India Mandates 12-Hour Patch Deadline Amid AI-Driven Cyber Threats

India Mandates 12-Hour Patch Deadline Amid AI-Driven Cyber Threats

First seen 26 May 2026, 16:41 UTC Infosecurity-MagazineGbhackersAicerts.AiCybersecuritynewsCrnasia+3 85% similarity 72.5

Article Content

Browse articles
ThreatCluster

India's CERT-In has issued a directive requiring organizations to patch critical vulnerabilities on internet-facing and crown-jewel systems within 12 hours of discovery or active exploitation. This guidance responds to the accelerated pace of AI-assisted cyber-attacks, which have reduced the time available for defenders to react. The new framework categorizes vulnerabilities into tiers, with specific timelines: 1 day for critical external flaws, 3 days for internal criticalities, and 5 days for high-severity issues. Organizations are advised to implement interim measures if no patch is available. The blueprint emphasizes the need for robust governance, zero-trust architecture, and AI-aware security operations. This aggressive timeline reflects a significant shift in India's cybersecurity policy, aiming to enhance vulnerability management and threat intelligence integration. However, skepticism remains regarding the feasibility of such rapid patching, given historical compliance challenges.

Key Points: • CERT-In mandates a 12-hour patching deadline for critical vulnerabilities. • AI-driven attacks are compressing response times, necessitating faster remediation. • Organizations must adopt a risk-based approach to vulnerability management.

ThreatCluster AI

Timeline

2026-05-25
CERT-In publishes new patching guidance
The guidance sets a 12-hour deadline for patching critical vulnerabilities on exposed systems, reflecting the urgency of AI-assisted attacks.
Infosecurity-Magazine
2026-05-26
India's emergency patching rule announced
The rule aims to compress cyber response times, with specific timelines for different vulnerability tiers.
Aicerts.Ai
2026-05-27
Increased pressure on organizations to patch
As AI-assisted attacks evolve, organizations are urged to enhance their vulnerability management practices to meet new timelines.
Cybersecuritynews

Community

Browse all →