Advancing UK Aerospace, Defence, Security & Space Solutions Worldwide
  • Home
  • /
  • Security
  • /
  • NCSC warns mistaking AI vulnerability could lead to large-scale breaches

Security

NCSC warns mistaking AI vulnerability could lead to large-scale breaches

The National Cyber Security Centre (NCSC) – a part of GCHQ – has shared critical insights cautioning cyber security professionals against comparing prompt injection and more classical application vulnerabilities classed as SQL injection.

Image by frank60 / copyright Shutterstock

A new blog advises that, contrary to first impressions, prompt injection attacks against generative artificial intelligence applications may never be totally mitigated in the way SQL injection attacks can be.

Unlike SQL mitigation techniques, which hinge on enforcing a clear separation between data and instructions, prompt injection exploits the inability of large language models (LLMs) to distinguish between the two.

Advertisement
ODU RT

Without action addressing this misconception, the NCSC warns, websites risk falling victim to data breaches exceeding those seen from SQL injection attacks in the 2010s, impacting UK businesses and citizens into the next decade.

Backing proactive adoption of cyber risk management standards, the NCSC challenges claims that prompt injections can be ‘stopped’.

Advertisement
Security & Policing Rectangle

Instead, it suggests efforts should turn to reducing the risk and impact of prompt injection and driving up resilience across AI supply chains.

As AI technologies become embedded in more UK business operations, the NCSC calls on AI system designers, builders and operators to take control of manageable variables, acknowledging that LLM systems are “inherently confusable” and their risks managed in different ways.

Advertisement
Babcock LB Babcock LB
Smiths Detection delivers automated IRBS between South Korea and US

Aerospace Security

Smiths Detection delivers automated IRBS between South Korea and US

21 January 2026

Smiths Detection has enabled the launch of a fully automated International Remote Baggage Screening System (IRBS), setting a new global standard for cross-border aviation security and passenger processing between South Korea and the United States.

Amentum and Rolls-Royce SMR partner on small modular reactors

Security

Amentum and Rolls-Royce SMR partner on small modular reactors

20 January 2026

Amentum has been selected as the programme delivery partner for the first deployments of the Rolls-Royce Small Modular Reactor (SMR) in the UK and Czech Republic.

NCSC issues hacktivist warning

Security

NCSC issues hacktivist warning

20 January 2026

The National Cyber Security Centre (NCSC) – a part of GCHQ – has issued an alert highlighting the persistent targeting of UK organisations by Russian state-aligned hacktivist groups aiming to disrupt networks.

GeoCue partners with Coptrz to expand TrueView LiDAR in UK drone market

Aerospace Defence Security

GeoCue partners with Coptrz to expand TrueView LiDAR in UK drone market

20 January 2026

UK drone specialists Coptrz have joined forces with GeoCue to offer the complete TrueView LiDAR product range, from entry-level to engineering-grade solutions.

Advertisement
ODU RT
JFD Global to collaborate with ST Engineering Marine in Singapore

Defence Security

JFD Global to collaborate with ST Engineering Marine in Singapore

19 January 2026

James Fisher Defence (JFD Global) has signed a Memorandum of Understanding (MoU) with ST Engineering Marine to explore new opportunities for collaboration in Singapore and beyond.

Serco named Britain’s Most Admired Company in its sector

Security

Serco named Britain’s Most Admired Company in its sector

19 January 2026

Serco has secuured the top prize in the Support Services (People & Places) category in the Britain’s Most Admired Companies study, which is the UK’s longest-running independent study of corporate reputation.

Advertisement
Security & Policing Rectangle
Advertisement
Babcock LB Babcock LB