'Zoomsday' hack uncovered using fewer than 20 AI prompts
Image credit: The Verge · tap image for original
Researchers showed a Zoom flaw that let an attacker seize every device on a call after fewer than 20 AI prompts.
Summary
- Security researchers told The Verge a Zoom vulnerability allowed takeover of other participants' devices during a call.
- They reported uncovering and developing the attack path with fewer than 20 prompts to an AI system.
- The bug sits in the same era as prior Zoom screen-sharing weaknesses that let outsiders meddle with calls.
- Enterprise and government users still run sensitive meetings on the platform despite repeated security scares.
- AI assistance collapsed the time from curiosity to working exploit for the researchers' demo.
Commentary
When an AI can help weaponize a meeting app in under 20 prompts, assume the other side already did it without a press cycle.
Critical infrastructure and public officials should default to locked-down stacks, not consumer convenience.
China and DPRK operators will industrialize this class of find. Patch speed is national security.
Discussion
Did AI just erase the amateur hour in Zoom exploitation?
sec_rat
Fewer than 20 prompts is the headline because it kills the talent myth.
midwest_vet
Treat meeting apps like weapons platforms. Update or get out.
campus_take
Researchers are the problem for disclosing scary things.
rule_first
Disclosure beats silent enemy use. Patch is the adult response.
tokyo_ally
Government Zoom habits need a rethink across the alliance.
aid_fan
More digital literacy workshops will fix zero-days.
docket_rat
Workshops do not patch shared-screen bugs. Vendors and mandates do.
border_dad
If a call can own the endpoint, it is an access problem like a bad border gate.
press_clip
Verge named Zoomsday. CISOs should not wait for the meme to fade.
night_shift
Force updates. Kill legacy clients. Assume AI-sped offense.
Inspired by public posts on X — paraphrased, not attributed.