Sponsored By Curtiss Wright
https://www.curtisswright.com/
———————————————————————————————————————————————————————————————————————————————————————————————————————————————
22 May 25. Terma announced the launch of Terma SPECTRA, a Software-Defined Radio (SDR) TT&C modem. Developed in collaboration with the European Space Agency (ESA) and built by experts in Electrical Ground Support Equipment (EGSE) and Radio Frequency Special Check-Out Equipment (RF-SCOE), Terma SPECTRA reflects years of hands-on experience, protocol mastery and innovation in real-world space missions. Terma announces the launch of Terma SPECTRA (Software-defined Platform for Enhanced Communication, Telemetry, and Ranging Applications) — a new SDR TT&C modem, a flexible, scalable solution for satellite communication and testing. Powered by SDR technology, the modem combines flexible and cloud-ready architecture, multi-channel support for TX & RX, built-in security by design and native L- and S-Band support to deliver a compact and cost-effective solution for reducing CAPEX and OPEX. Designed to serve ground stations and testing facilities, the modem supports operations from satellite modem verification to satellite communications, EGSE/SCOE integration, system-level and end-to-end testing. Its versatility makes it a strong backbone for both operational and testing environments. Built by experts with deep domain knowledge in satellite EGSE and RF-SCOE – and developed in collaboration with ESA – Terma SPECTRA reflects years of hands-on experience, protocol expertise, and innovation in real-world space missions. Its modular design ensures users benefit from easy upgrade paths, keeping the software ready for future mission needs while being cost effective. Among its standout capabilities are CCSDS-compliant TM/TC processing, multi-channel support for transmission and reception, and a compact, cost-effective footprint. An intuitive and multi-functional user interface ensures it is easy to use, while a secure and fail-safe design gives you the security and reliability that you need.
“Terma SPECTRA is a game-changer in communication, offering unparalleled flexibility with its distributed architecture, parallel processing capabilities, and cloud-readiness. By supporting industry standards and enabling scalable, multi-mission operations, it provides customers with the reliability, flexibility, and efficiency needed to tackle the most demanding environments,” says Günther F. Lackner, Senior Vice President at Terma Space.
With its future-proof architecture, Terma SPECTRA overcomes the limitations of traditional hardware-based RF systems, empowering ground stations to operate more efficiently and respond more rapidly to evolving mission requirements.
21 May 25. Global: Ransomware attacks will sustain elevated security risks for businesses in medium term. Earlier on 21 May, international news outlets reported that the threat group ‘Scattered Spider’ targeted the financial sector via ransomware attacks before April. This preceded three consecutive cyber attacks against high-profile UK retailers (Marks & Spencer, The Co-operative Group and Harrods) between April and early May, highlighting the group’s wide target pool. These attacks resulted in the exfiltration of customer data and significant operational disruption, as well as long-term reputational and financial damage for the targeted retailers. On 14 May, the technology company Google also warned that Scattered Spider had started to target retailers in the US, underscoring the rapid propagation of its operations. The group reportedly often switches targeted sectors depending on the skillset of its current members; we assess this will sustain elevated security risks for global businesses in the medium term given the momentum and rapidity of Scattered Spider’s recent attacks. (Source: Sibylline)
21 May 25. Nokia 5G tech supports defence ops at Joint Viking 2025. During the trials, capabilities of the 5G technology helped improve situational awareness and collaboration. Finnish telecommunications company Nokia has conducted trials of its 5G technology within the context of Joint Viking 2025 military exercise in northern Norway. The test was carried out in collaboration with various industry entities and aimed at demonstrating the role of 5G in a defence setting. During the trial, Nokia deployed its 5G AirScale radio products and 5G Standalone Core technology, which had been tailored for defence applications. These tools were used to support tactical communication and improve information systems across the multinational force. Nokia’s 5G communications platform enabled military units to access real-time battlefield data. This capability supported quicker decision-making and bolstered situational awareness. The command-and-control leadership of Joint Viking used the technology to coordinate operations more effectively, enhancing both safety and operational efficiency. Norway’s Ministry of Defense liaison for 5G COMPAD programme and radio architect Kennet Nomeland said: “We collaborate with the industry to develop innovative defence solutions based on commercial technologies. (Source: army-technology.com)
21 May 25. Rubrik (NYSE: RBRK), a leading cyber resilience company, and Rackspace Technology (NASDAQ: RXT), a leading end-to-end hybrid cloud and AI solutions company, have announced Rackspace Cyber Recovery Service – a new managed service for customers operating in public cloud. By combining Rubrik’s orchestrated data protection and cyber recovery solutions with Rackspace’s DevOps principles and managed services, enterprises can simplify and accelerate recovery from ransomware attacks. Automated workflows deliver clean data and workloads through immutable backups, zero-trust architecture and Infrastructure as Code. With Rackspace Cyber Recovery Service, critical business workloads running in public clouds can be restored in hours, helping enterprises significantly strengthen their cyber resilience.
