Attacker Takes over Zoom AI
Summary
ZoomMate's AI agent reportedly operates with broad network access, enabling a malicious Skill to establish command-and-control and exfiltrate data from Zoom and connected services. The attack persists even after the user stops the agent, underscoring risks in AI-driven vendors and the need for stronger sandboxing and skill vetting. The article emphasizes awareness and defense against prompt injections and insecure AI environments.