PAN-India 36-Hour Bug Bounty Challenge 2026 – BOSS OS by C-DAC
Centre for Development of Advanced Computing (C-DAC)
📌About the Event
PAN-India 36-Hour Bug Bounty Challenge 2026 – BOSS OS by C-DAC is a national-level cybersecurity challenge focused on finding and responsibly reporting vulnerabilities in BOSS GNU/Linux, India’s indigenous operating system. The event brings together students, ethical hackers, researchers, open-source contributors, and cybersecurity professionals to strengthen India’s secure digital infrastructure through real-world OS security testing.
ℹ️ Event Details
- Theme: Security testing and vulnerability assessment of BOSS GNU/Linux
- Mode of Conduct: Offline, at designated venues across India
- Duration: 36 hours non-stop
- Event Dates: 7 July 2026, 9:00 AM to 8 July 2026, 9:00 PM
- Coverage: 4 zones and 11 venues across India
- Venue Cities: Noida, Mohali, Chennai, Hyderabad, Bengaluru, Kolkata, Patna, Guwahati, Mumbai, Gandhinagar, and Indore
- Focus Areas: OS-level security testing, vulnerability assessment, privilege escalation analysis, secure configuration validation, kernel security, and application security testing.
📅 Important Dates
- Registration Start Date: 10 June 2026
- Challenge Dates: 7–8 July 2026
- Challenge Timing: 7 July, 9:00 AM to 8 July, 9:00 PM
- Registration Link: Available through the official SSM/C-DAC portal
🎯 Eligibility & Rules
- Who Can Participate: Ethical hackers, cybersecurity professionals, students, researchers, open-source contributors, security enthusiasts, red team members, and vulnerability analysts
- Student Requirement: Students need to complete their SSM portal profile and should be 18+ to be added to a team
- Team Format: SPOCs can manage teams; the portal mentions teams of up to 5 participants
- Allowed Activities: Testing only in the provided BOSS OS environment and creating proof-of-concept vulnerability reports
- Not Allowed: Testing production systems, denial-of-service attacks, data theft, unauthorized access to real information, and public disclosure before approval
- Problem Areas: Kernel and system calls, authentication and access control, package management, network stack, boot process, desktop GUI, file system, logging, cryptography, containerisation, and other BOSS OS vulnerabilities
🏆 Benefits for the Participants
- 1st Prize: ₹1,00,000
- 2nd Prize: ₹75,000
- 3rd Prize: ₹50,000
- Additional Recognition: Certificates, CVE recognition, national awards, and recognition by C-DAC
- Career Value: Real-world cybersecurity exposure, experience in responsible disclosure, and potential opportunities for future collaboration and research engagement