Why does this matter?
Organizations running key workloads in public clouds face growing challenges when responding to cyber attacks – from limited visibility and inconsistent backup policies to slow recovery times and lack of automation to rebuild at scale. At the same time, IT leaders are grappling with increasingly complex and distributed cloud environments, making it difficult to maintain consistency, ensure visibility and execute reliable recovery. Recently, Rubrik Zero Labs revealed that 90% of global IT and security executives reported cyber attacks in the last year. In the event of major disruptions – such as ransomware attacks – many enterprises struggle to restore critical workloads quickly due to fragmented tooling, manual processes, untrusted data and inadequate automation.
“Enterprises can no longer rely on traditional recovery methods in a cloud-first, threat-intensified world,” said DK Sinha, President for Public Cloud at Rackspace Technology. “To ensure recoverability in the public cloud, they must adopt a new approach that leverages cloud native tools, modern DevOps methodologies and trusted expertise. Through our partnership with Rubrik, Rackspace Cyber Recovery Service sets a new standard for cyber resilience of public cloud workloads.”
Rackspace Cyber Recovery Service Extends Fast and Confident Cyber Resilience to Public Cloud
Rackspace Cyber Recovery Service applies Infrastructure as Code and platform engineering principles to cyber recovery, enabling restoration of critical workloads across multi-cloud environments. The journey begins with a professional services-led transformation, where Rackspace experts modernize recovery architectures and codify resilient workflows tailored to each environment. These capabilities are then transitioned into a ‘Day 2’ fully managed service, ensuring continuous validation, optimization and operational readiness. By orchestrating Recovery as Code, the solution delivers rapid, repeatable and auditable workflows aligned with modern DevOps practices. Paired with Rubrik’s immutable architecture and AI-driven threat detection and containment, it ensures clean data recovery into secure landing zones with minimal operational disruption.
“Amidst the evolving complexities of multiple cloud environments, proactive cyber resilience is not a luxury but a necessity. Together, Rackspace and Rubrik offer a differentiated, engineering-led approach to cyber resilience,” said Ghazal Asif, Vice President of Global Channels and Alliances at Rubrik. “Specifically designed for complex, distributed cloud environments, our companies are at the forefront of safeguarding organizations against the rising tide of ransomware attacks in the realm of cloud and SaaS platforms.”
Rackspace Cyber Recovery Service provides enterprises running public cloud workloads with:
- Proactive Protection: Continuous anomaly detection and threat monitoring to identify and resolve potential issues before they impact backups or recovery capabilities
- Expert Management: Optimal backup configuration, policy and lifecycle management
- Cloud Management: Infrastructure management services to ensure your applications are managed efficiently in the cloud while infrastructure and data restoration procedures are tested for recovery during incidents or disasters
- Improved Compliance: The ability to support data retention policies and regulatory requirements with consistent management and detailed reporting
- Advisory & Professional Services: Strategic guidance and implementation of Rubrik-powered cyber recovery solutions – including RTO/RPO planning, regulatory alignment and deployment of automated Infrastructure as Code workflows into secure landing zones
About Rackspace Technology
Rackspace Technology is a leading end-to-end, hybrid, and AI solutions company. We can design, build, and operate our customers’ cloud environments across all major technology platforms, irrespective of technology stack or deployment model. We partner with our customers at every stage of their cloud journey, enabling them to modernize applications, build new products, and adopt innovative technologies.
