Sponsored By Curtiss Wright
https://www.curtisswright.com/
———————————————————————————————————————————————————————————————————————————————————————————————————————————
06 Nov 25. Lockheed Martin has made a major breakthrough in artificial intelligence (AI) technology with the introduction of the STAR.OS™ solution, a powerful new tool that enables different AI systems to work together smoothly and effectively. This innovative solution has the potential to be used in future collaborations with private sector companies and solves a long-standing challenge in the field of AI by providing a common framework that makes it easier to combine different AI systems and services to achieve a common goal. The STAR.OS™ solution seamlessly integrates Systems, Tactical applications, Autonomy/AI, and Rapid deployment, providing a unified framework for AI deployments that support national security. The platform consists of three main components: a toolkit for developers (STAR.SDK™), a system that connects different AI systems (STAR.IO™), and a user-friendly interface that provides a clear view of how AI is being used in real-time (STAR.UI™).
“With the STAR.OS™ solution, we’re taking a major step forward in our ability to bring together different AI systems and make them work together seamlessly,” said Mike Baylor, Lockheed Martin vice president and chief digital AI officer. “This will help us provide more effective and efficient solutions to our customers and ultimately help them make more informed decisions and stay ahead of emerging threats.”
STAR.OS is a key part of Lockheed Martin’s efforts to integrate AI systems across different domains, making it easier to deploy AI capabilities and enhance mission effectiveness for the Department of War, U.S. government and beyond.
Key Components of STAR.OS™
The STAR.OS™ platform is made up of three product lines, each designed to address specific challenges in AI integration:
- Service Development Kit (STAR.SDK™): A toolkit that helps developers create and deploy AI services quickly and efficiently, so they can focus on what they want to achieve rather than how to achieve it.
- Interoperability (STAR.IO™): A system that connects different AI systems and allows them to work together, ensuring they can communicate and share information seamlessly.
- User Interface (STAR.UI™): A user-friendly interface that lets engineers and operators see how AI is being used in real-time, and get insights into how it’s performing, with the help of built-in AI assistants.
Making a Difference
Early instances of the STAR.OS™ solution are being used to support the Department of War and other government customers, with successful integrations in areas such as detecting threats at sea and missile warning. At a recent internal hackathon as part of AI Fight Club™, the STAR.OS™ solution showcased its ability to integrate multiple AI services into a digital environment, demonstrating its potential to enhance mission effectiveness for the warfighter.
STAR.OS™ is now available to federal and private sector customers as a unified framework for combining different AI systems and services. For more information about Lockheed Martin’s the STAR.OS™ solution, visit: https://www.lockheedmartin.com/STAROS
05 Nov 25. Blackwired, a global cybersecurity innovation firm setting new standards for cyber defence, today announced it has launched a new way to hunt for cyber adversaries through enhancements to its ThirdWatch platform. Combining 3D Threat Visualisation, Direct Threat Intelligence (DTI) and its unique Aim-Ready-Fire (ARFi) methodology, the new platform delivers comprehensive cyber security capabilities to stop the threat before it strikes. The world is facing an exponential growth in cyber-attacks, fuelled by the artificial intelligence (AI) capabilities of cyber adversaries. Recent breaches in the UK include Marks & Spencer, Co-op, Jaguar Land Rover, and key airport systems provider Collins Aerospace. In the US, the breach affecting the Salesforce CRM platform impacted hundreds of companies, including Google, Cisco, Farmers Insurance, Pandora, and TransUnion, with over 4.4 m individuals affected. In Asia, Qantas suffered a breach exposing six m customer records and an estimated AU$7bn in reputational damage, while Asahi Group Holdings faced a ransomware attack causing daily financial losses of more than £9m. Beyond the reputational harm and regulatory repercussions, the financial fallout is eyewatering – cybercrime damages globally are projected to reach $10.5trn annually by the end of 2025.
ThirdWatch’s new capabilities deliver unprecedented 3D threat visualisation and pre-emptive cyber protection via AI, taking cyber security to the next level beyond the failed 1980s ‘detect and respond’ paradigm. With more than a decade of research and development in the pursuit to end the cyber war, Blackwired has built a cyber security solution to defeat cyber adversaries before they attack.
“Enhancements to ThirdWatch were developed in response to every sector’s desperate need to survive in the digital age,” said Jeremy Samide, CEO at Blackwired. “We’ve created an innovative platform to predict cyber-attacks before they strike, effectively preventing intellectual property and data theft, fines, and lost productivity. Blackwired is the only pre-emptive cyber security provider in the market today.”
“With strong, innovative cyber defences, businesses can rationalise their cybersecurity toolkit and stack, as well as staff, and redirect freed-up resources into more revenue-generating activities. They can also avoid regulatory fines, investigations and other consequences of cyber-attacks, effectively making an organisation more competitive, trusted, resilient, valued and ultimately more profitable,” said Dr. Ruth Wandhöfer, Head of European Markets at Blackwired.
Blackwired’s ThirdWatch platform has the following core components:
- 3D Threat Visualisation of external cyber-attack campaigns, sequences and vectors directly targeting a specific organisation;
- ARFi (Aim-Ready-Fire) methodology, which proactively neutralises adversaries during their targeting and reconnaissance phases;
- DTI (Direct Threat Intelligence): client-specific, actionable intelligence delivered via secure application programming interface (API) directly into the client’s security infrastructure;
- Third Party Risk Intelligence, where organisations can monitor external threat levels and looming cyber-attacks relating to their third-party suppliers, supporting compliance with the Digital Operational Resilience Act (DORA);
- Enhanced Attack Surface Management Module (eASM), which maps the direct, external threats (DTI) facing an organisation to its known vulnerabilities produced from a vulnerability report;
- AI-Anticipated Attacks, using AI to analyse patterns, anomalies and intent indicators across vast data sources to predict external threats before they materialise.
06 Nov 25. Way Down in the Deep South. Another September, another EW Live event. Launched in 2022 this conference, exhibition and live demonstration has become an established fixture on Europe’s annual calendar of electronic warfare extravaganzas. It has emerged as the perfectly timed complement to the Association of Old Crows’ annual EW Europe event. EW Europe occurs in the spring, with EW Live taking place in early autumn. The former sets the community up for the summer, the latter welcomes us back from our holidays. Both events are suitably unique to be thoroughly complementary. EW Europe is an excellent opportunity to hear scintillating presentations and spirited discussion, to browse the halls and chat with organisations and companies large and small. EW Live, which takes place in the delightful southern Estonian city of Tartu, also includes an exhibition and conference. Nonetheless, it is the live demonstrations of EW kit that really sets this event apart. Airshows have their flying displays with fast jets and helicopters zipping around the sky. Land warfare events let armoured vehicles increase dry cleaning bills as they fling mud around with abandon. Visitors to fleet reviews can watch handsome warships cruise past. EW Live’s unique selling point is that electrons are fighting each other in the spectrum. In short it is an invisible firepower demonstration; the defender pitted against the attacker. All the fun and games happen at Tartu’s international airport which is largely closed during the four-day long event. The airfield is in a serene, verdant spot. Trees and rolling meadows stand majestically in the morning mist. Estonia’s aviation academy shares the site. However, the bucolic beauty belies the particles congesting and contesting the local spectrum. EW Live plays another important role in sorting aspirational acumen from actual capability. If a company or organisation has good kit that is ready for use, why not bring it along? One could even argue that the event has a subtle strategic overtone. Tartu is just under 100 kilometres/km (60 miles) from Estonia’s border with Russia. If Russian signals intelligence cadres are taking an interest from their side of the frontier, hopefully they are getting the right message. North Atlantic Treaty Organisation (NATO) and allied nations bring potent materiel which is driven hard during representative spectrum engagements. If the myriad of Russian military units in the city of Pskov, 155km (96 miles) away, get ordered to advance along the E263 highway into Estonia, and hence into NATO, some of the kit at work during EW Live will no doubt be used by Alliance troops on the frontline. A complementary event to EW Europe, EW Live is a valuable chance to see equipment in action at an event with important strategic undertones. Hats off to the Tangent Link team for delivering yet another triumph. The electronic warfare community in Europe and beyond looks forward to future iterations as EW Live firmly embeds itself in the continent’s electronic warfare calendar. (Source: Armada)
04 Nov 25. Six Days in August. The Alaskan Air Defence Identification Zone has been probed by Russian signals intelligence gathering aircraft of late. Several flights were performed by a Russian Aerospace Forces’ Il-20M SIGINT aircraft during late August when US military exercises were taking place in and around the state. A Russian Aerospace Force Il-20M signals intelligence gathering aircraft made several flights into Alaska’s Air Defence Identification Zone in August. What was the aircraft up to? For six days in August, between 19th and 25th of that month, a Russian Aerospace Forces (RASF) Il-20M (North Atlantic Treaty Organisation/NATO reporting name Il-20M Coot-A) flew inside Alaska’s Air Defence Identification Zone (ADIZ). Open sources state that the Alaska ADIZ stretches from the state’s international border with Canada and westwards into the Pacific Ocean past the Aleutian Islands. The Il-20M is a reconnaissance platform equipped with Signals Intelligence (SIGINT) gathering equipment and a side-looking airborne radar. According to EW Analytics LLC the Il-20M flew alone, unaccompanied by any escorting RASF aircraft.
