Sponsored By Curtiss Wright
https://www.curtisswright.com/
——————————————————————————————————————————————————————————————————————————————————————————————————————————————–
06 Aug 25. RTX to Optimize Cyber Vulnerability Detection for DARPA. RTX BBN Technologies to advance high-fidelity exploit chain testing and evaluation. RTX’s (NYSE: RTX) BBN Technologies was awarded a contract from DARPA to support its Intelligent Generation of Tools for Security, or INGOTS, program. INGOTS aims to strengthen cybersecurity by developing advanced methods to identify and mitigate complex exploit chains, preventing their use in real-world attacks. Exploit chains pose a growing threat, amplified by the increasing complexity and sophistication of cyberattacks. The U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog has surpassed 1,300 entries, with steady growth reflecting the increasing number of threats targeting essential services and networks. Despite this rising threat, current assessment methods rely heavily on manual analysis, requiring significant expertise and time. INGOTS seeks to address this challenge by automating the creation, modification, modeling and analysis of exploit chains to enable faster and more effective security interventions.
“Effectively countering exploit chains requires more than just identifying individual vulnerabilities. It demands a system that can replicate real-world attack scenarios and anticipate potential risks before they are exploited,” said Jack Dietz, BBN principal investigator.
To support this effort, BBN will apply its expertise in testbed architecture to develop the System Test of Android at Large-scale Accelerating Generation and Modeling for INGOTS Test and Evaluation, or STALAGMITE. This system will serve as a comprehensive platform for testing and evaluating exploit analysis tools, offering key capabilities such as:
- Accurate real-world simulations: High-fidelity testing in combined virtual and physical environments ensures realistic assessments of Android vulnerabilities in a secure and controlled setting.
- Proactive threat responses: Seamless integration of INGOTS components enables security teams to anticipate and mitigate potential attacks, enhancing preparedness against emerging threats.
- Efficient security research: A robust environment for reproducible, automated testing advances research in software vulnerabilities and countermeasures, improving operating system and application security.
“Today’s manual methods for assessing exploitability are costly, time-consuming and lack scalability and efficiency,” said Dietz. “We aim to alleviate this burden from security professionals by accelerating the automatic identification of security risks across various devices and configurations using precise testing and measurement to strengthen overall cybersecurity defenses.”
While the program focuses on the Android ecosystem, the methodologies and technologies developed under INGOTS are expected to have far-reaching applications across personal, business, government and military sectors.
The BBN-led team includes Assured Information Security. Work on the program will be completed in Cambridge, Massachusetts; Columbia, Maryland; and Rome, New York. (Source: ASD Network)
06 Aug 25. HawkEye 360 RF Data Powers Military Platforms in Talisman Sabre Exercise Integration. HawkEye 360 Inc., the global leader in signals intelligence data and analytics, announced its participation in Exercise Talisman Sabre 2025 (TS25), a large-scale, multinational military exercise designed to strengthen interoperability between the United States, Australia, other allies, and partner nations. As part of the exercise, HawkEye 360’s radio frequency (RF) data is being integrated into operational military platforms for the first time, delivering critical insights to enhance situational awareness and decision-making across multiple domains. HawkEye 360 is integrating its signals intelligence capabilities with Lockheed Martin’s advanced defense systems. This machine-to-machine integration enables operators to seamlessly ingest and correlate RF data with other tactical data sources, transforming it into actionable surveillance tracks that support threat detection and more precise geolocation, resulting in higher-quality tracking.
“This partnership represents a major milestone in expanding our tactical relevance within the Department of Defense,” said Todd Probert, President of US Government at HawkEye 360. “By integrating HawkEye 360’s RF data into tactical defense systems, we’re accelerating decision advantage across the battlespace. This is a clear example of how we’re providing our data to DoD, by delivering timely, trusted insights that enhance threat tracking and operational awareness across domains and command echelons.”
Exercise Talisman Sabre is the largest military exercise conducted in Australia, held every two years to enhance readiness and interoperability among Australia, the United States, and participating allies. TS25 marks the 11th and largest iteration of the exercise, involving live-fire drills, amphibious landings, ground maneuvers, air combat, and maritime operations. With 19 nations invited to participate, TS25 provides a complex and realistic environment for testing joint and combined force operations across air, land, maritime, space, and cyberspace domains.
“By combining Lockheed Martin and Hawkeye 360 expertise, we’ve delivered a first-of-its-kind capability showcasing the unparalleled value of collaboration. Easy integration was the key to integrating commercial radio frequency into a combat system and enhancing situational awareness for our customers.”
