• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • SPECTRA banner
  • Curtiss-Wright banner

BATTLESPACE Updates

   +44 (0)77689 54766
   

  • Home
  • Features
  • News Updates
  • Defence Engage
  • Company Directory
  • About
  • Contact

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

February 6, 2026 by

Sponsored By Curtiss Wright

https://www.curtisswright.com/


———————————————————————————————————————————————————————————————————————————————————————————————————————————————

07 Feb 26. Soldiers to get new AI capable radios, headsets and tablets with futuristic sensor data.

British soldiers will be able to make faster, better decisions on the battlefield through thousands of new radios, headsets and tablets.

  • New communications systems will give commanders faster battlefield information and speed up decision-making.
  • MOD awards contract worth up to £86m to British-based SME for advanced tactical communication systems, such as radios and tablets.
  • Contract creates 12 UK defence industry jobs and builds on successful deployment in Estonia.

The contract, worth up to £86m, has been awarded to UK-based company BlackTree Technologies with the systems rapidly reducing the time it takes for soldiers to receive reconnaissance and intelligence data, boosting lethality and reducing friendly fire incidents.

Known as the Dismounted Data System (DDS), the AI capable equipment includes radios, headsets, display tablets, cables, batteries, pouches and antennas.

They will provide precise information on surroundings and intelligence, meaning increased clarity on who are enemies and who are comrades.

With all soldiers linked to the same network through this equipment, DDS will also be tailored to different scenarios, allowing troops to receive either, or a combination of, voice or visual data, maximising effectiveness across all battlefield situations.

The new systems have already been tested by soldiers on deployment in Estonia. The testing, on NATO’s eastern flank, saw the visual information element allowing soldiers to be less distracted by loud noises on the battlefield.

This follows the government committing to the largest sustained increase in defence spending since the end of the Cold War – hitting 2.6% of GDP from 2027 – supporting good jobs and growth in every corner of the nation.

Minister for Defence Readiness and Industry, Luke Pollard MP said: “The ability to receive, share and deploy accurate information is crucial to battlefield advantage, and this state-of-the-art technology will make our soldiers more integrated and more lethal.

It will begin rolling out to the British Army this year and with the work delivered by a British-based SME, shows that our move to warfighting readiness is being seized as an opportunity to make defence an engine for growth in the UK.

One of the benefits of the new systems are that they have already been tested by soldiers on deployment in Estonia. The testing, on NATO’s eastern flank, saw the visual information element allowing soldiers to be less distracted from loud noises on the battlefield.

The contract supports this government’s commitment to spend more with UK small and medium sized enterprises (SMEs), with the work creating 12 new jobs in locations in Tewkesbury, Hereford and Birmingham.

The DDS will be delivered to the Army in multiple tranches from September, with the full roll out of equipment set to be complete in 2027. An initial £46 million contact has been made by the Army with BlackTree Technologies, with options for a further £40 million.

The contract supports the Chief of the General Staff’s ambition to double the British Army’s lethality by 2027, and it backs delivery of the Strategic Defence Review to move to warfighting readiness. ”

Head of Tactical Systems, National Armaments Director Group, Brigadier Jeremy Sharpe, said:  We are delighted to be building on the successful deployment in Estonia last year and looking forward to working with BlackTree Technologies to bring this game changing capability to more of the British Army.”

BlackTree founder and Managing Director, Neil Clements-Hill said:  “BlackTree are excited to be working with the TacSys team to field this cutting-edge technology to the British Army. Waveforms ensure that the Army can operate in the most demanding environments, when nothing else works.   From initial experimentation under the DSA programme, through the delivery of Project ASGARD in 2025, and now delivering Dismounted Data System capacity, we have been working closely with the Army for many years and are very happy to continue this close relationship and help ensure that they can achieve their vision of modernising their tactical networks.”

The MOD is ramping up support for UK SMEs, with the establishment in January of the Defence Office for Small Business Growth, and the spending target of an additional £2.5 billion with UK SMEs through to May 2028, taking total annual MOD spending with SMEs to £7.5 billion.  (Source: https://www.gov.uk/)

 

 

