this post was submitted on 25 Jul 2024
135 points (97.2% liked)

Technology

59534 readers
3209 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
top 10 comments
sorted by: hot top controversial new old
[–] octopus_ink@lemmy.ml 45 points 3 months ago (2 children)

It's a little bit ironic to me that the security company formerly run by the man who literally wrote the book on social engineering may have fallen victim to a social engineering attack.

[–] Evotech@lemmy.world 16 points 3 months ago (1 children)

And makes it's living on telling other companies how to increase their security posture

[–] cheese_greater@lemmy.world 8 points 3 months ago

The grift has come fulk circle

[–] radivojevic@discuss.online 5 points 3 months ago (1 children)

We learn more lessons by failing than succeeding.

[–] octopus_ink@lemmy.ml 3 points 3 months ago

True, but Kevin certainly had his share of both.

[–] TimeSquirrel@kbin.melroy.org 14 points 3 months ago

Guess they didn't KnowBe4.

[–] GildorInglorion@lemmy.world 11 points 3 months ago (1 children)

(https://blog.knowbe4.com/how-a-north-korean-fake-it-worker-tried-to-infiltrate-us) They are saying they caught the guy before he had access to anything important.

[–] Landless2029@lemmy.world 9 points 3 months ago* (last edited 3 months ago)

He made it though onboarding and got a company laptop with creds. Got flagged by SEC because he got malware day 1. Also they dug in and he was connected to the states with a VPN.

HR failed. SEC caught it. Now SEC/CIO yell at HR.

[–] AlternateRoute@lemmy.ca 8 points 3 months ago

This report makes it sound like they had a video call with camera on, vs other reports where they recommend people have camera on because they didn't

also used AI tools to create a profile picture and match that face during the video conference calls.

This doesn't sounds like the video was on / faked only that they had a call where the profile picture was used.

[–] YeetPics@mander.xyz 7 points 3 months ago* (last edited 3 months ago)

Boy, I bet they wish they.. (drumroll) KnewBe4