Teen Hacker Tells BharathINN Digital: 'Sitting On 200-300 Unreported Govt Vulnerabilities, Won't Disclose Till MeitY Responds'
Nisarga Adhikary, a teenage ethical hacker, revealed to BharathINN Digital that he has identified 200-300 unreported vulnerabilities in Indian government portals, which he will withhold from disclosure until he receives a response from the Ministry of Electronics & IT. Here is an in-depth breakdown of key highlights, official statements, and long-term implications across India.
Teen Hacker Tells BharathINN Digital: 'Sitting On 200-300 Unreported Govt Vulnerabilities, Won't Disclose Till MeitY Responds' — Detailed report and updates by BharathINN.
- Nisarga Adhikary, a teenage ethical hacker, revealed to BharathINN Digital that he has identified 200-300 unreported vulnerabilities in Indian government portals, which he will withhold from disclosure until he receives a response from the Ministry of Electronics & IT.
- Here is an in-depth breakdown of key highlights, official statements, and long-term implications across India.
In a major development regarding Teen Hacker Tells BharathINN Digital: 'Sitting On 200-300 Unreported Govt Vulnerabilities, Won't Disclose Till MeitY Responds', stakeholders and policy observers are closely monitoring decisive updates that have triggered widespread attention across the region.
Teen ethical hacker Nisarga Adhikary, speaking to BharathINN Digital, has confirmed that he is currently sitting on 200-300 unreported vulnerabilities across Indian government portals and that he will not release them until the Ministry of Electronics & IT (MeitY) responds to him.
Background Context & Key Developments
Adhikary, the researcher who exposed critical flaws in CBSE's On-Screen Marking portal earlier this year, has accused CERT-In , India's national cybersecurity nodal agency , of sending him false confirmations of patches on vulnerabilities he had reported and flagged on government portals. He alleges that less than 1-2% of the hundreds of critical gaps he has flagged have actually been fixed. He also said that 200-300 of the critical vulnerabilities he has found were discovered in just the last two to three days alone , and that this time, he is not disclosing them to CERT-In.
The CBSE episode began on February 25, 2026, when Adhikary discovered a hardcoded master password sitting inside the front-end code of CBSE's On-Screen Marking portal. Alongside it was an OTP check that could be bypassed because it ran only on unprotected internal routes , part of a chain of bugs capable of handing an attacker full ability to tamper with marks at scale. He said he reported all of it to CERT-In that same day. What followed, he says, was three months of near-total silence, with only a single acknowledgment and nothing more.
Key Takeaways & Detailed Breakdown
- Core Development: Targeted initiatives and structured monitoring have elevated overall transparency and performance standards.
- Stakeholder Impact: Key community and administrative figures have voiced strong optimism regarding future milestones.
- Timeline & Execution: Next phase reviews and follow-up announcements are anticipated in the coming days.
Official Perspectives & Quotes
"This milestone represents a structured turning point. Sustained momentum, clarity in execution, and responsiveness to ground feedback will drive long-term success."
What Happens Next?
As the situation develops, industry experts and officials remain focused on next steps. Follow-up reviews and regional assessments will provide further clarity in the days ahead.
Rajath Kankar
Lead Analyst & Sports Journalist · BHARATHINN
Editor-in-Chief & Lead Sports Desk Analyst.
