惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
Docker
人人都是产品经理
人人都是产品经理
小众软件
小众软件
博客园 - Franky
WordPress大学
WordPress大学
Jina AI
Jina AI
Google DeepMind News
Google DeepMind News
I
InfoQ
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
F
Fortinet All Blogs
博客园 - 【当耐特】
IT之家
IT之家
G
Google Developers Blog
J
Java Code Geeks
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
云风的 BLOG
云风的 BLOG
Recent Announcements
Recent Announcements
有赞技术团队
有赞技术团队
V
Visual Studio Blog
U
Unit 42
阮一峰的网络日志
阮一峰的网络日志
月光博客
月光博客
GbyAI
GbyAI
雷峰网
雷峰网

www.infosecurity-magazine.com

Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month Google Chrome Rolls Out Protection Against Infostealers Targeting Session Cookies STX RAT Targets Finance Sector With Advanced Stealth Tactics Bitcoin Depot Reports $3.6m Crypto Theft After System Breach Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group Governance Gaps Emerge as AI Agents Drive 76% Increase in NHIs Google Warns of New Threat Group Targeting BPOs and Helpdesks Google API Keys Quietly Gain Access to Gemini on Android Devices Critical Vulnerability in Ninja Forms Exposes WordPress Sites Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs New 'Storm' Infostealer Remotely Decrypts Stolen Credentials NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts Apple Expands iOS 18 Security Updates Amid DarkSword Threat Researchers Observe Sub-One-Hour Ransomware Attacks GitHub Used as Covert Channel in Multi-Stage Malware Campaign Most CNI Firms Face Up to £5m in Downtime from OT Attacks Google Introduces Android Dev Verification Amid Openness Debate New Venom Stealer MaaS Platform Automates Continuous Data Theft Chinese Hackers Target European Governments in Espionage Campaigns
India's CERT-In Sets 12-Hour Patch Deadline for Exposed F...
Alessandro Mascellino · 2026-05-26 · via www.infosecurity-magazine.com

Organizations in India have been urged to patch actively exploited internet-facing vulnerabilities within 12 hours under new guidance that responds to the speed AI now brings to cyber-attacks.

According to new guidance from the Indian Computer Emergency Response Team (CERT-In), attackers are using AI to compress the time between finding and exploiting a weakness, shrinking the window defenders have to respond.

The document, published on May 25, maps how generative AI, large language models (LLMs) and autonomous agents are accelerating reconnaissance, vulnerability discovery, phishing and malware development.

A Blueprint Built Around AI Threats

CERT-In set an indicative 12-hour expectation for containing or remediating known exploited vulnerabilities (KEVs) on "internet-facing and crown-jewel systems."

Other tiers follow a risk-based schedule: one day for critical externally exposed flaws, three days for critical internal vulnerabilities on high-value systems and five days for high-severity issues. Where no patch exists, the agency advised interim measures such as isolation, access restriction or web application firewall protection until a fix lands.

For prioritization, CERT-In pointed organizations toward the KEV catalog and the Exploit Prediction Scoring System (EPSS) rather than severity scores alone.

CERT-In stopped short of framing the timelines as binding, describing them as indicative expectations to be applied according to operational criticality and threat exposure.

Read more on national cybersecurity directives: CISA Closes Ten Emergency Directives After Federal Cyber Reviews

Securing AI Deployments and Reporting Incidents

Beyond patching, the blueprint lays out a framework spanning governance, zero-trust architecture, AI-aware security operations and supply-chain assurance through software and AI bills of materials (BOMs).

It devotes particular attention to securing organizations' own AI deployments, covering prompt injection, model theft, training-data poisoning and the governance of autonomous agents that act with limited human oversight.

The guidance also reiterates the existing requirement for entities to report cyber incidents to CERT-In within six hours of detection, a rule in force since 2022.

Organizations are encouraged to roll out the recommendations in three phases, starting with a 0-7-day push on governance, exposure reduction and multi-factor authentication (MFA), then moving through operational strengthening and on to red teaming and adversarial AI testing.