{"id":34405,"date":"2020-04-14T14:32:56","date_gmt":"2020-04-14T14:32:56","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/31115\/Zoom-Every-Security-Issue-Uncovered-In-The-Video-Chat-App.html"},"modified":"2020-04-14T14:32:56","modified_gmt":"2020-04-14T14:32:56","slug":"zoom-every-security-issue-uncovered-in-the-video-chat-app","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/zoom-every-security-issue-uncovered-in-the-video-chat-app\/","title":{"rendered":"Zoom: Every Security Issue Uncovered In The Video Chat App"},"content":{"rendered":"<p><span class=\"imageContainer\"><span><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/cnet3.cbsistatic.com\/img\/CgUiKZAMY0RMRyQGBlo4svIukm8=\/1092x0\/2020\/03\/24\/6d4a4d41-f7f5-4389-989d-65525058d751\/14-zoom-app-meetings-work-from-home-coronavirus.jpg\" class alt=\"14-zoom-app-meetings-work-from-home-coronavirus\" height=\"0\" width=\"1092\"><\/span><\/span><span class=\"credit\">Sarah Tew\/CNET<\/span><\/p>\n<p class=\"speakableTextP1\">As the&nbsp;<span class=\"link\"><a href=\"https:\/\/www.cbsnews.com\/live-updates\/coronavirus-pandemic-covid-19-latest-news-2020-04-14\/\" data-component=\"linkTracker\" data-link-tracker-options=\"{&quot;action&quot;:&quot;link_anchor&quot;}\" rel=\"noopener noreferrer\" target=\"_blank\">coronavirus pandemic<\/a><\/span>&nbsp;forced millions of people to&nbsp;<span class=\"link\" section=\"shortcodeLink\"><a href=\"https:\/\/www.cnet.com\/news\/best-services-for-working-eating-and-entertaining-yourself-at-home\/\">stay home<\/a><\/span>&nbsp;over the past month, Zoom suddenly became the video meeting service of choice: Daily meeting participants on the platform surged from 10 million in December to <span class=\"link\" section=\"shortcodeLink\"><a href=\"https:\/\/www.cnet.com\/news\/zoom-boss-says-itll-freeze-feature-updates-to-address-security-issues\/\">200 million in March<\/a><\/span>.<\/p>\n<p class=\"speakableTextP2\">With that popularity came Zoom&#8217;s&nbsp;<a href=\"https:\/\/www.cnet.com\/tags\/privacy\/\" data-annotation=\"true\" data-component=\"linkTracker\" data-link-tracker-options=\"{&quot;action&quot;:&quot;inline-annotation|Privacy|CNET_TAG|343&quot;}\" section=\"annotation\">privacy<\/a> risks extending rapidly to massive numbers of people. From built-in attention-tracking features to recent upticks in &#8220;<a href=\"https:\/\/www.cnet.com\/how-to\/zoombombing-what-it-is-and-how-you-can-prevent-it-in-zoom-video-chat\/\">Zoombombing<\/a>&#8221; (in which uninvited attendees break into and disrupt meetings with hate-filled or pornographic content), Zoom&#8217;s security practices have been drawing more attention &#8212; along with at least three lawsuits against the company.&nbsp;<\/p>\n<p>Here&#8217;s everything we know about the Zoom security saga, and when it happened. If you aren&#8217;t familiar with <span class=\"link\" section=\"shortcodeLink\"><a href=\"https:\/\/www.cnet.com\/news\/using-zoom-while-working-from-home-here-are-the-privacy-risks-to-watch-out-for\/\">Zoom&#8217;s security issues<\/a><\/span>, you can start from the bottom and work your way up to the most recent information. We&#8217;ll continue updating this story as more issues and fixes come to light.<\/p>\n<p><strong>Read more<\/strong>: <span class=\"link\" section=\"shortcodeLink\"><a href=\"https:\/\/www.cnet.com\/news\/using-zoom-while-working-from-home-here-are-the-privacy-risks-to-watch-out-for\/\">Using Zoom for work? Here are the privacy risks to watch out for<\/a><\/span><\/p>\n<div class=\"shortcode video v2\" data-video-playlist=\"[{&quot;id&quot;:&quot;e2c52f05-6083-4956-ae90-f317eea53c2d&quot;,&quot;title&quot;:&quot;Zoom privacy: How to keep spying eyes out of your meetings&quot;,&quot;description&quot;:&quot;It\\u0027s become the go-to app for working, learning and socializing from home, but the Zoom boom has also brought major privacy problems. Here\\u0027s how to keep your video chats private and secure.&quot;,&quot;slug&quot;:&quot;zoom-privacy-how-to-keep-spying-eyes-out-of-your-meetings&quot;,&quot;chapters&quot;:{&quot;data&quot;:[],&quot;paging&quot;:{&quot;total&quot;:0,&quot;limit&quot;:15,&quot;offset&quot;:0}},&quot;datePublished&quot;:&quot;2020-04-09 02:37:41&quot;,&quot;duration&quot;:345,&quot;mpxRefId&quot;:&quot;aaBoozy0h3jlgaJpEOEb_fBVduq9AOeC&quot;,&quot;ratingVChip&quot;:&quot;TV-14&quot;,&quot;primaryTopic&quot;:{&quot;id&quot;:&quot;1c0fd1cb-c387-11e2-8208-0291187b029a&quot;},&quot;author&quot;:{&quot;id&quot;:&quot;a69b7e66-7917-4573-b81f-1849e1e01d9d&quot;,&quot;firstName&quot;:&quot;Claire&quot;,&quot;lastName&quot;:&quot;Reilly&quot;},&quot;primaryCollection&quot;:{&quot;id&quot;:&quot;040fa0bc-bf08-43dc-ac3d-ee7869a9fc85&quot;,&quot;title&quot;:&quot;CNET News Video&quot;},&quot;image&quot;:{&quot;path&quot;:&quot;https:\\\/\\\/cnet3.cbsistatic.com\\\/img\\\/o34UnXzzMIPlQrgOFqHjODdKQKs=\\\/1280x720\\\/2020\\\/04\\\/09\\\/1a8422db-131b-4cbc-8a81-25f613e46a93\\\/zoomsecurity-00-01-04-21-still004.jpg&quot;},&quot;thumbnail&quot;:&quot;https:\\\/\\\/cnet2.cbsistatic.com\\\/img\\\/ZKExw2ZOZrpJYS_-ckEvxibmiNc=\\\/194x109\\\/2020\\\/04\\\/09\\\/1a8422db-131b-4cbc-8a81-25f613e46a93\\\/zoomsecurity-00-01-04-21-still004.jpg&quot;,&quot;closedCaptionPath&quot;:&quot;\\\/videos\\\/captions\\\/webvtt\\\/zoom-privacy-how-to-keep-spying-eyes-out-of-your-meetings.vtt&quot;,&quot;urlPath&quot;:&quot;\\\/videos\\\/zoom-privacy-how-to-keep-spying-eyes-out-of-your-meetings\\\/&quot;,&quot;isVertical&quot;:false,&quot;m3u8&quot;:&quot;https:\\\/\\\/cnetvideo.cbsistatic.com\\\/vr\\\/2020\\\/04\\\/09\\\/1722038339771\\\/294638_hls\\\/master.m3u8&quot;,&quot;mp4&quot;:&quot;https:\\\/\\\/cnetvideo.cbsistatic.com\\\/vr\\\/2020\\\/04\\\/09\\\/1722038339771\\\/ZoomSecurityYT_294637_740.mp4&quot;,&quot;index&quot;:0}]\" readability=\"6\">\n<div class=\"embeddedVideoContainer\" tabindex=\"0\" aria-label=\"Play video Zoom privacy: How to keep spying eyes out of your meetings\" data-load-video=\"0\" data-video-id=\"e2c52f05-6083-4956-ae90-f317eea53c2d\" readability=\"7\">\n<div class=\"videoContainer\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/cnet2.cbsistatic.com\/img\/zn2TtwtsciN1o8rcuug3B1mu7zE=\/196x110\/2020\/04\/09\/1a8422db-131b-4cbc-8a81-25f613e46a93\/zoomsecurity-00-01-04-21-still004.jpg\" class=\"photo\" alt height=\"110\" width=\"196\"><\/div>\n<p><span class=\"bold\"><span class=\"nowPlaying\">Now playing:<\/span> <span class=\"watchThis\">Watch this:<\/span><\/span> Zoom privacy: How to keep spying eyes out of your meetings<\/p>\n<p><span class=\"duration\">5:45<\/span><\/p>\n<\/div>\n<\/div>\n<div class=\"newsletter-subscribe-form desktop -inline\" section=\"subscribeNewsletter\" readability=\"6\">\n<div class=\"newsletterTitle\">\n<p><h2>CNET Coronavirus Update<\/h2>\n<\/p>\n<\/div>\n<div class=\"newsletter\" readability=\"7\">\n<p class=\"description\">Keep track of the coronavirus pandemic.