A hackathon that rewards rejecting the machine's wrong answers
NIELIT's CYBER KUSHTI 2026 hands every team an identical, deliberately flawed AI-generated security report — with false findings planted and real vulnerabilities omitted — and scores judgment rather than detection speed.
What happened
- NIELIT launched CYBER KUSHTI 2026, a national cybersecurity and AI hackathon.
- It tests human judgment rather than detection speed.
- Each team gets an identical, deliberately imperfect Security Assessment Package.
- It contains false, duplicated and genuine findings, with some real vulnerabilities omitted.
- Teams are rewarded for correctly rejecting false findings, not only for finding real ones.
For Prelims
- NIELIT: the National Institute of Electronics and Information Technology, under MeitY.
- CERT-In: the national computer emergency response team — knowledge partner for the hackathon.
- ISAC / NSD: the Information Sharing and Analysis Center Foundation, operating the National Security Database.
- CTF: Capture The Flag — the conventional hacking-competition format this event deliberately departs from.
- False positive: a reported vulnerability that is not real; false negative: a real vulnerability that goes unreported — the package contains both by design.
- SAST: static application security testing — one of the automated outputs included in the package.
- Secrets scanning: detecting credentials or keys accidentally committed into source code.
- Registration: open 15 August to 10 September 2026, free, teams of three.
For UPSC: An unusually thoughtful skilling item. Use it for AI in cybersecurity and the alert-fatigue problem, human-in-the-loop verification of machine output, CERT-In and the national cyber architecture, and assessment design that tests judgment rather than recall.
What it is NOT: This is a competition, not a certification or a policy instrument — its significance is in the assessment design, which treats false positives as a first-order problem rather than an afterthought.
For Mains
Syllabus: GS3.18 · GS3.13 · Linkage L3
Anchor
When machines produce findings faster than humans can read them, the scarce skill stops being detection and becomes discrimination.
Substantiation (data)
An identical Security Assessment Package for every team, seeded with false, duplicated and genuine findings and with real vulnerabilities deliberately omitted.
Exemplification
Scoring credits the correct rejection of a false finding as much as the discovery of a true one — the inverse of conventional Capture The Flag design.
Problematisation
Automated tooling scales alert generation but not accountability; alert fatigue causes real vulnerabilities to be closed unread.
Way-forward
Carry this assessment philosophy into professional cybersecurity certification and into public-sector audit standards.
Position
The value a human adds to an AI-assisted process is not speed — it is the willingness to say the machine is wrong.
Deploys into: Cyber security + frontier technology (GS3.18, GS3.13) · AI and alert fatigue, human-in-the-loop verification, and CERT-In in the national cyber architecture.
Ministry of Electronics & IT · 2026-08-16 · PRID 2300120 · PIB source ↗