cross-posted from: https://feddit.org/post/1094761

Archived version

KnowBe4 needed a software engineer for our internal IT AI team. “We posted the job, received resumes, conducted interviews, performed background checks, verified references, and hired the person,” the firm writes on its blog.

“We sent them their Mac workstation, and the moment it was received, it immediately started to load malware.”

[Special points to KnowBe4 for publishing this on its blog. If this can happen to a security awareness firm, it can happen to everyone.]

  • jet@hackertalks.com
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 months ago

    Hiring somebody without ever physically seeing them is a curious reality

    I’m surprised , if the intention has stated, is to work well paid job and place a resource, why load malware at all?

    If they’re just trying to remote into the device, why are they remoting indirectly to the laptop? Why not use a remote KVM that hooks up to the output and USB ports?