Advancing UK Aerospace, Defence, Security & Space Solutions Worldwide
  • Home
  • /
  • Security
  • /
  • NCSC warns mistaking AI vulnerability could lead to large-scale breaches

Security

NCSC warns mistaking AI vulnerability could lead to large-scale breaches

The National Cyber Security Centre (NCSC) – a part of GCHQ – has shared critical insights cautioning cyber security professionals against comparing prompt injection and more classical application vulnerabilities classed as SQL injection.

Image by frank60 / copyright Shutterstock

A new blog advises that, contrary to first impressions, prompt injection attacks against generative artificial intelligence applications may never be totally mitigated in the way SQL injection attacks can be.

Unlike SQL mitigation techniques, which hinge on enforcing a clear separation between data and instructions, prompt injection exploits the inability of large language models (LLMs) to distinguish between the two.

Advertisement
Security & Policing Rectangle

Without action addressing this misconception, the NCSC warns, websites risk falling victim to data breaches exceeding those seen from SQL injection attacks in the 2010s, impacting UK businesses and citizens into the next decade.

Backing proactive adoption of cyber risk management standards, the NCSC challenges claims that prompt injections can be ‘stopped’.

Advertisement
ODU RT

Instead, it suggests efforts should turn to reducing the risk and impact of prompt injection and driving up resilience across AI supply chains.

As AI technologies become embedded in more UK business operations, the NCSC calls on AI system designers, builders and operators to take control of manageable variables, acknowledging that LLM systems are “inherently confusable” and their risks managed in different ways.

Advertisement
ECS leaderboard banner
Respect the Range access rules strengthen UK Defence

Defence Security

Respect the Range access rules strengthen UK Defence

5 March 2026

The Ministry of Defence (MoD) is reminding the public to follow safe access rules when visiting military training areas, to keep everyone safe and avoid disrupting training.

Cambridge Pixel set to introduce HPx-700

Aerospace Defence Security

Cambridge Pixel set to introduce HPx-700

4 March 2026

Cambridge Pixel has revealed that it will be introducing its new HPx-700, an ARM-based embedded Radar Input & Signal Processor, with the advanced radar system solution becoming available from next month.

Kahootz expands into Japan to enhance cybersecurity

Security Events

Kahootz expands into Japan to enhance cybersecurity

4 March 2026

As the UK and Japan draw closer as partners to strengthen collective security, Kahootz is expanding its presence into Japan to support UK-Japan collaboration and to provide the necessary software to protect against malign actors looking to attack a partner nation.

Viasat and Galaxy 1 to enhance Velaris

Aerospace Security Space

Viasat and Galaxy 1 to enhance Velaris

3 March 2026

Galaxy 1 Communications is working with Viasat to enhance delivery of Velaris, Viasat’s dedicated satellite communications service for Uncrewed Aerial Vehicles (UAVs) and Advanced Air Mobility (AAM) aircraft.

Advertisement
PTC rectangle
Cyacomb introduces Similarity Matching

Security

Cyacomb introduces Similarity Matching

3 March 2026

Edinburgh based digital triage experts, Cyacomb, today announced the availability of a new Similarity Matching capability within its Examiner Plus platform, enabling law enforcement to identify Child Sexual Abuse Material (CSAM) on mobile devices in minutes, even when images have been shared via messaging applications and altered from their ...

Atos UK&I launches Sovereign MXDR

Security

Atos UK&I launches Sovereign MXDR

2 March 2026

Atos, a specialist in AI-powered digital transformation, today launched a Sovereign Managed eXtended Detection and Response (MXDR) service specifically designed for UK government, critical infrastructure, financial services and other UK organisations requiring stringent data sovereignty and regulatory compliance.

Advertisement
ODU RT
Advertisement
ECS leaderboard banner