Source: The Verge · 2026-08-11 · Original article ↗

'Zoomsday' hack uncovered using fewer than 20 AI prompts

Image credit: The Verge · tap image for original

Researchers showed a Zoom flaw that let an attacker seize every device on a call after fewer than 20 AI prompts.

Summary

Commentary

When an AI can help weaponize a meeting app in under 20 prompts, assume the other side already did it without a press cycle.

Critical infrastructure and public officials should default to locked-down stacks, not consumer convenience.

China and DPRK operators will industrialize this class of find. Patch speed is national security.

Discussion

Did AI just erase the amateur hour in Zoom exploitation?
sec_rat 5h
Fewer than 20 prompts is the headline because it kills the talent myth.
midwest_vet 4h
Treat meeting apps like weapons platforms. Update or get out.
campus_take 4h
Researchers are the problem for disclosing scary things.
rule_first 3h
Disclosure beats silent enemy use. Patch is the adult response.
tokyo_ally 3h
Government Zoom habits need a rethink across the alliance.
aid_fan 2h
More digital literacy workshops will fix zero-days.
docket_rat 2h
Workshops do not patch shared-screen bugs. Vendors and mandates do.
border_dad 90m
If a call can own the endpoint, it is an access problem like a bad border gate.
press_clip 70m
Verge named Zoomsday. CISOs should not wait for the meme to fade.
night_shift 40m
Force updates. Kill legacy clients. Assume AI-sped offense.
Inspired by public posts on X — paraphrased, not attributed.

More from this rōnin

Stories → Discoveries → Books → Buy me a coffee →
NOBUNAGA samurai icon
🏯 The wandering samurai now sits upon a shelf.
Hold the whole journey in your hands. Paperback today, the Kindle scroll very soon.
Visit my shelf on Amazon →
NOBUNAGA icon
One hand draws, one hand writes, and the tea has gone cold.
If you smiled even once, a coffee helps the next story get made.
☕ Treat the samurai to a coffee