New “Zoomsday” exploit could expose crypto users to zero click attacks

1 hour ago 2



A newly disclosed set of Zoom vulnerabilities has shown how attackers could take control of another meeting participant’s device without any action from the victim, creating a fresh security risk for crypto users who have repeatedly been targeted through video calls. Summary A Security said a researcher used fewer than 20 AI prompts to find three Zoom vulnerabilities and build a working exploit in under 24 hours. The Zoomsday attack could take control of a meeting participant’s device without requiring any action from the victim. Crypto users face added risk as hackers have previously used compromised Zoom meetings to steal wallet data and other sensitive information. Zoom released fixes between June 22 and July 20, but users on older versions still need to update their apps. According to Israeli cybersecurity firm A Security, a researcher used fewer than 20 prompts with publicly available artificial intelligence models to uncover the flaws and build a working attack in less than 24 hours. The firm named the attack “Zoomsday” and said the vulnerabilities affected Zoom’s annotation system, which lets meeting participants draw or add notes to shared content. Once exploited, the flaws...

Read Entire Article