• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • SPECTRA banner
  • Curtiss-Wright banner

BATTLESPACE Updates

   +44 (0)77689 54766
   

  • Home
  • Features
  • News Updates
  • Defence Engage
  • Company Directory
  • About
  • Contact

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

December 18, 2025 by

 

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

—————————————————————————————————————————————————————————————————————————————————————————————————————————————-

18 Dec 25. Hot Lines, Cool Minds. On 20th June 1963, the United States and Soviet Union signed the Memorandum of Understanding Regarding the Establishment of a Direct Communications Line. The memorandum paved the way for what would become known as the Moscow-Washington Direct Communications Link. You may not have heard of this, but you will have almost certainly heard of the ‘hot line’. In many peoples’ imagination, the hot line included red telephones on the desks of the US and Soviet leaders. The Cuban Missile Crisis had erupted a year earlier in October 1963. One of the lessons learned for both sides was a need for the political leadership of both countries to be able to communicate directly with one another in times of strife. Contrary to popular imagination, the hot line did not use red telephones. Instead, a secure teletype machines were employed. Written messages were thought to leave less chance of misunderstanding. By 1986, the teletype machines had been replaced by fax machines (remember them?) As of 2008, the American and Russian leadership has been linked with a dedicated, secure email service. Traffic was originally carried across undersea cables which were later supplemented by satellite communications. The hotline has more than earned its keep being used on numerous occasions to help reduce tensions between the US and the Soviet Union and, after the end of the Cold War, between the US and Russia. A hotline has been in existence between Beijing and Washington DC since November 2007. Like the Moscow-Washington line, the direct link between the United States and the People’s Republic of China has been used on multiple occasions. That said, the Chinese government has also chosen to withhold direct communications channels in times of tension between the two powers. Despite this, these links are being enhanced further following the news in early November that direct military-to-military channels to help deescalate potential flashpoints between the two countries will be established. The decision followed a meeting between US President Donald Trump and his Chinese counterpart Xi Jinping. Both countries should be praised for taking this cause of action, particularly in terms of improving military-to-military direct communications. That hotlines between Washington DC, Moscow and Beijing have helped ease tensions in times of crisis is not in doubt. The stronger the communications between all three powers, the higher the chances that politico-military leaderships can ‘talk things out’. Even a chat between an opposing general and admiral could be just the thing to help to start to diffuse a crisis at the optimum moment. British Prime Minister Winston S. Churchill said that “meeting jaw to jaw is better than war” reflecting on the importance of personal contact in times of trouble. When leaders cannot meet face to face, they can at least write to each other directly. After all, hot lines help cool minds. (Source: Armada)

 

08 Dec 25. GCAP SATCOM Strategy. The Global Combat Air Programme will develop an air platform with an advanced satellite communications capability to ensure connectivity in heavily congested and contested electromagnetic environments. (BAE Systems) More details are emerging regarding the communications architecture that will support the Global Combat Air Programme sixth-generation combat aircraft. The Global Combat Air Programme (GCAP) is a multinational project involving Italy, Japan and the United Kingdom to develop a new combat aircraft. Reports state that the first technology demonstrator aircraft is expected to fly in 2027. Service entry is expected from circa 2035. The aircraft’s communications architecture will be a key enabler for the platform as it is expected to work closely with accompanying Uncrewed Aerial Vehicles (UAVs), inhabited platforms and other military assets. Satellite Communications (SATCOM) form a key part of the aircraft’s connectivity. Armada understands that the jet is expected to benefit from global SATCOM coverage including satellite communications provision over the poles. Traditionally, SATCOM coverage has suffered shortcomings in these areas. GCAP SATCOM requirements emphasise low latency and high bandwidths. These features are particularly important as the pace of contemporary and future air combat places a premium on keeping gaps in signal transmission and reception to a minimum. Likewise, the GCAP platform is likely to continuously collect eye-watering quantities of data via its sensor package. Much of this data will be processed on the aircraft at the point of collection. Processing will depend on Artificial Intelligence (AI) enabled edge computing applications. Nonetheless, the platform will still need to send and receive significant quantities of relevant data to and from combat clouds. These clouds will underpin future operations connecting multitudes of assets as part of the North Atlantic Treaty Organisation’s Multi-Domain Operations (MDO) doctrine.

