Cybairsecurity
Intelligence Brief

Thinking out loud about aviation security.

Technical depth for the people who build, certify, and operate safety-critical aircraft systems.

DO-326A / LLM

Why DO-326A compliance is broken — and how LLMs can fix it

The current state of DO-326A compliance is a human-labour crisis disguised as a regulatory problem. We examine what is broken, why it has persisted, and what a language-model-native approach looks like in practice.

Coming soon12 min read
Threat Intelligence

The hidden attack surface: ARINC 429 and AFDX vulnerabilities nobody is tracking

A survey of publicly undocumented vulnerability classes in the two most widely deployed avionics data bus standards — and why the absence of CVE entries does not mean the absence of risk.

Coming soon18 min read
Architecture

Air-gapped by design: why aviation CVE intelligence must stay on-premise

Cloud-based threat intelligence has transformed enterprise security. It is the wrong model for aviation. This post makes the architectural case for why air-gap compatibility is a design constraint, not a feature.

Coming soon9 min read