Three days after the Indian Computer Emergency Response Team (Cert-In) asked a 19-year-old security researcher to tone down his social media posts about unresolved cyber vulnerabilities, the hacker demonstrated another potential security lapse by sending an email from an official gov.in account to the government’s cybersecurity nodal agency, and other government recipients.
He wrote on X that he had found a vulnerability that allowed him to send emails from an official government account. He did not reveal the name of the department concerned. “Will MeitY respond to my previous email, or will it also follow CERT-In’s approach of ignoring serious concerns? The screenshot shared by Adhikary on X shows the email being sent to Cert-In, with a government email address as the sender. The email itself takes a sarcastic tone, telling Cert-In: “this email is, in fact, coming from a @gov.in account. “‘White mercedes’ is basically about a dysfunctional relationship where one side keeps screwing things up, the other keeps taking them back and eventually there’s this feeling of ‘I don’t deserve you’.
In fresh emails also sent to a top official of the electronics and IT ministry and others on Monday, Adhikary said he has found a fresh batch of over 100-150 critical findings in connection with gov.in and nic.in domains.
Adhikary said in the email reviewed by HT. Adhikary said he has been sending “very critical zero day reports” over to the Indian Cybercrime Coordination Centre (I4C), home ministry and departments concerned directly. “I will not cooperate with Cert-In until my concerns are addressed,” he said. After months of me repeatedly going back to CERT-In with vulnerability reports despite everything that’s happened between me and Cert-In, it felt hilariously relatable,” he said.
Nisarga Adhikary posted a screenshot on X on Monday showing an email sent from a ‘gov.in’ email account to Cert-In’s incident reporting address.

