‏إظهار الرسائل ذات التسميات Hack. إظهار كافة الرسائل
‏إظهار الرسائل ذات التسميات Hack. إظهار كافة الرسائل

Denim Hacks: Creative Ways to Extend the Life of Your Denim Jeans

Denim men’s jeans are a timeless wardrobe staple for their durability and versatility. However, even the toughest pair of jeans can wear out over time. Instead of discarding your favorite denim, why not explore creative hacks to extend their lifespan?

So, keeping this in mind, we'll share some innovative ways to keep Levi’s India jeans looking fresh and stylish while reducing your environmental footprint. These hacks will save your hard-earned money and increase the life of your denim jeans. Let’s get started: -

Denim Hacks: Creative Ways to Extend the Life of Your Denim Jeans

Simple Secrets to Extend the Overall Life of Denim Jeans

1. Regular Maintenance

Regular maintenance is the first step in extending your denim men’s jeans life. That means avoid over-washing, as excessive laundering can cause denim to fade and lose its shape. Instead, spot clean stains and hang your jeans to air out between wears. However, turn them inside out when you wash them, and use cold water and a mild detergent. Air drying is preferable to a dryer, which can weaken the fabric and cause unnecessary wear and tear.

2. Tailoring and Hemming

The fit of women’s jeans can significantly impact their lifespan. Consult a tailor if your jeans no longer fit well or have become too long. They can take in the waist, shorten the length, or make other adjustments to ensure your jeans fit like a glove. Properly fitting jeans are less likely to experience wear in high-friction areas and will remain comfortable for years.

3. Freeze to Freshen

Believe it or not, freezing your jeans effectively eliminates odors without washing them. So, for best results, fold your jeans and place them in a sealable plastic bag before putting them in the freezer overnight. The cold temperature kills odor-causing bacteria while preserving the color and fabric integrity. This method extends the life of your jeans and conserves water and energy by reducing the need for frequent washing.

4. Pat. ch It Up

Don't let small holes or frayed edges discourage you from wearing your jeans. Get creative with patches! Iron-on or sewn patches add a trendy, personalized touch and reinforce weakened areas. From traditional denim patches to colorful and quirky options, patching your jeans can transform them into unique fashion statements.

5. Dye and Distress

If women’s jeans have faded or you're simply looking for a fresh look, consider dyeing or distressing them. You can experiment with various dye colors to revitalize your jeans or create a distressed appearance by strategically sanding or cutting them. These techniques breathe new life into your denim while letting you express your style. Just be cautious not to overdo it – less can often be more when it comes to distressing.

The Bottom Line

Denim men’s jeans can last for years with proper care and a touch of creativity. But for that, you have to follow these denim hacks; you can extend the life of your favorite jeans and reduce the environmental footprint. From patching up holes to upcycling old pairs, the above methods enable you to enjoy your denim in new and exciting ways. So, instead of tossing those worn-out jeans, give them a second life and contribute to a more sustainable and stylish wardrobe

Ethereum Inventor Vitalik Buterin’s X (Twitter) Account Hacked Leading $691K+ Losses from Victims' Accounts

Ethereum Inventor Vitalik Buterin’s X (Twitter) Account Hacked Resulting $691K+ Loss from Victims' Accounts

Vitalik Buterin, Ethereum’s inventor & co-founder, reportedly had his X (formerly Twitter) account hacked, resulting into loss of $691,000 from users who followed a malicious link posted to his X feed.

According to prominent blockchain investigator ZachXBT, the hacking incident has led to victims collectively losing over $691,000 after clicking on a corrupted link.

Dmitry Buterin, the father of Vitalik, announced on Sep. 9 in a post at X that his son’s account had been compromised and Vitalik is working on restoring access.

The account hack was first noticed on Saturday when a post appeared on Buterin’s post announcing the launch of a set of commemorative non-fungible tokens (NFTs) from software provider Consensys.

