New WhatsApp flaw can let cyberattackers deactivate account using user's phone number
By MYBRANDBOOK
As per reports, the new security flaw in WhatsApp can let cybercriminals suspend the account of any user using their phone number.
The attackers apparently do not need any information about the user other than his phone number. At the time the report was pushed out, there was no solution for the issue. However, the attacker can only get the user's account blocked but not gain access to it.
The first ones to discover the dangerous flaw were security researchers Luis Márquez Carpintero and Ernesto Canales Pereña. While this sounds like an impossible thing to do, the researchers have found that the attackers first download WhatsApp on their phones and try to log in using the victim's mobile number. When that is being done, WhatsApp's two-factor authentication system immediately sends a code to the victim's phone number. This prohibits the attacker to gain access to the account, but he keeps repeating the process. Due to several failed login attempts, WhatsApp disables login for 12 hours. This stops both the victim and attacker to log in to their WhatsApp account for 12 hours.
The next thing that the attackers do is email WhatsApp, asking them to deactivate or suspend the phone number of the victim. The attacker does not mention that it has logged the user out of the account but claims that the victim's phone has been lost or stolen. WhatsApp without cross-checking or asking for any inputs from the victim deactivates the WhatsApp account. If the process is repeated, WhatsApp can lock the account permanently.
Legal Battle Over IT Act Intensifies Amid Musk’s India Plans
The outcome of the legal dispute between X Corp and the Indian government c...
Wipro inks 10-year deal with Phoenix Group's ReAssure UK worth
The agreement, executed through Wipro and its 100% subsidiary,...
Centre announces that DPDP Rules nearing Finalisation by April
The government seeks to refine the rules for robust data protection, ensuri...
Home Ministry cracks down on PoS agents in digital arrest scam
Digital arrest scams are a growing cybercrime where victims are coerced or ...
Icons Of India : B.V.R. Subrahmanyam
A 1987 batch (Chhattisgarh cadre) Indian Administrative Service Office...
Icons Of India : Anil Agarwal
Anil Agarwal, the Founder and Chairman of Vedanta Resources Ltd., is r...
ICONS OF INDIA : VIJAY SHEKHAR SHARMA
Vijay Shekhar Sharma is an Indian technology entrepreneur and multimil...
IFFCO - Indian Farmers Fertiliser Cooperative
IFFCO operates as a cooperative society owned and controlled by its fa...
NIC - National Informatics Centre
NIC serves as the primary IT solutions provider for the government of ...
DRDO - Defence Research and Development Organisation
DRDO responsible for the development of technology for use by the mili...
Indian Tech Talent Excelling The Tech World - Anirudh Devgan , President, Cadence Design
Anirudh Devgan, the Global President and CEO of Cadence Design Systems...
Indian Tech Talent Excelling The Tech World - RAVI KUMAR S, CEO- Cognizant
Ravi Kumar S, appointed as CEO of Cognizant in January 2023, sets the ...
Indian Tech Talent Excelling The Tech World - ARVIND KRISHNA, CEO – IBM
Arvind Krishna, an Indian-American business executive, serves as the C...