Session Hijacking 2.0 — The Latest Way That Attackers are Bypassing MFA – OfficialSarkar

Session Hijacking 2.0 — The Latest Way That Attackers are Bypassing MFA – OfficialSarkar

Attackers are increasingly turning to session hijacking to get around widespread MFA adoption. The data supports this, as: 147,000 token replay attacks were detected by Microsoft in 2023, a 111% increase year-over-year (Microsoft). Attacks on session cookies now happen in the same order of magnitude as password-based attacks (Google). But session hijacking isn’t a new…

Critical Flaws in Tank Gauge Systems Expose Gas Stations to Remote Attacks – OfficialSarkar

Critical security vulnerabilities have been disclosed in six different Automatic Tank Gauge (ATG) systems from five manufacturers that could expose them to remote attacks. “These vulnerabilities pose significant real-world risks, as they could be exploited by malicious actors to cause widespread damage, including physical damage, environmental hazards, and economic losses,” Bitsight researcher Pedro Umbelino said…

Why Microsoft 365 Protection Reigns Supreme – OfficialSarkar

Imagine a sophisticated cyberattack cripples your organization’s most critical productivity and collaboration tool — the platform you rely on for daily operations. In the blink of an eye, hackers encrypt your emails, files, and crucial business data stored in Microsoft 365, holding it hostage using ransomware. Productivity grinds to a halt and your IT team…

UP Anganwadi Bharti 2024: उत्तर प्रदेश आंगनवाड़ी भर्ती जारी, 1218 पदों पे करें आवेदन [Career]

Uttar Pradesh Government has published the official notification for Anganwadi Worker posts on the official website of UP Anganwadi. For all the interested and eligible candidates who want to apply for this recruitment, all the information related to the recruitment is given below and the link to apply is given in the important link section…

Meta Fined €91 Million for Storing Millions of Facebook and Instagram Passwords in Plaintext – OfficialSarkar

Sep 30, 2024Ravie LakshmananGDPR / Data Privacy The Irish Data Protection Commission (DPC) has fined Meta €91 million ($101.56 million) as part of a probe into a security lapse in March 2019, when the company disclosed that it had mistakenly stored users’ passwords in plaintext in its systems. The investigation, launched by the DPC the…

Rajasthan Safai Karmchari Bharti 2024 Notification (Out) For 23820 Post [Career]

Local Self Government Department Rajasthan has recently published the official notification for the recruitment of Rajasthan Safai Karmachari Posts on the official website LSG. For all the interested and eligible candidates who want to apply for this recruitment, all the information related to the recruitment is given below and the link to apply is given…

Crypto Scam App Disguised as WalletConnect Steals $70K in Five-Month Campaign – OfficialSarkar

Sep 28, 2024Ravie LakshmananCryptocurrency / Mobile Security Cybersecurity researchers have discovered a malicious Android app on the Google Play Store that enabled the threat actors behind it to steal approximately $70,000 in cryptocurrency from victims over a period of nearly five months. The dodgy app, identified by Check Point, masqueraded as the legitimate WalletConnect open-source…

U.S. Charges Three Iranian Nationals for Election Interference and Cybercrimes – OfficialSarkar

U.S. federal prosecutors on Friday unsealed criminal charges against three Iranian nationals who are allegedly employed with the Islamic Revolutionary Guard Corps (IRGC) for their targeting of current and former officials to steal sensitive data. The Department of Justice (DoJ) accused Masoud Jalili, 36, Seyyed Ali Aghamiri, 34, and Yasar (Yaser) Balaghi, 37, of participating…

Progress Software Releases Patches for 6 Flaws in WhatsUp Gold – Patch Now – OfficialSarkar

Sep 27, 2024Ravie LakshmananSoftware Security / Vulnerability Progress Software has released another round of updates to address six security flaws in WhatsUp Gold, including two critical vulnerabilities. The issues, the company said, have been resolved in version 24.0.1 released on September 20, 2024. The company has yet to release any details about what the flaws…

New HTML Smuggling Campaign Delivers DCRat Malware to Russian-Speaking Users – OfficialSarkar

Sep 27, 2024Ravie LakshmananGenAI / Cybercrime Russian-speaking users have been targeted as part of a new campaign distributing a commodity trojan called DCRat (aka DarkCrystal RAT) by means of a technique known as HTML smuggling. The development marks the first time the malware has been deployed using this method, a departure from previously observed delivery…