The flaws, tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, were discovered by Israeli cybersecurity firm A Security. Researchers used fewer than 20 prompts with publicly available artificial intelligence models to identify the weaknesses and develop a functional exploit in under 24 hours. Once triggered, the malicious code executes silently, enabling attackers to install malware, activate microphones or cameras, and siphon sensitive data without the victim seeing a single warning prompt or clicking a link.
This development marks a shift in how attackers target the crypto industry. Previous campaigns against executives and developers relied on social engineering, such as deepfake video calls or requests to install fake software updates. The Zoomsday method removes these hurdles by turning a standard meeting session into an entry point. Because the exploit targets the annotation system, it functions regardless of whether the attacker is the presenter or a participant. While Zoom released patches between June 22 and July 20, the firm warns that server-side protections are insufficient for end-to-end encrypted meetings, making manual application updates mandatory for all users.

Comments (0)
No comments yet. Be the first!