06 Feb 26. Southeast Asia: Government, police entities face elevated Chinese-sponsored cyber espionage risks. On 4 February, the cyber security company Check Point reported that a Chinese state-sponsored subgroup (‘Amaranth-Dragon’) has targeted government and law enforcement agencies across Southeast Asia in a cyber espionage operation since at least March 2025. The group uses phishing emails as an initial attack vector to distribute malicious archives, which are hosted on legitimate file-sharing services to enhance legitimacy. In most instances, the archive exploits a software vulnerability (CVE 2025 8088) to execute a custom malware loader (‘Amaranth’) onto compromised systems. The loader then installs two additional malicious payloads (‘TGAmaranth RAT’ and ‘Havoc’) to establish communication with command-and-control (C2) infrastructure and conduct reconnaissance and intelligence collection. The group’s C2 infrastructure is configured only to respond to IP addresses located in targeted countries to increase the campaign’s stealth, highlighting Amaranth-Dragon’s sophistication and resources. Attacks reportedly flare up around relevant geopolitical events, raising security and cyber espionage risks to public sector entities in the region over the medium-to-long term. (Source: Sibylline)

 

05 Feb 26. Dependable Friends
President Donald Trump’s threats to cut the Ukrainian government off from critical intelligence his administration has hitherto been sharing is callous and grossly irresponsible. His latest threat to this effect occurred in late November 2025: Mr. Trump wanted to use the tactic to force Ukraine to accept a putative peace plan drafted by his administration. That peace plan was widely derided as a cheap imitation of the unacceptable demands made by Mr. Trump’s Russian counterpart to end the war. This was not the first occasion on which threats to end US intelligence sharing with Kyiv have been articulated. In March 2025 the Trump administration did pause some intelligence cooperation. This followed the infamous showdown between Ukraine’s President Volodymyr Zelenskyy and Mr. Trump and his vice president James ‘JD’ Vance in the Oval Office. Mr. Trump is either incapable, or unwilling, to understand that the quickest way to end the war in Ukraine is to give the latter all the military, political, economic and diplomatic support she needs to evict all Russian forces from her territory. However, Mr. Trump’s relationship, and seeming adoration of Mr. Putin, raises not only eyebrows but also serious questions, about the former’s allegiance.
Fortunately, there is some good news. As a new year dawned reports emerged that France had stepped into the breech as Ukraine’s biggest foreign intelligence supplier. Speaking on 15th January, President Emmanuel Macron said his country was now supplying two thirds of Ukraine’s foreign intelligence. This includes all-important signals intelligence that Ukrainian forces need to continue fighting the Russian military in the electromagnetic spectrum.
France’s actions are important for several reasons: They show the solidarity of Ukraine’s European allies as the war enters its fourth year. France’s intelligence provision demonstrates a reliable alternative to US-supplied materials. Moreover, European nations can clearly step into the breech when Mr. Trump’s irresponsible behaviour once more rears its head. Perhaps most importantly, France’s actions show that alternatives to US intelligence exist. The provision of the latter is frequently highlighted by some European security commentators as a key capability Europe cannot do without. By European nations working together on intelligence sharing as much as is practically possible, those same nations will help reduce overall dependences on the United States. Any step in this direction can only be a good thing; European strategic autonomy will be strengthened and the dependence on an increasingly adversarial US administration will be reduced or even eliminated. (Source: Armada)

 