COMINT payloads
EW Analytics LLC’s analysis continued that, in the past at least, the Il-20M was outfitted with an SRS-5 Vishnya Very/Ultra High Frequency (V/UHF: 30 megahertz/MHz to 300MHz) Communications Intelligence (COMINT) collection system. Armada understands that the SRS-5 Vishnya covers a comparatively narrow communications waveband of 100MHz to 400MHz within the Very/Ultra High Frequency (V/UHF: 30 megahertz/MHz to 300MHz) range. Nonetheless, this relatively narrow waveband would be sufficient to collect COMINT on military V/UHF air-to-air and air-to-surface/surface-to-air radio which tends to use frequencies of 225MHz to 399.95MHz. According to International Telecommunications Union stipulations the 225MHz to 328.6MHz waveband is reserved for military use by NATO and allied nations.
ELINT payload
Reportedly, the Il-20M’s COMINT payload is joined by two Electronic Intelligence (ELINT) gathering systems in the guise of the SRS-4 Romb and Kvadrat-2. EW Analytics LLC says that these two ELINT systems perform differing, but complementary, roles: The SRS-4 Romb undertakes the initial search for Signals-of-Interest (SOIs). When a SOI is discovered, the Kvadrat-2 performs the detailed analysis of that signal. What this means in practice is that the Kvadrat-2 will be used to extract precise signal parameters. These parameters will include specifics concerning the signal’s waveform. For example, is the radar signal performing a general search of the locale? Does the waveform use any low probability of interception/detection techniques? What are the waveform’s precise frequencies and amplitude? Such information is particularly important for radar threat libraries. Threat libraries are used by Electronic Support Measures (ESMs) equipping combat aircraft and warships to recognise hostile radar signals. Signal recognition enables countermeasures like jamming, or the use of physical decoys, to be brought to bear against these threats if necessary. Radar libraries can be used by SIGINT gathering assets like the Il-20M so that such signals can be easily recognised in the future allowing additional ELINT to be collected.mIl-20 variants are believed to have been used for SIGINT collection since the late 1970s. Open sources state that the first time NATO discovered an Il-20 airframe being used for this mission was in 1978. At the time, the aircraft was deployed by the Soviet Air Force: EW Analytics LLC has found first-hand accounts of the use of the IL-20 COMINT capabilities in missions over Afghanistan during the Soviet occupation of the country between 1979 and 1989. The Kvadrat-2 ELINT system is believed to have also been available for use since this timeframe, but has probably been updated extensively during the aircraft’s operational life. For example, EW Analytics LLC believes that the current Kvadrat-2 system is a significantly modernised version which digitally processes SOIs.
No details appear to exist in the public domain regarding the wavebands of the SRS-4 Romb or the Kvadrat-2. Conservatively, both systems are likely to cover wavebands of at least two gigahertz/GHz. This would allow the apparatus to collect SOIs transmitted by most ground-based air surveillance and fire control/ground-controlled interception radars, and naval surveillance radars. Extending the waveband up to 40GHz would let both systems collect ELINT on K-band (24.05GHz to 24.25GHz) and Ka-band (33.4GHz to 36GHz) radars. Some radars like variants of GEM Elettronica’s Gemini-DB naval surveillance radar transmit in Ka-band. Likewise, the SRS-5 Vishnya and SRS-Romb are likely to have been extensively upgraded since their service entry.
Motives
What was the reason for the August Il-20 flights in the ADIZ? EW Analytics LLC’s commentary notes that a United States Navy exercise, Northern Edge 2025, was ongoing while the flights were performed. Northern Edge commenced in Alaska on 17th August and concluded in early September. Might the flights have been performed to collect relevant SIGINT from US military assets participating in the exercise?
Another possibility is that the Il-20M missions were intended to convey a political message concerning Russia’s strategic presence and America’s northwest regions. The American and Russian Presidents Donald Trump and Vladimir Putin held a summit at Joint Base Elmendorf-Richardson in Anchorage, southern Alaska on 15th August. It is important to stress that the Il-20M was not breaking any international laws per se by flying into the ADIZ which is classified as international airspace. Nonetheless, aircraft flying into Alaska’s ADIZ are asked to identify themselves to US Federal Aviation Administration air traffic controllers and to the North American Aerospace Defence Command (NORAD). NORAD stated that it received no responses from the Il-20M to its challenges. The Russian aircraft performed four flights in total and was intercepted and escorted by USAF combat aircraft on each occasion.
Given that tensions between Russia and the United States show no signs of abating, future Russian SIGINT flights close to North American airspace should be expected. The same holds true for NATO-adjacent airspace, as evidenced by a similar Il-20M flight over the Baltic Sea on 21st September. It seems likely these will be as much about showing Russian force projection capabilities are they are about gathering signals intelligence. (Source: Armada)
05 Nov 25. Got Your Back. It is possible that both the Australian and New Zealand armies will soon receive Mastodon Design’s Terrestrial Layer System backpack electronic warfare apparatus which will help greatly enhance tactical EW interoperability with US Army deployments in the Asia-Pacific. Armada has learnt that both the Australian and New Zealand armies seem likely to acquire the Terrestrial Layer System backpack electronic warfare apparatus. The TLS backpack is equipping the United States Army. Mastodon Design won a contract to this end on 1st July 2024 worth almost $100 m. The TLS backpack forms a part of the US Army’s overhaul of its land manoeuvre force Electronic Warfare (EW) posture. As we have reported in the past, deliveries of the system to the US Army commenced in 2024. The backpack forms part of the wider TLS architecture which equips the force from division lever downwards. Three TLS capabilities are being developed: Stryker Brigade Combat Teams (BCT) will receive the TLS-BCT platform. This capability is housed onboard the medical evacuation variant of a General Dynamics M-1126 wheeled armoured fighting vehicle. According to the US Army, the M-1133 variant was chosen due to the abundance of power sockets within the vehicle’s interior. Lockheed Martin was chosen by the US Army to build a prototype TLS-BCT in August 2022. TLS-BCT systems will be produced in two sub-variants: One will be restricted to Signals Intelligence (SIGINT) collection and processing. The other will also have cyber/electronic attack capabilities. Armoured BCTs (ABCTs) will have their TLS architectures equipping tracked BAE Systems Armoured Multi-Purpose Vehicle (AMPV) platforms. Whether the ABCTs will receive two AMPV TLS variants, one of which will be confined to SIGINT and the other of which will also perform electronic attack, has not been revealed. Infantry BCTs (IBCTs) will be equipped with the TLS backpack. Divisions will be outfitted with the TLS Echelon Above Brigade (EAB) configuration. TLS-EAB prototype testing, including one design provided by Lockheed Martin, is continuing throughout 2025 and 2026, according to the US Army.
