
India's cybersecurity agency CERT-In has issued a critical-severity advisory warning for Google Chrome users on Windows, Mac, and Linux systems, highlighting the urgent nature of cybersecurity vulnerabilities facing desktop users. According to Business Standard, the advisory covers Chrome versions prior to 148.0.7778.178/179 for Windows and Mac, and Chrome versions prior to 148.0.7778.178 for Linux. The vulnerabilities pose significant risks including remote code execution, unauthorised access to sensitive data, disruption of services, and privileged escalation. As per CERT-In, these vulnerabilities stem from User-after-free in WebRTC, GPU, QUIC, XR and DOM, Out-of-bounds read in GPU, Heap buffer overflow in WebRTC and Chromecast, Type confusion in GFX, Insufficient policy enforcement in Service Worker, Insufficient validation of untrusted input in Input, and inappropriate implementation of UI. A remote attacker could exploit these vulnerabilities by convincing a victim to open a specially crafted web request.
India is conducting comprehensive tests of its most sensitive public-facing financial and government application software to better understand vulnerabilities to Anthropic PBC's next-generation Mythos AI model. According to reports from NDTV, technology giants Infosys Ltd. and Tata Consultancy Services Ltd. are among companies carrying out the tests of their software for vulnerabilities in a secure environment to Mythos. Infosys in particular is looking to devise patches to its widely used Finacle banking software, while TCS is working on government login systems. The companies, which don't currently have access to Mythos, are using Anthropic's Claude Opus 4.7 AI software to patch vulnerabilities. This testing initiative comes as CERT-In warns that known exploited vulnerabilities affecting internet-facing 'crown jewel' systems should ideally be patched, mitigated, or isolated within 12 hours wherever feasible, with critical externally exposed vulnerabilities requiring addressment within one day.
According to NDTV, the Reserve Bank of India has convened domestic banks multiple times to remind them to remain vigilant about risks Mythos may bring. This enhanced vigilance comes as banks face potential exposure to the advanced AI model that could exploit existing vulnerabilities in their systems. The central bank's proactive approach reflects the serious nature of the security concerns surrounding Mythos and the need for financial institutions to maintain heightened security protocols. The CERT-In blueprint reinforces this urgency, emphasizing that cybersecurity programs built around periodic controls, fragmented visibility, and slow remediation cycles are unlikely to remain effective against machine-speed attacks. Last month, India's Finance Minister Nirmala Sitharaman said India was closely monitoring the potential threats posed by Mythos and asked banks to step up vigilance to secure IT systems, safeguard customer data, and protect financial resources.
As reported by NDTV, India's state-run cybersecurity agency CERT-In is undergoing tests of key digital infrastructure including the Aadhaar national ID program and government login systems. This comprehensive approach reflects the critical importance of protecting India's vast digital infrastructure, including the 1.4 billion citizens currently onboarded to the Aadhaar national ID program. Many of India's largest software companies provide services for both the Indian government and private firms globally, with Infosys running the country's service-tax system and TCS running its passport system. Infosys's Finacle provides software to financial firms globally, adding urgency to the need to identify cyber-vulnerabilities. India sees closer cooperation with the US as key to protecting sensitive infrastructure and government networks, while also reducing reliance on rivals such as China.
According to NDTV, India's risk assessments are the latest sign of unease among governments and corporate boardrooms around the world over Mythos, the powerful AI software developed by Anthropic to root out cybersecurity vulnerabilities, but which has raised global alarm over its own extraordinary ability to power potential cyberattacks. So far, Anthropic has limited access to Mythos to a select few companies including Apple Inc. and JPMorgan Chase & Co., allowing them to use the technology to test their own cyberdefenses under an initiative called Project Glasswing. Infosys CEO Salil Parekh told analysts that Mythos was "exposing more vulnerabilities than one thought possible previously" and could lead to new opportunities for the company to help clients address vulnerabilities. Anthropic has told Indian authorities that it's for the US government to decide if they would like to share the advance Mythos with any company or country, and if so when. US Ambassador to India Sergio Gor said Washington was reviewing some of India's requests but declined to provide specifics, stating that "as a trusted partner, those are some things that we are definitely looking at."
The CERT-In blueprint introduces detailed recommendations around AI governance, AI inventory visibility, AI risk assessments, AI API security, prompt injection defense, AI logging, adversarial testing, and oversight of autonomous AI systems. The regulator warns organizations against uncontrolled use of public AI platforms and explicitly recommends restricting uploads of sensitive enterprise data into publicly accessible AI systems. This language reflects growing concern around shadow AI, where employees independently use generative AI platforms without organizational governance or visibility. The document also places emphasis on software and AI supply-chain visibility, strongly advocating adoption of SBOMs, AIBOMs, QBOMs, and CBOMs to improve dependency visibility, provenance validation, exposure assessment, and coordinated remediation. The regulator's insistence on human oversight is equally notable, with recommendations to restrict fully autonomous critical actions and maintain approval mechanisms and auditability for AI-assisted decisions.