Sponsored By Curtiss Wright
https://www.curtisswright.com/
—————————————————————————————————————————————————————————————————————————————————————————————————————————————
29 Jan 26. Global: AI-generated malware raises short-to-medium term security, information-theft risks for firms. On 28 January, the cyber security companies Symantec and Carbon Black reported that unidentified threat actors are distributing an artificial intelligence (AI)-generated remote access trojan (RAT; ‘PureRAT’) to conduct an information-theft campaign. The campaign starts with phishing emails containing fake job opportunities to trick victims into downloading PureRAT onto their systems. The malware then enables threat actors to maintain prolonged persistence within compromised systems and ultimately exfiltrate sensitive data, likely for financial profit. PureRAT’s code was reportedly written using AI as it displays several AI coding signatures (such as emojis and coding instructions), illustrating the growing adoption of AI in malicious cyber activity to compensate for less proficient skillsets among threat actors. This campaign has targeted entities indiscriminately, likely to boost success rates. We assess that this campaign will raise security, phishing and information-theft risks for global entities in the short-to-medium term. (Source: Sibylline)
27 Jan 26. Plextek, a leading global provider of advanced engineering consultancy services, has been selected as a supplier on the £180 m Digital Decision Accelerators for Defence (DDAD) Framework, supporting the British Army’s ASGARD programme, its flagship Transformative Capability Initiative focused on battlefield decision-making and digital targeting. ASGARD aims to reinvent how land forces deliver operational decision‑support and decision‑making software through AI/ML‑enabled applications to shorten decision timelines. DDAD is the framework through which these capabilities will be procured and delivered. To support the project, Plextek brings proven capabilities in electronic warfare, radar, radio communications and navigation, combined with deep expertise in generative AI and machine learning. This means the company can rapidly prototype, test and spiral develop solutions that address real operational problems.
Brent Hudson, CEO, Plextek commented, “ASGARD addresses a fundamental operational challenge: getting the right information to decision-makers faster. Our capabilities in EW, radar, communications and AI mean we can rapidly prototype and test solutions against real battlefield requirements.”
Through the project, it will be working as a UK-sovereign SME supply chain with two specialist partners:
- Teleplan Forsberg, a trusted centre of excellence for Position, Navigation & Timing and situational awareness, specialising in Battlefield Management Systems and mission planning. They build assured, resilient solutions for mission-critical operators.
- Nexor, a provider of capabilities across the Digital Targeting Web, cyber security, data fusion, and secure data transport. Their technology connects defence systems securely and makes them interoperable.
Plextek brings agility and pace to defence innovation including rapidly developing, integrating, and fielding new disruptive technologies alongside proven in‑service systems to deliver operational advantage through pace of decision making.
27 Jan 26. Integer unveils DIGIT mission assurance for maritime operations. DIGIT Mission Assurance Platform supports crewed and uncrewed surface and underwater vehicles. Integer Technologies has introduced its DIGIT Mission Assurance Platform, designed to support decision-making and mission planning for naval vessels operating in distributed maritime environments. DIGIT Mission Assurance Platform supports both autonomous and human-in-the-loop operations. It aims to maintain operational capability in denied, degraded, intermittent, and limited (DDIL) communication scenarios. The platform employs high-fidelity digital twins and real-time environmental forecasting, integrating live sensor inputs with physics-based models. This setup enables vessels and their operators to automatically adjust to emerging threats and maintain situational awareness for both crewed and uncrewed systems, even when standard communication lines are unavailable. DIGIT Mission Assurance Platform is compatible with a range of systems, including both surface and underwater vehicles. Integer Technologies states the system can be applied from individual ships to large groups, such as entire fleets. The company emphasises DIGIT Mission Assurance Platform’s scalability, interoperability, and adaptability for current and future naval assets like the newly announced guided missile battleship and future frigate. The initial release of the platform includes three modules tailored for different mission requirements. The “DIGIT COMMAND” module serves shore-side commanders by supplementing existing command and control structures with a decision-support layer across operational theatres.
