How Frontier AI is Transforming Vulnerability Discovery in India, ETCISO
India’s digital transformation—driven by the India Stack, UPI, and an aggressive push toward a digital-first economy—has made our infrastructure globally competitive. But this hyperconnectivity also makes us a prime target. The theoretical debate around AI in cybersecurity is officially over. Frontier AI is no longer just a tool for assisting security research—it is changing the speed, scale, and nature of vulnerability discovery.
Recent research by Unit 42 into autonomous vulnerability discovery offers a clearer view of how this shift is taking shape. Our two-month evaluation used Network and Open-Source Vulnerability Analyzer (NOVA), a fully autonomous, agentic system designed to analyze software history, identify candidate flaws, generate working proof-of-concept (PoC) exploits, validate them, and produce disclosure reports with zero human intervention until final review.
The findings point to a significant shift in the software security landscape, with implications for Indian enterprises, technology providers, and regulators alike.
The automation of zero-day discovery
In just weeks, the evaluation covered 3,915 open-source software (OSS) projects across six major ecosystems and identified 14,090confirmed vulnerabilities.
To put this into perspective, 99.4% of these vulnerabilities had not been previously reported as zero-days. Work that once required years of highly specialized, manual research can now be carried out across thousands of targets through an autonomous process.
Historically, automated discovery techniques such as fuzzing and OS-Fuzz have been highly effective at finding crash-oriented bugs, which accounted for only 8% of the findings. The remaining 92% were logic and semantic vulnerabilities, including complex access-control flaws, path traversals, and request forgeries. The findings indicate that frontier AI can also be applied to more nuanced, logic-based vulnerability classes that have traditionally required significant human expertise.
The supply chain ripple effect
The findings also highlight the extent to which vulnerability risk can extend beyond individual applications. Of the more than 14,000 flaws, over 5,400 were supply-chain findings. The evaluation identified 1,280 vulnerabilities deeply embedded within dependency packages, which subsequently created thousands of downstream software exposures.
For global enterprises, Indian IT giants, and fintech startups alike, many of which rely heavily on open-source libraries to innovate at speed, this represents a critical vulnerability vector. A flaw in a low-level package can cascade into the applications that rely on it. As vulnerability discovery becomes more automated, weaknesses in foundational software components can be identified at a scale that makes supply-chain exposure increasingly difficult to assess through manual processes alone.
Patching reality and the shift to risk-based priority
Let’s be candid: telling an organization to “just patch faster” in the face of this AI-driven vulnerability burst is fundamentally disconnected from reality.
Patching is notoriously difficult. IT and security teams are constantly hampered by end-of-life (EOL) and end-of-service (EOS) systems, complex vendor dependencies, and the risk of breaking critical legacy applications. When adversary AI accelerates discovery, the time available to assess and respond to vulnerabilities can shrink significantly. Adversaries can now reverse-engineer patches and develop exploits automatically, potentially compressing the industry-average 55-day patching window into a near-zero window of exposure. Our research also found that a patch can be reverse-engineered in less than 15 minutes, on average.
This is because patching alone simply cannot address this challenge. Organizations must prioritize building layered security architectures and risk-based approaches to vulnerability management. How threats are triaged and risk is assessed must evolve in this new age. It is no longer enough to let a static CVSS score dictate prioritization. Instead, priority must be defined by contextual risk—evaluating actual exposure, business impact, and exploitability within a specific environment, rather than relying solely on standardized scores.
Risk-based governance has always been at the core of business. In today’s frontier-AI cyber era, however, these risks increasingly need to be assessed in near real time, with AI helping organizations process, correlate, and contextualize the volume of information involved. This makes tools that provide rich telemetry, integrate data across security environments, and leverage AI-enabled systems increasingly important.
Navigating India’s aggressive regulatory mandates
In India, this operational reality also intersects with stringent and fast-moving regulatory mandates. The government is already recognizing the evolving frontier AI threat and acting decisively. Since April 2026, following the launch of Anthropic’s Mythos, the emergence of AI-enabled cyber threats has added further urgency to the conversation around cyber resilience.
Advisories from the Computer Emergency Response Team of India (CERT-In) and regulators have been clear: organizations must build robust defenses, reduce dependencies, improve their ability to respond quickly, and report incidents promptly.
For example, the Reserve Bank of India (RBI) requires commercial banks and NBFCs to report cyber incidents on the DAKSH platform within six hours of detection. Meeting a six-hour reporting window depends not only on the ability to respond, but also on how quickly an organization can identify, understand, and assess an incident. Relying on manual triage or legacy logging can make it more difficult to meet these requirements consistently.
The way forward: Securing the digital frontier
The era of relying solely on manual vulnerability management is over. Organizations can no longer rely on rigid patching cycles or static metrics to protect their environments. As AI continues to expand offensive capabilities, defensive approaches will need to evolve alongside them. The vulnerability management system must be real time risk based – integrating threat intelligence, asset value and exposure, exploitability factors, and overall business impact.
With prioritization driven by machine-led, risk-based systems, organizations must build highly resilient, layered architectures that can withstand a zero-day strike even when a system cannot be immediately patched. This means leveraging AI defensively, using it to continuously monitor environments, contextualize risk, implement virtual patching, and automate incident response before an exposure becomes a breach.
The findings from the NOVA evaluation point to a threat environment in which vulnerability discovery is becoming faster, more scalable, and increasingly automated. The implication is straightforward: cyber resilience is no longer an IT cost centre, its operation critical for organizations participating in India’s digital economy.
The author is Cdr Raj Shastrakar (retd), Director, Head Unit 42, India & SAARC.
Disclaimer: The views expressed are solely of the author and ETCISO does not necessarily subscribe to it. ETCISO shall not be responsible for any damage caused to any person/organization directly or indirectly.
Firewall Security Company India Complete Firewall Security Solutions Provider Company in India












