mt logoMyToken
ETH Gas
EN

研究人员用不到20条AI提示词发现Zoom漏洞,24小时内构建出攻击链

Favoritecollect
Shareshare

PANews 8月13日消息,据Decrypt报道,以色列网络安全公司ASecurity发布报告称,一名研究人员使用公开可用的AI模型,在不到24小时内通过不到20条提示词发现了Zoom注释工具中的多个漏洞,并构建出可利用的攻击链。该漏洞编号为CVE-2026-53413、CVE-2026-53414和CVE-2026-53415,攻击者可借此在会议中无需受害者任何操作即可远程执行代码,控制其设备并窃取数据、开启麦克风或摄像头。

该攻击在Windows、macOS、Linux、Android及iOS版Zoom上均测试有效,ASecurity称其达到“国家级”水准,以往构建此类利用工具需要专业团队数月工作和巨额预算。ASecurity于6月10日向Zoom报告首个漏洞,Zoom于6月22日至7月20日间陆续发布修复,但端到端加密会议中的服务器端防护无法过滤恶意消息,用户需手动更新。Zoom发言人确认问题已解决并建议用户保持最新版本。

Disclaimer: This article is copyrighted by the original author and does not represent MyToken’s views and positions. If you have any questions regarding content or copyright, please contact us.(www.mytokencap.com)contact
More exciting content is available on
X(https://x.com/MyTokencap)
or join the community to learn more:MyToken-English Telegram Group
https://t.me/mytokenGroup