Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access

May 27, 2026

India’s CERT-In Sets 12-Hour Patch Deadline for Exposed Flaws

May 26, 2026

Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer

May 26, 2026
Facebook X (Twitter) Instagram
Wednesday, May 27
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»India’s CERT-In Sets 12-Hour Patch Deadline for Exposed Flaws
News

India’s CERT-In Sets 12-Hour Patch Deadline for Exposed Flaws

Team-CWDBy Team-CWDMay 26, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Organizations in India have been urged to patch actively exploited internet-facing vulnerabilities within 12 hours under new guidance that responds to the speed AI now brings to cyber-attacks.

According to new guidance from the Indian Computer Emergency Response Team (CERT-In), attackers are using AI to compress the time between finding and exploiting a weakness, shrinking the window defenders have to respond.

The document, published on May 25, maps how generative AI, large language models (LLMs) and autonomous agents are accelerating reconnaissance, vulnerability discovery, phishing and malware development.

A Blueprint Built Around AI Threats

CERT-In set an indicative 12-hour expectation for containing or remediating known exploited vulnerabilities (KEVs) on “internet-facing and crown-jewel systems.”

Other tiers follow a risk-based schedule: one day for critical externally exposed flaws, three days for critical internal vulnerabilities on high-value systems and five days for high-severity issues. Where no patch exists, the agency advised interim measures such as isolation, access restriction or web application firewall protection until a fix lands.

For prioritization, CERT-In pointed organizations toward the KEV catalog and the Exploit Prediction Scoring System (EPSS) rather than severity scores alone.

CERT-In stopped short of framing the timelines as binding, describing them as indicative expectations to be applied according to operational criticality and threat exposure.

Read more on national cybersecurity directives: CISA Closes Ten Emergency Directives After Federal Cyber Reviews

Securing AI Deployments and Reporting Incidents

Beyond patching, the blueprint lays out a framework spanning governance, zero-trust architecture, AI-aware security operations and supply-chain assurance through software and AI bills of materials (BOMs).

It devotes particular attention to securing organizations’ own AI deployments, covering prompt injection, model theft, training-data poisoning and the governance of autonomous agents that act with limited human oversight.

The guidance also reiterates the existing requirement for entities to report cyber incidents to CERT-In within six hours of detection, a rule in force since 2022.

Organizations are encouraged to roll out the recommendations in three phases, starting with a 0-7-day push on governance, exposure reduction and multi-factor authentication (MFA), then moving through operational strengthening and on to red teaming and adversarial AI testing.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleCompromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer
Next Article SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access
Team-CWD
  • Website

Related Posts

News

SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access

May 27, 2026
News

Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer

May 26, 2026
News

Chinese Threat Actors Shift to Live Credential Interception

May 26, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Chronology of a Skype attack

February 5, 2026

A quick guide to recovering a hacked account

March 21, 2026

The WhatsApp screen-sharing scam you didn’t see coming

November 6, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.