TLS backpack capabilities
Reports note that the TLS backpack is equipping US Army IBCTs at a rate of two brigades per month with deliveries expected to conclude in 2027. An article penned by John Haystead in the April 2025 edition of the Journal of Electromagnetic Dominance stated that each IBCT will have six TLS backpack systems. The TLS backpack will collect SIGINT, perform emitter direction finding and provide the local Recognised Electromagnetic Picture (REMP). Assuming a total height of at least 2.5 metres/m (8.2 feet/ft) for a standing soldier and the TLS backpack’s antennas, Signals of Interest (SOIs) across a range of up to six kilometres (3.7 miles) should be detectable. Although a single backpack can perform emitter direction-finding, by networking two or more, backpacks, it maybe possible to geolocate a SOI’s source. It does not appear that the TLS backpack can electronically attack hostile emitters. SOI details can be sent upwards where commanders will then decide whether the signal’s source should be attacked electronically and/or with cyberwarfare using a system like the TLS-BCT or engaged kinetically. No information has reached the public domain regarding the TLS backpack’s wavebands. Given that the system is intended for use at or near the tactical edge, it is possible it can detect, identify and share information on SOIs within a 30 megahertz/MHz to six gigahertz waveband. This waveband would allow TLS backpack operators to capture SIGINT on a wide array of military and civilian very/ultra-high frequency radio communications at, or near, the tactical edge.
Australasia
TLS backpack systems destined for the Australian and New Zealand armies will likely equip these forces’ respective EW formations. In New Zealand, land manoeuvre force EW is the preserve of the 1st Command Support Regiment, as we articulated in this article. Australian Army electronic warfare units include the 7th Signals Regiment. No details have been made available on when these TLS backpacks will equip each country’s forces nor how many systems will be delivered. The acquisition of the TLS backpacks makes sense for both armies. Australia and New Zealand are both important US allies in the Asia-Pacific and share a close working relationship with the US military. US Army units in the region, notably those in the Republic of Korea and Japan, will receive the TLS EW capabilities listed above. These capabilities would be heavily relied upon to support the electromagnetic battle should war erupt with the People’s Republic of China. Any region-wide conflict would invariably involve both Australia and New Zealand who may have to fight alongside US Army land manoeuvre units.
Having a common dismounted SIGINT system deployed across three of the US’ most important allies in the region will help create powerful tactical EW synergies. This commonality will help simplify the logistics burden for all three nations through the deployment of a single type of dismounted tactical EW system. Such an approach could help pay tactical, and even operational, dividends in the quest to win and sustain electromagnetic superiority and supremacy over future opponents.
05 Nov 25. Enterprise Control Systems redefines data link management across air, land, and sea.
- Enterprise Control Systems (ECS) launches ECS Connect for better data link intelligence across land, sea, and air.
- First-of-its-kind data link network manager automates switching between communication protocols to ensure reliability, lower costs, and simplify operations.
Radio frequency (RF) technology specialist Enterprise Control Systems (ECS), part of SPX Communication Technologies, today announces the launch of ECS Connect. An intelligent data link network manager, ECS Connect automatically switches between multiple communication protocols, including COFDM, SATCOM, LTE, Cellular, and MESH, ensuring uninterrupted and reliable transmission of video, audio, and data between air, land, and sea. Designed to meet the growing demand for seamless and secure connectivity in complex mission environments, ECS Connect ensures operators always have access to the most reliable and cost-effective communication channel available without the burden of manual management. Different communication protocols have their own advantages and limitations. Dedicated COFDM links (ECS Evenlode) offer exceptional robustness and are often the primary transmission bearer, but are limited to the coverage available within the ground infrastructure. While alternatives like satellite or cellular can be more cost-effective, they can be less reliable in contested or remote environments.
ECS Connect solves this by intelligently managing and aggregating multiple networks, automatically switching to the optimal connection based on geography, signal strength, and mission demands.
With airborne platforms increasingly required to operate across diverse scenarios from border surveillance to Intelligence, Surveillance and Reconnaissance (ISR), ECS Connect provides the flexibility and assurance needed to maintain a continuous flow of intelligence data. It effectively acts as a managed service in the air, taking over complex link management and reducing pilot burden and the need for additional onboard operators.
“ECS Connect represents a significant step forward in data link technology,” said David Robins, Business Development Director for Data Links at ECS. “We’re enabling customers to move beyond single-solution systems towards a smarter, more adaptive approach to airborne and ground-based communication. ECS Connect is the first step in that journey, delivering the next generation of intelligent, resilient, reliable, any-mission-ready data links.”
“We’re seeing growing demand for secure, real-time data transfer between air and ground, especially as nations seek to strengthen their situational awareness and border security,” commented Ludovic Seixo, Sales Manager at expert radiocommunication distributor SORRAC. “ECS Connect will deliver for customers because it brings reliability, flexibility, and automation together to maintain critical communications even in the most demanding operational conditions.”
Guided by extensive customer feedback and building on ECS’s 30-year heritage of delivering reliable RF technology to defence, security, and public safety organisations, the announcement also marks a shift in ECS’s evolution from a data link hardware provider to a holistic managed connectivity solutions partner. For more information, please visit www.enterprisecontrol.co.uk.
06 Nov 25. Global: Cyber criminal alliance will pose high financial, operational risks to high-profile businesses. Earlier on 6 November, the software company Trustwave confirmed that three renowned ransomware groups (‘Scattered Spider’, ‘ShinyHunters’ and ‘LAPSUS$’) are co-operating to conduct extortion attacks. The alliance (‘SLH’) is also reportedly establishing Extortion-as-a-Service (EaaS) infrastructure to maximise profits. Simultaneously, it has incorporated new capabilities to streamline operations – including data brokerage services – showcasing the rapid expansion of its enterprise despite various takedown attempts. SLH relies on the messaging platform Telegram for command-and-control (C2) communication and has rebuilt at least 16 new channels within hours of being taken down since August, highlighting the alliance’s resources and resilience. Scattered Spider alone has caused significant financial and reputational damage to several high-profile UK and US-based companies since early 2025. SLH activity also suggests that the alliance intends to establish long-term infrastructure for the expansion of financially motivated operations. Consequently, we assess that SLH will pose high financial and operational risks to data-rich businesses in the medium term. (Source: Sibylline)
06 Nov 25. Didn’t See That Coming. Ukrainian forces revealed in early October they had successfully attacked a Russian 12A6 Sopka-2 ground-based air surveillance radar deployed close to the latter’s border with Ukraine as part of an ongoing Ukrainian offensive counter-air campaign against Russia’s integrated air defence system. It appears that the Ukrainian military is harnessing uncrewed aerial vehicle attacks inside Russia’s borders to degrade the country’s strategic integrated air defence system. On 2nd October, Ukrainian news sources stated that kamikaze Uncrewed Aerial Vehicles (UAVs) deployed by the country’s special forces had attacked 12A6 Sopka-2 S-band (2.7 gigahertz/GHz to 2.85GHz) and P-14F Lena (North Atlantic Treaty Organisation/NATO reporting name Tall King) Very High Frequency (VHF: 169 megahertz/MHz to 175MHz) ground-based air surveillance radars. The two systems were collocated in Russia’s Voronezh Oblast which directly borders northeastern Ukraine. The reports continued that both radars were believed to be under the command of the nearby Buturlinivka airbase. The facility at Buturlinivka does not appear to house any Russian Aerospace Forces (RASF) on a permanent basis. Instead, the airfield appears to be made available to units as and when needed. Satellite imagery taken in 2025 available on the Google Maps website appears to show RASF Su-34 (NATO reporting name Fullback) ground attack aircraft at the facility with air-to-surface ordnance stored nearby. Given the proximity of the base, it is likely these aircraft were supporting ongoing Russian combat operations in Ukraine.
