The cybersecurity researcher had earlier shot to prominence after uncovering vulnerabilities in CBSE’s online marks portal  
Exclusive

Exposing CBSE flaws to securing US DoJ, 19-year-old Indian hacker Nisarga in Hall of Fame

Nineteen-year-old Nisarga Adhikary had reported a critical vulnerability in a major US law-enforcement system that was patched within a week

CBSE teen hacker Nisarga enters US Justice Department Hall of Fame after flagging critical flaw

Nineteen-year-old Indian cybersecurity researcher Nisarga Adhikary, who came into the spotlight after exposing vulnerabilities in the CBSE’s Online Submission of Marks portal earlier this year, has been named in the US Department of Justice’s cybersecurity Hall of Fame after reporting what he described as a critical flaw in one of its major law-enforcement systems.

Adhikary said he discovered the vulnerability while browsing the department’s website and using custom scripts, and subsequently reported it to US authorities. The Justice Department validated the vulnerability and patched it within about a week before adding his name to its acknowledgements page for researchers who responsibly disclose valid security flaws.

Flaw fixed within week

“I found a critical vulnerability in one of their largest law enforcement systems,” Adhikary said, without revealing the nature of the vulnerability or identifying the affected system because of security considerations.

He said he reported the issue roughly a week before receiving the recognition. “They validated and patched this within a week and credited me on their Hall of Fame/acknowledgements page,” he said.

Adhikary said he did not receive any monetary reward for the discovery. Instead, the recognition came through his inclusion on the department’s acknowledgements page.

Explaining how he came across the flaw, the teenager said he discovered it himself while browsing the site and using custom scripts — programmes developed by researchers to identify potential vulnerabilities rather than relying solely on ready-made security tools.

US military flaw reported

Adhikary said the Justice Department vulnerability was not the only security issue he had reported to US authorities. He also claimed to have identified a vulnerability in a US Department of Defense system.

“I found a vulnerability in US Department of Defense/US military system,” he said, adding that the issue had been reported and subsequently validated. Remediation of that vulnerability was still underway, he said.

Adhikary has also received a “Thanks” acknowledgement from the US Department of Defense on HackerOne, a platform widely used by organisations and cybersecurity researchers for responsible vulnerability disclosure.

He said curiosity had been central to finding such security gaps and that he had reported other vulnerabilities to US authorities as well.

CBSE discovery brought spotlight

Adhikary first attracted national attention in May after identifying serious vulnerabilities in the CBSE’s Online Submission of Marks portal, which was being used as part of the board’s digital evaluation system.

He had claimed that vulnerabilities in the system could allow unauthorised access to students’ answer sheets without proper verification, triggering questions over the security of the digital evaluation infrastructure.

The episode brought Adhikary into the national cybersecurity spotlight and was followed by his appointment at C3iHub at IIT Kanpur as an Open-Source Intelligence and Threat Intelligence Engineer.

His latest recognition by the US Justice Department marks another significant development for the teenager within months of the CBSE episode, taking his vulnerability research from an Indian education platform to systems operated by US federal agencies.