the dark web, demanding a ransom payment within four days to prevent the public release of the entire dataset. Throughout October, Everest has also claimed attacks on Dublin Airport (DUB, Ireland) and on the UAE-based airline Air Arabia, highlighting the pace and resources of its operations. Everest has published partial datasets allegedly stolen during these attacks, underscoring the risk of follow-on social engineering attacks if the data is released. These incidents showcase the increased security, data-theft and financial risks facing data-rich sectors amid the continued expansion of ransomware operations. (Source: Sibylline)

 

29 Oct 25. Lockheed Martin (NYSE: LMT) and Google Public Sector today announced a strategic collaboration to integrate Google’s advanced generative AI, including its Gemini models, into the Lockheed Martin AI Factory. This collaboration will deploy Google’s powerful AI tools within Lockheed Martin’s secure, on-premises, and air-gapped environments, making them available to personnel across the enterprise. It is designed to empower Lockheed Martin’s teams to harness advanced, data-driven solutions, while ensuring all operations adhere to the highest security and mission assurance requirements essential for national security applications.  The collaboration will enable the Lockheed Martin AI Factory team to apply generative AI to tackle workloads with greater speed and efficiency, developing safe, secure, and trustworthy AI to advance 21st Century Security® solutions across sectors such as aerospace, space exploration, and cybersecurity, including:

  • Accelerated multi-modal data analysis: Rapidly processing and analyzing vast datasets to identify patterns, anomalies, and critical insights in minutes rather than days.
  • Advanced research and development: Streamlining exploration of novel materials, designs, and software to accelerate technology development cycles.
  • Optimized logistics: Improving supply chain management and logistical planning through intelligent resource allocation and route optimization.

“Collaborating with Google Public Sector to bring Gemini onpremises underscores our commitment to delivering cuttingedge, secure AI capabilities that directly support our missioncritical programs. This initiative equips our engineers with powerful tools—safely and at scale—to accelerate innovation in support of our business and critical missions,” said Greg Forrest, Vice President of AI Foundations and Commercialization at Lockheed Martin.

In the first phase, Google’s generative AI technologies will be integrated into Lockheed Martin’s unclassified on-premise environment, providing Lockheed Martin’s workforce access to Google’s suite of AI tools using Google Gemini on Google Distributed Cloud.

“Our collaboration with Lockheed Martin is a testament to our joint commitment to bringing the power of generative AI to meet the needs of our public sector customers,” said Jim Kelly, Vice President of Federal, Google Public Sector. “We are proud to take yet another industry-leading step with Lockheed Martin to deploy the most advanced AI tools to support government agencies, while adhering to the absolute highest standards of security and data governance.”

 

29 Oct 25. Royal Marines Fully Field Persistent MPU5 Radios Empowering the UK Commando Force Modernization Initiative.

  • Royal Marines field 2,000+ MPU5 radios, entering a new phase of large-scale operational deployment and collaboration with allied forces
  • Wave Relay MANET technology creates a global communications fabric, enabling the Royal Marines to dominate in contested environments

Persistent Systems, LLC (“Persistent”), a leader in mobile ad hoc network (MANET) technology, announced that the UK Royal Marines have now fully fielded over 2,000 MPU5 radio systems in support of their UK Commando Force (UKCF) transformation. This marks a significant step in the Royal Marines’ move toward a more agile, technology-enabled expeditionary force. MPU5 radios, running the Wave Relay® MANET, now form a highly scalable communications fabric uniting warfighters, unmanned systems, sensors, vehicles, and command posts. This deployment enables the Royal Marines to operate with greater autonomy, speed, and lethality in contested electronic warfare (EW) environments. The Royal Marines are divesting from legacy government-only systems and embracing commercial, non-ITAR defense technology. This makes their force more interoperable with allies and places the UK at the forefront of multinational collaboration.

“True interoperability is about more than just working with allies. It’s about uniting every Marine, every vehicle, and every sensor into a single resilient network,” said Eve Shapiro, Senior Director of Sales and Business Development at Persistent. “With the Wave Relay MANET, the Royal Marines can execute complex, distributed operations while maintaining constant connectivity and situational awareness.”

The UKCF represents the most significant modernization of the Royal Marines since WWII, aimed at creating a globally deployable, autonomous littoral force. It emphasizes small, lethal teams, unmanned and AI-enabled systems, and networked C4ISR capabilities. The MPU5 rollout, awarded to Persistent’s UK partner & distributor, Steatite Ltd., which includes handheld units and vehicle kits, supports UKCF’s operational demands across land, sea, and unmanned domains. Integration with platforms like all-terrain vehicles and unmanned systems enables uninterrupted connectivity regardless of terrain or mission set. (Source: ASD Network)

 

29 Oct 25. Datakey Mini-Bar: The World’s Smallest Crypto Ignition Key Now Available. ATEK Access Technologies has announced the availability of its new Datakey Mini-Bar series, the world’s smallest Crypto Ignition Key (CIK) portable memory system. Samples are now available, and orders are being accepted. A Crypto Ignition Key is a portable memory device used as a credential to enable or disable cryptographic equipment. Since producing its first CIK in 1986, Datakey portable memory products have continuously evolved to meet the changing needs of cryptographic systems. One of the most significant trends in these devices has been the ongoing reduction of size, weight, and power (SWaP). In 2009, Datakey introduced the Bar series, offering a compact CIK solution for tactical environments. Today, the new Mini-Bar form factor takes that innovation even further, being 60% smaller than the Bar series while still meeting the same MILSTD- 810 environmental specifications. Measuring just 21 mm x 15 mm, the Mini-Bar memory token is only slightly larger than a microSD card yet remains easy to handle. Mini-Bar memory tokens are available with serial EEPROM in 16 Kbit and 256 Kbit capacities, using either SPI or I²C interfaces. Models featuring Microchip’s CryptoAuthentication™ secure memory ICs are coming soon. Customized Mini-Bar tokens using customer-specified ICs will also be offered. The unique design of Mini-Bar receptacles allows them to be integrated into the corner of a housing, thereby minimizing the amount of volume required inside the enclosure while also minimizing the front panel space needed. Mini-Bar receptacles are offered with two different internal interfacing options:

  • The MBRHN Mini-Bar receptacle features an 8-pin header connector and measures

16.3 mm x 15.8 mm x 13.7 mm.

  • The MBRFN Mini-Bar receptacle features seven flat targets and measures

16.3 mm x 15.8 mm x 9.1 mm and is designed for use with an FFC/FPC interface board.

Both receptacles are offered with or without an adhesive gasket and can achieve an IP67 seal when properly mounted.

“The Mini-Bar employs the same proven design as its predecessor, the Bar—slide-in/slide-out operation, corner-mounting, and MIL-STD-810 environmental performance, but is more than 60% smaller,” said Paul

Plitzuweit, Senior Product Manager for the Datakey line. “This makes the Mini-Bar an ideal choice for nextgeneration cryptographic devices that have portable or embedded use cases. But the Mini-Bar is not limited to CIK applications. Any embedded system that requires a robust removable memory device for access control or data transfer applications could benefit from these revolutionary new products.” Customers in North America can now request samples and place orders through ATEK Access Technologies at https://datakey.com/. Customers outside of North America can find their authorized Datakey distributor at https://datakey.com/where-to-buy.

 

29 Oct 25. Germany to equip Quadriga jets with Eurofighter EK suite. Germany is to equip a portion of its Project Quadriga jets with an emitter locator system (ELS) and anti-radiation missile as part of the Luftwaffe’s wider Eurofighter Elektronischer Kampf (EK) electronic attack plans. A spokesperson for the Luftwaffe told Janes on 28 October that the previously announced plan to modernise 15 existing Eurofighter jets to the Eurofighter EK standard alongside 20 recently contracted newbuild Tranche 5 aircraft will be achieved by modernising some of the 38 Tranche 4 Quadriga aircraft now being assembled.

“The current plan is to contractually equip 15 Eurofighters from Quadriga and the newly ordered 20 Eurofighters (Tranche 5) with Arexis,” the spokesperson said, firming up the service’s plans, which had previously referred only to upgrading “existing jets” and newbuild Tranche 5s to the Eurofighter EK role.

For the Step 1 Eurofighter EK upgrade now under contract, the 15 Tranche 4 and 20 Tranche 5 aircraft will be equipped with the Saab Arexis ELS and Northrop Grumman AGM-88E Advanced Anti-Radiation Guided Missile (AARGM) for the suppression of enemy air defences (SEAD)/destruction of enemy air defences (DEAD) role. The Luftwaffe has previously told Janes that the Step 2 process to follow adds an Escort Jammer Pod for increased jamming power in the SEAD/DEAD role, as well as potentially manned-unmanned teaming and other high-end capabilities. The Eurofighter EK will enable the Luftwaffe to gradually transfer the capabilities of the Panavia Tornado Electronic Combat and Reconnaissance (ECR). (Source: Janes)

 

27 Oct 25. Today, Intel 471, the premier provider of cyber threat intelligence-driven solutions worldwide, delivers the newest release of its Geopolitical Intelligence solution to its Verity471 platform. This enhanced offering provides users with structured, actionable insights on countries and global issues to help organizations manage the impact of these dynamics on business operations, assets, stakeholder safety and strategic endeavors, all within its unified cyber intelligence platform.  According to the World Economic Forum, nearly 60% of organizations state that geopolitical tensions have affected their cybersecurity strategy. Geopolitics shape state and non-state threats in the cyber and physical domains, requiring organizations to continuously monitor areas of interest that affect their business operations and supply chain. Intel 471’s Geopolitical Intelligence provides a unique lens into significant regional events, including changes in policy, leadership and technology, that enable organizations to anticipate risk, swiftly identify threats and take decisive action.

“Within the nexus of complex cyber threat landscapes and heightened geopolitical tensions, it is imperative that organizations understand their exposure to regional threats, along with threats to their suppliers, subsidiaries and M&A activities,” says Michael DeBolt, Chief Intelligence Officer at Intel 471. “Our enhanced solution, available via our next-generation cyber intelligence platform, connects the dots between cybercrime, nation-state operations and geopolitical developments. As a result, security teams and intelligence professionals can move beyond siloed threat feeds to proactively mitigate risks to their organization’s attack surface.”

Geopolitical Intelligence leverages Verity471’s user-friendly interface, AI Reports Assistant and intuitive navigation to deliver rapid situational awareness, transparent country-specific risk scores and seamless connections between geopolitical events, nation-state actors, cyber underground activity and threat hunting operations. Additional core capabilities of the solution include:

  • Comprehensive, contextualized view of an organization’s threat landscape: Intel 471’s expert analysts deliver nuanced, actionable geopolitical intelligence, providing organizations an intelligence advantage across the global geopolitical environment, conflicts, policy decisions, major events and high-level activity from state-linked cyber threat groups.
  • Organized intelligence framework: Analysis in eight event categories – Social, Economic, Military, Political, Legal, Information and Technology, Cyber, and Environmental (SEMPLICE) – provide a framework for categorizing and organizing global events to ensure intelligence is relevant and easy to consume.
  • Timely, actionable insights into global events: Daily Significant Activity (SIGACT) reports provide a concise event summary and expert analyst commentary on complex global events to clearly identify associated cyber campaigns stemming from geopolitical events.
  • Picture intelligence summary (PICTINSUM): PICTINSUM plots SIGACT reports by location and SEMPLICE category, enabling pin-point visualization of an organization’s threat landscape and the ability to identify trends in incidents.
  • Country-specific baseline threat ratings and security assessments: Intelligence Estimate reports deliver baseline threat ratings and security assessments for over 50 countries to help organizations strengthen internal data protection policies, support business growth, and confidently manage employee safety and third-party risk.

“One of the greatest benefits of the Geopolitical Intelligence offering is the talented team of analysts behind our insights,” adds DeBolt. “Our team is composed of regional subject matter experts who provide an unmatched wealth of cultural knowledge, native-level language capabilities and deep experience conducting doctrinal intelligence community-grade analytical methodologies. Integrating Geopolitical Intelligence into our existing portfolio – including our unparalleled human intelligence (HUMINT) and malware intelligence capabilities – enriches our insights and adds a layer of depth and nuance that automated systems alone cannot replicate. Armed with this fully contextualized intelligence picture, security teams can anticipate, understand and act, with greater speed and confidence.”

To learn more about the latest version of Geopolitical Intelligence, visit https://www.intel471.com/platform/cyber-geopolitical-intelligence

About Intel 471

Intel 471 empowers enterprises, government agencies, and other organizations to win the cybersecurity war using the real-time insights about adversaries, their relationships, threat patterns, and imminent attacks relevant to their businesses. The company’s platform collects, interprets, structures, and validates human-led, automation-enhanced intelligence, which fuels our external attack surface and advanced behavioral threat hunting solutions. Customers utilize this operationalized intelligence to drive a proactive response to neutralize threats and mitigate risk. Organizations across the globe leverage Intel 471’s world-class intelligence, our trusted practitioner engagement and enablement, and globally dispersed ground expertise as their frontline guardian against the ever-evolving landscape of cyber threats to fight the adversary — and win. We are the source of reason and truth into the cybercriminal underground. Learn more at www.intel471.com. (Source: BUSINESS WIRE)

 

27 Oct 25. Middle East, North Africa and Turkey: Government, CNI sectors face long-term cyber espionage risks. On 24 October, international news outlets reported that an Iranian state-sponsored group (‘MuddyWater’) targeted more than 100 government and critical national infrastructure (CNI) entities in a suspected cyber espionage operation in August. MuddyWater distributed phishing emails to trick victims into opening a malicious Microsoft Word document. The document requested user input to execute a Visual Basic for Applications (VBA) macro that subsequently installed a malware loader (’FakeUpdate’) and a known backdoor (‘Phoenix’) onto compromised systems. In this operation, MuddyWater used a new version of Phoenix to gather system information and establish communication with command-and-control (C2) infrastructure, before employing a custom information-stealing payload to exfiltrate browser credentials, showcasing increased data theft risks for the government and CNI sectors. The campaign primarily targeted telecommunications companies, embassies, diplomatic missions, consulates and ministries of foreign affairs; due to this choice of targets, we assess that the operation was likely aimed to monitor and obtain strategic information. MuddyWater typically prioritises maintaining prolonged persistence during its operations, highlighting the long-term infection risks for government entities and CNI operators from Iranian threat actors amid ongoing geopolitical hostilities. (Source: Sibylline)

 

24 Oct 25. Cyber Update

Key points

  • Increased artificial intelligence (AI)-related cyber activity will sustain security risks to strategic targets from state-sponsored groups (see Sibylline Cyber Daily Analytical Update – 20 October 2025).
  • The large-scale outages that affected the cloud computing platform Amazon Web Services (AWS) underscore operational risks from concentrated third-party vendors (see Sibylline Cyber Daily Analytical Update –  21 October 2025).
  • The telecommunications sector in Europe faces long-term cyber espionage risks from the Chinese state-sponsored group ‘Salt Typhoon’ (see Sibylline Cyber Daily Analytical Update – 22 October 2025).
  • Regional government and war-relief entities in Ukraine face heightened cyber espionage risks amid the ongoing war (see Sibylline Cyber Daily Analytical Update – 23 October 2025 and our Technical analysis below).
  • European drone and unmanned aerial vehicle (UAV) companies face long-term cyber espionage risks from the North Korean threat actor ‘Lazarus’ (see Sibylline Cyber Daily Analytical Update – 24 October 2025).

Technical analysis of weekly stories

A cyber espionage operation called ‘PhantomCaptcha’ targeted Ukrainian regional government administrations and NGOs involved in war relief efforts during October. Preparations for the campaign reportedly started in March and continued through to October, even though the campaign itself was active for only one day, highlighting its pre-meditated and highly methodical nature. Threat actors distributed phishing emails, impersonating the Ukrainian president’s office to trick victims into opening an embedded PDF attachment. The attachment contained a conference link for the video-meeting platform Zoom that redirected users to a fake CAPTCHA verification page. This link established communication with the actors’ command-and-control (C2) infrastructure.

The next stage of the attack was twofold. In the first path, only users with an identifier that matched the actors’ instructions were taken to a legitimate, password-protected Zoom meeting. It is likely that threat actors intended to use social engineering techniques to obtain sensitive information during the meetings, though this attack path was not actively implemented. Conversely, the second attack path used ClickFix techniques to coerce victims into copying and pasting a token (after completing the fake CAPTCHA verification) that covertly executed a first-stage PowerShell script, thereby exploiting user execution to evade detection by security protections. The PowerShell script then initiated a multi-stage process to download the main payload after an obfuscated malware loader and a second-stage payload. Afterwards, the second-stage payload performed system reconnaissance (collecting information such as the computer name, domain information and hardware identifiers), while the main payload acted as a remote access trojan (RAT) facilitating data exfiltration and remote command execution. While PhantomCaptcha has not been attributed to any cyber threat groups, the campaign was reportedly linked to another Russian state-sponsored surveillance operation; it was operated from Russia-based infrastructure. The group targeted Android users in Lviv (Lviv oblast) to gather specific data (such as contacts, call logs, images and live location data), showcasing its targeted nature. The obfuscated and methodical approach of this campaign suggests that its perpetrators are likely highly sophisticated and knowledgeable.

Non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware.
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.

Our cyber word of the week: ClickFix attack

Definition: A technique whereby threat actors attempt to execute malicious command solely via social engineering techniques, in order to enhance obfuscation. (Source: Sibylline)

 

24 Oct 25. Europe: Drone, UAV companies face long-term cyber espionage risks from North Korean threat actors. On 23 October, the European software company ESET reported that a renowned North Korean state-sponsored group (‘Lazarus’) targeted at least three European drone and unmanned aerial vehicle (UAV) production companies in a cyber espionage operation in March. Reportedly, Lazarus used phishing emails and other social engineering techniques as initial attack vectors in order to trick victims into opening a PDF attachment. The group then executed a multi-stage deployment process that ultimately downloaded a known remote access trojan (RAT; ‘ScoringMathTea’) onto compromised systems to obtain remote control capabilities. Lazarus also disguised its malware loaders as legitimate software, enhancing their legitimacy and highlighting the group’s skillset. This campaign constitutes the latest iteration of ‘Operation DreamJob’, a long-term cyber espionage campaign first uncovered in 2020 that aims to collect sensitive military data and to strengthen Pyongyang’s security posture. As a result, we assess that this report underscores the long-term cyber espionage risks facing businesses in the drone and UAV production sector. (Source: Sibylline)

—————————————————————————————————————————————————————————————————————————————————————————————————————————————

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

—————————————————————————————————————————————————————————————————————————————————————————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

October 24, 2025 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

——————————————————————————————————————————————————————————————————————————————————————————————————————————————

23 Oct 25. Enhancing UAV Mission Control with LS Electronics SoftRadio. LS Electronics’ SoftRadio provides UAV operators with a flexible, IP-based dispatch system that supports reliable communication, hybrid radio integration, and remote mission coordination Radio Over IP (ROIP). LS Electronics, a specialist in mission-critical communication systems, offers the SoftRadio platform to meet the complex requirements of Unmanned Aerial Vehicle (UAV) operations. As UAVs continue to play a growing role in public safety, border surveillance, and infrastructure monitoring, operators require communication systems that combine flexibility with reliability across distributed networks. Conventional dispatch setups, designed for fixed installations, are often unsuited to the fluid and mobile nature of these missions. SoftRadio delivers a virtual dispatch environment with IP-based network connectivity and hybrid radio support, allowing UAV teams to maintain efficient communication and enhanced situational awareness wherever operations take place.

Flexible Deployment and Remote Accessibility

SoftRadio enables UAV ground operators to access and manage radio networks from any connected location, removing the constraints of centralized control rooms. The system can be operated from a command center, mobile platform, or temporary field base using a standard PC or tablet connected to the internet.

This capability supports a range of operational scenarios, including:

  • Search and rescue coordination
  • Disaster monitoring and emergency response
  • Border and remote-area surveillance
  • Temporary deployments and training exercises

With compatibility for both analog and digital radios, the software provides a consistent and unified interface across mixed communication infrastructures.

Built for Critical and Demanding Environments

SoftRadio incorporates tools specifically suited to high-reliability missions, offering:

  • Remote radio operation with multiple simultaneous audio streams
  • Integrated GPS mapping through Mimer MapView for live location tracking
  • Voice logging and AI-powered transcription for mission documentation
  • Minimal hardware demands, simplifying setup and reducing equipment costs

Its modular framework allows integration with existing communication networks and supports scalable expansion as mission requirements evolve.

Reliable Communication for Air and Ground Teams

SoftRadio provides a unified environment for communication between UAV operators and ground-based teams, ensuring consistent coordination in both autonomous and human-directed operations. Whether managing surveillance missions, assisting emergency responders, or overseeing airspace activities, the system maintains reliable communication links across all participants. Through its combination of virtual dispatching, hybrid radio interoperability, and secure IP-based connectivity, LS Electronics’ SoftRadio offers a dependable and adaptable communication capability for the distributed operations that define today’s UAV missions. (Source: https://www.defenseadvancement.com/)

 

23 Oct 25. A Force Multiplier for High-Frequency Communications: The L3Harris ARGUS-HF. The new solution is industry’s first multi-channel receiver available for L3Harris’s resilient tactical high-frequency data waveforms. Long-range High Frequency communication has undergone a dramatic digital modernization effort within L3Harris Technologies. An innovative new entry into the company’s Falcon® HF portfolio is smaller, faster and easier to use while providing reliable, beyond-line-of-sight and on-the-move data communications in congested and contested environments. The new L3Harris ARGUS-HF™ system enhances the capability of L3Harris resilient data waveforms by providing the ability to listen and receive on 16 different HF frequencies concurrently, as opposed to the single-channel capability provided by the radio itself. This reduces the coordination required for a successful HF connection, ensuring multiple elements can contact users concurrently with no important messages missed. It can be operated as a standalone receive device or integrated directly with a Falcon III HF system. In addition, its web interface provides access to web messaging and to a live spectrograph view of HF frequencies.

“L3Harris built its foundation on HF communications 60 years ago, and we have been innovating ever since, adding new technology and resiliency to support and enhance our customers’ PACE (Primary, Alternative, Contingency & Emergency) options. Our new ARGUS-HF solution allows for faster and more-informed resilient HF decisions, and the device seamlessly integrates into the Falcon III HF family of products for instantaneous access to new capabilities.” Chris Aebli, President, Tactical Communications, L3Harris

The multi-channel receiving capability of ARGUS-HF allows simultaneous monitoring and reception of multiple frequencies, enhancing situational awareness and operational flexibility. This capability is particularly valuable in situations when spectrum availability and interference management are critical, according to Brian Calvasina, Product Manager, L3Harris. ARGUS-HF integrates advanced technology to overcome HF signal propagation and interference challenges and leverages L3Harris’ proprietary Last Ditch Data resilient waveform family to ensure device and network protection, added Calvasina. The new receiver’s ability to monitor multiple resilient waveform channels simultaneously provides an ideal solution in dynamic environments, especially in scenarios requiring robust and reliable HF communications, such as military operations, emergency response and remote field communications. These advances to venerable HF technology – notably ARGUS-HF’s simultaneous and resilient HF data inputs – ensure beyond-line-of-sight common operational picture connectivity in satellite-denied environments. Coupled with the ARGUS-HF’s resilient data tools, the system delivers enhanced BLOS situational awareness for more-informed, data-driven tactical decisions – an important complement to next-generation command-and-control modernization efforts. L3Harris HF systems, including ARGUS-HF and the AN/PRC-160, deliver assured voice and data, even in the most austere environments, providing powerful connectivity options to support the next generation of communications infrastructure.

“ARGUS-HF’s advanced radio-frequency spectrum monitoring capabilities and the ability to receive multiple waveforms simultaneously enhances the ability to detect, analyze and respond to a wide range of signals, providing a significant operational advantage,” said Calvasina. “Having a larger number of channels can help ease communication planning where multiple frequencies can be monitored, as well as channel selection based on time of day or other environmental conditions.”

Innovative engineering, extensive testing and leveraging leading-edge technology ensured L3Harris designed a high-performance and reliable solution that effectively manages simultaneous multi-channel HF signal processing while minimizing interference, said Calvasina. ARGUS-HF will enter into full-rate production in 2026.

“ARGUS-HF represents a signification advancement in HF communication technology,” said Calvasina. “It offers unparalleled capabilities in multi-channel reception, spectrum monitoring and operational flexibility. ARGUS-HF’s design meets the demanding requirements of modern communication environments and provides a strategic advantage in a multitude of applications.” (Source: ASD Network)

 

23 Oct 25. Asio, a pioneer in tactical combat solutions, in collaboration with Israel’s Ministry of Defense Directorate of Defense Research and Development (DDRD), the IDF Intelligence Directorate, and the IDF Ground Forces Command, has completed the development and significant upgrade of Taurus (known in the IDF as “Noam”), an advanced tactical battle management computer designed for battalion intelligence officers. Asio will supply hundreds of these tactical intelligence systems to the IDF. The system delivers critical intelligence information directly to front-line units, enables operational autonomy at the battalion level, and provides commanders with advanced tools for terrain analysis, intelligence collection from drones and sensors, and for generating combat plans and targets under dynamic battlefield conditions. It provides autonomy to battalion intelligence officers and real-time access to updated intelligence data on the battlefield. A key new capability added to Taurus enables real-time creation of 3D terrain models: a drone scans the operational area and instantly generates an accurate, photo-realistic model. This capability has become central to the IDF’s evolving intelligence doctrine, giving commanders immediate visual understanding of the battlefield and enabling mission planning based on current terrain data. Taurus operates alongside the IDF’s widely deployed Orion system (known in the IDF as “Olar”), which supports mission management across tens of thousands of maneuvering forces, from squad leaders to battalion commanders. While Orion provides real-time intelligence access across the force, Taurus gives battalion intelligence officers the ability to perform 3D mapping, situational assessments and mission planning directly from the field. The system operates intuitively, allowing units to work independently with up-to-date and relevant information. Commanders at the battalion level, from sergeants to battalion leaders, gain full autonomy to conduct terrain analysis, perform 3D calculations, and assess operational situations directly from the field, without dependence on central systems or communications. The system also enables simultaneous updates to dozens of Orion systems – including map layers, apps, and large-scale intelligence data updates at record speed – while integrating with additional IDF systems. Upcoming enhancements will allow commanders to manage and monitor operations through a unified interface directly within the Taurus platform.

Head of the DDR&D R&D Division, Brig. Gen. Yehuda Elmakayes: “As part of the ongoing effort to advance network-centric warfare for ground forces, we have invested in developing advanced mapping infrastructures with an emphasis on the tactical edge. Orion provides advanced mapping tools directly to the soldier, while Taurus enables real-time mapping updates in response to the rapidly changing battlefield. The next step is to link Orion to the digital ground forces ecosystem, ensuring operational continuity through C4I systems. Another key integration is the Lynx system, which offers advanced situational awareness and rapid targeting capabilities.”

Tomer Malchi, Founder & CEO of Asio Technologies: “The deployment of Taurus marks a significant advancement in tactical battlefield intelligence. By delivering real-time, mission-critical data directly to front-line units – including 3D terrain modeling and other capabilities – we’re providing intelligence autonomy and ground dominance, contributing to safer and more effective mission completion. This system was developed in close partnership with Israel’s defense establishment and represents our shared commitment to providing combat units with the tools they need to operate effectively in dynamic, high-threat environments.”

The Orion system is critical to maintaining the IDF’s ground superiority against threats such as Hamas, Hezbollah, and other regional adversaries. It enables advanced mission planning, including terrain and line-of-sight analysis, navigation route design, and combat position planning. Orion supports a wide range of advanced features such as 3D modeling and augmented reality (AR). Its Android-based interface, the size of a smartphone, makes it highly effective under combat conditions. The Orion family also includes Lynx (known in the IDF as “Maayan”), a tactical augmentation binocular system. Orion was developed through collaboration between Asio, the Ministry of Defense (DDRD), and multiple IDF branches – including the Intelligence Directorate, Ground Forces Command, C4I and Cyber Defense Directorate, and the IDF Mapping Unit.

About Asio: Asio develops combat-proven solutions that ensure operational independence for tactical forces. Its portfolio includes mission-enhancement systems, jam-proof and drift-free self-positioning for aerial platforms, advanced target acquisition, and north-finding technologies, all powered by its proprietary GeoFusion™ core. ASIO systems are deployed by IDF units and defense customers worldwide https://asiotech.com/.

 

21 Oct 25. TEKEVER and Avantix Sign Strategic MoU to Strengthen French and European EW and SIGINT Capabilities. A new partnership to study the integration of Avantix’s Electronic Warfare (EW) and Signals Intelligence (SIGINT) systems on TEKEVER platforms. TEKEVER has signed a Memorandum of Understanding with Avantix, an Eviden (Atos Group) company, to accelerate the integration of advanced French EW and SIGINT systems into TEKEVER platforms. Signed during UAV Show 2025 in Bordeaux, this MoU formalises a long-term technical collaboration between the two companies. Its aim is to assess and demonstrate the interoperability of TEKEVER systems with Avantix payloads, including compact tactical SIGINT sensors. This cooperation will lead to the development of modular, resilient, integrated ISR solutions for defence and homeland security applications. As an integrator of cutting-edge and mission-critical technology, TEKEVER continues to strengthen its position as a European leader in autonomy, artificial intelligence and airborne innovation, designing sovereign, autonomous and operational solutions that meet the evolving needs of its customers. This strategic step forms part of TEKEVER’s €100m investment plan in France, announced at the Choose France 2025 event. France is becoming a major hub for TEKEVER’s activities in Europe, with growing R&D, production, testing and operational support capabilities across both civil and military sectors.

Nadia Maaref, Managing Director of TEKEVER France, commented: “This is a major milestone in TEKEVER’s industrial and technological development in France. Through this partnership with Avantix, we are reinforcing our ability to integrate the most advanced electronic warfare and signals intelligence technologies into our systems, ensuring that our customers have access to the best-adapted tools for their missions. It further highlights our long-term commitment to innovation, collaboration and talent in France.”

Bernard Payer, Managing Director of Avantix, added: “This partnership with TEKEVER is a turning point in expanding our EW and SIGINT solutions across new UAVs and airborne platforms. By combining our compact SIGINT payloads with TEKEVER’s proven expertise in autonomous systems, we can jointly deliver superior integrated airborne SIGINT solutions to enhance situational awareness, accelerate decision-making and increase resilience during critical operations — strengthening sovereign strategic drone capabilities for France and Europe.” (Source: ASD Network)

 

22 Oct 25. Integrated Battle Command System Proves Performance in Flight Test. Since 2015, IBCS has successfully executed 32 of 32 flight tests.

In August, a successful flight test demonstrated the operational capabilities of the U.S. Army’s Integrated Battle Command System (IBCS), featuring advanced software and hardware developed by Northrop Grumman Corporation (NYSE: NOC). This milestone marked the first live-fire demonstration using IBCS’ Low-Rate Initial Production (LRIP) hardware, which is now being deployed to Europe and the Indo-Pacific.

  • The test scenario involved a simulated air breathing target which was effectively tracked and classified by IBCS and the in development Lower Tier Air and Missile Defense Sensor (LTAMDS).
  • IBCS calculated how to engage the target and then successfully defeated it using a Patriot Advanced Capability 3 Missile Segment Enhancement interceptor.

Kenn Todorov, vice president and general manager, command and control weapons integration, Northrop Grumman: “This decisive test solidifies IBCS as the solution for meeting the critical integrated air and missile defense demands of U.S. and allied warfighters on a global scale. The seamless integration and outstanding performance exhibited demonstrates IBCS’ readiness to operate in the most complex threat environments worldwide, strengthening international security and domestic defense initiatives.”

Northrop Grumman, a trusted innovator with a legacy of disruption, recently completed major end item deliveries under its LRIP contract with the Army and will manufacture IBCS under a full-rate production contract in Huntsville. The new Enhanced Production and Integration Center (EPIC) builds on the company’s ability to scale production and manufacture critical capabilities at speed, expanding capacity for high-rate production programs. IBCS is a revolutionary system that delivers fire control quality and battle management, unifying current and future systems regardless of source, service or domain. Through its network enabled, modular, open and scalable architecture, IBCS fuses sensor data for a single, actionable picture of the full battlespace. This ready-now capability gives warfighters more time to make decisions on how best to defeat threats and is a foundational element for enabling joint and coalition, multi-domain operations. IBCS is in production, currently fielded in Poland and planned for fielding in Combatant Commands in Europe and the Indo-Pacific as part of the U.S. Army program of record for integrated air and missile defense modernization. In September, Poland’s Ministry of National Defense conducted a successful operational exercise for its IBCS-enabled WISLA medium-range air defense system. This achievement highlights the exceptional collaboration between Poland and the United States and Northrop Grumman’s dedication to advancing allied defense modernization. (Source: ASD Network)

 

20 Oct 25. Atos, a leading provider of AI-powered digital transformation, has announced a holistic new approach to delivering people-first digital sovereign and agentic AI capabilities across its end-to-end IT service portfolio. Its new suite of services provides the building blocks for companies to have a tailored, resilient, and future-ready approach that enables fast and easy adaptation to evolving regulations, geopolitical pressures and unique operational needs.  The three hubs will address the growing demand for UK-based IT delivery, data hosting and resiliency for public sector, defence and critical national infrastructure (CNI) businesses.

Sovereign Orchestration Hub

The Sovereign Orchestration Hub will be a state-of-the-art, sustainably built delivery centre. It will leverage Atos’ 30 years of engineering heritage to provide an AI-enabled suite of offerings that build upon its existing sovereign capabilities, including the Atos Sovereign Cloud portfolio. The Hub will provide cutting-edge, resilient Sovereign Cloud-on-site solutions, AI-driven Digital Workplace services, Sovereign Extended Device Lifecycle Services (beyond net-zero), Sovereign Bridge and a converged Network Operations Centre / Security Operations Centre capability. This will give clients unparalleled monitoring and management with a single view of their IT and OT environments, facilitating proactive issue resolution and increasing efficiency, security and resilience. The Hub will set new standards for secure, compliant and scalable technology innovation, centered around digital sovereignty as a vital component of the UK&I’s technological resilience and strategic autonomy.

Digital Agentic Centre

Atos’ Digital Agentic Centre will host and manage sovereign AI capabilities to offer clients autonomy, security and data sovereignty to meet their AI requirements. It will revolutionise Application Services to pursue +50% automation in engineering, testing and DevOps services, significantly reducing operational costs and time-to-value. These efficiencies will free up capital to help clients accelerate their digital transformation journeys and the use of agents will make services more intelligent, resilient and adaptable to future demand. Using modern AI-powered Application Services, sustainability, green IT and social value initiatives, the Centre will provide clients with a unified, consistent, standardised application portfolio, tailored to their individual requirements.

Sovereign Digital Enablement Centre

Atos’ Sovereign Digital Enablement Centre (DEC) is designed to support faster ICT delivery and innovation across defence and critical national infrastructure. The Centre acts as an accelerant for mission-critical digital solutions, enabling rapid and secure building, testing and assurance in a collaborative sovereign environment. Supported by key partners, Microsoft and AWS, the DEC will provide a trusted space where SMEs, academia and larger industry players can innovate and test new technologies at speed. The Centre will foster a sandbox approach that accelerates secure delivery and strengthens sovereign digital capabilities across the UK.

People-First AI-Proofed Careers

In line with these developments, Atos is reinforcing its commitment to developing diverse talent by increasing the number of graduates and apprentices it hires, offering AI-proofed career paths with flexible practices available such as term-time contracts. Rather than training in just one field of technology, new recruits will gain hands-on experience across AI, cloud, cybersecurity, data analytics, and digital services. This approach ensures individuals grow alongside AI, building resilient careers that evolve with technology rather than compete with it.

Atos will welcome the first cohort of around 50 new early-career employees in its centres in 2026.

Michael Herron, Head of Atos UK&I, said, “Our new sovereign offerings will ensure our clients have a future-ready end-to-end IT estate under their control so that they can easily adapt to any regulatory or geopolitical changes. For businesses in the public, defence and critical national infrastructure sectors, the need for sovereign AI capabilities is mission-critical, and we’re proud to be working with them to make safe and reliable digital and AI development possible.

“As part of this, we are reimagining what an IT career pathway looks like in an age where humans and AI co-exist together. Our new early-career roles will give young people in the UK a multi-faceted career in the digital arena. Sovereignty, for us, includes nurturing the next generation of tech talent in the UK&I.”

 

20 Oct 25. Global: Increased AI-related cyber activity will sustain security risks from state actors. On 17 October, the US-based technology company Microsoft reported that cyber threat actors are incorporating artificial intelligence (AI) into cyber operations at an increased rate. State-sponsored actors have reportedly used AI to spread misinformation and disinformation on their perceived adversaries, automating cyber attacks and boosting the sophistication of social engineering campaigns. Organisations in the US constitute the primary target for AI-enabled operations, while Israel and Ukraine remain the second and third most popular targets; this underscores the likely nexus between geopolitical developments and cyber attacks. Microsoft’s report also noted that state-sponsored actors affiliated with China, Iran, North Korea and Russia have used AI to create online content in at least 200 instances – over double the number registered in July 2024. Given the rapid growth of this trend, we assess that this will sustain the security risks posed by the increased adoption of AI technologies to global organisations. (Source: Sibylline)

 

17 Oct 25. Global: New malware campaign poses increased security, data theft risks to key industries. On 15 October, the US-based cyber security company Palo Alto Networks reported that unnamed threat actors are targeting key industries in a multi-stage data theft campaign. The campaign distributes phishing emails purporting to provide information on upcoming payments and/or legal actions, in order to trick victims into opening a malicious attachment. This attachment executes several obfuscated scripts that use steganography to deploy a malware loader (‘PhantomVAI’), showcasing the threat actors’ stealth attack capabilities. Upon deployment, PhantomVAI identifies the environment it is running in to evade detection by virtual machines (VMs) before establishing persistence, highlighting its sophistication. PhantomVAI then installs multiple information-stealing payloads, used to exfiltrate sensitive information, hijack user accounts and initiate fraudulent money transfers. Given the continuous development of the cyber threat landscape, we assess that key industries will continue to face increased security and data theft risks in the medium-to-long term. (Source: Sibylline)

 

17 Oct 25. Cyber Update

Key points

  • Russia’s dynamic cyber strategy will sustain security risks for government and defence entities amid the ongoing war in Ukraine (see Sibylline Cyber Daily Analytical Update – 13 October 2025).
  • A large-scale multi-country botnet highlights the increased short-term security risks to global businesses (see Sibylline Cyber Daily Analytical Update –  14 October 2025).
  • The adoption of a new persistence technique showcases the long-term security risks stemming from the Chinese state-sponsored group ‘Flax Typhoon’ (see Sibylline Cyber Daily Analytical Update – 15 October 2025).
  • A new attack pathway (‘Pixnapping’) raises short-to-medium-term exploitation risks to vulnerable Android users (see Sibylline Cyber Daily Analytical Update – 16 October 2025 and our Technical analysis below).
  • A new malware campaign will pose increased security and data theft risks to several key industries (see Sibylline Cyber Daily Analytical Update – 17 October 2025 and our Technical analysis below).

Technical analysis of weekly stories

Researchers have reported the discovery of Pixnapping, a new attack pathway that enables threat actors to steal sensitive data from vulnerable Android devices. After threat actors infiltrate a device, Pixnapping deploys a malicious application to launch targeted applications or webpages. This allows threat actors to exploit a software vulnerability (CVE-2025-48561) to load a secondary concealed window and to isolate the pixels that compose the page displayed on a victim’s screen. The pixels are then mapped and analysed to determine which ones are white and non-white, in an effort to simplify the next stages of the attack. Simultaneously, the secondary window operates in the background to recover isolated characters before adopting optical character recognition (OCR) techniques to differentiate characters and digits of interest. Threat actors then use graphical data compression to exfiltrate visual information to command-and-control (C2) infrastructure. This method can be used to steal credentials and authentication data from multiple legitimate applications, thereby facilitating account takeovers, financial theft and other illicit activities. This highlights Pixnapping‘s stealth and sophistication. Threat researchers have stated that the exfiltration of two-factor authentication (2FA) codes can take less than 30 seconds, highlighting Pixnapping’s rapidity despite the relatively low number of pixels exfiltrated per second.

Unnamed threat actors are targeting key industries in a multi-stage data theft campaign. The campaign starts with phishing emails that purport to provide information on upcoming payments and/or legal actions, in order to trick victims into opening a malicious attachment. The attachments contain obfuscated JavaScript and VBScript formats that in turn execute and decode a secondary PowerShell script. This script then downloads a GIF or another image file type, using steganography to deploy a malware loader (‘PhantomVAI’). PhantomVAI displays three main capabilities; it encompasses checking the system environment to avoid detection by virtual machines (VMs), establishing persistence and retrieving the final payload. The identified final payload encompasses several different information-stealers that are alternately deployed, depending on the operation. Reports on this campaign note that a new information-stealing payload (‘Katz Stealer’) has been used during the attacks, enabling comprehensive data exfiltration (including browser data, credentials, crypto currency wallets and other third-party data). We assess that threat actors intend to use the stolen data to hijack user accounts, initiate fraudulent money transfers and conduct other illicit activities.

Non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware.
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.

Our cyber word of the week: Steganography

Definition: A technique used by threat actors to conceal malicious code within legitimate-looking files and/or images. (Source: Sibylline)

—————————————————————————————————————————————————————————————————————————————————————————————————————————————

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

———————————————————————————————————————————————————————————————————————————————————————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

October 17, 2025 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

—————————————————————————————————————————————————————————————————————————————————————————————————————————————

16 Oct 25. The Wall.

An ‘incursion’ of Russian Uninhabited Aerial Vehicles (UAVs) in Poland on 8th September concentrated the minds of politicians and securocrats alike in free Europe. This was not the first time. Russian UAVs have a habit of landing in NATO territory. No less than 15 examples of Russian UAVs violating NATO airspace have been recorded since Russia’s second invasion of Ukraine commenced in February 2025. Most of these infringements have affected the airspace of Poland and Romania. Unsurprising then that the European Union (EU) is considering taking measures against these violations. Andrius Kubilius, the EU’s commission for defence and space, has mooted the construction of a so-called ‘drone wall’ to provide an impregnable shield against the Russian UAV menace. Exact details on the drone wall’s specifications are scant which is understandable given that the initiative has only just been announced. Mr. Kubilius did give some clues hinting that the defences would include sensors like radar and acoustic devices. Effectors would also form part of the mix. Presumably, this could include jammers to hit the radio links connecting the UAV to its pilot and blocking out global navigation satellite system signal reception. Kinetic effectors could include surface-to-air missiles and anti-aircraft artillery. As can be seen, electromagnetics will be fundamental to the drone wall. Ground-based air surveillance radars which can accurately detect, identify and track a UAV will be imperative. Not all such radars can do this: UAVs have low radar cross sections on account of their small physical size and largely non-metallic construction. However, specialist systems are available which use innovative approaches like micro-Doppler processing to determine the spinning blades of a UAV, and to discriminate it from other small flying objects like birds. Secondly robust, survivable, wideband communications are a must. NATO’s Eastern Flank might not face UAVs violating its airspace in piecemeal fashion. As the incident in Poland on 8th September illustrated, multiple aircraft may test the drone wall. Sensors will need to share their imagery to populate a rich recognised radar and electromagnetic picture to assist battle management. Moreover, these communications must be secure and survivable. It is not impossible to image Russian electronic warfare assets attempting to jam NATO radio communications while airspace violations are ongoing. A good approach would be to use civilian and military communications which are already in place. Local fifth-generation cellular networks have the bandwidth necessary to share bucket-loads of data. Conventional telecommunications and fibre optics have their part to play, as do deployed military communications networks. It is likely that EU and NATO member nations will deploy their own counter-UAV defences to the Eastern Flank as part of the drone wall, and they will bring their military communications with them.

A prudent approach of the EU to the drone wall’s construction would be to use as many assets as it already collectively possesses to form the constituent parts. This will help keep costs down and send a political message that the EU and NATO take collective responsibility for the drone wall. Using existing communications, military and civilian, and deploying additional capability where necessary, should form a key part of this approach. (Source: Armada)

 

16 Oct 25. Emulating Everything.

The DBRE heralds a step change in the fidelity, speed and density with which radio frequency emitters can be emulated. The technology may also help DARPA develop autonomous and digital twin technologies. This August, the United States’ DARPA unveiled the Digital Radio Frequency Battlespace Emulator which will greatly enhance how the agency recreates radio emitters. The Defence Advanced Research Projects Agency (DARPA) claims that the Digital Radio Frequency Battlespace Emulator (DRBE) is the “world’s largest high-fidelity, real-time virtual radio frequency test range”. The system generates a synthetic test range where multitudes of RF emissions can be emulated. There are important differences between simulation and emulation: Simulation, according to established definitions, focuses on the creation of a mathematical model to evaluate the behaviour and performance of a specific system. Emulation replicates a system’s actual hardware and software to effectively create a copy of it in a synthetic environment. According to DARPA’s official literature, the DRBE “offers a powerful new tool for testing (artificial intelligence) enabled (electronic warfare) capabilities and accelerating the development of next-generation RF systems”. Traditional RF test ranges have their limitations: Their physical size may restrict them to the number of emitters that can be deployed on these facilities at any one time. Governmental licensing restrictions from spectrum regulators may limit the type of signals that can be emitted and the times these emissions can be performed. Testing may also have to be organised and booked months in advance, especially if the facilities are in high demand. Furthermore, conventional test ranges can be expensive to acquire, manage and upgrade. DARPA claims that the DRBE is largely free of such strictures, promising “unachievable scale and realism in the emulation of EW scenarios”.

Dr. Anna Tauke-Pedretti, DRBE programme manager, told Armada that “(a) virtual RF environment is, broadly stated, a digital testbed. Rather than relying on outdoor ranges or physical facilities, it takes in signals from radars or other RF systems and recreates how those signals would behave in the real world”. The DRBE, Dr. Tauke-Pedretti continued, also contrasts with laboratory-based DBRE emulators: “Traditional laboratory RF emulators can typically only handle a handful of transmitters and receivers at a time, which limits the realism of testing. Outdoor ranges offer more realism, but they are costly to operate and not always practical. By contrast, DRBE can process a much larger number of inputs while providing high-fidelity emulation”.

Performance

Development and implementation of the DRBE is the responsibility of DARPA’s microsystems technology office, the agency’s literature continued. At the heart of the DRBE is a high-performance, real-time wafer-scale computing architecture which is powered by what DARPA says is the world’s largest processor. A key performance aspect of the DRBE is its low latency. Latency is the measurement of the gap in time between when a machine is instructed to perform a specific task, and when that task is executed. Radio signals travel at the speed of light; 299,274 kilometres-per-second/186,000 miles-per-second. Thus, it becomes imperative that RF emitters can be emulated with representative speeds. For example, a military tactical radio may change frequency several thousand times per second. The DRBE will need to replicate such velocities. The agency says that plans for the DRBE’s development include the use of optical connections within the emulator’s architecture. Such components will increase the bandwidth of the overall system, increasingly the spread of frequencies that can be emulated. Optical connections will also be employed to increase the quantity of wafer-scale computers yet further, helping to enhance the DRBE’s performance. DARPA’s literature says that “these enhancements will unlock the potential for even larger-scale RF scenarios”. Moreover, the improvements open “pathways for (the) DRBE’s architecture to support additional mission domains, including battlespace autonomy, materials science, and digital twins”.

Implementation

DARPA says that the United States Navy will take delivery of the first DRBE example by the end of 2025 becoming part of the Department of Defence’s (DOD) overall testing and evaluation capability. Cerebras Systems and Massachusetts Institute of Technology’s Lincoln Laboratory helped develop the DRBE system the US Navy will receive. Additional assistance in this regard was provided by the US Army Research Laboratory. Dr. Tauke-Pedretti added that a final demonstration is planned for the DRBE in 2026. Undoubtedly, the DRBE will provide a major leap forward in DOD RF testing and evaluation when it enters service. This will not only help system development but will enhance understanding of emitter threats in the electromagnetic environment. (Source: Armada)

 

16 Oct 25. Time is of the Essence.

Motorola handheld radios used by Ukrainian manoeuvre forces for tactical communications employ AES-256 encryption which may be vulnerable to Russian decryption efforts. Armada has learnt that Russian communications intelligence cadres have some restrictions on their ability to decrypt the AES-256 encryption standard. In August 2023 Armada published an article which revealed that Russian Communications Intelligence (COMINT) cadres had successfully broken the Advanced Encryption Standard-256 (AES-256) protocol. AES-256 was created by the United States National Institute of Standards and Technology. Entering service in the early 2000s, AES-256 replaced the earlier US Data Encryption Standard developed by IBM in the 1970s. The new encryption standard was used to secure US military and government classified information. AES-256 has since become a standard encryption tool for communications traffic. It is used extensively in the public and private sector as well as by military and government users. It would take a whole series of articles to clearly explain AES-256 encryption and how it works and Armada highly recommends consulting this online guide. This guide says that AES-256 is a “virtually impenetrable symmetric encryption algorithm”. The article continues that it is not impossible to crack AES encryption with “(a) combination of the perfect brains, the most powerful computer and sheer hacking talent,” although it argues such a process may take a long time. Nonetheless, powerful software does exist which can perform the necessary complex mathematics to decrypt AES-256 protected traffic. COMINT Consulting is one company that provides AES-256 decryption software, incorporating the capability into its Krypto1000 COMINT system. Decrypting AES-256 traffic is also possible should the encryption keys needed to convert the traffic being transmitted into cyphertext be compromised. Cyphertext is unreadable unless the recipient has the requisite encryption key to change this material back into plain text.

AES-256 and Motorola

It is unknown whether Russian COMINT cadres have access to AES-256 keys. Sources who are involved in actively countering Russian communications intelligence told Armada that Russian COMINT experts have devised their own software that can crack AES-256 traffic. This should rightly be a cause for alarm. The Motorola DP4400E and DP4800 ultra high frequency (300 megahertz to three gigahertz) handheld radios deployed by the Ukrainian military use AES-256 encryption according to open sources. These radios, Armada understands, are primarily used for tactical squad-level communications.

On the one hand, Armada understands that the ability of Russian COMINT cadres to crack AES-256 is a cause for concern not only for the Ukrainians, but for other forces using Motorola handheld radios with AES-256. Nonetheless, there are some important caveats regarding the competencies of the Russian communications intelligence experts in this regard. Firstly, Armada has been told that Russian AES-256 decryption does not occur in real time. It typically takes between two and three hours for encrypted traffic captured on the battlefield to be collected, processed, analysed and distributed to those who need it. The more AES-256 traffic Russian COMINT professionals must process, the longer this process takes. Even assuming the Russian military signals intelligence community has AES-256 decryption software, it has a finite quantity of COMINT operatives. Conversely, the quantity of AES-256 traffic which may be captured at any time is not fixed. Secondly, Russia’s AES-256 processing is only able to handle protected voice traffic and cannot decrypt protected data or identification traffic. Why this is the case remains unknown. Decrypting AES-256 voice traffic may also be a double-edged sword the Russian military. Knowing that the traffic can be compromised means that the Ukrainians can also sow false and misleading information into these tactical networks to fox their adversaries.

Perishable intelligence

While decrypting AES-256 protected voice traffic will be of some benefit to Russian COMINT cadres, the problem for them is that these radios are typically used for tactical communications at the tactical edge. The pace of battle dictates that tactical communications traffic can often be highly perishable. For example, knowing that a battalion will begin advancing towards its objective in 20 minutes is of limited use if it takes a minimum of two hours to decrypt the relevant voice traffic disclosing this. To paraphrase the famed US Army armoured warfare expert General George S. Patton, intelligence is like eggs, the fresher the better. Decrypting traffic which ultimately tells you about events that have long since occurred in the tactical battle can be of limited relevance.

This is not a reason to be complacent regarding Russian expertise in AES-256 decryption. While it may take several hours to decrypt the traffic, this time lag is certain to reduce assuming Russian COMINT experts continue to invest in their relevant capabilities. Should Russian COMINT cadres decrypt AES-256 protected data traffic in the future, this will be an added headache.

The key takeaway for North Atlantic Treaty Organisation (NATO), and allied militaries, is that AES-256’s protection can no longer be guaranteed. One should assume that any, and all, traffic using this encryption scheme can be decrypted. Alternative communications security protocols should be used where relevant. Furthermore, these same militaries should be accelerating service entry of other communications/transmission security protocols which, to our knowledge, the Russians still struggle to exploit. Reducing AES-256 reliance can only make life more difficult for Russian COMINT cadres. (Source: Armada)

 

16 Oct 25. Zeros, Ones, Bullets and Bombs.

The UK’s Digital targeting Web could cost over $12bn and reach a full operational capability by 2027, although some voices in the country’s Ministry of Defence have questioned whether funding will be available to meet this aggressive schedule. The United Kingdom’s Ministry of Defence has shared more details regarding the new Digital Targeting Web recently revealed in the country’s Strategic Defence Review. The UK’s Ministry of Defence (MOD) published the country’s Strategic Defence Review (SDR) in early June. The document outlines the United Kingdom’s strategic priorities, the defence policies to meet those priorities and the capabilities required therein. Tellingly, the United Kingdom is moving towards becoming what the SDR calls an Integrated Force by completing “the journey from ‘joint’ to ‘integrated’”. The UK has already embraced the North Atlantic Treaty Organisation’s (NATO’s) commitment to Multi-Domain Operations (MDO). NATO defines MDO as “the push for NATO to orchestrate military activities across all operating domains and environments.” The alliance adds that “(t)hese actions are synchronised with non-military activities and enable (NATO) to create desired outcomes at the right time and place”. MDO emphasises the intra- and interforce connectivity of all military assets at all levels of war for synchronous operations across the entire spectrum of conflict. The aim of MDO is to promote better quality decision-making at a more rapid pace than one’s adversaries. The ultimate goal is for the red force to seize and maintain the initiative across the battlespace at the blue force’s expense. The UK’s Integrated Force will have no fixed force design. Instead, force structures will evolve and develop as threats and technologies change and emerge. The SDR says the Integrated Force will be “underpinned by a common digital foundation and shared data”. This common digital foundation will be enabled by a “Digital Targeting Web” (DTW). This targeting web will connect sensors, deciders and effectors to create “choice and speed in deciding how to degrade or destroy an identified target across domains and in a contested cyber and electromagnetic domain”

Spinning the Web

Armada learned more details regarding the DTW’s implementation at this year’s International Defence and Security Exhibition, better known as DSEI, held in London between 9th and 12th September. The web will enable a deep synergy between UK cross-service Command and Control (C2) and Intelligence, Surveillance and Reconnaissance (ISR) capabilities using a digital communications backbone.

Developing the digital backbone will be challenging. Information at all levels of classification will need to flow between C2 and ISR assets. Information will also need to move outwards to other government organisations which may be non-military but involved in defence and security. The UK’s domestic and foreign security services are examples of the latter. Allies will also need to connect into the DTW to send and receive relevant information. This latter point will be particularly important when UK forces are involved in coalition and/or multinational operations. For example, the UK will need to ensure the web can link with the Five Eyes’ Pegasus communications network. Five Eyes is a formal intelligence sharing and defence cooperation organisation involving Australia, Canada, New Zealand, the UK and the United States.

The DTW will share information with the Secret Cloud; a cloud computing initiative for UK land forces that can store and handle classified data. Google Cloud is currently developing the Secret Cloud, which was announced in September by the UK Ministry of Defence. Although no details appear in the public domain, Armada understands that the Secret Cloud should become operational over the next five years. Sources continued that edge computing will be imperative to manage information flows up to the cloud from capabilities like sensors to avoid information deluge.

Protection

There are understandable fears that initiatives like the DTW and the Secret Cloud could introduce vulnerabilities, particularly regarding cybersecurity, which hostile actors could exploit. MOD sources have emphasised that robust cyber protection and resilience will be integral to both initiatives. Similarly, the networks supporting the DTW must be robust against electronic attack. Parallel initiatives like UK Position, Navigation and Timing (PNT) resilience will help provide alternate timing, navigation and geolocation services independent of Global Navigation Satellite System (GNSS) constellations. Experts involved with the DTW also talked of the importance of having a decentralised construction. This means that the DTW will not have a single point of failure through any of its constituent parts.

Costs

No final figure has been publicly announced regarding the DTW’s overall cost. The initiative is expected to receive an initial $1.4 bn of funding from the MOD. The programme could then cost circa $5.4 bn annually, Armada understands. Publicly available reports talk of the DTW’s initial operational capability being declared in 2026. Full operational capability is expected one year later. Despite the funding and aggressive schedule, some senior MOD figures have expressed scepticism regarding the DTW’s cost. One told Armada that the funding for the DTW was unlikely to be available over these timelines. They dubbed the initiative a “pipe dream”. Time will tell if their prediction becomes apparent. (Source: Armada)

 

16 Oct 25. October Radio Roundup. October 16, 2025TERASi’s new RU1 millimetric wave radio handles traffic across a waveband of 71GHz to 86GHz. Applications mooted for the radio include uninhabited ground and air vehicles.

Armada’s monthly roundup of all the latest news in the military communications product, programme and operational domains.

MMW Gets Smaller

On 21st August, TERASi launched what the company claims is the world’s smallest and lightest Millimetric Wave (MMW), military-grade, ultra-compact radio, according to a press release. Millimetric wave radio signals typically inhabit frequencies from 30 gigahertz/GHz to 300GHz. Known as the RU1, the press release continued that the radio transmits on frequencies above 60GHz. Specifically, the radio handles frequencies of 71GHz to 86GHz, according to James Campion, TERASI’s co-founder and chief executive officer. Mr. Campion says that SpaceX’s Starlink system is using these frequencies for the company’s next high-capacity Satellite Communications (SATCOM) gateways. He expects other SATCOM operators to employ these wavebands in the future for similar high-capacity links. TERASi says the RU1 can be up to 40 times smaller and 100 times lighter than “the nearest in-class products”. Applications mooted for the RUI include the provision of MMW SATCOM links for space- and weight-constrained platforms like uninhabited air and ground vehicles. Mr. Campion continued that the RU1 generates over 55 decibels-per-milliwatt of power. RU1 customer field trials are expected to commence by the fourth quarter of this year.

Arc Ascending

AscendArc has told Armada that the company expects to launch the first of its planned communications satellites in the first half of 2027. Although AscendArc will provide commercial Satellite Communications (SATCOM) using its constellation, it will also make SATCOM services available to military customers. The spacecraft will be in geostationary orbits. The company continued that commercial and military Ka-band (14 gigahertz/GHz uplink and 10.9GHz to 12.75GHz downlink) channels will be provided via the satellites. AscendArc added that it has done developmental working looking at ultra-high frequency (399 megahertz/MHz to 470MHz) and X-band (7.9GHz to 8.4GHz uplink and 7.25GHz to 7.75GHz downlink) connectivity for the United States Department of Defence (DOD). L-band (1.2GHz to 1.8GHz and 1.67GHz to 1.71GHz), C-band (5.925GHz to 6.425GHz uplink and 3.7GHz to 4.2GHz downlink) and S-band (2.2GHz to 2.4GHz) links could be facilitated on future satellites. AscendArc said that each satellite can cover a 24 m square kilometre (9.3 m square miles) area. This footprint equates to a swathe of territory roughly the size of Europe or North America. The company said that it could begin providing SATCOM services to military customers from 2028. (Source: Armada)

 

15 Oct 25. US: Increased botnet activity underscores short-term security risks to businesses. On 13 October, international news outlets reported that unnamed threat actors have been using a large-scale multi-country botnet to attempt to infiltrate US-based systems since at least 8 October. Reportedly, the cyber threat actors hijack administrative user accounts via brute-forcing techniques and/or scan for open ports, in order to exploit remote desktop protocol (RDP) services. The botnet then conducts two types of RDP-related attacks to steal valid usernames and to enumerate additional user accounts. We assess that the threat actors likely intend to expand the botnet’s infrastructure, though the campaign’s objective remains unclear. The botnet comprises at least 100,000 IP addresses located across approximately 100 countries, highlighting the scale of this operation. The same botnet has also previously targeted devices across Africa, East Asia, Latin America and the Middle East, suggesting that its activity is opportunistic in nature. We assess that US-based entities will face increased security risks from botnet attacks in the short term. (Source: Sibylline)

 

13 Oct 25. Proteus Maritime, ECU partner to enhance communication. The proposed mesh communication system will provide a network akin to Wi-Fi beneath the ocean’s surface. Proteus Maritime and Edith Cowan University (ECU), both based in Western Australia, have embarked on a collaborative project to enhance underwater communication. The partnership aims to develop an undersea mesh communication system to address the inherent challenges faced by radio-frequency communications in aquatic environments. The proposed system will provide a network akin to Wi-Fi beneath the ocean’s surface. This network facilitates real-time connectivity for devices deep in the ocean. Unlike traditional systems that depend on a single central hub, each device within the mesh can establish connections with multiple neighbouring units. This creates a “reliable web” of communication that is less susceptible to failure, according to the Western Australia Government. The practical applications are expected to enhance the operational effectiveness of submarines, subsea drones, and sensors. Moreover, it has potential benefits for scientific research and search and rescue missions. This concept was initially introduced during last year’s Exercise Western Dawn (Ex WD) Innovation Program and earned recognition as the overall winner for 2024.

Western Australia Science and Innovation Minister Stephen Dawson said: “This work by Proteus Maritime and ECU could prove to be a game changer for creating reliable pathways in undersea communications for submarines, subsea drones and sensors.”

Proteus Maritime and ECU have received a A$200,000 ($131,543) grant from the government for their project. Western Australia Defence Industries Minister Paul Papalia: “Congratulations to Proteus Maritime and Edith Cowan University for being awarded the WA Government’s A$200,000 Defence and Research Teaming grant.

“This technology will potentially give our submarines, and sea drones the upper hand with a clear line of communication even in hostile waters.

“We are proud of what our local businesses and researchers are achieving, and the State Government continues to invest in the defence sector to help it to grow.” (Source: naval-technology.com)

 

13 Oct 25. NATO expands command network with CAOC Bodø opening.

This new centre will also take on the Norwegian QRA responsibilities.

NATO has opened its third Combined Air Operations Centre (CAOC) in Bodø, Norway.

The new centre will boost NATO’s capacity to oversee and manage air operations throughout the Nordic region, the Arctic, and the broader territories of the political and military alliance. In conjunction with the existing CAOCs in Uedem, Germany, and Torrejón, Spain, CAOC Bodø will oversee as many as 30,000 daily aircraft movements throughout NATO’s European airspace. The establishment of CAOC Bodø is expected to increase situational awareness in the High North. It will also offer vital backup into the Alliance’s air command and control (C2) infrastructure, NATO said.

By integrating this third centre into the existing network, the alliance bolsters its ability to manage dispersed air operations from multiple locations, thus ensuring robust coordination in an increasingly challenging security landscape. This new centre will also take on the Norwegian Quick Reaction Alert (QRA) responsibilities, a task that has been a cornerstone of Norway’s defence since 1961. The QRA mission involves intercepting and identifying aircraft that have not been pre-identified, thereby securing NATO’s northern airspace. Pilots operating the F-35 Lightning II fighters will continue this vigilant tradition at CAOC Bodø, following in the footsteps of their predecessors who flew F-86 Sabre jets over 60 years ago. Although CAOC Bodø is currently in its initial operational phase, it is slated to progressively expand its missions and capabilities. Initially manned predominantly by Norwegian personnel, CAOC Bodø is expected to develop its operational capacity in tandem with its counterparts in Uedem and Torrejón. Its activation is set to augment NATO’s preparedness for integrated multi-domain operations within the Arctic and High North regions, where dynamic response and interoperability are vital for maintaining stability. The operational remit of CAOC Bodø is particularly relevant to NATO’s newest operational command, Joint Force Command Norfolk, which has jurisdiction over an extensive area stretching from Florida to Finland. The opening ceremony was attended by officials from Norway, Finland, Sweden, and NATO leadership. During this event, Norwegian Major General Tron Strand was formally appointed as the first Commander of CAOC Bodø.

“The mission task and our area of responsibility will continue to increase as the organization matures and grows. CAOC Bodø will provide the necessary contributions to the future CAOC model. We will contribute credible deterrence for the Alliance, and we will be ready to fight if necessary,” Tron Strand said.

In June 2025, the Norwegian Government committed to invest 5% of Gross Domestic Product (GDP) towards defence capabilities. (Source: airforce-technology.com)

 

13 Oct 25. Supporting Connectivity for US Army Next-Gen Command and Control Objectives. Current conflicts have demonstrated the urgent need to enable on-the-move communications capabilities for warfighters downrange. Gone are the days of stopping to set up elaborate operations centers, with their tents, generators, and forward-operating base feel.  The pace of war has increased to the point where stealth, avoidance, and frequent movement are the keys to surviving on the modern battlefield. The U.S. Army is actively working to modernize and transform the way that it shares information. The branch’s Next-Generation Command and Control (NGC2) initiative will “provide commanders with the ability to make more, better, and faster decisions through advanced analytics, an integrated data layer, open architecture, and robust and resilient transport.”  NGC2 aims to integrate advanced technologies, improve network redundancy and resilience, and provide real-time data to soldiers on the ground, in the air, and at command and-control nodes while on the move. At the upcoming 2025 Association of the United States Army (AUSA) annual meeting and exposition, Viasat will be sharing its innovations that enable universal connectivity across the Army – to ensure real-time information sharing for tactical communications and decision making is available for service members on-the-move and on-the-pause. Our dedication to innovation is unwavering, and we’ve consistently proven our ability to deliver cutting-edge solutions that meet the Army’s most demanding requirements.

“Viasat’s commitment to the Army is rooted in our long heritage of fielding edge solutions designed to solve the unique connectivity challenges faced by military operations. We are proud to collaborate closely with Army leaders and soldiers to identify gaps in current systems and develop solutions that address the needs of the NGC2 initiative,” said David Schmolke, Vice President of Viasat Mission Connections and Cybersecurity.

During AUSA, our team will be highlighting solutions designed to support NGC2 objectives, including:

Mobile Network Terminal (MNT)

For more than two decades, Blue Force Tracking (BFT) transceivers have enabled real-time vehicle tracking to help with command, control, and navigation.  Viasat’s Mobile Network Terminal (MNT) is a complete modernization of Viasat’s BFT capabilities, delivering modern functionality and communications flexibility to meet the needs of today’s missions and anticipated future requirements. The terminal is designed to deliver access to, and management of multiple transports, including LEO, GEO and Line-of-Sight.

The MNT is designed to be form & fit compatible with existing BFT transceiver hardware, eliminating the need to reconfigure Army vehicles to fit new terminals. MNT’s software-defined radios, mesh networking capability, and edge AI/ML applications enable intelligent orchestration to deliver on-the-move access to warfighter applications using multiple transports. The MNT is enabled by the Qualcomm Snapdragon Mission Tactical Radio (SMTR) capability. The integrated SMTR SoC delivers 15 Trillion Operations Per Second (TOPS) of on-device intelligence capability, while the Smart Mobility Architecture (SMARC) slot ensures seamless future upgradability when mission requirements evolve without hardware replacement. The SMTR hosts Viasat NetAgility SDN and includes a government-purpose software load on Qualcomm Snapdragon chipsets that allow the radio to use a library of DoW waveforms.

Additionally, the terminal is backward and forward compatible, allowing for methodical investment and installation while ensuring seamless communications between divisions which may have different hardware baselines. Ultimately, Viasat’s MNT offers a flexible and scalable solution for the Army’s command post communications and tactical vehicle needs.

NMR-50 Router

The NetAgility Mobile Router 50 (NMR-50) is a compact, rugged edge router built for small form factor applications (SOCOM MODPAYLOAD compliant). It can serve as the communications backbone inside autonomous platforms, as well as adds an additional compute and data storage capability. The Qualcomm SMTR software-defined radio solution delivers access to multiple integrated, diverse transports orchestrated through Viasat’s NetAgility SDN platform, enabling soldiers to utilize various waveforms and satellites and quickly adapt to changing mission communications needs. The NMR-50 and MNT each have a neural processing unit (NPU) capable of running AI workloads and the SMARC slot enables seamless upgrades as mission needs change.

Quicksilver Free Space Optical (FSO) Terminal

The development of electronic warfare (EW) capabilities to detect, disrupt, and degrade traditional communications networks by peer and near-peer adversaries necessitates a resilient, reliable alternative for connectivity in contested environments. Viasat’s Quicksilver solution is an FSO terminal that delivers high-capacity data transmission, with increased security, and lighter infrastructure. This includes offering data rates of 10 Gbps with an operational range of 50-70km. Supporting on-the-pause communications, this quick setup solution enables low-latency communications with a Low Probability of Intercept/Low Probability of Detect (LPI/LPD) anti-jam link. With Quicksilver, customers can rapidly deploy a high bandwidth, zero radio frequency emission capability without the restrictions of obtaining spectrum clearances or licenses. Quicksilver is an expansion of Viasat’s FSOC solutions, following the introduction of the on-the-move Mercury FSOC terminal in 2023. These are just a few of Viasat’s tactical networking and communications solutions that are built to enhance Army communications and support strategic needs for future operations. (Source: ASD Network)

 

10 Oct 25. Cyber Update.

Key points

  • A data theft attack by a well-known ransomware group (‘Clop’) highlights security and financial risks stemming from the exploitation of a zero-day vulnerability (CVE-2025-61882) in third-party services (see Sibylline Cyber Daily Analytical Update – 6 October 2025).
  • A new version of a highly sophisticated backdoor (‘XWorm’) will pose long-term data theft and financial risks to global firms (see Sibylline Cyber Daily Analytical Update –  7 October 2025 and our Technical analysis below).
  • North Korean cyber operations continue to pose long-term heightened financial and social engineering risks to global entities (see Sibylline Cyber Daily Analytical Update – 8 October 2025).
  • A ransomware attack underscores the reputational and financial risks posed by the ransomware group ‘Qilin’ to high-profile brands (see Sibylline Cyber Daily Analytical Update – 9 October 2025).
  • Pro-Russia hacktivist group ‘TwoNet’ is conducting disruptive cyber operations against Western critical national infrastructure (CNI) entities, raising operational and security risks (see Sibylline Cyber

Technical analysis of weekly stories

Threat actors have been targeting global organisations utilising a new version of the highly sophisticated backdoor XWorm since at least September. The cyber actors typically use phishing emails alongside other non-social engineering techniques to infiltrate a company’s targeted systems. Some of these techniques include disguising the malware as a legitimate file, while simultaneously using artificial intelligence (AI) themes to trick targeted individuals into deploying the malware onto compromised systems; this represents an evolution from the previous reliance on email attachments and .LNK files. The malicious file installs an executable via a multi-stage process to check whether the compromised systems have any third-party security applications, in order to evade detection. The file also ensures that any existing security services remain disabled in case of system reboots, allowing for prolonged obfuscation. Upon execution, XWorm establishes communication with command-and-control (C2) infrastructure and conducts reconnaissance to gather system information. XWorm has extensive backdoor capabilities, including collecting and exfiltrating sensitive information (such as financial and crypto currency wallet information, used for financial profit), launching distributed denial-of-service (DDoS) attacks and deploying additional malicious payloads. XWorm’s new variant also contains more than 35 plug-ins, enabling it to act as ransomware to encrypt systems’ files, highlighting its sophistication.

The pro-Russia hacktivist group TwoNet is reportedly targeting Western CNI entities in disruptive cyber operations. In September, TwoNet used default credentials to infiltrate operational technology (OT) within a fake water treatment facility that had been created by Western threat researchers to observe threat actors’ cyber activity (a practice known as a honeypot). The group then ran a structured query language (SQL) request to identify the system’s databases, before exploiting a cross-site-scripting (XSS) vulnerability (CVE-2021-26829) to display a pop-up alert about the attack on a compromised human-machine interface (HMI). TwoNet subsequently disabled logs, alarms and real-time updates by removing the connected programmable logic controller (PLC) from the data source list. This infiltration of a decoy target demonstrates TwoNet’s intent and capability of disrupting adversarial CNI. The incident highlights a potential shift in pro-Russia hacktivist tactics to encompass disruptive attacks on OT systems, rather than simply targeting information technology (IT) systems with low-level DDoS attacks. The group also engaged in doxxing, ransomware and other cyber operations at the same time, though it has reportedly ceased operations as of the time of writing.

Our cyber word of the week: Human-machine interface (HMI)

Definition: A piece of hardware or software that enables human operators to interact with and control industrial machines via a user interface. (Source: Sibylline)

 

——————————————————————————————————————————————————————————————————————————————————————————————————————————-

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

———————————————————————————————————————————————————————————————————————————————————————————————————————————-

 

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

October 9, 2025 by

 

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

——————————————————————————————————————————————————————————————————————————————————————————————————————————————–

09 Oct 25. Spectra Group and 2iC Boost Tactical Data Reach with GENSS MANET Integration. Spectra Group, a specialist provider of secure voice, data and satellite communications systems, is announcing at AUSA, a unique Mobile Ad-hoc Networks (MANET) bridging solution using GENSS, the first of its kind over a BLOS satellite solution.  This tactical data solution, created in collaboration with software from 2iC, will deliver real time strategic level battlefield data via GENSS to remotely deployed tactical users.  The Spectra Group team will be on the ground at AUSA to discuss the exciting capabilities that GENSS offers for specialist and regular forces deployed to remote austere locations globally. Spectra’s SlingShot revolutionised tactical comms with over 10,000 systems fielded worldwide; GENSS builds on that legacy with even greater reach, flexibility, and data resilience.  GENSS (Next Generation SlingShot) takes all the successes and lessons learnt from SlingShot and embodies Spectra Group’s vision of producing the ultimate radio system that capitalises on technological advances, adapts to the evolving demands of military operations and simplifies the user experience.   In addition to being backwards compatible with SlingShot and being a powerful satellite software defined radio (SDR) in its own right, the GENSS delivered solution uses enhanced modulation and waveforms optimised to deliver a Data Network/MANET bridging capability to cope with extending the proliferation of wide band data usage (64KBps over a 25KHz channel) in the tactical battlespace beyond normal Line of Sight propagation. To maximise this ability to bridge MANET and other data networks, Spectra Group has collaborated with 2iC, a UK based global leader in battlespace software integration.  Their lean service architecture and integration products are used by MODs and defence primes all over the world to quickly, easily and securely connect the myriad of disparate devices, sensors and systems on the battlefield digitally.  Working together, Spectra Group and 2iC have delivered and continue to develop a series of ‘middleware’ applications, consisting of a combination of 2iCs operationally proven products such as 2iC NODE and TAK Module alongside the GENSS application software and its Open API radio firmware.  This combination allows for efficient data flow management to be delivered over narrow band L-TAC BLOS bearer systems and enable GENSS to be seamlessly interoperable with ATAK or other battlefield management systems.  The end user gets a simplified and unified battle picture across multiple terminals/access platforms over vast distances while on the move.  This means that not only does GENSS retain ultimate flexibility and interoperability as a software defined radio, but it also has an open architecture construct able to easily integrate with existing systems and rapidly adapt to future demands.

Graham Booth, CEO and Co-founder 2iC said, “We are very excited to bring our vast experience of delivering digital interoperability in the battlespace to our work with Spectra Group. Our proven off-the-shelf software, such as 2iC CONNECT:TAK, alongside our extensive experience with ATAK, are proving invaluable. Together we are developing bespoke software to maximise MANET capabilities and ensure GENSS is highly future proofed.”

Simon Perrett, Head of Research and Development at Spectra Group said, “It is very rewarding when you can work together with subject matter experts from different disciplines and collectively the output is greater than the sum of the individual parts.   Working with 2iC, we are maximising the capability and ease of use of GENSS in its MANET bridging role, which is a massive benefit to the user on the ground and goes to the heart of our ethos at Spectra Group.   GENSS is a step change in tactical radio capability and for the soldier on the ground, GENSS will be plug-and-play; delivering secure, simplified access to mission-critical data BLOS and on the move.”

What a Difference a Day Makes

Remember to pencil 12th September into your calendar. You now have a new day to celebrate. Ukraine’s President Volodymyr Zelensky recently issued Decree 679/2025. His ordinance designated this date as the day to commemorate the service of his country’s Electronic Warfare (EW) personnel. Mr. Zelensky said that the country’s EW cadres are vital in “ensuring the repulsion and deterrence of armed aggression against Ukraine”. He added that the day is an opportunity to celebrate the people “who work invisibly but very professionally” to protect the country.

Tellingly, the only other nation that has a day of commemoration for its EW cadres is Russia. She marks this occasion on 15th April. This was the first time EW was used in combat. On that day in 1904, during the Russo-Japanese War, Russian signallers successfully used jamming. In doing so, they disrupted Imperial Japanese Navy naval bombardment fire control against the Russian military presence in Port Arthur. Port Arthur is today known as Lüshun City and is in the north of the People’s Republic of China.

Your editor would like to make a humble request. NATO and allied nations should also adopt 12th September as a day of electronic warfare commemoration. Such an action presents an invaluable opportunity to put electronic warfare ‘on the map’ for societies as a whole. Everyone, military and civilian alike, needs to become more ‘spectrum minded’. The use of electronic warfare has consequences far beyond the battlefield. The jamming of global navigation satellite system position, navigation and timing signals causes routine disruption in the Baltic, the Black Sea, eastern Mediterranean and the Asia-Pacific. An EW commemoration day would be an ideal moment to remind societies that electronic warfare affects them all.

Our discipline nurtures and supports skilled jobs in industry and academe as well as in the military. The EW day would be a great opportunity to remind people of the careers this discipline offers. Moreover, electronic warfare fosters cutting edge science and technology with benefits far beyond the battlefield. For example, the growth of cognitive EW will be impactful in the wider artificial intelligence world. Last, but by no means least, military EW cadres perform their work in an invisible environment. For some, their work lacks the cache and glamour of armour, fast jets and warships, but their work is just as important. Others may not even know the EW discipline exists and will be captivated upon learning that it does.

Let’s take a moment to commemorate and celebrate our discipline, and to give thanks to those who protect our use of the electromagnetic spectrum and advance our national interests through it. Our societies depend on this environment. Taking some time to remember this will help everyone get more spectrum minded. (Source: Armada)

 

09 Oct 25. October Spectrum SitRep . TCI ECS launched the company’s new 995 and 997 communications intelligence receivers at this year’s DSEI exhibition. These products can cover wavebands of between nine kilohertz and 8.5 gigahertz, providing between 80 megahertz and 160 megahertz of instantaneous bandwidth.

Armada’s monthly round-up of all the latest electronic warfare news in the product, programme and operational domains.

New TCI Receivers

TCI ECS launched two new Radio Frequency (RF) receivers at this year’s International Defence and Security Exhibition in London held between 9th and 10th September. A company press release said that the receivers are designed to support the Communications Intelligence (COMINT) mission. The first new products is the 995 rack-mounted COMINT and geolocation system. The 995 is joined by the 997 rack-mounted COMINT and independent geolocation system. TCI ECS told Armada that both these products can detect and process signals across wavebands of nine kilohertz to six gigahertz/GHz for radio monitoring and between 20 megahertz/MHz to 8.5GHz for Direction Finding (DF). The press release continued that the new products offer up to 80MHz and 160MHz of instantaneously bandwidth respectively. Instantaneous bandwidth is a measure of how much of the radio spectrum COMINT systems can ‘see’ at any one time. Both systems use hybrid-angle-of-arrival and time-difference-of-arrival techniques to geolocate emitters of interest. The 995 can be vehicle-mounted or used in a stand-alone configuration. The 997 offers “enhanced processing capacity for simultaneous, independent tasking and networked multi-sensor geolocation across dispersed teams,” according to TCI ECS literature. Both systems offer up to 72 hours of recording and use the TCI ECS’s Blackbird COMINT software. The company told Armada that “(the 995) has a single RF/DF processor unit which combines RF collection and DF in a single rackmount processing module”. The 957, meanwhile, “has separate dedicated processors for RF collection and direction finding, which allows it to support direction-finding tasking from multiple stations operating at different frequency bands”. Both models are available for order and over 20 have been procured so far by North Atlantic Treaty Organisation (NATO) and non-NATO nations. Deliveries will commence from early 2026.

Ghost Mantis Revealed

In late September SRC unveiled the company’s new Ghost Mantis Electronic Warfare (EW) payload designed to equip Uninhabited Combat Air Vehicles (UCAVs). Reports stated that the organisation has earmarked Ghost Mantis for so-called Loyal Wingman platforms intended to work with inhabited combat aircraft. Ghost Mantis will be capable of detecting, processing and engaging threats across a waveband of 300 megahertz to 18 gigahertz. Reports continued that Ghost Mantis can replicate the radar cross section and electromagnetic signature of other inhabited platforms. This tactic is especially useful when flying in contested airspace. Red force air defenders will see two targets represented on their screens and be faced with a dilemma : Which is a genuine target, and which is not? SRC says that Ghost Mantis uses an open architecture making it easy to reconfigure, and is platform agnostic regarding the uninhabited aircraft it can equip. An SRC spokesperson told Armada that Ghost Mantis is currently at Technology Readiness Level Seven (TRL-7). United States Department of Defence definitions say that TRL-7 denotes that a prototype has been demonstrated in an operational environment. Ghost Mantis low-rate initial production is expected to commence from early 2027. Alongside UCAVs, SRC foresees Ghost Mantis equipping inhabited aircraft and uninhabited surface vehicles. (Source: Armada)

 

09 Oct 25. Cornerstone Moves Forward. Up to eleven of the British Army’s Boxer wheeled armoured fighting vehicles will carry the modular Cornerstone and Poynting electronic warfare architecture to support land manoeuvre force EW at the tactical and operational levels. The United Kingdom’s Ministry of Defence expects to advance its fulfilment of the British Army’s Project Cornerstone requirement in the coming months, according to sources close to the initiative. Project Cornerstone was launched in November 2022 and is valued at between $121 m and $485m. Cornerstone will see the delivery of a “networked land Electronic Warfare (EW) and signals intelligence capability,” the project’s tender specified. Few details were revealed in the tender notice beyond the requirement for Cornerstone’s architecture to use “common standards”. A written statement previously provided to Armada by the UK Ministry of Defence (MOD) said the Cornerstone architecture will include hardware and software. This hardware and software will be integrated “into relevant platforms to support brigade combat teams”. As we have previously reported, the British Army is acquiring eleven ARTEC Boxer wheeled armoured fighting vehicles configured for EW. The MOD’s statement confirmed the EW-configured Boxers will accommodate the Cornerstone architecture “based on current planning and funding”. Once delivered, the MOD expects to continually enhance Cornerstone throughout its service life: “This aims to deliver the capability (identified by continuous operational analysis) to the end user as early as possible, whilst maximising flexibility to adjust to any future opportunities and threats.  To that end there may/will be several vendors that are cohered into a system of systems delivery”. The MOD had not revealed details on when Cornerstone will enter service. Armada understands that acquisition is now being accelerated with successful bidders expected to be chosen by the end of the year. The ministry plans to follow an aggressive scheduled: An initial operational capability is planned for late 2026. Full operational capability could be declared a minimum of one year later.

CEMA and SDR

As noted in the UK’s Strategic Defence Review (SDR) published this June, the country’s armed forces are reinvigorating their cyberwarfare and EW capabilities. Several recommendations relevant to these two disciplines were contained in the SDR, namely the activation of a Cyber and Electromagnetic Activities (CEMA) Command. A new Digital Warfighting Group (DWG) will be subordinate to the CEMA Command to “defend Britain from daily attacks in the grey zone,” according to the SDR. The command is expected to be activated by late 2025 and will form part of the UK’s Strategic Command. A UK Ministry of Defence (MOD) spokesperson told Armada in June that the CEMA Command will be headed by a two-star officer. Other details regarding the command’s structures “are subject to work building up to (the) initial operating capability”. The DWG will “exploit technology such as sensors, (artificial intelligence) powered systems, and (uninhabited aerial vehicles) to achieve a decisive advantage,” the SDR continued. These personnel will work alongside conventional forces in aiding the delivery of cyber and electromagnetic effects. Armada understands that the EW-configured Boxers will also carry the Poynting architecture. A crucial difference between Cornerstone and Poynting is that the latter is a dedicated tactical CEMA capability. Cornerstone, on the other hand, will be configured for tactical-to-operational level cyberwarfare and EW. Sources have shared that the modular architectures of Cornerstone and Poynting means they can be swapped in and out of the Boxers as missions dictate. The vehicles are expected to be deployed with the 14th Signals Regiment (Electronic Warfare), the army’s dedicated EW formation. This regiment is part of 6th (UK) Division and is headquartered at RAF Upavon, southwest England. The division is responsible for cyber, EW and information operations. The British Army’s existing 21st Signal Regiment, a communications unit, is being rerolled for CEMA. Cyber operations will be the responsibility of the new 13th Signals Regiment which should be raised by 2028. All three units will comprise the army’s new CEMA group and form one element of the Digital Warfighter Group. It is possible that the Boxers will form a common ‘pool’ of platforms made available to these formations, configured accordingly as and when needed. The aggressive schedule the MOD is following to get Cornerstone into service is undoubtedly a response to Europe’s fragile security situation given the ongoing war in Ukraine. It would not be surprising if Cornerstone is eventually deployed with UK units in the Baltic. The country deploys forces as part of the North Atlantic Treaty Organisation’s (NATO’s) so-called Enhanced Forward Presence (EFP). The MOD notes that UK land forces are deployed to Estonia with around 900 personnel continually rotated through theatre. The UK’s contribution to the EFP is codenamed Operation Cabrit. UK troops join their Danish and French counterparts alongside the Maavägi (Estonian Land Forces’) Estonian Division. The deployment of the Cornerstone capability with those units could represent a significant enhancement of NATO’s electromagnetic manoeuvre forces in this region. (Source: Armada)

 

09 Oct 25. Thinking about Cognition. The second edition of Drs. Karen Haigh’s and Julia Andrusenko’s book Cognitive Electronic Warfare: An Artificial Intelligence Approach contains important updates, and useful practical exercises, highly relevant to this fast-moving discipline. The second edition of the seminal work on cognitive electronic warfare provides excellent, thought-provoking discussions, real world examples and useful practical exercises. The first edition of Drs. Karen Haigh’s and Julia Andrusenko’s landmark book Cognitive Electronic Warfare: An Artificial Intelligence Approach was published in 2021. Armada reviewed the work that same year. We concluded that “(t)he defence community has been waiting for someone to define cognitive EW”. Drs. Haigh and Andrusenko did this with aplomb. In doing so they provided the most thorough and readable analysis of cognitive Electronic Warfare (EW) yet written. We predicted at the time that “(t)his robust, thought-provoking book will become a standard text in this fast-emerging field”. The intervening years has seen their work become exactly that. As a testament to the speed at which cognitive EW is moving, aided in no small part by the development of Artificial Intelligence (AI) technology, the two authors recently published a second edition of their book. Dr. Haigh was a recent guest on our Radioflash! podcast where she discussed the new work and its perspectives. The second edition expands on many themes articulated in the first, adding some interesting new insights. From the outset, a very useful aspect of the book is that it provides useful definitions for Artificial Intelligence (AI) and Machine Learning (ML). These two terms are often used interchangeably, but this is problematic. As the authors note ML is a sub-discipline of AI which is already being applied to electronic warfare. In a nutshell, AI mimics the way the human brain works to perform complex tasks. ML uses algorithms trained on specific data to realise software models capable of performing complex tasks. The authors observe that machine learning approaches are already being used for waveform classification.

Trust

AI has long been heralded as a miracle technology for electronic warfare and the bedrock upon which cognitive EW will be built. A key aspect of the continual incorporation of AI techniques into EW is trust. If users do not trust the technology, its uptake will be slowed, if not altogether stalled. Moreover, AI technologies must demonstrate that they can perform a task better and faster than a human if they are to be adopted for EW. The authors argue that trust is ultimately a function of risk: The more authority is granted to an AI technique or technology “the greater the validation and assurance requirements”. Usefully, the authors state that trust depends on the level of risk the user can tolerate. These are useful maxims as we consider the increasing prevalence of cognitive EW-enabled capabilities in the electromagnetic manoeuvre space in the future. Another of the author’s observations relates to the dependence of cognitive EW systems, particularly those performing signals intelligence collection and analysis, on data. The more relevant data a system receives, the more it can learn about its current environment to recognise, and act upon, events in the future. The quandary for cognitive EW systems is that actual combat data may be rare or impossible to source. Classification issues can complicate things in this regard. Warfare, like life, is unpredictable and Drs. Haigh and Andrusenko stress that cognitive EW systems must learn to respond to surprises beyond the bounds of their data. Every minute of every hour a cognitive system is deployed will also be unique. This fact has an impact on our expectations of a cognitive EW system’s output: “We would not expect a human being to perform identically every day, especially when presented with the same scenario, we should therefore not expect identical performance from a cognitive system”. In summary, the questions the authors have tackled present the EW community with handy ‘rules of the road’. Such rules will help establish design standards for cognitive electronic warfare systems much as the celebrated science fiction author Isaac Asimov did with his Three Laws of Robotics.

The strategic picture

It is arguably all but impossible in the military sphere to discuss the application of AI technology to military capabilities without discussing competition between the United States and People’s Republic of China (PRC). Both nations are racing each other for artificial intelligence supremacy. The authors posit that the PRC may have caught up with the United States in the middle of last decade. They warn that China is “aiming to become the global leader in AI by 2030”. The PRC is excelling in face and speech recognition, and computer vision, the authors note. Chinese efforts often eclipse North Atlantic Treaty Organisation members and allied nations in these areas. One can only imaging the strides PRC researchers are making in cognitive EW.

Future editions

Hopefully the second edition of Cognitive Electronic Warfare: An Artificial Intelligence Approach will not be the last. The cognitive EW discipline is evolving at such a pace that regular updates of Drs. Haigh and Andrusenko’s work will be not only welcome but essential. Publishers please take note. Another important point is that the book has some useful examples on how individuals can start working with the discipline. The authors include a series of exercises that individuals can perform at their leisure. Useful insight into some of the principles underpinning cognitive EW is provided by these exercises. As with the first edition, the book excels at discussing technical aspects clearly enabling them to be easily grasped by the non-specialist. Engineers and computer scientists will welcome further examination of cognitive EW software challenges. Strategists will enjoy dissecting the geopolitical impact of cognitive EW proliferation. Practitioners get a handy guide on what cognitive EW can do for them in the electromagnetic manoeuvre space. Once again, Drs. Haigh and Andrusenko have effortlessly encapsulated a vast and challenging subject into a lucid and digestible volume. With their second edition, the standard work on cognitive EW has set new benchmarks. (Source: Armada)

 

09 Oct 25. Séance de Brouillage. The French DGA defence procurement and evaluation agency has recently qualified the Serval-GE variant of the KNDS VBMR-L armoured vehicle as a communications intelligence platform. Armada has learnt that the French Army will receive a new vehicle-mounted jammer to enhance its land manoeuvre electronic warfare forces. News emerged in September that France’s Direction Générale de l’Armement (DGA/General Armament Directorate) has qualified the Armée de Terre (French Army’s) new Signals Intelligence (SIGINT) apparatus. The DGA is the country’s defence procurement and evaluation agency. This new capability adorns an undisclosed number of KNDS Véhicule Blindé Multi-Rôle Léger (VBMR-L: Light Multi-role Armoured Vehicle) platforms. Reports continued that deliveries of the first examples of these vehicles will be made to the army’s 54e Régiment de Transmissions (54th Transmissions Regiment) before the end of the year. The 54th Transmissions Regiment is based in Hagenau, northern France, forming part of the army’s Corps de Transmissions (Signals Corps). No information appears to have been released to the public domain, but it would seem likely that Thales has provided the vehicle’s SIGINT payload. This payload can probably detect, locate and analyse (henceforth known as process) emitters transmitting signals in frequencies of circa 30 megahertz/MHz to six gigahertz/GHz. Such a waveband would allow the system to process signals from friendly, neutral and hostile communications emitters. These emitters could include military tactical communications, civilian telecommunications, including cellphone traffic, and possibly some satellite communications.

VAB LINX and SAEC

Known as the Serval-GE (Guerre Electronique/Electronic Warfare), this new platform replaces a host of legacy French Army tactical Communications Intelligence (COMINT) capabilities. Renault Véhicle de l’Avant Blindés (VAB: Forward Armoured Vehicles) have hitherto been used to accommodate the army’s LINX (Localisation et Interception des Émissions Exotiques/Exotic Emissions Localisation and Interception) COMINT system. LINX is thought capable of processing COMINT regarding Very High Frequency (VHF: 30MHz to 300MHz) and Ultra High Frequency (UHF: 300MHz to three gigahertz) signals. LINX’s targets are likely to include hostile radios and communications networks using transmission and communications security protocols such a frequency-hopping and encryption. Armada understands that the VAB LINX supports operational-level COMINT processing while the VAB SEAC (Système d’Appui Electronique de Contact/Electronic Contact Support System) processes V/UHF COMINT in support of the manoeuvre forces at the tactical level. These VAB variants began to equip the French Army from 1993.

Griffon jammer

Armada has learnt from sources close to the 54th Transmission Regiment that plans are afoot to take delivery of a new jamming platform over the coming five years. The jammer will be housed onboard a KNDS Griffon VBMR (Véhicule Blindé Multi-Rôle/Multirole Armoured Vehicle) platform. The Griffon is a larger six-wheel drive vehicle compared to the four-wheel drive Serval-GE. The additional volume of the Griffon is necessary to house the amplifiers the platform will need to generate jamming signals. It is expected that the new jammer will be capable of developing up to 1,000 Watts (60 decibels/dB) of signal strength.

The French Army is planning to acquire a variant of the KNDS Griffon VBMR armoured vehicle to house a new electronic attack system. The vehicle’s large internal volume will be used to house amplifiers capable of generating circa 1,000 Watts of jamming power.

Open sources state that land-based communications jammers can have an average antenna gain of two decibels when performing general, omnidirectional jamming over a wide area. Gain is a measurement of how much signal power an antenna focuses in a specific direction. Likewise, open sources state that military handheld radios can have an antenna gain averaging 4.5dB. Assuming a range to target from the jammer to a handheld radio of 25 kilometres (15.5 miles) a jammer with these characteristics may be capable of transmitting circa 118dB of power. Given that the radio will generate around ten decibels of power, the jammer’s signal strength of 118dB will significantly eclipse the latter preventing the radio from transmitting effectively. If the jammer increases antenna gain by using directional jamming against a known target, or in the specific direction of the radio, the jammer signal strength increases to 125dB.

As these figures illustrate it is likely that the French Army’s new jammer could be a potent adversary on the battlefield. Armada understands that jammers currently used by the force are relatively weak, developing just over 100dB of power. Clearly the new vehicles will be a perfect complement to the Serval-GE platforms, strengthening the EW capabilities of the 54th Transmission Regiment still further. (Source: Armada)

 

08 Oct 25. India enhances military communication with IRSA standard 1.0.. IRSA aims to ensure waveform compatibility, SDR interoperability, and adherence to certification and conformance standards. Officials during the launch of IRSA standard 1.0 at DRDO Bhawan, New Delhi. Credit: Ministry of Defence. India’s Defence Research and Development Organisation (DRDO), in partnership with the Integrated Defence Staff (IDS) and Tri-Services, has introduced the Indian Radio Software Architecture (IRSA) standard 1.0. Released during a national workshop held at DRDO Bhawan in New Delhi on 6 October, 2025, the IRSA standard 1.0 is designed to facilitate interoperability in military communication.  The IRSA is a detailed software specification tailored for Software Defined Radios (SDR). It encompasses standardised interfaces, application programming interfaces (APIs), execution environments, and waveform portability mechanisms.  The key focus of IRSA is to facilitate waveform portability and ensure interoperability, certification, and conformance of SDRs. The Indian Ministry of Defence stated that this launch marks a considerable step in India’s journey to achieve “self-reliance in defence communication technologies.”

“The specification is designed to evolve with operational requirements. It also lays the foundation for integrating future technologies,” the statement said.

The event served as a forum for stakeholders from industry, academia, and the Tri-Services to explore collaborative ventures, pilot schemes, and strategies for adopting the new standard. The gathering saw participation from various sectors including the Indian Armed Forces, Department of Defence Production (DDP), Defence Public Sector Undertakings (DPSUs), industry representatives, academic institutions, and research bodies. The IRSA was envisioned in 2021 when the essential role of SDRs in modern military operations was recognised, prompting the need for a national software standard. A dedicated technical team from DRDO commenced work in 2022 alongside IDS and the Tri-Services to consolidate operational and user requirements. Following thorough reviews and stakeholder consultations, IRSA Version 1.0 received approval from the High-Level Advisory Committee (HLAC) in 2025. (Source: army-technology.com)

 

08 Oct 25. Ultra I&C will demonstrate its latest command and control solutions at the 2025 Association of the United States Army Annual Meeting & Expo (booth #139) at the Walter E. Washington Convention Center in Washington, D.C., October 13-15, 2025. As the battlefield becomes increasingly complex and data-saturated, the ability to process information at speed and deliver actionable intelligence is foundational to mission success. Warfighters operating in contested, multi-domain environments face an avalanche of data from distributed sensors and platforms — dynamics which demand faster processing, smarter automation, and seamless integration across classification boundaries. Ultra I&C will demonstrate the Knox family of multifunction processors, Maxwell the AI agent, and mission applications from the Apex orchestration platform — a command and control stack purpose-built to cut through data overload and deliver decision advantage at the tactical edge. Each solution operates independently, but when layered together, they unlock optimized mission-data processing and autonomous mission support for the warfighter.

Knox family of multifunction processors

Designed for mission-critical applications at the edge, Knox manages diverse data flows across air, land and maritime missions. Built on SOSA-aligned, 3U OpenVPX rugged architecture with support for VITA 49.2 and modern frameworks, Knox securely powers cloud-native workloads, AI/ML models and mission applications where it matters most, at the point of need.

Maxwell AI agent

Maxwell automates complex tasks and reduces operator fatigue by learning mission priorities, monitoring system health, and maintaining focus without human input. What traditionally takes hours or days — reporting, analysis, link performance assessment — Maxwell completes in minutes. It autonomously identifies breakpoints, analyzes degraded links and initiates fixes, keeping operators focused on the mission rather than troubleshooting systems.

Certified commercial solution mission applications with Apex

The Apex suite is a commercial solution providing a modular, open-architecture ecosystem that eliminates integration bottlenecks and enables true cross-platform interoperability. Secure APIs connect mission applications like ADSI®, Rain™ and other third-party tools, orchestrating and managing data flow across classification levels in real time. With latency-optimized compute, multilevel security, and hardware-independent upgrades, Apex delivers the flexibility and speed required for tactically responsive operations.

Ultra I&C delivers differentiated capabilities that transform complexity into clarity — empowering operators to act faster, with confidence, in any contested environment. By simplifying integration and accelerating insight, Ultra I&C ensures warfighters maintain decision advantage when the mission demands it. (Source: PR Newswire)

 

09 Oct 25. ADVENT and FLEETSTAR Begin Service with the Indonesian Navy. HAVELSAN has achieved a new milestone in Southeast Asia with the successful delivery and integration of its indigenously developed Combat Management System, ADVENT, and the FLEETSTAR Ship Data Distribution System aboard the Indonesian Navy’s KRI BELATI-622 fast attack craft. This achievement marks a major step for Türkiye’s naval technologies in the Asia-Pacific region and further strengthens HAVELSAN’s position as a trusted partner in global defense cooperation.

Enhanced Digital Capabilities at Sea

The integration of ADVENT and FLEETSTAR on the KCR-60 class vessel, built by PT TESCO Indomaritim, demonstrates HAVELSAN’s engineering excellence and advanced system interoperability. During the extensive sea trials and live-fire tests, both systems performed exceptionally, successfully completing all phases of operational validation. HAVELSAN engineers provided on-site support throughout the testing process, ensuring smooth system performance and full compatibility with the ship’s command and control infrastructure.

Representatives from the Indonesian Ministry of Defense, the SATGAS test team, and PT TESCO Indomaritim praised the systems’ technological sophistication and robust digital design, emphasizing their contribution to Indonesia’s naval modernization goals.

ADVENT and FLEETSTAR: The Core of Next-Generation Naval Platforms

ADVENT serves as the digital brain of modern fleets, enabling network-centric warfare by integrating sensors, weapons, communication, and decision-support systems into a single tactical environment. The FLEETSTAR Platform Data Distribution System acts as the digital backbone, collecting and securely sharing critical data across ship subsystems. Together, ADVENT and FLEETSTAR provide naval operators with a highly resilient, cyber-secure, and data-driven operational framework that improves situational awareness, decision-making speed, and mission effectiveness.

Strengthening Strategic Cooperation

HAVELSAN CEO Dr. Mehmet Akif Nacar highlighted the significance of this collaboration with Indonesia, noting that the success of the ADVENT and FLEETSTAR integration underscores HAVELSAN’s expanding international footprint:

“This achievement reflects not only the technological excellence of HAVELSAN but also the strong strategic partnership we are building with Indonesia. The successful integration of ADVENT and FLEETSTAR demonstrates Türkiye’s capability to deliver advanced, network-centric naval systems on a global scale.”

Dr. Nacar also emphasized HAVELSAN’s intent to broaden its cooperation with the Indonesian Navy through upcoming naval programs, including OPV-90, Merah Putih, and additional KCR-60 / KCR-70 class vessels. (Source: ASD Network)

 

08 Oct 25. NAL Research, a leader in innovative, global connectivity solutions trusted by government and enterprise customers, is announcing a powerful addition to its industry-defining SHOUT product line with SHOUT nano 200. The new tracker provides federal agencies and militaries with enhanced performance, assurance, and adaptability for connectivity in any mission. Unlike traditional handheld trackers that require a clear view of the sky to communicate, SHOUT nano 200 overcomes this challenge by offering dual-mode connectivity. The device allows users to connect via three methods: satellite communications for global reach, mesh networking for secure device-to-device links, and 5G LTE when paired with an enabled cellular device. Use NAL’s Android Team Awareness Kit (ATAK-CIV/GOV/MIL) plug-in or companion application to access capabilities such as messaging, situational awareness, and SOS alert sending. Among the many advantages of SHOUT nano 200 is its seamless integration with ATAK, which can be used to determine location and communicate with other SHOUT trackers via its mesh and satellite networks. The intuitive and durable solution also features automatic SOS alerts, an enhanced user screen, and a field-replaceable battery that can be charged inside the device for longer operations.

“For over 25 years, users around the world have trusted NAL to deliver reliable tracking, safety, and mission-critical communications,” said NAL Research’s Director of Connectivity Solutions, Bart Polizotto. “SHOUT nano 200 is the most advanced SHOUT yet, offering flexible communication options and robust features to support the success of global dismounted government and military customers.”

See a demonstration of this powerful solution at NAL Research’s AUSA 2025 booth #3054, October 13-15.

SHOUT nano 200 is available for pre-order and will be commercially available in November 2025. For more information, contact . To learn about NAL’s comprehensive SHOUT produce line, visit https://www.nalresearch.com/.

ABOUT NAL RESEARCH

NAL Research is a pioneer in delivering trusted and resilient connectivity and PNT solutions – designed to meet the dynamic communications, data intelligence, location, and timing needs of the future. In 2024, NAL Research and Blue Sky Network strategically merged to optimize operations and provide a diverse enterprise and government customer base with transformative solutions and enhanced service and support. NAL and Blue Sky Network’s combined portfolio now includes emerging satellite and mobile technology products, satellite-based tracking systems, powerful APNT modules, intelligent software applications, IoT tracking, and two-way devices enabling seamless global connectivity. For more information visit www.nalresearch.com.

 

08 Oct 25. Cubic Defense, a recognized industry leader in providing digital intelligence, edge compute and networking, live, virtual and constructive (LVC) training and secure communications will demonstrate its latest multi-domain convergence solutions at the Association of the United States Army (AUSA) Annual Meeting & Exposition, from October 13-15 at the Walter E. Washington Convention Center in Washington, D.C.

“As the Army modernizes for the future fight, it requires capabilities that ensure readiness and decision advantage in multi-domain operations,” said Anthony Verna, Senior Vice President and General Manager of DTECH Mission Solutions. “Cubic’s solutions, validated across exercises and operations, bring trusted data to achieve information dominance, assured connectivity and realistic training at the point of need.”

Visit Cubic Defense at booth 7177, Halls DE. Attendees can also vote for Cubic’s entry (Tethys) in AUSA’s National Partner Best New Product/Service award via event QR codes located throughout the venue. Featured demonstrations include:

Edge Compute and Networking

  • DTECH Fusion Trust combines the power and resilience of DTECH platforms with advanced partner technologies to ensure a secure, zero-trust, quantum-ready network resilient in DDIL conditions.
  • DTECH Family of Systems connects edge to cloud, enabling complex data processing and AI-driven decision-making across the multi-domain battlespace.

Secure Communications

  • Cubic’s multi-beam, multi-band, multi-orbit SATCOM, software-defined radios and protected waveforms solutions enable advanced teaming operations in contested spectrum environments and extend the reach of Future Vertical Lift platforms.

Digital Intelligence

  • TAKTICS Regional Nodes, Edge Nodes, and new AutoSync Maps deliver up-to-date imagery and maps directly to TAK devices, even in DDIL conditions
  • Tethys orchestrates AI/ML and multi-INT data flows to provide real-time, actionable intelligence
  • HiPER Geospatial Suite delivers GEOINT products from enterprise networks to the tactical edge, ensuring every echelon shares a common picture
  • Unified Video (UV+) transforms how the Army manages and exploits full-motion video with DVR, Cesium visualization and rapid export.

LVC Ground Training

  • Live Training System (LTS) – Individual uses lightweight, wireless modules integrated with soldier gear to deliver weapon-effect and threat detection without added burden.
  • LTS – Vehicle provides wireless force-on-force training with intuitive touch-screen interfaces, enhancing fidelity and casualty assessments.
  • LTS – Mortar replicates live-fire mortar operations with surrogate systems, propagating real-time effects across training networks for accurate AAR.
  • LTS – Unmanned Aerial System (LTS – UAS) simulates drone engagements across EW, kinetic defeat, ordnance delivery and direct fire, enhancing counter-UAS training
  • LTS – Instrumentation Systems (LTS – IS) is a mobile, battalion-level training solution integrating GPS, comms and digital mapping with automated AAR tools, federated with LVC networks.

To learn more about Cubic products and services, visit www.cubic.com.

 

09 Oct 25. U.S. Army Awards General Dynamics Mission Systems Contract to Deliver Initial CMFF Prototype Systems. General Dynamics Mission Systems announced today that it has been awarded an Army contract valued at $28.3 m to deliver critical C5ISR/EW Modular Open Suite of Standards (CMOSS) Mounted Form Factor (CMFF) prototype systems. The contract was awarded by the PEO C3N PM Mission Command through the C5 Consortium and is for two years.

“This award allows for the rapid fielding of new, best-of breed capability by using field-swappable, commercial open-standard boards for computing, radio, position, navigation, and timing, electronic warfare, and cryptological capabilities,” said Scott Dunderdale, General Dynamics Mission Systems vice president and general manager for Land and Air Systems. “The system has already run with boards from more than twenty different vendors, including Abaco, Behlman Electronics, and Pacific Defense, with many more to come. The Army can now continuously develop, test and field capability in DevSecOps mode.”

“Backed by the leading provider of tactical high-assurance cryptological systems in the world, the CMOSS systems resists threats through NSA-certifiable muti-level security, HEMP/EW hardening, and full tactical ruggedization,” added Dunderdale.

The CMOSS system is optimized to run advanced battlefield software such as Palantir Maven and Anduril Lattice to enable Next Generation Command and Control (NGC2).

The chassis is designed to fit within the SINGCARS radio space in any vehicle or platform. It collapses several different capabilities (APNT, Radio, EW) into one system featuring individual slots where 3U VPX processor cards can be inserted and upgraded rapidly with a variety of capabilities. The system is also designed to support the Future Long-Range Assault Aircraft as well as other aviation assets without the need for costly modifications. General Dynamics has supported the U.S. Army CMOSS and CMFF initiatives with key investments in CMFF chassis prototypes, critical payload modules, and CMOSS management software to ensure that the system is production ready. The CMFF chassis specifically represents a significant investment by General Dynamics to ensure that the Army has a solution on Day 1 that can be scalable to support the full capability payloads envisioned for the CMFF chassis. General Dynamics is already finalizing early orders for this product and has large-scale production capacity through its cryptological and radio products portfolio. The production-ready chassis is fully aligned to the CMFF Reference Architecture, features key design provisions enabling NSA certification, and was designed from the ground up with soldier useability as a focus. The company’s proven manufacturing expertise and ability to scale hardware production position General Dynamics to support the rapid transition of the CMFF program from initial prototyping to full-scale production. The contract includes prototype CMFF chassis development and delivery, CMOSS management software development, system modeling, and supporting system integration services. (Source: ASD Network)

 

07 Oct 25. Global: New malware variant highlights long-term data theft, financial risks to firms. On 6 October, international news outlets reported that threat actors have been targeting global organisations with a new version of a highly sophisticated backdoor (‘XWorm’) since at least September. The cyber threat actors typically use phishing emails alongside other non-social engineering techniques to infiltrate targeted systems. Such operations include hiding XWorm within fake applications that mimic legitimate services, while simultaneously using artificial intelligence (AI) themes to trick the targeted individuals into executing the malware onto compromised systems. This highlights the continuous development of cyber attack distribution methods. Upon execution, XWorm can collect and exfiltrate sensitive data (such as financial and crypto currency wallet information for financial profit), launch distributed denial-of-service (DoS) attacks and deploy additional malicious payloads. XWorm’s new variant contains more than 35 plug-ins that allow it to act as ransomware and to encrypt a system’s files. We assess that global businesses will face long-term security, data theft and financial risks as cyber threat actors continuously develop more sophisticated variants of existing malware. (Source: Sibylline)

 

06 Oct 25. Mercury Systems, Inc. (NASDAQ: MRCY, www.mrcy.com), a global technology company that delivers mission-critical processing to the edge, and Nightwing, the cyber and national security solutions company defining the edge of possible to advance our nation’s interests, today announced an agreement to enhance the cyber resiliency of Mercury Systems hardware with Nightwing cyber resiliency technology. Through this agreement, the companies will offer pre-integrated cybersecurity and anti-tamper solutions that enhance the integrity of applications for the entirety of their runtimes. This collaboration gives government customers an expertly curated set of security capabilities shaped by Nightwing’s experience spanning U.S. military and intelligence community missions.

“This agreement brings together Mercury’s trusted hardware technology portfolio with one of the nation’s foremost cybersecurity providers to better protect critical customer missions,” said Tom Smelker, Mercury’s Senior Vice President of Processing Technologies. “Collaboration between commercial suppliers increases delivered capability while reducing total cost of ownership. Together we will give our customers and partners more options to meet their performance, affordability, and maintainability needs.”

“Mission-critical systems are more open and connected than ever before,” said Tim Zentz, Nightwing’s Vice President of Cyber Offense and Defense Experts (CODEX). “Cyberattacks can come from unexpected vectors—over the air, through compromised components in the supply chain, or even through infected maintenance equipment. The integration of our cyber resiliency technology with Mercury’s industry-leading hardware products and solutions will provide customers with greater security and faster, more efficient fielding of equipment.”

Mercury Systems – Innovation that matters®

Mercury Systems is a global technology company that delivers mission-critical processing power to the edge, making advanced technologies profoundly more accessible for today’s most challenging aerospace and defense missions. The Mercury Processing Platform allows customers to tap into innovative capabilities from silicon to system scale, turning data into decisions on timelines that matter. Mercury’s products and solutions are deployed in more than 300 programs and across 35 countries, enabling a broad range of applications in mission computing, sensor processing, command and control, and communications. Mercury is headquartered in Andover, Massachusetts, and has more than 20 locations worldwide. To learn more, visit mrcy.com. (Nasdaq: MRCY)

About Nightwing

Nightwing is the national security solutions company defining the edge of possible to advance our nation’s interests. The company delivers the most advanced full-spectrum cyber, data operations, systems integration, and intelligence services for government agencies, businesses, and organizations. Nightwing is proud to partner with our government and commercial customers to protect their most critical information, systems, and operations with breakthrough technology and world-class talent. Headquartered in Dulles, Virginia and previously part of a leading Fortune 100 company, Nightwing became independent in April 2024. Learn more at Nightwing.com.

 

03 Oct 25. Cyber Update

Key points

  • The exploitation of the communications platform Microsoft Teams points to the increased security and financial risks facing global IT systems (see Sibylline Cyber Daily Analytical Update – 29 September 2025).
  • A data breach impacting the UK-based department store Harrods underscores the operational, data-theft and financial risks facing high-profile businesses (see Sibylline Cyber Daily Analytical Update – 30 September 2025).
  • A long-term cyber campaign highlights the sustained security and financial risks stemming from North Korea-affiliated threat actors (see Sibylline Cyber Daily Analytical Update – 1 October 2025).
  • Key strategic targets across the Asia-Pacific, Middle East, North Africa and Turkey and Sub-Saharan Africa regions face data-theft and cyber espionage risks stemming from the Chinese state-sponsored group ‘Phantom Taurus’ (see Sibylline Cyber Daily Analytical Update – 2 October 2025 and our Technical analysis below).
  • A suspected surveillance operation showcases the security and data-theft risks facing UAE-based Android users (see Sibylline Cyber Daily Analytical Update – 3 October 2025 and our Technical analysis below).

Technical analysis of weekly stories

A newly identified Chinese state-sponsored group (Phantom Taurus) has targeted the government and telecommunications sectors across the Asia-Pacific, Middle East, North Africa and Turkey and Sub-Saharan Africa regions since at least 2023. While the initial attack vector is unclear, Phantom Taurus employs a custom malware suite (‘NET-STAR’) during its operations to infiltrate systems’ Internet Information Services (IIS) web servers. The malware suite contains three backdoors (‘IIServerCore’, ‘AssemblyExecuter V1’ and ‘AssemblyExecuter V2’) to maintain persistence within compromised systems, as well as to enable in-memory execution of malicious code and to execute additional malicious payloads. IIServerCore executes directly into the system’s memory and uses randomised compilation times to enhance detection evasion, showcasing the threat actors’ skillset and capabilities. The backdoor can also establish communication with command-and-control (C2) infrastructure to execute arbitrary code as well as additional malicious payloads, underscoring prolonged infection risks. Phantom Taurus exfiltrated specific emails in the initial stages of the campaign and subsequently shifted towards targeting databases, highlighting the strategic nature of its activity. The group used a set of rare custom malware payloads throughout the campaign, underscoring its sophistication; it also employed more common tools typically associated with other Chinese threat actors (including ‘China Chopper’, ‘Impacket’ and the ‘Potato Suite’). Two suspected surveillance operations (‘ProSpy’ and ‘ToSpy’) have targeted Android users in the UAE since at least 2022. The perpetrators reportedly distribute fake applications emulating legitimate messaging programmes such as Signal and (the now-defunct) ToTok via phishing websites to infiltrate targeted systems. One of the pages mimics the legitimate Samsung Galaxy Store and advertises the fake ToTok application as an authentic download. The threat actors have advertised a new version of ToTok and fake Signal encryption plugins as part of the ProSpy campaign; they then distribute the ToTok spyware variant. Upon installation, both applications request permissions to access sensitive user and device information before exfiltrating stolen data to C2 infrastructure. The applications also mimic legitimate services and redirect users to their genuine counterparts to prolong detection evasion, highlighting the threat actors’ sophistication and resources. The ToSpy campaign has distributed the fake ToTok application since at least 2022 to encrypt and exfiltrate sensitive user data while employing similar detection-evasion mechanisms.

