Nisarga Adhikary, the 19-year-old cybersecurity researcher who discovered serious vulnerabilities in CBSE’s OSM portal earlier this year, has now been included in the US Department of Justice (DoJ)’s Cybersecurity Hall of Fame. Nisarga said the recognition came after he identified a major security flaw in one of the department’s systems.
“I found a critical vulnerability in one of their largest law enforcement systems,” Nisarga told India Today Tech. The teenager was unable to disclose details about the vulnerability or identify the affected system. However, he said the DoJ addressed the issue soon after receiving his report.
“I reported the vulnerability roughly a week ago, they validated and patched this within a week and credited me on their Hall of Fame/acknowledgements page,” he said.
Nisarga also posted a screenshot on X of the DoJ’s acknowledgements page, which lists researchers who have responsibly reported valid security vulnerabilities to the department.
[Nisarga]
Nisarga shared the update on X.
Explaining how he discovered the critical vulnerability, Nisarga said, “I found this myself when browsing their site and by using some custom scripts.” Such scripts are typically programmes developed by researchers themselves to detect potential security weaknesses, rather than relying on commercially available or off-the-shelf tools.
The 19-year-old also said he was not paid for identifying and reporting the vulnerability.
Nisarga says he also reported flaw to US Military
Nisarga Adhikary said his work has not been limited to the US Department of Justice. He confirmed that he has reported other vulnerabilities to American authorities, including the US military.
“I found a vulnerability in US Department of Defense/US military system,” he said. “I reported it and after validation, they found it was valid. Remediation is still under way though.”
Remediation refers to the process through which an organisation investigates, verifies and fixes a reported security vulnerability.
Nisarga has also received a “Thanks” acknowledgement from the US Department of Defense on HackerOne, a widely used platform for reporting cybersecurity vulnerabilities. He said he has identified and reported additional flaws to US authorities as well, adding that his curiosity has played a major role in helping him uncover such issues.
Nisarga first attracted widespread attention in May after discovering vulnerabilities in CBSE’s Online Submission of Marks (OSM) portal. He found that answer sheets belonging to students could be accessed online without proper verification. Following the CBSE episode, Nisarga was hired by C3iHub at IIT Kanpur as an open-source intelligence (OSINT) and Threat Intelligence Engineer.
