惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
DataBreaches.Net
GbyAI
GbyAI
aimingoo的专栏
aimingoo的专栏
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
月光博客
月光博客
大猫的无限游戏
大猫的无限游戏
M
MIT News - Artificial intelligence
腾讯CDC
博客园 - Franky
Engineering at Meta
Engineering at Meta
C
Check Point Blog
T
The Blog of Author Tim Ferriss
有赞技术团队
有赞技术团队
Microsoft Azure Blog
Microsoft Azure Blog
MyScale Blog
MyScale Blog
I
InfoQ
Blog — PlanetScale
Blog — PlanetScale
P
Proofpoint News Feed
The GitHub Blog
The GitHub Blog
N
Netflix TechBlog - Medium
Last Week in AI
Last Week in AI
S
SegmentFault 最新的问题
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
WordPress大学
WordPress大学

MEDIANAMA

India in talks with US, Anthropic for Mythos access; no Indian firms in Project Glasswing yet Eternal Q4FY26: All Users Pay Higher Platform Fee, Only Some Get Discounts Amazon, Meta to challenge PhonePe-Google Pay dominance as UPI cap delayed since 2020 Meta failed to protect the safety of under-13s: European Commission If markets and regulators are ready for network slicing, we are ready: JIO Why defining ‘news’ won’t fix the free speech problems of draft IT Rules? #NAMA Eternal Q4FY26: Goyal Dismisses AI Disruption Risk as Zomato Quietly Builds Agentic Commerce Infrastructure Karnataka files appeal challenging the bike taxi ban lift in the Supreme Court How did WhatsApp turn 17 govt. flags into 9,400 digital arrest scam bans? Google Wallet integrates Aadhaar as digital ID, expands India’s mobile identity ecosystem Kerala HC issues notice on MediaOne’s Facebook page block in India MeitY warns VPN providers against enabling access to blocked betting platforms Shreya Singhal targeted private censorship. Today’s threat is the State #NAMA Amazon scales its quick delivery service ‘Amazon Now’ in 100 cities Can MeitY issue binding rules via advisories? Experts raise alarm over draft IT Rules #NAMA How 2019 election code of ethics became India’s three-hour content takedown mandate #NAMA Australia proposes new levy on big tech to fund news, opens draft law for consultation ‘judge, jury, executioner’: experts warn of Inter-Departmental Committee (IDC) overreach under New draft IT Rules Lowdown: TRAI flags low deployment under PM-WANI in public Wi-Fi consultation paper Why the NBFC licence matters for MobiKwik China blocks Meta-Manus deal, asserts origin-country jurisdiction: what this means for India ‘No transparency’: experts warn of expanding powers to block online speech in India #NAMA X launches standalone iOS messaging app XChat with encryption in India How India’s content takedown framework was built and where It has gone wrong #NAMA Claude Mythos puts India on alert: CERT-In, telcos, banks assess unprecedented cyber risks Explained: why did the RBI cancel Paytm’s banking licence? Meta now instantly blocks content in India Govt. asks ZEE5 to halt ‘Lawrence of Punjab’ web series release Online Gaming Rules notified, to be in effect from May 1, what are the major changes? RBI mandates additional factor authentication for e-mandates
After CBSE marking system, a researcher exposes the NTA r...
Azdhan · 2026-06-01 · via MEDIANAMA

“NTA’s Re-examination portal has a superadmin login bypass by using extremely weak credentials,” wrote Dubai-based cybersecurity researcher Rylen Anil. 

He further said that this vulnerability exposed the content related to Personally Identifiable Information (PII). “This exposes bulk user data: ~7.9k observers, 676 CCs, 5.4k CS/centers, including names, emails, and phone numbers,” he added. 

“Beyond leaking data, the bypass gives access to the superadmin dashboard itself. From there, the portal exposes admin functions to manage observers. It also has controls to export CSVs, generate/download appointment letters, upload templates, upload nodal officer mappings, etc.,” he further wrote on X. 

Source: Rylen Anil

At the time of writing this report, the URL shared by Anil is inaccessible. The 404 error notice read: “The requested URL was not found on this server.” However, after a few hours of Anil’s post, a X user posted a screenshot of the site being publicly accessible on a mobile network. 

CBSE’s Digilocker portal is also compromised: He posted another vulnerability in CBSE’s DigiLocker portal. He said that it “uses client-side AES encryption with a hard-coded passphrase.” “All the encryption logic is in a public JS file where anyone can read it. This makes the login encryption easy to copy and not a real security boundary,” he further added. He didn’t disclose if he had reported these incidents to NTA, CERT-IN, or CBSE.

What it means: CBSE’s DigiLocker portal encrypts login data using AES, a strong encryption standard, but does so entirely in the user’s browser using a fixed, hard-coded passphrase. He demonstrated that all the encryption logic, including that passphrase, is stored in a publicly readable JavaScript file that anyone can access using standard browser developer tools, rendering the protection meaningless. An attacker who intercepts login traffic already has everything needed to decrypt the encrypted keys, since the key and the algorithm are openly available within the JavaScript. 

What is NTA? NTA (National Test Agency) is India’s organisation responsible for conducting competitive national-level entrance examinations for various students. For example: 

  • NEET (for medical college admissions),
  • JEE Mains & Advanced (for engineering),
  • UGC NET (for university teaching positions),
  • CUET (for undergraduate and graduate admissions across central universities),
  • and various other exams for government jobs

Quick recap of CBSE’s recent vulnerability: On May 22, Nisarga Adhikary publicly exposed the security vulnerabilities of the Central Board of Secondary Education (CBSE) On-Screen Marking (OSM) system. He posted the blog after CERT-In failed to act to fix OSM’s systems, despite flagging the issue to India’s cybersecurity agency over three months ago.

After more than a week, on May 31, CBSE finally acknowledged the vulnerability and said, “an expert team of cybersecurity professionals has been deployed over the last few days.” They also claimed that identified vulnerabilities were contained and other exploitable weaknesses were being ruled out.

You can read MediaNama’s coverage of this incident here: [Link-1 | Link-2 ]

We have reached out to NTA, CERT-In and CBSE for a comment. We will update the copy if we receive a response.

AI disclosure: We used Claude to understand a few technical concepts. 

Also Read: