CERT-In issues rapid patching guidelines for internet-facing systems
Public Sector Action
Summary
Hide ▲
Show ▼
CERT-In issued new guidelines requiring organizations to patch internet-exposed critical vulnerabilities within 12 hours where feasible, tightening defensive timelines against AI-assisted cyber exploitation. The 38-page blueprint also sets faster remediation windows for known exploited vulnerabilities and other critical flaws across critical systems. The directive pushes organizations toward rapid exposure reduction, layered controls, and temporary mitigations when patches are not immediately available.
Related Happenings
CISA recommends continuous secrets scanning and stronger key management after GitHub leak
Defensive Guidance
H score26
First: 13.07.2026 18:03
Last: 13.07.2026 18:03
Sources 1
About this happening:
CISA now recommends continuous secrets scanning and stronger key management after a contractor left internal credentials in a public GitHub repository for nearly *...
CISA recommends continuous secrets scanning and stronger key management after GitHub leak
Defensive GuidanceAbout this happening: CISA now recommends continuous secrets scanning and stronger key management after a contractor left internal credentials in a public GitHub repository for nearly *...
OpenAI Daybreak expands with GPT-5.5-Cyber and Codex Security patch automation
Security Tool/Service
H score14
First: 23.06.2026 17:15
Last: 23.06.2026 17:15
Sources 1
About this happening:
OpenAI expanded Daybreak with a full release of GPT-5.5-Cyber and updated Codex Security, widening AI-assisted patch automation for verified defenders. The rollout...
OpenAI Daybreak expands with GPT-5.5-Cyber and Codex Security patch automation
Security Tool/ServiceAbout this happening: OpenAI expanded Daybreak with a full release of GPT-5.5-Cyber and updated Codex Security, widening AI-assisted patch automation for verified defenders. The rollout...
OpenAI upgrades GPT-5.5-Cyber and Codex Security plugin for vulnerability discovery and patching
Security Tool/Service
H score14
First: 23.06.2026 06:56
Last: 23.06.2026 06:56
Sources 1
About this happening:
OpenAI expanded Daybreak by releasing an improved GPT-5.5-Cyber model and updating the Codex Security plugin, giving trusted defenders faster tooling for finding...
OpenAI upgrades GPT-5.5-Cyber and Codex Security plugin for vulnerability discovery and patching
Security Tool/ServiceAbout this happening: OpenAI expanded Daybreak by releasing an improved GPT-5.5-Cyber model and updating the Codex Security plugin, giving trusted defenders faster tooling for finding...
CERT-In issues 12-hour patch guidance for Indian organizations
Public Sector Action
H score38
First: 26.05.2026 13:30
Last: 26.05.2026 13:30
Sources 1
About this happening:
CERT-In published new guidance on May 25 urging Indian organizations to patch actively exploited internet-facing vulnerabilities within 12 hours, tightening respon...
CERT-In issues 12-hour patch guidance for Indian organizations
Public Sector ActionAbout this happening: CERT-In published new guidance on May 25 urging Indian organizations to patch actively exploited internet-facing vulnerabilities within 12 hours, tightening respon...
CERT-In 12-hour KEV remediation guidance
Advisory/Mitigation
H score39
First: 26.05.2026 13:30
Last: 26.05.2026 13:30
Sources 1
About this happening:
CERT-In set a 12-hour expectation for containing or remediating known exploited vulnerabilities on internet-facing and crown-jewel systems, sharply shortening response...
CERT-In 12-hour KEV remediation guidance
Advisory/MitigationAbout this happening: CERT-In set a 12-hour expectation for containing or remediating known exploited vulnerabilities on internet-facing and crown-jewel systems, sharply shortening response...
Timeline
-
26.05.2026 12:13 2 articles · 1mo ago
CERT-In orders 12-hour patching for internet-exposed critical vulnerabilities
Legal Policy Action UpdateCERT-In issued a 38-page blueprint directing organizations to patch critical security vulnerabilities in internet-exposed systems within 12 hours where feasible, and to remediate known exploited vulnerabilities and other high-risk flaws on accelerated timelines. The guidance cites AI-assisted cyber exploitation that can shorten vulnerability discovery, weaponization, and exploitation, and it recommends layered controls, continuous monitoring, Zero Trust, SBOM-based supply-chain checks, and temporary mitigations such as isolation, access restriction, WAF/API protection, enhanced monitoring, or feature disablement when patches are not immediately available.
Show sources
- CERT-In Recommends 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks — thehackernews.com — 26.05.2026 12:13
- CERT-In Recommends 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks — thehackernews.com — 26.05.2026 12:13