
A Security built a working Zoomsday exploit in under 24 hours with public AI. Users who skip Zoom updates remain exposed to wallet theft on unpatched clients.
Israeli cybersecurity firm A Security said a researcher used fewer than 20 prompts with publicly available AI models to find a set of Zoom vulnerabilities and build a working attack in less than 24 hours. The firm named the attack Zoomsday and said the flaws sit in Zoom's annotation system, the feature that lets meeting participants draw or add notes to shared content.
The three vulnerabilities, CVE-2026-53413 through CVE-2026-53415, were tested against Zoom applications on Windows, macOS, Linux, Android and iOS. The attack can be launched from either side of a call. A compromised presenter could target participants, and a participant could target the presenter, the researchers said. An attacker only needed to join or host the meeting and send the malicious data that triggered the flaw.
The result is a zero-click attack. The target does not need to download a file or click a link. A Security said the victim receives no visible warning that the device has been compromised.
“Once the nefarious code is running on the victim’s device, the threat actor can quietly steal personal data, switch on the microphone or camera to spy on the target, or install other malicious software,” the firm said.
“Exploits like this one are weapons. Governments regulate their export. Criminal organizations pay millions for them,” the researchers wrote.
The firm said the researcher completed the process in a single day with an AI agent and models that were publicly accessible.
In April, Mozilla said an early version of Anthropic’s Claude Mythos identified 271 vulnerabilities in Firefox during internal testing. All of the flaws were patched. Mozilla said the experiment showed AI could search large codebases and flag security problems at a pace that would otherwise require extensive human review. The Firefox work did not uncover gaps beyond what skilled security researchers could find. The process itself, Mozilla said, demonstrated the acceleration.
Video meetings have repeatedly been an entry point for attacks on cryptocurrency professionals. The Zoomsday exploit removes the persuasion step those campaigns relied on. No fake update or patch is needed. The researchers said simply being in the same meeting could provide the path to the targeted machine.
In January, crypto.news reported that hackers were using compromised Telegram accounts and deepfake Zoom calls against cryptocurrency professionals. The attackers impersonated people known to their targets, then used apparent audio problems during the calls to convince victims to install malicious software. BTC Prague co-founder Martin Kuchař said at the time that a high-level campaign was targeting Bitcoin and crypto users.
A September 2025 attack on THORChain co-founder JP Thor ended with about $1.3 million in cryptocurrency stolen. A compromised Telegram account belonging to a friend drew Thor into what looked like a legitimate Zoom meeting. Thor said he joined through an official Zoom link and saw a deepfake of his friend before a malicious script began copying files from his computer. The script copied his iCloud documents folder into a temporary directory. Thor traced the compromise back to the meeting.
A December 2025 report described a $300 million campaign in which North Korean hackers allegedly hijacked trusted Telegram accounts and used fake Zoom or Microsoft Teams meetings to target cryptocurrency executives. Attackers used prerecorded footage of recognizable industry contacts and created fake technical problems. Victims were directed to install supposed patches containing remote-access malware, which gave the attackers control of their computers and access to cryptocurrency wallets.
An earlier attack on Mehdi Farooq, an investment partner at Hypersphere and former Animoca Brands executive, followed a similar pattern. In June 2025, Farooq said he lost a large portion of his life savings after receiving a Telegram message from a professional acquaintance whose account had been compromised. The attacker later asked him to move a scheduled conversation to Zoom Business, after which malware was introduced through a fake update.
Manta Network co-founder Kenny Li reported an attempted Zoom attack in April 2025. Li said a known contact invited him to a meeting where the participant appeared on camera with no audio. He was asked to download a script presented as a Zoom update. He declined and tried to verify the participant through another channel.
A Security said it reported the first Zoom vulnerability on June 10, two days after discovering it, and worked through the disclosure process while fixes were prepared. Zoom released fixes between June 22 and July 20, according to the researchers. The firm said updating the application remains necessary because a server-side protection designed to block malicious messages cannot inspect the same content inside end-to-end encrypted meetings.
Zoom’s July security bulletins also included CVE-2026-53412, a critical improper input validation vulnerability affecting Zoom Workplace for Windows. The bulletin described an unauthenticated attacker carrying out an account takeover through network access.
According to A Security, Zoom has patched the Zoomsday vulnerabilities. Users running older versions of the app still need to update their clients. Server-side protections alone cannot fully block the attack.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.