“DIGIT CORE” provides on-board perception, planning, and resolution for individual platforms, enabling ongoing evaluation of internal systems like propulsion and power.
The “DIGIT UxV” module handles mission planning for unmanned surface and underwater vehicles, modelling the interaction between platforms and their environments to enable resilience even when communications are disrupted.
Integer Technologies co-founder and CEO Duke Hartman said: “The next generation of defence technology will be defined by software that can anticipate, not just respond. From platform-level introspection to global fleet orchestration, DIGIT provides the software architecture to win the fight.
“It represents a fundamental shift towards mission-aware technology, giving operators and autonomous systems the foresight to make confident decisions to deliver successful mission outcomes.”
Currently, DIGIT Mission Assurance Platform is supporting US Navy UxV efforts regarding unmanned vehicles, including mission assurance work for the Metron-developed Lancet long-range multi-mission unmanned undersea vehicle. (Source: naval-technology.com)
27 Jan 26. Bittium has entered into a Basic Ordering Agreement (BOA) with the NATO Communications and Information Agency (NCIA). This agreement designates Bittium as a preferred supplier for the NCIA and NATO member countries, enabling accelerated procurement of Bittium’s secure mobile communications devices, software, and accessories. The agreement covers Commercial Off-The-Shelf (COTS) solutions that NATO uses to maintain its technological edge and respond to cyber threats.
“Bittium is a trusted forerunner and supplier of defense and security technologies, and the agreement with NATO further streamlines the ability of member countries to procure our high-quality security solutions. We are very proud of this milestone, as it enables us to support NATO and its member nations in advancing cybersecurity and critical capabilities”, said Tommi Kangas, Senior Vice President of Bittium’s Defense & Security business segment.
Solutions offered under the agreement include secure Bittium Tough Mobile™ smartphones as well as quantum-safe Bittium SafeMove® and Bittium Secure Call™ software solutions that provide encrypted connectivity, secure communication, and comprehensive device and application management. The multi-platform software solutions support Android™, iOS, and Microsoft Windows to enable organization-wide secure communications. The Bittium SafeMove® Mobile VPN encryption solution also supports hybrid networking and ensures secure interoperability across tactical networks and 4G/5G mobile networks. Bittium’s solutions are used globally by over 75,000 users and enable absolute security for mitigating the ever-increasing cyber threats faced by government agencies, defense forces, law enforcement, and critical infrastructure organizations. Bittium Tough Mobile™ 2 C is an information security solution approved for NATO Restricted-level use and secures mobile communications between government officials and authorities. Both the Tough Mobile 2 C and the recently launched Bittium Tough Mobile 3 smartphone eliminate the need of having separate devices for personal and professional use, which streamlines workflows without compromising data boundaries. This is enabled by a unique dual operating system, meaning two completely isolated, hardened environments. Users can easily switch between the environments via dual-boot, ensuring total separation of personal and professional use.
26 Jan 26. Asia-Pacific: AI-assisted backdoor points to elevated security risks to blockchain developers, firms. On 26 January, international media outlets reported that the North Korean state-sponsored group ‘Konni’ is conducting a phishing campaign to deploy an artificial intelligence (AI)-generated backdoor (‘PowerShell’). The campaign is reportedly targeting software developers and engineers with access to or expertise in blockchain resources and infrastructure in the Asia-Pacific region including Australia, India and Japan. This indicates an expansion in Konni’s targeted areas, increasing security risks to firms outside of Europe, Russia and South Korea. The PowerShell backdoor appears to have used AI in its development due to its unusually polished structure that clearly describes the script’s functionality – not a typical feature of threat-actor-made PowerShell implants. This underscores a growing trend by threat actors to employ AI in cyber operations to improve or develop new malware. This campaign also indicates a shift in Konni’s behaviour towards prioritising establishing a foothold in development environments rather than targeting individual end-users. Consequently, blockchain developers and related firms face increased security risks in the medium-to-long term. (Source: Sibylline)
27 Jan 26. Kognitiv Spark: Secure Augmented Reality for Defence Operations.
With UKDI-DASA funding, Kognitiv Spark deployed a cyber secure augmented reality technology that enables remote expert support for military operations.
