Indian authorities have requested a 19-year-old security researcher to delay disclosing software vulnerabilities until they are resolved, sparking a heated exchange between the individual and the country's primary cybersecurity agency. The Indian Computer Emergency Response Team (Cert-In), which operates under the Ministry of Electronics and Information Technology (MeitY), reportedly issued a formal communication to Nisarga Adhikary, asking him to refrain from making public announcements regarding unresolved issues. Adhikary, known for exposing weaknesses in India's Central Board of Secondary Education (CBSE) online grading system earlier this year, responded strongly, rejecting the request and accusing Cert-In of inefficiency. According to Adhikary, he has submitted more than 200 vulnerability reports to Cert-In since February 2026, primarily targeting private sector systems. However, he claims that fewer than one percent of these have been addressed. In his response to Cert-In, Adhikary emphasized that his efforts are driven by a desire to improve security rather than cause harm. He further alleged that the agency is attempting to deter him from continuing his work and is seeking to claim credit for the vulnerabilities he has identified. A message from Cert-In, dated August 28, stated that Adhikary's disclosures were premature and urged him to limit public discussion on unresolved vulnerabilities. The agency requested that he involve them in any future disclosure timelines, referencing its Responsible Vulnerability Disclosure and Coordination Policy. This policy allows affected entities time to address flaws before they are made public. A senior MeitY official explained that public disclosure could potentially allow malicious actors to exploit the vulnerabilities, adding that the ultimate responsibility lies with the organizations owning the affected systems to implement necessary patches. Adhikary had been vocal on social media leading up to the incident. On August 28, he announced having over 100 critical security reports pending submission to Cert-In. Earlier in the week, he highlighted that critical vulnerabilities he had previously identified within police and law enforcement infrastructures remained unfixed despite repeated communications from Cert-In requesting retesting. His response to the agency referenced the CBSE case, asserting that those flaws might not have been corrected without his public intervention. Adhikary clarified that he typically provides organizations three to four weeks before disclosing vulnerabilities publicly and avoids sharing proof-of-concept code, reproduction steps, endpoints, or credentials. Despite these precautions, he maintains that the pressure to disclose publicly arises due to the slow pace of resolution by the relevant agencies. Cert-In did not provide immediate comments on Adhikary's allegations. Karan Saini, another independent security researcher based in New Delhi, echoed similar sentiments, stating that Cert-In has historically been slow and non-transparent, particularly concerning critical infrastructure. He pointed to delays in addressing vulnerabilities related to the Aadhaar database, Delhi Police’s ZIPNET system, the Right to Information (RTI) portal, and the Election Commission’s website. Saini argued that public disclosure often becomes the only effective method to ensure fixes are implemented promptly, noting that several of his reported vulnerabilities were only addressed after he disclosed sufficient details to draw attention to the issues.
★
Keep the news honest.
ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €4/month.
Become a Supporter