Sponsored By Curtiss Wright
https://www.curtisswright.com/
————————————————————————————————————————————————————————————————————————————————————————————————————————————————
28 Aug 25. Pentagon Halts Chinese Coders Affecting DOD Cloud Systems. Defense Secretary Pete Hegseth said the Pentagon has halted a decade-old Microsoft program that has allowed Chinese coders, remotely supervised by U.S. contractors, to work on sensitive DOD cloud systems. In a digital video address to the public posted yesterday, the secretary said DOD was made aware of the “digital escorts” program last month and that the program has exposed the Defense Department to unacceptable risk — despite being designed to comply with government contracting rules.
“If you’re thinking ‘America first,’ and common sense, this doesn’t pass either of those tests,” Hegseth said, adding that he initiated an immediate review of the program upon learning of it.
“I want to report our initial findings. … The use of Chinese nationals to service Department of Defense cloud environments? It’s over,” he said.
Additionally, Hegseth said DOD has issued a formal letter of concern to Microsoft, documenting a breach of trust, and that DOD is requiring a third-party audit of the digital escorts program to pore over the code and submissions made by Chinese nationals.
The audit will be free of charge to U.S. taxpayers, he said.
The secretary also said he’s tasking DOD experts with a separate investigation to determine whether any digital escort employees have negatively impacted the coding of DOD cloud systems, and that all Defense Department software vendors must now identify and terminate any Chinese involvement with DOD cloud systems.
“It blows my mind that I’m even saying these things … that we ever allowed it to happen,” Hegseth said of DOD’s use of the digital escorts program, adding that the Pentagon is now vigorously working to course correct, and that the department expects its vendors to put U.S. national security ahead of profit maximization.
“I’m committed, like is, to ensuring that our national security networks are secure,” Hegseth said.
“Again, it’s ‘America first,’ and it’s common sense.” (Source: U.S. DoD)
27 Aug 25. Omnisys highlights its BRO™ – a unique, fully-integrated Battle Resource Optimization system that revolutionizes combat mission planning and execution. BRO™ is the only system that builds mission plans based on the actual inventory of available weapon systems and resources, significantly improving effectiveness without requiring additional force structure and provide multi-mission and multi-domain solution. Supporting the entire mission lifecycle -planning, execution, and post-mission debriefing, BRO™ enables commanders to achieve over 30% better mission performances using existing assets. By integrating operational data regarding: weapon systems capabilities, environmental conditions, terrain, intelligence,about enemy systems, BRO™ generates real-time, AI-driven recommendations that ensure optimal decisions at every stage. Its intuitive, automated design minimizes human error, shortens planning cycles, and delivers consistent performance regardless of battlefield pressure or fatigue.
“The BRO™ system is operationally validated and in use worldwide,including by NATO nations”, says Alfred (Fredi) Tzimet, Deputy CEO of Omnisys. “It protects civilians, saves lives, and strengthens defense capabilities by turning every asset into a smarter, more impactful operational tool. BRO™ delivers true operational superiority in an increasingly complex battlespace. With over 25 years of expertise, Omnisys continues to deliver scalable, combat-proven solutions that empower defense forces with smarter decisions and unmatched battlefield advantage.”
BRO™ software-powered, microservices, and web technology-based system that includes GEO (DTM/DSM) services, weapon systems physical modeling, advanced AI-driven analysis and optimization algorithms, and simulation capabilities .It supports real-time mission operations, long-term force build-up planning, and seamless integration with C4I systems, or can operate independently. Adaptable to evolving operational concepts, BRO™ covers a wide range of mission types, including air defense, air surveillance, electronic warfare, spectrum management, intelligence gathering, and border security.
About Omnisys
Omnisys is a leading global provider of combat-proven optimization systems for multi-mission planning and real-time decision-making. AI-driven BRO™ Battle Resource Optimization systems empower mission commanders to improve the performance of complex multi-domain missions, including intelligence gathering, spectrum management, air defense, air surveillance, border security, and electronic warfare. For Further informaion: https://www.omnisys.co.il/
27 Aug 25. India: Cyber operation highlights security, espionage risks to government, defence sectors. On 25 August, international media sources reported that the Pakistan-linked state-sponsored group ‘APT36’ targeted Indian government and defence entities in an August cyber espionage campaign. The campaign initiates via phishing emails containing procurement themes. The phishing email contains a .ZIP file with Linux-specific malicious files, which subsequently fetch a dropper from Google Drive. The dropper conducts security checks, establishes persistence and connects to the command-and-control (C2) server. The campaign specifically targets Linux Boss environments, highlighting APT36’s growing sophistication. Customisations to the malware delivery mechanisms depending on the operating system of the target increase the rate of successful and persistent infections while evading traditional security controls, further showcasing APT36’s skillset. As such, we assess that the Indian government and defence sectors face sustained security and cyber espionage risks amid ongoing bilateral tensions between India and Pakistan. (Source: Sibylline)
25 Aug 25. GIADS IV achieves full technical capability within German Airforce. The GIADS IV system is completely integrated with the Nato Integrated Air and Missile Defence System. This advancement follows a series of rigorous tests. The system is on track for full operational capability by 2026, which will include comprehensive training components. Developed by Airbus Defence and Space, the system operates on the Deployable Control and Reporting Centre (DCRC) platform. It is now fully integrated with the Nato Integrated Air and Missile Defence System (NATINAMDS). This achievement builds on the initial technical capability reached in 2023 and the deployment to the Baltic Sea region in 2024 as part of Nato’s enhanced Baltic Air Policing mission. GIADS IV plays a vital role in maintaining the integrity and security of German airspace throughout the year. At its core is Airbus Fortion 1SkyControl software, which facilitates Nato interoperability through its ability to enable seamless communication of data via Tactical Data Links. The software consolidates information from various radar sensors to deliver precise tracking and automatic correlation of flight and mission plans. It offers multi-domain situational awareness, aids in identifying aircraft, provides tactical guidance, and coordinates with military and civilian air traffic control systems, according to the company. A key feature of GIADS IV is its capability to automatically discern all objects within its monitored airspace, significantly reducing the potential for misidentification of friendly forces. The rollout of GIADS IV encompasses both hardware and software enhancements for the DCRC, said Airbus. The software’s open system architecture includes elements such as private cloud services and machine learning technologies, offering flexibility for future updates and integration with emerging systems. Airbus said it “will continue to empower the German Air Force in safeguarding national and coalition airspace”. In June this year, Airbus secured a contract from the German procurement agency (BAAINBw) to retrofit 23 Luftwaffe A400M aircraft with directed infrared counter measures (DIRCM) systems. (Source: airforce-technology.com)
25 Aug 25. Korean Air, LIG Nex1 announce collaboration to enter EW aircraft project. Korean Air and LIG Nex1 have announced that they will form a consortium to compete in South Korea’s ‘Block-I Electronic Warfare (EW) System Development Project’, which aims to provide the Republic of Korea Air Force (RoKAF) with an airborne EW platform. Seoul is investing a sum of KRW1.7775trn (USD1.2bn) in the project, with selected South Korean companies to conduct research and development for the new platform, according to statements by Korean Air and LIG Nex1. The final proposal for the project is scheduled for submission in early September, according to Korean Air. South Korea’s Defense Acquisition Program Administration (DAPA) has been accepting bids for the project since 15 July, according to LIG Nex1. DAPA deliberated and approved the basic strategy for the project in 2023 and subsequently approved the ‘basic system development plan’ in June 2025, the company added. DAPA told Janes in 2023 that the new platform would operate as a “stand-off jammer aircraft”, similar to the US Air Force’s (USAF’s) new EA-37B ‘Compass Call’ aircraft. Janes previously reported that South Korea intends to acquire four aircraft by 2032. Domestic companies selected for the project will be responsible for EW systems integration and aircraft modifications. The role of Korean Air in the consortium is to handle systems integration and aircraft modification or manufacturing. LIG Nex1 will be responsible for system development and EW equipment development and installation, according to statements by both companies. (Source: Janes)
22 Aug 25. Fiber Optic FPV Drones Featured in US Navy Electronic Warfare Exercise. A first-person view (FPV) type quadcopter drone controlled via a fiber optic cable was among the participants in a U.S. Navy-led exercise earlier this year focused on exploring new distributed electronic warfare capabilities. Fiber optic kamikaze FPVs, which Russia first began using in Ukraine last year and have now become a fixture on both sides of that conflict, are notably immune to jamming and many other forms of electronic warfare. The Michigan National Guard released pictures of the fiber optic FPV and other uncrewed systems that took part in Exercise Silent Swarm 25. The event itself took place back in July at the Alpena Combat Readiness Training Center (CRTC) in Alpena, Michigan. The Navy’s Naval Surface Warfare Center, Crane Division (NSWC Crane) has been holding Silent Swarm events annually at the Alpena CRTC in cooperation with the Michigan National Guard and other elements of the U.S. military since 2022.
“During the series of technology experiments, private companies, academic institutions, and military organizations used swarms of unmanned systems to ‘attack’ and ‘defend’ locations in Thunder Bay, off the coast of Alpena in Lake Huron,” according to a press release on the exercise the Michigan National Guard put out today. “As the two forces conducted their operations, all parties collected data on which technologies offered the greatest advantages.”
“The hypothesis for Silent Swarm is to identify those systems that can outmatch and have an impact in the most challenging environments,” Rob Gamberg, project lead for Silent Swarm at Naval Surface Warfare Center, Crane Division (NSWC Crane), also said in a statement. “We are learning from each other with every iteration, which is exactly what we hope to see.”
How many total fiber optic FPVs took part in Silent Swarm 25, and whether they were used as ‘attackers’ or ‘defenders,’ or both, is unclear. However, their inclusion in the exercise at all makes good sense. As noted, Russia first began using FPVs with this kind of control method last year, primarily in response to growing electronic warfare threats. The fiber optic-controlled first-person view (FPV) type drone seen being prepared for use during Silent Swarm 25. Michigan National Guard Fiber optic control offers additional benefits, including a more reliable, secure, and higher-speed link with lower latency (key for FPV operation) that is also immune to cyber intrusion. The hard link helps mitigate the effects of terrain that can interfere with radio control, something that is also a factor for operating drones inside buildings. Fiber optic drones also do not pump out radio frequency emissions that passive sensors can detect, making them harder to spot. The control scheme is not without its own disadvantages, including the potential for the cable to become tangled on or severed by various obstacles. The drones are also not invulnerable, including to laser and microwave directed energy weapons. Still, Ukrainian forces followed suit in adopting fiber optic FPVs for the same general reasons. Fiber optic cables have also since emerged as a means to control small uncrewed ground vehicles.
“The idea is great, because you are operating in total radio silence, so you cannot be detected by any radar system [passive sensors]. And any electronic warfare means that later on, they are just inefficient,” the commander of the 12th Special Forces Brigade Azov of the Ukrainian National Guard’s Unmanned Systems Battalion, who uses the call sign Yas, told TWZ in an interview in May. “At the same time, the use of fiber optic cables, as with any FPV drone, has its own peculiarities of operation, and if the pilot is not skilled enough, that is going to lead to significant losses in such equipment and systems.”
“I would like to say that at the moment, Russian electronic warfare is undoubtedly one of the leading in the world,” he added. “So I do not want to underestimate the enemy. We need to accept, to acknowledge, the level of the enemy.”
The use of fiber optic FPV in Ukraine has become so commonplace that videos have begun to emerge showing dense, tangled webs of leftover cables littered on the ground. There are also signs now that fiber optic FPVs may be starting to proliferate outside of Ukraine.
“We are so far behind,” U.S. Army Lt. Gen. Joseph Ryan, the service’s deputy chief of staff for operations, plans, and training, said in March about the U.S. military’s response to the impact fiber optic drones are already having. Ryan’s comments came during a panel discussion at an Association of the U.S. Army (AUSA) conference. (Source: UAS VISION/The War Zone)
26 Aug 25. Southeast Asia: Cyber campaign underscores sustained security risks to diplomatic entities. On 25 August, the technology company Google reported that the China-nexus threat actor ‘UNC6384’ is targeting diplomats in Southeast Asia in a cyber espionage operation. The actor targets captive portals; these are the web pages displayed for a newly connected WiFi network, allowing users to authenticate access, enter login credentials or pay before gaining access to the network. The actor then uses adversary-in-the-middle (AitM) techniques to direct the victim to an actor-controlled page where the ‘PlugX’ backdoor is subsequently executed onto the compromised machine. PlugX can exfiltrate files, launch a remote command shell, log keystrokes and upload and download files; it can also install additional plugins. These attributes highlight the security and espionage risks the malware poses to targeted entities. UNC6384’s use of a new downloader (‘STATICPLUGIN’) during this campaign underscores the actor’s continued development and sophistication. We assess that the campaign will sustain long-term security risks to strategic diplomatic entities in Southeast Asia. (Source: Sibylline)
22 Aug 25. Cyber Update.
Key points
- Taiwanese web infrastructure faces elevated espionage and information-theft risks from the Chinese actor ‘UAT-7237.’
- A malware operation highlights security and information-theft risks to diplomatic entities in South Korea.
- The resurfaced backdoor ‘PipeMagic’ underscores security and operational risks from ransomware group ‘Play.’
- The Russian state-sponsored group ‘Static Tundra’ poses long-term security and cyber espionage risks to global firms.
- A new macOS variant of the ‘Atomic’ macOS information stealer targeting global Apple users, underscoring heightened information-theft risks.
Technical analysis of weekly stories
The Chinese actor UAT-7237 is exploiting software vulnerabilities to target exposed devices in a cyber espionage operation against Taiwanese web infrastructure. The group initially scans the internet to identify vulnerable, unpatched servers, which serve as potential targets. Once the actors gain initial access to targeted systems, they conduct rapid fingerprinting to evaluate whether the target is of sufficient value to merit the conducting of further malicious activity. Should the infected system be deemed a valuable target, UAT-7237 will deploy web shells to establish backdoor channels, using the SoftEther virtual private network (VPN) client to establish persistence and access the systems via remote desktop protocol (RDP). After establishing persistence and conducting reconnaissance, the actors pivot into other systems within the infected network, using living-off-the-land (LotL) techniques. Subsequently, UAT-7237 deploys both custom and open-source tools to perform various tasks on the infected machines. A custom tool (‘SoundBill’) is used as a shellcode loader, which may be a tool to execute arbitrary commands or install ‘Cobalt Strike’. The group also uses the tool ‘JuicyPotato’ (a privilege escalation tool commonly used by various Chinese-speaking threat actors), highlighting the collaboration between Chinese threat groups. The group aims to steal credentials from infected endpoint devices to establish long-term access to networks and propagate into other devices, highlighting prolonged security and cyber espionage risks to Taiwanese web infrastructure posed by the campaign. A sophisticated cyber espionage operation targeted various diplomatic entities in South Korea between March and July. Suspected North Korean threat actors conducted at least 19 spear phishing attacks, impersonating diplomatic contacts and attempting to trick embassy staff via legitimate-looking meeting invites, official letters and event invitations. These were disguised as .ZIP files to evade security detections and execute a malicious .LNK file that subsequently triggers a PowerShell script, connecting to an actor-controlled GitHub repository to download the ‘XenoRAT’ malware. This allows the operation to establish persistence through scheduled tasks and connect to the command-and-control (C2). XenoRAT is a remote access trojan (RAT) that allows for complete system control, providing threat actors access to a variety of potentially strategic information while maintaining a prolonged covert presence in the network, underscoring the long-term security and espionage risks from this campaign. This campaign’s tactics align with the North Korean group ‘Kimsuky’; however, there are also indications of Chinese support or connections, given the activity correlated to Chinese time zones and paused during a major Chinese holiday. This highlights the realistic possibility that certain operators of this campaign may reside in China or have Chinese origins, further complicating attribution and motivations for the attack.
Non-exhaustive recommendations to mitigate against these threats include:
- Monitor devices and networks for suspicious activity.
- Add available Indicators-of-Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware.
- Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
- Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.
Our cyber word(s) of the week: Fingerprinting. (Source: Sibylline)
——————————————————————————————————————————————————————————————————————————————————————————————————————————————
Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.
We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.
Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.
————————————————————————————————————————————————————————————————————————————————————————————————————————————

