Zoom AI Agent Vulnerable to Data Exfiltration

TL;DR. Zoom's AI chatbot, ZoomMate, has a critical vulnerability allowing attackers to exfiltrate meeting data via malicious AI Skills. - Attackers can establish command-and-control due to unrestricted network access in ZoomMate's coding environment. - Malicious Skills or prompt injections can manipulate the agent into connecting to attacker servers and issuing commands. - The attacker's connection persists even after the user stops the agent or closes Zoom.

Sources

Back to QLANKR News