Researchers found a major Zoom vulnerability using under 20 AI prompts
Zoom patched a serious security flaw, nicknamed "Zoomsday," that could let an attacker hijack a participant's device during a meeting by abusing the screen-annotation feature. Researchers at A Security said they found the exploit using fewer than 20 prompts to publicly available AI models, and it required no action from the victim beyond being in the meeting.
Why it matters: This is a concrete example of AI lowering the skill floor for vulnerability discovery in widely used software, a trend security researchers have been warning about as coding-capable models get better at find-and-exploit workflows. It's also a reminder that the same AI-assisted techniques used defensively here could just as easily be used by attackers before a patch ships.