CERT-In Urges Patching Critical Vulnerabilities in Multiple Systems
Key Takeaways India’s national cybersecurity agency, CERT-In, has issued a stringent directive for organizations to patch critical vulnerabilities. The new guidelines mandate a 12-hour patching...
Key Takeaways
- India’s national cybersecurity agency, CERT-In, has issued a stringent directive for organizations to patch critical vulnerabilities.
- The new guidelines mandate a 12-hour patching window for actively exploited, internet-facing, or critical systems.
- This accelerated timeline is a direct response to the increasing speed and sophistication of AI-assisted cyberattacks.
- The directive affects all enterprises, particularly those in critical sectors like government, banking, telecom, healthcare, and digital public infrastructure.
- Organizations must adopt continuous exposure management and enhance AI-aware governance to mitigate risks.
India’s national computer emergency response team, CERT-In, has issued a critical directive for all organizations: immediately patch high-risk vulnerabilities on internet-facing and critical systems. The agency emphasizes a strict 12-hour remediation window for flaws that are either newly discovered or already under active exploitation. This urgent mandate stems from the escalating threat posed by AI-assisted cyberattacks, which are dramatically shrinking the time available for defenders to respond.
Table Of Content
The new guidance is detailed in CERT-In’s “Blueprint for Reducing Exposure and Defending against AI-Assisted Vulnerabilities Exploitation in Digital Infrastructure.” This comprehensive document highlights how threat actors are increasingly leveraging generative AI, large language models, and autonomous agents to streamline reconnaissance, identify vulnerabilities, and develop exploits across various exposed services, APIs, and cloud assets. The integration of AI tools allows attackers to chain multiple flaws, generate malicious code, and orchestrate semi-autonomous campaigns, compressing the window between a vulnerability’s disclosure and its active exploitation from days to mere hours.
CERT-In warns that this accelerated attack timeline transforms any unpatched internet-facing system into a prime target, especially for organizations operating in vital sectors such as government, banking, telecommunications, healthcare, and digital public infrastructure.
Accelerated Patching Mandate
To counteract the rapid pace of AI-driven attacks, the CERT-In blueprint outlines a series of risk-based remediation timelines. The most aggressive of these targets internet-exposed systems that are already experiencing active exploitation. For such critical and actively exploited flaws affecting internet-facing or essential assets, organizations are now required to contain the threat and, where feasible, remediate it within a mere 12 hours. This tight deadline aims to close the vulnerability window before automated exploitation campaigns can scale rapidly.
Other critical externally exposed vulnerabilities must be addressed within one day. For critical internal flaws impacting high-value systems, organizations are given up to three days for resolution. General high-severity issues, provided a robust risk-based prioritization process is in place, allow for up to five days for remediation.
Beyond Reactive Measures: Proactive Security
CERT-In stresses that traditional security practices, such as periodic assessments and compliance-driven audits, are no longer sufficient in an environment where AI constantly scans the internet for new weaknesses. Instead, the agency advocates for a shift towards continuous exposure management. This proactive approach involves constant asset discovery, real-time attack surface monitoring, and regular assessments of internet-facing web, cloud, and API endpoints.
These ongoing activities should feed into a centralized vulnerability management process. This process must leverage lists of known exploited vulnerabilities, exploit prediction scores, and business criticality assessments to drive prioritized remediation efforts. Beyond immediate patching, the blueprint also calls for the implementation of AI-aware governance and zero-trust principles to minimize the impact radius should a breach occur.
Recommended measures include enhanced leadership oversight of cyber and AI-related risks, alongside the strict enforcement of multi-factor authentication (MFA) and least-privilege access controls. Organizations are also advised to implement micro-segmentation to prevent lateral movement from compromised internet-facing systems.
Furthermore, CERT-In urges organizations to modernize their Security Operations Center (SOC) capabilities by integrating AI for telemetry correlation, behavioral analytics, and advanced threat hunting. The agency also recommends deepfake-aware training for employees to bolster defenses against AI-driven phishing and impersonation attempts.
The blueprint links rapid patching to broader resilience obligations, emphasizing the importance of regular backup testing, incident response simulations, and red-team exercises. These activities are crucial for validating that existing controls remain effective under AI-enabled attack scenarios. Entities are also reminded of their existing obligation to report qualifying cyber incidents to CERT-In within six hours, facilitating coordinated responses and sector-wide intelligence sharing. Ultimately, CERT-In describes the 12-hour patching mandate for exploited internet-facing systems as a fundamental requirement in today’s AI-driven threat landscape, urging Indian organizations to embrace exposure reduction as a continuous security practice rather than a mere periodic compliance task.
What You Should Do
- Prioritize Patching: Immediately apply patches for actively exploited, internet-facing, or critical vulnerabilities within 12 hours of discovery or notification.
- Implement Continuous Exposure Management: Regularly discover assets, monitor your attack surface, and conduct recurring assessments of web, cloud, and API endpoints.
- Enhance Vulnerability Management: Integrate known-exploited-vulnerability lists, exploit prediction scores, and business criticality into your remediation prioritization.
- Adopt AI-Aware Governance: Strengthen leadership oversight of cyber and AI risks, and enforce multi-factor authentication and least-privilege access.
- Segment Networks: Implement micro-segmentation to limit lateral movement within your network from potentially compromised systems.
- Modernize SOC Operations: Utilize AI for telemetry correlation, behavioral analytics, and proactive threat hunting.
- Educate Employees: Provide deepfake-aware training to help staff recognize and defend against AI-driven phishing and impersonation attacks.
- Test Resilience: Conduct regular backup testing, incident response simulations, and red-team exercises to validate security controls against AI-enabled threats.
- Report Incidents Promptly: Report qualifying cyber incidents to CERT-In within six hours as per existing directives.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.