AlternateRoute@lemmy.ca
on 25 Jul 2024 17:15
nextcollapse
This report makes it sound like they had a video call with camera on, vs other reports where they recommend people have camera on because they didn’t
also used AI tools to create a profile picture and match that face during the video conference calls.
This doesn’t sounds like the video was on / faked only that they had a call where the profile picture was used.
octopus_ink@lemmy.ml
on 25 Jul 2024 17:52
nextcollapse
It’s a little bit ironic to me that the security company formerly run by the man who literally wrote the book on social engineering may have fallen victim to a social engineering attack.
Evotech@lemmy.world
on 25 Jul 2024 18:35
nextcollapse
And makes it’s living on telling other companies how to increase their security posture
cheese_greater@lemmy.world
on 25 Jul 2024 20:20
collapse
The grift has come fulk circle
radivojevic@discuss.online
on 25 Jul 2024 20:32
collapse
We learn more lessons by failing than succeeding.
octopus_ink@lemmy.ml
on 25 Jul 2024 21:21
collapse
True, but Kevin certainly had his share of both.
GildorInglorion@lemmy.world
on 25 Jul 2024 20:33
nextcollapse
Landless2029@lemmy.world
on 26 Jul 2024 00:57
collapse
He made it though onboarding and got a company laptop with creds. Got flagged by SEC because he got malware day 1. Also they dug in and he was connected to the states with a VPN.
HR failed. SEC caught it. Now SEC/CIO yell at HR.
YeetPics@mander.xyz
on 25 Jul 2024 20:38
nextcollapse
Boy, I bet they wish they… (drumroll) KnewBe4
TimeSquirrel@kbin.melroy.org
on 25 Jul 2024 20:39
collapse
threaded - newest
This report makes it sound like they had a video call with camera on, vs other reports where they recommend people have camera on because they didn’t
This doesn’t sounds like the video was on / faked only that they had a call where the profile picture was used.
It’s a little bit ironic to me that the security company formerly run by the man who literally wrote the book on social engineering may have fallen victim to a social engineering attack.
And makes it’s living on telling other companies how to increase their security posture
The grift has come fulk circle
We learn more lessons by failing than succeeding.
True, but Kevin certainly had his share of both.
(blog.knowbe4.com/how-a-north-korean-fake-it-worke…) They are saying they caught the guy before he had access to anything important.
He made it though onboarding and got a company laptop with creds. Got flagged by SEC because he got malware day 1. Also they dug in and he was connected to the states with a VPN.
HR failed. SEC caught it. Now SEC/CIO yell at HR.
Boy, I bet they wish they… (drumroll) KnewBe4
Guess they didn't KnowBe4.