惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - Franky
J
Java Code Geeks
腾讯CDC
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Jina AI
Jina AI
博客园 - 司徒正美
Stack Overflow Blog
Stack Overflow Blog
美团技术团队
L
LangChain Blog
WordPress大学
WordPress大学
A
About on SuperTechFans
Martin Fowler
Martin Fowler
月光博客
月光博客
Y
Y Combinator Blog
U
Unit 42
D
Docker
Recent Announcements
Recent Announcements
Hugging Face - Blog
Hugging Face - Blog
B
Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
G
Google Developers Blog
Last Week in AI
Last Week in AI
T
The Blog of Author Tim Ferriss
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com

MEDIANAMA

India in talks with US, Anthropic for Mythos access; no Indian firms in Project Glasswing yet Eternal Q4FY26: All Users Pay Higher Platform Fee, Only Some Get Discounts Amazon, Meta to challenge PhonePe-Google Pay dominance as UPI cap delayed since 2020 Meta failed to protect the safety of under-13s: European Commission If markets and regulators are ready for network slicing, we are ready: JIO Why defining ‘news’ won’t fix the free speech problems of draft IT Rules? #NAMA Eternal Q4FY26: Goyal Dismisses AI Disruption Risk as Zomato Quietly Builds Agentic Commerce Infrastructure Karnataka files appeal challenging the bike taxi ban lift in the Supreme Court How did WhatsApp turn 17 govt. flags into 9,400 digital arrest scam bans? Google Wallet integrates Aadhaar as digital ID, expands India’s mobile identity ecosystem Kerala HC issues notice on MediaOne’s Facebook page block in India MeitY warns VPN providers against enabling access to blocked betting platforms Shreya Singhal targeted private censorship. Today’s threat is the State #NAMA Amazon scales its quick delivery service ‘Amazon Now’ in 100 cities Can MeitY issue binding rules via advisories? Experts raise alarm over draft IT Rules #NAMA How 2019 election code of ethics became India’s three-hour content takedown mandate #NAMA Australia proposes new levy on big tech to fund news, opens draft law for consultation ‘judge, jury, executioner’: experts warn of Inter-Departmental Committee (IDC) overreach under New draft IT Rules Lowdown: TRAI flags low deployment under PM-WANI in public Wi-Fi consultation paper Why the NBFC licence matters for MobiKwik China blocks Meta-Manus deal, asserts origin-country jurisdiction: what this means for India ‘No transparency’: experts warn of expanding powers to block online speech in India #NAMA X launches standalone iOS messaging app XChat with encryption in India How India’s content takedown framework was built and where It has gone wrong #NAMA Claude Mythos puts India on alert: CERT-In, telcos, banks assess unprecedented cyber risks Explained: why did the RBI cancel Paytm’s banking licence? Meta now instantly blocks content in India Govt. asks ZEE5 to halt ‘Lawrence of Punjab’ web series release Online Gaming Rules notified, to be in effect from May 1, what are the major changes? RBI mandates additional factor authentication for e-mandates
SEBI forms task force, orders immediate cybersecurity ove...
Aakriti Bans · 2026-05-06 · via MEDIANAMA

The circular can be accessed here.

The Securities and Exchange Board of India (SEBI) has named Anthropic’s Claude Mythos in a circular dated May 5, ordering every regulated entity in Indian securities markets to immediately overhaul their cybersecurity infrastructure. SEBI is the first Indian financial markets regulator to name a specific AI model in a formal circular; CERT-In had first named Mythos across all sectors on April 26.

The circular covers stock exchanges, depositories, mutual funds, brokers, credit rating agencies, custodians, merchant bankers, and portfolio managers, among others.

SEBI’s concern: Mythos can identify and exploit vulnerabilities “using speed and scale,” threatening data confidentiality, application integrity, and reliability of outputs. Because all market participants are interconnected, one breach can trigger a domino effect across the entire ecosystem.

SEBI has also constituted a task force called cyber-suraksha.ai, comprising representatives from market infrastructure institutions (MIIs), qualified registrars and transfer agents (QRTAs), and other regulated entities, to examine AI-driven cybersecurity risks, share threat intelligence, report cyber incidents on priority, and review third-party vendor security posture.

