Summary

Summary

  • A Zoom Workplace vulnerability allowed attackers to run code on meeting participants’ devices through screen sharing, even without direct interaction.
  • The flaw affected every supported operating system running Zoom Workplace versions earlier than 7.1.0.
  • Zoom has patched the vulnerability, so users should check their installed version and update to the latest release immediately. A security researcher discovered a vulnerability in Zoom Workplace that allowed an attacker to run code on participants’ devices. Simply having screen sharing enabled by one participant could put everyone in the meeting at risk, even those who never interacted with the attacker. The bug wasn’t limited to a specific operating system, either, affecting Windows, MacOS, Linux, iOS, and Android. According to the security advisory that Zoom issued, it affected all supported platforms running versions earlier than 7.1.0. The Zoom vulnerability is patched, yet AI has made such bugs easier to exploit While machine-learning has noticeably helped detect and prevent cybersecurity threats, there exists plenty of ways that hackers can use generative AI to carry out their attacks. As covered by Wired magazine, cybersecurity firm A Security claims that the democratization of such AI tools has dropped the barrier to entry significantly, and hackers could be only a few prompts away from carrying out an attack: “Before, it would have taken a team of five people maybe six months with a lot of refining and iteration to find this,” A Security’s Omer Guli told Wired. “Now people can reach the same results with under 20 prompts. And Zoom is an important type of target because people assume trust when using it. They don’t see it as a threat.” This Zoom vulnerability wasn’t itself an AI-powered attack, but it arrives as AI is making malware significantly more adaptable. Researchers have already demonstrated an AI-powered worm that can spread and modify its behavior in real time, potentially allowing threats to respond to defenses as they encounter them. That makes promptly closing a known entry point, such as this Zoom flaw, more important than ever. Thankfully, most software companies are quick at updating and patching security issues, but not every newly-discovered vulnerability requires an immediate update. Still, many such issues could be avoided if people installed important security updates as soon as they are rolled out. To check your Zoom version, open the app, select your profile picture, and go to Help > About Zoom Workplace. If it’s outdated, select Check for Updates from the same menu or download the latest version directly from Zoom’s website.

By Hamed Paydarfar

Original Article