05 Feb 26. Passive Aggressive?
A constituent part of the Chinese DWL002 passive radar system is seen here during a military parade in Algeria. Venezuela is another DWL002 user alongside Pakistan, the People’s Republic of China and Turkmenistan.
Armada has learnt that the People’s Republic of China supplied at least one DWL002 passive radar to the Venezuelan military. What role did this system play during Operation Absolute Resolve?
Venezuela’s DWL002 acquisition is thought to have occurred before Operation Absolute Resolve. This was the codename for the America military initiative to capture the erstwhile Venezuelan dictator President Nicolàs Maduro, and his wife Cilia Flores, on 3rd January. The operation was noteworthy for its success: Only a single helicopter from the United States Army’s 160th Special Operations Aviation Regiment was damaged by Venezuelan ground-based air defences, according to reports. The helicopter was carrying commandoes to and from their objective, Mr. Maduro’s compound in downtown Caracas. Absolute Resolve included a comprehensive Offensive Counter-Air (OCA) component. The OCA effort resulted in the strike package of circa 150 US combat aircraft supporting the operation suffering no losses.
DWL002 defined Open-source information states that the is designed to detect, locate and identify (henceforth known as process) air and maritime surface targets via their Radio Frequency (RF) signals. The vehicle-mounted system consists of three containers, each of which has a receiving antenna. By using three antennas the DWL002 determines the origin of Signals of Interest (SOIs). This is done by triangulating the line-of-bearing of each signal from each receiving antenna. The DWL002 uses two techniques to process a SOI; time difference or arrival and angle of arrival. By placing at least one of the receiving antennas on a higher point compared to the others, the DWL002 can determine a target’s angle of elevation. Alongside the three receiving antenna containers, the DWL002 has a master station from where the system is controlled. These constituent elements are networked using microwave radio links. These links use X-band (eight gigah,ertz/GHz to ten gigahertz) and Ku-band (twelve gigahertz to 18GHz) frequencies.
Alongside these techniques the DWL002 can detect disturbances to residual civilian television and radio broadcasting signals caused by their reflections from airborne targets. The system is equipped with three Yagi antennas collocated on each receiving mast for this purpose. The exploitation of residual RF radiation is intended to aid the detection of airborne targets using Emission Control (EMCON) techniques. Open sources continue that targets with a Radar Cross Section (RCS) of circa 0.01 square metres (-20 decibels-per-milliwatt/dBm) can be detected with using the Yagi antennas. Sources continue that RF signals from combat aircraft can be detected at ranges of circa 216 nautical miles/nm (400 kilometres/km). SOIs captured and processed by the DWL002 include those from airborne surveillance and fire control radars, naval surveillance radars, identification friend or foe transponders, and airborne/maritime radio communications and navigation systems. Sources continue that the DWL002 can process emissions across wavebands of 100 megahertz to 18GHz. This waveband encompasses most radar and radio communications signals emitted by combat aircraft and warships.
The DWL002 and Venezuelan air defence
Several questions surround the DWL002 and its use, or otherwise, as part of Venezuela’s Integrated Air Defence System (IADS) and accompanying Ground-Based Air Defences (GBAD) on 3rd January. Firstly, was the system activated? As a passive system, the DWL002 would be attractive to deploy as it would not make any RF emissions that US Electronic Support Measures (ESMs) could process. Even its X-band and Ku-band communications signals would be difficult to detect at range: Their highly directional nature would make them hard to detect unless an ESM’s receiving antenna was directly pointing at them.
Nonetheless, the deployment of the system, with its three masts, supporting vehicles and containers could be relatively easy to identify from reconnaissance imagery unless heavily camouflaged. It is entirely possible that Venezuela’s DWL002 systems were not deployed prior to Operation Absolute Resolve. As tensions with the United States increased in the latter half of 2025, did the Venezuelan military decide to keep the passive radars out of the field? Keeping the DWL002s in the barracks may have avoided them being targeted by US assets.
It remains unknown how many DWL002s Venezuela acquired, when these were delivered or which of Venezuela’s armed forces operates them. Armada understands that the country’s air defences are the responsibility of the Ejército Bolivariano (Bolivian Army of Venezuela) and Aviación Militar Bolivariana (Bolivian Military Aviation of Venezuela). The army is the custodian of the country’s long-range/high-altitude and medium-range/medium-altitude surface-to-air missile batteries. The country’s militia and national guard are responsible for short-range air defence. The air force performs the command and control of the country’s CODAI (Comando de Defensa Aeroespacial Integral/Integrated Airspace Defence Command). CODAI is the national IADS and integrates the country’s GBAD assets and fighters. It is assumed that the DWL002 is commanded by the Venezuelan army.
The DWL002’s manufacturer advertises that the system can detect, locate and identify aircraft with low RCSs. The US Air Force’s Lockheed Martin F-22A Raptor combat aircraft which participated in Operation Absolute Resolve has a reported RCS of between 0.0002 and 0.0005 square metres (-37dBm and -33dBm). The RCS of the Lockheed Martin F-35 Lightning series combat aircraft, another participant, is reportedly 0.0015 square metres (-28.2dBm). Perhaps these RCSs were just too small for the DWL002 to adequately process?
Assuming that the DWL002 was active on the night in question, did US EMCON discipline simply deprive the DWL002 of any RF emissions to exploit? No doubt rigid EMCON discipline was exercised by both the participating American aircraft and ships. Was the DWL002 was able to detect some US assets that had been lackadaisical regarding EMCON? Even so, what if this information was shared but never reached a CODAI command and reporting centre? Although details remain sparse it seems likely that significant jamming efforts may have been performed by US air defence suppression assets like the US Navy Boeing E/A-18G Growler aircraft participating in the operation. The Growlers could have brought their capabilities to bear to significantly degrade radio networking knitting the IADS and GBAD assets. Cyberattacks against the IADS may have been successful by rendering its digital elements unserviceable or untrustworthy.
Assessment
Operation Absolute Resolve and the participation, or otherwise, of the DWL002 illustrates some important realities: First, a system like the DWL002 is arguably only effective as an air defence asset if it is networked into wider IADS and GBAD architectures. Second, the low RCSs of platforms like the F-22A and F-35 may be too small to be detected with any accuracy or precision by a system like the DWL002. Third IADS, and accompanying GBAD elements writ large, must be as survivable as possible. Survivability depends on kinetic, electronic and cyber resilience, redundancy and survivability. Ultimately, a system like the DWL002 is but one important part of an anti-access/area denial posture, but it is in no way a panacea. (Source: Armada)

