Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
15 résultats taggé zoom  ✕
Mitigating ELUSIVE COMET Zoom remote control attacks - The Trail of Bits Blog https://blog.trailofbits.com/2025/04/17/mitigating-elusive-comet-zoom-remote-control-attacks/
21/04/2025 09:10:28
QRCode
archive.org

When our CEO received an invitation to appear on “Bloomberg Crypto,” he immediately recognized the hallmarks of a sophisticated social engineering campaign. What appeared to be a legitimate media opportunity was, in fact, the latest operation by ELUSIVE COMET—a threat actor responsible for millions in cryptocurrency theft through carefully constructed social engineering attacks.

This post details our encounter with ELUSIVE COMET, explains their attack methodology targeting the Zoom remote control feature, and provides concrete defensive measures organizations can implement to protect themselves.

trailofbits EN 2025 ELUSIVE-COMET CEO invitation zoom threat-actor social-engineering crypto
Fake Zoom Ends in BlackSuit Ransomware https://thedfirreport.com/2025/03/31/fake-zoom-ends-in-blacksuit-ransomware/
31/03/2025 20:56:58
QRCode
archive.org
thumbnail

Key Takeaways The threat actor gained initial access by a fake Zoom installer that used d3f@ckloader and IDAT loader to drop SectopRAT. After nine days of dwell time, the SectopRAT malware dropped …

thedfirreport EN 2025 Fake Zoom IDAT loader SectopRAT d3f@ckloader incident analysis
CVE-2024-39825 and CVE-2024-39818: High-Risk Zoom Flaws Require Urgent Updates https://securityonline.info/cve-2024-39825-and-cve-2024-39818-high-risk-zoom-flaws-require-urgent-updates/
13/08/2024 21:53:19
QRCode
archive.org
thumbnail

Among the most critical are CVE-2024-39825 and CVE-2024-39818, both with a CVSS score of 8.5, indicating a high level of severity

securityonline EN 2024 CVE-2024-39825 CVE-2024-39818 High-Risk Zoom
RATs Distributed Through Skype, Zoom, & Google Meet Lures https://www.zscaler.com/blogs/security-research/android-and-windows-rats-distributed-online-meeting-lures
06/03/2024 06:41:27
QRCode
archive.org
thumbnail

Threat actors are creating and using fake Skype, Zoom, and Google Meet pages to spread RATs.

zscaler EN 2024 fake Skype Zoom meet RAT Lures
Zoom fixed critical flaw CVE-2024-24691 in Windows software https://securityaffairs.com/159121/security/zoom-crirical-cve-2024-24691.html
14/02/2024 20:15:28
QRCode
archive.org
thumbnail

Zoom fixed 7 flaws in its desktop and mobile applications, including a critical bug (CVE-2024-24691) affecting the Windows software

securityaffairs CVE-2024-24691 EN 2024 Zoom Windows critical
Investigation: Apparent Russian disinformation group posing as ex-president Poroshenko targets foreign fighters in Ukraine https://kyivindependent.com/investigation-apparent-russian-disinformation-group-posing-as-ex-president-poroshenko-targets-foreign-fighters-in-ukraine/
04/02/2024 10:45:41
QRCode
archive.org
thumbnail
  • An apparent Russian state-aligned group is targeting Ukraine’s International Legion in a disinformation campaign
  • The Kyiv Independent obtained and analyzed exclusive video that shows the group used doctored footage to pose as the Ukrainian ex-president on a Zoom call that took place in early January
  • Legion members are being tricked into agreeing with incendiary statements against Zelensky
  • Lack of cultural context, morale issues and low pay in some units have made the International Legion more susceptible to such attacks
  • The attack appears linked to the Russian government-aligned provocateurs Vladimir Kuznetsov and Alexey Stolyarov, known as Vovan and Lexus
  • The effort highlights ongoing disinformation threats in the Ukraine-Russia war as well as possible information security vulnerabilities of Ukraine’s foreign fighters
kyivindependent EN 2024 Russia-Ukraine-war deepfake TA499 Zoom
Unveiling VISS: a revolutionary approach to vulnerability impact scoring https://www.zoom.com/en/blog/viss-approach-to-vulnerability-impact-scoring/
20/12/2023 20:59:39
QRCode
archive.org
thumbnail

Our open-source vulnerability impact scoring system is now available and enhances incident response capabilities. Here's how VISS is unique.

zoom EN 2023 VISS vulnerability impact scoring
Zoom Patches High Risk Flaws on Windows, MacOS Platforms https://www.securityweek.com/zoom-patches-high-risk-flaws-windows-macos-platforms
11/01/2023 09:23:06
QRCode
archive.org

