LIVE · cybersecurity feed
Live wire
hackathon

NIELIT Launches Cyber Kushti 2026, a National Hackathon That Scores Security Judgment Over Detection Speed

NIELIT has opened free registration for Cyber Kushti 2026, a national cybersecurity and AI hackathon run with the ISAC Foundation under the National Security Database, with CERT-In as knowledge partner. Instead of hunting vulnerabilities, teams must correct a deliberately imperfect AI-generated security assessment, and the finale plays out live at NCCDFI 2026 in New Delhi this October.

zeroday.news ·

The National Institute of Electronics and Information Technology (NIELIT) used Independence Day to launch Cyber Kushti 2026, a national cybersecurity and artificial intelligence hackathon built around a question most competitions never ask: not whether a team can find security problems, but whether it can tell which reported problems are real, which matter most, and which deserve to be fixed first. The competition was formally launched by Prof. (Dr.) M. M. Tripathi, Vice Chancellor and Director General of NIELIT.

The hackathon is the official parallel technical track of the 3rd National Conference on Cyber Security, Digital Forensics and Intelligence (NCCDFI 2026) and is conducted in collaboration with the Information Sharing and Analysis Center (ISAC Foundation) under the National Security Database (NSD), with CERT-In as the knowledge partner. NIELIT operates under the Ministry of Electronics and Information Technology. Registration opened on 15 August and closes on 10 September 2026. Entry is free and open to students and independent researchers competing in teams of three.

The format is a deliberate break from the established hackathon template. Competitors are not asked to discover vulnerabilities or capture flags, work that automated tools and AI systems now churn through at high speed and volume. Instead, every team receives an identical and deliberately imperfect Security Assessment Package: AI-generated findings, static analysis output, dependency and secrets scans, architecture documentation, source code and application logs. Some findings in the package are false, some are duplicated, and some genuine issues have been quietly left out. Teams must return a corrected and prioritised assessment, and they are marked on the decisions they can defend. Correctly rejecting a false finding earns as much as identifying a real one.

"The most difficult part of security work has shifted," said Prof. Tripathi. "For a generation, the scarce skill was finding the problem. Today, machines generate findings faster than any team can read them. What they cannot yet do reliably is tell us which findings are real, which matter most, and what must be fixed first. That judgment is now the skill our institutions must build, and it is the only thing this competition measures."

Because the starting material is tool output released to every team at the same moment, the format strips away the advantage that expensive security tooling normally confers. Teams may use any AI tools they wish, a provision stated openly and built into the design of the competition.

"A student from a college in any part of the country can compete on entirely equal terms with a corporate team," Tripathi added. "That is deliberate. We are launching on Independence Day because independence, in an era of increasingly capable machines, means something quite specific: the confidence to examine what one is handed, to disagree with it, and to say precisely why."

The competition runs in three rounds that carry the event's wrestling vocabulary. Round 1, the Akhada, is held online on 15 September 2026, with 50 teams advancing. Round 2, the Dangal, follows online on 24 September and narrows the field to ten finalist teams. The Kesari Round, the final, is conducted in person on 9 October at the Dr. Ambedkar International Centre in New Delhi, where the ten teams work under supervision on the conference floor before presenting and defending their assessments on the main stage. An automated analysis of the same material will be displayed alongside the presentations, letting delegates watch where machine analysis and expert human judgment converge and where they part ways.

Finalists face an eminent jury constituted jointly by NIELIT and ISAC, comprising senior cybersecurity practitioners and experts from government, industry and academia, including National Cyber Security Scholars recognised under the NSD. The winning team carries the title Cyber Kesari 2026 and is presented the Gada, the mace traditionally awarded in kushti. The runners-up take the titles Rustam and Pahalwan. Every Round 1 participant receives a certificate and an individual scorecard, teams advancing beyond Round 1 earn NSD recognition credits, and a separate award has been instituted for the most instructive incorrect submission, recognising reasoning documented clearly enough to be of instructional value.

All competition activity takes place inside controlled environments provided by the organisers. At no stage are participants directed towards, or permitted to engage with, any live system, third party or public infrastructure. NCCDFI 2026 itself convenes government, law enforcement agencies, the judiciary, industry, academia, researchers and students at the Dr. Ambedkar International Centre in New Delhi on 9 and 10 October 2026. Registration and competition details are available at nccdfi.nielitkohima.in/cyber-kushti.

hackathonnielitcert-inaiindia
ShareXLinkedInWhatsAppFacebook

More News

view all →
ransomware

Philips and GE investigating Clop ransomware data theft claims

Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]

security

Hacking Public Wi-Fi DNS to Steal Credentials

Criminals are hacking into public Wi-Fi devices—at hotels, conference centers, and so on—around the world and changing their DNS settings. The goal is to redirect users to fake login pages and steal their credentials.

security

Fake TikTok rewards promise cash you’ll never get

TikTok-branded rewards pages offer cash for simple tasks and daily check-ins. But getting your hands on the money is another story.

vulnerability

Recent macOS Screen Sharing Vulnerability Exploited in Attacks

Threat actors gained root access to the vulnerable systems and deployed a Monero miner. The post Recent macOS Screen Sharing Vulnerability Exploited in Attacks appeared first on SecurityWeek.

CVE-2026-58231critical

Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure

The vulnerability tracked as CVE-2026-58231 can be exploited to execute arbitrary code and compromise internal components. The post Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure appeared first on SecurityWeek.

vulnerability

Police bust cybercrime ring accused of stealing €30 million in four-day spree

German and Brazilian police dismantled an international bank fraud ring blamed for a €30 million cyberattack on a German financial institution, arresting four people in Brazil and pursuing three more suspects in Spain and Bulgaria. Brazilian police named the operation “Klonen.” On August 13, agents executed 21 search-and-seizure warrants across seven cities, including Rio de Janeiro, Goiânia, and