Attacker Takes over Zoom AI

Security researchers have identified a vulnerability in Zoom's AI agent, ZoomMate, which allows attackers to exfiltrate data through malicious prompts or plugins. The agent's unrestricted network access enables attackers to bypass user controls and maintain persistence.
Attacker takes over the victim’s Zoom AI, exfiltrating data from across Zoom and connected services Context Zoom’s flagship AI feature is ZoomMate, an agentic chatbot that operates on data from across a user’s Zoom account and any connected services (e.g., OneDrive, Google, connectors, etc). The agent appears to have been given an environment with unrestricted HTTPS network access, with no user or admin-level configuration to lock it down.
Get the full story
Sign up for Headlinne to unlock AI insights, political bias analysis, and your personalized news feed.
Create free accountAlready have an account? Sign in