CERT-In professes 12-hour patching for AI-assisted attacks
CERT-In says exploited internet-facing or crown-jewel systems should be patched or isolated within 12 hours where feasible.
Intelligence analysis by GPT-5.4 Mini
India’s CERT-In has advised defenders to patch, mitigate, or remove exposure to exploited internet-facing or critical systems within 12 hours where feasible, citing faster AI-assisted attacks. The guidance is more flexible for internal systems, where a 24-hour window applies.
A cyber safety team in India says some broken computer locks need to be fixed very fast, sometimes within half a day. If the lock guards a big, important door on the internet, the team says people should patch it or block it quickly.
The reason is that bad actors now have faster tools, kind of like having a burglar who gets a power drill instead of a screwdriver. That means the break-in can happen much sooner than before.
Security teams may not always be able to fix everything right away, so they can also put up a temporary fence, like closing a gate or cutting off access, until the real repair is ready.
Analysis
What CERT-In is saying
India’s Computer Emergency Response Team has issued new guidance aimed at AI-assisted cyberattacks. Its main recommendation is that when a vulnerability is already being exploited and the affected system is internet-facing or a “crown jewel,” defenders should try to patch, mitigate, or remove exposure within 12 hours where feasible.
The guidance draws a distinction between those high-risk systems and other cases. For a standard critical flaw on an internal system, or even a known exploited bug affecting an internal system, CERT-In says the response window can be 24 hours. That makes the advice less absolute than it first sounds, but still much faster than many organizations are used to.
Why the window is so short
CERT-In says AI-assisted cyber exploitation reduces the time attackers need to find, weaponize, and use weaknesses in exposed services, weak identities, insecure APIs, and misconfigured systems. The report also argues that organizations are increasingly tied together through cloud services, software supply chains, operational tech, and AI-enabled platforms, so a weakness in one place can spread damage more widely.
What practitioners think
Security professionals quoted by The Register said 12 hours is usually too short for full patch testing and deployment. But they agreed the idea is directionally right because the recommendation includes temporary mitigations. One expert, Dray Agha of Huntress, said isolation, access restriction, or disablement can buy time before a coordinated patching plan.
The article frames this as part of a broader shift: AI is not only helping defenders automate work, it is also helping attackers move faster. The practical takeaway is that security teams need faster containment playbooks, not just better patch calendars.
Key points
- CERT-In recommends patching, mitigating, or removing exposure to exploited internet-facing or crown-jewel systems within 12 hours where feasible.
- For standard critical flaws or exploited bugs on internal systems, CERT-In allows a 24-hour window.
- The guidance is meant to respond to faster AI-assisted exploitation across exposed services, identities, APIs, and misconfigurations.
- Security professionals quoted in the article said 12 hours is often too short for full patch testing, but temporary mitigations make the advice more workable.
- The story frames AI as speeding up both attacker workflows and defender expectations.



