Sponsored By Curtiss Wright
https://www.curtisswright.com/
————————————————————————————————————————————————————————————————————————————————————————————————————————————-
19 Feb 26. Bittium, a leading supplier of resilient software-defined radio-based communications, and KNL, a pioneer in HF radio technology, have started a collaboration to provide advanced hybrid communications capabilities for defense. In hybrid networks, KNL’s solutions operating on HF (High Frequency) bands complement Bittium’s network solutions operating on VHF and UHF (Very High Frequency, Ultra High Frequency) bands. Through this cooperation, customers can be offered interoperable networks that cover distances of up to thousands of kilometres, enabling also resilient cross‑border communications that strengthens situational awareness and supports operational superiority. The jointly integrated, seamless hybrid communications solution combines Bittium’s reliable Line‑of‑Sight (LOS) and Non‑Line‑of‑Sight (NLOS) communications solutions, including the wideband, mobile TAC WIN backbone network and the new generation Tough SDR radios, with KNL’s long‑range, Beyond‑Line‑of‑Sight (BLOS) cognitive HF radios. The interoperability of the solutions has been verified in joint demonstrations. The combined solution enables connections between tactical networks and HF nodes located farther away. IP‑level integration allows networks to be expanded freely and flexibly. The network can also be extended seamlessly with the ESSOR High Data Rate Waveform, which NATO has approved as the interoperability standard for tactical communications. The waveform can be used with Bittium’s Tough SDR radios to connect allied forces into the same network.
“The cooperation with KNL brings a new long‑range dimension to Bittium’s tactical networks, enabling seamless hybrid communications across multi-domain operations. Thanks to IP‑level integration, networks can be expanded flexibly across wide geographical areas, improving command and control and strengthening interoperability between nations. This is also essential from the perspective of European sovereignty. We are entering an era in which defense networks are increasingly complex and combine several different technologies. Bittium’s and KNL’s technologies interconnect into a single resilient entity that scales dynamically according to operational needs. The goal is a comprehensive network in which every connection, whether HF, satellite, or commercial 5G, functions seamlessly as part of the same IP‑based architecture, providing continuous situational awareness for command and control in all conditions”, says Tommi Kangas, Senior Vice President of Bittium’s Defense & Security Business Segment.
“This isn’t traditional HF communication with two operators holding handsets. It’s data flowing directly from beyond the horizon into tactical IP networks and command systems – and vice versa. Our combined solution enables connecting tactical bubbles across the scattered battlefield and extension of core network services even to the most remote soldiers operating beyond the enemy lines. The collaboration with Bittium demonstrates how modern HF functions as a natural part of IP-based battle management systems”, says Toni Lindén, CEO of KNL.
19 Feb 26. Global: Exposed organisations face elevated security risks from zero-day vulnerability exploitation. On 18 February, the cyber security firm Mandiant reported that a suspected Chinese state-sponsored group (‘UNC6201’) had been exploiting a software vulnerability (CVE-2026-22769) to conduct malicious cyber activity since at least mid-2024. The vulnerability affects virtual machines (VMs) provided by the technology company Dell and enables unauthenticated threat actors to move laterally, maintain prolonged persistence and deploy malicious payloads. It is possible that UNC6201 infiltrated a network edge appliance to gain initial access. In September 2025, the group also deployed a new backdoor (‘Grimbolt’) onto compromised systems, which uses ahead-of-time (AOT) techniques to enhance detection evasion, highlighting its sophistication. It is likely that the objective of UNC6201’s campaign is cyber espionage based on China’s long-term cyber strategy. Although Dell released a fix for this vulnerability on 17 February, we assess that vulnerable organisations in key adversarial sectors will face heightened security risks in the short-to-medium term, underscoring the importance of timely patch management. (Source: Sibylline)
19 Feb 26 . Kongsberg Discovery has upgraded its innovative Kongsberg Listen electromagnetic sensor system, setting new standards for inspections, surveys and knowledge acquisition in complex underwater environments. Formerly known as Argeo Listen, the system has undergone comprehensive hardware and software enhancements, delivering much-improved data processing and visualisation capabilities. The platform agnostic technology is now available for a huge range of applications across the ocean science, defence, energy and minerals sectors, amongst others.