<\/p>\n<\/p><\/div>\n<\/div>\n<h2>April 14<\/h2>\n<h3>New privacy option for paid accounts&nbsp;<\/h3>\n<p>In a <a href=\"https:\/\/blog.zoom.us\/wordpress\/2020\/04\/13\/coming-april-18-control-your-zoom-data-routing\/\" rel=\"noopener noreferrer nofollow\" target=\"_blank\" data-component=\"externalLink\">Tuesday blog post<\/a>, Zoom said that, starting April 18, all paying subscribers will be be able to select which of the company&#8217;s regional servers they would like to use or avoid. The move follows an <a href=\"https:\/\/citizenlab.ca\/2020\/04\/move-fast-roll-your-own-crypto-a-quick-look-at-the-confidentiality-of-zoom-meetings\/\" rel=\"noopener noreferrer nofollow\" target=\"_blank\" data-component=\"externalLink\">investigation by City Lab<\/a> that found Zoom call traffic had been routed through Chinese servers, which prompted privacy concerns based on the Chinese government&#8217;s ability to obtain encryption keys.&nbsp;<\/p>\n<h2>April 13<\/h2>\n<h3>500,000 Zoom accounts sold on hacker forums<\/h3>\n<p>Cybersecurity intelligence firm Cyble discovered that over 500,000 Zoom accounts are being sold on the dark web and hacker forums, according to a Monday <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/over-500-000-zoom-accounts-sold-on-hacker-forums-the-dark-web\/\" rel=\"noopener noreferrer nofollow\" target=\"_blank\" data-component=\"externalLink\">report from Bleeping Computer<\/a>. The accounts are being sold for less than a penny each, with some being given away for free. Zoom users are advised to change their passwords and to check the data breach notification site, <a href=\"https:\/\/haveibeenpwned.com\/\" rel=\"noopener noreferrer nofollow\" target=\"_blank\" data-component=\"externalLink\">Have I Been Pwned<\/a>, to help determine whether their email addresses were among those leaked in the attack.&nbsp;<\/p>\n<h2>April 10<\/h2>\n<h3>Pentagon restricts Zoom use<\/h3>\n<p>The Department of Defense issued new guidance on the use of Zoom, as reported Friday by&nbsp;<a href=\"https:\/\/www.voanews.com\/silicon-valley-technology\/pentagon-issues-new-guidance-zoom-use?utm_medium=social&amp;utm_campaign=dlvr.it\" rel=\"noopener noreferrer nofollow\" target=\"_blank\" data-component=\"externalLink\">Voice of America<\/a>. While the Pentagon&#8217;s new rule allows the use of Zoom for Government, a paid service tier of the software, a spokesperson told VOA that &#8220;DOD users may not host meetings using Zoom&#8217;s free or commercial offerings.&#8221;&nbsp;<\/p>\n<h2>April 9<\/h2>\n<h3>Senate to avoid Zoom&nbsp;<\/h3>\n<p>The <span class=\"link\" section=\"shortcodeLink\"><a href=\"https:\/\/www.cnet.com\/news\/us-senate-reportedly-tells-members-to-avoid-zoom\/\">US Senate told members to avoid using Zoom<\/a><\/span> for remote work during the coronavirus lockdown due to <a href=\"https:\/\/redirect.viglink.com\/?format=go&amp;jsonp=vglnk_158644548477711&amp;key=ce074976249105acf14d8c9cf69bdcd1&amp;libId=k8st0lvt01003n6p000DA8mwneqd8opf2&amp;loc=https%3A%2F%2Fwww.cnet.com%2Fnews%2Fus-senate-reportedly-tells-members-to-avoid-zoom%2F&amp;v=1&amp;out=https%3A%2F%2Fwww.ft.com%2Fcontent%2Fdac7d60b-54fa-402b-8469-70f85aaace76&amp;title=US%20Senate%20reportedly%20tells%20members%20to%20avoid%20Zoom%20-%20CNET&amp;txt=Financial%20Times%20reported\" rel=\"noopener noreferrer nofollow\" target=\"_blank\" data-component=\"externalLink\">security issues surrounding the videoconferencing app<\/a>, the Financial Times reported Thursday. It reportedly isn&#8217;t an official ban, like Google issued for its employees, but senators were apparently asked to use an alternative platform.&nbsp;<\/p>\n<h3>Singapore teachers banned from Zoom<\/h3>\n<p>Singapore&#8217;s Ministry of Education said it&#8217;s suspended the use of Zoom by teachers after receiving <a href=\"https:\/\/www.channelnewsasia.com\/news\/singapore\/moe-suspends-zoom-home-based-learning-obscene-images-12626534\" rel=\"noopener noreferrer nofollow\" target=\"_blank\" data-component=\"externalLink\">reports of obscene Zoombombing incidents targeting students<\/a> learning remotely. Channel News Asia reported that the ministry is currently investigating the incidents.&nbsp;<\/p>\n<h3>German government warns against Zoom use<\/h3>\n<p>According to German newspaper <a href=\"https:\/\/www.handelsblatt.com\/technik\/it-internet\/it-sicherheit-auswaertiges-amt-untersagt-nutzung-von-zoom-auf-dienstlichen-geraeten\/25726922.html\" rel=\"noopener noreferrer nofollow\" target=\"_blank\" data-component=\"externalLink\">Handelsblatt<\/a>, the German Ministry of Foreign Affairs told employees in a circular this week to <a href=\"https:\/\/www.zdnet.com\/article\/us-senate-german-government-tell-employees-not-to-use-zoom\/\" rel=\"noopener noreferrer\" target=\"_blank\" data-component=\"externalLink\">stop using Zoom due to security concerns<\/a>. &#8220;Because of the associated risks for our IT system as a whole, we have, like other departments and industrial companies, also decided for the (Federal Foreign Office) not to allow the use of Zoom on the devices used for business purposes,&#8221; the ministry said in a statement.&nbsp;<\/p>\n<h2>April 8<\/h2>\n<h3>Fourth lawsuit<\/h3>\n<p>In a lawsuit filed Tuesday in federal court, Zoom shareholder Michael Drieu accused the company of having &#8220;inadequate data privacy and security measures&#8221; and falsely asserting that the service was end-to-end encrypted. Drieu also said that media reports and public admissions by the company on <span class=\"link\" section=\"shortcodeLink\"><a href=\"https:\/\/www.cnet.com\/news\/zoom-sued-by-shareholder-over-security-issues\/\">security problems have caused Zoom&#8217;s stock price to plummet<\/a><\/span>.<\/p>\n<h3>Google bans Zoom<\/h3>\n<p>In an email to employees, which cited security vulnerabilities, Google banned the use of Zoom on company-owned employee devices and warned that the software will stop working on those devices this week. Zoom is a competitor to <a href=\"https:\/\/www.cnet.com\/news\/zoom-vs-google-hangouts-video-chat-apps-for-working-and-keeping-in-touch-compared\/\">Google&#8217;s Hangout Meet app<\/a>.&nbsp;<\/p>\n<p>In an email to BuzzFeed, a Google spokesperson said <a href=\"https:\/\/www.buzzfeednews.com\/article\/pranavdixit\/google-bans-zoom\" rel=\"noopener noreferrer nofollow\" target=\"_blank\" data-component=\"externalLink\">employees using Zoom while working remotely would need to look elsewhere<\/a> and that Zoom &#8220;does not meet our security standards for apps used by our employees.&#8221;&nbsp;<\/p>\n<h3>Bug bounty hunters emerge<\/h3>\n<p><span class=\"link\"><a href=\"https:\/\/www.cnet.com\/tags\/hacking\/\" data-component=\"linkTracker\" data-link-tracker-options=\"{&quot;action&quot;:&quot;link_anchor&quot;}\">Hackers<\/a><\/span> around the world have begun turning to bug bounty hunting, searching for potential vulnerabilities in Zoom&#8217;s technology to be sold to the highest bidder. A Motherboard report detailed a rise in the bounty payout for weaknesses known as zero-day exploits, with one source estimating that <a href=\"https:\/\/www.vice.com\/en_us\/article\/akwpxp\/zoom-hacks-zero-day-exploits\" rel=\"noopener noreferrer nofollow\" target=\"_blank\" data-component=\"externalLink\">hackers are selling the exploits for $5,000 to $30,000<\/a>.&nbsp;<\/p>\n<h3>New security advisor and council<\/h3>\n<p>Zoom brought former Facebook and Yahoo Chief Security Officer Alex Stamos on board after he <a href=\"https:\/\/twitter.com\/alexstamos\/status\/1245197052314677249\" rel=\"noopener noreferrer\" target=\"_blank\" data-component=\"externalLink\">defended the company on Twitter<\/a>. As reported by <a href=\"https:\/\/www.zdnet.com\/article\/former-facebook-cso-alex-stamos-to-join-zoom-as-outside-security-consultant\/\" rel=\"noopener noreferrer\" target=\"_blank\" data-component=\"externalLink\">CNET sister site ZDNet<\/a>, Stamos said he <a href=\"https:\/\/www.zdnet.com\/article\/former-facebook-cso-alex-stamos-to-join-zoom-as-outside-security-consultant\/\" rel=\"noopener noreferrer\" target=\"_blank\" data-component=\"externalLink\">joined the company as a security advisor<\/a> after a phone call last week with Zoom founder and CEO Eric Yuan, and that he&#8217;ll be working with Zoom&#8217;s engineering team.<\/p>\n<p><a href=\"https:\/\/blog.zoom.us\/wordpress\/2020\/04\/08\/update-on-zoom-90-day-plan-to-bolster-key-privacy-and-security-initiatives\/\" rel=\"noopener noreferrer nofollow\" target=\"_blank\" data-component=\"externalLink\">In a statement<\/a>, Zoom announced the formation of a chief information and security officer council and advisory board. The board&#8217;s goal will be to conduct a full security review of the company&#8217;s technology and will include, Yuan said, &#8220;a subset of CISOs who will act as advisors to me personally.&#8221;&nbsp;<\/p>\n<h3>Classroom security<\/h3>\n<p>In an email, a Zoom spokesperson told CNET that the company is continuing to push for wider user education on existing security features and explained its move to secure classroom uses of the product.<\/p>\n<p>&#8220;We recently changed the default settings for education users enrolled in our K-12 program to enable virtual waiting rooms and ensure teachers are the only ones who can share content in class,&#8221; the spokesperson said.&nbsp;<\/p>\n<p>&#8220;Effective April 5, we are enabling passwords and virtual waiting rooms by default for our Free Basic and Single Pro users. We are also continuing to proactively educate users on how they can protect their meetings from unwanted intruders, including through our offering of trainings, tutorials and webinars to help users understand their own account features and how to best use the platform.&#8221;<\/p>\n<p><strong>Read more<\/strong>: <a href=\"https:\/\/www.cnet.com\/how-to\/zoombombing-what-it-is-and-how-you-can-prevent-it-in-zoom-video-chat\/\">Zoombombing: What it is and how you can prevent it in Zoom video chat<\/a><\/p>\n<h3>Usability versus security<\/h3>\n<p>In an interview with NPR, <a href=\"https:\/\/www.npr.org\/sections\/coronavirus-live-updates\/2020\/04\/08\/829330707\/zoom-ceo-tells-npr-he-never-thought-seriously-about-online-harassment-until-now\" rel=\"noopener noreferrer nofollow\" target=\"_blank\" data-component=\"externalLink\">Yuan said the balance between security and user-friendliness had shifted<\/a> for him.&nbsp;<\/p>\n<p>&#8220;When it comes to a conflict between usability and privacy and security, privacy and security [are] more important &#8212; even at the cost of multiple clicks,&#8221; he said. &#8220;We&#8217;re going to transform our business to a privacy-and-security-first mentality.&#8221;<\/p>\n<h3>IDs hidden<\/h3>\n<p>The company released a software update aimed at improving security, which removes the meeting ID from the title bar when meetings are taking place. As reported by Bleeping Computer, the move is meant to <a href=\"https:\/\/www.bleepingcomputer.com\/news\/software\/zoom-removes-meeting-ids-from-client-title-bar-to-boost-security\/\" rel=\"noopener noreferrer nofollow\" target=\"_blank\" data-component=\"externalLink\">slow attackers who circulate screenshots of meeting IDs<\/a> on the open internet.<\/p>\n<h3>Weekly webinars<\/h3>\n<p>Yuan held the first of Zoom&#8217;s promised weekly webinars, available on <a href=\"https:\/\/www.youtube.com\/watch?v=TeohYK-hsO4\" rel=\"noopener noreferrer\" target=\"_blank\" data-component=\"externalLink\">the company&#8217;s YouTube channel<\/a>, emphasizing the surge of users working from home due to the COVID-19 pandemic &#8220;far surpassed anything we expected.&#8221;<\/p>\n<p>Yuan said that prior to the surge, daily peak use of the product amounted to around 10 million users but that it now amounts to more than 200 million. Yuan also detailed the company&#8217;s mistakes during the surge: Zoom&#8217;s user-facing security features aren&#8217;t friendly enough for the average user, and enterprise-focused tools like its <a href=\"https:\/\/www.cnet.com\/news\/using-zoom-while-working-from-home-here-are-the-privacy-risks-to-watch-out-for\/\">attention-tracking feature<\/a> don&#8217;t make sense for privacy-minded average consumers.&nbsp;<\/p>\n<p>Yuan also denied selling any customer data, and he recommended that users engage the software&#8217;s security features as often as possible. He also said the company is working on ensuring Zoom&#8217;s webinar tool has waiting room improvements, which allow meeting hosts to approve users before they can enter a meeting, but he didn&#8217;t have a timeline for completion. Another security feature in the works over the next 45 days is an encryption-standard improvement, and a renewed focus on protecting health-related data, he said.&nbsp;<\/p>\n<h3>AI Zoombomb<\/h3>\n<p><a href=\"https:\/\/www.cnet.com\/how-to\/zoombombing-what-it-is-and-how-to-prevent-it-in-zoom-video-chat\/\">Zoombombing<\/a> took a surreal turn when a Samsung engineer Zoombombed a colleague with an AI-generated version of Elon Musk.&nbsp;<\/p>\n<h2>April 7<\/h2>\n<h3>Taiwan bans Zoom from government use<\/h3>\n<p>Taiwan&#8217;s government agencies were <a href=\"https:\/\/www.zdnet.com\/article\/taiwan-instructs-government-agencies-not-to-use-zoom\/\" rel=\"noopener noreferrer\" target=\"_blank\" data-component=\"externalLink\">told not to use Zoom due to security concerns<\/a>, with Taiwan&#8217;s Department of Cybersecurity authorizing the use of alternatives such as products from Google and Microsoft, according to a statement released Tuesday.&nbsp;<\/p>\n<h2>April 6<\/h2>\n<h3>Some school districts ban Zoom<\/h3>\n<p><span class=\"link\" section=\"shortcodeLink\"><a href=\"https:\/\/www.cnet.com\/news\/school-districts-reportedly-ban-zoom-over-security-issues\/\">School districts began banning teachers from using Zoom<\/a><\/span> to teach remotely in the midst of the coronavirus outbreak, citing security and privacy issues surrounding the videoconferencing app. New York&#8217;s Department of Education urged schools to switch to <span data-error=\"was unable to determine path for annotation\" data-annotation-type=\"CNET_FAM_SERIES\">Microsoft Teams<\/span> &#8220;as soon as possible,&#8221; <a href=\"https:\/\/redirect.viglink.com\/?format=go&amp;jsonp=vglnk_158620522237210&amp;key=ce074976249105acf14d8c9cf69bdcd1&amp;libId=k8oxm95r01003n6p000DA1jf8bshbto7mg&amp;loc=https%3A%2F%2Fwww.cnet.com%2Fnews%2Fschool-districts-reportedly-ban-zoom-over-security-issues%2F&amp;v=1&amp;out=https%3A%2F%2Fchalkbeat.org%2Fposts%2Fny%2F2020%2F04%2F04%2Fnyc-forbids-schools-from-using-zoom-for-remote-learning-after-privacy-concerns-emerge%2F&amp;title=School%20districts%20reportedly%20ban%20Zoom%20over%20security%20issues%20-%20CNET&amp;txt=Chalkbeat%20reported\" rel=\"noopener noreferrer nofollow\" target=\"_blank\" data-component=\"externalLink\">Chalkbeat reported<\/a>.<\/p>\n<h3>Zoom accounts found on the dark web<\/h3>\n<p>Cybersecurity firm Sixgill revealed that it discovered an actor in a popular dark web forum had posted a link to a collection of 352 compromised Zoom accounts. <a href=\"https:\/\/finance.yahoo.com\/news\/hackers-are-posting-verified-zoom-accounts-on-the-dark-web-161442319.html\" rel=\"noopener noreferrer nofollow\" target=\"_blank\" data-component=\"externalLink\">Sixgill told Yahoo Finance<\/a> that these links included email addresses, passwords, meeting IDs, host keys and names, and the type of Zoom account. Most were personal, but not all.<\/p>\n<p>&#8220;One belonged to a major US health care provider, seven more to various educational institutions, and one to a small business,&#8221; Sixgill told Yahoo Finance.&nbsp;<\/p>\n<p><strong>Read more<\/strong>: <span class=\"link\" section=\"shortcodeLink\"><a href=\"https:\/\/www.cnet.com\/news\/zoombombing-what-it-is-and-how-you-can-prevent-it-in-zoom-video-chat\/\">Zoombombing: What it is and how you can prevent it<\/a><\/span><\/p>\n<h3>Zoom seeks to grow its lobbying presence in Washington<\/h3>\n<p>Zoom&#8217;s response to security concerns pivoted to Washington, DC. The company <a href=\"https:\/\/www.politico.com\/newsletters\/morning-tech\/2020\/04\/06\/zoom-looks-to-reframe-its-narrative-in-the-beltway-786661\" rel=\"noopener noreferrer nofollow\" target=\"_blank\" data-component=\"externalLink\">told Politico<\/a> it was looking to grow its lobbying presence in Washington, and had hired Bruce Mehlman, a former assistant secretary of commerce for technology policy under President George W. Bush.&nbsp;<\/p>\n<h3>Urging an FTC investigation<\/h3>\n<p><a href=\"https:\/\/epic.org\/privacy\/ftc\/EPIC-FTC-Zoom-Apr2020.pdf\" rel=\"noopener noreferrer nofollow\" target=\"_blank\" data-component=\"externalLink\">In an open letter<\/a>, the Electronic Privacy Information Center urged the Federal Trade Commission to investigate Zoom and issue privacy guidelines for videoconferencing platforms.&nbsp;<\/p>\n<p>Sen. Richard Blumenthal, a Connecticut Democrat more recently known for spearheading&nbsp; <a href=\"https:\/\/www.eff.org\/deeplinks\/2020\/01\/congress-must-stop-graham-blumenthal-anti-security-bill\" rel=\"noopener noreferrer nofollow\" target=\"_blank\" data-component=\"externalLink\">legislation that critics say could cripple modern encryption standards<\/a>, called on the FTC to investigate Zoom over what he described as &#8220;a pattern of security failures and privacy infringements.&#8221;&nbsp;<\/p>\n<h3>Third class action lawsuit filed<\/h3>\n<p>A <a href=\"https:\/\/drive.google.com\/file\/d\/1Xdfisiu2XETY6nVvMyY--cdJ6QVQcZTq\/view\" rel=\"noopener noreferrer\" target=\"_blank\" data-component=\"externalLink\">third class action lawsuit<\/a> was filed against Zoom in California, citing the three most significant security issues raised by researchers: <a href=\"https:\/\/www.cnet.com\/tags\/facebook\/\" data-annotation=\"true\" data-component=\"linkTracker\" data-link-tracker-options=\"{&quot;action&quot;:&quot;inline-annotation|Facebook|CNET_TAG|418&quot;}\" section=\"annotation\">Facebook<\/a> data-sharing, the company&#8217;s admittedly incomplete end-to-end <a href=\"https:\/\/www.cnet.com\/tags\/encryption\/\" data-annotation=\"true\" data-component=\"linkTracker\" data-link-tracker-options=\"{&quot;action&quot;:&quot;inline-annotation|Encryption|CNET_TAG|325&quot;}\" section=\"annotation\">encryption<\/a>, and the vulnerability which allows malicious actors to access users&#8217; webcams.&nbsp;<\/p>\n<p><strong>Read more:<\/strong> <a href=\"https:\/\/www.cnet.com\/news\/10-free-zoom-alternative-apps-for-video-chats\/\">10 free Zoom alternative apps for video chats<\/a><\/p>\n<h2>April 5&nbsp;<\/h2>\n<h3>Calls mistakenly routed through Chinese whitelisted servers<\/h3>\n<p>In a statement, Zoom admitted that <a href=\"https:\/\/finance.yahoo.com\/news\/zoom-admits-calls-were-mistakenly-123356776.html\" rel=\"noopener noreferrer nofollow\" target=\"_blank\" data-component=\"externalLink\">some video calls were &#8220;mistakenly&#8221; routed through two Chinese whitelisted servers<\/a> when they should not have been. Certain meetings were &#8220;allowed to connect to systems in China, where they should not have been able to connect,&#8221; it said.&nbsp;<\/p>\n<h2>April 4<\/h2>\n<h3>Another Zoom apology<\/h3>\n<p>&#8220;I really messed up as CEO, and we need to win their trust back. This kind of thing shouldn&#8217;t have happened,&#8221; <a href=\"https:\/\/www.wsj.com\/articles\/zoom-ceo-i-really-messed-up-on-security-as-coronavirus-drove-video-tools-appeal-11586031129\" rel=\"noopener noreferrer nofollow\" target=\"_blank\" data-component=\"externalLink\">Zoom CEO Eric Yuan told the Wall Street Journal<\/a> in a lengthy interview.&nbsp;<\/p>\n<p>Surveying the damage to the company&#8217;s reputation, Yuan described how Zoom pushed for expansion in an effort to accommodate workforce changes during the early stages of the COVID-19 outbreak in China.&nbsp;<\/p>\n<h2>April 3<\/h2>\n<h3>Zoom video call records left viewable on the web<\/h3>\n<p>An <a href=\"https:\/\/www.washingtonpost.com\/technology\/2020\/04\/03\/thousands-zoom-video-calls-left-exposed-open-web\/\" rel=\"noopener noreferrer\" target=\"_blank\" data-component=\"externalLink\">investigation by The Washington Post<\/a> found thousands of recordings of Zoom video calls were left unprotected and viewable on the open web. A large number of the unprotected calls included discussion of personally identifiable information, such as private therapy sessions, telehealth training calls, small-business meetings that discussed private company financial statements, and elementary school classes with student information exposed, the newspaper found.&nbsp;<\/p>\n<h3>Attackers planning &#8216;Zoomraids&#8217;<\/h3>\n<p>Reporting from both <span class=\"link\" section=\"shortcodeLink\"><a href=\"https:\/\/www.cnet.com\/news\/instagram-twitter-used-to-organize-harassment-campaigns-on-zoom\/\">CNET<\/a><\/span> and&nbsp;<a href=\"https:\/\/www.nytimes.com\/2020\/04\/03\/technology\/zoom-harassment-abuse-racism-fbi-warning.html\" rel=\"noopener noreferrer\" target=\"_blank\" data-component=\"externalLink\">The New York Times<\/a> revealed social media platforms, including <a href=\"https:\/\/www.cnet.com\/tags\/twitter\/\" data-annotation=\"true\" data-component=\"linkTracker\" data-link-tracker-options=\"{&quot;action&quot;:&quot;inline-annotation|Twitter|CNET_TAG|150&quot;}\" section=\"annotation\">Twitter<\/a> and Instagram, were being used by anonymous attackers as spaces to organize &#8220;Zoomraids&#8221; &#8212; the term for coordinated mass Zoombombings where intruders harass and abuse private meeting attendees. Abuse reported during Zoomraids has included the use of racist, anti-Semitic and pornographic imagery, as well as verbal harassment.<\/p>\n<h3>Zoom apologizes, again<\/h3>\n<p><a href=\"https:\/\/www.zdnet.com\/article\/zoom-concedes-custom-encryption-is-sub-standard-as-citizen-lab-pokes-holes-in-it\/\" rel=\"noopener noreferrer\" target=\"_blank\" data-component=\"externalLink\">Zoom conceded that its custom encryption is substandard<\/a> after a Citizen Lab report found the company had been rolling its own encryption scheme, using a less secure AES-128 key instead of the AES-256 encryption it previously claimed to be using. <a href=\"https:\/\/blog.zoom.us\/wordpress\/2020\/04\/03\/response-to-research-from-university-of-torontos-citizen-lab\/\" rel=\"noopener noreferrer nofollow\" target=\"_blank\" data-component=\"externalLink\">In a direct response<\/a>, Yuan said publicly, &#8220;We recognize that we can do better with our encryption design.&#8221;<\/p>\n<h3>Second class action lawsuit filed<\/h3>\n<p>Tycko and Zavareei LLP filed a <a href=\"https:\/\/www.dropbox.com\/s\/h078rfxsq4x22um\/TZ_TaylorVZoom_Complaint_Final.pdf?dl=0\" rel=\"noopener noreferrer nofollow\" target=\"_blank\" data-component=\"externalLink\">class action lawsuit against Zoom<\/a> &#8212; the second suit against the company &#8212; for sharing users&#8217; personal information with Facebook.<\/p>\n<h3>Congress requests information<\/h3>\n<p>Democratic Rep. Jerry McNerney of California and 18 of his Democratic colleagues from the House Committee on Energy and Commerce sent <a href=\"https:\/\/mcnerney.house.gov\/sites\/mcnerney.house.gov\/files\/Letter%20to%20Zoom_04.03.2020.pdf\" rel=\"noopener noreferrer nofollow\" target=\"_blank\" data-component=\"externalLink\">a letter to Yuan<\/a> raising concerns and questions regarding the company&#8217;s privacy practices. The letter requested a response from Zoom by April 10.&nbsp;<\/p>\n<div class=\"shortcode video v2\" data-video-playlist=\"[{&quot;id&quot;:&quot;f82f03a2-212c-41a5-83f1-82b296c4ed43&quot;,&quot;title&quot;:&quot;Zoom responds to privacy concerns&quot;,&quot;description&quot;:&quot;This week\\u0027s major tech stories include Zoom\\u0027s response to privacy concerns, coronavirus scams already costing consumers millions and reports that say Nintendo is planning a slew of Mario releases to celebrate the iconic videogame character\\u0027s 35th anniversary.&quot;,&quot;slug&quot;:&quot;zoom-responds-to-privacy-concerns&quot;,&quot;chapters&quot;:{&quot;data&quot;:[],&quot;paging&quot;:{&quot;total&quot;:0,&quot;limit&quot;:15,&quot;offset&quot;:0}},&quot;datePublished&quot;:&quot;2020-04-04 11:00:01&quot;,&quot;duration&quot;:94,&quot;mpxRefId&quot;:&quot;jauE_9n2XQxhw_UdCt6lhotJZ2Whu1ZL&quot;,&quot;ratingVChip&quot;:&quot;TV-14&quot;,&quot;primaryTopic&quot;:{&quot;id&quot;:&quot;1c0fd1cb-c387-11e2-8208-0291187b029a&quot;},&quot;author&quot;:{&quot;id&quot;:&quot;3dd87c14-8176-11e2-9d12-0018fe8a00b0&quot;,&quot;firstName&quot;:&quot;Jeff&quot;,&quot;lastName&quot;:&quot;Bakalar&quot;},&quot;primaryCollection&quot;:{&quot;id&quot;:&quot;0d8f9ac8-61cb-4e36-9263-552d5468e04b&quot;,&quot;title&quot;:&quot;Tech Today&quot;},&quot;image&quot;:{&quot;path&quot;:&quot;https:\\\/\\\/cnet3.cbsistatic.com\\\/img\\\/VIXpYJfNcblSy4WVFSxmgul7tls=\\\/1280x720\\\/2020\\\/04\\\/03\\\/6b30218b-e3db-4e8f-9631-e0cf09a858f8\\\/040420pic.jpg&quot;},&quot;thumbnail&quot;:&quot;https:\\\/\\\/cnet2.cbsistatic.com\\\/img\\\/7LfEVkEtqG5Dp0xC4sRymYfcgdw=\\\/194x109\\\/2020\\\/04\\\/03\\\/6b30218b-e3db-4e8f-9631-e0cf09a858f8\\\/040420pic.jpg&quot;,&quot;closedCaptionPath&quot;:&quot;\\\/videos\\\/captions\\\/webvtt\\\/zoom-responds-to-privacy-concerns.vtt&quot;,&quot;urlPath&quot;:&quot;\\\/videos\\\/zoom-responds-to-privacy-concerns\\\/&quot;,&quot;isVertical&quot;:false,&quot;m3u8&quot;:&quot;https:\\\/\\\/cnetvideo.cbsistatic.com\\\/vr\\\/2020\\\/04\\\/03\\\/1720093251831\\\/292785_hls\\\/master.m3u8&quot;,&quot;mp4&quot;:&quot;https:\\\/\\\/cnetvideo.cbsistatic.com\\\/vr\\\/2020\\\/04\\\/03\\\/1720093251831\\\/TT_040420_292784_740.mp4&quot;,&quot;index&quot;:0}]\" readability=\"6\">\n<div class=\"embeddedVideoContainer\" tabindex=\"0\" aria-label=\"Play video Zoom responds to privacy concerns\" data-load-video=\"0\" data-video-id=\"f82f03a2-212c-41a5-83f1-82b296c4ed43\" readability=\"7\">\n<div class=\"videoContainer\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/cnet2.cbsistatic.com\/img\/vyFIlG3rad_R7C-2NC7hn20vfhE=\/196x110\/2020\/04\/03\/6b30218b-e3db-4e8f-9631-e0cf09a858f8\/040420pic.jpg\" class=\"photo\" alt height=\"110\" width=\"196\"><\/div>\n<p><span class=\"bold\"><span class=\"nowPlaying\">Now playing:<\/span> <span class=\"watchThis\">Watch this:<\/span><\/span> Zoom responds to privacy concerns<\/p>\n<p><span class=\"duration\">1:34<\/span><\/p>\n<\/div>\n<\/div>\n<h2>April 2<\/h2>\n<h3>Automated tool can find Zoom meetings<\/h3>\n<p>Security researchers revealed an automated tool was able to find around 100 Zoom meeting IDs in an hour, gathering information for nearly 2,400 Zoom meetings in a single day of scans, as reported by <a href=\"https:\/\/krebsonsecurity.com\/2020\/04\/war-dialing-tool-exposes-zooms-password-problems\/\" rel=\"noopener noreferrer nofollow\" target=\"_blank\" data-component=\"externalLink\">security expert Brian Krebs<\/a>.