Security researchers from Abnormal Security discovered a new phishing campaign targeting Microsoft Office 365 users via a legitimate SurveyMonkey domain to evade security filters. The hackers sent a lookalike SurveyMonkey domain link to Office 365 users prompting them to participate in a survey. On clicking, it redirected them to a phishing site that asked users to enter email login credentials and other sensitive information. The malicious survey links targeted almost 15,000 to 50,000 Office 365 users.
“Within the body of the email is a hidden redirect link appearing as the text Navigate to access statement, with a brief message, “Please do not forward this email as its survey link is unique to you.” But clicking on the link redirects to a site hosted on a Microsoft form submission page. This form asks the user to enter their Office 365 email and password. If the user is not vigilant and provides their credentials, the user account would be compromised,” the researchers said.
Effective Phishing
The researchers stated that the malicious URL is not visible within the email body text, making it difficult for users to identify. The first URL redirects to a legitimate SurveyMonkey link and then lands to a phishing site.
“As these emails originated from the legitimate SurveyMonkey email address, and the body of the email contains a link to the real survey monkey domain, one would easily believe the email to be benign. However, it is not until the second redirect where the user is led to a phishing page that the attacker controls,” researchers added.
Growing Attacks on MS Office 365
Multiple cyberattacks have been reported on MS Office 365 tools earlier. Another research claimed that hackers used a fake Office 365 website to trick users into downloading the TrickBot password-stealing Trojan masked as Chrome and Firefox browser updates. The security team explained that the fake site gives a pop-up stating that the user’s browser needs an update. When the user clicks on the update option, an executable file, named upd365_58v01.exe, gets downloaded and installs the TrickBot information-stealing Trojan to exploit the system.
A survey from the web application security provider Tala Security revealed that cybercriminals are exploiting security vulnerabilities in websites to launch client-side attacks like Magecart, cross-site scripting, form-jacking, and credit card skimming. The survey “Global Data at Risk – 2020 State of the Web Report” stated these attacks exploit vulnerable JavaScript integrations that run on 99% of popular websites globally. Only 1.1% of websites were found to have adequate security measures in place, which is a 11% decline from 2019.
After analyzing the security posture of the Alexa top 1000 websites, the survey revealed that website data risk is on the surge, but most of the website owners fail to deploy necessary security precautions to defend against client-side attacks.
“Without controls, every piece of code running on websites – from every vendor included in the site owner’s website supply chain – can modify, steal or leak information via client-side attacks enabled by JavaScript. In many cases, this data leakage is taking place via whitelisted, legitimate applications, without the website owner’s knowledge,” the survey stated.
The average website includes content from 32 third-party JavaScript vendors, up slightly from 2019
58% of the content that displays on customer browsers is delivered by third-party JavaScript integrations identified above. This website supply chain leverages client-side connections that operate outside the span of effective control in 98% of sampled websites. The client-side is a primary attack vector for website attacks today
Despite increasing numbers of high-profile breaches, forms found on 92% of websites expose data to an average of 17 domains. This is PII, credentials, card transactions, and medical records. While most users would reasonably expect this data to be accessible to the website owner’s servers and perhaps a payment clearing house, Tala’s analysis shows that this data is exposed to nearly 10X more domains than intended. Nearly one-third of websites studied expose data to more than 20 domains
While other client-side attacks such as Magecart capture most of the headlines, no attack is more widespread than Cross-Site Scripting (XSS). This study found that 97% of websites are using dangerous JavaScript functions that could serve as injection points to initiate a DOM XSS attacks
Over 99% of websites are at risk from trusted, whitelisted domains like Google Analytics. These can be leveraged to exfiltrate data, underscoring the need for continuous PII leakage monitoring and prevention. This has significant implications for data privacy, and by extension, GDPR and CCPA
30% of the websites analyzed had implemented security policies – an encouraging 10% increase over 2019
Aanand Krishnan, Founder and CEO of Tala Security, said, “Websites generate massive volumes of high-value data, making them a primary target for attackers. The fundamental issue with the way today’s websites is that user data is greatly exposed to third-party applications and services and that data leakage is occurring even from trusted third-party resources. It’s imperative that organizations keep security top-of-mind and pay much closer attention to what has become a pervasive attack vector.”
Following in the footsteps of the U.S. and India, South Korea now seems to have tightened its grip around the China-based social media company, TikTok. South Korean telecommunication watchdog, Korea Communications Commission (KCC), found TikTok guilty of mishandling child data in the country and thus imposed a 186 million won (i.e. approximately US$155,000) fine. The KCC’s investigation that originally began to investigate secret extraction of user data by the Chinese government through this app led them to these findings.
Things We Know…
The Korea Communications Commission (KCC) began the investigation in October 2019 to originally investigate the claims of TikTok’s data being extracted by the Chinese government.
As per the findings of KCC, TikTok illegally collected a minimum of 6,007 pieces of child data between May 31, 2017, and December 6, 2019, of users younger than 14 years.
Additionally, the investigation revealed that TikTok uses four cloud service providers, Alibaba Cloud, Fastly, Edgecast, and Firebase, of which a few are located overseas. As per KCC, the company failed to notify its users that their data was being transferred outside the country’s borders, which is again a failure of compliance guidelines.
Based on the findings from the investigation, KCC held TikTok guilty on various counts of data mishandling under the country’s Personal Information Protection Act.
The 186 million won fine amounts to nearly 3% of TikTok’s annual revenue in South Korea.
Same Trouble in the Far West?
In the U.S., a group of privacy and children welfare advocates led by Campaign for a Commercial-Free Childhood and The Center for Digital Democracy filed a complaint against TikTok alleging violation of children’s privacy. The group stated that TikTok had disregarded an agreement, which it made with the Federal Trade Commission (FTC) in 2019. As per the agreement, TikTok had promised to remove all previously uploaded content by children under the age of 13 and implement stricter parental controls and consent when collecting children’s personal data.
However, the complainants said, “We found that TikTok currently has many regular account holders who are under age 13, and many of them still have videos of themselves that were uploaded as far back as 2016, years prior to the consent decree.”
As per sources, the Federal Trade Commission (FTC) and the U.S. Department of Justice (DOJ) are now looking into it rather seriously.
Security researchers from Kaspersky found that cybercriminals are using thousands of inactive domains to redirect users to malicious URLs. According to Kaspersky, cybercriminals kept 1,000 inactive websites for sale on auction platforms, which redirected the visitors to over 2500 malicious URLs. The URLs were designed to automatically download the “Shlayer Trojan,” a malware that tries to steal information from macOS computers. Between March 2019 to February 2020, 89% of these unwanted domains redirected users to ad-related pages and 11% redirected to malicious sites that contained a malicious script.
“We noticed that from time to time visitors who initially went to the now inactive website of the app developer did not land on the auction stub, but on a malicious resource. Next, we learned that the stub site redirects visitors not to a specific resource, but to different websites, including ones on partner networks. The type of redirect can vary depending on the country and user agent: When accessing from a macOS device, the victim might land on a page that downloads the Shlayer Trojan,” the researchers said.
“We checked the list of addresses from which Shlayer was downloaded and found that the vast majority of domain names had been put up for auction on the same trading platform. Then we decided to check the requests to the resource that Razor Enhanced users got redirected to, and found that around 100 other stubs on this trading platform sent their visitors to the same address. During the study, we found about 1,000 of these pages in total, but the real figure is probably much higher,” the researchers added. While the attackers behind this malicious campaign are unknown, researchers said that it can be an act of a well-organized network for financial gains.
Risks with Malicious URLs
Opening or downloading malicious links or attachments could result in severe security issues. A research from security firm NetMotion revealed that cyberthreats soared as remote workers visited risky websites outside of corporate networks. The analysis found that remote employees clicked on 76,440 links that redirected them to malicious websites. NetMotion highlighted that they collected a sample of network traffic data to find users who accessed blocked URLs or risky content. All these sites were visited on office laptops while working from home via home or public Wi-Fi or a data network.
Google Cloud Next ’20: OnAir kicked off today and Google announced new solutions across its smart data analytics and security portfolios, to help accelerate customers’ ability to digitally transform with cloud computing. The announcements concerning cloud security and compliance include a new Confidential Computing portfolio and Assured Workloads for Governments.