Accelerating innovation
Kongsberg Discovery acquired Argeo’s electromagnetic sensing technologies, and recruited its expert staff, in August 2025, and has since focused on integrating the solutions into its existing portfolio, while accelerating innovation. Kongsberg Listen demonstrates the fruits of that commitment. The system has already been integrated and extensively operated on Kongsberg’s HUGIN family of AUVs, demonstrating excellent results in commercial surveys, and is now being rolled out commercially. Next month’s Oceanology International in London marks its trade show debut as Kongsberg Listen.
Delivering confidence
“Argeo Listen was already a world leading passive electromagnetic sensing solution and this upgrade takes it to a new level,” comments Audun Berg, EVP Kongsberg Discovery. “The refinements combine to deliver clearer, more precise results with enhanced efficiency and simplicity, whatever the demands of the mission. This helps users move from data acquisition to actionable insights with increased speed and confidence. The results we’ve already been seeing onboard HUGINs gives an indication of what customers can look forward to – with proven high performance in applications spanning everything from pipeline inspection with cathodic protection evaluations, to marine mineral explorations, and geophysical surveys including buried cable positioning. Kongsberg Listen is the solution the market has been waiting for.”
Flexible approach
Users familiar with Argeo Listen will immediately recognise the significantly enhanced software environment, now tightly integrated with Kongsberg’s Blue Insight ecosystem. The upgraded suite enables streamlined, end‑to‑end workflows, delivering seamless data processing from raw electromagnetic measurements through to client‑ready information and visualisation within a common operational framework.
The flexibility of the system is also a key selling point, with ease of installation and use on an array of industry-essential platforms, from AUVs and ROVs through to towed sensing assets.
“We’re thrilled to be showcasing Kongsberg Listen for the first time in London this March,” Berg concludes. “It dovetails perfectly with the other innovations we’ll be revealing and demonstrating, proving how we never stand still in our quest to support customer ambitions and deliver practical solutions for the real operational challenges of today, and tomorrow.”
London calling
Those eager to experience the solution, and talk to experts about its unique capabilities, are invited to visit Kongsberg Discovery’s stand (D600) at Oceanology International, taking place 10-12 March at ExCel London.
The company, a global leader within ocean robotics and sensor technology, will also be using the occasion to launch further products, run live feeds from the Oslofjord CMI Protection Test Bed, hold workshops and presentations, and run live technology demonstrations on the dockside by the exhibition centre.
For further information please see https://www.kongsberg.com/discovery/news/events/oceanology-international/
18 Feb 26. Indra Group, a global company at the forefront of defence, aerospace, and advanced technologies in Europe, and ELT Group, an international champion in developing and applying innovative and proprietary technologies in the use of the electromagnetic spectrum and cyberspace, have signed a strategic framework agreement designed to enhance their industrial and technological cooperation in multi-domain defence. The agreement establishes a common framework for developing and fostering a collaboration in three key areas, namely the land and space domains and Uncrewed Aerial Vehicles (UAVs). The partnership will bring together two strategic players in the European defence ecosystem, thus leveraging their complementary capabilities and aligning their technological visions and operational maturity so as to drive the reinforcing of Europe’s critical capabilities, technological sovereignty and strategic autonomy in the face of the current-day challenges. On the one hand, Indra Group will contribute its capabilities as a benchmark integrator of next- generation defence programs, and its leadership of multi-domain systems, radar technology, space, electronic warfare, and cyberdefence. On the other, ELT Group will provide its best-in-class expertise in EMSO (Electromagnetic Spectrum Operations) advanced solutions and systems designed to ensure the control, protection and exploitation of the electromagnetic spectrum in military operations, to gain information superiority and operational edges. Indra Group Executive Chairman Ángel Escribano declared that “this agreement with Elt Group will consolidate Indra’s desire to drive a more sovereign, interoperable, and multi-domain form of European defence. By bringing together our complementary capabilities in radar, space, cybersecurity, and electromagnetic spectrum operations, we’re taking a decisive step towards deploying high-value European solutions to protect our citizens and reinforce the continent’s strategic autonomy in the land, space and unmanned system domains”.