Our cyber word of the week: Internet Information Services (IIS)

(Source: Sibylline)

 

03 Oct 25. Anduril and Palantir battlefield communication system ‘very high risk,’ US Army memo says.

  • Summary
  • Army memo highlights security issues in NGC2 platform
  • Anduril says memo reflects outdated program state
  • Palantir stock drops over 7%

The much-needed modernization of the U.S. Army’s battlefield communications network being undertaken by Anduril, Palantir (PLTR.O), and others is rife with “fundamental security” problems and vulnerabilities, and should be treated as a “very high risk,” according to a recent internal Army memo. The two Silicon Valley companies, led by allies of U.S. President Donald Trump, have gained access to the Pentagon’s lucrative flow of contracts on the promise of quickly providing less expensive and more sophisticated weapons than the Pentagon’s longstanding arms providers. (Source: Reuters)

 

03 Oct 25. EDA and ECCC Strengthen Cooperation to Reinforce EU Cyber Defence. The European Defence Agency (EDA) and the European Cybersecurity Competence Centre (ECCC) signed a Memorandum of Understanding (MoU) on 30 September that will strengthen cooperation between the civil and defence communities in the field of cybersecurity research and innovation.  The agreement gives practical effect to the Council Conclusions on the EU Policy on Cyber Defence (May 2023) and the Joint Communication on EU Cyber Defence (November 2022), which both underline the need for stronger EU resilience against cyber threats, closer civil–military cooperation, and investment in cutting-edge cyber defence capabilities.  By aligning their respective mandates, EDA and ECCC will support these policy objectives, ensuring that EU-level funding, research, and capability development in cybersecurity and cyber defence move forward in a coherent and mutually reinforcing manner.

A Living Roadmap for Cooperation

The MoU foresees the establishment of a joint roadmap to be regularly updated with priority topics for collaboration. This mechanism will allow both organisations to exchange perspectives, compare notes, and identify synergies in their respective roles:

  • ECCC, as the EU body created to manage the cybersecurity parts of Horizon Europe and Digital Europe, sets research priorities and channels funding to civilian and dual-use projects.
  • EDA, by contrast, identifies research and technology priorities for defence, including cyber defence, and develops collaborative projects to address capability needs.

By coordinating and aligning their relevant work strands, the two bodies aim to avoid duplication, build on complementary expertise, and ensure that investments in cybersecurity serve both civilian and defence needs.

Operational Cooperation via CapTech Cyber

From the EDA side, the cooperation will be carried out through CapTech Cyber, one of EDA’s 15 Capability Technology groups, which focuses on research and technology activities to meet agreed defence capability needs. Close interaction between CapTech Cyber and the ECCC is expected to further enhance Europe’s ability to deliver impactful collaborative projects.

Strengthening Europe’s Resilience

The MoU is another milestone in building a stronger, more resilient Europe. It reflects the political ambition expressed by Member States to act together for a stronger cyber defence, to strengthen civil–military coordination, and to invest in full-spectrum cyber capabilities – as called for by the Council and the Commission. (Source: ASD Network)

————————————————————————————————————————————————————————————————————————————————————————————————————————————-

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

——————————————————————————————————————————————————————————————————————————————————————————————————————————————–

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

October 3, 2025 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

———————————————————————————————————————————————————————————————————————————————————————————————————————————————–

29 Sep 25. PentenAmio reveals TrapRadio electronic deception system. UK/Australian digital security firm PentenAmio has developed an electronic deception system that mimics radio networks to disguise real locations and provide camouflage in the electronic spectrum. According to PentenAmio, “Electronic deception distorts enemy intelligence efforts, creates false targets, masks critical movements, and triggers operational doubt.  It uses electronic signals to mislead adversaries by manipulating their perception of the battlefield.” The new development, called TrapRadio, is an electronic deception system that replicates the radio frequency (RF) signature and the behaviour of forces, not just a single radio. It consists of a software-defined radio transmitter paired with an artificial intelligence (AI)-driven mission planning application, which can build and scale RF signatures to manipulate an electronic order of battle or replicate force units of any scale, size, or composition demanded by an operation. With a power output of up to 10 W, the transmitter covers the frequency range of 30–520 MHz, and can generate a range of military, first responder, and commercial waveforms, and different modulation types. A PentenAmio representative told Janes at the DSEI 2025 exhibition in September that the RF characteristics of the typical equipment for a particular unit can be loaded into the mission planning application, which then uses AI to create and replicate typical unit electronic signatures and network characteristics. When activated the radio can then generate and regenerate the simulated network to replicate complex electronic pattern of life behaviour. Users can adjust parameters such as decoy unit numbers and sizes, radio types, and operational tempo. (Source: Janes)

 

30 Sep 25. MetTel, a leader in digital transformation and communications, and TekSynap, a premier provider of IT services for national security and defense agencies, today announced a strategic partnership dedicated to modernizing and transforming communications infrastructure across the U.S. federal government, with a focus on defense and intelligence sectors. MetTel and TekSynap Announce Strategic Partnership to Deliver Agile, Secure Communications Solutions for U.S. Defense and Intelligence Agencies Both MetTel and TekSynap are award-winning players in the federal technology space—recognized for their ability to execute large-scale, complex initiatives with agility, speed, and innovation. Together, they will offer government agencies powerful solutions including Software-Defined Wide Area Network (SD-WAN), POTS Transformation, and Next-Gen Wi-Fi, delivering increased bandwidth, resilience, and security—critical for mission assurance and operational continuity in today’s rapidly evolving threat landscape.

A Shared Commitment to Innovation and Excellence

MetTel has consistently been recognized as an industry pioneer of SD-WAN in the commercial sector—and was the first company to successfully deliver SD-WAN over Starlink for a US defense agency in 2021. The United States Postal Service entrusted MetTel to digitally transform copper landlines across 17,000 locations nationwide- the largest federal POTS replacement project commissioned to date and was awarded the prestigious USPS Supplier Excellence Award in 2024 for masterful execution of this initiative. MetTel is recognized as a five-time and current leader of the Gartner® Magic Quadrant™ for Managed Network Services and has generated over $2.5 bn in government task awards in recent years. TekSynap has earned a reputation for excellence within defense and intelligence circles, honored multiple times by Inc. 5000 and Washington Technology Fast 50 for rapid growth, innovation, and the ability to deliver transformative IT solutions in high-security, mission-critical environments. The company has been entrusted with high-profile initiatives supporting the Department of Defense, the Defense Health Agency, and numerous intelligence community partners.

“MetTel’s partnership with TekSynap brings together deep expertise in secure network services and agile IT solutions to help defense and intelligence agencies strengthen mission performance,” said Don Parente, VP of Sales & Solution Architecture, MetTel Public Sector. “Together, we’re bringing federal agencies the tools they need to modernize legacy infrastructure while enhancing resilience, performance, and security.”

“MetTel is an ideal partner, reflecting the very qualities we value most at TekSynap; Customer mission outcomes, agility, innovation, and an unwavering commitment to excellence,” said Henry Tragle, SVP of Integration Services at TekSynap.

“Together, we are uniquely positioned to deliver resilient communications, advanced cybersecurity, and comprehensive mission support, empowering our nation’s defenders with the trusted technology and services they need to succeed in an increasingly complex environment.”

Powerful Solutions. Impactful Results.

Through this strategic partnership, MetTel and TekSynap will help federal agencies:

  • Leverage SD-WAN to modernize network infrastructure, improve performance, and simplify management
  • Transform legacy copper (POTS) lines that support security and safety-critical systems for improved reliability, cost-efficiency, and compliance
  • Enhance connectivity through secure, scalable Wi-Fi solutions built for high-demand, high-security environments
  • Ensure continuity and resilience across mission-critical operations, even for the most challenging environments

With a shared DNA rooted in adaptability, mission focus, and technical excellence, MetTel and TekSynap are poised to usher in a new era of what agile, innovative companies can deliver in the federal space.

About MetTel

A leading provider of digital transformation and communications solutions for enterprise and government clients, MetTel is recognized as a Leader in the Gartner Magic Quadrant for Managed Network Services for the last five consecutive years. With award-winning SD-WAN services, a global footprint, and deep expertise in network modernization, MetTel enables organizations to connect, grow, and thrive in an increasingly digital world. For more information visit mettel.net, follow us on X (@OneMetTel) and LinkedIn, or call us directly at (877) 963-8663. MetTel. Connect Smarter™.

About TekSynap

TekSynap is a globally focused, full-spectrum systems integrator. The company deploys industry-leading technical solutions to provide effective computing, cloud, and secure operational environments. TekSynap enables mission-enhancing automated systems through flexible and agile development. Its team of IT professionals, with management experience and technical expertise, ensures that projects and programs are completed on time and within budget using industry best practices. For more information about TekSynap’s capabilities visit TekSynap.com or connect with us on LinkedIn, (Source: PR Newswire)

 

29 Sep 25. In a field of more than 2,600 applicants from across the NATO Alliance, two of Estonia’s defense sector companies – Wayren and Telearmy – have been selected among a group of 15 advancing to Phase 2 of NATO’s Defence Innovation Accelerator for the North Atlantic (DIANA) program that connects 75 innovation centres worldwide.

Wayren and Telearmy are building solutions that tackle some of NATO’s toughest defense challenges in modern warfare:

  • Wayren  builds resilient battlefield communications networks that keep data and voice links alive even in disruption. They use a hybrid platform that seamlessly switches between satellite, radio, and mobile networks.

“Being selected for DIANA Phase 2 is a huge vote of confidence in our mission to ensure mission-cricial teams stay operational when it matters most. Our reliable communication platform provides rapid decision making and command and control capabilities even when everything else fails – with difficult terrain, disruptions and infrastructure failure. DIANA gives us the resources and partners to get our technology into the hands of NATO forces faster,” said Henry Härm, CEO of Wayren.

  • Telearmy  develops remote driving technology for military vehicles turning them into unmanned systems for logistics, reconnaissance, and evacuations in high-risk zones. Their next-generation system retrofits with any ground platform  from light ATVs to heavier armored vehicles .

“Estonia’s size, tech-savviness, and openness to new technologies have given us unique tools to move with agility and bring deep technologies into real use cases. With our technology already war-proven in Ukraine, NATO DIANA’s quality stamp, and now high-level support, we can scale rapidly – turning any military vehicle into a remotely operated from very far distances, keeping soldiers out of danger and providing a more flexible way to operate on the changing battlefield” said Enn Laansoo Jr., CEO of Telearmy.

Congratulating the companies, Hanno Pevkur, Minister of Defense, said:

“I am very pleased to see Estonia’s contribution to NATO DIANA stand out so strongly. The fact that three of the teams that accelerated here in Estonia – including two of our own defense industry companies – have advanced to the next stage shows how quickly Estonian entrepreneurs can adapt, act and seize opportunities. The same applies to our Defense Forces, who have been on board with testing new solutions.”

Each company will receive €300,000 in non-dilutive funding, access to NATO test centers, and tailored support to move their technology closer to operational use through NATO’s Rapid Adoption Service program.

Standing alongside the United States, Canada and the United Kingdom, Estonia is one of the only countries represented by two or more firms, giving Estonia one of the strongest showings among NATO nations in the second phase. This comes at a time when Estonia has committed to raise its defense spending to 5.4% of GDP by 2026, with a projected €10 bn investment over 2026-2029. Already in 2025, defense expenditures are expected to be about 3.38% of GDP which sets Estonia well above the EU and NATO averages. (Source: PR Newswire)

 

29 Sep 25. Global: Continued exploitation of legitimate applications points to increased security, financial risks. On 27 September, international news outlets reported that cyber threat actors are using fake versions of the communications platform Microsoft Teams to infiltrate global IT systems. The campaign starts with ‘malvertising’ and/or search engine optimisation (SEO) ‘poisoning’ to trick victims into visiting a threat actor-made website. The website displays a fake installer file for Microsoft Teams that, if opened, covertly installs a backdoor (‘Oyster’) onto compromised systems. Malvertising and SEO poisoning have been used to distribute Oyster since at least 2023, showcasing the effectiveness of these techniques. Oyster allows threat actors to maintain persistence, execute commands, exfiltrate data and deploy additional malicious payloads. It has previously been used to facilitate ransomware deployments, as well as credential exfiltration for financial profit, highlighting the increased financial risks facing compromised systems in the short-to-medium term stemming from the continued exploitation of legitimate applications. (Source: Sibylline)

 

26 Sep 25. Cyber Update Key points

  • A large-scale cyber attack against several Europe-based airports showcases the operational risks associated with the software supply chain (see Sibylline Cyber Daily Analytical Update – 22 September 2025).
  • Co-operation between two Russian state-sponsored groups (‘Turla’ and ‘Gamaredon’) underscores long-term cyber espionage risks to organisations in Ukraine (see Sibylline Cyber Daily Analytical Update – 23 September 2025 and our Technical analysis below).
  • An influence operation underscores disinformation risks from Russian threat actors amid parliamentary elections in Moldova (see Sibylline Cyber Daily Analytical Update – 24 September 2025).
  • A Chinese state-sponsored cyber operation showcases the long-term security and cyber espionage risks facing key adversarial sectors (see Sibylline Cyber Daily Analytical Update – 25 September 2025 and our Technical analysis below).
  • A cyber operation showcases elevated social engineering and financial risks stemming from a Vietnamese cyber threat group (‘Lone None’; Technical analysis of weekly stories

Two Russian state-sponsored groups, Gamaredon and Turla, collaborated in at least four cyber espionage operations against Ukrainian entities between February and June. In February, Gamaredon reportedly infiltrated a targeted device and downloaded two custom malware loaders, a PowerShell-based loader (‘PetroGraphin’) and a second-stage loader (‘PteroOdd’). PetroGraphin established communication with command-and-control (C2) infrastructure via an encrypted channel, while PteroOdd likely enabled Turla to deploy a custom backdoor (‘Kazuar v3’) onto compromised systems. During the incident, Turla used Kazuar to exfiltrate sensitive system information, though the backdoor displays several other malware functionalities. In April, Gamaredon compromised another system to deploy a PowerShell loader (‘PetroEffigy’) and directly execute Kazuar v2. Similarly, in June, Gamaredon infected two additional systems to install another PowerShell-based loader (‘PteroPaste’) and Kazuar v2. In March, Gamaredon started deploying Kazuar without Turla’s intervention, likely showcasing the evolution of the groups’ tactics and co-operation.

A Chinese state-sponsored group (‘RedNovember’) conducted a reconnaissance and cyber espionage operation between July 2024 and July 2025. RedNovember reportedly used spear phishing attacks and exploited software vulnerabilities affecting network edge devices and third-party services to infiltrate targeted organisations. It then deployed a backdoor (‘Pantegana’) to establish communication with C2 infrastructure. In some instances, RedNovember also exploited virtual private network (VPN) services to maintain remote control over compromised systems. The group also installed multiple other open-source tools to monitor compromised systems and exfiltrate sensitive data while offsetting resource costs and enhancing detection evasion. This included a malware loader (‘LESLIELOADER’) to execute a remote access trojan (‘SparkRAT’), as well as the Cobalt Strike beacon to enable persistence, stealthy command execution, lateral movement and data exfiltration. In April, the group primarily targeted Ivanti Connect Secure (ICS) VPN devices to infiltrate the US and South Korean engineering and nuclear sectors, underscoring the continuous development and sophistication of this campaign.

Non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware.
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.

Our cyber word of the week: Reconnaissance  (Source: Sibylline)

—————————————————————————————————————————————————————————————————————————————————————————————————————————————

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

—————————————————————————————————————————————————————————————————————————————————————————————————————————–

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

September 26, 2025 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

——————————————————————————————————————————————————————————————————————————————————————————————————————————————

25 Sep 25. DTC Unveils New Military-Grade Mesh MANET Radio. DTC has introduced the Sentry 6161, a military-grade mesh MANET radio that combines sovereign manufacturing, software-defined flexibility, and dual power support for military, government, and public safety operations. DTC, a Codan Company, has released the Sentry 6161, a military-grade mesh MANET radio built on a software-defined architecture for front-line forces and other professional users. The Sentry 6161 is designed to support a wide range of applications, including government, public safety, critical infrastructure, unmanned systems, and commercial sectors. The radio’s sovereign build and lifecycle assurance provide armed forces with verifiable control over components, firmware, and production. This end-to-end manufacturing process supports national security and long-term sustainment strategies. It is engineered for both dismounted and platformed military use, offering resilient mesh routing, low-latency, and adaptive link management to ensure command, control, and situational awareness in contested or GPS-denied environments. The software-defined foundation allows military users to run DTC waveforms and securely host approved third-party or in-house waveforms on a single hardened hardware platform. This approach enables the rapid deployment of mission-specific waveforms, reduces vendor lock-in, and promotes interoperability across coalition and joint operations. Additionally, the radio supports multiple RF bands, allowing tactical planners to adapt to spectrum availability and operate alongside existing communications infrastructure. This flexibility simplifies logistics by reducing the number of different radios needed for varied missions. The 6161 features a dual power strategy, supporting traditional rugged clip-on batteries for immediate field use and hot-swapping, while also being designed to integrate with next-generation soldier systems that use centralized battery buses. This enables centralized power management, reduces soldier load, and extends mission endurance. The radio’s multi-MANET capability allows forces to operate multiple MANET implementations and waveforms as required by missions, extending its usable life and improving interoperability in coalition environments. The modular hardware and controlled software provisioning simplify repairs, upgrades, and mission-specific configurations, which helps lower the total cost of ownership and supports a long service life. According to DTC, the Sentry 6161 has been used in military demonstrations to validate its manufacturing, tactical performance, waveform hosting, and power-integration capabilities. Trials have demonstrated the radio’s ability to operate with both clip-on batteries and centralized power systems, host multiple waveforms, and interoperate across different tactical networks. While the Sentry 6161 is optimized for military users, its features are also valuable for government, public safety, critical infrastructure, and commercial customers. The Sentry 6161 is now available globally, and DTC is accepting requests for demonstrations, trials, and integration support.

Alf Ianniello, Codan Group CEO, commented, “From squad radios to dismounted networks, the Sentry 6161 was designed with the military end user in mind. We prioritized sovereign supply-chain control, operational versatility and a clear migration path so armed forces can modernize comms, protect investment and field new capabilities rapidly — without losing continuity of logistics or mission effectiveness.”

Tthe Premier of South Australia, The Honourable Peter Malinauskas, added, “The Sentry 6161 soldier radio designed and manufactured in Mawson Lakes is a clear example of South Australia’s strength as the Defence State and our global standing in advanced manufacturing. Communications technology is a vital sovereign capability, enhancing national Defence readiness and expanding export opportunities. This innovation from DTC, a subsidiary of the Codan Group and one of our largest advanced manufacturers, reflects the world-class expertise being developed in South Australia.”

Treasurer and Minister for Defence and Space Industries, the Honourable Stephen Mullighan MP stated, “South Australia’s defence industry continues to deliver world-leading capability for the modern defence force. The Sentry 6161 soldier radio also demonstrates the dual-use potential of advanced communications technology across government, civilian and commercial sectors. This kind of innovation reinforces our role as a trusted partner in global supply chains and a leader in sovereign capability.” (Source: https://www.defenseadvancement.com/)

 

24 Sep 25.  Department of War Announces New Cybersecurity Risk Management Construct. The Department of War (DoW) today announced the implementation of a groundbreaking Cybersecurity Risk Management Construct (CSRMC), a transformative framework to deliver real-time cyber defense at operational speed. This five-phase construct ensures a hardened, verifiable, continuously monitored, and actively defended environment to ensure that U.S. warfighters maintain technological superiority against rapidly evolving and emerging cyber threats.

Addressing Legacy Shortcomings

The previous Risk Management Framework was overly reliant on static checklists and manual processes that failed to account for operational needs and cyber survivability requirements. These limitations left defense systems vulnerable to sophisticated adversaries and slowed the delivery of secure capabilities to the field. The CSRMC addresses these gaps by shifting from “snapshot in time” assessments to dynamic, automated, and continuous risk management, enabling cyber defense at the speed of relevance required for modern warfare.

The construct is composed of a five-phase lifecycle and ten foundational tenets.

The Five-Phase Lifecycle

The new construct organizes cybersecurity into five phases aligned to system development and operations:

  1. Design Phase – Security is embedded at the outset, ensuring resilience is built into system architecture.
  2. Build Phase – Secure designs are implemented as systems achieve Initial Operating Capability (IOC).
  3. Test Phase – Comprehensive validation and stress testing are performed prior to Full Operating Capability (FOC).
  4. Onboard Phase – Automated continuous monitoring is activated at deployment to sustain system visibility.
  5. Operations Phase – Real-time dashboards and alerting mechanisms provide immediate threat detection and rapid response.

Ten Foundational Tenets

The CSRMC is grounded in ten core principles:

  • Automation – driving efficiency and scale
  • Critical Controls – identifying and tracking the controls that matter most to cybersecurity
  • Continuous Monitoring and ATO – enabling real-time situational awareness to achieve constant ATO posture
  • DevSecOps – supporting secure, agile development and deployment
  • Cyber Survivability – enabling operations in contested environments
  • Training – upskilling personnel to meet evolving challenges
  • Enterprise Services & Inheritance – reducing duplication and compliance burdens
  • Operationalization – ensuring stakeholders near real-time visibility of cybersecurity risk posture
  • Reciprocity – reuse assessments across systems
  • Cybersecurity Assessments – integrating threat-informed testing to validate security

Delivering Cybersecurity at the Speed of War

By institutionalizing this construct across the Department, the DoW is ensuring cyber survivability and mission assurance in every domain: air, land, sea, space, and cyberspace.

“This construct represents a cultural fundamental shift in how the Department approaches cybersecurity,” said Kattie Arrington, performing the duties of the DoW CIO. “With automation, continuous monitoring, and resilience at its core, the CSRMC empowers the DoW to defend against today’s adversaries while preparing for tomorrow’s challenges.”

For more information on the Cyber Security Risk Management Construct, click here.

For more information on the CSRMC Strategic Tenets, click here: chrome-extension://efaidnbmnnnibpcajpcglclefindmkaj/https://media.defense.gov/2025/Sep/24/2003808112/-1/-1/1/DOD-CIO-CYBER-SECURITY-RISK-MANAGEMENT-CONSTRUCT.PDF (Source: U.S. DoD)

 

24 Sep 25. Poland conducts first international live-fire exercise of IBCS. The IBCS effectively “engaged and intercepted” surrogate air-breathing targets during the test. Poland’s Ministry of National Defense has executed a successful operational exercise for its WISŁA medium-range air defence system, which is enabled by the Integrated Battle Command System (IBCS) developed by Northrop Grumman. This event, which was held in Poland, marked IBCS’s first international live-fire operational exercise.

The system effectively “engaged and intercepted” surrogate air-breathing targets, Northrop Grumman said.

Northrop Grumman vice president and command and control and weapons integration general manager Kenn Todorov said: “This achievement not only highlights the exceptional performance and capabilities of IBCS but also demonstrates Poland’s steadfast commitment to homeland defence and the enhancement of European security.”

Poland selected IBCS as a central component of its WISŁA air defence modernisation programme in 2018, becoming the first US ally to do so. The IBCS is part of the US Army’s programme for air and missile defence modernisation. In 2024, Poland’s Ministry of National Defense declared Initial Operational Capability for two IBCS-enabled batteries under this programme.

IBCS is a command-and-control system that provides fire control and battle management. It unifies various systems, regardless of their service, source, or domain. IBCS integrates sensor data to create a single, actionable view of the battlespace through its network-enabled, modular, open, and scalable architecture. IBCS is in production and has been deployed in Poland. Further deployments have been planned for Combatant Commands in Europe and the Indo-Pacific under the US Army’s integrated air and missile defence modernisation programme. In December 2021, Northrop Grumman secured a five-year contract worth more than $1bn from the US Army for the production of IBCS.

“IBCS revolutionises interoperability and integration between Poland, US, and allies across multiple domains, delivering advanced capabilities needed to counter complex threats. Central to this success is the robust partnership between Polish industry and Northrop Grumman,” Todorov added.

Earlier in 2025, Northrop Grumman secured two contracts totalling $1.4bn, to modernise global air and missile defence capabilities for the US Army and Poland. (Source: army-technology.com)

 

24 Sep 25. Memorandum of Understanding sets Babcock and KNL on the same frequency. Babcock International Group (Babcock), the defence company and KNL, a radio communications equipment manufacturer, have signed a Memorandum of Understanding (MoU) to offer next generation High Frequency (HF) Communications support to armed forces across the land, sea and air domains. The MoU builds on existing collaboration between the companies, with the convergence of their respective capabilities set to transform the HF spectrum. Babcock, a world leader in HF comms already provides a variety of services to the UK, Australia and New Zealand, all of which are part of the Five Eyes intelligence alliance. Coupled with KNL’s growing market presence and cutting-edge capabilities, the organisations will further explore the integration of disparate networks and systems in challenging communications environments.

Matt Taylor, Managing Director-Sense and Connect, Mission Systems-Babcock said: “This MoU enables the development of products and services that will support complex and vital defence programmes with the needs and safety of military personnel at the heart of our approach. We have a longstanding association with KNL, and this collaboration underlines our intent to deliver technology-led, innovative solutions through our growing relationship.”

Toni Lindén, CEO of KNL said. “Our vision at KNL has always been to provide uncompromised connectivity where it matters most. This partnership aligns perfectly with our mission and together we can create real operational advantages for our customers. We look forward to working closely with Babcock and growing our offering.”

The companies have already joined forces through the Army Warfighting Experiment’s (AWE) Distinguished Visitors’ Day, showcasing a HF Communications solution utilising Wideband High Frequency Beyond Line-of-Sight communications, connecting dispersed groups of users, transmitting rich Situational Awareness and Intelligence, Surveillance and Reconnaissance data. The Low Probability of Interception/ Detection properties, in conjunction with other unique features, place Babcock and KNL at the forefront of a HF renaissance that focusses on increased communications survivability and resilience. The companies will now promote their joint HF capability in the multi domain environment.

 

23 Sep 25. L3Harris Introduces Pod Capability for Viper Shield EW System. The Viper Shield Pod variant offers flexibility for nations adding to or augmenting electronic warfare capabilities in F-16 fleets. Nations looking to upgrade their F-16 fleets with advanced L3Harris Viper Shield electronic warfare (EW) protection now have a podded variant option that offers the same level of protection as an internally integrated system.

“Seven U.S. partner nations, most recently Poland, have selected Viper Shield for the suite’s advanced EW capabilities and ease of upgrade,” said Ed Zoiss, President, Space and Airborne Systems, L3Harris. “Future customers – especially those who operate the F-16 Block 50 or earlier – may prefer the flexibility of the Viper Shield external Pod to increase aircraft survivability.”

Here are five reasons why:

Advanced EW protection that’s affordable advanced digital, electronic self-protection – Viper Shield’s active production line combined with current partner nation development funding and L3Harris’ internal investments make both the internal and Pod variants affordable. The Pod’s mobility allows F-16 operators to purchase fewer Pods to support their fleets, giving ground crews the ability to swap an entire system from one aircraft to another to meet mission requirements.

Electronic Warfare (EW) – Market and Technology Forecast to 2030

Market forecasts by Region, Procurement Plan, IEW Components, System Elements, System Type, Jammer Type, RWR Type, and by End-user (Air Force, Navy, Ground, Space). Regional and Country Analysis, Market and Technology Overview, and Leading Companies

Rapid fielding to fight tonight with growth opportunities – Viper Shield leverages fully funded development for rapid fielding and integration. Its open-system design supports new growth capabilities, such as high-tech radar and electronic systems that will further enhance situational awareness, threat detection and countermeasure capabilities. Advanced features for both variants leverage commercial off-the-shelf technology and software-defined architecture.

Flexibility – Viper Shield is lighter, smaller and more modular in design than previous EW systems. The Pod fits on all F-16 blocks, from legacy to new. Its line replaceable units (LRUs) can be easily removed and replaced in the field, with room to add advanced capabilities via 3U Versatile Performance Extension upgrades in the future.

Commonality – In production today, the Viper Shield Pod and internal components are identical, down to the same part numbers giving ground crews the ability to swap an entire system from one aircraft to another to meet mission requirements. Nations will benefit from system interoperability in partner or coalition training and employment regardless of the variant they choose.

Reduced aircraft downtime – As with the internal variant, Viper Shield Pod maintenance is managed through a commercial contract with the platform prime for greater efficiency. The Pod’s accessibility and separation from the aircraft offer simple, fast repairs and quick return to service.

“Whether Viper Shield customers select the Pod variant, internal variant or both, they’ll extend the F-16’s operational life to enhance their fleet,” said Zoiss. “We’ve applied decades of F-16 EW experience to Viper Shield so these venerable fighter jets can evolve to meet the challenges of the modern battlefield and bring pilots home safely.” (Source: ASD Network)

 

24 Sep 25. MASS, part of the Cohort plc Group, has launched the latest version of its Networked Electronic Warfare Training Simulator – NEWTS IQ. Supporting electronic warfare (EW) and communications intelligence (COMINT) training in the classroom and in the field, NEWTS IQ provides a realistic learning environment for the next generation of Electronic Warfare & Signals Intelligence (EWSI) personnel. NEWTS IQ provides your personnel with fundamental EW and COMINT skills and knowledge including how to search for radio signals of a hostile nature, extract and exploit what is being said, and make a report against it. Combining a classroom-based simulator with the ability to train out in the field, personnel can learn and develop their skills in a safe and realistic environment in which all elements of the intelligence cycle can be followed. The platform brings the proven SESCO methodology to life, providing a comprehensive framework that can be applied beyond training to operational continuous validation.

Stuart (Taph) Willumsen, Head of Spectrum Warfare Training at MASS, said: “While it remains a vital part of military training to enable operators to understand the technical and tactical aspects of EW activity, the pressures and strains of the battlespace cannot be replicated in a classroom environment alone. The NEWTS IQ platform has been designed to serve the next generation of operators, with software that is standardised, repeatable, and simulates extremely challenging scenarios in increasingly realistic environments. With real world experience of deployed EW operations, and working in collaboration with the Royal Signals, MASS is committed to providing quality training opportunities within the military. NEWTS IQ demonstrates our capability to take personnel from simulation-based training through to field-based emulation and calibration training – truly enabling them to train the environment.”

The platform integrates the SESCO methodology throughout the training process, ensuring comprehensive coverage from classroom-based simulation training through to field-based emulation and calibration training. The SESCO framework sits at the heart of NEWTS IQ’s approach, enabling the transition from simulation and emulation-based training at the start, through to stimulation of current equipment, and finally calibration ready for seamless transition into an operational deployment.

The mission-specific training offered by the platform incorporates four key steps:

  • Requirements, planning and direction: plan EW, COMINT and J6 (communications) asset deployments via the BATTLEYE planning tool; determine best mission location; view maps of coverage area; and carry out Path Profile Analysis
  • Collection and exploitation: allow ability to search, intercept, direction finding and analyse IQ-embedded signals of interest (SOI); generate realistic operator experiences; offer repeatable, scalable and standardised COMINT training scenarios
  • Processing, analysis and collation: search against SOI parameters to make sense of call signs, frequency, lines of bearing and keywords
  • Production, dissemination and reporting: use the SOI repository to support a range of reporting – e.g. activity reports, tactical tip-offs, jamming reports, intelligence reports, and up and down Command and control (C2 reports)

NEWTS IQ also offers a solution to a well-known industry challenge – how to base training objectives around unknown networks.

Placing the trainer in control of each scenario, it allows them to accurately assess whether students are meeting the right objectives. A ‘train as you would fight’ tool, it immerses students in realistic environments and identifies gaps in their skills base. Blending the classroom with in-field training, students gain confidence and real-life skills prior to operational deployment.

 

23 Sep 25. Boeing [NYSE: BA] and Palantir [NASDAQ: PLTR] announced at the annual Air, Space & Cyber Conference the two companies are working together to integrate artificial intelligence (AI) systems and software across Boeing Defense, Space & Security (BDS) factories and programs. BDS will leverage Palantir’s groundbreaking Foundry platform, which leverages AI to unify complex and disparate systems under a streamlined and intuitive user interface. BDS operates more than a dozen major production lines manufacturing military aircraft, helicopters, satellites, spacecraft, missiles and weapons. The partnership between BDS and Palantir will help standardize data analytics and insights across its geographically dispersed family of defense factories.

“Palantir is on the cutting edge when it comes to leveraging Artificial Intelligence to accelerate getting critical products, services and capabilities in the hands of military operators,” said Steve Parker, CEO, Boeing Defense, Space & Security. “This collaboration is a natural fit that brings together two great companies with a common mission: supporting uniformed personnel in protecting freedom around the world.”

In addition, BDS has tapped Palantir to provide AI expertise and capabilities on a number of undisclosed classified and proprietary efforts focused on supporting military customers’ most sensitive missions.

“Palantir and Boeing Defense, Space & Security are committed to delivering dominant capabilities to the warfighter to deter conflict and defend the homeland,” said Mike Gallagher, Palantir’s Head of Defense. “This partnership will turbocharge production and innovation, allowing Boeing and Palantir to bring cutting-edge technology to current and next-generation defense programs. America’s enemies aren’t slowing down and neither can we.”

 

23 Sep 25. Raytheon’s ADVEW prototype for US Navy clears critical review. Raytheon will execute more demonstrations and deliver shipsets in the coming month for government-run integration testing. Raytheon’s Advanced Electronic Warfare (ADVEW) prototype for the US Navy’s F/A-18E/F Super Hornet has completed an important review, marking a critical milestone in its development. The new system is designed to replace the existing AN/ALQ-214 integrated defensive electronic countermeasure and AN/ALR-67(V)3 radar warning receiver of the aircraft. The review it cleared had validated the progress of the prototype’s software development, its integration with flight-representative hardware, and overall alignment with government reference architecture. Raytheon advanced products and solutions president Daniel Theisen said: “Our ADVEW prototype continues to showcase significant progress in both hardware and software that will improve the aircraft’s ability to detect and counter electronic threats.

“We are on track with our fast-paced schedule and will continue developing the system to meet all necessary requirements on the US Navy’s accelerated fielding timeline.”

In concert with the review, Raytheon has finalised a Test Plan Working Group to coordinate and streamline the in-flight performance evaluation of ADVEW. In the upcoming months, the company plans to undertake more demonstrations and deliver shipsets for government-run integration testing. Raytheon secured the $80m contract to prototype ADVEW for the F/A-18E/F Super Hornet from the US Navy in December 2023. The prototype will undergo preliminary design review, critical design review, and flight testing, as per RTX. The Delta design review for ADVEW prototype was already concluded in December last year. The primary development and testing of ADVEW are set to take place in Goleta, California. The new system will integrate closely with other combat-tested, radio frequency sensors and effectors used by the Super Hornet. This integration is expected to significantly enhance survivability against advanced threats while maintaining operational electronic warfare superiority for the F/A-18E/F Super Hornets. The F/A-18E/F Super Hornet, a high-performance twin-engine striker, has been in service since 1999 and is available in single-seat (E) and two-seat (F) configurations. (Source: airforce-technology.com)

 

23 Sep 25. Bombardier Defense Delivers Ninth Global Aircraft to the U.S. Air Force for BACN Program.

  • Delivery ceremony took place in September at Hanscom Air Force Base, MA
  • The Bombardier Global family of aircraft, recognized for its outstanding range, speed, reliability and endurance, is an ideal fixed-wing solution for special airborne missions worldwide?
  • Enduring success of the BACN program underscores Bombardier Defense’s role as a partner of choice for the U. S. military

Bombardier Defense is proud to announce the delivery of a ninth Bombardier Global aircraft to the United States Air Force. The delivery, which was celebrated at Hanscom Air Force Base earlier this month, is the latest in a long-standing and highly successful partnership between the USAF and Bombardier Defense.  The fleet of Battlefield Airborne Communications Node (BACN) aircraft, which are known in the Air Force as E-11A and often referred to as “Wi-Fi in the sky”, are a specialized communications platform that enables enhanced situational awareness and interoperability acting as high-altitude communications gateways. The Bombardier Global fleet serving the USAF has been performing critical communications missions around the world for close to two decades, serving to bridge voice and tactical data between air and land forces, while surmounting obstacles such as mountains, rough terrain or distance.

“At Bombardier Defense, we are honored to see our reliable, high-performing Global aircraft serve the United States Air Force in critical missions worldwide through the BACN program,” said Jean-Christophe Gallagher, Executive Vice President, Aircraft Sales and Bombardier Defense. “We are grateful for the longstanding trust of the U.S. Air Force, and we look forward to continuing to support the operational needs of the United States.”  (Source: ASD Network)

 

23 Sep 25. Electronic Warfare Capabilities Must Evolve at The Speed of Battle. To win in today’s highly contested electromagnetic spectrum (EMS) environment, L3Harris’ Distributed Spectrum Collaboration and Operations (DiSCO™) architecture enables the weaponization of electronic warfare (EW) data to counter advanced threats at the speed of relevance.  DiSCO technology is key to delivering real-time shared situational awareness, allowing planners, operators, analysts, and battle managers to understand the complex EMS operating environment. This is essential for orchestrating the use of non-kinetic effects across all domains.

“DiSCO’s technology provides the tools needed to orchestrate C2 across a mesh network of distributed sensors and jammers to enhance lethality and survivability for the U.S. and our partners,” said Ed Zoiss, President, Space and Airborne Systems, L3Harris. “We believe this is the only way to deliver the kind of next-gen electromagnetic spectrum operations capabilities needed at a scale. DiSCO is a perfect example of this commitment, and it isn’t just a glossy brochure – we have demonstrated real hardware and software at multiple exercises in several combatant commands across the globe.”

Joining the Battle at Talisman Sabre, U.S. Indo-Pacific Command

During Talisman Sabre 2025 in Australia – the largest bilateral military training event between Australia and the United States – L3Harris demonstrated DiSCO’s capabilities to employ distributed multi-domain platforms in a remote theatre.  The company connected an aircraft and two autonomous surface vessels equipped with compact EW payloads that were streaming and fusing radio frequency (RF) signal information coming from attacking vessels to enable real-time situational awareness, signal analysis and tactical intelligence support. DiSCO’s precision geolocation and autonomous reprogramming capabilities gave the U.S. Indo-Pacific commander actionable information on high-priority surface targets while countering incoming attacks. The L3Harris team also gained valuable insight into operational challenges and warfighter needs to guide future development.

Connecting Across an Ocean at DSEI in London, U.S. European Command

L3Harris joined Defence and Security Equipment International (DSEI) 2025 with a live DiSCO demonstration that combined communications data from an EW sensor onsite in London with live radar RF data from an EW sensor located at the company’s site in Clifton, New Jersey. The team also integrated live radar RF data from New Jersey with prerecorded communications data from a Modular Electronic Warfare System (MEWS) sensor that was integrated on an uncrewed surface vessel in London. These demonstrations proved DiSCO’s ability to incorporate communications and radar sensor data into a real-time cloud-connected common operating picture across thousands of miles. They also provide DiSCO’s ability to integrate a non-U.S.-built and fielded EW sensor with associated signal data.

Ensuring Global Electronic Warfare Superiority across all Combatant Commands

Modern adversaries will continue to employ advanced, long-range and agile threat systems that are difficult to detect, locate, identify and counter. Addressing these trends will require solutions that provide access to relevant EW data and can operate in heavily contested, congested and complex operational environments.

“We are investing heavily as a company to develop multi-domain, cloud-based and software-defined technologies to deliver this much needed next-gen capability,” Zoiss said.

Building on the success of Talisman Sabre, DSEI and ongoing internally funded development activities, L3Harris is planning more DiSCO demonstrations at upcoming exercises with U.S. and international partners. These events will further validate the need for DiSCO’s cloud-connected EW data sharing, advanced processing, and command-and-control functions to deliver electromagnetic battle management capabilities to the warfighter as quickly as possible. (Source: ASD Network)

 

23 Sep 25. Patria CATCHR introduced at EW Live in Tartu. Next generation ESM surveillance system offering superior situational awareness. Patria showcases its new high-performance ESM (Electronic Support Measures) surveillance system Patria CATCHR at the EW Live exhibition in Tartu on September 23, 2025. The system delivers real-time situational awareness by cutting through the noise — enabling fast, informed actions and precision countermeasures.

“In today’s crowded electromagnetic battlespace, even the faintest signal can reveal a critical threat. Staying ahead in intelligence and surveillance requires early, accurate detection and the ability to distinguish targets from a dense and dynamic signal environment. Vulnerable active sensors must be complemented with covert and agile passive sensors to ensure mission survivability. We are proud to launch this new innovative product in this area, Patria CATCHR,” says Mikko Leino, Executive Vice President of Patria’s Defence and Weapon Systems business area.

Patria CATCHR delivers the full capabilities of a high-performance ESM system combined with advanced signal intelligence features. It intercepts, geolocates, and tracks radar emitters generating a recognized situational picture, while allowing operators to explore detailed signal patterns. When deployed as a distributed sensor network, the system provides passive, wide-area surveillance that remains invisible to adversaries – offering superior situational awareness and enabling rapid countermeasures against evolving threats. Patria CATCHR is designed to perform under pressure. Built on advanced signal processing algorithms, it sorts through dense electromagnetic traffic, detects and classifies even the weakest radar emissions, geolocates threats with high precision, and operates completely passively, without revealing its own position.

 

22 Sep 25.  Europe: Large-scale cyber attack showcases operational risks in software supply chain. Earlier on 22 September, the EU Agency for Cyber Security (ENISA) reported that an unnamed ransomware operation was behind the large-scale cyber attack that targeted the high-profile aviation technology provider Collins Aerospace on 20 September. This cyber attack impacted one of the company’s aggregate digital services, ‘Multi-User System Environment’ (MUSE), resulting in the disruption of automatic check-in services at several major airports across Europe. This caused delays and flight cancellations as affected airports were forced to resort to manual check-ins, highlighting the spillover impact of such attacks. Earlier on 22 September, Brussels Airport (BRU, Belgium) warned of ongoing cancellations, while major disruption at London Heathrow Airport (LHR, UK) and Berlin Brandenburg Airport (BER, Germany) had eased by 21 September. We assess that it will possibly take a few more days for full resumption of air traffic operations, as investigations are ongoing. Collins Aerospace is reportedly finalising software updates to remediate the attack. This cyber attack showcases the security and operational risks stemming from the software supply chain. (Source: Sibylline)

 

19 Sep 25. Cyber Update Key points

  • A data-theft operation has highlighted the supply chain and security risks facing several high-profile customers of a popular sales management platform.
  • A North Korean state-sponsored group (‘Kimsuky’) poses sustained security and social engineering risks to the South Korean defence sector through the adoption of deepfake military ID cards.
  • A large-scale data leak operation against a Swedish IT systems provider will increase security, social engineering and second-order risks to Swedish entities.
  • The US financial sector will face increased financial and operational risks from the cyber criminal group ‘Scattered Spider.’
  • A cyber operation by the Chinese state-sponsored group ‘APT41’ has underscored the long-term security and cyber espionage risks facing US organisations.

Technical analysis of weekly stories

The North Korean state-sponsored group Kimsuky has used deepfakes to conduct a cyber operation against South Korean military agencies since at least July. The group distributes phishing emails impersonating a legitimate South Korean defence organisation to infiltrate targeted systems. The emails trick users into clicking on an embedded deepfake ID card for targeted military personnel; these ID cards are created using the generative artificial intelligence (AI) platform ChatGPT, highlighting the increased exploitation of legitimate AI platforms for malicious cyber activity. This action covertly executes malicious scripts hidden within the cards to establish communication with command-and-control (C2) infrastructure and download additional malicious files. Kimsuky then creates a scheduled task to maintain persistence within compromised systems, enabling data exfiltration and remote control. Script execution is delayed by a few seconds after the fake cards are opened, so as to remain obfuscated; meanwhile, the scheduled task is disguised as a legitimate update, further showcasing the group’s detection evasion capabilities.

The cyber criminal group Scattered Spider conducted a cyber attack against an unnamed financial institution in the US in August. The group reportedly used social engineering techniques to hijack an executive’s account via the access management solution ‘Microsoft Entra ID’. Scattered Spider then moved laterally through the organisation’s virtual private network (VPN) and cloud environments to monitor data and infrastructure. It also compromised virtual machines to steal employee credentials before escalating privileges to exfiltrate sensitive information. We assess that the group likely used the stolen data for extortion after encrypting the system’s files and deleting backup files to hinder recovery. This operation follows the discovery of several domains associated with Scattered Spider that target the financial sector, pointing to a potential shift in the group’s priorities. Some of the domains also overlapped with activity from another cyber criminal group (‘Shiny Hunters’), indicating a possible collaboration between the two groups.

Non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware.
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.

Our cyber word of the week: Scheduled task (Source: Sibylline)

 

19 Sep 25.  L3Harris, Palantir advance radio-as-a-sensor concept. Palantir Technologies has teamed with L3Harris to advance a new data network concept, leveraging data collected from L3Harris’ family of software-defined radios and using Palantir-built software to turn this data into actionable battlefield intelligence. The ‘radio-as-a sensor’ concept was borne out of L3Harris’ artificial intelligence (AI) integration work with the US Army’s Tactical Intelligence Targeting Access Node (TITAN) programme, for which programme officials had already been working with Palantir, according to Samir Mehta, president of Communications Systems at L3Harris.

“The work we’re doing with Palantir now … is figuring what level of compute do you need” aboard a given radio tactical communications device, Mehta said regarding technology maturation work on the radio-as-a-sensor concept.

“We always think about what kind of AI we need on the device or radio, but what we really [want] to develop is the radio as a sensor. It is not just what [data] the radio processes but what [data does] the radio sense, and right now that information goes into the ether,” Mehta told Janes during an August interview at the company’s tactical radio facility in Rochester, New York.

“When you turn on a radio, it [scans] different frequencies to figure out what the appropriate frequency [should be] given the threats that are out there,” Mehta said. “So [the radio] finds the appropriate frequency and it optimises around it and communicates using that frequency,” he explained. (Source: Janes)

—————————————————————————————————————————————————————————————————————————————————————————————————————————————

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

—————————————————————————————————————————————————————————————————————————————————————————————————————————————

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

September 18, 2025 by

Sponsored By Curtiss Wright

 

https://www.curtisswright.com/

———————————————————————————————————————

16 Sep 25. Persistent Systems, LLC (“Persistent”), a leader in mobile networking solutions, announced today that its Cloud Relay™ Virtual Hub Router is now available on Microsoft Azure, expanding from its previous availability on Amazon Web Services (AWS). This expansion enables seamless access to a unified networking capability, unlocking multiple gateways to global distributed operations for the Department of Defense (DoD) and allied forces.

“Cloud Relay is increasingly requested and integrated into customer solutions because it has moved beyond just providing Beyond Line-of-Sight (BLOS) connectivity,” said Adrien Robenhymer, Vice President of Business Capture for the Air Force at Persistent Systems. “It now serves as a highly resilient and secure Software Defined Wide Area Network (SD-WAN), enabling rapid global deployment and a global fabric of connectivity by uniting all sensors, shooters, warfighters, and devices in real time.”

Previously, Cloud Relay has been operationalized and used during major exercises such as PC-C5 and Valiant Shield 2024, as part of the MANET-Cloud High Mobility Radio (MCHMR) solution, which supports Agile Combat Employment (ACE) for rapid deployment across land and sea.

“With Cloud Relay and MCHMR, acting as the switchboard that unites the Air Force, Army, and Marines onto a single operating picture, they can seamlessly coordinate across vast distances, integrate low-cost attritable systems, and make decisions faster, transforming how they operate,” said Robenhymer.

While traditional networks have single points of failure, MCHMR, utilizing Cloud Relay, ensures resilient connectivity in RF-denied and degraded environments, even as forces rapidly move operations. Providing the backbone for MCHMR, Cloud Relay unites various transport mechanisms – satellite, cellular, fiber, and government datalinks – to ensure that all services can extract, share, and act on sensor and shooter data from a unified network.

The ability to deploy globally and access the cloud across multiple regions ensures that forces maintain situational awareness, shorten the kill chain, and synchronize operations in real time, giving warfighters a ‘fight tonight’ capability to counter emerging threats anywhere in the world.

“Ultimately, the network is what communicates to weapon systems when and where they should launch,” Robhenhymer added.

With the expansion to Microsoft Azure, Persistent Systems will be able to support up to 60 global regions, providing broader accessibility for international operations and faster cloud-based integration. As the DoD moves toward low-cost, attritable systems and seeks to avoid vendor lock, Cloud Relay delivers the transport-layer solution necessary to integrate diverse platforms and partners.

 

17 Sep 25. Sweden: Large-scale data leak operation will increase security, social engineering risks. On 16 September, the Swedish prosecution authority reported that a threat group (‘Datacarry’) conducted a large-scale data leak operation against a high-profile Swedish IT systems provider in August. The attack resulted in the exfiltration of the personal data of approximately 1.5 m people (nearly 15% of Sweden’s population), including names, addresses and contact details. Datacarry released the stolen data on the dark web, possibly because the targeted company failed to meet the group’s demand for a payment of 1.5 Bitcoin (about USD 170,000). The attack affected at least 164 municipalities and several private companies, including those in the defence and transportation sectors, showcasing the operation’s scale and potential impact. Threat actors will likely exploit the stolen data in further social engineering attacks in the short term. As such, we assess that Swedish organisations will face elevated security, social engineering and second-order impact risks.(Source: Sibylline)

 

16 Sep 25. Honeywell And Redwire Advance Collaboration On Quantum-Secured Communications For Civil And Defense Customers. Companies will advance next generation quantum-secured satellite communications on Honeywell’s QKDSat Project with the European Space Agency, sponsored by the UK, Belgian, Austrian, Canadian, and Czech Republic Space Agencies.

Honeywell (NASDAQ: HON) today announced a Memorandum of Understanding (MOU) that advances a European Space Agency-backed initiative to develop new quantum-secured satellite communication systems.

The MOU, signed with Redwire Corporation (NYSE: RDW), is the latest milestone under the Quantum Key Distribution Satellite consortium (QKDSat), which was launched in 2024 and is being led by Honeywell. It will enable the two companies to explore opportunities to mature and expand the use of quantum key distribution technology as part of the consortium, which operates under the European Space Agency’s QKDSat Public Private Partnership.

The aim is to combine Redwire’s quantum platform technology with Honeywell’s quantum optical payload, creating a fully functional payload and platform by mid-2026. The collaboration aims to advance quantum-secured technologies that could help governments and defense agencies protect sensitive information from emerging cyber and quantum threats, while also accelerating next generation quantum key distribution services for commercial customers.

The QKDSat project brings together companies from ESA Member States including Belgium, Austria, Canada, Czechia, and the United Kingdom to develop an ultra-secure telecommunications satellite that ensures the secure and private exchange of sensitive information.

“The defense and space communications landscapes are evolving rapidly, with security and resiliency now the top priority for governments and critical industries,” said Lisa Napolitano, vice president and general manager, Space, Honeywell Aerospace Technologies. “By combining Honeywell’s quantum optical payload technology and experience in satellite communications with Redwire’s expertise in agile platforms and onboard quantum computing, we are bringing the promise of quantum-secured communications closer to reality.”

In addition to civil and defense-related applications, Honeywell and Redwire plan to demonstrate space and ground-based quantum communications capabilities for commercial organizations such as financial institutions, telecommunications providers, and critical infrastructure companies that generate large volumes of confidential data.

“Quantum-enabled telecommunications could be a gamechanger for government agencies and the private sector, and our collaboration with Honeywell is focused on delivering cutting edge innovation to mitigate increasingly sophisticated threats,” said Marc Dielissen, General Manager of Redwire Space Belgium. “Working together with ESA, the world-class team of Redwire and Honeywell leverages the strength of Public-Private Partnerships to initiate a quantum-secure space network that could set a new standard for secure global communications.” (Source: ASD Network)

 

12 Sep 25. Nato agency to take advantage of Oracle Cloud Infrastructure. It is expected to improve performance, availability, incorporate AI innovation, and enhance security for NCIA’s operations. As part of its modernisation efforts, NCIA is seeking to enhance system capacity and optimise performance. Credit: Tada Images/Shutterstock.com. The Nato Communications and Information Agency (NCIA) has selected Oracle Cloud Infrastructure (OCI) as the new platform for its essential workloads. The transition, facilitated by Red Reply and Shield Reply—companies within the Reply Group that focus on Oracle technologies—and led by Thales as the prime contractor, aims to leverage OCI’s dedicated cloud solutions.

Proximus is tasked with providing advanced networking capabilities.

The move is expected to improve performance, availability, incorporate AI innovation, and enhance security for NCIA’s operations previously managed on-premises.

NCIA serves as Nato’s technological and cybersecurity nerve centre, with a mandate to connect the Alliance, defend its networks, and support its operations through “secure, cost-efficient, and interoperable communication and information systems”.

As part of its modernisation efforts, NCIA is seeking to enhance system capacity and optimise performance.

Thales network and infrastructure systems vice president Alexandre Bottero said: “Together with Oracle, we are committed to helping NCIA provide secure, cloud-oriented, and interoperable communications and information systems and services to Nato.

“With OCI, NCIA will be able to take advantage of the latest cloud and AI innovations to modernise its technology infrastructure without compromising the security of its mission-critical data.”

The capabilities of OCI’s sovereign cloud are set to meet NCIA’s stringent requirements for data residency, hyperscale services, and operational controls.

Reply CTO Filippo Rizzante said: “Red Reply and Shield Reply, as the selected Oracle partners, will bring their deep expertise in Oracle technologies, delivering a full suite of consulting and managed services — from discovery and secure design to the migration of three legacy data centres to Oracle Cloud Infrastructure.

“Our goal is to ensure a secure, seamless, and future-proof transition to the cloud for NCIA’s mission-critical workloads.”

In related news, Google Cloud has secured a £400m ($543m) contract to establish a UK sovereign cloud for the UK Ministry of Defence (MoD).

The project will furnish a secure cloud platform that fosters innovation while enhancing data control for the MoD.

It aligns with the MoD’s Strategic Defence Review objectives of utilising advanced cloud infrastructure for advanced capabilities in secure information processing.

The partnership is also set to stimulate job creation, develop skills, and growth among startups and small-to-medium enterprises in the UK defence sector.

Google Cloud’s investment includes assembling a team within the UK dedicated to this initiative.

Google Cloud EMEA president Tara Brady said: “This partnership will enable the MOD to accelerate its digital modernisation efforts while maintaining the highest levels of security and data sovereignty.” (Source: army-technology.com)

 

15 Sep 25. UK and US share defence intelligence through Google Cloud. This £400m expenditure will exploit the latest technology including, the MoD stated, AI, data analytics, and cyber security. The UK Ministry of Defence (MoD) announced that it will contribute £400m ($543.5m) toward securing intelligence sharing with the United States through the Google Cloud platform. Slightly subsumed by the extensive industry activity to come out of DSEI 2025 last week, the move to secure communications between the two nations will exploit the latest technology, including, the MoD stated, artificial intelligence (AI), data analytics, and cyber security.

Defence intelligence and national security specialists on both sides of the Atlantic will share secure information and “outcompete” their adversaries, namely Russia and China.

The deal has already led to ms of pounds of inward investment from Google Cloud, the UK government suggested without revealing any specific sum, the US company will recruit a specialist dedicated team in Britain to manage these technologies.

Second state visit

The move touches on several tenets underlying the Strategic Defence Review (SDR), for a digitally integrated service, and the more recent Defence Industrial Strategy, which introduced a new consulatation policy where UK investment overseas then strengthens the British economy is in return with jobs and technology.

Furthermore, the MoD also hinted that more will come when the US president Donald Trump’s second state visit later this week. (Source: army-technology.com)

 

16 Sep 25. South Korea: Defence sector faces sustained security risks from North Korean actors. On 15 September, the software company Genians reported that the North Korean state-sponsored group ‘Kimsuky’ has used deepfakes to conduct a cyber operation against South Korean military agencies since at least July. The group distributes phishing emails impersonating a legitimate South Korean defence organisation to infiltrate targeted systems. The emails trick users into clicking on an embedded deepfake ID card for targeted military personnel, which is created using artificial intelligence (AI) to enhance legitimacy, highlighting the increased incorporation of AI into malicious cyber activity. This action covertly executes several malicious scripts onto compromised systems that enable Kimsuky to maintain persistence and exfiltrate sensitive data, likely for espionage purposes and/or financial profit. Kimsuky also uses several advanced obfuscation techniques, underscoring its continuous development and sophistication. Consequently, we assess that this operation showcases the long-term security risks facing defence organisations, as South Korea remains one of Pyongyang’s key strategic targets. (Source: Sibylline)

 

16 Sep 25. Filtronic joins TEAM FORTITUDE as founding partner to deliver sovereign electronic deception capability. Filtronic, a leading designer and manufacturer or advanced RF and microwave solutions, has announced it has joined TEAM FORTITUDE, a sovereign partnership with Penten Amio, Mercury-EW and a wider supplier ecosystem. This collaboration brings together trusted British SMEs to deliver high-performance, agile and export-ready Electronic Deception capabilities.

TEAM FORTITUDE is a response to the growing demand for sovereign capability in the Electronic Warfare domain, leveraging the agility and innovation of UK SMEs. Together, the partners offer a flexible and scalable ecosystem that can rapidly respond to evolving defence requirements. The core team is also able to draw on a wider network of sovereign specialist SMEs and best-in-class suppliers, enabling a tailored and modular approach to customer needs.

Filtronic’s role in TEAM FORTITUDE is to provide specialist design, development, manufacturing, and testing of complex RF hardware, enabling rapid transition from early technology readiness levels (TRL) to scalable volume production. With decades of experience in high-reliability RF solutions for defence, aerospace and space markets, Filtronic ensures that mission-critical Electronic Warfare hardware is delivered on time, to specification, and ready for deployment.

“We’re proud to be a founding partner of TEAM FORTITUDE, bringing our RF engineering expertise to support the UK’s sovereign defence capabilities,” said Nat Edington, CEO of Filtronic. “This partnership showcases the strength of collaboration between innovative British SMEs and creates a robust platform for delivering cutting-edge EW technology both at home and abroad.”

“Our mission is to deliver trusted innovation that gives our defence partners the operational edge,” said Matt Thomas, UK CEO, PentenAmio. “By forming TEAM FORTITUDE, we’re uniting best-of-British capability to accelerate the delivery of electronic deception technologies—not only for the UK MOD, but also in support of our AUKUS partners across Australia, the United States, and the broader allied defence community.”

“At Mercury EW, we firmly believe that human performance is central to operational success,” said Andrew Lonsdale, CTO, Mercury EW. “With the increasing prevalence of technology and automated intelligence in military operations, we must train our people cleverer, earlier, and with absolute fidelity to overmatch our adversaries. As a proud co-founding member of team Fortitude, that is our objective.”

TEAM FORTITUDE also opens significant export opportunities, positioning the UK as a key player in the global Electronic Warfare market. The combination of sovereign capability, agile innovation and proven industrial capacity presents a compelling proposition for allied nations seeking trusted partners for advanced Electronic Deception capabilities.

Looking ahead, the team sees opportunities for growth across land, maritime, air and space domains, offering high-performance, scalable solutions that can be tailored for both current and future operational needs.

 

12 Sep 25. Leonardo confirms latest in EW – BriteCloud, BriteStorm. On the sidelines of DSEI 2025, Leonardo confirmed new details regarding its electronic warfare suite. Leonardo has confirmed details of its electronic warfare (EW) systems, BriteCloud and BriteStorm, during DSEI 2025.

BriteCloud

BriteCloud is said to be the world’s first Digital Radio Frequency Memory (DRFM) Expendable Active Decoy (EAD). The system protects fast-jet aircraft and their crews against a growing range of airborne and surface-based radio frequency (RF) threats.

In doing so, the EAD has a self-contained jammer – meaning the device has all the necessary components (a transmitter and power source within a single unit, ready for immediate use). Leonardo engineers designed the decoy to disrupt incoming missiles’ RF tracking systems and produce a ‘miss distance’, minimising the risk of a missile exploding on or close to the platform.

On the second day of DSEI, Michael Lea, vice president of sales for EW at Leonardo, officially confirmed that BriteCloud is indeed the United States’ extant ALQ-260(V)1 EAD.

Previously, the US Air National Guard issued a ‘fielding recommendation’ for BriteCloud 218 (2x1x8 inches) as part of a Foreign Comparative Testing programme involving American F-16 Fighting Falcon fighter jets.

Going forward, Lea also revealed that BriteCloud will be integrated onto the F-35 Lightning II multirole aircraft, and in the same breath, mentioned that the company has already dispensed the systems to the user. Furthermore, development is already underway to integrate the EADs onto the F-18 Super Hornet at sea.

“We should have a fleet wide Nato embodiment of BriteCloud onto F-35… after the US went public, we had a range of inquiries come in,” Lea confirmed.

However, the Eurofighter Typhoon will deploy a different cylindrical ‘BriteCloud 55/55T’ variant, compatible with the aircraft’s 55mm chaff and flare dispenser. The alternative 55T variant provides greater radiated power and endurance, Lea discerned, and the system is in trials with the first frontline deployment expected in 2026.

BriteStorm

Meanwhile, BriteStorm is a low size, weight, and power stand-in jammer payload, meaning the EW system operates in close proximity to enemy air defences to suppress or decieve them.

The EW jewel in the crown for the UK Royal Air Force (RAF) is StormShroud, a modular TEKEVER AR3 autonomous collaborative platform (ACP) that utilises Leonardo’s BriteStorm capability. Specialists have already trialled the capability with RAF assets and coalition aircraft. The service will reach initial operational capability within the next 12 months, Lea added.

“We very much see a force mix of ACPs working in conjunction with fourth, fifth generation aircraft… using the same underlying software architectures,” Lea remarked.

BriteStorm can act as a decoy to stimulate enemy air defences. BriteStorm can also produce obscuration and confusion techniques to deny the enemy from building up a complete air picture. “So they may decide to use an ACP with BriteStorm on as a decoy or they may decide to use it as a stand-in jamming capability in itself,” he continued.

Lea also confirmed that the future roadmap includes autonomy and cognitive EW, enabling ACPs to switch mission functions dynamically and integrate with Typhoon and F-35 operations. There is currently interest from the UK, Europe and the United States with export opportunities being pursued. (Source: airforce-technology.com)

———————————————————————————————————————-

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

———————————————————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

September 14, 2025 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

—————————————————————————————————————-

12 Sep 25. Morpheus goes incremental. Sources close to BATTLESPACE at DSEI suggest that due to budgetary restrictions and the settlement of the extra funding with GDUK for the EVO project, that Morpheus will not be the big bang approach as originally envisaged. The data terminals will be sole sourced from Leonardo DSR and the radios competed on an incremental basis.

 

11 Sep 25. Take the Blame

‘Named and Shamed’, the editorial for the September edition of Armada’s Electronic Warfare Newsletter, our sister publication, discusses the recent unmasking of the alleged perpetrator responsible for the loss of Azerbaijan Airlines Flight 8243. On 25th December 2024 an Embraer 190 airliner crashed on approach to Aktau international airport, western Kazakhstan. The aircraft had been hit by a missile fired from a Russian Army Pantsir-S1 (NATO reporting name SA-22 Greyhound) short-range air defence system. The Pantsir-S1 has been deployed near Grozny, southern Russia. The identity of the Pantsir-S1 unit’s commander who ordered the shot has now been revealed. 67 passengers and crew were aboard the airliner, 38 of whom lost their lives.

Armada chronicled in our ‘Someone had Blundered’ article published on 6th February factors surrounding the shootdown. The piece articulated reports that the aircraft had experienced interference to its Global Navigation Satellite System (GNSS) receiver as it flew from Baku to Grozny that day. The interference was likely to have been caused by deliberate jamming and spoofing of Position, Navigation and Timing (PNT) signals transmitted from GNSS constellations by Russian military deployments near Grozny.

This is not the first time the Russian military, and by default the Russian government, have been accused of reckless, deliberate, PNT signal interference. Over the last decade, reports of GNSS jamming and spoofing blamed on Russia have increased in the Baltic and Black Sea regions. Russia is trying to protect key politico-military, industrial and urban targets from attack by GNSS-guided weapons and uninhabited aerial vehicles. It is deeply irresponsible for any state to deliberately interfere with GNSS reception. Moscow would doubtless argue it is protecting potential targets against Ukrainian GNSS-guided weapons, despite Russia being the initiator of her war with Ukraine. This is no excuse if such actions cause a loss of life for third parties not involved in the conflict.

In July, the International Civil Aviation Organisation (ICAO) called on Russia to cease and desist deliberate GNSS disruption. Moscow has 30 days to explain its actions, otherwise the ICAO assembly may consider these a violation of international law. Whether Russia will listen to the ICAO’s request is another matter. As of late August, it did not appear any response to the ICAO’s request has been received. The sad thing is that Russia will probably continue with the GNSS jamming, and that this will continue to disrupt air travel in the parts of the world where it is occurring. Fortunately, airliners have several navigation systems they can use to ensure safe flight. Technically, the loss of the GNSS signal should be manageable. Yet Azeri authorities investigating Flight 8243 have determined PNT disruption as a potential contributing factor. At the very least, losing the signal may have degraded cockpit situational awareness. The best course of action Russia could take is to stop all GNSS jamming with immediate effect. At the very least, this would help to reduce the likelihood that GNSS disruption becomes a factor in any future tragedy. (Source: Armada)

 

11 Sep 25. September Radio Roundup.

All Space Hydra-4 MAX satellite communications terminals will receive upgrades to their modems allowing them to use Telesat Government Solutions’ forthcoming Lightspeed low earth orbit satellite communications network.

Armada’s monthly roundup of all the latest news in the military communications product, programme and operational domains.

Globalstar secures CRADA

Globalstar has been awarded a Cooperative Research and Development Agreement (CRADA) from the US Army to evaluate the company’s satellite data solutions for military applications. The news was revealed in a company press release published on 16th July. Henry Orejuela, Globalstar’s head of government sales and business development, told Armada that this “partnership with the US Army is structured to provide direct access to emerging commercial satellite communications technologies for tactical and field-based applications”. Mr. Orejuela said that the army will evaluate Globalstar’s “low size, weight, power and cost satellites for IOT (Internet of Things) devices which are designed for long-duration deployment in austere environments without the need for regular maintenance and infrastructure support”. He added that the force will evaluate how these terminals perform in “real-world defence scenarios”. Such scenarios include asset tracking, CBRN (Chemical, Biological, Radiological and Nuclear) monitoring, unattended ground sensing and uninhabited system telemetry. The company’s devices have low probability of interception/detection attributes to help ensure protection against electronic attack. Globalstar also has a slice of the radio spectrum in the 11.5 megahertz terrestrial segment of the radio spectrum known as Band-53/N53. Band-53/N53 provides fifth generation (5G) cellular connectivity. Mr. Orejuela added that the army will evaluate how this band could support “pop-up 5G networks for tactical use” via the CRADA. The agreement is expected to last for three years concluding in 2027.

Lightspeed SATCOM Partnership

Telesat Government Solutions and All Space have concluded a Memorandum of Understanding (MOU) that will see the latter’s terminals integrated with the former’s Low Earth Orbit (LEO) network. Armada was told via a written statement that the MOU will see both companies collaborating “on joint customer use-case evaluations and field demonstrations”. This work will ensure that All Space’s Hydra-2 MAX and Hydra-4 MAX military Satellite Communications (SATCOM) terminals have type certification. The effort will also ensure the terminals are ready for when Telesat’s Lightspeed SATCOM services commence. All Space terminals are in operational use with the United States Army and US Navy, the statement added. Armada understands that the terminals will be made ready for Lightspeed via an upgrade to the terminal’s modems. This upgrade is currently under development. Telesat Lightspeed satellites will be launched from late 2026 with global SATCOM services commencing in 2027. Type approval should occur that same year once several of the Lightspeed LEO satellites are in orbit and terminal testing can begin. (Source: Armada)

 

11 Sep 25. Kahootz, the leading British provider of secure online collaboration platforms, announced the launch of Kahootz in a Box, a game-changing deployable solution designed for organisations that demand the highest levels of security and data sovereignty. Delivered in partnership with Nightball Technologies, the platform combines Kahootz’s proven secure collaboration expertise with Nightball’s CRIW® Cyber Resilient platform to create a fully autonomous system that can be deployed in even the most demanding operational environments without the common assurance challenges.

Kahootz in a Box allows organisations to stand up a complete collaborative environment interoperable with their own infrastructure entirely independent of external cloud services and designed to be deployed across multiple classification levels. From air-gapped networks to rapid field deployments, it integrates seamlessly with existing security protocols and architectures. For government agencies, defence firms, and other critical enterprises, this means total operational sovereignty and control over sensitive data, whilst retaining the full collaborative capabilities trusted by the UK’s most critical programmes.

Luca Leone, CEO of Kahootz, said: “Kahootz in a Box gives our clients the freedom to deploy secure collaboration wherever and whenever it is needed. It combines rapid deployment with the uncompromising security and functionality our customers expect, ensuring teams can work effectively even in the most sensitive environments.”

The launch marks another step in Kahootz’s continued growth in the secure collaboration market, with recent contract awards from the MOD, and international partnerships with major defence and security providers, and new government deployments.

Polly O’Meara, Managing Director of Nightball Technologies, said: “Nightball Technologies are proud to work closely with Kahootz, bringing together our experience of deploying secure solutions with Kahootz’s secure collaboration expertise. It is vital our customers have a secure way of collaborating, even in the most complex of environments.”

 

04 Sep 25. YEO Messaging, the British leader in AI-powered secure communications with continuous biometric authentication, has announced it has signed an agreement with CS Comms, a specialist provider in delivering secure, robust communications to defence organisations operating in some of the world’s most austere, and tightly controlled military environments.

In the collaboration agreement, CS Comms will use the YEO Messaging for Business app as the encrypted messaging backbone behind its Phantom Signal solution, to give UK defence and government personnel operating discreetly on the ground, a combined bespoke specialised global SIM service with a fully encrypted, continually facial recognition verified, geo-fenced messaging platform.

Founded by military veteran Craig Sykes, CS Comms first emerged from years of service within the highest levels of UK Defence, and has subsequently evolved into a trusted provider of bespoke, defence-ready SIM technology and more. Phantom Signal now integrates SIM-level protection with YEO Messaging’s continuous biometric authentication; end-to-end encryption to secure messages; and voice and video calls. Together, the combined solution ensures that sensitive operational communications remain private, controlled, and compliant, even in high-threat environments.

“In the environments we operate, secure communications are the foundation of survival. By integrating YEO Messaging for Business into our Phantom Signal platform, we’ve added a layer of identity-verified encryption that matches the strength of our SIM technology.”  Noted Craig Sykes, Founder of CS Comms.  “Together, this gives defence teams complete confidence that their communications are secure, private, and under their control, no matter where they are in the world.”

“CS Comms takes YEO Messaging into some of the most demanding and sensitive environments imaginable. Pairing our identity-verified, end-to-end encrypted platform with their Phantom Signal infrastructure creates a uniquely secure communications channel that’s not only resistant to interception, but also simple for personnel to use in the field.” Said Christo Conidaris, CRO of YEO Messaging. “It’s a powerful example of how the right technology partnership can directly enhance the operational safety of our armed forces.”

 

12 Sep 25. Savox Communications Oy Ab (Ltd) (Savox) and Nokia Solutions and Networks Oy (Nokia) today announced a Memorandum of Understanding (MoU) to explore the development of joint solutions in the defense communications space. By combining their technical expertise, Savox and Nokia aim to create innovative solutions for tactical communications that provide unmatched connectivity, speed, and reliability for mission-critical operations. Under the agreement, this collaboration will explore:

  • Enhanced Connectivity: Leveraging 5G and 6G networks to provide seamless and ultra-fast communication channels for tactical operations, ensuring real-time data exchange and improved situational awareness.
  • Advanced Solutions: Developing innovative solutions that combine the strengths of both companies, such as secure communication devices, advanced encryption technologies, and robust network infrastructure.
  • Global Reach: Expanding the reach of tactical communication solutions to global markets, enabling defense and security forces worldwide to benefit from state-of-the-art technology and enhanced operational capabilities.

“By integrating Savox mission-critical audio, command and control solutions with Nokia´s advanced networks, we will deliver reliable, scalable communications tailored for the most demanding operations,” said Jerry Kettunen, CEO at Savox.

“Nokia is committed to innovation and excellence in communications technology,” said Giuseppe Targia, Head of Space and Defense, Nokia. “We look forward to working with Savox to create new and innovative solutions that will benefit our customers and the industry as a whole.”

 

12 Sep 25. AARONIA AG showcased its AARTOS Drone Detection & Defense System (DDS) and demonstrated live how state-of-the-art CUAV capabilities are key to enhancing the agility and resilience of tomorrow’s armed forces – fully aligned with this year’s motto, “Preparing the Future Force.”

Programmable 360° Smart Jammer – Full Spectrum Control

The new AARTOS 360° Smart Jammer redefines electronic countermeasures, setting an entirely new benchmark. Instead of relying on rigid presets, operators – or the software itself, if desired – can mark and suppress any signal in real time within the 400 MHz to 6 GHz range (expandable upon request).

Whether targeting individual channels, multiple frequency bands, or the entire spectrum, the Smart Jammer enables surgical precision interventions. Equipped with 4 to 8 sector antennas, its effects can be directed with pinpoint accuracy into one or multiple directions simultaneously, achieving ranges of up to 10 km and an output power of up to 800 W CW (up to 5000 W EIRP).

It is currently the only system worldwide that combines frequency programmability, 360° coverage, sector-based steering, and real-time operator intervention. For electronic warfare specialists, this means maximum flexibility, instant responsiveness, and a system that adapts seamlessly to any tactical scenario.

Modularity, Precision, Speed

In addition to the Smart Jammer, AARONIA highlighted the modular architecture of AARTOS:

Ultra-compact, agile systems for flexible deployments

Mobile turnkey solutions such as the Mercedes Zetros 6×6 with integrated AARTOS X9

Wide-area protection networks covering entire operational zones

All systems deliver precise direction finding, reliable geolocation, and ultra-fast sweep rates to provide a resilient real-time operational picture. Hardware capabilities are enhanced by the RTSA-Suite PRO software, which analyzes broadband data streams, integrates multiple receivers, and supports decoders as well as pattern recognition for rapid, reliable decision-making.

Targeted Demand at DSEI

“The conversations at the exhibition made it clear: decision-makers today seek not broad information but precise, tailored solutions to specific operational scenarios,” said Stephan Kraschansky, CEO of Aaronia Austria. “With AARTOS, we can meet these requirements – through modular hardware, precise localization, rapid analysis, and the programmable 360° Smart Jammer as the centerpiece of modern electronic warfare.”

Proven Protection – Ready for the Future

AARTOS is deployed in over 650 installations worldwide and has proven itself in highly critical scenarios – from summit and large-event security to 24/7 military operations. It combines cutting-edge sensors, powerful effectors, an integrated C2 system, and programmable jamming – available in a variety of turnkey solutions ranging from shelters to military and civilian vehicles, as well as large-scale infrastructures. This provides armed forces with maximum flexibility and resilience against future threats.

With its presence at DSEI 2025, AARONIA has underscored how the programmable 360° Smart Jammer, in combination with the modular AARTOS systems, is setting new benchmarks in electronic warfare – and making a vital contribution to building the Future Force.

 

12 Sep 25.  AI-related campaign underscores elevated security risks to businesses. On 11 September, the cyber security company Trend Micro reported that unnamed threat actors are leveraging fake artificial intelligence (AI) tools to infiltrate targeted organisations. Threat actors reportedly create and distribute fake AI applications on newly registered websites purporting to provide authorised software downloads. The applications then covertly execute malicious code during the download process that deploys malware onto compromised systems (‘EvilAI’). The applications can simultaneously carry out advertised functionalities to enhance legitimacy, highlighting the actors’ sophistication and detection evasion capabilities. EvilAI primarily acts as a backdoor to maintain persistence within compromised systems and deploy additional payloads. However, the campaign’s main objectives remain unclear. EvilAI compromised multiple different sectors across several countries before its detection, underscoring the scale of this campaign. We assess that this report highlights the elevated security risks facing global businesses as threat actors continue to incorporate AI into malicious cyber activity. (Source: Sibylline)

 

12 Sep 25. Cyber Update.

Key points

  • A new phishing technique has highlighted increased security and social engineering risks facing entities in Colombia (see Sibylline Cyber Daily Analytical Update – 8 September 2025).
  • A Chinese state-sponsored cyber operation has underscored sustained security and cyber espionage risks facing key sectors in the US (see Sibylline Cyber Daily Analytical Update – 9 September 2025).
  • The exploitation of the legitimate IT application Docker in malicious activity has highlighted increased security risks to global businesses (see Sibylline Cyber Daily Analytical Update – 10 September 2025 and our Technical analysis below).
  • Military and key sectors in the Philippines face elevated security and cyber espionage risks from a Chinese advanced persistent threat (APT) group (see Sibylline Cyber Daily Analytical Update – 11 September 2025 and our Technical analysis below).
  • A cyber campaign related to artificial intelligence (AI) has underscored heightened security risks to global businesses (see Sibylline Cyber Daily Analytical Update – 12 September 2025).

Technical analysis of weekly stories

A Chinese APT group targeted a military company in the Philippines in a cyber espionage operation. While the operation’s initial attack vector remains unclear, the group reportedly used a new multi-stage malware toolkit to penetrate the system. The attack’s first stage comprised the deployment of two malware loaders (‘EggStremeFuel’ and ‘EggStremeLoader’) to prepare the environment for later stages, gather initial system information and establish persistent communication with command-and-control (C2) infrastructure. EggStremeLoader was ultimately responsible for executing the main backdoor (‘EggStremeAgent’) into the system’s memory to remain obfuscated. EggStremeAgent uses the remote procedure call (gRPC) protocol for encrypted C2 communication and possesses 58 distinct commands. These include system fingerprinting, resource enumeration, privilege escalation, command execution, data exfiltration, process injection and file directory manipulation. The group also deployed an additional backdoor (‘EggStremeWizard’) to ensure persistence, showcasing the toolkit’s complexity. We assess that this also suggests that the group likely values long-term access, as well as espionage.

Unnamed threat actors are exploiting exposed application programming interfaces (APIs) from the container application Docker to infiltrate targeted organisations. Threat actors send container creation requests to exposed APIs for initial access. This causes existing containers to execute embedded code that establishes communication with C2 infrastructure and subsequently executes a second-stage script. Threat actors use the Tor network for C2 communication to guarantee anonymity and modify secure shell (SSH) configurations to ensure persistence, highlighting their capabilities and sophistication. The script then enables threat actors to maintain prolonged access, block any future external attempts to access the same API and deploy additional payloads, showcasing the actors’ sophistication and knowledge of modern IT infrastructure. The script also installs additional tools (including ‘masscan’, ‘zstd’, ‘libpcap’ and ‘torsocks’) to evade detection and support replication efforts, such as scanning and propagation. The infection strain continues to create containers to spread the infection, while masscan also checks for other exposed ports. This suggests that threat actors may be in the initial stages of attempting to create a large-scale botnet network, pointing to long-term operational and infection risks.

Non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware.
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.

Our cyber word of the week: Containers (Source: Sibylline)

 

10 Sep 25. Thales and Autonomous Devices team up to develop drone-based electronic warfare solution for naval and land forces

  • At DSEI 2025, Thales and the UK company Autonomous Devices announced an agreement to jointly develop a versatile, modular, turnkey drone-based electronic warfare solution for naval and land forces.
  • Thales draws on its electronic warfare expertise to develop a payload capable of performing both electronic support, to detect, identify and locate threats, and electronic attack, i.e. ​ jamming, roles. Autonomous Devices is responsible for designing a new-generation drone with high manoeuvrability and long endurance capabilities.
  • This drone-based electronic warfare solution is currently undergoing initial testing, which will continue throughout the year.

Thales and the UK company Autonomous Devices will co-develop the EW-UAS1 in the latest of a series of joint projects by the two partners.

This turnkey solution will benefit from Thales’ expertise in electronic warfare command-and-control system integration and certifications needed for drones to fly in civil and military airspace.

Recent conflicts have confirmed the growing importance of both defensive and offensive electronic warfare in all domains of military operations. The armed forces need to rely on agile and long-endurance platforms, easy to recover and re-use, to deploy their electronic warfare systems. The combination of the drone from Autonomous Devices and the payload from Thales will meet these requirements, providing a high-performance drone-based electronic warfare solution tailored to the challenges of modern warfare.

“The drone-based electronic warfare solution developed by Thales and Autonomous Devices is a technological game-changer for the armed forces, providing a reliable passive capability to counter modern threats while ensuring long- range protection around their strategic assets,” said Marie Gayrel, Vice-President in charge of the Intelligence, Surveillance and Reconnaissance activities, Thales.

“The integration of these technologies in a turnkey solution promises to unlock EW capabilities well beyond the state of the art, providing an effective counter to rapidly-evolving threats, and this agreement represents a significant step en route to delivering these capabilities to the warfighter,” said Ken Wahren, CEO, Autonomous Devices

EW-UAS has a key role to play in defending ships from new and emerging threats. Thanks to its speed, agility and endurance, this drone can be quickly deployed to detect anti-ship missiles and initiate electronic countermeasures (soft kill), thereby improving ship survivability while minimising ordnance.

EW-UAS will also provide proactive protection for sensitive military assets engaged in land and naval operations, conducting complementary jamming missions to disrupt the adversary’s radar surveillance and targeting capabilities and bolster electronic defences in the theatre of operations. The drone can also be used for passive detection and surveillance, to anticipate threats by extending detection coverage. It can reposition itself quickly to enable the electronic warfare payload to detect enemy radar emissions (weapon guidance, targeting and surveillance), then jam or manipulate these signals to create an alternative radar reality. These deception tactics confuse radar operators, send missiles off-course and ensure that sensitive assets are not detected.

——————————————————————————————————————

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

————————————————————————————————————————–

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

September 10, 2025 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

————————————————————————————————————————————————————————————————————————————————————————————————————————————————-

08 Sep 25.  Department of War Announces the Final Defense Federal Acquisition Regulation Supplement Rule Implementing the Cybersecurity Maturity Model Certification Program. On September 9, the Department of War (DoW) released the final Defense Federal Acquisition Regulation Supplement (DFARS) rule implementing the Cybersecurity Maturity Model Certification (CMMC) Program as described at 32 CFR 170.3 for public inspection in the Federal Register.  The final rule will ensure DoW procurements will include CMMC assessment requirements that ensure defense contractors properly safeguard the Department’s Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).   The CMMC program will provide a consistent methodology for assessing compliance with DoW’s cybersecurity requirements.

“We expect our vendors to put U.S. national security at the top of their priority list,” said Kate Arrington, performing the duties of the DoW Chief Information Officer. “By complying with cyber standards and achieving CMMC, this shows our vendors are doing exactly that.”

The Federal Register Notice is available for public inspection at the following location:

https://public-inspection.federalregister.gov/2025-17359.pdf

An introductory course about the CMMC program is available to both Government and industry students at:

https://www.dau.edu/courses/cyb-1010

Additional information on the CMMC Program can be found at:

https://dodcio.defense.gov/CMMC/ (Source: U.S. DoD)

 

09 Sep 25. Babcock launches cutting-edge AI communications intelligence device for military and security services at DSEI. Babcock International has unveiled a cutting-edge AI-powered communications intelligence product at DSEI which will give front line military and security services real-time information at the touch of a button. Nomad™ is Babcock’s first fully AI-powered product that can clean, transcribe, translate, and analyse voice and text data, providing real-time intelligence directly to users in communications denied environments. Nomad™ addresses one of the biggest challenges we face globally in the race to keep up with disruptive technologies like AI – the ability to extract, analyse and understand data intelligence in seconds anywhere in the world, across any domain. Globally there is shortage of linguists and analysts that can do this. On the battlefield where every second counts Nomad can provide valuable intelligence in real-time.

How does it work?

Nomad has been developed by Babcock with a unique ability to bring together multiple AI technologies and can be customised to bespoke end user needs. This includes providing advanced communications intelligence at the tactical edge, operating completely independently from any external AI services.

Mission Systems CEO, Neal Misell, described Nomad as a product that will “break boundaries” for UK defence.

“Nomad™ can give end-users the ability to make critical decisions where every second counts and lives are at risk – even when they are cut off from a command and control centre. We have created a product, which can give any operator vital intelligence in real time, where and when they need it. Creating Nomad™ has meant investing in and building, a rapid AI development team, and deepening our footprint in AI along with the specialist skills we need in that space.”

In June, Babcock was one of a number of companies that joined the first UK Sovereign AI Industry Forum established by NVIDIA, with the aim of strengthening the nation’s economic security by advancing sovereign AI infrastructure and accelerating the growth of the UK’s AI startup ecosystem. All enquiries on Nomad should be sent to

 

09 Sep 25. At the 2025 edition of DSEI UK (stand S6-135), ELT Group will present its EMSO solutions, across the five operational domains (Land, Sea, Air, Space and Cyber), and the technological innovations needed to meet today’s and tomorrow’s defence and security challenges within the electromagnetic spectrum that joins the domains and enables interoperability between the various operational assets. ELT Group systems cover operational intelligence and platform protection requirements with integrated passive and active solutions in radar, communications, and infrared. In addition to solutions for protecting critical assets and infrastructure from the threat of UAVs, synergistically integrating electromagnetic spectrum management capabilities (to achieve information superiority on the battlefield) with cyber capabilities (to ensure operational security), which is referred to as CEMA (Cyber Electro-Magnetic Activities). In addition to its own stand, ELT Group is also present at the stand dedicated to the GCAP programme, the future sixth-generation fighter, as a representative of the ISANKE&ICS sensor domain. Among the main activities currently underway, it is worth mentioning the development of a proposal, in cooperation with EURODASS partners, to upgrade the self-protection system of the EFA Typhoon, currently the most widely used platform in Europe for board controller operations, with the aim of supporting the extension of the platform’s operational life and making it a key asset in the future operational context of next-generation Systems of Systems. In the space sector, the company continues to develop Signal Intelligence (SIGINT), Situational Awareness and Asset Protection solutions for satellite protection. In addition to the Scorpio system, developed by the company and launched into orbit two years ago for electronic intelligence activities, ELT Group now also offers SHARP, designed for passive and continuous radio frequency monitoring and installed on a HAPS (High Altitude Pseudo Satellite) platform. In the naval sector, the company offers integrated solutions for effective surveillance, situational awareness and countermeasures against all types of threats, in the areas of radio frequency, infrared, communications, as well as naval C-UAS systems. Among the innovative areas in which ELT Group is operating, we mention that relating to MUM-T (Manned-Unmanned Teaming) applications, through the miniaturisation of its EW/SIGINT solutions for unmanned naval, underwater, avionics and terrestrial platforms, for the surveillance of the electromagnetic spectrum in an operational context that requires Distributed EW.

 

09 Sep 25. HENSOLDT and KX to develop next generation technology to accelerate real-time defence data capabilities. Companies have committed to a mission-driven outcome, combining cutting-edge sensors and real-time analytics to deliver decisive data advantage in multi-domain operations. HENSOLDT and real-time analytics pioneer KX signed a Memorandum of Understanding (MoU) to collaborate on next-generation defence data solutions. The agreement marks a strategic alignment between HENSOLDT’s advanced sensor, mission system, and Electromagnetic Warfare capabilities and KX’s world-class high-performance analytics platform, used globally across sectors where milliseconds matter. By integrating KX’s ultra-low latency analytics with HENSOLDT’s multi-domain intelligence, surveillance, and reconnaissance (ISR / SIGINT) systems, the two companies aim to deliver faster, smarter situational awareness to armed forces — starting with the German military and approved international partners.

“Modern defence operations demand the rapid transformation of sensor data into actionable intelligence,” said Jürgen Halder, Vice President Airborne SIGINT at HENSOLDT. “KX’s real-time analytics perfectly complement HENSOLDT’s sensor portfolio, creating a formidable capability to meet our customers’ most demanding operational needs.”

“This strategic relationship extends KX’s proven real-time technology into mission-critical defence operations,” said Gary Connolly, Vice President Aerospace, Defence, Space and Security at KX. “Together with HENSOLDT, we will help armed forces achieve the speed, precision, and situational awareness required to succeed in the most demanding environments.”

The collaboration will initially focus on delivering real-time command-level intelligence across multi-domain operations, advanced battlespace management, synthetic training environments, and Electromagnetic Warfare scenarios. With modern conflicts increasingly driven by the ability to act on data in real time, this represents a long-term commitment to delivering decisive information advantage and mission success in modern defence operations.

 

09 Sep 25. Gentex Corporation is proud to announce its role as a key partner in the U.S. Army’s Soldier Borne Mission Command (SBMC) program, awarded to Anduril Industries. Under this contract, Gentex will provide advanced helmet and communications integration to support the Army’s next-generation Heads Up Displays (HUDs), ensuring seamless soldier adoption and enhanced survivability in the most demanding environments.

“This program represents the next step in connecting soldiers with the tools they need to outpace evolving threats. Gentex is proud to bring our proven platforms and capabilities to SBMC, ensuring that cutting-edge HUD technology integrates seamlessly into protective systems already trusted on the battlefield,” said L.P. Frieder III, President & CEO, Gentex Corporation.

As part of the SBMC ecosystem, Gentex will leverage its industry-leading Ops-Core® helmet systems and AMP® communication headsets to provide the scalable, modular foundation required for optimal HUD integration. Building on extensive feedback from the Integrated Visual Augmentation System (IVAS) program, the SBMC effort represents the next step in equipping soldiers with mission-ready hardware that combines protection, comfort, and connectivity in one platform. Gentex’s role in SBMC ensures HUD technology integrates seamlessly with combat-proven helmets and communications systems already trusted by the U.S. Army and allied forces worldwide, while also contributing expertise to the development of future soldier-vision technologies. The result is a scalable, mission-ready system that reduces complexity, accelerates decision-making, and enhances survivability while delivering both immediate impact and a foundation for the next generation of soldier-vision capabilities. (Source: BUSINESS WIRE)

 

09 Sep 25. INVISIO announces H-Series: A new generation of tactical smart hubs that drastically improves battlefield efficiency. Tactical communication expert INVISIO is announcing the H-Series, a new generation of tactical smart hubs for professionals in mission-critical environments. It unifies radios, sensors, EUDs, laptops, audio, and power into a single connected system resulting in a faster setup, fewer failure points, and quicker decisions under pressure.

Tactical smart hubs to unify hardware

Communication on today’s battlefield relies on data, not just voice. Soldiers carry radios, digital devices, batteries, smartphones, and laptops – often from different generations and vendors. These devices don’t naturally work together. Traditional hubs only pass power and signals, forcing operators to juggle adapters, manual setups, and device-specific apps. In high-pressure missions, that complexity can put success – and safety – at risk.  A tactical smart hub is different. It unifies separate devices into one system. By removing all the complexity, it delivers faster access to mission-critical data, streamlined power distribution, and simplified control. The result is reduced cognitive load on the operator, and more focus on the mission.

H-Series: Designed for the modern battlefield

The INVISIO H-series meets the need of modern soldiers. It dramatically reduces operator burden and accelerates mission readiness by offering:

  • Embedded computing: Mission-critical software can run on the hub itself, not just on the EUD. This reduces latency and keeps essential functions online.
  • Data routing: The hubs act as a router; prioritizing and forwarding data between radios, EUDs, and sensors, so teams receive the right information at the right time.
  • Centralized power control: Power is distributed and prioritized based on role or mission profile to maximize system run-time and keep the most critical devices alive.
  • Open and updatable: An optimized operating system with secure boot, no storage of data-at-rest, a web-based configuration UI, and over-the-air updates turn the hub into an adaptable, serviceable asset, not a black box.
  • Interoperability: Bridges legacy and modern devices, so organizations can modernize and interoperate with partners without full replacement.

Two models for different mission profiles

  • H4: 4-port, low-profile, lightweight hub for streamlined setups.
  • H6: 6-port hub with expanded connectivity for complex mission profiles.

“In dynamic tactical operations, being prepared and performing at speed are non-negotiable,” highlights Colin Argue, Product Line Director at INVISIO. “The H-Series delivers precisely this: empowering users with a simplified setup, faster coordination, and improved overall operational effectiveness.”

Preparing for what’s next in tactical operations

With the H-series, INVISIO is enabling organizations to prepare for a future of tactical operations that is increasingly software-defined, networked, and mobile. As platforms and systems evolve, hubs like the INVISIO H-Series will be key to bridging legacy systems with emerging tech. From drone feeds to Battle Management System overlays, the hub will enable the unification of equipment, faster sharing of information and greater precision in planning and execution.

“This launch reflects the broader direction of INVISIO; delivering modular and scalable systems that are ready for what’s next in modern missions,” says Lars Højgaard, CEO at INVISIO. “This is more than a product announcement. It’s a step toward the kind of integrated systems that modern operations demand. We’re committed to leading that shift.”

The H-Series is expected to be available for shipment in 2026, contact INVISIO for more information.

The H-Series will be presented at DSEI September 9-12 in London, booth number S13-510. Visit INVISIO there, or alternatively, visit Invisio.com or contact your local INVISIO representative.

To access high-resolution visuals, please click here.

Additional product data are available on request.

 

10 Sep 25. Ultra Cyber Ltd., an Ultra I&C company, and DTC, a Codan company, have signed a Memorandum of Understanding (MOU) to develop encrypted high frequency (HF) radio capabilities for Five Eyes countries, NATO partners and international defence customers. This collaboration advances secure communications for AUKUS, NATO and European forces operating in contested environments. The partnership combines Ultra Cyber Ltd.’s advanced cryptographic and key management solutions with DTC’s non-ITAR HF radio technology to deliver secure voice and data capabilities for mission-critical operations. The integration will provide allied forces with resilient, interoperable communications designed for modern battlespace requirements where secure connectivity is paramount. Together, the companies will develop encrypted HF solutions that address evolving operational demands across allied networks.

“Every mission relies upon secure and trusted communications,” said Juliette Wilcox, president of Ultra Cyber Ltd. “By integrating our proven cryptographic expertise with DTC’s HF radios, we will deliver NATO and international partners secure, resilient communications tailored for the ever-changing battlespace.”

“With each mission’s success having growing requirements to secure information advantage, we are pleased to partner with Ultra Cyber Ltd. to continue providing user focused sustainable solutions at the speed of relevance,” said Steve Beeching, SVP of DTC. “Our investments, talent and partnership are all focused on solving our customers communication challenges and outpacing the expanding adversary threats across both the contested spectrum and battlespace.”

The MOU was formally signed during the DSEI trade exhibition event in London, U.K, by Juliette Wilcox and Steve Beeching and enables technology integration and knowledge sharing between both companies to ensure interoperability across defence networks.

About Ultra I&C

Ultra I&C is powering decision speed across the multidomain battlespace with resilient tactical communications, mission optimisation and encryption technologies. We secure, move, and make sense of data across all domains—delivering real-time, mission-ready intelligence that gives operators at the edge the clarity to act and the speed to win. Ultra Cyber Ltd. develops advanced encryption and cyber solutions that defend critical communications against sophisticated threats to ensure trusted connectivity for the British government and allied nations. For decades, global defence forces and allied partners have relied on Ultra I&C to outpace threats and cut through complexity on the battlefield. With more than 700 employees across the global enterprise, we deliver battle-proven technology purpose-built for decision advantage in contested, high-threat environments. For more information, visit https://www.ultra-ic.com.

 

03 Sep 25. Creomagic Expands Tactical Communications Ecosystem with the Launch of CreoEdge-Dome at DSEI 2025 Creomagic’s new solution delivers wide-area coverage and secure, high-bandwidth performance — keeping deployed forces seamlessly connected across the most challenging environments. Creomagic Ltd., a leading developer of advanced communication technologies, will unveil CreoEdge-Dome, a new tactical broadband communications solution with full, 360-degree coverage, that merges the resilience of MANET (Mobile Ad-Hoc Networks) technology with the capacity and efficiency of tactical cellular concepts. This milestone in Creomagic’s tactical communication solutions addresses one of the most pressing challenges in modern operations – maintaining secure, high-capacity connectivity across broad operational zones without any infrastructure. Deployed mission-critical teams, from rescue units to security forces, cannot afford a moment of downtime. They need secure, high data rate connectivity everywhere, all the time. To achieve their mission objectives, they must operate as a single coordinated and effective entity, yet in practice are often spread across challenging terrains or regions lacking in infrastructure, not to mention congested and contested electronic environments. It is no surprise then that traditional comms systems struggle to deliver reliable, real-time connectivity across broad geographic zones, leaving gaps that compromise mission success. That is where Creomagic’s new platform comes in. CreoEdge-Dome operates as an easy-to-deploy, omnidirectional hub that creates a persistent, AI-assisted communications bubble for high-capacity voice, video and data transmission – regardless of any existing infrastructure. Inspired by 5G-grade efficiency, CreoEdge-Dome features dynamic resource scheduling and sectorized antennas with seamless sector handover. This allows users to move between sectors without interruption or having to re-establish links, delivering full, uncompromised, 360-degree coverage for ground, naval and joint-operation tactical units. Rugged and rapidly deployable, this “mobile tactical communications tower” provides throughput of up to 80 Mbps and wide-area coverage, with mast-mounted broadband reach for tactical zones, forward units and HQ links, along with long-range or directional links for bridging dispersed MANET clusters (thereby extending operational range). Capable of being vehicle- or carrier-mounted, CreoEdge-Dome transforms into a mobile broadband hub for surrounding units, seamlessly relaying video and data up the chain of command. CreoEdge-Dome integrates CreoNet advanced technologies, including MIMO technology, high-speed connectivity, dynamic spectrum management, smart power management, as well as frequency hopping capabilities and real-time intelligent interference avoidance – all to ensure stable communications for deployed forces in congested or contested RF environments. In addition, its self-forming, self-healing MANET architecture delivers built-in robustness and adaptability for any mission. Whether on land, at sea, or across multi-domain operations, CreoEdge-Dome delivers more data, less interference and a truly stable connection, enabling close coordination, instant intelligence sharing and enhanced situational awareness – without complex setup or the need for any additional equipment or mechanical tracking.

“CreoEdge-Dome was developed in direct response to operational demands from the field,” explained Alexander Shapochnik, CreoMagic’s CEO. “Deployed units need broadband connectivity everywhere, all the time – and CreoEdge-Dome delivers exactly that: secure, reliable communications over wide areas, without regard to the limitations of any fixed infrastructure. By seamlessly integrating with our existing systems – from CreoHub for infantry and mission-critical teams to CreoEdge for vehicles and maritime platforms – we are extending Creomagic’s tactical communications ecosystem into a complete, end-to-end, multi-domain network. This marks a true leap forward in how tactical networks are deployed and sustained.”

Creomagic will be showcasing CreoEdge-Dome along with its full range of advanced communications solutions for ground, marine and aerial platforms at DSEI 2025 (London, United Kingdom, 9-12 September, Stand# N11-216).

About Creomagic Ltd.

Creomagic develops and manufactures innovative communications solutions that form intelligent Mobile Ad-Hoc Networks (MANETs), designed for mission-critical teams and tactical operations. Their radio technology provides users with reliable, secure and resilient on-the-go communication networks for any mission. Operationally proven, their solutions serve key defense players worldwide, including tactical teams, ground robotics, maritime applications and a wide range of UAS manufacturers. Creomagic solutions are engineered and fine-tuned by a highly experienced team, committed to the highest standards across their products and services. With customer needs paramount, Creomagic invests in constant development and innovation, providing tailored tactical solutions and ensuring crucial operational advantages for each mission.

—————————————————————————————————————————————————————————————————————————————————————————————————————————————-

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

——————————————————————————————————————————————————————————————————————————————————————————————————————————————-

 

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

September 8, 2025 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

——————————————————————————————————————————————————————————————————————————————————————————————————————————————

08 Sep 25. Thales completes key tests for Royal Navy’s Type 31 frigates. Following the FAT, the Type 31 programme will now progress to land-based testing at the Shore Integration Facility. Thales has concluded Factory Acceptance Tests (FAT) for the Mission System and Combat System on the Type 31 Inspiration-class frigates of the Royal Navy. The company, in collaboration with Babcock and the Royal Navy as part of an international team, finalised all essential factory-based tasks for this programme. The Mission System FATs were finished by the end of April 2025, with the Combat System tests following at the end of June 2025. Thales’s Combat Management System, TACTICOS, serves as the central operational component of the Type 31 frigates, managing sensor control, compiling situational data, assessing threats, supporting decision-making, and controlling weaponry. With these tests now complete, the next phase will involve land-based trials at a Shore Integration Facility before installation on HMS Venturer, the first-of-five Type 31 Inspiration-class frigates currently under construction at Babcock’s Rosyth facility. Thales UK Above Water Systems managing director Andy Laing said: “Working closely with our Royal Navy and Babcock colleagues, we are delighted to have successfully completed this critical stage in the development of the Royal Navy’s new Type 31 frigates. It represents another demonstration of Thales’s proven ability to deliver integrated naval mission systems to the highest standards.” Designed to replace the Type 23 frigates in service since the early 1990s, the Type 31 frigate is a UK-specific adaptation of Babcock’s Arrowhead 140 design. It forms part of the UK government’s 2030 vision for defence readiness against various threats and is being developed as part of the National Shipbuilding Strategy. These vessels are slated to start joining service by 2028 and will operate alongside Type 32 and Type 26 frigates focused on anti-submarine warfare. In February 2025, Thales was contracted by UK Defence Equipment & Support to provide maintenance and upgrades for communication systems across the Royal Navy’s fleet of warships and submarines. (Source: naval-technology.com)

 

08 Sep 25. HAVELSAN Technologies Strengthen Turkiye’s 8th MILGEM Frigate, TCG ICEL. Türkiye’s national shipbuilding program reached another milestone with the launch of the eighth MILGEM vessel, TCG IÇEL, at Sefine Shipyard in Yalova. Designed for multi-role missions including anti-submarine and surface warfare, air defense, and electronic warfare, the frigate represents the latest achievement of Türkiye’s growing naval capabilities. Behind this success lies the contribution of Türkiye’s defense industry, with HAVELSAN playing a key role in equipping TCG IÇEL with next-generation command and control technologies. With its integration of ADVENT and FLEETSTAR (Ship Data Distribution System), TCG IÇEL is now fully prepared to operate as a next-generation combat platform, equipped with the resilience, adaptability, and technological depth demanded by 21st-century naval missions.

ADVENT: The Brain of the Ship

TCG IÇEL is equipped with HAVELSAN’s ADVENT Network Enabled Combat Management System (CMS). Developed jointly with the Turkish Naval Forces Research Center Command, ADVENT enables real-time situational awareness, rapid decision-making, and secure interoperability with allied units. Already operational on numerous platforms, ADVENT has become the technological “brain” of Türkiye’s modern warships.

ADVENT has been adopted across four continents and multiple strategic regions, proving its adaptability to diverse naval platforms and complex operational environments. From offshore patrol vessels and corvettes to submarines and fast attack craft, ADVENT enables navies to operate not as isolated units, but as a network-enabled force capable of joint and multinational operations.

FLEETSTAR (Ship Data Distribution System): The Digital Heart of the Platform

Complementing ADVENT, HAVELSAN’s FLEETSTAR (Ship Data Distribution System)has also been integrated into TCG IÇEL. Acting as the “digital heart” of the vessel, FLEETSTAR (Ship Data Distribution System)ensures that critical data from sensors, navigation, and weapon systems is securely collected, synchronized, and distributed without interruption. The system, which has matured through years of local engineering and production, now serves on more than 60 platforms at home and abroad.

Strengthening the Blue Homeland

The launch of TCG IÇEL once again demonstrates how national engineering and local technologies contribute directly to Türkiye’s Blue Homeland vision. By integrating indigenous solutions such as ADVENT andFLEETSTAR (Ship Data Distribution System) HAVELSAN continues to strengthen the operational independence of the Turkish Navy while offering trusted, export-ready technologies to allied navies worldwide.

We are proud to be part of the MILGEM journey — a program that not only strengthens Türkiye’s naval capabilities but also demonstrates HAVELSAN’s ability to deliver advanced, future-ready technologies trusted by navies around the world. (Source: ASD Network)

 

08 Sep 25. Insta, a trusted cyber security and defence technology provider, has launched Insta DomainLink Secret™, a high-performance cross-domain solution (CDS) for secure, real-time data exchange between different networks and systems. Modern technological solution enables real-time, secure bi-directional data transfer between military domains, such as land, maritime, and air, and security clearance between different classification levels across the chain of command. Developed in collaboration with Lockheed Martin for the exchange of data in complex military network environments, its advanced operational security and cybersecurity capabilities help safeguard data against threats. The system also enables improved situational awareness and faster tactical decision-making across military domains.

Modern military operations require quick data centric decision-making

Typically, military branches, such as the navy and air defence, have their own command and control systems with limited ability to exchange information in a controlled way due to a lack of proper cybersecurity controls to enable connections. This can slow decision making which reduces situational awareness and might jeopardise the mission and put troops at risk. Multi-domain operations refer to military operations that integrate and synchronise actions across multiple military branches to achieve a key strategic objective. For example, a major NATO mission can include land, maritime, air, space, and cyber operations – all taking place at the same time over a vast area. The more NATO operatives participate, the more complex the data exchange between different networks and systems becomes.

“For example, if there were a military conflict in Europe, it would be necessary to communicate critical information between different systems and chains of command. An F-35 on a stealth mission needs to be able to share the information that all of its sophisticated sensor systems detect with the rest of the forces. If the aircraft detects an enemy threat, you need to decide very quickly who responds to it: the air force, a navy vessel, or ground-based assets? Real-time sharing of data and its effects across all branches is critical for both command and on-field operatives to effectively respond to threats and achieve high joint operational capability,” says Petri Reiman, Senior Vice President, Defence and Cyber Security at Insta.

Tailor-made solutions are on the way to being replaced by flexible systems

In order to benefit from cross-domain technologies in the past, it has been necessary to have them tailor-made, or they have required complex coding and scripting, slowing down their implementation. Programming or scripting-based solutions are further limited by static, pre-defined rule sets that could not be changed during real-time operation. Any changes require re-coding and testing by a developer.

In contrast, Insta DomainLink Secret™ introduces a new level of agility, empowering system operators themselves to adapt and refine operational rules instantly, without technical bottlenecks.

Information superiority and increasing cyber threats drive investment in defence

The last few years have also seen a rise in cyber attacks targeting defence systems and the military. Governments have responded, with, for example, the UK increasing spending on cyber capabilities in 2025. Additionally, at the 2025 NATO Summit in The Hague, member states pledged to spend 5% of GDP on defence by 2035, with 1.5% dedicated towards cybersecurity and critical infrastructure protection. While mission-critical data is available from multiple sources in the field, certain information should not be shared across the entire chain of command. To ensure operational security for any mission or procedures, Insta DomainLink Secret™’s filtering feature allows users to control data flows and who has access to them. In practice, the system can be programmed to control what information is transmitted, what information can be received or even what data, for example, a radar is permitted to send out.

“Information superiority is a key dimension of multi-domain operations – you simply must have a full operational picture available at all times. Our Cross Domain Solution has been specifically developed to meet the increasing challenges of the modern defence and military realities, including cyber threats. Our decades of experience in demanding defence solutions and strong focus on developing state-of-the-art command and control systems utilising data and AI put us in a unique position to offer secure solutions for NATO needs,” says Reiman.

To further enhance performance and security in critical environments, Insta DomainLink Secret™ is built on Field Programmable Gate Array (FPGA) technology that enables hardware-based content validation and filtering, enhancing performance and security in critical environments. Additionally, FPGA technology is highly adaptable and can be reconfigured to different situations and threats as the hardware does not need to be removed for updates.

The F-35 stealth fighters, which Finland will start receiving in 2026, are known as the world’s most modern and versatile fighter jets. In addition to maintaining the aircraft’s avionics systems, Insta will also be responsible for integrating the new fighter’s systems with the Finnish command and control systems in collaboration with the Finnish Defence Forces. Insta will showcase the solution at DSEI UK 2025 organised in London 9–12 September.

 

04 Sep 25. YEO Messaging, the British leader in AI-powered secure communications with continuous biometric authentication, has announced it has signed an agreement with CS Comms, a specialist provider in delivering secure, robust communications to defence organisations operating in some of the world’s most austere, and tightly controlled military environments. In the collaboration agreement, CS Comms will use the YEO Messaging for Business app as the encrypted messaging backbone behind its Phantom Signal solution, to give UK defence and government personnel operating discreetly on the ground, a combined bespoke specialised global SIM service with a fully encrypted, continually facial recognition verified, geo-fenced messaging platform. Founded by military veteran Craig Sykes, CS Comms first emerged from years of service within the highest levels of UK Defence, and has subsequently evolved into a trusted provider of bespoke, defence-ready SIM technology and more. Phantom Signal now integrates SIM-level protection with YEO Messaging’s continuous biometric authentication; end-to-end encryption to secure messages; and voice and video calls. Together, the combined solution ensures that sensitive operational communications remain private, controlled, and compliant, even in high-threat environments.

“In the environments we operate, secure communications are the foundation of survival. By integrating YEO Messaging for Business into our Phantom Signal platform, we’ve added a layer of identity-verified encryption that matches the strength of our SIM technology.”  Noted Craig Sykes, Founder of CS Comms.  “Together, this gives defence teams complete confidence that their communications are secure, private, and under their control, no matter where they are in the world.”

“CS Comms takes YEO Messaging into some of the most demanding and sensitive environments imaginable. Pairing our identity-verified, end-to-end encrypted platform with their Phantom Signal infrastructure creates a uniquely secure communications channel that’s not only resistant to interception, but also simple for personnel to use in the field.” Said Christo Conidaris, CRO of YEO Messaging. “It’s a powerful example of how the right technology partnership can directly enhance the operational safety of our armed forces.”

Both companies will be showcasing Phantom Signal at the DSEI Show (9–12 September 2025, stand S15-240) and you can schedule press meetings and see the solution live using the attached link. YEO Messaging, founded in 2017, is known for its continuous facial recognition, geofencing controls, and audit-ready secure messaging. The company’s “privacy-by-design” approach has seen recent traction with other defence clients such as ASU, Mission Critical Comms, One-Beyond, and Example IT.

 

05 Sep 25. New phishing techniques will increase security risks to businesses. On 3 September, the cyber security company Barracuda reported that threat actors are using new techniques to deliver a phishing-as-a-service (PhaaS) kit (Tycoon). In some instances, threat actors use a URL-encoding technique to create and subsequently distribute stealthy malicious links. This technique allows threat actors to bypass trusted security services by inserting and authenticating additional spaces and characters in a legitimate-looking web address. A second technique (known as Redundant Protocol Prefix) also relies on web address manipulation by inserting additional characters into a partially hyperlinked URL. Security protections typically only check hyperlinked URLs, enabling threat actors to evade detection while showcasing their knowledge. The malicious links ultimately redirect users to fake login pages to facilitate credential theft for financial profit. We assess that this report underscores increased security, social engineering and financial risks to global businesses as threat actors continuously develop new, more sophisticated techniques to bypass security mechanisms. (Source: Sibylline)

 

05 Sep 25. Cyber Update

Key points

  • A disruptive cyber attack targeting at least 60 Iranian ships has underscored the sustained security and operational risks stemming from a suspected hacktivist group.
  • Critics of the Russian state and various academics face heightened cyber espionage risks from the Russian state-sponsored group ‘APT29’.
  • A cyber operation has sustained the security and espionage risks facing South Korean entities from the North Korean state-sponsored group ‘APT37’ (see Sibylline Cyber Daily Analytical Update – 3 September 2025 and our Technical analysis below).
  • The exploitation of a legitimate artificial intelligence (AI)-powered red teaming tool (‘HexStrike-AI’) has underscored the heightened security risks facing businesses.
  • New techniques to deliver a phishing-as-a-service (PhaaS) kit (‘Tycoon’) have underscored the elevated security risks facing global firms.

Technical analysis of weekly stories

A North Korean state-sponsored group (APT37) conducted a multi-phase cyber espionage operation (‘HanKook Phantom’) against South Korean academics, as well as government officials and intelligence officers. The first phase comprised the distribution of spear phishing emails to trick victims into downloading a malicious PDF document. The email emulated a monthly newsletter (typically published by a South Korean research group) that informs members of upcoming events to enhance legitimacy, highlighting the tailored nature of this operation. The PDF document contains an .LNK file that deploys a backdoor (‘RokRAT’) via an embedded PowerShell script. RokRAT executes a system function that checks the type of environment in which it is running to evade detection within secure environments (such as sandboxes and virtual machines). The malware then establishes communication with command-and-control (C2) infrastructure to facilitate data exfiltration after storing data of interest in a temporary file. The second phase of the cyber espionage operation entailed another phishing campaign that utilised a statement concerning relations between North Korea and South Korea to deploy a further .LNK file. This file can also execute a payload in a system’s memory and deletes the staged file to remain obfuscated, underscoring APT37’s detection-evasion capabilities. This cyber espionage operation showcases APT37’s continued efforts to refine its phishing techniques in order to tailor its victims and facilitate system infiltration.

A Russian state-sponsored group (APT29) targeted academics and other individuals who are critical of the Russian state in a cyber espionage operation. The group conducted a watering hole attack, injecting multiple legitimate and commonly visited websites with malicious JavaScript code that redirected approximately 10% of visitors to threat actor-controlled domains. The domains emulated Cloudflare verification pages to trick users into authenticating threat actor-controlled devices through a Microsoft device authentication flow in order to deploy malware, harvest credentials and collect information. APT29 used several advanced obfuscation techniques during the attack to prolong detection evasion; it used randomisation to redirect a small percentage of users and established cookies to prevent any one user from being redirected twice. The group can also quickly pivot to new infrastructure when detected, further highlighting its operational resilience and detection-evasion capabilities. This operation showcases the continued expansion of APT29’s operations beyond government and key sector targets.

Non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware.
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.

Our cyber word(s) of the week: URL encoding (Source: Sibylline)

 

03 Sep 25. Creomagic Ltd., a leading developer of advanced communication technologies, will unveil CreoEdge-Dome, a new tactical broadband communications solution with full, 360-degree coverage, that merges the resilience of MANET (Mobile Ad-Hoc Networks) technology with the capacity and efficiency of tactical cellular concepts. This milestone in Creomagic’s tactical communication solutions addresses one of the most pressing challenges in modern operations – maintaining secure, high-capacity connectivity across broad operational zones without any infrastructure. Deployed mission-critical teams, from rescue units to security forces, cannot afford a moment of downtime. They need secure, high data rate connectivity everywhere, all the time. To achieve their mission objectives, they must operate as a single coordinated and effective entity, yet in practice are often spread across challenging terrains or regions lacking in infrastructure, not to mention congested and contested electronic environments. It is no surprise then that traditional comms systems struggle to deliver reliable, real-time connectivity across broad geographic zones, leaving gaps that compromise mission success.

That is where Creomagic’s new platform comes in. CreoEdge-Dome operates as an easy-to-deploy, omnidirectional hub that creates a persistent, AI-assisted communications bubble for high-capacity voice, video and data transmission – regardless of any existing infrastructure. Inspired by 5G-grade efficiency, CreoEdge-Dome features dynamic resource scheduling and sectorized antennas with seamless sector handover. This allows users to move between sectors without interruption or having to re-establish links, delivering full, uncompromised, 360-degree coverage for ground, naval and joint-operation tactical units. Rugged and rapidly deployable, this “mobile tactical communications tower” provides throughput of up to 80 Mbps and wide-area coverage, with mast-mounted broadband reach for tactical zones, forward units and HQ links, along with long-range or directional links for bridging dispersed MANET clusters (thereby extending operational range). Capable of being vehicle- or carrier-mounted, CreoEdge-Dome transforms into a mobile broadband hub for surrounding units, seamlessly relaying video and data up the chain of command. CreoEdge-Dome integrates CreoNet advanced technologies, including MIMO technology, high-speed connectivity, dynamic spectrum management, smart power management, as well as frequency hopping capabilities and real-time intelligent interference avoidance – all to ensure stable communications for deployed forces in congested or contested RF environments. In addition, its self-forming, self-healing MANET architecture delivers built-in robustness and adaptability for any mission. Whether on land, at sea, or across multi-domain operations, CreoEdge-Dome delivers more data, less interference and a truly stable connection, enabling close coordination, instant intelligence sharing and enhanced situational awareness – without complex setup or the need for any additional equipment or mechanical tracking.

“CreoEdge-Dome was developed in direct response to operational demands from the field,” explained Alexander Shapochnik, CreoMagic’s CEO. “Deployed units need broadband connectivity everywhere, all the time – and CreoEdge-Dome delivers exactly that: secure, reliable communications over wide areas, without regard to the limitations of any fixed infrastructure. By seamlessly integrating with our existing systems – from CreoHub for infantry and mission-critical teams to CreoEdge for vehicles and maritime platforms – we are extending Creomagic’s tactical communications ecosystem into a complete, end-to-end, multi-domain network. This marks a true leap forward in how tactical networks are deployed and sustained.”

Creomagic will be showcasing CreoEdge-Dome along with its full range of advanced communications solutions for ground, marine and aerial platforms at DSEI 2025 (London, United Kingdom, 9-12 September, Stand# N11-216).

About Creomagic Ltd.

Creomagic develops and manufactures innovative communications solutions that form intelligent Mobile Ad-Hoc Networks (MANETs), designed for mission-critical teams and tactical operations. Their radio technology provides users with reliable, secure and resilient on-the-go communication networks for any mission. Operationally proven, their solutions serve key defense players worldwide, including tactical teams, ground robotics, maritime applications and a wide range of UAS manufacturers. Creomagic solutions are engineered and fine-tuned by a highly experienced team, committed to the highest standards across their products and services. With customer needs paramount, Creomagic invests in constant development and innovation, providing tailored tactical solutions and ensuring crucial operational advantages for each mission.

 

08 Sep 25. Insta launches Insta DomainLink Secret™ to empower tactical decision-making and improve situational awareness across military branches and systems. The transition of military systems towards multi-domain operations The transition of military systems towards multi-domain operations requires real-time, effective coordination and sharing of data and decisions. Insta DomainLink Secret™ has been designed for data exchange between systems using NATO standards, operational security concerning information transmissions, and cybersecurity to protect and limit what data may be received and transmitted by communicating parties. Insta, a trusted cyber security and defence technology provider, has launched Insta DomainLink Secret™, a high-performance cross-domain solution (CDS) for secure, real-time data exchange between different networks and systems. Modern technological solution enables real-time, secure bi-directional data transfer between military domains, such as land, maritime, and air, and security clearance between different classification levels across the chain of command. Developed in collaboration with Lockheed Martin for the exchange of data in complex military network environments, its advanced operational security and cybersecurity capabilities help safeguard data against threats. The system also enables improved situational awareness and faster tactical decision-making across military domains.

Modern military operations require quick data-centric decision-making

Typically, military branches, such as the navy and air defence, have their own command and control systems with limited ability to exchange information in a controlled way due to a lack of proper cybersecurity controls to enable connections. This can slow decision-making which reduces situational awareness and might jeopardise the mission and put troops at risk. Multi-domain operations refer to military operations that integrate and synchronise actions across multiple military branches to achieve a key strategic objective. For example, a major NATO mission can include land, maritime, air, space, and cyber operations – all taking place at the same time over a vast area. The more NATO operatives participate, the more complex the data exchange between different networks and systems becomes.

“For example, if there were a military conflict in Europe, it would be necessary to communicate critical information between different systems and chains of command. An F-35 on a stealth mission needs to be able to share the information that all of its sophisticated sensor systems detect with the rest of the forces. If the aircraft detects an enemy threat, you need to decide very quickly who responds to it: the air force, a navy vessel, or ground-based assets? Real-time sharing of data and its effects across all branches is critical for both command and on-field operatives to effectively respond to threats and achieve high joint operational capability,” says Petri Reiman, Senior Vice President, Defence and Cyber Security at Insta.

Tailor-made solutions are on the way to being replaced by flexible systems

In order to benefit from cross-domain technologies in the past, it has been necessary to have them tailor-made, or they have required complex coding and scripting, slowing down their implementation. Programming or scripting-based solutions are further limited by static, pre-defined rule sets that could not be changed during real-time operation. Any changes require re-coding and testing by a developer.

In contrast, Insta DomainLink Secret™ introduces a new level of agility, empowering system operators themselves to adapt and refine operational rules instantly, without technical bottlenecks.

Information superiority and increasing cyber threats drive investment in defence

The last few years have also seen a rise in cyber attacks targeting defence systems and the military. Governments have responded, with, for example, the UK increasing spending on cyber capabilities in 2025. Additionally, at the 2025 NATO Summit in The Hague, member states pledged to spend 5% of GDP on defence by 2035, with 1.5% dedicated towards cybersecurity and critical infrastructure protection. While mission-critical data is available from multiple sources in the field, certain information should not be shared across the entire chain of command. To ensure operational security for any mission or procedures, Insta DomainLink Secret™’s filtering feature allows users to control data flows and who has access to them. In practice, the system can be programmed to control what information is transmitted, what information can be received or even what data, for example, a radar is permitted to send out.

“Information superiority is a key dimension of multi-domain operations – you simply must have a full operational picture available at all times. Our Cross Domain Solution has been specifically developed to meet the increasing challenges of the modern defence and military realities, including cyber threats. Our decades of experience in demanding defence solutions and strong focus on developing state-of-the-art command and control systems utilising data and AI put us in a unique position to offer secure solutions for NATO needs,” says Reiman.

To further enhance performance and security in critical environments, Insta DomainLink Secret™ is built on Field Programmable Gate Array (FPGA) technology that enables hardware-based content validation and filtering, enhancing performance and security in critical environments. Additionally, FPGA technology is highly adaptable and can be reconfigured to different situations and threats as the hardware does not need to be removed for updates. The F-35 stealth fighters, which Finland will start receiving in 2026, are known as the world’s most modern and versatile fighter jets. In addition to maintaining the aircraft’s avionics systems, Insta will also be responsible for integrating the new fighter’s systems with the Finnish command and control systems in collaboration with the Finnish Defence Forces. Insta will showcase the solution at DSEI UK 2025 organised in London 9–12 September.

———————————————————————————————————————————————————————————————————————————————————————————————————————————————

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

——————————————————————————————————————————————————————————————————————————————————————————————————————————————

 

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

September 5, 2025 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

——————————————————————————————————————————————————————————————————————————————————————————————————————————————–

03 Sep 25. Spectra Group completes latest round of successful GENSS trials. Spectra Group, a specialist provider of secure voice, data and satellite communications systems, has announced for DSEi 25, the successful completion of their latest user trials for their next generation tactical radio GENSS.  The concept for GENSS was announced last year and since then Spectra Group has successfully completed full product development and now field testing with select user groups.  Spectra Group will be showcasing GENSS (pronounced genesis /jĕn′ĭ-sĭs), their award-winning tactical satellite SlingShot system and their recent addition to the Troposcatter Family of Systems, Troposcatter on the Move (TOTM), at DSEi, Excel, London (9-12 September 2025) at stand N2-430.

GENSS builds on the foundations created by the award-winning SlingShot system, embodying Spectra Group’s vision of producing ultimate radio systems that capitalise on technological advances, adapt to the evolving demands of military operations and simplify the user experience.  It has been designed and developed through a collaborative effort of tactical communication experts, seasoned military specialists and top-tier U.K. scientists and engineers.  GENSS is a significant advancement in the field of tactical radio communications, due to its modular core framework and software-defined flexibility, heralding a new era in communication technology and along with the other Spectra Group products delivers a robust layered communications network to support mission critical headquarters and uncrewed systems over the horizon.

These latest field trials further validated the success and user benefits of GENSS, delivering a single tactical radio capable of meeting the extensive secure data, voice and application demands of modern military users.  GENSS is a modular, hardware-agnostic radio system designed and now proven to be exceptionally agile, providing ultimate interoperability through straightforward software reprogramming allowing it to adapt quickly and easily to diverse user needs.  GENSS is backwards compatible with SlingShot and has the benefit it will automatically tune to the L-TAC frequency, converting any military or civilian HF, VHF or UHF FM radio into a mobile global satellite communications system.

GENSS is also a multi-mode and multi-mission software defined radio in its own right, designed for agility and interoperability whilst focusing on cognitive simplicity for the operator.  As well as a bespoke radio firmware package, Spectra Group has developed an integrated software data management package that allows Beyond Line of Sight (BLOS) bridging capability for closed/remoted MANET networks.  Integrating and managing MANET data feeds into ATAK mission software, Spectra has ensured that wide band mission critical data, such as Personal Location Information (PLI) and Cursor on Target (CoT), can be transmitted over narrowband L-TAC channels, with recent trials also proving streaming video over L-TAC services is possible.   By maximising the capability and flexibility that L-TAC offers, GENSS overcomes all traditional BLOS barriers and delivers true Communications on the Move (COTM) for individuals and platforms and by design has a low probability of detection or interception, enhancing its security and operational effectiveness.  GENSS is therefore a robust and agile solution for voice and data transmission across all domains and platforms, whether on land, sea or in the air.

Simon Davies, Chief Executive at Spectra Group said, “As a veteran led organisation, my mission has been to craft the ultimate radio system — user-friendly, light, modular and supremely flexible to adapt to the evolving demands of military operations and technological advances.  I am immensely proud and excited of what the GENSS team have managed to achieve, and these trials represent the pinnacle of our collective efforts to provide the user with simple and effective solutions.  With this latest round of trials, and the rigorous process of full military specification certification to 801/461G complete, we remain on track to bring GENSS to market in the very near future.”

 

04 Sep 25. Named and Shamed. Pity the Russian air defender. It is getting ever harder to shoot down a civilian airliner without your identity being unmasked and splashed all over the internet. Neither is this a phenomenon of the digital age. On 1st September 1983, Soviet air defenders shot down Korean Air Lines Flight 007 using a Soviet Air Defence Force Su-15TM (NATO reporting name Flagon-F) combat aircraft. The Boeing 747-230B airliner was engaged after it strayed into Soviet airspace by K-8 (AA-3 Anab) air-to-air missiles fired from the SU-15TM above the Sea of Japan. All 269 souls onboard perished. General Anatoly Kornukov, commander of the 40th Fighter Division of the Soviet Far East Air Defence Forces, was responsible. It was Gen. Kornukov who ordered the airliner’s destruction. The trigger was pulled by Major Gennadiy Osipovich, the Su-15TM’s pilot. Fast forward to 17th July 2014 and Malaysian Airlines Flight 17 was shot down while overflying Ukraine by a Russian Army Buk 9M38 (SA-11 Gadfly) medium-range/medium altitude Surface-to-Air Missile (SAM). As with the loss of Flight 007, all 298 souls died. Dogged work by the open-source investigative journalism organisation Bellingcat unmasked the perpetrators. Bellingcat determined that two Russian nationals, Igor Girkin and Sergey Dubinskiy, were responsible. Leonid Kharchenko, a Ukrainian collaborator, was also blamed. All three men were later convicted by a Dutch court of murder. The Netherlands led the investigation into the killings. The subsequent trial was held in absentia in a Dutch court. All three men have chosen to take the coward’s way out and not face sentencing. They are thought to remain at large in Russia. On 25th December 2024, Azerbaijan Airlines Flight 8243 crashed near Aktau international airport in western Kazakhstan after being hit by a Russian SAM. 38 of the 67 people on board died in the crash. An investigation by Azerbaijan blamed a Russian Army Pantsir-S1 (SA-22 Greyhound) short-range air defence system for firing the 23YA6 SAM at the aircraft. The missile caused catastrophic damage to the jet as it overflew Grozny, southern Russia. In late July, Dmitry Paladychuk was named following investigative work by the Minval Politika media organisation. It was Mr. Paladychuk who gave the order to fire the missile. The Azeri government is currently preparing lawsuits against its Russian counterpart in relation to the incident. Naming names in such cases is especially important: It gives the perpetrators of such actions public visibility and hopefully makes them look over their shoulders. They are marked men, and their ability to travel outside Russia now limited. Forget going to any nation that would enact the Netherlands’ arrest warrant. Secondly, revealing identities helps to subject such individuals to international sanctions if they have financial interests or bank accounts outside Russia. Thirdly, revealing identifies tells the Russian government that its actions will have consequences. Moscow will deny everything, but Moscow is not known for pravda. Finally, telling the world who is responsible means the culprits cannot hide from their actions. Perhaps they will not face justice, but forever they will carry their guilt, living their lives with the Mark of Cain upon them. (Source: Armada)

 

01 Sep 25. Spectrum Aware. An example of 3dB Labs’ Spectrum Situational Awareness System, which the company is developing for the US Army, seen here deployed in a stand-alone configuration. Another piece of the US Army’s manoeuvre force tactical Cyber and Electromagnetic Activities capability jigsaw is falling into place. On 20th August, the US Army announced that troops from the 11th and 25th Infantry Divisions, 101st Airborne Division and Special Operations Command had performed an assessment of 3dB Labs’ Spectrum Situational Awareness System (S2AS). The army had announced on 2nd April that the company had been selected to develop the S2AS prototype. As revealed in a US Army press release, the S2AS prototype contract is worth $6.1 m and has a 14-month duration. Few technical details have appeared in the public domain, but the press release did say the S2AS will “detect and identify signals of interest”. Photographs of the system show it being used in backpack, stand-alone and vehicle-mounted configurations. This implies that the S2AS is designed to equip dismounted troops operating at, or near, the tactical edge. Likewise, several systems could be deployed in an unattended fashion, providing spectrum situational awareness across a specific area. Vehicle-mounted systems could be used to gather Signals Intelligence (SIGINT) at the halt, or while mobile. The latter task could help enhance real time electromagnetic situational awareness as mechanised units manoeuvre.

Attributes

It is likely that the S2AS detects, identifies and locates blue and red force Signals-of-Interest (SOIs) in wavebands of at least 30 megahertz to three gigahertz. This waveband would let the system collect SIGINT, primarily Communications Intelligence (COMINT), from very/ultra-high frequency emitters. Such emitters include tactical radios, and their networks, on the battlefield. US Army video of a prototype S2AS show its antennas mounted on a mast circa two-metres (six-feet) high. At this height, the antenna could detect and process surface emitters at a range of almost six kilometres (3.7 miles). The S2AS forms part of the army’s emerging tactical CEMA posture alongside other capabilities like Raytheon’s Electronic Warfare Planning and Management Tool (EWPMT) and Terrestrial Layer System (TLS). The EWPMT is the army’s CEMA manoeuvre force battle management system. COMINT will flow into the EWPMT and populate the commander’s tactical Recognised Electromagnetic Picture (REMP). The REMP is vitally important. The picture depicts all detected emitters, and their characteristics, including those of the blue and red force. Knowing the location of blue force emitters will ensure these are left undisturbed by cyber and electronic attack. Cyber and electronic attacks will be performed at the tactical level by the Terrestrial Layer System (TLS) architecture. Three TLS capabilities are being developed: Stryker Brigade Combat Teams (SBCTs) will receive the TLS Brigade Combat Team (TLS BCT) platform. This capability is housed onboard the medical evacuation variant of a General Dynamics M-1126 wheeled armoured fighting vehicle. According to the US Army, the M-1133 variant was chosen due to the abundance of power sockets within the vehicle’s interior. Lockheed Martin was chosen by the US Army to build a prototype TLS-BCT in August 2022. TLS-BCT systems will be produced in two sub-variants: One variant will be restricted to SIGINT collection and processing, and the other will also have cyber/electronic attack capabilities. The decision to split the programme was based on feedback from US Army operational prototype TLS-BCT demonstrations in 2023. The army says it will perform operational demonstrations of the SIGINT TLS-BCT variant in June 2026. Similar demonstrations of the full TLS-BCT variant “will follow sometime later” the force disclosed in an official document. Armoured BCTs (ABCTs) will have their TLS architectures equipping BAE Systems Armoured Multi-Purpose Vehicle (AMPV) variants which are tracked platforms. Whether the ABCTs will receive two AMPV TLS variants, one of which will be confined to SIGINT and the other of which will also perform electronic attack, has not been revealed. Infantry BCTs will be equipped with the TLS backpack which is the responsibility of Mastodon Design. Deliveries of the TLS backpack to the US Army commenced in 2024. The US Army’s Mastodon Design TLS backpack provides cyber and electronic attack capabilities to infantry brigade combat team manoeuvre formations. Ongoing TLS backpack deliveries commenced in 2024.

Continued experimentation

The assessment of the S2AS with the formations mentioned above has been dubbed by the army as a chance for troops to get a ‘first touch’ of the system, alongside training with it. During the assessment, the S2AS was deployed with two companies. The system shared its SIGINT upwards to a brigade headquarters during the evaluations. The army expects to perform its first operational demonstration of the S2AS in 2026 with initial deliveries following shortly afterwards before the end of that year. The EWPMT is already in service with US Army manoeuvre force units, notably BCT signals companies which are tasked with the CEMA mission. The TLS backpack has followed suit, and the S2AS appears well on the way to deployment, thanks to this recent assessment. Despite the reorientation of the programme, the vehicular TLS-BCT variants will probably enter service too over the coming two years. The army has taken an incremental approach to revitalising its electronic warfare capabilities. Nonetheless, this approach has resulted in a gradual, yet steady, improvement in the manoeuvre force’s ability to win and sustain electromagnetic spectrum superiority and supremacy.(Source: Armada)

 

02 Sep 25. Georgia Satellites.  Unknown suspected Russian EW units are seen in this picture shrouded behind green awnings which have not prevented them being spotted from the air. What type of electronic warfare platform these are remain unknown although they appear to be deployed onboard BTR wheeled armoured vehicles. In July Finland’s CheckFirst research group published a new report on the signals intelligence capabilities of Russia’s FSB intelligence service. CheckFirst’s Open Source Intelligence (OSINT) report specifically focused on the FSB’s 16th Centre which is tasked with gathering, interpreting and disseminating Signals Intelligence (SIGINT). The report stated that the 16th Centre’s responsibilities include communications interception, cryptanalysis and cyber operations. Usefully, the Finnish researchers have pinpointed several SIGINT stations deployed around Russia which are detailed in the table below: Interestingly, Unit 03110 is located 25 kilometres/km (15.5 miles) south of Sochi in southwestern Russia. CheckFirst’s work claims that Unit 03110’s SIGINT collection facilities are just 0.5km (0.3 miles) from Russia’s border with Georgia, close to the region of Abkhazia. Abkahzia is a northwest region of Georgia that has been under Russian occupation since 2008. Russia also occupies the Georgian region of South Ossetia in the central part of the country adjacent to the Georgian-Russian border. The FSB’s Unit 03110 headquarters can be located easily on Google Maps. Its coordinates are 43.391751, 40.002668 according to CheckFirst’s report. The SIGINT base near Georgia is particularly significant: In November 2023 Armada published an article which examined the deployment of Russian Electronic Warfare (EW) assets to Abkhazia and South Ossetia. Sources in Georgia had informed Armada that EW units from the 74th Radio Engineering Regiment and 14th Separate Electronic Warfare Battalion had been deployed into these parts of the country. The 14th Separate EW Battalion forms part of Russia’s 58th Combined Arms Army. This formation is part of Russia’s Southern Military District. The 74th Radio Engineering Regiment, sources suggest, is part of the GRU presence in the occupied regions. The GRU is Russia’s military intelligence service. The sources continued that these EW units would regularly deploy close to the frontiers between Georgia and her occupied areas. Large radomes and radio frequency arrays can be clearly seen at the Unit 03110 facility using Google StreetView. The radomes may house antennas used for collection satellite communications intelligence. Such deployments are almost certainly intended for the collection of Communications Intelligence (COMINT) from inside Georgia. The units often take advantage of elevated terrain to extend their COMINT collection line-of-sight into Georgian territory. Signals of interest probably include radio traffic from Georgian military, border police and law enforcement units on south of the de-facto borders. Russian EW units may also have some interest in civilian communications in border areas.

Capabilities

Our November 2023 article noted two Russian electronic warfare vehicles, that we had not previously encountered in our research on such capabilities, active in these regions. Sources in Georgia told Armada that these systems, both equipping BTR wheeled armoured vehicles, are used for cellphone COMINT. The sources continued that the platforms are deployed by GRU military intelligence units. Unmarked civilian vehicles are known to be operating in Russian-occupied areas carrying the Artikul-M COMINT system. Artikul-M is also probably used for covert cellphone traffic COMINT collection.

Unknown suspected Russian EW units are seen in this picture shrouded behind green awnings which have not prevented them being spotted from the air. What type of electronic warfare platform these are remain unknown although they appear to be deployed onboard BTR wheeled armoured vehicles.

Assessment

The work of CheckFirst has revealed the existence of Unit 03110, and its potential role in collecting, processing and disseminating SIGINT from Georgia. The question must be asked whether this unit is tasked with handling the SIGINT collected by the GRU and Russian Army EW systems discussed in our article? It would be unsurprising if COMINT collected these EW platforms is flowing into Unit 03110. This facility may act as the clearing house for all SIGINT arriving from Abkhazia and South Ossetia. There, the intelligence is likely to be analysed if arriving in raw form. If some processing has been done at the collection level, further analysis maybe performed. It is then likely that Unit 03110 disseminates the intelligence to consumers including FSB headquarters and the GRU’s Unit 54777, both in Moscow. One of the key roles of Unit 54777 is psychological and information operations, according to open sources. Despite the strenuous efforts of Russia’s defence and intelligence communities to keep their SIGINT operations in these Georgian regions under wraps, their activities are increasingly visible. It appears ever more difficult for Moscow to mask its covert activities from the gaze of the OSINT world. (Source: Armada)

 

04 Sep 25.  September Spectrum SitRep. Quadsat have successfully installed the company’s radio frequency sensing and geolocation system onboard an uninhabited aerial vehicle. The company is now looking towards making the payload platform agnostic to expand the assets that it can equip. Armada’s monthly round-up of all the latest electronic warfare news in the product, programme and operational domains.

Pinpointing GNSS Disruption Sources

Late July saw HawkEye 360 announce new upgrades to the company’s Global Navigation Satellite System-Interference (GNSS-I) product suite via a company press release. According to the company, the enhancements provide “unprecedented” accuracy, coverage and insight for global GNSS jamming threats. Specifically, GNSS-I users will benefit from new algorithms that have improved means to distinguish individual emitters and detect GNSS Position, Navigation and Timing (PNT) spoofing as well as jamming. Geolocation accuracy for PNT signal jamming and spoofing sources is terrain-adjusted, thanks to the enhancements, improving geolocation accuracy. The global geolocation of spoofers and jammers is also enhanced via this upgrade. Company sources shared with Armada that the upgrades improve the detection of individual PNT attack systems by a factor of 15. Users of HawkEye 360’s software do not need to download any software updates per se to benefit from these improvements. Instead, the upgrades are delivered as standard data files using secure delivery methods.

Quadsat Secures Funding

Quadsat announced that the company has secured funding from several investors to help expand the its Radio Frequency (RF) geolocation and spectrum intelligence offerings for the defence sector. Investors include Join Capital and North Ventures alongside Seraphim Space Capital, Denmark’s Export and Investment Fund, Helge Munk Holdings and TPC Management. The funding will help evolve and develop the company’s RF analysis and location system. Quadsat told Armada, via a written statement, that it has “developed a payload which can transmit and receive RF signals”. The technology has been proven onboard an uninhabited aerial vehicle, and work is ongoing to make this platform-agnostic: “The payload is mounted on a gimbal and is therefore able to rotate. It can take an angular sweep and determine the direction of the signal or interference by moving the horn antenna around”, the statement added. The system refines the data it is receiving with each measurement, accurately pinpointing the interference source. Quadsat’s RF sensing technology is already used to test and validate satellite antennas with customers around the world. Moreover, via a partnership with Skyeton, Quadsat’s RF sensing technology “has been deployed to help with war efforts in Ukraine”.

Breaking Down the Siloes

On 14th August, Picogrid revealed it had been awarded a United States Army contract to provide the company’s Legion software to unify third-party army Signals Intelligence (SIGINT) systems. A Picogrid press release said the software will be used to “integrate radio frequency … sensors and analytical tools from multiple vendors into a single, cohesive operational view”. The software will contribute to building the manoeuvre force Recognised Electromagnetic Picture (REMP) by providing a common data fabric. The data fabric will integrate disparate SIGINT sensor feeds to help build the commander’s REMP. The company told Armada in a written statement that Legion provides a bridge between deployed sensors and Command and Control (C2) systems. The latter can include software like the Android Team Awareness Kit/Android Tactical Assault Kit developed by the US Air Force Research Laboratory. The statement continued that initial versions of Legion “will be deployed at the tactical level” with US Army units. However, the statement continued that Legion can be used to knit together sensors and C2 systems across large areas. Picogrid’s contract concludes in September 2026, the company added. (Source: Armada)

 

04 Sep 25. Thales ready to deliver high performance mission and combat systems to the Royal Navy for the Type 31 Frigate programme.

  • Thales has successfully completed Factory Acceptance Tests (FATs) for both the Mission System and the Combat System on the Royal Navy’s new Type 31 Inspiration-class frigates – marking major milestones in one of the UK’s most significant naval programmes.
  • Working as part of an integrated international team, and in close partnership with Babcock and the Royal Navy, Thales has now completed all core factory-based activity for the programme – further reinforcing its role as a trusted partner in the delivery of complex naval systems for the UK.
  • Thales’s Combat Management System (CMS), TACTICOS, functions as the operational heart of UK’s Type 31 frigates. It will be the central command and decision-making part of these frigates’ combat systems. Its function and performance – supporting sensor control, picture compilation, situation assessment, action support and weapon control – are critical to the operational effectiveness of the naval vessel.

The Mission System FATs were completed at the end of April 2025. Delivered to a high standard by Thales’s international team, in close collaboration with industry partners, this achievement showcases the quality, openness and technical expertise that have defined Thales’s approach to the Type 31 delivery – earning praise from the Royal Navy. The Combat System FATs followed at the end of June 2025. Built around Thales’s latest version of its TACTICOS Combat Management System – delivered by Thales in the Netherlands – it includes the latest software release that enables Type 31’s operational capabilities, reinforcing TACTICOS’s position as a leading CMS for next-generation naval platforms. With all Factory Acceptance Tests now complete, the programme will move onto land-based testing at the Shore Integration Facility, before being installed on board the HMS Venturer, first of the five Type 31 Inspiration-class frigates, the construction of which is underway at Babcock’s Rosyth facility.

Paul Watson, Arrowhead Managing Director at Babcock said: “The successful completion of the Mission and Combat Systems FATs marks another significant step forward for the Type 31 programme and reflects the strength of our collaboration with Thales and our wider industry partners. Together, we are delivering a world-class capability for the Royal Navy and creating a strong foundation for the future of the Inspiration Class frigates.”

Andy Laing, Managing Director, Above Water Systems UK, Thales, added: “Working closely with our Royal Navy and Babcock colleagues, we are delighted to have successfully completed this critical stage in the development of the Royal Navy’s new Type 31 frigates. It represents another demonstration of Thales’s proven ability to deliver integrated naval mission systems to the highest standards.”

The Type 31 programme underscores Thales’s long-standing commitment to support the Royal Navy with world-leading maritime technologies, while strengthening UK and European defence capability and industrial resilience.

 

04 Sep 25. Hensoldt South Africa signs major deal to enhance Saudi Arabia’s EW capabilities. Hensoldt South Africa’s GEW business unit – specialising in spectrum dominance – has signed a landmark contract with Saudi Arabian Military Industries Advanced Electronics Company (SAMI-AEC), representing one of the largest projects in GEW’s history. The multi-year project will provide a modern electronic warfare capability in Saudi Arabia in support of civil and military operations, while advancing capability development in line with the Saudi Vision 2030 objectives, Hensoldt South Africa said in a statement on 3 September. The scope of delivery includes state-of-the-art communications intelligence (COMINT) technologies as part of the Kingdom’s C4I (Command, Control, Communications, Computers, and Intelligence) capability, augmented by comprehensive training programmes. These advanced sensor systems will enable early detection and countering of threats, ensuring the safety of communities and critical infrastructure, according to Hensoldt South Africa.

“The programme strengthens the longstanding industrial partnership between Hensoldt South Africa and SAMI-AEC, with Hensoldt Middle East providing technical support on the ground. Wholly owned by Hensoldt South Africa, Hensoldt Middle East has been developed over several years to strategically address the local market, while driving knowledge transfer, technology development and skills enhancement in the region,” according to the company.

“Electronic warfare is increasingly critical in our current global context,” said Gilbert do Nascimento, Managing Director of the GEW business unit. “This contract is both a recognition of our proven track record in this vital domain – and a commitment to equip our partners with cutting-edge capabilities. We highly value our partnership with SAMI and look forward to supporting the Kingdom of Saudi Arabia in strengthening its strategic capabilities and long-term vision.”

Hensoldt South Africa, the Group’s largest industrial base outside of Germany with 800 South African employees across four sites, has been active in the Middle East for nearly two decades, with major deliveries since 2007.

“As the largest economy in the Middle East and one of the fastest-growing worldwide, Saudi Arabia remains pivotal in the future defence landscape. By supporting Saudi Vision 2030 and investing in local skills, technology transfer and capability development, Hensoldt South Africa aims to play a role in shaping the trajectory of defence in the region,” the company said.

Hensoldt South Africa had a big presence at last year’s World Defence Show in Saudi Arabia, saying the country holds “strategic importance for Hensoldt SA”. At the exhibition, collaboration agreements with INTRA Defence Technologies, SCOPA Military Industries and STIRA Strategic Systems solidified Hensoldt SA’s role in developing next-generation electro-optic systems and spectrum dominance solutions for the defence, security and civilian market in Saudi Arabia, the company said. SAMI-AEC was established in 1988 and in December 2020 was fully acquired by SAMI, making it a 100% Saudi-owned company. Today it is active across Defence and Aerospace (D&A), Digital Business, Energy and Security Business units. “SAMI-AEC has been able to acquire significant technical knowledge through its emphasis on the development of comprehensive Engineering & Development (E&D) capabilities and the establishment of partnerships with international companies,” according to SAMI-AEC. It has developed “substantial design and manufacturing, systems engineering and integration, systems development and IT services capabilities” and continues to invest in expanding its capabilities in E&D, manufacturing, test processes and manpower development. SAMI-AEC employs more than 3 600 staff, including over 1 500 engineers and experts. (Source: https://www.defenceweb.co.za/)

 

04 Sep 25. U.S. Army begins fielding BAE Systems’ mission-critical software-defined radios across rotary-wing aviation fleet.  BAE Systems’ AN/ARC-231A Multi-mode Aviation Radio Set (MARS) has completed initial installation and is operationally ready for use today on select U.S. Army rotary-wing aircraft. This fielding marks a major step forward in equipping warfighters with an advanced, secure, and fast-operating communications solution to inform key decisions in the field. The AN/ARC-231A MARS system is the newest generation of multi-band, multi-mission, airborne communications systems with Type 1 crypto modernization. BAE Systems designed the system to enable U.S. Army secure waveform upgrades across its rotary-wing fleet or tailored to specific mission needs. MARS’ programmability supports evolving communication needs, special mission modifications, and performance enhancements. The software communications architecture and software-defined radio design enables deployment of new capabilities as software-only upgrades.

“The fielding of the AN/ARC-231A MARS system marks a significant milestone to equip warfighters with advanced communications capabilities and an increase in mission readiness to respond more effectively to emerging threats,” said Brian Shadiack, director of Adaptive Communications and Sensing at BAE Systems. “This next-generation, software-defined radio has undergone rigorous testing to ensure it meets the highest standards of performance. Its design reflects a deep understanding of warfighters’ evolving needs in a rapidly changing operational environment.”

The AN/ARC-231A MARS system is comprised of the RT-1987 radio with associated ancillaries, including amplifiers and mounting bases. It serves as a drop-in replacement for the original ARC-231 radio currently fielded across U.S. armed forces and allies. MARS focuses on configurability and allows for flexible integration and mission deployment options that ensure interoperability for joint force operations. Available through foreign military sales, it provides international compliant air traffic control communications and a full range of mandatory U.S. and NATO capabilities. With more than 100,000 radios deployed globally, BAE Systems’ battle-proven communications products offer significantly increased capability of legacy products. The company’s compact radio sets also offer multi-band, secure anti-jam voice, data imagery transmission, and network-capable communications. The MARS system is manufactured at BAE Systems’ facility in Fort Wayne, Indiana with engineering support in Largo, Florida.

 

04 Sep 25. Bittium has made a significant donation to the 6G Test Centre at the University of Oulu by providing a tactical communications system for its use. As part of NATO’s DIANA network and Finland’s 6G Flagship programme, the Centre acts as an engine for innovation, enabling development of dual-use solutions that address both civilian and defence needs. Bittium’s communications system allows the Test Centre to integrate secure tactical communications into its hybrid testbeds, where commercial 5G, satellite systems, and future 6G solutions converge. This gives emerging startups and major players hands-on access to military-grade software-defined radio system, enabling interoperability trials, resilience assessments, and secure mobility testing under demanding real-world conditions.

“By providing our top-of-the-line tactical communications technology, we help advance new concepts that could shape both future commercial networks and secure communications. Partnering with the University of Oulu’s 6G Test Centre, as part of Finland’s 6G Flagship and NATO DIANA, reflects Bittium’s commitment to supporting dual-use innovation on a global scale,” said Tommi Kangas, Senior Vice President of Bittium’s Defense & Security business segment.

“Bittium’s system strengthens the 6G Test Centre’s role as a world-class environment for testing and validating future networks. With this tactical communications system, we can push forward Finland’s leadership in 6G research, supporting innovators from startups to global industry leaders. The donation ensures the Centre remains central to both our national 6G Flagship programme and international collaboration,” said Hannu Nikurautio, Research Director of the 6G Test Centre.

 

04 Sep 25. Hanwha Aerospace has signed a Memorandum of Understanding (MOU) with leading Estonian software companies Nortal and SensusQ on September 3rd at the International Defence Industry Exhibition (MSPO) in Poland. This agreement establishes a partnership to jointly develop a state-of-the-art Battlefield Management System (BMS) for a wide range of platforms including Hanwha’s Redback Infantry Fighting Vehicle (IFV). BMS is an essential tool for military operations, providing integrated information acquisition and processing to enhance command and control. It provides a near real-time flow of information to tactical commanders, allowing for the sharing of battalion-level combat information across the battlefield. The collaboration will leverage Hanwha’s field proven Redback IFV platform as the foundation for a new, highly advanced system that will be designed for integration with multiple platforms. Nortal will contribute its extensive experience in digital transformation and complex systems integration, while SensusQ will provide its unique domain and technological expertise shaped by operational experience. The pioneering next-generation BMS will feature a modular, non-monolithic architecture, enabling rapid integration not only with the Redback but also with a wide range of other platforms. It is designed to deliver real-time, multi-domain decision support, automated intelligence processing, and secure, coalition-ready interoperability, ensuring long-term scalability to meet the operational demands of future high-tempo warfare.

Dong-hyun Kim, the Head of LS Business Group of Hanwha Aerospace said, “This MOU is about building a genuine security partnership. By collaborating with esteemed Estonian companies, we are committed to contributing to the growth of the local and European defence industry.”

Within their strategic collaboration framework, the companies are exploring initial partnership opportunities with Estonia as well as with other Central and Eastern European countries, to develop a pioneering BMS tailored to their operational and technological needs.

“Together we are building the foundation for long-term, trusted international cooperation to meet the evolving challenges of modern warfare. This BMS can help defence forces achieve digital supremacy by preventing, countering and responding to hybrid threats with faster response times and reduced operational costs, harnessing seamless integrations and interoperability,” said Peeter Smitt, Business Area Director for Defence at Nortal.

“This partnership marks a significant milestone for Estonia’s defence industry. By combining Hanwha Aerospace’s advanced platform with the agility and innovation of Estonian software companies, we are shaping the next generation of Battlefield Management Systems, tailored to the operational needs of modern armies. For SensusQ, it is both an honour and a responsibility to contribute our expertise in situational awareness and decision-support solutions,”added Villiko Nurmoja, Co-Founder of SensusQ.

 

03 Sep 25. Everfox, the trusted high assurance cybersecurity company, announced the launch of High Speed Verifier-Turnkey (HSV-T). This hardware-enforced secure data transfer solution enhances digital collaboration and interoperability between allied nations, safeguarding mission-critical data transfers from high threat networks. Designed for tactical field deployments, HSV-T offers customizable, built-in threat removal capabilities that protect data flows between classified and unclassified networks for government, defense and intelligence systems without compromising speed or security.

“Data is a strategic asset on the battlefield, and securing its access and transfer is mission-critical,” said Sean Berg, CEO of Everfox. “Everfox’s HSV-T technology is a breakthrough in providing hardware-enforced cybersecurity in remote environments while reducing costly infrastructure.”

HSV-T operates in environments where no management network exists. It uses a Field Programmable Gate Array (FPGA) to enforce protocol separation of the data being exchanged, enabling applications like email, chat, and UAM video feeds. Part of Everfox’s HSV family, HSV-T enables safe data transfer using simple hardware logic to augment software-based security in tactical environments.

HSV-T’s applications include:

  • Streaming real-time drone video from unclassified platforms to secure command centers.
  • Delivering command and control data from forward deployed sensors.
  • Exchanging intelligence data between coalition networks with different classification levels.

For allied missions, these applications improve speed and trust in intelligence, enhance operational interoperability, and reduce vulnerability of classified networks. HSV-T’s protocol filtering diode meets NCDSMO Raise the Bar security standards for cross domain solutions.

About Everfox

Everfox (formerly Forcepoint Federal) has safeguarded the world’s critical data and networks for more than 30 years. As a leader in cross domain solutions, multi-level information sharing and data transfer and a provider of state-of-the-art threat protection and insider risk solutions, we move mission-critical information quickly and securely and prevent malware and human threats from compromising our customers’ networks. Everfox empowers governments and enterprise organizations to use data safely wherever and however their people need it. Learn more at www.everfox.com. (Source: BUSINESS WIRE)

 

03 Sep 25. A new report, published by BAE Systems’ Digital Intelligence business, has revealed that four in five (82%) defence and aerospace decision-makers and engineers said artificial intelligence (AI) is at the forefront of their digital strategies – highlighting the importance of cutting-edge technologies to staying ahead in today’s demanding defence landscape.

A key focus for organisations adopting solutions like AI is ensuring customer assets such as warships, armoured vehicles and combat aircraft, remain mission ready. With 80% of respondents stating that available, reliable assets are crucial as customers respond to mounting geopolitical tensions, around two-thirds said they are investing more in digital solutions for asset management this year compared to 2024.

Gathering insight from 540 senior IT and business decision-makers and engineers from across the globe, the report – Emerging technology behind the scenes of defence – examines the state of asset readiness in defence and the technology challenges decision-makers face.

Defence under pressure amid a new era of threat

These findings come against a backdrop of complexity. Nearly all (97%) decision-makers in defence and aerospace said there is pressure to keep assets mission ready and eight in ten (81%) stated that transforming their organisation’s approach is a key priority for 2025, citing challenges such as a lack of interoperability between systems and a deluge of data.

Andrea Thompson, Group Managing Director at BAE Systems’ Digital Intelligence business, said: “The rapidly evolving nature of warfare is placing heightened pressure on many of our customers to meet the demands of a constantly shifting threat landscape. That pressure includes ensuring critical assets operate at peak performance, for as long and as often as possible.

“To help, we’ve developed our data integration solution, PropheSEA®, which harnesses emerging innovation to ease the burden on forces and support the fast, informed decision-making today’s battlespace demands. Next generation, AI-powered solutions can help to overcome key data challenges – ultimately ensuring that assets remain warfighting ready amid a new era of threat.”

The research demonstrates a clear need for complex asset management solutions, such as BAE Systems’ PropheSEA® – a systems and data integration software that uses AI to deliver integrated product support across an asset’s entire lifecycle. Already in use with the UK Royal Navy and NATO allies, PropheSEA® enables users to securely connect data related to their assets. By bringing together information around the asset’s condition, preparedness and performance into one place, the solution cuts through the complexity so that leaders can make accurate and quick decisions.

Digital strategies prioritise data management, AI and analytics

Moving forward, introducing more advanced digital solutions will elevate asset management and levels of readiness. Only 12% of respondents, however, can say they’re at an advanced or optimised stage with this currently, highlighting the potential still to be realised.

Despite this, there are signs of strong momentum. Alongside putting AI at the heart of their strategies, some of the ways organisations are evolving their complex asset management approach include: standards-based technologies; big data and advanced analytics; condition-based monitoring systems; advanced simulation and modelling tools; and product life cycle management / enterprise resource planning.

To learn more about the emerging technologies behind the scenes of defence, download the report today: https://baesystems.com/defencetechtruths

 

03 Sep 25. LM Awarded Prototype Agreement by the US Army for Next Generation Command and Control (NGC2). Lockheed Martin (NYSE: LMT) Rotary and Mission Systems was awarded a prototype agreement to partner with the U.S. Army and serve as a Team Lead to develop a data-centric Next Generation Command and Control (NGC2) prototype. Lockheed Martin will spearhead a collaborative effort with the U.S. Army, leveraging our C2 systems engineering and project management expertise to empower small businesses, non-traditional innovators and commercial technology providers including Raft, Hypergiant (an Accelint company) and others to scale their capabilities to NGC2. NGC2 is an Army-wide, data-centric C2 transformation that enables commanders to make faster, and better decisions in the most dynamic and unpredictable environments. NGC2 will transform how the U.S. Army conducts digital mission command utilizing a data layer to provide a continuous common operating picture with a single, integrated view of the battlefield to enable swift and decisive action.  By leveraging Application Programming Interfaces and a Modular Open Systems Architecture (MOSA), Lockheed Martin is creating an ecosystem that eases third party integration, fosters innovation, accelerates development, and delivers transformative capabilities to the warfighter.

“The NGC2 effort is a central component of the Army’s transformation, and we are so proud to be playing a key role in its development,” said Chandra Marshall, vice president at Lockheed Martin. “We are committed to partnering with the U.S. Army to implement this complex system of systems solution to meet warfighter needs, advancing mission-critical capabilities.”

A Rich History in Command and Control

Lockheed Martin has extensive experience developing, integrating and deploying innovative command and control solutions.  We will support the U.S. Army in identifying opportunities for cross-domain reuse and integrating best-of-breed industry solutions.  Through its ongoing modernization efforts across the corporation, Lockheed Martin brings its experience in evolving architectures and software to MOSA standards and bridging from legacy systems to future, scalable architectures.   With NGC2, Lockheed Martin is not just partnering to build a better command and control system – we’re building a better future for our customers and our nation.  (Source: ASD Network)

 

03 Sep 25. South Korea: Government, academic sectors face security, espionage risks from North Korean actors. On 1 September, international news outlets reported that a North Korean state-sponsored group (‘APT37’) conducted a multi-phase cyber espionage operation (‘HanKook Phantom’) against South Korean academics, as well as government officials and intelligence officers. The first phase comprised the distribution of spear phishing emails that emulated a monthly newsletter to trick victims into downloading a malicious PDF document. The document enabled APT37 to install a backdoor (‘RokRAT’) to maintain persistence within compromised systems and exfiltrate sensitive data. The second phase entailed another phishing campaign to download multiple payloads and facilitate data exfiltration. The second-phase payload also self-deleted upon execution, while the first-phase payload executed in-memory alongside using other obfuscation techniques, highlighting the operation’s stealth. Like several other North Korean state-sponsored actors, APT37 continues to refine its phishing techniques to tailor to its victims and facilitate system infiltration. We assess that this operation underscores sustained cyber espionage risks to the aforementioned entities amid long-term geopolitical tensions. (Source: Sibylline)

 

01 Sep 25. Cyber & Specialist Operations Command – Established to tackle the threats of today and tomorrow. The Ministry of Defence has reshaped the Cyber & Specialist Operations Command (CSOC) to enhance the UK’s ability to help keep the United Kingdom secure at home and strong abroad. In an era where the first blows of conflict are often struck in cyberspace, the Ministry of Defence has today reshaped the Cyber & Specialist Operations Command (CSOC), following the announcement on 31 July, to help keep the United Kingdom secure at home and strong abroad.    Building on the foundations of Strategic Command, CSOC unites Defence’s cyber and specialist capabilities under a single command, ensuring the Armed Forces are ready to respond across all domains: land, sea, air, space, and cyberspace.   This change reflects the ambition of the 2025 Strategic Defence Review, which sets out a bold vision to make Britain safer, secure at home, and strong abroad. CSOC is at the heart of this vision, driving a landmark shift in deterrence and supporting the move of the Armed Forces towards warfighting readiness.    CSOC stands as the fourth Military Command alongside the Royal Navy, British Army and Royal Air Force – playing a core role in shaping and delivering Defence’s Integrated Force.   CSOC’s mission is to generate and operate specialist capabilities, ready to fight across all domains, to make the United Kingdom secure at home and abroad.   CSOC provides vital and game-changing capabilities for Defence, in support of HMG’s National Security Objectives. This includes commanding and conducting integrated operations 24/7 – for all of Defence and the UK Armed Forces – to protect the UK and support NATO, ensuring warfighting readiness – whilst keeping our forces healthy, fit to fight and ready to respond globally.  Cyberspace and the electromagnetic spectrum connect every aspect of modern life, but this connectivity also creates significant vulnerabilities. The frontline of conflict now extends beyond traditional battlefields to the digital networks underpinning businesses, national infrastructure, and daily life. Recent conflicts have shown that disinformation campaigns and persistent cyberattacks are defining features of modern warfare. CSOC stands at the forefront of this fight. Every day, its cyber specialists defend the UK’s critical networks, military assets, supply chains, and people.  CSOC brings together over 26,000 specialists across 130 global sites, uniting expertise across cyber operations, medical support, intelligence, special forces, education, and our Defence attachés overseas.

General Sir James Hockenhull, Commander CSOC, said: “Across all we do—whether delivering specialist operations, combatting daily cyber threats, arming Defence with intelligence, uniting the Integrated Global Defence Network, or preparing the next generation of Defence leaders—CSOC is always on, acting with insight, speed, and impact.   We are across every UK operation, delivering specialist capabilities and always ready to respond, anywhere and anytime.  This reshaping ensures we are equipped to out-think, out-pace, and out-fight our adversaries, keeping the UK safe at home and strong abroad. The conflict in Ukraine has underscored the needs to move to warfighting readiness, achieved through closer collaboration across Defence, wider Government, industry, and our international allies and partners. CSOC embeds frontline lessons, harnessing AI, data, drones and digital warfare to enhance the UK’s operational advantage. “

CSOC’s close collaboration with UK industry is central to this effort. By uniting operational insight with technical ingenuity, CSOC is driving innovation in areas such as cybersecurity and digital warfare. These partnerships not only strengthen national security but also create high-skilled jobs and support the growth of UK businesses at the forefront of defence technology.

As one of four UK military commands, CSOC operates at the forefront of modern warfare. Whether delivering precision targeting, constantly combatting cyber and electromagnetic threats, or uniting Defence’s Integrated Global Defence Network, CSOC ensures the UK is prepared to meet the challenges of modern warfare and protect our society, now and in the future. (Source: https://www.gov.uk/)

 

29 Aug 25. Cyber Update Key points.

  • Diplomats in Southeast Asia face increased security risks from the China-nexus threat actor ‘UNC6384’ (see Sibylline Cyber Daily Analytical Update – 26 August 2025 and our Technical analysis below).
  • The Pakistan-linked state-sponsored group ‘APT36’ poses heightened security risks to the defence and government sectors in India (see Sibylline Cyber Daily Analytical Update – 27 August 2025).
  • Supply chain-critical manufacturing organisations face elevated security and operational risks from the ‘MixShell’ malware (see Sibylline Cyber Daily Analytical Update – 28 August 2025 and our Technical analysis below).
  • Ransomware actors shifting targets to hybrid cloud environments highlights the long-term security and operational risks facing global firms (see Sibylline Cyber Daily Analytical Update – 29 August 2025)

Technical analysis of weekly stories

The China-nexus actor UNC6384 has been targeting diplomats in Southeast Asia in a cyber espionage operation since March. The group hijacks captive portals by using adversary-in-the-middle (AitM) techniques to redirect users from the portal login to an actor-controlled website. Subsequently, the victim is tricked into believing that a software update is required for the browser; victims are then provided a plugin update installer that instead downloads the first-stage malware ‘STATICPLUGIN’. STATICPLUGIN contains a valid signed digital certificate, allowing the downloader to bypass endpoint security detections, highlighting the defence evasion capabilities of UNC6384. STATICPLUGIN then retrieves a Microsoft Standard Installer (MSI) package that executes ‘CANONSTAGER’ via DLL side-loading to install a backdoor (‘SOGU.SEC‘) on the compromised network. This backdoor collects system information, downloads and uploads files from its command-and-control (C2) infrastructure and can execute remote commands. The group’s extensive defence evasion techniques during this campaign highlight its sophistication and the long-term cyber espionage risks it poses to Southeast Asian diplomatic entities.

A social engineering campaign aimed at supply chain organisations is abusing a company’s legitimate ‘contact us’ form to target employees. The victims then contact the threat actors, where both sides converse for several weeks prior to any malicious activity, building rapport and feigning legitimacy to targets, before sharing a .ZIP archive hosted on a legitimate web hosting platform. The use of legitimate platforms and services underscores the defence evasion capabilities of threat actors, pointing to long-term exploitation risks to these types of providers. Once victims open the .ZIP archive, both benign documents and malicious payloads are delivered. However, in some instances, the .ZIP archive only contained harmless decoy documents, indicating that the malicious content might be delivered via the compromised web hosting platform, depending on the victim’s IP address or other indicators. This emphasises the targeted nature of the campaign. When the malicious payloads are executed, ‘MixShell’ (a custom in-memory malware) is deployed on the machine. MixShell establishes a connection to actor-controlled C2 infrastructure and enables backdoor access to compromised networks to exfiltrate strategic data and maintain persistence in the network.

Non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware.
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.

Our cyber word(s) of the week: Captive portal (Source: Sibylline)

—————————————————————————————————————————————————————————————————————————————————————————————————————————————-

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

————————————————————————————————————————————————————————————————————————————————————————————————————————————

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

September 4, 2025 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

———————————————————————————————————————————————————————————————————————————————————————————————————————————————

03 Sep 25. Spectra Group completes latest round of successful GENSS trials. Spectra Group, a specialist provider of secure voice, data and satellite communications systems, has announced for DSEi 25, the successful completion of their latest user trials for their next generation tactical radio GENSS.  The concept for GENSS was announced last year and since then Spectra Group has successfully completed full product development and now field testing with select user groups.  Spectra Group will be showcasing GENSS (pronounced genesis /jĕn′ĭ-sĭs), their award-winning tactical satellite SlingShot system and their recent addition to the Troposcatter Family of Systems, Troposcatter on the Move (TOTM), at DSEi, Excel, London (9-12 September 2025) at stand N2-430. GENSS builds on the foundations created by the award-winning SlingShot system, embodying Spectra Group’s vision of producing ultimate radio systems that capitalise on technological advances, adapt to the evolving demands of military operations and simplify the user experience.  It has been designed and developed through a collaborative effort of tactical communication experts, seasoned military specialists and top-tier U.K. scientists and engineers.  GENSS is a significant advancement in the field of tactical radio communications, due to its modular core framework and software-defined flexibility, heralding a new era in communication technology and along with the other Spectra Group products delivers a robust layered communications network to support mission critical headquarters and uncrewed systems over the horizon.

These latest field trials further validated the success and user benefits of GENSS, delivering a single tactical radio capable of meeting the extensive secure data, voice and application demands of modern military users.  GENSS is a modular, hardware-agnostic radio system designed and now proven to be exceptionally agile, providing ultimate interoperability through straightforward software reprogramming allowing it to adapt quickly and easily to diverse user needs.  GENSS is backwards compatible with SlingShot and has the benefit it will automatically tune to the L-TAC frequency, converting any military or civilian HF, VHF or UHF FM radio into a mobile global satellite communications system.

GENSS is also a multi-mode and multi-mission software defined radio in its own right, designed for agility and interoperability whilst focusing on cognitive simplicity for the operator.  As well as a bespoke radio firmware package, Spectra Group has developed an integrated software data management package that allows Beyond Line of Sight (BLOS) bridging capability for closed/remoted MANET networks.  Integrating and managing MANET data feeds into ATAK mission software, Spectra has ensured that wide band mission critical data, such as Personal Location Information (PLI) and Cursor on Target (CoT), can be transmitted over narrowband L-TAC channels, with recent trials also proving streaming video over L-TAC services is possible.   By maximising the capability and flexibility that L-TAC offers, GENSS overcomes all traditional BLOS barriers and delivers true Communications on the Move (COTM) for individuals and platforms and by design has a low probability of detection or interception, enhancing its security and operational effectiveness.  GENSS is therefore a robust and agile solution for voice and data transmission across all domains and platforms, whether on land, sea or in the air.

Simon Davies, Chief Executive at Spectra Group said, “As a veteran led organisation, my mission has been to craft the ultimate radio system — user-friendly, light, modular and supremely flexible to adapt to the evolving demands of military operations and technological advances.  I am immensely proud and excited of what the GENSS team have managed to achieve, and these trials represent the pinnacle of our collective efforts to provide the user with simple and effective solutions.  With this latest round of trials, and the rigorous process of full military specification certification to 801/461G complete, we remain on track to bring GENSS to market in the very near future.”

 

04 Sep 25. Motorola Solutions (NYSE: MSI) and Nokia today announced a strategic collaboration to deliver a next-generation, containerised, tactical communications network solution for U.K. defence agencies. The modular system combines Motorola Solutions’ deployable Terrestrial Trunked Radio (TETRA) infrastructure and Nokia’s industry-leading 5G AirScale portfolio for reliable and secure voice and data communications on the front lines. The solution is housed in rugged, deployable containers and can be operational in under 30 minutes. Motorola Solutions’ Silvus MANET technology provides the resilient backhaul to extend connectivity across diverse operational environments and extensive geographical areas. The scalable, self-healing Silvus mesh network enables high-throughput communication links between forward-deployed units and command nodes, and supports highly secure, AI-enabled and long-range video sensors and uncrewed systems for greater situational awareness and command and control.

“Secure, resilient and real-time connectivity is crucial for modern military operations,” said Fergus Mayne, U.K. and Ireland country manager, Motorola Solutions. “With Nokia, we’re providing defence forces with powerful, next-generation communications to help bring critical information to the front lines. This innovative communications solution builds on our global footprint in mission-critical land mobile radio and previous containerised network solutions to address the dynamic and evolving needs of modern defence operations.”

“Our collaboration with Motorola Solutions to develop a compact, modular solution for reliable mission-critical communications underscores the unmatched flexibility of our private 4G and 5G

solutions, designed to meet the evolving needs of defence,” said Giuseppe Targia, head of Space and Defence, Nokia. “Our industry-leading technology enables secure, high-speed data, voice and video connectivity, empowering military operations in the most demanding environments.”

In 2021, Motorola Solutions announced the deployment of containerised communications networks to the German Armed Forces. The networks are available in both mobile and stationary versions and interoperate with the communication networks of the German Public Safety Organisations, NATO and the EU for collaboration during crisis or disaster relief situations.

 

02 Sep 25. Bittium introduces the new Bittium TAC WIN Smart Link 360™ functionality to its Bittium TAC WIN Waveform™. Smart Link 360 is the world’s first solution whose adaptive and fully automated directional antenna functionality further enhances extreme protection against jamming and significantly improves performance for broadband tactical communications on the battlefield. The solution leverages directional antennas instead of omnidirectional ones in wireless and mobile MANET (mobile ad hoc network) environments, while extending MANET capabilities into link networks. As part of the TAC WIN Waveform, and together with Bittium Tactical Wireless IP Network™ (TAC WIN) Radio Head III and IV units as well as Bittium Tough SDR Vehicular™ radios, Smart Link 360 reinforces the advanced and unique qualities of Bittium’s comprehensive tactical communications system.

Smart Link 360 enables electronic antenna beam steering across a full 360-degree range. With this functionality, neighboring nodes in the network are automatically identified, enabling fast and effortless link creation without operator intervention. It supports full mesh topology —direct node-to-node connectivity that allows multiple transmission routes—and ensures mobility by dynamically tracking node movements. This makes Smart Link 360 ideally suited for both link networks and mobile nodes. Powered by the advanced TAC WIN routing algorithm, Smart Link 360 further increases network resilience by automatically directing antenna beams toward the optimal communication path while mitigating interference from other directions. The Bittium TAC WIN Network Manager Tool™ provides operators with real-time visualization of both network topology and antenna beam orientation.

“The advanced TAC WIN Waveform, together with the new Smart Link 360 functionality, particularly supports the rapid operations of mobile forces, delivering significant performance advantages in command and control. A key benefit is the increased automation of the communications network, which is especially critical for unmanned vehicles. We have refined these capabilities in the European iMUGS program, which is developing next-generation unmanned systems for the battlefield. With Smart Link 360, we are addressing both current and future customer requirements,” said Tommi Kangas, Senior Vice President, Defense & Security business segment at Bittium.

Bittium will showcase the TAC WIN Smart Link 360, along with other solutions for tactical communications, at stand N8-250 during the DSEI UK exhibition, September 9–12, 2025.

 

03 Sep 25. Everfox, the trusted high assurance cybersecurity company, announced the launch of High Speed Verifier-Turnkey (HSV-T). This hardware-enforced secure data transfer solution enhances digital collaboration and interoperability between allied nations, safeguarding mission-critical data transfers from high threat networks. Designed for tactical field deployments, HSV-T offers customizable, built-in threat removal capabilities that protect data flows between classified and unclassified networks for government, defense and intelligence systems without compromising speed or security.

“Data is a strategic asset on the battlefield, and securing its access and transfer is mission-critical,” said Sean Berg, CEO of Everfox. “Everfox’s HSV-T technology is a breakthrough in providing hardware-enforced cybersecurity in remote environments while reducing costly infrastructure.”

HSV-T operates in environments where no management network exists. It uses a Field Programmable Gate Array (FPGA) to enforce protocol separation of the data being exchanged, enabling applications like email, chat, and UAM video feeds. Part of Everfox’s HSV family, HSV-T enables safe data transfer using simple hardware logic to augment software-based security in tactical environments.

HSV-T’s applications include:

  • Streaming real-time drone video from unclassified platforms to secure command centers.
  • Delivering command and control data from forward deployed sensors.
  • Exchanging intelligence data between coalition networks with different classification levels.

For allied missions, these applications improve speed and trust in intelligence, enhance operational interoperability, and reduce vulnerability of classified networks. HSV-T’s protocol filtering diode meets NCDSMO Raise the Bar security standards for cross domain solutions.

About Everfox

Everfox (formerly Forcepoint Federal) has safeguarded the world’s critical data and networks for more than 30 years. As a leader in cross domain solutions, multi-level information sharing and data transfer and a provider of state-of-the-art threat protection and insider risk solutions, we move mission-critical information quickly and securely and prevent malware and human threats from compromising our customers’ networks. Everfox empowers governments and enterprise organizations to use data safely wherever and however their people need it. Learn more at www.everfox.com. (Source: BUSINESS WIRE)

 

02 Sep 25.  INVISIO announces launch of new T30 headset. Tactical communications expert INVISIO is announcing a brand-new headset offering unlimited versatility in the field, with zero compromise to sound quality, hearing protection and situational awareness. The new headset is suited for both dismounted and mounted operations.This means customers and end-users can now rely on one headset to serve their needs across a range of environments from training to missions, dismounted and mounted. The versatility of the T30 is a groundbreaking development in tactical communications, as it removes the necessity for different headsets for different situations and reduces the need for additional equipment, training and costs.