About Rubrik
Rubrik (NYSE: RBRK) is on a mission to secure the world’s data. With Zero Trust Data Security™, we help organizations achieve business resilience against cyberattacks, malicious insiders, and operational disruptions. Rubrik Security Cloud, powered by machine learning, secures data across enterprise, cloud, and SaaS applications. We help organizations uphold data integrity, deliver data availability that withstands adverse conditions, continuously monitor data risks and threats, and restore businesses with their data when infrastructure is attacked.
21 May 25. Roke, a UK company that stands at the forefront of defence and security, and Kaigai Corporation have announced an expansion of their strategic partnership, significantly increasing the availability of Roke’s cutting-edge products and services to the Japanese market. Building on a successful foundation of cooperation, the expanded agreement will see a broader portfolio of Roke’s advanced solutions—including Electromagnetic Warfare (EW) systems, Resilient Position Navigation and Timing (RPNT), Cyber, AI-enabled surveillance technologies, and secure communications platforms—offered through the Japanese defence contractor’s extensive defence and security network in the country. The new enhanced partnership reinforces both companies’ commitment to advancing national security and technological innovation in the region.
Paul MacGregor, MD of Roke, said: “Japan represents a key strategic market for Roke, and this partnership allows us to deliver greater value to Japanese defence and security stakeholders through localised support and expanded access to our technologies. This announcement comes at a time of increasing demand for advanced defence technologies in the Asia-Pacific region, and underscores both companies’ dedication to supporting the evolving needs of allied nations. This partnership marks a pivotal step in our mission to bring world-class defence technologies to Japan,” said Masayoshi Yamazaki, President of Kaigai Corporation. “Roke’s proven expertise and innovative capabilities align perfectly with our vision for a safer, more secure future.”
The expanded partnership will also include knowledge exchange programs and enhanced technical support to ensure seamless integration of Roke’s solutions into Japan’s defence infrastructure.
20 May 25. Global: State-sponsored cyber attacks showcase long-term security risks amid global tensions. On 19 May, the software company ESET reported that threat groups aligned with China, Iran, North Korea and Russia continued to consistently use cyber operations to achieve their strategic objectives between October 2024 and March. China-nexus groups focused on cyber espionage operations primarily against the governmental and transportation sectors in Europe. These groups often exploited third-party virtual private network (VPN) services to infiltrate targeted systems, underscoring the security risks associated with the software supply chain. Groups aligned with North Korea honed in on financially motivated cyber operations against the financial services and cryptocurrency sectors. These groups aimed to combat ongoing economic sanctions and bolster Pyongyang’s weapons programme. Iran- and Russia-nexus groups continued to target Israeli and Ukrainian organisations amid ongoing regional wars; Russia is notably shifting towards a more methodical and less destructive cyber strategy against Ukraine. As such, we assess that this report indicates sustained security risks to perceived adversarial entities amid ongoing geopolitical tensions. (Source: Sibylline)
20 May 25. Quadsat, expert in UAV-based RF testing and measurement, has entered a strategic collaboration with Skyeton, a Ukrainian manufacturer of unmanned aerial systems (UAS) to deliver solutions for monitoring the electromagnetic spectrum. Together the companies are supporting electromagnetic warfare operations, enhancing situational awareness, and strengthening threat response in contested electromagnetic environments. The partnership combines Skyeton’s fixed-wing UAS platform, Raybird, known for its battlefield-proven performance in Ukraine, with Quadsat’s industry-validated radio frequency (RF) payload and spectrum monitoring technology. Raybird has proven an unmatched endurance and exceptional resilience, making it a natural choice for gathering battlefield intelligence. Quadsat’s test and measurement solutions are relied upon by many of the world’s leading satellite companies to ensure a high level of equipment performance. The joint solution offers a highly effective, scalable, and tactically agile solution for acquiring real-time electromagnetic spectrum intelligence. It expands Skyeton’s portfolio of mission-ready systems with advanced capabilities for spectrum monitoring and RF emitter detection in complex operational environments.