Operating in congested and contested spectrum

Other requirements for the GCAP SATCOM architecture include the ability to use several different bearer networks, frequencies and wavebands, and to do so seamlessly. This implies that the architecture will use cognitive approaches underpinned by AI. Cognitive communications use AI to continually search for and use optimum channels for communications according to the level at which the local radio spectrum is congested and contested. At the same time, the significant reliability the aircraft will have on SATCOM creates potential vulnerabilities: The plane’s location could be derived via its radio emissions. Moreover, these signals could be jammed or spoofed. A similar risk exists that SATCOM antennas could be exploited as an aperture through which jamming/spoofing waveforms and/or cyberattacks could enter the aircraft. The latter could see malware not only contaminating the platform, but the networks it depends on and other military assets connected therein. Low probability of interception/detection SATCOM waveforms will be front and centre of the aircraft’s electronic protection and communications resilience.

Configurations

How will these requirements for bearer network and frequency flexibility and resilience by realised? Sources close to the programme emphasise the aircraft’s SATCOM system will have a multi-frequency, multi-bearer, multi-orbit design permitting the use of a diverse array of networks and constellations. Avantgarde SATCOM techniques will employed like free space optical communications. Relying on light as opposed to radio signals, this communications methodology does enjoy some protection against electronic attack. The aircraft’s ground element will similarly need to be robust, agile and deployable. The ongoing war in Ukraine continues to show that ground-based SATCOM infrastructure remains a target for electronic warfare. SATCOM receivers are at risk not only from jamming, spoofing and cyberattack, but also from kinetic action. Some questions remain regarding the overall GCAP communications architecture: What will the aircraft employ in terms of conventional radio links? What are the expectations regarding GCAP’s employment of tactical datalinks? Will the aircraft also use cognitive methodologies in its other communications systems? What is the relationship of the aircraft’s radio communications and other RF systems like its radar and EW apparatus? Work is no doubt continuing to address these questions and requirements, although information is yet to reach the public domain. GCAP is following an aggressive schedule with the first flight of the demonstration aircraft expected in two years. The project’s engineers have an aggressive schedule to perfect the aircraft’s communications systems. They must also produce what will arguably be the most advanced connectivity architecture yet installed on a combat aircraft. (Source: Armada)

 

16 Dec 25. Illicit Channels.  Russian forces are also using Starlink terminals for UAV communications. Russia is primarily using the Starlink satellite communications network for backhaul at the tactical edge and for uncrewed aerial vehicle control, Armada has learned. Russian deployed in Ukraine are reliant on both SpaceX’s Starlink and Iridium Communications’ eponymous Satellite Communications (SATCOM) networks. Starlink provides wideband links across Ku-band (14 gigahertz/GHz uplink/10.9GHz to 12.75GHz downlink) and Ka-band (26.5GHz to 40GHz uplink/18GHz to 20GHz downlink) channels. According to Starlink, users typically enjoy download speeds of between 25 megabits-per-second/mbps and 220mbps. Upload speeds of between five megabits-per-second and 20mbps are also achievable. Armada understands that these rates reduce on the battlefield where uplink speeds of circa 3.72mbps and downlink speeds of up to 50.56mbps are routinely witnessed. This reduction can be the result of the deliberate jamming of Starlink frequencies. Latency rates across the link range between 25 milliseconds/ms and 100ms. Iridium Communications’ SATCOM services use L-band frequencies of 1.616GHz to 1.6265GHz. Furthermore K-band frequencies of 19.1GHz to 19.6GHz provide downlink and Ka-band channels using a 29.1GHz to 29.3GHz waveband are used for uplink, according to the company. Each Iridium channel has a 31.5 kilohertz/KHz bandwidth and channels are spaced 41.667KHz apart. Data rates offered by Iridium channels stretch from 176 kilobits-per-second/kbps to 700kbps. Iridium latency rates are around 395ms, give or take 100ms.

Russia’s Starlink and Iridium use

Russia has been blocked from using Starlink since May 2024, but this has not stopped her military obtaining Starlink terminals through illicit channels. On the battlefield, Russian forces typically connect their terminal to a router and thence, via a virtual private network, to a server in Asia, Europe or Russia. When connected thus, the user can access Russia’s internet via the Starlink terminal. The router and terminal can connect either with Wi-Fi or via a fibre optic cable. The latter helps reduce the chance of the terminal’s detection and geolocation via its Wi-Fi signal. Russia’s land forces deployed to Ukraine typically use Starlink terminals at, or close, to the tactical edge to provide backhaul communications to higher echelons. Given the distinctive square shape of the Starlink antenna Russian troops take strenuous efforts to camouflage these terminals to prevent them being spotted by reconnaissance. Camouflage netting is used, and terminals are hidden behind, or within, innocent-looking objects like debris. An added complication of using camouflage is that the coverings must blend in with the temperature of the surrounding area. This is essential to prevent the antenna’s thermal signature contrasting with the local landscape. For example, heat coming from the antenna can melt snow at a higher rate than it would do in the surrounding area. Once again, this can help thermal imaging optronics contrast the heat signature of the antenna from the local terrain. To an extent, Ukraine faces the tyranny of geography regarding Starlink provision. The country’s military depends on Starlink, particularly for the beyond line-of-sight links that SATCOM provision excels at. However, although Starlink coverage is not available in Russia, coverage continues in Ukraine. In some areas particularly over, or near, the frontline this coverage cannot be deactivated or jammed without having a detrimental effect on the ability of Ukraine’s troops to use Starlink. Armada understands that Russian forces typically use Starlink terminals at a between 20 kilometres/km (twelve miles) and 30km (19 miles) from the tactical edge. Regarding Iridium use, Armada understands that some Russian UAVs are outfitted with Garmin’s InReach Mini-2 satellite communications terminal to use the Iridium network. Usefully for the Russians this apparatus can also act as a global navigation satellite system position, navigation and timing signal receiver. Iridium receivers have been seen in the wreckage of Shahed-131 suicide UAVs Russian forces use to attack targets in Ukraine. Starlink terminals have also been installed on Russia’s Shahed-136 suicide UAVs to provide air-to-surface/surface-to-air communications. Armada understands that Starlink terminals may also provide air-to-air communications between Shahed-136s deployed in a swarm. In addition, Starlink terminals are being used onboard Russia’s new RD-8 UAV.

Assessment

Ukraine is in a bind regarding Starlink: Requesting SpaceX for the removal of coverage over the frontline would deprive Russian forces of Starlink, but not without doing the same to the Ukrainians. That Russia has obtained Starlink and Iridium terminals highlights the need to continue to restrict Moscow’s access to such kit. The acquisition of these terminals is being done covertly through third parties. There is an imperative on Ukraine’s allies to increase pressure on countries and jurisdictions unwilling or unable to clamp down on Russia’s acquisitions. The covert procurement of sanctioned SATCOM terminals can probably not be stopped outright. Alas, there will always be an unscrupulous regime, organisation or individual willing to turn a blind eye, or even help facilitate this trade. Nonetheless, working to prevent as many terminals as possible finding their way into Russian-occupied parts of Ukraine will help to hamper Russian battlefield communications. Hitting the communications links Russian land forces rely on will pay dividends in helping dislocate command and control. Russia’s tactical communications weaknesses are something that Armada has extensively chronicled since Moscow’s second invasion of Ukraine in February 2022. These weaknesses are a centre of gravity Ukraine can exploit as she strives to win and sustain electromagnetic superiority and supremacy. (Source: Armada)

 

18 Dec 25. Enhancing the HDRWF. A new capability contract has been concluded between the A4ESSOR consortium and OCCAR. What does this mean for the European Secure Software Defined Radio waveform initiative? On 3rd November the A4ESSOR consortium, which is developing the European Secure Software Defined Radio (ESSOR) set of tactical communications waveforms, made an important announcement. The consortium had signed a procurement contract with the pan-European OCCAR (Organisation Conjointe de Coopération en Matière d’Armement/Organisation for Joint Armament Co-operation) defence procurement agency. The contract paves the way for the “capability deployment” of the ESSOR High Date Rate Waveform (HDRWF), according to an A4ESSOR press release detailing the news.

HDRWF

ESSOR waveforms are being realised through a procurement initiative involving Finland, France, Germany, Italy, Poland and Spain. The a4ESSOR consortium is the programme’s industrial element involving Bittium, Indra, Leonardo, Radmor, Rohde and Schwarz, and Thales. All six countries will be introducing ESSOR waveforms into their tactical and operational communications over the coming years. Two of the ESSOR nations, Finland and France, have already introduced the HDRWF into service with their tactical radios. Two nations outside the ESSOR membership, Croatia and the Republic of Ireland, are also adopting the HDRWF. The HDRWF is an Ultra-High Frequency (UHF) waveform using a waveband of 225 megahertz/MHz to 400MHz. Up to 200 nodes can be accommodated on a single HDRWF network. The waveform can handle data rates of up to one megabit-per-second. It sustains full duplex data and voice-over-internet-protocol communications, and transmission security provision includes fast frequency hopping. The HDRWF can work in environments where Global Navigation Satellite System (GNSS) Position, Navigation and Timing (PNT) signals are badly degraded or denied. This waveform is not the only deliverable in the A4ESSOR portfolio: The ESSOR Three-Dimensional Waveform (E3DWF) is optimised for air-ground-air communications. E3DWF covers similar UHF wavebands to those of the HDRWF. The frequency-hopping E3DWF performs simultaneous voice and data transmission using frequency hopping Mobile Ad Noc Networking (MANET). E3DWF network synchronisation is provided using GNSS PNT signals. According to A4ESSOR up to 32 nodes can be accommodated on each E3DWF network. The ESSOR Narrowband Waveform (NBWF) is optimised to support communications in urban, rural, littoral, undulating and mountainous terrain using a MANET architecture. The waveform employs frequency hopping across wavebands of 30MHz to 88MHz, or 225MHz to 400MHz. Moreover, A4ESSOR says that up to 60 nodes can be accommodated on an NBWF network. Long term plans are afoot for A4ESSOR to introduce the ESSOR Tactical UHF Satellite Communications Waveform (ESATWF).

