CriticalSecurity & Privacy
‘Zoomsday’ hack uncovered using fewer than 20 AI prompts
A critical Zoom vulnerability exploitable through the annotation feature was discovered using fewer than 20 AI prompts, enabling attackers to remotely execute malicious code and compromise all meeting participants' devices without detection. This incident demonstrates that AI-powered vulnerability discovery has democratized what previously required nation-state resources, significantly lowering the barrier to entry for sophisticated exploits and expanding the attack surface for enterprise communications platforms. IT organizations must urgently reassess their vulnerability management strategies, patch timelines, and assumption that complex exploits remain exclusive to well-resourced threat actors.

Zoom has patched a major security vulnerability that could allow an attacker to hijack anyone's device during a meeting. In a blog post on Tuesday, researchers at A Security say they uncovered the flaw using "fewer than 20 prompts on publicly available AI models," as reported earlier by Wired. The exploit involved Zoom's annotation feature, which allows users to draw on their screen while sharing it with other meeting participants. With the exploit, an attacker could join or host a meeting and run malicious code on victims' devices, allowing them to steal data, turn on the camera or microphone, or install malware. The attack required no act … Read the full story at The Verge.