Sponsored By Curtiss Wright
https://www.curtisswright.com/
———————————————————————————————————————————————————————————————————————————————————————————————————————————————–
11 Jun 25. Spectra Group, a specialist provider of secure voice, data and satellite communications systems, is unveiling its new Troposcatter on the Move (TOTM) capability at Indo Defence and will be showcasing this and their other strategic communication capabilities in Booth D167f at Jakarta International Expo, June 11-14th 2025. Asia Pacific nations face unique challenges in achieving seamless connectivity across vast island chains and coastal territories. TOTM, engineered with Spectra’s signature expertise in advanced troposcatter technology, delivers robust, secure, high-bandwidth data communications between ship-to-shore and ship-to-ship — even while on the move. Unlike satellite-based systems, TOTM operates independently of GPS and offers a critical advantage in contested or denied environments marking a significant leap forward in mobile, high-bandwidth data communications for the Asia Pacific region’s maritime and archipelagic requirements. Spectra Group has been working in partnership with Comtech and BATS Wireless antennas throughout 2024 to develop the TOTM concept, for which, as the systems integrator Spectra Group has full distribution rights. Comtech and Spectra Group recognised the need for increased manoeuvre and large network data on the move, and so, working together with BATS wireless proved the concept of TOTM. Subsequently, Spectra Group working in partnership with BATS Wireless has produced a fully integrated TOTM solution that combines Comtech’s COMET troposcatter with BATS Electronically Steered Antennas (ESAs) into a single fully integrated terminal to deliver an industry first capability. Extensive sea trials successfully tested and validated TOTM scenarios by simulating island hopping in the Florida Keys, Florida Panhandle and off the coast of California. The tests involved ship to shore and ship to ship scenarios proving the concept of TOTM by demonstrating systems tracking and communicating with other nodes while on the move using GPS, but also showcasing the potential for advanced mobile connectivity in challenging environments without reliance on GPS. TOTM enhances the utility and operational effectiveness of COMET in a littoral manoeuvre context, especially in contested, GPS or satellite denied environments. Its mobility and capacity delivers band-widths of up to 210 Mbps and ranges in excess of 100 Km to support a wide range of mobile applications such as Ship to Ship or Ship to Shore communications, Beyond Line of Sight strategic communications or Wide Area Networks, secure data links for autonomous sensors, control of remote vessels, Intelligence Surveillance and Reconnaissance (ISR) and any other application that requires big data delivered to the front line. The TOTM solution can also be utilized with land vehicles for efficient “at the pause” applications, enabling users to quickly establish Troposcatter communications without having to set up and align antennas, allowing rapid data transmission from positions of opportunity.
Simon Davies, CEO of Spectra Group said: “TOTM’s launch in Asia Pacific couldn’t be more timely, with increasing demands for rapid, resilient connectivity across archipelagic states, TOTM provides a decisive edge in high-mobility scenarios. TOTM is about ensuring command and control even in the most challenging maritime environments.”
12 Jun 25. Viasat developing wearable MOJO Mini variant. Satellite communications (satcom) provider Viasat is developing a wearable variant of its Move Out/Jump Off (MOJO) Mini tactical satcom gateway, with programme officials working to mature the yet-to-be released prototype system, Janes has learnt. Programme engineers at Viasat have designed the wearable MOJO Mini prototype, along with a vest-based mounting system with integrated computing and power management capability, and this is ready for demonstration, said David Schmolke, vice-president of Mission Connections and Cybersecurity at Viasat.
“We even integrated high assurance encryption capability” he said of the wearable prototype satcom gateway system, dubbed the Secure Wireless Hub (SWH), during a June interview with Janes.
On the compute side, the new SWH prototype “can host a lot of the functionality of that common operational picture (COP) integration” and intermesh that functionality with the data from the tactical satcom radios the user is already equipped with, Schmolke said.
“They are already carrying a Link 16-enabled radio, or something along those lines … they can high-end their existing [tactical] radio ecosystem” and have COP data integrated into that ecosystem, via the MOJO Mini prototype, he added.
