Sponsored By Curtiss Wright
https://www.curtisswright.com/
———————————————————————————————————————————————————————————————————————————————————————————————————————————-
21 Jan 26. Thales – Why computing power, as much as platform design, determines
DigitalCrew® AI-powered classification capabilities – Thales
Modern AI classification is the bedrock for the latest mission support tools and second order effects that are set to transform battlefield effectiveness and lethality – capabilities Stewart, Head of Digital Strategy at Thales, referenced in his article last year ahead of IAVC 2025. These algorithms are proven and deployable today.
Yet most armoured platforms cannot run them effectively – not because their sensors are not capable, not because the algorithms are not mature, but because the computer architecture sitting between them was designed for a different technological era. “The limiting factor for deploying AI at scale isn’t the platform itself, but the processing hardware sitting inside it,” says Stewart, Head of Digital Strategy at Thales.
Why processing hardware matters now
Achieving the Chief of the General Staff’s goal to triple Army lethality by 2030 requires us to think differently about how we deploy capability to the frontline
DigitalCrew capabilities are already deployed and delivering operational value. Utilising traditional mathematical algorithms for detection, tracking, and image fusion, they are running perfectly well on current processing hardware. These building blocks are proven on platforms today, helping crews detect and track potential threats across complex battlespaces. This is not the case for AI classification and the second-order effects that flow from it.
What we are talking about is not incremental improvement – it is unlocking entirely new classes of capability from sensors already installed on platforms. These second-order effects transform raw data into a step-change in tactical advantage. But delivering that kind of capability leap demands significant increases in processing power.
The structural challenge: procurement vs technology evolution
Defence procurement, in its current form, locks in technical specifications years before fielding. Platform development cycles can span 15 years or more to move from a design to frontline service. This timeline works perfectly well for components with multi-decade service lives – such as hull armour, powertrains, and optical systems. These remain capable throughout a platform’s operational lifetime.
But GPU evolution follows a completely different clock. New GPU architectures emerge every three to five years, and some manufacturers will cease support on similar timelines, making it increasingly difficult to develop algorithms for older hardware. The result is an unavoidable gap between processing hardware specification during the design phase and algorithm capability at fielding.
Commercial sectors have adapted to this reality, operating on three-to-five-year hardware refresh cycles to keep pace with technology evolution. Defence procurement needs to adopt similar iteration loops for processing hardware, while maintaining longer lifecycles for the platforms themselves.
The consequences of not doing so are already visible. Consider a platform where computer hardware was specified in the early 2010s, now fielding in the mid-2020s. The sensors remain front-line ready and will last the lifetime of the platform, yet the GPU is already struggling to run today’s latest algorithms. Running classification algorithms, it manages just 5-6 frames per second versus the required 30-60 fps. The consequence is jerky, unusable displays for human operators – viable only for machine-to-machine data passing rather than real-time crew decision-making.
The real-world consequence: locked opportunitie
The impact of this mismatch is profound. Modern armoured fighting vehicles can have dozens of cameras providing 360-degree awareness around the platform, yet human crews can actively monitor perhaps two feeds at most. AI classification could monitor all feeds simultaneously, alerting crews when threats appear. The algorithms exist. The sensors exist. Yet the processing hardware cannot connect them at operational tempo.
Without it, this locks away those second-order effects that would provide genuine tactical advantage. Passive ranging, for instance, would allow crews to determine target distance without laser detection, avoiding the risk of revealing their position. Threat prioritisation algorithms could assess multiple targets based on type, range, and behaviour, then recommend which to engage first. Classification enables vehicle configuration analysis, determining gun orientation, and anomaly detection – all capabilities that help crews make faster, better-informed decisions under pressure.
Perhaps most importantly though, AI classification reduces the cognitive burden. If, instead of requiring crews to watch everything, AI can handle the monitoring tasks, then crews are freed up to focus on decision-making and engagement. The opportunity cost of not having these capabilities is significant: crews operating without advantages that could be unlocked through hardware refresh rather than platform replacement.
