Cybersecurity Researcher and Agency Clash Over Public Vulnerability Disclosures
India's national cybersecurity agency CERT-In requested a researcher stop public disclosures of vulnerabilities, but the researcher refused, citing a lack of timely response.

India's national cybersecurity agency, CERT-In, has asked independent cybersecurity researcher Nisarga Adhikary to cease public disclosures of vulnerabilities he discovers before they are remediated.
Adhikary refused the request, particularly if the concerned organizations or CERT-In do not respond to disclosed vulnerabilities within a reasonable timeframe, such as 3-4 weeks. The researcher emphasizes he performs his work independently and responsibly, unlike paid officials whom he accuses of imposing "pointless rules."
According to Adhikary, he gives organizations 3-4 weeks to fix issues and does not publish actionable proof-of-concepts or details. He previously gained attention for exposing vulnerabilities in India's Central Board of Secondary Education (CBSE) systems, subsequently securing a position at IIT Kanpur. He has also highlighted the agency's struggles in addressing reported security flaws and, at times, its technical competency.
The researcher claims CERT-In often fails to remediate vulnerabilities and takes credit for the research. Another cybersecurity expert, Karan Saini, has previously criticized CERT-In's technical team, stating that public money on cybersecurity in India is largely wasted.