Analysis and reporting by Brian Pereira, Principal Editor, CISO MAG
Google Cloud Next ’20: OnAir is a free, nine-week, in-depth digital event series starting July 14. It will have over 200 sessions ranging from compelling keynotes from industry luminaries to advanced learning opportunities with top Google developers.
Confidential Computing protects sensitive data
A major concern for enterprises is how to process sensitive data while keeping it private. To get around this, Google Cloud encrypts data-at-rest and in-transit. But customer data must be decrypted for processing, opening up a possibility of a confidentiality breach. That concern may have just been addressed with Confidential Computing, which Google believes is a “breakthrough technology.”
Confidential Computing encrypts data in-use — while it is being processed. Confidential Computing environments keep data encrypted in memory and elsewhere outside the central processing unit (CPU). Google says this technology will transform the way organizations process data in the cloud, maintain control over their data, and preserve confidentiality.
Confidential VMs is the first product in Google Cloud’s Confidential Computing portfolio. Google Cloud already employs a variety of isolation and sandboxing techniques as part of its cloud infrastructure to help make its multi-tenant architecture secure. Confidential VMs, now in beta, take this to the next level by offering memory encryption so that customers can further isolate workloads in the cloud.
Confidential VMs are available on AMD CPUs and take advantage of the secure encrypted virtualization supported by 2nd Gen AMD EPYC CPUs.
“Customers across all industries are navigating the complexities of compliance and privacy in the cloud, especially those in regulated industries, such as financial services firms, health care companies, and government agencies,” said Sunil Potti, General Manager and VP of Security at Google Cloud. “These companies want to adopt the latest cloud technologies, but strict requirements for data privacy or compliance are often barriers. Confidential VMs will help us better serve customers in these industries, so they can securely take advantage of the innovation of the cloud while also simplifying security operations.”
Thomas Kurian, CEO, Google Cloud
Delivering the keynote address at Google Cloud Next ’20: OnAir, Thomas Kurian, CEO, Google Cloud said Confidential Computing will ensure that Google’s customer data is not only encrypted at rest or in transit but also while it is being processed.
Kurian said Google has also developed other solutions to protect customer data and to give threat visibility – for intrusion monitoring and for zero trust access to apps that are web-based and which reside on Google cloud and on other clouds.
Assured Workloads for Governments
Google is also introducing Assured Workloads for Government, which is currently in Private Beta. Google says the product will help serve government workloads without the compromises of traditional “government clouds.” This service simplifies the compliance configuration process and provides seamless platform compatibility between government and commercial cloud environments.
In a virtual press briefing held last week, Google spokespersons said Assured Workloads for Governments will first be launched for the US Government and later be extended to other global governments.
Google Cloud CEO, Thomas Kurian said during his keynote that (in the near future because it is still in beta) Assured Workloads will ensure those customer workloads on Google Cloud will automatically comply with industry standards and also with the organization’s own security policies.
CISO MAG interprets this as “compliance by default” though we are unsure how Google is going to enable that. Every industry has specific standards in addition to the region-wise standards like GDPR. We also asked Google Cloud a question about future compliance with India’s forthcoming Personal Data Protection Act (PDPA) and are awaiting a response.
For now, it seems Google is only focusing on the Government for Assured Workloads, and that too only in the U.S.
In a blog post, Christopher Johnson, Security & Product Manager, Google Cloud and Bhavna Batra, Trust & Compliance PMM, Google Cloud wrote: “With Assured Workloads for Government, Google Cloud customers can quickly and easily create controlled environments where U.S. data location and personnel access controls are automatically enforced in any of our U.S. cloud regions. Assured Workloads for Government helps government customers, suppliers, and contractors to meet the high security and compliance standards set forth by the Department of Defense (i.e., IL4), the FBI’s Criminal Justice Information Services Division (CJIS), and the Federal Risk and Authorization Management Program (FedRAMP), while still having access to all the latest features in our portfolio.”
New BigQuery Omni solution enables data analysis across cloud platforms
It is now common to see enterprise workloads across multiple clouds, on-premises, and on proprietary systems. This results in siloed data stored across these clouds and a major challenge is analyzing this data for business insights. The data needs to be consolidated into a common resource pool such as a data lake before it can be processed or analyzed. Google just solved this problem with its new BigQuery Omni solution.
