The Inferno Drainer malware that plagued the crypto world throughout 2023 ultimately compromised about 130,000 victims and stole about $87 million in total, according to a new report from Group-IB. It was part of a broader movement of "crypto drainer" services that some security experts believe is poised to become the next big thing in cybercrime in 2024.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
A major internal security breach involving the copying of a master key has forced South African Post Office Bank to replace 12 million bank cards at a cost of $58 million.
Attackers can commit payment fraud using a locked iPhone with Apple Pay Transit Mode set with a Visa card. Both companies evaded responsibility for the vulnerability.
Digital identity is important as it’s closely tied to the data that represents us or the technologies that act on our behalf. What are the ways that can help us secure our digital identity?
Easy targets. That’s the best way to describe universities and colleges as targets of cyberattacks. Most still operate using legacy systems and infrastructure, and many users, devices, and inadequate cybersecurity policies make them easy prey for bad actors.
$1.3 million BEC attacks on three large financial services companies in U.K. and Israel shows how far cyber criminals are willing to go and what they are capable of.
OpenAI did not comment on the Modal Labs incident specifically, but had previously released a statement indicating that the AI agent had ranged further afield than previously realized and had breached accounts at four other services in addition to the known Hugging Face incident.
World’s fourth-largest generic drugs manufacturer Sun Pharmaceuticals disclosed a ransomware attack that compromised some of its file systems.
Crypto exchange Coinbase has said that it will reimburse customers that lost funds due to a recent data breach, and is also setting aside a $20 million reward for information leading to the arrest and conviction of the hackers.
Lateral movement has been a common factor in breaches, using identity as a universal attack vector to traverse environments unchecked. Organizations must have full visibility of the threat posed by identity and proactively wrap MFA round exposed assets.