- The Defence and Security Accelerator, part of UK Defence Innovation (UKDI-DASA), funded Kognitiv Spark through the DTEP programme to deploy their augmented reality remote support solution on secure defence infrastructure.
- The technology enables users out in the field, such as technicians and engineers, to connect with remote experts worldwide using AR headsets, sharing real-time audio-visual feeds and PDF documents, capturing photos with annotations.
- UKDI-DASA funding helped catalyse partnerships with major defence organisations including Rheinmetall MAN Military Vehicles (RMMV), Rheinmetall BAE Systems Land (RBSL) and MSI Defence Systems, and follow-on Army Innovation projects exploring AR as a core military capability.
Augmented Reality for Defence
Picture this scenario: A military technician in Estonia is working on a critical piece of equipment that’s malfunctioning. The specialist with the expertise to fix it is 1,000 miles away in the UK. In the past, this could mean costly delays, expensive travel, or potentially mission-critical equipment remaining offline for days.
Now, with Kognitiv Spark’s augmented reality solution, RemoteSpark, the technician can put on an augmented reality headset and instantly connect with a remote expert. The specialist can see exactly what the technician sees, annotate their shared view in real-time, overlay diagrams, and guide them through the repair step-by-step—all whilst maintaining military-grade security. In a scenario such as this, the equipment can be back online within hours rather than weeks.
This is just one use case that Kognitiv Spark, a small technology company, has created for defence operations worldwide with UKDI-DASA funding support.
Introducing Kognitiv Spark
Kognitiv Spark was founded in 2016 with a clear mission: to enhance worker capabilities through augmented reality remote support, without replacing human expertise. The company, now employing 25 people across the UK, US and Canada, specialises in connecting field workers with remote experts using heads-up, hands-free AR technology.
What sets Kognitiv Spark apart is their “cybersecurity and defence at heart” approach. Adam Clay, Managing Director, UK & EMEA, Kognitiv Spark explains: “Our co-founder Ryan Groom started a cybersecurity company that ended up specialising in augmented reality. Coming from that genesis meant the core product has always been agnostic to network and able to have adaptability to work within the constraints of certain networks.”
This foundation proved crucial for defence applications, where security requirements are paramount.
From concept to deployment with UKDI-DASA support
Kognitiv Spark’s relationship with UKDI-DASA began through the Defence Technology Exploitation Programme (DTEP) in 2022. The SME understood that the AR space had matured, and support for defence uses was growing with the potential to address challenges within the support chain and to help deliver operational efficiencies.
“The DTEP project was twofold,” explains Clay. “In addition to developing the technology, it was also about exposing secure AR to more users across the services and exploring use cases, whilst focusing on secure by design. If this is going to be adopted as a core capability in defence, it needs to adhere to MOD’s security requirements.”
Real-world impact: from workshops to battlefields
The AR technology can work across diverse environments – from workshops and power plants to military field operations. Using AR headsets or smart glasses, defence users can connect with experts anywhere in the world, sharing real-time video/audio feeds whilst simultaneously viewing technical documentation, schematics and receiving guidance from remote workers anywhere in the world.
Their AR solution offers real-time access to support and training, better utilising personnel and digital assets backed up by specialist advice, both deployed and across the Defence Support Network, enabling operational equipment to return to service more rapidly.
Crucially, the solution operates on low-bandwidth connectivity, making it viable in challenging operational environments where network capacity is limited.
Prior to their UKDI-DASA project, Kognitiv Spark had already conducted early work with individual army units, receiving positive feedback from user groups interested in the capabilities of AR and remote support.
However, UKDI-DASA funding enabled greater exposure across defence services, with traction in land and field army applications.
