‘Zoomsday’ hack uncovered using fewer than 20 AI prompts
Summary
Researchers at A Security discovered a severe security vulnerability in Zoom that could allow attackers to hijack a user's device during a meeting without any user interaction or visual cues. The exploit leveraged Zoom's screen annotation feature to execute malicious code, potentially stealing data or accessing hardware like cameras and microphones. Notably, the researchers developed this working exploit in a single day using fewer than 20 prompts on publicly available AI models. Zoom has since released a security patch to address the vulnerability across Windows, macOS, Linux, Android, and iOS.
(Source:The Verge)