<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Client-Side on CuraSec</title><link>https://curasec.metacog.co.kr/tags/client-side/</link><description>Recent content in Client-Side on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 12 Aug 2026 11:57:00 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/client-side/index.xml" rel="self" type="application/rss+xml"/><item><title>Zoom Annotation Zero-Click Flaw Allows Meeting Client Hijack</title><link>https://curasec.metacog.co.kr/insights/2026-08-12-zoom-annotation-flaws-could-let-a-meeting-participant-hijack/</link><pubDate>Wed, 12 Aug 2026 11:57:00 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-12-zoom-annotation-flaws-could-let-a-meeting-participant-hijack/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Zero-click client-side RCE via Zoom&amp;rsquo;s annotation feature is a real exposure for any enterprise using Zoom for screen sharing. No KEV listing or public PoC present, so no immediate exploitation pressure — but update Zoom desktop clients to the patched version this sprint.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Noteworthy attack class (zero-click compromise through meeting software without user interaction) but no IOCs, no reported exploitation, and no viable detection surface is described; nothing actionable for rule writing or hunting today.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> The attack surface is broad — any employee on a Zoom call — but with no active exploitation or breach reported, this sits below the threshold for leadership action; file it as context for your next risk-register review of collaboration tool controls.&lt;/li>
&lt;/ul></description></item></channel></rss>