The new advisory, released late on Sunday, comes days after Union Finance Minister Nirmala Sitharaman and other senior government officials met to discuss the impact of Claude Mythos on the financial security of various government systems.
Cert-In, which functions under the Ministry of Electronics and Information Technology, is the government’s nodal agency for all things related to cybersecurity. In its advisory, Cert-In has warned that the latest developments in general-purpose language models, such as Claude Mythos, indicate a significant increase in cyber-capability maturity, including the ability to autonomously discover security vulnerabilities in widely used software, analyse source code, and plan and chain together multi-stage attacks.
These frontier AI systems, Cert-In has said, perform these activities “at a speed and scale that previously required teams of skilled human experts”.
“It is likely that AI systems with such advanced cyber capabilities will continue to emerge and mature in near future. While they hold promise for defensive applications, their dual-use nature means organisations face heightened risks,” Cert-In said.
Cert-In said: “Such capabilities could lower the barrier to entry for malicious cyber actors and be leveraged to accelerate attack execution, automate exploitation workflows and scale cyber campaigns.”
To help prepare for the challenges posed by frontier models such as Claude Mythos, Cert-In has suggested that companies, as well as micro, small, and medium enterprises (MSMEs), should maintain an elevated alert posture, increase the frequency of threat monitoring, and review all systems.
All companies should also review and reduce internet-exposed attack surfaces within their systems and disable unnecessary ports and protocols, Cert-In has said in its advisory.
Further, any company that discovers a critical vulnerability in any widely deployed systems or software should treat it as “something that could be exploited within hours, not weeks”.
To prevent attacks from being organisation-wide, Cert-In has also suggested that companies divide their digital systems and architecture “into smaller, isolated segments so that an attacker who compromises one part of the network cannot easily move to others”.
“Review and harden, or replace, legacy remote-access systems such as older VPN appliances. These have repeatedly been used as entry points by attackers and are particularly attractive to automated tools. Make sure no production system is exposed to the public internet unless strictly necessary. Maintain an up-to-date inventory of all systems that are exposed in this way,” Cert-In said in its advisory.
To prevent a repeat of incidents in which attackers gain access to systems through open-source software, the government’s nodal cybersecurity agency has asked companies and MSMEs to regularly review and patch open-source software components.
As part of their cyber-hygiene, companies must also “monitor and restrict” all outbound network traffic to known AI services to curb the sanctioned use of such automated tools, Cert-In has said in its advisory.
Apart from these, companies and MSMEs should also train their internal security teams to detect how “AI-augmented attackers operate” so that responses can be quick.
“Conduct regular phishing and social engineering awareness training for all employees, including realistic simulations that account for AI-generated text, voice and video lures. Invest in ongoing skill development for staff through recognised industry certifications. Build an internal community of practice for AI security and designate AI security champions in each business unit,” the Cert-In advisory said.