&nbsp;<\/p>\n<div class=\"twitterContainer\" readability=\"5.6687116564417\">\n<blockquote class=\"twitter-tweet\" readability=\"5.6687116564417\">\n<p lang=\"en\" dir=\"ltr\">Automated Zoom conference meeting finder &#8216;zWarDial&#8217; discovers ~100 meetings per hour that aren&#8217;t protected by passwords. The tool also has prompted Zoom to investigate whether its password-by-default approach might be malfunctioning <a href=\"https:\/\/t.co\/dXNq6KUYb3\" rel=\"noopener noreferrer nofollow\" target=\"_blank\" data-component=\"externalLink\">https:\/\/t.co\/dXNq6KUYb3<\/a> <a href=\"https:\/\/t.co\/h0vB1Cp9Tb\" rel=\"noopener noreferrer nofollow\" target=\"_blank\" data-component=\"externalLink\">pic.twitter.com\/h0vB1Cp9Tb<\/a><\/p>\n<p>\u2014 briankrebs (@briankrebs) <a href=\"https:\/\/twitter.com\/briankrebs\/status\/1245742480462696448?ref_src=twsrc%5Etfw\" rel=\"noopener noreferrer\" target=\"_blank\" data-component=\"externalLink\">April 2, 2020<\/a><\/p><\/blockquote>\n<\/div>\n<p>The discoverable meetings were those left unprotected by passwords, but the tool was able to successfully generate meeting IDs up to 14% of the time, according to <a href=\"https:\/\/www.theverge.com\/2020\/4\/2\/21206061\/zoom-meeting-id-zwardial-automated-tool\" rel=\"noopener noreferrer nofollow\" target=\"_blank\" data-component=\"externalLink\">reporting from The Verge<\/a>.&nbsp;<\/p>\n<h3>More plans for Zoombombing<\/h3>\n<p>Motherboard, meanwhile, discovered that 8chan forum users had <a href=\"https:\/\/www.vice.com\/en_us\/article\/qjd9b7\/8chan-users-coordinated-antisemitic-zoombombing-campaign\" rel=\"noopener noreferrer nofollow\" target=\"_blank\" data-component=\"externalLink\">planned to hijack the Zoom calls<\/a> of a Jewish school in Philadelphia in an anti-Semitic Zoombombing campaign.<\/p>\n<h3>Data-mining feature discovered<\/h3>\n<p>The <a href=\"https:\/\/www.nytimes.com\/2020\/04\/02\/technology\/zoom-linkedin-data.html\" rel=\"noopener noreferrer\" target=\"_blank\" data-component=\"externalLink\">New York Times reported<\/a> that a data-mining feature on Zoom allowed some participants to surreptitiously have access to <a href=\"https:\/\/www.cnet.com\/tags\/linkedin\/\" data-annotation=\"true\" data-component=\"linkTracker\" data-link-tracker-options=\"{&quot;action&quot;:&quot;inline-annotation|LinkedIn|CNET_TAG|150&quot;}\" section=\"annotation\">LinkedIn<\/a> profile data about other users.<\/p>\n<h2>April 1<\/h2>\n<h3>SpaceX bans Zoom<\/h3>\n<p>Elon Musk&#8217;s <span class=\"link\" section=\"shortcodeLink\"><a href=\"https:\/\/www.cnet.com\/news\/spacex-everything-to-know-about-elon-musk-space-company\/\">SpaceX<\/a><\/span> rocket company prohibited employees from using Zoom, citing &#8220;significant privacy and security concerns,&#8221; <span class=\"link\" section=\"shortcodeLink\"><a href=\"https:\/\/www.cnet.com\/news\/spacex-reportedly-bans-use-of-zoom-videoconferencing-app-by-employees\/\">as reported by Reuters<\/a><\/span>.&nbsp;<\/p>\n<h3>More security flaws discovered<\/h3>\n<p><a href=\"https:\/\/www.vice.com\/en_us\/article\/k7e95m\/zoom-leaking-email-addresses-photos\" rel=\"noopener noreferrer nofollow\" target=\"_blank\" data-component=\"externalLink\">Reporting from Motherboard<\/a>&nbsp;again revealed another damaging security flaw in Zoom, finding the application was leaking users&#8217; email addresses and photos to strangers via a feature loosely designed to operate as a company directory.&nbsp;<\/p>\n<h3>Apologies from Yuan<\/h3>\n<p>Yuan issued a public apology <a href=\"https:\/\/blog.zoom.us\/wordpress\/2020\/04\/01\/a-message-to-our-users\/\" rel=\"noopener noreferrer nofollow\" target=\"_blank\" data-component=\"externalLink\">in a blog post<\/a>, and vowed to improve security. That included enabling waiting rooms and password protection for all calls. Yuan also said the company would <span class=\"link\" section=\"shortcodeLink\"><a href=\"https:\/\/www.cnet.com\/news\/zoom-boss-says-itll-freeze-feature-updates-to-address-security-issues\/\">freeze features updates to address security issues<\/a><\/span> in the next 90 days. &nbsp;<\/p>\n<h2>March 30&nbsp;<\/h2>\n<h3>The Intercept investigation: Zoom doesn&#8217;t use end-to-end encryption as promised<\/h3>\n<p>An <a href=\"https:\/\/theintercept.com\/2020\/03\/31\/zoom-meeting-encryption\/\" rel=\"noopener noreferrer nofollow\" target=\"_blank\" data-component=\"externalLink\">investigation by The Intercept<\/a> found that Zoom call data was being sent back to the company without the end-to-end encryption promised in its marketing materials.&nbsp;<\/p>\n<p>&#8220;Currently, it is not possible to enable E2E encryption for Zoom video meetings,&#8221; a Zoom spokesperson told The Intercept.&nbsp;<\/p>\n<h3>More bugs discovered<\/h3>\n<p>After the discovery of a Windows-related Zoom bug that opened people up to password theft, two more bugs were <a href=\"https:\/\/appleinsider.com\/articles\/20\/04\/01\/two-more-macos-zoom-flaws-surface-as-lawsuit-government-probe-loom\" rel=\"noopener noreferrer nofollow\" target=\"_blank\" data-component=\"externalLink\">discovered by a former NSA hacker<\/a>, one of which could allow malicious actors to assume control of a Zoom user&#8217;s microphone or webcam. Another of the vulnerabilities allowed Zoom to gain root access on MacOS <a href=\"https:\/\/www.cnet.com\/topics\/desktops\/\" data-annotation=\"true\" data-component=\"linkTracker\" data-link-tracker-options=\"{&quot;action&quot;:&quot;inline-annotation|Desktops|CNET_CAT_TOPIC|225&quot;}\" section=\"annotation\">desktops<\/a>, a risky level of access at best. &nbsp;<\/p>\n<div class=\"twitterContainer\" readability=\"6.8869565217391\">\n<blockquote class=\"twitter-tweet\" readability=\"7.7478260869565\">\n<p lang=\"en\" dir=\"ltr\">Ever wondered how the <a href=\"https:\/\/twitter.com\/zoom_us?ref_src=twsrc%5Etfw\" rel=\"noopener noreferrer\" target=\"_blank\" data-component=\"externalLink\">@zoom_us<\/a> macOS installer does it\u2019s job without you ever clicking install? Turns out they (ab)use preinstallation scripts, manually unpack the app using a bundled 7zip and install it to \/Applications if the current user is in the admin group (no root needed). <a href=\"https:\/\/t.co\/qgQ1XdU11M\" rel=\"noopener noreferrer nofollow\" target=\"_blank\" data-component=\"externalLink\">pic.twitter.com\/qgQ1XdU11M<\/a><\/p>\n<p>\u2014 Felix (@c1truz_) <a href=\"https:\/\/twitter.com\/c1truz_\/status\/1244737672930824193?ref_src=twsrc%5Etfw\" rel=\"noopener noreferrer\" target=\"_blank\" data-component=\"externalLink\">March 30, 2020<\/a><\/p><\/blockquote>\n<\/div>\n<h3>First class action lawsuit filed<\/h3>\n<p>A <a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2020-03-31\/zoom-sued-for-allegedly-illegally-disclosing-personal-data\" rel=\"noopener noreferrer nofollow\" target=\"_blank\" data-component=\"externalLink\">class-action lawsuit was filed<\/a> against the company, alleging that Zoom violated California&#8217;s new data protection law by not obtaining proper consent from users about the transfer of their Zoom data to Facebook.&nbsp;<\/p>\n<h3>Letter from New York Attorney General sent<\/h3>\n<p>The office of New York Attorney General Letitia James <a href=\"https:\/\/www.nytimes.com\/2020\/03\/30\/technology\/new-york-attorney-general-zoom-privacy.html\" rel=\"noopener noreferrer\" target=\"_blank\" data-component=\"externalLink\">sent Zoom a letter<\/a> outlining privacy vulnerability concerns, and asking what steps, if any, the company had put in place to keep its users safe, given the increased traffic on its network.&nbsp;<\/p>\n<h3>Classroom Zoombombings reported<\/h3>\n<p>Reporting cases of classroom Zoombombings, including an incident where hackers broke into a class meeting&nbsp; and displayed a swastika on students&#8217; screens, led the FBI to <a href=\"https:\/\/www.fbi.gov\/contact-us\/field-offices\/boston\/news\/press-releases\/fbi-warns-of-teleconferencing-and-online-classroom-hijacking-during-covid-19-pandemic\" rel=\"noopener noreferrer nofollow\" target=\"_blank\" data-component=\"externalLink\">issue a public warning<\/a> about Zoom&#8217;s security vulnerabilities. The organization advised educators to protect video calls with passwords and to lock down meeting security with currently available privacy features in the software. &nbsp;<\/p>\n<h2>March 27<\/h2>\n<h3>Zoom removes Facebook data collection feature<\/h3>\n<p>Responding to concerns raised by the Motherboard investigation, <a href=\"https:\/\/www.vice.com\/en_us\/article\/z3b745\/zoom-removes-code-that-sends-data-to-facebook\" rel=\"noopener noreferrer nofollow\" target=\"_blank\" data-component=\"externalLink\">Zoom removed the Facebook data collection feature<\/a> from its <a href=\"https:\/\/www.cnet.com\/tags\/ios-12\/\" data-annotation=\"true\" data-component=\"linkTracker\" data-link-tracker-options=\"{&quot;action&quot;:&quot;inline-annotation|iOS 12|CNET_TAG|183&quot;}\" section=\"annotation\">iOS<\/a> app and apologized in a statement.&nbsp;<\/p>\n<p>&#8220;The data collected by the Facebook SDK did not include any personal user information, but rather included data about users&#8217; devices such as the mobile OS type and version, the device time zone, device OS, device model and carrier, screen size, processor cores, and disk space,&#8221; Zoom told Motherboard.&nbsp;<\/p>\n<h2>March 26&nbsp;<\/h2>\n<h3>Motherboard investigation: Zoom iOS app sending user data to Facebook<\/h3>\n<p>An <a href=\"https:\/\/www.vice.com\/en_us\/article\/k7e599\/zoom-ios-app-sends-data-to-facebook-even-if-you-dont-have-a-facebook-account\" rel=\"noopener noreferrer nofollow\" target=\"_blank\" data-component=\"externalLink\">investigation by Motherboard<\/a> revealed that Zoom&#8217;s iOS app was sending user analytics data to Facebook, even for Zoom users who did not have a Facebook account, via the app&#8217;s interaction with Facebook&#8217;s Graph API.&nbsp;<\/p>\n<hr>\n<div class=\"shortcode video v2\" data-video-playlist=\"[{&quot;id&quot;:&quot;0839d803-4b60-42a7-a693-78b9c397c7fd&quot;,&quot;title&quot;:&quot;YouTube at work on TikTok rival, Zoom\\u0027s privacy risks&quot;,&quot;description&quot;:&quot;Today\\u0027s major tech headlines include YouTube\\u0027s work on a TikTok rival, the potential privacy risks associated with using the now ultra-popular Zoom service and a report that says consumers have already lost millions thanks to coronavirus scams.&quot;,&quot;slug&quot;:&quot;youtube-at-work-on-tiktok-rival-zooms-privacy-risks&quot;,&quot;chapters&quot;:{&quot;data&quot;:[],&quot;paging&quot;:{&quot;total&quot;:0,&quot;limit&quot;:15,&quot;offset&quot;:0}},&quot;datePublished&quot;:&quot;2020-04-02 11:00:01&quot;,&quot;duration&quot;:103,&quot;mpxRefId&quot;:&quot;ei_rxLt1tKDMRgB_NYcxSUtINYsJJ2HX&quot;,&quot;ratingVChip&quot;:&quot;TV-14&quot;,&quot;primaryTopic&quot;:{&quot;id&quot;:&quot;1c0fd1cb-c387-11e2-8208-0291187b029a&quot;},&quot;author&quot;:{&quot;id&quot;:&quot;3dd87c14-8176-11e2-9d12-0018fe8a00b0&quot;,&quot;firstName&quot;:&quot;Jeff&quot;,&quot;lastName&quot;:&quot;Bakalar&quot;},&quot;primaryCollection&quot;:{&quot;id&quot;:&quot;0d8f9ac8-61cb-4e36-9263-552d5468e04b&quot;,&quot;title&quot;:&quot;Tech Today&quot;},&quot;image&quot;:{&quot;path&quot;:&quot;https:\\\/\\\/cnet3.cbsistatic.com\\\/img\\\/rNpb7o4L85kNWjtWlwRH4FlfNd4=\\\/1280x720\\\/2020\\\/04\\\/02\\\/49b2a1b4-2858-4346-adb3-c36e4e91bcc5\\\/tt-040220.jpg&quot;},&quot;thumbnail&quot;:&quot;https:\\\/\\\/cnet2.cbsistatic.com\\\/img\\\/1HRt0w3CfVyhOTtriovMuvXWtVA=\\\/194x109\\\/2020\\\/04\\\/02\\\/49b2a1b4-2858-4346-adb3-c36e4e91bcc5\\\/tt-040220.jpg&quot;,&quot;closedCaptionPath&quot;:&quot;\\\/videos\\\/captions\\\/webvtt\\\/youtube-at-work-on-tiktok-rival-zooms-privacy-risks.vtt&quot;,&quot;urlPath&quot;:&quot;\\\/videos\\\/youtube-at-work-on-tiktok-rival-zooms-privacy-risks\\\/&quot;,&quot;isVertical&quot;:false,&quot;m3u8&quot;:&quot;https:\\\/\\\/cnetvideo.cbsistatic.com\\\/vr\\\/2020\\\/04\\\/02\\\/1719200323740\\\/292313_hls\\\/master.m3u8&quot;,&quot;mp4&quot;:&quot;https:\\\/\\\/cnetvideo.cbsistatic.com\\\/vr\\\/2020\\\/04\\\/02\\\/1719200323740\\\/TT_040220_292312_740.mp4&quot;,&quot;index&quot;:0}]\" readability=\"6.5\">\n<div class=\"embeddedVideoContainer\" tabindex=\"0\" aria-label=\"Play video YouTube at work on TikTok rival, Zoom's privacy risks\" data-load-video=\"0\" data-video-id=\"0839d803-4b60-42a7-a693-78b9c397c7fd\" readability=\"8\">\n<div class=\"videoContainer\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/cnet2.cbsistatic.com\/img\/8yS7zmGW_3yWN-1xeFlhSU4U8Ig=\/196x110\/2020\/04\/02\/49b2a1b4-2858-4346-adb3-c36e4e91bcc5\/tt-040220.jpg\" class=\"photo\" alt height=\"110\" width=\"196\"><\/div>\n<p><span class=\"bold\"><span class=\"nowPlaying\">Now playing:<\/span> <span class=\"watchThis\">Watch this:<\/span><\/span> YouTube at work on TikTok rival, Zoom&#8217;s privacy risks<\/p>\n<p><span class=\"duration\">1:43<\/span><\/p>\n<\/div>\n<\/div>\n<p>READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/31115\/Zoom-Every-Security-Issue-Uncovered-In-The-Video-Chat-App.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":34406,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[60],"tags":[8580],"class_list":["post-34405","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-packet-storm","tag-headlinehackerprivacyphoneflawcryptography"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Zoom: Every Security Issue Uncovered In The Video Chat App 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/zoom-every-security-issue-uncovered-in-the-video-chat-app\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Zoom: Every Security Issue Uncovered In The Video Chat App 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/zoom-every-security-issue-uncovered-in-the-video-chat-app\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2020-04-14T14:32:56+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/04\/zoom-every-security-issue-uncovered-in-the-video-chat-app.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1092\" \/>\n\t<meta property=\"og:image:height\" content=\"728\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"15 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zoom-every-security-issue-uncovered-in-the-video-chat-app\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zoom-every-security-issue-uncovered-in-the-video-chat-app\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Zoom: Every Security Issue Uncovered In The Video Chat App\",\"datePublished\":\"2020-04-14T14:32:56+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zoom-every-security-issue-uncovered-in-the-video-chat-app\\\/\"},\"wordCount\":2978,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zoom-every-security-issue-uncovered-in-the-video-chat-app\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/04\\\/zoom-every-security-issue-uncovered-in-the-video-chat-app.jpg\",\"keywords\":[\"headline,hacker,privacy,phone,flaw,cryptography\"],\"articleSection\":[\"Packet Storm\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zoom-every-security-issue-uncovered-in-the-video-chat-app\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zoom-every-security-issue-uncovered-in-the-video-chat-app\\\/\",\"name\":\"Zoom: Every Security Issue Uncovered In The Video Chat App 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zoom-every-security-issue-uncovered-in-the-video-chat-app\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zoom-every-security-issue-uncovered-in-the-video-chat-app\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/04\\\/zoom-every-security-issue-uncovered-in-the-video-chat-app.jpg\",\"datePublished\":\"2020-04-14T14:32:56+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zoom-every-security-issue-uncovered-in-the-video-chat-app\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zoom-every-security-issue-uncovered-in-the-video-chat-app\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zoom-every-security-issue-uncovered-in-the-video-chat-app\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/04\\\/zoom-every-security-issue-uncovered-in-the-video-chat-app.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/04\\\/zoom-every-security-issue-uncovered-in-the-video-chat-app.jpg\",\"width\":1092,\"height\":728},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zoom-every-security-issue-uncovered-in-the-video-chat-app\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,hacker,privacy,phone,flaw,cryptography\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinehackerprivacyphoneflawcryptography\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Zoom: Every Security Issue Uncovered In The Video Chat App\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Zoom: Every Security Issue Uncovered In The Video Chat App 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/zoom-every-security-issue-uncovered-in-the-video-chat-app\/","og_locale":"en_US","og_type":"article","og_title":"Zoom: Every Security Issue Uncovered In The Video Chat App 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/zoom-every-security-issue-uncovered-in-the-video-chat-app\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2020-04-14T14:32:56+00:00","og_image":[{"width":1092,"height":728,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/04\/zoom-every-security-issue-uncovered-in-the-video-chat-app.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"15 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/zoom-every-security-issue-uncovered-in-the-video-chat-app\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/zoom-every-security-issue-uncovered-in-the-video-chat-app\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Zoom: Every Security Issue Uncovered In The Video Chat App","datePublished":"2020-04-14T14:32:56+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/zoom-every-security-issue-uncovered-in-the-video-chat-app\/"},"wordCount":2978,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/zoom-every-security-issue-uncovered-in-the-video-chat-app\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/04\/zoom-every-security-issue-uncovered-in-the-video-chat-app.jpg","keywords":["headline,hacker,privacy,phone,flaw,cryptography"],"articleSection":["Packet Storm"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/zoom-every-security-issue-uncovered-in-the-video-chat-app\/","url":"https:\/\/www.threatshub.org\/blog\/zoom-every-security-issue-uncovered-in-the-video-chat-app\/","name":"Zoom: Every Security Issue Uncovered In The Video Chat App 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/zoom-every-security-issue-uncovered-in-the-video-chat-app\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/zoom-every-security-issue-uncovered-in-the-video-chat-app\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/04\/zoom-every-security-issue-uncovered-in-the-video-chat-app.jpg","datePublished":"2020-04-14T14:32:56+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/zoom-every-security-issue-uncovered-in-the-video-chat-app\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/zoom-every-security-issue-uncovered-in-the-video-chat-app\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/zoom-every-security-issue-uncovered-in-the-video-chat-app\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/04\/zoom-every-security-issue-uncovered-in-the-video-chat-app.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/04\/zoom-every-security-issue-uncovered-in-the-video-chat-app.jpg","width":1092,"height":728},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/zoom-every-security-issue-uncovered-in-the-video-chat-app\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,hacker,privacy,phone,flaw,cryptography","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinehackerprivacyphoneflawcryptography\/"},{"@type":"ListItem","position":3,"name":"Zoom: Every Security Issue Uncovered In The Video Chat App"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/34405","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=34405"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/34405\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/34406"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=34405"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=34405"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=34405"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}