If applicable, the prototype can also incorporate the user’s Android Team Awareness Kit (ATAK) application for an additional layer of mobile, cellular data into the ecosystem, he said. The wearable variant “is not formally on the market yet, but its sort of like at [technology readiness level] 6 or 7 capability”, according to Schmolke. (Source: Janes)
12 Jun 25. Network to Deter. Perhaps not receiving the coverage it should, but there’s good news from Taiwan’s Ministry of National Defence. In early May, it announced that the country’s Field Information Communications System (FICS) had completed testing in the United States. Few details exist in the public domain, but it is understood that FICS is an operational and tactical level communications, and Command and Control (C2), system. Reports have stated that deliveries of the system will commence by the end of 2025. FICS was procured in 2020 as a replacement for the Taiwanese Army’s existing Tactical Area Communications System. Taiwan’s Chungshan Institute of Science and Technology is responsible for implementing the system and has worked closely with the United States Army in this endeavour. As an internet protocol-dependent system, robust cybersecurity has been a sine qua non for FICS from the outset. The introduction of the new system comes at a time of deepening tensions between Taiwan and the People’s Republic of China (PRC). The latter regards Taiwan as a renegade province which must be unified with China, by force if necessary. The introduction of the Field Information Communications System represents an important enhancement of the Taiwanese Army’s C2 and communications systems. Sophisticated and survivable C2 and networks are likely to prove themselves vital war-winning weapons during any war between Beijing and Taipei. Enhancing interoperability within and between Taiwan’s armed forces will be key, as will connectivity with Taiwan’s allies. The global disruption that would be caused by an attempted invasion of Taiwan by China would require a global response. Hopefully, Taiwan’s allies like the United States will come to her aid to defend the country against Chinese aggression. Ensuring that similarly robust and survivable connectivity and networking exists outwards to connect Taiwan’s friends and allies will be vitally important. (Source: Armada)
09 Jun 25. Trunk Flunked. This graphic demonstrates the coverage footprint above Russia and eastern Ukraine provided by the Express AMU-1 communications satellite. Recent analysis has revealed that this satellite provides trunk communications for Russian forces occupying parts of Ukraine. Further details have come to light, courtesy of the counteroffensive.pro news service and website, concerning Russian military trunk communications in Ukraine. In an analysis published in April two of counteroffensive.pro’s authors, Oleksandr Matviienko and Zoriana Semenovych, provided some new perspectives on this intriguing subject. A key observation of their analysis was that Russian forces in Ukraine seem to lack dedicated, theatre-wide, operational level communications. Instead, a variety of different systems and networks appear to be employed. A recent Armada article noted that Russian forces are illicitly using the United States’ Ultra High Frequency Follow-On (UFO) military Satellite Communications (SATCOM) constellation. It appears that Russian units can access this network and use it for beyond line-of-sight trunk communications in Ukraine.
Express AMU-1
Counteroffensive.pro’s analysis stated that other capabilities like Russia’s Express AMU-1 satellite support tactical and operational communications. Express AMU-1 was designed and built by EADS Astrium, now part of Airbus’ defence and space subsidiary. The satellite was launched in October 2015 and provides uplink channels using Ka-band frequencies of 29.4 gigahertz/GHz to 30GHz. Downlink is provided on frequencies of 19.2GHz to 20.2GHz. Open sources say the Express AMU-1 SATCOM network ensures data rates of between ten megabits-per-second and 40mbps. Counteroffensive.pro continued that Express AMU-1 provides coverage over eastern Ukraine. Users access Express AMU-1 via an appropriate terminal housing the correct waveform software. This satellite supplements the unauthorised Russian military access to SpaceX’s Starlink SATCOM network which has been documented in the past.
Cellular provision
Beyond SATCOM, the analysis continues that Wi-Fi provides internet access on the battlefield at distances of up to 50 kilometres (31 miles) from the Wi-Fi transmitter. Internet protocol traffic is sent and received via the transmitter which then routes traffic through cables to its intended destination. Likewise, Orlan-10 Uninhabited Aerial Vehicles (UAVs) have been used by Russian land forces as airborne relays. It is known that the Russian Army’s RB-314V Leer-3 electronic warfare system uses Orlan-10 UAVs. These UAVs gather communications intelligence from cellphones and jam these devices. Leer-3 can also disseminate false, demoralising and misleading traffic to cellphones. Suitably equipped Orlan-10s perform this mission by acting as airborne cellphone nodes. It is possible that these nodes can be used to provide an airborne cellphone network as and when required. The UAVs could then connect to terrestrial cellphone networks to move cellular traffic within and without the theatre of operations. Counteroffensive.pro’s analysis adds that Russian forces use the cellular infrastructure present in the parts of Ukraine they currently occupy.