Video messaging giant Zoom has released patches for multiple security vulnerabilities that expose both Windows and macOS users to malicious hacker attacks.

securityweek EN 2023 CVE-2022-36930 CVE-2022-36929 CVE-2022-36927 patch-tuesday zoom zoom-rooms windows macos video-conferencing video-messaging privilege-escalation vulnerability
New Malware Campaign Targets Zoom Users https://blog.cyble.com/2022/09/19/new-malware-campaign-targets-zoom-users/
26/09/2022 09:49:59
QRCode
archive.org
thumbnail

Cyble Research and Intelligence Labs analyzes a new malware campaign targeting Zoom users.

cyble EN 2022 Malware Zoom Vidar Stealer
Zoom’s latest update on Mac includes a fix for a dangerous security flaw https://www.theverge.com/2022/8/14/23305548/zoom-update-macos-fix-dangerous-security-flaw-hackers?scrolla=5eb6d68b7fedc32c19ef33b4
16/08/2022 06:51:56
QRCode
archive.org
thumbnail

Zoom has issued a patch for a bug on macOS that could allow a hacker to take control of a user’s operating system (via MacRumors). In an update on its security bulletin, Zoom acknowledges the issue (CVE-2022-28756) and says a fix is included in version 5.11.5 of the app on Mac, which you can (and should) download now.

theverge EN 2022 CVE-2022-28756 macos Zoom
You're M̶u̶t̶e̶d̶ Rooted https://speakerdeck.com/patrickwardle/youre-muted-rooted
13/08/2022 22:44:11
QRCode
archive.org
thumbnail

With a recent market cap of over $100 billion and the genericization of its name, the popularity of Zoom is undeniable. But what about its security? This imperative question is often quite personal, as who amongst us isn't jumping on weekly (daily?) Zoom calls?

In this talk, we’ll explore Zoom’s macOS application to uncover several critical security flaws. Flaws, that provided a local unprivileged attacker a direct and reliable path to root.

The first flaw, presents itself subtly in a core cryptographic validation routine, while the second is due to a nuanced trust issue between Zoom’s client and its privileged helper component.

After detailing both root cause analysis and full exploitation of these flaws, we’ll end the talk by showing how such issues could be avoided …both by Zoom, but also in other macOS applications.

patrickwardle EN 2022 macOS zoom rooted defcon PoC
Zoom Zero Day: 4+ Million Webcams & maybe an RCE? Just get them to visit your website! https://infosecwriteups.com/zoom-zero-day-4-million-webcams-maybe-an-rce-just-get-them-to-visit-your-website-ac75c83f4ef5
03/06/2022 08:54:50
QRCode
archive.org

A vulnerability in the Mac Zoom Client allows any malicious website to enable your camera without your permission. The flaw potentially exposes up to 750,000 companies around the world that use Zoom to conduct day-to-day business.

infosecwriteups EN 2019 Zoom macos Apple malicious CVE-2019–13449 CVE-2019–13450
Apple has pushed a silent Mac update to remove hidden Zoom web server https://techcrunch.com/2019/07/10/apple-silent-update-zoom-app/
03/06/2022 08:52:49
QRCode
archive.org
thumbnail

Apple has released a silent update for Mac users removing a vulnerable component in Zoom, the popular video conferencing app, which allowed websites to automatically add a user to a video call without their permission. The Cupertino, Calif.-based tech giant told TechCrunch that the update — now released — removes the hidden web server, which […]

techcrunch 2019 macos Zoom privacy apple EN patch silent update hidden CVE-2019–13449
New Zoom Flaws Could Let Attackers Hack Victims Just by Sending them a Message https://thehackernews.com/2022/05/new-zoom-flaws-could-let-attackers-hack.html
25/05/2022 08:13:54
QRCode
archive.org

Popular video conferencing service Zoom has resolved as many as four security vulnerabilities, which could be exploited to compromise another user over chat by sending specially crafted Extensible Messaging and Presence Protocol (XMPP) messages and execute malicious code.

thehackernews EN 2022 XMPP Zoom CVE-2022-22784 CVE-2022-22785 CVE-2022-22786 CVE-2022-22787
Why is the Zoom app listening on my microphone... https://community.zoom.com/t5/Meetings/Why-is-the-Zoom-app-listening-on-my-microphone-when-not-in-a/m-p/41449#M20549
13/02/2022 01:48:22
QRCode
archive.org
thumbnail

I'm running MacOS Monterey. Several times in the last few weeks, I've noticed the orange dot indicating the microphone is being used by an app, and I click on the Control Center and see that Zoom is accessing the microphone. I'm not in a meeting and simply have the Zoom app open. Why would Zoom be accessing the microphone when I'm not in a meeting?

zoom EN macOS bug microphone
4470 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio