Particle.news
Download on the App Store

IIT Kanpur Hires 19-Year-Old Who Exposed Flaws in CBSE’s On‑Screen Marking Portal

The contractual appointment signals institutional recognition of hands‑on security research after the researcher helped audit and patch parts of the evaluation system.

Overview

  • IIT Kanpur confirmed it has recruited 19‑year‑old Nisarga Adhikary into C3iHub as an Open‑Source Intelligence and Threat Intelligence engineer on a contractual basis after senior faculty reviewed his work.
  • Adhikary publicly disclosed on May 22 that he had reported multiple OSM vulnerabilities to CERT‑In in February, including a hardcoded master password in plain text, client‑side OTP validation that could be bypassed, and missing route protections that allowed unauthorized access.
  • CBSE says the exposed site was a testing environment and that the live evaluation system was not compromised, while IIT Kanpur and IIT Madras deputed expert teams to audit the portal, patch some issues and ultimately take the service offline for remediation.
  • Press investigations raised questions about the OSM procurement, reporting that tender criteria were lowered before awarding the contract to Coempt Edu Teck and that submitted cybersecurity certificates did not reflect a production deployment.
  • Adhikary has said his pay is lower than he expected; IIT Kanpur says the hire illustrates a shift toward recruiting practical cyber talent and plans measures such as hackathon‑based intake and hands‑on training for future cybersecurity students.