“We’ve been able to expose and receive feedback on our technology from a wide array of Army stakeholders. Not only has it given them time to understand the technology, but it’s also provided them with ideas on how it can be directly used and how to deploy it to solve their challenges,” explains Clay. “Additionally, for Kognitiv Spark, as a small organisation, being able to take on feedback and grow alongside the project has been hugely enabling.”
This exposure led to visibility with users and has generated significant commercial outcomes and partnerships with major defence original equipment manufacturers (OEMs) who recognised the same support challenges their military customers face.
Kognitiv Spark now works with Rheinmetall BAE Systems Land (RBSL), Rheinmetall MAN Military Vehicles (RMMV), and MSI Defence Systems amongst others, providing remote support capabilities that improve efficiency and knowledge sharing across their operations.
DTEP: Combining the expertise of both defence primes and SMEs
The DTEP project enabled Kognitiv Spark to tackle their most significant technical challenge: deploying their SparkOps application on secure sovereign defence cloud infrastructure.
Working with their DTEP higher-tier supplier Serco, Kognitiv Spark was introduced to Prolinx, an SME specialising in secure sovereign cloud solutions for government and MOD.
“Prolinx had a replica sandbox environment of a MOD secure network and experience of the secure by design process,” notes Clay. “We’re now very proud to say that our system has deployed on secure sovereign defence cloud.”
Pioneering the future of military capability
The DTEP project catalysed two additional Army Innovation initiatives that Kognitiv Spark has completed in parallel. The first, ARPAI (Augmented Reality Pan Army Implementation Plan), examined army-level implementation of the AR tech. This work also led to PJ ESART (Project Equipment Support using Augmented Reality), which explores additional support applications.
The UKDI-DASA experience
“This was our first rodeo as an SME dealing with this sort of framework and funding,” reflects Clay. “It had an administration burden in terms of recording and reporting as would be expected for a project of this nature. But the support from our Project Monitoring Officer and others at UKDI-DASA and Dstl has been superb.”
“For innovation to succeed in defence, you need three things aligned: user demand, senior leaders who will champion it, and a sustained funding line. Without all three connected, even excellent projects hit a cliff edge and can’t continue.”
The UKDI-DASA funding allowed us to do this work and test out a theory. Nearly two years on, we’ve emerged and proved it can be done. Thanks to UKDI-DASA and the DTEP project, we’ve had greater exposure within MOD, greater usage within the defence supply chain, and deployment within an environment that MOD can use.
Dual-use innovation for UK defence and industry
Kognitiv Spark exemplifies how UKDI-DASA investment strengthens both defence capabilities and UK technology innovation. Their journey demonstrates how small, agile companies can develop transformative technologies when given strategic support to overcome technical and commercial barriers.
As the company continues developing relationships across the defence ecosystem and proving their technology’s value as potential core military capability, they represent the innovation goals UKDI-DASA funding is designed to nurture – turning great ideas into reality whilst building sustainable UK businesses. (Source: https://www.gov.uk/)
26 Jan 26. Calian Group Ltd. (TSX: CGY), a mission-critical solutions company focused on defence, space, healthcare and other strategic critical infrastructure sectors, announces a strategic initiative to help accelerate the development and deployment of sovereign C5ISRT capabilities through Calian VENTURES (VENTURES), Canada’s defence innovation orchestrator. As Canada places increasing priority on sovereign defence capability, operational readiness and long-term resilience, Calian will advance technology collaboration and mobilize funding to accelerate capability development across Canada. Funding will be drawn from multiple sources, including capital investment from VENTURES, co-development of new intellectual property from Calian alongside multiple Canadian small to mid-size enterprise (SMEs), contributions from regional investment agencies, and federal programs. The first initiative will establish a national, sea-to-sea-to-sea network of regional development labs to accelerate the testing, validation and scaling of defence technologies developed through VENTURES. These labs will convene small and medium-sized enterprises, the Canadian Armed Forces, NATO, government, academia, and industry partners to advance innovative, interoperable solutions from concept to operational capability. By providing VENTURES partners and defence primes with access to shared infrastructure, technical expertise and integration pathways, Calian and its partners will help Canada move faster toward its defence objectives—strengthening Arctic sovereignty, enhancing national security at scale, and modernizing the Canadian Armed Forces.