According to José Vicente de los Mozos, Indra Group’s CEO, the agreement “opens instant opportunities to submit integrated and competitive proposals to European programs, combining Indra’s experience and ELT’s expertise in advanced electronic warfare solutions, signals intelligence, spectrum monitoring, and the protection of critical communications in multi-domain environments. Mastering the electromagnetic spectrum is essential, because much of modern military technology currently depends on it. By teaming up with ELT we’ll be able to bolster our joint capabilities, move forward in a coordinated manner within the European framework, expand our portfolio in prioritized areas, and provide sovereign solutions to increase our customers’ resilience and operational superiority”.
Elt Group President and Ceo Enzo Benigni, declared that: “This agreement marks an important step forward in strengthening European industrial cooperation in the Defence sector. Indra Group and ELT have already actively collaborated in consortium programmes like the Eurofighter and share a common vision on the need to develop advanced technologies and integrated capabilities to address emerging multi-domain challenges. By combining our technological excellence, we are confident we can create value for our customers and contribute concretely to Europe’s security”
Domitilla Benigni, CEO and COO of ELT Group stated: “Distinctive capabilities such as those of Elt Group and Indra Group in sigint, EW and management of the electromagnetic spectrum are, at this historical moment, a strategic asset for Europe. The challenges we face, the technological strength outside Europe and Nato blocks push us towards valuable partnerships. This is a pillar of our strategic plan that we are pleased to share with Indra”.
By signing this agreement, Indra Group and ELT Group are taking a decisive step towards the consolidation of their strategic industrial cooperation, fostering a more robust defence ecosystem that’s capable of providing sovereign technological solutions with high added value to guarantee security and stability in an increasingly complex multi-domain global environment.
17 Feb 26. Global: Malware distribution raises security, data-theft risks to businesses via legitimate platforms. On 15 February, the cyber security company CTM360 reported that unnamed threat actors are exploiting legitimate infrastructure affiliated with the technology company Google to distribute two known malware variants (‘Lumma Stealer’ and ‘Ninja Browser’). The threat actors reportedly use Google forums to post technical discussions and trick users into clicking on malicious links, showcasing the continued abuse of legitimate services for malicious cyber activity. Upon infiltrating targeted systems, threat actors employ password-protected archives to ultimately deploy Lumma Stealer and Ninja Browser with the aim of monitoring user activity, exfiltrating sensitive data and executing additional commands, likely for financial profit. The execution files are and are inflated in size (with null bytes) and are distributed via shortened URLs to evade traditional security tools’ scanning thresholds and mask the true destinations, highlighting the actors’ sophistication. As a result, we assess that global entities will face increased security and data-theft risks, as threat actors have already targeted companies worldwide. (Source: Sibylline)
17 Feb 26. Myriota rolls out AssetHawk for global asset tracking beyond mobile coverage. Australian satellite IOT company Myriota has launched AssetHawk, a rugged, long-life asset tracker designed to deliver reliable global visibility well beyond the reach of traditional cellular networks. The new device is aimed at operators managing assets in remote and harsh environments, including mining, agriculture and heavy industry. Ready to deploy out of the box, AssetHawk can be installed in minutes and integrates with third-party visualisation and analytics platforms. AssetHawk’s compact, low-profile design supports flexible mounting including magnetic options making it suitable for rotating fleets and temporary assets. Built to withstand tough conditions, AssetHawk features an IP68-rated enclosure, allowing it to operate reliably despite dust, impact, extreme temperatures and even submersion. Using Myriota’s low-power satellite connectivity, the tracker supports scalable monitoring of trailers, containers, pallets, vehicles and unpowered assets across vast geographies. This enables operators to confirm delivery milestones, cut asset loss, improve utilisation and reduce operating costs as deployments grow. Myriota chief executive Ben Cade said many tracking initiatives falter once they move beyond pilot programs.
“Most tracking projects fail not in the lab, but at scale – when battery swaps, coverage gaps and complex integrations erode the business case,” he said. “AssetHawk is designed to flip that equation by combining global coverage, predictable multi-year battery life and straightforward integration in a single device.”
