{
  "id": 4832865,
  "title": "Told to stop posting flaws, teen hacker uses govt email ID to troll Cert-In",
  "url": "https://urgent.news/2026/09/01/told-to-stop-posting-flaws-teen-hacker-uses-govt-email-id-to-troll",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-01T09:17:07.000Z",
  "source": {
    "name": "Hindustan Times",
    "slug": "hindustan-times",
    "url": "https://www.hindustantimes.com/india-news/told-to-stop-posting-flaws-teen-hacker-uses-govt-email-id-to-troll-certin-101788254228186.html"
  },
  "original_language": "en",
  "account": "Three days after the Indian Computer Emergency Response Team (Cert-In) requested a 19-year-old researcher to moderate his social media posts about unaddressed cyber vulnerabilities, the hacker showcased another possible security flaw. Nisarga Adhikary shared a screenshot on X displaying an email sent from a 'gov.in' email account to the government's cybersecurity coordinator and other government recipients. He claimed he discovered a flaw that allowed him to send emails from an official government account, though he did not disclose the department's name. Adhikary informed HT that the department disabled the affected subdomain but its email service remained accessible through a separate gov.in subdomain. He asserted that the exploit continued to function against the email service.\n\nAdhikary, who currently works as an Open-Source Intelligence (OSINT) and threat intelligence engineer at IIT Kanpur's C3iHub, stated that he has identified a fresh batch of over 100-150 critical findings related to gov.in and nic.in domains. He questioned MeitY's reaction to his previous email, implying that they would likely ignore serious concerns, just like Cert-In. Adhikary mentioned that he has been sending \"very critical zero day reports\" to the Indian Cybercrime Coordination Centre (I4C), the home ministry, and other concerned departments. He vowed to cease cooperation with Cert-In until his concerns were addressed. The screenshot shared by Adhikary on X displayed the email being sent to Cert-In, with a government email address as the sender. The email contained a sarcastic tone, addressing Cert-In and providing a link to a Charli XCX song titled 'White Mercedes'. The song's relatable theme of a dysfunctional relationship resonated with Adhikary, as he had been repeatedly sending vulnerability reports to Cert-In despite the agency's lack of action. On August 28, Cert-In sent Adhikary an email, asking him to refrain from publicizing vulnerabilities while they were being resolved, claiming his posts were \"premature\" and requesting coordination on disclosure timelines. Adhikary, who previously gained attention for breaching CBSE's online marking portal, refused to comply, labeling the agency \"incompetent.\" He previously alerted Cert-In about more than 200 vulnerabilities primarily affecting private companies, but less than 1% had been fixed. He also accused the agency of ignoring unpatched vulnerabilities in police and law-enforcement infrastructure, even after being informed that they were marked \"patched, please retest.\"",
  "summary": "Nisarga Adhikary has demonstrated another potential security lapse by sending an email from an official gov.in account to Cert-In and other govt recipients",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}