A 19-year-old Indian cybersecurity researcher, Nisarga Adhikary, is reportedly recognized by the US Department of Justice for finding and responsibly disclosing a “critical vulnerability” in a law-enforcement-related system. Multiple outlets say his work is linked to identifying a flaw that is then patched shortly after he reports it through appropriate channels.

Reports describe Adhikary as a self-taught researcher from Siliguri, West Bengal, and a threat intelligence engineer associated with IIT Kanpur’s C3iHub. One outlet says he used custom scripts to detect the issue and that the DOJ acknowledges such researchers publicly under its Vulnerability Disclosure Policy (VDP), which is designed to protect good-faith reporters from legal action when they follow disclosure procedures.

Both sources also describe prior vulnerability reporting by Adhikary, including earlier work involving India’s CBSE On-Screen Marking (OSM) portal. The outlets differ mainly in emphasis: one highlights the “Hall of Fame” framing and specific details of the disclosure timeline, while the other focuses on his broader cybersecurity engagement, including work related to US systems.

Across the coverage, the central shared theme is that Adhikary’s recognition is presented as the result of responsible disclosure rather than exploitation.