 

05 Feb 26. About Time
Russia’s IL222M Avtobaza-M signals intelligence platforms have also been exported to Iran and Armenia. The system maybe undergoing an upgrade to provide it with accurate timing systems.
New research by EW Analytics LLC reveals some serious deficiencies in the performance of Russia’s IL222M Avtobaza-M SIGINT system an upgrade programme is trying to remedy.
In May 2024, Armada published an article examining Russia’s IL222M Avtobaza-M Signals Intelligence (SIGINT) collection platform, and its use by the Islamic Republic of Iran military. Alongside Iran, the IL222M is used by the Russian and Armenian armed forces. Regular visitors to the Armada website, and readers of our monthly Electronic Warfare Newsletter, will be familiar with our regular collaborations with EW Analytics LLC. EW Analytics LLC recently shared new research the company is publishing pertaining to the IL222M. It has revealed that Russian Avtobaza-Ms may be undergoing an upgrade programme to improve their capabilities.
Avtobaza’s capabilities
As noted above, the IL222M collects SIGINT, specifically in support of Ground-Based Air Defence (GBAD). It detects, locates and identifies (henceforth referred to as processes) air threats via their electromagnetic emissions. Russian military documents seen by Armada say the IL222M processes emissions on a 200 megahertz/MHz to 18 gigahertz/GHz waveband. Avtobaza-M will process signals from Identification Friend or Foe (IFF) transponders equipping aircraft. These transponders usually squawk across wavebands of one gigahertz/GHz to 1.21GHz. Aircraft Tactical Air Navigation (TACAN) emissions from 962MHz to 1.213MHz can be processed by Avtobaza-M. Other key targets include emissions from Airborne Early Warning (AEW) aircraft.
Armada understands from official Russian language documents that the Avtobaza-M processes signals with a minimum strength of -88 decibels-per-milliwatt. Emission direction-finding is determined with between 0.4- and one-degree of accuracy. The documents continue that targets can be detected at ranges of up to 108 nautical miles (200 kilometres). Avtobaza-M shares data on target azimuth and elevation angle, radar type (pulse-Doppler and/or continuous wave) and emission waveform. Up to 60 targets can be simultaneously processed. Target detection is done using a rotating antenna making either six or twelve revolutions-per-minute. The IL222M consumes twelve kilowatts of electricity. The system’s architecture includes one processing station, and four detection and direction-finding stations. The entire system is deployed on two vehicles and networked using a two-way fibre optic link carrying data at a rate of 1.2 kilobits-per-second. Target information (target angle, azimuth and elevation) is displayed on the operator’s console. Other parameters like signal carrier frequency and pulse duration are also displayed. Avtobaza-M’s human-machine interface is highly customisable by the operator. For example, taboo frequencies can be set along with specific search sectors and/or off-limits areas.
Air targets can be processed via their emissions providing bearing information relative to the system’s location. Once this information is determined, it can be shared with GBAD assets to alert the latter on a target’s possible ingress vectors. Likewise, this data can be shared with fighter controllers to direct combat aircraft to perform interceptions.
SOI’s source
EW Analytics LLC has examined patent documents filed with the Russian government’s Federal Intellectual Property Service. The company’s analysis noted that several patent applications had been lodged with the intellectual property service in 2015, 2016 and 2025. These patent applications either explicitly pertained to the Avtobaza-M or pertained to a system with almost identical capabilities.
The most recent patent application stressed that the IL222M in its current form is unable to accurately geolocate the origin of Signals of Interest (SOIs). Specifically, the pre-upgraded system cannot use Direction Finding (DF) techniques like Time Difference of Arrival (TDOA) to determine a SOI’s point of origin. This is because prior to the recent upgrade, the Avtobaza-M did not have access to precision timing data provided by an atomic clock which is needed to perform TDOA processing, and which can be calibrated by a Global Navigation Satellite System (GNSS).
Until now, the lack of an accurate time source will have severely impeded the ability of the IL222M to support the defensive counter-air battle. It is one thing knowing that SOIs are being transmitted by hostile aircraft in range of the system. However, this information is of limited use to GBAD elements if the location of the source of these emissions cannot be determined.
EW Analytics LLC’s analysis shows that the Russian military is aware of this shortcoming and that it is being addressed. Given that Russia has domestic industrial expertise in producing atomic clocks and GNSS receivers such subsystems may not be difficult to obtain. That said, Russia remains under international sanctions because of her ongoing war against Ukraine. These sanctions could impinge the country’s ability to source components for timing systems that cannot be obtained domestically. What is interesting about the IL222M upgrade is that it highlights a gap between the advertised capabilities of a Russian EW system and current performance realities. One wonders if similar discrepancies exist in other Russian electronic warfare platforms?
(Source: Armada)

