My work laptop got crypto'd after I clicked a fake Zoom invite last Tuesday
IT said the email passed their filter because it came from a compromised vendor account, but the real kicker was that the ransomware spread through our shared drive in under 40 minutes, so has anyone else seen those 'meeting rescheduled' links that look too clean to spot?
Yikes, I don't buy the "too clean to spot" angle, those invites almost always have a weird sender domain if you hover over the link first. The shared drive blowing up in 40 minutes is the real problem, that's a permissions issue, not a phishing one.