talking to @ni5arga and @datavorous_ motivated me to f*** with indian gov websites and turns out i found a flaw in @NTA_Exams jee mains and cuet website that allowed me to reset the password of all accounts,
posting now because it has been fixed now
amazed at @IndianCERT speed
My god ...please watch this. I swear this country is being held together by a chewing gum.@ni5arga well done on exposing these vulnerabilities and even answering the media so confidently. I know this is not easy for you and took a lot of courage 🙌
"They said they are working with IIT, it is a buzzword for them, they will throw IIT at people and tell them it's ok, it's under control" - @ni5arga
😂🤣
The reason Modi remains totally silent on crises like the CBSE OSM fiasco is that the issue will then reach the entire Indian population quickly, which otherwise would be restricted to a small group of directly affected folks, as the entire Godi Media suppresses stories with an unmatched zeal, and WhatsApp University creates diversions and new nonsense every hour. So issues die their unnatural early death, and he simply moves on.
Repeat on loop.
The govt should consider creating a national pool of young ethical hackers, cybersecurity researchers, and talented students to regularly test the security of its websites and digital infrastructure.
Every year, crores are spent on private contractors to build and maintain govt portals. Yet many remain slow, poorly designed, vulnerable to security flaws, plagued by glitches, and raise concerns about data privacy.
As the recent CBSE controversy showed, even a small technical vulnerability can trigger confusion, mistrust, and nationwide outrage. So why not tap into the talent that already exists in the country?
A structured bug bounty and security-audit program, with attractive rewards, would encourage some of India's brightest minds to identify vulnerabilities before malicious actors do. The cost would be a fraction of current spending and should be made part of contractors' obligations.
While some govt platforms already have bug bounty programs, the current approach is either not comprehensive enough or not effective enough. A stronger, centralized, and better-funded system may be needed. No system is perfectly secure, but having thousands of skilled people actively looking for weaknesses is more effective than relying solely on a handful of vendors.
A researcher found critical Windows zero-days.
Reported them to Microsoft.
Microsoft denied the bug bounty.
Deleted their account.
Banned them from GitHub.
Then threatened criminal charges.
The researcher dropped six zero-days in six weeks.
Three got used in real attacks within days.
Other researchers are now handing them free vulnerabilities as a gift.
Microsoft’s Digital Crimes Unit is considering legal action.
Against the person whose bugs they refused to pay for.
This is Microsoft’s bug bounty program.
CBSE people didn't configure their AWS bucket properly and now we can paginate & enumerate all their media which has 2026 answersheets & question papers. ListObjectsV2 works without any auth and the bucket root is listable too — anyone on the internet can download any scanned booklet — across institutions. Multiple institutions are using the same bucket, insanely insecure.
If Pakistan dares to launch a nuclear missile, India will strike back instantly.
S-400, AAD, and Prithvi Air Defence — we’ll destroy it mid-air before it hits.
“No First Use” is our policy, but the response will be unforgettable.
(An excellent cinematic presentation)
Huge: Something that most people (including me) missed yesterday but spotted by @detresfa_—the IAF also struck an air defence site in Karachi’s Malir Cantt. This campaign just keeps getting bigger with more details emerging.
Please circulate this.
It should reach every Indian.
FM S JaiShankar ji clarification should be widely publicized..
Something which should be VIRAL .
Jai Hind 🇮🇳
THREAD: The Ghost Who Stared Back: Ajit Doval’s Secret War for Bharat
Some heroes hold swords.
Others walk into the enemy’s den wearing a smile, a fake beard, and no backup.
Ajit Doval was never just a man.
He is Bharat’s eyes in the dark, its mind in the shadows, and when needed, its wrath in silence.
From disguises to diplomacy, espionage to execution; Ajit Doval’s life isn’t a story. It’s a multi-decade operation.
Let me tell you a story.
1/