惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

量子位
Recent Announcements
Recent Announcements
D
Docker
V
V2EX
阮一峰的网络日志
阮一峰的网络日志
Vercel News
Vercel News
Microsoft Security Blog
Microsoft Security Blog
The GitHub Blog
The GitHub Blog
U
Unit 42
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
月光博客
月光博客
腾讯CDC
B
Blog
博客园_首页
罗磊的独立博客
D
DataBreaches.Net
IT之家
IT之家
酷 壳 – CoolShell
酷 壳 – CoolShell
L
LangChain Blog
aimingoo的专栏
aimingoo的专栏
MongoDB | Blog
MongoDB | Blog
GbyAI
GbyAI
Stack Overflow Blog
Stack Overflow Blog
M
MIT News - Artificial intelligence

The Hindu: Latest News today from India and the World, Breaking news, Top Headlines and Trending News Videos.

U.K. pauses its plan to cede Chagos Islands after U.S. opposition Driver jailed for 7 days for driving sleeper bus in drunken condition Kim Jong Un supports China’s “multipolar world” vision during talks with Wang Yi Uttar Pradesh boat tragedy: Punjab town mourns deaths Relief for Bengaluru commuters as Silk Board flyover set to open fully, but inspection by BTP reveals likely bottleneck Repolling underway at booth of Karimganj North Assembly seat in Assam PM Modi interacts with Rahul Gandhi as leaders gather to pay tribute to Mahatma Jyotiba Phule Anil Kapoor’s ‘24’ set to release on OTT Vance, Iranian delegation arrives in Islamabad for U.S. talks amid ceasefire hopes Fire at Hyderabad’s Chintal Basti apartment, 17 residents evacuated safely Centre nudges States to view farm solarisation as a route to wiping off ₹2.4 lakh crore subsidy bill Why voter turnout hit record highs in Assam, Kerala & Puducherry Strait of Hormuz to be open “fairly soon”, says Trump ‘Jana Nayagan’ leak tests new legal penalties, torrent downloads under scanner Vijay’s ‘Jana Nayagan’ controversy explained: From legal battles to piracy chaos HYDRAA brings down guest house and other structures at Ameenpur Row erupts over removal of Ambedkar statue at midnight in Secunderabad Cantonment area Nitish may resign as Bihar CM on April 13; son Nishant likely to become one of two JD(U) Dy CMs Police open fire on youth while he was trying to flee Struggling CSK look to snap their losing streak | Vidyut Sivaramakrishnan ED raids former Trinamool Minister Partha Chatterjee’s residence Karnataka’s Gruha Jyothi scheme dimmed the scope of PM’s Surya Ghar Muft Bijli Yojana: KRESMA After Artemis II, NASA looks to SpaceX, Blue Origin for Moon landings Ayush Shetty storms into Badminton Asia Championships final Scholarships: April 11, 2026 Andhra Pradesh’s Socio-Economic Survey missing in recent Budget Session; efforts underway Inside Péro’s fun office Penciljam sessions in Bengaluru help hone artistic talent Watch: The mistake killing high-concept films | Escalation without calibration | FMM 19 Tamil Nadu Assembly election 2026: DMK demands reinstatement of N. Muruganandam as Chief Secretary
When students audit the system
The Hindu Bureau · 2026-06-01 · via The Hindu: Latest News today from India and the World, Breaking news, Top Headlines and Trending News Videos.

After public posts by ethical hackers exposed vulnerabilities in the Central Board of Secondary Education’s On-Screen Marking platform OnMark, the board on Sunday (May 31, 2026) stated that the identified vulnerabilities “have been contained and other exploitable weaknesses are being ruled out”. As per the official statement, an expert team of cybersecurity professionals has been deployed from across various arms of the government as well as the IITs to fortify CBSE’s systems.

The CBSE said it was “grateful” to alert citizens for pointing out “such weaknesses”. The citizens being two teenagers who explored the vulnerabilities in the CBSE’s systems. Sarthak Sidhant, a 17-year-old Class 12 student from Jharkhand, published an investigative blog ‘How CBSE rewrote rules to favour Coempt EduTeck’, which probed the dilution of the tender for an allegedly favourable vendor for OSM evaluation. Another, 19-year-old, Nisarga Adhikary, an ethical hacker who claims to have hacked into the OSM portal, and was able to read, write and edit answer sheets.

Mr. Adhikary claimed that he had hacked the CBSE’s digital evaluation ecosystem. He explained that personal information of students was processed by Google’s Gemini in automation scripts prepared by quality assurance engineers of COEMPT. 

After the results were declared, many Class 12 students alleged scoring discrepancies and also claimed that the scanned copies of their answer sheets uploaded by the Board did not match their handwriting, taking to social media to raise concerns over a possible mix-up in the OSM system.

John Xavier, Technology Editor, The Hindu, who interviewed both Mr. Sidhant and Mr. Adhikary, talks to us about key takeaways from their conversation.

What do you think of what Mr. Sidhant and Mr. Adhikary saying?

Nisarg and Sarthak were investigating two different aspects of the CBSE system. Nisarg’s focus is on how the digital infrastructure is built, managed and run. He notes that when he hacked into the OSM portal, he was able to read, write and edit documents (answer sheets).

Sarthak’s probe was focused on the dilution of the tender to suit a particular vendor. He mentions about 15 points to show how this process was tweaked to favour Coempt. 

Were you surprised by what they said at how robust or not robust the systems are?

I was surprised by Nisarga’s finding that he spotted traces of Gemini API in the CBSE portal. He claims that personally identifiable data of students was being shared with an AI model that has its server outside India. This is a clear data sovereignty issue. 

What is your take on how things can be made better?

Creating an audit cum review based system is a definite must. Perhaps, a reputed professional firm, like KPMG, Deloitte or EY, must be allowed to do an independent audit of CBSE’s digital systems. Secondly, students must be made aware of the changes well in advance. And large scale changes should be made only after running several pilots in different regions in the country. 

Do you think the CBSE portal internal architecture is typical of govt tech operations affecting people?

I can’t comment on this as I’m not aware of whether CBSE’s portal is similar to other government sites. But, one thing is clear, CBSE must have far greater security safeguards in place as it handles sensitive data of lakhs of Indian students.

Published - June 01, 2026 03:36 pm IST