Contractual obligations

The press release stated that the capability deployment discussed above will see the design of a “common mission framework aimed at shared planning capability (for HDRWF) network parameters”. Once this work is completed, any nation using the HDRWF will be able to factor the waveform’s parameters and capabilities into their operational-level Command and Control (C2) systems. Having this capability enshrined in these C2 systems is imperative: Nations participating in multinational/coalition operations will be able to adequately plan the deployment of tactical/operational level communications networks using this waveform. A key aspiration of ESSOR is to deepen pan-European interoperability making this is a significant step. In addition, the contract covers the continued field testing of the HDRWF on a range of transceivers and networks to assess the waveform’s performance and reliability in various scenarios and environments. The latter includes rural, urban and undulating terrain, according to the press release. Scenarios include using the waveform for direct Line-of-Sight (LOS) and beyond LOS communications. Waveform performance in congested and contested electromagnetic environments will also be evaluated. The purpose of this ongoing testing is to aid the continual evolution and improvement of the waveform during its service life. Although the ESSOR programme has been in existence since 2008 it is now delivering important dividends as the HDRWF is already in service. The other waveforms are likely to follow this waveform’s example in the next five years. Given that the prevailing security environment in Europe vis-à-vis the threat from Russia is unlikely to improve any time soon, enhancing pan-European communications interoperability is vital. Fighting together demands robust, seamless C2 which in turn depends on reliable and secure waveforms. (Source: Armada)

 

18 Dec 25. December Radio Roundup. COMINT Consulting’s new v1.022 software release for the company’s Krypto1000 COMINT system increases the number of decoders for customers and also reduces decryption times. Armada’s monthly roundup of all the latest news in the military communications product, programme and operational domains.

New Krypto Software Enhancements

COMINT Consulting has performed a major release of new enhancements for the company’s Krypto500 and Krypto1000 Communications Intelligence (COMINT) software. The former covers Extremely Low Frequency (ELF: three hertz/Hz to 30Hz) and High Frequency (HF: three megahertz/MHz to 30MHz) communications. The Krypto1000 covers Very High Frequency (VHF: 30MHz to 300MHz) and Super High Frequency (SHF: three gigahertz/GHz to 30GHz) communications traffic. The company says that these latter wavebands can also include frequencies used for satellite communications. Dubbed software release V1.279 this can decode traffic from ISIRAN PRC-120 and VRC-131 HF tactical radios. Other systems like the Sunair T-9000E HF and CTM RKP-8100 multiband (1.5MHz to 512MHz) transceivers can also have their traffic decoded by V1.279 release. The company told Armada that “(s)everal new parsers, among them the HF2000 version of (the North Atlantic Treaty Organisation’s Standardisation Agreement-5066/STANAG-5066) have been added for increased intelligence extraction”. The process of parsing identifies “file types, users, formats in use and more” COMINT Consulting told Armada. This helps users “understand more quickly what to target (and what must not be targeted)”. Other new decoders can work with STANAG-4539 Annex-D configured traffic alongside decoders relevant to Codan’s 3012, 3212 and 9001 data modems. Furthermore, the software enhancement covers additional variants of the AW448 modem.

Quantum Networking Contract

Qunnect has shared details regarding a contract the company was awarded in early October to provide quantum networking infrastructure to the United States Air Force (USAF) research laboratory. A press release announcing the news says the contract will cover quantum networking for “national defence applications”. Qunnect claims to be the first company to have deployed large-scale, entanglement-based quantum networks on commercial fibre optic networks. Noel Goddard, Qunnect’s chief executive officer, continued in the press release that “with the air force’s support, we’re extending those capabilities to validate defence-grade specifications and accelerate national security use cases”. The company told Armada that the new contract “advances the entanglement validation components that are part of Qunnect’s Carina entanglement distribution product suite”. These components will be used by the laboratory to develop “new protocols for entanglement using our technology”. As for the company’s quantum entanglement technology writ large: “Current public demonstrations have shown (ranges of) up to 100 kilometre (62 miles) for useful entanglement rates. Qunnect is currently working on advancing quantum repeaters (to) extend that range”.