Azarts and Aqueducts
This recent analysis helps fill some important gaps in the existing knowledge of Russian tactical and operational level communications in the Ukraine theatre. It is already known that Russia’s military communications satellite constellations provide operational and strategic connectivity. Russia is though to possess around 40 dedicated military communications satellites. The Cosmos and Meridian constellations are the most numerous. Russian forces use High Frequency (HF: three megahertz to 30MHz) transceivers such as the legacy R-123 Magnolia vehicular radio for trunk communications. The R-123 is in the process of being replaced by the R-187P Azart handheld transceiver which uses frequencies of 27MHz to 520MHz. Russia’s airborne forces employ the R-168 Aqueduct multiband radio. Aqueduct provides HF and very/ultra high frequency links on a 30 megahertz to three gigahertz waveband. The disappointing performance of the R-168 is seeing the radio replaced by the R-187P.
Networking weaknesses
The plethora of links used for trunk communications by Russian forces in Ukraine indicate that the Russian military writ large has struggled to deploy robust, secure theatre-wide operational level communications networks with built-in redundancy. Mixing military systems like the R-187 with civilian systems like Express AMU-1 and cellphone networks bring Communications/Transmission Security (COMSEC/TRANSEC) challenges. It is unlikely these civilian networks have military-grade standard COMSEC/TRANSEC bringing attendant security shortfalls. Insufficiently robust COMSEC/TRANSEC within Russian military communications and networks has been a persistent problem for Moscow throughout the conflict. It is unlikely common messaging standards and protocols exist to move traffic seamlessly between these differing civilian and military networks. This may mean that traffic which should be classified is often moved en clair. The lackadaisical approach Russian personnel take to discussing classified and secret information on publicly accessible networks is well known, as scores of radio amateurs can attest.
It seems unlikely that Russia’s land forces operational communications challenges will be solved any time soon. The country remains locked in a war that she looks unable to win, with a huge proportion of her forces supporting this effort. These are hardly conditions conducive to the roll-out of new military-grade trunk communications networks. The Russian military was conducting a major upgrade of its land forces communications systems and networks when the second invasion of Ukraine occurred in 2022. Notionally, this programme is continuing. Nonetheless, all it appears to have yielded so far is a hodgepodge of new and legacy military and civilian communications systems and networks that struggle to interoperate. Good news for Ukraine, but bad news for Russia. (Source: Armada)
10 Jun 25. Talking to UFOs. Up to eight of the original UFO military communications satellites manufactured by Boeing are presumed to remain in service. Some of the satellites are believed to be used by the Russian military for trunk communications in Ukraine. The Russian military is thought to be using communications channels provided by the US Department of Defence’s UFO satellite constellation. The Hackaday website has revealed that the Russian military maybe using the United States’ Department of Defence’s Ultra High Frequency Follow-On (UFO) satellites for communications. The report articulated revelations shared by the saveitforparts Youtube channel. The Hackaday report says that it has been possible to listen to unencrypted Russian military communications moving across these satellites. This is done using a web-based Software Defined Radio, known as a WebSDR. Open sources note that the UFO satellites use a 243 megahertz/MHz to 270MHz downlink channel, and an uplink employing a waveband of 292MHz to 317MHz. Each satellite provides 17 25 kilohertz and 21 five kilohertz channels. The sources continue that, as of 2025, eight of the satellites remain active in a geostationary orbit, although they are approaching the end of their operational lives.
Altai and FLTSATCOM
The Youtube video explains that it is not impossible to access these satellites using radios and Satellite Communications (SATCOM) terminals adapted to the UFO constellation’s frequencies. The video says that Russia’s Altai mobile phone system introduced in the mid-1960s used frequencies of 250MHz to 300MHz. Altai employed a switching system that allowed radio telephony to connect with landlines and vice versa. Early US military SATCOM constellations like the Fleet Satellite Communications System (FLTSATCOM), the forerunner of UFO, could receive radio traffic moving across Altai. Russian communications experts realised they could use FLTSATCOM to provide beyond line-of-sight communications. This was presumably a significant benefit given the Soviet Union, and now Russia’s, significant landmass. It is possible that Russian forces in Ukraine are using the UFO F/0 7 and UFO F/O 10 satellites. Both spacecraft are positioned over the middle of the Atlantic Ocean in an equatorial geostationary orbit.
The use of the UFO satellites for Russian military trunk communications in Ukraine may have arisen because of technical problems experienced with the country’s existing SATCOM constellations. Armada’s records indicate that Russia’s Ministry of Defence may have circa 40 communications satellites in its possession. However, the capabilities and condition of these spacecraft remain unknown. Existing Russian military SATCOM wavebands could be saturated which may explain a spillover onto the UFO SATCOM channels. In February 2024, Ukraine’s defence intelligence service said the Russian military was making unauthorised use of the SpaceX Starlink SATCOM network. Russian forces were thought to be using Starlink to satisfy trunk communication requirement that could not be met with existing domestic capabilities.
Ease of Access
Why is the Russian military able to employ these UFO channels? Firstly, it is not thought that any specific barriers exist to Russian users accessing the constellation’s frequencies and using them accordingly. It is arguably in the interest of the US signals intelligence community to ensure the Russian military keep using the UFO channels. Much of what is discussed across the constellation tends to be unencrypted chat. Russian troops complain about their superiors and local civilians under Russian occupation. Such information provides important indications of Russian morale in Ukraine. One UFO satellite, UFO F/O 11, has even been used by a Russian pirate radio station for broadcasts. UFO F/O 11 is in a geostationary equatorial orbit above the middle of the Indian Ocean. Armada contacted the US Space Force to obtain more information about Russia’s use of the UFO constellation, how the Russian military was able to do this, and steps that could be taken to prevent this access. Unfortunately, we did not receive any responses to our questions before this article was published. (Source: Armada)
12 Jun 25. June Radio Roundup. Bittium is supplying its TAC WIN tactical internet protocol communications system to the Croatian military. TAC WIN was used during a recent demonstration of fourth-generation and fifth-generation tactical cellular connectivity involving Nokia. Armada’s monthly roundup of all the latest news in the military communications product, programme and operational domains.
New Comms for Croatia
Bittium made two announcements in late April. The first concerned communications the company is supplying to Croatia, and the second covered a new initiative involving Nokia. Bittium is supplying $2 m worth of tactical communications systems to Croatia. These capabilities include the company’s Tactical Wireless Internet Protocol Network, also known as TACWIN. Joining TACWIN in the Croatian order is Bittium’s Tough SDR vehicular radios. Reports continued that these new radios include the European Secure Software Defined Radio (ESSOR) High Data Rate Waveform (HDRWF). This marks the second occasion on which a country beyond the original ESSOR national membership has procured the HDRWF. The first non-ESSOR partner nation to do so was the Republic of Ireland. Bittium told Armada that the supply of these radios to the Croatian armed forces will commence and conclude this year. The transceivers will be used by Hrvatska Kopnena Vojska (Croatian Army) and Hrvatska Ratna Mornarica (Croatian Navy). On 30th April, news emerged that Bittium and Nokia had demonstrated a hybrid tactical communications network to the Finnish military. The demonstration involved Bittium’s TAC WIN and Tough SDR handheld and vehicular radios. These communications systems were used alongside Nokia’s Banshee Mobile Radio and Banshee Tactical Radio. Combining these capabilities enabled a zone of fourth and fifth generation (4G/5G) cellular communications to be created over a specific area. Bittium told Armada that “(i)n this demonstration the hybrid network was a combination of a tactical network and military-grade 4G/5G bubbles.” These bubbles provide 4G/5G connectivity as part of the wider, deployed tactical network. This also allowed devices using 4G and 5G connectivity to access the tactical network: “Hybrid networking can be seen as something that benefits multi-domain operations and total defence,” Bittium added.
Viasat recently launched its new MOJO Mini Next tactical gateway which facilitates Link-16 tactical datalink network access and use. The product has a reduced Size, Weight and Power (SWAP) consumption footprint to ease deployment on board SWAP-constrained platforms.
Find your MOJO
On 5th May, Viasat revealed its new MOJO Mini Next expeditionary tactical gateway. The new product provides Link-16 tactical datalink (960 megahertz/MHz to 1.215 gigahertz/GHz) connectivity. A company press release said that the MOJO Mini Next has been designed to have low Size, Weight and Power (SWAP) consumption characteristics. Applications mooted for the new product include installation on SWAP-constrained platforms like small boats and ground vehicles. The MOJO Mini Next works alongside L3Harris’ KOR-24A Link-16 multichannel radio which provides the requisite communications security. David Schmolke, Viasat’s vice president of mission connections and cybersecurity, told Armada that the product “has successfully completed development and prototyping phases, with baseline hardware and system integration validated.” The company has already secured customers and “interest in the solution has been strong across both US and international defence communities.” Moreover, “full rate production is moving forward, and customers are now able to purchase the new solution.” The product forms part of Viasat’s wider MOJO family of tactical gateways and “builds on this operational legacy with a more compact, ruggedised form factor tailored for expeditionary missions.” (Source: Armada)
11 Jun 25. Today, Securonix, a five-time Leader in the Gartner® Magic Quadrant™ for Security Information and Event Management (SIEM), announced the acquisition of ThreatQuotient, a four-time leader in threat intelligence based on QKS Group Spark Matrix report and the force behind ThreatQ, the most innovative external threat intelligence platform. This combination will create a comprehensive, modular, and fully integrated AI-driven platform for threat detection, investigation, and response (TDIR), leveraging advanced analytics and insights across both internal and external threats. This acquisition accelerates the modernisation of security operations by uniting internal and external threat intelligence with real-time analytics and agentic AI. Unlike external threat intelligence bolt-on solutions with disconnected management interfaces, the integrated platform from Securonix and ThreatQuotient will deliver unified visibility, faster response, and greater operational clarity.
“Bringing threat intelligence management and SIEM together in a unified platform is a game changer. We’ve already seen the value of deeply enriched advanced analytics and detection in our Securonix SIEM environment – but coupling that with integrated threat curation, prioritisation, and response should help customers move even faster. It means fewer swivel-chair investigations, more accurate triage, and greater confidence that security analysts are working with the most relevant threats. This kind of integration has the potential to accelerate the ability to detect, respond, and stay ahead,” said Marcel Jonker, Director of Cybersecurity Operations at Cambia Health Systems.
The integration of Securonix and ThreatQuotient promises to deliver up to a 70% reduction in Mean Time to Respond (MTTR), enabling security teams to detect, investigate, and remediate threats significantly faster. By combining curated threat intelligence with AI-driven automation, the solution will deliver exponential improvements in filtering out false positives, enriching alerts with actionable context, and automating historical threat sweeps and incident response. This reduces alert overload, speeds up root cause analysis, and minimises manual handoffs – cutting investigation time from hours to minutes and enabling automated containment before threats escalate.
“Security teams are drowning in noise and struggling to keep up with evolving threats,” said Kash Shaikh, CEO and President of Securonix. “This acquisition brings together Securonix’s Agentic AI-driven Platform with ThreatQuotient’s deep threat intelligence to deliver clarity, speed, and automated workflows to our customers, reducing false positives by up to 90%. Together, we’re building the modern SOC Platform – proactive, intelligent, and built for what’s next.”
Kash added, “Securonix and ThreatQuotient bring together complementary strengths – deep innovation across internal and external threat domains, and a shared commitment to innovation and customer service. Both companies serve enterprise and government customers as well as Managed Security Service Providers (MSSPs), and we’re excited to welcome the talented ThreatQuotient team and their customers to Securonix.”
Purpose-Built for Analysts. Proven Against Real-World Threats.
ThreatQuotient’s Threat Intelligence Platform (TIP) strength lies in delivering curated, contextualised threat intelligence that drives smart, timely decisions. When combined with Securonix’s EON Agentic AI-based SIEM, SOAR, UEBA and Data Pipeline Manager, customers can accelerate their migration from reactive threat hunting-based defence to proactive, real-time, behaviour-driven, open-agentic security operations.
With this integration, Securonix customers and partners will enjoy the following benefits:
- Gain clear visibility: Integrate deep enriched real-time analytics from Securonix with curated external intelligence from ThreatQuotient to create a single, high-context stream of alerts. Eliminate blind spots and accelerate threat identification with confidence.
- Stay ahead of risk: Auto-enrich Indicator of compromise (IoCs) and pre-emptively respond to repeat attacks, blocking 90 percent before they start.
- Act smarter: Automate repetitive tasks, reduce false positives, and streamline investigations. Teams can stay focused on high-priority threats and reduce time spent on manual triage.
- Deploy your way: Continue to use ThreatQ as a standalone threat intelligence platform or as part of the fully integrated Securonix solution. Deploy on-premise or SaaS in a way that fits the current architecture and scales with needs.
- Accelerated Roadmap: Combined R&D synergies will accelerate upcoming roadmap innovations, including Agentic AI and ThreatQuotient’s innovation priorities.
With this acquisition, ThreatQuotient customers and partners will enjoy the following benefits:
- Increased Scale: ThreatQ customers can take advantage of Securonix’s global R&D scale and GTM reach, including access to Securonix’s Threat Labs Intelligence.
- Deeper Integrations: Gain access to an enriched roadmap and integration between Securonix’s best-in-class SIEM, SOAR and UEBA portfolio and ThreatQ, including extension of Agentic AI advancements.
