Zoomsday: Anyone in Your Meeting Can Own You episode artwork

EPISODE · Aug 18, 2026 · 12 MIN

Zoomsday: Anyone in Your Meeting Can Own You

from Cyberside Chats: Cybersecurity Insights from the Experts · host Chatcyberside

Anyone who can join your Zoom meeting could run code on your device: no click, no download, no sign that anything happened. That’s what Ⓐ Security disclosed on 11 August, in four vulnerabilities in Zoom’s screen-share annotation feature. Zoom patched quickly. The part that should concern security leaders is how the exploit was built — Ⓐ says one researcher did it in under 24 hours, using fewer than 20 prompts to publicly available AI models, against a closed protocol with no published specification. Sherri Davidoff and Matt Durrin walk through how the attack works, compare it to what a zero-click exploit of this class cost to build in 2021, explain why Zoom’s interim fix couldn’t protect the customers who’d enabled end-to-end encryption, and look at what the evidence actually says about AI-accelerated vulnerability discovery — including the data that argues against the panic. Plus what all of this means for organizations that buy software rather than build it. Key Takeaways: 1. Ask every critical software vendor how fast they patch, and put the answer in the contract. Zoom went from report to shipped fix in 12 days. Your exposure window is that vendor cycle plus your own deployment cycle, and you only control the second. A vendor who won’t commit to a remediation timeline is a documented risk decision, not a technical detail. 2. Inventory the software components inside the products you buy, not just the products themselves. Zoom’s Video SDK is affected and sits embedded inside third-party applications — telehealth platforms, contact-centre tools, banking apps. Organizations with no developers carry this exposure entirely through vendors and can’t patch it themselves. Zoom itself only added the Video SDK to its affected-products list three days after publication. 3. Ask vendors which of their security mitigations stop working when you turn on encryption or privacy features. Zoom’s interim server-side fix could not apply to end-to-end encrypted meetings, because the server can’t read what it’s asked to filter — and the bulletins didn’t say so. Any control that depends on a vendor inspecting your traffic is void the moment you encrypt end to end. 4. Treat "no public exploit exists" as a statement about timing, not about risk. There’s no in-the-wild exploitation, no KEV listing, and no validated public proof-of-concept. That reflects where researchers chose to spend effort — macOS was demonstrated because it was cheapest, while Windows and Linux are affected and simply weren’t targeted. That’s someone else’s schedule, not your risk assessment. 5. Assign someone the authority to say what does — and does not — get fixed. FIRST projects roughly 66,000 CVEs this year, with volume up 45%. If you write no code, that flood arrives as vendor advisories, scanner output and emergency patch cycles for software you bought. At that volume most of the job is deciding what to leave alone, and nobody will own that call without explicit cover. Resources: 1. Ⓐ Security — ZOOMSDAY (original research): https://a.security/blog/asecurity-zoomsday 2. Zoom Security Bulletins, ZSB-26015 to ZSB-26018 (affected versions and patches): https://www.zoom.com/en/trust/security-bulletin/ 3. Google Project Zero — A deep dive into an NSO zero-click iMessage exploit (FORCEDENTRY): https://projectzero.google/2021/12/a-deep-dive-into-nso-zero-click.html 4. VulnCheck — State of Exploitation 1H-2026: https://www.vulncheck.com/blog/state-of-exploitation-1h-2026 5. Google Threat Intelligence Group — Adversaries Leverage AI for Vulnerability Exploitation: https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access  

Episode metadata supplied by the publisher feed · Published Aug 18, 2026

Embed this episode

Ready to play

Zoomsday: Anyone in Your Meeting Can Own You

0:00 12:12

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Cyberside Chats: Cybersecurity Insights from the Experts?

This episode is 12 minutes long.

When was this Cyberside Chats: Cybersecurity Insights from the Experts episode published?

This episode was published on August 18, 2026.

Can I download this Cyberside Chats: Cybersecurity Insights from the Experts episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!