• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • SPECTRA banner
  • Curtiss-Wright banner

BATTLESPACE Updates

   +44 (0)77689 54766
   

  • Home
  • Features
  • News Updates
  • Defence Engage
  • Company Directory
  • About
  • Contact

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

March 6, 2026 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

—————————————————————————————————————–

05 Mar 26. Middle East, North Africa and Turkey region: Iran-linked cyber activity will raise security risks from compromised IP cameras, technical equipment. On 4 March, cyber security company Check Point reported that the ongoing Israel-US-Iran war has precipitated an increase in Iran-led cyber attacks on internet protocol (IP) cameras across Middle Eastern countries since it began on 28 February. Reportedly, Iran-linked threat actors previously compromised cameras during the Israel-Iran war in June 2025 for operational support, battle damage assessment (BDA) and (in some cases) to tailor missile launches. At the time of writing, the recent uptick in cyber attacks has targeted cameras in Bahrain, Cyprus, Kuwait, Lebanon, Qatar and the UAE, likely to inform ongoing retaliatory efforts. Data from January and early February also suggests that Iran consistently increases such cyber activity during geopolitical escalations, highlighting the complementary nature of its cyber strategy. Consequently, we assess that cameras and possibly other technical equipment across the Middle East, North Africa and Turkey region will face heightened security risks in the short term, as Iran will likely seek to use cyber intelligence to enhance kinetic action. (Source: Sibylline)

 

02 Mar 26. Thales sets a world first in quantum-safe security for 5G networks.

  • Thales has successfully demonstrated a world-first innovation that prepares 5G networks for the age of quantum computing, marking a major milestone for the global telecommunications industry.
  • The collaboration with a top tier mobile operator, showed that existing 5G SIM / eSIM cards already deployed in the field can be securely upgraded to quantum-safe protection, without disrupting service or impacting the customer experience.
  • This Post-Quantum Cryptographic (PQC) breakthrough proves that mobile networks can evolve their security through crypto agility to address quantum cyber threats.

Quantum computing has the potential to break today’s encryption methods in the future, putting mobile communications, personal data and critical infrastructure at risk. For telecom operators, this is not a distant theoretical issue: 5G networks underpin everything from smartphones and connected vehicles to emergency services, industry and national infrastructure.

The challenge is scale. Replacing ms of devices every time security standards evolve is neither practical nor sustainable. The industry needs a new approach. With this demonstration, Thales shows that security can be upgraded remotely and instantly, directly on SIM and eSIM cards already in use. This capability, known as crypto agility, allows operators to adapt their security protections as threats and standards evolve, without waiting for new product generations.

Indeed, this innovation underlines how Thales can strengthen the security of SIM and eSIM already deployed, by remotely downloading post-quantum cryptographic algorithms directly onto the card. This happens seamlessly in the background, preserving existing data and services while instantly enhancing security. With Thales’ unique crypto-agile approach, operators can remotely update the device protection without replacing cards, changing devices or interrupting connectivity.

It means 5G networks can remain secure, resilient and trusted over time, even as quantum computing becomes a reality. This successful demonstration is the first of its kind and sends a strong signal to the market:

  • Quantum-safe security can be introduced over the air without changing devices or interrupting service.
  • Mobile networks can evolve securely over time, even as threats change.
  • Telecom operators can protect long-term investments while preparing for the next era of quantum computing.

It also builds on Thales’ strong leadership in post-quantum cryptography, backed by dedicated research teams across the Group. Thales not only integrates future-proof security technologies, but it also actively develops them, with its own quantum-resistant methods submitted to international standardization efforts such as those led by the U.S. National Institute of Standards and Technology (NIST).

This successful test shows that quantum-safe security is no longer a future concept, it’s something networks can start preparing for today,” said Eva Rudin, VP Mobile Connectivity solutions at Thales. “By enabling remote upgrades, we help operators protect their customers and critical services without disruption. We will continue working together to help bring quantum-ready security to commercial and private 5G networks worldwide, ensuring trust, resilience and continuity in a rapidly changing digital world.”

 

04 Mar 26. Global: Widespread AI exploitation will raise security risks from various cyber threat actors. On 3 March, the cyber security company Cloudflare reported that a wide range of threat actors are increasingly exploiting artificial intelligence (AI) to facilitate cyber intrusions. The report claimed that AI and large language models (LLMs) are being leveraged at scale to automate the early stages of the cyber attack chain, thus lowering the technical barrier of entry and compensating for limited skillsets. In particular, threat actors are using AI-generated ‘deepfakes’ (fake images, video or audio) to impersonate high-profile individuals as well as job applicants. For instance, in February, a North Korean state-sponsored group (‘UNC1069’) used a deepfake to impersonate a company’s CEO to subsequently install data miners for financial profit. Although human-led social engineering techniques continue to be successful, the company’s researchers stated that AI-enabled cyber capabilities – including but not limited to phishing – can also intensify the impact of an attack. Consequently, we assess that this trend will raise the long-term security risks to global entities amid the rapid development of the AI ecosystem. (Source: Sibylline)

 

27 Feb 26. Cyber Update

Key points

  • Sophisticated monitoring capabilities underscore long-term surveillance risks from a known spyware variant (‘Predator’; see Sibylline Cyber Daily Analytical Update – 23 February 2026).
  • The distribution of a stealthy remote access trojan (RAT; ‘Pulsar RAT’) will heighten security risks for global users of repository platform NPM (see Sibylline Cyber Daily Analytical Update – 24 February 2026 and our technical analysis below).
  • Healthcare organisations in the US and Middle East, North Africa and Turkey region face elevated ransomware risks from North Korean state-sponsored groups (see Sibylline Cyber Daily Analytical Update – 25 February 2026).
  • A cyber campaign perpetrated by a suspected Chinese state-sponsored group (‘UNC2814’) highlights long-term espionage risks for telecommunications and government firms worldwide (see Sibylline Cyber Daily Analytical Update – 26 February 2026 and our technical analysis below).
  • The healthcare and education sectors face heightened security risks from North Korean state-sponsored groups via the distribution of a new malware variant.

Technical analysis of weekly stories

Unnamed threat actors are abusing legitimate code repository platform NPM to distribute a known RAT (Pulsar RAT). Reportedly, threat actors use typo-squatting techniques to name a malicious file after a legitimate software package, with the exception of a few characters. This aims to trick victims into downloading the malicious file, which is typically advertised on NPM’s platform for distribution. The file then installs a malware loader inflated in size through the inclusion of a large volume of void commands, thereby complicating analysis efforts and enhancing obfuscation. Subsequently, the file reassembles a PowerShell script that enumerates any anti-virus products present on compromised machines, before downloading a portable networks graphics (.PNG) image. Subsequently, the image employs steganography techniques to extract additional malicious payloads through a multi-phase process that reads binary data concealed within the image to appear legitimate, highlighting the cyber attack’s sophistication and persistent stealth. Threat actors also adopt process hollowing to execute and store the final payload (Pulsar RAT) within a legitimate Windows process, while continuing to evade detection. Pulsar RAT facilitates remote control, data exfiltration and the monitoring of compromised systems, likely for espionage purposes.

A suspected Chinese state-sponsored group (UNC2814) targeted telecommunications and government organisations in a long-term cyber espionage operation since at least 2023. The group possibly exploited software vulnerabilities in public-facing web severs and/or network edge devices to infiltrate targeted systems. UNC2814 reportedly moved laterally through compromised systems via the secure shell (SSH) protocol and subsequently leveraged living-off-the-land (LotL) techniques to perform reconnaissance, escalate privileges and deploy a backdoor (‘GRIDTIDE’). The group also deployed a virtual private network (VPN) service to establish and maintain a connection to an external IP address. GRIDTIDE then established communication with command-and-control (C2) infrastructure by abusing the application programming interface (API) associated with the spreadsheet service Google Sheets. More specifically, upon execution, the backdoor uses the API to connect to a spreadsheet, which it then sanitises by deleting the first 200 rows to avoid any activity interference. GRIDTIDE uses specific spreadsheet cells for different functions with the aim of maintaining C2 communication and exfiltrating data, highlighting its sophistication. It also sends status requests every few seconds until it reaches 120 instances before reducing the request frequency to enhance obfuscation.

Non-exhaustive recommendations to mitigate these threats include:

  • Monitor devices and networks for suspicious activity.
  • Add available Indicators of Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware.
  • Adopt behaviour-based endpoint detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.

Our cyber word of the week: Typo-squatting

Definition: A technique where threat actors register common misspellings and/or variations of popular domain names to trick users into clicking on malicious attachments.

Example: ‘Threat actors […] reportedly use typo-squatting techniques to emulate legitimate packages and trick victims into downloading the file onto their systems.’ (Source: Sibylline)

——————————————————————————————————————-

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

—————————————————————————————————————–

Primary Sidebar

Advertisers

  • Pythia
  • Teledyne
  • Exensor
  • Visit the Oxley website
  • Blighter
  • SPECTRA
  • Britbots logo
  • Faun Trackway
  • Systematic
  • CISION logo
  • ProTEK logo
  • ProTEK logo
  • ssafa logo
  • IEE
  • EXFOR logo
  • sibylline logo
  • Team Thunder logo
  • Comtech logo
  • GoExporting logo
  • ECHODYNE logo
  • Supercat logo
  • Galvion logo
  • Leonardo DRS logo
  • MTC logo
  • IDC logo
  • DSEI logo
  • DVD2024 logo
  • SDSC logo
  • TELEDYNE FLIR logo
  • VeteranUK logo
  • Matrix Space logo
  • ST Engineering logo
  • EWS logo
  • sentinel photonics logo
  • capua logo
  • Curtiss-Wright logo
  • Brave1 logo
  • Drone Evolution logo
  • AEI Systems logo
  • EOS logo
  • NMSUK logo
  • Openworks logo
  • Sandown Park logo
Hilux UKDSE AARTOS ST Engineering Future Artillery

Contact Us

BATTLESPACE Publications
41 St Georges Drive
London SW1V 4DG

+44 (0)77689 54766

BATTLESPACE Technologies

An international defence electronics news service providing our readers with up to date developments in the defence electronics industry.

Recent News

  • Protek Selected By Dutch Armed Forces

    May 2, 2026
    Read more
  • PARLIAMENTARY QUESTIONS

    May 1, 2026
    Read more
  • MANAGEMENT ON THE MOVE

    May 1, 2026
    Read more

Copyright BATTLESPACE Publications © 2002–2026.

This website uses cookies to improve your experience. If you continue to use the website, we'll assume you're ok with this.   Read More  Accept
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT