IIT Kanpur student hacks campus website after rejection
A student broke into parts of the IIT Kanpur and IIT Madras websites after IIT Kanpur rejected him from its new undergraduate cybersecurity program. He left a message on the site and posted screenshots on X and Reddit to prove his skills, and IIT Kanpur is now testing him instead of pursuing legal action right away.
- Report priority
- Critical
- Involves
- IIT Kanpur
What to do
IIT Kanpur says it will formally test the student's technical skills and had considered but not filed an FIR, so watch for updates on that assessment and any legal outcome.
Reported details
A student applies to IIT Kanpur's new undergraduate cybersecurity program, pays the fees, and submits his application and proof of work, but is not shortlisted for the hackathon stage. He breaches sections of the IIT Kanpur and IIT Madras websites and leaves a message on the IIT Kanpur site reading "Site is hacked. All I need is just a fair chance." He then posts screenshots of the breach on X and Reddit to show what he can do.
IIT Kanpur Director Manindra Agrawal confirmed the student gained access to certain portions of both the IIT Kanpur and IIT Madras websites, but neither the institute nor the student has publicly disclosed the technical method used to get in. The institute had considered filing a First Information Report but instead chose to verify his claims and offer a structured skills evaluation, citing a prior case where it recruited a young researcher who had found flaws in the CBSE online screen-marking portal.
References
- docs.gitlab.com · patch-release-gitlab-19-2-1-released (patches) patch release notes
- docs.gitlab.com · releases patch release notes
- github.com · v15.5.21 (tag) patch release notes
- github.com · v16.2.11 (tag) patch release notes
- github.com · GHSA-7qpv-r5mr-78m4 vendor advisory
- github.com · GHSA-x692-q9x7-8c3f vendor advisory
- github.com · advisories vendor advisory
- nvd.nist.gov · CVE-2026-63077 vdb entry
- livemint.com · student-hacks-iit-kanpur-and-iit-madras-websites-after-being-denied-admission-may-get-a-seat-now-11785316376410.html The Cyber Express
- wionews.com · student-denied-admission-to-iit-kanpur-s-cybersecurity-program-hacks-websites-to-prove-a-point-1785317417167 The Cyber Express
- cyble.com · what-is-cybersecurity The Cyber Express
- sec.cloudapps.cisco.com · cisco-sa-notice-L4XfJg8S Cisco PSIRT
- blogs.cisco.com · strengthening-the-foundation-a-predictable-customer-focused-response-to-ai-accelerated-vulnerability-discovery Cisco PSIRT
- cert.ssi.gouv.fr · CERTFR-2026-AVI-0949 CERT-FR Advisories
- cert.ssi.gouv.fr · CERTFR-2026-AVI-0958 CERT-FR Advisories
- wid.cert-bund.de · securityadvisory CERT-Bund Advisories
- cyber.gc.ca · google-security-advisory-av26-768 CCCS Canada
- chromereleases.googleblog.com · stable-channel-update-for-desktop_0887107924.html CCCS Canada
- cyber.gc.ca · gladinet-security-advisory-av26-765 CCCS Canada
- centrestack.com CCCS Canada
- cyber.gc.ca · php-group-security-advisory-av26-764 CCCS Canada
- cyber.gc.ca · control-systems-phoenix-contact-security-advisory-av26-762 CCCS Canada
- certvde.com · VDE-2026-008 CCCS Canada
- cyber.gc.ca · gitlab-security-advisory-av26-758 CCCS Canada
- cyber.gc.ca · vercel-security-advisory-av26-754 CCCS Canada
- cyber.gc.ca · jetbrains-security-advisory-av26-752 CCCS Canada
- jetbrains.com · issues-fixed CCCS Canada
- blog.jetbrains.com · security CCCS Canada
- cyber.gc.ca · erlang-security-advisory-av26-750 CCCS Canada
- cyber.gc.ca · microsoft-security-advisory-av26-747 CCCS Canada
- msrc.microsoft.com · CVE-2026-57978 CCCS Canada
- msrc.microsoft.com · CVE-2026-57989 CCCS Canada
- msrc.microsoft.com · CVE-2026-57990 CCCS Canada
- msrc.microsoft.com · vulnerability CCCS Canada
- openwall.com · 9 Openwall oss-security
- rapid7.com · ra-unauthenticated-rce-in-jetbrains-teamcity-cve-2026-63077 Rapid7
- blog.jetbrains.com · CVE-2026-63077 Rapid7
- jetbrains.com · teamcity Rapid7
- cisa.gov · known-exploited-vulnerabilities-catalog Rapid7