Arctic Steerable Beams

In October Viasat announced it had successfully demonstrated its GX-10 steerable beam high-speed arctic communications payload in Northern Canada. The test employed a Gulfstream Aerospace Gulfstream-III business jet and demonstrated that wireless devices could be connected using Ka-band (26.5 gigahertz/GHz to 40GHz uplink/18GHZ to 20GHz downlink) links across distances of up to 516 nautical miles (956 kilometres). The company says its GX-10 A/B payloads are already in service onboard Norway’s Northrop Grumman ASBM-1/2 Arctic Satellite Broadband Mission communications satellites. These antennas allow users to benefit from wideband satellite communications coverage in areas above 63 degrees’ latitude. Arctic regions have traditionally suffered from a paucity of satellite communications provision. The company told Armada that the demonstration was performed “to further illustrate the connectivity now available for government and defence operations in the (arctic) region”. (Source: Armada)

 

18 Dec 25. Lockheed Martin (NYSE: LMT) Skunk Works® and XTEND collaborated to integrate the XTEND Operating System (XOS) into Skunk Works’ MDCX™ autonomy platform, allowing simultaneous Command and Control (C2) of multiple classes of UAS, creating improved situational awareness for lower-level mission execution in joint all-domain C2 (JADC2) scenarios. In November, the two companies demonstrated an integrated Multi-Class MDCX (MC-MDCX) workstation in support of a marsupial drone mission. In the demonstration, a larger class UAS delivered a smaller UAS class 1 drone to perform a close-in mission. In previous constructs the operator of the larger class UAS would pass control over to an operator with lower-level controls for classes 1 or 2 vehicles. These types of controls include first-person views, mark-and-fly commands, and immersive environments for the drone operator to fully execute the mission. With the planned integration of XTEND’s XOS into Lockheed Martin’s MC-MDCX, a single operator can conduct both missions. The integration demonstration proved a reduction in total manpower for complex mission executions, removing the need for mission handoffs to lower-tiered operators, and improving situational awareness across the mission space. XTEND is a leader in combat-proven drone C2 solutions, deployed by militaries around the world. Their products provide a layered response and operational stepdown processes, enabling platform operations even when Global Positions System (GPS) signals are denied, or radio frequency datalinks are jammed. XOS allows new operators to conduct missions at near expert-level proficiency, thus reducing training time, increasing operational effectiveness, and improving informed decision-making. Lockheed Martin Skunk Works and XTEND are now focused on how these techniques can be applied to JADC2 missions and decision loops for advancing autonomous systems. Skunk Works is dedicated to enabling piloted and drone teaming to optimize operational flexibility, abbreviate data-to-decision timelines and improve pilot safety. We continue to collaborate with and invest in enabling technologies to keep our customers ahead of emerging threats.

About Lockheed Martin

Lockheed Martin is a global defense technology company driving innovation and advancing scientific discovery. Our all-domain mission solutions and 21st Century Security® vision accelerate the delivery of transformative technologies to ensure those we serve always stay ahead of ready. More information at Lockheedmartin.com.

About XTEND

XTEND’s AI-driven autonomous and tactical drone solutions serve the worldwide defense, law enforcement, and security markets, providing mission-critical systems and capabilities. Its proprietary XOS operating system fuses human intelligence and machine autonomy to enhance operator capabilities and reduce cognitive load. XTEND is a global company with offices in Tampa (Florida), Tel Aviv (Israel), Singapore and Latvia. For more information, visit http://www.xtend.me

 

18 Dec 25. Europe: Government sectors face increased cyber espionage risks from evolving Chinese tactics. On 16 December, the cyber security company Check Point reported that a Chinese state-sponsored group (‘Ink Dragon’) is exploiting misconfigured servers to conduct stealthy cyber espionage operations targeting the government sector in Europe. Ink Dragon typically searches for misconfigured Internet Information Services (IIS), SharePoint and other web servers provided by the technology company Microsoft on public-facing websites, in order to exploit their vulnerabilities and infiltrate targeted systems. Ink Dragon then attempts to hijack administrative-level accounts to execute a module that converts compromised servers into relay devices. This enables Ink Dragon to conceal command-and-control (C2) infrastructure by relaying malicious traffic between compromised victims’ devices. Reportedly, another Chinese state-sponsored group (‘RudePanda’) has used the same compromised devices for its own cyber operations, highlighting the widespread exploitation of this vulnerability. We assess that European government entities will face increased security and cyber espionage risks amid the continuous evolution of Chinese state-sponsored cyber tactics. (Source: Sibylline)

 

17 Dec 25. Scarlet Dragon Links Military, Industry to Test Artificial Intelligence for Warfighters. On a cold, December day deep in a training area at Fort Bragg, North Carolina, soldiers, airmen, Marines and civilian industry partners came together to test the latest drone and counter unmanned aircraft systems technology, while rapidly sharing targeting data through the National Geospatial-Intelligence Agency’s Maven Smart System. Scarlet Dragon is the XVIII Airborne Corps’ premier innovation exercise, where new ideas and technologies are tested to solve current issues on the battlefield.