Zero compromise, just tactical excellence

T30 leverages INVISIO’s expertise in this field, delivering market-leading hearing protection of 30 dB SNR / 33 dB NRSA20 combining passive hearing protection with active noise reduction. The active noise reduction contributes to increased protection in low frequency noise environments, often associated with mounted situations. This allows users to spend more time in vehicles and reduces potential fatigue. The T30 also provides a unique implementation of active noise reduction, where noise reduction is active while full situational awareness is maintained, enabling maximum protection in all situations. Due to an upgraded acoustic design, the T30 provides best-in-class sound localization down to 9 degrees.

T30 offers double hearing protection (38 dB SNR / 39 dB NRSA20) with optimized situational awareness. In double hearing protection mode, hear-through audio is fitted to match an acoustic filter in the in-ear plug, ensuring the user gets full double hearing protection whilst still gaining optimized situational awareness.

The T30 also provides headset embedded INVISIO audio, delivering unrivalled sound quality and Automatic RX Volume Adjustment, adjusting radio volume in line with surrounding noise, along with VOX Capability enabling voice activated transmission.

Unlimited connectivity, versatile by design

Along with uncompromised audio quality, it delivers versatile connectivity to personnel in the field, connecting with INVISIO control units as well as the specially designed and ultra-light Push-to-Talk P30. The P30 adds flexibility for the wearer, as it can be mounted in a left, right and center orientation. Additionally, two P30s can be connected simultaneously, providing the user with a very flexible dual-radio setup. The headset can also be connected directly to digital devices such as smartphones and laptops, offering rich audio sound and power from these devices.

The T30 offers the capability of connecting external microphones through its U-173 plug, allowing easy integration with equipment such as gas masks. Automatic smart detection ensures the external microphone gets priority over the boom microphone. The Redundancy Tx feature will allow voice pick-up from the hear-through microphones in case the boom arm is lost or defective. Versatile power modes mean the T30 can operate as a stand-alone headset, powered by a single AA battery (up to 110 hours battery life), or draw power from a connected device. The headset transitions between power modes without operational disruptions. Users can easily swap between wearing styles in two minutes, without using tools, providing added versatility. On top of this, the headset is water and humidity repellent, submersible down to two meters for two hours.

Jonathan Wassberg, Product Manager of Headsets at INVISIO, said: “The T30 is a groundbreaking addition to our tactical communications systems and really does offer something we haven’t seen before – a stand-alone headset that eliminates the need to change headsets in different scenarios, offering unlimited versatility with zero compromise to audio quality, hearing protection and situational awareness.

“From versatile connectivity, design, and power modes to unrivalled audio adaptability, hearing protection and situational awareness, this is the culmination of INVISIO’s years of experience in this field, and answers the needs of personnel across the world, in an array of scenarios that has never been seen before.”

The INVISIO T30 in highlights:

  • Market-leading hearing protection of 30 dB SNR / 33 dB NRSA20.
  • 360-degree situational awareness with sound localization down to 9 degrees.
  • Headset-embedded INVISIO Audio, adaptive volume control and VOX capability.
  • Combined Active Noise Reduction and passive hearing protection.
  • Double hearing protection with optimized situational awareness.
  • Connection with INVISIO eco-system, 3rd party PTTs and digital devices.
  • Easy swap between three wearing styles in less than 2 minutes. No use of tools.
  • Multiple powering modes– through control units, digital devices, radios and AA batteries.
  • Right and left boom microphone configuration.
  • 2 meters for 2 hours submersibility.

The product is expected to be available for shipment within the coming 6 months, subject to regions and variants.

The T30 will be presented at DSEI September 9-12 in London, booth number S13-510. Visit INVISIO there, or alternatively, visit Invisio.com or contact your local INVISIO representative.

 

02 Sep 25. Bittium will unveil its latest innovations for tactical and secure communications – purpose-built to ensure mission success in the most demanding operational environments at DSEI. The advanced tactical communications solutions empower C6ISTAR with high performance, seamless interoperability, resilience, and future readiness to support defense forces as they modernize and digitalize their critical communications infrastructure across domains. At the core is a modular, mobile IP-based backbone network capable of covering large geographical areas while combining wireless and wired connectivity. Together with next-generation tactical radios and waveforms, this creates a seamless full IP MANET. A unique dispersed voice solution, engineered specifically for tactical environments, ensures resilient voice across the network. For secure communications, Bittium showcases its ultra secure smartphones and cross-platform software solutions meeting the high requirements of defense forces, governments, and authorities. In addition to its own Tough Mobile devices, Bittium’s software is compatible with all major operating systems, including Android™, iOS, and Microsoft Windows, for achieving organization-wide secure communication, connectivity, and device and application management.

Highlights

  • World premiere: Bittium TAC WIN Smart Link 360™ – a world’s first solution whose adaptive and fully automated directional antenna functionality further enhances extreme protection against jamming and significantly increases performance for broadband tactical communications on the battlefield.
  • Quantum-safe secure communications – responding to the challenge of quantum computing and the threat of “harvest now, decrypt later”, Bittium showcases the Bittium SafeMove® Mobile VPN and Bittium Secure Call™ software solutions for quantum-resistant mobile communications.
  • Live demonstration – simulating real-world operations with a hybrid solution that unites Bittium’s tactical and secure communications to ensure secure interoperability across tactical and mobile 4G/5G networks.

“Modern defense forces require more than just reliable communications – they demand secure, interoperable, and future-proof solutions that work seamlessly across domains,” said Tommi Kangas, Senior Vice President, Defense & Security business segment at Bittium. “At DSEI UK, we are proud to showcase innovations to keep armed forces connected and mission-ready at all times.”

More information on solutions for tactical and secure communications: https://www.bittium.com/defense-security/

In addition to showcasing the tactical and secure communications portfolio, Bittium introduces the expansion of its engineering services to meet the evolving needs of defense industry. With proven capabilities in wireless, tactical communications, secure software, and rugged electronics, Bittium provides tailored engineering services to industry OEM’s and system integrators to accelerate innovation, enhance operational readiness, and deliver solutions built to withstand the toughest environments. More information on engineering services: https://www.bittium.com/engineering-services/defense-security/

 

29 Aug 25. Comand AI embed in the UK defence ahead of DSEI 2025. Prevail has already hit the ground running on the continent with the French Army and German Bundeswehr. The pan-European start-up Comand AI is expanding its footprint in London after its flagship platform, Prevail, hit the ground running on the continent with the French Army, German Bundeswehr, and with another ongoing project in Ukraine. It is a natural next step for an organisation bringing generative artificial intelligence (GenAI) to military planning – a priority enshrined in the UK’s Strategic Defence Review, in which the trio of authors recommended that autonomy complement the ‘heavy metal’ of tanks and artillery.

Paul Billings, vice president of the emerging UK entity, delivered an exclusive demo of Prevail for Army Technology at its office in London ahead of the leading UK defence exhibition, DSEI, where the start-up will dwell within the French pavillion, having been founded in Paris by defence expert Loïc Mougeolle just two years ago.

Ultimately, Prevail is a GenAI platform composed of two integrated components: Plans and Lessons. Together, they speed up and inform tactical decisions, allowing command and control (C2) to act faster in the mission planning stage, creating a smoother tempo on the battlefield with more time to focus on other military actions.

Prevail: Plans

Prevail processes the receipt of orders brief after which the GenAI tool helps personnel analyse missions, evaluate terrain, assess threats, and generate viable courses of action. The tool utilises data from open street maps and low latency satellite pictures. This could extend to data gathered from disaggregated sensor nodes on the ground but this depends on user requirements. In the end, the platform allows decision-makers to wargame options under different criteria, such as logistics, flexibility, or C2.

Learn more about Strategic Intelligence

Comand AI say this brings a fourfold increase in analysis and scenario development speed.

“This work would normally be done in 2025 with a sheet of plastic over a map [jotted by] humans with felt tip pens,” Billings said as he parsed through an AI-generated timeline of overlapping tactical actions among different military units for a fictional scenario across the complex, forested terrain south of the city of Chornobyl.

The manual methods of mission planning “would take an entire staff of 12 [or] 15 people, [around] 30 minutes, and we’ve just done it in three minutes,” he reckoned.

Computer devices featuring Prevail. Credit: Comand AI.

Prevail: Lessons

Meanwhile, the ‘lessons’ element allows the Armed Forces to draw insights from distinct data sets – missions, academia, and doctrine – into a coherent brief. The lessonsautomatically feed relevant insights into the Plans section, closing an enduring gap between operations and lessons learned.

“You can’t take six months in learning lessons because the technology would be more abundant. You’ve missed two or three iterations by the time you get back to it,” Billings considered, “so how do you draw lessons?”

In this instance, Prevail consumed information given in interviews with Vietnam War veterans.

“We’ll pick a document,” Billings said, guiding through the Lessons interface. “If you go into it, you see it has generated lessons and observations. Observations create lessons, and then lessons create trends, and then you go from there.”

Currently, Comand AI are working with the French Army using the Lessons tool, and the start-up sped up the process from up to four months to just two weeks while still maintaining a large degree of human interaction. Billings noted the platform saved around 80% of the typical timeframe.

“You can take articles, academia, but also, and more pertinent to that, rapid lesson cycles, post operational reports, post operational insights, post exercise reports, interviews from the battlefield, drop them in.”

Tapping into UK defence, DSEI 2025

Alongside their new office in London, Comand AI plan to inject more than £35m ($47.5bn) in British defence over the next five years. This ambition builds on the €12m ($14m) raised in pre-seed and seed funds. The Anglo-French company have hired more British engineers which will no doubt feed into UK government requirements for a strong domestic footprint. Besides, Comand AI have a significant advantage as a software supplier. Hardware suppliers “have to suddenly scale up to produce 250,000 [units] in three months, which is a problem that governments can have in the way it establishes hardware contracts,” Billings mentioned. (Source: army-technology.com)

 

19 Aug 25. Global Skyware, part of the Global Invacom Group, has unveiled its XY antenna. Ideally suited for rapid response, mission critical applications, the XY offers users the highest degree of modularity, flexibility and simple assembly for on-the -move and on-the-pause connectivity.  The XY antenna allows multi-orbit capability across Geostationary Earth Orbit Satellite (“GEO”), Low Earth Orbit (“LEO”), Medium Earth Orbit (“MEO”) and High Earth Orbit (“HEO”). It can be switched between the high frequency Ka- and Ku-bands and can also be operated using outdoor or indoor control systems, depending on user requirements. The antenna’s integrated system is unique on the market today, with no requirement for the transportation of multiple discrete feed elements and radio frequency (“RF”) units. This is all packaged into a transceiver that is attached to the back of the antenna reflector. The use of a transceiver brings huge advantages in terms of reduced size, weight, power and cost (“SWaPC”). It packs the equivalent of multiple Block Up Converters (“BUCs”), Low-Noise Block Down Converters (“LNBs”) and ports into one neat package. Highly suitable for government and defence applications, the antenna is exempted from restrictions under the International Traffic in Arms Regulations (“ITAR”) and is World Geodetic System (“WGS”) compliant. Hardened to enable it to function in the most extreme environments, it is also available with a Digital Intermediate Frequency Interoperability (“DIFI”) interface or hosted software defined modems, supporting multi network capability and the virtualisation of satcoms ground infrastructure. The XY antenna is packaged such that it is also compliant with Internation Air Transport Association (“IATA”) requirement, as well as being easy to handle and transport on aircraft.

Robert Potter, Chief Technology Officer at Global Invacom said: “The XY antenna is our most innovative antenna to date: lighter, smaller and includes the use of a transceiver rather than discrete RF, which results in a significantly more compact system. During the development process, we have taken every step to ensure that this antenna delivers for the user. It’s incredibly flexible, easy to use and highly reliable enabling it to adapt to many different user profiles.”

The Global Invacom team will be at the Defence & Security Equipment International (DSEI) exhibition in London from 9th to 12th September 2025. To book a meeting, please visit: https://globalinvacom.com/blogs/news/dsei

 

08 Jul 25. Savox and Insta Launch Collaboration – Aiming to Develop Integrated Audio and Vehicle Solutions. Savox Communications and Insta and have signed an agreement to combine their top-tier technologies and expertise in developing and delivering advanced defence and security solutions. The collaboration will be officially announced at the international DSEI 2025 exhibition in London, taking place from 9-12 September. The collaboration leverages Savox’s position as a leading provider of mission-critical communication solutions and technology company Insta’s strong capabilities in networked defence solutions and system integration. Together, the companies aim to develop more comprehensive, integrated, and interoperable solutions tailored for the demanding needs of defence and public safety operators – with a particular focus on integrated audio and vehicle environments, where real-time situational awareness, connectivity, and compatibility are critical.

– Collaborating with Insta supports our strategy to strengthen our offering with holistic solutions that enhance operational effectiveness and situational awareness in challenging conditions, says Jerry Kettunen, CEO of Savox Communications.

– Savox’s technological know-how perfectly complements Insta’s system development capabilities. As experts in the state-of-the-art technology, we highly value collaboration to provide purposeful products and solutions. We see strong growth potential both in Finland and on the international market, says Ville Kettula, Vice President of Insta ILS Oy.

The joint solution will be showcased at the DSEI 2025 exhibition in London this September.

For more information about Savox, visit: www.savox.com

About Savox:

Savox Communications designs and manufactures advanced, rugged and robust hearing protection and communication solutions for the most demanding conditions. Headquartered in Finland, our worldwide network, distributors and agents deliver mission-critical systems for defense, fire and rescue, law enforcement, and industrial sectors across global markets. Over 40 years of experience in the industry and our agile and highly advanced R&D and engineering capability have earned Savox a reputation for superior quality. Our 300 co-workers around the world pride themselves on ensuring the safety and enhancing the operational capability of teams and individuals in challenging conditions where seamless access to voice and information is vital.

About Insta:

Decisive defence technology for the future

Insta is a diversified technology company with in-depth expertise to enable secure and customer-focused solutions for the needs of industry, defence, software development, and cyber security.  We are a reliable partner that develops future security and decisive performance in an ever more rapidly changing, networked world. Insta is also a strategic partner of the Finnish Defence Forces.  Advanced technology allows you to see further, react earlier, and influence more efficiently – on land, sea, and in the air. We use our strong know-how to build defence by integrating systems, developing and maintaining capabilities, enhancing command and control, and creating the real-time situational picture to support decisions.

Continuous movement, experience and responsibility are at the core of our safety culture. In 2024, the net sales of our growing family business was 176,2 m euros and we employed approximately 1,200 people. Insta – Decisive Impact.  Further information: www.insta.fi

 

19 Aug 25.  MilDef takes a comprehensive approach to the data-driven defense. At the global defense exhibition DSEI 2025 in London, September 9-12, MilDef will present the next generation of systems for a digitalized, data-driven defense – focusing on increased efficiency and connectivity, NATO interoperability, and future-proof technology. Visit MilDef at booth N7-130. Among a wide range of rugged computers, servers, network products, tablets, displays, and specialized electronics for battlefield digitalization, MilDef will showcase the next generation of rugged displays and vehicle electronics based on GVA standards and video over ethernet technology. MilDefs solutions enable real-time data sharing, enhanced crew safety, and future-proof, modular upgrades – for superior operational efficiency in the harshest environments. From NVIS compatible displays to integrated sensor systems, MilDef demonstrate how connected, scalable architectures are shaping the future of military vehicles.

“At DSEI, MilDef is at the forefront of helping armed forces stay connected, protected, and mission-ready. We are showcasing the latest in technology development for greater interoperability, modernization, and mission-critical support – when and where the stakes are the highest. Never before have we presented such a complete spectrum of end-to-end solutions for the data-driven defense, enabling our customers to digitalize critical information flows in challenging environments”, says Fredrik Persson, CTO and Vice President of MilDef Group.

—————————————————————————————————————————————————————————————————————————————————————————————————————————————

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

————————————————————————————————————————————————————————————————————————————————————————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

August 29, 2025 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

————————————————————————————————————————————————————————————————————————————————————————————————————————————————

28 Aug 25. Pentagon Halts Chinese Coders Affecting DOD Cloud Systems. Defense Secretary Pete Hegseth said the Pentagon has halted a decade-old Microsoft program that has allowed Chinese coders, remotely supervised by U.S. contractors, to work on sensitive DOD cloud systems. In a digital video address to the public posted yesterday, the secretary said DOD was made aware of the “digital escorts” program last month and that the program has exposed the Defense Department to unacceptable risk — despite being designed to comply with government contracting rules.

“If you’re thinking ‘America first,’ and common sense, this doesn’t pass either of those tests,” Hegseth said, adding that he initiated an immediate review of the program upon learning of it.

“I want to report our initial findings. … The use of Chinese nationals to service Department of Defense cloud environments? It’s over,” he said.

Additionally, Hegseth said DOD has issued a formal letter of concern to Microsoft, documenting a breach of trust, and that DOD is requiring a third-party audit of the digital escorts program to pore over the code and submissions made by Chinese nationals.

The audit will be free of charge to U.S. taxpayers, he said.

The secretary also said he’s tasking DOD experts with a separate investigation to determine whether any digital escort employees have negatively impacted the coding of DOD cloud systems, and that all Defense Department software vendors must now identify and terminate any Chinese involvement with DOD cloud systems.

“It blows my mind that I’m even saying these things … that we ever allowed it to happen,” Hegseth said of DOD’s use of the digital escorts program, adding that the Pentagon is now vigorously working to course correct, and that the department expects its vendors to put U.S. national security ahead of profit maximization.

“I’m committed, like is, to ensuring that our national security networks are secure,” Hegseth said.

“Again, it’s ‘America first,’ and it’s common sense.”     (Source: U.S. DoD)

 

27 Aug 25. Omnisys highlights its BRO™ – a unique, fully-integrated Battle Resource Optimization system that revolutionizes combat mission planning and execution. BRO™ is the only system that builds mission plans based on the actual inventory of available weapon systems and resources, significantly improving effectiveness without requiring additional force structure and provide multi-mission and multi-domain solution. Supporting the entire mission lifecycle -planning, execution, and post-mission debriefing, BRO™ enables commanders to achieve over 30% better mission performances using existing assets. By integrating operational data regarding: weapon systems capabilities, environmental conditions, terrain, intelligence,about enemy systems, BRO™ generates real-time, AI-driven recommendations that ensure optimal decisions at every stage. Its intuitive, automated design minimizes human error, shortens planning cycles, and delivers consistent performance regardless of battlefield pressure or fatigue.

“The BRO™ system is operationally validated and in use worldwide,including by NATO nations”, says Alfred (Fredi) Tzimet, Deputy CEO of Omnisys. “It protects civilians, saves lives, and strengthens defense capabilities by turning every asset into a smarter, more impactful operational tool. BRO™ delivers true operational superiority in an increasingly complex battlespace. With over 25 years of expertise, Omnisys continues to deliver scalable, combat-proven solutions that empower defense forces with smarter decisions and unmatched battlefield advantage.”

BRO™ software-powered, microservices, and web technology-based system that includes GEO (DTM/DSM) services, weapon systems physical modeling, advanced AI-driven analysis and optimization algorithms, and simulation capabilities .It supports real-time mission operations, long-term force build-up planning, and seamless integration with C4I systems, or can operate independently. Adaptable to evolving operational concepts, BRO™ covers a wide range of mission types, including air defense, air surveillance, electronic warfare, spectrum management, intelligence gathering, and border security.

About Omnisys

Omnisys is a leading global provider of combat-proven optimization systems for multi-mission planning and real-time decision-making. AI-driven BRO™ Battle Resource Optimization systems empower mission commanders to improve the performance of complex multi-domain missions, including intelligence gathering, spectrum management, air defense, air surveillance, border security, and electronic warfare. For Further informaion: https://www.omnisys.co.il/

 

27 Aug 25. India: Cyber operation highlights security, espionage risks to government, defence sectors. On 25 August, international media sources reported that the Pakistan-linked state-sponsored group ‘APT36’ targeted Indian government and defence entities in an August cyber espionage campaign. The campaign initiates via phishing emails containing procurement themes. The phishing email contains a .ZIP file with Linux-specific malicious files, which subsequently fetch a dropper from Google Drive. The dropper conducts security checks, establishes persistence and connects to the command-and-control (C2) server. The campaign specifically targets Linux Boss environments, highlighting APT36’s growing sophistication. Customisations to the malware delivery mechanisms depending on the operating system of the target increase the rate of successful and persistent infections while evading traditional security controls, further showcasing APT36’s skillset. As such, we assess that the Indian government and defence sectors face sustained security and cyber espionage risks amid ongoing bilateral tensions between India and Pakistan. (Source: Sibylline)

 

25 Aug 25. GIADS IV achieves full technical capability within German Airforce. The GIADS IV system is completely integrated with the Nato Integrated Air and Missile Defence System. This advancement follows a series of rigorous tests. The system is on track for full operational capability by 2026, which will include comprehensive training components. Developed by Airbus Defence and Space, the system operates on the Deployable Control and Reporting Centre (DCRC) platform. It is now fully integrated with the Nato Integrated Air and Missile Defence System (NATINAMDS).  This achievement builds on the initial technical capability reached in 2023 and the deployment to the Baltic Sea region in 2024 as part of Nato’s enhanced Baltic Air Policing mission. GIADS IV plays a vital role in maintaining the integrity and security of German airspace throughout the year. At its core is Airbus Fortion 1SkyControl software, which facilitates Nato interoperability through its ability to enable seamless communication of data via Tactical Data Links. The software consolidates information from various radar sensors to deliver precise tracking and automatic correlation of flight and mission plans. It offers multi-domain situational awareness, aids in identifying aircraft, provides tactical guidance, and coordinates with military and civilian air traffic control systems, according to the company. A key feature of GIADS IV is its capability to automatically discern all objects within its monitored airspace, significantly reducing the potential for misidentification of friendly forces. The rollout of GIADS IV encompasses both hardware and software enhancements for the DCRC, said Airbus. The software’s open system architecture includes elements such as private cloud services and machine learning technologies, offering flexibility for future updates and integration with emerging systems. Airbus said it “will continue to empower the German Air Force in safeguarding national and coalition airspace”. In June this year, Airbus secured a contract from the German procurement agency (BAAINBw) to retrofit 23 Luftwaffe A400M aircraft with directed infrared counter measures (DIRCM) systems. (Source: airforce-technology.com)

 

25 Aug 25. Korean Air, LIG Nex1 announce collaboration to enter EW aircraft project. Korean Air and LIG Nex1 have announced that they will form a consortium to compete in South Korea’s ‘Block-I Electronic Warfare (EW) System Development Project’, which aims to provide the Republic of Korea Air Force (RoKAF) with an airborne EW platform. Seoul is investing a sum of KRW1.7775trn (USD1.2bn) in the project, with selected South Korean companies to conduct research and development for the new platform, according to statements by Korean Air and LIG Nex1. The final proposal for the project is scheduled for submission in early September, according to Korean Air. South Korea’s Defense Acquisition Program Administration (DAPA) has been accepting bids for the project since 15 July, according to LIG Nex1. DAPA deliberated and approved the basic strategy for the project in 2023 and subsequently approved the ‘basic system development plan’ in June 2025, the company added. DAPA told Janes in 2023 that the new platform would operate as a “stand-off jammer aircraft”, similar to the US Air Force’s (USAF’s) new EA-37B ‘Compass Call’ aircraft. Janes previously reported that South Korea intends to acquire four aircraft by 2032. Domestic companies selected for the project will be responsible for EW systems integration and aircraft modifications. The role of Korean Air in the consortium is to handle systems integration and aircraft modification or manufacturing. LIG Nex1 will be responsible for system development and EW equipment development and installation, according to statements by both companies. (Source: Janes)

 

22 Aug 25. Fiber Optic FPV Drones Featured in US Navy Electronic Warfare Exercise. A first-person view (FPV) type quadcopter drone controlled via a fiber optic cable was among the participants in a U.S. Navy-led exercise earlier this year focused on exploring new distributed electronic warfare capabilities. Fiber optic kamikaze FPVs, which Russia first began using in Ukraine last year and have now become a fixture on both sides of that conflict, are notably immune to jamming and many other forms of electronic warfare. The Michigan National Guard released pictures of the fiber optic FPV and other uncrewed systems that took part in Exercise Silent Swarm 25. The event itself took place back in July at the Alpena Combat Readiness Training Center (CRTC) in Alpena, Michigan. The Navy’s Naval Surface Warfare Center, Crane Division (NSWC Crane) has been holding Silent Swarm events annually at the Alpena CRTC in cooperation with the Michigan National Guard and other elements of the U.S. military since 2022.

“During the series of technology experiments, private companies, academic institutions, and military organizations used swarms of unmanned systems to ‘attack’ and ‘defend’ locations in Thunder Bay, off the coast of Alpena in Lake Huron,” according to a press release on the exercise the Michigan National Guard put out today. “As the two forces conducted their operations, all parties collected data on which technologies offered the greatest advantages.”

“The hypothesis for Silent Swarm is to identify those systems that can outmatch and have an impact in the most challenging environments,” Rob Gamberg, project lead for Silent Swarm at Naval Surface Warfare Center, Crane Division (NSWC Crane), also said in a statement. “We are learning from each other with every iteration, which is exactly what we hope to see.”

How many total fiber optic FPVs took part in Silent Swarm 25, and whether they were used as ‘attackers’ or ‘defenders,’ or both, is unclear. However, their inclusion in the exercise at all makes good sense. As noted, Russia first began using FPVs with this kind of control method last year, primarily in response to growing electronic warfare threats. The fiber optic-controlled first-person view (FPV) type drone seen being prepared for use during Silent Swarm 25. Michigan National Guard Fiber optic control offers additional benefits, including a more reliable, secure, and higher-speed link with lower latency (key for FPV operation) that is also immune to cyber intrusion. The hard link helps mitigate the effects of terrain that can interfere with radio control, something that is also a factor for operating drones inside buildings. Fiber optic drones also do not pump out radio frequency emissions that passive sensors can detect, making them harder to spot. The control scheme is not without its own disadvantages, including the potential for the cable to become tangled on or severed by various obstacles. The drones are also not invulnerable, including to laser and microwave directed energy weapons. Still, Ukrainian forces followed suit in adopting fiber optic FPVs for the same general reasons. Fiber optic cables have also since emerged as a means to control small uncrewed ground vehicles.

“The idea is great, because you are operating in total radio silence, so you cannot be detected by any radar system [passive sensors]. And any electronic warfare means that later on, they are just inefficient,” the commander of the 12th Special Forces Brigade Azov of the Ukrainian National Guard’s Unmanned Systems Battalion, who uses the call sign Yas, told TWZ in an interview in May. “At the same time, the use of fiber optic cables, as with any FPV drone, has its own peculiarities of operation, and if the pilot is not skilled enough, that is going to lead to significant losses in such equipment and systems.”

“I would like to say that at the moment, Russian electronic warfare is undoubtedly one of the leading in the world,” he added. “So I do not want to underestimate the enemy. We need to accept, to acknowledge, the level of the enemy.”

The use of fiber optic FPV in Ukraine has become so commonplace that videos have begun to emerge showing dense, tangled webs of leftover cables littered on the ground. There are also signs now that fiber optic FPVs may be starting to proliferate outside of Ukraine.

“We are so far behind,” U.S. Army Lt. Gen. Joseph Ryan, the service’s deputy chief of staff for operations, plans, and training, said in March about the U.S. military’s response to the impact fiber optic drones are already having. Ryan’s comments came during a panel discussion at an Association of the U.S. Army (AUSA) conference. (Source: UAS VISION/The War Zone)

 

26 Aug 25. Southeast Asia: Cyber campaign underscores sustained security risks to diplomatic entities. On 25 August, the technology company Google reported that the China-nexus threat actor ‘UNC6384’ is targeting diplomats in Southeast Asia in a cyber espionage operation. The actor targets captive portals; these are the web pages displayed for a newly connected WiFi network, allowing users to authenticate access, enter login credentials or pay before gaining access to the network. The actor then uses adversary-in-the-middle (AitM) techniques to direct the victim to an actor-controlled page where the ‘PlugX’ backdoor is subsequently executed onto the compromised machine. PlugX can exfiltrate files, launch a remote command shell, log keystrokes and upload and download files; it can also install additional plugins. These attributes highlight the security and espionage risks the malware poses to targeted entities. UNC6384’s use of a new downloader (‘STATICPLUGIN’) during this campaign underscores the actor’s continued development and sophistication. We assess that the campaign will sustain long-term security risks to strategic diplomatic entities in Southeast Asia. (Source: Sibylline)

 

22 Aug 25. Cyber Update.

Key points

  • Taiwanese web infrastructure faces elevated espionage and information-theft risks from the Chinese actor ‘UAT-7237.’
  • A malware operation highlights security and information-theft risks to diplomatic entities in South Korea.
  • The resurfaced backdoor ‘PipeMagic’ underscores security and operational risks from ransomware group ‘Play.’
  • The Russian state-sponsored group ‘Static Tundra’ poses long-term security and cyber espionage risks to global firms.
  • A new macOS variant of the ‘Atomic’ macOS information stealer targeting global Apple users, underscoring heightened information-theft risks.

Technical analysis of weekly stories

The Chinese actor UAT-7237 is exploiting software vulnerabilities to target exposed devices in a cyber espionage operation against Taiwanese web infrastructure. The group initially scans the internet to identify vulnerable, unpatched servers, which serve as potential targets. Once the actors gain initial access to targeted systems, they conduct rapid fingerprinting to evaluate whether the target is of sufficient value to merit the conducting of further malicious activity. Should the infected system be deemed a valuable target, UAT-7237 will deploy web shells to establish backdoor channels, using the SoftEther virtual private network (VPN) client to establish persistence and access the systems via remote desktop protocol (RDP). After establishing persistence and conducting reconnaissance, the actors pivot into other systems within the infected network, using living-off-the-land (LotL) techniques. Subsequently, UAT-7237 deploys both custom and open-source tools to perform various tasks on the infected machines. A custom tool (‘SoundBill’) is used as a shellcode loader, which may be a tool to execute arbitrary commands or install ‘Cobalt Strike’. The group also uses the tool ‘JuicyPotato’ (a privilege escalation tool commonly used by various Chinese-speaking threat actors), highlighting the collaboration between Chinese threat groups. The group aims to steal credentials from infected endpoint devices to establish long-term access to networks and propagate into other devices, highlighting prolonged security and cyber espionage risks to Taiwanese web infrastructure posed by the campaign. A sophisticated cyber espionage operation targeted various diplomatic entities in South Korea between March and July. Suspected North Korean threat actors conducted at least 19 spear phishing attacks, impersonating diplomatic contacts and attempting to trick embassy staff via legitimate-looking meeting invites, official letters and event invitations. These were disguised as .ZIP files to evade security detections and execute a malicious .LNK file that subsequently triggers a PowerShell script, connecting to an actor-controlled GitHub repository to download the ‘XenoRAT’ malware. This allows the operation to establish persistence through scheduled tasks and connect to the command-and-control (C2). XenoRAT is a remote access trojan (RAT) that allows for complete system control, providing threat actors access to a variety of potentially strategic information while maintaining a prolonged covert presence in the network, underscoring the long-term security and espionage risks from this campaign. This campaign’s tactics align with the North Korean group ‘Kimsuky’; however, there are also indications of Chinese support or connections, given the activity correlated to Chinese time zones and paused during a major Chinese holiday. This highlights the realistic possibility that certain operators of this campaign may reside in China or have Chinese origins, further complicating attribution and motivations for the attack.

Non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware.
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.

Our cyber word(s) of the week: Fingerprinting. (Source: Sibylline)

——————————————————————————————————————————————————————————————————————————————————————————————————————————————

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

————————————————————————————————————————————————————————————————————————————————————————————————————————————

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

August 22, 2025 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

———————————————————————————————————————————————————————————————————————————————————————————————————————————————-

21 Aug 25. IFS, the leading provider of Industrial AI software, today released a global study revealing the accelerating scale of Industrial AI adoption across industries. The research identifies an ‘Invisible Revolution’: a rapid but under-recognised shift away from consumer productivity-led AI experimentation and toward embedded, operational AI across core business processes. But as with all revolutions, significant challenges are emerging. The IFS Invisible Revolution Study 2025*, which surveyed over 1,700 senior decision makers at industrial enterprises globally, found that while organisations are adopting AI today, they are not fully prepared for its full implementation. This has created what IFS has dubbed the ‘AI Execution Gap.’ This gap has been formed by companies moving faster into AI adoption than their staff are able to upskill. In the next 12 months, the number of companies still in early AI experimentation will collapse from 24% to just 7% moving up in the maturity curve, yet 52% of senior leaders say their management teams don’t fully understand AI, and 99% of global workforces will require major reskilling to harness the positive impacts of AI adoption on the industrial world.

“AI is a core driver of business performance, it’s time to plug the ‘AI Execution Gap’—bring people, process, and product together to deliver tangible outcomes,” said Kriti Sharma, CEO, IFS Nexus Black. “The pace of adoption is inspiring, but the next big unlock will come from scaling trust, strategy, and talent. Industrial AI is a powerful force for good, and we’re in a moment of opportunity: those who move fast will lead the next decade of industry.”

Growing AI value, but lagging readiness and trust issues

The research reveals a striking contrast at the heart of the AI surge. While the technology is already delivering impressive returns, most organisations remain unprepared to scale its impact. More than half of business leaders (53%) admit their organisation still lacks a clear AI strategy, yet the study clearly finds opportunities available to companies that embrace AI. 70% of businesses report better-than-expected ROI from their AI investments, and on average 88% say AI has already improved profitability, rising to 92% in the US and 94% in Germany.  So how do enterprises adapt to ensure they stay competitive? Training and upskilling—supporting employees to thrive in an AI-First environment will be key to ensuring that industrial companies remain relevant. The study found that over half of the business leaders interviewed estimated that up to 60% of their employees will need new skills, with a third saying it could be as high as 100%. Despite growing confidence in AI’s potential to boost productivity and growth, trust remains a major hurdle. Only 29% of global leaders are comfortable allowing AI to make strategic decisions autonomously, while 68% say a human must still confirm or approve AI-generated outputs. Concerns about bias also persist—particularly in the US, where 63% of respondents cite it as a top concern, compared to just 40% in the Nordics. Encouragingly, 65% of global leaders support the creation of an independent, international AI regulatory body to help close the trust gap.

Industrial AI triggers a business model shift

While AI has captured attention for revolutionising productivity and creative tasks for predominantly white-collar workers, it’s Industrial AI that is fundamentally reshaping the way industrial enterprises run. It is being embedded deep within core operations, automating maintenance, predicting disruptions, optimising supply chains, and orchestrating intelligent decision-making across field service, asset management, and manufacturing. This isn’t a future ambition, it’s already happening. 54% of global organisations are using automation AI, while 45% are deploying predictive AI. Already, 35% are experimenting with Agentic AI, capable of autonomously executing decisions across workflows. Traditional business models are being influenced by AI with 77% of global leaders saying it is accelerating servitisation, the evolution from product sales to outcome-based services, where businesses deliver uptime, performance, and continuous value instead of just physical goods.

Kriti Sharma continued: “This is a bold new era where AI is redefining how industries create and deliver value. Industrial AI is moving into real-time, decision-grade intelligence embedded across the enterprise. It’s already securely automating the complex, predicting the unexpected, and powering new service-led business models. This is about shifting from tasks to transformation, and the organisations who embrace that shift will lead the next industrial chapter.”

The clock is ticking

The IFS research signals a new stage of enterprise AI, no longer confined to innovation labs, but powering frontline operations. The next 12 months will be decisive as those organisations that close the ‘AI Execution Gap’ now will shape the future of industrial leadership.

Kriti Sharma concluded: “We’re experiencing one of the most profound and underestimated shifts in global business. Industrial AI is here and already reshaping how entire industries run, compete, and grow. The time is now.”

IFS Nexus Black applies deep domain expertise and industrial-grade AI to build production-ready products proven to minimise risk, maximise return, and deliver results in weeks, not years.

 

21 Aug 25. Cyber A.I. Group, Inc. (“CyberAI” or the “Company”), an emerging growth Cybersecurity, Artificial Intelligence and IT services company engaged in the development of next-generation market disruptive AI-driven Cybersecurity technology, today announced it has entered into a strategic joint venture agreement with London-based Synergy Associates Ltd (“Synergy”), a leading global IT Managed Services Provider with operations in London, New York, Los Angeles, Paris, Hong Kong and Dubai. The partnership will center on the Beta testing and pre-commercial deployment of CyberAI’s patent-pending CyberAI Sentinel 2.0 advanced AI-driven cybersecurity platform—which is designed to deliver autonomous threat detection, adaptive risk mitigation and intelligent system resilience to enterprise and cloud environments. The patent for CyberAI Sentinel 2.0 was filed with the United States Patent and Trademark Office on July 11, 2025.

“This joint venture represents an important step as part of the development process for CyberAI Sentinel 2.0,” said A.J. Cervantes, Jr., Executive Chairman of CyberAI. “Once the Beta program begins, Synergy’s global footprint and deep customer relationships will allow us to test the platform in demanding, real-world conditions. We expect the resulting feedback to be pivotal in ensuring we deliver a transformative, market-ready AI-driven cybersecurity solution.”

With a 20-year track record serving some of the most security-sensitive sectors, Synergy is recognized for delivering high-availability IT support, advanced cloud services and rigorous cybersecurity measures to industries such as finance, creative services and professional services. The company’s trusted advisor status with its clients makes it uniquely positioned to integrate, evaluate and provide real-world operational insights into CyberAI Sentinel 2.0 before the product’s global market introduction. Alexander Caplan, CEO of Synergy, stated: “Our clients are increasingly looking for solutions that can anticipate and defuse threats before they cause damage. By partnering with CyberAI, we will soon be in a position to offer selected customers early access to a platform that learns, adapts and evolves in real time. This Beta test will give us—and them—a front-row seat to what we believe could redefine the future of cybersecurity.”

Under the agreement, Synergy will deploy CyberAI Sentinel 2.0 with a select group of clients drawn from its existing portfolio of enterprise customers. Over the course of an initial six-month Beta program, the joint venture will evaluate live-environment performance, gather structured customer feedback and execute iterative refinements to optimize platform capabilities ahead of a full-scale commercial launch. The Beta program is structured to ensure maximum operational insight without cost to participating customers during the testing phase.

About Synergy Associates Ltd

Synergy is an international IT Managed Services Provider specializing in delivering high-performance IT support and cybersecurity solutions to diversified industries, including creative and financial services. Headquartered in London and with local operations spanning New York, Los Angeles, Paris, Hong Kong and Dubai, Synergy combines local expertise with global reach, ensuring operational excellence, innovation and security for its international client base. For more information, please visit: synergy.tech

About Cyber A.I. Group

Cyber A.I. Group, Inc. (“CyberAI”) is a next-generation technology company pioneering the development of advanced, proprietary platforms at the intersection of Artificial Intelligence and Cybersecurity. With a mission to redefine how organizations protect, predict and respond to digital threats, CyberAI is positioning patent pending technologies that enable autonomous threat detection, adaptive risk mitigation and intelligent system resilience across enterprise and cloud environments. At the core of CyberAI’s innovation is a team of world-class technologists, data scientists and cybersecurity experts dedicated to creating breakthrough solutions that are scalable, secure and globally deployable. The company’s technologies are designed to address the most urgent and complex challenges facing today’s digital infrastructure—from AI-driven security orchestration to autonomous anomaly detection and predictive analytics for critical systems. CyberAI’s commitment to continuous innovation and deep IP development is positioning it at the critical merger between AI and the global cybersecurity landscape. By fusing artificial intelligence with real-world cyber defense expertise, the company aims to set new standards for intelligent infrastructure protection and digital trust. For more information, please visit: cyberaigroup.io

 

19 Aug 25. Global Skyware, part of the Global Invacom Group, has unveiled its XY antenna. Ideally suited for rapid response, mission critical applications, the XY offers users the highest degree of modularity, flexibility and simple assembly for on-the -move and on-the-pause connectivity. The XY antenna allows multi-orbit capability across Geostationary Earth Orbit Satellite (“GEO”), Low Earth Orbit (“LEO”), Medium Earth Orbit (“MEO”) and High Earth Orbit (“HEO”). It can be switched between the high frequency Ka- and Ku-bands and can also be operated using outdoor or indoor control systems, depending on user requirements. The antenna’s integrated system is unique on the market today, with no requirement for the transportation of multiple discrete feed elements and radio frequency (“RF”) units. This is all packaged into a transceiver that is attached to the back of the antenna reflector. The use of a transceiver brings huge advantages in terms of reduced size, weight, power and cost (“SWaPC”). It packs the equivalent of multiple Block Up Converters (“BUCs”), Low-Noise Block Down Converters (“LNBs”) and ports into one neat package. Highly suitable for government and defence applications, the antenna is exempted from restrictions under the International Traffic in Arms Regulations (“ITAR”) and is World Geodetic System (“WGS”) compliant. Hardened to enable it to function in the most extreme environments, it is also available with a Digital Intermediate Frequency Interoperability (“DIFI”) interface or hosted software defined modems, supporting multi network capability and the virtualisation of satcoms ground infrastructure. The XY antenna is packaged such that it is also compliant with Internation Air Transport Association (“IATA”) requirement, as well as being easy to handle and transport on aircraft.

Robert Potter, Chief Technology Officer at Global Invacom said: “The XY antenna is our most innovative antenna to date: lighter, smaller and includes the use of a transceiver rather than discrete RF, which results in a significantly more compact system. During the development process, we have taken every step to ensure that this antenna delivers for the user. It’s incredibly flexible, easy to use and highly reliable enabling it to adapt to many different user profiles.”

The Global Invacom team will be at the Defence & Security Equipment International (DSEI) exhibition in London from 9th to 12th September 2025. To book a meeting, please visit: https://globalinvacom.com/blogs/news/dsei

 

19 Aug 25. South Korea: Malware operation highlights security, information-theft risks to diplomatic entities. On 18 August, the cyber security company Trellix reported that the ‘XenoRAT’ malware has been used in a suspected North Korean state-sponsored operation against foreign embassies in South Korea since March. At least 19 targeted spear phishing attacks have occurred against high-value targets where malicious actors pretend to be EU delegation officials to trick users into opening a malicious .LNK file disguised as a PDF. The spear phishing emails were written in several languages and contained themes related to real events to feign legitimacy, underscoring the pre-mediated nature of the campaign. The .LNK file would then deploy the XenoRAT malware on the infected device and establish persistence via scheduled tasks. XenoRAT can access the webcam and microphone, conduct remote shell operations, log keystrokes, perform file transfers and take screenshots. This highlights the campaign’s goal to steal sensitive information for cyber espionage purposes, elevating security and information-theft risks to diplomatic entities in South Korea. (Source: Sibylline)

 

18 Aug 25. Taiwan: Web infrastructure faces elevated espionage, information-theft risks from Chinese actor. On 15 August, the technology company Cisco Talos reported that the Chinese advanced persistent threat (APT) group (‘UAT-7237’) has been targeting Taiwanese web infrastructure in a cyber espionage operation. The group exploits existing software vulnerabilities on internet-connected servers to obtain initial access. The group then uses remote desktop protocol (RDP) and SoftEther virtual private network (VPN) clients to establish persistent access. Subsequently, UAT-7237 establishes a backdoor connection while using open-source tools to steal credentials. The use of both open-source and custom tools points to the sophistication and defence evasion capabilities of both groups. Additionally, UAT-7237 used the privilege escalation tool ‘JuicyPotato’. This tool is used by various Chinese threat actors, indicating a potential connection between groups. This campaign appears to focus on gaining access to web providers’ VPN and cloud infrastructure. As such, we assess that the long-term infection and security risks to the sector remain persistent as Chinese actors continue to target global communications infrastructure in prolonged cyber espionage operations.  (Source: Sibylline)

 

15 Aug 25. Cyber Update Key points.

  • Compromised software packages underscore increased security risks facing South Korea-based developers (see Sibylline Cyber Daily Analytical Update – 11 August 2025).
  • The growing exploitation of legitimate tools in cyber attacks underscores elevated security risks to global businesses (see Sibylline Cyber Daily Analytical Update – 12 August 2025 and our Technical analysis below).
  • Europe-based critical national infrastructure (CNI) and government entities face sustained security and cyber espionage risks from the Russia-linked group ‘Curly COMrades’ (see Sibylline Cyber Daily Analytical Update – 13 August 2025 and our Technical analysis below).
  • A new ransomware family (‘Charon’) will elevate long-term financial, operational and security risks to the aviation and public sectors in the Middle East (see Sibylline Cyber Daily Analytical Update – 14 August 2025).
  • A cyber attack against a water dam in Norway underscores long-term security and operational risks from pro-Russia hacktivist groups (see Sibylline Cyber Daily Analytical Update – 15 August 2025).

Technical analysis of weekly stories

Threat actors are increasingly exploiting legitimate tools to infiltrate targeted systems. In a series of recent incidents, threat actors reportedly used social engineering attacks as an initial vector to steal user credentials and hijack Microsoft accounts. This enabled them to exploit the Microsoft file-sharing service OneDrive to send a legitimate-looking email notification and trick victims into clicking on an embedded link. Previous attacks typically spoofed external email addresses to send fake file-sharing notifications, highlighting the stealth of this new attack technique. The link was created using the note-taking application OneNote and redirected victims to an organisation’s genuine OneDrive environment to enhance legitimacy and evade traditional security mechanisms. This underscores the pervasive adoption of legitimate Microsoft tools during campaigns, as well as the actors’ stealth and detection evasion capabilities. Threat actors then displayed a fake login portal to coerce victims into disclosing their credentials and subsequently propagate the infection. The actors used website builders powered by artificial intelligence (AI) to create the phishing portals, also showcasing the continued incorporation of AI in cyber attacks. The tools created pages that were almost identical to their legitimate counterparts and contributed to the campaign’s high success rate, further highlighting the growing risks stemming from the development and availability of AI alongside legitimate tools. A Russia-linked group (Curly COMrades) has targeted government and critical national infrastructure (CNI) entities in a cyber espionage campaign since at least mid-2024. While the initial attack vector is unknown, the group deployed a new backdoor variant (‘MucorAgent’) onto compromised systems to maintain prolonged persistence, execute PowerShell scripts and exfiltrate data. Curly COMrades uses a Windows component (‘NGEN’) to covertly activate the malware at random times to remain obfuscated and enhance detection evasion. NGEN conducts optimisation tasks during system idle times to convert an application’s code into native machine code and to reduce startup times and memory usage. Curly COMrades exploits this mechanism to load MucorAgent at the same time as the optimisation tasks, highlighting the group’s stealth and sophistication. The group also installs several proxy tools and other payloads to maintain persistence, monitor compromised systems and exfiltrate sensitive data. The proxy tools include ‘CurlCat’, ‘Resocks’, ‘RuRat’ and ‘SOCS5 Binary’ to establish multiple persistent access points and covertly relay malicious traffic. Certain exfiltration techniques also comprise extracting hashes and authentication data from New Technology Director Service (NTDS) databases, as well as dumping Local Security Authority Subsystem Service (LSASS) memory to obtain credentials. We assess that the combination of sophisticated and new techniques and tools throughout this operation underscores the continuous development of Russia-linked cyber tactics.

Non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware.
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.

Our cyber word(s) of the week: New Technology Directory Service (NTDS) (Source: Sibylline)

———————————————————————————————————————————————————————————————————————————————————————————————————————————–

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

———————————————————————————————————————————————————————————————————————————————————————————————————————————–

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

August 15, 2025 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

———————————————————————————————————————————————————————————————————————————————————————————————————————————————–

14 Aug 25. In everyone’s interests. How do you ensure robust, dependable, secure and capable telecommunications connectivity across a country while safeguarding national security? This is a vexing question for many governments around the world. National and individual prosperity and wellbeing is increasingly dependent on internet connectivity. Companies pay suppliers and take orders via online platforms. People chat with their nearest and dearest on messaging applications. Birthday presents are purchased, fashion disasters are returned, all through a software app. Trying to imagine a world before this connectivity is like trying to imagine the world before motorcars and mass transportation. Militaries need the spectrum not only for connectivity but to ensure sensors like radar can do their job. The radio spectrum is a finite resource as physics dictates there is only so much to go around. The more people, businesses and organisations rely on this spectrum, the more congested it becomes. Some of the bandwidths fifth generation (5G) cellular communications protocols rely on are where some radars perform their mission, notably the two-to-four gigahertz S-band waveband. L-band (one-to-two gigahertz) and C-band (four-to-eight gigahertz) are under similar pressure from the onward march of 5G. Good news then that a group of Senators is close to securing legal protection to safeguard parts of the S-band from being auctioned off by the United States’ Federal Communications Commission (FCC). FCC auctions are planned to provide additional bandwidth for 5G and other uses. The safeguards are enshrined in the Budget Reconciliation Text of the Senate Committee on Commerce, Science and Transportation. Led by the committee’s chair Ted Cruz, a group of Republican senators drafted the reconciliation bill which looks set to protect key sections of the band. In a show of bipartisanship several Democrats threw their support behind the initiative. Nobody wants prosperity to suffer, but a compromise must be struck. For a nation to flourish, she must be protected, and for her to be protected, bandwidth must be available. The senators should be commended for their actions. (Source: Armada)

 

14 Aug 25. ACCESS All Areas. The Artificial Intelligence Multifunction Aperture and Transceiver project is situated within the European Union’s Arctic Command and Control Sensor and Effector System Permanent Structured Cooperation programme. The European Union’s AIMA programme will develop a prototype software defined aperture and transceiver for inhabited and uninhabited platforms. In May a consortium led by Patria, known as Artificial Intelligence Warfare Adaptive Swarm Platform, was selected to provide the Artificial Intelligence Multifunction Aperture and Transceiver (AIMA) initiative. AIMA is a project financed by the European Defence Fund (EDF). The EDF forms a pillar of the European Union’s (EU) Common Security and Defence Policy. According to the EU, the fund can be used by member states for defence and security research, development and acquisition. The fund was activated in 2016 with the intention of improving defence research and increasing member state military interoperability. The EU continues that the AIMA initiative is worth circa $59 m. Around $53 m of these funds have been allocated to date. Finland is leading the project with Estonia, Greece, Italy, Spain and Sweden as participants.

ACCESS PESCO

Work began on the AIMA initiative in 2020. The project was folded into the Arctic Command and Control Sensor and Effector System (ACCESS) Permanent Structured Cooperation (PESCO) launched in 2023. PESCO projects are EU multinational defence research and development programmes supported by the EDF. An EU factsheet says that the ACCESS project will enhance information superiority and cross-domain capabilities. Specifically, the project aims to create “a knowledge base for the development of new concepts and battlefield solutions making use of technological convergence.” Key to this is the examination of the extent to which multifunction systems can provide simultaneous sensor, effector and Command and Control (C2) support. Regarding outputs, ACCESS will develop technological solutions for combined wireless, software-defined C2 and sensor systems. Requirements for the ACCESS PESCO outputs include the ability of the solutions to operate in Arctic conditions, and Global Navigation Satellite System (GNSS) denied environments.

Difficult environments

According to a written statement from the Finnish Ministry of Defence (MOD), the AIMA project will “will study and develop a new generation scalable and cognitive artificial intelligence-controlled multifunctional software defined aperture and transceiver for military use in manned and unmanned platforms.” Deliverables include prototype hardware and software for demonstrations in representative environments. To this end, laboratory, functional and field testing will be performed. The goal of the AIMA initiative is for the deliverables to reach Technology Readiness Level Six (TRL-6). According to EU definitions, TRL-6 denotes that the technology has been demonstrated in a relevant environment.

The statement continued that the “project will study different technological approaches (and) materials.” End-user specifications will be examined including applicable criteria like North Atlantic Treaty Organisation standards. The latter is particularly important for northern and arctic environments along with high temperature, high humidity climates. Work completed via AIMA will have relevance to other pan-European military communications programmes like ESSOR.

Higher TRLs

The Finnish MOD statement said that AIMA is currently in the contracting phase with the consortium expected to commence research and development work in January 2026. Formal contracts are expected to be signed by late 2025. Following contract signature, a project roadmap will be made public. The work is expected to take three and a half years. Over the long term the statement notes that Finland and some of the other nations involved in AIMA and ACCESS have proposed taking the AIMA technology to a higher TRL level. This evolution would be achieved via a future project dubbed AIMA-2. AIMA-2 could be included in the EDF’s 2027 or 2028 workplan. (Source: Armada)

 

14 Aug 25. Signs of the Zodiac. The British Army’s Project Zodiac is overhauling the force’s intelligence, surveillance and reconnaissance data gathering, processing and dissemination mechanisms. Zodiac forms a key part of the UK’s emerging Digital Targeting Web architecture. The British Army’s Project Zodiac is delivering a digital intelligence, surveillance and reconnaissance architecture to the force designed to work in electromagnetically congested and contested environments. Roke was named as the initiative’s prime contractor in September 2023. Subcontractors include Systematic which provides its SitaWare battle management software. Zodiac will merge disparate intelligence feeds from a plethora of sources to create rich common operating picture. In 2024, the Zodiac so-called Minimum Viable Product was delivered to the British Army’s 3rd (United Kingdom) Division according to reports. This formation is headquartered at Bulford Camp, southwest England. The Zodiac architecture was taken to the United States for Exercise Warfighter 2025 which took place at Fort Cavazos, Texas in May. The 3rd (UK) Division participated alongside the Armée de Terre (French Army’s) 1st Division, the Heer (German Army’s) 10th Panzer Division and the US Army’s 3rd Armoured Corps. Reports said that Zodiac supported the British division’s finding, fixing and destruction of hostile targets. Zodiac does not replace any specific British Army ISR capabilities. Instead, it amalgamates several processes “that have not been able to talk to each other before through a sovereign data fabric”, Chris Squier, Roke’s defence director told Armada. The architecture is “digitising processes and procedures that have historically taken place (using) whiteboards, voice communications, maps, spreadsheets, and an assortment of disconnected (command and control/C2) and planning tools.

Zodiac and Digital Deterrence

Zodiac forms a key part of the British Army’s overall digitisation of the force’s sensor-decider-effector cycle. These improvements are intended to enhance the pace and quality of decision-making and action at all levels of war across the entire spectrum of conflict. According to a Roke press release, the Zodiac architecture will provide a platform on which artificial intelligence can be introduced into army ISR processes. The architecture will link outwards to share ISR data with other British military, UK government and allied stakeholders.

Zodiac defined

Although initial versions of Zodiac have entered army service the programme will not have a final in-service date. Zodiac’s introduction is iterative and the architecture “will likely never be ‘finished’”, Mr. Squier adds; “it’s a true spiral development.” The system has been designed to be network agnostic and operate across whatever links are available, he continues. These networks can be “military radios or ‘bearers of opportunity’ such as high bandwidth commercial satellite communications terminals like Starlink”. Mr. Squier says that “Zodiac has been designed to be able to work seamlessly on the army’s existing communications systems, including Bowman, rather than needing dedicated or new high bandwidth internet protocol links on day one of the project.” Zodiac provides ISR convergence from operational level corps/divisional headquarters to the tactical edge, he notes. The realisation of Zodiac, and its implementation into British Army service, comes at an opportune moment. The UK Ministry of Defence announced last month the development of the Digital Targeting Web (DTW). The DTW is discussed in more detail in this article. It forms a key part of the UK’s embrace of the North Atlantic Treaty Organisation’s Multi-Domain Operations concept. Moreover, the Digital Targeting Web, and by default systems like Zodiac, form a key strand of the UK’s Digital Deterrence concept. This stresses the sophistication and connectivity of British C2 systems as a deterrent via the pace at which UK forces will be able to navigate the famed observe, orient, decide and act decision-making cycle. (Source: Armada)

 

14 Aug 25. August Radio Roundup. Sentrycs released Version 6.0 of its counter-uninhabited aerial vehicle software in early July. Using a cyber-over-radio frequency approach the software lets air defenders take control of an errant uncrewed aircraft and remove it from an area where it should not be flying, or make it land safely, for example. Armada’s monthly roundup of all the latest news in the military communications product, programme and operational domains.

CORF to Counter Drones

On 10th July Sentrycs announced it had released Version 6.0 of its Cyber Over Radio Frequency (CORF) Counter-Uninhabited Aerial Vehicle (CUAV) software. The company said in a press release that this software update “brings significant upgrades across detection, mitigation and (its) user interface”. The press release continued that the improved software extends CUAV mitigation ranges to a ten-kilometre (6.2-mile) diameter. Mitigation tools to tackle DJI drones using the OcuSync 4.0 protocol have also been added letting users counter threats from DJI’s Air-3, Mini-4 Pro and Matrice-4 UAVs. According to the company, Version 6.0 allows “not only detection and mitigation, but complete protocol-level takeover.” Other additions include an improved command and control interface. All these improvements are delivered through software enhancements without any changes necessary for hosting hardware. Sentrycs told Armada, via a written statement, that its CORF approach “manipulates the communications protocol between the (UAV) and its operator.” As opposed to using conventional jamming or kinetic effects “real-time protocol analysis down to the bit level (allows the user) to identify, disconnect and assume control of the (UAV), ultimately enabling safe landing or redirection without collateral damage”. The company added that Version 6.0 is already in service “and deployed across operational environments”. Sentrycs said that additional enhancements for its CUAV CORF software will be released in the near future.

Battle of the Bands

Kymeta’s new multi-band, multi-orbit antenna handles Ka-band and Ku-band traffic using four subarrays heralding savings in size, weight and power consumption for platforms and capabilities depending on satellite communications. Kymeta has announced it has developed a compact Satellite Communications (SATCOM) antenna that can simultaneously operate across Ku-band (14GHz uplink/10.9GHz to 12.75GHz downlink) and Ka-band (26.5GHz to 40GHz uplink/18GHz to 20GHz downlink) links. The company has claimed in a press release that this innovation is a world first. It continued that the new Kymeta KuKa Multi-Band/Multi-Orbit Antenna lets users interoperate across SATCOM networks with different wavebands and orbits. Benefits heralded by this innovation include “higher bandwidths, faster data rates and more bits per second”. The press release continued that the antenna’s realisation was possible by using so-called metamaterials. The document continued that the technology was successfully demonstrated and validated on 22nd April. The antenna combines four interleaved subarrays with Ku-band transmit/receive (Tx/Rx) and Ka-band Tx/Rx apertures. This approach, when combined with artificial intelligence-enabled algorithms, provides full duplex communications while alleviating spectrum contention.