 

05 Feb 26. Testing Legion
Picogrid announced towards the end of January that the company’s Legion data platform had been employed during testing performed by the United States Army’s 1st Cavalry Division (1CD). The testing took place at the National Training Centre, Fort Irwin, California. According to a press release announcing the news, Picogrid’s Legion software integrates disparate sensor networks. In a written statement provided to Armada, the company said that Legion “provides common command and control services such as data federation, tasking of remote systems, role-based access control, tracks and correlation”. Picogrid observes that it is “faster and more cost-effective for the military to integrate sensors, effects and (uninhabited) systems, resulting in superior, real-time situational awareness, faster decision-making, and autonomous behaviour”. Legion can be used as a cloud-based service. Alternatively, it can be deployed in a containerised fashion, depending on the mission, the company’s written statement continued. Testing initiatives help the army to evaluate technologies and capabilities and thus inform future procurements. The press release said that during this latest testing effort Legion received inputs from passive radio frequency and acoustic sensors alongside radar data. Sensor feeds were fused, correlated and then shared with those parts of the 1CD’s manoeuvre force needing these data. This latest evaluation saw sensor inputs and data outputs supporting the Counter-Uninhabited Aerial Vehicle (CUAV) mission. The press releases stated that Legion “enabled triangulation and track correlation” to provide high fidelity UAV tracks. The higher the track quality provided to manoeuvre force CUAV assets, the higher the probability that hostile UAVs will be successfully intercepted. The press release concluded by saying that the company plans to continue “supporting future exercises and training events” as the army “advances its modernisation efforts” in the future.
Cirra Moves Ahead
In late January Helsing revealed it had completed testing of its Cirra Electronic Support Measure (ESM). According to reports, Cirra was integrated onto a flying testbed for evaluation. The reports continued that the ESM was able to identify radar threats in real time during testing. The ESM uses Artificial Intelligence (AI) enabled software to identify radar threats. During the tests, details of these threats were sent across a satellite communications link and validated against actual operational radar data. The development of Cirra marks a departure from some traditional Electronic Intelligence (ELINT) techniques. Traditionally, ESMs could be pre-programmed with signal parameters taken from a threat library. The parameters of detected signals are then matched against these library parameters to identify an unknown radar and/or its behaviour. By using AI enabled software and deep learning Cirra analyses a signal’s parameters to infer the radar’s intent. The company claims that Cirra is the only sovereign system able to interpret previously unencountered radar signals in real time which is available to European air forces. In November 2025, Helsing announced its selection to provide Cirra software to equip the Luftwaffe (German Air Force’s) forthcoming Eurofighter Typhoon-EK electronic warfare combat aircraft. Cirra will be integrated with the Saab Arexis EW sensor suite equipping these jets. (Source: Armada)

 

05 Feb 26. Global: Increased industrial, technological exploitation underscores operational, supply-chain risks. On 4 February, international news outlets reported that the number of cyber attacks on operational technology (OT) environments increased significantly in 2025. This increase reportedly included an 84% rise in cyber attacks that exploited OT-specific protocols, highlighting cyber threat actors’ growing ability to disrupt industrial processes. Cyber attacks on Internet-of-Things (IoT) devices also rose from 16% to 19% over 2025, suggesting that these devices remain a popular attack vector. More broadly, the number of cyber attacks mounted from the top ten origin-countries in 2024 decreased by 22%, showcasing a growing global dispersion as threat actors increasingly abuse cloud technologies. Elsewhere, threat actors exploited vulnerabilities in artificial intelligence (AI) platforms, profiting from the wider adoption of these technologies among businesses to improve cyber security practices. Consequently, we assess that this report underscores the increased security, operational and supply-chain risks from the growing abuse of both IT and OT for malicious cyber activity. (Source: Sibylline)

 