Klaus Aude, Chief Commercial Officer, Quadsat, commented: “By combining our robust RF payload with Skyeton’s battle-proven UAS, we are able to bring a powerful new solution to the electromagnetic warfare space. The fact that Raybird has exceptional endurance, with up to 28 hours of flight time, while being easy and rapid to deploy, makes it especially practical for defense applications. Quadsat’s technology is platform-agnostic, and our integration with fixed-wing systems is a clear demonstration of that.”
Pavlo Shevchuk, International CEO of Skyeton: “This partnership marks a significant step forward in expanding the capabilities of our Raybird UAS. By integrating Quadsat’s cutting-edge RF technology, we are equipping our platform with an advanced spectrum monitoring tool that is essential for modern operational environments. It’s a natural evolution of our mission to deliver high-endurance, mission-ready systems that provide actionable intelligence when and where it matters most”.
Quadsat and Skyeton will co-exhibit and perform a joint demonstration flight at the International Drone Show 2025 in Denmark from 18th–19th June. The demo will feature Skyeton’s Raybird UAS carrying Quadsat’s RF payload, showcasing real-time spectrum monitoring and RF target detection capabilities.
19 May 25. Global: New malware underscores elevated security risks posed by ransomware groups. On 16 May, international news outlets reported that ransomware groups are deploying a new backdoor (‘Skitnet’) during attacks on an increased basis to conduct post-exploitation activities. Threat actors typically use a first-stage malware loader to execute Skitnet within a compromised system’s memory, leveraging several highly obfuscated techniques to evade traditional security measures. The malware then connects to command-and-control (C2) infrastructure, initiating three separate channels of communication to facilitate command execution, data exfiltration and monitoring activities. Skitnet can execute PowerShell scripts for enhanced attack customisation, allowing it to download remote access tools and perform persistence tasks. This likely enables threat actors to retain prolonged control over compromised systems, pointing to the longevity of infections. The malware can be purchased online, allowing threat actors to quickly upscale and streamline cyber operations. Skitnet has already been used in ransomware attacks by well-known groups (such as ‘BlackBasta’ and ‘Cactus’), highlighting the elevated security risks associated with the continuous evolution of ransomware enterprises. (Source: Sibylline)
18 May 25. Royal Air Force introduces StormShroud with Leonardo’s BriteStorm electronic warfare payload. The Royal Air Force (RAF) has unveiled its new ‘StormShroud’ autonomous collaborative platforms (ACPs), equipped with BriteStorm, Leonardo’s latest electronic warfare payload. This cutting-edge system aims to confuse and suppress enemy radars during air combat missions, offering a strategic advantage against advanced air defence systems. BriteStorm, described as a ‘stand-in jammer’, is designed to operate ahead of high-value crewed combat aircraft, using small uncrewed aircraft or missiles. It disrupts enemy Integrated Air Defence Systems (IADS) by employing high-powered digital jamming and deception techniques, maximising operational freedom for friendly forces.
“BriteStorm counters the threats of today and tomorrow,” said a Leonardo spokesperson. The payload’s adaptability is enhanced by its open software approach, allowing operators to configure it against a wide range of evolving threats, using intelligence gathered during missions.
