Cert-In asks teen researcher to hold off public vulnerability disclosures
The Indian Computer Emergency Response Team (Cert-In), the government’s cybersecurity nodal agency, has asked a 19-year-old security researcher to hold off on publicising vulnerabilities while they are being fixed — a request the researcher rejected in a sharply worded reply accusing the agency of incompetence
The Indian government's cybersecurity agency, Cert-In, has requested that a 19-year-old security researcher, Nisarga Adhikary, delay public disclosure of vulnerabilities they have reported, accusing him of premature comments. Adhikary, who has disclosed over 200 vulnerabilities since February 2026, mostly involving private companies, has rejected the request in a strongly worded response, claiming the agency displays incompetence.
Adhikary has flagged vulnerabilities in various systems including CBSE, police infrastructure, and public sector portals, but less than 1% have been fixed. He alleges Cert-In is attempting to intimidate him and take credit for the vulnerabilities he has exposed. Cert-In's email to Adhikary, dated August 28, deemed his posts "premature" and requested he limit public commentary on unresolved vulnerabilities while informing the agency about disclosure timelines.
This request aligns with Cert-In's Responsible Vulnerability Disclosure and Coordination Policy, which aims to give companies time to resolve issues before public disclosure. However, Adhikary argues that public disclosure was crucial in previous cases, such as the CBSE episode, where flaws remained unfixed despite his private reporting.
He further stated he adheres to a three-to-four-week public disclosure window and never posts exploitative code or sensitive details. Independent researcher Karan Saini echoed similar sentiments, criticizing Cert-In's slow and opaque handling of vulnerabilities, particularly those impacting Aadhaar, Delhi Police systems, and government websites.
He contends that public disclosure is often the most effective way to prompt timely fixes, as demonstrated by cases where vulnerabilities only received attention after Adhikary's public disclosure.
Written by urgent.news from Hindustan Times's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.