This post has a malicious link, which could have been displayed to a large number of Vitalik's 4.9 million followers, and prompted followers to follow the link and eventually connect their wallets to mint the NFT, but in reality, it allowed the hacker(s) to get access to their funds in their wallets.

The post on Vitalik's account was later deleted. However, the damage was done already.

This incident has even led Ethereum developer Bok Khoo, better known as Bokky Poobah on X, to allegedly suffered losses in his CryptoPunk NFT collection.

Notably, no official comment has been made by Vitalik, so far, in this hacking incident. According to ZachZPT, the hacker subsequently sent a stolen NFT to Vitalik.


Blockchain Gaming Platform Hacked, Stealing $625 Mn worth of Cryptos

Blockchain Gaming Platform Hacked Stealing $625 Mn worth of Cryptos

$625 million worth of cryptocurrency has been stolen in a fearless attack on Axie Infinity, an NFT -based and blockchain-based online video game developed by Vietnamese studio Sky Mavis, known for its in-game economy which uses Ethereum-based cryptocurrencies.

Axie Infinity is built on the Ronin Network, an Ethereum-linked sidechain developed by Sky Mavis. A sidechain is a separate blockchain which runs in parallel to Ethereum Mainnet and operates independently.

Axie Infinity is a video game in which players collect and mint NFTs which represent axolotl-inspired digital pets.

The Ronin bridge has been exploited for 173,600 Ethereum and 25.5M USDC, said the Ronin Network, in a newsletter, this week's Tuesday.,

Sky Mavis says it’s working with law enforcement to recover 173,600 Ethereum (currently worth around $600 million) and 25.5 million USDC (a cryptocurrency pegged to the US dollar) from the culprit, who withdrew it from the network on March 23rd.

According to Sky Mavis, an attacker used hacked private security keys to compromise the network nodes that validate transfers to and from the Ronin blockchain. That let the attacker quietly withdraw large quantities of Ethereum and USDC. The transfer was discovered today — nearly a week later — when another user attempted to withdraw 5,000 Ethereum through the bridge.

Ronin Network said, "We are in the process of conducting a thorough investigation; working with Chainalysis to monitor the stolen funds and Crowdstrike to handle forensics and the setup of surveillance tools."

It is being speculated that this is the largest hack to date of "decentralized finance" (DeFi) networks. Last year in August, Hackers stole more than $600 million in Ethereum and other cryptocurrencies. This is the biggest theft ever in the decentralized finance or DeFi space.

WhatsApp can be Hacked, says Israeli Cyber Security Firm Check Point

Israeli cyber security firm Check Point has claimed that WhatsApp can be hacked allowing the attacker to intercept and manipulate messages sent by those in a group or private conversation, which the messaging platform strongly denied.

Check Point, in a blog underlining the vulnerability, said it has already informed WhatsApp of its findings.

When contacted, a Facebook spokesperson said: "We carefully reviewed this issue a year ago and it is false to suggest there is a vulnerability with the security we provide on WhatsApp".

"The scenario described here is merely the mobile equivalent of altering replies in an email thread to make it look like something a person didn't write. We need to be mindful that addressing concerns raised by these researchers could make WhatsApp less private - such as storing information about the origin of messages," the spokesperson said.

In its blog post, Check Point claimed that its "researchers have discovered a vulnerability in WhatsApp that allows a threat actor to intercept and manipulate messages sent by those in a group or private conversation".

It added that by doing so, the "attackers can put themselves in a position of immense power to not only steer potential evidence in their favour, but also create and spread misinformation".

WhatsApp, which has about 400 million users in India, has drawn flak for abuse of its platform for spread of fake messages and misinformation.

Last year, fake news circulated on WhatsApp incited mob fury that led to several instances of lynching across India.

The IT ministry had said that digital platforms cannot escape their responsibility for such rampant abuse and needed to find originators of provocative messages. It had also warned that in the absence of adequate checks, it will treat the messaging platform as 'abettor' of rumour propagation and legal consequences will follow.

WhatsApp, on its part, has also undertaken campaigns in newspapers, television and radio to provide users with easy tips to spot fake news.

The Indian government has been insisting on WhatsApp developing a mechanism to trace origin of messages in cases where the platform is misused by terrorists and 'rogue' elements.

However, the Facebook-owned company has so far, resisted any move that will undermine end-to-end encryption and affect privacy protection for users. PTI PRS SR MBI

UIDAI’s Aadhaar Software Hacked, Anyone Across the World can Enroll, Confirm Experts

The credibility, authenticity and security of India's Aadhaar has long been questioned but the stubborn, ignorant Indian government never accepted that Aadhaar system might need a big overhaul and despite plenty of evident and obvious proofs both UIDAI and central government always ran for cover-ups.

Eventually in a latest unfortunate and biggest incidence of all, personal information of over 1 billion Indians, has been compromised by a software patch that disables critical security features of the software used to enroll new Aadhaar users, revealed an investigation by HuffPost India.

The software patch that hacked Aadhaar's software is freely available for mere Rs 2,500 -- a bonanza for million of other hackers -- that allows unauthorized persons, based anywhere in the world, to generate Aadhaar numbers at will, and is still in widespread use.

Skilled hackers have disabled the security features of Aadhaar enrollment software and even circulated hack on Whatsapp, said the report.

Ironically, a 'Patch' is defined as a set of changes to a computer program or its supporting data designed to update, fix, or improve it. However in case of Aadhaar, the culprit patch allegedly hacked the whole system putting the database of over 1 billion citizens at stake and in more worst scenario about same numer of bank accounts as well is also in serious threat.

This comes within few weeks after a petition was filed against UIDAI as well as the central government of India, alleging that the fundamental right to privacy of all Indians with an Aadhaar card has been violated because of Aadhaar data breaches that occurred on numerous occasion.

The hack, which indeed has significant implications for India's national security, comes at time when when the Indian government has sought to make Aadhaar numbers the gold standard for citizen identification, and mandatory for everything from using a mobile phone to accessing a bank account.

Also Read - India Is About To Privatize 100 Terabytes of Its Citizens Data

According to HuffPost India, the patch is in possession of it and the online portal had even got it analysed by three internationally reputed experts, and two Indian analysts, to confirm that the database has indeed been hacked.

About 1,224,222,809 Aadhaar (122 Crore or 1.22 billion) has been generated till the writing of this article, as per the UIDAI website.

According to the experts, the patch lets a user bypass critical security features such as biometric authentication of enrolment operators to generate unauthorised Aadhaar numbers. It disables the enrollment software's in-built GPS security feature (used to identify the physical location of every enrollment centre), which means anyone, whether he or she is an Indian or not, can use the software to enroll in Aadhaar system.

Moreover, the patch reduces the sensitivity of the enrolment software's iris-recognition system, making it easier to spoof the software with a photograph of a registered operator, rather than requiring the operator to be present in person.

According to a 2012 news piece of Economic Times, The Aadhaar number repository and its IT infrastructure is run run by HCL Infosystems, which won the contract worth 2,200-crore from the UIDAI, in March 2012.

In July this year, the Aadhaar data of the chief of Indian telecom watchdog, TRAI, got leaked when he pose a challenge on Twitter to hack his Aadhaar details.

Last year in July, the government was warned about the vulnerability of Aadhaar when Indian apex court discussed privacy issues with regard to the Aadhaar card. At the same time, a report from the Center for Internet and Society suggests that the records of about 135 million Indians may have been leaked from four government portal due to lack of IT security practices. Additionally, a loophole was also identified that allows all records in Aadhaar to be accessed by anyone though hackers can find other routes.

To recall, UIDAI has recently announced that from 30th of September, the face recognition feature will be rolled out in phased manner, starting with telecom service providers.

Four Govt Websites Hacked/Crashed in A Single Day

The website of the Ministry of Defence was 'hacked' on Friday evening, reported PTI, quoting officials. According to officials, there were Chinese characters on the website, indicating that Chinese hackers may be involved in it.

Moreover, to everyone's surprise, three more websites of -- home, law and labour ministries, also crashed this evening around the same time, which raised suspicion that these had been hacked. But a top cyber security official emphatically denied any hacking and blamed the issue to be a hardware problem. The home ministry also denied that its website had been hacked.

The National Informatics Centre (NIC) also denied reports of hack of Defense Ministry website, instead terming the matter a "technical issue," reported ANI. "Ministry of Defence website is not hacked. There is some technical issue since 2:30pm today," said NIC manifesting the ignorant approach.

Later, defence minister Nirmala Sitharaman took to Twitter to say that "Action is initiated after the hacking of MoD website ( http://mod.nic.in ). The website shall be restored shortly. Needless to say, every possible step required to prevent any such eventuality in the future will be taken. @DefenceMinIndia @PIB_India @PIBHindi,” Sitharaman tweeted.




Eventually, websites of defence and labour ministries have been restored, although sites of home and law ministries are still down till writing this story.

The above news was taken from reports of NDTV.com and Times of India.

The National Informatics Centre, which maintains all these the government websites, is apparently using an in-house developed CMS (Content Management System) which is named as Content Management Framework a.k.a CMF, which was launched as part of the 'Digital India' programme, and is primarily directed towards making government Websites more usable, user centric and unusually accessible. Security feature is perhaps missing from the CMF features list.

Unlike to India, the US however do not use any in house built CMS at all instead they use the same CMS/software that are already available in market and mostly open source software such as Drupal, WordPress, IBM WebSphere WCM and Documentum, among others.

Drupal powers more than 150 sites for the US federal government, including the White House; the House of Representatives; NASA; and the departments of Education, Energy, Commerce, Health, Defense, Justice, Transportation, Homeland Security and Agriculture. It was perhaps the 2009 decision to move Whitehouse.gov and its associated sites to Drupal that gave the open source platform its biggest boost and gave other government agencies the confidence they needed to follow suit. To date, 34 state and territory agencies also use Drupal, with every new adopter solidifying the offering and creating new avenues for innovation. [Read More Here]

Earlier in March, a report in PTI stated that over 22,000 incidents of hacking of Indian websites were reported between April 2017 to January 2018. The report also mentioned that 114 government portals were hacked over that period. In a written reply to Lok Sabha, Minister of State for Electronics and IT K J Alphons had then stated, “As per information reported to and tracked by Indian Computer Emergency Response Team (CERT-In), a total of 22,207 Indian websites including 114 government websites were hacked during April 2017 to January 2018. A total number of 493 affected websites were used for malware propagation."

In February, IndianWeb2 reported that how a security analyst discovered that the official website of Start-up India was --or probably still -- infected with a hidden Trojan virus.

Last October, an IBM study report warned India that despite talents and tools, the country is still unprepared to protect itself from a big cyberattack.

Last year, India's billion dollar valued startup Zomato was hacked and passwords of about 17 million users were stole, however later the company managed to brought every thing in right place. Prior to that, in 2015 cab-hailing startup Ola website got hacked however the company denied any breach.

Four Govt Websites Hacked/Crashed in A Single Day

The website of the Ministry of Defence was 'hacked' on Friday evening, reported PTI, quoting officials. According to officials, there were Chinese characters on the website, indicating that Chinese hackers may be involved in it.

Moreover, to everyone's surprise, three more websites of -- home, law and labour ministries, also crashed this evening around the same time, which raised suspicion that these had been hacked. But a top cyber security official emphatically denied any hacking and blamed the issue to be a hardware problem. The home ministry also denied that its website had been hacked.

The National Informatics Centre (NIC) also denied reports of hack of Defense Ministry website, instead terming the matter a "technical issue," reported ANI. "Ministry of Defence website is not hacked. There is some technical issue since 2:30pm today," said NIC manifesting the ignorant approach.

Later, defence minister Nirmala Sitharaman took to Twitter to say that "Action is initiated after the hacking of MoD website ( http://mod.nic.in ). The website shall be restored shortly. Needless to say, every possible step required to prevent any such eventuality in the future will be taken. @DefenceMinIndia @PIB_India @PIBHindi,” Sitharaman tweeted.




