The Axios supply chain attack used individually targeted social engineering

simonwillison.net

47 points by cmitsakis 2 days ago


skrtskrt - 2 days ago

As a general rule I install none of these web conferencing things on my machine. Either the browser version works fine, as Google Meet, Zoom, Teams and even WebEx all do, or this is not a meeting I need to be on.

jruohonen - 2 days ago

"the meeting said something on my system was out of date. i installed the missing item as i presumed it was something to do with teams, and this was the RAT."

Oh dear.

PufPufPuf - 2 days ago

I wonder if I would have been saved by my absolute disdain for installing anything Microsoft Teams-related on my computer. The web version works fine, thanks.

Up to usual Microsoft Teams standards

jeffrallen - a day ago

I don't want to pile on this poor guy, but video conferencing software in browser works, and does not require software installation.

Use the browser sandbox to protect yourself.

jeremie_strand - 2 days ago

[dead]