What the circular requires:

  1. Patch immediately. All operating systems and applications must be updated right away. Where patches don’t exist yet, entities must use virtual patching, a temporary protective layer applied over a vulnerability when no official fix is available.
  2. Run AI-based vulnerability assessments. Entities must conduct Vulnerability Assessment and Penetration Testing (VAPT), simulated cyberattacks used to find weaknesses before real attackers do, continuously using both conventional and AI-based tools, in line with SEBI’s Cyber Security and Cyber Resilience Framework (CSCRF).
  3. Hold vendors accountable. Entities must engage third-party vendors on timely patching. Exchanges and depositories must specifically direct their empaneled application vendors to run comprehensive risk assessments on AI-led vulnerability detection models and implement safeguards, including patching, VAPT, and continuous monitoring.
  4. Lock down change management. Every system change, including minor ones, requires full documentation, impact analysis, structured review, rigorous testing, and secure deployment.
  5. Secure all APIs. An Application Programming Interface (API) is a connection point that lets different software systems communicate; in financial markets, APIs connect brokers, exchanges, and payment systems. The circular requires:
  • Updated inventory of all APIs and apps using them
  • Strong authentication on a least-privilege basis (users get access only to what they strictly need)
  • Rate limiting and throttling to detect abuse
  • Connections only via whitelist

6. Overhaul SOC monitoring. A Security Operations Centre (SOC) monitors an organisation’s systems for threats around the clock. The circular requires:

  • Daily monitoring of all systems and networks including low-priority alerts that are typically ignored
  • Implementation of a SOAR (Security Orchestration, Automated Response) playbooks integrated with SIEM (Security Incident and Event Management) solutions for automated threat detection and response
  • Fast-track onboarding onto the Market SOC (M-SOC), a centralised 24×7 security platform run by NSE and BSE
  • MIIs to run workshops to help entities integrate with M-SOC

7. Include AI as a risk scenario. Periodic risk assessments must now explicitly model AI model capabilities as a threat scenario.

8. Harden systems. Entities must adopt secure configurations, disable unnecessary services and default accounts, and enforce Zero Trust Network Architecture (ZTNA), a security model that requires verification at every step, assuming no user or system is trustworthy by default.

9. Update software inventory. Entities must periodically update their Software Bill of Materials (SBOM), a complete list of all software components, including open-source code, for all critical applications.

10. Build long-term AI defence. All regulated entities must prepare a long-term plan for using AI in detection and autonomous agentic mitigation, where AI systems independently identify and respond to threats without waiting for human instruction, including AI-augmented SOC transformation.

Why this matters: SEBI naming Mythos in a circular is a significant regulatory moment. As MediaNama has reported, no Indian company, bank, or government agency has secured access to Mythos under Project Glasswing, Anthropic’s $100 million restricted access programme. MeitY Secretary S. Krishnan confirmed on April 28 that India is still working out logistics with US authorities.

This creates a structural contradiction: SEBI is ordering Indian financial institutions to defend against a model they cannot access to defend themselves with. Claude Security, Anthropic’s enterprise defensive tool, gives Indian firms an indirect path through Infosys as a named partner, but runs on Opus 4.7, which produces two working exploits on the Firefox 147 benchmark against Mythos’s 181, a 90x capability gap.

MediaNama founder Nikhil Pahwa identified the core problem: “A tool that compresses attack timelines without compressing defense timelines increases systemic risk before it improves security.”

The data localisation conflict also remains unresolved. India’s 2018 rules require payment system providers to store all transaction data on servers within India, while Mythos is hosted on US-based servers. The National Payments Corporation of India (NPCI) has not publicly addressed this.

Finance Minister Nirmala Sitharaman chaired a meeting on April 23 with Reserve Bank of India (RBI), NPCI, Indian Banks’ Association (IBA), and CERT-In officials, calling the Mythos threat “unprecedented.” CERT-In has separately issued a high-severity advisory directing organisations to treat every newly disclosed vulnerability as exploitable within hours, not weeks.

Also read: