Get a Pentest and security assessment of your IT network.

News

Vulnerability Spotlight: Zoom Communications user enumeration

Cisco Talos is disclosing a user enumeration vulnerability in Zoom Communications that could allow a malicious user to obtain a complete list of Zoom users inside a specific organization. The vulnerability arises from the lack of validation to ensure the requesting user belongs to a queried domain. The exploitation process requires the user to properly authenticate to Zoom with a valid user account, the user then sends an XMPP message with the content below to receive a list of users associated with the domain arbitrary_domain.com.”]

Source: https://blog.talosintelligence.com/2020/04/zoom-user-enumeration.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Botnet authors use Evernote account as C&C Server

News

Canadian agency breached as hackers exploit CVE-2017-5638 flaw in Apache Struts 2