๐จ ACTIVE EXPLOITATION
- Zoom patches Zoomsday zero-click flaw enabling remote code execution
Researchers found a Zoom flaw that enabled zero-click remote code execution during meetings.
- Zoom Workplace users on Windows, macOS, Linux, iOS, and Android were affected, along with Zoom Rooms and Meeting SDK deployments.
- Annotation-engine flaws
CVE-2026-53413andCVE-2026-53414enabled remote code execution or client crashes. - A specially crafted annotation message was automatically parsed through Zoom's proprietary protocol without victim interaction.
- A working exploit was confirmed against Zoom 7.0.5; fixes include Workplace 7.1.5 and 7.0.6, Rooms 7.1.5, and Meeting SDK 7.1.5.
- A Security researchers used fewer than 20 AI prompts and less than 24 hours to develop the exploit. ๐ Coverage: securityboulevard.com ยท ๐ via securityboulevard.com (discovered)
๐ต๏ธ RESEARCH & DEEP DIVES
- DeadLock ransomware uses Polygon blockchain to resist infrastructure takedowns
DeadLock ransomware uses Polygon smart contracts to maintain resilient extortion infrastructure.
- DeadLock has impacted IT, mining, transportation, manufacturing, hospitality, consumer goods, and other sectors worldwide.
- The Rust-based ransomware has listed more than 80 alleged victims since July 2025 and uses double extortion.
- Its recovery HTML page retrieves rotating proxy addresses and leak-blog content from two Polygon smart contracts.
- Victim communications use the Session messaging network, while leaked files are hosted through Wasabi-compatible storage.
- Observed indicators include the .dlock extension, Polygon wallets 0x8EF7c3e531d871D3B9D559722DE77EB1dEc19dAe and 0x757984507c82c8dA1d3969c535dB5706eEE6426C, and proxy IP 138.226.236[.]51. ๐ Coverage: bleepingcomputer.com ยท ๐ via BleepingComputer