عاجل
CN日本千葉縣遭遇史無前例豪雨,多市發布最高級大雨特別警報CN全球市場吸收中國過剩產能能力逼近極限,保護主義抬頭ESEl diésel rompe los cálculos del Gobierno: suben la rebaja del impuesto en septiembreESIncendio de Niebla: 60 vecinos regresan a sus casas mientras se intensifica la lucha en el flanco esteUKUK Defends Seizure of Russian 'Shadow Fleet' Oil Tanker Amid Putin's ThreatsRUUkrainian Initiative to Mobilize Childless Women Criticized as 'Genocide Policy'ARالأوضاع في شمال كردفان بعد استعادة الجيش السيطرةUSUganda's Lenacapavir Rollout: A Promising HIV Prevention Drug Faces Distribution and Funding ChallengesINNepal Loses Original 1816 Sugauli Treaty Document Amid Border Dispute with IndiaARزيلينسكي يطلب 300 صاروخ باتريوت من واشنطن: كمية غير كافية لأوكرانياCN日本千葉縣遭遇史無前例豪雨,多市發布最高級大雨特別警報CN全球市場吸收中國過剩產能能力逼近極限,保護主義抬頭ESEl diésel rompe los cálculos del Gobierno: suben la rebaja del impuesto en septiembreESIncendio de Niebla: 60 vecinos regresan a sus casas mientras se intensifica la lucha en el flanco esteUKUK Defends Seizure of Russian 'Shadow Fleet' Oil Tanker Amid Putin's ThreatsRUUkrainian Initiative to Mobilize Childless Women Criticized as 'Genocide Policy'ARالأوضاع في شمال كردفان بعد استعادة الجيش السيطرةUSUganda's Lenacapavir Rollout: A Promising HIV Prevention Drug Faces Distribution and Funding ChallengesINNepal Loses Original 1816 Sugauli Treaty Document Amid Border Dispute with IndiaARزيلينسكي يطلب 300 صاروخ باتريوت من واشنطن: كمية غير كافية لأوكرانيا
Newsgather
رجوعResearcher Uses AI to Build Working Zoom Exploit in Under 24 Hours
Researcher Uses AI to Build Working Zoom Exploit in Under 24 Hours
يتطور
Decryptقبل 9 ساعاتتقنية1 د قراءة

Researcher Uses AI to Build Working Zoom Exploit in Under 24 Hours

Israeli cybersecurity firm A Security warns of 'nation-state-grade' vulnerabilities that allow complete device takeover on Zoom.

نظرة سريعة

Israeli cybersecurity firm A Security revealed that a researcher used AI models to find Zoom vulnerabilities and build a working exploit within 24 hours, enabling silent device takeovers.

ملخص مُنشأ بالذكاء الاصطناعي

لماذا يهم

A Security published a report detailing vulnerabilities found in Zoom's annotation tool using AI prompts.

حجم الخط

AI is making it faster and easier to find serious security flaws. Now, a researcher says he used publicly available models to find vulnerabilities in the video chat platform Zoom and build a working attack in less than 24 hours.

Calling it ‘Zoomsday’ in a report published Tuesday, Israeli cybersecurity firm A Security said a researcher used fewer than 20 AI prompts to uncover flaws in Zoom’s annotation tool that could let someone in a meeting take control of another participant’s device without any action from the victim.

“Once the nefarious code is running on the victim's device, the threat actor can quietly steal personal data, switch on the microphone or camera to spy on the target, or install other malicious software,” A Security wrote. “In a large call, that's a room full of targets from a single message, with no safe seat in it.”

According to A Security, the attack was tested on Zoom’s apps for Windows, macOS, Linux, Android, and iOS. The firm called it “nation-state-grade,” arguing that building such an exploit once required specialists, months of work, and a large budget.

The flaws are tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415. CVEs are public identifiers for security vulnerabilities.

“Exploits like this one are weapons. Governments regulate their export. Criminal organizations pay millions for them,” they wrote. “Acquiring one has always required nation-state infrastructure, elite teams, and months of work.”

A Security said the exploit also enables attackers to either join or host a meeting, target any participant, and take over their machine with “no required action from the victim and no visual cue indicating the compromise.”

“It worked in both directions: a compromised presenter could reach every participant, and any participant could reach the presenter,” they wrote.

A Security said it reported the first flaw to Zoom on June 10, two days after discovering it. Zoom released fixes between June 22 and July 20, but users still needed to update because its server-side safeguard could not filter malicious messages in end-to-end encrypted meetings.

“As shared on our Zoom Security Bulletin page, we’ve already resolved this issue," a Zoom spokesperson told Decrypt. "We always recommend users keep up to date with the latest version of Zoom so that they’re taking advantage of our latest features and updates."

ما الذي يجب مراقبته

توقعات الذكاء الاصطناعي — احتمالات وليست حقائق

  • Zoom users will need to update apps to secure against the CVEs.

    مرجح جداً · خلال أيام

أسئلة مفتوحة

  • Were any malicious actors able to exploit the flaws before patches were applied?
  • What specific AI models were used by the researcher?

مواضيع ذات صلة

This article was originally published by Decrypt.

أخبار ذات صلة

المزيد حول هذا الموضوعzoom