Ryan Stevenson, Kymeta’s senior vice president and chief scientist, told Armada that the new antenna “provides significant advantages in size, weight, and power consumption over conventional phased array approaches, thereby bringing this level of connectivity to highly mobile, tactical edge platforms” such as uninhabited air and surface vehicles. Having two bands available in one antenna “not only optimises space efficiency, low power consumption and low cost, but also serves as a network hub and backhaul for downstream communication using mobile ad-hoc networking, mesh and cellular networks that will enable autonomous system operations at scale.” Mr. Stevenson added that “there is tremendous interest in the technology within the US Department of Defence and allied countries around the world.” Customer technology demonstrations are commencing imminently. (Source: Armada)

 

13 Aug 25. Europe: Russian actors will sustain security, cyber espionage risks to CNI, government entities. On 12 August, the software company BitDefender reported that a Russia-linked group (‘Curly COMrades’) has targeted government and critical national infrastructure (CNI) entities in a cyber espionage campaign since at least mid-2024. While the initial attack vector is unknown, the group deployed a new backdoor variant (‘MucorAgent’) onto compromised systems to maintain prolonged persistence and execute additional payloads. Curly COMrades uses a Windows component (‘NGEN’) hidden within MucorAgent to covertly activate the malware at random times to enhance detection evasion, highlighting the group’s sophistication. It then installs proxy tools and other payloads to monitor compromised systems and exfiltrate sensitive information while mimicking legitimate traffic to remain obfuscated. The operation has primarily targeted entities in Eastern Europe with a specific focus on Georgia and Moldova due to geopolitical hostilities. This underscores the strategic nature of Russia’s cyber strategy. Consequently, we assess that this development showcases sustained security and cyber espionage risks. (Source: Sibylline)

 

12 Aug 25. Global: Growing exploitation of legitimate tools underscores increased security risks to businesses. On 11 August, the security company Varonis reported that threat actors are increasingly exploiting legitimate tools to infiltrate targeted systems. In one incident, threat actors exploited the Microsoft file-sharing service OneDrive to send an email notification and trick victims into clicking on an embedded link. The link was created using the note-taking application OneNote and redirected victims to the organisation’s genuine OneDrive environment to enhance legitimacy. This highlights the pervasive adoption of legitimate Microsoft tools during campaigns, as well as actors’ stealth and detection evasion capabilities. Threat actors then displayed a fake login portal to coerce victims into disclosing their credentials and to subsequently spread the infection. The actors reportedly used artificial intelligence (AI)-powered website builders to create the phishing portals, also underscoring the continued incorporation of AI in cyber attacks. We assess this highlights the increased security risks to global businesses stemming from the continuous evolution of cyber tactics. (Source: Sibylline)

 

11 Aug 25. Havelsan Integrates National Artificial Intelligence Into ADVENT Combat Management System. HAVELSAN, a leading provider of advanced software-based solutions in the Turkish defense industry, is enhancing the capabilities of its Network-Enabled Data Integrated Combat Management System (ADVENT) with cutting-edge national artificial intelligence technology. This integration aims to meet the complex demands of modern naval operations and provide a decisive strategic advantage for the Turkish Naval Forces and allied navies worldwide. Developed in partnership with the Naval Research Center Command, ADVENT is recognized as one of the world’s leading combat management systems, designed to address the interoperability needs of joint and multinational task forces. Currently deployed in nine countries, including Türkiye, ADVENT enables advanced real-time decision-making, command, and control, positioning HAVELSAN as a trusted and effective player in global defense technology. As part of its AI innovation strategy, HAVELSAN has developed the Corporate Artificial Intelligence Platform (MAIN), an enterprise-grade solution built with a unique language architecture. MAIN can be trained on organization-specific data, operates securely in closed networks or via the internet, and offers role-based access control, data privacy, and user-friendly interfaces for efficiency in complex workflows.

MAIN is now being integrated into ADVENT as a Maintenance Support Assistant. This AI-driven capability assists operators by:

  • Determining and guiding maintenance steps
  • Locating and providing maintenance instructions
  • Offering system-wide question-and-answer support
  • Enhancing operational safety and verification through natural language interaction

Following the successful completion of Phase 1 testing in a laboratory environment, Phase 2 integration activities are underway across various systems. In addition to maintenance support, MAIN will also contribute directly to operational decision-making, offering recommendations and assisting commanders in real time.

AI-Driven Capabilities for Modern Naval Operations

Through the integration of MAIN with ADVENT, HAVELSAN is advancing AI-driven decision mechanisms to deliver:

  • Identification and classification of threats
  • Anomaly detection
  • Enhanced navigation safety
  • Improved situational awareness
  • Intelligent training and simulation support

These capabilities are powered by advanced technologies including big data analytics, machine learning, image recognition, and large language models (LLM). By leveraging AI, HAVELSAN aims to accelerate decision-making, improve accuracy, and optimize human–machine collaboration in the defense and security domain. (Source: ASD Network)

 

08 Aug 25. Cyber Update Key points.

  • Reports of stealthy infiltration techniques underscore long-term security risks from the North Korean state-sponsored group ‘Lazarus’ (see Sibylline Cyber Daily Analytical Update – 4 August 2025).
  • The expansion of a remote access trojan (RAT) known as ‘PlayPraetor’ highlights sustained security and financial risks to Spanish and French-speaking Android users (see Sibylline Cyber Daily Analytical Update – 5 August 2025 and our Technical analysis below).
  • Increased co-ordination between Iranian cyber threat actors will elevate long-term security risks to Israeli entities (see Sibylline Cyber Daily Analytical Update – 6 August 2025).
  • A new spyware variant (‘LunaSpy’) highlights increased surveillance and data-theft risks facing global Android users (see Sibylline Cyber Daily Analytical Update – 7 August 2025).
  • Reports of a cyber operation highlight ongoing security risks to Ukraine’s defence sector from the cyber threat group ‘UAC-0099’ (see Sibylline Cyber Daily Analytical Update – 8 August 2025 and our Technical analysis below).

Technical analysis of weekly stories

The threat group UAC-0099 is reportedly conducting a cyber operation against Ukraine’s defense sector. The group distributes phishing emails containing keywords such as ‘court summons’ in the subject line to trick victims into clicking on an embedded link. The link then redirects the victim to a legitimate file-hosting service that contains a double archive and a malicious .HTA file. The file runs an obfuscated VBScript to establish persistence and prepare compromised systems for the deployment of a malware loader (‘MATCHBOIL’) and subsequently two additional payloads (‘MATCHWOK’ and ‘DRAGSTARE’). MATCHWOK is a backdoor that enables UAC-0099 to execute encrypted PowerShell commands on compromised systems. It also contains several anti-analysis features and avoids and/or terminates its execution if security tools are detected, underscoring its stealth. DRAGSTARE is a information-stealer that collects archives, cookies and login credentials, highlighting the continuous development of the group’s toolset.

Unnamed threat actors are using a remote access trojan (RAT) known as PlayPraetor to target Spanish and French-speaking Android users. PlayPraetor is reportedly managed via a shared command-and-control (C2) infrastructure. This enables affiliates to conduct independent campaigns, highlighting the actors’ sophistication. PlayPraetor affiliates are divided into three categories based on their operations’ targets. The first category (principal affiliates) primarily target Arabic, English, French and Portuguese speakers. The second, (regional specialists) focus on Arabic, French and Spanish users. In contrast, the third group displays a far more diversified target pool. PlayPraetor was first detected in April and has already displayed five different versions, underscoring the rapid expansion and evolution of this operation. It comprises around 16,000 fake domains and impersonates at least 200 financial institutions, emphasising the operation’s scale. Threat actors use fake domains to trick users into downloading a malicious application that emulates a legitimate financial and/or cryptocurrency organisation. The RAT then exploits accessibility services to facilitate data exfiltration and real-time device control (as well as other monitoring activities), before likely using stolen information to hijack user accounts for financial profit. The malware establishes a persistent WebSocket connection to its C2 infrastructure to allow for real-time management and command execution. It also uses the Real-Time Messaging Protocol (RTMP) for live video streaming, further showcasing the actors’ advanced capabilities.

Non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware.
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.

Our cyber word(s) of the week: Real-Time Messaging Protocol (RTMP) (Source: Sibylline)

 

08 Aug 25. Formez vos Battalions! France’s President Emmanuel Macron has had his share of tribulations. Some of these have emanated from an arguably needless snap parliamentary election he called in June and July 2024. The results of this poll caused his party to lose its majority in the Assemblée Nationale (National Assembly), France’s lower house of parliament. As a result, the country has a minority government whose ability to pass legislation is at the mercy of opposition députés (members of parliament). Led by prime minister François Bayrou, the government has a sword of Damocles over its head: It can potentially be dissolved by a vote of no confidence in parliament. Such a move would trigger fresh parliamentary elections. As commander-in-chief of France’s military Mr. Macron exercises major influence over the country’s defence and foreign policy. The President took the opportunity of the annual Bastille Day celebrations on 14th July to support an increase in defence spending. He struck a hawkish tone mirroring the spirit of the insurgents who stormed the Bastille prison on that fateful day in 1789. This momentous event signalled the start of the French Revolution. Mr. Macron told members of the country’s armed forces in a speech the evening before commemorations that “(E)veryone must be present at their battle stations”. Reflecting on the threat faced by Europe from a belligerent Russia, the president added that “if you want to be feared, you must be powerful”. Words are being reinforced by actions. France’s annual defence budget was worth $37.6 bn in 2017 and increased to $50.5 bn for this financial year. The budget will grow further to $67 bn in 2030. Although France needs to reduce its national debt of $72bn, the good news is that Mr. Bayrou has said the defence budget will be “sacrosanct” from cuts. These spending increases, in line with similar increases ongoing in other European North Atlantic Treaty Organisation members, include money for Electronic Warfare (EW) capabilities. To be fair, France has made some significant EW investments in recent years. A new Signals Intelligence (SIGINT) gathering aircraft will soon equip the Armée de l’Air (French Air Force). All the country’s armed forces, and her intelligence services, are receiving a joint SIGINT processing capability. France’s EW funding commitment shows that the government values and supports the discipline. Like the military parades and fireworks that characterise Bastille Day, this is also something to celebrate. (Source: Armada)

 

07 Aug 25. Waveform Wizard. NATO has tested its GANDALF-4 sensor which can be deployed across a large area to ascertain sources of jamming, with the resulting signals intelligence helping to populate the tactical and/or operational recognised electromagnetic picture. NATO is moving forward with its GANDALF electromagnetic threat and direction-finding system which has reached prototype stage. The North Atlantic Treaty Organisation (NATO) commenced development of its Ground Based Asset for Direction and Location Finding (GANDALF) sensor in 2013. The initiative is being led by NATO’s Communications and Information Agency’s (NCIA’s) Joint Intelligence, Surveillance and Reconnaissance (JISR) centre, according to a statement provided to Armada by the NCIA. The JISR’s Electronic Warfare and Surveillance branch is directly responsible for GANDALF. The initiative began as an effort to develop a ground-based Global Navigation Satellite System (GNSS) Position, Navigation and Timing (PNT) signal jamming and spoofing detection capability, according to a NATO Joint Air Power Competence Centre article. The current version of the architecture is known as GANDALF-4 which NATO sources informed Armada is an electromagnetic threat and direction-finding system. The NCIA statement says that work began on GANDALF-4 two years ago. The initiative is being performed as part of an “effort aimed at expanding NCIA’s understanding of both operational and technical requirements through real-world deployments” the statement continued. GANDALF-4 has not been identified as a programme of record, the NCIA document underscored. Nonetheless, the architecture could “eventually be industrialised and become a NATO Common Funded Capability”. This would mean that the asset may be owned by the alliance, or by one or more alliance members, but made available to NATO as and when required. The initiative is funded by NATO’s membership.

TRL-6 and TRL-7

According to the NCIA, GANDALF-4 has been tested in a live environment with representative real-world threats. As matters stand at present, the architecture has been developed to Technology Readiness Level Six (TRL-6). United States Department of Defence TRL-6 stipulates that a prototype system has been verified and demonstrated in an operational environment. NCIA says that plans are afoot to move the GANDALF-4 technology to TRL-7. Should this occur, it will mean that an integrated pilot system has been demonstrated in an operational environment. One concept of operations envisaged for GANDALF-4 is for a network of monitoring stations to be deployed over a specific area. These stations could feed signals intelligence data into command and control and/or battle management systems to enrich the local recognised electromagnetic picture. Mounting the GANDALF-4 architecture on a vehicle could improve the sensor’s mobility still further. NCIA continues that learning outcomes from the GANDALF-4’s development and capabilities will be valuable. These could be fed into future NATO Standardisation Agreements/Standard Recommendations regarding navigation warfare. Alliance members continue to experience significant GNSS PNT disruption in the Baltic and Black Sea regions. The eastern Mediterranean is also experiencing the scourge, as are parts of the Persian Gulf. The latter regions are out of NATO’s traditional area of concern. Nonetheless they could affect NATO militaries operating in these areas. Having a capability that can pinpoint the location of PNT signal jamming and spoofing will be useful for the alliance from tactical and operational standpoints: In peacetime, areas where PNT jamming could cause disruption could be avoided. In wartime, determining sources of GNSS PNT disruption could help provide target aimpoints which can then be engaged with kinetic effects. That NATO is developing such a capability may have important deterrent effects: Actors maybe dissuaded from deploying GNSS jammers given that GANDALF will aid the avoidance or destruction of such capabilities. (Source: Armada)

 

06 Aug 25. Damned if You Do, Damned if You Don’t. MBDA’s One-Way Effector was designed as a response to the French government’s Drone Pact initiative which aims to deepen Europe’s uninhabited aerial vehicle industrial base. This year’s Paris Air Show, held in the city between 16th and 22nd June, saw MBDA unveil its One-Way Effector anti-radar weapon. According to the company, the One-Way Effector (OWE) is a ground-launched Uninhabited Aerial Vehicle (UAV) designed to overwhelm Ground-Based Air Defences (GBAD) and Integrated Air Defence Systems (IADS). MBDA’s literature says the OWE’s concept of operations is for it to be launched in salvos. Equipped with a 40 kilogram (88 pound) kinetic warhead, the effector can saturate and target red force IADS and GBAD. This tactic is intended to fully occupy hostile air defences while conventional aircraft, air- and surface-launched weapons, and other UAVs head towards their targets in contested airspace. The effector could prove to be a powerful capability for the Suppression of Enemy Air Defences (SEAD). Hence the OWE could play an important part in the Offensive Counter-Air (OCA) mission.

One Way System

The OWE’s saturation tactic is akin to that used by the Israeli Air Force (IAF) to overwhelm Syria’s GBAD and IADS during IAF operations above the Bekaa Valley, eastern Lebanon. Operation Mole Cricket 19 was launched by the Israeli Air Force on 9th June 1982. Massed UAV flights into the lethal engagement envelopes of Syrian GBAD were used to simulate incoming strike packages of Israeli combat aircraft. Syrian air defenders took the bait. By firing Surface-to-Air Missiles (SAMs) at these UAVs the Syrians revealed the positions of their SAM batteries. With the SAM batteries’ launchers now exhausted of missiles, and needing reloads, the IAF attacked in relative safety inflicting a mortal blow on Syria’s deployed GBAD.

Open sources note that the OWE is equipped with a jet engine, can achieve a range of 270 nautical miles (500 kilometres) and has a top speed of 216 knots (400 kilometre-per-hour). Reports have stated that MBDA plans to achieve a monthly production rate of 1,000 weapons. The company has partnered with an unnamed automotive manufacturer, believed to be Renault, to develop and produce the UAV. Weapons guidance is provided by an integral global navigation satellite system position, navigation and timing signal receiver. The flight planning process is relatively simple: Waypoints and rallying zones are programmed and indicated to the One-Way Effectors to create swarm effects and ensure that salvoes arrive precisely on time and on target.

According to a statement provided to Armada by MBDA, the OWE is designed to place an adversary in a tactical dilemma. The weapon “exhausts enemy resources. It exerts constant pressure on the adversary’s air defences, thanks to its warhead, which is sufficiently large to require its destruction by the enemy defences.” Engaging the effector “forces even the most sophisticated air defences to leave themselves exposed, making them easier to detect and neutralise, in coordination with other long-range strike systems.” In essence, choose not to engage the weapon, and GBAD/IADS capabilities risk being destroyed. Choose to engage the weapon, and GBAD/IADS targets can be determined and engaged.

The Drone Pact

MBDA told Armada that the company developed the One-Way Effector as a response to the 2024 Drone Pact launched by France’s Direction Générale de l’Armement (General Armament Directorate). The DGA is France’s defence procurement agency. Reports state that the Drone Pact was established to improve the research, development and production of UAVs in France for the French and European militaries. The weapon itself is a “compromise solution between the need for mass and performance and the principle of least cost, meeting the challenges of the war economy.”

The maiden flight of the One-Way Effector is expected in the third quarter of 2025, the company continued, adding that this will be less than one year since the programme commenced. MBDA self-funded development and expects to have a production lead time of circa 18 months for the first batch of weapons. (Source: Armada)

 

07 Aug 25. August Spectrum SitRep. The US Navy is expected to formally contract Leonardo to deliver its BriteCloud expendable RF decoys by November 2026, following a procurement notice issued in April. Deliveries will commence in 2027 and should conclude in 2031. Armada’s monthly round-up of all the latest electronic warfare news in the product, programme and operational domains.

Brite Idea

The United States Navy is close to ordering examples of Leonardo’s BriteCloud expendable Radio Frequency (RF) decoys. Official US government documents seen by Armada say the US Navy’s Naval Air Systems Command issued a procurement notice on 28th April for “Active Expendable Decoy Procurement and Support”. The notice announced that the decoys will furnish the navy’s Lockheed Martin F-35C Lightning-II and McDonnell Douglas/Boeing F-18 Hornet/Super Hornet series combat aircraft. Other unnamed types may also receive the decoy, the notice continued. An initial 6,000 decoys could be procured by the navy for the first two years of the contract, followed by a further 6,000. Deliveries are expected to commence in 2027 and conclude in 2031, the notice continued. The contract is expected to be awarded in November 2026. In US service, the BriteCloud decoy is designated as the AN/ALQ-260(V)1. Open sources say the AN/ALQ-260(V)1 equips US Air National Guard General Dynamics/Lockheed Martin F-16 series combat aircraft. Other platforms deploying the decoy include General Atomics MQ-9 Reaper series uninhabited combat aerial vehicles flown by US forces. BriteCloud is thought to cover X-band (8.5 gigahertz/GHz to 10.68GHz) to K-band (24.05GHz to 24.25GHz) frequencies. This waveband enables the decoy to jam and spoof fire control/ground control interception radars and air-to-air/surface-to-air missile active radar homing seekers. Both these radar types commonly use such frequencies.

Terma to Refurbish Argentine Vipers

On 2nd July, Terma announced that the company had signed a support agreement with Argentina’s Ministry of Defence regarding the General Dynamics/Lockheed Martin F-16 series combat aircraft the latter is buying. The Fuerza Aérea Argentina (FAA/Argentine Air Force) is acquiring 24 of the jets from Flyvevåbnet (Royal Danish Air Force) stocks. The aircraft are a mixture of F-16A/B models. Reports note that deliveries of the aircraft are due to commence in December 2025. Terma’s press release said the company “has been selected to provide key upgrades and support services related to the aircraft’s Electronic Warfare (EW) systems.” The jets are being refurbished by Lockheed Martin prior to their delivery to the FAA. The press release continued that Terma will provide “software and hardware enhancements, mission planning tools, ground support equipment and engineering assistance”. The company would not be drawn on precisely what electronic warfare capabilities it would be supplying to the FAA F-16s. Nonetheless, it did share in a statement that Terma “is a long-standing supplier of EW systems for F-16” aircraft. These products include the company’s AN/ALQ-213 EW management system, Advanced Countermeasures Dispenser System and Pylon Integrated Dispenser System. (Source: Armada)

————————————————————————————————————————————————————————————————————————————————————————————————————————————–

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

——————————————————————————————————————————————————————————————————————————————————————————————————————————–

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

August 8, 2025 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

——————————————————————————————————————————————————————————————————————————————————————————————————————————————–

06 Aug 25. RTX to Optimize Cyber Vulnerability Detection for DARPA. RTX BBN Technologies to advance high-fidelity exploit chain testing and evaluation. RTX’s (NYSE: RTX) BBN Technologies was awarded a contract from DARPA to support its Intelligent Generation of Tools for Security, or INGOTS, program. INGOTS aims to strengthen cybersecurity by developing advanced methods to identify and mitigate complex exploit chains, preventing their use in real-world attacks. Exploit chains pose a growing threat, amplified by the increasing complexity and sophistication of cyberattacks. The U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog has surpassed 1,300 entries, with steady growth reflecting the increasing number of threats targeting essential services and networks. Despite this rising threat, current assessment methods rely heavily on manual analysis, requiring significant expertise and time. INGOTS seeks to address this challenge by automating the creation, modification, modeling and analysis of exploit chains to enable faster and more effective security interventions.

“Effectively countering exploit chains requires more than just identifying individual vulnerabilities. It demands a system that can replicate real-world attack scenarios and anticipate potential risks before they are exploited,” said Jack Dietz, BBN principal investigator.

To support this effort, BBN will apply its expertise in testbed architecture to develop the System Test of Android at Large-scale Accelerating Generation and Modeling for INGOTS Test and Evaluation, or STALAGMITE. This system will serve as a comprehensive platform for testing and evaluating exploit analysis tools, offering key capabilities such as:

  • Accurate real-world simulations: High-fidelity testing in combined virtual and physical environments ensures realistic assessments of Android vulnerabilities in a secure and controlled setting.
  • Proactive threat responses: Seamless integration of INGOTS components enables security teams to anticipate and mitigate potential attacks, enhancing preparedness against emerging threats.
  • Efficient security research: A robust environment for reproducible, automated testing advances research in software vulnerabilities and countermeasures, improving operating system and application security.

“Today’s manual methods for assessing exploitability are costly, time-consuming and lack scalability and efficiency,” said Dietz. “We aim to alleviate this burden from security professionals by accelerating the automatic identification of security risks across various devices and configurations using precise testing and measurement to strengthen overall cybersecurity defenses.”

While the program focuses on the Android ecosystem, the methodologies and technologies developed under INGOTS are expected to have far-reaching applications across personal, business, government and military sectors.

The BBN-led team includes Assured Information Security. Work on the program will be completed in Cambridge, Massachusetts; Columbia, Maryland; and Rome, New York. (Source: ASD Network)

 

06 Aug 25. HawkEye 360 RF Data Powers Military Platforms in Talisman Sabre Exercise Integration. HawkEye 360 Inc., the global leader in signals intelligence data and analytics, announced its participation in Exercise Talisman Sabre 2025 (TS25), a large-scale, multinational military exercise designed to strengthen interoperability between the United States, Australia, other allies, and partner nations. As part of the exercise, HawkEye 360’s radio frequency (RF) data is being integrated into operational military platforms for the first time, delivering critical insights to enhance situational awareness and decision-making across multiple domains. HawkEye 360 is integrating its signals intelligence capabilities with Lockheed Martin’s advanced defense systems. This machine-to-machine integration enables operators to seamlessly ingest and correlate RF data with other tactical data sources, transforming it into actionable surveillance tracks that support threat detection and more precise geolocation, resulting in higher-quality tracking.

“This partnership represents a major milestone in expanding our tactical relevance within the Department of Defense,” said Todd Probert, President of US Government at HawkEye 360. “By integrating HawkEye 360’s RF data into tactical defense systems, we’re accelerating decision advantage across the battlespace. This is a clear example of how we’re providing our data to DoD, by delivering timely, trusted insights that enhance threat tracking and operational awareness across domains and command echelons.”

Exercise Talisman Sabre is the largest military exercise conducted in Australia, held every two years to enhance readiness and interoperability among Australia, the United States, and participating allies. TS25 marks the 11th and largest iteration of the exercise, involving live-fire drills, amphibious landings, ground maneuvers, air combat, and maritime operations. With 19 nations invited to participate, TS25 provides a complex and realistic environment for testing joint and combined force operations across air, land, maritime, space, and cyberspace domains.

“By combining Lockheed Martin and Hawkeye 360 expertise, we’ve delivered a first-of-its-kind capability showcasing the unparalleled value of collaboration. Easy integration was the key to integrating commercial radio frequency into a combat system and enhancing situational awareness for our customers.”

HawkEye 360’s data integration into this dynamic operational environment enables defense partners to maintain consistent situational awareness over vast areas, offering a new layer of insight into RF activity across critical regions. This capability underscores the growing significance of commercial data solutions in supporting national security missions and coalition operations. (Source: ASD Network)

 

06 Aug 25. LM Achieves Key Milestone in RIG-360 Development, Advances 360-Degree Missile Communications. The Remote Interceptor Guidance – 360 (RIG-360) completed the first phase of the Engineering, Manufacturing and Development (EMD) program. This is a critical milestone as the Lockheed Martin (NYSE: LMT) and PEO Missiles and Space, Integrated Fires and Mission Command (IFMC) team work together to deliver the first RIG-360 units to the field.

“RIG-360 is a game-changing capability,” said Stu Chaffey, director of Integrated Air and Missile Defense Advanced Programs at Lockheed Martin Missiles and Fire Control. “RIG-360’s capabilities will allow soldiers to use the best weapon available on the Integrated Battle Command System (ICBS) Integrated Fire Control Network (IFCN) to eliminate incoming threats.”

  • The RIG-360 team completed the first Array Assembly officially moving the RIG-360 EMD program into the second phase.
  • The Array Assembly is one of three critical subsystems in the EMD program.
  • The Array Assembly is the most complex subsystem and acts as the communications hub for the RIG-360 that can send, receive and translate radio frequency data for beacon tracking.

RIG-360 is a missile communications device that enables 360-degree, in-flight communications for the Patriot Advanced Capability – 3 (PAC-3) Family of Missiles within the IBCS. RIG-360 will support PAC-3 engagements and advances IAMD goals of pairing any sensor with the best available weapon system within the U.S. Army’s modern IAMD architecture.  IFMC awarded the RIG-360 program a $114M definitized contract on May 9, 2025, another big milestone for the new program. This award reinforces IFMC’s commitment and support of the program. Lockheed Martin is currently building a dedicated RIG-360 EMD production facility in Grand Prairie, Texas. This facility features state-of-the-art advanced manufacturing tools and centralizes personnel, process and equipment to drive speed, efficiency and innovation. The facility is expected to be completed in late 2026.  (Source: ASD Network)

 

04 Aug 25. Global: Stealthy techniques underscore long-term security risks from North Korean groups. Earlier on 4 August, international news outlets reported that the North Korean state-sponsored group ‘Lazarus’ has increased its use of malicious open source software to infiltrate targeted organisations since at least January. The group reportedly creates fake open-source software that impersonates legitimate development libraries as the initial attack vector. The malicious software contains a malware dropper that subsequently establishes communication with command-and-control (C2) infrastructure and deploys a highly obfuscated loader. This then executes several payloads to steal browser and cryptocurrency wallet data and credentials, as well as other sensitive information, highlighting a potential shift in the group’s strategy to prioritise information theft over crypto-mining. The group also performs checks to identify any active security protections to prolong detection evasion, underscoring the operation’s capacity for stealth. Lazarus routinely conducts cyber operations to bolster Pyongyang’s weapons and missile programmes and security posture, underscoring the long-term security and data-theft risks to global businesses. (Source: Sibylline)

 

01 Aug 25. Cyber Update Key points.

  • A large-scale, highly sophisticated cyber operation will elevate security risks facing virtual machines (VMs) from the ransomware group ‘Scattered Spider’ (see Sibylline Cyber Daily Analytical Update – 28 July 2025 and our Technical analysis below).
  • A large-scale cyber attack indicates heightened security risks to Russian businesses from pro-Ukraine and anti-Belarus hacktivist groups (‘Silent Crow’ and ‘Cyber-Partisans’, see Sibylline Cyber Daily Analytical Update – 29 July 2025).
  • A cyber attack against the French telecommunications provider Orange highlights long-term security risks facing key infrastructure sectors (see Sibylline Cyber Daily Analytical Update – 30 July 2025).
  • The continuous evolution of cyber tactics will increase financial, operational and reputational risks to global businesses (see Sibylline Cyber Daily Analytical Update – 31 July 2025).
  • A newly-reported espionage cyber operation underscores sustained security and cyber espionage risks to Moscow-based foreign entities from the Russia-linked group ‘Secret Blizzard’ (see Sibylline Cyber Daily Analytical Update – 1 August 2025 and our Technical analysis below).

Technical analysis of weekly stories

The ransomware group Scattered Spider is targeting virtual machines (VMs) to conduct a highly sophisticated and large-scale, financially motivated operation. The group reportedly uses phishing phone calls (vishing) to impersonate employees and call the targeted company’s help desk. During the phone call, the group tricks victims into resetting the employee’s active directory (AD) password before beginning a two-pronged reconnaissance process to escalate privileges. This entails scanning SharePoint sites, network drives, password managers and/or other Privileged Access Management (PAM) solutions to identify potential high-value targets. Scattered Spider then uses gathered information to make a second phone call to persuade the help desk to reset the password for a chosen administrator. This enables the group to hijack the VMware vCenter Server Appliance (vCSA) to manage all virtual environments and maintain persistence via an open-source remote access tool (‘teleport’). Scattered Spider then identifies a virtual machine acting as a Domain Controller to steal authentication and authorisation data. The stolen data is then exfiltrated through a two-part process to the actors’ command-and-control (C2) infrastructure, likely to be used at a later stage for extortion. The group subsequently deploys a ransomware payload to encrypt all stored files while wiping all backup files to hinder recovery processes and increase pressure. The entire operation occurs within a company’s virtual infrastructure, which typically falls outside the protection scope of most security services, highlighting the group’s capacity for detection evasion.

The Russia-linked advanced persistent threat (APT) group Secret Blizzard has targeted foreign embassies in Moscow in a cyber espionage operation since at least 2024. The group reportedly intercepts local internet service providers (ISPs) via an Adversary-in-the-Middle (AiTM) attack to infiltrate targeted systems, before displaying a fake portal (mimicking a legitimate Microsoft connectivity check) to covertly execute custom malware (‘ApolloShadow’) onto compromised systems. ApolloShadow then checks the system’s privileges, tricking users with elevated privileges into granting Secret Blizzard full control over their devices via a fake certificate installer emulating the cyber security service provider Kaspersky. If the system’s privileges are low, ApolloShadow immediately communicates with C2 infrastructure and establishes long-term persistence for data exfiltration, payload execution and traffic monitoring. The malware changes behaviour depending on how the target devices’ system privileges are configured, highlighting the operation’s sophistication. Upon installing the aforementioned certificate, ApolloShadow also sets the network to private to weaken firewall protections, showcasing the group’s detection evasion capabilities.

Non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware.
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.

Our cyber word(s) of the week: Active Directory (AD) (Source: Sibylline)

 

31 Jul 25. Northrop Grumman fulfils US Army IBCS MEIs delivery. The company has delivered 142 major end items under the contract. An Engagement Operations Center (EOC) at Northrop Grumman’s EPIC manufacturing facility in Madison, Alabama. Credit: Northrop Grumman.  Northrop Grumman has completed delivery of all major end items (MEIs) for the US Army’s Integrated Battle Command System (IBCS) under the low-rate initial production (LRIP) contract.  The delivery of these MEIs signifies Northrop Grumman’s ability to produce and deliver defence systems at scale, allowing the US Army to expedite the fielding of IBCS. It comes after the company delivered first full set of IBCS MEIs last year. The company delivered 142 MEIs under LRIP phase, which include 35 engagement operations centres (EOC), 32 integrated fire control network (IFCN) relays, and 75 integrated collaborative environments (ICE) from its facility in Huntsville, Alabama. Northrop Grumman global command and control solutions vice president Jeremy Knupp said: “Northrop Grumman’s delivery of IBCS MEIs to the US Army underscores our commitment to deliver cutting-edge technology.

“We have the manufacturing depth and capacity to deliver IBCS at speed, ensuring our armed forces are equipped to meet the challenges of modern warfare with enhanced situational awareness, decision-making precision and operational adaptability.”

Northrop Grumman is set to commence manufacturing IBCS under a full-rate production contract at its Enhanced Production and Integration Center (EPIC) in Madison, Alabama. The EPIC is designed to further Northrop Grumman’s ability to scale up and accelerate production while expanding capacity for high-rate manufacturing programmes. IBCS integrates sensors and effectors into a unified command and control system, offering warfighters a comprehensive view of the battlefield. Its network-enabled, modular, open, and scalable architecture merges sensor data into a cohesive and actionable battlespace picture. This capability provides warfighters with additional time to assess and respond to threats and serves as a critical element for enabling joint and coalition multi-domain operations. Currently in production, IBCS will be deployed as part of the US Army’s programme of record for integrated air and missile defence modernisation. In December 2021, Northrop Grumman receive five-year contract valued at over $1bn from the US Army for both low-rate initial production and full-rate production of IBCS. The US Army’s IBCS, developed by Northrop Grumman, successfully integrated with the service’s new Indirect Fire Protection Capability (IFPC) system in December 2024. (Source: army-technology.com)

—————————————————————————————————————————————————————————————————————————————————————————————————————————————-

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

———————————————————————————————————————————————————————————————————————————————————————————————————————————

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

August 1, 2025 by

Sponsored By Curtiss Wright

 

https://www.curtisswright.com/

 

————————————————————————————————————————————————————————————————————————————————————————————————————————————–

31 Jul 25. IFS, the leading provider of enterprise cloud and Industrial AI software, has announced a strategic partnership with carbon intelligence platform Climatiq. The Climatiq data engine has been integrated into a new Emissions Management module within IFS Cloud and is a key part of the broader IFS strategy to embed sustainability directly into business operations, enabling customers to make informed, carbon-aware decisions based on their own data. The partnership is further underscored by the release of a joint white paper: “IFS Cloud: Carbon Emissions Scope 3 Overview and Statement of Direction.” The collaboration between IFS and Climatiq brings together industrial AI and expert carbon intelligence to transform how companies manage sustainability, at a time when it’s never been more important. The partnership allows asset intensive industries to actively manage their carbon footprint, and how to reduce it all while maintaining strong operating and efficiency standards. IFS Cloud now integrates Climatiq’s carbon calculation engine and extensive database of scientifically-vetted emission factors, enabling automatic carbon calculations from within core business systems. Emission Management leverages the existing asset hierarchy in IFS Cloud to quickly and accurately build your emissions sources while ensuring consistency and fast setup. The newly launched Emissions Management module empowers organisations to automate emissions calculations and embed sustainability into daily operations. With prebuilt templates, standard methodologies, and available directing in IFS Cloud, the application helps businesses achieve accurate carbon insights at scale. To support this initiative, IFS and Climatiq have co-authored a new white paper. The paper outlines how the IFS embedded sustainability capabilities can transform business activity data into actionable emissions insights. In turn, companies can streamline their reporting processes to meet global standards such as the Corporate Sustainability Reporting directive (CSRD) and allow for smarter, greener decision-making.

“Sustainability regulations are under constant change and review, and our customers are under increasing pressure to meet these evolving obligations while continuing to adapt,” said Caitlin Keam, VP of Sustainability Applications at IFS. “By integrating Climatiq’s verified emissions factor database into Emissions Management in IFS Cloud, we enable organisations to embed sustainability into day-to-day operations, allowing them to adapt quickly, gain clear insights, and make better decisions directly within their core system.”

“This partnership brings together IFS’s deep industry expertise and Climatiq’s carbon intelligence to put climate impact at the heart of business decision-making,” said Hessam Lavi, CEO and co-founder at Climatiq.“By embedding emissions data directly into enterprise workflows and releasing a joint white paper that outlines the path forward for scope 3 reporting, we are helping customers power the green transition through practical, data-driven solutions and collaborative research.”

IFS’s commitment to sustainability has been further strengthened by its recent investment from Generation Investment Management, the pioneering sustainable investment firm. This backing serves as a powerful endorsement of IFS’s long-term commitment to sustainability. The collaboration with Climatiq exemplifies how IFS is actively driving innovation toward a greener future, aligning its strategy with the values of one of the world’s most respected sustainability-focused investors.

 

31 Jul 25. Silvus Technologies Partners with Commdex to Expand Access to StreamCaster MANET Radios for State, Local and Federal Agencies. Silvus Technologies, Inc., a leader in advanced wireless communications systems, has announced a strategic partnership with Commdex, a premier systems integrator for mission-critical communications. The collaboration will expand nationwide access to Silvus’ StreamCaster Mobile Ad Hoc Network (MANET) radios to state, local, and federal agencies. Effective immediately, this partnership integrates Silvus’ industry-leading tactical mesh networking technology into Commdex’s solutions portfolio – addressing the rising demand for mobile, resilient, and decentralized communications. From natural disasters to high-risk tactical operations, StreamCaster MANET radios enable critical connectivity when every second counts.

“We’re proud to partner with Commdex to deliver the performance and reliability of StreamCaster MANET radios to public safety, first responders and disaster response organizations across the country,” said Jimi Henderson, Vice President of Sales at Silvus Technologies. “Commdex’s deep expertise in designing and deploying advanced, communications networks make them an ideal partner to support government agencies in implementing secure, reliable mesh networks that perform when it matters most.”

The Silvus family of StreamCaster MANET radios are engineered to operate independently of traditional communications infrastructure, deliver high-fidelity video, voice and data communications with class-leading output power, range, and mobility. At the heart of every StreamCaster MANET radio is Silvus’ leading-edge MN-MIMO waveform technology that creates a self-healing, self-forming, and adaptive mesh network – capable of linking hundreds of nodes with unmatched data rate throughput, EW resiliency, and scalability. This architecture enables the creation of a Tactical Bubble – a mission-ready ecosystem that connects personnel, vehicles, unmanned systems, and command elements into a unified, resilient communications network.

“Commdex and Silvus share a common mission – delivering networking solutions that provide the vital communications link to those responsible for the safety and security of our communities.” said Prince Niyyar, CEO of Commdex. “Recent natural disasters have exposed critical gaps in emergency communications when traditional infrastructure fails. Through this partnership, we’re providing our clients with a critical capability – resilient, high performance mesh networks that perform in the most challenging environments, and when every second could mean the difference between life and death.”

In addition to Silvus StreamCaster MANET radios, Commdex clients will now have access to the recently launched Spectrum Dominance 2.0. Available as a software licensable extension of Silvus’ proprietary MN-MIMO waveform, Spectrum Dominance 2.0 is an ever-expanding suite of Low Probability of Intercept/Detection (LPI/LPD), Anti-Jamming, and Advanced Threat Protection capabilities that provide secure and protected electronic warfare (EW) resilient communications in contested environments, without sacrificing performance. Commdex will begin immediate deployment of StreamCaster systems, backed by hands-on training and technical support through their nationwide service network. Agencies looking to enhance their tactical communications capabilities with Silvus’ StreamCaster MANET radios can contact Commdex for more information.

About Silvus Technologies, Inc.

As the world’s leading provider of advanced MANET and MIMO communications systems, Silvus Technologies is reshaping mesh network technology for mission-critical applications – on the ground, in the air, and at sea. Its battle proven StreamCaster family of MANET radios and proprietary MN-MIMO waveform provides the vital communications link for defense, law enforcement, and public safety agencies around the world, and in the toughest operational environments. Developed by a team of top PhD scientists and design engineers, Silvus Technologies continues to innovate communications technology for the tactical edge with unmatched range, data throughput, EW resiliency, and scalability. Silvus Technologies is privately held with world headquarters located in Los Angeles, CA.

About Commdex

Commdex provides network solutions to telecommunications service providers and manufacturers for the deployment of telecom networks, facilities, and supporting systems. Commdex specializes in designing and implementing mission-critical voice and data networks over 4G/5G, Wi-Fi, microwave, land mobile radio, DAS, SATCOM, and other technologies. Commdex offers a broad, rich portfolio of proven telecom solutions. Its solutions, services, and methodologies have been tested and proven in hundreds of customer environments. Its customer base ranges from state, local, and federal customers to large enterprises and equipment manufacturers. (Source: UAS VISION)

 

30 Jul 25. Global: Evolving cyber tactics will increase financial, operational, reputational risks to businesses. On 30 July, the security company Akamai reported that cyber threat actors are continuously adapting cyber tactics to boost success rates and amplify the impact of their attacks. Ransomware-as-a-Service (RaaS) groups are reportedly using quadruple extortion techniques to increase pressure on victims to pay ransom demands. The technique involves conducting distributed denial-of-service (DDoS) attacks to maximise operational disruption, as well as harassing customers and business partners to increase the risk of reputational damage. Cyber criminals are also increasingly adopting generative artificial intelligence (AI) to compensate for skill deficiencies, improve social engineering techniques and write malicious code. Hacktivist groups are employing RaaS platforms to amplify the impact of politically motivated attacks; this highlights the continuous overlap and co-operation among cyber threat groups, likely further complicating attribution and mitigation efforts. As a result, we assess that this showcases intensifying financial, operational, reputational and security risks facing global businesses amid the continuous development of the cyber threat landscape. (Source: Sibylline)

 

30 Jul 25. US Army seeks commercial solutions for airborne EW family of systems. The US Army’s prime intelligence and electronic warfare (EW) directorate is shifting strategies on development of the Multi-Function Electronic Warfare (MFEW) family of systems (FoS), focusing on commercially developed platforms and subsystems to support programme requirements for drone-mounted EW payloads, service officials announced in July. The decision to primarily pursue commercial off-the-shelf (COTS) and government off-the-shelf (GOTS) solutions for the service’s MFEW – Air Large (MFEW-AL) variant was driven by a need to close “gaps in extended-range, persistent ground, and airborne EW assets”, programme officials from the army’s Program Executive Office Intelligence, Electronic Warfare and Sensors (PEO IEW&S) said in a June statement. As a result of the COTS and GOTS acquisition focus, service leaders will “utilize an incremental approach for delivery of capability that will evolve over time toward[s] the full Army’s Airborne Electromagnetic Attack requirements”, with regard to the MFEW-AL, the statement said. To this end, successful integration of commercial platform solutions to the MFEW-AL programme “will be key in meeting recent [Pentagon] direction … [to] achieve electromagnetic dominance by 2027”, programme officials added in the June statement. As designed, the MFEW-AL will provide “electronic attack and electronic warfare support capability” via an EW pod mounted aboard the ground service’s MQ-1C Gray Eagle unmanned aircraft system (UAS), according to a US Department of Defense (DoD) fact sheet. (Source: Janes)

 

28 Jul 25. Consortium GSS+ (Hensoldt and Steep) Hands Over GSCS Mission Support System to the German Armed Forces. The deployable Ground Support Container System for the Eurofighter weapon system (GSCS WaSys EF) enables the Air Force to read and evaluate mission, maintenance and repair data on site during operations or deployments as part of exercises, exactly as the Air Force is accustomed to doing in the domestic infrastructure of its squadrons. The GSS+ consortium, consisting of sensor specialist/solution provider HENSOLDT and steep GmbH, has been developing and implementing further diverse equipment on behalf of the Federal Office for Equipment, Information Technology and In-Service Support of the German Armed Forces (BAAINBw) as part of the extensive ‘GSCS WaSys EF 2.Los’ project since 2022. As a specialist in IT-related complete solutions, HENSOLDT’s ‘IT and Communication System Integration’ division was centrally responsible for the functional components of the system within the overall project. Other departments, including Logistics/Documentation and Information and Cyber Security, also made significant contributions to the overall success.  The GSCS has state-of-the-art networks for multiple security domains and IP-based communication solutions for ground and air radio as well as external communication, in compliance with all demanding military information security requirements. The system was handed over to the customer at the Fürstenfeldbruck site as part of a functional acceptance test. The participation of users up to Air Force command level underscores the special significance of the system for the Air Force. The operational support system will now be fully taken over and accredited by the Air Force in the near future in order to achieve full operational readiness and be deployed for the first time in 2025. (Source: ASD Network)

 

28 Jul 25. UK-US: Sophisticated attack techniques will sustain elevated security risks from ransomware groups. On 27 June, international news outlets reported that the ransomware group ‘Scattered Spider’ is targeting virtual machines to conduct a highly sophisticated and large-scale operation. The group reportedly uses phishing phone calls (impersonating a company’s IT help desk) to obtain user credentials for the employee Active Directory (AD) and infiltrate targeted systems for financial gain. This enables Scattered Spider to access a company’s VMware vCenter Server Appliance (vCSA) to manage all virtual environments and exfiltrate sensitive data for extortion, highlighting the group’s high sophistication. The group subsequently deploys the main ransomware payload to encrypt all stored files while wiping all backup files to hinder recovery and increase pressure. The rate of Scattered Spider attacks against UK and US-based businesses (including the insurance, transportation and retail sectors) has markedly increased since April. We assess that this report indicates elevated security, financial and operational risks facing global businesses amid the increased exploitation of virtualised environments. (Source: Sibylline)

 

25 Jul 25. Cyber Update Key points

  • A cyber operation conducted by the Chinese state-sponsored group ‘APT41’ will increase security risks for government services across Africa  Technical analysis below.
  • A new version of the ‘DCHSpy’ Android spyware will sustain surveillance and security risks for English and Farsi speakers globally  Technical analysis below.
  • The exploitation of two zero-day software vulnerabilities by Chinese state-sponsored threat actors has elevated the security risks facing global businesses.
  • The resumption of operations using the ‘Lumma Stealer’ malware points to ongoing security and data-theft risks facing users.
  • Threat actors are deploying ransomware on compromised systems, abusing recently disclosed zero-day vulnerabilities; this underscores the heightened exploitation risks facing global entities.

Technical analysis of weekly stories

The Chinese state-sponsored group APT41 has targeted government services across Africa, likely as part of a cyber operation to obtain strategic information and financial data. Historically, Africa had experienced the least amount of activity stemming from APT41, indicating a possible shift in targeting by the group. APT41 likely compromised a user account on an unprotected device to infiltrate targeted systems; however, the initial attack vector is currently unclear. After obtaining access to the system, APT41 scanned the infected machine to glean if there were any security solutions installed on the device before harvesting credentials from registry files to use in subsequent attacks. APT41 leveraged two compromised domain accounts with administrator privileges to deploy ‘Cobalt Strike’ so as to communicate with the command-and-control (C2) server. APT41 was observed using both open-source and custom tools; the threat actors updated their toolset during the campaign so as to adapt to their victim’s infrastructure and thereby ensure prolonged infections. This highlights both the group’s capabilities and the prolonged security threats it poses to organisations in Africa.

An Android spyware tool is targeting English and Farsi speakers globally in a campaign conducted by ‘Muddy Water’, a group suspected of having ties to the Iranian Ministry of Intelligence and Security (MOIS). The campaign disguises itself as fake virtual private network (VPN), banking and Starlink applications to trick users into downloading the malicious applications via Telegram. The most recent iteration of this spyware (DCHSpy) appears to have emerged shortly after the Iran-Israel war in June, highlighting the speed with which the tool was deployed amid the geopolitical developments. DCHSpy collects WhatsApp data, contact information, SMS messages, files, locations and call logs; it can also record audio and take photos. Once data is illicitly obtained, it is compressed and encrypted before being sent to threat actor-controlled infrastructure via the C2 server. DCHSpy shares infrastructure with another Android malware (‘SandStrike’), which is also attributed to Muddy Water, underscoring the group’s focus on surveillance operations amid escalating regional tensions.

Non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering

Our cyber word(s) of the week: On-premises (Source: Sibylline)

 

25 Jul 25. Global: Continued abuse of software vulnerabilities points to increased security, operational risks. On 23 July, the technology company Microsoft disclosed that China-based cyber criminal actor ‘Storm-2603’ has been exploiting previously discovered SharePoint software vulnerabilities  to deploy ransomware on targeted systems. The campaign abuses CVE-2025-53770 and CVE-2025-53771 to bypass identity controls on compromised machines and subsequently deploy the ‘Warlock’ ransomware. The attack chain abusing these vulnerabilities (dubbed ‘ToolShell’) has been exploited by both state-sponsored and cyber criminal threat actors, highlighting its widespread potential impact on global firms. Microsoft reports that over 400 organisations have been actively compromised as of 23 July and that more will likely be affected in the short term. Microsoft also stressed the importance of timely patch management policies and robust security detection controls. We assess that software vulnerabilities will continue to pose elevated security, operational and reputational risks to global firms in the long term. (Source: Sibylline)

——————————————————————————————————————————————————————————————————————————————————————————————————————————————

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

—————————————————————————————————————————————————————————————————————————————————————————————————————————————

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

July 25, 2025 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

——————————————————————————————————————————————————————————————————————————————————————————————————————————————–

24 Jul 25. Japan joins AUKUS partners to enhance underwater communications for unmanned systems. The militaries of Japan, Australia, the UK, and US have been testing unmanned maritime systems and associated technologies including communication technologies under the ongoing Exercise ‘Talisman Sabreʼ 2025 held in Jervis Bay, Australia. (Commonwealth of Australia) The Japan Self-Defense Forces (JSDF) has joined the militaries of Australia, the United Kingdom, and United States to test underwater communications for unmanned maritime systems as part of AUKUS Pillar 2 efforts. Japan’s Ministry of Defense (MoD) and Australia’s Department of Defence (DoD) announced on 23 July that the tests were conducted during Exercise ‘Talisman Sabreʼ 2025 held in Australia from 13 July to 4 August. The tests were part of the AUKUS ‘Maritime Big Playʼ initiative, which is a series of integrated trilateral experiments and exercises aimed at advancing autonomous maritime systems and improving interoperability between the partners.

“The AUKUS partners and Japan worked together to enhance their use of underwater acoustic communications to task an underwater uncrewed vehicle to conduct activities at sea,” the DoD said.

In addition to testing underwater acoustic communications, the AUKUS partners demonstrated their ability to remotely control each other’s unmanned systems from great distances using common control technologies. For example, the Royal Australian Navy (RAN) was able to remotely transfer mission control of an extra-large unmanned underwater vehicle (XL-UUV) located in the UK to the UK Royal Navy (RN) from Jervis Bay in New South Wales, the DoD added. The DoD said, “The integration of autonomy and greater interoperability between our forces gives our military commanders more options to protect and defend critical seabed infrastructure and sea lanes of communication.” (Source: Janes)

 

24 Jul 25. Radio Over IP Communications for Defense & Security Forces. Defense Advancement showcases LS Electronics’ Radio Over IP Communications solutions for defense, security, and unmanned systems. LS Electronics is a Swedish communications technology specialist with over 30 years of experience delivering secure, scalable solutions for defense, public safety, and unmanned platforms. As a supplier partner, Defense Advancement is showcasing innovative solutions and capabilities across the LS Electronics’ supplier profile.

Mimer SoftRadio

Mimer SoftRadio addresses the challenge of fragmented voice systems by enabling real-time communication between disparate radio types, such as analog, TETRA, DMR, and VHF/UHF—through IP-based connectivity. The system allows operators to remotely access, transmit, and manage audio from multiple devices using standard PCs or control consoles without requiring direct RF access or proprietary telecom links. Communications from radios, phones, intercoms, and paging systems are all managed from a single interface, increasing operational clarity and coordination.

Mimer SoftRadio Service

Mimer SoftRadio Service extends radio control to cloud-hosted or remote deployments via an open, IP-based middleware platform. It supports analog, DMR, and TETRA systems and is engineered for integration with custom dispatch consoles, PoC applications, and unmanned system command software. Each connected radio and user is uniquely identified with a MimerID, ensuring accurate routing and control.

Mimer SoftLine

Mimer SoftLine delivers compact, rugged Audio over IP functionality for linking analog and digital radios, telephony, and intercom systems across secure IP networks. It allows operators to modernize communications while retaining legacy hardware, supporting cross-patching and remote access over LAN or internet connections.

Mimer X-Link

Mimer X-Link enables seamless interconnection of multiple radio networks across wide areas using standard IP networks. It transmits audio, PTT, and control signals between geographically separated radio systems, allowing them to operate as if on the same local network.

Mimer VoiceLog

Mimer VoiceLog is an IP-based audio logging system for capturing communications across radios, consoles, phones, and unmanned platforms. It supports time-stamped, multi-channel recording with metadata such as PTT activation and user ID, allowing secure storage, playback, and export for mission review and legal compliance. The system includes AI-powered voice-to-text transcription for searchable records and real-time keyword alerts, particularly valuable for operations involving USVs and UAVs. It is suitable for both centralized and field deployments requiring reliable documentation of voice communications. (Source: https://www.defenseadvancement.com/)

 

24 Jul 25. Aselsan signs landmark agreement with Pamodzi to produce radios in South Africa. The signing ceremony between Pamodzi and Aselsan at IDEF 2025. At the IDEF 2025 defence exhibition currently underway in Istanbul, Turkey’s Aselsan has signed its first local production contract in South Africa, with Pamodzi Group, to produce two-way handheld radios primarily for the defence and security sectors. The agreement was finalised in May this year and signed on 22 July at IDEF by Frederick Leketi, Pamodzi Group Chief Investment Officer and Ahmet Akyol, Aselsan Group CEO. They were joined by South Africa’s Ambassador to Ankara, Dipuo Letsatsi‑Duba, and Deputy Minister of Defence and Military Veterans Bantu Holomisa. The local production contract is for Aselsan’s Astela 3710 radios. Mike Kgobe, head of the Aviation and Defence Systems division at Pamodzi Group, explained to defenceWeb that the agreement came out of a Department of Trade, Industry and Competition (the dtic) requirement in 2016/17 for two-way radios after it found the government was spending significant amounts of money on foreign radios (the police, defence force, state-owned entities, correctional services, and other government departments are big users of two-way radios, but the private security sector is also a large user).  On the back of a National Treasury (NT) Instruction Note 1 of 2016/17 for localisation of two-way handheld radios, the local defence and security industry was asked to localise radio production but was not able to, resulting in National Treasury and the dtic having to approve exemptions and deviations to public procurement legislation whenever public entities needed to procure two-way radios, Kgobe said.

He went on to say it did not make sense to reinvent the wheel, but to rather work with tested models to achieve a transfer of technology supporting localisation, industrialisation, and job creation.

Under the agreement, semi-knockdown kits will be acquired from Turkey, with local assembly and testing by Pamodzi BMG Electronic Communications, which was set up to handle the radio businesses. This is a partnership between Pamodzi Aviation and Defence Systems and BM Global Defence Systems, a black-owned investment holding company. In 2016 BM Global was inducted in the Defence Transformative Enterprise Development incubation programme of the Department of Defence, managed by Armscor. Pamodzi Aviation and Defence Systems owns 60% of Pamodzi BMG Electronic Communications, with BM Global owning the remaining 40%. Pamodzi and Aselsan will be working with the Independent Communications Authority of South Africa (ICASA) as the regulator as well as the Council for Scientific and Industrial Research (CSIR), which have well-established facilities for electromagnetic spectrum testing. Kgobe explained that South Africa is an industrialised economy able to supply many of the required components, and local suppliers are being identified for the radios to achieve the required localisation content. The transfer of technology is a landmark agreement as it is the first Aselsan has done in Africa, but the Turkish company has carried out transfers of technology with radios for other customers around the world – it allows for local encryption to ensure security and sovereignty is retained. This is the first transfer of technology project concluded by Aselsan in South Africa. The two-way radio agreement is a starting point in South Africa and other projects with Aselsan are planned to follow. Aselsan is not taking any equity stake in the arrangement in order to speed up market penetration, but is subsidising a portion of the project. The company will also provide training for engineers and technicians.

Leketi told defenceWeb that Pamodzi has a nearly 50-year history in South Africa, with diversified investments across construction, food, fashion, catering, IT and many other interests. This includes defence, with Pamodzi having previously a 26% stake in LMT. Pamodzi Group is expanding further into the aerospace and defence sector, notably through the establishment of its Aviation and Defence Systems division.

As Pamodzi has a lot of strong relationships with private sector entities, it is optimistic about securing orders from private security players, notably large security firms. Other potential users include the South African National Defence Force (SANDF), Transnet, Eskom, Border Management Authority (BMA) etc. At a later stage, export sales will be considered on a case-by-case basis.

According to Kgobe, the main markets for Aselsan’s two-way radios are the South African National Defence Force, Department of Correctional Services, emergency medical services, and provincial governments, with most demand coming from the public sector. However, he believes that once the public sector acquires the radios, the private sector – particularly the security industry – will follow suite, especially as there is no direct competition in South Africa for locally produced two way radios. Local manufacture also means after-sales support and economies of scale.

Kgobe noted that Aselsan and Pamodzi are not aiming to offer the cheapest radio on the market but the most capable, including features like encryption and compatibility with other systems like body cameras.

The Astela Apco 3710 can, according to the manufacturer, operate in simplex (from radio-to-radio), direct (via repeaters), wide area conventional system and wide area trunk system modes. The radio has backward compatibility with legacy analogue FM radios, which provides radio users with the possibility of easy transition from analogue to digital communication.

The radio is ruggedised for use in challenging environments such as very high or very low temperature, high humidity, low pressure, sand and dust (it supports MIL STD 810G standards and has IP67 Ingress Protection).

Thanks to the integrated GNSS module, the Apco 3710 can detect its current location depending on the received signals from GPS, GLONASS and GALILEO satellites. In addition, radio users can send their locations – manually or automatically – in all digital operation modes. Bluetooth capability supports peripheral accessories.

The Apco 3710 is part of Aselsan’s broad public safety and mission critical communications systems portfolio, which includes radios, repeaters, and tethered drone mobile relay systems, amongst others.

Aselsan South Africa was established as a branch of the Turkish company in 2011 after Aselsan had acquired a local engineering firm which it had contracted to develop high end electro-optical systems for airborne military use. The South African division subsequently designed and produced high performance airborne thermal imagers, multi-spectral airborne sensors, in-flight boresighting systems and targeting electro optical payloads for airborne applications.

Aselsan sees South Africa’s strategic position as serving as a gateway to the African continent, and coupled with its size, economic influence, and advanced infrastructure, makes it an ideal base for expanding its presence across the region.