Eventually, websites of defence and labour ministries have been restored, although sites of home and law ministries are still down till writing this story.

The above news was taken from reports of NDTV.com and Times of India.

The National Informatics Centre, which maintains all these the government websites, is apparently using an in-house developed CMS (Content Management System) which is named as Content Management Framework a.k.a CMF, which was launched as part of the 'Digital India' programme, and is primarily directed towards making government Websites more usable, user centric and unusually accessible. Security feature is perhaps missing from the CMF features list.

Unlike to India, the US however do not use any in house built CMS at all instead they use the same CMS/software that are already available in market and mostly open source software such as Drupal, WordPress, IBM WebSphere WCM and Documentum, among others.

Drupal powers more than 150 sites for the US federal government, including the White House; the House of Representatives; NASA; and the departments of Education, Energy, Commerce, Health, Defense, Justice, Transportation, Homeland Security and Agriculture. It was perhaps the 2009 decision to move Whitehouse.gov and its associated sites to Drupal that gave the open source platform its biggest boost and gave other government agencies the confidence they needed to follow suit. To date, 34 state and territory agencies also use Drupal, with every new adopter solidifying the offering and creating new avenues for innovation. [Read More Here]

Earlier in March, a report in PTI stated that over 22,000 incidents of hacking of Indian websites were reported between April 2017 to January 2018. The report also mentioned that 114 government portals were hacked over that period. In a written reply to Lok Sabha, Minister of State for Electronics and IT K J Alphons had then stated, “As per information reported to and tracked by Indian Computer Emergency Response Team (CERT-In), a total of 22,207 Indian websites including 114 government websites were hacked during April 2017 to January 2018. A total number of 493 affected websites were used for malware propagation."

In February, IndianWeb2 reported that how a security analyst discovered that the official website of Start-up India was --or probably still -- infected with a hidden Trojan virus.

Last October, an IBM study report warned India that despite talents and tools, the country is still unprepared to protect itself from a big cyberattack.

Last year, India's billion dollar valued startup Zomato was hacked and passwords of about 17 million users were stole, however later the company managed to brought every thing in right place. Prior to that, in 2015 cab-hailing startup Ola website got hacked however the company denied any breach.

Hackers Attack Indian Bank To Transfer Out $2 Million

Last October, an IBM study report warned India that despite talents and tools, the country is still unprepared to protect itself from a big cyberattack.

Within four months of this IBM warning report, cybercriminals have managed to hack and transferred US$2 million from India’s City Union Bank through three unauthorized remittances to lenders based abroad via the SWIFT financial platform, the institution revealed over the weekend, said a Reuters report.

Cyber criminals hacked into the system and did three transactions. The three fraudulent remittances were sent via correspondent banks, to accounts in Dubai, Turkey, and China.

“This is basically a cyberattack by international cybercriminals,” the bank’s CEO N. Kamakodi told Reuters.

"There was no evidence internal staff was involved, but that it was clear account holders are part of the fraud", he added.

City Union Bank, a small private lender based in south India, blocked one of the remittances for US$500,000 that was being sent through a Standard Chartered Bank account in New York to a Dubai-based lender and another transfer of EUR300,000 (US$370,110) routed through Frankfurt to Turkey.

The tactics used by hackers are very similar to those employed in the unsolved cyber heist of $81 million from Bangladesh's central bank in 2016. Notably, more than one-third companies suffered losses due to cyber attacks in year 2016, globally.

The bank said it was working with the Ministry of External Affairs and officials in Turkey and China to repatriate the funds.

It’s possible that blockchain technology could have prevented the City Union attack.

Other Indian financial institutions, such as Axis Bank, Yes Bank and ICICI have already adopted blockchain technology for payment and remittance related transactions.

It was the ICICI Bank that had first announced about using the blockchain solutions for international trade finance and remittances in October 2016. This was followed by Yes Bank announcing the usage of the technology for vendor financing and then Axis Bank in January 2017.