03 Feb 26. Thales Strengthens its Digital Core in Singapore
• Three Memorandums of Understanding (MoUs) signed with the Singapore Economic Development Board (EDB) during the Singapore Airshow 2026 will strengthen Thales’ capabilities in AI, cloud, edge computing, data engineering and manufacturing in Singapore.
• Thales will grow its pool of Inflight Entertainment (IFE) experts to nearly 40 in the next three years in order to support the development of its FlytEDGE IFE solution.
• Fintech and other highly regulated industries can now keep their critical data cybersecure and compliant with the latest Regulatory Technology (‘RegTech’) managed service, powered by AI and created locally by Thales.
• Smart automation solutions will drive greater efficiencies and scale in manufacturing at Thales’ largest Cyber & Digital Manufacturing Competence Centre in Singapore.
Thales has invested in its industrial and technological footprint in Singapore for over 50 years. From the establishment of Avionics activities in 1973 to the launch of cortAIx, Thales’ AI accelerator, in Singapore last year, the Group is paving the way as a deep tech company, innovating in AI, cybersecurity and quantum technologies. At the Singapore Airshow 2026, Thales announces its investments in new technologies within the following sectors:
1. Singapore becomes one of three global R&D centres for the FlytEDGE IFE solution, training close to 40 experts by 2030
Thales’ award-winning FlytEDGE is the industry’s first and only cloud-native inflight entertainment platform, helping airlines deliver extraordinary digital experiences and deepen customer connections in real-time. In Singapore, Thales established its IFE Cloud Centre of Excellence (CCoE) in 2021 to develop local expertise in cloud-based digital services. Through a new MoU, the CCoE will ramp up its expertise in cloud, data engineering and edge computing, becoming one of three global R&D centres for FlytEDGE, alongside France and the United States.
In the next three years, 40 experts will provide technical and engineering support for FlytEDGE in Singapore, as well as develop new end-to-end services that integrate cloud and edge computing, cybersecured-by-design. Edge computing will enable advanced processing, accurate data collection and insights in real time on-board, while cloud automation will reduce manual operations. FlytEDGE enables passengers to seamlessly bring their personal devices and their world into the aircraft.
2. Thales keeps companies compliant in their cloud environments with a new Regulatory Technology managed service
Developed jointly by Thales teams in Singapore and France, the unique service is a cybersecure AI-enabled solution tailored to multiple public cloud infrastructures, including AWS, Azure and Google Cloud. This solution creates a secure cloud environment (‘landing zones’) in which project teams can build and deploy applications quickly and be audit-ready for applicable regulations. This landing zone integrates controls and continuous real-time monitoring, adapted to multiple industries and jurisdictions. Thanks to its ability to continuously collect digital evidence, this solution ensures that companies across all industries remain cyber secured, audit-ready, and aligned with latest regulatory standards in their cloud journey. It is available for Fintech customers, with the aim to serve other regulated sectors like pharmaceuticals and aerospace in the coming months.
3. Boosting manufacturing capabilities with greater automation and talent development
With an annual capacity to produce over 200 m banking cards, 12 m identity cards and close to 10 m passport datapages annually, the Singapore Cybersecurity & Digital Identity Manufacturing Competence Centre is a flagship multi-product facility in Asia. The third MoU marks a new step in the site’s industrial transformation with the integration of advanced smart automation technologies like Collaborative Robots (COBOTs) and Autonomous Mobile Robots (AMRs) for transportation, loading & unloading, inspection and machine setups across the production. This transformation also fuels workforce upskilling, shifting teams toward higher-value roles. By combining human expertise with intelligent automation, the 21,000 square metre site continues to set benchmarks for performance and agility, positioning it amongst Thales’ most competitive production facilities. This factory is fully aligned with Singapore’s ambition as a global hub for advanced, high-tech manufacturing.
“We greatly value Thales’ partnership and commitment to develop a future-ready talent pool and drive transformative impact from Singapore. These investments will reinforce our position as a global innovation hub for frontier technologies, and exemplify how companies can tap on our trusted and comprehensive ecosystem to co-create new solutions in advanced manufacturing.” Zheng Jingxin, Vice President and Head of Mobility, EDB.
“These agreements illustrate Thales’ continued investment in Singapore, where we are deepening our expertise in technologies like AI, cyber, quantum and cloud, developing home-grown solutions, while transforming our industrial operations to meet customers’ expectations. The support and partnership from the EDB is pivotal and I look forward to bringing the best of our capabilities to strengthen Singapore’s cyber and digital positioning, and advance its manufacturing ambitions.” Emily Tan, Country Director and Chief Executive, Thales in Singapore.
Thales is at the Singapore Airshow on stand #G24 (Hall A) from 2-8 February.