“We’re focused on bringing new technologies and approaches to solve operational capability gaps and requirements that we identify from operational plans around the globe,” said Rob Braun, XVIII Airborne Corps chief technical officer.

The Scarlet Dragon exercise series started in 2020 as a tabletop exercise in the basement of the XVIII Airborne Corps’ headquarters and has evolved into a triannual innovation event where joint services, government agencies and industry partners come together to test and integrate the latest technology for the modern warfighter. During this iteration, known as Scarlet Dragon 26-1, the XVIII Airborne Corps tested several initiatives. The 18th Field Artillery Brigade trained with the Air Force to rapidly load and deploy an M142 high mobility artillery rocket system from a C-17 Globemaster III, all while simultaneously receiving targeting data through NGA’s Maven Smart System. The streamlined data sharing allows the HIMARS unit to rapidly deploy anywhere in the world and quickly set up for offensive or defensive engagements.

“We’re doing cold-load training with a C-130, putting the HIMARS on the aircraft, driving it off, executing a rapid-fire mission and getting back on quickly,” said Army 2nd Lt. Ryan Mitchell, 18th Field Artillery Brigade, HIMARS platoon leader. “Through Scarlet Dragon, we are doing advanced targeting with data received through Maven, rapidly getting that information to the launcher so we can deploy and shoot faster.”

Another initiative included real time data sharing and tracking between AH-64 Apache helicopters from the 82nd Airborne Division’s Combat Aviation Brigade, drones and small UAS with the XVIII Airborne Corps Air and Missile Defense team, Sentinel radars from the 82nd Airborne Division, and newly fielded SGT STOUT short range air defense systems from the 108th Air Defense Artillery Brigade. The Sentinel radars and SGT STOUTs tracked Apaches and drones, pushing data to the corps headquarters to validate faster early warning systems for troops on the ground. Apache pilots tested their ability to identify and track small drones, while the SGT STOUT teams validated their tracking and targeting capabilities. The integration of the SGT STOUT into the maneuver force is a critical step in providing protection against short-range air threats.

“What I like about Scarlet Dragon is how I push, not just the soldiers, but also the equipment that we have to our limits and to see what we are capable of and how we can improve our system capabilities,” said Army Spc. Daniel Rosas, XVIII Airborne Corps Air Defense Battle Management System operator. “With the way the world is currently moving, especially when it comes to UAS or drones, it is a big threat, and it helps for us to push forward on what we can adapt when it comes to gauging and tracking these threats.”

Scarlet Dragon gives service members and industry partners the opportunity to test new ideas and innovations in an open and minimum-risk environment.

“That’s what I really like about Scarlet Dragon,” said Army Chief Warrant Officer 4 Sean Benson, XVIII Airborne Corps senior geo-intelligence imagery technician. “It’s not an exercise with defined timelines or deliverables. It’s whatever we want to try to get to the outcome we need. If you have an idea and it sticks when you throw it on the wall, we’ll give it a shot.”

The Future of Scarlet Dragon

With every iteration of Scarlet Dragon, the integration process is refined and the technology improves. In the future, the Scarlet Dragon exercise series will be tied in with Fort Bragg and XVIII Airborne Corps’ new Lt. Gen. James M. Gavin Joint Innovation Outpost, which will officially open Jan. 23, 2026.

“During Scarlet Dragon 26-1, the XVIII Airborne Corps and Fort Bragg held a soft opening for our new Joint Innovation Outpost, or JIOP,” said Army Lt. Gen. Greg Anderson, commanding general of the XVIII Airborne Corps. “With the JIOP and our Scarlet Dragon series of exercises, we will be able to develop and test soldier-driven, rapid innovation and technical transformation while providing the Army a model to revolutionize the acquisition process. It is making us more lethal at the tactical and operational levels of war.”

