How to Comply with CERT-In's Guidelines for Responding to AI-Powered Threats
- Nisha Gautam
- Jul 6
- 3 min read

Artificial Intelligence (AI) is transforming the way we live and work - but it is also changing the way cybercriminals operate. Unlike traditional attacks that required hackers to manually perform each step, today's AI-powered attacks can automate the entire process. From identifying vulnerable systems to stealing sensitive data and launching ransomware, AI can complete complex attacks in a fraction of the time.
A recent incident involving Langflow, an AI application development platform, highlighted this growing concern. Researchers discovered an AI-driven “ransomware-as-code” attack on Langflow (an open-source AI-agent framework). A critical Langflow vulnerability (CVE-2026-33017) was added to CISA’s Known Exploited list after hackers-built exploits within hours of disclosure. Security firm Sysdig found an AI agent (codenamed JADEPUFFER) that chained tasks - breaking in, stealing credentials, pivoting, and encrypting a database - entirely on its own. These events underscore that attackers can now hire or build AI agents to run multi-stage attacks with no human code-writer at the keyboard.
How AI Is Reshaping Cyber Threats
AI has become a powerful tool for attackers. It can rapidly scan thousands of systems for security weaknesses, generate convincing phishing emails, create malicious software, and adapt its actions based on the target. Tasks that once required days of planning and technical expertise can now be completed automatically and at a much larger scale.
This shift lowers the barrier for cybercriminals while increasing the speed, accuracy, and reach of cyberattacks. As AI technology becomes more accessible, organizations of every size are facing a rapidly evolving threat landscape. In short, AI makes attacks cheaper, faster, and more scalable than ever.
CERT-In's Response to AI-Powered Threats
To address this emerging challenge, CERT-In (Indian Computer Emergency Response Team) has urged organizations to rethink how they respond to Cyber Security risks. Its latest guidance recommends treating every newly discovered critical vulnerability as an urgent threat that should be addressed within 24 hours, rather than waiting for routine update cycles.
CERT-In also emphasizes stronger access controls, continuous security monitoring, reduced exposure of internet-facing systems, and faster reporting of cyber incidents. The focus has shifted from reacting after an attack to building resilience before one occurs.
From Businesses to Individuals: Who Is Affected?
The impact of AI-powered cyberattacks extends far beyond the technology sector. Modern applications, cloud platforms, businesses, government agencies, healthcare institutions, educational organisations, and financial services increasingly rely on AI-enabled systems to manage sensitive information.
As a result, a successful attack can lead to data breaches, financial losses, operational disruptions, reputational damage, and loss of customer trust. Employees are also becoming prime targets, as AI can produce highly realistic phishing emails, fake messages, and social engineering attacks that are increasingly difficult to distinguish from genuine communication.
Strengthening Your Cyber Security Posture
To defend against AI-assisted threats, follow these key steps:
Patch and Update Continuously: Apply fixes immediately. Follow CERT‑In’s 24‑hour rule on critical vulnerabilities.
Harden and Isolate Systems: Never expose code-execution endpoints or admin interfaces to the public internet. Change all default passwords and signing keys. Network-segment critical systems (Zero Trust) so a compromise can’t spread.
Protect Secrets: Store API keys, database passwords and cloud credentials in vaults or secret managers, not in code or AI tools. Use strong, unique credentials and multi-factor authentication everywhere.
Monitor and Detect: Deploy real-time monitoring and AI-augmented detection to spot unusual behaviour (e.g. unknown processes or outbound beacons). Using runtime defences is advised because “attackers beat patch cycles by hours”.
Backup and Incident Planning: Keep offline backups of critical data and a tested incident-response plan. If an attack occurs, isolate infected hosts immediately and preserve evidence.
Educate and Test: Train staff to recognize AI-powered phishing or social engineering. Conduct regular drills (include CERT‑In reporting steps) so your team responds swiftly.
Follow Guidance: Refer to CERT‑In’s AI threat blueprint and report incidents promptly.
By combining proactive cyber security, continuous monitoring, expert advisory, and employee awareness, CyCDO (Cyint Cyber Defence Operations) helps organizations stay protected, resilient, and ready for the next generation of AI-powered cyber threats. Cyint Technologies help organisations strengthen their cyber resilience through SOC-as-a-Service, Application Security-as-a-Service, AI security implementation, Security Validation Services, and comprehensive triage, detection, and incident response capabilities.




