:

INDIAN EXAM BOARD CONFIRMS SECURITY FLAWS IN GRADING PORTAL

SECURITY DESK2 MIN READ
SUN, MAY 31, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

India's national school exam board acknowledged vulnerabilities in its online grading system after a teenage cybersecurity researcher discovered the weaknesses. The board said it has contained the issues affecting one of the country's most critical school-leaving exams.

The exam board disclosed that it has been actively monitoring and has now contained cybersecurity vulnerabilities in the portal used for grading a major national exam. The flaws were initially reported by a teenage security researcher who identified gaps in the system's defenses. The vulnerabilities posed potential risks to the integrity of the grading process for one of India's most important educational assessments. Such exam portals typically handle sensitive student data and grades, making security a critical concern. The board's confirmation marks a significant acknowledgment of the security gaps. While the organization stated it has contained the vulnerabilities, specifics about the nature of the flaws or the timeline for their discovery remain limited. The incident highlights how security researchers, including younger specialists, continue to identify weaknesses in critical digital infrastructure. The discovery underscores ongoing challenges with cybersecurity in educational systems across India. Exam boards and educational institutions have faced increasing pressure to modernize their systems while maintaining robust security protocols to protect student information and maintain the credibility of examination processes. The teenage researcher's identification of these vulnerabilities demonstrates the importance of responsible disclosure and external security audits. Educational institutions and government bodies increasingly rely on digital platforms for administration, making cybersecurity expertise essential. No details have been provided regarding potential exposure of student data or the specific vulnerability types. The board's statement that vulnerabilities have been "contained" suggests remedial action has been taken, though comprehensive disclosure of remediation steps remains unclear. This incident adds to a broader pattern of security concerns within India's digital educational infrastructure, particularly as institutions accelerate their shift toward online systems.

■ SOURCES

Bloomberg Tech

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Researchers at Cisco Talos developed a new framework to detect malware and hacking tools powered by AI chatbots. The discovery revealed an unusual threat: autonomous malware operating without human handlers.

JUST NOWAI Desk

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency directive ordering federal agencies to patch a high-severity vulnerability in Zyxel GS1900 series switches. Attackers are actively exploiting the flaw to steal data.

1H AGOSecurity Desk

WordPress disclosed an unauthenticated path traversal vulnerability that could lead to conditional remote code execution. The issue affects WordPress core and has been documented in an official security advisory.

3H AGOIndustry Desk

Security researchers have demonstrated an attack allowing hackers with privileged access to register fake MFA providers and harvest user passwords during login. The vulnerability exploits the authentication process itself.

3H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.