The JIOP will allow soldiers to bring innovative solutions to the facility to work with civilian industry and academic partners to refine and produce new technology that can then be tested in Scarlet Dragon exercises and eventually shared across the joint force. In 2026, Scarlet Dragon will shift to the Indo-Pacific theater and U.S. Army Japan for their annual combined exercise with the Japanese Ground Self Defense Forces, Yama Sakura. (Source: U.S. DoD)

 

17 Dec 25. Bittium Wireless Ltd, a subsidiary of Bittium Corporation, has received purchase orders from the Finnish Defence Forces for Bittium Tough SDR Handheld and Vehicular radios and related accessories, and for further development work for software and related services. The total value of the purchase orders received now is approximately EUR 15.9m, of which the share of Tough SDR order is approximately EUR 12.4m. Product deliveries and development work will take place during 2025 and 2026. Bittium Tough SDR radios will replace the Finnish Defence Forces’ existing stock of analogue tactical radios in stages with modern software-defined radios enabling broadband tactical communications. The radios will also offer significantly better performance for the Finnish Defence Forces compared to the earlier generation digital tactical radios. The Tough SDR radios are compatible with the software-defined Bittium Tactical Wireless IP Network™ (TAC WIN) system used by the Finnish Defence Forces for forming a backbone for broadband tactical communications.  The solutions come together as a seamless network that enables resilient communications for all troops across domains and military branches. Part of the performance of the software-defined radios is created with the software used in the radios and software development enables performance enhancements for the radios throughout their whole life cycle.

“The purchase order reflects the Finnish Defence Forces’ strong confidence in Bittium’s advanced software-defined radios. The waveforms, which play a central role in radio data transmission, are being continuously improved to address evolving threats, particularly in electronic warfare. The Tough SDR radios, combined with the NATO-standardized pan-European ESSOR High Data Rate Waveform, facilitate seamless interoperability also with allied forces,” says Tommi Kangas, Senior Vice President, Defense & Security business segment at Bittium.

In addition to the Tough SDR radios, the Finnish Defence Forces have ordered development of the Tactical Device Management system that enables secure deployment and operative use of the radios. The system will expand to support also the TAC WIN system and Bittium Tough Comnode™ devices, enabling centralized and streamlined installation, software updates, and key management for the solutions. The purchase orders have been issued under a Partnership Agreement between Bittium and the Finnish Defence Forces. The Partnership Agreement applies to the years 2025–2036 and establishes a framework for purchasing Bittium’s devices, software, and services. The purchases are planned together with the Finnish Defence Forces for each year. The Finnish Defence Forces will issue separate purchase orders for the products and services in several batches according to what has been agreed in the Partnership Agreement.

 

16 Dec 25. Global: Widespread vulnerability exploitation heightens security risks to firms using JavaScript library. On 13 December, the technology company Google reported that more than five Chinese state-sponsored groups are actively exploiting a newly disclosed software vulnerability (CVE-2025-55182). CVE-2025-55182 enables unauthenticated actors to execute arbitrary code onto devices hosting vulnerable React interface services (i.e. a widely used JavaScript library), in order to conduct malicious cyber activity. Google’s report comes after the US-based technology companies Palo Alto and Amazon Web Services (AWS) issued two warnings announcing that Chinese state-sponsored actors had started exploiting the vulnerability hours after its disclosure on 3 December. This rapidity showcases the quickly evolving nature of the cyber threat landscape. Between 14 and 15 December, over 670 IP addresses reportedly attempted to abuse CVE-2025-55182 across East Asia and Pacific, Europe and North America, highlighting the potential scale of the vulnerability’s exploitation. Consequently, we assess that entities using React interface services will face heightened security risks in the short-to-medium term amid the ongoing implementation of remediation patches. (Source: Sibylline)

 

12 Dec 25. Cyber Update

Key points

  • The government and IT sectors in the US and Canada face increased security risks from a long-term Chinese state-sponsored cyber operation (see Sibylline Cyber Daily Analytical Update – 8 December 2025).
  • A new spyware variant (‘ClayRAT’) poses increased data-theft and surveillance risks for global Android users (see Sibylline Cyber Daily Analytical Update –  9 December 2025).
  • A new ‘Mirai’-based botnet variant (‘Broadside’) poses elevated disruption risks for the maritime shipping sector via the exploitation of a software vulnerability (CVE-2024-3721, see Sibylline Cyber Daily Analytical Update – 10 December 2025).
  • Financial and cryptocurrency institutions across Europe face heightened data-theft and financial risks from a new phishing kit (‘Spiderman’, see Sibylline Cyber Daily Analytical Update – 11 December 2025 and our technical analysis below).
  • A Hamas-affiliated cyber threat group (‘Ashen Lepus’) poses an elevated cyber espionage threat to government entities in the Middle East and North Africa (see Sibylline Cyber Daily Analytical Update – 12 December 2025 and our technical analysis below).

