惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

量子位
Vercel News
Vercel News
Microsoft Azure Blog
Microsoft Azure Blog
爱范儿
爱范儿
N
Netflix TechBlog - Medium
Google DeepMind News
Google DeepMind News
H
Help Net Security
罗磊的独立博客
The Cloudflare Blog
J
Java Code Geeks
博客园 - 叶小钗
I
InfoQ
B
Blog
Blog — PlanetScale
Blog — PlanetScale
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
腾讯CDC
月光博客
月光博客
博客园_首页
雷峰网
雷峰网
M
MIT News - Artificial intelligence
博客园 - 【当耐特】
美团技术团队
T
The Blog of Author Tim Ferriss
博客园 - 司徒正美

Latest Business News, Business News India Today | The HinduBusinessLine

Draft CAFE-3 Norms: Govt eases penalties, focuses on carbon credit trading for auto sector Modi seeks opposition backing to implement women’s reservation before 2029 polls West Asia crisis: Ludhiana handtool export units face labour, gas supply shortages, high input costs Patent application filings in India rise 30.2% to 1.43 lakh in 2025-26: Goyal Meet the man with 138 degrees: Dashrath Singh, an ex-serviceman, earns latest qualification from IGNOU Europe missed AI bus, but India has potential to catch up: Former WEF Director AIG Hospitals, ICMR team up for digital health innovation Juno Joule Bio Fuels begins construction of compressed bio-gas project in Telangana Legendary playback singer Asha Bhosle dies at 92 Signature Global cuts net debt by 77% to ₹200 crore in FY26 Iran aims to restore majority of refining capability within two months Supreme Court to hear on Monday pleas related to SIR of electoral rolls in West Bengal US, India hold engagements to advance defence cooperation Trump shares article suggesting option with him to enforce naval blockade on Iran NCLAT reaffirms project-specific insolvency proceedings against realty firms Iran-US talks in Pakistan ended without deal as Tehran cites ‘excessive demands’ from US Two supertankers U-turn in Hormuz as US-Iran talks break down Time has come to implement Women's Reservation Act: PM Modi's letter to LS, RS floor leaders Iran war diverts US military, attention from Asia ahead of Trump's summit with China's leader Trump says China will have big problems if it ships arms to Iran India will soon become self-reliant in defence sector, find itself among leading nations of the world: Rajnath Singh Pakistan to continue facilitating US-Iran talks, says Dar; urges ceasefire More than 2,000 people killed by Israeli strikes in Lebanon during Israel-Hezbollah war: officials Iran denies US claims of mine clearing ships’ passage through Strait of Hormuz AI to reduce uncertainties and expand opportunities - RBI DG EAM Jaishankar meets members of Indian community in UAE 4 ways war in Iran has weakened United States in great power game US-Iran talks fail after 21 hours in Islamabad, JD Vance cites nuclear deadlock Delhi EV Policy: Electric 3-Wheelers Only by 2027, 2-Wheelers by 2028 Islamabad talks: US and Iran begin negotiations aimed at ending West Asia conflict
Government must act seriously on cybersecurity lapses in ...
By S Ronendra Singh · 2026-05-26 · via Latest Business News, Business News India Today | The HinduBusinessLine

A young ethical hacker, Nisarga Adhikary, has exposed a glaring vulnerability in India’s digital education infrastructure, demonstrating that a crucial Central Board of Secondary Education (CBSE) portal was left wide open to manipulation. As part of its ‘Digital India’ push, the CBSE recently transitioned to an online On-Screen Marking (OSM) system for Class 12 board exams, where examiners log in to evaluate scanned answer scripts. However, a major security failure by the system’s developer, Hyderabad-based Coempt EduTeck Pvt Ltd, left the platform so exposed that virtually anyone could have hacked in to alter student answer sheets. The security breakdown is compounded by a sluggish official response. When Adhikary discovered the flaws on February 25, 2026, he immediately alerted the Indian Computer Emergency Response Team (CERT-In) under the Ministry of Electronics and Information Technology (MeitY). Despite the high stakes, he received only a generic “Thank you” acknowledgement. Months after no corrective action was taken to secure the platform, Adhikary went public, detailing the vulnerabilities in a May 22 blog post. In an exclusive interview with businessline, Adhikary breaks down how he breached the system and the deeper institutional apathy that followed. Edited excerpts:

How did you get to know about the vulnerabilities of the CBSE portal? What kind of response did you get from CERT-In when you pointed out the vulnerabilities?

Back on February 25, while my own Class 12 Board exams were underway, CBSE announced that evaluation would be entirely digital. Out of sheer curiosity, I started looking into how the system worked. I opened the portal and began analyzing it. Because I didn’t have a login ID or password, I couldn't send standard requests, but I managed to extract the source code. That is when I discovered a hardcoded 'Master Password' that could bypass all authentication, regardless of the user ID. I found a valid user ID, paired it with the Master Password, and immediately gained access to the main dashboard where I could actively edit students' marks. I recorded the entire process and flagged it to CERT-In. Their response was a automated "Thank you for reporting”. A few days later, I reported five additional vulnerabilities. In response, they took the portal down for two or three days, removed the Master Password, and called it a day. But the remaining flaws were just as severe, and they left them completely untouched. That is why I decided to go public.

How easy was it hack into the system?

I have been doing ethical hacking for a long long time now. I am 19 now but when I was in sixth or seventh grade, I started experimenting with it. It is really easy for me and it will be just as easy for anyone, even those who have never tried hacking before, because it was just a really easy mistake on their side, lazy engineering and really bad at what they did.

What about this company that had developed this website, did you tell them their mistakes?

Yes, I also contacted the company. But they did not reply. Actually, this company has a bad track record. They used to be known as something else in 2019, and they did a similar kind of goof-up and it resulted in major howlers, students committing suicides. I think it was Telangana State Board exams.

So what is your message to the government or authorities because such incidents keep happening now and youngsters are suffering?

I just hope that they take us a little bit seriously. This has happened because of their negligence. This needs to be audited properly by them. I reported it several times, urging them to take it seriously. I just hope they become a little more serious and they start caring more about cybersecurity and data privacy. We’re also seen a lot of leaks happening in India, and government didn’t take any action and that is serious negligence.

Going forward, what kind of future do you see for yourself? What do you want to pursue as a career?

I want to be an engineer...cybersecurity is just a hobby for me. I’ll do engineering. I also did many internships and jobs in the past, mostly in software-related roles.

Published on May 26, 2026