India Requires Companies to Patch Critical Flaws Within 12 Hours as AI Threats Rise
Generative AI and automation tools are sharply reducing the time hackers need to conduct reconnaissance, write malware and exploit vulnerabilities, leaving companies’ weekly or monthly patching cycles unable to respond quickly enough. The Indian Computer Emergency Response Team (CERT-In) has therefore strengthened its cybersecurity guidance in an effort to reduce the risk of autonomous attacks on critical infrastructure and businesses.
According to the latest developments covered in the June 1–5 cybersecurity weekly report, CERT-In requires companies and organizations to patch critical vulnerabilities within 12 hours of disclosure, significantly shortening previous response timelines. The new guidance also calls for zero-trust architecture, multi-factor authentication and continuous monitoring to counter the rapid spread of AI-assisted attacks. No financial amount was involved.
All Coverage
2 original reportsThe Backstory
The history behind this eventUS CISA Sets Three-Day Patch Deadline for Highest-Risk Flaws as AI Threats Mount
The US Cybersecurity and Infrastructure Security Agency, or CISA, uses binding operational directives to standardize vulnerability handling across federal civilian executive branch agencies. As AI helps attackers analyze vulnerabilities and develop attack tools more quickly, the interval between disclosure and exploitation continues to shrink, making patching speed critical to the security of government systems and critical infrastructure.
CISA's newly issued BOD 26-04 directs federal agencies to prioritize vulnerability remediation according to risk, requiring the highest-risk flaws to be patched within three days of confirmation. The new framework sharply compresses the response window to help government defenses keep pace with AI-accelerated attacks and reduce the risk of vulnerabilities being exploited before they are patched.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →