VidBodh AcademyThe art and science of civil services preparation

Science and Technology › Computing and AI

Cyber security and data protection

Cyber security and data protection: how attacks work, including those on artificial intelligence systems and critical infrastructure, cyber crime, the agencies that respond, and the law that protects personal data. It serves GS3 answers on cyber security.

All 4 subjects shown; the 1 that changed from 1 to 15 July 2026 are marked.Show only these

Prompt injection and ASCII smuggling

Copy link to Prompt injection and ASCII smuggling

Prelims

Unicode extends ASCII to the world's scripts, keeping ASCII itself as its own first 128 characters. It also carries tag characters, which copy those 128 but never show on screen, and hiding them inside ordinary text is what ASCII smuggling means.

  • Spammers were found using it against AI email filters, which read a broken word where the recipient reads an ordinary one.
  1. Hide

    Tag characters are slipped into a message, inside a word such as funding or as hidden instructions

  2. Software reads them

    A spam filter reads fun and ding instead of funding, and an AI tool obeys the hidden instructions

  3. Human sees nothing odd

    The reader sees only funding and ordinary text

From The Indian Express, 6 September 2026

What changed

  1. 6 Sep 2026

    The Indian Express, 6 Sep 2026: What is ASCII smuggling, and how is it helping spammers bypass AI email filters? (opens in a new tab)

  2. 6 Sep 2026

    • Prompt injection was the technique's first use: hidden tag characters carrying instructions that an AI agent would read and obey.

    The Indian Express, 6 Sep 2026: What is ASCII smuggling, and how is it helping spammers bypass AI email filters? (opens in a new tab)

Prelims and Mains

The Kudankulam plant is India's largest nuclear power station, and the files published on it by a ransomware group came from a contractor's data held by a third party, which is the supply chain weakness typical of attacks on critical infrastructure.

What changed

  1. 15 Jul 2026New subject

    • A ransomware group published about 19,000 files on the Kudankulam nuclear plant, taken from a contractor's data hosted with a third party provider and not from the plant's own network.
    • The operator says the files concern the conventional balance of plant, the non nuclear support systems of Units 3 and 4, and not nuclear safety systems.

    Mains: the breach came through the supply chain, which is the standard weakness of critical infrastructure.

    The Indian Express, 15 Jul 2026 · The Indian Express, 17 Jul 2026: Kudankulam project files surface on the dark web through a contractor's breach (opens in a new tab) · The Hindu, 16 Jul 2026: Leak of Kudankulam nuclear plant data sparks 'commotion' (opens in a new tab)

CERT-In and AI driven threats

Copy link to CERT-In and AI driven threats

Prelims and Mains

The Indian Computer Emergency Response Team is the national agency for cyber incidents, and its guidelines require equipment makers and providers to use artificial intelligence in testing, monitoring and patching against attackers who work at machine speed.

What changed

  1. 30 Jul 2026New subject

    • Guidelines of June 2026 from the Indian Computer Emergency Response Team require equipment makers and technology providers to use AI assisted security testing, monitoring and patching.
    • The second threat report for banking and payments names AI asymmetry as the defining risk: work that once needed specialist teams is now done at machine speed by attackers with few resources.

    PIB, 30 Jul 2026: CERT-In Conducts 10 Cyber Security Exercises on AI-Driven Cyber Threats with 1,470 Participants from 345 Government and Private Organisations (opens in a new tab) · PIB, 13 Jul 2026: Report Highlights AI Asymmetry and Emerging Cyber Trends to Strengthen Security and Resilience in India's BFSI and Payments Ecosystem (opens in a new tab)

Sanchar Saathi, ASTR and Chakshu

Copy link to Sanchar Saathi, ASTR and Chakshu

Prelims

Sanchar Saathi is the Department of Telecommunications portal against telecom fraud, ASTR is its artificial intelligence tool for finding suspicious connections, and Chakshu is its channel for citizens to report fraud calls and messages.

What changed

  1. 23 Jul 2026New subject

    • ASTR, an AI tool of the Department of Telecommunications, flags suspicious mobile connections, and more than 88 lakh have been disconnected after failing fresh verification.
    • Chakshu lets citizens report suspected fraud calls and messages on the Sanchar Saathi portal, and 11.18 lakh reports have led to 50.90 lakh disconnections.

    PIB, 23 Jul 2026: Measures Taken to Tackle Cyber Frauds (opens in a new tab)

Also filed elsewhere

  • C-DOT quantum security products · on Quantum science and technology

    A quantum computer able to break today's encryption does not exist yet, but traffic recorded today can be kept and read once one does.