03 Feb 26. Global: Software update exploitation shows long-term supply-chain risks from Chinese threat actors. On 2 February, international news outlets reported that unnamed Chinese state-sponsored actors hijacked legitimate software updates to conduct a cyber operation between June and December 2025. The threat actors specifically exploited a vulnerability affecting the popular open-source editing tool Notepad++ to direct update requests to malicious servers and ultimately infiltrate targeted systems. They subsequently performed reconnaissance activity likely to familiarise themselves with compromised environments and collect strategic intelligence. The attack reportedly only compromised specific users of interest, highlighting its targeted nature and contained scope. In September 2025, after losing access due to firmware updates, the threat actors restored their access to compromised systems through stolen credentials, showcasing their resilience. While the attack was detected and successfully remediated in December 2025, we assess that it illustrates the long-term security and supply chain risks stemming from Chinese state actors amid geopolitical hostilities. (Source: Sibylline)

 

02 Feb 26. Global: Increase in ransomware attacks highlight data-theft, disruption risks to high-profile sectors. On 30 January, international news outlets reported an increase in the number of organisations targeted in ransomware attacks in Q4 2025, despite a decrease in the number of active ransomware groups. The number of organisations that suffered data leaks following an infiltration and deployment of ransomware rose by 50% compared to Q3 2025, and 40% compared to Q4 2024. Threat actors partially released stolen data during the attacks to increase pressure on victims to pay the ransom, highlighting the continued use of extortion tactics. The most prolific ransomware groups during Q4 2025 included ‘Qilin’, ‘Akira’ and ‘Sinobi’; attacks by the latter increased by over 300% compared to the previous quarter. These groups continue to prioritise speed in their attacks, likely to avoid detection before they can deploy the ransomware payload. The groups’ victims span multiple high-profile organisations and sectors, including critical national infrastructure, sustaining information-theft, disruption and financial risks in the medium-to-long term. (Source: Sibylline)

 

30 Jan 26. Cyber Update
Key points
• The renowned Russian state-sponsored group ‘Sandworm’ poses elevated operational and destruction risks to Polish critical national infrastructure (CNI) (see Sibylline Cyber Daily Analytical Update – 26 January 2026).
• A North Korean state-sponsored group (‘Konni’) poses increased security risks to blockchain developers via the distribution of an artificial intelligence (AI)-assisted ‘PowerShell’ backdoor (see Sibylline Cyber Daily Analytical Update – 27 January 2026 and our technical analysis below).
• Extortion attacks by the renowned cyber criminal alliance ‘SLSH’ underscore heightened security and financial risks to large organisations (see Sibylline Cyber Daily Analytical Update – 28 January 2026).
• The distribution of an AI-generated remote access trojan (RAT; ‘PureRAT’) raises short-to-medium term security and information-theft risks for global firms (see Sibylline Cyber Daily Analytical Update – 29 January 2026).
• A spyware campaign underscores the surveillance and cyber espionage risks to Android mobile users in Pakistan (see Sibylline Cyber Daily Analytical Update – 30 January 2026 and our technical analysis below).
Technical analysis of weekly stories
A renowned North Korean state-sponsored group (Konni) is targeting cryptocurrency and blockchain software developers and engineers across the Asia-Pacific region with an artificial intelligence (AI)-generated PowerShell backdoor. Konni likely uses phishing emails to trick victims into clicking on a malicious link hosted on the communications platform Discord to deploy a ZIP archive onto compromised systems. The archive contains a PDF document likely designed to enhance legitimacy, and an LNK file responsible for downloading a malware loader. The loader subsequently deploys another decoy file alongside a CAB archive containing the main backdoor, two batch files and an executable, highlighting the multi-pronged and complex nature of this attack. These files work together to stealthily execute PowerShell, establish communication with command-and-control (C2) infrastructure and reduce forensic visibility. Upon deployment, PowerShell conducts anti-analysis and sandbox-evasion checks to ensure its obfuscation while initiating the data exfiltration process. Notably, the backdoor’s code starts with a human-readable sentence which details the script’s functionality and is divided into clearly defined logical sections; it also contains verbose comments throughout, further indicating the use of AI during the generation process. We assess that this demonstrates the increased adoption of this AI across all levels of resources and capabilities.
Unknown threat actors are targeting Android users in Pakistan in a cyber espionage and surveillance campaign. Threat actors distribute a malicious application that emulates a legitimate Android dating service available on the Google Play Store as initial attack vector. Upon execution, the application requests several user permissions to display a login overlay that prompts victims into entering hardcoded credentials. Subsequently, victims are shown an interface populated with a series of locked dating profiles which can only be accessed with an exclusive code, likely to enhance the social engineering campaign. Meanwhile, the malicious application covertly installs a spyware component (‘GhostChat’) onto compromised devices to continuously monitor and exfiltrate user information. Once the exclusive code is provided, threat actors also redirect users to a chat on the messaging platform WhatsApp which uses multiple Pakistan-based phone numbers, likely to gain further data access. We assess that this highlights the actors’ skills and resources, particularly as the campaign also comprises other sophisticated attack vectors.
Non-exhaustive recommendations to mitigate these threats include:
• Monitor devices and networks for suspicious activity.
• Add available Indicators of Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware.
• Adopt behaviour-based endpoint detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
• Conduct cyber-hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.
Our cyber word of the week: Blockchain
Definition: The system whereby cryptocurrency transactions and assets are publicly recorded across an interconnected network.
Example: ‘The campaign is reportedly targeting software developers and engineers with access to or expertise in blockchain resources […].’
(Source: Sibylline)