“Canada is facing a fundamentally different security environment and meeting the moment requires sustained investment, trusted partners and long-term commitment,” said Patrick Houston, Chief Executive Officer, Calian. “This investment reflects Calian’s confidence in Canada’s defence future and our responsibility as a Canadian company to help strengthen Canadian sovereignty as well as help build the Canadian defence industrial base.”
What is C5ISRT
C5ISRT—Command, Control, Communications, Computers, Cyber, Intelligence, Surveillance, Reconnaissance and Targeting—represents the modern defence architecture required to operate effectively in today’s contested, multi-domain environment. Unlike legacy C4ISR approaches, C5ISRT integrates cyber and targeting as core operational functions, enabling faster decision-making, tighter sensor-to-effect integration, and resilient operations across land, sea, air, space and cyber.
“C5ISRT is not a future concept. It is an operational requirement of today’s battlefield and for Canada to own a truly sovereign capability,” said Chris Pogue, President, Defence and Space, Calian. “Mission success now depends on integrating data, systems and people across domains and the ability to sense, decide and act with speed and precision. Through this investment we are scaling the environments, integration pathways, and partnerships needed to turn innovation into operational capability, while ensuring Canada retains trusted, sovereign control of its defence data and systems.”
Calian’s Role as Canada’s C5ISRT Leader
With more than 40 years supporting defence customers, Calian brings unmatched experience in integrating people, systems and operations across domains. Our capabilities span synthetic training, cybersecurity, space and satellite communications, systems engineering and secure-by-design C5ISRT architectures supported by Canadian-based manufacturing of GNSS and antenna manufacturing that strengthens sovereign supply and long-term sustainment of Canadian defence capabilities.
Calian’s workforce—consisting of hundreds of engineers and software developers, including many veterans who understand the operational realities of modern conflict—has delivered mission-critical capabilities where failure is not an option. That experience, combined with VENTURES’ innovation-orchestration model, is what positions Calian to lead Canada’s evolution from legacy defence systems to a fully integrated C5ISRT future.
26 Jan 26. Global: Long-term cyber operation sustains high security risks for developers, technology firms. On 21 January, the technology company Jamf reported that North Korean state-sponsored cyber threat actors are targeting macOS software developers in an ongoing operation. The threat actors likely use social engineering techniques to trick victims into accessing actor-made code repositories to ultimately infiltrate targeted systems. Victims are then prompted to trust the repository’s author which then covertly deploys a JavaScript payload by abusing Visual Studio (VS) code configuration files. The payload conducts initial system reconnaissance before establishing communication with command-and-control (C2) infrastructure, effectively operating as a backdoor. The themes used during the initial phase of the attack indicate that this is the latest iteration of North Korea’s long-term job-recruitment-themed cyber campaign, which aims to steal sensitive information to bolster Pyongyang’s security posture. Consequently, we assess that North Korean state-sponsored threat actors will continue to pose heightened security and information-theft risks to global software developers and technology firms amid geopolitical hostilities. (Source: Sibylline)
26 Jan 26, Trident Solutions (“Trident”), a defense electronics platform backed by ATL Partners, today announced the launch of its Wolf Multi-Domain Communications portfolio. This portfolio unifies mission-critical communications offerings under a single, purpose-built brand while introducing a new product designed to meet emerging operational requirements with reduced soldier cognitive load. The Wolf portfolio reflects Trident’s focus on delivering secure, resilient, and agile communications offerings for operations across air, land and sea domains. Built for contested, denied, and austere environments, Wolf products are engineered to provide assured connectivity, interoperability, and rapid deployment in support of joint and coalition operations.
“The launch of Wolf represents both a unification of proven capabilities and the introduction of new innovation,” said James Yates, Chief Growth and Strategy Officer. “As operational demands continue to evolve, Wolf products will provide a scalable communications foundation designed to operate reliably across domains and alongside allied and partner forces.”
