Visualização normal

Antes de ontemCybersecurity News

CERT-In Urges Firms to Patch Critical Vulnerabilities Within 12 Hours Amid AI Threat Surge

CERT-In

India’s Computer Emergency Response Team, Indian Computer Emergency Response Team, has introduced a new cybersecurity framework urging organizations to patch critical security vulnerabilities in internet-facing systems within 12 hours of detection whenever feasible. The recommendation comes amid growing concerns that cybercriminals are increasingly using artificial intelligence tools and large language models (LLMs) to accelerate cyber attacks, automate exploit development, and scale malicious operations more efficiently. The guidance was published in a 38-page blueprint released on Monday and reflects mounting fears around AI-assisted cyber exploitation. According to CERT-In, the rapid adoption of AI and LLMs by threat actors is significantly shrinking the time between the discovery of security vulnerabilities and active exploitation. “AI-assisted cyber exploitation reduces the time required for adversaries to identify, weaponize, and exploit vulnerabilities, exposed services, weak identities, insecure APIs, and misconfigured systems,” CERT-In stated in the document.

AI and LLMs Are Reshaping Cyber Attack Timelines 

CERT-In warned that as organizations become more dependent on cloud ecosystems, interconnected infrastructure, operational technology, software supply chains, and AI-enabled platforms, the risks associated with AI-driven attacks continue to rise across industries. The agency noted that attackers are already using AI and LLMs for a broad range of malicious activities, including attack surface mapping, exploit analysis, phishing campaigns, malware creation, and automated reconnaissance. The use of AI allows attackers to compress traditional attack preparation timelines and evade some conventional security controls. The blueprint also highlighted that AI-enabled environments themselves can become targets. Threat actors may exploit weaknesses through prompt injection attacks, model manipulation, jailbreaking methods, data leakage vulnerabilities, training data poisoning, model theft, and orchestration pipeline compromises. Such attacks can undermine the confidentiality, integrity, and reliability of AI systems. According to CERT-In, organizations should prepare for a future where cyberattacks become autonomous, and exploitation timelines collapse further due to advancements in AI and LLMs. The agency said this shift requires stronger operational readiness, proactive patching strategies, continuous threat assessment, and aggressive exposure reduction practices.

CERT-In Calls for Stronger Defenses Against Security Vulnerabilities 

To counter AI-assisted attacks and reduce exposure to security vulnerabilities, CERT-In outlined several defensive principles that organizations should adopt.  One of the key recommendations is the assumption that breaches are inevitable. Organizations are encouraged to prepare for rapid detection, containment, and recovery during compromise scenarios. The blueprint also stresses the adoption of Zero Trust security models that enforce continuous verification and least-privilege access controls.  CERT-In further recommended implementing defense-in-depth strategies with layered protections across infrastructure to minimize the impact of successful breaches and eliminate single points of failure. The agency emphasized continuous monitoring and remediation of security vulnerabilities, along with integrating secure-by-design practices into applications, infrastructure, and AI workflows.  The framework also advises organizations to maintain operational continuity during cyber incidents and ensure the protection of sensitive and operationally critical data throughout its lifecycle. Another major focus area is software supply chain security. CERT-In urged enterprises to reduce risks linked to third-party software, AI models, and dependencies through Software Bills of Materials (SBOMs), provenance validation, and security assessments.  To evaluate the effectiveness of cybersecurity controls, the agency recommended regular red teaming exercises, vulnerability assessments, penetration testing, and independent audits. It also advised organizations to prioritize controls based on operational importance and threat exposure while establishing formal governance frameworks for AI usage and maintaining visibility into AI systems and integrations.  “Organizations should implement layered, risk-based, and continuously validated technical controls to reduce exposure to AI-assisted cyber threats,” CERT-In said. “Controls should prioritize protection of internet-facing systems, critical business applications, identities, cloud environments, APIs, sensitive data, AI-enabled systems, and operational infrastructure.” 

