New day, new pwn 🫠
“Certified secure” lore just got funnier.
Reports said Coempt gave CBSE cybersecurity certificates linked to OneX/BPUT/pre-production context not clearly CBSE’s actual OnMark production system.
So I looked at OneX too, and guess what? Critical vulnerability found. Direct super admin access without OTP, verification, approval flow, hardcoded master password, brute force, credential stuffing, or social engineering. Just broken access control at the worst possible privilege level.
Reported responsibly, and CERT-In along with the concerned team moved fast to get it patched. a certificate from some other scope or environment does not mean your real production ecosystem is secure. Audit scope matters. Production security matters more.
#CBSE #OSM #ONMARK #COEMPT #CYBERSECURITY