ON
← Back to feed
Cert-In asks teen researcher to hold off public vulnerability disclosures
India🏛️ PoliticsLean Progressive3 hr. ago

Cert-In asks teen researcher to hold off public vulnerability disclosures

A 19-year-old cybersecurity researcher named Nisarga Adhikary has criticized India's Cybersecurity Agency (Cert-In) for allegedly discouraging him from disclosing software vulnerabilities. Adhikary, known for previously breaching the CBSE online marking system, claims he has reported over 200 vulnerabilities to Cert-In since 2026, with less than 1% resolved. Cert-In requested he delay public disclosure until fixes are implemented, which Adhikary rejected, accusing the agency of incompetence and intimidation. He argued that public exposure was necessary to ensure vulnerabilities are addressed, especially in critical systems like law enforcement infrastructure. Cert-In cited its Responsible Vulnerability Disclosure policy, emphasizing the need for organizations to patch issues before public release. Independent researcher Karan Saini supports Adhikary, stating Cert-In has been slow and opaque in addressing vulnerabilities affecting sensitive systems.

Indian authorities have requested a 19-year-old security researcher to delay disclosing software vulnerabilities until they are resolved, sparking a heated exchange between the individual and the country's primary cybersecurity agency. The Indian Computer Emergency Response Team (Cert-In), which operates under the Ministry of Electronics and Information Technology (MeitY), reportedly issued a formal communication to Nisarga Adhikary, asking him to refrain from making public announcements regarding unresolved issues. Adhikary, known for exposing weaknesses in India's Central Board of Secondary Education (CBSE) online grading system earlier this year, responded strongly, rejecting the request and accusing Cert-In of inefficiency. According to Adhikary, he has submitted more than 200 vulnerability reports to Cert-In since February 2026, primarily targeting private sector systems. However, he claims that fewer than one percent of these have been addressed. In his response to Cert-In, Adhikary emphasized that his efforts are driven by a desire to improve security rather than cause harm. He further alleged that the agency is attempting to deter him from continuing his work and is seeking to claim credit for the vulnerabilities he has identified. A message from Cert-In, dated August 28, stated that Adhikary's disclosures were premature and urged him to limit public discussion on unresolved vulnerabilities. The agency requested that he involve them in any future disclosure timelines, referencing its Responsible Vulnerability Disclosure and Coordination Policy. This policy allows affected entities time to address flaws before they are made public. A senior MeitY official explained that public disclosure could potentially allow malicious actors to exploit the vulnerabilities, adding that the ultimate responsibility lies with the organizations owning the affected systems to implement necessary patches. Adhikary had been vocal on social media leading up to the incident. On August 28, he announced having over 100 critical security reports pending submission to Cert-In. Earlier in the week, he highlighted that critical vulnerabilities he had previously identified within police and law enforcement infrastructures remained unfixed despite repeated communications from Cert-In requesting retesting. His response to the agency referenced the CBSE case, asserting that those flaws might not have been corrected without his public intervention. Adhikary clarified that he typically provides organizations three to four weeks before disclosing vulnerabilities publicly and avoids sharing proof-of-concept code, reproduction steps, endpoints, or credentials. Despite these precautions, he maintains that the pressure to disclose publicly arises due to the slow pace of resolution by the relevant agencies. Cert-In did not provide immediate comments on Adhikary's allegations. Karan Saini, another independent security researcher based in New Delhi, echoed similar sentiments, stating that Cert-In has historically been slow and non-transparent, particularly concerning critical infrastructure. He pointed to delays in addressing vulnerabilities related to the Aadhaar database, Delhi Police’s ZIPNET system, the Right to Information (RTI) portal, and the Election Commission’s website. Saini argued that public disclosure often becomes the only effective method to ensure fixes are implemented promptly, noting that several of his reported vulnerabilities were only addressed after he disclosed sufficient details to draw attention to the issues.

2 reports

Hindustan Times logoHindustan TimesIndependentCenter3 hr. ago
How NEET portal flaws flagged by a teen led to IIT Kanpur job

Rylen Anil, a 16-year-old student in India, discovered security vulnerabilities in the National Testing Agency's NEET re-examination portal and the JEE Advanced website managed by IIT Roorkee. After reporting these issues through proper channels, including CERT-In, authorities acted swiftly to address them. As a result of his findings, Anil was offered a remote position as a junior cybersecurity engineer at IIT Kanpur's cybersecurity innovation hub, C3iHub. This made him the youngest individual ever hired by an IIT. The hiring process required additional time due to legal requirements for minors, with his father acting as a guardian. Anil's work involves conducting security analyses of web portals under supervision.

Bias read (Center): The article presents a factual account of a young individual's technical achievement and its impact on institutional processes. While it highlights a significant accomplishment and the involvement of governmental agencies like CERT-In, there is no overt ideological framing or emphasis on political立场

Hindustan Times logoHindustan TimesIndependentProgressiveyesterday
Cert-In asks teen researcher to hold off public vulnerability disclosures

A 19-year-old cybersecurity researcher named Nisarga Adhikary has criticized India's Cybersecurity Agency (Cert-In) for allegedly discouraging him from disclosing software vulnerabilities. Adhikary, known for previously breaching the CBSE online marking system, claims he has reported over 200 vulnerabilities to Cert-In since 2026, with less than 1% resolved. Cert-In requested he delay public disclosure until fixes are implemented, which Adhikary rejected, accusing the agency of incompetence and intimidation. He argued that public exposure was necessary to ensure vulnerabilities are addressed, especially in critical systems like law enforcement infrastructure. Cert-In cited its Responsible Vulnerability Disclosure policy, emphasizing the need for organizations to patch issues before public release. Independent researcher Karan Saini supports Adhikary, stating Cert-In has been slow and opaque in addressing vulnerabilities affecting sensitive systems.

Bias read (Progressive): The article frames Cert-In's actions as obstructive and incompetent, highlighting systemic failures in cybersecurity governance. The emphasis on the researcher's 'good faith' and the critique of bureaucratic inefficiency aligns with progressive critiques of state institutions. While the subject is a

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €4/month.

Become a Supporter

Related stories