• Home
  • About US
  • Contact Us
  • Privacy Policy
  • Terms of Use

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • March 2022
  • February 2022
  • January 2022
  • November 2019

Categories

  • Auto
  • Business
  • Climate & Earth
  • Coronavirus
  • Crypto
  • Entertainment
  • Happiness Basket
  • India
  • Learn | Unlearn | Relearn
  • Lifestyle
  • Politics
  • Research Discoveries
  • Science & Technology
  • Sports
  • Trending
  • Video
  • World
  • Home
  • About US
  • Contact Us
  • Privacy Policy
  • Terms of Use
Read Selective
  • World
  • Politics
  • India
  • Business
  • Entertainment
  • Lifestyle
  • Auto
  • Crypto
  • Coronavirus
  • Happiness Basket
  • Research Discoveries
  • India

India’s cyber vulnerabilities begin long before a breach

  • June 21, 2026

The CBSE-OSM controversy exposes deeper faults in cybersecurity audits, procurement and institutional accountability

Activists protest in New Delhi against irregularities in CBSE’s on-screen marking system. Credit: PTI Photo

In February 2026, Nisarga Adhikary, a 19-year-old security researcher and Grade 12 student, discovered vulnerabilities in the online platform used for Central Board of Secondary Education’s (CBSE) pilot on on-screen marking (OSM) system. CBSE used a platform developed by Coempt Eduteck Private Limited, a private company that also provides technology solutions to state education boards and universities.

Keeping aside the purported merits and efficiency of OSM, as well as the controversies surrounding the procurement process, it is worth examining the failures that led to CBSE’s embarrassing OSM pilot and discussing how security should be addressed in mission-critical systems going forward.

Nisarga reported the vulnerabilities he found to the Indian Computer Emergency Response Team (CERT-In) on February 25 and received an acknowledgement from the agency the following day. Security researchers often report vulnerabilities to CERT-In because of its status as the national nodal agency for receiving and responding to vulnerability, and incident reports. However, many are unaware that CERT-In has no real enforcement powers.

Following Nisarga’s responsible disclosure, Coempt Eduteck Private Limited fixed the most serious of the several vulnerabilities he had reported. The vulnerability in question involved a client-side hardcoded credential that could be used to bypass the normal authentication process altogether, effectively functioning as an easily discoverable backdoor for anyone who examined the application. Nisarga sought updates from CERT-In on the status of his report for several weeks but did not receive a satisfactory response.

That remained the case until May 22, when Nisarga publicly disclosed all the vulnerabilities he had discovered, on his blog, including those that had not been fixed. It is worth noting that public disclosure of vulnerabilities is a recognised practice in the cybersecurity industry, particularly when vendors are unresponsive — a process commonly known as “full disclosure.” Google’s own vulnerability disclosure policy provides a 90-day disclosure timeline from the date of initial notification, which is reduced to seven days when there is evidence of active exploitation.

Source : https://www.deccanherald.com/india/indias-cyber-vulnerabilities-begin-long-before-a-breach-4046682#google_vignette

Previous Article
  • India

Krishna Byre Gowda blames mismanaged metro sites for Bengaluru’s ‘visual disfigurement’

  • June 20, 2026
View Post
Next Article
  • India
  • Trending

Delegates from BRICS countries visit Taj Mahal, Agra Fort

  • June 21, 2026
View Post
You May Also Like
View Post
  • India

‘Is Ambani the real boss of India?’: Musk doubles down as govt rejects Starlink charges; ‘Wait till you discover the other guy’, Rahul responds

  • October 9, 2026
View Post
  • India

Stay away from ‘SaPa and Sharab’: Yogi Adityanath’s sally against Samajwadi Party

  • October 9, 2026
View Post
  • India
  • Trending

24 Hours To Go For ‘Jantar Mantar Season 2’: CJP Gears Up For Oct 10 Protest Against CEC Gyanesh Kumar

  • October 9, 2026
View Post
  • India

‘More Women Personnel, Body Cameras, Liquor Shops Shut’: Delhi Police Steps Up Security Ahead Of CJP’s Oct 10 Protest

  • October 9, 2026
View Post
  • India

SC Directs NALSA To Consider Plea For Better Pay, Allowances For Lok Adalat Members

  • October 9, 2026
View Post
  • India

Nana Patekar’s Birthplace Is Home To A 450-Year-Old Sea Fort With A Remarkable History

  • October 9, 2026
View Post
  • India

‘Lot Of Men Around Me’: Last Text By Assam Dancer Found Dead In Andhra

  • October 9, 2026
View Post
  • India

Delhi Police check hotels for ‘suspicious’ guests, tracks arrivals ahead of CJP’s October 10 protest at Jantar Mantar

  • October 9, 2026

Recent Posts

  • ‘Is Ambani the real boss of India?’: Musk doubles down as govt rejects Starlink charges; ‘Wait till you discover the other guy’, Rahul responds
  • Medical devices need redesign for reuse, recycling: Study
  • Stay away from ‘SaPa and Sharab’: Yogi Adityanath’s sally against Samajwadi Party
  • Full texts between ‘Cornell 7’ Jane Doe, frat brother she later accused of rape revealed: ‘Our body our choice’
  • Ex-NY prosecutor claims AG Letitia James pushed Trump probe despite investigators finding nothing: ‘What Tish wanted, Tish got’
Categories
  • Auto (43)
  • Business (459)
  • Climate & Earth (16)
  • Coronavirus (17)
  • Crypto (26)
  • Entertainment (843)
  • Happiness Basket (7)
  • India (5,925)
  • Learn | Unlearn | Relearn (163)
  • Lifestyle (329)
  • Politics (95)
  • Research Discoveries (423)
  • Science & Technology (455)
  • Sports (987)
  • Trending (1,701)
  • Video (1)
  • World (9,807)
Read Selective

For Feedbacks, Advertisements or Any Other Concerns mail us at info@readselective.com

Pages
  • Home
  • About US
  • Contact Us
  • Privacy Policy
  • Terms of Use
Categories
  • Auto
  • Business
  • Climate & Earth
  • Coronavirus
  • Crypto
  • Entertainment
  • Happiness Basket
  • India
  • Learn | Unlearn | Relearn
  • Lifestyle
  • Politics
  • Research Discoveries
  • Science & Technology
  • Sports
  • Trending
  • Video
  • World
© 2024 Read Selective | Developed by SUGARA Technologies
  • Home
  • About US
  • Contact Us
  • Privacy Policy
  • Terms of Use

Input your search keywords and press Enter.

Go to mobile version