 

02 Feb 26. The new R&S FPL1044 from Rohde & Schwarz offers a frequency range of 10 Hz to 44 GHz. It is the first and only spectrum analyzer in this price range on the market to reach the 44 GHz milestone, drastically lowering the entry barrier for high-frequency testing.
Setting itself apart within the FPL family, the FPL1044 is the only model to offer a DC coupling option, expanding the measurable frequency range starting from as low as 10 Hz. This feature ensures maximum versatility for analyzing signals from extremely low frequencies up to the critical Ka-band. The analyzer maintains the compact, lightweight dimensions and robust design of the FPL family, ensuring portability and efficient use of bench space. It features a standard 2.92 mm male input connector for reliable high-frequency measurements.
Launching simultaneously with the R&S FPL1044 is the new R&S FPL1-K41R 40 MHz real-time spectrum analysis option. This upgrade is compatible with all frequency variants of the FPL family, empowering users across the entire product line with the ability to capture and analyze even shortest events with a Probability of Intercept (POI) time as low as 4.2 µs.
For the new R&S FPL1044, this means 40 MHz real-time frequency analysis is now available up to 44 GHz, providing a complete, affordable solution for the challenging world of high-frequency signal monitoring and component testing.
Targeting critical high-frequency applications
The frequency range of 26.5 GHz to 44 GHz is vital for the aerospace & defense industry, as well as the components industry and for research. It is used for satellite links, radar, radio navigation, earth observation and radio astronomy. Key applications for the R&S FPL1044 are testing satellite and radar systems and components, production quality control of high-frequency components (e.g., filters, amplifiers, traveling-wave tubes) as well as on-site repair and maintenance.
The R&S FPL1044 spectrum analyzer and the R&S FPL1-K41R 40 MHz real-time spectrum analysis option are available now from Rohde & Schwarz. For more information, go to: http://www.rohde-schwarz.com/product/fpl
———————————————————————————————————————————————————————————————————————————————————————————————————————————————-
Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.
Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

————————————————————————————————————————————————————————————————————————————————————————————————————————————-

Primary Sidebar

Advertisers

  • Pythia
  • Teledyne
  • Exensor
  • Visit the Oxley website
  • Blighter
  • SPECTRA
  • Britbots logo
  • Faun Trackway
  • Systematic
  • CISION logo
  • ProTEK logo
  • ProTEK logo
  • ssafa logo
  • IEE
  • EXFOR logo
  • sibylline logo
  • Team Thunder logo
  • Comtech logo
  • GoExporting logo
  • ECHODYNE logo
  • Supercat logo
  • Galvion logo
  • Leonardo DRS logo
  • MTC logo
  • IDC logo
  • DSEI logo
  • DVD2024 logo
  • SDSC logo
  • TELEDYNE FLIR logo
  • VeteranUK logo
  • Matrix Space logo
  • ST Engineering logo
  • EWS logo
  • sentinel photonics logo
  • capua logo
  • Curtiss-Wright logo
  • Brave1 logo
  • Drone Evolution logo
  • AEI Systems logo
  • EOS logo
  • NMSUK logo
  • Openworks logo
  • Sandown Park logo
Hilux UKDSE AARTOS ST Engineering Future Artillery

Contact Us

BATTLESPACE Publications
41 St Georges Drive
London SW1V 4DG

+44 (0)77689 54766

BATTLESPACE Technologies

An international defence electronics news service providing our readers with up to date developments in the defence electronics industry.

Recent News

  • Protek Selected By Dutch Armed Forces

    May 2, 2026
    Read more
  • PARLIAMENTARY QUESTIONS

    May 1, 2026
    Read more
  • MANAGEMENT ON THE MOVE

    May 1, 2026
    Read more

Copyright BATTLESPACE Publications © 2002–2026.

This website uses cookies to improve your experience. If you continue to use the website, we'll assume you're ok with this.   Read More  Accept
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT