The Modern Cyber Threat Landscape: Emerging Risks for Today’s Combat Aircraft

B-2 Bomber with callout text of what is vulnerable.
ChatGPT-Generated Image

In the last 20 years, aerospace systems have undergone a sweeping and irreversible transformation. Software has replaced mechanical linkages, commercial hardware has replaced bespoke government unique systems, cloud connected development pipelines have replaced isolated labs, and wireless interfaces have proliferated across every domain of operation. While these changes have unlocked unprecedented capability, they also have ushered in an era of vastly expanded cyber risk—one in which adversaries have more access, tools, and opportunity to threaten mission success. From the earliest design files to deployed aircraft in contested environments, today’s threat landscape spans an ecosystem far larger than the cockpit. Accordingly, understanding this landscape—and the systemic vulnerabilities within it—is now foundational to maintaining aircraft security and ensuring operational dominance.

This article explores the modern threat environment across six critical domains: the development environment, supply chain, deployed aircraft, test and training facilities, international partnerships, and the emergence of artificial intelligence (AI)/machine learning (ML) (see Figure 1). Also highlighted is the technological and strategic response currently underway across government, industry, and the defense industrial base.

Six Critical Domains of the Threat Environment.Figure 1. Six Critical Domains of the Threat Environment.

A Background of Rapid Change

Just two decades ago, military aircraft systems relied heavily on government off the shelf (GOTS) components and niche, specialized hardware. Their architectures were substantially different from the commercial and Internet of Things (IoT) ecosystems familiar today. Since then, however, the sector has seen a dramatic pivot toward COTS hardware and software, enabled by global innovation cycles and driven by the need for rapid capability deployment (as illustrated in Figure 2).

The Shift to COTS.Figure 2. The Shift to COTS (Source: Adobe Firefly-Generated Image).

This transformation has brought extraordinary benefits, including lower cost, more features, faster development, and higher performance. Unfortunately, it also has introduced increased risks, such as:

  • Global technology exposure
  • Increased wireless connectivity
  • Full connectivity across platforms
  • Massive software dependency
  • Higher integration with enterprise architectures
  • “Speed to fleet” pressures that can compress security considerations.

The ultimate result has been the fielding of modern combat aircraft that are more advanced and more capable—but also more exposed to cyber attack—than any generation before them.

The Development Environment: The First Battleground

The beginning of the aircraft life cycle—design, development, testing, and integration—is also one of its greatest points of vulnerability. Modern engineering occurs in highly connected networks, housing everything from requirements to manufacturing data. These environments include thousands of computers, build systems, design repositories, simulation tools, and, increasingly, cloud-based pipelines.

Once an adversary breaches that digital perimeter, the consequences are profound. Consequences can range from the theft of sensitive intellectual property to subtle, undetected manipulation of design artifacts. Traditional perimeter defense models make it difficult to contain intruders once inside, which often allows them to move laterally with relative ease.

Another concern is the rise of insider threats, whether malicious or accidental. As systems grow more complex and more interconnected, the number of individuals with deep access increases. A single insider—whether coerced, careless, or compromised—can achieve what once required a nation-state adversary. In short, the development environment is no longer just a workplace; it’s a battlespace.

The Supply Chain: A New Era of Global Exposure

As aerospace systems embrace commercial components—chips, boards, modules, open-source software—the supply chain becomes a parallel arena of risk. Commercial hardware and software each bring unique vulnerabilities. Open-source code, for example, can be easier for adversaries to inspect or modify, though it may also be easier to audit if organizations are willing to invest in thorough review. Closed-source software hides implementation details but offers no guarantee that vulnerabilities, backdoors, or unexpected behaviors aren’t embedded deep inside. Figure 3 highlights a variety of aspects of the evolving supply chain threat.

The Evolving Supply Chain Threat.Figure 3. The Evolving Supply Chain Threat (Source: Adobe Firefly-Generated Image).

Hardware introduces even greater complexity. Chips may be designed in one country, manufactured in another, tested in a third, and assembled into systems by still other vendors. Offshore fabrication and opaque supply chains are fertile ground for adversaries who aim to embed latent malicious functionality at the silicon level. Insider threat scenarios again loom large. The overarching lesson is simple: if an aircraft relies on a component, that component’s entire global production pipeline becomes part of the aircraft’s attack surface.

Deployed Aircraft: A Growing Attack Surface in the Field

Once fielded, aircraft face an array of cyber risks that grow more diverse every year. Because modern military systems incorporate so many commercial technologies, many commercial attack techniques are suddenly relevant to defense platforms. This situation thus lowers the barrier to entry for adversaries—no longer limited to state-sponsored actors with custom tool chains but now extending to criminals; hacktivists; and small, independent threat groups.

Key threat vectors include:

  • Over-the-air (OTA) attacks, exploiting wireless links
  • Tactical communications exploitation
  • Payloads delivered via cyber tools as offensive cyber capabilities grow
  • Physical interfaces, such as USB ports or ethernet jacks
  • Software loading processes that rely on removable media
  • Accidental misuse (e.g., treating USB ports as “charging stations”).

Reverse-engineering risks also escalate when an aircraft or component is lost, captured, or otherwise compromised. Once an adversary can inspect an asset directly, that adversary can extract immense intelligence about system behavior, firmware, and vulnerabilities. Hybrid attacks—pairing cyber techniques with inexpensive physical assets such as small drones—illustrate how the battlefield is evolving. Cyber is thus no longer a standalone domain; it’s a force multiplier for every other attack vector.

Test and Training Facilities: New Targets in Plain Sight

Historically, test ranges and training environments were viewed as relatively secure spaces. Today, adversaries actively monitor them—and, in some cases, physically encroach on them. Several specific concerns have emerged:

  • Adversaries purchasing or controlling land near test or training ranges
  • Commercial infrastructure (e.g., cell towers) that provide range visibility
  • Attacks on insecure remote equipment (e.g. remote range units on public property far from range personnel)
  • Large geographical scales that can make comprehensive monitoring difficult.

In addition, security is often deferred to operational systems, which leaves test/training environments more exposed—and an enticing target for hostile surveillance or cyber disruption.

International Partners: Complex Trust in a Globalized Defense Ecosystem

Whether we like it (or want to admit it) or not, aircraft often involve multinational development, production, and deployment. While this cooperation is often operationally essential, it also introduces significant cyber security considerations. Not all partners have equal cyber maturity, protections, or trust levels. Political dynamics can shift rapidly, and allies may, intentionally or accidentally, share sensitive information with adversarial nations. In some cases, cyber security steps are shortened or bypassed to deliver platforms quickly, leaving openings for exploitation. Once documentation or hardware leaves a controlled environment, the risk of reverse engineering rises sharply. Insider threats are again a factor—not just within companies, but within partner governments, subcontractors, and fielded units. The international defense ecosystem is powerful, but only when secured.

AI/ML and LLM’s: A Double Edged Sword

Clearly, no domain is evolving faster than the AI domain. AI, ML, and large language models (LLM’s) are radically transforming engineering workflows—automating artifact generation, accelerating coding, assisting with design, and enhancing test activities. These tools promise faster development cycles and improved performance.

But the threats mirror those faced in COTS software, namely:

  • Compromised training data can compromise models
  • Malicious training data can embed vulnerabilities or biased behaviors
  • LLM’s may generate insecure code or flawed architectures
  • Models deployed on aircraft or support systems may be susceptible to adversarial attacks.

AI/ML is thus a dual-use technology—simultaneously a powerful enabler and a potential point of infiltration, with training data integrity becoming as critical as hardware assurance or software signing. AI/ML and LLM’s bring powerful capabilities but carry with them real risks (as illustrated in Figure 4).

AI/ML-Associated Concerns.Figure 4. AI/ML-Associated Concerns (Source: Adobe Firefly-Generated Image).

