<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Zoom on CuraSec</title><link>https://curasec.metacog.co.kr/tags/zoom/</link><description>Recent content in Zoom on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 12 Aug 2026 11:57:00 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/zoom/index.xml" rel="self" type="application/rss+xml"/><item><title>Zoom Annotation Zero-Click Flaw Allows Meeting Client Hijack</title><link>https://curasec.metacog.co.kr/insights/2026-08-12-zoom-annotation-flaws-could-let-a-meeting-participant-hijack/</link><pubDate>Wed, 12 Aug 2026 11:57:00 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-12-zoom-annotation-flaws-could-let-a-meeting-participant-hijack/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Zero-click client-side RCE via Zoom&amp;rsquo;s annotation feature is a real exposure for any enterprise using Zoom for screen sharing. No KEV listing or public PoC present, so no immediate exploitation pressure — but update Zoom desktop clients to the patched version this sprint.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Noteworthy attack class (zero-click compromise through meeting software without user interaction) but no IOCs, no reported exploitation, and no viable detection surface is described; nothing actionable for rule writing or hunting today.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> The attack surface is broad — any employee on a Zoom call — but with no active exploitation or breach reported, this sits below the threshold for leadership action; file it as context for your next risk-register review of collaboration tool controls.&lt;/li>
&lt;/ul></description></item><item><title>Zoom patches critical unauthenticated account-takeover flaw in Windows client</title><link>https://curasec.metacog.co.kr/insights/2026-07-16-zoom-warns-of-critical-account-takeover-vulnerability/</link><pubDate>Thu, 16 Jul 2026 12:18:39 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-16-zoom-warns-of-critical-account-takeover-vulnerability/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Zoom&amp;rsquo;s Windows desktop client and SDK carry a critical unauthenticated account-takeover flaw — high severity but no KEV listing or public PoC moves this to Plan rather than Act. Update Zoom Windows clients and any SDK integrations to the patched version as soon as your next patch window allows.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs, active exploitation evidence, or mapped TTPs accompany this advisory, so there is no immediate detection or hunt work. File awareness of the attack vector (unauthenticated ATO on Zoom Windows) so detection rules can be prioritized if exploitation begins appearing in the wild.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Zoom is standard enterprise communication infrastructure, and a critical unauthenticated account-takeover flaw warrants confirming that endpoint and IT teams are deploying the patched client org-wide. Without reported exploitation this does not require leadership escalation yet, but track it for the next risk review.&lt;/li>
&lt;/ul></description></item><item><title>Zoom Patches Critical Windows Flaw (CVSS 9.8) Enabling Account Takeover</title><link>https://curasec.metacog.co.kr/insights/2026-07-16-zoom-patches-critical-windows-flaw-that-could-enable-account/</link><pubDate>Thu, 16 Jul 2026 12:18:39 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-16-zoom-patches-critical-windows-flaw-that-could-enable-account/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> A public PoC on GitHub for a CVSS 9.8 improper-input-validation flaw in Zoom Desktop Client, VDI Client, and Meeting SDK for Windows raises exploitation risk significantly even without KEV listing; update all three Zoom Windows products to the patched versions immediately.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> With a public PoC in circulation for a critical Zoom account-takeover vulnerability, exploitation attempts against unpatched Windows endpoints are plausible now; hunt for anomalous Zoom process behavior and unexpected authentication events since the patch cycle may lag exposure.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Zoom is near-universal in enterprise environments, and a CVSS 9.8 flaw with a public PoC in the Windows client warrants confirming with engineering that patching is tracked and on a days-not-weeks timeline before this surfaces in customer security questionnaires.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-53412 — CISA KEV: not listed, EPSS n/a, public PoC on GitHub&lt;/li>
&lt;/ul></description></item></channel></rss>