- Continued Focus: Zero interruption of their existing service, as ThreatQuotient will continue to operate as a standalone offering, with no disruption to existing roadmap and workflows.
“Enterprises, government institutions and Managed Security Service Providers rely on ThreatQuotient to protect their mission critical businesses. Joining Securonix marks a powerful new chapter for ThreatQuotient. By uniting our strengths, we can accelerate innovation, expand our reach, and deliver greater value to our customers. I’m proud of what we’ve built and excited for what’s ahead.” said John Czupak, CEO of ThreatQuotient.
BTIG, LLC served as exclusive financial advisor, and King & Spalding LLP served as legal advisor to ThreatQuotient. Vinson & Elkins LLP served as legal advisor to Securonix.
09 Jun 25. Nuvotronics, a leader in advanced Radio Frequency (RF) technology, announces the launch of the StrataWorks ® platform, a web-based design solution that enables customers to rapidly create and customize PolyStrata®-based passive RF components. The first capability in the StrataWorks suite, StrataWorks® Filters, allows engineers to design high-performance, surface-mount RF filters with exceptional speed, precision, and flexibility.
“Our customers told us they needed a faster, more flexible, and cost-efficient way to create custom filters without sacrificing performance or reliability,” said Scott Meller, General Manager, Nuvotronics. “With the StrataWorks design tool, users can go from concept to simulation in minutes, receiving quotes within 24 hours. These designs are ready for volume production with the quality and repeatability Nuvotronics is known for.”
The StrataWorks platform streamlines the design and specification process for production of RF devices using the company’s proprietary PolyStrata® microfabrication technology. The tool incorporates intelligent design rules that empower engineers with complete freedom to tailor components to their exact specifications, enabling true design innovation without compromise. Production is equally efficient. Designs can be fabricated on Nuvotronics’ regularly scheduled bi-monthly multi-user runs, delivering high-performance, surface-mountable components in as little as 12–16 weeks. While the initial release focuses on filter design, the StrataWorks platform will expand to support a broad range of passive RF devices, allowing engineers to leverage PolyStrata technology across an even wider array of applications.
“We invite forward-thinking companies to explore StrataWorks and experience a faster, smarter path to RF innovation,” Meller added. “With our platform, expert support, and scalable production, your custom designs are closer to reality than ever before.”
10 Jun 25. As part of the Letter of Intent (LOI) signed in February 2025 between ELT Group and EDGE Group, a Strategic Cooperation Letter was signed today to advance discussions on the supply of electronic warfare (EW) systems for the Kuwait Navy’s missile boats, with ELT Group outlined as the preferred supplier. The letter was signed by Domitilla Benigni, CEO & COO of ELT Group, and Omar Al Zaabi, President – Trading and Mission Support, EDGE Group, and was witnessed by Rodrigo Torres, Group CFO, EDGE, and Paolo Zani, Managing Director for ELT Group UAE. The letter reflects both Parties’ shared intent to accelerate the process and collaborate towards formalising the contract. It marks the first significant milestone in their partnership, which also includes plans for the potential establishment of a joint venture in the UAE.
10 Jun 25. Global: Cyber operation highlights security risks to businesses. On 9 June, international news outlets reported that unnamed threat actors are targeting global developers in a destructive cyber operation. Threat actors inject legitimate npm packages (typically used by developers to download two application programming interfaces that enable data syncing between two applications) with malicious code that covertly installs backdoor malware onto compromised systems. The backdoors prepare targeted systems for attack by establishing communication with command-and-control (C2) infrastructure and by conducting initial system reconnaissance. Threat actors then use the backdoors to inject a hidden command that subsequently erases all data from infected applications (including source code and directory), effectively rendering the system unusable. The attack reportedly leaves no traces of its execution and uses legitimate processes for communication, showcasing its sophistication. This operation highlights the increased development of destructive cyber capabilities designed to permanently disrupt adversarial systems. This indicates elevated security risks to global businesses amid the continuous evolution of cyber tactics. (Source: Sibylline)
10 Jun 25. pureLiFi has announced the release of its latest LiFi system, Kitefin XE, designed to protect networks in an era marked by growing security threats. This cutting-edge wireless technology, first released exclusively within the National Security community, is now available to a wider spectrum of sectors, from government and defence to enterprise customers and beyond. Guaranteeing data security has become an increasingly complex task for both governmental bodies and private businesses. The Kitefin XE system is founded on technology crafted for the National Security community and has demonstrated its reliability in the most secure settings where communication privacy is paramount. Customers have reported that Kitefin XE allows them to introduce wireless capabilities where previously not possible, improving mission viability and success. This revolutionary system allows for high-speed wireless internet connectivity through Invisible Light rather than Radio Frequencies (RF) used in traditional wireless technologies such as WiFi and Cellular. LiFi provides a revolutionary level of security unmatched by RF technologies as it is not susceptible to detection, interception and jamming. LiFi also offers massive capacity that outperforms WiFi in real-world environments, and its low latency capabilities offer a better user experience.