New Patching Deadlines Introduced for Critical Flaws 

A major component of the blueprint focuses on vulnerability management and patching timelines. CERT-In urged organizations to adopt continuous, risk-based vulnerability and patch management practices to reduce risks associated with security vulnerabilities, insecure APIs, misconfigurations, publicly exposed services, and weak identities.  Under the new recommendations, known exploited vulnerabilities affecting internet-facing and critical systems should be remediated within 12 hours wherever applicable. The agency also introduced additional remediation timelines based on severity and exposure levels.  Critical externally exposed vulnerabilities should be addressed within one day. Known exploited vulnerabilities impacting internal systems should also be remediated within one day unless alternative mitigation measures are implemented and documented. Critical internal vulnerabilities affecting high-value systems should be patched within three days, while high-severity vulnerabilities should be resolved within five days based on risk prioritization.  CERT-In acknowledged that immediate patching may not always be possible. In situations where fixes are unavailable, the agency advised organizations to deploy temporary mitigations such as system isolation, restricted access controls, web application firewall (WAF) or API protections, enhanced monitoring, and feature disablement until official patches are released.  The new recommendations reflect growing global concerns about the role of AI and LLMs in modern cyber warfare. As threat actors continue to automate the discovery and exploitation of security vulnerabilities, cybersecurity agencies and enterprises are facing pressure to strengthen patching practices, reduce exposure windows, and improve resilience against rapidly evolving digital threats.

Canvas Hackers ShinyHunters Say Their Official Domain Was Suspended

ShinyHunters says its shinyhunte.rs domain was suspended after the Canvas LMS attacks, forcing the group to move fully to its dark web (.onion) site.
  • ✇Security Boulevard
  • AI Overviews Rife With Scam Phone Numbers Teri Robinson
    In a new take on an old scam, AI Overviews are inadvertently coughing up fraudulent phone numbers for companies that appear in search queries leading callers to miscreants who elicit sensitive data and payment information.  The post AI Overviews Rife With Scam Phone Numbers appeared first on Security Boulevard.
     
  • ✇Security Boulevard
  • Attacker Breached 600 FortiGate Appliances in AI-Assisted Campaign: Amazon Jeffrey Burt
    An single threat actor used AI tools to create and run a campaign that compromised more then 600 Fortinet FortiGate appliances around the world over five weeks, according to Amazon threat researchers, the latest example of how cybercriminals are using the technology in their attacks. The post Attacker Breached 600 FortiGate Appliances in AI-Assisted Campaign: Amazon appeared first on Security Boulevard.
     

Attacker Breached 600 FortiGate Appliances in AI-Assisted Campaign: Amazon

23 de Fevereiro de 2026, 01:51
AI technology, security, AI security, visibility, insights, security platform, Arctic Wolf, zero-trust encrypted AI Trend Micro cybersecurity poverty line, data-centric, SUSE cloud Wiz Torq AirTag Skyhawk SASE security cloud security visibility PwC Survey Finds C-Level Execs Now View Cybersecurity as Biggest Risk

An single threat actor used AI tools to create and run a campaign that compromised more then 600 Fortinet FortiGate appliances around the world over five weeks, according to Amazon threat researchers, the latest example of how cybercriminals are using the technology in their attacks.

The post Attacker Breached 600 FortiGate Appliances in AI-Assisted Campaign: Amazon appeared first on Security Boulevard.

  • ✇Arstechnica
  • OpenAI helps spammers plaster 80,000 sites with messages that bypassed filters Dan Goodin
    Spammers used OpenAI to generate messages that were unique to each recipient, allowing them to bypass spam-detection filters and blast unwanted messages to more than 80,000 websites in four months, researchers said Wednesday. The finding, documented in a post published by security firm SentinelOne’s SentinelLabs, underscores the double-edged sword wielded by large language models. The same thing that makes them useful for benign tasks—the breadth of data available to them and their ability to us
     

OpenAI helps spammers plaster 80,000 sites with messages that bypassed filters

9 de Abril de 2025, 16:32

Spammers used OpenAI to generate messages that were unique to each recipient, allowing them to bypass spam-detection filters and blast unwanted messages to more than 80,000 websites in four months, researchers said Wednesday.

The finding, documented in a post published by security firm SentinelOne’s SentinelLabs, underscores the double-edged sword wielded by large language models. The same thing that makes them useful for benign tasks—the breadth of data available to them and their ability to use it to generate content at scale—can often be used in malicious activities just as easily. OpenAI revoked the spammers’ account in February.

“You are a helpful assistant”

The spam blast is the work of AkiraBot—a framework that automates the sending of messages in large quantities to promote shady search optimization services to small- and medium-size websites. AkiraBot used python-based scripts to rotate the domain names advertised in the messages. It also used OpenAI’s chat API tied to the model gpt-4o-mini to generate unique messages customized to each site it spammed, a technique that likely helped it bypass filters that look for and block identical content sent to large numbers of sites. The messages are delivered through contact forms and live chat widgets embedded into the targeted websites.

Read full article

Comments

© Getty Images | Iurii Motov

❌
❌