Last year, India's billion dollar food delivery startup Zomato was hacked and passwords of about 17 million users were stole, however later the company managed to brought every thing in right place. Prior to that, in 2015 cab-hailing startup Ola website got hacked however the company denied any breach.

Hackers Attack Indian Bank To Transfer Out $2 Million

Last October, an IBM study report warned India that despite talents and tools, the country is still unprepared to protect itself from a big cyberattack.

Within four months of this IBM warning report, cybercriminals have managed to hack and transferred US$2 million from India’s City Union Bank through three unauthorized remittances to lenders based abroad via the SWIFT financial platform, the institution revealed over the weekend, said a Reuters report.

Cyber criminals hacked into the system and did three transactions. The three fraudulent remittances were sent via correspondent banks, to accounts in Dubai, Turkey, and China.

“This is basically a cyberattack by international cybercriminals,” the bank’s CEO N. Kamakodi told Reuters.

"There was no evidence internal staff was involved, but that it was clear account holders are part of the fraud", he added.

City Union Bank, a small private lender based in south India, blocked one of the remittances for US$500,000 that was being sent through a Standard Chartered Bank account in New York to a Dubai-based lender and another transfer of EUR300,000 (US$370,110) routed through Frankfurt to Turkey.

The tactics used by hackers are very similar to those employed in the unsolved cyber heist of $81 million from Bangladesh's central bank in 2016. Notably, more than one-third companies suffered losses due to cyber attacks in year 2016, globally.

The bank said it was working with the Ministry of External Affairs and officials in Turkey and China to repatriate the funds.

It’s possible that blockchain technology could have prevented the City Union attack.

Other Indian financial institutions, such as Axis Bank, Yes Bank and ICICI have already adopted blockchain technology for payment and remittance related transactions.

It was the ICICI Bank that had first announced about using the blockchain solutions for international trade finance and remittances in October 2016. This was followed by Yes Bank announcing the usage of the technology for vendor financing and then Axis Bank in January 2017.

Last year, India's billion dollar food delivery startup Zomato was hacked and passwords of about 17 million users were stole, however later the company managed to brought every thing in right place. Prior to that, in 2015 cab-hailing startup Ola website got hacked however the company denied any breach.

Zomato Hacking: Hackers Just Wanted to Reveal Security Flaws; Zomato to Launch Bug Bounty Program Soon

Today morning we reported how hackers named 'nclay' had hacked into Zomato and later the company confirmed that around 17 million user records from its database were stolen, which include emails and hashed passwords.

Now, in an another official blog post by Zomato, the company's security team has confirmed that no damage has done to any of its users as the hackers were reportedly good guys, co-operative and Ethical Hackers. The hacking was done in order to reveal security flaws that were present in Zomato's system.

"The hacker has been very cooperative with us. He/she wanted us to acknowledge security vulnerabilities in our system and work with the ethical hacker community to plug the gaps. His/her key request was that we run a healthy bug bounty program for security researchers," said Gunjan Patidar, who is part of Zomato's Security Team.

"The hacker also gave us all the details on the way he/she got access to this database. We will post this information on our blog once we close the loopholes, so that others can learn from our mistakes," added Gunjan.

Zomato also confirmed that only 5 data points were exposed -- user IDs, Names, Usernames, Email addresses, and Password Hashes with salt. No other information was exposed to anyone, and most importantly, the payment information of all the users are absolutely safe.

After this incidence, Zomato has decided that it will soon launch a bug bounty program on Hackerone -- bug bounty platform that connects businesses with ethical hackers and researchers. Zomato's big bounty program will be in line with Facebook's 'White Hat' program which the company is running since 2011.

For unattended, Bug Bounty is a program was created to report security flaws and bugs. These programs allow the developers to discover and resolve bugs before the general public, preventing incidents of widespread abuse. Bug bounty programs have been implemented by Facebook, Yahoo, Google, Reddit, Square, and Microsoft. Notably, no Indian internet-based company offers such program and Zomato -- if launches the program, will be the first Indian Company to do so.

Meanwhile, Zomato is still discovering the loopholes unearthed by this hacking incidence till writing of this article.

Zomato Hacked, Email and Password of 17 Million Users Stolen

If you're a Zomato user, then this piece of news might be important to you.

The food delivery app today shockingly announced that the app was recently hacked, and the security breach has resulted in compromising the data of over 17 million users on its network.

According to a security blog, Hackread, a vendor going by the online handle of “nclay” is claiming to have hacked Zomato and selling the data of its 17 million registered users on a popular Dark Web marketplace. The database, which includes emails and password hashes of registered Zomato users is being sold for USD 1,001.43 (BTC 0.5587). The vendor also shared a trove of sample data to prove that the data is legit.

[caption id="attachment_116875" align="alignnone" width="700"]
Image-hackread[/caption]

Zomato is primarily unfazed by the whole chain of events and claims that even though the usernames and hashed passwords were stolen by the attackers, but the fact that the Zomato passwords were encrypted means that they will be harder to access. However, experts have a different opinion to offer. According to them, though it is a difficult task but such data eventually does get cracked.

Though the company has claimed that it is confident that there is nothing to worry, but it has strongly recommended its users to change their password for any other services that they are using the same password.

Publishing a blogpost on the security breach, company has also assured that all the payment data of its customers is stored separately from the stolen data, and that no payment information or credit card data has been stolen. The blogpost reads, "Your credit card information on Zomato is fully secure, so there’s nothing to worry about there."

The food delivery app as a precaution has reset the passwords for all affected users and logged them out of the app and website. The company's security team is actively scanning all possible breach vectors and closing any gaps that might be present in their environment. According to the company, its preliminary investigation is pointing towards an internal (human) security breach- possibly one of its employee’s development account got compromised.

Interestingly, this isn't the first time that Zomato has been hacked. The food delivery was previously hacked two years ago by an Indian ethical hacker Anand Prakash, who not only discovered a critical security flaw in the app's data recall system but also informed the company about the same.

Zomato Hacked, Email and Password of 17 Million Users Stolen

If you're a Zomato user, then this piece of news might be important to you.

The food delivery app today shockingly announced that the app was recently hacked, and the security breach has resulted in compromising the data of over 17 million users on its network.

According to a security blog, Hackread, a vendor going by the online handle of “nclay” is claiming to have hacked Zomato and selling the data of its 17 million registered users on a popular Dark Web marketplace. The database, which includes emails and password hashes of registered Zomato users is being sold for USD 1,001.43 (BTC 0.5587). The vendor also shared a trove of sample data to prove that the data is legit.

[caption id="attachment_116875" align="alignnone" width="700"]
Image-hackread[/caption]

Zomato is primarily unfazed by the whole chain of events and claims that even though the usernames and hashed passwords were stolen by the attackers, but the fact that the Zomato passwords were encrypted means that they will be harder to access. However, experts have a different opinion to offer. According to them, though it is a difficult task but such data eventually does get cracked.

Though the company has claimed that it is confident that there is nothing to worry, but it has strongly recommended its users to change their password for any other services that they are using the same password.

Publishing a blogpost on the security breach, company has also assured that all the payment data of its customers is stored separately from the stolen data, and that no payment information or credit card data has been stolen. The blogpost reads, "Your credit card information on Zomato is fully secure, so there’s nothing to worry about there."

The food delivery app as a precaution has reset the passwords for all affected users and logged them out of the app and website. The company's security team is actively scanning all possible breach vectors and closing any gaps that might be present in their environment. According to the company, its preliminary investigation is pointing towards an internal (human) security breach- possibly one of its employee’s development account got compromised.

Interestingly, this isn't the first time that Zomato has been hacked. The food delivery was previously hacked two years ago by an Indian ethical hacker Anand Prakash, who not only discovered a critical security flaw in the app's data recall system but also informed the company about the same.

Market Reports

Market Report & Surveys
IndianWeb2.com © all rights reserved