Wolf Portfolio Overview
The Wolf portfolio currently consists of three products, including two rebranded, fielded systems and one newly introduced capability:
- Wolf Mini (formerly Mini-Secure Communications Controller)
A lightweight, plug-and-play tactical voice bridge that provides audio cross connection capability in a handheld form-factor. Fully ruggedized and certified to US Military standards, the Wolf Mini provides interoperability of radios ranging from commercial cell phones to legacy and modern military radios, public safety radios, Voice-Over-IP (VoIP), push-to-talk and full duplex radios.
- Wolf Access Point (formerly Shipboard Wireless Access Point)
A ruggedized shipboard wireless access point that delivers the performance, coverage, reliability and security required to enable secure wireless environments for DoD and Federal Government secure applications. Ruggedized and tested to withstand the rigors of the shipboard environment, The Wolf Access Point provides simultaneous support for high-speed wireless data, voice and video services.
- Wolf Talk (New Product)
A small form-factor, plug and play intercom and radio bridging device for use in mobile command centers and with advance teams. Supporting chassis-mountable and stand-alone operation, Wolf Talk allows operators to monitor dedicated talk groups and immediately connect with all other operators on the dedicated intercom.
As part of the launch, Wolf products feature a new visual identity and naming convention aligned with their operational role, while preserving continuity in performance, technical support, and existing customer programs. Current customers will experience no disruption to ongoing contracts, sustainment, or roadmap commitments.
Follow future updates on Trident’s products and partnerships at www.tridsys.com.
About Trident Solutions
Trident Solutions (Trident) is a leading defense electronics platform providing mission-ready spaceflight units, integrated processing systems, command and control solutions, and precision optical sensors. With deep expertise across multiple domains—space, air, land, and sea—Trident delivers agile, high-performance systems purpose-built for the most demanding national security applications. Trident maintains AS9100-certified quality management systems and is appraised at CMMI Level 3. Learn more at www.tridsys.com. (Source: PR Newswire)
26 Jan 26. Cyber Update
Key points
- US-based critical national infrastructure (CNI) sectors face heightened security and disruption risks from a suspected Chinese state-sponsored group (‘UAT-8837’; see Sibylline Cyber Daily Analytical Update – 19 January 2026).
- Ongoing cyber attacks are sustaining CNI security and disruption risks from pro-Russia hacktivist groups (see Sibylline Cyber Daily Analytical Update – 20 January 2026 and our technical analysis below).
- A new, highly sophisticated malware family (‘PDFSider’) poses increased security risks for global organisations (see Sibylline Cyber Daily Analytical Update – 21 January 2026).
- A long-term cyber operation conducted by North Korean state-sponsored actors is sustaining security risks for developers and technology firms (see Sibylline Cyber Daily Analytical Update – 22 January 2026 and our technical analysis below).
- The rapid exploitation of software vulnerabilities poses high security risks for global organisations in the long term (see Sibylline Cyber Daily Analytical Update – 23 January 2026).
Technical analysis of weekly stories
A suspected Chinese state-sponsored group (UAT-8837) has targeted US-based CNI in a cyber operation since at least 2025. The group exploits known software vulnerabilities and/or stolen credentials to infiltrate targeted systems. Additionally, the tactics and infrastructure associated with UAT-8837 were previously used to exploit a zero-day vulnerability (CVE-2025-53690), which suggests that the group’s arsenal is possibly also capable of identifying zero-day vulnerabilities. Upon obtaining access, UAT-8837 performs initial system reconnaissance to map active directory (AD) environments and to steal internal user credentials, likely in an effort to facilitate lateral movement and privilege escalation. This phase comprises the deployment of several known tools for AD reconnaissance, such as ‘SharpHound’ and ‘Certipy’, as well as other living-off-the-land (LotL) tools and a network tunnelling payload (‘Earthworm’) to expose internal endpoints. Subsequently, the group disables several security mechanisms to evade detection and establishes communication with command-and-control (C2) infrastructure, prolonging persistence and executing malicious code. Various tools used during this next phase include ‘GoTokenTheft’ (to steal an access token), ‘DWAgent’ (for remote administration) and ‘GoExec’ (for remote execution). UAT-8837’s operations reportedly started in 2025 with sporadic attacks throughout the year, highlighting its likely goal of securing long-term access to US CNI for potential future disruption.
