this post was submitted on 20 Dec 2024
18 points (95.0% liked)

Cybersecurity

5846 readers
91 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected]

Notable mention to [email protected]

founded 2 years ago
MODERATORS
top 4 comments
sorted by: hot top controversial new old
[–] [email protected] 4 points 1 day ago (2 children)

So it's still ultimately the victim opening a dodgy email attachment or link. Apparently, people will never learn not to do this.

[–] [email protected] 3 points 1 day ago (1 children)

You get 20 emails a week with pdfs attached claiming to be sponsoring offers. How do you know the malware one is laced with malware?

[–] [email protected] 2 points 1 day ago

You really don't. The clever bit is the social engineering so that the victim has their guard down. But it does pay to be extra careful with all email attachments and links.

[–] [email protected] 4 points 1 day ago

It's more nuanced than that. Collaboration is often initiated by simple, "Hey, can we collaborate?" emails, and that's how these are crafted to look. Legitimate emails of this sort may or may not have attached business proposals.

What is being exploited here is the banality of these kinds of routine business interactions, and it highlights where people have gotten lax in their own practices.

So while I agree that it's essentially people not following the same standard security advice that's been repeated over the last two decades, there's an element of "business dealings are not exempt" that many of these and future entrepreneurs need to remember.