Attention, Zoom users: Install the latest software patch right away.
Researchers from cybersecurity firm A Security identified a vulnerability that could allow bad actors to completely commandeer the devices of Zoom meeting participants. The exploit requires no action from victims, nor does it offer any visual cues that they’ve been compromised. Once in control, hackers can steal data, run malicious software, or use the device’s microphone or camera to spy.
“In a large call, that’s a room full of targets from a single message, with no safe seat in it,” A Security researcher Idan Levcovich wrote in a blog post.
Researchers from A Security discovered the flaw back in June, Wired reported, but only published more detail on Aug 11 in order to offer Zoom time to fix it. Zoom disclosed the vulnerability in a security bulletin on Aug 11, and encouraged users to download the most updated version of the videoconferencing platform. Affected products include Zoom Workplace platforms that predate 7.1.5 and 7.0.6, the versions of Zoom’s virtual desktop infrastructure prior to 7.0.11 and 6.6.16, and versions of Zoom Rooms and the Zoom Meeting software development kit that predate 7.1.0.
Zoom did not immediately respond to Inc’s request for comment.
Levcovich wrote in A Security’s blog that it took fewer than 20 AI prompts and 24 hours to find the flaw and build a means of exploiting it. It’s remarkable, he wrote, because Zoom is “the class of target defenders assume is safe because it is large, scrutinised, and opaque.
“Producing a working exploit against it has always been nation-state work: elite teams, months of effort, budgets that governments regulate as weapons,” he wrote in the blog, adding that his team “did it in a single day, with an AI agent and models anyone can access today.”
As AI grows more sophisticated, frontier labs and cybersecurity experts alike are warning it is accelerating the pace of cyberattacks. There have even been recent cases of AI models going rogue and hacking organisations autonomously. But just as AI can empower attackers, it can also increase the speed and sophistication of defence.
A Security describes these capabilities as something like a genie escaping its bottle, and urges defenders to take certain actions to reduce their risk. Levcovich recommended that companies “turn the same offensive capability inward” through continuous vulnerability monitoring, and patch vulnerabilities quickly when they are found. He advised leaders to reduce potential attack surfaces by eliminating unnecessary permissions like, for example, the ways participants can join Zoom meetings, and who can share their screen. Lastly, A Security recommends multilevel cybersecurity protections that block malware and monitor system functioning at the device level.
“The barrier that kept these weapons scarce has collapsed, and it will not come back. Attackers already have this capability. The only open question is whether defenders reach their own exposures first,” Levcovich wrote. – Inc./Tribune News Service