HawkEye 360’s data integration into this dynamic operational environment enables defense partners to maintain consistent situational awareness over vast areas, offering a new layer of insight into RF activity across critical regions. This capability underscores the growing significance of commercial data solutions in supporting national security missions and coalition operations. (Source: ASD Network)
06 Aug 25. LM Achieves Key Milestone in RIG-360 Development, Advances 360-Degree Missile Communications. The Remote Interceptor Guidance – 360 (RIG-360) completed the first phase of the Engineering, Manufacturing and Development (EMD) program. This is a critical milestone as the Lockheed Martin (NYSE: LMT) and PEO Missiles and Space, Integrated Fires and Mission Command (IFMC) team work together to deliver the first RIG-360 units to the field.
“RIG-360 is a game-changing capability,” said Stu Chaffey, director of Integrated Air and Missile Defense Advanced Programs at Lockheed Martin Missiles and Fire Control. “RIG-360’s capabilities will allow soldiers to use the best weapon available on the Integrated Battle Command System (ICBS) Integrated Fire Control Network (IFCN) to eliminate incoming threats.”
- The RIG-360 team completed the first Array Assembly officially moving the RIG-360 EMD program into the second phase.
- The Array Assembly is one of three critical subsystems in the EMD program.
- The Array Assembly is the most complex subsystem and acts as the communications hub for the RIG-360 that can send, receive and translate radio frequency data for beacon tracking.
RIG-360 is a missile communications device that enables 360-degree, in-flight communications for the Patriot Advanced Capability – 3 (PAC-3) Family of Missiles within the IBCS. RIG-360 will support PAC-3 engagements and advances IAMD goals of pairing any sensor with the best available weapon system within the U.S. Army’s modern IAMD architecture. IFMC awarded the RIG-360 program a $114M definitized contract on May 9, 2025, another big milestone for the new program. This award reinforces IFMC’s commitment and support of the program. Lockheed Martin is currently building a dedicated RIG-360 EMD production facility in Grand Prairie, Texas. This facility features state-of-the-art advanced manufacturing tools and centralizes personnel, process and equipment to drive speed, efficiency and innovation. The facility is expected to be completed in late 2026. (Source: ASD Network)
04 Aug 25. Global: Stealthy techniques underscore long-term security risks from North Korean groups. Earlier on 4 August, international news outlets reported that the North Korean state-sponsored group ‘Lazarus’ has increased its use of malicious open source software to infiltrate targeted organisations since at least January. The group reportedly creates fake open-source software that impersonates legitimate development libraries as the initial attack vector. The malicious software contains a malware dropper that subsequently establishes communication with command-and-control (C2) infrastructure and deploys a highly obfuscated loader. This then executes several payloads to steal browser and cryptocurrency wallet data and credentials, as well as other sensitive information, highlighting a potential shift in the group’s strategy to prioritise information theft over crypto-mining. The group also performs checks to identify any active security protections to prolong detection evasion, underscoring the operation’s capacity for stealth. Lazarus routinely conducts cyber operations to bolster Pyongyang’s weapons and missile programmes and security posture, underscoring the long-term security and data-theft risks to global businesses. (Source: Sibylline)
01 Aug 25. Cyber Update Key points.
- A large-scale, highly sophisticated cyber operation will elevate security risks facing virtual machines (VMs) from the ransomware group ‘Scattered Spider’ (see Sibylline Cyber Daily Analytical Update – 28 July 2025 and our Technical analysis below).
- A large-scale cyber attack indicates heightened security risks to Russian businesses from pro-Ukraine and anti-Belarus hacktivist groups (‘Silent Crow’ and ‘Cyber-Partisans’, see Sibylline Cyber Daily Analytical Update – 29 July 2025).
- A cyber attack against the French telecommunications provider Orange highlights long-term security risks facing key infrastructure sectors (see Sibylline Cyber Daily Analytical Update – 30 July 2025).
- The continuous evolution of cyber tactics will increase financial, operational and reputational risks to global businesses (see Sibylline Cyber Daily Analytical Update – 31 July 2025).
- A newly-reported espionage cyber operation underscores sustained security and cyber espionage risks to Moscow-based foreign entities from the Russia-linked group ‘Secret Blizzard’ (see Sibylline Cyber Daily Analytical Update – 1 August 2025 and our Technical analysis below).
Technical analysis of weekly stories
The ransomware group Scattered Spider is targeting virtual machines (VMs) to conduct a highly sophisticated and large-scale, financially motivated operation. The group reportedly uses phishing phone calls (vishing) to impersonate employees and call the targeted company’s help desk. During the phone call, the group tricks victims into resetting the employee’s active directory (AD) password before beginning a two-pronged reconnaissance process to escalate privileges. This entails scanning SharePoint sites, network drives, password managers and/or other Privileged Access Management (PAM) solutions to identify potential high-value targets. Scattered Spider then uses gathered information to make a second phone call to persuade the help desk to reset the password for a chosen administrator. This enables the group to hijack the VMware vCenter Server Appliance (vCSA) to manage all virtual environments and maintain persistence via an open-source remote access tool (‘teleport’). Scattered Spider then identifies a virtual machine acting as a Domain Controller to steal authentication and authorisation data. The stolen data is then exfiltrated through a two-part process to the actors’ command-and-control (C2) infrastructure, likely to be used at a later stage for extortion. The group subsequently deploys a ransomware payload to encrypt all stored files while wiping all backup files to hinder recovery processes and increase pressure. The entire operation occurs within a company’s virtual infrastructure, which typically falls outside the protection scope of most security services, highlighting the group’s capacity for detection evasion.
The Russia-linked advanced persistent threat (APT) group Secret Blizzard has targeted foreign embassies in Moscow in a cyber espionage operation since at least 2024. The group reportedly intercepts local internet service providers (ISPs) via an Adversary-in-the-Middle (AiTM) attack to infiltrate targeted systems, before displaying a fake portal (mimicking a legitimate Microsoft connectivity check) to covertly execute custom malware (‘ApolloShadow’) onto compromised systems. ApolloShadow then checks the system’s privileges, tricking users with elevated privileges into granting Secret Blizzard full control over their devices via a fake certificate installer emulating the cyber security service provider Kaspersky. If the system’s privileges are low, ApolloShadow immediately communicates with C2 infrastructure and establishes long-term persistence for data exfiltration, payload execution and traffic monitoring. The malware changes behaviour depending on how the target devices’ system privileges are configured, highlighting the operation’s sophistication. Upon installing the aforementioned certificate, ApolloShadow also sets the network to private to weaken firewall protections, showcasing the group’s detection evasion capabilities.
Non-exhaustive recommendations to mitigate against these threats include:
- Monitor devices and networks for suspicious activity.
- Add available Indicators-of-Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware.
- Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
- Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.
Our cyber word(s) of the week: Active Directory (AD) (Source: Sibylline)
31 Jul 25. Northrop Grumman fulfils US Army IBCS MEIs delivery. The company has delivered 142 major end items under the contract. An Engagement Operations Center (EOC) at Northrop Grumman’s EPIC manufacturing facility in Madison, Alabama. Credit: Northrop Grumman. Northrop Grumman has completed delivery of all major end items (MEIs) for the US Army’s Integrated Battle Command System (IBCS) under the low-rate initial production (LRIP) contract. The delivery of these MEIs signifies Northrop Grumman’s ability to produce and deliver defence systems at scale, allowing the US Army to expedite the fielding of IBCS. It comes after the company delivered first full set of IBCS MEIs last year. The company delivered 142 MEIs under LRIP phase, which include 35 engagement operations centres (EOC), 32 integrated fire control network (IFCN) relays, and 75 integrated collaborative environments (ICE) from its facility in Huntsville, Alabama. Northrop Grumman global command and control solutions vice president Jeremy Knupp said: “Northrop Grumman’s delivery of IBCS MEIs to the US Army underscores our commitment to deliver cutting-edge technology.
“We have the manufacturing depth and capacity to deliver IBCS at speed, ensuring our armed forces are equipped to meet the challenges of modern warfare with enhanced situational awareness, decision-making precision and operational adaptability.”
Northrop Grumman is set to commence manufacturing IBCS under a full-rate production contract at its Enhanced Production and Integration Center (EPIC) in Madison, Alabama. The EPIC is designed to further Northrop Grumman’s ability to scale up and accelerate production while expanding capacity for high-rate manufacturing programmes. IBCS integrates sensors and effectors into a unified command and control system, offering warfighters a comprehensive view of the battlefield. Its network-enabled, modular, open, and scalable architecture merges sensor data into a cohesive and actionable battlespace picture. This capability provides warfighters with additional time to assess and respond to threats and serves as a critical element for enabling joint and coalition multi-domain operations. Currently in production, IBCS will be deployed as part of the US Army’s programme of record for integrated air and missile defence modernisation. In December 2021, Northrop Grumman receive five-year contract valued at over $1bn from the US Army for both low-rate initial production and full-rate production of IBCS. The US Army’s IBCS, developed by Northrop Grumman, successfully integrated with the service’s new Indirect Fire Protection Capability (IFPC) system in December 2024. (Source: army-technology.com)
—————————————————————————————————————————————————————————————————————————————————————————————————————————————-
Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.
We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.
Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.
———————————————————————————————————————————————————————————————————————————————————————————————————————————

