Researchers found a way to hijack devices through Zoom screen sharing

Researchers discovered critical vulnerabilities in Zoom's screen-sharing annotation protocol that could allow silent device hijacking of any participant using fewer than 20 AI-assisted prompts, demonstrating the democratization of AI-powered vulnerability discovery and drastically lowering barriers to sophisticated cyberattacks. While Zoom has already deployed fixes across all platforms, this incident exposes a strategic risk where trusted communication tools can become attack vectors, with potential for lateral movement and enterprise-wide compromise through a single compromised employee. IT leaders must reassess their assumptions about the security posture of widely-trusted third-party platforms and strengthen endpoint security and network segmentation strategies accordingly.

Lily Hay Newman, wired.comArs Technica2 min read
Read full article
Researchers found a way to hijack devices through Zoom screen sharing
As AI models gain advanced capabilities to find vulnerabilities in software, develop ways to exploit them, and even carry out autonomous hacking sprees, researchers offered a sobering new example on Tuesday, disclosing vulnerabilities in the video conferencing platform Zoom that could have been exploited to take over targets’ devices. Anyone on a call that involved screen sharing, whether participants or the host, would have been vulnerable to a silent attack that could be carried out with no indication and no interaction from the victim. Researchers from the digital defense firm A Security say the bug was discovered in early June using publicly available AI models, and that it took fewer than 20 prompts to uncover the vulnerabilities and create a working attack. Zoom issued a security advisory on Tuesday, including details about fixes the company has already begun rolling out to address the flaws, which affected devices running all operating systems that Zoom supports—Windows, macOS, Linux, iOS, and Android. “What is interesting for us and what we believe is dangerous is the democratization of these capabilities—the barrier to entry is dropping rapidly,” A Security cofounder Omer Gull told WIRED ahead of the disclosure. “Before it would have taken a team of five people maybe six months with a lot of refining and iteration to find this. Now people can reach the same results with under 20 prompts. And Zoom is an important type of target because people assume trust when using it. They don’t see it as a threat.”Read full article Comments