The radars
As Armada has chronicled in the past the Sopka-2 has a range of circa 243 nautical miles/nm (450 kilometres/km). Open-source information says the radar can detect a target at circa 328,084-feet/ft (100,000-metres/m) altitude at circa 65nm (120km). Targets at circa 32,808ft (10,000m) altitude can be detected at ranges of 216nm (400km). The P-14F has a range of around 594nm (320km) for airborne targets. Reports noted that both radars had been used to monitor the skies over Russia’s eastern borders with Ukraine to detect, identify and track, henceforth known as process, UAVs. It is likely that the P-14F is used for the initial processing of targets at range. As these targets approach, the Sopka-2 is used to provide more detailed target information. This information is then shared with air defence units so that targets can be engaged either by combat aircraft or ground-based air defences. One can assume that, on this occasion, both radars were incapable of processing the UAVs that destroyed them. Alternatively, perhaps one, or both, radars were able to process the targets, but Russian air defenders were unable to engage the threats either kinetically and/or electronically.
Assessment
This is not the first time that Ukrainian forces have struck radars supporting Russia’s strategic Integrated Air Defence System (IADS). Open sources state that a 55ZH6U (NATO reporting name Tall Rack) VHF (133MHz to 144MHz/216MHz to 225MHz) ground-based air surveillance radar in the Bryansk Oblast on Russia’s border with northern central Ukraine was struck in April 2024. The 55ZH6U is believed to have an instrumented range of 378nm (700km), a maximum altitude of 262,467ft (80,000m) and can track up to 200 targets simultaneously. Other attacks have included the destruction of a 39N6 Kasta-2E (NATO reporting name Flat Face-E) ground-based air surveillance radar in the Kursk Oblast, on Ukraine’s northeastern border. Open sources say that the 39N6 transmits in L-band (1.215GHz to 1.4GHz) and can achieve ranges of circa 81nm (150km). The Ukrainian military is clearly performing an offensive counter-air campaign against Russia’s strategic IADS, particularly IADS targets close to Ukraine’s northern and eastern borders with Russia. By attacking these radars, the Ukrainian military is progressively degrading Russian radar coverage in this part of the country. Rolling back Russian radar coverage provides Ukrainian UAV operators more latitude in then hitting other Russian targets located in areas now free of radar surveillance. It helps Ukraine that these radars will be complex, expensive systems to build and replace. To further complicate matters, international sanctions on Russia aimed at curtailing her access to sophisticated electronics, while not perfect, will hamper the manufacture of replacement systems at pace. At the strategic level, Ukraine’s actions show that Russia’s strategic IADS is vulnerable, particularly to UAV strikes. This is a tactic that NATO and allied nations could adopt against the IADS should they find themselves fighting Russia in the future. Individual actions against individual radars may seem small, but added together, they may well have a growing significance. (Source: Armada)
06 Nov 25. November Spectrum SitRep. Textron is developing a counter-battery radar electronic warfare payload for the company’s UAV-based Damocles-LE air-to-surface/surface-to-surface weapon. Armada’s monthly round-up of all the latest electronic warfare news in the product, programme and operational domains.
Damocles-LE Counter-Battery Radar Variant
Textron has shared with Armada that the company is developing a dedicated counter-battery radar electronic warfare payload for its Damocles Launched Effect (Damocles-LE) system it unveiled in July. Damocles-LE is a surface-to-surface/air-to-surface weapon employing an advanced, explosively formed penetrator for top attack missions against surface targets, according to company literature. Alongside the kinetic payload, Damocles-LE can accommodate Electronic Warfare (EW) and intelligence, surveillance and reconnaissance packages. The company declined to share which radar frequencies the EW payload will cover. Given the counter-battery radar mission, it is likely these frequencies will include S-band (2.3 gigahertz/GHz to 2.5GHz/2.7GHz to 3.7GHz) and C-band (5.25GHz to 5.925GHz) at a minimum. Damocles-LE uses Ascent Aerospace’s NX-30 Spartan uncrewed aerial vehicle. Textron continued that it expects to reach Technology Readiness Level Six (TRL-6) by April 2026 for Damocles-LE. US Department of Defence definitions state that TRL-6 denotes that a representative model or prototype system has been tested in a relevant environment.
EW-EDMT Unveiled
ERA demonstrated the company’s new EW-EDMT system at the recent EW Live event in Tartu, southern Estonia. A basic version of the product is already in service, and the full version is scheduled for delivery to its first customer early next year.
ERA took advantage of this year’s EW Live event held in Tartu, southern Estonia between 23rd and 26th September to unveil the company’s Electromagnetic Warfare ERA Data Management Toolkit (EW-EDMT). An ERA press release said that the EW-EDMT can manage electronic support measure databases and automatic data processing. Delegates attending EW Live were able to see the EW-EDMT in action. The document continued that the system processes Signals Intelligence (SIGINT), particularly Electronic Intelligence (ELINT), from reception to dissemination: “It’s main purpose is to determine (the) identification of targets such as the platform, emitter and emitter node”. By using the EW-EDMT SIGINT professionals can extract information relevant to threat libraries and emitter databases. ERA told Armada in a written statement that the EW-EDMT architecture comprises an emitter tool to manage and update reference databases. A data mining tool stores, processes and evaluates ELINT data. The EW-EDMT’s mission tool maintains situational awareness and detects priority targets during missions. Finally, the target tool provides detailed information on military platforms, emitters and weapons systems to assist order-of-battle creation. The company added that a basic version of the EW-EDMT has already been delivered to over five North Atlantic Treaty Organisation (NATO) and non-NATO nations. The first full version of the EW-EDMT is expected to be delivered to an undisclosed customer in early 2026.
New NEWTS
The NEWTS IQ is the latest edition to MASS’ NEWTS electronic warfare training system. NEWTS IQ can use in-phase and quadrature data to help replicate an accurate electromagnetic environment.
