‘Zoomsday’ hack uncovered using fewer than 20 AI prompts
TL;DR
Zoom has patched a serious vulnerability that let an attacker hijack another participant's device during a meeting. Researchers at A Security say they found the flaw using fewer than 20 prompts on publicly available AI models. The bug sat in Zoom's annotation feature, which lets participants draw on a shared screen. An attacker could run malicious code on victims' devices to steal data, switch on the camera or microphone, or install malware.
Nauti's Take
The real progress here is the method: if 20 prompts are enough to surface a critical flaw in mainstream software, serious security research gets much cheaper and faster. That is exactly the risk too, because the same shortcut is open to attackers, and they do not wait for a patch.
For teams the takeaway is simple, install the update now and assume the discovery rate for widely used tools keeps climbing.