AI News HubLIVE
站內改寫1 分鐘閱讀

待翻譯:‘Zoomsday’ hack uncovered using fewer than 20 AI prompts

AI 服務暫時不可用,以下為來源摘要,待恢復後補全翻譯:Zoom has patched a major security vulnerability that could allow an attacker to hijack anyone's device during a meeting. In a blog post on Tuesday, researchers at A Security say they uncovered the flaw using "fewer than 20 prompts on publicly available AI models," as reported earlier by Wired. The exploit involved Zoom's annotation feature, which allows users to draw on their screen while sharing it with other meeting participants. With the exploit, an attacker could join or host a meeting and run malicious code on victims' devices, allowing them to steal data, turn on the camera or microphone, or install malware. The attack required no act … Read the full story at The Verge.

來源The Verge AI作者: Emma Roth

AI 服務暫時不可用,以下為來源正文,待恢復後補全翻譯。

Zoom has patched a major security vulnerability that could allow an attacker to hijack anyone’s device during a meeting. In a blog post on Tuesday, researchers at A Security say they uncovered the flaw using “fewer than 20 prompts on publicly available AI models,” as reported earlier by Wired. The exploit involved Zoom’s annotation feature, which allows users to draw on their screen while sharing it with other meeting participants. With the exploit, an attacker could join or host a meeting and run malicious code on victims’ devices, allowing them to steal data, turn on the camera or microphone, or install malware. The attack required no action from victims and showed “no visual cue indicating the compromise,” according to A Security. [Media: https://youtu.be/wejvsWneFko?si=3Zp7Ux_CPujAZxYu] “Producing a working exploit against it has always been nation-state work: elite teams, months of effort, budgets that governments regulate as weapons,” Idan Levcovich, a vulnerability researcher at A Security, writes in the blog post. “A [Security] did it in a single day, with an AI agent and models anyone can access today.” Zoom issued a fix for the vulnerability on Tuesday, which impacted the app across Windows, macOS, Linux, Android, and iOS.