Negócios em Emersão  ·  Vamos Emergir?  ·  Cadastre-se e ganhe 50 REC de bonus

Researchers found a way to hijack devices through Zoom screen sharing

Redação Recifes
123 visualizações
Researchers found a way to hijack devices through Zoom screen sharing

Researchers found a way to hijack devices through Zoom screen sharing. A public AI tool found the dangerous Zoom flaw in under 20 prompts.

O que aconteceu

As AI models gain advanced capabilities to find vulnerabilities in software, develop ways to exploit them, and even carry out autonomous hacking sprees, researchers offered a sobering new example on Tuesday, disclosing vulnerabilities in the video conferencing platform Zoom that could have been exploited to take over targets’ devices.

Anyone on a call that involved screen sharing, whether participants or the host, would have been vulnerable to a silent attack that could be carried out with no indication and no interaction from the victim.

Researchers from the digital defense firm A Security say the bug was discovered in early June using publicly available AI models, and that it took fewer than 20 prompts to uncover the vulnerabilities and create a working attack.

Por que importa

A pauta interessa a quem acompanha Tech porque altera expectativas e decisões práticas.

Consequência prática

Zoom issued a security advisory on Tuesday, including details about fixes the company has already begun rolling out to address the flaws, which affected devices running all operating systems that Zoom supports—Windows, macOS, Linux, iOS, and Android.

“What is interesting for us and what we believe is dangerous is the democratization of these capabilities—the barrier to entry is dropping rapidly,” A Security cofounder Omer Gull told WIRED ahead of the disclosure.

“Before it would have taken a team of five people maybe six months with a lot of refining and iteration to find this.

Now people can reach the same results with under 20 prompts.

As AI models gain advanced capabilities to find vulnerabilities in software, develop ways to exploit them, and even carry out autonomous hacking sprees, researchers offered a sobering new example on Tuesday, disclosing vulnerabilities in the video conferencing platform Zoom that could have been exploited to take over targets’ devices. o movimento reforça a leitura de que decisões em Tech precisam ser acompanhadas com atenção aos dados e ao desfecho concreto.

Anyone on a call that involved screen sharing, whether participants or the host, would have been vulnerable to a silent attack that could be carried out with no indication and no interaction from the victim. o movimento reforça a leitura de que decisões em Tech precisam ser acompanhadas com atenção aos dados e ao desfecho concreto.

Researchers from the digital defense firm A Security say the bug was discovered in early June using publicly available AI models, and that it took fewer than 20 prompts to uncover the vulnerabilities and create a working attack. o movimento reforça a leitura de que decisões em Tech precisam ser acompanhadas com atenção aos dados e ao desfecho concreto.

Zoom issued a security advisory on Tuesday, including details about fixes the company has already begun rolling out to address the flaws, which affected devices running all operating systems that Zoom supports—Windows, macOS, Linux, iOS, and Android. o movimento reforça a leitura de que decisões em Tech precisam ser acompanhadas com atenção aos dados e ao desfecho concreto.

Artigo originalmente publicado em arstechnica.com
Compartilhar:

Comentários

Seja o primeiro a comentar!