Washington DC; September 2026: 19-year-old Indian cybersecurity researcher Nisarga Adhikary who had flagged CBSE security gaps has now been honoured by the…
Washington DC; September 2026: 19-year-old Indian cybersecurity researcher Nisarga Adhikary who had flagged CBSE security gaps has now been honoured by the US Justice Department for responsibly reporting a critical security vulnerability
Nisarga Adhikary said he has discovered a critical vulnerability in one of the US Department of Justice’s law-enforcement systems while researching its website. He reportedly submitted a vulnerability report to the department, which he said validated the finding and patched the issue within a week
Adhikary shared a screenshot of the department’s cybersecurity acknowledgements page on X. The page credits researchers who have responsibly disclosed valid vulnerabilities to the department, while further asserting that he has not received any payment for reporting the flaw
The discovery pertinent to the Department Of Justice was not Adhikary’s first reported vulnerability involving US government systems. He has reiterated that he had also identified a vulnerability in a US Department of Defense or military system and reported it to the relevant authorities. “I found a vulnerability in the US Department of Defense/US military system. I reported it and after validation, they found it was valid. Remediation is still under way though”, he said
Adhikary has also received a “Thanks” acknowledgement from the US Department of Defense through HackerOne, a platform used by organisations to receive vulnerability reports from security researchers
He has not disclosed technical details of the vulnerabilities or identified the affected systems
Adhikary have first attracted attention in India in 2026 after reporting security vulnerabilities in the Central Board of Secondary Education’s Online Submission of Marks (OSM) portal. He said he reported the issues to CERT-In in February before publishing details of his findings in May. His findings raised concerns about the security of examination data on the platform. Following the CBSE episode, Adhikary joined IIT Kanpur’s C3iHub as an OSINT and Threat Intelligence Engineer
His career in cybersecurity began several years earlier. According to his LinkedIn profile, his first internship was with the New Delhi Space Society in 2023, where he worked as a web developer. He later founded and led a Hack Club before working with technology companies including Skann, Cypherock and Wavelength. At 19, his journey has taken him from identifying security issues in India’s examination infrastructure to working in OSINT and threat intelligence at IIT Kanpur and reporting vulnerabilities to US government agencies
‘Rank is not competence’ - Adhikary’s growing cybersecurity career has also shaped his criticism of India’s education system






टिप्पणियाँ 0