North Korean state-sponsored cyber threat actors are targeting macOS developers in an ongoing operation. The threat actors likely use social engineering techniques to trick victims into accessing threat actor-made code repositories to infiltrate targeted systems. The repositories can be downloaded from the popular platform GitHub, which – in combination with the themes used in this initial phase of the attack – indicate that this is the latest iteration of North Korea’s long-term job-recruitment-themed cyber campaign. The repositories require victims to use Visual Studio (VS) Code for configuration and to trust the repositories’ author, as well as to deploy a JavaScript payload covertly. The payload effectively operates as a backdoor, conducting initial system reconnaissance and establishing persistent communication with C2 infrastructure. It also retrieves instructions a few minutes after the initial infection to set up additional payloads for other malicious activities, which likely include stealing sensitive information to bolster Pyongyang’s security posture.
Non-exhaustive recommendations to mitigate against these threats include:
- Monitor devices and networks for suspicious activity.
- Add available Indicators of Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware.
- Adopt behaviour-based endpoint detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
- Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.
Our cyber word(s) of the week: Dynamic Link Library (DLL)
Definition: A shared library in the Microsoft Windows operating system that can contain executable code (functions), data and resources. It can be exploited by threat actors to deploy malware while blending in with legitimate traffic.
Example: ‘This archive contains the PDFSider payload, which is deployed directly into a system’s memory via Dynamic Link Library (DLL) sideloading techniques […]’
Frequency of TTPs during this monitoring period: LOW frequency, MODERATE frequency, HIGH frequency
The MITRE ATT&CK framework is a globally accessible documented collection of information detailing the malicious behaviours of cyber threat actors. It is used as the foundation for organising the processes that threat actors execute during cyber operations. It provides an encyclopaedic reference for organisations, highlighting the TTPs cyber threat actors employ in campaigns, while also providing suggestions for detecting and mitigating against specific TTPs to bolster organisations’ security mechanisms. The framework organises a threat actor’s entire operational lifecycle from reconnaissance to exfiltration and impact.
(Source: Sibylline)
26 Jan 26. Global: Rapid vulnerability exploitation will pose high, long-term security risks to businesses. On 21 January, cyber security company VulnCheck reported that the percentage of software vulnerabilities exploited before or on the day of their public disclosure increased from 23.6% in 2024 to 28.9% in 2025. This showcases threat actors’ increased ability to identify and exploit software vulnerabilities rapidly. VulnCheck identified approximately 884 vulnerabilities abused in cyber operations in 2025 (a rise from 2024). These operations include the exploitation of zero-day vulnerabilities in third-party services in October 2025 and a November 2025 attack targeting the National Health Service (NHS), highlighting data-theft risks to organisations (see Sibylline Cyber Monthly Review – October 2025). Additionally, network edge devices experienced the highest rate of exploitation of both new and old software vulnerabilities, highlighting the importance of patch management policies to protect systems. Software vulnerabilities are a sophisticated attack vector; they enable threat actors to infiltrate targeted systems and to conduct a wide range of malicious activity. We assess that software vulnerabilities will pose high long-term security risks to global organisations, as threat actors continue to develop their capabilities.. (Source: Sibylline)
26 Jan 26. Poland: Russian state-sponsored threat actor poses elevated operational, destruction risks to CNI . On 23 January, cyber security company ESET reported that the Russian state-sponsored group ‘Sandworm’ was responsible for a cyber attack on Poland’s energy infrastructure on 29 and 30 December 2025. The attack attempted to deploy the date-wiper malware ‘DynoWiper’ against two combined heat and power plants, as well as a management system for renewable electricity from wind and solar farms, pointing to the group’s destructive intent against the country’s energy sector. While the attack was reportedly not successful in causing disruption, it highlights Sandworm’s intent and capability to cause disruption and damage operational processes. This attack is allegedly the largest attempted cyber attack on Poland in recent years. We assess that this highlights the elevated long-term security and operational risks to Polish and wider European critical national infrastructure (CNI) as Russian state-sponsored threat actors continue to adapt their cyber strategy amid increasingly strained relations between Russia and the West. (Source: Sibylline)
