New “Zoomsday” exploit could expose crypto users to zero click attacks
A newly disclosed set of Zoom vulnerabilities has shown how attackers could take control of another meeting participants device without any action from the victim, creating a fresh security risk for crypto users who have repeatedly been targeted through video calls. SummaryA Security said a researcher used fewer than 20 AI prompts to find three Zoom vulnerabilities and build a working exploit in under 24 hours.The Zoomsday attack could take control of a meeting participants device without requiring any action from the victim.Crypto users face added risk as hackers have previously used compromised Zoom meetings to steal wallet data and other sensitive information.Zoom released fixes between June 22 and July 20, but users on older versions still need to update their apps. According to Israeli cybersecurity firm A Security, a researcher used fewer than 20 prompts with publicly available artificial intelligence models to uncover the flaws and build a working attack in less than 24 hours. The firm named the attack “Zoomsday” and said the vulnerabilities affected Zooms annotation system, which lets meeting participants draw or add notes to shared content. Once exploited, the flaws could allow malicious code to run on another participant‘s device without requiring the person to download a file,