Aselsan specialises in tactical military radios, electronic warfare, avionic modernisation and defence electronic systems, primarily for the Turkish Armed Forces, but exports account for a substantial amount of revenue. Its business divisions are involved in things like radar, satellites, cyber security, air and missile defence, land weapons systems, electro-optical systems, traffic automation and transportation.

(Source: https://www.defenceweb.co.za/)

24 Jul 25. Global: Information stealer resurgence underscores raised security, data-theft risks to businesses. On 22 July, the cyber security company Trend Micro reported that operators of the ‘Lumma Stealer’ malware have resumed operations following a law enforcement takedown in May. Law enforcement had reportedly blocked around 2,300 malicious domains alongside infecting its control panel to disrupt marketplace operations. However, Lumma operators started restoring infrastructure in the weeks following the takedown, showcasing the actors’ resilience. The new infrastructure uses multiple service providers, including some located in Russia to enhance obfuscation and evade detection. Threat actors have also adopted new infection vectors to distribute the stealer including fraudulent websites, fake cheat codes for online games and social media posts, highlighting the rapid evolution of its tactics. Lumma compromised nearly 400,000 Windows devices worldwide before its takedown, enabling extensive data exfiltration. We assess that this report underscores the increased security and data-theft risks to entities as Lumma operations will likely continue to grow in the short-to-medium term. (Source: Sibylline)

 

24 Jul 25. Silvus Technologies Introduces StreamCaster 4400 XTREME – Ultra-Ruggedized MANET Radio. Silvus Technologies, Inc., a leading global supplier of advanced wireless networking solutions, has announced the launch of the StreamCaster 4400 XTREME (SC4400X) MANET radio. Delivering high-fidelity video, voice, and IP data communications in an ultra-ruggedized form factor, the SC4400X is purpose-built for maritime, littoral, and other highly corrosive environments where durability and maximum MANET radio performance are mission-critical. Engineered to be as tough as the mission, the SC4400X builds upon the proven performance of the StreamCaster 4400 Enhanced (SC4400E) MANET radio with up to 20 Watts of output power (80W effective, thanks to TX Eigen Beamforming), 100 Mbps data throughput and single/dual band frequency options, making it ideal for fixed infrastructure, vehicular and airborne applications in the harshest environments. Constructed from sea-grade aluminum with MIL-A-8625-F Type III hard anodizing, the SC4400X design features a single locking marine-grade connector, and optimized enclosure with enhanced thermal characteristics to improve passive cooling and thermal performance during sustained high-power operations. Designed for maximum versatility, the SC4400X supports a wide 9 – 50 VDC input voltage range for flexible platform integration and features a built-in status LED for real-time operational feedback. Compatibility with the existing SC4400E mounting pattern allows for seamless incorporation into existing deployed integrations, including StreamCaster PRISM. Powered by Silvus’ battle-proven MN-MIMO waveform, the SC4400X delivers robust, high-bandwidth connectivity – capable of creating massively scalable mesh networks that connect hundreds of nodes with unmatched range, data throughput, and EW resiliency in contested spectrum environments. In addition to AES256 and FIPS 140-3 Level 2 encryption for secure operations, the SC4400X provides access to Spectrum Dominance 2.0 – an expansive suite of LPI/LPD, Anti-Jamming EW resiliency and Advanced Threat Protection capabilities – providing secure and protected communications without sacrificing performance, even in contested environments.

“We developed the SC4400X in direct response to the growing demand for resilient MANET radio solutions that can operate in salt-laden, high-humidity and highly corrosive environments without compromising performance,” said Neema Daneshvar, Vice President of Product at Silvus Technologies. “Whether for shipboard, littoral, or offshore applications, the SC4400X delivers the class-leading tactical mesh networking power of Silvus’ StreamCaster 4400 MANET radio in a form factor that thrives where others corrode.”

With the launch of the SC4400X, Silvus Technologies continues to expand the StreamCaster family of MANET radios, reinforcing its commitment to delivering mission-ready, wireless networking solutions that extend tactical communications across the world’s most challenging operational environments. (Source: UAS VISION)

 

23 Jul 25. Global: Exploitation of software vulnerabilities will elevate security risks from Chinese actors. Earlier on 23 July, several international news outlets reported that three Chinese state-sponsored groups (‘Linen Typhoon’, ‘Violet Typhoon’ and ‘Storm-2603’) have been exploiting two software vulnerabilities (CVE-2025-49706 and CVE-2025-49704) to infiltrate systems since at least early July. The vulnerabilities affect on-premises Microsoft SharePoint servers and enable threat actors to bypass authentication processes and execute remote commands on compromised systems. A scan of more than 23,000 SharePoint servers worldwide revealed that approximately 400 systems (including government agencies in the US and Spain) had been compromised, underscoring the potential scale of the infection. There is a realistic possibility that the groups have sought to steal user credentials and cryptographic keys during the breaches, increasing the risk of follow-on attacks in the short term. Microsoft released a third patch on 21 July to address the vulnerabilities, highlighting the importance of effective patch management policies. We assess that this will elevate security risks in the short-to-medium term amid the continued development of China’s cyber strategy. (Source: Sibylline)

 

22 Jul 25. Italy purchases two L3Harris EA-37B electronic attack aircraft. Italy has purchased two L3Harris EA-37B Compass Call electronic attack (EA) aircraft for USD300 m, the company announced on 21 July. In October 2024, the US Department of State announced that it had cleared Italy to purchase an undisclosed number of EA-37Bs via the Foreign Military Sales process for USD600 m. Italy is the first foreign country approved to operate the aircraft. It is unclear whether its aircraft will be equipped with the Compass Call Baseline 4 (Systemwide Open Reconfigurable Dynamic Architecture: SWORD-A) electronic systems the US Air Force (USAF) uses or Italy will use a bespoke configuration. The EA-37B is based on the Gulfstream G550 platform. The G550, although designed as a business jet, is often modified by armed forces for special missions – particularly for VIP transport and intelligence, surveillance, and reconnaissance (ISR). The Italian Air Force operates two Gulfstream G550s with identical structural modifications – the prominent ‘cheeks’ on either side of the fuselage and bulbous tail cone – equipped with Elta Systems EL/W‐2085 radars to perform airborne early warning (AEW) missions. The service is also acquiring two G550-based Joint Airborne Multisensor Multimission System (JAMMS) aircraft from L3Harris, intended for passive electronic intelligence missions. Once sourced from the used aircraft market – the G550 is no longer in production – the aircraft enter Gulfstream’s Savannah, Georgia, factory for structural modifications and are then sent to L3Harris’s Waco, Texas, facility for installation of the BAE Systems-built mission equipment. (Source: Janes)

 

21 Jul 25. Africa: Cyber attack highlights elevated security risks from Chinese state-sponsored groups. Earlier on 21 July, the cyber security company Kaspersky reported that the Chinese state-sponsored group ‘APT41’ targeted government services across the Africa region in a cyber operation. The group likely compromised a user account on an unprotected device to infiltrate targeted systems; however, the initial attack vector is currently unclear. The group then escalated privileges by hijacking two administrative accounts, established communication with command-and-control (C2) infrastructure and downloaded the penetration testing tool Cobalt Strike to maintain persistence. APT41 deployed multiple information stealers to steal credentials, email and chat messages and other sensitive information as well as financial data. The group typically conducts both cyber espionage and financially motivated operations to bolster its resources. Africa has typically been one of the regions least targeted by APT41’s cyber operations. We assess that this report highlights elevated security risks to Africa-based government entities amid possible target expansion. (Source: Sibylline)

 

22 Jul 25. Kratos and Intelsat Successfully Demo 5G NTN Over GEO. Over-the-air testing validates satellite’s role in delivering end-to-end 5G services. Kratos Defense & Security Solutions, Inc. (Nasdaq: KTOS), a technology company in Defense, National Security and Global Markets, today announced the successful demonstration of an end-to-end 5G-NTN network that combines the Kratos OpenSpace® software-defined satellite ground system with Intelsat’s space and ground network, including its cloud-native, virtualized 5G core. This event represents a key milestone towards the seamless extension of terrestrial 5G networks with satellite technology, providing critical validation of satellite’s role in the delivery of ubiquitous 5G services. The Third Generation Partnership Program (3GPP) incorporated Non-Terrestrial Networks (NTNs) into its 5G specifications with 3GPP Release 17, paving the way for the seamless extension of 5G services beyond terrestrial limits. Both Kratos and Intelsat are leading the market in 5G-NTN adoption; Kratos is working with key industry partners to develop cloud native 5G-NTN solutions for satellite operators, while Intelsat is focused on building a multi-layer, next-generation software-defined network. Kratos and its partner Radisys announced last year their plans to develop a satellite base station – a 5G NTN gNodeB — delivered completely as cloud-native software, to be deployed as part of the OpenSpace® system. The over-the-air (OTA) demo conducted by Kratos and Intelsat validated that joint solution, leveraging it to orchestrate a 5G NR-NTN cell that was activated over Intelsat’s Galaxy 19 Ku-band GEO satellite. Multiple User Equipment (UE) emulators from partner VIAVI Solutions successfully attached and established PDU) traffic flows from different locations within the 5G-NTN cell, demonstrating that any standards-compliant terminal can access the 5G network on a satellite connection. This brings the industry closer to truly ubiquitous broadband services for all customers, regardless of location.

“This demonstration represents a significant milestone in both companies’ progress in advancing ubiquitous 5G connectivity that spans both terrestrial and space networks,” said Greg Quiggle, Senior Vice President of Product Management at Kratos. “This remarkable technical accomplishment demonstrates the value of the OpenSpace virtual ground system in enabling that connectivity.”

5G-NTN opens the door to a broad range of new communications services in markets unserved or underserved by terrestrial connectivity alone. It paves the way for seamless service delivery across satellite orbits, satellite operators and for mainstreaming satellite-enabled services seamlessly across the global web of terrestrial communications networks. Kratos’ OpenSpace platform will play a key role in that revolution by bringing the dynamic software-defined networking principles that are common in today’s terrestrial networks to the legacy satellite environment and leveraging a common, standards-based architecture for the delivery of global 5G services with terrestrial network partners. (Source: ASD Network)

 

21 Jul 25. Anduril wins $100m deal to build US Army’s next-gen C2 ecosystem. The U.S. Army has picked Anduril to be the lead integrator to build its next-generation command-and-control prototype, or C2, awarding the tech company a $99.6m contract to deliver it in less than a year, according to statements from the service and company. The prototype architecture will consist of “integrated and scalable” C2 capabilities using hardware, software and applications through a common data layer, the Army stated in a July 18 announcement. The Army’s effort to overhaul its command-and-control ecosystem, dubbed Next-Generation C2, is one of the top priorities for Army modernization — if not the highest. The capability will be delivered to the 4th Infantry Division, the service said. The prototype will be “integrated onto compute nodes aboard multiple different types of mechanized vehicles” throughout the Division immediately upon award of the contract, Anduril noted, and will be continuously developed working directly with soldiers. The Army’s command-and-control architecture, which enables commanders to plan, decide and execute missions, was cobbled together over 20 years during the Global War on Terror. Most warfighting functions used separate stove-piped systems, amounting to a total of 17 programs of record. Army Chief of Staff Gen. Randy George recognized getting command-and-control right was imperative to future battlefield success and decided to embark on a program to fix the service’s C2 capabilities to avoid operational disruption while creating the necessary clean-sheet system from scratch. The Army’s effort to overhaul its command-and-control ecosystem, dubbed Next-Generation C2, is one of the top priorities for Army modernization — if not the highest. Roughly 18 months ago, at the National Training Center at Fort Irwin, California, soldiers at the Army’s experimentation event Project Convergence and industry partners, including Anduril, demonstrated a proof-of-concept at the unclassified level for what a Next-Generation C2 system, or NGC2, might look like.

The Army established the NGC2 program office in April 2025.

“NGC2 is not just a capability. It’s a blueprint for how we’ll deliver future Army systems,” Gen. James Rainey, Army Futures Command commander, said in the service’s statement. “This award reflects a fundamentally different relationship with industry, built on shared purpose, speed, and trust. By co-developing with our industry partners and putting soldiers at the center of design, we’re delivering what they need — faster, more integrated, and ready for the fight.”

Anduril will, over the next 11 months, come together with other industry partners like Palantir, Striveworks, Govini, Instant Connect Enterprise (ICE), Research Innovations, Inc. (RII) and Microsoft, the company listed in a statement.

“For NGC2, Anduril and its partners will create an ecosystem that can rapidly integrate a range of technologies into a singular architecture so that soldiers can access various kinds of compute, communications and information processing capabilities all at once,” the company describes. “Time sensitive decisions will be faster and soldiers will be more connected across Corps to Company.” (Source: Defense News)

 

18 Jul 25. Cyber Update Key points

  • The discovery of a new multi-stage social engineering attack technique highlights heightened security risks stemming from legitimate artificial intelligence platforms.
  • A new social engineering technique (‘FileFix’) underscores the increased security risks to global businesses from the ransomware group ‘Interlock,’ see our Technical analysis below.
  • A newly reported cyber operation will sustain security risks to global Android mobile users.
  • Reports of a sophisticated cyber operation will heighten security, financial and reputational risks to Hong Kong-based financial institutions, see our Technical analysis below.
  • The targeting of the US National Guard in a cyber operation highlights long-term security and cyber espionage risks from the Chinese state-sponsored group ‘Salt Typhoon’

Technical analysis of weekly stories

Unnamed threat actors are conducting a covert, highly sophisticated cyber operation against financial institutions in Hong Kong. The operation starts with spear phishing emails (impersonating financial institutions) to trick victims into opening an enclosed .RAR archive disguised as an invoice. The archive emulates a legitimate Word document to enhance legitimacy and executes a loader malware (‘SquidLoader’) onto compromised systems upon opening. SquidLoader then establishes communication with command-and-control (C2) infrastructure, enables persistent access to compromised systems by employing ‘Cobalt Strike’ and locates unresolved Windows application programming interfaces (APIs) to aid detection evasion and remote code execution. The malware displays a fake error message to solicit user interaction and impede automated malware analysis, in addition to using a URL that mimics legitimate services (including Kubernetes) to conceal malicious traffic. It also performs regular checks to delete itself from compromised systems if detected by security mechanisms and boasts several other anti-analysis techniques, further highlighting SquidLoader’s sophistication. Several campaign instances have also been identified in Australia and Singapore, underscoring the possible expansion of this campaign.

The ransomware group Interlock is using a new social engineering technique (‘FileFix’) to deploy a PHP variant of its custom remote access trojan (RAT). Interlock distributes compromised websites to infiltrate targeted systems by displaying overlays and/or browser updated prompts via a web injector (‘KongTuke’). This tricks users into copying malicious PowerShell code onto the clipboard before unknowingly executing the code by pasting the file path into File Explorer. The code ultimately deploys the RAT onto systems, allowing the group to collect and exfiltrate sensitive data before deploying the ransomware. The malware exploits the legitimate Cloudflare Tunnel service to conceal C2 infrastructure, alongside using legitimate user interface (UI) services (such as File Explorer) to enhance legitimacy and prolong detection evasion. The RAT also enables interactive communication with C2 infrastructure to allow remote command execution, highlighting Interlock’s sophistication. FileFix is the newest iteration of another less stealthy attack technique (‘ClickFix’), showcasing the continued evolution of ransomware operations.

Non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering (Source: Sibylline)

—————————————————————————————————————————————————————————————————————————————————————————————————————————-

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

—————————————————————————————————————————————————————————————————————————————————————————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

July 18, 2025 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

——————————————————————————————————————————————————————————————————————————————————————————————————————————————-

18 Jul 25.  Statement of condemnation by the North Atlantic Council concerning Russian malicious cyber activities

  1. We strongly condemn Russia’s malicious cyber activities, which constitute a threat to Allied security. We stand in solidarity and recognise that Estonia, France, the United Kingdom and the United States have recently attributed malicious cyber activity targeting several NATO Allies and Ukraine to Russia’s military intelligence service (GRU).  We recall that in 2024, Germany and the Czech Republic individually attributed activity to APT 28, which is sponsored by the GRU. We also note with concern that the same threat actor targeted other national governmental entities, critical infrastructure operators and other entities across the Alliance, including in Romania. These attributions and the continuous targeting of our critical infrastructure, with the harmful impacts caused across several sectors, illustrate the extent to which cyber and wider hybrid threats have become important tools in Russia’s ongoing campaign to destabilise NATO Allies and in Russia’s brutal and unprovoked war of aggression against Ukraine.
  2. We call on Russia to stop its destabilising cyber and hybrid activities. These activities demonstrate Russia’s disregard for the United Nations framework for responsible state behaviour in cyberspace, which Russia claims to uphold. Russia’s actions will not deter Allies’ support to Ukraine, including cyber assistance through the Tallinn Mechanism and IT capability coalition. We will continue to use the lessons learned from the war against Ukraine in countering Russian malicious cyber activity.
  3. NATO stands for a free, open, peaceful and secure cyberspace. We call on all States, including Russia, to uphold their international obligations, also when acting in cyberspace, and to act consistently with the framework for responsible state behaviour in cyberspace as affirmed by all members of the United Nations.
  4. We remain united in our determination to counter, constrain, and contest Russian malicious cyber activities and are investing in our defences; including through the establishment of the NATO Integrated Cyber Defence Centre and upholding our Cyber Defence Pledge commitments as well as through the commitments made in the Hague Summit Declaration.
  5. We are determined to employ the full range of capabilities in order to deter, defend against and counter the full spectrum of cyber threats.  We will respond to these at a time and in a manner of our choosing, in accordance with international law, and in coordination with our international partners including the EU.

 

18 Jul 25. Bittium Corporation’s Subsidiary Bittium Wireless Ltd. and Indra Group to Sign a Letter of Intent for Strategic Cooperation on Tactical Radio Communications Solution. Bittium Corporation’s subsidiary Bittium Wireless Ltd and Indra Group have today signed a Letter of Intent to establish strategic cooperation in the development of Software Defined Radio (SDR) solution – a key technology in defense modernization – at the Ministry of Defense in Madrid, Spain. The intent of the cooperation is to explore a technology transfer from Bittium regarding Software Defined Radios for tactical communications, with Indra contributing its extensive experience in the field of Software Defined Radio and waveforms and performing the necessary evolution for the implementation in Spain of the required technological and industrial capabilities to develop a European fully proprietary solution thus meeting Spanish and Allied Armed Forces requirements. Bittium has long experience in tactical communication solutions, including modern, high performance tactical IP network system and next generation Software Defined Radios supplied in various countries, such as Finland, Estonia, Croatia, and Austria. Indra Group develops and produces radios for critical and military communications and has supplied its solutions to various countries, including US and Canada.

“We are excited to provide our technology to Indra as a critical asset for the use for the military programs in jointly agreed market areas. Bittium will continue to be a global supplier of tactical communications and SDR radios in the future. With over 40 years of experience, Bittium has been positioned as a forerunner in advanced next generation tactical communication solutions and Software Defined Radios for the modernization of military tactical communications. Together with Indra, we are stronger to meet the requirements in the agreed market areas”, says Petri Toljamo, CEO of Bittium Corporation.

“With this agreement, we want to take another step forward in Indra’s extensive track record in developing proprietary technologies and experience over the past 15 years in the field of SDR technology and waveforms, which has positioned us as a national leader in this area,” said Ángel Escribano, president of Indra Group.

Both Indra Group, in coordination with Spanish authorities, and Bittium are among the founding members of the a4ESSOR joint venture, which brings together the most advanced companies in Europe working on the development of waveforms specifically designed to enable armed forces to interoperate more securely and efficiently. Two years ago, NATO adopted one of the high-speed data waveforms developed by this joint venture and approved its use for tactical communications on radio platforms. Bittium announced earlier on 11 July 2025 that the Spanish Ministry of Defense plans to launch a project to acquire new national software-based tactical radios. Bittium and Indra will work together to provide Bittium’s technology to the jointly agreed market areas. The negotiations are still in the early stages, and it is too early to estimate the size of the financial potential of this cooperation to Bittium, nor to estimate the size of the potential deals.

 

18 Jul 25. US: Chinese actors will sustain long-term security, espionage risks to defence, government entities. On 17 July, international news outlets reported that the Chinese state-sponsored group ‘Salt Typhoon’ targeted a US Army National Guard network in a cyber espionage operation between March and December 2024. The attack reportedly resulted in the exfiltration of administrator credentials, configuration files, network diagrams and the personal information of service members. Between 2023 and 2024, Salt Typhoon stole approximately 1462 network diagrams associated with around 70 US government and critical national infrastructure (CNI) entities, showcasing the scale of the group’s operations. It later used the stolen diagrams to compromise at least one US government agency, suggesting that the group will likely attempt to use stolen documents from the National Guard for follow-on operations. Salt Typhoon routinely targets critical sectors in the US to obtain sensitive information and maintain prolonged persistence for potential future disruption. We assess that this development underscores sustained long-term security and cyber espionage risks amid ongoing geopolitical tensions. (Source: Sibylline)

 

17 Jul 25. QinetiQ launches ‘Droneworks’ and plans complex UAS jamming testing. QinetiQ has revealed to Janes its new test and evaluation (T&E) framework, which it calls ‘Droneworks’, to help companies developing unmanned air systems (UASs) solve complex engineering problems and provide specialist assessment. Droneworks is provided through QinetiQ’s Long Term Partnering Agreement (LTPA) with the UK Ministry of Defence (MoD). On 22 May 2025 QinetiQ announced a five-year, GBP1.54 bn (USD2.06 bn) extension to the 25-year LTPA, originally signed in 2003. The MoD said the LTPA investment supports an extensive supply chain of 825 companies, including 590 small-to-medium enterprises (SMEs). Droneworks was established by QinetiQ under the LTPA extension’s Innovation Gateway, designed to make LTPA services more accessible to SMEs. Evolving out of the Air Test and Evaluation Centre (ATEC) construct between QinetiQ and the MoD, Droneworks provides a UAS test and evaluation hub for the RAF’s Air and Space Warfare Centre (ASWC), the RAF’s Rapid Capabilities Office (RCO), QinetiQ, 744 Naval Air Squadron (which in 2024 transitioned to the Joint Uncrewed Air System Test and Evaluation Squadron (JUAS TES)), and various companies, from major defence primes to small and medium enterprises. The UK’s 2025 Strategic Defence Review (SDR), published on 2 June, called for “an initial operating capability for a new Defence Uncrewed Systems Centre established by February 2026”. Commonly referred to as a ‘Drone Centre of Excellence’, Peter Barnfield, senior business development manager at QinetiQ, told Janes. (Source: Janes)

 

16 Jul 25. Global: Cyber operation will sustain security risks to Android mobile users. On 15 July, the security company BforeAI reported that unnamed threat actors are conducting a cyber operation against global Android mobile users. Threat actors reportedly distribute links and/or QR codes to trick victims into visiting a malicious website and downloading a fake version of the messaging application Telegram. The campaign boasts approximately 607 malicious domains and targets Android visitors with a download banner, highlighting the sophistication and potential scale of this operation. Threat actors also exploited an Android vulnerability (affecting all versions between 5.0 and 8.0) to insert malicious code into the application without changing its signature. This allows it to bypass standard security detection methods. Upon deployment, the application performs legitimate tasks to evade detection while covertly granting threat actors remote execution permissions. However, the campaign’s objective remains unclear. We assess that this report demonstrates sustained elevated security risks to Android mobile users amid the continued development of cyber capabilities. (Source: Sibylline)

 

16 Jul 25. Four US companies to help accelerate DoD adoption of advanced AI. Anthropic, Google, OpenAI, and xAI are each positioned to receive a maximum of $200m in under the contract. Pentagon’s Chief Digital and Artificial Intelligence Office (CDAO) has awarded contracts to four major US-based AI companies to expedite the military’s integration of advanced AI via the US Department of Defense (DoD). Each of the four companies, namely Anthropic, Google, OpenAI, and xAI, will receive awards with a ceiling of $200m. The DoD will harness the expertise and innovation of these companies to create generative AI-driven workflows for various national security missions. This initiative is expected to expand DoD’s engagement with AI capabilities and facilitate a deeper understanding among these tech companies of the national security requirements that their AI solutions can address. DoD chief digital and AI officer Dr Doug Matty said: “The adoption of AI is transforming the Department’s ability to support our warfighters and maintain strategic advantage over our adversaries.

“Leveraging commercially available solutions into an integrated capabilities approach will accelerate the use of advanced AI as part of our Joint mission essential tasks in our warfighting domain as well as intelligence, business, and enterprise information systems.”

The DoD is pursuing a “commercial-first” strategy to fast-track the implementation of AI. The awards are part of this initiative, bringing advanced US-based AI expertise to bear on specific DoD challenges. Additionally, the CDAO is facilitating access to some of the most recent generative AI models for general use by various defence entities through platforms like the Army’s Enterprise Large Language Model Workspace powered by Ask Sage. This access extends to broader enterprise applications via embedded AI models in data and AI platforms such as Advancing Analytics (Advana), Maven Smart System, and Edge Data Mesh nodes. These platforms are designed to integrate AI directly into data environment workflows. In an effort to consolidate federal efforts around AI technology procurement and utilisation, the DoD is also collaborating with the General Services Administration (GSA). This partnership aims to harness government-wide purchasing power for AI production and computational resources, ensuring that federal agencies have access to premier AI technologies. In December 2024, CDAO initiated a new programme to expedite the deployment of advanced AI technologies within the US DoD. (Source: naval-technology.com)

 

14 Jul 25. Global: New attack technique highlights heightened security risks stemming from AI tools. On 13 July, international news outlets reported that the artificial intelligence (AI) platform Gemini can be exploited to conduct a new multi-stage social engineering attack. The first stage of the attack involves the creation of an email containing malicious instructions that are written in white, zero-size font to render them invisible. If the email recipient uses Gemini to obtain a summary of the email’s content, the tool follows the embedded instructions and warns users that their password has been compromised. This tricks users into calling a phone number to reset their password, enabling threat actors to steal user credentials. While this technique has reportedly not yet been exploited by threat actors, it highlights the potential exploitation of legitimate AI tools for malicious cyber activity. We assess that this technique highlights heightened security and social engineering risks to global businesses amid the increased adoption of AI tools. (Source: Sibylline)

 

11 Jul 25. Cyber Update Key points.

  • A cyber operation by the China-linked threat group ‘UNC5174’ has underscored the security risks facing critical national infrastructure (CNI) in France (see Sibylline Cyber Daily Analytical Update – 7 July 2025).
  • A long-term cyber campaign has underscored the security and cyber espionage risks facing government entities in the Middle East and North Africa region from the Iranian state-sponsored group ‘BladedFeline’ (see Sibylline Cyber Daily Analytical Update – 8 July 2025).
  • Activity by a mobile malware variant (‘Anatsa’) will sustain the long-term security and financial risks facing US-based Android mobile users (see Sibylline Cyber Daily Analytical Update – 9 July 2025 and our Technical analysis below).
  • Activity by the India-linked advanced persistent threat (APT) group ‘DoNot APT’ has elevated the security and cyber espionage risks facing diplomatic entities in Europe (see Sibylline Cyber Daily Analytical Update – 10 July 2025 and our Technical analysis below).
  • Activity by an Iranian Ransomware-as-a-Service (RaaS) group, ‘Pay2Key’, will sustain the security and disruption risks facing Israeli and US entities (see Sibylline Cyber Daily Analytical Update – 11 July 2025).

Technical analysis of weekly stories

Unnamed threat actors are using a banking trojan (Anatsa) to conduct a financially motivated operation against US-based Android mobile users. The trojan is hidden within a fake actor-made PDF reader application that is distributed via the Google Play Store. Threat actors reportedly released the malicious version of the application after six weeks of advertising a clean version to gain popularity and enhance legitimacy. The clean version ranked among the ‘top free tools’ on the app store while the malicious version amassed approximately 50,000 downloads before its removal, underscoring the scale of the operation. Upon deployment, the application overlays a maintenance message whenever users open their banking application to conceal malicious activity, allowing threat actors to hijack accounts covertly and initiate fraudulent money transfers. Anatsa can also perform credential theft prior to conducting overlay attacks depending on the target. The trojan can target a wide range of banking institutions, which can be dynamically selected via command-and-control (C2) communication, further showcasing its sophistication. The operation was carried out in June; activity by previous iterations was observed since February 2024, highlighting the longevity of this threat.

The India-linked APT group DoNot APT has conducted a suspected cyber espionage operation against an unnamed European foreign affairs ministry. DoNot APT distributed phishing emails discussing a diplomatic visit between Italy and Bangladesh to trick users into clicking on an embedded Google Drive link. The HyperText Markup Language (HTML) included special characters in the email text in order to enhance legitimacy, highlighting the group’s detection-evasion capabilities. The link triggered the download of a .RAR archive, as well as a malicious executable that mimicked a legitimate PDF document and ultimately deployed a custom remote access trojan (RAT) called ‘LopTikMod’. Upon deployment, LopTikMod establishes communication with C2 infrastructure to enable command execution and deploy additional malicious payloads, as well as to exfiltrate data. DoNot APT obfuscated crucial parts of the malware’s code and used American Standard Code for Information Interchange (ASCII) characters to decode malware elements upon deployment. The group also employs anti-virtual machine techniques and creates a mutex to prevent LopTikMod from executing in multiple environments, further showcasing the sophistication of the group’s capabilities. The malware also uses scheduled tasks to maintain persistence.

Non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering

Our cyber word(s) of the week: Virtual machine (VM) (Source: Sibylline)

———————————————————————————————————————————————————————————————————————————————————————————————————————————————-

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

—————————————————————————————————————————————————————————————————————————————————————————————————————————————

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

July 11, 2025 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

———————————————————————————————————————————————————————————————————————————————————————————————————————————————-

10 Jul 25.  Europe: India-linked actors will raise cyber espionage, security risks to diplomatic entities. On 8 July, the cyber security company Trellix reported that the India-linked advanced persistent threat (APT) group ‘DoNot APT’ has conducted a suspected cyber espionage operation against an unnamed European foreign affairs ministry. DoNot APT distributed phishing emails to trick users into clicking on a Google Drive link that triggered the download of a .RAR archive. The archive then deployed a custom remote access trojan (RAT) called ‘LoptikMod’ to establish communication with command-and-control (C2) infrastructure, execute commands, download additional malicious payloads and exfiltrate data. LopTikMod also displays anti-virtual machine techniques to prevent the malware from executing in multiple environments and hinder analysis, highlighting the sophistication of its detection evasion capabilities. The adoption of LopTikMod showcases a likely shift in the group’s tactics to include more targeted and premeditated operations against diplomatic entities across Europe. This will therefore raise security and cyber espionage risks in the medium-to-long term amid shifting geopolitical relations. (Source: Sibylline)

 

10 Jul 25. Mergers and Acquisitions. As these words were being written in late June, it was no exaggeration to say the Islamic Republic of Iran’s Integrated Air Defence System (IADS) and Ground-Based Air Defences (GBAD) were no longer a threat. Israel commenced her attacks against Iranian Weapons of Mass Destruction (WMD), and politico-military targets, on 13th June. The goal of the attacks being to destroy Iran’s ability to develop and deploy nuclear weapons. The United States joined the fray on 21st June, hitting three targets associated with Iran’s WMD ambitions. So far, it appears Israel and US warplanes have suffered no losses. Israel declared air superiority over Tehran on 15th June. It seems likely the Israeli Air Force now has air superiority, or even air supremacy, over much of northwestern Iran. That the Iranian IADS and GBAD folded so quickly has come as a surprise, but the clues may have already been there. Surface-to-Air Missile (SAM) batteries Iran secured from Russia in recent years were unable to protect the country from the aerial onslaught. Iran’s home-grown systems, much vaunted in kitsch propaganda videos, fared little better. Tell-tale clues of the ramshackle nature of Iran’s air defences came to light in mid-May: An analysis performed by the James Martin Centre for Non-proliferation Studies indicated that Iranian air defence radar may lack robust networking. It could be argued that the strength of an IADS can be measured by the extent to which its constituent fighters, SAMs, radars and Command and Control (C2) centres are connected. Air combat occurs at high speed across large areas. It is axiomatic that IADS federate these assets to provide as detailed picture of as large a slice of airspace as possible in real time. Radar pictures are merged at tactical and operational levels to provide a detailed Recognised Air Picture (RAP) of local airspace and air approaches. These individual RAPs converge at the national level to provide a ‘Super RAP’ of a country, or an operational theatre’s airspace and its environs. This lack of networking was inadvertently revealed by Iranian air defenders in a video showing the defences around the Natanz WMD site in central Iran. A two-second clip showed four separate radar screens and their imagery. Researchers determined that each radar screen represented a separate system. The radar screens also inadvertently revealed the position of each radar relative to the Natanz facility. At a stroke, the Iranians had accidentally revealed exactly where the radars were located, and where the accompanying SAM batteries these radars served were positioned. What was also surprising was that the RAPs generated by each of these radars were not merged on a single screen. The deeper their situational awareness, the better chance air defenders have of engaging and defeating hostile aircraft. Four radar operators, looking at four different radar screens will struggle to enjoy the same level of awareness, as four operators looking at a merged radar image, the latter having the tactical advantage. Why the radar pictures were not merged is unclear. Perhaps Iranian engineers had not developed software to translate the presumably different radar output languages and merge the disparate imagery into a single RAP? We may never know the reasons why a key tenet of air defence theory appears not to have been followed by Iran’s air defenders. What we do know is that despite the decades of bombastic bluster about the superior capabilities of Iranian air defence technology, bns of dollars spent protecting Iranian skies has been wasted. Like the facility in Natanz, which was attacked by US warplanes on 222nd June, Iran’s air defences are in ruins. (Source: Armada)

 

08 Jul 25.  Is this a DIGAR I see before me? Underscoring the problem of GNSS jamming and spoofing around the world, the flightradar24 website publishes a daily map of GNSS disruption concentrations. The red areas are where jamming and spoofing is particularly acute. Efforts to mitigate the threat of satellite navigation signal spoofing and jamming through technological innovation are deepening in the United States. The June/July edition of Armada International includes an article that examines recent incidences of United States military aircraft experiencing Global Navigation Satellite System (GNSS) signal disruption. Worrying reports emerged this April: GNSS Position, Navigation and Timing (PNT) signal receivers equipping US Air Force (USAF) aircraft flying over the Persian Gulf had experienced jamming. Evidence was provided via the flightradar24 website. The website showed a USAF Boeing C-17A Globemaster-III turbofan airlifter appearing to follow an erratic flightpath. It seems that the incoming PNT signal received by the Globemaster’s GNSS system may have been corrupted. This then affected the outward Automatic Dependent System-Broadcast (ADS-B) transmission by the aircraft which was then depicted by flightradar24. The website relies on ADS-B data to show the location, identity and other characteristics of flights. ADS-B in turn relies on a PNT signal to display an aircraft’s position. If the incoming PNT signal is disrupted, so will the outgoing ADS-B transmission. Mindful of the dangers of GNSS PNT signal disruption, deliberate or otherwise, the United States Department of Defence (DOD) has embarked on several efforts to mitigate or eliminate this. Many of these efforts focus on improving the capabilities of GNSS receivers or investing in alternative PNT technologies. One example of these efforts is the Digital Global Positioning System Anti-Jam Receiver (DIGAR) programme. DIGAR is being rolled out across various USAF aircraft types by the US Air Force Life Cycle Management Centre (AFLMC). In 2018, Rockwell Collins (now Collins Aerospace) was selected by the AFLMC to provide its DIGAR technology to equip US Air National Guard and US Air Force Reserve General Dynamics/Lockheed Martin F-16 series combat aircraft. In 2022, BAE Systems won a contract to provide DIGAR technology for USAF McDonnell Douglas/Boeing F-15E Strike Eagle jets.

Architecture

Dhiraj Raghwani, BAE Systems’ director of airborne programme management, told Armada that the company’s approach to GNSS jamming/spoofing mitigation uses an innovative beamforming approach. BAE Systems’ literature says its DIGAR products use up to 24 simultaneous beams to enhance jamming immunity. What this means in practice is that “each channel in the (GNSS) receiver gets assigned to a beam dedicated to one unique satellite that it is tracking” says Mr. Raghwani. This combination of the individual satellite, and that satellite’s incoming PNT signal, “forms a unique antenna pattern that is optimised for a single satellite.” What this means in practice is that the DIGAR system is continually looking at this antenna pattern, as opposed to looking at the whole sky, for incoming PNT signals. GNSS jamming relies on seemingly genuine PNT jamming and/or spoofing signals being received by the GNSS system. These counterfeit signals are often more powerful than the comparatively weak incoming PNT signals which have lost much of their power after the long journey from space to Earth. Once received by the GNSS system, the counterfeit signals start to do damage. By only monitoring the unique antenna pattern, a DIGAR system ignores all GNSS signals, real or otherwise, that do not match this.

DIGAR works with a host of GNSS signals, notably those transmitted by the US DOD’s Global Positioning System (GPS). Signals include the dedicated military P(Y)-Code transmitted on the GPS constellation’s L1 and L2 channels which use frequencies of 1.57542 Gigahertz/GHz and 1.22760GHz respectively. The US DOD’s new military M-Code GPS PNT signal also uses the L1/L2 channels. The principal difference between civilian C/A-Code (Coarse Acquisition Code) and P(Y)-Code is precision and encryption: C/A code will afford around four-metres (13-feet) of accuracy while P(Y)-Code provides under three-metres’ (ten-feet’) accuracy. Both P(Y)-Code and M-Code are encrypted. Logically, a GNSS system which can detect P(Y)-Code and M-Code should ignore all incoming PNT signals lacking the requisite encryption. However, one key difference between P(Y)-Code and M-Code is that the former must initially acquire a C/A-Code signal before the receiver can begin obtaining the P(Y)-Code. The receiver might not necessarily obtain the P(Y)-Code if the C/A-Code PNT signal is already being disrupted. This is not the case for the M-Code signal which does not require this initial ‘handshake’.

DIGAR variants

BAE Systems’ DIGAR series comprises three distinct systems: DIGAR-300 is a Line Replaceable Unit (LRU) comprising hardware and software which needs a 28-volt direct current power supply. DIGAR-200 has a similar design but needs a 115-volt alternating current power supply. The DIGAR-200S includes an internal GPS module to provide position, velocity and time information to a host computer. All DIGAR systems can be used with an array of Controlled Reception Pattern Antennas (CRPAs) equipping “airborne, maritime and/or land platforms” says Mr. Raghwani. CRPA antennas can be used to ‘null’ directions from where jamming and/or spoofing has been identified to improve GNSS receiver resilience. Mr. Raghwani adds that the next-generation “DIGAR will be offered as an LRU including hardware and embedded software, with and without an internal M-code GPS module to provide position, velocity and timing (information) to the host computer.” While M-Code and P(Y)-Code provides resistance to GNSS jamming and/or spoofing, DIGAR takes this protection further. That the system has been installed on the USAF F-15E and F-16 fleets indicates the seriousness with which the DOD is tackling the PNT jamming/spoofing menace. Other US and allied platforms look set to receive this technology in the future as the GNSS threat proliferates. (Source: Armada)

 

09 Jul 25. Building the Integrated Force. In the second of two articles Armada examines what the United Kingdom’s Strategic Defence Review, published on 3rd June, will mean for British military communications. The UK’s Ministry of Defence (MOD) published the country’s Strategic Defence Review (SDR) in early June. The document outlines the United Kingdom’s strategic priorities, the defence policies to meet those priorities and the capabilities required therein. Tellingly, the United Kingdom is moving towards becoming what the SDR calls an Integrated Force by completing “the journey from ‘joint’ to ‘integrated’”, according to the review. The UK has already embraced the North Atlantic Treaty Organisation’s (NATO’s) commitment to Multi-Domain Operations (MDO). NATO defines MDO as “the push for NATO to orchestrate military activities across all operating domains and environments.” The alliance adds that “(t)hese actions are synchronised with non-military activities and enable (NATO) to create desired outcomes at the right time and place.” Put another way, MDO emphasises the intra- and interforce connectivity of all military assets at all levels of war for synchronous operations across the spectrum of conflict. The aim of MDO is to promote better quality decision-making at a more rapid pace than one’s adversaries to seize and maintain initiative across the battlespace. The UK’s Integrated Force will have no fixed force design. Instead, force structures will evolve and develop as threats and technologies change and emerge. The Integrated Force will be under the command of a new Military Strategic Headquarters (MSHQ). The MSHQ will be under the command of the Chief of the Defence Staff and their subordinate service chiefs. Furthermore, the Integrated Force will be able to operate unilaterally, or multilaterally, as circumstances dictate.

Digital Targeting Web

The SDR emphasises that the Integrated Force must be “underpinned by a common digital foundation and shared data”. This common digital foundation will be enabled by a “Digital Targeting Web” (DTW). The review states that the SDW is to be delivered by 2027. This targeting web will connect sensors, deciders and effectors to create “choice and speed in deciding how to degrade or destroy an identified target across domains and in a contested cyber and electromagnetic domain.” In common with the UK’s erstwhile Multi Domain Integration approach, now superseded by the Integrated Force, the latter will take a whole-of-government approach. What this means in practice is that the military will integrate other stakeholders, like the nation’s intelligence services, as and when necessary during crisis, contingency and/or combat operations. Delivering the Integrated Force requires “resilient and secure communications networks (and) an assured data fabric”. The data fabric is described by the review as a “sophisticated system that enables the efficient management and integration of large amounts of data across multiple sources”. Another technology vital for the Integrated Force is the Secret Cloud. This is described by the review as a “secure and scalable platform for storing and sharing information classified at Secret (level).” Plans call for the Digital Targeting Web capability to be available to the UK military from 2027, with the complementary Secret Cloud to be available one year earlier. An MOD spokesperson told Armada that the UK government plans to invest up to $1.4 bn by 2027 “to support faster identification and lethal response to threats across land, sea, air and space”. It is hoped that this investment will “give the UK a decisive advantage on the battlefield through greater integration and communication between our armed forces.”

Questions remain

Much remains unknown regarding the DTW architecture: What links, and communications hardware and software, will the digital targeting web use? How will existing MOD military communications initiatives like LETACCIS (Land Environment Tactical Communications and Information Systems) work with the DTW? What are the long term prospects for the troubled Project Morpheus land forces tactical communications and command and control programme? The Digital Targeting Web is an ambitious, and potentially expensive, undertaking. The UK’s and NATO’s commitment to multi-domain operations means that it cannot be allowed to fail. The future of the United Kingdom’s Integrated Force depends on it. (Source: Armada)

 

10 Jul 25. Devices and Desires. Army’s Next Generation Command and Control system were put through their paces at the force’s recent Project Capstone Convergence effort which took place between March and April in California. The US Army has taken an important step towards implementing an ambitious new command and control architecture for its manoeuvre force that takes a novel approach to communications links and devices. In April the United States Army’s Next Generation Command and Control (NGC2) system became a formal programme of record. In the army’s own words, the NGC2 will fundamentally change how its manoeuvre force performs command and control. The initiative is led by the army’s Programme Executive Office for Command, Control, Communications and Networks (PEO C3N). From an architecture perspective, the NGC2 comprises an array of networks, existing and planned, software and hardware. According to the PEO C3N, the army has been taking NGC2 technology through its paces during annual Project Convergence Capstone events. The events are joint and multinational initiatives “to transform and ensure future war-fighting readiness”, according to the US Department of Defence (US DOD). The DOD is the event’s sponsor. The most recent PCC took place in March and April this year at Fort Irwin, California. The PCC initiative plays a key role in examining technologies applicable to the US DOD’s Multi-Domain Operations (MDO) philosophy. The inter- and intra-force connectivity integral to MDO will be facilitated by the Combined Joint All-Domain Command and Control (CJADC2) system. The Next Generation Command and Control initiative commence in 2024 as an army-directed experiment under leadership of the Army Futures Command. Put simply, the command ensures the army remains at the leading edge of technological innovation for the benefit of the manoeuvre force. A key design feature of the NGC2 is that it will use open and modular architectures “comprised of command and control data, software systems and applications, as well as the underlying network, transport and infrastructure solutions” Colonel Christopher Anderson, the NGC2’s programme manager at the PEO C3N, told Armada. This open and modular approach will “refine and swap out capabilities in response to changing operational needs, emerging technologies, and deliver solutions that are modular and configurable for commanders.”

End user devices

The NGC2 architecture will overhaul the command and control architectures used by the army’s manoeuvre forces at tactical (battalion and brigade) through to division and corps (operational) levels. At the latest PCC event NGC2 technologies, notably “applications, data infrastructure, software, and hardware such as tablets, end user devices, and mobile communications equipment” was trialled with an armoured battalion, and a brigade and division headquarters. Col. Anderson added that PCC events “provide positive operational feedback on NGC2 to build upon technical insights from earlier experimentation efforts.” These efforts will enable the army “to now move forward with equipping a prototype division” with NGC2 capabilities. From a hardware perspective new devices incorporating edge computing will be delivered as part of the NGC2 suite of capabilities. New edge computing devices and communications will see some dismounted and mounted tactical radios being replaced, where appropriate, with alternatives. However, Col. Anderson emphasises that “(t)he army is not doing away with tactical radios altogether, as we continue to anticipate the need for high assurance (and) assured voice communications at echelon.” One of the alternatives being explored is to employ end user devices like smartphones. These devices can use links like fifth-generation (5G) networking and wifi “to send and receive data, assuming the infrastructure exists to support those capabilities”, Col. Anderson notes.

Hybrid procurement

Plans are afoot to deliver the architecture using initial contracts what will take a hybrid approach “to enable competition for best-of-breed solutions throughout the NGC2 ‘technology stack’ with continuous opportunities for competition,” Col. Anderson stated. The hybrid procurement approach “will allow the government to on-ramp and off-ramp capabilities for best of breed capability (for) the NGC2 ecosystem.” Crucially, the procurement approach being taken vis-à-vis NGC2 will look beyond the traditional defence supplier base to acquire civilian, or dual use, technology applicable to the architecture. The approach will also eliminate the use of single-vendor, multi-year contracts Col. Anderson continues: “No one company can provide a complete solution for NGC2, and the government intends to continue to competitively onboard vendor teams for additional components and architecture layers that will be available after the initial prototyping awards.” NGC2 capabilities will be delivered as they are acquired with operational units. There is unlikely to be a ‘big bang’ moment when NGC2 will reach an initial/full operational capability. Instead, capabilities will be introduced in an iterative fashion. (Source: Armada)

 

10 Jul 25. July Radio Roundup. The Colombian Navy’s new Plataforma Estratégica de Superficie (Strategic Surface Platform) frigates will be outfitted with EID’s OeanNEX command and control system, and the company’s ICCS7 communications architecture. Armada’s monthly roundup of all the latest news in the military communications product, programme and operational domains.

New Colombian Navy Communications

In May EID announced that it had won a contract to equip surface combatants of the Armada Nacional de la República de Colombia (Colombian Navy) with the company’s communications, and Command and Control (C2) systems. The Colombian Navy is acquiring five Plataforma Estratégica de Superficie (Strategic Surface Platform) frigates. Gregory Flippes, EID’s commercial and marketing director, told Armada that the first of these vessels should enter Colombian naval service in 2030. The core of EID’s provision is built around the company’s OceaNEX C2 and ICCS7 communications systems. The systems “will be adapted to meet the specific requirements of the Colombian Navy.” He continued that “the latest generation of the (ICCS7) allows for seamless communication across all onboard and external systems, with strong resilience and maintainability.” Design features include advanced cybersecurity, and a full internet protocol architecture, “using standard, open technologies for integration and interoperability.” Both systems are reconfigurable and employ modular, scalable designs Mr. Flippes continued.

Magnetic Personality

Leidos has revealed that its MagNav navigation system is currently undergoing flight testing. MagNav uses quantum sensing to provide a navigation alternative to Global Navigation Satellite System (GNSS) Position, Navigation and Timing (PNT) reliance. The company told Armada that the goal of the programme is to “demonstrate a prototype MagNav solution on a variety of platforms by the end of a (two-year) period of performance.” Leidos’ statement continued that the MagNav architecture uses “commercial advances in COTS (Commercial Off-The-Shelf) quantum magnetometers.” Leidos expects that the commercialisation of MagNav, and its integral sensor technology, “will take additional time since different applications have different requirements.” MagNav depends on an accurate magnetometer and dedicated software. The system’s hardware includes the sensor head, support electronics and a computer to host the MagNav software. It is this software that produces position, velocity and altitude outputs. These components can be installed within a platform in such a fashion as to meet size, weight, power and magnetic isolation requirements. Potential applications for the technology include inhabited and uninhabited aircraft and munitions. Furthermore, the “technology is well suited for any (military and/or civilian) flight platforms that may be vulnerable to (GNSS) outages.”

NSA Certification for Wave Relay

In June Persistent Systems announced that its Wave Relay tactical communications products have been approved by the United States National Security Agency (NSA) as IP SEC VPN (Internet Protocol Security Virtual Private Network) and MAC SEC (Media Access Control Security) components, according to a press release. When integrated with NSA-approved capability packages, this approval lets the systems handle classified information. This process of approval provides an alternative to the NSA’s Type-1 encryption standard and ensures that Persistent Systems’ products are on the NSA’s Commercial Solutions for Classified (CSFC) component list. The CSFC process complements, and does not replace, NSA Type-1 certification. The company told Armada, via a written statement, that “Wave Relay devices are (now) approved commercial components to protect our nation’s most sensitive data when integrated in accordance with NSA guidelines.” Software modifications to these devices were integral to realising this approval. The statement continued that “(t)he approval applies to actively fielded fifth-generation Wave Relay devices with a no cost software-based upgrade.” (Source: Armada)

 

09 Jul 25. Cuashub.com said today that Silvus strengthens drone comms resilience in EW environments. Silvus Technologies has released a new software update to its StreamCaster radios, introducing enhanced electronic warfare (EW) defense features under the name Spectrum Dominance 2.0. The update is intended to improve the performance of Silvus’ mobile ad hoc networking (MANET) radios in contested and congested radio frequency environments. The upgrade builds on the company’s existing MN-MIMO waveform by introducing two new capabilities: Wake on Wireless and Dual Frequency Link. These join a suite of existing features aimed at Low Probability of Intercept/Detection (LPI/LPD), anti-jam protection and threat mitigation. According to the company, the new version is available via firmware update for existing StreamCaster AN/PRC-169 radios, enabling previously deployed systems to receive the enhancements without new hardware. The radios are used in handheld, vehicle-mounted and OEM-integrated configurations by U.S. and allied forces. Silvus describes the update as a “layered EW defense” system, offering modular options that can be activated individually or as part of a broader spectrum defense configuration. This approach is designed to maintain secure, high-throughput communications during attempts to disrupt radio signals, such as jamming or spoofing. While no operational or customer data was provided, the company emphasized that the release continues its focus on scalable, field-upgradable tactical communication systems capable of operating in high-threat environments. Silvus is a U.S.-based company that develops tactical wireless communication systems, including mesh networking technologies used in military, public safety and industrial applications. https://cuashub.com/en/content/silvus-strengthens-drone-comms-resilience-in-ew-environments/ (Source: https://cuashub.com/)

 

08 Jul 25. Savox and Insta Launch Collaboration – Aiming to Develop Integrated Audio and Vehicle Solutions. Savox Communications and Insta and have signed an agreement to combine their top-tier technologies and expertise in developing and delivering advanced defence and security solutions. The collaboration will be officially announced at the international DSEI 2025 exhibition in London, taking place from 9-12 September. The collaboration leverages Savox’s position as a leading provider of mission-critical communication solutions and technology company Insta’s strong capabilities in networked defence solutions and system integration. Together, the companies aim to develop more comprehensive, integrated, and interoperable solutions tailored for the demanding needs of defence and public safety operators – with a particular focus on integrated audio and vehicle environments, where real-time situational awareness, connectivity, and compatibility are critical.

– Collaborating with Insta supports our strategy to strengthen our offering with holistic solutions that enhance operational effectiveness and situational awareness in challenging conditions, says Jerry Kettunen, CEO of Savox Communications.

– Savox’s technological know-how perfectly complements Insta’s system development capabilities. As experts in the state-of-the-art technology, we highly value collaboration to provide purposeful products and solutions. We see strong growth potential both in Finland and on the international market, says Ville Kettula, Vice President of Insta ILS Oy.

The joint solution will be showcased at the DSEI 2025 exhibition in London this September.

For more information about Savox, visit: www.savox.com

About Savox:

Savox Communications designs and manufactures advanced, rugged and robust hearing protection and communication solutions for the most demanding conditions. Headquartered in Finland, our worldwide network, distributors and agents deliver mission-critical systems for defense, fire and rescue, law enforcement, and industrial sectors across global markets. Over 40 years of experience in the industry and our agile and highly advanced R&D and engineering capability have earned Savox a reputation for superior quality. Our 300 co-workers around the world pride themselves on ensuring the safety and enhancing the operational capability of teams and individuals in challenging conditions where seamless access to voice and information is vital.

About Insta:

Decisive defence technology for the future

Insta is a diversified technology company with in-depth expertise to enable secure and customer-focused solutions for the needs of industry, defence, software development, and cyber security.  We are a reliable partner that develops future security and decisive performance in an ever more rapidly changing, networked world. Insta is also a strategic partner of the Finnish Defence Forces.  Advanced technology allows you to see further, react earlier, and influence more efficiently – on land, sea, and in the air. We use our strong know-how to build defence by integrating systems, developing and maintaining capabilities, enhancing command and control, and creating the real-time situational picture to support decisions.

Continuous movement, experience and responsibility are at the core of our safety culture. In 2024, the net sales of our growing family business was 176,2 m euros and we employed approximately 1,200 people. Insta – Decisive Impact.  Further information: www.insta.fi

 

04 Jul 25. Cyber Update Key points.

  • A new wave of ransomware attacks has underscored the elevated security risks facing the transport and aviation sectors stemming from the ransomware group ‘Scattered Spider.’
  • A ransomware attack against a third-party provider for the Swiss government highlights the long-term security and supply-chain risks facing data-rich sectors (see Sibylline Cyber Daily Analytical Update – 1 July 2025).
  • The increasing overlap between cyber criminal and state-sponsored groups points to the heightened security risks facing global businesses.
  • The likely co-operation between cyber threat groups underscores the increasing security and financial risks facing Latin American financial institutions.
  • New malware (‘NimDoor’) has underscored the security and financial risks facing Web3 and cryptocurrency platforms stemming from North Korean state-sponsored actors (see Sibylline Cyber Daily Analytical Update – 4 July 2025).

Technical analysis of weekly stories

Cyber criminal and state-sponsored cyber threat actor activity is increasingly overlapping. In February, the cyber security company Proofpoint detected several cyber espionage operations that it attributed to the financially motivated threat group ‘TA829’. While it is unclear whether TA829 has any connections to the Russian state, the group has conducted cyber espionage operations against Ukraine since the onset of the war in that country in February 2022. However, TA829 reportedly acquires services and infrastructure from the cyber criminal underworld and typically employs tactics associated with cyber criminal activity, which likely enhances detection evasion and complicates attribution efforts. The group uses compromised MikroTik routers to relay malicious traffic via mail providers and to distribute phishing emails. These emails aim to trick victims into clicking on a malicious link embedded in the email and/or a PDF attachment. The link redirects users to a fake online storage platform emulating Google Drive and/or OneDrive and contains an executable that (if downloaded) initiates the infection chain. This deploys two malware loaders (‘RustyClaw’ and ‘MeltingClaw’) and subsequently two backdoors (‘DustyHammock’ and ‘SingleCamper’).

DustyHammock was previously employed in campaigns solely for cyber criminal purposes, while SingleCamper was used as an espionage-first tool. However, TA829 has started employing the payloads interchangeably in cyber criminal and espionage operations, further exacerbating attribution difficulties. Both malware variants are likely managed via a unified control panel and enable remote command execution as well as system monitoring. In the same month, Proofpoint also uncovered another activity cluster (‘UNK_GreenSec’) that employed similar tactics to TA829 to target organisations in North America (while using different infrastructure and deployment methods). UNK_GreenSec also installed a different backdoor (‘TransferLoader’) to maintain persistence within compromised systems and, in some cases, deploy ransomware. We assess this further showcases the complications stemming from the increasing convergence between cyber criminal operations and state-sponsored activity.

Non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering

Our cyber word(s) of the week: Binary file (Source: Sibylline)

————————————————————————————————————————————————————————————————————————————————————————————————————————————–

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

————————————————————————————————————————————————————————————————————————————————————————————————————————————–

  • « Go to Previous Page
  • Page 1
  • Page 2
  • Page 3
  • Page 4
  • Interim pages omitted …
  • Page 6
  • Go to Next Page »

Primary Sidebar

Advertisers

  • Pythia
  • Teledyne
  • Exensor
  • Visit the Oxley website
  • Blighter
  • SPECTRA
  • Britbots logo
  • Faun Trackway
  • Systematic
  • CISION logo
  • ProTEK logo
  • ProTEK logo
  • ssafa logo
  • IEE
  • EXFOR logo
  • sibylline logo
  • Team Thunder logo
  • Comtech logo
  • GoExporting logo
  • ECHODYNE logo
  • Supercat logo
  • Galvion logo
  • Leonardo DRS logo
  • MTC logo
  • IDC logo
  • DSEI logo
  • DVD2024 logo
  • SDSC logo
  • TELEDYNE FLIR logo
  • VeteranUK logo
  • Matrix Space logo
  • ST Engineering logo
  • EWS logo
  • sentinel photonics logo
  • capua logo
  • Curtiss-Wright logo
  • Brave1 logo
  • Drone Evolution logo
  • AEI Systems logo
  • EOS logo
  • NMSUK logo
  • Openworks logo
  • Sandown Park logo
Hilux UKDSE AARTOS ST Engineering Future Artillery

Contact Us

BATTLESPACE Publications
41 St Georges Drive
London SW1V 4DG

+44 (0)77689 54766

BATTLESPACE Technologies

An international defence electronics news service providing our readers with up to date developments in the defence electronics industry.

Recent News

  • Protek Selected By Dutch Armed Forces

    May 2, 2026
    Read more
  • PARLIAMENTARY QUESTIONS

    May 1, 2026
    Read more
  • MANAGEMENT ON THE MOVE

    May 1, 2026
    Read more

Copyright BATTLESPACE Publications © 2002–2026.

This website uses cookies to improve your experience. If you continue to use the website, we'll assume you're ok with this.   Read More  Accept
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT