خبری درباره‌ی Manta Network (MANTA)

New “Zoomsday” exploit could expose crypto users to zero click attacks

crypto.news ۲۰۲۶/۰۸/۱۴ خلاصه‌ی فارسی · ۴۴۴ کلمه
New “Zoomsday” exploit could expose crypto users to zero click attacks

A newly disclosed set of Zoom vulnerabilities has shown how attackers could take control of another meeting participant’s device without any action from the victim, creating a fresh security risk for crypto users who have repeatedly been targeted through video calls. Summary A Security said a researcher used fewer than 20 AI prompts to find three Zoom vulnerabilities and build a working exploit in under 24 hours. The Zoomsday attack could take control of a meeting participant’s device without requiring any action from the victim. Crypto users face added risk as hackers have previously used compromised Zoom meetings to steal wallet data and other sensitive information. Zoom released fixes between June 22 and July 20, but users on older versions still need to update their apps. According to Israeli cybersecurity firm A Security, a researcher used fewer than 20 prompts with publicly available artificial intelligence models to uncover the flaws and build a working attack in less than 24 hours. The firm named the attack “Zoomsday” and said the vulnerabilities affected Zoom’s annotation system, which lets meeting participants draw or add notes to shared content. Once exploited, the flaws could allow malicious code to run on another participant’s device without requiring the person to download a file, click a link, or approve an action, according to the report. According to the firm, the attacker could then steal personal information, install malware, or activate a device’s microphone and camera. For cryptocurrency users, the ability to compromise a computer directly through a meeting could carry added risks because attackers have previously used Zoom calls to reach crypto wallets, private files and other sensitive information. Zoom exploit could target any meeting participant The vulnerabilities, tracked as CVE-2026-53413, CVE-2026-53414 and CVE-2026-53415, were tested against Zoom applications running on Windows, macOS, Linux, Android and iOS. The attack could work from either side of a call. According to the researchers, a compromised presenter could attack participants, while a participant could also target the presenter. An attacker only needed to join or host the meeting before sending the malicious data required to trigger the vulnerability. No further interaction was required from the target, and A Security said the victim would receive no visible warning that the device had been compromised. You might also like: North Korean ‘fake Zoom’ hustle drains $300m from crypto execs’ wallets “Once the nefarious code is running on the victim’s device, the threat actor can quietly steal personal data, switch on the microphone or camera to spy on the target, or install other malicious software,” the firm said. “Exploits like this one are weapons. Governments regulate their export. Criminal organizations pay millions for them,” the researchers wrote.

عنوان اصلی (انگلیسی): New “Zoomsday” exploit could expose crypto users to zero click attacks

مشاهده‌ی خبر کامل در منبع ↗ بازگشت به Manta Network

این خلاصه به‌صورت خودکار از کوین‌مارکت‌کپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاع‌رسانی است و توصیه‌ی معاملاتی نیست.