The path forward: treating processing hardware as consumable
“We need to recognise that GPU hardware requires planned three-to-five-year replacement cycles, independent of platform lifecycle. One practical way to deliver this is through a hardware as a service model for military platforms, where onboard computing processing is provided, maintained, and refreshed on a contracted cycle to sustain AI performance over the life of the vehicle,” says Stewart.
Delivering this at scale requires a common, GPU-enabled processing architecture across platforms and domains. Standardised interfaces would make DigitalCrew building blocks truly portable – develop once, deploy anywhere without re-engineering the software wrapper for each new system.
The benefits are clear:
- Agility: planned GPU replacement every three-to-five-years keeps processing capability aligned with algorithm evolution, without waiting for platform replacement.
- Portability: standardised architecture means developing once and deploying anywhere, with no re-engineering for each platform.
- Cost: reduced integration costs and predictable refresh budgeting over platform lifetime.
- Immediate impact: unlocking AI capabilities on existing fleets without vehicle replacement.
This is not about choosing between new platforms and new processors – it is about recognising they operate on different timescales. New platforms are essential, but their processing architecture must be designed for regular hardware refresh from day one.
Where the next leap comes from
Sensors and vehicle platforms remain capable for decades. The factor limiting their lethality is the computing hardware sitting between the sensors and the shooter. By treating that hardware as consumable, requiring periodic refresh, forces can unlock new waves of AI-enabled performance without rebuilding fleets.
The next major leap in armoured vehicle capability won’t come from a new turret design, a new engine, or a new hull. It will come from upgrading the GPU inside – not because the platform needs replacing, but because the technology evolution cycle demands it. The armies that understand this will field AI-enabled advantages on existing platforms while others wait for next-generation procurement cycles to deliver similar capabilities.
The question isn’t whether to modernise processing hardware. It’s whether to do it proactively, as part of a planned refresh strategy, or reactively when the capability gap becomes a tactical liability.
21 Jan 26. Global: New, highly sophisticated malware increases security risks to organisations. On 18 January, the cyber security company Resecurity reported that various cyber threat actors are using a new malware family (‘PDFSider’) to conduct stealthy, highly sophisticated cyber operations. Targets are widespread, though some reported victims include government and energy organisations. Threat actors distribute spear phishing emails to trick victims into downloading a ZIP archive. This archive contains the PDFSider payload, which is deployed directly into a system’s memory via Dynamic Link Library (DLL) sideloading techniques to remain obfuscated. Then, the malware conducts initial system reconnaissance and establishes persistent communication with command-and-control (C2) infrastructure for additional malicious activity. PDFSider can detect virtual environments and security tools while encrypting C2 traffic to prolong detection evasion, highlighting its sophistication. Multiple ransomware groups have reportedly used PDFSider to facilitate persistence and download malicious payloads, likely for data exfiltration and encryption. As such, we assess that global organisations will face increased security risks amid the persistent development of malware. (Source: Sibylline)
20 Jan 26. cortAIx, Thales AI accelerator, launched in Germany to Drive AI for Critical Systems
- In January 2026, cortAIx, Thales AI accelerator, has opened a new site in Germany, bringing the total number of these cortAIx entities to five, after France, the United Kingdom, Canada, and Singapore
- This initiative aims to contribute to the development of transparent and trustworthy AI solutions, specifically for critical systems and security-relevant military applications
By establishing cortAIx in Germany, Thales is responding to the rising demand for trusted and resilient AI solutions in the defence and security sectors. cortAIx in Germany represents an additional building block in Thales’ global AI network, which aims to strengthen the responsible and effective use of AI to tackle complex challenges. The focus is on developing robust solutions for AI for cybersecurity, and military use cases such as autonomous cyber-defence, agent-based penetration testing, command & control, and sensor-centric applications. Based on customer feedback and Thales in-house research, new potentials for innovative or existing solutions are identified—solutions that can be effectively applied and ease users’ workloads with the help of trustworthy AI. The cortAIx approach extends from customer-centric basic research to the development of use cases and minimum viable products, and to market-ready products. This approach has already proven successful in NATO countries with an existing cortAIx presence, such as Canada, the UK, and France.
