New WhatsApp flaw can let cyberattackers deactivate account using user's phone number
By MYBRANDBOOK
As per reports, the new security flaw in WhatsApp can let cybercriminals suspend the account of any user using their phone number.
The attackers apparently do not need any information about the user other than his phone number. At the time the report was pushed out, there was no solution for the issue. However, the attacker can only get the user's account blocked but not gain access to it.
The first ones to discover the dangerous flaw were security researchers Luis Márquez Carpintero and Ernesto Canales Pereña. While this sounds like an impossible thing to do, the researchers have found that the attackers first download WhatsApp on their phones and try to log in using the victim's mobile number. When that is being done, WhatsApp's two-factor authentication system immediately sends a code to the victim's phone number. This prohibits the attacker to gain access to the account, but he keeps repeating the process. Due to several failed login attempts, WhatsApp disables login for 12 hours. This stops both the victim and attacker to log in to their WhatsApp account for 12 hours.
The next thing that the attackers do is email WhatsApp, asking them to deactivate or suspend the phone number of the victim. The attacker does not mention that it has logged the user out of the account but claims that the victim's phone has been lost or stolen. WhatsApp without cross-checking or asking for any inputs from the victim deactivates the WhatsApp account. If the process is repeated, WhatsApp can lock the account permanently.
Legal Battle Over IT Act Intensifies Amid Musk’s India Plans
The outcome of the legal dispute between X Corp and the Indian government c...
Wipro inks 10-year deal with Phoenix Group's ReAssure UK worth
The agreement, executed through Wipro and its 100% subsidiary,...
Centre announces that DPDP Rules nearing Finalisation by April
The government seeks to refine the rules for robust data protection, ensuri...
Home Ministry cracks down on PoS agents in digital arrest scam
Digital arrest scams are a growing cybercrime where victims are coerced or ...
Icons Of India : NIKHIL RATHI
Co-founder & CEO of Web Werks, a global leader in Data Centers and Clo...
ICONS OF INDIA : SANJAY GUPTA
Sanjay Gupta is the Country Head and Vice President of Google India an...
Icons Of India : Girish Mathrubootham
Girish Mathrubootham is the Founder of Freshworks (previously known ...
GSTN - Goods and Services Tax Network
GSTN provides shared IT infrastructure and service to both central and...
NSE - National Stock Exchange
NSE is the leading stock exchange in India....
ECIL - Electronics Corporation of India Limited
ECIL is distinguished by its diverse technological capabilities and it...
Indian Tech Talent Excelling The Tech World - Lal Karsanbhai, President & CEO, Emerson
Lal Karsanbhai, President and CEO of Emerson, assumed the leadership i...
Indian Tech Talent Excelling The Tech World - Steve Sanghi, Executive Chair, Microchip
Steve Sanghi, the Executive Chair of Microchip Technology, has been a ...
Indian Tech Talent Excelling The Tech World - REVATHI ADVAITHI, CEO- Flex
Revathi Advaithi, the CEO of Flex, is a dynamic leader driving growth ...