On August 28, the Indian Computer Emergency Response Team (CERT-In) requested cybersecurity researcher Nisarga Adhikary to stop publicly disclosing vulnerabilities he discovers until coordination and remediation efforts are complete, according to medianama.com. Adhikary refused, stating he independently researches and reports vulnerabilities without compensation and expects organizations or CERT-In to respond within a 3-4 week timeframe before he speaks publicly.
Adhikary emphasized that he does not publish actionable details such as proof of concepts, reproduction steps, endpoints, or credentials. He argued that merely stating that critical vulnerabilities remain unfixed should not be equated with publishing exploits. In response to CERT-In’s directive, Adhikary criticized the agency for attempting to police his tweets and questioned its effectiveness in handling vulnerability disclosures.
This dispute highlights ongoing tensions between independent cybersecurity researchers and government agencies tasked with managing vulnerability disclosures. CERT-In’s role is to coordinate remediation efforts and prevent exploitation, but researchers like Adhikary stress the importance of transparency and timely public awareness to pressure organizations to fix security flaws. The case underscores challenges in balancing responsible disclosure with public safety in India’s cybersecurity landscape.
CERT-In’s letter to Adhikary and his public response have sparked debate within India’s cybersecurity community about disclosure norms and government accountability. The exchange was reported by medianama.com on September 2, 2026.