Researchers: Zoom’s Videoconferencing Software Lets Attackers Send Network Links to Steal Windows Credentials

Tsing

The FPS Review
Staff member
Joined
May 6, 2019
Messages
12,595
Points
113
zoom-logo-blue-1024x576.jpg
Image: Zoom



With COVID-19 locking workers at home, Zoom’s videoconferencing software is seeing a tremendous surge in usage and popularity, but it’s led to some serious scrutiny that isn’t working in the platform’s favor. Following allegations of data sharing, researchers now claim that Zoom has a security bug that lets attackers steal Windows logins and passwords.



This revolves around the fact that Zoom lets users paste UNC (Universal Naming Convention) paths into a chat window (e.g., \evil.server.com\images\cat.jpg), which are then automatically translated into clickable links. According to Bleeping Computer – which...

Continue reading...
 
Last edited by a moderator:
Become a Patron!
Back
Top