Technical analysis of weekly stories

Cyber threat actors are targeting European banks with a new and highly sophisticated phishing kit (Spiderman). Spiderman can be managed through a unified control panel that facilitates the automation of the attack chain, enabling a wider range of both high- and low-skilled threat actors to conduct sophisticated attacks. During the distribution phase, threat actors can also restrict access to phishing pages using several techniques – such as country and internet service provider (ISP) whitelisting, device-type filtering and customer redirect control – to avert unwanted visitors and prolong detection evasion. The kit can target dozens of financial institutions across at least five European countries with a single interface, highlighting the large-scale security risks stemming from its highly dynamic functionality. Spiderman can steal login details in real-time and simultaneously deploy additional interfaces for extensive data collection to hijack user accounts fully (and initiate fraudulent money transfers). Stolen data typically includes credentials such as one’s full name, phone number, date of birth and credit card details, providing threat actors with ample follow-on attack avenues. The kit also boasts the ability to exfiltrate specific cryptocurrency information such as wallet data and seed phrases, showcasing the all-encompassing nature of its financial-theft capabilities.

A Hamas-affiliated cyber threat group (Ashen Lepus) has consistently targeted government entities in the Middle East and North Africa region through cyber espionage operations since at least the beginning of the Israel-Hamas war in late 2023. The group likely uses social engineering techniques to distribute a PDF file that tricks victims into downloading and opening an RAR archive. The archive contains a loader that ultimately executes the ‘AshTag’ malware suite onto compromised systems via a multi-stage process. Namely, upon execution, the malware loader (‘AshenLoader’) sends initial system reconnaissance to command-and-control (C2) infrastructure before deploying a malware stager (‘AshenStager’). AshenStager is responsible for injecting the main payload (AshTag) into the system’s memory to enhance detection evasion. AshTag acts as a backdoor to perform system reconnaissance, maintain prolonged persistence and execute remote commands. During the latest operations, Ashen Lepus has used new domains mimicking legitimate services for C2 infrastructure to obfuscate malicious traffic. The group has also started deploying the entire malware suite in this latest phase, rather than simply exiting a victim’s system after infiltration. We assess this suggests that Ashen Lepus is consistently developing its tactics. This development is also reflected in the expansion of its target pool which now also includes Oman and Morocco alongside its usual targets.

Non-exhaustive recommendations to mitigate these threats include:

  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs, PSB) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware.
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.

Our cyber word(s) of the week: User Datagram Protocol (UDP) flooding

Definition: A type of denial-of-service (DoS) attack in which threat actors send a large amount of UDP requests to overwhelm a victim’s system with the aim of causing operational disruption.Example: ‘[…] executes the Mirai malware […], thereby allowing threat actors to conduct DDoS attacks via User Datagram Protocol (UDP) flooding techniques’ (see Sibylline Cyber Daily Analytical Update – 10 December 2025). (Source: Sibylline)

———————————————————————————————————————————————————————————————————————————————————————————————————————–

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

————————————————————————————————————————————————————————————————————————————————————————————————————————————-

Primary Sidebar

Advertisers

  • Pythia
  • Teledyne
  • Exensor
  • Visit the Oxley website
  • Blighter
  • SPECTRA
  • Britbots logo
  • Faun Trackway
  • Systematic
  • CISION logo
  • ProTEK logo
  • ProTEK logo
  • ssafa logo
  • IEE
  • EXFOR logo
  • sibylline logo
  • Team Thunder logo
  • Comtech logo
  • GoExporting logo
  • ECHODYNE logo
  • Supercat logo
  • Galvion logo
  • Leonardo DRS logo
  • MTC logo
  • IDC logo
  • DSEI logo
  • DVD2024 logo
  • SDSC logo
  • TELEDYNE FLIR logo
  • VeteranUK logo
  • Matrix Space logo
  • ST Engineering logo
  • EWS logo
  • sentinel photonics logo
  • capua logo
  • Curtiss-Wright logo
  • Brave1 logo
  • Drone Evolution logo
  • AEI Systems logo
  • EOS logo
  • NMSUK logo
  • Openworks logo
  • Sandown Park logo
Hilux UKDSE AARTOS ST Engineering Future Artillery

Contact Us

BATTLESPACE Publications
41 St Georges Drive
London SW1V 4DG

+44 (0)77689 54766

BATTLESPACE Technologies

An international defence electronics news service providing our readers with up to date developments in the defence electronics industry.

Recent News

  • Protek Selected By Dutch Armed Forces

    May 2, 2026
    Read more
  • PARLIAMENTARY QUESTIONS

    May 1, 2026
    Read more
  • MANAGEMENT ON THE MOVE

    May 1, 2026
    Read more

Copyright BATTLESPACE Publications © 2002–2026.

This website uses cookies to improve your experience. If you continue to use the website, we'll assume you're ok with this.   Read More  Accept
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT