/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

A vulnerability in Zoom's Windows client could let attackers steal Windows login credentials of users who click on malicious links in chat messages

The Zoom Windows client is vulnerable to UNC path injection in the client's chat feature that could allow attackers to steal the Windows credentials of users who click on the link.

BleepingComputer Lawrence Abrams

Discussion

  • @hackerfantastic Hacker Fantastic on x
    Hi @zoom_us & @NCSC - here is an example of exploiting the Zoom Windows client using UNC path injection to expose credentials for use in SMBRelay attacks. The screen shot below shows an example UNC path link and the credentials being exposed (redacted). https://twitter.com/...
  • @_g0dmode Mitch on x
    #Zoom chat allows you to post links such as \\x.x.x.x\xyz to attempt to capture Net-NTLM hashes if clicked by other users.
  • @0xamit Amit Serper on x
    1. Link has to be clicked 2. Meeting has to be public for someone malicious to even join and post the link (which should probably be your in threat model anyhow) 3. This is how windows explorer works, it's vulnerable as well Conclusion: Stop using windows. #IHaveOpinions https://…
  • @bleepincomputer @bleepincomputer on x
    Security researchers @_g0dmode and @hackerfantastic revealed tonight that the Zoom client is vulnerable to UNC injection that can be used to steal Windows login credentials or attempt to launch a program.
  • @reckless Nilay Patel on x
    The biggest question facing Zoom is whether these gaffes are move-fast-break-things mistakes, or reflective of a deeper culture of disrespect for user privacy. Or... both. https://www.theverge.com/...
  • @reckless Nilay Patel on x
    Also: you sort of expect these issues as consumer products go to the enterprise. But Zoom is an enterprise product, and it appears that none of its enterprise customers did any sort of worthwhile vendor security review.
  • @danamodio Dan Amodio on x
    Worth noting that zoomAutenticationTool is a signed bin.. and you can use it as an auth trampoline for whatever script you want... https://twitter.com/... https://twitter.com/...
  • @random_walker Arvind Narayanan on x
    Let's make this simple: Zoom is malware. https://twitter.com/...
  • @random_walker Arvind Narayanan on x
    Every day there's a fresh Zoom privacy/security horror story. Why now, all at once? It's simple: the problems aren't new but suddenly everyone is forced to use Zoom. That means more people discovering problems and also more frustration because opting out isn't an option. https://…
  • @slightlylate Alex Russell on x
    Move everything you possibly can to the web and don't look back. https://twitter.com/...
  • @ehn Andreas Ehn on x
    As anyone who has built desktop software at scale can attest to, in the typical user's home/office environment, “just works” is indistinguishable from malware. This unfortunate situation is a byproduct of the cat-and-mouse game between actual attackers and system engineers. 🤷‍♂️ …
  • @alexstamos Alex Stamos on x
    This week is going to be a critical one for Zoom and $ZM shareholders. This is going to get worse, as the entire infosec world descends on a spectacularly complicated product with lots of attack surface and some sketchy design trade-offs. An opportunity for a trust turn-around. h…
  • @dhh @dhh on x
    Here's how they're abusing the OSX installer to avoid need you to authorize the installation (a good malware trick). https://twitter.com/... https://twitter.com/...
  • @profcarroll @profcarroll on x
    Folks love Zoom because it just ‘works’ but one of the ways it seems so effortless is how they bypass security established to prevent malware. https://twitter.com/...
  • @stshank Stephen Shankland on x
    End to middle ≠ end to end. By Zoom's definition, Gmail could be E2E encrypted even though it's sitting on a Google server. That lets Google do useful things (search, spam filtering), but it means Google doesn't get to brag email is E2E encrypted. https://twitter.com/...
  • @trevortimm Trevor Timm on x
    Zoom says all over the place—on its app, website, security white paper—that its video calls are “end-to-end encrypted,” but when @theintercept asked them about it they said: “Currently, it is not possible to enable E2E encryption for Zoom video meetings.” https://theintercept.com…
  • @shanvav Shannon Vavra on x
    The FBI issued a warning today that Zoom and other teleconferencing may not be as private/secure as advertised. As remote work/classes surge w/ coronavirus, this raises privacy, security, & possibly national security issues, as world leaders use Zoom too. https://www.cyberscoop.c…
  • @mgsiegler M.G. Siegler on x
    Unclear if the Zoomlash is going to last two weeks, two days, or two minutes in our current distorted temporal state of reality. https://twitter.com/...
  • @cradvocacy @cradvocacy on x
    “Zoom should update their terms to ensure that data collected during meetings from any participant or host is explicitly excluded from any advertising or marketing use...” says CR's @JustinBrookman. See our tips for enhancing your privacy on Zoom: https://www.consumerreports.org/…
  • @jason_koebler Jason Koebler on x
    Design flaw in Zoom lets random strangers video call people and also leaks photos and email addresses of anyone using nonstandard email addresses: https://www.vice.com/...
  • @vice @vice on x
    A Zoom user filed a class action lawsuit against the company for sending data to Facebook, arguing that Zoom violated California's new data protection law. https://www.vice.com/...
  • @random_walker Arvind Narayanan on x
    Zoom is also a privacy disaster https://blogs.harvard.edu/... The creepiest feature is attention tracking. If it's on, it reports to the host if a user clicks away from the Zoom window for 30 seconds. As we all know, your boss constantly watching your screen is a great way to wor…
  • @yuanfenyang Yuan Yang on x
    The UK: We really shouldn't give our sensitive data to Huawei if we can't guarantee the integrity of its security Also the UK: We should give it all to Zoom instead Also see: https://theintercept.com/... https://twitter.com/...
  • @ow @ow on x
    Zoom is such a dodgy/misleading company across the board and using it should be reconsidered 🙅‍♀️ https://theintercept.com/...
  • @jilliancyork @jilliancyork on x
    I was willing to write off the other stuff about Zoom, but not this. I'll be looking for a better solution for anything personal. https://theintercept.com/...
  • @profcarroll @profcarroll on x
    Zoom: “We take privacy seriously.” NY AG: “We too take privacy seriously.” https://www.nytimes.com/...
  • @fbiboston FBI Boston on x
    FBI Warns of Teleconferencing and Online Classroom Hijacking During COVID-19 Pandemic: As large numbers of people turn to video-teleconferencing (VTC) platforms to stay connected in the wake of the COVID-19 crisis, reports of VTC hijacking are emerging ... https://www.fbi.gov/...
  • @joshgerstein Josh Gerstein on x
    ‘Without end-to-end encryption, Zoom has the technical ability to spy on private video meetings and could be compelled to hand over recordings of meetings to governments or law enforcement in response to legal requests.’ https://twitter.com/...
  • @mltellado Marta L. Tellado on x
    Great reporting by @allenstjohn who wrote about the privacy concerns of using Zoom. Thanks, Doc Searls @dsearls for elevating this issue & calling @consumerreports “the greatest moral conscience in the history of business” https://www.consumerreports.org/ ...