The system consists of a Miniature Techniques Generator (MTG) and Transmit Receive Modules (TRMs), which are lightweight and energy-efficient. This makes BriteStorm adaptable to various uncrewed aircraft, including the Tekever AR3 small Uncrewed Air Systems (UAS), which will enter RAF service under the StormShroud name. BriteStorm’s design reflects lessons learned from recent operations, emphasising its attritable nature. While it can be rapidly reprogrammed and redeployed after a mission, the system’s loss in defence of higher-value platforms would be considered acceptable. Research and development of BriteStorm began in 2017 at Leonardo’s Luton site, Europe’s leading hub for electronic warfare technology. The facility, employing over 1,200 people, invested nearly £175 m with British suppliers in 2024, contributing significantly to the UK’s defence industrial combat air enterprise. StormShroud itself has been developed by the Royal Air Force Rapid Capabilities Office (RCO) and the Catalyst team in Defence Equipment & Support (DE&S). It will be operated by both regular and reserve personnel from 216 Squadron, with ongoing support from Leonardo and other industry partners. (Source: DIE)
16 May 25. Cyber Update Key points.
- A new information-stealing malware (‘Noodlophile’) abuses generative artificial intelligence (AI) tools, elevating information-theft and financial risks to global users (see Sibylline Cyber Daily Analytical Update – 12 May 2025).
- A multi-stage cyber operation highlights long-term security risks posed by the China-nexus group ‘Earth Ammit’ towards high-value targets in Taiwan and South Korea (see Sibylline Cyber Daily Analytical Update – 13 May 2025).
- Multiple cyber operations against Ukrainian government entities underscore elevated cyber espionage risks from the North Korean state-sponsored group ‘Konni’.
- A new, highly advanced information-stealing malware (‘Chihuahua’) highlights heightened data-theft and financial risks to global users.
- A suspected Russian state-sponsored cyber operation (‘RoundPress’) highlights long-term cyber espionage risks exacerbated by the exploitation of software vulnerabilities
A new, highly advanced information-stealing malware (Chihuahua) is being used to target global users in an ongoing data-theft operation. Threat actors likely use social engineering techniques to trick victims into opening a Google Drive document. The document reportedly contains a PowerShell script that initiates a highly obfuscated, multi-stage infection process. Namely, the script installs a malware loader that deploys the Chihuahua payload into a system’s memory, after establishing communication with command-and-control (C2) infrastructure. The payload is hidden within a PowerShell string (a sequence of characters) and is dynamically decoded and re-constructed to evade signature-based detection, highlighting the sophistication of Chihuahua’s obfuscation capabilities. Chihuahua then gathers system information, assigning encrypted victim identifiers to each system to facilitate data exfiltration and storage. The malware extracts sensitive data from web browsers (including autofill data, browsing history, cookies, credentials and payment information) as well as cryptocurrency wallets, likely to hijack user accounts for financial profit. Chihuahua then uses file and directory deletion commands to erase logs and evade detection.
Threat actors exploited several zero-day and pre-existing cross-site scripting (XSS) vulnerabilities (affecting several high-profile email providers) to conduct a cyber espionage operation (RoundPress) between 2023 and 2024. RoundPress targeted government entities, defence companies and national infrastructure across Africa, Eastern Europe and Latin America and was likely carried out by the Russian state-sponsored group ‘APT28’. Threat actors used spear-phishing emails concerning current political events as initial attack vectors to trick victims into opening the email in a web browser. The emails then exploited the vulnerabilities to execute malicious code hidden within the email body without requiring any additional user interaction. This then established communication with C2 infrastructure and installed a JavaScript payload (‘SpyPress’) to exfiltrate sensitive information, including authentication data, credentials and login history. The operation did not display any sophisticated persistence mechanism, though the malicious code is re-loaded every time victims open the phishing email. Threat actors exploited both newly identified and old vulnerabilities, highlighting the importance of timely patch management policies to prevent exploitation.
Non-exhaustive recommendations to mitigate against these threats include:
- Monitor devices and networks for suspicious activity
- Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware
- Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
- Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering
Our cyber word(s) of the week: Cross-site scripting (XSS) (Source: Sibylline)
16 May 25. Global: Exploitation of vulnerabilities highlights long-term espionage risks facing critical sectors. On 15 May, the cyber security company ESET reported that threat actors exploited cross-site scripting (XSS) vulnerabilities (affecting high-profile email providers) to conduct a cyber espionage operation (‘RoundPress’) between 2023 and 2024. The operation targeted government entities, defence companies and national infrastructure across Africa, Eastern Europe and Latin America; it was likely carried out by the Russian state-sponsored group ‘APT28’. Threat actors distributed spear phishing emails to victims so that they could infiltrate targeted systems. When the victims opened the emails, software vulnerabilities were exploited so as to execute malicious code (hidden within the email body); this did not require any additional user interaction. Communication was consequently established with command-and-control (C2) infrastructure, automating the exfiltration of sensitive information. Software vulnerabilities continue to provide state-sponsored groups with an effective access and remote execution vector into high-value sectors; as such, we assess this highlights the long-term cyber espionage risks stemming from Russian state-sponsored actors facing the aforementioned sectors. (Source: Sibylline)
16 May 25. DOD Leaders Urge Congress to Bolster Cyberdefenses. Defense Department leaders delivered a stark warning about adversaries exploiting cyberspace and threatening national security during a House Armed Services Committee cyber, information technologies and innovation subcommittee hearing in Washington today. Laurie Buckhout, performing the duties of assistant secretary of defense for cyber policy, and Army Lt. Gen. William Hartman, acting commander of U.S. Cyber Command, called for heightened strategic focus, cutting-edge innovation and a world-class workforce to counter sophisticated cyberthreats.
“Adversaries transform cyberspace — a domain powering global connectivity, communications and innovation — into a contested battlespace,” Buckhout said.
With over 40 years of experience in communications, intelligence and cyberoperations, Buckhout spotlighted the alarming rise of Chinese state-sponsored actors like Volt Typhoon. She said the group infiltrates critical infrastructure, including power grids, water systems and telecommunications networks, using stealthy “living off the land” tactics that exploit legitimate tools to evade detection.
“Volt Typhoon’s actions expose the urgent need for relentless vigilance and advanced countermeasures,” she said, citing its potential to disrupt essential services or enable espionage.
Her warning aligns with a 2024 Cybersecurity and Infrastructure Security Agency advisory, which revealed Volt Typhoon’s deep penetration of infrastructure sectors, posing a “significant risk” to national security.
Buckhout also flagged Russia’s integration of cyberoperations with geopolitical aims, Iran’s persistent malicious activities and North Korea’s ransomware campaigns. She noted that transnational criminal organizations further increase the threat, targeting infrastructure with profit-driven cyberattacks.
Defense Secretary Pete Hegseth’s vision for cyberdominance underpins Buckhout’s call to action.
“We’re pushing real-time inclusion of cyber — offense and defense — into planning cycles to leverage it fully,” he said during an address at the U.S. Naval Academy in April. “In a world where cyber and space dominance will determine future battlefields, if we do it right … it should be our comparative advantage.”
His directive drives the department’s push to align resources with the most lethal and effective capabilities, prioritizing homeland defense against near-peer competitors like China.
Cybercom’s Daily Battle
Hartman painted a vivid picture of Cybercom’s relentless engagement.
“We fight cyberwarfare every day, defending the nation, securing DOD networks and empowering the joint force,” he said.
In 2024, Cybercom executed over 6,000 operations — a 25% surge from 2023 — targeting malicious actors worldwide. “Our operations grow in scale, speed and complexity,” he told lawmakers, projecting even greater activity this year.
Hartman highlighted the command’s collaboration with the National Security Agency to optimize resources and technical expertise. He cited a congressionally mandated artificial intelligence roadmap, which fuels pilot programs to enhance operational efficiency.
“AI transforms how we analyze threats and deploy capabilities,” Hartman said, aligning with President Donald J. Trump’s emphasis on AI as a cornerstone of cybersecurity superiority.
Refining Cybercom 2.0
Buckhout addressed the ongoing evolution of Cybercom 2.0, an initiative inherited from the prior administration to streamline workforce management, training and innovation.
“We value Cybercom 2.0’s foundation but recognize its shortcomings,” she said. The current administration is conducting a comprehensive review to align the program with evolving threats.
“We view cyberspace as mission-critical and we’re committed to delivering a refined strategy,” Buckhout told the committee.
After lawmakers pressed for clarity on Cybercom 2.0’s future structure, Hartman revealed that Cybercom favors a model similar to U.S. Special Operations Command, where a unified command oversees training and force development while geographic combatant commanders retain operational control.
“This model balances efficiency with flexibility,” Hartman explained.
Workforce Challenges in a Competitive Landscape
Hartman said building a world-class cyber workforce remains a top priority, but intense competition with the private sector complicates recruitment and retention. He added that strong retention in specialized roles — interactive on-net operators, exploitation analysts and coders — is driven by the unique allure of national security missions.
“We offer opportunities no tech company can match,” he said. However, Cybercom is struggling to attract broader talent, such as linguists, intelligence analysts and planners essential for comprehensive cyberoperations.
Hartman said the current hiring freeze and workforce reductions threaten to increase these challenges, noting that 5 to 8% of the command’s workforce accepted voluntary separation offers.
“Our junior leaders will step up, but the loss is significant,” he said.
Mental health support for cyberoperators facing chronic stressors emerged as a concern during the hearing. Lawmakers cited a congressional report targeting inadequate mental health resources for cyberpersonnel.
Hartman explained that Cybercom hired its first psychologist in 2025 and is actively seeking additional specialists to combat the issue. (Source: U.S. DoD)
15 May 25. US Army may halve planned HADES buy from 12 to 6 new spy planes.
“This is very early in the process. My guidance, to my staff, is nobody really overreact to this global transformation. We must transform,” said ISR Task Force Director Andrew Evans.
AAAA 2025 — The US Army will potentially pare its fleet of High Accuracy Detection and Exploitation System (HADES) aircraft in half as part of a larger acquisition shakeup, according to an EXORD obtained by Breaking Defense and confirmed by service officials.
Earlier this month, the service began releasing details about force structure changes and weapons cuts as part of its Army’s Transformation Initiative (ATI), and an executive order from Army leadership dated May 7 details additional cuts, including cutting the HADES fleet from 12 aircraft down to six.
“This is very early in the process,” ISR Task Force Director Andrew Evans told reporters today. “My guidance, to my staff, is nobody really overreact to this global transformation. We must transform … and we’re all in on supporting the Army’s effort to do this.”
Col. Joe Minor, the project manager for fixed-wing aircraft, said that since the plan was always to produce a small number of HADES that are essentially “hand-built,” he does not expect the overall cost of the program to soar if the buy is halved.
Last year, the Sierra Nevada Corporation (SNC) won an Army contract to integrate a suite of capabilities onto the Bombardier Global 6500 jet under the HADES program. The service wants to have an initial aircraft ready for the force by the end of 2026 or early 2027 and had planned to acquire more than a dozen aircraft under a one-per-year buy, depending on budgets and the threat analysis.
Then on Wednesday, at the Army Aviation Association of America’s annual conference in Nashville, Tenn., Laurence Mixon — with the Program Executive Office for Intelligence, Electronic Warfare and Sensors — told reporters that there would likely be several changes to his team’s portfolio while Evans hinted at today’s HADES announcement.
“There’s nothing … that we can say specifically on a specific program that’s going away or changing,” Mixon told reporters. “But I will tell you, there is no longer an appetite to reinforce failure.”
The key question for HADES, Evans added, will be how many systems the service ultimately acquires.
“It will not be whether we require it at all … until warfighters cease their demand for ISR,” Evans said. (Source: Breaking Defense.com)
—————————————————————————————————————————————————————————————————————————————————————————————————————————————
Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.
We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.
Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.
——————————————————————————————————————————————————————————————————————————————————————————————————————————————–

