India’s CERT-In has released updated guidance urging organizations to patch critical security vulnerabilities in internet-exposed systems within 12 hours once they are identified and flagged, where it is feasible to do so. The guidance is aimed at reducing risk from vulnerabilities that could be quickly exploited by malicious actors. Both outlets report that the recommendation is framed in the context of faster-moving attacks and the increased use of AI-related tools, including large language models, which can help attackers automate parts of the exploitation process and potentially shorten the time between discovery and misuse.
The guidance focuses on exposed flaws—those accessible from the internet—and applies a time-based remediation expectation of 12 hours after notification, subject to feasibility. CERT-In’s message is that rapid patching is a key control to limit exposure windows for high-impact vulnerabilities. The reports do not indicate specific affected products or vulnerability lists in the provided material, but they describe the policy shift toward accelerated timelines for addressing critical internet-facing issues.