Real-World Proof: Examples Under Seal

Lest anyone think that these cyber risks are all theoretical, many verifiable real-world examples exist. For example, the author is personally familiar with a program in which a COTS processor card was used for a wide range of critical applications and was subsequently found to be riddled with malware, including “phone-home” capabilities that were extremely well hidden.

Further, we have clear proof of weapons that have been rendered ineffective due to compromised technology. Although we are not at liberty to discuss the details of such compromised weapons in the publicly releasable format of this article, these examples (and many others) soberly underscore the fact that the cyber threat is not theoretical—adversaries are active, capable, and constantly probing.

Mitigation Strategies: Building a Stronger Security Future

Despite the sweeping scale of today’s cyber risks, substantial progress is being made across the aerospace ecosystem.

Key advancements include:

  • Widespread adoption of encryption, including signed software/firmware and protected data storage
  • Implementation of zero trust architectures and deeper defense-in-depth
  • Expansion of insider threat programs
  • Increased security maturity of COTS devices
  • Centralized repositories for hardened, secure container images, such as Iron Bank
  • Consortium-driven secure open standards, such as OMS and SOSA
  • Renewed focus on air-gapped development environments
  • Stronger roots of trust and on shore fabrication efforts
  • Improved protection against emanations and side-channel leakage.

Other mitigation efforts are also accelerating, such as:

  • Greater emphasis on CWE/CVE hygiene
  • Expanded DevSecOps practices
  • Routine patching of software and firmware
  • Advanced packaging and supply chain protections, such as device DNA and fingerprinting
  • Closed AI/ML development using trusted data sources
  • The use of AI/ML to detect or mitigate cyber attacks
  • Improved security of test and training ranges, including the use of live/virtual hybrid training environments not visible from range perimeters
  • Enhanced protections and dissimilarity strategies for foreign military sales.

In short, the community is mobilizing, and solutions are emerging faster each year.

Conclusion: Finding Security in an Evolving Battlespace

Clearly, across all domains—development, supply chain, deployed systems, training ranges, global partnerships, and AI—the threat landscape has expanded exponentially. Thus, hoping we can avoid any manifestation of “the peacetime illusion of availability” is no longer viable in an era where adversaries are persistent, patient, and increasingly sophisticated.

But there is good news. The industry, government, and defense ecosystem are not standing still. More secure architectures, deeper inspection methods, improved standards, enhanced testing, and stronger supply-chain oversight are combining to move us in the right direction. Innovation in cyber security is rising at the same pace as innovation in aircraft design. And cyber security in aerospace is no longer a bolt-on discipline; it’s integral to mission assurance.

In the end, there is no free lunch—it takes effort to maintain security in the modern evolving threat landscape. Going forward, the key will be acknowledging the threat, embracing the responsibility, and continuing to innovate faster than our adversaries. And if we can do that, we can preserve not just aircraft, but the capability, trust, and strategic advantage of our entire defense enterprise.

About the Author

Mr. James Marek currently works as an Enterprise Cybersecurity Architect and Senior Technical Fellow, Cybersecurity for Collins Aerospace. With 39 years of experience in the design, development, and deployment of safety and security and critical systems, he’s served in various positions, focusing on high assurance, low power, embedded computing, networking, and graphics systems for safe and secure avionics, communications, and navigation products in aerospace and defense applications. Mr. Marek has supported international NATO studies and has architected and designed a variety of products and systems that have been certified and accredited to the highest levels of assurance (FAA/EASE, CC EAL6+, NSA Type 1/HA, NCDSMO RTB, RMF, ATEA, GPS SPO, TEMPEST, and DCID 6/3 PL5). In addition, he holds 28 patents and a bachelor’s and master’s degree in computer engineering from Iowa State University.

EDITOR’S NOTE: Parts of this article were taken from the author’s presentation at the Threat Weapons & Effects Conference on 12–14 May 2026 at Eglin AFB, FL.

By:  James Marek

Read Time:  8 minutes

Table of Contents

Aircraft Survivability Journal

Archives

Scroll to Top