A 19-year-old ethical hacker who came into the national spotlight after identifying security vulnerabilities in the Central Board of Secondary Education's (CBSE) on-screen marking (OSM) portal has been appointed as an open-source intelligence (OSINT) and threat intelligence engineer at IIT Kanpur's cybersecurity hub, C3iHub.
The appointment of Nisarga Adhikary marks a remarkable transition from student researcher to cybersecurity professional and underscores the growing recognition of responsible vulnerability disclosure in India.
According
to reports by Hindustan Times (
HT) and
The Economic Times (
ET), IIT Kanpur reached out to Nisarga after he published a detailed blog in May highlighting security weaknesses in CBSE's digital evaluation platform. The blog, which reportedly served as an unconventional job application, drew the attention of IIT Kanpur director professor Manindra Agrawal.
Confirming the appointment, professor Agrawal said Nisarga is among the youngest engineers to be recruited by the Institute.
"Nisarga Adhikary has been appointed as an engineer in our cybersecurity team. A few years ago, we had similarly recruited a couple of young engineers for the same team. I am not sure whether he is the youngest recruit at IIT Kanpur, but he is certainly among the youngest engineers to have been hired by the institute," professor Agrawal was quoted as saying by Hindustan Times.
In a separate statement issued by IIT Kanpur, professor Agrawal described Nisarga as a talented young engineer with significant potential.
"Nisarga Adhikary has joined IIT Kanpur's C3iHub as an OSINT and Threat Intelligence Engineer. He is a talented young engineer who has demonstrated noteworthy technical capabilities at a young age. We believe he has significant potential, and working at IIT Kanpur will provide him with the opportunity to further develop his capabilities while contributing to cybersecurity and threat intelligence initiatives at C3iHub," professor Agrawal said.
Nisarga's recruitment follows a controversy surrounding CBSE's OSM portal, a critical digital platform used by affiliated schools to upload and manage students' examination marks. The system plays an important role in the board examination process, enabling schools to submit marks electronically for compilation and result preparation.
According to media reports, Nisarga identified multiple security weaknesses in the platform, including flaws related to access controls and data security that could potentially expose sensitive student and school-related information if exploited by malicious actors.
Rather than attempting to misuse the vulnerabilities, Nisarga followed responsible disclosure practices and reported the issues to the Indian Computer Emergency Response Team (CERT-In), India's national cybersecurity watchdog.
As reported by Hindustan Times, Nisarga said he informed CERT-In about the vulnerabilities on 25 February 2026. He claimed to have identified five critical flaws in the OSM portal, including the storage of a master password in plain text that allegedly enabled users to bypass two-factor authentication. According to the report, only one vulnerability was initially addressed while the remaining issues persisted until the portal was eventually taken offline. The disclosures attracted widespread attention within cybersecurity circles and the education sector, with many experts praising the teenager's ethical approach to vulnerability reporting.
From Ethical Hacker to Threat Intelligence Engineer
At IIT Kanpur's C3iHub, Nisarga will analyse publicly available information to identify potential threats and vulnerabilities in websites and applications. His work will involve helping organisations detect, assess and address cybersecurity weaknesses before they can be exploited.
"I am excited about this opportunity because it is the first time I will be working in a security-focused role. In my earlier jobs, I primarily worked as a software engineer, while cybersecurity was more of a hobby," Nisarga told Hindustan Times.
The teenager, who cleared his Class 12 examinations this year, said his interest in technology began at an early age.
"I started coding when I was six or seven years old, but I became seriously involved in cybersecurity and began participating in capture-the-flag (CTF) and other cybersecurity competitions when I was in Class 6," he said.
Despite having no family background in cybersecurity—both his parents work in the finance sector—Nisarga developed expertise through self-learning, cybersecurity competitions and professional work with start-ups, according to media reports.
His appointment comes at a time when India is witnessing growing demand for cybersecurity professionals amid increasing cyber threats targeting government agencies, educational institutions, businesses and critical infrastructure.
About C3iHub
C3iHub, formally known as the IHUB NTIHAC Foundation, is one of India's leading cybersecurity research centres. Established at IIT Kanpur under the National Mission on Interdisciplinary Cyber-Physical Systems, the hub focuses on securing critical infrastructure, identifying cybersecurity vulnerabilities, supporting cybercrime investigations and developing advanced cyber-defence technologies.
While neither IIT Kanpur nor Nisarga disclosed details of his remuneration, the young cybersecurity researcher indicated that the compensation was lower than what he had anticipated after working with US-based firms.
"The salary is decent, but I was expecting a bit more. I'm used to working on projects and with companies based in the US, and I do miss the financial advantage that comes with earning in dollars because of the US dollar-Indian rupee conversion," he told HT.
Nisarga also revealed that he does not currently plan to pursue a college degree, preferring instead to focus on building technology products and start-ups.
"I want to work on building start-ups and products which people use. I am not much interested in academia," he said.
IIT Kanpur may also consider another ethical hacker for a role at the cybersecurity centre, reflecting the institute's willingness to tap unconventional talent pools in the rapidly evolving cybersecurity domain, the report from ET says.
Nisarga's appointment represents a rare example of a young ethical hacker being recognised for responsible disclosure efforts and technical skills, transforming a blog post exposing vulnerabilities into a professional opportunity at one of the country's premier technology institutions.