For long-term deployments, AssetHawk is engineered to minimise ongoing operational overheads. Its low-power design delivers up to 10 years of battery life using two standard AA batteries. Intelligent firmware automatically increases location update frequency when movement is detected, providing more detailed insights without compromising power efficiency. The device operates on a standards-based 3GPP Release 17 architecture and uses private data paths to protect against unauthorised access or interference, embedding security and data integrity into the platform. Developed using a TAA-compliant supply chain, AssetHawk is designed to meet the needs of government, defence and enterprise customers where resilience and trust are critical. Optional Bluetooth Low Energy capability will be available shortly, allowing the tracker to collect condition data, such as temperature and vibration from compatible sensors. AssetHawk is available now in key markets, including Australia, New Zealand, United States, Canada, Brazil and Mexico, with further international rollouts planned. Customers and partners can begin deployments using the AssetHawk QuickStart Kit, which includes mounting accessories and API integration guides. Over the past decade, Myriota has built an expanding satellite constellation, amassed a patent portfolio of more than 170 patents and raised over US$100 m (AU$141.2 m) in funding. The company provides satellite connectivity and hardware that underpin critical operations across agriculture, utilities, logistics, mining, environmental monitoring and defence, enabling assets to be tracked and monitored even in the most remote locations on Earth. (Source: Space Connect)
16 Feb 26. Ericsson (NASDAQ: ERIC), international defense company Leonardo, and the Italian Navy have conducted a maritime connectivity test using an Ericsson 5G Standalone system. The trial was successfully completed, enabling connectivity between naval units engaged in a day and night training scenario on the open sea. A completely self-contained end-to-end Ericsson 5G SA network – comprising Ericsson Ultra Compact Core and Ericsson Massive MIMO Radio Access Network products and solutions – was installed on board the Italian Navy’s amphibious landing ship San Giorgio, which served as the lead unit during a recent experimentation campaign. Ericsson 5G SA customer premises equipment (CPE) was installed on board a second unit of the Italian Navy – the Multi-Purpose Combat Ship Raimondo Montecuccoli. Leonardo and Ericsson collaborated in the EDF 5G COMPAD project and demonstrated its outcomes during the Italian Navy’s Operational Experimentation (OPEX) 2-25 in the Gulf of Taranto. Using Ericsson’s 5G Standalone connectivity and Leonardo’s NINE encryption solution, the trial enabled the secure, real-time exchange of classified and unclassified information between two naval units, including full situational awareness from the Combat Management System and video streams from 12 unmanned systems processed via the AI Brain platform. The OPEX validated the performance, security and resilience of 5G SA for on-board connected systems, while also showing how a unified 5G network can optimize spectrum usage compared to multiple standalone communication systems operating on unlicensed and potentially overlapping, bands with interference risks.
Patrick Johansson, Senior Vice President and Head of Ericsson Europe, Middle East and Africa, says: “The Italian Navy is seeking the best possible connectivity solutions for its related needs, and we are proud to work with them towards that goal. Italy’s central Mediterranean location, with an exclusive economic zone spanning more than 500,000 Sq Km of sea, means the Italian Navy plays a strategically important role in Europe.”
Freddie Södergren, Head of Mission Critical Networks, Ericsson, says: “This successful trial with Leonardo and the Italian Navy represents a significant milestone in our ongoing commitment to advancing defense capabilities through 5G technology. As an integral part of Ericsson’s defense portfolio, our 5G platform is designed to meet the rigorous demands of the sector. This collaboration not only demonstrates the versatility of dual-use 5G in critical operations, but also highlights how enhanced connectivity at sea can significantly strengthen naval communications and operational effectiveness.”
The same Italian Navy experimentation – officially called the Italian Navy open-sea Operational Experimentation (OPEX Task 2-25), within the framework of the Multi-Domain Operational Experimentation Committee – included several other ecosystem partners testing at sea capabilities. Ericsson also collaborated with the Italian Navy as part of 2024 NATO trials, when an end-to-end 5G SA network was installed in the Italian Naval base at Taranto. (Source: PR Newswire)
13 Feb 26. Cyber Update
Key points
- Targeted sectors face elevated security and disruption risks from increased, large-scale distributed denial-of-service (DDoS) attacks (see Sibylline Cyber Daily Analytical Update – 9 February 2026 and our technical analysis below).
- An unnamed UK-based construction firm faces increased security and data-theft risks via new Russia-linked botnet (‘Prometei’) activity (see Sibylline Cyber Daily Analytical Update – 10 February 2026 and our technical analysis below).
- The telecommunications sector in Singapore faces elevated security risks from a Chinese state-sponsored advanced persistent threat (APT) group (‘UNC3886’; see Sibylline Cyber Daily Analytical Update – 11 February 2026).
- Financial and cryptocurrency firms face long-term security and financial risks from an artificial intelligence (AI)-enabled North Korean state-sponsored cyber operation (see Sibylline Cyber Daily Analytical Update – 12 February 2026).
- Chinese state-sponsored actors will pose heightened security risks to US-based organisations via increased AI automation (see Sibylline Cyber Daily Analytical Update – 13 February 2026).
Technical analysis of weekly stories
The renowned Russia-linked botnet Prometei has targeted an unnamed UK-based construction firm in a cyber operation since at least January. It is possible that threat actors exploited default credentials to infiltrate the company’s remote desktop protocol (RDP) servers. Upon obtaining access, threat actors ran two commands (an elevated command prompt and PowerShell code) to download, decrypt and execute the main Prometei payload. Then, the malware added exceptions to the Windows firewall service and conducted initial system reconnaissance, in order to store itself stealthily within the company’s Windows server. According to the code, if the payload had not detected the first command, it would have performed a series of decoy actions before terminating, in a bid to remain obfuscated and evade sandbox detection mechanisms. Prometei subsequently established communication with command-and-control (C2) infrastructure and deployed additional malicious payloads. Although Prometei is typically used to mine cryptocurrency for financial profit, the payloads it used throughout this attack – including ‘Mimikatz’, for instance – demonstrate its interest and ability to control compromised systems remotely and to conduct data exfiltration. Furthermore, the malware changes configurations on its host server to ensure that no other threat actors can infiltrate compromised systems. Prometei also monitors failed login attempts to prevent any further compromises, highlighting the sophistication of its persistence and detection evasion capabilities.
The number of large-scale DDoS attacks increased by 40% in the fourth quarter (Q4) of 2025 compared to the third quarter (Q3) of 2025. DDoS attacks flood victims’ systems with large amounts of traffic – typically averaging between 7 and 29 terabytes per second (TBps) – with the aim of temporarily disrupting operations. According to US-based security company Cloudflare, the size of DDoS attacks in Q4 2025 also grew by over 700% compared to the largest attacks detected in late 2024, with some incidents exceeding rates of 200 m requests per second (RPS). One attack perpetrated by the ‘Aisuru/Kimwolf’ botnet reached an unprecedented 31.4 TBps, highlighting the scale of its potential impact. Reportedly, the number of DDoS attacks more than doubled in 2025, reaching a total of 47.1 m following a 236% increase between 2023 and 2025. In Q4 2025, Hong Kong became the second most targeted country, while the UK was the sixth. However, the largest increase was in DDoS attacks targeting the network layer, a 31% rise compared to Q3 2025 and 58% compared to 2024.
Non-exhaustive recommendations to mitigate these threats include:
- Monitor devices and networks for suspicious activity.
- Add available Indicators of Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware.
- Adopt behaviour-based endpoint detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
Our cyber word(s) of the week: Cryptocurrency miner
Definition: A type of software that uses computing power to verify transactions, subsequently adding new blocks to the blockchain in exchange for cryptocurrency tokens. It can be exploited by threat actors to garner illicit profit.
Example: ‘[…] UNC1069 tricked victims into downloading multiple malicious payloads onto their systems, including […] data miners to obtain cryptocurrency.’ (Source: Sibylline)
————————————————————————————————————————————————————————————————————————————————————————————————————————————-
Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.
We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.
Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.
—————————————————————————————————————————————————————————————————————————————————————————————————————————