Also taking advantage of EW Live to launch new products was MASS which revealed the latest version of the company’s NEWTS electromagnetic environment training system. Dubbed NEWTS IQ, the system provides the means to replicate realistic electromagnetic environment factors using in-phase and quadrature data. This replication can be done without needing to emit any radio frequency signals, says the company on its website. Stuart Willumsen, MASS’ head of spectrum warfare training, told Armada that “all NEWTS IQ hardware … can deliver targets to CEMA (Cyber and Electromagnetic Activities) training audiences at a spectral density that enables full decoding and decryption, which means that they are, to all intents and purposes, targets which present as authentic”. Another useful training feature is that NEWTS IQ can replicate a congested and contested electromagnetic environment for students. The replication is provided using wide band recordings. Alternatively the local live electromagnetic environment can be injected into NEWTS IQ: “These separate aspects of NEWTS IQ mean a fully realistic, immersive and importantly, challenging environment for CEMA training audiences, making them more proficient at their primary role as well as expediting knowledge transfer,” Mr. Willumsen continues. NEWTS IQ is already in service with two United Kingdom customers. MASS expects further iterations and enhancements of the overall NEWTS family in the future: “NEWTS IQ is an evolving capability, which is in the spirit of the rapid development cycles forced by the current operational context,” Mr. Willumsen concluded. (Source: Armada)
05 Nov 25. Enabling the Swarm: Equipping Drones with Electronic Warfare Capabilities. Northrop Grumman is redefining the future of electronic warfare by creating cutting-edge technology that delivers unmatched capability – even in the smallest of systems. The modern battlespace is defined by contested and degraded environments where allies and adversaries compete for crucial bandwidth. To maintain a decisive advantage and degrade the capabilities of enemy forces, the U.S. and its allies require electronic warfare (EW) technology that is not only advanced but also agile, resilient and scalable. That’s why Northrop Grumman, has developed a revolutionary technology, compact yet powerful, that can dominate in any environment. At Silent Swarm 2025, an annual U.S. Navy demonstration of advanced EW for small, unmanned systems, Northrop Grumman delivered a live, proof-of-concept. On-site, the company integrated its Tactical Edge Electromagnetic Solutions (TEEMS) onto compact platforms – ranging from tiny robots to unmanned surface vessels and drones – demonstrating how these small systems can produce outsized impacts. With TEEMS embedded, these platforms become powerful tools capable of detecting and jamming enemy signs with speed and precision, ensuring superiority across every domain.
A Big Punch in a Tiny Package
In contested environments, where every inch of space and ounce of weight matters, EW solutions must combine top-tier performance with ultra-efficient size, weight and power (SWaP) for unmatched mission flexibility. Northrop Grumman’s TEEMS solution delivers exactly that, integrating high-performance EW capabilities into a compact 1U Modular Payload. Measuring smaller than a business card, it was not only the smallest at the event, but also the most capable, packing powerful performance into an unprecedented form factor. The demonstration was a testament to the power of resilient, scalable technologies, designed for mobility. While on-site, Northrop Grumman’s team:
- Countered Evolving Threats: The team successfully geolocated a frequency-agile target emitter – which are known to be difficult to disrupt – and performed stand-in jamming.
- Achieved Intelligent, Integrated Operations: Through the integration with Tactical Assault Kit software, the team remotely controlled multiple unmanned ground and surface units across a large, 50-square-mile operational area. The system’s ability to seamlessly coordinate with these diverse assets demonstrated its capacity for intelligent, integrated mission solutioning.
- Maximized Combat Impact: In a single, simultaneous action, TEEMS knocked out three different radios that were spread across a wide frequency range.
Enabling the Swarm: Equipping Drones with Electronic Warfare Capabilities
Northrop Grumman is at the forefront of building technology that delivers maximum impact – packing big power into pocket-sized tech. The Tactical Edge Electromagnetic Solutions (TEEMS) Tactical Edge Device packages “Rock Ridge,” Northrop Grumman’s state-of-the-art electronic warfare (EW) transceiver, into a compact 1U Modular Payload. (Photo Credit: Northrop Grumman)
“Silent Swarm 2025 was a resounding success, not just for its technological achievements, but because it underscored our team’s ability to innovate and execute under pressure,” said Angela Johns, vice president, weapons integration & mission solutions, Northrop Grumman. “This effort reinforces our commitment to delivering mission-ready solutions tested in simulated environments and solidifying our role in advancing tactical operation dominance both today and in the future.”
By successfully showcasing that high-end electronic warfare (EW) capabilities can be integrated in a compact, modular package, Northrop Grumman is empowering the U.S. and its allies to remain mission-ready at the tactical edge. The work accomplished at Silent Swarm 2025, along with technology such as the TEEMS device, illustrates how the company is architecting the advantage for today’s performance and tomorrow’s success along the tactical edge. (Source: ASD Network)
05 Nov 25. Sitep Australia Joins Rohde & Schwarz Team for Hunter Class Frigate Communications. Rohde & Schwarz Australia has awarded a contract to Sitep Australia to equip the Royal Australian Navy’s first three Hunter class frigates with its world-leading antenna technology for the Ultra High Frequency Military Satellite Communication (UHF-MILSATCOM) system. World-leading antenna technology from Sitep will be equipped as part of the Hunter class frigate UHF-MILSATCOM system following a contract with Rohde & Schwarz to supply their NAVICS communications technology for the first three ships of the Hunter Class Frigate Program.
Managing Director of Rohde & Schwarz Australia Gareth Evans said, “Sitep Australia has been operating in Australia since 1999, establishing sovereign communication and navigation systems and service delivery capabilities here. With their proven track record, we’re pleased to have them onboard and are confident they will deliver a high-quality solution that integrates with the ship and the NAVICS Multi-Level Security communications system to meet the Navy’s requirements.”
Raffaele Iannizzotto, Business Development Director of Sitep Australia, said: “This contract clearly validates the highly collaborative working relationship established with Rohde & Schwarz. Sitep Australia’s antenna technology for the UHF-MILSATCOM antenna systems have been installed and are operational on Anzac class frigates, Hobart class destroyers, and AOR vessels of the Royal Australian Navy. This demonstrates our commitment to building a resilient local capacity to innovate, create, and supply communication systems. We are a trusted partner to both the Commonwealth and Rohde & Schwarz, supporting the Sovereign Defence Industrial Priority of Continuous Naval Shipbuilding and Sustainment.” (Source: ASD Network)
05 Nov 25. Bittium Corporation’s Subsidiary Bittium Wireless Ltd has signed a Framework Agreement in the Field of Command-and-Control Systems with the Finnish and Swedish Defence Forces. Inside Information: Bittium Corporation’s Subsidiary Bittium Wireless Ltd has signed a Framework Agreement in the Field of Command-and-Control Systems with the Finnish and Swedish Defence Forces
Bittium Corporation, Stock Exchange Release, 5 November 2025, at 1.30 pm (CET+1)
Tommi Kangas, Senior Vice President Bittium Group’s Defense & Security Business Segment, and Major General Tero Ylitalo, Chief of the Finnish Defence Forces Logistics Command, and Johan Andersson, Deputy Director Command and Information Systems Division, Swedish Defence Materiel Administration (FMV), have today signed a framework agreement in the field of command-and-control systems (C4I, Command, Control, Communications, Computers and Intelligence). The agreement enables the procurement of Bittium’s tactical communication systems and products, software-defined radios, as well as security software and phones. The modern, software-defined tactical communication system Bittium Tactical Wireless IP Network™ and the related software-defined Bittium Tough SDR™ radios have been developed in cooperation with the Finnish Defence Forces. In addition to Finland, Bittium’s solutions are used in four European countries as part of their defence command-and-control systems, and pilot projects are ongoing in several other countries. The framework agreement continues the procurement cooperation between Finland and Sweden in the field of command-and-control systems, covering products and services that provide a common situational awareness, communications, intelligence, and decision support for command operations and troop leadership. The framework agreement also enables joint product development between Finland, Sweden, and Bittium. The newly signed framework agreement is initially valid for ten years, after which it will automatically continue for one year at a time. Norway and Denmark, who are also participating in Nordic defence cooperation may also join the agreement.
“Cooperation between Finland and Sweden in the field of defense has become commonplace, and this is yet another demonstration of its effectiveness. Joint framework agreements enable cost-effective joint procurements, which improve the countries’ ability to operate together. Joint framework agreements in the field of command-and-control systems allow for larger procurement volumes, resulting in lower prices for products and services. These agreements also enhance our ability to engage in joint product development with the system supplier. With this agreement, we achieve broad benefits for our defense,” says Finnish Minister of Defence Antti Häkkänen.
“We are proud that Bittium’s solutions meet the future needs of defence. Modern defense forces require not only reliable and resilient communications but also high-level security, interoperability, and flexibility” says Tommi Kangas, Senior Vice President, Bittium’s Defense & Security Business Segment and continues “We are excited about the opportunity to expand cooperation to other Nordic countries through this agreement. Harmonizing the communication solution between the Nordic countries would enable efficient and seamless communication in all defense operational domains”.
“Developing command-and-control systems in cooperation with Sweden strengthens our defence capability and improves the interoperability of our troops. Joint solutions enable efficient information exchange and decision-making in all operational domains. This agreement is a step towards even closer Nordic defence cooperation,” says Major General Tero Ylitalo, Chief of the Finnish Defence Forces Logistics Command.
04 Nov 25. Indicium and Mesh-AI announce their integration to form Indicium AI, creating one of the world’s leading data and AI consultancies. Backed by Columbia Capital, the combined organization brings together deep expertise, cutting-edge technology, and world-class talent to accelerate enterprise transformation across the Americas, Europe, and Latin America (LATAM). Both brands will continue to operate independently until Q1 2026, when the new brand, Indicium AI, will be officially launched and business operations will be integrated.
A Strategic Partnership for the Future of Enterprise AI
The union brings together two leaders at the forefront of data and AI innovation with clients such as National Grid, Experian, PepsiCo, and Roche. Both companies drive enterprise transformation through AI and serve enterprises across Financial Services, Energy & Utilities, Pharma, Retail & CPG, Manufacturing, and Media, among others. Indicium’s expertise in data modernization and AI execution joins Mesh-AI’s strategic capability in enterprise data and AI. Together, they deliver end-to-end solutions that help Fortune 500 and global enterprises unlock measurable value from data and AI.
“We’re incredibly excited to bring these two innovative companies together,” said Jason Booma, Partner at Columbia Capital. “This integration combines exceptional talent, technology, and vision to address the most pressing data and AI challenges facing enterprises today. Together, we seek to create an unparalleled suite of solutions to enable enterprises to accelerate data and AI transformation on a global scale.”
Kelly Manthey has been appointed Global CEO of Indicium AI. A proven leader with over 25 years of experience, she previously served as CEO of Kin + Carta, where she led the global consultancy and operations across multiple markets. Her engineering background and track record in international growth positions her to lead the next chapter of this global data and AI powerhouse.
“I am thrilled to be leading this business. By uniting the exceptional talents of Indicium and Mesh-AI, we are creating an unparalleled customer proposition,” said Kelly Manthey. “We combine world-class expertise, technology, and talent to accelerate enterprise transformation and unlock measurable value from data and AI for the enterprise with unmatched clarity, speed, and capability.”
Matheus Dellagnelo, former CEO of Indicium, will serve as CEO Americas, and Jacob Parsons, former CEO of Mesh-AI, will serve as CEO Europe.
Partnering with the Best to Drive Innovation
The combined company continues to collaborate closely with industry leaders including Databricks, AWS, OpenAI, Anthropic, and Microsoft to deliver responsible, scalable innovation for enterprises worldwide. Databricks Ventures invested in Indicium in September 2025 to advance shared goals in data modernization and enterprise AI transformation.
“Our recent investment in Indicium reflects a shared commitment to shaping the future of enterprise AI,” said Kori O’Brien, Senior Vice President, Global Partnerships at Databricks. “We’ve seen firsthand how Indicium delivers data and AI transformation on the Databricks Data Intelligence Platform with speed, precision, and measurable results. Now, with the creation of Indicium AI, they are poised to drive even more customer value and scale.”
A New Era for Data and AI
With an expanded presence across the Americas, Europe, and LATAM, this integration enhances the company’s ability to serve multinational enterprises. As enterprises accelerate AI adoption and face challenges unlocking its full value, they seek partners capable of delivering measurable impact at global scale. Indicium AI emerges as the only specialist data and AI consultancy operating globally. Its mission is to deliver end-to-end data and AI transformation, helping the world’s most complex enterprises embrace this shift with clarity, speed, and capability.
With over 600 data and AI specialists and a portfolio of Fortune 500 clients, the combined organization is positioned to shape the future of intelligent enterprise transformation and capture new opportunities in the rapidly growing global data and AI market.
Empowering People and Culture
This integration creates expanded career opportunities for professionals who want to shape the future of data and AI. Both teams share a culture of collaboration, curiosity, and impact, and are hiring globally.
About Mesh-AI
Headquartered in London, Mesh-AI is a data and AI consultancy that helps enterprises leverage data and AI at scale to achieve transformative outcomes. With deep expertise in highly regulated industries such as financial services and energy & utilities, Mesh-AI enables organizations to unlock value, enhance resilience, and drive innovation. Learn more at www.mesh-ai.com.
About Indicium
Headquartered in New York, Indicium is a global data and AI services company helping enterprises migrate faster, optimize platforms and build scalable data products. Our team of more than 500 certified experts delivers across the full data lifecycle. Our proprietary AI-enabled IndiMesh framework powers every engagement with collective intelligence, proven expertise, and rigorous quality control. Industry leaders like PepsiCo and Bayer trust Indicium to reduce risk, accelerate outcomes and deliver lasting value. Visit www.indicium.ai.
04 Nov 25. Global: New backdoor attack highlights increased security risks via abuse of legitimate technologies. On 3 November, the technology company Microsoft reported that unnamed threat actors had used a new backdoor (‘SesameOp’) to conduct a long-term cyber espionage operation. While the initial attack vector is unclear, threat actors executed a malware loader and first-stage backdoor to install SesameOp after infiltrating the targeted system. SesameOp exploited built-in capabilities from the Assistants Application Programming Interface (API) created by the artificial intelligence (AI) company OpenAI for secure command-and-control (C2) communication and storage. Threat actors also used legitimate cloud services to store SesameOp, further illustrating the increased integration of legitimate technologies into malicious cyber activity. The adoption of these services enabled threat actors to remain obfuscated and maintain persistence within compromised systems for several months before being detected, showcasing the operation’s stealth. OpenAI reportedly disabled the API key after Microsoft discovered the attack in July. However, this operation highlights the security risks associated with the increased exploitation of legitimate technologies. (Source: Sibylline)
04 Nov 25. STV Group a.s. (“STV”), one of the world’s fastest-growing defence innovators, has signed a multi-year licence agreement to use Post-Quantum’s groundbreaking quantum-safe communications platform and signed a Strategic Cooperation Agreement to accelerate deployment across Europe, NATO, and global defence markets. With quantum computing threatening to render traditional encryption obsolete, the move positions STV at the forefront of the cybersecurity revolution – arming governments, defence forces, and enterprises with next-generation resilience against “Harvest Now, Decrypt Later” attacks. By fusing Post-Quantum’s NATO-tested modular platform with its own world-class defence solutions, STV is setting a new global benchmark for secure communications and digital trust. Together, the two companies are delivering the most advanced, future-proof systems to protect sensitive data and mission-critical operations – ensuring that even in the quantum era, allied communications remain impenetrable. The partnership represents a decisive leap forward, combining STV’s defence innovation track record with Post-Quantum’s pioneering expertise to deliver communications and data protection systems that go beyond current industry standards.
JUDr. Pavel Kudrhalt, CEO of STV, said: “This isn’t just about acquiring technology – it’s about building an uncompromising, end-to-end secure ecosystem for the future. Our customers demand full supply chain assurance, from manufacturing and tamper-proof transport to deployment and monitoring. With the rising threat of ‘Harvest Now, Decrypt Later’ attacks, quantum-safe defences are no longer optional. Post-Quantum’s platform doesn’t just lead the field – it allows STV to be the first-mover to redefine the very standards of digital trust in defence solutions. By embedding their technology into our portfolio, we are giving NATO allies, EU partners, and national clients the strongest possible protection for the quantum era – whether that’s safeguarding command and control chains, operating mission-critical drones, or deploying munitions in battlefield communications.”
Rikky Hasan, CEO of Post-Quantum, added: “STV’s vision and leadership in defence innovation make them the ideal partner. Together we are unleashing a new wave of secure, quantum-safe solutions that protect the world’s most sensitive data against today’s adversaries and tomorrow’s quantum threats. Our modular approach to Identity, Transmission and Encryption – already proven in NATO environments – offers the fastest and most agile way to integrate into STV’s global portfolio. This is a proud moment for both companies, and a milestone for global cybersecurity.”
This acquisition and alliance signal the dawn of a new era: one where quantum-resilient platforms are no longer optional, but essential. United by a shared mission to safeguard the future, STV and Post-Quantum are leading the charge toward a world where critical communications remain impenetrable – even in the face of quantum computing’s disruptive power.
About STV
STV Group a.s. is one of Europe’s fastest-growing defence innovators, delivering advanced security and defence solutions to governments, NATO allies, and commercial partners worldwide. Headquartered in the Czech Republic, the company combines cutting-edge engineering with a bold vision for the future of security. Building on a century of industrial tradition, STV Group has become the Czech Republic’s leading producer of munitions, loitering systems, armoured vehicle platforms and integrated lifecycle services. The group is also a European leader in ecological disposal and demilitarisation of surplus ammunition, underscoring its commitment to safety and sustainability. With NATO-tested technologies and global partnerships, STV Group is trusted to deliver the resilient, future-proof capabilities that keep nations secure in an era of emerging threats.
About Post-Quantum
Post-Quantum is leading the charge into the quantum era by upgrading the world’s encryption. Its quantum-safe platform protects organisations across their entire digital footprint with modular software for Identity, Transmission, and Encryption—designed to be interoperable, crypto-agile and seamlessly backward compatible. Already trusted by NATO, critical national infrastructure providers, and major financial institutions, Post-Quantum has a proven track record in safeguarding mission-critical data. The company is the inventor of NTS-KEM (now known as Classic McEliece in the NIST competition) and the author of the IETF’s Hybrid Post-Quantum VPN standard, which is now the global benchmark for secure connectivity. With its pioneering technologies, Post-Quantum is ensuring the world stays one step ahead of the quantum threats.
03 Nov 25. Bittium, a leading supplier of resilient communications solutions based on software-defined radio technology, continues development of interoperable ESSOR waveform for tactical communications as part of the multinational a4ESSOR joint venture. a4ESSOR S.A.S (Alliance for ESSOR – European Secure Software Defined Radio) develops European secure software-defined radio (SDR) technology for military use and has signed a new procurement contract with the intergovernmental Organisation for Joint Armament Cooperation (OCCAR) for the next, fourth stage of development of ESSOR technology. The contract covers capability development for the ESSOR High Data Rate Waveform (EHDRWF) that can be ported to national software-defined radios. Through this unique approach, any nation can use its own radio and be interoperable with other nations in their tactical communications. The contract for the ESSOR Development Stage #4 (ES4) is valued in excess of EUR 47 m. Work will be shared, in relation to the shares of the member states, between the six companies participating in a4ESSOR: Bittium (Finland), Indra (Spain), Leonardo (Italy), Radmor (Poland), Rohde & Schwarz (Germany), and Thales (France). The work is split in relation to the shares of the member states, where Bittium’s share is significantly lower than the directly calculated relative proportion would be. The six nations involved and their respective industry leaders have then been working to add new features, such as electronic protection measures and support of modern cryptographic standards, leading to several successful interoperability demonstrations and qualification tests, and to the adoption of ESSOR High Data Rate Waveform as NATO STANAG 5651 in 2023. Under the new contract, a4ESSOR will design a common mission framework aimed at a shared planning capability for the network parameters of the EHDRWF. Once implemented in the command-and-control system of each nation, the mission framework will ensure high interoperability at operational level, allowing quick and accurate deployment of multinational EHDRWF networks.
a4ESSOR will conduct field tests of the EHDRWF on the various radio systems to assess the maturity, performance, and reliability of the waveform in various scenarios, providing valuable feedback for future waveform enhancements. The field test will also include trials in different operational environments (urban, rural, and hilly terrains), line-of-sight/non-line-of-sight and mobility scenarios, as well as analysis of waveform performance under potential interference conditions. Furthermore, the contract will define an ESSOR in-service support framework and will set up an ESSOR laboratory as the reference for interoperability validation.
“Enabling seamless defense cooperation with solutions that are based on software-defined radio technology is at the core of our leading knowhow and expertise. We put a lot of emphasis on the a4ESSOR collaboration and the development of the ESSOR waveforms. The ESSOR High Data Rate Waveform has already been ported to the Bittium Tough SDR radio platforms, and with the new development phase beginning now, our customers will gain new operational capabilities to support with their objectives,” said Tommi Kangas, Senior Vice President of Bittium’s Defense & Security business segment.
Lino Laganà, President and General Manager of a4ESSOR, said “a4ESSOR has been active for over 16 years playing a crucial role to develop and test ESSOR capabilities and technologies to address multinational defence requirements as a valuable solution in addition to the existing legacy waveforms. The ESSOR HDRWF standard is capable to facilitate seamless communications across diverse radio platforms and nations, affirming its potential to enhance collaborative defence operations across Europe and NATO countries. The mission framework will allow a quantum leap forward in terms of interoperability among armed forces from various countries, as it will define what’s needed to achieve the interoperability in mission planning and management. We will work at defining the required solutions towards their integration onto command-and-control systems of the various countries. It’s an evolution enabler, from technical to operational interoperability.”
Lino Laganà continued “The project aligns with the European Union’s strategic objectives of strengthening defence cooperation, enhancing autonomy, and improving the efficiency of combined military missions. By equipping EU member states with secure, interoperable, and scalable communication solutions, the initiative strengthens Europe’s collective ability to respond to threats and ensures seamless coordination in operations.”
03 Nov 25. a4ESSOR S.A.S (Alliance for ESSOR – European Secure Software Defined Radio), a multinational joint venture that develops secure software defined radio (SDR) technology, has signed a procurement contract with the intergovernmental Organisation for Joint Armament Cooperation (OCCAR) to carry out the capability deployment of the ESSOR High Data Rate Waveform – EHDRWF. The waveform can be ported to national software-defined radios; through this unique approach, any nation can use its own radio and be interoperable with other nations in their tactical communications. The contract for the so called ESSOR Development Stage #4 (ES4) is valued in excess of 47m EUR. The six nations involved and their respective industry leaders (Finland – Bittium, France – Thales, Germany – Rohde & Schwarz, Italy – Leonardo, Poland – Radmor, Spain – Indra) have then been working to add new features, such as electronic protection measures and support of modern cryptographic standards, leading to several successful interoperability demonstrations and qualification tests and to the adoption of ESSOR High Data Rate Waveform as NATO STANAG 5651 in 2023. Under the new contract, a4ESSOR will design a common mission framework aimed at shared planning capability of network parameters of the EHDRWF. Once implemented in the command-and-control system of each nation, the mission framework will ensure high interoperability at operational level, allowing quick and accurate deployment of multinational EHDRWF networks.
a4ESSOR will conduct field tests of the EHDRWF on the various radio systems to assess the maturity, performance and reliability of the waveform in various scenarios, providing valuable feedback for future waveform enhancements. The field test will also include trials in different operational environments (urban, rural and hilly terrains), line-of-sight/non-line-of-sight and mobility scenarios, as well as analysis of waveform performances under potential interference conditions. Furthermore, the contract will define an ESSOR in-service support framework and will set up an ESSOR laboratory as the reference for interoperability validation.
Lino Laganà, President and General Manager of a4ESSOR, said “a4ESSOR has been active for over 16 years playing a crucial role to develop and test ESSOR capabilities and technologies to address multinational defence requirements as a valuable solution in addition to the existing legacy waveforms. The ESSOR HDRWF standard is capable to facilitate seamless communications across diverse radio platforms and nations, affirming its potential to enhance collaborative defence operations across Europe and NATO countries.”
“The mission framework will allow a quantum leap forward in terms of interoperability among armed forces from various countries, as it will define what’s needed to achieve interoperability in mission planning and management. We will work at defining the required solutions towards their integration onto command & control systems of the various countries. It’s an evolution enabler, from technical to operational interoperability.”
Lino Laganà continued “The project aligns with the European Union’s strategic objectives of strengthening defence cooperation, enhancing autonomy, and improving the efficiency of combined military missions. By equipping EU member states with secure, interoperable, and scalable communication solutions, the initiative strengthens Europe’s collective ability to respond to threats and ensures seamless coordination in operations.”
03 Nov 25. Europe: Diplomatic entities face long-term cyber espionage risks from China-affiliated threat actors. On 1 November, international news outlets reported that a China-nexus group (‘UNC6384’) has targeted diplomatic entities across Europe in a cyber espionage operation since at least September. The group distributes phishing emails containing a malicious LNK file to infiltrate targeted systems and to deploy malicious payloads. It then exploits a zero-day vulnerability ‘(ZDI-CAN-25373’) to execute the LNK attachment onto compromised systems, in order to install a remote access trojan (RAT; ‘PlugX’) via a multi-stage process. PlugX enables data exfiltration and monitoring; it is executed directly within a system’s memory to enhance obfuscation, which indicates that the campaign likely aims to maintain prolonged persistence for strategic data collection. The campaign has targeted diplomatic entities across Europe, including in Belgium, Hungary, Italy, the Netherlands and Serbia, showcasing its highly co-ordinated nature. We assess that this campaign underscores the long-term security and cyber espionage risks faced by strategic sectors in Europe amid ongoing geopolitical hostilities. (Source: Sibylline)
31 Oct 25. DRDO tests new airborne EW suite for LCA Mk 1A. India’s Defence Research & Development Organisation (DRDO) is flight-testing its new Swayam Raksha Kavach (SRK) airborne electronic warfare (EW) suite that will be fielded by the Indian Air Force’s (IAF’s) future fleet of Hindustan Aeronautics Limited (HAL) Tejas light combat aircraft (LCA) Mk 1A fighter aircraft. Simultaneously, DRDO has updated its older D-29 EW suite that was developed over a decade ago for use by IAF Mikoyan-Gurevich MiG-29 fighter aircraft. Development of the SRK suite began in 2021, and it is currently being subject to flight tests using an LCA Mk 1A, a DRDO official told Janes on 30 October on the sidelines of DRDO’s Samanvay 2025 industry summit in Bangalore. During the two-day summit (held on 29 and 30 October), DRDO transferred several technologies to industry partners. This included the transfer of all-improved D-29 EW suite-related technologies and intellectual property (IP) held by DRDO’s Combat Aircraft Systems Development and Integration Centre (CASDIC) to a production partner, Bharat Electronics Limited (BEL).
SRK capabilities
Janes understands that the SRK is an evolution of the D-29 EW suite and has improved capabilities.
The suite comprises a radar warning receiver (RWR) integrated into the body of the fighter aircraft and a jammer pod installed on a hardpoint. According to the official, DRDO expects to conclude flight trials of the system by mid-2026, with deployment on the Mk 1A platform from the end of 2026. (Source: Janes)
31 Oct 25. Cyber Update Key points.
- Government and critical national infrastructure (CNI) sectors face long-term cyber espionage risks from the Iranian state-sponsored group ‘MuddyWater’ (see Sibylline Cyber Daily Analytical Update – 27 October 2025).
- A new Malware-as-a-Service (MaaS) operation underscores the sustained financial risks to Android users through the distribution of ‘HyperRat’, a new remote access trojan.
- A ransomware operation (‘Everest’) poses increased security, data-theft and financial risks to data-rich and high-profile sectors
- Cyber attacks on Ukrainian organisations highlight sustained cyber espionage risks from Russian state-sponsored groups.
- Canadian CNI faces elevated security and operational risks from hacktivist groups
Technical analysis of weekly stories
Threat actors are targeting Android users with HyperRat. This RAT can be purchased as part of a MaaS operation that provides affiliates with a malicious Android Package Kit (APK) to distribute the malware and a centralised control panel, highlighting the continuous growth of cyber criminal enterprises. We assess that threat actors will likely advertise fake applications containing the malicious APK to trick victims into downloading HyperRat onto their devices. Upon deployment, HyperRat can check existing permissions and enumerate all applications installed on compromised devices. This feature allows threat actors to request necessary permissions, as well as to tailor phishing overlays and other prompts, in order to appear legitimate and covertly exfiltrate sensitive data. HyperRat affiliates can manage all infected devices from a centralised panel that communicates in real time with the messaging application Telegram, showcasing the sophistication of its command-and-control (C2) infrastructure. Furthermore, threat groups can bulk send follow-on social engineering messages through compromised devices, underscoring increased propagation risks.
Between June and August, a Russian state-sponsored group (‘Seashell Blizzard’) used Living-off-the-Land (LotL) techniques to conduct cyber attacks on at least two Ukrainian organisations. The first infection reportedly started on 27 June, when threat actors likely exploited multiple software vulnerabilities to infiltrate an unnamed business services firm. Soon after accessing their system, Seashell Blizzard deployed an initial web shell (‘Localolive’) to establish communication with C2 infrastructure and conduct system reconnaissance. On 29 June, the group installed a second web shell to move laterally through the network, before enumerating all system files. It then used scheduled tasks and a PowerShell backdoor to conduct memory dumps, harvest credentials and exfiltrate sensitive data. Seashell Blizzard disabled security protections and avoided deploying heavyweight custom malware payloads, thereby enhancing the operation’s stealth. Some of the techniques the group adopted throughout the attacks resemble the modus operandi of the Russian advanced persistent threat (APT) group ‘Sandworm’, highlighting a potential overlap between the groups. It remains unclear when the second infection started, though it only lasted a week, in contrast to the first operation, which lasted two months and terminated in August.
Non-exhaustive recommendations to mitigate against these threats include:
- Monitor devices and networks for suspicious activity.
- Add available Indicators-of-Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware.
- Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
- Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.
Our cyber word(s) of the week: Memory dump
Definition: A snapshot of a system’s Random Access Memory (RAM) that threat actors often exploit to extract sensitive data from compromised systems.
Example: ‘It then used scheduled tasks and a PowerShell backdoor to conduct memory dumps, harvest credentials and exfiltrate sensitive data’ (see our Technical analysis above). (Source: Sibylline)
————————————————————————————————————————————————————————————————————————————————————————————————————————————-
Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.
We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.
Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.
————————————————————————————————————————————————————————————————————————————————————————————————————————————

