Zoom 修复重大漏洞:攻击者可用不到 20 条 AI 提示劫持设备
‘Zoomsday’ hack uncovered using fewer than 20 AI prompts
Zoom has patched a major security vulnerability that could allow an attacker to hijack anyone's device during a meeting. In a blog post on Tuesday, researchers at A Security say they uncovered the flaw using "fewer than 20 prompts on publicly available AI models," as reported earlier by Wired.
Zoom已修补了一个重大安全漏洞,该漏洞可能允许攻击者在会议期间劫持任何人的设备。据《连线》杂志早前报道,在周二的一篇博客文章中,A Security公司的研究人员表示,他们利用“公开可用的AI模型上的不到20条提示”发现了这一缺陷。
The exploit involved Zoom's annotation feature, which allows users to draw on their screen while sharing it with other meeting participants. With the exploit, an attacker could join or host a meeting and run malicious code on victims' devices, allowing them to steal data, turn on the camera or microphone, or install malware. The attack required no act …
该漏洞涉及Zoom的注释功能,该功能允许用户在与会议其他参与者共享屏幕时在屏幕上绘图。利用该漏洞,攻击者可以加入或主持一场会议,并在受害者的设备上运行恶意代码,从而窃取数据、打开摄像头或麦克风,或安装恶意软件。该攻击无需任何操作……
Read the full story at The Verge.
阅读The Verge上的完整报道。
更进一步:量化金融体系
看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力