惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

大猫的无限游戏
大猫的无限游戏
云风的 BLOG
云风的 BLOG
小众软件
小众软件
V
V2EX
博客园 - Franky
博客园 - 司徒正美
Apple Machine Learning Research
Apple Machine Learning Research
量子位
博客园 - 【当耐特】
雷峰网
雷峰网
WordPress大学
WordPress大学
Jina AI
Jina AI
Google DeepMind News
Google DeepMind News
N
Netflix TechBlog - Medium
爱范儿
爱范儿
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
阮一峰的网络日志
阮一峰的网络日志
IT之家
IT之家
Blog — PlanetScale
Blog — PlanetScale
Hugging Face - Blog
Hugging Face - Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
V
Visual Studio Blog
Microsoft Security Blog
Microsoft Security Blog

The Hindu: Latest News today from India and the World, Breaking news, Top Headlines and Trending News Videos.

U.K. pauses its plan to cede Chagos Islands after U.S. opposition Driver jailed for 7 days for driving sleeper bus in drunken condition Kim Jong Un supports China’s “multipolar world” vision during talks with Wang Yi Uttar Pradesh boat tragedy: Punjab town mourns deaths Relief for Bengaluru commuters as Silk Board flyover set to open fully, but inspection by BTP reveals likely bottleneck Repolling underway at booth of Karimganj North Assembly seat in Assam PM Modi interacts with Rahul Gandhi as leaders gather to pay tribute to Mahatma Jyotiba Phule Anil Kapoor’s ‘24’ set to release on OTT Vance, Iranian delegation arrives in Islamabad for U.S. talks amid ceasefire hopes Fire at Hyderabad’s Chintal Basti apartment, 17 residents evacuated safely Centre nudges States to view farm solarisation as a route to wiping off ₹2.4 lakh crore subsidy bill Why voter turnout hit record highs in Assam, Kerala & Puducherry Strait of Hormuz to be open “fairly soon”, says Trump ‘Jana Nayagan’ leak tests new legal penalties, torrent downloads under scanner Vijay’s ‘Jana Nayagan’ controversy explained: From legal battles to piracy chaos HYDRAA brings down guest house and other structures at Ameenpur Row erupts over removal of Ambedkar statue at midnight in Secunderabad Cantonment area Nitish may resign as Bihar CM on April 13; son Nishant likely to become one of two JD(U) Dy CMs Police open fire on youth while he was trying to flee Struggling CSK look to snap their losing streak | Vidyut Sivaramakrishnan ED raids former Trinamool Minister Partha Chatterjee’s residence Karnataka’s Gruha Jyothi scheme dimmed the scope of PM’s Surya Ghar Muft Bijli Yojana: KRESMA After Artemis II, NASA looks to SpaceX, Blue Origin for Moon landings Ayush Shetty storms into Badminton Asia Championships final Scholarships: April 11, 2026 Andhra Pradesh’s Socio-Economic Survey missing in recent Budget Session; efforts underway Inside Péro’s fun office Penciljam sessions in Bengaluru help hone artistic talent Watch: The mistake killing high-concept films | Escalation without calibration | FMM 19 Tamil Nadu Assembly election 2026: DMK demands reinstatement of N. Muruganandam as Chief Secretary
CBSE says OnMark portal ‘vulnerabilities’ contained amid ...
Maitri Porecha · 2026-05-31 · via The Hindu: Latest News today from India and the World, Breaking news, Top Headlines and Trending News Videos.
CBSE said it was grateful to alert citizens and ethical hackers who pointed out such weaknesses and had contacted some of them directly. File

CBSE said it was grateful to alert citizens and ethical hackers who pointed out such weaknesses and had contacted some of them directly. File | Photo Credit: The Hindu

After public posts by ethical hackers exposed vulnerabilities in the Central Board of Secondary Education’s On-Screen Marking platform OnMark, the board on Sunday (May 31, 2026) stated that the identified vulnerabilities “have been contained and other exploitable weaknesses are being ruled out”.

The CBSE also said it was “grateful” to alert citizens for pointing out “such weaknesses”.

“We have been closely monitoring the vulnerabilities in the OnMark portal of our service provider that are being flagged in the public domain. An expert team of cybersecurity professionals has been deployed over the last few days from across various arms of the government as well as the IITs [Indian Institutes of Technology] to fortify these systems, including taking them over to a more secure set-up,” the CBSE said in an official statement on X. “The identified vulnerabilities have been contained, and other exploitable weaknesses are being ruled out.”

The CBSE’s statement comes after 19-year-old ethical hacker Nisarga Adhikary claimed that he had hacked the CBSE’s digital evaluation ecosystem.

Speaking with The Hindu, Mr. Adhikary said he felt “happy and satisfied” that the CBSE had finally acknowledged the vulnerabilities in its Information Technology (IT) ecosystem. “I had sent my first report to the CBSE on February 25, and within three to four days, they took the portal down. Six to seven vulnerabilities were still active and exploitable later but the CBSE did not respond to my e-mails. This was pretty frustrating. I noticed that the CBSE had poorly managed infrastructure and the passwords used were easy to guess,” Mr. Adhikary said. 

Earlier, the CBSE had rejected claims that its evaluation platform had been compromised. Mr. Adhikary had countered this claim. 

On May 30, Mr. Adhikary managed to hack into the CBSE’s Principals dashboard in the On-Screen Marking platform. “The dashboard and the portal had had 9.3 million columns and rows of sensitive student data, including images of answer sheets of students which lay unprotected and could be easily tampered with,” Mr. Adhikary further said. 

Mr. Adhikary has alleged that there are data sovereignty issues with how COEMPT Eduteck [the CBSE’s technology vendor] handled sensitive student exam data. He has alleged that an Amazon Web Services (AWS) bucket containing 2026 answer sheets and question papers could be accessed without authentication. 

“COEMPT should have ideally stored the data on their own servers, but they took the ‘cheap easy route,’ of storing answer sheets in Amazon Web Services public buckets without any security checks,” Mr. Adhikary stated. 

He further explained that sensitive data, including personal information of students, was processed by Google’s Gemini in automation scripts prepared by quality assurance engineers of COEMPT. 

Mr. Adhikary called this “scary” and “sad”, where a third party sends such data to the U.S. for processing. “Data Privacy Laws are not respected and they [the company] should get sued for doing this without student consent,” he further said. 

Published - May 31, 2026 04:48 pm IST