“With cortAIx in Germany, we are bridging the gap between technological innovation and the highest standards of security. Our goal is to provide our customers in the defence and security sector with solutions that are not only technologically advanced, but above all, trustworthy and sovereign. In a world of mounting digital threats, resilient AI is no longer a ‘nice-to-have’—it is the backbone of modern security architectures. We invite our partners and customers to join us in this important endeavor. Close collaboration between industry, academia, and public sector is crucial for advancing AI innovations that both strengthen Europe and Germany’s sovereign capabilities and meet the highest standards of transparency, ethics, and accountability.” Christoph Ruffner, CEO & Country Director Thales in Germany
Global AI Expertise of cortAIx
To pool the comprehensive expertise of Thales and efficiently advance trustworthy AI development, experts from cortAIx in Germany benefit from the global network. Thales already employs over 800 AI and data specialists, and is the leading patent applicant for AI for critical systems in Europe, with more than 200 patents filed to date. With over 100 products integrating AI, Thales is accelerating the development and deployment of trusted AI-based systems in the most demanding environments. cortAIx in Germany builds on this success and will serve as a central hub for AI innovation—bringing together cutting-edge technology, talent, and research with the goal of delivering AI solutions that provide the right data foundation for the right decisions in critical scenarios.
cortAIx’s research and development focuses on solutions for critical systems, including:
- Building resilient data and knowledge foundations as prerequisites for efficient, scalable AI systems;
- Developing and evaluating AI systems that act autonomously and make independent decisions in highly dynamic, security-critical environments, as well as implementing defence measures against hybrid (cyber & physical) threats;
- Securing AI systems against manipulation, malfunction, and attacker influence throughout their entire lifecycle.
19 Jan 26. General Atomics Aeronautical Systems, Inc. (GA-ASI) –– the world leader in unmanned systems – and Barzan Holdings, Qatar’s national defence and security leader, signed a Memorandum of Understanding (MOU) to collaborate on the development of advanced Battle Management software capabilities. The signing took place on Monday during the Doha International Maritime Defence Exhibition and Conference (DIMDEX). The MOU provides a framework for cooperation between GA-ASI, GA-Intelligence, and Barzan Holdings to develop software solutions that enhance theater-level situational awareness and enable the efficient processing, correlation, and dissemination of intelligence. These capabilities are intended to support faster, higher-quality decision-making in complex, multi-domain operational environments. For General Atomics, the agreement underscores the strategic importance of collaboration with Barzan Holdings and the State of Qatar. The partnership reflects a shared commitment to long-term cooperation, technological innovation, and the advancement of interoperable command-and-control solutions aligned with modern defense and aerospace requirements. In addition to its best-in-class unmanned aircraft systems, GA-ASI is a premiere developer of airborne Intelligence, Surveillance and Reconnaissance (ISR) systems, while GA-Intelligence has the ability to take hundreds of sources of commercial data, including data provided from GA-ASI’s unmanned systems, to produce a comprehensive operating picture.
“Collaboration with Barzan and Qatar is central to GA’s approach to delivering operationally relevant, next-generation capabilities,” said a GA-ASI CEO Linden Blue. “By combining GA’s expertise in mission systems and autonomy with Barzan’s regional insight and defense focus, we are positioned to advance battle management solutions that significantly improve situational awareness and intelligence exploitation.”
16 Jan 26. Cyber Update Key points.
- A new phishing campaign targeting government, think tank and academic organisations has underscored the data-theft and cyber espionage risks stemming from the renowned North Korean state-sponsored group ‘Kimsuky’ (see Sibylline Cyber Daily Analytical Update – 12 January 2026).
- The Russian state-sponsored group ‘APT28’ poses increased data-theft risks for energy, government, military and media sectors (see Sibylline Cyber Daily Analytical Update – 13 January 2026 and our technical analysis below).
- Users of the social media platform Facebook face long-term information-theft risks stemming from a sophisticated phishing technique (see Sibylline Cyber Daily Analytical Update – 14 January 2026 and our technical analysis below).
- Linux systems face increased security risks stemming from a new and highly sophisticated malware framework called ‘VoidLink’ (see Sibylline Cyber Daily Analytical Update – 15 January 2026).
- A phishing operation carried out by the Russian state-sponsored group ‘Void Blizzard’ poses heightened security risks for Ukrainian defence entities (see Sibylline Cyber Daily Analytical Update – 16 January 2026).
Technical analysis of weekly stories
The renowned Russian state-sponsored group APT28 (also known as ‘Fancy Bear’) has targeted energy, government, military and media sectors in a large-scale, data-theft cyber operation since at least February 2025. APT28 likely uses spear phishing emails to trick victims into clicking on an embedded malicious link. The link redirects victims to APT28-made pages impersonating legitimate email, authentication and virtual private network (VPN) services – including Microsoft Outlook Web Access (OWA) and Sophos – to prompt users to input their credentials. The link reportedly conceals two shortened URLs that display legitimate-looking PDF documents pertaining to the sector’s expertise prior to the phishing pages, likely to enhance the operation’s legitimacy. The malicious pages also leverage Hypertext Markup Language (HTML) and JavaScript, as well as several free tunnelling services to capture and exfiltrate user data, highlighting the resource-efficient nature of this operation. The phishing pages emulate both login and password reset services and use similar credential-harvesting techniques for both attack pathways. We assess that the group likely uses stolen credentials to hijack user accounts to collect strategic intelligence and to strengthen its security posture.
Unnamed cyber criminals are targeting users of the social media platform Facebook in a sophisticated information-theft operation. Threat actors reportedly distribute phishing emails containing a fake warning regarding copyright infringement, suspicious and unauthorised login attempts and/or security updates to trick users into clicking on an embedded link. The link redirects users to a legitimate Facebook page where the threat actors conduct a Browser-in-the-Browser (BitB) attack by displaying a threat actor-made phishing pop-up window. Threat actors use URL shortening techniques to embed a portion of legitimate Facebook URLs into the pop-up window’s URL to appear authentic, as well as CAPTCHA pages to feign legitimacy further. The pop-up prompts victims to enter sensitive information and credentials, subsequently allowing the threat actors to hijack user accounts, exploit stolen data and conduct follow-on malicious activity. The threat actors also use legitimate cloud services to host phishing infrastructure and simultaneously evade security mechanisms, showcasing the continued exploitation of legitimate platforms for malicious cyber activity.
Non-exhaustive recommendations to mitigate these threats include:
- Monitor devices and networks for suspicious activity.
- Add available Indicators-of-Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware.
- Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
- Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.
Our cyber word(s) of the week: Browser-in-the-Browser (BitB) attack
Definition: A type of cyber attack wherein threat actors create a fake, credential-harvesting pop-up window within a legitimate webpage to deceive users and subsequently trick them into disclosing sensitive information.
Example: ‘The link redirects users to a legitimate-looking Facebook page where threat actors conduct a browser-in-the-browser attack’ (see Sibylline Cyber Daily Analytical Update – 14 January 2026).
Frequency of TTPs during this monitoring period: LOW frequency, MODERATE frequency, HIGH frequency
The MITRE ATT&CK framework is a globally accessible documented collection of information detailing the malicious behaviours of cyber threat actors. It is used as the foundation for organising the processes which threat actors execute during cyber operations. It provides an encyclopaedic reference for organisations, highlighting the TTPs cyber threat actors employ in campaigns, while also providing suggestions for detecting and mitigating against specific TTPs to bolster organisations’ security mechanisms. The framework organises a threat actor’s entire operational lifecycle from reconnaissance to exfiltration and impact. (Source: Sibylline)
————————————————————————————————————————————————————————————————————————————————————————————————————————————-
Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.
We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.
Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.
————————————————————————————————————————————————————————————————————————————————————————————————————————————