Google says BigQuery Omni is a multi-cloud analytics solution that enables customers to bring the power of BigQuery to data stored in Google Cloud, Amazon Web Services (AWS) and Azure (coming soon).
Google Cloud CEO, Thomas Kurian said BigQuery Omni enables customers to query their data on other clouds like AWS and Azure. “We bring the power of Big Query Analytics to where your data sits without the need to pay expensive Egress fees for moving that data from other cloud providers to Google Cloud,” said Kurian.
He also mentioned that Streaming Analytics can support 100 parallel streams in Big Query.
Powered by Google Cloud’s Anthos, BigQuery Omni will allow customers to connect directly to their data across Google Cloud, AWS and Azure for analysis without having to move or copy datasets. Through a single user interface, customers will be able to analyze data in the region where it is stored, providing a unified analytics experience.
“For customers, moving data across different clouds is both cumbersome and expensive. To address this, we continue to invest in multi-cloud in an effort to democratize access to the best technologies for our customers, no matter what cloud provider they’re using today,” said Debanjan Saha, General Manager of Data Analytics, Google Cloud. “BigQuery Omni provides enterprises with the openness and portability they need to break down silos and create actionable business insights, all without having to pay expensive egress fees for moving data from other cloud providers to Google Cloud.”
Our Analysis
These new products (especially Confidential VMs) will bring more confidence to organizations who are skeptical about data privacy and compliance on the cloud. Compliance with industry standards is especially important to regulated industries like banking, insurance, telecom, and health care. We feel Assured Workloads is crucial for governments who are facing increasing attacks on their infrastructure by hackers from enemy nations through cyber warfare. But Google says the product is in “private beta” now so we will have to wait for it.
Three years ago, on July 14, 2017, we launched CISO MAG with a vision to report unbiased and authentic news to information security professionals working in critical sectors to help them prevent, respond to, and counter security challenges. Ever since then, it has been a journey of publishing that can’t be explained in mere words — years of anxiety, toil, long hours, and sleepless nights. But it has all been worth it!
Within the year of its inception, CISO MAG crossed 50,000 readers across 100 countries, which just continued to grow. It was then that it became clear— there was no looking back.
In the last three years, a lot changed. We grew bigger as a team; we came up with newer initiatives. We interviewed hundreds of security leaders and built a solid community of C-level executives in the information security domain. We tackled every hurdle that was thrown at us, and we continued to march forward as a team. Even when the pandemic hit us, and the world stalled, we continued to do what we do best. And eventually, we became what we aspired to be — the voice of the cybersecurity industry.
There are a few things that haven’t changed: our dedication, outrageous persistence and journalistic ethics to bring out a better cybersecurity e-magazine, issue after issue, and to keep our audience updated about every major cybersecurity incident happening across the globe.
We also took to our self the responsibility of introducing a few of the biggest names in cybersecurity to our readers—including the likes of Brian Krebs, Rik Ferguson, and few more who would soon make their appearance.
This year, the e-magazine was completely redesigned for a contemporary look that is appealing to our readers. The CISO MAG website would also have a bold new design this year. In addition, we would be establishing a community and board for those who contribute articles on a regular basis.
Since people enjoy content in different forms and video being the most consumed content globally, we introduced webinars to drive a wider engagement and educate the attendees about the happenings in the cyberspace. The visual interactive sessions, surveys, live Q&A have enabled us to have a diverse audience and more opportunities to connect with industry professionals.
We conducted webinars with high profile personalities, including:
Bryan Ware, Assistant Director for Cybersecurity, Cybersecurity and Infrastructure Security Agency (CISA), Department of Homeland Security (DHS)
Chris Roberts, Researcher, Hacker and CISO
Erdal Ozkaya, Regional CISO at a Global Bank
Thomas Tschersich, Chief Security Officer (CSO) Deutsche Telekom
CISO MAG editors are on track to produce four Market Research reports this year:
Network Security
Cloud Security
Data Security
Endpoint Security
The credit for whatever CISO MAG has achieved in the last three years goes to an executive contributor panel comprising of a few of the best cybersecurity experts in the world. And the rest and most of it goes a bunch of hard-working professional staff of CISO MAG who are always looking at outdoing themselves to improve the content, its quality and reach daily.
Last but not the least, we would like to earnestly thank you — the readers of CISO MAG — for your interest. It has been your continued feedback that has enabled us to get better year by year. Please keep sending us your feedback and ideas. We would always be profoundly indebted to you.
We will continue to carry the torch that guides every stakeholder of safe internet.
Cheers to the years that have gone by! Cheers to the years to come!
A recent survey from cybersecurity firm Bitdefender revealed that nearly 50% of infosec professionals admitted that their organization doesn’t have a contingency plan to handle a situation like COVID-19 or a similar. In the survey “the Indelible Impact Of Covid-19 On Cybersecurity” 86% of respondents stated that cyberattacks were on the rise during the pandemic.
The survey also highlighted that supply chain attacks, cyberwarfare, and IoT attacks increased by 38%, followed by ransomware attacks by 31% and DDoS attacks by 36%. 2 in 5 organizations said that their employees were using untrusted networks and 38% reported there is a definitive risk in another person having access to an employee company device. Financial services (43%), healthcare (34%), and the public sector (29%) were the most affected by cybersecurity risks at the moment.
“As a result of the increase in home working, many changes have been made to security strategies. Yet, despite their fears of a rise in attacks, only 14% have invested a significant amount of money in upgrading security stacks, 12% have bought additional cybersecurity insurance, and only 11% have implemented a zero trust policy — all of which indicates more changes are still to be made,” the report said.
“The pandemic has provided a valuable opportunity to infosec professionals to learn how to tackle changes in workforce patterns, and how to plan for unexpected events. One in three infosec professionals (31%) say they intend to keep 24/7 IT support, and will increase the number of training sessions in IT security for employees. Almost a quarter (23%) have also cited that they are going to increase the cooperation with key business stakeholders when defining cybersecurity policies, and an equal percentage will increase outsourcing IT security expertise,” the report added.
Remote Work Threatens Businesses
A similar study from HiveIO revealed that nearly 85% of organizations anticipate a larger remote workforce will threaten operations because of new risks. “The IT departments are working at a deficit in their ability to support and maintain business continuity while optimizing IT support,” the report said. The study stated that several organizations are unable to introduce new security solutions designed to improve the efficiency of work-from-home employees. Around 70% of respondents admitted that they have suffered increased costs due to the ongoing pandemic. And 25% of respondents reported shrinking staff support and another 18% fear additional staff reductions.
A survey on the current state of security operations center (SOC) performance revealed that even though organizations have increased their cybersecurity budget on SOC, the overall results are not satisfactory. It is found that the average annual cybersecurity budget for organizations rose $6 million to $31 million, with the SOC representing one-third of that total.
According to the survey, jointly conducted by Devo Technology and Ponemon Institute, 72% of IT security practitioners in organizations with a SOC classify the unit as essential or very important to their organization’s cybersecurity strategy. However, 1 in 6 (60%) of SOC team members are considering changing their careers due to stress associated with the current field.
The survey also highlighted that high-performing teams have led strong business consensus, with 73% of SOC objectives aligned with business objectives, versus low performers for whom 63% have no alignment at all. The three major actions for organizations to relieve SOC analyst pain are greater workflow automation (71%), implementing advanced analytics/machine learning (63%), and access to more out-of-the-box content (55%).
70% suffer a lack of visibility into the IT infrastructure
64% combat turf issues between IT and the SOC
While 76% say training/retention is highly important, more than 50% have no formal programs in place, and more than 50% cite the lack of skilled personnel as a major factor in SOC inefficiency
Mean time to response (MTTR) remains unacceptably high, with 39% saying their average time to resolve an incident is months or even years
71% need greater automation, especially as they continue to spend substantial manual cycles on tasks such as alert management (47%), evidence gathering (50%), and malware protection and defense (50%)
Environmental factors are driving substantially higher pain, including information overload (67%, up from 62%), burnout from increased workloads (75%, up from 73%) and complexity and chaos in the SOC (53%, up from 49%)
Not surprisingly, the perennial issue of a skills shortage (seen by more than 50% of respondents) is close to the heart of the issue.
Organizations have too many tools (nearly 40%), and more than half don’t have all the data necessary, nor the ability to capture actionable intelligence
“For respondents, whose organizations have invested in people, process, and technology, the performance differences are stark. Strong business alignment (73%) and extensive training (67%) help high-performing SOCs more than double the effectiveness of their lower-performing brethren. However, the pain and barriers facing SOC teams are universal and worsening, with higher performers citing 10% more pain at an extreme level (9-10 on a 10-point scale), and virtually no difference in the level below that (7-8),” the survey stated.
The survey findings are based on the responses from 585 IT and IT security practitioners in organizations that have a SOC and aware of their organizations’ cybersecurity practices.
Threat intelligence firm Cyble discovered that personal records of U.S. citizens were exposed on darknet forums. The researchers stated that an unknown hacker posted an advertisement on the dark web claiming that they had stolen personal details of more than 40,000 U.S. citizens. The exposed information included citizens’ first names, last names, address, city, state, Zip codes, social security numbers (SSNs), and date of birth.
Image Source: Cyble
Cyble’s researchers also recommended certain security measures to online users, these include:
Never share personal information, including financial information over the phone, email, or SMS
Use strong passwords and enforce multi-factor authentication where possible
Regularly monitor your financial transaction, if you notice any suspicious transaction, contact your bank immediately
Turn-on automatic software update feature on your computer, mobile and other connected devices where possible and pragmatic
Use a reputed anti-virus and internet security software package on your connected devices including PC, laptop, and smartphone
Stolen Data Floods Darknet
The discovery comes after Cyble recently identified and reported another massive data breach, in which the members of the “Shiny Hunters” hacking group compromised 73.2 million user records from over 11 companies and kept them on the darknet for sale. The hackers are from the same group who are behind the Tokopedia data breach, in which 91 million user records were compromised and kept on sale on the hacking forums for $5,000. Later, the group breached India-based online learning platform Unacademy, which exposed details of 22 million users and kept the records for sale on the darknet forums for $2,000.
Several incidents have been reported in recent times about hackers selling stolen information on the darknet markets. According to Cyble, attackers were also selling over 267 million Facebook records for £500 (US$623) on dark websites and hacker forums. The records contain information that could allow attackers to perform spear phishing or SMS attacks to steal credentials.
The MGM Resorts, in February 2020, reported a data breach that affected nearly 10.6 million of its guests. The company took help of two cybersecurity firms to probe the incident and correspondingly beefed-up the security lines to avoid such breaches in the future. However, it was recently discovered that a cybercriminal is selling details of 142,479,937 MGM Resorts’ guests, which might have been originally leaked during the first MGM Resorts data breach that took place in the summer of 2019. The offer price of this data on the dark web is placed at $2,939.76.
The Story So Far…
The actual data breach took place in July 2019.
MGM notified its guests about the data breach in August 2019.
The cause of the original data breach was traced back to a misconfigured cloud server.
10.6 million guest details including names, date of birth, email addresses, phone numbers, etc., were compromised as per MGM’s statement.
No reports of loss of financial data like payment card information or password information.
In February 2020, MGM officially confirmed details about the 2019 data breach after these records appeared as a free download on an underground forum.
In July 2020, 142 million MGM Resorts’ guest details appear for sale on the dark web for a price of $2,939.
The cybercriminal behind this latest sale has claimed to have obtained the MGM Resorts data after he recently carried out a data breach against DataViper, a data leak monitoring service of Night Lion Security. Although the compromised data does not involve any financial details and/or personal IDs like the SSN (social security number) or license and passport numbers, it would be wise for MGM customers to take the following as precautionary measures:
Change all passwords of accounts related to MGM resorts bookings.
Set up a credit monitoring service if you do not have one.
Beware of phishing and smishing attacks.
Be vigilant and report any suspicious activity to the authorities concerned.
Keep a track of all the records and communications between MGM and yourself. This could potentially be very useful in case of filing a class-action lawsuit.
Ensuring that you get the best experience is our only purpose for using cookies. If you wish to continue, please accept. You are welcome to provide a controlled consent by visiting the cookie settings. For any further queries or information, please see our privacy policy.
This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
Cookie
Duration
Description
cookielawinfo-checkbox-analytics
11 months
This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional
11 months
The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary
11 months
This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others
11 months
This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance
11 months
This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy
11 months
The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.