22 Jan 26. Silvus Technologies Unveils StreamCaster MINI 5200 Tactical MANET Radio. Silvus Technologies (Silvus), a Motorola Solutions company and a global leader in advanced tactical wireless communications, has announced the StreamCaster MINI 5200 (SM5200). It is Silvus’ smallest, fully-featured mobile ad hoc network (MANET) radio, designed to equip ground forces with next-generation mesh networking to securely share voice, video and data without the need for dedicated infrastructure. The ultra-compact 182-gram SM5200 features the high-speed power of a two-by-two MIMO radio, with up to two watts of output power and 100 Mbps of data throughput, providing the secure, reliable connection teams need to stay synced during critical missions. Powered by Silvus’ battle-proven MN-MIMO waveform, StreamCaster MANET radios create a self-forming and adaptive mesh network capable of delivering real-time data, including high-fidelity video across hundreds of nodes, even in the most contested environments.
“The SM5200 is a significant leap forward in providing communications flexibility at the tactical edge,” said Neema Daneshvar, vice president of Product at Silvus Technologies. “It is the smallest radio we’ve ever built that delivers full-size StreamCaster MANET radio capabilities, helping operators gain maximum mobility without sacrificing the range or throughput they depend on.”
The SM5200 eliminates bulky, cable-heavy setups, enhancing operators’ freedom of movement, whether used alone or integrated into tactical networking systems like the StreamCaster NEXUS. Its next-generation audio circuitry delivers advanced voice quality and its push-to-talk (PTT) function allows users to listen to two talk groups simultaneously. The SM5200’s dedicated radio over internet protocol (RoIP) interface seamlessly integrates land mobile radio (LMR) systems into the Silvus mesh digital networks to keep the entire team connected across devices.
The SM5200 supports consistent field uptime with diverse “plug-and-play” power options, from vehicle supplies to wearable batteries, while providing rapid connectivity for cameras, sensors and end-user devices via Ethernet, USB and RS-232 ports. The SM5200 is housed in a ruggedized, IP68-rated waterproof enclosure to perform in punishing environments where standard equipment often fails.
The SM5200 features AES256 and FIPS 140-3 encryption to protect sensitive data. With access to Spectrum Dominance 2.0, an ever-expanding licensable suite of low probability of intercept/low probability of detection, anti-jam electronic warfare resiliency and advanced threat protection capabilities, operators can achieve decision dominance and radio frequency spectrum overmatch even under electronic attack.
About Silvus Technologies, a Motorola Solutions company
As a leading provider of advanced MANET and MIMO communications systems, Silvus Technologies is reshaping mesh network technology for mission-critical applications on the ground, in the air and at sea. Its battle-proven StreamCaster family of MANET radios and proprietary MN-MIMO waveform provides the vital communications link for defense, law enforcement and public safety agencies in the toughest operational environments around the world. Developed by a team of top PhD scientists and design engineers, Silvus Technologies continues to innovate communications technology for the tactical edge with unmatched range, data throughput, EW resiliency and scalability. A Motorola Solutions company, Silvus Technologies is headquartered in Los Angeles.
About Motorola Solutions | Solving for safer
Safety and security are at the heart of everything we do at Motorola Solutions. We build and connect technologies to help protect people, property and places. Our solutions foster the collaboration that’s critical for safer communities, safer schools, safer hospitals, safer businesses, and ultimately, safer nations. (Source: UAS VISION)
——————————————————————————————————————————————————————————————————————————————————————————————————————————————–
Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.
We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.
Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.
———————————————————————————————————————————————————————————————————————————————————————————————————————————