Alistair Banham, CEO of pureLiFi, stated, “Securing sensitive data, whether it’s critical to national security, protecting intellectual property, and company data is becoming increasingly challenging for both governments and enterprises. Kitefin XE will enable wireless communication in previously impossible scenarios and revolutionise the way companies deploy connectivity, providing confidence and protection in this evolving security landscape.”
pureLiFi is part of In-Q-Tel’s (IQT) portfolio, the not-for-profit strategic investor for the U.S. national security community and its allies.
Clayton Williams, Managing Director of IQT, remarked, “IQT is excited to support the broader launch of Kitefin XE. This innovation has the potential to transform how our partners approach wireless connectivity—and help enterprises stay secure in today’s complex cybersecurity landscape.”
Kitefin XE is the latest in a series of Kitefin systems developed for government and defence that aims to save missions and lives. Kitefin Tactical and Kitefin Office were deployed with the US Army in the first-ever large-scale deployment of LiFi. Building on their predecessors’ success, Kitefin XE offers room-filling LiFi coverage of over 80 Sq. Metres and provides Gbps capacity, making it the highest-performing LiFi system available on the market for government and defence which complies with IEEE 802.11bb standard. All pureLiFi systems are based on IEEE 802.11 protocols, making them the simplest LiFi systems to integrate into existing networks. Kitefin XE is also available for both ethernet and fibre deployments.
With Kitefin XE, pureLiFi sets a new standard in secure, high-capacity wireless communication technology, paving the way for a future where data security is uncompromised.
10 Jun 25. Thales and Proximus consortium will enhanceme the resilience and efficiency of NATO’s Communications and Information Agency business network
- NATO Communications and Information Agency (NCIA) has awarded a contract to a consortium formed by Thales, a global leader in high technology, and Proximus, Belgium’s leading telecommunications provider.
- This strategic partnership will operate and manage some key infrastructure elements for NCIA’s business network, ensuring enhanced resilience, security, and operational efficiency across five NCIA locations The infrastructure will be supported using cloud based technology, providing NCIA’s personnel with highly secure and efficient access to essential IT services, facilitating real-time communication, collaboration and data management across multiple sites.
This modernisation is an opportunity to enhance capacity, improve compatibility, and upgrade systems to ensure optimal performance.
Under the terms of the contract, Thales and Proximus will deliver a fully managed service, providing:
- infrastructure as a service (IaaS) on a certified and accredited cloud;
- end-user devices as a service (DaaS) for personnel;
- robust cybersecurity solutions, ensuring a highly secure digital environment;
- advanced networking capabilities at NCIA sites for seamless connectivity;
- comprehensive platform administration services;
- scalable cloud services for secure storage and high-performance computing.
Thales is providing a secure cloud infrastructure and a fully managed service, while Proximus is delivering a secure multi-domain laptop and is upgrading the Wi-Fi networks at The Hague and Braine L’Alleud, as well as enabling a high speed connection to their Cloud for 5,000 users at NCIA sites.
“Together with Proximus, Thales reaffirms its commitment to strengthening NATO’s digital resilience, ensuring secure, high-performance and future-proof IT infrastructure to support the Alliance’s evolving needs. By outsourcing commodity services to trusted industry leaders, NCIA is taking a forward-looking approach that ensures a fully managed, secure, and scalable solution.” said Alex Bottero, VP Network and Infrastructure Systems, Thales.
“This strategic project reflects our commitment to providing cutting-edge connectivity, mobility, and security solutions. We are proud that Proximus has been chosen for this large-scale project, which will enable NATO to strengthen its digital capabilities with a secure and scalable infrastructure. Thanks to our collaboration with Thales, we are confident that we will be able to meet NCIA’s needs and support its essential missions.” adds Anne-Sophie Lotgering, Enterprise Market Lead at Proximus.
With stringent performance metrics and service level agreements (SLAs) in place, this solution will guarantee high availability, security and operational stability for NCIA’s ecosystem.
09 Jun 25. Global: New botnet variant sustains elevated security, disruption risks to vulnerable devices. On 6 June, the cyber security company Kaspersky reported that unnamed threat actors are exploiting a software vulnerability (CVE-2024-3721) to distribute a new variant of the ‘Mirai’ botnet. The vulnerability reportedly affects digital video recording devices (versions TBK DVR-4104 and DVR-4216) and enables remote command execution. Threat actors exploit CVE-2024-3721 after infiltrating targeted systems to deploy a malicious payload, establish communication with command-and-control (C2) servers and enlist infected devices into the botnet infrastructure. It is likely that threat actors subsequently use the botnet to proxy malicious traffic for additional cyber activity and/or to conduct distributed denial-of-service (DDoS) attacks. It is unclear whether the provider has released a fix for CVE-2024-3721; approximately 50,000 internet-facing devices are vulnerable to exploitation. This underscores the potential large-scale impact of the operation. We assess that this report showcases sustained security and disruption risks to vulnerable devices stemming from botnet-related activity. (Source: Sibylline)
06 Jun 25. Cyber Update Key points.
- A series of cyber attacks against US-based healthcare facilities indicates elevated security and disruption risks to the sector (see Sibylline Cyber Daily Analytical Update – 2 June 2025).
- A cryptocurrency-theft operation underscores the security and financial risks to global Windows and Linux systems (see Sibylline Cyber Daily Analytical Update – 3 June 2025 and our Technical analysis below).
- A new version of the ‘Crocodilus’ malware points to increased security and financial risks to global Android mobile users (see Sibylline Cyber Daily Analytical Update – 4 June 2025 and our Technical analysis below).
- The rise in cyber attack attempts against operational technology (OT) environments indicates raised long-term security risks (see Sibylline Cyber Daily Analytical Update – 5 June 2025).
- A cyber attack against a critical national infrastructure (CNI) entity in Ukraine showcases sustained security and operational risks from Russian actors (see Sibylline Cyber Daily Analytical Update – 6 June 2025).
Technical analysis of weekly stories
Threat actors exploited an internet-facing artificial intelligence (AI) interface (Open WebUI) to conduct a crypto-jacking campaign against an unnamed company. The interface was mistakenly configured to allow for unauthenticated administrator access; it enabled threat actors to inject malicious Python code into Open WebUI and execute remote commands. Threat actors also reportedly used large language models (LLMs) to partially assist with the script’s creation, showcasing the increased incorporation of AI in malicious cyber operations. The code subsequently downloads crypto-mining payloads (‘T-Rex’ and ‘XMRig’), compiles headers for stealth and establishes persistence and communication within command-and-control (C2) infrastructure. Threat actors then use T-Rex and XMRig to mine cryptocurrency before transferring it to actor-controlled cryptocurrency wallets. The script can dynamically adjust the malware’s execution process based on the type of compromised system (Linux or Windows systems) and boasts several other highly advanced obfuscation techniques, further highlighting its sophistication.
An unnamed Russia-nexus advanced persistent threat (APT) group used a new wiper malware (‘PathWiper’) to conduct a destructive cyber attack against a CNI entity in Ukraine. The group reportedly compromised a legitimate administrative console to manage the attack and enable remote command execution, though the initial attack vector is unknown. The console communicated with all endpoints within the compromised system, enabling threat actors to run a VBScript file and ultimately download the main PathWiper payload. Throughout the attack, threat actors also mimicked legitimate system activity, highlighting the premeditated nature of this operation. PathWiper then listed all connected storage media (including physical drives, containers and network drives) before overriding all files directly on a system’s disk with random data, effectively destroying a system’s functionality. While the impact of the attack is unknown, there is a realistic possibility that the malware will permanently disrupt the target organisation’s ability to provide key services. PathWiper’s capabilities resemble those of another wiper malware (‘HermeticWiper’) that was used by the Russian state-sponsored group ‘Sandworm’ to target Ukrainian entities in 2022; we assess that this highlights a possible overlap between the two groups.
Non-exhaustive recommendations to mitigate against these threats include:
- Monitor devices and networks for suspicious activity
- Add available Indicators-of-Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware
- Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
- Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering
Our cyber word(s) of the week: Vishing
(Source: Sibylline)
————————————————————————————————————————————————————————————————————————————————————————————————————————————–
Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.
We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.
Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.
—————————————————————————————————————————————————————————————————————————————————————————————————————————————

