1 hr ago
Nisarga Adhikary’s Cybersecurity Work Brings Recognition and IIT Job
Nisarga Adhikary is a 19-year-old who likes learning how computer systems work.
While examining CBSE’s online exam-marking system, he said he found security weaknesses.
He reported what he found to India’s cybersecurity response agency.
His findings drew public attention, and CBSE later said it was monitoring vulnerabilities and working to strengthen the system.
Nisarga also received an acknowledgement from the US Department of Justice for reporting a security flaw in its systems.
He now works at a cybersecurity hub at IIT Kanpur.
His job includes looking for and understanding possible security threats.
He says the recognition did not feel like a major personal milestone.
At 19, Nisarga Adhikary received an email from the US Department of Justice acknowledging his report of a security flaw.
He said he found alleged weaknesses in CBSE’s On-Screen Marking system, including an OTP bypass and misconfigured storage that exposed about 1.8 million scanned answer sheets.
Nisarga reported his findings to CERT-In in February and published a detailed account in May.
CBSE initially denied that its portal had been compromised, then said it was monitoring reported vulnerabilities and had deployed cybersecurity professionals to strengthen the system.
Nisarga joined C3iHub, IIT Kanpur’s cybersecurity-focused innovation hub, as an Open-Source Intelligence and Threat Intelligence Engineer.
- Who
- Nisarga Adhikary, a 19-year-old cybersecurity researcher from Siliguri, West Bengal.
- What
- He reported alleged security weaknesses in CBSE’s On-Screen Marking system, received US Department of Justice recognition for reporting a separate flaw, and joined C3iHub at IIT Kanpur.
- Where
- The CBSE system and US Department of Justice systems; Nisarga is now at IIT Kanpur in Kanpur, India.
- When
- The CBSE findings were reported in February and described publicly in May; the US Department of Justice email arrived on September 22, with no year specified in the article.
- Why
- He says he examines systems out of curiosity and to understand how they work.
Nisarga’s findings
CBSE’s response
Whether the portal was compromised
Nisarga’s findings
Nisarga said he found weaknesses including an OTP bypass and access to poorly configured storage containing about 1.8 million scanned answer sheets.
CBSE’s response
CBSE initially denied that its OSM portal had been compromised; it later said cybersecurity issues had been flagged publicly and that it was monitoring vulnerabilities and strengthening the system.
Accessing a teacher’s account
Nisarga’s findings
Nisarga said he accessed a physics teacher’s account to demonstrate the vulnerability, blurred the teacher’s details, and used the access only for that demonstration.
CBSE’s response
The article does not report a specific response from CBSE or the teacher to this demonstration.
Key facts
- Age
- 19
- Hometown
- Siliguri, West Bengal
- CBSE system examined
- On-Screen Marking (OSM), used to evaluate scanned answer sheets
- Reported exposure
- About 1.8 million scanned answer sheets, according to Nisarga
- Reported to
- Indian Computer Emergency Response Team (CERT-In), in February
- IIT Kanpur role
- Open-Source Intelligence and Threat Intelligence Engineer at C3iHub
- CBSE response
- The board said it was monitoring vulnerabilities and had deployed cybersecurity professionals to fortify the system.
Quotes
Nisarga Adhikary
A 19-year-old cybersecurity researcher from Siliguri, now working at IIT Kanpur’s C3iHub.
“I love to break stuff. Hacking things is a part of me trying to understand how things work.”
indianexpress.com
“I was unamused. It was like any other normal Hall of Fame mention for me.”
indianexpress.com









