In section Cryptocurrency

Zoomsday exploit turns Zoom meetings into zero-click attack vectors

A newly disclosed set of vulnerabilities, dubbed Zoomsday, allows attackers to seize control of a target's device during a Zoom call without requiring any user interaction. By exploiting the platform’s annotation system, hackers can bypass traditional social engineering, posing a severe threat to high-profile cryptocurrency users.

Zoomsday exploit turns Zoom meetings into zero-click attack vectors

The flaws, tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, were discovered by Israeli cybersecurity firm A Security. Researchers used fewer than 20 prompts with publicly available artificial intelligence models to identify the weaknesses and develop a functional exploit in under 24 hours. Once triggered, the malicious code executes silently, enabling attackers to install malware, activate microphones or cameras, and siphon sensitive data without the victim seeing a single warning prompt or clicking a link.

This development marks a shift in how attackers target the crypto industry. Previous campaigns against executives and developers relied on social engineering, such as deepfake video calls or requests to install fake software updates. The Zoomsday method removes these hurdles by turning a standard meeting session into an entry point. Because the exploit targets the annotation system, it functions regardless of whether the attacker is the presenter or a participant. While Zoom released patches between June 22 and July 20, the firm warns that server-side protections are insufficient for end-to-end encrypted meetings, making manual application updates mandatory for all users.

Share:on TelegramXFacebook

Subscribe to our newsletter

Once a week — the best stories from our editors, no ads or push notifications. Delivered Sunday morning.

Comments (0)

Leave a comment

No comments yet. Be the first!