cd /news/ai-tools/turns-out-you-dont-need-the-most-pow… · home topics ai-tools article
[ARTICLE · art-93331] src=gizmodo.com ↗ pub= topic=ai-tools verified=true sentiment=↓ negative

Turns Out You Don’t Need The Most Powerful AI Models to Cause a Major Cybersecurity Incident

A Security, a cybersecurity firm, disclosed a zero-click remote code execution vulnerability in Zoom's annotation feature that could let attackers hijack any participant's device during a screen-sharing call, affecting every version of Zoom on all operating systems, including calls with end-to-end encryption. The flaw was discovered using publicly available AI models in fewer than 20 prompts and under 24 hours, highlighting AI's growing role in cybersecurity. Zoom has patched the vulnerability, but users must update to stay protected.

read2 min views1 publishedAug 12, 2026
Turns Out You Don’t Need The Most Powerful AI Models to Cause a Major Cybersecurity Incident
Image: Gizmodo (auto-discovered)

There are few things more mortifying than the prospect of sharing something you didn’t intend to on a work Zoom call. Now imagine it’s entirely out of your control. That is the risk of a security flaw discovered and disclosed by a cybersecurity company called A Security, which found a vulnerability that allowed an attacker to hijack the device of any user involved in a call with screen sharing. Notably, the group claims to have found the issue with just a few AI prompts.

According to the firm, the vulnerability was about as bad as it gets: a zero-click remote code execution that takes advantage of the way Zoom’s annotation feature works. The company explained in a blog post that because Zoom’s client “automatically parses whatever it receives” while the annotation feature is in use, an attacker could send a “specially crafted message to corrupt the receiving client’s memory and run code on it.” And because the protocol within the app creates a direct channel between the viewer and sharer, each participant on the call could be targeted individually.

That’s pretty bad, made worse by the fact that the vulnerability was apparently present in every version of Zoom on every operating system, and was even exploitable in calls where end-to-end encryption was active. It has since been patched, but you’ll have to update to make sure you’re not subject to the hijacking technique.

What makes the flaw particularly worth mentioning is how it was discovered in the first place. According to A Security, the company was able to find the vulnerability using publicly available AI models, which were able to identify and exploit the issue in fewer than 20 prompts and in under 24 hours. Of course, the models were guided by security researchers with real know-how providing direction on what to look for, but it does speak to the ways that AI models are impacting the cybersecurity landscape.

All of the frontier AI labs have made hay about just how powerful their top-tier models are—so powerful, in fact, that access to them must be restricted so the power doesn’t fall into the wrong hands. But even the publicly available tools seem to be upending the cyber industry. Just last week, officials from the United States and the United Kingdom warned at the Black Hat cybersecurity conference in Las Vegas that the speed at which people are discovering vulnerabilities is quickly surpassing the ability to patch them.

Safety was never guaranteed, but it seems we’re all increasingly vulnerable without fully realizing it.

── more in #ai-tools 4 stories · sorted by recency
── more on @a security 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/turns-out-you-dont-n…] indexed:0 read:2min 2026-08-12 ·