• All News
  • |
  • World Travel
    • Africa
    • Asia
    • Europe
    • North America
  • |
  • Educational Articles
    • Art & Culture
    • Books & Literature
    • History & Politics
    • Lifestyle & Relationships
    • Professional Development
    • Science & Nature
  • |
  • About
    • About Us
    • Our Mission
    • Editorial Standards
    • Corrections Policy
    • Licensing & Redistribution
    • Image Use Policy
  • Help
  • Contact
Friday, June 12, 2026
Login
THX News | Global News, Travel & Education.
  • USA
    • Business and Commerce
    • Immigration & Border Security
    • International
      • Africa
      • Asia
      • Europe
      • Middle East
    • Law & Order
    • Local Government
      • Arizona
        • Phoenix
        • Tucson
      • California
        • San José
      • Oregon
        • Happy Valley
        • Hillsboro
        • Josephine County
        • Portland
        • Salem
        • Washington County
      • Virginia
        • Loudoun
    • Medicine & Health
    • Military
    • Space & Exploration
    • Technology
  • Canada
    • Community
    • Culture
    • Healthcare
    • Housing & Home Building
    • International
    • Military
    • Obituaries
    • Politics
    • Technology & Innovation
  • United Kingdom
    • Economy and Economics
      • Business
      • Jobs & Employment
      • Money and Taxes
    • Energy
    • Environment
    • Medical
    • International
    • Law and Order
      • Immigration
    • Military
    • Science & Technology
      • Space and Exploration
      • Technology
      • Transport
    • Society & Culture
      • Culture
      • Education
      • Housing & Land
  • European Union
  • Africa
    • Angola
    • Democratic Republic of the Congo
    • Egypt
    • Guinea
    • Kenya
    • Nigeria
    • Somalia
    • South Africa
  • Middle East
No Result
View All Result
THX News | Global News, Travel & Education.
  • USA
    • Business and Commerce
    • Immigration & Border Security
    • International
      • Africa
      • Asia
      • Europe
      • Middle East
    • Law & Order
    • Local Government
      • Arizona
        • Phoenix
        • Tucson
      • California
        • San José
      • Oregon
        • Happy Valley
        • Hillsboro
        • Josephine County
        • Portland
        • Salem
        • Washington County
      • Virginia
        • Loudoun
    • Medicine & Health
    • Military
    • Space & Exploration
    • Technology
  • Canada
    • Community
    • Culture
    • Healthcare
    • Housing & Home Building
    • International
    • Military
    • Obituaries
    • Politics
    • Technology & Innovation
  • United Kingdom
    • Economy and Economics
      • Business
      • Jobs & Employment
      • Money and Taxes
    • Energy
    • Environment
    • Medical
    • International
    • Law and Order
      • Immigration
    • Military
    • Science & Technology
      • Space and Exploration
      • Technology
      • Transport
    • Society & Culture
      • Culture
      • Education
      • Housing & Land
  • European Union
  • Africa
    • Angola
    • Democratic Republic of the Congo
    • Egypt
    • Guinea
    • Kenya
    • Nigeria
    • Somalia
    • South Africa
  • Middle East
THX News | Global News, Travel & Education.
No Result
View All Result
Home News Europe United Kingdom Military Cyber Security

Government Cyber Pilot Finds 407 Vulnerabilities

GC3, NCSC and DSIT tested frontier AI models on government code to identify vulnerabilities and improve public sector cyber resilience.

THX News by THX News
3 hours ago
in Cyber Security
Reading Time: 6 mins read
A A
Computer Code. Photo by One Idea.

Computer Code. Photo by One Idea.

Table of Contents

Toggle
  • Frontier AI tested in government cyber defence
    • How the pilot scanned public code
  • AI approaches used by participating teams
    • Pilot Method Indicators
  • Findings from the government cyber pilot
    • Pilot Findings Summary
  • Critical vulnerability example
    • Lessons from using AI in cyber defence
  • Next phase of the GC3 pilot

The Department for Science, Innovation and Technology and the National Cyber Security Centre published results from a Government Cyber Coordination Centre pilot on 12 June 2026, after frontier AI models helped identify 407 cyber findings across nine government organisations.

The work was carried out through weekly, in-person hackathons led by the Government Cyber Coordination Centre, known as GC3. Teams scanned public government code repositories with support from specialists at the UK AI Security Institute and the National Cyber Security Centre.

The pilot tested whether frontier AI could help find and mitigate previously unidentified vulnerabilities before they could be exploited. It also examined how model performance in controlled evaluations translates into applied cyber defence across real public sector environments.

 

Frontier AI tested in government cyber defence

The pilot was linked to the Government Cyber Action Plan, which aims to improve cyber resilience across the UK public sector. GC3 explored how emerging AI systems could be used safely as part of defensive cyber work across government.

The government said frontier models have developed quickly in cyber-related tasks, but synthetic benchmarks can give only a partial view of real-world performance. The pilot therefore focused on operational testing against public code repositories rather than relying only on laboratory-style evaluation.

  • Applied testing: teams used frontier AI in practical defensive workflows rather than standalone benchmark tasks.
  • Human oversight: findings were checked by specialists before escalation or remediation decisions were made.
  • Public code focus: repositories already published in the open could be reviewed quickly with limited additional sharing checks.

 

How the pilot scanned public code

The hackathons gave participating teams access to frontier models and allowed them to develop their own tools and workflows. Instead of mandating one approach, GC3 observed what worked each week and encouraged teams to build on the most effective methods.

The pilot used public government repositories because UK Government policy encourages new source code to be open by default, with specific and justified exceptions. The source material said openness can create visibility that attackers may also use, while also reducing duplication and supporting cleaner code maintenance.

 

AI approaches used by participating teams

Teams tested a range of approaches to determine how frontier AI could support vulnerability discovery. Some combined traditional security scanning tools with AI-assisted review, while others built specialised workflows designed to validate findings and reduce false positives.

The pilot found there was no single successful model. Departments adapted methods to suit their own systems, allowing GC3 to compare different approaches and identify techniques that produced the most useful results.

 

Pilot Method Indicators

Indicator Recent Movement Context
Testing format Weekly hackathons GC3 led in-person sessions with specialists from AISI and NCSC.
Code estate Public repositories The pilot focused on government code already published in the open.
Tooling model Varied team approaches Departments built their own workflows instead of using one mandated method.

 

Findings from the government cyber pilot

Participants identified 407 findings in total. The source material said these included weaknesses exposing services to authentication bypass, data exposure and remote code execution.

Some findings were already understood and mitigated through compensating controls, while others had not previously been identified. All highest-risk weaknesses were remediated, and no evidence of exploitation was identified for any finding.

The pilot cost £13,000 in tokens across the month. That work covered nine government organisations and showed how AI models could trace vulnerabilities across service boundaries and connect business logic with technical detail.

  • Findings total: participants reported 407 findings across the pilot period.
  • Organisations involved: the work covered nine government organisations during the month.
  • Token cost: the reported model token cost was £13,000.

 

Pilot Findings Summary

Indicator Recent Movement Context
Total findings 407 GC3 reported the total across participating government organisations.
Highest-risk remediation Completed The source material said all highest-risk weaknesses were remediated.
Evidence of exploitation None identified No evidence of exploitation was found for any reported finding.

 

Critical vulnerability example

One notable finding affected legacy GitHub Actions in a repository supporting a government digital service. The issue allowed an external user to trigger a workflow chain by posting a specially structured comment on an open pull request.

The source material said the workflow was triggered by a comment rather than the pull request itself. This bypassed the usual protections for pull requests from unknown contributors and created a route to remote code execution on the GitHub Actions runner.

The workflow took content from the comment, passed it into deployment parameters and used it in an environment substitution step. The source material said this could have allowed malicious actors to extract secrets and tokens available to the workflow.

 

Lessons from using AI in cyber defence

The pilot found that carefully designed workflows produced better results than using AI models alone. Human validation remained essential because potential vulnerabilities were identified faster than security teams could fully assess them.

The pilot also showed that finding vulnerabilities is not the same as fixing them. Identified weaknesses still had to enter normal remediation pipelines, with prioritisation, review and patching aligned to existing human-centred processes.

 

Next phase of the GC3 pilot

GC3 will begin a second phase with more departments, additional models and an extension from public code into closed-source estates. The stated aim is to identify vulnerabilities earlier and help departments share proven defensive techniques.

AISI and NCSC involvement will also deepen as the government continues to evaluate AI for cyber defence in applied settings. The next phase is expected to focus on closing the gap between theoretical model scores and measurable reductions in cyber risk.

 

The GC3 pilot tested frontier AI models against public government code to assess their practical value in cyber defence. The work identified 407 findings, remediated the highest-risk weaknesses and found no evidence of exploitation. The next phase will widen participation, add more models and move into closed-source estates while keeping human validation central to government cyber resilience work.

 

Sources: Department for Science, Innovation and Technology and National Cyber Security Centre.

 

Prepared by Ivan Alexander Golden, Founder of THX News, an independent news organisation delivering timely insights from global official sources. Combines AI-analysed research with human-edited accuracy and context.

 

Tags: artificial intelligenceCyber SecurityNCSCpublic sector
THX News

THX News

THX News is a governance-first information system focused on deterministic, source-verified reporting.

The platform operates under a fail-closed architecture, where publication occurs only when verification and attribution requirements are met. Content is produced from primary materials including government press releases and official documents, with all reporting traceable to source.

The system prioritises consistency, transparency, and reproducibility over output volume, forming part of a long-horizon information infrastructure.

Related Posts

Dan Jarvis MBE2C Minister for Security. Photo by the UK Government.
Cyber Security

UK cyber defence plan targets AI collaboration

April 22, 2026
Ministry of Defence, London. Photo by Chris Nyborg. **dept-uk-ministry-of-defence**
Cyber Security

UK Leads Defence Cyber Marvel Exercise

February 11, 2026
500 students now learning latest digital and cyber defence skills. Photo by the MOD.
Cyber Security

Defence cyber bursary reaches 500 students

January 21, 2026
Man holding table while accessing a cyber world. Photo by Pixabay.
Cyber Security

International Collaboration on Cyber Security

April 4, 2025
Energy infrastructure. Artwork by Cabinet Office.
Cyber Security

UK Boosts Critical Infrastructure Security

November 26, 2024
Act Don't React. Photo by Pedrik.
Cyber Security

UK Unveils AI Security Research

November 25, 2024

Explore & Discover More

Recent Posts

  • Government Cyber Pilot Finds 407 Vulnerabilities
  • MenB Vaccine Offered To Students
  • MHRA Approves First UK Weight Loss Tablet
  • State threats bill targets foreign proxy groups
  • Understanding China’s Underground Banking System

THX News

Reporting on the Official Record.

THX News delivers clarity by providing unfiltered news direct from primary sources. Our commitment is to foster an informed global community through fact-driven reporting you can trust.

About THX News

  • Our Mission
  • About Us
  • System Proof
  • System Repository

Help

  • Contact Us
  • Licensing & Redistribution
  • RSS

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • November 2020

© 2020-2026 THX News, Inc. All Rights Reserved.

No Result
View All Result
  • News
  • Canada
    • Community
    • Healthcare
    • Housing & Home Building
    • International
    • Military
    • Obituaries
    • Politics
    • Technology & Innovation
  • UK
    • Education
    • Environment
    • Healthcare
    • Housing & Land
    • Jobs & Employment
    • Law & Order
    • Money and Taxes
    • Technology
  • European Union
  • USA
    • Economics & Money
    • Immigration & Border Security
    • International
    • Law & Order
    • Local Government
      • Arizona
      • California
      • Oregon
      • Virginia
    • Medicine & Health
    • Military
    • Space & Exploration
    • Technology
  • Africa
    • Angola
    • Democratic Republic of the Congo
    • Egypt
    • Guinea
    • Kenya
    • Nigeria
    • Somalia
    • South Africa
  • Middle East
  • —
  • Travel
    • Africa
    • Asia
    • Europe
    • USA
  • Education
    • Art & Culture
    • Books & Authors
    • Fashion
    • History & Politics
    • Lifestyle & Relationships
    • Music
  • —
  • About Us
  • Help & FAQ
  • Contact Us
  • Login

© 2020-2026 THX News, Inc. All Rights Reserved.

THX News™ uses cookies. By using this website you are giving consent to the use of cookies. Visit our Privacy and Cookie Policy.